Commit graph

296 commits

Author SHA1 Message Date
Kevin Fenzi
e4e4e305de rdu3: add some hosts files until dns is sorted
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-21 15:37:17 -07:00
Michal Konecny
7b58dfdce8 Remove fedmsg and github2fedmsg from staging
The messaging bridges openshift project and github2fedmsg VM were
already removed in staging. This is to clean the ansible playbooks.

I will create a separate one for production after this one is merged.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-02-04 09:13:40 +01:00
6a3816dfdc ansiblelint fixes-- fqcn[action-core] - copy to ansible.builtin.copy
Replaces many references to 'copy' with ansible.builtin.copy

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 10:43:31 +10:00
691adee6ee Fix name[casing] ansible-lint issues
fix 1900 failures of the following case issue:

`name[casing]: All names should start with an uppercase letter.`

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-14 20:20:07 +10:00
Kevin Fenzi
a60ca7159f nuancier: retire and remove from ansible
See https://pagure.io/fedora-infrastructure/issue/11371
This service is retired.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-15 10:44:00 -08:00
Kevin Fenzi
c1e6e2fb02 ns13: define a local hosts file so we can get to the vpn to install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-30 15:21:16 -08:00
Kevin Fenzi
8ee9c66072 hosts: try again as the last simple fix was too simple
So, we need a bit more logic here.
We want to use the vpn hosts file only if something is on the vpn and
it's also not in iad2. In iad2 we want the normal hosts file.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-05 10:15:52 -07:00
Kevin Fenzi
d36a478580 hosts: make a hacky, but hopefully working way of handling vpn
This isn't very clever, but it should work and be easily understandable.
We likely want to come up with a better way to do these hosts files
entirely, but it can wait until after freeze.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-05 10:07:58 -07:00
Kevin Fenzi
b4df850535 Revert "hosts: then and if swapped?"
This reverts commit b8f411c96b.
2021-04-01 16:47:21 -07:00
Kevin Fenzi
b8f411c96b hosts: then and if swapped?
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-01 16:16:23 -07:00
Nils Philippsen
7a2024398f hosts: do the right thing for VPN hosts
Move the vpn ./. base logic from the ipa/client role into the hosts
role, so that applying the latter doesn't apply the base profile on VPN
hosts.

Fixes: fedora-infrastructure#9822

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-04-01 16:31:59 +02:00
110084afb1 cleanup: remove phx2 hosts files 2021-03-29 22:49:35 +00:00
Nils Philippsen
bcfe96b710 ipa/client: Enable VPN hosts to talk to IPA
This requires the canonical names of IPA servers to be mapped to their
IP addresses on the VPN as well as specifying the IPA server explicitly
when enrolling clients.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 18:19:11 +01:00
Kevin Fenzi
2af0042d5c koji01.stg: rename some files to the current domain name.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-08-26 15:46:55 -07:00
Kevin Fenzi
450cc3db87 hosts: drop stg hosts file that was phx2 specific
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-20 12:47:17 -07:00
Kevin Fenzi
b4c583b8ef Remove old infrastructure ip from cloud hosts.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-12 17:16:55 -07:00
Kevin Fenzi
122e0e2707 hosts / notifs*: drop all these wrong host files.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-02 14:52:15 -07:00
Kevin Fenzi
73f8fe76ad proxies: drop vpn workaround for registries
The iad2 registries should be reachable now via the normal path, so we
can drop this workaround. Should make things faster too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-20 13:16:09 -07:00
Kevin Fenzi
f8043f6c5a pagure01: For some reason workers started looking for db-pagure
I have no idea why they are, perhaps this is an upstream default?

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-20 11:56:28 -07:00
Kevin Fenzi
624dbd04a9 proxies in iad2: set hosts file to use vpn for talking to container regestries
Currently the proxies can't talk to the container registries directly,
so for now route these over the vpn.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-13 14:37:46 -07:00
Kevin Fenzi
f3233ba3d6 iad2 / proxy101: candidate registry
Right now, proxy101 is what is resolved to internally in iad2 for
candidate-registry.fedoraproject.org. It has haproxy to reach
oci-candidate-registry01.iad2.fedoraproject.org on port 5000 for this,
but that doesn't work currently due to RHIT firewall.

So, for now we add the vpn endpoint to /etc/hosts there so haproxy works
and internal machines can use the candidate registry.

Once we fix the rhit firewall we should remove this.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-11 18:10:33 -07:00
Kevin Fenzi
cb2fa9f453 openshift cluster: drop hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-11 16:55:43 -07:00
Patrick Uiterwijk
1ffffcbfb3 Revert "iad2: add a hosts file for now on wiki01.iad2 to get auth working"
This reverts commit d03c3a528b.
2020-06-11 18:16:53 +02:00
Kevin Fenzi
83d53fd622 iad2: delete hosts file for autosign01.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-07 16:03:48 -07:00
Stephen Smoogen
11baf9ef99 try adding a hosts files for the s390 builders 2020-06-07 15:35:15 -04:00
Kevin Fenzi
d03c3a528b iad2: add a hosts file for now on wiki01.iad2 to get auth working
The problem is that id.fedoraproject.org resolves to the iad2 versions
in iad2. This is fine, but break oidc which has a talk between the
provider and the requestor, so if you use the phx2 ipsilon, you need
to use it for the entire thing. Will fix this better in dns soon.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-05 18:17:47 -07:00
Pierre-Yves Chibon
0f7a6efc2b pagure and distgit/pagure: Drop the db-pagure hostname and populate the db used in the inventor host file instead
Basically, instead of relying on an obscure db-pagure variable that
then needs to be specified in the /etc/hosts file.
Just define the pagure_db_host variable in the host's inventory
file so it exists as a variable available in the playbook/role.
This makes things more explicit and easier to debug/tweak as needed.

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-05-26 14:08:01 +02:00
Pierre-Yves Chibon
d898123fb3 Drop hosts file for a host that is long gone
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-05-26 14:04:14 +02:00
Kevin Fenzi
ace20e5603 iad2: clean up some hosts files and make sure bodhi-backend01.iad2 is actually in the iad2 datacenter
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-25 16:38:58 -07:00
Kevin Fenzi
ba001ac2eb blockerbugs: drop hosts files.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-23 11:32:45 -07:00
Pierre-Yves Chibon
ba9bfed241 openshift: update the hosts file pointing to registry.rh.io
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-05-19 21:49:42 +02:00
Kevin Fenzi
1ddae8f094 openshift hosts: update registry.redhat.io ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-17 15:38:49 -07:00
Kevin Fenzi
c529380547 Spring cleaning time. :)
I removed all the old files, inventory, playbooks, roles and other from
services we no longer run or use. There was a bunch of cruft in there
and I hope that will make the repo cleaner and easier to look for things
we actually do run and care about.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-13 14:02:41 -07:00
Kevin Fenzi
ffcf517a4f iad2: add hosts file for bastion01.iad2 for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-06 12:49:24 -07:00
Pierre-Yves Chibon
8d27d922f6 Openshift-stg: Apparently registry.rh.io changed IP address
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-04-24 21:34:29 +02:00
Stephen Smoogen
3180cac828 remove final elections items from ansible 2020-04-24 21:34:29 +02:00
Stephen Smoogen
660af1f1d3 And this will make sure that 30 and 31 are similar in ansible 2020-04-24 21:34:28 +02:00
Stephen Smoogen
4164c240d8 add a specific hosts file because our script assumes all staging is in phoenix. this is going to be fun to fix after move 2020-04-24 21:34:26 +02:00
Stephen Smoogen
9d02ba6cf4 add proxy30 to config files 2020-04-24 21:34:21 +02:00
siddharthvipul
f121177b05 OSBS: add /etc/hosts file with RedHat registry
Signed-off-by: siddharthvipul <siddharthvipul1@gmail.com>
2020-04-24 21:34:17 +02:00
Rick Elrod
bfbe977dbe hosts: unindent to be consistent with most of our other files
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:15 +02:00
Rick Elrod
cf67c4bc84 hosts: try getting rid of files subsection here
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
ccd4c894f4 hosts: try specifying the role_path
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
7463139d30 hosts: ok, try just defaulting here.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
5c7e74c4f3 hosts: not there in the middle of the loop though
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
5445c73468 hosts: try moving the ignore up
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
28308be9ac hosts: it's errors: ignore
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Kevin Fenzi
3f72916683 hosts: another case of skip:true
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Rick Elrod
d07b5a512c base/os: same here
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:14 +02:00
Rick Elrod
e3fd43fa80 base/os-stg: point registry.redhat.io to new ip
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:14 +02:00