Commit graph

118 commits

Author SHA1 Message Date
Kevin Fenzi
b1a2d105c9 In ansible 2.2 always_run is depreciated. Switch to check_mode. 2016-11-01 16:29:49 +00:00
Patrick Uiterwijk
fa67aa9531 The backends actually use 88
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-25 16:52:01 +00:00
Patrick Uiterwijk
bf5ec300ff Add krb:1088 to haproxy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-25 16:46:32 +00:00
Patrick Uiterwijk
39c59360d8 We now also have certificates for production IPA
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-13 13:59:19 +00:00
Patrick Uiterwijk
1c74f98cca Add production IPA cert
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-13 13:46:34 +00:00
Patrick Uiterwijk
0a5758a918 Add IPA to proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-13 11:23:52 +00:00
Patrick Uiterwijk
6550392ee7 Deploy mirrorlist as docker container on staging
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-09 00:43:05 +00:00
Kevin Fenzi
a21b3b5448 Drop gallery from stg. 2016-09-16 17:34:13 +00:00
1c43c268bc Add proxy config for stg only
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2016-09-06 04:55:23 +00:00
Patrick Uiterwijk
18d37c7875 Enable candidate registry on prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-02 14:34:57 +00:00
Patrick Uiterwijk
0cd6667e7f Create candidate registry at proxy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-29 16:50:20 +00:00
Kevin Fenzi
221479b040 Rework haproxy template so we do not have a block of whitespace changes with staging conditionals 2016-08-08 17:08:42 +00:00
Patrick Uiterwijk
4790fb31d8 Update check url for ipa
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-04 21:47:52 +00:00
Patrick Uiterwijk
0a85ce47cf This is not a client cert...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-04 21:26:40 +00:00
Patrick Uiterwijk
ffd0a12fa4 Fix stg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-04 21:25:11 +00:00
Patrick Uiterwijk
28ebec92ee Proxy IPA through haproxy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-04 21:23:07 +00:00
56ca900f6e missed this one
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2016-08-03 09:26:16 +00:00
447341f88d blah paths
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2016-08-03 08:30:26 +00:00
d0e6cdf04c try adding fas3 to haproxy stg?
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2016-08-03 07:34:38 +00:00
Pierre-Yves Chibon
499a4b49af pps is port 80 2016-07-27 15:59:00 +02:00
Pierre-Yves Chibon
0279643468 Add ++ service to the proxies 2016-07-27 15:19:24 +02:00
Pierre-Yves Chibon
e9c9707c51 Move mdapi to run at port 8080 2016-07-27 14:20:04 +02:00
Patrick Uiterwijk
8a5171cc67 osbs-master01 dns has synced out. Enable it
This reverts commit f992ec5593.
2016-07-14 12:26:11 +00:00
Patrick Uiterwijk
f992ec5593 Don't deploy osbs to haproxy just yet
This reverts commit 440abf0ea7.
2016-07-13 23:44:42 +00:00
Patrick Uiterwijk
440abf0ea7 Also deploy haproxy for osbs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-07-13 23:02:29 +00:00
Patrick Uiterwijk
86b83c3e2b Enable registry.fp.o prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-07-12 15:22:05 +00:00
Kevin Fenzi
71f5bd9bb5 Setup varnish to handle lists.fedoraproject.org. 2016-05-18 17:39:43 +00:00
Michael Simacek
c2bbe8e9e5 Point haproxy at koschei-backend 2016-05-12 15:46:09 +00:00
Patrick Uiterwijk
0a12373742 Seems OSBS requires port 8443
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-15 11:01:02 +00:00
Michael Simacek
cc9d792966 Fix stg condition 2016-04-15 12:50:07 +02:00
Michael Simacek
b5d33a6199 Point haproxy at koschei-web in stg 2016-04-15 01:21:15 +02:00
Patrick Uiterwijk
97b00e90ab Use Fedora proxies as only proxy for Docker Registry
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-12 13:56:26 +00:00
Kevin Fenzi
193bdc7ba1 Move bodhi02.stg to bodhi01.stg since it's not booting right anyhow. 2016-04-11 19:28:13 +00:00
Patrick Uiterwijk
02e7acf487 For osbs and docker, we have internal SSL as well as external
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 17:49:43 +00:00
Patrick Uiterwijk
6afb9e9f5a These were supposed to be staging-only, not production-only
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 17:03:23 +00:00
Patrick Uiterwijk
7e64e13604 Add haproxy entries for osbs, docker-registry, retrace and faf
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 17:02:10 +00:00
Patrick Uiterwijk
8b7fd1a7d8 Finish merge by removing the prod in task name
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 16:55:04 +00:00
Patrick Uiterwijk
488bc45cfc Fix missing space
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 16:51:43 +00:00
Patrick Uiterwijk
4330aa92f3 Fix two copy-paste errors in the merge
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 16:48:36 +00:00
Patrick Uiterwijk
7c611964d6 Merge stg and prod haproxy config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-04-05 16:45:38 +00:00
Michael Scherer
856abe494e Move a few handlers to the only role using them 2016-04-04 20:46:29 +00:00
Ralph Bean
9a28ab58eb Proxy config for zanata2fedmsg. 2016-03-04 19:37:31 +00:00
Ralph Bean
2a9caceebe Back in you go. 2016-02-26 22:10:35 +00:00
Ralph Bean
9ceed08aa6 Try again. 2016-02-26 21:19:18 +00:00
Ralph Bean
707851edb1 Take datagrepper01 out of haproxy to test in isolation. 2016-02-26 21:13:57 +00:00
Kevin Fenzi
43ac10c8cd Switch darkserver in stg to use darkserver-web01 and darkserver-web02 2016-01-29 20:42:06 +00:00
Kevin Fenzi
9a29e07d3c Revert "Drop the openqa haproxy check in production too."
This reverts commit d50a8c1453.
2016-01-27 22:20:24 +00:00
Patrick Uiterwijk
342c9cf65e This needs /darkserver/
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-01-27 21:24:35 +00:00
Patrick Uiterwijk
4a031d01e5 Proxy darkserver
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-01-27 21:18:49 +00:00
Kevin Fenzi
d50a8c1453 Drop the openqa haproxy check in production too. 2016-01-27 18:56:31 +00:00