Kevin Fenzi
ff74860db5
new ca cert for prod openshift
2018-09-27 22:27:51 +00:00
Kevin Fenzi
a63607d51b
update os-master ca
2018-09-10 21:35:11 +00:00
Kevin Fenzi
233f22575a
New openshift ssl ca
2018-05-31 23:47:27 +00:00
Patrick Uiterwijk
06f53389bc
Add a README for the os-cert
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-31 02:11:07 +02:00
Kevin Fenzi
1f74423825
Update staging cert
2018-05-31 00:09:32 +00:00
Kevin Fenzi
8a19a0ef8d
try this one
2018-02-24 01:44:25 +00:00
Kevin Fenzi
b651061e5c
new staging ca cert
2018-02-24 01:13:56 +00:00
Ricky Elrod
a5d017c71f
new os-master cert
...
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 07:14:00 +00:00
Kevin Fenzi
3ae95a6169
fix names
2017-08-22 19:49:20 +00:00
Kevin Fenzi
4047dc3228
move file for env name
2017-08-22 19:45:25 +00:00
Kevin Fenzi
9d330280ef
add prod os CA and make haproxy use it
2017-08-22 19:41:07 +00:00
Patrick Uiterwijk
67939cfd7a
New OS certificate
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-06-29 15:17:47 +00:00
Kevin Fenzi
04e93913b4
update openshift ca from current install
2017-05-25 19:35:48 +00:00
Kevin Fenzi
eb1dd0ae0f
look, you can fix a error with 0s
2017-05-16 15:24:23 +00:00
Patrick Uiterwijk
331a664f1e
Updatecert
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-05-12 15:03:41 +00:00
Patrick Uiterwijk
2b365b3c32
Add the newest openshift cert
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-05-12 02:34:39 +00:00
bbe6c25b6f
try os-master proxy setup
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2017-05-11 19:49:31 +00:00
Kevin Fenzi
077cbc03d6
remove fedorahosted from nagios
2017-03-02 22:16:19 +00:00
Patrick Uiterwijk
1c74f98cca
Add production IPA cert
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-13 13:46:34 +00:00
Patrick Uiterwijk
28ebec92ee
Proxy IPA through haproxy
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-08-04 21:23:07 +00:00
Till Maas
ff2f58c243
Move planet.fedoraproject.org to fedoraplanet.org
2015-07-31 18:56:04 +02:00
Kevin Fenzi
553da4b213
Switch haproxy to prefer a local mirrorlist server if available.
...
Allow port 443 connections from those proxies on mirrorlists.
Add hosts entries for proxy10 and proxy01 that should allow ssl to work right.
Will test this on one proxy/mirrorlist and move on to the others.
2015-05-31 17:17:41 +00:00
Adrian Reber
900552f038
Switch to another URL for mirrormanager haproxy check
...
The haproxy check URL for the MirrorManager web frontend was a URL
which resulted in a large DB query. Every proxy, every minute. This
resulted in two much memory and CPU consumption. This switches the
check to a small static file to reduce the load on mm-frontend01.
2015-05-20 14:30:05 +00:00
Kevin Fenzi
8341e0c5bf
Drop duplicate mirrormanager entries
2015-05-07 15:21:45 +00:00
Pierre-Yves Chibon
7f03e4a597
Adjust haproxy in stg to enable /mirrormanager/
2015-05-07 17:18:15 +02:00
Mikolaj Izdebski
7d480abcbf
Add proxy configuration for Koschei staging
2015-05-07 09:25:27 +00:00
Kevin Fenzi
7c0f38f9e8
Drop torrent02, it's gone. Add torrent01 to acls for downloads.
2015-05-05 14:08:11 +00:00
Patrick Uiterwijk
fd417782c1
And fix the checkpath for ipsilon
2015-03-19 17:55:18 +00:00
Patrick Uiterwijk
029e9eafad
Switch FedOAuth to Ipsilon in stg
2015-03-19 17:48:20 +00:00
Kevin Fenzi
997d2a99bf
Set proxy01.stg to get mirrorlists from mirrorlist-phx2.stg
2015-03-18 11:54:04 +00:00
Ralph Bean
3dafc11783
Omit the ".stg" here. None of the other services use it.
2015-01-28 02:23:37 +00:00
Patrick Uiterwijk
ce8d1e9b7b
Bump maxconns to 5000 and disable keepalive for geoip and mirrorlist
2015-01-27 18:37:51 +00:00
Pierre-Yves Chibon
932ab8863d
Adjust the proxy and varnish settings for mirrormanager2
2015-01-16 11:23:14 +01:00
ef4de9db57
keep this up to date too?
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2015-01-09 23:32:18 +00:00
Kevin Fenzi
936fe46720
See about making sundries01.stg a mirrorlist1 server for stg.
2015-01-06 21:38:57 +00:00
Ralph Bean
0a457060a9
A custom selinux module for our haproxy setup.
2015-01-06 19:53:19 +00:00
Pierre-Yves Chibon
7adeb26a4d
Start working on the haproxy role
2014-12-07 23:36:14 +00:00