Commit graph

6941 commits

Author SHA1 Message Date
Mark O'Brien
75f42908a1 osbs: create network file for eth0 stage 2020-11-11 11:43:41 +00:00
Mark O'Brien
e7bbf8ff29 osbs: update python package to py3 stage 2020-11-11 11:34:38 +00:00
Pavel Raiskup
04aa62f691 copr: comment-out persistent_clout.yml
At this moment we don't have any OpenStack for that, and the recursive
include of basessh role breaks the playbook execution.
2020-11-11 11:17:07 +01:00
Mark O'Brien
924aef6f79 osbs: dont install fas in staging 2020-11-11 09:16:49 +00:00
Pavel Raiskup
f6fe521591 copr: enable @copr/copr on devel instances 2020-11-11 09:32:06 +01:00
Aurélien Bompard
d58d1bd208
IPA: don't add the mod_wsgi role, let the installed set the options it wants
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-11-10 12:07:49 +01:00
Adam Williamson
95f062c07a openQA: allow all workers NFS write access, other tweaks
The main goal of these changes is to allow all workers in each
deployment NFS write access to the factory share. This is because
I want to try using os-autoinst's at-job-run-time decompression
of disk images instead of openQA's at-asset-download-time
decompression; it avoids some awkwardness with the asset file
name, and should also actually allow us to drop the decompression
code from openQA I think.

I also rejigged various other things at the same time as they
kinda logically go together. It's mostly cleanups and tweaks to
group variables. I tried to handle more things explicitly with
variables, as it's better for use of these plays outside of
Fedora infra.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2020-11-05 16:10:32 -08:00
Kevin Fenzi
f3bdbf3da5 openshift_apps / docstranslation: try mode using quotes
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-05 08:01:08 -08:00
Pierre-Yves Chibon
414a063625 Proxy-websites: create the testdays.fic.o
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:50:56 +01:00
Pierre-Yves Chibon
b1b0365f95 proxies: fix typo
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:48:26 +01:00
Pierre-Yves Chibon
439844863e Proxies: add a redirect from testdays.fic.o to testdays.fp.o
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:47:18 +01:00
Pierre-Yves Chibon
1390d242ef proxies: get testdays to redirect to openshift in stg and prod
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 13:56:44 +01:00
Pierre-Yves Chibon
48531f4b5b testdays: drop the route for resultsdb
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 13:47:44 +01:00
Pierre-Yves Chibon
e6969d8113 testdays: Prepare deploying to prod
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 13:39:20 +01:00
Kevin Fenzi
e0555ee173 proxies / reverseproxy: drop duplicate website var
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-03 15:24:45 -08:00
František Zatloukal
e28852c22e Testdays: Purge serivce 2020-11-02 16:17:00 +01:00
František Zatloukal
0335579fa2 testsdays: add a local/custom resultsdb instance just for us 2020-11-02 15:08:34 +01:00
Kevin Fenzi
48e878b9fe testdays: fix up testdays proxying in staging
It was redirecting it to the old fedorainfracloud ip.
Then it wasn't proxying to openshift.

When moving to prod, the conditionals here should be removed.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-01 11:33:52 -08:00
c366454e46 docstranslation: fix key reading for secrets injection 2020-10-29 16:38:18 +00:00
27295e92da
docstranslation: use include_role instead of import_role 2020-10-28 23:40:28 +01:00
673855471a docstranslation: generate ssh key & add missing secrets 2020-10-28 18:13:03 +00:00
Aurélien Bompard
05ef3ccb93
Fixup last commit
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-28 12:00:37 +01:00
Aurélien Bompard
096f281528
Make the noggin theme a parameter
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-28 11:35:26 +01:00
Kevin Fenzi
511654cda5 proxies / redirects: Add a redirect for iot.fp.o -> getfedora/iot
Fixes ticket #9401

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-27 13:14:02 +00:00
Rick Elrod
ad55b9ddc8 Revert "Disable prerelease redirects"
This reverts commit 54c4089a70.
2020-10-27 07:28:53 -05:00
Pierre-Yves Chibon
5a3e371298 docsbuilding: give pingou access so he can see the logs
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-10-23 11:35:34 +02:00
Adam Saleh
a460c9ae61 Attempting to change the route from edge to re-encrytp. 2020-10-21 09:03:20 +02:00
Adam Saleh
d95cb43414 Adding service account to work with oauth proxy for monitor dashboard. 2020-10-21 08:34:47 +02:00
Adam Saleh
8caf5318b7 Reverting the monitor-dashboard password to template.
Pingou removed the special chars, should help prevent attempts
at evaluation or commenting parts of the password string.
2020-10-21 07:41:22 +02:00
Adam Saleh
a920e43a92 Monitor dashboard secret needs to be a template 2020-10-20 13:40:58 +02:00
Adam Saleh
c75d6cd6e4 Wirking around the datanommer password special chars for monitor dashboard by puttin it in env-var 2020-10-20 13:28:53 +02:00
Adam Saleh
6fb2ddb763 Monitor dashboard had template interpreted as plain file. 2020-10-20 09:42:20 +02:00
Adam Saleh
d532057da7 Wrong name for the monitor-dashboard datasource config 2020-10-20 09:21:59 +02:00
Adam Saleh
619fb93049 Monitor-dashboard file/template mixup. 2020-10-19 22:39:13 +02:00
Adam Saleh
5241c92d52 Added preset dashboards and a route. 2020-10-19 20:22:54 +00:00
Aurélien Bompard
44d019e203
First try for the test-auth app
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-19 17:43:28 +02:00
Aurélien Bompard
5078c95140
The ipsilon service is accessible from the ipsilon hosts, not the ipa hosts
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-15 18:51:12 +02:00
Aurélien Bompard
157f1d2d52
Ipsilon: improve the HBAC rule
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-15 18:46:51 +02:00
Aurélien Bompard
b219aad49f
Try to fix ipsilon's openid
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-15 16:45:20 +02:00
Clement Verna
b52a7b7e22 Allow mattia to access bodhi in OpenShift (prod/stg)
Signed-off-by: Clement Verna <cverna@tutanota.com>
2020-10-15 08:36:32 +00:00
Kevin Fenzi
e59166aeac pkgs / staging: sort out staging certs and sites.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 16:20:32 -07:00
Kevin Fenzi
50cc7317bf certgetter / staging: drop certgetter01.stg
We can just use the main one and not bother with a specific stg one

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 16:07:41 -07:00
Kevin Fenzi
150f53ecb0 Freeze Break Request: Update openshift ssl certs
These certs are used for *.app.os.fedoraproject.org.
ie, things that don't also have/use a fedoraproject.org route.
THis includes the console and some apps that just never bothered to make
a fedoraproject route.

Fixes 9162

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 19:38:24 +00:00
Kevin Fenzi
5c70045704 Update staging openshift ssl cert to new one.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 09:32:07 -07:00
Stephen Smoogen
7d2b81a658 Made whitespace change. 2020-10-14 10:37:01 -04:00
Stephen Smoogen
539cf52303 Add a host for CentOS testing of noggin
This adds in for the staging environment a minimal system for centos
admins to test how items work in staging. Because this server will be
administered by CentOS, we only set up a minimal environment.

ToDo: Put in lines to get and copy the correct root ssh key into
/root/.ssh/authorized_keys for CentOS admins.

Signed-off-by: Stephen Smoogen <ssmoogen@redhat.com>
2020-10-14 10:33:16 -04:00
Stephen Smoogen
c1014c4a8c Change download-sync location and update script.
The download-sync for rdu-cc needs to use the /root versus default
quick-fedora-mirror git repository. This allows for it to only copy
the modules needed.

Signed-off-by: Stephen Smoogen <ssmoogen@redhat.com>
2020-10-12 17:07:33 -04:00
Jan Kaluza
32e4f83062 ODCS: Configure ODCS releng backend as separate task.
Signed-off-by: Jan Kaluza <jkaluza@redhat.com>
2020-10-12 07:40:38 +02:00
Pierre-Yves Chibon
542cc75a07 koji sync from stg: attempt to fix the migration
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-10-07 16:24:15 +02:00
Aurélien Bompard
38cc67731b
Proxy: attempt to move ipsilon back to a VM in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-07 10:59:41 +02:00