From 580cd252c53a6e459d485b9635e474ee87763165 Mon Sep 17 00:00:00 2001 From: Kevin Fenzi Date: Tue, 16 Nov 2021 13:27:57 -0800 Subject: [PATCH] Inventory group/host variables: Sort yaml This was done using yq ( https://mikefarah.gitbook.io/yq/operators/sort-keys ) Doing things this way makes it much easier to see if a variable is set in a file or if two hosts differ in what variables they set. Hopefully we can keep things sorted moving forward. Basically this means just sort a-z anything you add to any host or group vaiable and it will be in the right place. Additionally, this enforces 'normal' intent rules for all the variable files which we should also try and obey. 2 spaces for first level, 3 for next, etc. When in doubt you can run yq on it. This should cause NO actual vairable changes, it's all just readability fixing for humans, ansible parses it exactly the same. Signed-off-by: Kevin Fenzi --- inventory/group_vars/aarch64_test | 4 +- inventory/group_vars/all | 590 ++++++------------ inventory/group_vars/autosign | 47 +- inventory/group_vars/autosign_hardware | 1 - inventory/group_vars/badges | 14 +- inventory/group_vars/badges_backend | 97 ++- inventory/group_vars/badges_backend_stg | 94 ++- inventory/group_vars/badges_stg | 16 +- inventory/group_vars/badges_web | 89 ++- inventory/group_vars/badges_web_stg | 86 ++- inventory/group_vars/basset | 23 +- inventory/group_vars/basset_stg | 19 +- inventory/group_vars/bastion | 124 ++-- inventory/group_vars/bastion_stg | 96 ++- inventory/group_vars/batcave | 139 ++--- inventory/group_vars/bkernel | 14 +- inventory/group_vars/blockerbugs | 69 +- inventory/group_vars/blockerbugs_stg | 64 +- inventory/group_vars/bodhi_backend | 70 +-- inventory/group_vars/bodhi_backend_stg | 89 ++- inventory/group_vars/builders | 19 +- inventory/group_vars/builders_stg | 19 +- inventory/group_vars/buildhw | 30 +- inventory/group_vars/buildvm | 48 +- inventory/group_vars/buildvm_aarch64 | 51 +- inventory/group_vars/buildvm_aarch64_stg | 65 +- inventory/group_vars/buildvm_armv7 | 57 +- inventory/group_vars/buildvm_armv7_stg | 65 +- inventory/group_vars/buildvm_ppc64le | 64 +- inventory/group_vars/buildvm_ppc64le_stg | 64 +- inventory/group_vars/buildvm_s390x | 43 +- inventory/group_vars/buildvm_s390x_stg | 20 +- inventory/group_vars/buildvm_stg | 61 +- inventory/group_vars/buildvmhost | 24 +- inventory/group_vars/busgateway | 47 +- inventory/group_vars/busgateway_stg | 43 +- inventory/group_vars/bvirthost | 6 +- inventory/group_vars/certgetter | 12 +- inventory/group_vars/certgetter_stg | 9 +- inventory/group_vars/checkcompose | 11 +- inventory/group_vars/checkcompose_common | 14 +- inventory/group_vars/checkcompose_stg | 7 +- inventory/group_vars/cloud | 4 +- inventory/group_vars/cloud_aws | 11 +- inventory/group_vars/cloud_hardware | 7 +- inventory/group_vars/copr | 38 +- inventory/group_vars/copr_all_instances_aws | 1 + inventory/group_vars/copr_aws | 118 ++-- inventory/group_vars/copr_back | 50 +- inventory/group_vars/copr_back_aws | 68 +- inventory/group_vars/copr_back_dev | 52 +- inventory/group_vars/copr_back_dev_aws | 68 +- inventory/group_vars/copr_back_stg | 33 +- inventory/group_vars/copr_db_all | 5 +- inventory/group_vars/copr_dev | 36 +- inventory/group_vars/copr_dev_aws | 117 ++-- inventory/group_vars/copr_dist_git | 9 +- inventory/group_vars/copr_dist_git_aws | 9 +- inventory/group_vars/copr_dist_git_dev | 11 +- inventory/group_vars/copr_dist_git_dev_aws | 11 +- inventory/group_vars/copr_dist_git_stg | 5 +- inventory/group_vars/copr_front_aws | 35 +- inventory/group_vars/copr_front_dev_aws | 48 +- inventory/group_vars/copr_hypervisor | 45 +- inventory/group_vars/copr_keygen | 10 +- inventory/group_vars/copr_keygen_aws | 11 +- inventory/group_vars/copr_keygen_dev | 10 +- inventory/group_vars/copr_keygen_dev_aws | 11 +- inventory/group_vars/copr_keygen_stg | 13 +- inventory/group_vars/copr_stg | 18 +- inventory/group_vars/datagrepper | 38 +- inventory/group_vars/datagrepper_stg | 30 +- inventory/group_vars/dbserver | 12 +- inventory/group_vars/dbserver_stg | 12 +- inventory/group_vars/debuginfod | 41 +- inventory/group_vars/debuginfod_stg | 41 +- inventory/group_vars/dell_fx_build | 22 +- inventory/group_vars/dns | 43 +- inventory/group_vars/download | 184 +++--- inventory/group_vars/download_iad2 | 13 +- inventory/group_vars/download_ib | 7 +- inventory/group_vars/download_rdu2 | 13 +- inventory/group_vars/fedimg | 62 +- inventory/group_vars/fedimg_stg | 65 +- inventory/group_vars/fedora_nightlies | 16 +- inventory/group_vars/github2fedmsg | 122 ++-- inventory/group_vars/github2fedmsg_stg | 120 ++-- inventory/group_vars/gnome_backups | 10 +- inventory/group_vars/greenwave | 9 +- inventory/group_vars/greenwave_stg | 12 +- inventory/group_vars/ipa | 38 +- inventory/group_vars/ipa_stg | 28 +- inventory/group_vars/ipsilon | 14 +- inventory/group_vars/ipsilon_stg | 14 +- inventory/group_vars/kernel_qa | 14 +- inventory/group_vars/kerneltest | 49 +- inventory/group_vars/koji | 91 ++- inventory/group_vars/koji_stg | 111 ++-- inventory/group_vars/kojipkgs | 66 +- inventory/group_vars/logging | 20 +- inventory/group_vars/mailman | 126 ++-- inventory/group_vars/mailman_stg | 108 ++-- inventory/group_vars/maintainer_test | 23 +- inventory/group_vars/mbs | 18 +- inventory/group_vars/mbs_backend | 64 +- inventory/group_vars/mbs_backend_stg | 59 +- inventory/group_vars/mbs_frontend | 62 +- inventory/group_vars/mbs_frontend_stg | 62 +- inventory/group_vars/mbs_stg | 16 +- inventory/group_vars/memcached | 26 +- inventory/group_vars/memcached_stg | 23 +- inventory/group_vars/mm | 21 +- inventory/group_vars/mm_backend | 32 +- inventory/group_vars/mm_backend_stg | 28 +- inventory/group_vars/mm_crawler | 33 +- inventory/group_vars/mm_crawler_stg | 30 +- inventory/group_vars/mm_frontend | 45 +- inventory/group_vars/mm_frontend_stg | 43 +- inventory/group_vars/mm_stg | 19 +- inventory/group_vars/nagios | 139 ++--- inventory/group_vars/notifs | 14 +- inventory/group_vars/notifs_backend | 60 +- inventory/group_vars/notifs_backend_stg | 55 +- inventory/group_vars/notifs_stg | 16 +- inventory/group_vars/notifs_web | 39 +- inventory/group_vars/notifs_web_stg | 39 +- inventory/group_vars/nuancier | 14 +- inventory/group_vars/nuancier_stg | 12 +- inventory/group_vars/oci_registry | 15 +- inventory/group_vars/oci_registry_stg | 13 +- inventory/group_vars/ocp | 10 +- inventory/group_vars/ocp_stg | 10 +- inventory/group_vars/odcs | 123 ++-- inventory/group_vars/odcs_backend | 88 ++- inventory/group_vars/odcs_backend_releng | 3 +- inventory/group_vars/odcs_backend_stg | 86 ++- inventory/group_vars/odcs_frontend | 78 +-- inventory/group_vars/odcs_frontend_stg | 65 +- inventory/group_vars/odcs_stg | 103 ++- inventory/group_vars/openqa | 36 +- inventory/group_vars/openqa_lab | 55 +- inventory/group_vars/openqa_lab_workers | 37 +- inventory/group_vars/openqa_servers_common | 92 ++- inventory/group_vars/openqa_tap_workers | 19 +- inventory/group_vars/openqa_workers | 32 +- inventory/group_vars/openstack_compute | 6 +- inventory/group_vars/os | 15 +- inventory/group_vars/os_control | 4 +- inventory/group_vars/os_control_stg | 4 +- inventory/group_vars/os_masters | 27 +- inventory/group_vars/os_masters_stg | 17 +- inventory/group_vars/os_nodes | 11 +- inventory/group_vars/os_nodes_stg | 10 +- inventory/group_vars/os_proxies | 28 +- inventory/group_vars/os_stg | 15 +- inventory/group_vars/osbs | 63 +- inventory/group_vars/osbs_aarch64_masters | 82 +-- inventory/group_vars/osbs_aarch64_masters_stg | 82 +-- inventory/group_vars/osbs_aarch64_node | 21 +- inventory/group_vars/osbs_aarch64_nodes | 21 +- inventory/group_vars/osbs_aarch64_nodes_stg | 21 +- inventory/group_vars/osbs_control | 18 +- inventory/group_vars/osbs_control_stg | 13 +- inventory/group_vars/osbs_masters | 266 ++++---- inventory/group_vars/osbs_masters_stg | 266 ++++---- inventory/group_vars/osbs_nodes | 28 +- inventory/group_vars/osbs_nodes_stg | 15 +- inventory/group_vars/osbs_stg | 64 +- inventory/group_vars/packages | 63 +- inventory/group_vars/packages_stg | 52 +- inventory/group_vars/pagure | 169 +++-- inventory/group_vars/pagure_stg | 162 +++-- inventory/group_vars/pdc_web | 78 ++- inventory/group_vars/pdc_web_stg | 69 +- inventory/group_vars/people | 75 +-- inventory/group_vars/persistent_cloud | 2 +- inventory/group_vars/pkgs | 183 +++--- inventory/group_vars/pkgs_stg | 183 +++--- inventory/group_vars/proxies | 233 +++---- inventory/group_vars/proxies_stg | 211 +++---- inventory/group_vars/rabbitmq | 54 +- inventory/group_vars/rabbitmq_stg | 80 +-- inventory/group_vars/releng_compose | 113 ++-- inventory/group_vars/releng_compose_stg | 15 +- inventory/group_vars/relvalconsumer | 2 +- inventory/group_vars/relvalconsumer_common | 22 +- inventory/group_vars/relvalconsumer_test | 7 +- inventory/group_vars/repospanner_temp | 30 +- inventory/group_vars/resultsdb_dev | 66 +- inventory/group_vars/resultsdb_prod | 106 ++-- inventory/group_vars/resultsdb_stg | 103 ++- inventory/group_vars/retrace | 89 ++- inventory/group_vars/retrace_stg_aws | 12 +- inventory/group_vars/secondary | 45 +- inventory/group_vars/sign_bridge | 17 +- inventory/group_vars/sign_vault | 8 +- inventory/group_vars/smtp_mm | 45 +- inventory/group_vars/staging | 62 +- inventory/group_vars/sundries | 51 +- inventory/group_vars/sundries_stg | 49 +- inventory/group_vars/tang | 4 +- inventory/group_vars/torrent | 63 +- inventory/group_vars/unbound | 28 +- inventory/group_vars/value | 131 ++-- inventory/group_vars/value_stg | 131 ++-- inventory/group_vars/virthost | 29 +- inventory/group_vars/virthost_comm | 3 +- inventory/group_vars/virthost_communishift | 2 +- inventory/group_vars/waiverdb | 9 +- inventory/group_vars/waiverdb_stg | 12 +- inventory/group_vars/wiki | 83 ++- inventory/group_vars/wiki_stg | 58 +- inventory/group_vars/zabbix_stg | 44 +- .../aarch64-test02.fedorainfracloud.org | 47 +- .../armv7-test01.fedorainfracloud.org | 41 +- .../armv7-test02.fedorainfracloud.org | 42 +- .../autosign01.iad2.fedoraproject.org | 46 +- .../autosign01.stg.iad2.fedoraproject.org | 16 +- .../host_vars/backup01.iad2.fedoraproject.org | 59 +- .../badges-backend01.iad2.fedoraproject.org | 19 +- ...adges-backend01.stg.iad2.fedoraproject.org | 13 +- .../badges-web01.iad2.fedoraproject.org | 16 +- .../badges-web01.stg.iad2.fedoraproject.org | 8 +- .../bastion01.iad2.fedoraproject.org | 27 +- .../bastion02.iad2.fedoraproject.org | 27 +- .../host_vars/bastion13.fedoraproject.org | 33 +- .../batcave01.iad2.fedoraproject.org | 24 +- .../batcave13.rdu2.fedoraproject.org | 58 +- .../bkernel01.iad2.fedoraproject.org | 49 +- .../bkernel02.iad2.fedoraproject.org | 49 +- .../blockerbugs01.iad2.fedoraproject.org | 22 +- .../blockerbugs01.stg.iad2.fedoraproject.org | 19 +- .../bodhi-backend01.iad2.fedoraproject.org | 167 +++-- ...bodhi-backend01.stg.iad2.fedoraproject.org | 45 +- .../bootstrap.ocp.iad2.fedoraproject.org | 79 +-- .../bootstrap.ocp.stg.iad2.fedoraproject.org | 79 +-- .../buildhw-a64-01.iad2.fedoraproject.org | 53 +- .../buildhw-a64-02.iad2.fedoraproject.org | 60 +- .../buildhw-a64-03.iad2.fedoraproject.org | 68 +- .../buildhw-a64-04.iad2.fedoraproject.org | 68 +- .../buildhw-a64-05.iad2.fedoraproject.org | 69 +- .../buildhw-a64-06.iad2.fedoraproject.org | 68 +- .../buildhw-a64-07.iad2.fedoraproject.org | 4 +- .../buildhw-a64-08.iad2.fedoraproject.org | 46 +- .../buildhw-a64-09.iad2.fedoraproject.org | 4 +- .../buildhw-a64-10.iad2.fedoraproject.org | 4 +- .../buildhw-a64-11.iad2.fedoraproject.org | 68 +- .../buildhw-a64-19.iad2.fedoraproject.org | 68 +- .../buildhw-a64-20.iad2.fedoraproject.org | 68 +- .../buildhw-a64-21.iad2.fedoraproject.org | 65 +- .../buildhw-a64-22.iad2.fedoraproject.org | 64 +- .../buildhw-a64-23.iad2.fedoraproject.org | 64 +- .../buildhw-a64-24.iad2.fedoraproject.org | 65 +- .../buildhw-x86-01.iad2.fedoraproject.org | 42 +- .../buildhw-x86-02.iad2.fedoraproject.org | 54 +- .../buildhw-x86-03.iad2.fedoraproject.org | 50 +- .../buildhw-x86-04.iad2.fedoraproject.org | 50 +- .../buildhw-x86-05.iad2.fedoraproject.org | 54 +- .../buildhw-x86-06.iad2.fedoraproject.org | 51 +- .../buildhw-x86-07.iad2.fedoraproject.org | 50 +- .../buildhw-x86-08.iad2.fedoraproject.org | 51 +- .../buildhw-x86-09.iad2.fedoraproject.org | 50 +- .../buildhw-x86-10.iad2.fedoraproject.org | 50 +- .../buildhw-x86-11.iad2.fedoraproject.org | 50 +- .../buildhw-x86-12.iad2.fedoraproject.org | 50 +- .../buildhw-x86-13.iad2.fedoraproject.org | 50 +- .../buildhw-x86-14.iad2.fedoraproject.org | 50 +- .../buildhw-x86-15.iad2.fedoraproject.org | 50 +- .../buildhw-x86-16.iad2.fedoraproject.org | 50 +- .../buildvm-a32-01.iad2.fedoraproject.org | 3 +- .../buildvm-a32-01.stg.iad2.fedoraproject.org | 4 +- .../buildvm-a32-02.iad2.fedoraproject.org | 3 +- .../buildvm-a32-02.stg.iad2.fedoraproject.org | 3 +- .../buildvm-a32-03.iad2.fedoraproject.org | 3 +- .../buildvm-a32-03.stg.iad2.fedoraproject.org | 2 +- .../buildvm-a32-04.iad2.fedoraproject.org | 3 +- .../buildvm-a32-05.iad2.fedoraproject.org | 3 +- .../buildvm-a32-06.iad2.fedoraproject.org | 3 +- .../buildvm-a32-07.iad2.fedoraproject.org | 3 +- .../buildvm-a32-08.iad2.fedoraproject.org | 3 +- .../buildvm-a32-09.iad2.fedoraproject.org | 3 +- .../buildvm-a32-10.iad2.fedoraproject.org | 3 +- .../buildvm-a32-11.iad2.fedoraproject.org | 3 +- .../buildvm-a32-12.iad2.fedoraproject.org | 3 +- .../buildvm-a32-13.iad2.fedoraproject.org | 3 +- .../buildvm-a32-14.iad2.fedoraproject.org | 3 +- .../buildvm-a32-15.iad2.fedoraproject.org | 3 +- .../buildvm-a32-16.iad2.fedoraproject.org | 3 +- .../buildvm-a32-17.iad2.fedoraproject.org | 3 +- .../buildvm-a32-18.iad2.fedoraproject.org | 3 +- .../buildvm-a32-19.iad2.fedoraproject.org | 3 +- .../buildvm-a32-20.iad2.fedoraproject.org | 3 +- .../buildvm-a32-21.iad2.fedoraproject.org | 3 +- .../buildvm-a32-22.iad2.fedoraproject.org | 3 +- .../buildvm-a32-23.iad2.fedoraproject.org | 3 +- .../buildvm-a32-24.iad2.fedoraproject.org | 3 +- .../buildvm-a32-25.iad2.fedoraproject.org | 3 +- .../buildvm-a32-26.iad2.fedoraproject.org | 3 +- .../buildvm-a32-27.iad2.fedoraproject.org | 3 +- .../buildvm-a32-28.iad2.fedoraproject.org | 2 +- .../buildvm-a32-29.iad2.fedoraproject.org | 2 +- .../buildvm-a32-30.iad2.fedoraproject.org | 2 +- .../buildvm-a32-31.iad2.fedoraproject.org | 3 +- .../buildvm-a32-32.iad2.fedoraproject.org | 3 +- .../buildvm-a32-33.iad2.fedoraproject.org | 3 +- .../buildvm-a64-01.iad2.fedoraproject.org | 3 +- .../buildvm-a64-01.stg.iad2.fedoraproject.org | 3 +- .../buildvm-a64-02.iad2.fedoraproject.org | 3 +- .../buildvm-a64-02.stg.iad2.fedoraproject.org | 3 +- .../buildvm-a64-03.iad2.fedoraproject.org | 3 +- .../buildvm-a64-03.stg.iad2.fedoraproject.org | 2 +- .../buildvm-a64-04.iad2.fedoraproject.org | 3 +- .../buildvm-a64-05.iad2.fedoraproject.org | 3 +- .../buildvm-a64-06.iad2.fedoraproject.org | 3 +- .../buildvm-a64-07.iad2.fedoraproject.org | 3 +- .../buildvm-a64-08.iad2.fedoraproject.org | 3 +- .../buildvm-a64-09.iad2.fedoraproject.org | 3 +- .../buildvm-a64-10.iad2.fedoraproject.org | 3 +- .../buildvm-a64-11.iad2.fedoraproject.org | 3 +- .../buildvm-a64-12.iad2.fedoraproject.org | 3 +- .../buildvm-a64-13.iad2.fedoraproject.org | 3 +- .../buildvm-a64-14.iad2.fedoraproject.org | 3 +- .../buildvm-a64-15.iad2.fedoraproject.org | 3 +- .../buildvm-a64-16.iad2.fedoraproject.org | 3 +- .../buildvm-a64-17.iad2.fedoraproject.org | 3 +- .../buildvm-a64-18.iad2.fedoraproject.org | 3 +- .../buildvm-a64-19.iad2.fedoraproject.org | 3 +- .../buildvm-a64-20.iad2.fedoraproject.org | 3 +- .../buildvm-a64-21.iad2.fedoraproject.org | 3 +- .../buildvm-a64-22.iad2.fedoraproject.org | 3 +- .../buildvm-a64-23.iad2.fedoraproject.org | 3 +- .../buildvm-a64-24.iad2.fedoraproject.org | 3 +- .../buildvm-a64-25.iad2.fedoraproject.org | 3 +- .../buildvm-a64-26.iad2.fedoraproject.org | 3 +- .../buildvm-a64-27.iad2.fedoraproject.org | 3 +- .../buildvm-a64-28.iad2.fedoraproject.org | 2 +- .../buildvm-a64-29.iad2.fedoraproject.org | 2 +- .../buildvm-a64-30.iad2.fedoraproject.org | 2 +- .../buildvm-a64-31.iad2.fedoraproject.org | 3 +- .../buildvm-a64-32.iad2.fedoraproject.org | 3 +- .../buildvm-a64-33.iad2.fedoraproject.org | 3 +- ...ildvm-aarch64-01.stg.arm.fedoraproject.org | 13 +- ...buildvm-armv7-01.stg.arm.fedoraproject.org | 13 +- .../buildvm-ppc64le-01.iad2.fedoraproject.org | 3 +- ...ldvm-ppc64le-01.stg.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-02.iad2.fedoraproject.org | 3 +- ...ldvm-ppc64le-02.stg.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-03.iad2.fedoraproject.org | 3 +- ...ldvm-ppc64le-03.stg.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-04.iad2.fedoraproject.org | 3 +- ...ldvm-ppc64le-04.stg.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-05.iad2.fedoraproject.org | 3 +- ...ldvm-ppc64le-05.stg.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-06.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-07.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-08.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-09.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-10.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-11.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-12.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-13.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-14.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-15.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-16.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-17.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-18.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-19.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-20.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-21.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-22.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-23.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-24.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-25.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-26.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-27.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-28.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-29.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-30.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-31.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-32.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-33.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-34.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-35.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-36.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-37.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-38.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-39.iad2.fedoraproject.org | 3 +- .../buildvm-ppc64le-40.iad2.fedoraproject.org | 3 +- ...uildvm-s390x-01.stg.s390.fedoraproject.org | 14 +- .../buildvm-s390x-07.s390.fedoraproject.org | 54 +- .../buildvm-s390x-15.s390.fedoraproject.org | 45 +- .../buildvm-s390x-16.s390.fedoraproject.org | 45 +- .../buildvm-s390x-17.s390.fedoraproject.org | 45 +- .../buildvm-s390x-18.s390.fedoraproject.org | 45 +- .../buildvm-s390x-19.s390.fedoraproject.org | 45 +- .../buildvm-s390x-20.s390.fedoraproject.org | 45 +- .../buildvm-s390x-21.s390.fedoraproject.org | 45 +- .../buildvm-s390x-22.s390.fedoraproject.org | 42 +- .../buildvm-s390x-23.s390.fedoraproject.org | 45 +- .../buildvm-s390x-24.s390.fedoraproject.org | 48 +- .../buildvm-x86-01.iad2.fedoraproject.org | 2 +- .../buildvm-x86-02.iad2.fedoraproject.org | 2 +- .../buildvm-x86-03.iad2.fedoraproject.org | 2 +- .../buildvm-x86-04.iad2.fedoraproject.org | 2 +- .../buildvm-x86-05.iad2.fedoraproject.org | 2 +- .../buildvm-x86-06.iad2.fedoraproject.org | 2 +- .../buildvm-x86-07.iad2.fedoraproject.org | 2 +- .../buildvm-x86-08.iad2.fedoraproject.org | 2 +- .../buildvm-x86-09.iad2.fedoraproject.org | 2 +- .../buildvm-x86-10.iad2.fedoraproject.org | 2 +- .../buildvm-x86-11.iad2.fedoraproject.org | 2 +- .../buildvm-x86-12.iad2.fedoraproject.org | 2 +- .../buildvm-x86-13.iad2.fedoraproject.org | 2 +- .../buildvm-x86-14.iad2.fedoraproject.org | 2 +- .../buildvm-x86-15.iad2.fedoraproject.org | 2 +- .../buildvm-x86-16.iad2.fedoraproject.org | 2 +- .../buildvm-x86-17.iad2.fedoraproject.org | 2 +- .../buildvm-x86-18.iad2.fedoraproject.org | 2 +- .../buildvm-x86-19.iad2.fedoraproject.org | 2 +- .../buildvm-x86-20.iad2.fedoraproject.org | 2 +- .../buildvm-x86-21.iad2.fedoraproject.org | 2 +- .../buildvm-x86-22.iad2.fedoraproject.org | 2 +- .../buildvm-x86-23.iad2.fedoraproject.org | 2 +- .../buildvm-x86-24.iad2.fedoraproject.org | 2 +- .../buildvm-x86-25.iad2.fedoraproject.org | 2 +- .../buildvm-x86-26.iad2.fedoraproject.org | 2 +- .../buildvm-x86-27.iad2.fedoraproject.org | 2 +- .../buildvm-x86-28.iad2.fedoraproject.org | 2 +- .../buildvm-x86-29.iad2.fedoraproject.org | 2 +- .../buildvm-x86-30.iad2.fedoraproject.org | 2 +- .../buildvm-x86-31.iad2.fedoraproject.org | 2 +- .../buildvm-x86-32.iad2.fedoraproject.org | 2 +- .../busgateway01.iad2.fedoraproject.org | 20 +- .../busgateway01.stg.iad2.fedoraproject.org | 20 +- .../bvmhost-a64-01.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-02.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-03.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-04.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-05.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-06.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-07.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-08.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-09.iad2.fedoraproject.org | 47 +- .../bvmhost-a64-10.iad2.fedoraproject.org | 48 +- .../bvmhost-p08-03.iad2.fedoraproject.org | 8 +- .../bvmhost-p08-04.iad2.fedoraproject.org | 8 +- .../bvmhost-p09-01.iad2.fedoraproject.org | 47 +- .../bvmhost-p09-02.iad2.fedoraproject.org | 47 +- .../bvmhost-p09-03.iad2.fedoraproject.org | 47 +- .../bvmhost-p09-04.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-01.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-01.stg.iad2.fedoraproject.org | 49 +- .../bvmhost-x86-02.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-02.stg.iad2.fedoraproject.org | 49 +- .../bvmhost-x86-03.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-03.stg.iad2.fedoraproject.org | 49 +- .../bvmhost-x86-04.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-04.stg.iad2.fedoraproject.org | 56 +- .../bvmhost-x86-05.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-05.stg.iad2.fedoraproject.org | 56 +- .../bvmhost-x86-06.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-07.iad2.fedoraproject.org | 47 +- .../bvmhost-x86-08.iad2.fedoraproject.org | 47 +- ...os-ipa-client01.stg.iad2.fedoraproject.org | 23 +- ...os-ipa-client02.stg.iad2.fedoraproject.org | 23 +- .../certgetter01.iad2.fedoraproject.org | 18 +- .../certgetter01.stg.iad2.fedoraproject.org | 18 +- .../cloud-noc-os01.rdu-cc.fedoraproject.org | 106 ++-- .../cloud-noc01.fedorainfracloud.org | 46 +- .../compose-branched01.iad2.fedoraproject.org | 92 ++- .../compose-iot01.iad2.fedoraproject.org | 64 +- .../compose-rawhide01.iad2.fedoraproject.org | 90 ++- .../compose-x86-01.iad2.fedoraproject.org | 113 ++-- .../compose-x86-01.stg.iad2.fedoraproject.org | 41 +- .../copr-be-dev-temp.aws.fedoraproject.org | 10 +- .../copr-be-dev.aws.fedoraproject.org | 18 +- .../copr-be-dev.cloud.fedoraproject.org | 57 +- .../copr-be-stg.fedorainfracloud.org | 45 +- .../host_vars/copr-be.aws.fedoraproject.org | 18 +- .../host_vars/copr-be.cloud.fedoraproject.org | 61 +- .../copr-db-stg.aws.fedoraproject.org | 63 +- .../copr-dist-git-dev.aws.fedoraproject.org | 41 +- .../copr-dist-git-dev.fedorainfracloud.org | 44 +- .../copr-dist-git-stg.fedorainfracloud.org | 42 +- .../copr-dist-git.aws.fedoraproject.org | 36 +- .../copr-dist-git.fedorainfracloud.org | 44 +- .../copr-fe-dev.aws.fedoraproject.org | 37 +- .../copr-fe-dev.cloud.fedoraproject.org | 43 +- .../host_vars/copr-fe.aws.fedoraproject.org | 63 +- .../host_vars/copr-fe.cloud.fedoraproject.org | 60 +- .../copr-keygen-dev.aws.fedoraproject.org | 32 +- .../copr-keygen-dev.cloud.fedoraproject.org | 42 +- .../copr-keygen-stg.fedorainfracloud.org | 41 +- .../copr-keygen.aws.fedoraproject.org | 30 +- .../copr-keygen.cloud.fedoraproject.org | 49 +- .../datagrepper01.iad2.fedoraproject.org | 17 +- .../datagrepper01.stg.iad2.fedoraproject.org | 17 +- .../datagrepper02.iad2.fedoraproject.org | 17 +- .../db-datanommer01.iad2.fedoraproject.org | 49 +- ...db-datanommer01.stg.iad2.fedoraproject.org | 50 +- .../db-datanommer02.iad2.fedoraproject.org | 55 +- .../host_vars/db-fas01.iad2.fedoraproject.org | 70 +-- .../db-fas01.stg.iad2.fedoraproject.org | 69 +- .../db-koji01.iad2.fedoraproject.org | 76 +-- .../db-koji01.stg.iad2.fedoraproject.org | 54 +- .../db-openqa01.iad2.fedoraproject.org | 51 +- .../host_vars/db-qa02.iad2.fedoraproject.org | 51 +- .../host_vars/db-qa03.iad2.fedoraproject.org | 47 +- .../host_vars/db01.iad2.fedoraproject.org | 142 ++--- .../host_vars/db01.stg.iad2.fedoraproject.org | 62 +- .../host_vars/db03.iad2.fedoraproject.org | 46 +- .../host_vars/db03.stg.iad2.fedoraproject.org | 46 +- .../debuginfod01.iad2.fedoraproject.org | 18 +- .../debuginfod01.stg.iad2.fedoraproject.org | 16 +- .../dedicatedsolutions01.fedoraproject.org | 71 +-- .../host_vars/dl01.iad2.fedoraproject.org | 35 +- .../host_vars/dl02.iad2.fedoraproject.org | 37 +- .../host_vars/dl03.iad2.fedoraproject.org | 37 +- .../host_vars/dl04.iad2.fedoraproject.org | 37 +- .../host_vars/dl05.iad2.fedoraproject.org | 37 +- .../download-cc-rdu01.fedoraproject.org | 46 +- .../host_vars/download-ib01.fedoraproject.org | 84 ++- .../download-rdu01.fedoraproject.org | 109 ++-- .../host_vars/el7-test.fedorainfracloud.org | 22 +- .../host_vars/el8-test.fedorainfracloud.org | 24 +- .../host_vars/fedimg01.iad2.fedoraproject.org | 14 +- .../fedocal01.iad2.fedoraproject.org | 18 +- .../fedocal02.iad2.fedoraproject.org | 18 +- .../github2fedmsg01.iad2.fedoraproject.org | 16 +- ...github2fedmsg01.stg.iad2.fedoraproject.org | 16 +- .../host_vars/host1plus01.fedoraproject.org | 12 +- .../host_vars/ibiblio01.fedoraproject.org | 19 +- .../host_vars/ibiblio05.fedoraproject.org | 19 +- .../host_vars/iddev.fedorainfracloud.org | 13 +- .../host_vars/internetx01.fedoraproject.org | 17 +- .../host_vars/ipa01.iad2.fedoraproject.org | 17 +- .../ipa01.stg.iad2.fedoraproject.org | 16 +- .../host_vars/ipa02.iad2.fedoraproject.org | 17 +- .../ipa02.stg.iad2.fedoraproject.org | 16 +- .../host_vars/ipa03.iad2.fedoraproject.org | 17 +- .../ipsilon01.iad2.fedoraproject.org | 18 +- .../ipsilon01.stg.iad2.fedoraproject.org | 18 +- .../ipsilon02.iad2.fedoraproject.org | 18 +- .../host_vars/kernel01.iad2.fedoraproject.org | 9 +- .../kerneltest01.iad2.fedoraproject.org | 18 +- .../host_vars/koji01.iad2.fedoraproject.org | 28 +- .../koji01.stg.iad2.fedoraproject.org | 28 +- .../host_vars/koji02.iad2.fedoraproject.org | 27 +- .../kojipkgs01.iad2.fedoraproject.org | 22 +- .../kojipkgs02.iad2.fedoraproject.org | 22 +- .../host_vars/log01.iad2.fedoraproject.org | 32 +- .../mailman01.iad2.fedoraproject.org | 19 +- .../mailman01.stg.iad2.fedoraproject.org | 16 +- .../mbs-backend01.iad2.fedoraproject.org | 19 +- .../mbs-backend01.stg.iad2.fedoraproject.org | 17 +- .../mbs-frontend01.iad2.fedoraproject.org | 19 +- .../mbs-frontend01.stg.iad2.fedoraproject.org | 17 +- .../memcached01.iad2.fedoraproject.org | 16 +- .../memcached01.stg.iad2.fedoraproject.org | 16 +- .../mm-backend01.iad2.fedoraproject.org | 23 +- .../mm-backend01.stg.iad2.fedoraproject.org | 23 +- .../mm-crawler01.iad2.fedoraproject.org | 16 +- .../mm-crawler01.stg.iad2.fedoraproject.org | 24 +- .../mm-crawler02.iad2.fedoraproject.org | 16 +- ...-frontend-checkin01.iad2.fedoraproject.org | 39 +- .../mm-frontend01.iad2.fedoraproject.org | 19 +- .../mm-frontend01.stg.iad2.fedoraproject.org | 19 +- .../host_vars/noc01.iad2.fedoraproject.org | 32 +- inventory/host_vars/noc02.fedoraproject.org | 98 ++- .../notifs-backend01.iad2.fedoraproject.org | 20 +- .../notifs-backend02.iad2.fedoraproject.org | 20 +- .../notifs-web01.iad2.fedoraproject.org | 24 +- .../notifs-web02.iad2.fedoraproject.org | 24 +- .../host_vars/ns01.iad2.fedoraproject.org | 21 +- inventory/host_vars/ns02.fedoraproject.org | 87 ++- .../host_vars/ns02.iad2.fedoraproject.org | 21 +- inventory/host_vars/ns05.fedoraproject.org | 51 +- .../host_vars/ns13.rdu2.fedoraproject.org | 41 +- .../nuancier01.iad2.fedoraproject.org | 22 +- .../nuancier02.iad2.fedoraproject.org | 22 +- ...andidate-registry01.iad2.fedoraproject.org | 24 +- ...date-registry01.stg.iad2.fedoraproject.org | 24 +- .../oci-registry01.iad2.fedoraproject.org | 24 +- .../oci-registry01.stg.iad2.fedoraproject.org | 24 +- .../oci-registry02.iad2.fedoraproject.org | 24 +- .../ocp01.ocp.iad2.fedoraproject.org | 79 +-- .../ocp01.ocp.stg.iad2.fedoraproject.org | 79 +-- .../ocp02.ocp.iad2.fedoraproject.org | 79 +-- .../ocp02.ocp.stg.iad2.fedoraproject.org | 79 +-- .../ocp03.ocp.iad2.fedoraproject.org | 79 +-- .../ocp03.ocp.stg.iad2.fedoraproject.org | 79 +-- ...cs-backend-releng01.iad2.fedoraproject.org | 21 +- .../odcs-backend01.iad2.fedoraproject.org | 21 +- .../odcs-backend01.stg.iad2.fedoraproject.org | 20 +- .../odcs-frontend01.iad2.fedoraproject.org | 21 +- ...odcs-frontend01.stg.iad2.fedoraproject.org | 20 +- ...openqa-a64-worker01.iad2.fedoraproject.org | 99 ++- ...openqa-a64-worker02.iad2.fedoraproject.org | 99 ++- ...openqa-a64-worker03.iad2.fedoraproject.org | 99 ++- .../openqa-lab01.iad2.fedoraproject.org | 27 +- ...openqa-p09-worker01.iad2.fedoraproject.org | 99 ++- ...openqa-p09-worker02.iad2.fedoraproject.org | 99 ++- ...openqa-x86-worker01.iad2.fedoraproject.org | 110 ++-- ...openqa-x86-worker02.iad2.fedoraproject.org | 110 ++-- ...openqa-x86-worker04.iad2.fedoraproject.org | 110 ++-- .../host_vars/openqa01.iad2.fedoraproject.org | 23 +- .../os-control01.iad2.fedoraproject.org | 32 +- .../os-control01.stg.iad2.fedoraproject.org | 21 +- .../os-master01.iad2.fedoraproject.org | 32 +- .../os-master01.stg.iad2.fedoraproject.org | 24 +- .../os-master02.iad2.fedoraproject.org | 32 +- .../os-master02.stg.iad2.fedoraproject.org | 24 +- .../os-master03.iad2.fedoraproject.org | 32 +- .../os-master03.stg.iad2.fedoraproject.org | 24 +- .../os-node01.iad2.fedoraproject.org | 35 +- .../os-node01.stg.iad2.fedoraproject.org | 31 +- .../os-node02.iad2.fedoraproject.org | 35 +- .../os-node02.stg.iad2.fedoraproject.org | 31 +- .../os-node03.iad2.fedoraproject.org | 35 +- .../os-node03.stg.iad2.fedoraproject.org | 31 +- .../os-node04.iad2.fedoraproject.org | 35 +- .../os-node04.stg.iad2.fedoraproject.org | 31 +- .../os-node05.iad2.fedoraproject.org | 35 +- .../os-node05.stg.iad2.fedoraproject.org | 31 +- .../host_vars/os-proxy01.fedorainfracloud.org | 39 +- .../host_vars/os-proxy02.fedorainfracloud.org | 39 +- ...bs-aarch64-master01.iad2.fedoraproject.org | 25 +- ...arch64-master01.stg.iad2.fedoraproject.org | 25 +- ...osbs-aarch64-node01.iad2.fedoraproject.org | 24 +- ...-aarch64-node01.stg.iad2.fedoraproject.org | 24 +- ...osbs-aarch64-node02.iad2.fedoraproject.org | 24 +- ...-aarch64-node02.stg.iad2.fedoraproject.org | 24 +- .../osbs-control01.iad2.fedoraproject.org | 24 +- .../osbs-control01.stg.iad2.fedoraproject.org | 17 +- .../osbs-master01.iad2.fedoraproject.org | 24 +- .../osbs-master01.stg.iad2.fedoraproject.org | 25 +- .../osbs-node01.iad2.fedoraproject.org | 24 +- .../osbs-node01.stg.iad2.fedoraproject.org | 25 +- .../osbs-node02.iad2.fedoraproject.org | 24 +- .../osbs-node02.stg.iad2.fedoraproject.org | 25 +- .../host_vars/osuosl01.fedoraproject.org | 8 +- .../host_vars/osuosl02.fedoraproject.org | 8 +- .../host_vars/osuosl03.fedoraproject.org | 8 +- .../host_vars/pagure-stg01.fedoraproject.org | 35 +- .../host_vars/pagure02.fedoraproject.org | 54 +- .../pdc-backend01.iad2.fedoraproject.org | 24 +- .../pdc-backend02.iad2.fedoraproject.org | 28 +- .../pdc-backend03.iad2.fedoraproject.org | 28 +- .../pdc-web01.iad2.fedoraproject.org | 19 +- .../pdc-web01.stg.iad2.fedoraproject.org | 19 +- .../pdc-web02.iad2.fedoraproject.org | 19 +- .../host_vars/people02.fedoraproject.org | 97 ++- .../host_vars/pkgs01.iad2.fedoraproject.org | 48 +- .../pkgs01.stg.iad2.fedoraproject.org | 25 +- .../ppc64le-test.fedorainfracloud.org | 1 - .../host_vars/proxy01.iad2.fedoraproject.org | 65 +- .../proxy01.stg.iad2.fedoraproject.org | 22 +- inventory/host_vars/proxy02.fedoraproject.org | 79 +-- .../proxy02.stg.iad2.fedoraproject.org | 23 +- inventory/host_vars/proxy03.fedoraproject.org | 79 +-- inventory/host_vars/proxy04.fedoraproject.org | 79 +-- inventory/host_vars/proxy05.fedoraproject.org | 86 ++- inventory/host_vars/proxy06.fedoraproject.org | 79 +-- inventory/host_vars/proxy07.fedoraproject.org | 18 +- inventory/host_vars/proxy09.fedoraproject.org | 79 +-- .../host_vars/proxy10.iad2.fedoraproject.org | 63 +- .../host_vars/proxy101.iad2.fedoraproject.org | 61 +- inventory/host_vars/proxy11.fedoraproject.org | 79 +-- .../host_vars/proxy110.iad2.fedoraproject.org | 62 +- inventory/host_vars/proxy12.fedoraproject.org | 79 +-- inventory/host_vars/proxy13.fedoraproject.org | 33 +- inventory/host_vars/proxy14.fedoraproject.org | 79 +-- inventory/host_vars/proxy30.fedoraproject.org | 13 +- inventory/host_vars/proxy31.fedoraproject.org | 13 +- inventory/host_vars/proxy32.fedoraproject.org | 13 +- inventory/host_vars/proxy33.fedoraproject.org | 14 +- inventory/host_vars/proxy34.fedoraproject.org | 14 +- inventory/host_vars/proxy35.fedoraproject.org | 14 +- inventory/host_vars/proxy36.fedoraproject.org | 14 +- inventory/host_vars/proxy37.fedoraproject.org | 14 +- inventory/host_vars/proxy38.fedoraproject.org | 14 +- inventory/host_vars/proxy39.fedoraproject.org | 14 +- inventory/host_vars/proxy40.fedoraproject.org | 14 +- .../qvmhost-x86-01.iad2.fedoraproject.org | 46 +- .../qvmhost-x86-02.iad2.fedoraproject.org | 9 +- .../rabbitmq01.iad2.fedoraproject.org | 12 +- .../rabbitmq01.stg.iad2.fedoraproject.org | 2 +- .../rabbitmq02.iad2.fedoraproject.org | 12 +- .../rabbitmq02.stg.iad2.fedoraproject.org | 2 +- .../rabbitmq03.iad2.fedoraproject.org | 12 +- .../rabbitmq03.stg.iad2.fedoraproject.org | 2 +- .../resultsdb01.iad2.fedoraproject.org | 18 +- .../resultsdb01.stg.iad2.fedoraproject.org | 18 +- .../retrace-stg.aws.fedoraproject.org | 150 +++-- .../retrace03.rdu-cc.fedoraproject.org | 177 +++--- .../secondary01.iad2.fedoraproject.org | 23 +- .../sign-bridge01.iad2.fedoraproject.org | 16 +- .../sign-bridge01.stg.iad2.fedoraproject.org | 16 +- .../sign-vault01.iad2.fedoraproject.org | 6 +- .../sign-vault01.stg.iad2.fedoraproject.org | 16 +- .../smtp-mm-cc-rdu01.fedoraproject.org | 15 +- .../host_vars/smtp-mm-ib01.fedoraproject.org | 56 +- .../smtp-mm-osuosl01.fedoraproject.org | 17 +- .../storinator01.rdu-cc.fedoraproject.org | 29 +- .../sundries01.iad2.fedoraproject.org | 18 +- .../sundries01.stg.iad2.fedoraproject.org | 16 +- .../sundries02.iad2.fedoraproject.org | 18 +- .../host_vars/tang01.iad2.fedoraproject.org | 18 +- .../host_vars/tang02.iad2.fedoraproject.org | 18 +- .../host_vars/torrent02.fedoraproject.org | 85 ++- .../unbound-cc-rdu01.fedoraproject.org | 12 +- .../host_vars/unbound-ib01.fedoraproject.org | 60 +- .../unbound-osuosl01.fedoraproject.org | 14 +- .../host_vars/value01.iad2.fedoraproject.org | 21 +- .../value01.stg.iad2.fedoraproject.org | 12 +- .../host_vars/value02.iad2.fedoraproject.org | 18 +- .../value02.stg.iad2.fedoraproject.org | 12 +- .../virthost-cc-rdu01.fedoraproject.org | 8 +- .../virthost-cc-rdu02.fedoraproject.org | 8 +- .../virthost-cc-rdu03.fedoraproject.org | 8 +- .../virthost-cloud01.fedorainfracloud.org | 13 +- .../virthost-rdu01.fedoraproject.org | 22 +- .../virthost-rdu02.fedoraproject.org | 17 +- .../vmhost-a64-cc01.rdu-cc.fedoraproject.org | 59 +- .../vmhost-ocp01.stg.iad2.fedoraproject.org | 8 +- .../vmhost-ocp02.stg.iad2.fedoraproject.org | 8 +- .../vmhost-ocp03.stg.iad2.fedoraproject.org | 8 +- .../vmhost-ocp04.stg.iad2.fedoraproject.org | 8 +- ...vmhost-p08-copr01.rdu-cc.fedoraproject.org | 86 ++- ...vmhost-p08-copr02.rdu-cc.fedoraproject.org | 86 ++- .../vmhost-x86-01.iad2.fedoraproject.org | 46 +- .../vmhost-x86-01.stg.iad2.fedoraproject.org | 57 +- .../vmhost-x86-02.iad2.fedoraproject.org | 46 +- .../vmhost-x86-02.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-03.iad2.fedoraproject.org | 46 +- .../vmhost-x86-03.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-04.iad2.fedoraproject.org | 46 +- .../vmhost-x86-04.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-05.iad2.fedoraproject.org | 46 +- .../vmhost-x86-05.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-06.iad2.fedoraproject.org | 46 +- .../vmhost-x86-06.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-07.iad2.fedoraproject.org | 46 +- .../vmhost-x86-07.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-08.iad2.fedoraproject.org | 46 +- .../vmhost-x86-08.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-09.iad2.fedoraproject.org | 46 +- .../vmhost-x86-09.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-10.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-11.stg.iad2.fedoraproject.org | 56 +- .../vmhost-x86-12.stg.iad2.fedoraproject.org | 52 +- .../vmhost-x86-cc05.rdu-cc.fedoraproject.org | 122 ++-- .../vmhost-x86-cc06.rdu-cc.fedoraproject.org | 122 ++-- ...vmhost-x86-copr01.rdu-cc.fedoraproject.org | 60 +- ...vmhost-x86-copr02.rdu-cc.fedoraproject.org | 63 +- ...vmhost-x86-copr03.rdu-cc.fedoraproject.org | 60 +- ...vmhost-x86-copr04.rdu-cc.fedoraproject.org | 60 +- .../host_vars/wiki01.iad2.fedoraproject.org | 16 +- .../wiki01.stg.iad2.fedoraproject.org | 16 +- .../host_vars/wiki02.iad2.fedoraproject.org | 16 +- .../worker01.ocp.iad2.fedoraproject.org | 74 +-- .../worker01.ocp.stg.iad2.fedoraproject.org | 74 +-- .../worker02.ocp.iad2.fedoraproject.org | 74 +-- .../worker02.ocp.stg.iad2.fedoraproject.org | 74 +-- .../worker03.ocp.iad2.fedoraproject.org | 74 +-- .../worker03.ocp.stg.iad2.fedoraproject.org | 74 +-- .../worker04.ocp.stg.iad2.fedoraproject.org | 79 +-- .../worker05.ocp.stg.iad2.fedoraproject.org | 79 +-- .../zabbix01.stg.iad2.fedoraproject.org | 12 +- 769 files changed, 12115 insertions(+), 15787 deletions(-) diff --git a/inventory/group_vars/aarch64_test b/inventory/group_vars/aarch64_test index 2fd8375f78..756896c1c4 100644 --- a/inventory/group_vars/aarch64_test +++ b/inventory/group_vars/aarch64_test @@ -1,6 +1,6 @@ --- +ansible_ifcfg_blocklist: true freezes: false +host_group: cloud sudoers: "{{ private }}/files/sudo/arm-packager-sudoers" sudoers_main: nopasswd -host_group: cloud -ansible_ifcfg_blocklist: true diff --git a/inventory/group_vars/all b/inventory/group_vars/all index d1bc2aaeeb..a8d87fe62d 100644 --- a/inventory/group_vars/all +++ b/inventory/group_vars/all @@ -5,321 +5,56 @@ # Background/reference about external repos pulled in: # https://pagure.io/fedora-infrastructure/issue/5476 # +# IPA settings +additional_host_keytabs: [] ansible_base: /srv/web/infra - -# Path to the openshift-ansible checkout as external git repo brought into -# Fedora Infra -openshift_ansible: /srv/web/infra/openshift-ansible/ - -# -# END: Ansible roles_path variables -####### - -freezes: true -# most of our systems are in IAD2 -datacenter: iad2 -preferred_dc: iad2 -postfix_group: "none" - -# usually we do not want to enable nested virt, only on some virthosts -nested: false - -# most of our systems are 64bit. -# Used to install various nagios scripts and the like. -libdir: /usr/lib64 - -# Most EL systems need default EPEL repos. -# Some systems (notably fed-cloud*) need to get their own -# EPEL files because EPEL overrides packages in their core repos. -use_default_epel: true - -# example of ports for default iptables -# tcp_ports: [ 22, 80, 443 ] -# udp_ports: [ 110, 1024, 2049 ] -# multiple lines can be handled as below -# custom_rules: [ '-A INPUT -p tcp -m tcp --dport 8888 -j ACCEPT', -# '-A INPUT -p tcp -m tcp --dport 8889 -j ACCEPT' ] -# We default these to empty -udp_ports: [] -tcp_ports: [] -custom_rules: [] -nat_rules: [] -custom6_rules: [] - -# defaults for hw installs -install_noc: none - -# defaults for virt installs -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7 -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ -mem_size: 4096 -num_cpus: 2 -lvm_size: 20000 - -# on MOST infra systems, the interface connected to the infra network -# is eth0. but not on quite ALL systems. e.g. on s390 boxes it's enc900, -# on openqa-ppc64le-01.qa it's eth2 for some reason, and on qa01.qa and -# qa02.qa it's em3. currently this only affects whether GATEWAY, DOMAIN -# and DNS1/DNS2 lines are put into ifcfg-(device). -ansible_ifcfg_infra_net_devices: [ 'eth0', 'enc900' ] - -# Default netmask. All of our iad2 nets are /24's. Almost all of our -# non-iad2 sites are less than a /24. -eth0_nm: 255.255.255.0 -eth1_nm: 255.255.255.0 -eth1_ip: 10.0.0.10 -br0_nm: 255.255.255.0 -br1_nm: 255.255.255.0 -nm: 255.255.255.0 - # Default to managing the network, we want to not do this on select # hosts (like cloud nodes) ansible_ifcfg_blocklist: false # List of interfaces to explicitly disable ansible_ifcfg_disabled: [] +# on MOST infra systems, the interface connected to the infra network +# is eth0. but not on quite ALL systems. e.g. on s390 boxes it's enc900, +# on openqa-ppc64le-01.qa it's eth2 for some reason, and on qa01.qa and +# qa02.qa it's em3. currently this only affects whether GATEWAY, DOMAIN +# and DNS1/DNS2 lines are put into ifcfg-(device). +ansible_ifcfg_infra_net_devices: ['eth0', 'enc900'] # -# The default virt-install works for rhel7 or fedora with 1 nic +# Autodetect python version # -virt_install_command: "{{ virt_install_command_one_nic }}" - -main_bridge: br0 -nfs_bridge: br1 -mac_address: RANDOM -mac_address1: RANDOM - - -virt_install_command_pxe_rhcos: virt-install -n {{ inventory_hostname }} - --vcpus {{ num_cpus }},maxvcpus={{ num_cpus }} - --cpu host - --memory {{ mem_size }} - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --nographics - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --hvm --accelerate - --autostart --wait=-1 - --extra-args "ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:ens2:none hostname={{ inventory_hostname }} nameserver={{ dns }} console=ttyS0 nomodeset rd.neednet=1 coreos.inst=yes coreos.inst.install_dev=vda coreos.live.rootfs_url={{ rhcos_install_rootfs_url }} coreos.inst.ignition_url={{ rhcos_ignition_file_url }}" - --os-variant rhel7 - --location {{ rhcos_install_url }} - - -virt_install_command_one_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --watchdog default --rng /dev/random --cpu host - -virt_install_command_two_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none - ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} - --autostart --noautoconsole --watchdog default --rng /dev/random - -virt_install_command_one_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns1 }} - ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --watchdog default --rng /dev/random --cpu host - -virt_install_command_two_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --network bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} - --autostart --noautoconsole --watchdog default --rng /dev/random - -virt_install_command_ppc64le_one_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --watchdog default --rng /dev/random - -virt_install_command_ppc64le_two_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none - ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} - --autostart --noautoconsole --watchdog default --rng /dev/random - -virt_install_command_aarch64_one_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole - -virt_install_command_aarch64_one_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole - -virt_install_command_aarch64_2nd_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole - -virt_install_command_aarch64_two_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none - ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} - --autostart --noautoconsole --rng /dev/random - -virt_install_command_armv7_one_nic: virt-install -n {{ inventory_hostname }} --arch armv7l - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyAMA0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }} - --autostart --noautoconsole --rng /dev/random - -virt_install_command_armv7_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --arch armv7l - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyAMA0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }} - --autostart --noautoconsole --rng /dev/random --qemu-commandline="-machine highmem=off" - -virt_install_command_s390x_one_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --rng /dev/random --cpu host - -virt_install_command_s390x_one_nic_unsafe: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ipv4 }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --rng /dev/random --cpu host - -virt_install_command_rhel6: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - "inst.ksdevice=eth0 inst.ks={{ ks_url }} ip={{ eth0_ip }} netmask={{ nm }} - gateway={{ gw }} dns={{ dns }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }}" - --network=bridge=br0 --autostart --noautoconsole --watchdog default - -max_mem_size: "{{ mem_size * 5 }}" -max_cpu: "{{ num_cpus * 5 }}" - -# This is the wildcard certname for our proxies. It has a different name for -# the staging group and is used in the proxies.yml playbook. -wildcard_cert_name: wildcard-2020.fedoraproject.org -wildcard_crt_file: wildcard-2020.fedoraproject.org.cert -wildcard_key_file: wildcard-2020.fedoraproject.org.key -wildcard_int_file: wildcard-2020.fedoraproject.org.intermediate.cert - -# This is the openshift wildcard cert. Until it exists set it equal to wildcard -os_wildcard_cert_name: wildcard-2021.app.os.fedoraproject.org -os_wildcard_crt_file: wildcard-2021.app.os.fedoraproject.org.cert -os_wildcard_key_file: wildcard-2021.app.os.fedoraproject.org.key -os_wildcard_int_file: wildcard-2021.app.os.fedoraproject.org.intermediate.cert - -# This is the openshift wildcard cert for ocp -ocp_wildcard_cert_name: wildcard-2021.apps.ocp.fedoraproject.org -ocp_wildcard_cert_file: wildcard-2021.apps.ocp.fedoraproject.org.cert -ocp_wildcard_key_file: wildcard-2021.apps.ocp.fedoraproject.org.key -ocp_wildcard_int_file: wildcard-2021.apps.ocp.fedoraproject.org.intermediate.cert - -# This is the mirrors.centos.org certs -mirrors_centos_org_cert_name: mirrors.centos.org -mirrors_centos_org_cert_file: mirrors.centos.org.cert -mirrors_centos_org_key_file: mirrors.centos.org.key - -# Everywhere, always, we should sign messages and validate signatures. -# However, we allow individual hosts and groups to override this. Use this very -# carefully.. and never in production (good for testing stuff in staging). -fedmsg_sign_messages: True -fedmsg_validate_signatures: True - -# By default, nodes get no fedmsg certs. They need to declare them explicitly. -fedmsg_certs: [] - -# By default, fedmsg should not log debug info. Groups can override this. -fedmsg_loglevel: INFO - -# By default, fedmsg sends error logs to sysadmin-datanommer-members@fp.o. -fedmsg_error_recipients: -- sysadmin-datanommer-members@fedoraproject.org - -# By default, fedmsg hosts are in passive mode. External hosts are typically -# active. -fedmsg_active: False - -# Other defaults for fedmsg environments -fedmsg_prefix: org.fedoraproject -fedmsg_env: prod - -# Amount of time to wait for connections after a socket is first established. -fedmsg_post_init_sleep: 1.0 - -# A special flag that, when set to true, will disconnect the host from the -# global fedmsg-relay instance and set it up with its own local one. You can -# temporarily set this to true for a specific host to do some debugging -- so -# you can *replay real messages from the datagrepper history without having -# those broadcast to the rest of the bus*. -fedmsg_debug_loopback: False +ansible_python_interpreter: auto +# Set variable if we want to use our global iptables defaults +# Some things need to set their own. +baseiptables: True +# by default set become to false here We can override it as needed. +# Note that if become is true, you need to unset requiretty for +# ssh controlpersist to work. +become: false +br0_nm: 255.255.255.0 +br1_nm: 255.255.255.0 +# assume collectd apache +collectd_apache: true +# true or false if we are or are not a copr build virthost. +# Default to false +copr_build_virthost: false +# assume createrepo is true and this builder has the koji nfs mount to do that +createrepo: True +csi_primary_contact: Fedora Admins - admin@fedoraproject.org +csi_purpose: Unspecified +csi_relationship: | + Unspecified. + * What hosts/services does this rely on? + * What hosts/services rely on this? + To update this text, add the csi_* vars to group_vars/ in ansible. +# This vars get shoved into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: Unspecified +custom6_rules: [] +custom_rules: [] +# most of our systems are in IAD2 +datacenter: iad2 # These are used to: # 1) configure mod_wsgi # 2) open iptables rules for fedmsg (per wsgi thread) @@ -330,130 +65,187 @@ fedmsg_debug_loopback: False # By default, nodes don't backup any dbs on them unless they declare it. dbs_to_backup: [] - -# by default the number of procs we allow before we whine -nrpe_procs_warn: 250 -nrpe_procs_crit: 300 - -# by default, the number of emails in queue before we whine -nrpe_check_postfix_queue_warn: 2 -nrpe_check_postfix_queue_crit: 5 - +dns1: "10.3.163.33" +dns2: "10.3.163.34" # env is staging or production, we default it to production here. env: production env_prefix: "" -env_suffix: "" env_short: prod - -# nfs mount options, override at the group/host level -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - -# by default set become to false here We can override it as needed. -# Note that if become is true, you need to unset requiretty for -# ssh controlpersist to work. -become: false - -# default the root_auth_users to nothing. -# This should be set for cloud instances in their host or group vars. -root_auth_users: '' - -# This vars get shoved into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ -csi_security_category: Unspecified -csi_primary_contact: Fedora Admins - admin@fedoraproject.org -csi_purpose: Unspecified -csi_relationship: | - Unspecified. - * What hosts/services does this rely on? - * What hosts/services rely on this? - - To update this text, add the csi_* vars to group_vars/ in ansible. - +env_suffix: "" +# Default netmask. All of our iad2 nets are /24's. Almost all of our +# non-iad2 sites are less than a /24. +eth0_nm: 255.255.255.0 +eth1_ip: 10.0.0.10 +eth1_nm: 255.255.255.0 +# By default, fedmsg hosts are in passive mode. External hosts are typically +# active. +fedmsg_active: False +# By default, nodes get no fedmsg certs. They need to declare them explicitly. +fedmsg_certs: [] +# A special flag that, when set to true, will disconnect the host from the +# global fedmsg-relay instance and set it up with its own local one. You can +# temporarily set this to true for a specific host to do some debugging -- so +# you can *replay real messages from the datagrepper history without having +# those broadcast to the rest of the bus*. +fedmsg_debug_loopback: False +fedmsg_env: prod +# By default, fedmsg sends error logs to sysadmin-datanommer-members@fp.o. +fedmsg_error_recipients: + - sysadmin-datanommer-members@fedoraproject.org +# By default, fedmsg should not log debug info. Groups can override this. +fedmsg_loglevel: INFO +# Amount of time to wait for connections after a socket is first established. +fedmsg_post_init_sleep: 1.0 +# Other defaults for fedmsg environments +fedmsg_prefix: org.fedoraproject +# Everywhere, always, we should sign messages and validate signatures. +# However, we allow individual hosts and groups to override this. Use this very +# carefully.. and never in production (good for testing stuff in staging). +fedmsg_sign_messages: True +fedmsg_validate_signatures: True # -# say if we want the apache role dependency for mod_wsgi or not -# In some cases we want mod_wsgi and no apache (for python3 httpaio stuff) -# -wsgi_wants_apache: true - -# IPA settings -additional_host_keytabs: [] +# END: Ansible roles_path variables +####### +freezes: true +# defaults for hw installs +install_noc: none +ipa_admin_password: "{{ ipa_prod_admin_password }}" +ipa_realm: FEDORAPROJECT.ORG ipa_server: ipa01.iad2.fedoraproject.org ipa_server_nodes: - ipa01.iad2.fedoraproject.org - ipa02.iad2.fedoraproject.org #- ipa03.iad2.fedoraproject.org -ipa_realm: FEDORAPROJECT.ORG -ipa_admin_password: "{{ ipa_prod_admin_password }}" -primary_auth_source: ipa - -# Normal default sshd port is 22 -sshd_port: 22 -# This enables/disables the SSH "keyhelper" used by Pagure for verifying users' -# SSH keys from the Pagure database -sshd_keyhelper: false - -# List of names under which the host is available -ssh_hostnames: [] - -# assume collectd apache -collectd_apache: true - -# assume vpn is false -vpn: False - -# assume createrepo is true and this builder has the koji nfs mount to do that -createrepo: True - +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +# defaults for virt installs +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7 +# most of our systems are 64bit. +# Used to install various nagios scripts and the like. +libdir: /usr/lib64 +lvm_size: 20000 +mac_address: RANDOM +mac_address1: RANDOM +main_bridge: br0 +max_cpu: "{{ num_cpus * 5 }}" +max_mem_size: "{{ mem_size * 5 }}" +mem_size: 4096 +mirrors_centos_org_cert_file: mirrors.centos.org.cert +# This is the mirrors.centos.org certs +mirrors_centos_org_cert_name: mirrors.centos.org +mirrors_centos_org_key_file: mirrors.centos.org.key +nagios_Can_Connect: true # Nagios global variables nagios_Check_Services: - mail: true - nrpe: true - sshd: true - named: false dhcpd: false httpd: false - swap: true + mail: true + named: false + nrpe: true ping: true raid: false - -nagios_Can_Connect: true - -# Set variable if we want to use our global iptables defaults -# Some things need to set their own. -baseiptables: True - + sshd: true + swap: true +nat_rules: [] +# usually we do not want to enable nested virt, only on some virthosts +nested: false +nfs_bridge: br1 +# nfs mount options, override at the group/host level +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +nm: 255.255.255.0 # Most of our machines have manual resolv.conf files # These settings are for machines where NM is supposed to control resolv.conf. nm_controlled_resolv: False -dns1: "10.3.163.33" -dns2: "10.3.163.34" - +nrpe_check_postfix_queue_crit: 5 +# by default, the number of emails in queue before we whine +nrpe_check_postfix_queue_warn: 2 +nrpe_procs_crit: 300 +# by default the number of procs we allow before we whine +nrpe_procs_warn: 250 +num_cpus: 2 +# ocp4 is only set true in some proxy roles +ocp4: false +ocp_wildcard_cert_file: wildcard-2021.apps.ocp.fedoraproject.org.cert +# This is the openshift wildcard cert for ocp +ocp_wildcard_cert_name: wildcard-2021.apps.ocp.fedoraproject.org +ocp_wildcard_int_file: wildcard-2021.apps.ocp.fedoraproject.org.intermediate.cert +ocp_wildcard_key_file: wildcard-2021.apps.ocp.fedoraproject.org.key +# Path to the openshift-ansible checkout as external git repo brought into +# Fedora Infra +openshift_ansible: /srv/web/infra/openshift-ansible/ +# This is the openshift wildcard cert. Until it exists set it equal to wildcard +os_wildcard_cert_name: wildcard-2021.app.os.fedoraproject.org +os_wildcard_crt_file: wildcard-2021.app.os.fedoraproject.org.cert +os_wildcard_int_file: wildcard-2021.app.os.fedoraproject.org.intermediate.cert +os_wildcard_key_file: wildcard-2021.app.os.fedoraproject.org.key +postfix_group: "none" # This is a list of services that need to wait for VPN to be up before getting started. postvpnservices: [] - -# true or false if we are or are not a copr build virthost. -# Default to false -copr_build_virthost: false - +preferred_dc: iad2 +primary_auth_source: ipa # # Set a redirectmatch variable we can use to disable some redirectmatches # like the prerelease to final ones. # redirectmatch_enabled: True - +# default the root_auth_users to nothing. +# This should be set for cloud instances in their host or group vars. +root_auth_users: '' +# List of names under which the host is available +ssh_hostnames: [] +# This enables/disables the SSH "keyhelper" used by Pagure for verifying users' +# SSH keys from the Pagure database +sshd_keyhelper: false +# Normal default sshd port is 22 +sshd_port: 22 # # sshd can run a internal sftp server, we need this on some hosts, but # not on most of them, so default to false sshd_sftp: false - +tcp_ports: [] +# example of ports for default iptables +# tcp_ports: [ 22, 80, 443 ] +# udp_ports: [ 110, 1024, 2049 ] +# multiple lines can be handled as below +# custom_rules: [ '-A INPUT -p tcp -m tcp --dport 8888 -j ACCEPT', +# '-A INPUT -p tcp -m tcp --dport 8889 -j ACCEPT' ] +# We default these to empty +udp_ports: [] +# Most EL systems need default EPEL repos. +# Some systems (notably fed-cloud*) need to get their own +# EPEL files because EPEL overrides packages in their core repos. +use_default_epel: true # -# Autodetect python version +# The default virt-install works for rhel7 or fedora with 1 nic # -ansible_python_interpreter: auto - +virt_install_command: "{{ virt_install_command_one_nic }}" +virt_install_command_aarch64_2nd_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole +virt_install_command_aarch64_one_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole +virt_install_command_aarch64_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole +virt_install_command_aarch64_two_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} --autostart --noautoconsole --rng /dev/random +virt_install_command_armv7_one_nic: virt-install -n {{ inventory_hostname }} --arch armv7l --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyAMA0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }} --autostart --noautoconsole --rng /dev/random +virt_install_command_armv7_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --arch armv7l --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyAMA0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }} --autostart --noautoconsole --rng /dev/random --qemu-commandline="-machine highmem=off" +virt_install_command_one_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --watchdog default --rng /dev/random --cpu host +virt_install_command_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns1 }} ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --watchdog default --rng /dev/random --cpu host +virt_install_command_ppc64le_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --watchdog default --rng /dev/random +virt_install_command_ppc64le_two_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} --autostart --noautoconsole --watchdog default --rng /dev/random +virt_install_command_pxe_rhcos: virt-install -n {{ inventory_hostname }} --vcpus {{ num_cpus }},maxvcpus={{ num_cpus }} --cpu host --memory {{ mem_size }} --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --nographics --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --hvm --accelerate --autostart --wait=-1 --extra-args "ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:ens2:none hostname={{ inventory_hostname }} nameserver={{ dns }} console=ttyS0 nomodeset rd.neednet=1 coreos.inst=yes coreos.inst.install_dev=vda coreos.live.rootfs_url={{ rhcos_install_rootfs_url }} coreos.inst.ignition_url={{ rhcos_ignition_file_url }}" --os-variant rhel7 --location {{ rhcos_install_url }} +virt_install_command_rhel6: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x "inst.ksdevice=eth0 inst.ks={{ ks_url }} ip={{ eth0_ip }} netmask={{ nm }} gateway={{ gw }} dns={{ dns }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }}" --network=bridge=br0 --autostart --noautoconsole --watchdog default +virt_install_command_s390x_one_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --rng /dev/random --cpu host +virt_install_command_s390x_one_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ipv4 }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --rng /dev/random --cpu host +virt_install_command_two_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} --autostart --noautoconsole --watchdog default --rng /dev/random +virt_install_command_two_nic_unsafe: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }},cache=unsafe,io=threads --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 inst.ksdevice=eth0 inst.ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --network bridge={{ nfs_bridge }},model=virtio,mac={{ mac_address1 }} --autostart --noautoconsole --watchdog default --rng /dev/random +# assume vpn is false +vpn: False +# This is the wildcard certname for our proxies. It has a different name for +# the staging group and is used in the proxies.yml playbook. +wildcard_cert_name: wildcard-2020.fedoraproject.org +wildcard_crt_file: wildcard-2020.fedoraproject.org.cert +wildcard_int_file: wildcard-2020.fedoraproject.org.intermediate.cert +wildcard_key_file: wildcard-2020.fedoraproject.org.key +# +# say if we want the apache role dependency for mod_wsgi or not +# In some cases we want mod_wsgi and no apache (for python3 httpaio stuff) +# +wsgi_wants_apache: true # set no x-forward header by default x_forward: false - -# ocp4 is only set true in some proxy roles -ocp4: false diff --git a/inventory/group_vars/autosign b/inventory/group_vars/autosign index 24c7c464d7..2b06041e9a 100644 --- a/inventory/group_vars/autosign +++ b/inventory/group_vars/autosign @@ -1,39 +1,32 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 2048 -num_cpus: 2 - +ansible_ifcfg_allowlist: + - eth0 + - eth1 +csi_primary_contact: Release Engineering - rel-eng@lists.fedoraproject.org +csi_purpose: Automatically sign Rawhide and Branched packages +csi_relationship: | + This host will run the robosignatory application which should automatically sign + builds. It listens to koji over fedora-messaging for notifications of new builds, + and then asks sigul, the signing server, to sign the rpms and store the new rpm + header back in Koji. +# For the MOTD +csi_security_category: High # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file # Make connections from signing bridges stateless, they break sigul connections # https://bugzilla.redhat.com/show_bug.cgi?id=1283364 custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT'] - -ansible_ifcfg_allowlist: -- eth0 -- eth1 - +fedmsg_error_recipients: [] host_group: autosign +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: autosign ipa_host_group_desc: Hosts signing content automatically -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -fedmsg_error_recipients: [] - +lvm_size: 30000 +mem_size: 2048 nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -# For the MOTD -csi_security_category: High -csi_primary_contact: Release Engineering - rel-eng@lists.fedoraproject.org -csi_purpose: Automatically sign Rawhide and Branched packages -csi_relationship: | - This host will run the robosignatory application which should automatically sign - builds. It listens to koji over fedora-messaging for notifications of new builds, - and then asks sigul, the signing server, to sign the rpms and store the new rpm - header back in Koji. - +num_cpus: 2 diff --git a/inventory/group_vars/autosign_hardware b/inventory/group_vars/autosign_hardware index 478f0e7583..767f52c912 100644 --- a/inventory/group_vars/autosign_hardware +++ b/inventory/group_vars/autosign_hardware @@ -2,5 +2,4 @@ # Make connections from signing bridges stateless, they break sigul connections # https://bugzilla.redhat.com/show_bug.cgi?id=1283364 custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT'] - host_group: autosign diff --git a/inventory/group_vars/badges b/inventory/group_vars/badges index a46018e530..819b0689f0 100644 --- a/inventory/group_vars/badges +++ b/inventory/group_vars/badges @@ -1,10 +1,10 @@ --- -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-badges + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-badges ipa_host_group: badges ipa_host_group_desc: Hosts running the Badges application -ipa_client_shell_groups: -- sysadmin-badges -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-badges +primary_auth_source: ipa diff --git a/inventory/group_vars/badges_backend b/inventory/group_vars/badges_backend index eaae9b0755..a1bf3ab946 100644 --- a/inventory/group_vars/badges_backend +++ b/inventory/group_vars/badges_backend @@ -1,60 +1,51 @@ --- -lvm_size: 20000 -mem_size: 16384 -num_cpus: 2 -freezes: false - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007 ] - - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- sysadmin-badges-members@fedoraproject.org - -fedmsg_hub_auto_restart: True -fedmsg_hub_memory_limit_mb: "{{ (mem_size / 2) | int }}" - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fedbadges - owner: root - group: fedmsg - can_send: - - fedbadges.badge.award - - fedbadges.person.rank.advance - - -# For the MOTD -csi_security_category: Low csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org csi_purpose: Run fedmsg-hub with the fedbadges plugin to award badges (+ some crons) csi_relationship: | - fedbadges integrates many different services.. + fedbadges integrates many different services.. - * The fedbadges fedmsg-hub plugin relies on: - * the fedmsg bus, to deliver messages - * pkgdb, for queries about who owns what packages - * fas, to lookup what irc nick corresponds to what fas user. - * db-datanommer for the fedmsg history - * db01, for storing badge awards + * The fedbadges fedmsg-hub plugin relies on: + * the fedmsg bus, to deliver messages + * pkgdb, for queries about who owns what packages + * fas, to lookup what irc nick corresponds to what fas user. + * db-datanommer for the fedmsg history + * db01, for storing badge awards - * badges-web01 will be expecting to display badges entered into the tahrir - db on db01. So, if badges stop showing up there, the problem is likely - here. + * badges-web01 will be expecting to display badges entered into the tahrir + db on db01. So, if badges stop showing up there, the problem is likely + here. - * Locally, of note there exists: - * a git repo of badge rules and images to be synced here by ansible - to /usr/share/badges/ - * a local file cache in /var/tmp/fedbadges-cache.dbm (not memcached, atm) - * Furthermore, there are a ton of cronjobs for awarding badges in - /usr/share/badges/cronjobs/ that depends on all sorts of third parties - (flickr, google+, libravatar, etc..). + * Locally, of note there exists: + * a git repo of badge rules and images to be synced here by ansible + to /usr/share/badges/ + * a local file cache in /var/tmp/fedbadges-cache.dbm (not memcached, atm) + * Furthermore, there are a ton of cronjobs for awarding badges in + /usr/share/badges/cronjobs/ that depends on all sorts of third parties + (flickr, google+, libravatar, etc..). +# For the MOTD +csi_security_category: Low +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedbadges.badge.award + - fedbadges.person.rank.advance + group: fedmsg + owner: root + service: fedbadges +# These people get told when something goes wrong. +fedmsg_error_recipients: + - sysadmin-badges-members@fedoraproject.org +fedmsg_hub_auto_restart: True +fedmsg_hub_memory_limit_mb: "{{ (mem_size / 2) | int }}" +freezes: false +lvm_size: 20000 +mem_size: 16384 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] diff --git a/inventory/group_vars/badges_backend_stg b/inventory/group_vars/badges_backend_stg index cf6ae1dda0..52b2b804bc 100644 --- a/inventory/group_vars/badges_backend_stg +++ b/inventory/group_vars/badges_backend_stg @@ -1,59 +1,51 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 8192 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007 ] - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- sysadmin-badges-members@fedoraproject.org - -fedmsg_hub_auto_restart: True -fedmsg_hub_memory_limit_mb: "{{ (mem_size / 2) | int }}" - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fedbadges - owner: root - group: fedmsg - can_send: - - fedbadges.badge.award - - fedbadges.person.rank.advance - - -# For the MOTD -csi_security_category: Low csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org csi_purpose: Run fedmsg-hub with the fedbadges plugin to award badges (+ some crons) csi_relationship: | - fedbadges integrates many different services.. + fedbadges integrates many different services.. - * The fedbadges fedmsg-hub plugin relies on: - * the fedmsg bus, to deliver messages - * pkgdb, for queries about who owns what packages - * fas, to lookup what irc nick corresponds to what fas user. - * db-datanommer for the fedmsg history - * db01, for storing badge awards + * The fedbadges fedmsg-hub plugin relies on: + * the fedmsg bus, to deliver messages + * pkgdb, for queries about who owns what packages + * fas, to lookup what irc nick corresponds to what fas user. + * db-datanommer for the fedmsg history + * db01, for storing badge awards - * badges-web01 will be expecting to display badges entered into the tahrir - db on db01. So, if badges stop showing up there, the problem is likely - here. + * badges-web01 will be expecting to display badges entered into the tahrir + db on db01. So, if badges stop showing up there, the problem is likely + here. - * Locally, of note there exists: - * a git repo of badge rules and images to be synced here by ansible - to /usr/share/badges/ - * a local file cache in /var/tmp/fedbadges-cache.dbm (not memcached, atm) - * Furthermore, there are a ton of cronjobs for awarding badges in - /usr/share/badges/cronjobs/ that depends on all sorts of third parties - (flickr, google+, libravatar, etc..). + * Locally, of note there exists: + * a git repo of badge rules and images to be synced here by ansible + to /usr/share/badges/ + * a local file cache in /var/tmp/fedbadges-cache.dbm (not memcached, atm) + * Furthermore, there are a ton of cronjobs for awarding badges in + /usr/share/badges/cronjobs/ that depends on all sorts of third parties + (flickr, google+, libravatar, etc..). +# For the MOTD +csi_security_category: Low +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedbadges.badge.award + - fedbadges.person.rank.advance + group: fedmsg + owner: root + service: fedbadges +# These people get told when something goes wrong. +fedmsg_error_recipients: + - sysadmin-badges-members@fedoraproject.org +fedmsg_hub_auto_restart: True +fedmsg_hub_memory_limit_mb: "{{ (mem_size / 2) | int }}" +lvm_size: 20000 +mem_size: 8192 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] diff --git a/inventory/group_vars/badges_stg b/inventory/group_vars/badges_stg index 7249fcbfae..06cf4e86b3 100644 --- a/inventory/group_vars/badges_stg +++ b/inventory/group_vars/badges_stg @@ -1,11 +1,11 @@ --- +ipa_client_shell_groups: + - sysadmin-badges + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-badges + - sysadmin-noc + - sysadmin-veteran ipa_host_group: badges ipa_host_group_desc: Hosts running the Badges application -ipa_client_shell_groups: -- sysadmin-badges -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-badges -- sysadmin-noc -- sysadmin-veteran diff --git a/inventory/group_vars/badges_web b/inventory/group_vars/badges_web index 90ca468036..5f6e20864e 100644 --- a/inventory/group_vars/badges_web +++ b/inventory/group_vars/badges_web @@ -1,9 +1,48 @@ --- +csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org +csi_purpose: Run the 'tahrir' mod_wsgi app to display badges.fedoraproject.org +csi_relationship: | + The apache/mod_wsgi app is the only thing really running here + + * This host relies on: + * db01 for its database of badge awards (and users, etc..) + * a collection of .pngs in /usr/share/badges/pngs put there by ansible + * memcached! + + * Conversely, a few things rely on this site: + * We have a mediawiki plugin that hits a JSON endpoint to display badges. + It should be resilient, but issues in the badges app may cascade into + mediawiki issues in the event of faults. + * fedora-mobile (the android app) queries the JSON api here. + * zodbot has a .badges command that queries the JSON api here. + * openbadges.org may call back to this app to verify that badge assertions + are really certified by us (this will happen anytime someone exports + their fedora badges to the mozilla universe via the tahrir web + interface, but may also happen later in the future to ensure we did not + revoke such and such badge). +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedbadges.badge.award + - fedbadges.person.rank.advance + - fedbadges.person.login.first + group: tahrir + owner: root + service: tahrir +freezes: false lvm_size: 20000 mem_size: 6144 num_cpus: 2 -freezes: false - +tcp_ports: [80] # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -11,49 +50,3 @@ freezes: false wsgi_fedmsg_service: tahrir wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: tahrir - owner: root - group: tahrir - can_send: - - fedbadges.badge.award - - fedbadges.person.rank.advance - - fedbadges.person.login.first - - -# For the MOTD -csi_security_category: Low -csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org -csi_purpose: Run the 'tahrir' mod_wsgi app to display badges.fedoraproject.org -csi_relationship: | - The apache/mod_wsgi app is the only thing really running here - - * This host relies on: - * db01 for its database of badge awards (and users, etc..) - * a collection of .pngs in /usr/share/badges/pngs put there by ansible - * memcached! - - * Conversely, a few things rely on this site: - * We have a mediawiki plugin that hits a JSON endpoint to display badges. - It should be resilient, but issues in the badges app may cascade into - mediawiki issues in the event of faults. - * fedora-mobile (the android app) queries the JSON api here. - * zodbot has a .badges command that queries the JSON api here. - * openbadges.org may call back to this app to verify that badge assertions - are really certified by us (this will happen anytime someone exports - their fedora badges to the mozilla universe via the tahrir web - interface, but may also happen later in the future to ensure we did not - revoke such and such badge). diff --git a/inventory/group_vars/badges_web_stg b/inventory/group_vars/badges_web_stg index 1053550f1b..06e1d4ded7 100644 --- a/inventory/group_vars/badges_web_stg +++ b/inventory/group_vars/badges_web_stg @@ -1,9 +1,48 @@ --- # Define resources for this group of hosts here. +csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org +csi_purpose: Run the 'tahrir' mod_wsgi app to display badges.fedoraproject.org +csi_relationship: | + The apache/mod_wsgi app is the only thing really running here + + * This host relies on: + * db01 for its database of badge awards (and users, etc..) + * a collection of .pngs in /usr/share/badges/pngs put there by ansible + * memcached! + + * Conversely, a few things rely on this site: + * We have a mediawiki plugin that hits a JSON endpoint to display badges. + It should be resilient, but issues in the badges app may cascade into + mediawiki issues in the event of faults. + * fedora-mobile (the android app) queries the JSON api here. + * zodbot has a .badges command that queries the JSON api here. + * openbadges.org may call back to this app to verify that badge assertions + are really certified by us (this will happen anytime someone exports + their fedora badges to the mozilla universe via the tahrir web + interface, but may also happen later in the future to ensure we did not + revoke such and such badge). +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedbadges.badge.award + - fedbadges.person.rank.advance + - fedbadges.person.login.first + group: tahrir + owner: root + service: tahrir lvm_size: 20000 mem_size: 2048 num_cpus: 2 - +tcp_ports: [80] # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -11,48 +50,3 @@ num_cpus: 2 wsgi_fedmsg_service: tahrir wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: tahrir - owner: root - group: tahrir - can_send: - - fedbadges.badge.award - - fedbadges.person.rank.advance - - fedbadges.person.login.first - - -# For the MOTD -csi_security_category: Low -csi_primary_contact: Badges admins - sysadmin-badges-members@fedoraproject.org -csi_purpose: Run the 'tahrir' mod_wsgi app to display badges.fedoraproject.org -csi_relationship: | - The apache/mod_wsgi app is the only thing really running here - - * This host relies on: - * db01 for its database of badge awards (and users, etc..) - * a collection of .pngs in /usr/share/badges/pngs put there by ansible - * memcached! - - * Conversely, a few things rely on this site: - * We have a mediawiki plugin that hits a JSON endpoint to display badges. - It should be resilient, but issues in the badges app may cascade into - mediawiki issues in the event of faults. - * fedora-mobile (the android app) queries the JSON api here. - * zodbot has a .badges command that queries the JSON api here. - * openbadges.org may call back to this app to verify that badge assertions - are really certified by us (this will happen anytime someone exports - their fedora badges to the mozilla universe via the tahrir web - interface, but may also happen later in the future to ensure we did not - revoke such and such badge). diff --git a/inventory/group_vars/basset b/inventory/group_vars/basset index 7d64268466..57f70a4d42 100644 --- a/inventory/group_vars/basset +++ b/inventory/group_vars/basset @@ -1,22 +1,13 @@ --- # Define resources for this group of hosts here. +custom_rules: [ + # fas01, fas02 + '-A INPUT -p tcp -m tcp -s 10.5.126.25 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.26 --dport 80 -j ACCEPT', + # wiki01, wiki02 + '-A INPUT -p tcp -m tcp -s 10.5.126.63 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.73 --dport 80 -j ACCEPT', + # os-node* + '-A INPUT -p tcp -m tcp -s 10.5.126.248 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.164 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.165 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.166 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.167 --dport 80 -j ACCEPT'] lvm_size: 30000 mem_size: 4096 num_cpus: 2 - -custom_rules: [ - # fas01, fas02 - '-A INPUT -p tcp -m tcp -s 10.5.126.25 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.26 --dport 80 -j ACCEPT', - # wiki01, wiki02 - '-A INPUT -p tcp -m tcp -s 10.5.126.63 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.73 --dport 80 -j ACCEPT', - # os-node* - '-A INPUT -p tcp -m tcp -s 10.5.126.248 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.164 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.165 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.166 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.167 --dport 80 -j ACCEPT', -] - primary_auth_source: ipa diff --git a/inventory/group_vars/basset_stg b/inventory/group_vars/basset_stg index 566a92e32c..c1c139efe2 100644 --- a/inventory/group_vars/basset_stg +++ b/inventory/group_vars/basset_stg @@ -1,17 +1,12 @@ --- # Define resources for this group of hosts here. +custom_rules: [ + # fas01.stg + '-A INPUT -p tcp -m tcp -s 10.5.128.129 --dport 80 -j ACCEPT', + # wiki01.stg + '-A INPUT -p tcp -m tcp -s 10.5.128.188 --dport 80 -j ACCEPT', + # os-node*.stg + '-A INPUT -p tcp -m tcp -s 10.5.128.104 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.128.105 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.128.106 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.128.107 --dport 80 -j ACCEPT'] lvm_size: 20000 mem_size: 4096 num_cpus: 2 - -custom_rules: [ - # fas01.stg - '-A INPUT -p tcp -m tcp -s 10.5.128.129 --dport 80 -j ACCEPT', - # wiki01.stg - '-A INPUT -p tcp -m tcp -s 10.5.128.188 --dport 80 -j ACCEPT', - # os-node*.stg - '-A INPUT -p tcp -m tcp -s 10.5.128.104 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.128.105 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.128.106 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.128.107 --dport 80 -j ACCEPT', -] diff --git a/inventory/group_vars/bastion b/inventory/group_vars/bastion index 56ad9ae205..2173ca0318 100644 --- a/inventory/group_vars/bastion +++ b/inventory/group_vars/bastion @@ -1,72 +1,5 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 8192 -num_cpus: 4 - -# -# allow incoming openvpn and smtp -# -tcp_ports: [ 22, 25, 1194 ] -udp_ports: [ 1194 ] - -# -# drop incoming traffic from less trusted vpn hosts -# allow ntp from internal RH 10 nets -# -custom_rules: [ - '-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', - '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT', -] - -primary_auth_source: ipa - -# allow a bunch of sysadmin groups here so they can access internal stuff -ipa_host_group: bastion -ipa_host_group_desc: Bastion hosts - -ipa_client_shell_groups: -- pungi-devel -- sysadmin-analysis -- sysadmin-dba -- sysadmin-ppc -- sysadmin-secondary -- sysadmin-spin -- sysadmin-troubleshoot -- sysadmin-qa -- sysadmin-kernel -ipa_client_shell_groups_inherit_from: -- batcave - -fasjson_url: https://fasjson.fedoraproject.org/ - -# -# This is a postfix gateway. This will pick up gateway postfix config in base -# -postfix_group: gateway -postfix_transport_filename: transports.gateway - -# -# Set this to get fasclient cron to make the aliases file -# -fas_aliases: true - -# -# Set this to get fasjson-client cron to make the aliases file -# -fasjson_aliases: false - -# -# Sometimes there are lots of postfix processes -# -nrpe_procs_warn: 1100 -nrpe_procs_crit: 1200 - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: sysadmin-main admin@fedoraproject.org csi_purpose: SSH proxy to access infrastructure not exposed to the web csi_relationship: | @@ -75,9 +8,58 @@ csi_relationship: | - All incoming SMTP from iad2 and VPN, as well as outgoing SMTP, pass or are filtered here. - Bastion does not accept any mail outside phx2/vpn. - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +# +# drop incoming traffic from less trusted vpn hosts +# allow ntp from internal RH 10 nets +# +custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT'] +# +# Set this to get fasclient cron to make the aliases file +# +fas_aliases: true +# +# Set this to get fasjson-client cron to make the aliases file +# +fasjson_aliases: false +fasjson_url: https://fasjson.fedoraproject.org/ +ipa_client_shell_groups: + - pungi-devel + - sysadmin-analysis + - sysadmin-dba + - sysadmin-ppc + - sysadmin-secondary + - sysadmin-spin + - sysadmin-troubleshoot + - sysadmin-qa + - sysadmin-kernel +ipa_client_shell_groups_inherit_from: + - batcave +# allow a bunch of sysadmin groups here so they can access internal stuff +ipa_host_group: bastion +ipa_host_group_desc: Bastion hosts +lvm_size: 20000 +mem_size: 8192 nagios_Check_Services: - nrpe: true mail: false - -# needed for rhel8 + nrpe: true +nrpe_procs_crit: 1200 +# +# Sometimes there are lots of postfix processes +# +nrpe_procs_warn: 1100 +num_cpus: 4 +# +# This is a postfix gateway. This will pick up gateway postfix config in base +# +postfix_group: gateway +postfix_transport_filename: transports.gateway +primary_auth_source: ipa +# +# allow incoming openvpn and smtp +# +tcp_ports: [22, 25, 1194] +udp_ports: [1194] diff --git a/inventory/group_vars/bastion_stg b/inventory/group_vars/bastion_stg index b4ccb05934..49d4f8633f 100644 --- a/inventory/group_vars/bastion_stg +++ b/inventory/group_vars/bastion_stg @@ -1,59 +1,16 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 8192 -num_cpus: 4 - -# -# allow incoming openvpn and smtp -# -tcp_ports: [ 22, 25, 1194 ] -udp_ports: [ 1194 ] - -# -# drop incoming traffic from less trusted vpn hosts -# allow ntp from internal RH 10 nets -# -custom_rules: [ - '-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', - '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT', -] -# -# allow a bunch of sysadmin groups here so they can access internal stuff -# -ipa_host_group: bastion -ipa_host_group_desc: Bastion hosts - +bastion_ipa_client_shell_groups: + - pungi-devel + - sysadmin-analysis + - sysadmin-dba + - sysadmin-ppc + - sysadmin-secondary + - sysadmin-spin + - sysadmin-troubleshoot # this only works if the `batcave_stg` group and at least one host in it is defined # batcave_ipa_client_shell_groups: "{{ hostvars[groups['batcave_stg'][0]]['ipa_client_shell_groups'] | default([]) }}" batcave_ipa_client_shell_groups: [] -bastion_ipa_client_shell_groups: -- pungi-devel -- sysadmin-analysis -- sysadmin-dba -- sysadmin-ppc -- sysadmin-secondary -- sysadmin-spin -- sysadmin-troubleshoot - -ipa_client_shell_groups: "{{ (bastion_ipa_client_shell_groups + batcave_ipa_client_shell_groups) | sort | unique }}" - -# -# Set this to get fasjson-client cron to make the aliases file -# -fasjson_aliases: true - -# -# Sometimes there are lots of postfix processes -# -nrpe_procs_warn: 1100 -nrpe_procs_crit: 1200 - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: sysadmin-main admin@fedoraproject.org csi_purpose: SSH proxy to access STAGING infrastructure not exposed to the web csi_relationship: | @@ -62,9 +19,38 @@ csi_relationship: | - All incoming SMTP from iad2 and VPN, as well as outgoing SMTP, pass or are filtered here. - Bastion does not accept any mail outside phx2/vpn. - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +# +# drop incoming traffic from less trusted vpn hosts +# allow ntp from internal RH 10 nets +# +custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT'] +# +# Set this to get fasjson-client cron to make the aliases file +# +fasjson_aliases: true +ipa_client_shell_groups: "{{ (bastion_ipa_client_shell_groups + batcave_ipa_client_shell_groups) | sort | unique }}" +# +# allow a bunch of sysadmin groups here so they can access internal stuff +# +ipa_host_group: bastion +ipa_host_group_desc: Bastion hosts +lvm_size: 20000 +mem_size: 8192 nagios_Check_Services: - nrpe: true mail: false - -# needed for rhel8 + nrpe: true +nrpe_procs_crit: 1200 +# +# Sometimes there are lots of postfix processes +# +nrpe_procs_warn: 1100 +num_cpus: 4 +# +# allow incoming openvpn and smtp +# +tcp_ports: [22, 25, 1194] +udp_ports: [1194] diff --git a/inventory/group_vars/batcave b/inventory/group_vars/batcave index dde45d9bf6..d05a84c54e 100644 --- a/inventory/group_vars/batcave +++ b/inventory/group_vars/batcave @@ -1,83 +1,76 @@ --- -lvm_size: 500000 -mem_size: 24576 -num_cpus: 10 - -tcp_ports: [ 80, 443, 8442, 8443 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: batcave -ipa_host_group_desc: The Bat Cave -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-ask -- sysadmin-badges -- sysadmin-bot -- sysadmin-centos -- sysadmin-cloud -- sysadmin-copr -- sysadmin-coreos -- sysadmin-cvs -- sysadmin-datanommer -- sysadmin-debuginfod -- sysadmin-fedimg -- sysadmin-koschei -- sysadmin-libravatar -- sysadmin-mbs -- sysadmin-messaging -- sysadmin-noc -- sysadmin-odcs -- sysadmin-osbs -- sysadmin-qa -- sysadmin-retrace -- sysadmin-releasemonitoring -- sysadmin-releng -- sysadmin-tools -- sysadmin-upstreamfirst -- sysadmin-veteran -- sysadmin-web - ansible_base: /srv/web/infra -freezes: true -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - ansible.playbook.complete - - ansible.playbook.start - - logger.log -- service: scm - owner: root - group: sysadmin - can_send: - - infragit.receive - -# For the MOTD -csi_security_category: High csi_primary_contact: admin@fedoraproject.org / sysadmin-main-members csi_purpose: Central management host for ansible csi_relationship: | - From the batcave batman ventures out to fight crime and protect gotham city! + From the batcave batman ventures out to fight crime and protect gotham city! - batcave is the central management host for ansible. - It also is the infrastructure.fedoraproject.org website with various content. - It houses a number of infrastructure git repos. + batcave is the central management host for ansible. + It also is the infrastructure.fedoraproject.org website with various content. + It houses a number of infrastructure git repos. - * This host relies on: - The virthost it's hosted on (virthost22) + * This host relies on: + The virthost it's hosted on (virthost22) - * Things that rely on this host: - Things that access rhel/fedora/infra rpm repos, including builders and infra hosts. - If this host is down, ansible runs cannot be made to update other hosts. - If this host is down, crime may go up in gotham city. - -nrpe_procs_warn: 900 + * Things that rely on this host: + Things that access rhel/fedora/infra rpm repos, including builders and infra hosts. + If this host is down, ansible runs cannot be made to update other hosts. + If this host is down, crime may go up in gotham city. +# For the MOTD +csi_security_category: High +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +fedmsg_certs: + - can_send: + - ansible.playbook.complete + - ansible.playbook.start + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - infragit.receive + group: sysadmin + owner: root + service: scm +freezes: true +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-ask + - sysadmin-badges + - sysadmin-bot + - sysadmin-centos + - sysadmin-cloud + - sysadmin-copr + - sysadmin-coreos + - sysadmin-cvs + - sysadmin-datanommer + - sysadmin-debuginfod + - sysadmin-fedimg + - sysadmin-koschei + - sysadmin-libravatar + - sysadmin-mbs + - sysadmin-messaging + - sysadmin-noc + - sysadmin-odcs + - sysadmin-osbs + - sysadmin-qa + - sysadmin-retrace + - sysadmin-releasemonitoring + - sysadmin-releng + - sysadmin-tools + - sysadmin-upstreamfirst + - sysadmin-veteran + - sysadmin-web +ipa_host_group: batcave +ipa_host_group_desc: The Bat Cave +lvm_size: 500000 +mem_size: 24576 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" nrpe_procs_crit: 1000 -vpn: true +nrpe_procs_warn: 900 +num_cpus: 10 +primary_auth_source: ipa sshd_sftp: true +tcp_ports: [80, 443, 8442, 8443] +vpn: true diff --git a/inventory/group_vars/bkernel b/inventory/group_vars/bkernel index 042951816a..9d3bde61b2 100644 --- a/inventory/group_vars/bkernel +++ b/inventory/group_vars/bkernel @@ -1,13 +1,11 @@ --- host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -ipa_host_group: kojibuilder-kernel -ipa_host_group_desc: Koji Build hosts for kernel builds # Both of these default to sysadmin-main in the ipa/client role ipa_client_shell_groups: [] ipa_client_sudo_groups: [] +ipa_host_group: kojibuilder-kernel +ipa_host_group_desc: Koji Build hosts for kernel builds +koji_hub_nfs: "fedora_koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" diff --git a/inventory/group_vars/blockerbugs b/inventory/group_vars/blockerbugs index b241d13f2b..88682c43b3 100644 --- a/inventory/group_vars/blockerbugs +++ b/inventory/group_vars/blockerbugs @@ -1,48 +1,39 @@ --- -lvm_size: 30000 -mem_size: 4096 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443, 8888 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: blockerbugs -ipa_host_group_desc: Blocker bug tracking service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-qa -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-qa - -# This gets overridden by whichever node we want to run special cronjobs. -master_blockerbugs_node: False - -host_group: blockerbugs - -blockerbugs_secret_key: "{{ stg_blockerbugs_secret_key }}" -blockerbugs_url: 'https://qa.fedoraproject.org/blockerbugs/' -blockerbugs_bugzilla_url: 'https://bugzilla.redhat.com/' blockerbugs_bodhi_url: 'https://bodhi.fedoraproject.org/' -blockerbugs_pagure_url: 'https://pagure.io/' -blockerbugs_pagure_repo_token_secret: "{{ blockerbugs_pagure_repo_token }}" -blockerbugs_pagure_repo_webhook_key_secret: "{{ blockerbugs_pagure_repo_webhook_key }}" - +blockerbugs_bugzilla_url: 'https://bugzilla.redhat.com/' +blockerbugs_db_host: "{{ blockerbugs_db_host_machine }}" ############################################################ # blockerbugs db details ############################################################ - blockerbugs_db_host_machine: db01.iad2.fedoraproject.org -blockerbugs_db_host: "{{ blockerbugs_db_host_machine }}" -blockerbugs_db_port: 5432 blockerbugs_db_name: blockerbugs +blockerbugs_db_password: "{{ prod_blockerbugs_db_password }}" +blockerbugs_db_port: 5432 # these aren't right but they're just placeholders for now blockerbugs_db_user: "{{ prod_blockerbugs_db_user }}" -blockerbugs_db_password: "{{ prod_blockerbugs_db_password }}" +blockerbugs_pagure_repo_token_secret: "{{ blockerbugs_pagure_repo_token }}" +blockerbugs_pagure_repo_webhook_key_secret: "{{ blockerbugs_pagure_repo_webhook_key }}" +blockerbugs_pagure_url: 'https://pagure.io/' +blockerbugs_secret_key: "{{ stg_blockerbugs_secret_key }}" +blockerbugs_url: 'https://qa.fedoraproject.org/blockerbugs/' +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +host_group: blockerbugs +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-qa + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: blockerbugs +ipa_host_group_desc: Blocker bug tracking service +lvm_size: 30000 +# This gets overridden by whichever node we want to run special cronjobs. +master_blockerbugs_node: False +mem_size: 4096 +num_cpus: 2 +primary_auth_source: ipa +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, 8888] diff --git a/inventory/group_vars/blockerbugs_stg b/inventory/group_vars/blockerbugs_stg index f4b3e313d4..eba12a41f7 100644 --- a/inventory/group_vars/blockerbugs_stg +++ b/inventory/group_vars/blockerbugs_stg @@ -1,44 +1,36 @@ --- -lvm_size: 30000 -mem_size: 4096 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443, 8888 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: blockerbugs -ipa_host_group_desc: Blocker bug tracking service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-qa -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-qa - -# This gets overridden by whichever node we want to run special cronjobs. -master_blockerbugs_node: False - -blockerbugs_secret_key: "{{ stg_blockerbugs_secret_key }}" -blockerbugs_url: 'https://qa.stg.fedoraproject.org/blockerbugs/' -blockerbugs_bugzilla_url: 'https://bugzilla.stage.redhat.com/' blockerbugs_bodhi_url: 'https://bodhi.stg.fedoraproject.org/' -blockerbugs_pagure_url: 'https://stg.pagure.io/' -blockerbugs_pagure_repo_token_secret: "{{ blockerbugs_stg_pagure_repo_token }}" -blockerbugs_pagure_repo_webhook_key_secret: "{{ blockerbugs_stg_pagure_repo_webhook_key }}" - +blockerbugs_bugzilla_url: 'https://bugzilla.stage.redhat.com/' +blockerbugs_db_host: "{{ blockerbugs_db_host_machine }}" ############################################################ # blockerbugs db details ############################################################ - blockerbugs_db_host_machine: db01.stg.iad2.fedoraproject.org -blockerbugs_db_host: "{{ blockerbugs_db_host_machine }}" -blockerbugs_db_port: 5432 blockerbugs_db_name: blockerbugs -blockerbugs_db_user: "{{ stg_blockerbugs_db_user }}" blockerbugs_db_password: "{{ stg_blockerbugs_db_password }}" +blockerbugs_db_port: 5432 +blockerbugs_db_user: "{{ stg_blockerbugs_db_user }}" +blockerbugs_pagure_repo_token_secret: "{{ blockerbugs_stg_pagure_repo_token }}" +blockerbugs_pagure_repo_webhook_key_secret: "{{ blockerbugs_stg_pagure_repo_webhook_key }}" +blockerbugs_pagure_url: 'https://stg.pagure.io/' +blockerbugs_secret_key: "{{ stg_blockerbugs_secret_key }}" +blockerbugs_url: 'https://qa.stg.fedoraproject.org/blockerbugs/' +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-qa + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: blockerbugs +ipa_host_group_desc: Blocker bug tracking service +lvm_size: 30000 +# This gets overridden by whichever node we want to run special cronjobs. +master_blockerbugs_node: False +mem_size: 4096 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, 8888] diff --git a/inventory/group_vars/bodhi_backend b/inventory/group_vars/bodhi_backend index 0806ecec89..9618c94a32 100644 --- a/inventory/group_vars/bodhi_backend +++ b/inventory/group_vars/bodhi_backend @@ -1,50 +1,36 @@ --- # common items for the releng-* boxes -lvm_size: 100000 -mem_size: 16384 -num_cpus: 16 -nm: 255.255.255.0 -gw: 10.5.125.254 -dns: 10.5.126.21 - -ks_url: http://10.5.126.23/repo/rhel/ks/kvm-rhel-7 -ks_repo: http://10.5.126.23/repo/rhel/RHEL7-x86_64/ - -virt_install_command: "{{ virt_install_command_two_nic }}" - -# Do not use testing repositories on production -testing: False - -# Make connections from signing bridges stateless, they break sigul connections -# https://bugzilla.redhat.com/show_bug.cgi?id=1283364 -custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.5.125.71 -j ACCEPT'] - -# With 16 cpus, theres a bunch more kernel threads -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -host_group: bodhi2 - bodhi_message_queue_name: "bodhi{{ env_suffix }}_composer" # Define the topics that our fedora-messaging queue should be subscribed to. bodhi_message_routing_keys: - "org.fedoraproject.*.bodhi.composer.start" - -## XXX -- note that the fedmsg_certs declaration does not happen here, but -# happens instead at the inventory/host_vars/ level s - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -sudoers: "{{ private }}/files/sudo/00releng-sudoers" - +# Make connections from signing bridges stateless, they break sigul connections +# https://bugzilla.redhat.com/show_bug.cgi?id=1283364 +custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.5.125.71 -j ACCEPT'] +dns: 10.5.126.21 +gw: 10.5.125.254 +host_group: bodhi2 +ipa_client_shell_groups: + - sysadmin-bodhi + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-bodhi + - sysadmin-releng ipa_host_group: bodhi ipa_host_group_desc: Bodhi update service -ipa_client_shell_groups: -- sysadmin-bodhi -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-bodhi -- sysadmin-releng - -## XXX - note that the csi_ stuff is kept at the host_vars/ level. - +ks_repo: http://10.5.126.23/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.5.126.23/repo/rhel/ks/kvm-rhel-7 +lvm_size: 100000 +mem_size: 16384 +## XXX -- note that the fedmsg_certs declaration does not happen here, but +# happens instead at the inventory/host_vars/ level s +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +# With 16 cpus, theres a bunch more kernel threads +nrpe_procs_warn: 900 +num_cpus: 16 +sudoers: "{{ private }}/files/sudo/00releng-sudoers" +# Do not use testing repositories on production +testing: False +virt_install_command: "{{ virt_install_command_two_nic }}" diff --git a/inventory/group_vars/bodhi_backend_stg b/inventory/group_vars/bodhi_backend_stg index 03e01fb9ff..1e3b52c5c3 100644 --- a/inventory/group_vars/bodhi_backend_stg +++ b/inventory/group_vars/bodhi_backend_stg @@ -1,59 +1,52 @@ --- # common items for the releng-* boxes -lvm_size: 100000 -mem_size: 4096 -num_cpus: 2 -nm: 255.255.255.0 -gw: 10.5.126.254 -dns: 10.5.126.21 - -# Use the infra-testing repo -testing: True - -# Make connections from signing bridges stateless, they break sigul connections -# https://bugzilla.redhat.com/show_bug.cgi?id=1283364 -# this is sign-bridge01.iad2 ip 10.3.169.120 -custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT'] - -# With 16 cpus, theres a bunch more kernel threads -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -host_group: bodhi2 - bodhi_message_queue_name: "bodhi{{ env_suffix }}_composer" # Define the topics that our fedora-messaging queue should be subscribed to. bodhi_message_routing_keys: - "org.fedoraproject.*.bodhi.composer.start" - -ipa_host_group: bodhi -ipa_host_group_desc: Bodhi update service -ipa_client_shell_groups: -- sysadmin-bodhi -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-bodhi -- sysadmin-releng - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Releng Admins sysadmin-releng-members@fedoraproject.org csi_purpose: Run the Bodhi masher. csi_relationship: | - The mashing of repos here happens as part of the 'fedmsg-hub' daemon. Check - logs with 'journalctl -u fedmsg-hub'. Check the bodhi masher docs/code for - more detail on what it does: - https://github.com/fedora-infra/bodhi/blob/develop/bodhi/consumers/masher.py + The mashing of repos here happens as part of the 'fedmsg-hub' daemon. Check + logs with 'journalctl -u fedmsg-hub'. Check the bodhi masher docs/code for + more detail on what it does: + https://github.com/fedora-infra/bodhi/blob/develop/bodhi/consumers/masher.py - * This host relies on: - * db01 for its database, which is shares with the bodhi2 frontend nodes. - * An NFS mount of koji data in /mnt/koji/ - * The fedmsg bus for triggering mashes. - * XMLRPC calls to koji for tagging and untagging updates. - * bugzilla for posting comments about status changes - * the wiki for getting information about QA "Test Cases" - * taksotron (resultsdb) for getting status-check results (gating updates). + * This host relies on: + * db01 for its database, which is shares with the bodhi2 frontend nodes. + * An NFS mount of koji data in /mnt/koji/ + * The fedmsg bus for triggering mashes. + * XMLRPC calls to koji for tagging and untagging updates. + * bugzilla for posting comments about status changes + * the wiki for getting information about QA "Test Cases" + * taksotron (resultsdb) for getting status-check results (gating updates). - * No other systems rely directly on this host. Everything depends on it - indirectly for the creation of new updates repos (which get synced out to - the master mirror for distribution. + * No other systems rely directly on this host. Everything depends on it + indirectly for the creation of new updates repos (which get synced out to + the master mirror for distribution. +# For the MOTD +csi_security_category: Moderate +# Make connections from signing bridges stateless, they break sigul connections +# https://bugzilla.redhat.com/show_bug.cgi?id=1283364 +# this is sign-bridge01.iad2 ip 10.3.169.120 +custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT'] +dns: 10.5.126.21 +gw: 10.5.126.254 +host_group: bodhi2 +ipa_client_shell_groups: + - sysadmin-bodhi + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-bodhi + - sysadmin-releng +ipa_host_group: bodhi +ipa_host_group_desc: Bodhi update service +lvm_size: 100000 +mem_size: 4096 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +# With 16 cpus, theres a bunch more kernel threads +nrpe_procs_warn: 900 +num_cpus: 2 +# Use the infra-testing repo +testing: True diff --git a/inventory/group_vars/builders b/inventory/group_vars/builders index ab6475697b..7f68629a4c 100644 --- a/inventory/group_vars/builders +++ b/inventory/group_vars/builders @@ -2,15 +2,14 @@ # nagios items # We don't use nrpe to check any of the builders # Nor do we check swap there. -nagios_Check_Services: - nrpe: false - swap: false - mail: false - -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: kojibuilder ipa_host_group_desc: Koji Build hosts -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng +nagios_Check_Services: + mail: false + nrpe: false + swap: false +primary_auth_source: ipa diff --git a/inventory/group_vars/builders_stg b/inventory/group_vars/builders_stg index ab6475697b..7f68629a4c 100644 --- a/inventory/group_vars/builders_stg +++ b/inventory/group_vars/builders_stg @@ -2,15 +2,14 @@ # nagios items # We don't use nrpe to check any of the builders # Nor do we check swap there. -nagios_Check_Services: - nrpe: false - swap: false - mail: false - -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: kojibuilder ipa_host_group_desc: Koji Build hosts -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng +nagios_Check_Services: + mail: false + nrpe: false + swap: false +primary_auth_source: ipa diff --git a/inventory/group_vars/buildhw b/inventory/group_vars/buildhw index 0871cc3c28..b61d529663 100644 --- a/inventory/group_vars/buildhw +++ b/inventory/group_vars/buildhw @@ -1,27 +1,23 @@ --- -host_group: kojibuilder -freezes: true - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +docker_registry: "candidate-registry.fedoraproject.org" +freezes: true +host_group: kojibuilder +koji_hub: "koji.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.fedoraproject.org/koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" # These variables are for koji-containerbuild/osbs osbs_url: "osbs.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" source_registry: "registry.fedoraproject.org" -koji_root: "koji.fedoraproject.org/koji" -koji_hub: "koji.fedoraproject.org/kojihub" diff --git a/inventory/group_vars/buildvm b/inventory/group_vars/buildvm index 969df66260..3d54c45f9f 100644 --- a/inventory/group_vars/buildvm +++ b/inventory/group_vars/buildvm @@ -1,27 +1,5 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/BuildGuests -lvm_size: 262144 -mem_size: 15360 -max_mem_size: "{{ mem_size }}" -num_cpus: 6 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -nm: 255.255.255.0 -gw: 10.5.125.254 -dns: 10.3.163.33 -virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders. csi_relationship: | @@ -29,10 +7,28 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new - +csi_security_category: High +dns: 10.3.163.33 +docker_registry: "candidate-registry.fedoraproject.org" +gw: 10.5.125.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.fedoraproject.org/koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 262144 +max_mem_size: "{{ mem_size }}" +mem_size: 15360 +nm: 255.255.255.0 +num_cpus: 6 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" source_registry: "registry.fedoraproject.org" -koji_root: "koji.fedoraproject.org/koji" -koji_hub: "koji.fedoraproject.org/kojihub" +virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" +volgroup: /dev/BuildGuests diff --git a/inventory/group_vars/buildvm_aarch64 b/inventory/group_vars/buildvm_aarch64 index 544a19d9b7..54ad74f3a1 100644 --- a/inventory/group_vars/buildvm_aarch64 +++ b/inventory/group_vars/buildvm_aarch64 @@ -1,29 +1,5 @@ --- # common items for the buildvm-aarch64* koji builders -volgroup: /dev/vg_guests -lvm_size: 140000 -mem_size: 40960 -max_mem_size: "{{ mem_size }}" -num_cpus: 5 -max_cpu: "{{ num_cpus }}" -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/aarch64/os/ -nm: 255.255.255.0 -gw: 10.3.170.254 -dns: 10.3.163.33 - -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders. csi_relationship: | @@ -31,10 +7,29 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new - +csi_security_category: High +dns: 10.3.163.33 +docker_registry: "candidate-registry.fedoraproject.org" +gw: 10.3.170.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.fedoraproject.org/koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 140000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 40960 +nm: 255.255.255.0 +num_cpus: 5 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" source_registry: "registry.fedoraproject.org" -koji_root: "koji.fedoraproject.org/koji" -koji_hub: "koji.fedoraproject.org/kojihub" +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_aarch64_stg b/inventory/group_vars/buildvm_aarch64_stg index af39a5baf3..4ec6113824 100644 --- a/inventory/group_vars/buildvm_aarch64_stg +++ b/inventory/group_vars/buildvm_aarch64_stg @@ -1,32 +1,6 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/vg_guests -lvm_size: 140000 -mem_size: 40960 -max_mem_size: "{{ mem_size }}" -num_cpus: 5 -max_cpu: "{{ num_cpus }}" -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/aarch64/os/ -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder -datacenter: staging -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High +createrepo: True csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders (staging). csi_relationship: | @@ -34,15 +8,36 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +datacenter: staging +dns: 10.3.163.33 +docker_registry: "candidate-registry.stg.fedoraproject.org" +gw: 10.3.167.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.stg.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.stg.fedoraproject.org/koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ -# this is to enable nested virt, which we need for some builds -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 140000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 40960 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 +num_cpus: 5 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.stg.fedoraproject.org" source_registry: "registry.stg.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" -koji_root: "koji.stg.fedoraproject.org/koji" -koji_hub: "koji.stg.fedoraproject.org/kojihub" - -createrepo: True +# this is to enable nested virt, which we need for some builds +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_armv7 b/inventory/group_vars/buildvm_armv7 index 4400a5e72e..347f0039fb 100644 --- a/inventory/group_vars/buildvm_armv7 +++ b/inventory/group_vars/buildvm_armv7 @@ -1,32 +1,5 @@ --- # common items for the buildvm-aarmv7* koji builders -volgroup: /dev/vg_guests -lvm_size: 140000 -mem_size: 40960 -max_mem_size: "{{ mem_size }}" -num_cpus: 5 -max_cpu: "{{ num_cpus }}" -ks_url: http://10.3.163.35/repo/rhel/ks/buildvm-fedora-34-armv7 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/armhfp/os/ -nm: 255.255.255.0 -gw: 10.3.170.254 -dns: 10.3.163.33 - -# This is reverted so that eth1 gets br0 and eth0 gets br1 -# This seems some kind of bug where in the guest kernel the devices are swapped around -# when compared to the host. -virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders. csi_relationship: | @@ -34,10 +7,32 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new - +csi_security_category: High +dns: 10.3.163.33 +docker_registry: "candidate-registry.fedoraproject.org" +gw: 10.3.170.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.fedoraproject.org/koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/armhfp/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/buildvm-fedora-34-armv7 +lvm_size: 140000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 40960 +nm: 255.255.255.0 +num_cpus: 5 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" source_registry: "registry.fedoraproject.org" -koji_root: "koji.fedoraproject.org/koji" -koji_hub: "koji.fedoraproject.org/kojihub" +# This is reverted so that eth1 gets br0 and eth0 gets br1 +# This seems some kind of bug where in the guest kernel the devices are swapped around +# when compared to the host. +virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_armv7_stg b/inventory/group_vars/buildvm_armv7_stg index 2999c07f00..ae347a6902 100644 --- a/inventory/group_vars/buildvm_armv7_stg +++ b/inventory/group_vars/buildvm_armv7_stg @@ -1,32 +1,6 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/vg_guests -lvm_size: 140000 -mem_size: 40960 -max_mem_size: "{{ mem_size }}" -num_cpus: 5 -max_cpu: "{{ num_cpus }}" -ks_url: http://10.3.163.35/repo/rhel/ks/buildvm-fedora-34-armv7 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/armhfp/os/ -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder -datacenter: staging -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High +createrepo: True csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders (staging). csi_relationship: | @@ -34,15 +8,36 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +datacenter: staging +dns: 10.3.163.33 +docker_registry: "candidate-registry.stg.fedoraproject.org" +gw: 10.3.167.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.stg.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.stg.fedoraproject.org/koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ -# this is to enable nested virt, which we need for some builds -virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" - +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/armhfp/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/buildvm-fedora-34-armv7 +lvm_size: 140000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 40960 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 +num_cpus: 5 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.stg.fedoraproject.org" source_registry: "registry.stg.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" -koji_root: "koji.stg.fedoraproject.org/koji" -koji_hub: "koji.stg.fedoraproject.org/kojihub" - -createrepo: True +# this is to enable nested virt, which we need for some builds +virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_ppc64le b/inventory/group_vars/buildvm_ppc64le index 5d3c83cc5d..a152f2fd0f 100644 --- a/inventory/group_vars/buildvm_ppc64le +++ b/inventory/group_vars/buildvm_ppc64le @@ -1,41 +1,5 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/vg_guests -lvm_size: 600000 -mem_size: 20480 -max_mem_size: 20480 -num_cpus: 8 - -ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/ppc64le/os/ -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora - -ipa_server: ipa01.iad2.fedoraproject.org -nm: 255.255.255.0 -gw: 10.3.171.254 -dns: 10.3.163.33 -datacenter: iad2 - -# -# The ppc virthosts have different bridge names for the main and nfs bridges. -# -main_bridge: br0 - -virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of virtual machines to build packages for the Fedora project. This group builds packages for ppcle architecture. csi_relationship: | @@ -43,3 +7,31 @@ csi_relationship: | * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new * virtual instances +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +datacenter: iad2 +dns: 10.3.163.33 +gw: 10.3.171.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +ipa_server: ipa01.iad2.fedoraproject.org +koji_hub_nfs: "fedora_koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/ppc64le/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 600000 +# +# The ppc virthosts have different bridge names for the main and nfs bridges. +# +main_bridge: br0 +max_mem_size: 20480 +mem_size: 20480 +nm: 255.255.255.0 +num_cpus: 8 +virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_ppc64le_stg b/inventory/group_vars/buildvm_ppc64le_stg index 4481476520..d055e74c4f 100644 --- a/inventory/group_vars/buildvm_ppc64le_stg +++ b/inventory/group_vars/buildvm_ppc64le_stg @@ -1,33 +1,6 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/vg_guests -lvm_size: 150000 -mem_size: 10240 -max_mem_size: "{{ mem_size }}" -num_cpus: 4 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/ppc64le/os/ -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder -datacenter: staging -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -main_bridge: br0 - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High +createrepo: True csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders (staging). csi_relationship: | @@ -35,14 +8,35 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +datacenter: staging +dns: 10.3.163.33 +docker_registry: "candidate-registry.stg.fedoraproject.org" +gw: 10.3.167.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +koji_hub: "koji.stg.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.stg.fedoraproject.org/koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ -virt_install_command: "{{ virt_install_command_ppc64le_one_nic_unsafe }}" - +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/ppc64le/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 150000 +main_bridge: br0 +max_mem_size: "{{ mem_size }}" +mem_size: 10240 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 +num_cpus: 4 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.stg.fedoraproject.org" source_registry: "registry.stg.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" -koji_root: "koji.stg.fedoraproject.org/koji" -koji_hub: "koji.stg.fedoraproject.org/kojihub" - -createrepo: True +virt_install_command: "{{ virt_install_command_ppc64le_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvm_s390x b/inventory/group_vars/buildvm_s390x index d2c94b23c8..c1e1afa999 100644 --- a/inventory/group_vars/buildvm_s390x +++ b/inventory/group_vars/buildvm_s390x @@ -1,28 +1,5 @@ --- -lvm_size: 102400 -mem_size: 10240 -max_mem_size: "{{ mem_size }}" -num_cpus: 3 -varnish_group: s390kojipkgs -vmhost: buildvmhost-s390x-01.s390.fedoraproject.org -gw: 10.16.0.254 -main_bridge: vmbr -volgroup: /dev/fedora_linux_lpar_1 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/s390x/os/ -dns: 10.3.163.33 -nm: 255.255.255.0 -virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}" - createrepo: False -host_group: kojibuilder - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders. csi_relationship: | @@ -30,3 +7,23 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +dns: 10.3.163.33 +gw: 10.16.0.254 +host_group: kojibuilder +koji_hub_nfs: "fedora_koji" +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/34/Server/s390x/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +lvm_size: 102400 +main_bridge: vmbr +max_mem_size: "{{ mem_size }}" +mem_size: 10240 +nm: 255.255.255.0 +num_cpus: 3 +varnish_group: s390kojipkgs +virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}" +vmhost: buildvmhost-s390x-01.s390.fedoraproject.org +volgroup: /dev/fedora_linux_lpar_1 diff --git a/inventory/group_vars/buildvm_s390x_stg b/inventory/group_vars/buildvm_s390x_stg index 701f24a7e4..287e53c8e2 100644 --- a/inventory/group_vars/buildvm_s390x_stg +++ b/inventory/group_vars/buildvm_s390x_stg @@ -1,17 +1,6 @@ --- ansible_ifcfg_blocklist: True createrepo: False -host_group: kojibuilder -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/35/Server/s390x/os/ -virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}" - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders. csi_relationship: | @@ -19,3 +8,12 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +host_group: kojibuilder +koji_hub_nfs: "fedora_koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora-secondary/releases/35/Server/s390x/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}" diff --git a/inventory/group_vars/buildvm_stg b/inventory/group_vars/buildvm_stg index 931189c589..0c80eb1247 100644 --- a/inventory/group_vars/buildvm_stg +++ b/inventory/group_vars/buildvm_stg @@ -1,34 +1,5 @@ --- # common items for the buildvm-* koji builders -volgroup: /dev/vg_guests -lvm_size: 150000 -mem_size: 10240 -max_mem_size: "{{ mem_size }}" -num_cpus: 4 -dns: 10.3.163.33 -gw: 10.3.167.254 -nm: 255.255.255.0 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -ks_url: http://10.3.163.35/repo/rhel/ks/kvm_fedora -resolvconf: "resolv.conf/iad2" -virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" -ipa_server: ipa01.stg.iad2.fedoraproject.org - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -host_group: kojibuilder -datacenter: staging -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=4" - -koji_hub_nfs: "fedora_koji" -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders (staging). csi_relationship: | @@ -36,10 +7,36 @@ csi_relationship: | * Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. * Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new +csi_security_category: High +datacenter: staging +dns: 10.3.163.33 +docker_registry: "candidate-registry.stg.fedoraproject.org" +gw: 10.3.167.254 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +host_group: kojibuilder +ipa_server: ipa01.stg.iad2.fedoraproject.org +koji_hub: "koji.stg.fedoraproject.org/kojihub" +koji_hub_nfs: "fedora_koji" +koji_root: "koji.stg.fedoraproject.org/koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm_fedora +lvm_size: 150000 +max_mem_size: "{{ mem_size }}" +mem_size: 10240 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=4" +nm: 255.255.255.0 +num_cpus: 4 # These variables are for koji-containerbuild/osbs osbs_url: "osbs.stg.fedoraproject.org" +resolvconf: "resolv.conf/iad2" source_registry: "registry.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" -koji_root: "koji.stg.fedoraproject.org/koji" -koji_hub: "koji.stg.fedoraproject.org/kojihub" +virt_install_command: "{{ virt_install_command_one_nic_unsafe }}" +volgroup: /dev/vg_guests diff --git a/inventory/group_vars/buildvmhost b/inventory/group_vars/buildvmhost index ddef7e26bc..8af3b77d15 100644 --- a/inventory/group_vars/buildvmhost +++ b/inventory/group_vars/buildvmhost @@ -1,17 +1,15 @@ --- -nrpe_procs_warn: 1500 -nrpe_procs_crit: 1600 -virthost: true -nested: True - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of virtual machines to build packages for the Fedora project. This playbook is for the provisioning of a physical host for buildvm's. csi_relationship: | - * Relies on ansible, virthost, and is monitored by nagios - * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. - * Builder vm's are hosted on hosts created with this playbook. + * Relies on ansible, virthost, and is monitored by nagios + * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. + * Builder vm's are hosted on hosts created with this playbook. +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +nested: True +nrpe_procs_crit: 1600 +nrpe_procs_warn: 1500 +virthost: true diff --git a/inventory/group_vars/busgateway b/inventory/group_vars/busgateway index c22d21a1be..834b7f94c4 100644 --- a/inventory/group_vars/busgateway +++ b/inventory/group_vars/busgateway @@ -1,34 +1,29 @@ --- # Define resources for this group of hosts here. +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer +ipa_host_group: busgateway +ipa_host_group_desc: Bridge between fedmsg and fedora-messaging lvm_size: 20000 mem_size: 8192 num_cpus: 2 - +primary_auth_source: ipa # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ - 3999, # The fedmsg-relay republishes here. Listeners need to connect. - 9941, # The fedmsg-relay listens here. Ephemeral producers connect. - 3998, # The fedmsg-relay listens here. VPN producers connect. - 9940, # The fedmsg-gateway republishes here. Proxies need to connect. - 9919, # The websocket server publishes here. Proxies need to connect. +tcp_ports: [3999, # The fedmsg-relay republishes here. Listeners need to connect. + 9941, # The fedmsg-relay listens here. Ephemeral producers connect. + 3998, # The fedmsg-relay listens here. VPN producers connect. + 9940, # The fedmsg-gateway republishes here. Proxies need to connect. + 9919, # The websocket server publishes here. Proxies need to connect. ] - -primary_auth_source: ipa -ipa_host_group: busgateway -ipa_host_group_desc: Bridge between fedmsg and fedora-messaging -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log diff --git a/inventory/group_vars/busgateway_stg b/inventory/group_vars/busgateway_stg index df1b467345..2d9b0f17c0 100644 --- a/inventory/group_vars/busgateway_stg +++ b/inventory/group_vars/busgateway_stg @@ -1,32 +1,27 @@ --- # Define resources for this group of hosts here. +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer +ipa_host_group: busgateway +ipa_host_group_desc: Bridge between fedmsg and fedora-messaging lvm_size: 20000 mem_size: 4096 num_cpus: 1 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ - 3999, # The fedmsg-relay republishes here. Listeners need to connect. - 9941, # The fedmsg-relay listens here. Ephemeral producers connect. - 9940, # The fedmsg-gateway republishes here. Proxies need to connect. - 9919, # The websocket server publishes here. Proxies need to connect. +tcp_ports: [3999, # The fedmsg-relay republishes here. Listeners need to connect. + 9941, # The fedmsg-relay listens here. Ephemeral producers connect. + 9940, # The fedmsg-gateway republishes here. Proxies need to connect. + 9919, # The websocket server publishes here. Proxies need to connect. ] - -ipa_host_group: busgateway -ipa_host_group_desc: Bridge between fedmsg and fedora-messaging -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log diff --git a/inventory/group_vars/bvirthost b/inventory/group_vars/bvirthost index b99245238a..2e0b22e3b7 100644 --- a/inventory/group_vars/bvirthost +++ b/inventory/group_vars/bvirthost @@ -1,5 +1,5 @@ --- -virthost: true -nrpe_procs_warn: 1400 -nrpe_procs_crit: 1500 nested: true +nrpe_procs_crit: 1500 +nrpe_procs_warn: 1400 +virthost: true diff --git a/inventory/group_vars/certgetter b/inventory/group_vars/certgetter index a1d49d430d..ff0224b0b9 100644 --- a/inventory/group_vars/certgetter +++ b/inventory/group_vars/certgetter @@ -1,15 +1,11 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] lvm_size: 20000 mem_size: 2048 num_cpus: 2 - +primary_auth_source: ipa # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 80, 443 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa +tcp_ports: [80, 443] diff --git a/inventory/group_vars/certgetter_stg b/inventory/group_vars/certgetter_stg index e8e8154a6c..b5b6c5fae8 100644 --- a/inventory/group_vars/certgetter_stg +++ b/inventory/group_vars/certgetter_stg @@ -1,13 +1,10 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] lvm_size: 20000 mem_size: 2048 num_cpus: 2 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 80, 443 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] +tcp_ports: [80, 443] diff --git a/inventory/group_vars/checkcompose b/inventory/group_vars/checkcompose index 1f665972b3..d472142d0e 100644 --- a/inventory/group_vars/checkcompose +++ b/inventory/group_vars/checkcompose @@ -1,16 +1,15 @@ # This var should never be set for more than one machine -checkcompose_prod: true -checkcompose_env_suffix: -checkcompose_env: production - # The checkcompose settings below cause system(s) in this group to # send out check-compose reports. This could cause duplicate reports # if additional systems were added to this group. checkcompose_emailfrom: rawhide@fedoraproject.org checkcompose_emailto: "test@lists.fedoraproject.org devel@lists.fedoraproject.org" +checkcompose_env: production +checkcompose_env_suffix: +checkcompose_greenwaveurl: https://greenwave.fedoraproject.org +checkcompose_prod: true +checkcompose_smtp: bastion.iad2.fedoraproject.org checkcompose_subvariant_emails: AtomicHost: error: ["dusty@dustymabe.com", "walters@verbum.org", "atomic@lists.fedoraproject.org"] -checkcompose_smtp: bastion.iad2.fedoraproject.org checkcompose_url: "https://{{ external_hostname }}" -checkcompose_greenwaveurl: https://greenwave.fedoraproject.org diff --git a/inventory/group_vars/checkcompose_common b/inventory/group_vars/checkcompose_common index ae53f05424..2362753746 100644 --- a/inventory/group_vars/checkcompose_common +++ b/inventory/group_vars/checkcompose_common @@ -1,15 +1,13 @@ # we need this for our fedora-messaging consumer as it is not allowed # to create queues on the infra AMQP broker, by broker config -checkcompose_amqp_passive: true - -# fedora-messaging compose report sender settings -checkcompose_amqp_url: "amqps://openqa{{ checkcompose_env_suffix }}:@rabbitmq{{ checkcompose_env_suffix }}.fedoraproject.org/%2Fpubsub" checkcompose_amqp_cacert: /etc/fedora-messaging/cacert{{ checkcompose_env_suffix }}.pem -checkcompose_amqp_key: /etc/pki/fedora-messaging/openqa{{ checkcompose_env_suffix }}-key.pem checkcompose_amqp_cert: /etc/pki/fedora-messaging/openqa{{ checkcompose_env_suffix }}-cert.pem -checkcompose_amqp_queue: "openqa{{ checkcompose_env_suffix }}_checkcomp" -checkcompose_amqp_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"] - +checkcompose_amqp_key: /etc/pki/fedora-messaging/openqa{{ checkcompose_env_suffix }}-key.pem # fedora-messaging email error reporting settings checkcompose_amqp_mailto: ["adamwill@fedoraproject.org", "lruzicka@fedoraproject.org"] +checkcompose_amqp_passive: true +checkcompose_amqp_queue: "openqa{{ checkcompose_env_suffix }}_checkcomp" +checkcompose_amqp_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"] checkcompose_amqp_smtp: bastion +# fedora-messaging compose report sender settings +checkcompose_amqp_url: "amqps://openqa{{ checkcompose_env_suffix }}:@rabbitmq{{ checkcompose_env_suffix }}.fedoraproject.org/%2Fpubsub" diff --git a/inventory/group_vars/checkcompose_stg b/inventory/group_vars/checkcompose_stg index 1c57929a07..d8bdc14f0c 100644 --- a/inventory/group_vars/checkcompose_stg +++ b/inventory/group_vars/checkcompose_stg @@ -1,6 +1,5 @@ -checkcompose_prod: false -checkcompose_env_suffix: .stg checkcompose_env: staging - -checkcompose_url: "https://{{ external_hostname }}" +checkcompose_env_suffix: .stg checkcompose_greenwaveurl: https://greenwave-web-greenwave.app.os.stg.fedoraproject.org +checkcompose_prod: false +checkcompose_url: "https://{{ external_hostname }}" diff --git a/inventory/group_vars/cloud b/inventory/group_vars/cloud index 88fae2ffe1..dd7e4827d8 100644 --- a/inventory/group_vars/cloud +++ b/inventory/group_vars/cloud @@ -1,7 +1,7 @@ --- +ansible_ifcfg_blocklist: true +datacenter: cloud nagios_Check_Services: mail: false nrpe: false swap: false -datacenter: cloud -ansible_ifcfg_blocklist: true diff --git a/inventory/group_vars/cloud_aws b/inventory/group_vars/cloud_aws index d4533f8cbd..5579d63ed7 100644 --- a/inventory/group_vars/cloud_aws +++ b/inventory/group_vars/cloud_aws @@ -6,15 +6,14 @@ # Disable ethX ifcfg, let amazon handle these via DHCP. ansible_ifcfg_blocklist: true - datacenter: aws nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false diff --git a/inventory/group_vars/cloud_hardware b/inventory/group_vars/cloud_hardware index ca5576bd9f..f4b234ea16 100644 --- a/inventory/group_vars/cloud_hardware +++ b/inventory/group_vars/cloud_hardware @@ -1,10 +1,7 @@ --- -freezes: false - -use_default_epel: false - collectd_apache: false - +freezes: false nagios_Check_Services: nrpe: true swap: true +use_default_epel: false diff --git a/inventory/group_vars/copr b/inventory/group_vars/copr index d24f4333c6..e803768a95 100644 --- a/inventory/group_vars/copr +++ b/inventory/group_vars/copr @@ -1,30 +1,22 @@ --- -devel: false _forward_src: "forward" - +ansible_ifcfg_blocklist: true +backend_base_url: "https://download.copr.fedorainfracloud.org" +builders: + # max|max_spawn|max_prealloc + aws: + aarch64: [20, 10, 10] + armhfp: [20, 5, 5] + x86_64: [100, 20, 30] +copr_aws_region: us-east-1 # don't forget to update ip in ./copr-keygen, due to custom firewall rules # eth0, eth1 copr_backend_ips: ["172.25.33.79", "172.25.82.25"] -keygen_host: "172.25.33.75" - -resolvconf: "resolv.conf/cloud" - -backend_base_url: "https://download.copr.fedorainfracloud.org" -postfix_maincf: "postfix/main.cf/main.cf.copr" - -frontend_base_url: "https://copr.fedorainfracloud.org" -dist_git_base_url: "copr-dist-git.fedorainfracloud.org" - -ansible_ifcfg_blocklist: true - -copr_aws_region: us-east-1 - datacenter: cloud - -builders: - # max|max_spawn|max_prealloc - aws: - x86_64: [100,20,30] - armhfp: [20,5,5] - aarch64: [20,10,10] +devel: false +dist_git_base_url: "copr-dist-git.fedorainfracloud.org" +frontend_base_url: "https://copr.fedorainfracloud.org" +keygen_host: "172.25.33.75" +postfix_maincf: "postfix/main.cf/main.cf.copr" +resolvconf: "resolv.conf/cloud" diff --git a/inventory/group_vars/copr_all_instances_aws b/inventory/group_vars/copr_all_instances_aws index 9c230a9149..60cbc418a0 100644 --- a/inventory/group_vars/copr_all_instances_aws +++ b/inventory/group_vars/copr_all_instances_aws @@ -1 +1,2 @@ # Put here configuration for all copr instances (production, devel, ...) + diff --git a/inventory/group_vars/copr_aws b/inventory/group_vars/copr_aws index 1b56bfea92..91708e9fd0 100644 --- a/inventory/group_vars/copr_aws +++ b/inventory/group_vars/copr_aws @@ -1,76 +1,7 @@ --- -devel: false -datacenter: aws - -copr_messaging: true - _forward_src: "forward" - -# don't forget to update ip in ./copr-keygen, due to custom firewall rules - -# eth0, eth1 -copr_backend_ips: ["52.44.175.77", "172.30.2.203"] -keygen_host: "54.83.48.73" - -backend_base_url: "https://download.copr.fedorainfracloud.org" -postfix_group: copr - -frontend_base_url: "https://copr.fedorainfracloud.org" -dist_git_base_url: "copr-dist-git.fedorainfracloud.org" - ansible_ifcfg_blocklist: true - -copr_aws_region: us-east-1 - -services_disabled: false -nm_controlled_resolv: True - -builders: - # max|spawn_concurrently|prealloc - aws: - x86_64: [20, 4, 4] - aarch64: [8, 2, 2] - - aws_spot: - x86_64: [40, 8, 8] - aarch64: [30, 4, 6] - - x86_hypervisor_01: - x86_64: [20, 4, 20] - - x86_hypervisor_02: - x86_64: [20, 4, 20] - - x86_hypervisor_03: - x86_64: [20, 4, 20] - - x86_hypervisor_04: - x86_64: [20, 4, 20] - - ppc64le_hypervisor_01: - ppc64le: [15, 4, 15] - - # There's the ppc64le-test machine, so keep 2 builders less. - ppc64le_hypervisor_02: - ppc64le: [13, 4, 13] - -copr_builder_images: - hypervisor: - x86_64: copr-builder-x86_64-20211012_115536 - ppc64le: copr-builder-ppc64le-20211012_120530 - aws: - x86_64: ami-0baeeebc194e64780 - aarch64: ami-068c2760406b9e3c9 - aws_arch_subnets: - x86_64: - - subnet-0995f6a466849f4c3 - - subnet-08cadf5a14b530ac4 - - subnet-07b0b3168a353e3ee - - subnet-09c74a3e6420a206b - - subnet-01d4e967ab5e78005 - - subnet-05437ac82d63b6ef5 - # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1a). # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1d). # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1f). @@ -78,5 +9,54 @@ aws_arch_subnets: - subnet-0995f6a466849f4c3 - subnet-08cadf5a14b530ac4 - subnet-07b0b3168a353e3ee + x86_64: + - subnet-0995f6a466849f4c3 + - subnet-08cadf5a14b530ac4 + - subnet-07b0b3168a353e3ee + - subnet-09c74a3e6420a206b + - subnet-01d4e967ab5e78005 + - subnet-05437ac82d63b6ef5 +backend_base_url: "https://download.copr.fedorainfracloud.org" +builders: + # max|spawn_concurrently|prealloc + aws: + aarch64: [8, 2, 2] + x86_64: [20, 4, 4] + aws_spot: + aarch64: [30, 4, 6] + x86_64: [40, 8, 8] + ppc64le_hypervisor_01: + ppc64le: [15, 4, 15] + # There's the ppc64le-test machine, so keep 2 builders less. + ppc64le_hypervisor_02: + ppc64le: [13, 4, 13] + x86_hypervisor_01: + x86_64: [20, 4, 20] + x86_hypervisor_02: + x86_64: [20, 4, 20] + x86_hypervisor_03: + x86_64: [20, 4, 20] + x86_hypervisor_04: + x86_64: [20, 4, 20] +copr_aws_region: us-east-1 +# don't forget to update ip in ./copr-keygen, due to custom firewall rules +# eth0, eth1 +copr_backend_ips: ["52.44.175.77", "172.30.2.203"] +copr_builder_images: + aws: + aarch64: ami-068c2760406b9e3c9 + x86_64: ami-0baeeebc194e64780 + hypervisor: + ppc64le: copr-builder-ppc64le-20211012_120530 + x86_64: copr-builder-x86_64-20211012_115536 +copr_messaging: true +datacenter: aws +devel: false +dist_git_base_url: "copr-dist-git.fedorainfracloud.org" +frontend_base_url: "https://copr.fedorainfracloud.org" +keygen_host: "54.83.48.73" +nm_controlled_resolv: True +postfix_group: copr rpm_vendor_copr_name: Fedora Copr +services_disabled: false diff --git a/inventory/group_vars/copr_back b/inventory/group_vars/copr_back index a80f7146b4..6ed61670ef 100644 --- a/inventory/group_vars/copr_back +++ b/inventory/group_vars/copr_back @@ -1,39 +1,31 @@ --- +# copr_builder_image_name: "Fedora-Cloud-Base-20141203-21" +copr_builder_flavor_name: "ms2.builder" +copr_builder_images: + aarch64: copr-builder-20200120_133457 + aws: + aarch64: ami-0acfbfbed95798259 # copr-builder-aarch64-f31-20200421_133814 + x86_64: ami-09a4c035460759858 # copr-builder-x86_64-f31-20200421_131242 + ppc64le: copr-builder-ppc64le-f31-20200117_132023 + x86_64: copr-builder-x86_64-f31-20200117_120726 +copr_builder_key_name: "buildsys" +copr_builder_network_name: "copr-net" +copr_builder_security_groups: "ssh-anywhere-copr,default,ssh-from-persistent-copr" copr_nova_auth_url: "https://fedorainfracloud.org:5000/v2.0" copr_nova_tenant_id: "5d99f099b7fe4b0387f0352f6301ba6a" copr_nova_tenant_name: "copr" copr_nova_username: "copr" - -# copr_builder_image_name: "Fedora-Cloud-Base-20141203-21" -copr_builder_flavor_name: "ms2.builder" -copr_builder_network_name: "copr-net" -copr_builder_key_name: "buildsys" -copr_builder_security_groups: "ssh-anywhere-copr,default,ssh-from-persistent-copr" - -copr_builder_images: - x86_64: copr-builder-x86_64-f31-20200117_120726 - ppc64le: copr-builder-ppc64le-f31-20200117_132023 - aarch64: copr-builder-20200120_133457 - aws: - x86_64: ami-09a4c035460759858 # copr-builder-x86_64-f31-20200421_131242 - aarch64: ami-0acfbfbed95798259 # copr-builder-aarch64-f31-20200421_133814 - -nrpe_procs_warn: 2200 -nrpe_procs_crit: 2500 - -do_sign: "true" - -spawn_in_advance: "true" -frontend_base_url: "https://copr.fedorainfracloud.org" - - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the backend for copr (3rd party packages) csi_relationship: | - Backend: Management of copr cloud infrastructure (OpenStack). - Small frontend with copr's public stats +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +do_sign: "true" +frontend_base_url: "https://copr.fedorainfracloud.org" +nrpe_procs_crit: 2500 +nrpe_procs_warn: 2200 +spawn_in_advance: "true" diff --git a/inventory/group_vars/copr_back_aws b/inventory/group_vars/copr_back_aws index 6246a4dfa0..dd0bd61a0a 100644 --- a/inventory/group_vars/copr_back_aws +++ b/inventory/group_vars/copr_back_aws @@ -1,55 +1,41 @@ --- -description: copr dispatcher and repo server +_copr_be_conf: copr-be.conf +# There is no python2 on F30 +# what is the main backend service name +copr_backend_target: copr-backend.target +# copr_builder_image_name: "Fedora-Cloud-Base-20141203-21" +copr_builder_flavor_name: "ms2.builder" +copr_builder_key_name: "buildsys" +copr_builder_network_name: "copr-net" +copr_builder_security_groups: "ssh-anywhere-copr,default,ssh-from-persistent-copr" +# Copr vars +copr_hostbase: copr-be copr_nova_auth_url: "https://fedorainfracloud.org:5000/v2.0" copr_nova_tenant_id: "5d99f099b7fe4b0387f0352f6301ba6a" copr_nova_tenant_name: "copr" copr_nova_username: "copr" - -# copr_builder_image_name: "Fedora-Cloud-Base-20141203-21" -copr_builder_flavor_name: "ms2.builder" -copr_builder_network_name: "copr-net" -copr_builder_key_name: "buildsys" -copr_builder_security_groups: "ssh-anywhere-copr,default,ssh-from-persistent-copr" - -nrpe_procs_warn: 2200 -nrpe_procs_crit: 2500 - -do_sign: "true" - -spawn_in_advance: "true" -frontend_base_url: "https://copr.fedorainfracloud.org" - - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the backend for copr (3rd party packages) csi_relationship: | - Backend: Management of copr cloud infrastructure (OpenStack). - Small frontend with copr's public stats - -root_auth_users: msuchy pingou frostyx praiskup schlupov - -tcp_ports: [ 22, 80, 443 ] - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +description: copr dispatcher and repo server +do_sign: "true" +frontend_base_url: "https://copr.fedorainfracloud.org" +host_backup_targets: ['/var/lib/copr/public_html/results'] # consumed by roles/messaging/base messaging: certificates: - - key: copr - username: copr - app_name: Copr build system - -# Copr vars -copr_hostbase: copr-be - -host_backup_targets: ['/var/lib/copr/public_html/results'] -_copr_be_conf: copr-be.conf - -# There is no python2 on F30 - -# what is the main backend service name -copr_backend_target: copr-backend.target + - app_name: Copr build system + key: copr + username: copr +nrpe_procs_crit: 2500 +nrpe_procs_warn: 2200 +root_auth_users: msuchy pingou frostyx praiskup schlupov +spawn_in_advance: "true" +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_back_dev b/inventory/group_vars/copr_back_dev index dfc809148f..88338ce7c3 100644 --- a/inventory/group_vars/copr_back_dev +++ b/inventory/group_vars/copr_back_dev @@ -1,44 +1,36 @@ --- +copr_builder_flavor_name: "ms2.builder" +copr_builder_image_name: "builder-f24" +copr_builder_images: + aarch64: copr-builder-20200120_133457 + aws: + aarch64: ami-0acfbfbed95798259 # copr-builder-aarch64-f31-20200421_133814 + x86_64: ami-09a4c035460759858 # copr-builder-x86_64-f31-20200421_131242 + ppc64le: copr-builder-ppc64le-f31-20200117_132023 + x86_64: copr-builder-x86_64-f31-20200117_120726 +copr_builder_key_name: "buildsys" +copr_builder_network_name: "coprdev-net" +copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" copr_nova_auth_url: "https://fedorainfracloud.org:5000/v2.0" copr_nova_tenant_id: "a6ff2158641c439a8426d7facab45437" copr_nova_tenant_name: "coprdev" copr_nova_username: "copr" - -copr_builder_image_name: "builder-f24" -copr_builder_flavor_name: "ms2.builder" -copr_builder_network_name: "coprdev-net" -copr_builder_key_name: "buildsys" -copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" - -copr_builder_images: - x86_64: copr-builder-x86_64-f31-20200117_120726 - ppc64le: copr-builder-ppc64le-f31-20200117_132023 - aarch64: copr-builder-20200120_133457 - aws: - x86_64: ami-09a4c035460759858 # copr-builder-x86_64-f31-20200421_131242 - aarch64: ami-0acfbfbed95798259 # copr-builder-aarch64-f31-20200421_133814 - -do_sign: "true" - -spawn_in_advance: "false" -frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" - - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: Moderate csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the testing environment of copr's backend csi_relationship: This host is the testing environment for the cloud infrastructure of copr's backend - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: Moderate +do_sign: "true" +frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: lighttpd certificates: copr-be-dev.cloud.fedoraproject.org: - domains: - - copr-be-dev.cloud.fedoraproject.org challenge_dir: /var/lib/copr/public_html + domains: + - copr-be-dev.cloud.fedoraproject.org mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: lighttpd +spawn_in_advance: "false" diff --git a/inventory/group_vars/copr_back_dev_aws b/inventory/group_vars/copr_back_dev_aws index 3b0650e480..e568e1c88d 100644 --- a/inventory/group_vars/copr_back_dev_aws +++ b/inventory/group_vars/copr_back_dev_aws @@ -1,58 +1,44 @@ --- -description: copr dispatcher and repo server - dev instance - +_copr_be_conf: copr-be.conf-dev +# what is the main backend service name +copr_backend_target: copr-backend.target +copr_builder_flavor_name: "ms2.builder" +copr_builder_image_name: "builder-f24" +copr_builder_key_name: "buildsys" +copr_builder_network_name: "coprdev-net" +copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" +# Copr vars +copr_hostbase: copr-be-dev copr_nova_auth_url: "https://fedorainfracloud.org:5000/v2.0" copr_nova_tenant_id: "a6ff2158641c439a8426d7facab45437" copr_nova_tenant_name: "coprdev" copr_nova_username: "copr" - -copr_builder_image_name: "builder-f24" -copr_builder_flavor_name: "ms2.builder" -copr_builder_network_name: "coprdev-net" -copr_builder_key_name: "buildsys" -copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" - -do_sign: "true" - -spawn_in_advance: "false" -frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" - - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: Moderate csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the testing environment of copr's backend csi_relationship: This host is the testing environment for the cloud infrastructure of copr's backend - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: Moderate +datacenter: aws +description: copr dispatcher and repo server - dev instance +do_sign: "true" +frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: lighttpd certificates: copr-be-dev.cloud.fedoraproject.org: - domains: - - copr-be-dev.cloud.fedoraproject.org challenge_dir: /var/lib/copr/public_html + domains: + - copr-be-dev.cloud.fedoraproject.org mail: copr-devel@lists.fedorahosted.org - -root_auth_users: msuchy pingou frostyx praiskup schlupov - -tcp_ports: [ 22, 80, 443 ] - + predefined_deploy_script: lighttpd # consumed by roles/messaging/base messaging: certificates: - - key: copr - username: copr - app_name: Copr build system - -# Copr vars -copr_hostbase: copr-be-dev -_copr_be_conf: copr-be.conf-dev - -datacenter: aws - -# what is the main backend service name -copr_backend_target: copr-backend.target + - app_name: Copr build system + key: copr + username: copr +root_auth_users: msuchy pingou frostyx praiskup schlupov +spawn_in_advance: "false" +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_back_stg b/inventory/group_vars/copr_back_stg index 2ae271477a..40e6650d9c 100644 --- a/inventory/group_vars/copr_back_stg +++ b/inventory/group_vars/copr_back_stg @@ -1,28 +1,21 @@ --- -resolvconf: "resolv.conf/cloud" - +copr_builder_flavor_name: "ms2.builder" +copr_builder_image_name: "builder-f24" +copr_builder_key_name: "buildsys" +copr_builder_network_name: "coprdev-net" +copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" copr_nova_auth_url: "https://fedorainfracloud.org:5000/v2.0" copr_nova_tenant_id: "a6ff2158641c439a8426d7facab45437" copr_nova_tenant_name: "coprdev" copr_nova_username: "copr" - -copr_builder_image_name: "builder-f24" -copr_builder_flavor_name: "ms2.builder" -copr_builder_network_name: "coprdev-net" -copr_builder_key_name: "buildsys" -copr_builder_security_groups: "ssh-anywhere-coprdev,default,ssh-from-persistent-coprdev" - -do_sign: "true" - -spawn_in_advance: "false" -frontend_base_url: "https://copr.stg.fedoraproject.org" - - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: Moderate csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the testing environment of copr's backend csi_relationship: This host is the testing environment for the cloud infrastructure of copr's backend +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: Moderate +do_sign: "true" +frontend_base_url: "https://copr.stg.fedoraproject.org" +resolvconf: "resolv.conf/cloud" +spawn_in_advance: "false" diff --git a/inventory/group_vars/copr_db_all b/inventory/group_vars/copr_db_all index e9043c3806..b252b393bd 100644 --- a/inventory/group_vars/copr_db_all +++ b/inventory/group_vars/copr_db_all @@ -1,7 +1,6 @@ --- -tcp_ports: [22, 5432] - -csi_security_category: Low csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide the testing environment of copr's db csi_relationship: This host is the testing environment for copr's database +csi_security_category: Low +tcp_ports: [22, 5432] diff --git a/inventory/group_vars/copr_dev b/inventory/group_vars/copr_dev index f28f76ecfb..8e19a6d1e2 100644 --- a/inventory/group_vars/copr_dev +++ b/inventory/group_vars/copr_dev @@ -1,31 +1,23 @@ --- -devel: true #_forward-src: "{{ files }}/copr/forward-dev" _forward_src: "forward_dev" - +ansible_ifcfg_blocklist: true +backend_base_url: "https://download.copr-dev.fedorainfracloud.org" +builders: + # max|max_spawn|max_prealloc + aws: + aarch64: [5, 2, 2] + armhfp: [3, 1, 1] + x86_64: [20, 5, 5] +copr_aws_region: us-east-1 # don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules # eth0, eth1 copr_backend_ips: ["172.25.33.80", "172.25.144.254"] -keygen_host: "172.25.33.73" - -resolvconf: "resolv.conf/cloud" - -backend_base_url: "https://download.copr-dev.fedorainfracloud.org" -postfix_maincf: "postfix/main.cf/main.cf.copr" - -frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" +devel: true dist_git_base_url: "copr-dist-git-dev.fedorainfracloud.org" - -ansible_ifcfg_blocklist: true - -copr_aws_region: us-east-1 - +frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" +keygen_host: "172.25.33.73" +postfix_maincf: "postfix/main.cf/main.cf.copr" +resolvconf: "resolv.conf/cloud" services_disabled: true - -builders: - # max|max_spawn|max_prealloc - aws: - x86_64: [20,5,5] - armhfp: [3,1,1] - aarch64: [5,2,2] diff --git a/inventory/group_vars/copr_dev_aws b/inventory/group_vars/copr_dev_aws index bb6f717233..0ebd781762 100644 --- a/inventory/group_vars/copr_dev_aws +++ b/inventory/group_vars/copr_dev_aws @@ -1,76 +1,7 @@ --- -devel: true - -copr_messaging: true - -datacenter: aws - _forward_src: "forward_dev" - -# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules - -# eth0, eth1 -copr_backend_ips: ["18.208.10.131", "172.30.2.207"] -keygen_host: "54.225.23.248" - -backend_base_url: "https://download.copr-dev.fedorainfracloud.org" -postfix_group: copr - -frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" -dist_git_base_url: "copr-dist-git-dev.fedorainfracloud.org" - ansible_ifcfg_blocklist: true - -copr_aws_region: us-east-1 - -services_disabled: false -nm_controlled_resolv: True - -builders: - # max|spawn_concurrently|prealloc - aws: - x86_64: [4, 1, 1] - aarch64: [2, 1, 1] - - aws_spot: - x86_64: [5, 2, 2] - aarch64: [5, 2, 1] - - x86_hypervisor_01: - x86_64: [2,1,1] - - x86_hypervisor_02: - x86_64: [2, 1, 1] - - x86_hypervisor_03: - x86_64: [2, 1, 1] - - x86_hypervisor_04: - x86_64: [2, 1, 1] - - ppc64le_hypervisor_01: - ppc64le: [2, 1, 1] - - ppc64le_hypervisor_02: - ppc64le: [2, 1, 1] - -copr_builder_images: - hypervisor: - x86_64: copr-builder-x86_64-20211012_115536 - ppc64le: copr-builder-ppc64le-20211012_120530 - aws: - x86_64: ami-0baeeebc194e64780 - aarch64: ami-068c2760406b9e3c9 - aws_arch_subnets: - x86_64: - - subnet-0995f6a466849f4c3 - - subnet-08cadf5a14b530ac4 - - subnet-07b0b3168a353e3ee - - subnet-09c74a3e6420a206b - - subnet-01d4e967ab5e78005 - - subnet-05437ac82d63b6ef5 - # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1a). # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1d). # Your requested instance type (a1.xlarge) is not supported in your requested Availability Zone (us-east-1f). @@ -78,5 +9,53 @@ aws_arch_subnets: - subnet-0995f6a466849f4c3 - subnet-08cadf5a14b530ac4 - subnet-07b0b3168a353e3ee + x86_64: + - subnet-0995f6a466849f4c3 + - subnet-08cadf5a14b530ac4 + - subnet-07b0b3168a353e3ee + - subnet-09c74a3e6420a206b + - subnet-01d4e967ab5e78005 + - subnet-05437ac82d63b6ef5 +backend_base_url: "https://download.copr-dev.fedorainfracloud.org" +builders: + # max|spawn_concurrently|prealloc + aws: + aarch64: [2, 1, 1] + x86_64: [4, 1, 1] + aws_spot: + aarch64: [5, 2, 1] + x86_64: [5, 2, 2] + ppc64le_hypervisor_01: + ppc64le: [2, 1, 1] + ppc64le_hypervisor_02: + ppc64le: [2, 1, 1] + x86_hypervisor_01: + x86_64: [2, 1, 1] + x86_hypervisor_02: + x86_64: [2, 1, 1] + x86_hypervisor_03: + x86_64: [2, 1, 1] + x86_hypervisor_04: + x86_64: [2, 1, 1] +copr_aws_region: us-east-1 +# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules +# eth0, eth1 +copr_backend_ips: ["18.208.10.131", "172.30.2.207"] +copr_builder_images: + aws: + aarch64: ami-068c2760406b9e3c9 + x86_64: ami-0baeeebc194e64780 + hypervisor: + ppc64le: copr-builder-ppc64le-20211012_120530 + x86_64: copr-builder-x86_64-20211012_115536 +copr_messaging: true +datacenter: aws +devel: true +dist_git_base_url: "copr-dist-git-dev.fedorainfracloud.org" +frontend_base_url: "https://copr-fe-dev.cloud.fedoraproject.org" +keygen_host: "54.225.23.248" +nm_controlled_resolv: True +postfix_group: copr rpm_vendor_copr_name: Fedora Copr (devel) +services_disabled: false diff --git a/inventory/group_vars/copr_dist_git b/inventory/group_vars/copr_dist_git index 29cbfbaab5..c25a51531d 100644 --- a/inventory/group_vars/copr_dist_git +++ b/inventory/group_vars/copr_dist_git @@ -1,14 +1,13 @@ --- -tcp_ports: [22, 80, 443] datacenter: cloud freezes: false - # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: httpd certificates: copr-dist-git.fedorainfracloud.org: - domains: - - copr-dist-git.fedorainfracloud.org challenge_dir: /var/www/html + domains: + - copr-dist-git.fedorainfracloud.org mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_dist_git_aws b/inventory/group_vars/copr_dist_git_aws index 1a46a842b6..1a942e3024 100644 --- a/inventory/group_vars/copr_dist_git_aws +++ b/inventory/group_vars/copr_dist_git_aws @@ -1,14 +1,13 @@ --- -tcp_ports: [22, 80, 443] datacenter: aws freezes: false - # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: httpd certificates: copr-dist-git.fedorainfracloud.org: - domains: - - copr-dist-git.fedorainfracloud.org challenge_dir: /var/www/html + domains: + - copr-dist-git.fedorainfracloud.org mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_dist_git_dev b/inventory/group_vars/copr_dist_git_dev index ae9b3ddcf0..c9416dfd05 100644 --- a/inventory/group_vars/copr_dist_git_dev +++ b/inventory/group_vars/copr_dist_git_dev @@ -1,15 +1,14 @@ --- -tcp_ports: [22, 80, 443] datacenter: cloud -freezes: false devel: true - +freezes: false # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: httpd certificates: copr-dist-git-dev.fedorainfracloud.org: - domains: - - copr-dist-git-dev.fedorainfracloud.org challenge_dir: /var/www/html + domains: + - copr-dist-git-dev.fedorainfracloud.org mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_dist_git_dev_aws b/inventory/group_vars/copr_dist_git_dev_aws index ab60339786..a07a649dcc 100644 --- a/inventory/group_vars/copr_dist_git_dev_aws +++ b/inventory/group_vars/copr_dist_git_dev_aws @@ -1,15 +1,14 @@ --- -tcp_ports: [22, 80, 443] datacenter: aws -freezes: false devel: true - +freezes: false # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: httpd certificates: copr-dist-git-dev.fedorainfracloud.org: - domains: - - copr-dist-git-dev.fedorainfracloud.org challenge_dir: /var/www/html + domains: + - copr-dist-git-dev.fedorainfracloud.org mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_dist_git_stg b/inventory/group_vars/copr_dist_git_stg index 502e4fc16a..48c7552018 100644 --- a/inventory/group_vars/copr_dist_git_stg +++ b/inventory/group_vars/copr_dist_git_stg @@ -1,6 +1,5 @@ --- -resolvconf: "resolv.conf/cloud" - -tcp_ports: [22, 80, 443] datacenter: cloud freezes: false +resolvconf: "resolv.conf/cloud" +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_front_aws b/inventory/group_vars/copr_front_aws index b46a5f0583..5cc334c9c1 100644 --- a/inventory/group_vars/copr_front_aws +++ b/inventory/group_vars/copr_front_aws @@ -1,34 +1,27 @@ --- -tcp_ports: [22, 80, 443] +copr_fe_homedir: /usr/share/copr/coprs_frontend copr_frontend_public_hostname: "copr.fedorainfracloud.org" - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: Moderate +copr_kerberos_auth_enabled: false +copr_messaging_queue: "a9b74258-21c6-4e79-ba65-9e858dc84a2b" +copr_pagure_events: + io.pagure.prod.pagure: "https://pagure.io/" + org.fedoraproject.prod.pagure: "https://src.fedoraproject.org/" csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" csi_purpose: Provide a publicly accessible frontend for 3rd party packages (copr) csi_relationship: | - This host provides the frontend part of copr only. - It's the point of contact between end users and the copr build system (backend, package singer) - +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: Moderate # consumed by roles/copr/certbot letsencrypt: - predefined_deploy_script: httpd certificates: copr.fedorainfracloud.org: - domains: - - copr.fedorainfracloud.org challenge_dir: /var/www/html + domains: + - copr.fedorainfracloud.org mail: copr-devel@lists.fedorahosted.org - -copr_pagure_events: - io.pagure.prod.pagure: "https://pagure.io/" - org.fedoraproject.prod.pagure: "https://src.fedoraproject.org/" - -copr_messaging_queue: "a9b74258-21c6-4e79-ba65-9e858dc84a2b" - -copr_fe_homedir: /usr/share/copr/coprs_frontend - -copr_kerberos_auth_enabled: false + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_front_dev_aws b/inventory/group_vars/copr_front_dev_aws index 77f0ca41c8..a9044c441d 100644 --- a/inventory/group_vars/copr_front_dev_aws +++ b/inventory/group_vars/copr_front_dev_aws @@ -1,37 +1,29 @@ --- -tcp_ports: [22, 80, 443] -copr_frontend_public_hostname: "copr-fe-dev.cloud.fedoraproject.org" - -csi_security_category: Low -csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" -csi_purpose: Provide the testing environment of copr's frontend -csi_relationship: This host is the testing environment for copr's web interface - -copr_mbs_cli_login: Y29wcg==##vtvvikhcjncwkfkdcssv - -# consumed by roles/copr/certbot -letsencrypt: - predefined_deploy_script: httpd - certificates: - copr-fe-dev.cloud.fedoraproject.org: - domains: - - copr-fe-dev.cloud.fedoraproject.org - challenge_dir: /var/www/html - mail: copr-devel@lists.fedorahosted.org - allowlist_emails: - msuchy@redhat.com - praiskup@redhat.com - jkadlcik@redhat.com - schlupov@redhat.com - +copr_fe_homedir: /usr/share/copr/coprs_frontend +copr_frontend_public_hostname: "copr-fe-dev.cloud.fedoraproject.org" +copr_kerberos_auth_enabled: false +copr_mbs_cli_login: Y29wcg==##vtvvikhcjncwkfkdcssv +copr_messaging_queue: "c8e11df7-e863-4ca4-99b9-d37c6663c7f7" copr_pagure_events: io.pagure.prod.pagure: "https://pagure.io/" - org.fedoraproject.prod.pagure: "https://src.fedoraproject.org/" io.pagure.stg.pagure: "https://stg.pagure.io" - -copr_messaging_queue: "c8e11df7-e863-4ca4-99b9-d37c6663c7f7" - -copr_fe_homedir: /usr/share/copr/coprs_frontend - -copr_kerberos_auth_enabled: false + org.fedoraproject.prod.pagure: "https://src.fedoraproject.org/" +csi_primary_contact: "msuchy (mirek), frostyx, praiskup IRC #fedora-admin, #fedora-buildsys" +csi_purpose: Provide the testing environment of copr's frontend +csi_relationship: This host is the testing environment for copr's web interface +csi_security_category: Low +# consumed by roles/copr/certbot +letsencrypt: + certificates: + copr-fe-dev.cloud.fedoraproject.org: + challenge_dir: /var/www/html + domains: + - copr-fe-dev.cloud.fedoraproject.org + mail: copr-devel@lists.fedorahosted.org + predefined_deploy_script: httpd +tcp_ports: [22, 80, 443] diff --git a/inventory/group_vars/copr_hypervisor b/inventory/group_vars/copr_hypervisor index 320bd156c4..6c5168e93a 100644 --- a/inventory/group_vars/copr_hypervisor +++ b/inventory/group_vars/copr_hypervisor @@ -1,33 +1,26 @@ --- -virthost: true - -vpn: true -primary_auth_source: ipa -ipa_host_group: vmhost-copr -ipa_host_group_desc: VM hosts for COPR -ipa_client_shell_groups: -- sysadmin-copr -ipa_client_sudo_groups: -- sysadmin-copr - -nrpe_procs_warn: 1400 -nrpe_procs_crit: 1500 - -postfix_group: copr -postfix_maincf: "postfix/main.cf/main.cf.copr" - -freezes: false - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Host guest virtual machines. csi_relationship: | - - Guests on this host will be inaccessible if the host is down. - - This host will be required by any application with a virtual machine running on it, therefore, if this host is down those applications will be impacted. - + - Guests on this host will be inaccessible if the host is down. + - This host will be required by any application with a virtual machine running on it, therefore, if this host is down those applications will be impacted. +csi_security_category: High +dist_git_base_url: https://example.com/unset +freezes: false +frontend_base_url: https://exmaple.com/unset +ipa_client_shell_groups: + - sysadmin-copr +ipa_client_sudo_groups: + - sysadmin-copr +ipa_host_group: vmhost-copr +ipa_host_group_desc: VM hosts for COPR nagios_Check_Services: raid: true - +nrpe_procs_crit: 1500 +nrpe_procs_warn: 1400 +postfix_group: copr +postfix_maincf: "postfix/main.cf/main.cf.copr" +primary_auth_source: ipa rpm_vendor_copr_name: unset vendor -frontend_base_url: https://exmaple.com/unset -dist_git_base_url: https://example.com/unset +virthost: true +vpn: true diff --git a/inventory/group_vars/copr_keygen b/inventory/group_vars/copr_keygen index 514c8cc333..8ce40f1a64 100644 --- a/inventory/group_vars/copr_keygen +++ b/inventory/group_vars/copr_keygen @@ -1,12 +1,6 @@ --- -tcp_ports: [22] - # http + signd dest ports -custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.33.79 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.82.25 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.33.79 --dport 5167 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.82.25 --dport 5167 -j ACCEPT'] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 172.25.33.79 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.82.25 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.33.79 --dport 5167 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.82.25 --dport 5167 -j ACCEPT'] datacenter: cloud - freezes: false +tcp_ports: [22] diff --git a/inventory/group_vars/copr_keygen_aws b/inventory/group_vars/copr_keygen_aws index 58dc2400c1..bf1b60c3e6 100644 --- a/inventory/group_vars/copr_keygen_aws +++ b/inventory/group_vars/copr_keygen_aws @@ -1,14 +1,7 @@ --- copr_hostbase: copr-keygen - -tcp_ports: [22] - # http + signd dest ports -custom_rules: [ '-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 5167 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.30.2.203 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.30.2.203 --dport 5167 -j ACCEPT'] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 5167 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.30.2.203 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.30.2.203 --dport 5167 -j ACCEPT'] datacenter: aws - freezes: false +tcp_ports: [22] diff --git a/inventory/group_vars/copr_keygen_dev b/inventory/group_vars/copr_keygen_dev index 69cd97d5d7..19c4de0777 100644 --- a/inventory/group_vars/copr_keygen_dev +++ b/inventory/group_vars/copr_keygen_dev @@ -1,13 +1,7 @@ --- copr_hostbase: copr-keygen-dev -tcp_ports: [] - # http + signd dest ports -custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.33.80 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.33.80 --dport 5167 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.144.254 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.144.254 --dport 5167 -j ACCEPT'] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 172.25.33.80 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.33.80 --dport 5167 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.144.254 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.144.254 --dport 5167 -j ACCEPT'] datacenter: cloud - freezes: false +tcp_ports: [] diff --git a/inventory/group_vars/copr_keygen_dev_aws b/inventory/group_vars/copr_keygen_dev_aws index 4600279980..3955433314 100644 --- a/inventory/group_vars/copr_keygen_dev_aws +++ b/inventory/group_vars/copr_keygen_dev_aws @@ -1,14 +1,7 @@ --- copr_hostbase: copr-keygen-dev - -tcp_ports: [22] - # http + signd dest ports -custom_rules: [ '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 5167 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.30.2.207 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.30.2.207 --dport 5167 -j ACCEPT'] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 5167 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.30.2.207 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.30.2.207 --dport 5167 -j ACCEPT'] datacenter: aws - freezes: false +tcp_ports: [22] diff --git a/inventory/group_vars/copr_keygen_stg b/inventory/group_vars/copr_keygen_stg index f597352049..df6838f5d1 100644 --- a/inventory/group_vars/copr_keygen_stg +++ b/inventory/group_vars/copr_keygen_stg @@ -1,15 +1,8 @@ --- -resolvconf: "resolv.conf/cloud" - copr_hostbase: copr-keygen-stg -tcp_ports: [] - # http + signd dest ports -custom_rules: ['-A INPUT -p tcp -m tcp -s 172.25.33.49 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 209.132.184.44 --dport 80 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 172.25.33.49 --dport 5167 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 209.132.184.44 --dport 5167 -j ACCEPT'] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 172.25.33.49 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.184.44 --dport 80 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 172.25.33.49 --dport 5167 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.184.44 --dport 5167 -j ACCEPT'] datacenter: cloud - freezes: false +resolvconf: "resolv.conf/cloud" +tcp_ports: [] diff --git a/inventory/group_vars/copr_stg b/inventory/group_vars/copr_stg index bbe08821ea..79d3b662de 100644 --- a/inventory/group_vars/copr_stg +++ b/inventory/group_vars/copr_stg @@ -1,15 +1,11 @@ --- -devel: false #_forward-src: "{{ files }}/copr/forward-dev" _forward_src: "forward_dev" - -# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules - -copr_backend_ips: ["172.25.33.49", "209.132.184.44"] -keygen_host: "172.25.33.51" - -backend_base_url: "https://copr-be-stg.fedorainfracloud.org" -frontend_base_url: "https://copr.stg.fedoraproject.org" -dist_git_base_url: "copr-dist-git-stg.fedorainfracloud.org" - ansible_ifcfg_blocklist: true +backend_base_url: "https://copr-be-stg.fedorainfracloud.org" +# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules +copr_backend_ips: ["172.25.33.49", "209.132.184.44"] +devel: false +dist_git_base_url: "copr-dist-git-stg.fedorainfracloud.org" +frontend_base_url: "https://copr.stg.fedoraproject.org" +keygen_host: "172.25.33.51" diff --git a/inventory/group_vars/datagrepper b/inventory/group_vars/datagrepper index 85dc75ed7e..2a37e4c864 100644 --- a/inventory/group_vars/datagrepper +++ b/inventory/group_vars/datagrepper @@ -1,30 +1,22 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +deployment_type: prod +freezes: false +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer +ipa_host_group: datagrepper +ipa_host_group_desc: Service to grep through historical message bus data lvm_size: 20000 mem_size: 8192 num_cpus: 2 - +primary_auth_source: ipa # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 80, 443, 6996 ] -# Neeed for rsync from log01 for logs. -custom_rules: [ - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', -] - -primary_auth_source: ipa -ipa_host_group: datagrepper -ipa_host_group_desc: Service to grep through historical message bus data -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer - -freezes: false - -deployment_type: prod +tcp_ports: [80, 443, 6996] diff --git a/inventory/group_vars/datagrepper_stg b/inventory/group_vars/datagrepper_stg index 5329358b58..cc29c5a697 100644 --- a/inventory/group_vars/datagrepper_stg +++ b/inventory/group_vars/datagrepper_stg @@ -1,24 +1,20 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +freezes: false +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer +ipa_host_group: datagrepper +ipa_host_group_desc: Service to grep through historical message bus data lvm_size: 20000 mem_size: 2048 num_cpus: 1 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 80, 443, 6996 ] -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: datagrepper -ipa_host_group_desc: Service to grep through historical message bus data -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer - -freezes: false +tcp_ports: [80, 443, 6996] diff --git a/inventory/group_vars/dbserver b/inventory/group_vars/dbserver index 64c90a0811..42769283c2 100644 --- a/inventory/group_vars/dbserver +++ b/inventory/group_vars/dbserver @@ -1,9 +1,9 @@ --- +ipa_client_shell_groups: + - sysadmin-dba + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-dba ipa_host_group: dbserver ipa_host_group_desc: Database server hosts -ipa_client_shell_groups: -- sysadmin-dba -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-dba diff --git a/inventory/group_vars/dbserver_stg b/inventory/group_vars/dbserver_stg index 64c90a0811..42769283c2 100644 --- a/inventory/group_vars/dbserver_stg +++ b/inventory/group_vars/dbserver_stg @@ -1,9 +1,9 @@ --- +ipa_client_shell_groups: + - sysadmin-dba + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-dba ipa_host_group: dbserver ipa_host_group_desc: Database server hosts -ipa_client_shell_groups: -- sysadmin-dba -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-dba diff --git a/inventory/group_vars/debuginfod b/inventory/group_vars/debuginfod index 4b1fe41f84..7ad8354367 100644 --- a/inventory/group_vars/debuginfod +++ b/inventory/group_vars/debuginfod @@ -1,28 +1,23 @@ --- # Define resources for this group of hosts here. -lvm_size: 500000 -mem_size: 8192 -max_mem_size: 16384 -num_cpus: 4 - +csi_primary_contact: "#fedora-admin" +csi_purpose: Provides debuginfod services +csi_relationship: | + - This server provides a debuginfod server to allow downloading debuginfod +csi_security_category: Low deployment_type: prod - -tcp_ports: [ 8002 ] - -primary_auth_source: ipa +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-debuginfod +ipa_client_sudo_groups: + - sysadmin-debuginfod ipa_host_group: debuginfod ipa_host_group_desc: debuginfod servers -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-debuginfod -ipa_client_sudo_groups: -- sysadmin-debuginfod - -csi_security_category: Low -csi_primary_contact: "#fedora-admin" -csi_purpose: Provides debuginfod services -csi_relationship: | - - This server provides a debuginfod server to allow downloading debuginfod - +lvm_size: 500000 +max_mem_size: 16384 +mem_size: 8192 +num_cpus: 4 +primary_auth_source: ipa +tcp_ports: [8002] diff --git a/inventory/group_vars/debuginfod_stg b/inventory/group_vars/debuginfod_stg index dbf4d51f26..dfaf19ef53 100644 --- a/inventory/group_vars/debuginfod_stg +++ b/inventory/group_vars/debuginfod_stg @@ -1,28 +1,23 @@ --- # Define resources for this group of hosts here. -lvm_size: 500000 -mem_size: 8192 -max_mem_size: 16384 -num_cpus: 4 - +csi_primary_contact: "#fedora-admin" +csi_purpose: Provides debuginfod services +csi_relationship: | + - This server provides a debuginfod server to allow downloading debuginfod +csi_security_category: Low deployment_type: stg - -tcp_ports: [ 8002 ] - -primary_auth_source: ipa +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-debuginfod +ipa_client_sudo_groups: + - sysadmin-debuginfod ipa_host_group: debuginfod ipa_host_group_desc: debuginfod servers -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-debuginfod -ipa_client_sudo_groups: -- sysadmin-debuginfod - -csi_security_category: Low -csi_primary_contact: "#fedora-admin" -csi_purpose: Provides debuginfod services -csi_relationship: | - - This server provides a debuginfod server to allow downloading debuginfod - +lvm_size: 500000 +max_mem_size: 16384 +mem_size: 8192 +num_cpus: 4 +primary_auth_source: ipa +tcp_ports: [8002] diff --git a/inventory/group_vars/dell_fx_build b/inventory/group_vars/dell_fx_build index 630e6beb14..5b344629d3 100644 --- a/inventory/group_vars/dell_fx_build +++ b/inventory/group_vars/dell_fx_build @@ -1,16 +1,14 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -virthost: true - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should ovveride them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Koji service employs a set of virtual machines to build packages for the Fedora project. This playbook is for the provisioning of a physical host for buildvm's. csi_relationship: | - * Relies on ansible, virthost, and is monitored by nagios - * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. - * Builder vm's are hosted on hosts created with this playbook. + * Relies on ansible, virthost, and is monitored by nagios + * Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver. + * Builder vm's are hosted on hosts created with this playbook. +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should ovveride them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virthost: true diff --git a/inventory/group_vars/dns b/inventory/group_vars/dns index 99436e9a6d..ce370c0ade 100644 --- a/inventory/group_vars/dns +++ b/inventory/group_vars/dns @@ -1,30 +1,23 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 2048 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -udp_ports: [ 53 ] -tcp_ports: [ 53 ] - -primary_auth_source: ipa -ipa_host_group: dns -ipa_host_group_desc: DNS servers -ipa_client_shell_groups: -- sysadmin-dns -ipa_client_sudo_groups: -- sysadmin-dns - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - -sudoers: "{{ private }}/files/sudo/sysadmin-dns" - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Domain Name Service - +csi_security_category: High +ipa_client_shell_groups: + - sysadmin-dns +ipa_client_sudo_groups: + - sysadmin-dns +ipa_host_group: dns +ipa_host_group_desc: DNS servers +lvm_size: 30000 +mem_size: 2048 nagios_has_named: true +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 2 +primary_auth_source: ipa +sudoers: "{{ private }}/files/sudo/sysadmin-dns" +tcp_ports: [53] +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +udp_ports: [53] diff --git a/inventory/group_vars/download b/inventory/group_vars/download index 499f74c872..9e9bf3fef7 100644 --- a/inventory/group_vars/download +++ b/inventory/group_vars/download @@ -1,98 +1,96 @@ --- -primary_auth_source: ipa +dl_tier1: + - 10.0.0.0/8 # Red Hat Internal + - 128.171.104.148 # mirror.ancl.hawaii.edu. + - 129.101.198.59 # University of Idaho + - 129.21.171.98 # kirby.main.ad.rit.edu. + - 129.7.128.189 # pubmirror1.math.uh.edu. + - 129.7.128.190 # pubmirror2.math.uh.edu. + - 129.7.128.191 # pubmirror3.math.uh.edu. + - 130.225.254.116 # dotsrc.org + - 130.239.17.3 # its-ehm.its.umu.se. + - 137.138.120.188 # cern + - 137.138.148.168 # cern + - 137.138.44.122 # cern + - 140.247.173.57 # pool-computing-servers.seas.harvard.edu. + - 147.75.101.1 # ams.edge.kernel.org + - 147.75.197.195 # ewr.edge.kernel.org + - 147.75.69.165 # sjc.edge.kernel.org + - 147.75.95.133 # kernel.org apac + - 149.11.118.8/29 # Red Hat CZ + - 152.19.134.145 # vm6.fedora.ibiblio.org. + - 152.19.134.195 # vm15.fedora.ibiblio.org. + - 154.45.192.0/29 # Red Hat CZ New + - 166.78.229.128 # rackspace new infra + - 182.255.111.7 # dksn-k4.cdn.aarnet.edu.au. + - 188.184.104.133 # cern + - 188.184.116.38 # cern + - 195.220.108.108 # mandril.creatis.insa-lyon.fr. + - 198.129.224.34 # linux-src.es.net. + - 199.6.1.170 # isc.org + - 200.17.202.1/28 # ufpr.br + - 202.158.214.12 # bne-a-vms1.retain.aarnet.edu.au. + - 204.152.191.36 # isc.org + - 208.96.144.68 # University of Southern Indiana + - 208.96.144.90 # University of Southern Indiana + - 208.89.87.36 # Mirror.dst.ca + - 213.175.37.8/29 # ?? + - 66.187.233.206 # Red Hat BOS + - 71.19.151.18 # prgmr.com / nb.zone + - 72.4.120.222 # rackspace old infra + - 91.209.10.253 # Red Hat CZ New Newer + - 125.16.200.50 # Red Hat PNQ + - 2001:388:1:4066:225:90ff:fec7:777e # ?? + - 2001:4DE8:C0FD::/48 # ?? + - 2001:878:346::116 # dotsrc.org + - 2001:978:2:81::1:0/112 # ?? + - 2604:1380:3000:1500::1 # kernel.org apac + - 2620:52:3:1:dead:beef:cafe:fed1 # download-cc-rdu01's ipv6 address + - archive.linux.duke.edu # 152.3.102.53 + - 152.3.68.159 # new archive.linux.duke.edu + - auslistsdr01.us.dell.com # 143.166.224.62 + - auslistsprd01.us.dell.com # 143.166.82.43 + - download-ib01.fedoraproject.org # 152.19.134.145 + - download-cc-rdu01.fedoraproject.org # 8.43.85.72 + - fedora.c3sl.ufpr.br # 200.236.31.8 + - frisal.switch.ch # 130.59.113.36 + - ftp.heanet.ie # 193.1.193.64 + - ftp.linux.cz # 147.251.48.205 + - 2001:718:801:230::cd # ftp.linux.cz ipv6 address + - ftp.nrc.ca # 132.246.2.21 + - jobbot1.ibiblio.org # 152.19.134.30 + - elba.hrz.tu-chemnitz.de # 134.109.228.48 / 2001:638:911:b0e:134:109:228:48 + - waterloo.hrz.tu-chemnitz.de # 134.109.228.1 / 2001:638:911:b0e:134:109:228:1 + - lists.us.dell.com # 143.166.82.43 + - mirror.gtlib.gatech.edu # 128.61.111.11 + - mirror.hiwaay.net # 216.180.99.217 + - mirror.liquidtelecom.com # 197.155.77.1 + - mirror.prgmr.com # 71.19.148.193 + - mirror.speedpartner.de # 91.184.32.5 + - mirrors.mit.edu # 18.7.29.125 + - mirrors.pdx.kernel.org # 198.145.21.9 / 2001:19d0:306:6:0:1994:3:14 + - mirrors.rit.edu # 129.21.171.72 + - mirrors.sfo.kernel.org # 149.20.37.36 / 2001:4f8:4:6f:0:1994:3:14 + - mirrors.xmission.com # 198.60.22.13 + - nrt.edge.kernel.org # 147.75.95.133 / 2604:1380:3000:1500::1 + - odysseus.fi.muni.cz # 147.251.48.205 + - odysseus.linux.cz # 147.251.48.205 + - rhlx01.hs-esslingen.de # 129.143.116.10 + - rsyncer.ftp.heanet.ie # 193.1.219.88 + - sagres.c3sl.ufpr.br # 200.236.31.1 + - scrye.com # 75.148.32.185 + - sfo-korg-mirror.kernel.org # 149.20.37.36 / 2001:4f8:4:6f:0:1994:3:14 + - sinclair.wpi.edu # 130.215.32.86 + - mirr-web-p-u01.wpi.edu # 130.215.32.92 / 2607:f5c0:8040:a081::80 + - solar-one.mit.edu # 18.7.29.123 + - speculum.rbc.ru # 80.68.250.217 + - torrent01.fedoraproject.org # 152.19.134.141 + - torrent02.fedoraproject.org # 152.19.134.148 + - ultra.linux.cz # 195.113.15.27 + - wpi.edu # 130.215.36.26 + - zaphod.gtlib.gatech.edu # 128.61.111.12 ipa_host_group: download ipa_host_group_desc: Download servers - nagios_Check_Services: swap: false - -dl_tier1: - - 10.0.0.0/8 # Red Hat Internal - - 128.171.104.148 # mirror.ancl.hawaii.edu. - - 129.101.198.59 # University of Idaho - - 129.21.171.98 # kirby.main.ad.rit.edu. - - 129.7.128.189 # pubmirror1.math.uh.edu. - - 129.7.128.190 # pubmirror2.math.uh.edu. - - 129.7.128.191 # pubmirror3.math.uh.edu. - - 130.225.254.116 # dotsrc.org - - 130.239.17.3 # its-ehm.its.umu.se. - - 137.138.120.188 # cern - - 137.138.148.168 # cern - - 137.138.44.122 # cern - - 140.247.173.57 # pool-computing-servers.seas.harvard.edu. - - 147.75.101.1 # ams.edge.kernel.org - - 147.75.197.195 # ewr.edge.kernel.org - - 147.75.69.165 # sjc.edge.kernel.org - - 147.75.95.133 # kernel.org apac - - 149.11.118.8/29 # Red Hat CZ - - 152.19.134.145 # vm6.fedora.ibiblio.org. - - 152.19.134.195 # vm15.fedora.ibiblio.org. - - 154.45.192.0/29 # Red Hat CZ New - - 166.78.229.128 # rackspace new infra - - 182.255.111.7 # dksn-k4.cdn.aarnet.edu.au. - - 188.184.104.133 # cern - - 188.184.116.38 # cern - - 195.220.108.108 # mandril.creatis.insa-lyon.fr. - - 198.129.224.34 # linux-src.es.net. - - 199.6.1.170 # isc.org - - 200.17.202.1/28 # ufpr.br - - 202.158.214.12 # bne-a-vms1.retain.aarnet.edu.au. - - 204.152.191.36 # isc.org - - 208.96.144.68 # University of Southern Indiana - - 208.96.144.90 # University of Southern Indiana - - 208.89.87.36 # Mirror.dst.ca - - 213.175.37.8/29 # ?? - - 66.187.233.206 # Red Hat BOS - - 71.19.151.18 # prgmr.com / nb.zone - - 72.4.120.222 # rackspace old infra - - 91.209.10.253 # Red Hat CZ New Newer - - 125.16.200.50 # Red Hat PNQ - - 2001:388:1:4066:225:90ff:fec7:777e # ?? - - 2001:4DE8:C0FD::/48 # ?? - - 2001:878:346::116 # dotsrc.org - - 2001:978:2:81::1:0/112 # ?? - - 2604:1380:3000:1500::1 # kernel.org apac - - 2620:52:3:1:dead:beef:cafe:fed1 # download-cc-rdu01's ipv6 address - - archive.linux.duke.edu # 152.3.102.53 - - 152.3.68.159 # new archive.linux.duke.edu - - auslistsdr01.us.dell.com # 143.166.224.62 - - auslistsprd01.us.dell.com # 143.166.82.43 - - download-ib01.fedoraproject.org # 152.19.134.145 - - download-cc-rdu01.fedoraproject.org # 8.43.85.72 - - fedora.c3sl.ufpr.br # 200.236.31.8 - - frisal.switch.ch # 130.59.113.36 - - ftp.heanet.ie # 193.1.193.64 - - ftp.linux.cz # 147.251.48.205 - - 2001:718:801:230::cd # ftp.linux.cz ipv6 address - - ftp.nrc.ca # 132.246.2.21 - - jobbot1.ibiblio.org # 152.19.134.30 - - elba.hrz.tu-chemnitz.de # 134.109.228.48 / 2001:638:911:b0e:134:109:228:48 - - waterloo.hrz.tu-chemnitz.de # 134.109.228.1 / 2001:638:911:b0e:134:109:228:1 - - lists.us.dell.com # 143.166.82.43 - - mirror.gtlib.gatech.edu # 128.61.111.11 - - mirror.hiwaay.net # 216.180.99.217 - - mirror.liquidtelecom.com # 197.155.77.1 - - mirror.prgmr.com # 71.19.148.193 - - mirror.speedpartner.de # 91.184.32.5 - - mirrors.mit.edu # 18.7.29.125 - - mirrors.pdx.kernel.org # 198.145.21.9 / 2001:19d0:306:6:0:1994:3:14 - - mirrors.rit.edu # 129.21.171.72 - - mirrors.sfo.kernel.org # 149.20.37.36 / 2001:4f8:4:6f:0:1994:3:14 - - mirrors.xmission.com # 198.60.22.13 - - nrt.edge.kernel.org # 147.75.95.133 / 2604:1380:3000:1500::1 - - odysseus.fi.muni.cz # 147.251.48.205 - - odysseus.linux.cz # 147.251.48.205 - - rhlx01.hs-esslingen.de # 129.143.116.10 - - rsyncer.ftp.heanet.ie # 193.1.219.88 - - sagres.c3sl.ufpr.br # 200.236.31.1 - - scrye.com # 75.148.32.185 - - sfo-korg-mirror.kernel.org # 149.20.37.36 / 2001:4f8:4:6f:0:1994:3:14 - - sinclair.wpi.edu # 130.215.32.86 - - mirr-web-p-u01.wpi.edu # 130.215.32.92 / 2607:f5c0:8040:a081::80 - - solar-one.mit.edu # 18.7.29.123 - - speculum.rbc.ru # 80.68.250.217 - - torrent01.fedoraproject.org # 152.19.134.141 - - torrent02.fedoraproject.org # 152.19.134.148 - - ultra.linux.cz # 195.113.15.27 - - wpi.edu # 130.215.36.26 - - zaphod.gtlib.gatech.edu # 128.61.111.12 +primary_auth_source: ipa diff --git a/inventory/group_vars/download_iad2 b/inventory/group_vars/download_iad2 index 0a90dc3420..74306d49a9 100644 --- a/inventory/group_vars/download_iad2 +++ b/inventory/group_vars/download_iad2 @@ -1,14 +1,11 @@ --- +blocked_ips: [] datacenter: iad2 -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 dns: 10.3.163.33 - host_group: download-iad2 - # nfs mount options, overrides the all/default nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=3" - -blocked_ips: [ ] +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +tcp_ports: [80, 443, 873] diff --git a/inventory/group_vars/download_ib b/inventory/group_vars/download_ib index 5e4b8d1ffb..8a4e911480 100644 --- a/inventory/group_vars/download_ib +++ b/inventory/group_vars/download_ib @@ -1,7 +1,6 @@ --- datacenter: ibiblio -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" -nrpe_procs_warn: 900 nrpe_procs_crit: 1000 - +nrpe_procs_warn: 900 +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +tcp_ports: [80, 443, 873] diff --git a/inventory/group_vars/download_rdu2 b/inventory/group_vars/download_rdu2 index 3202e39d6c..5a5ab06243 100644 --- a/inventory/group_vars/download_rdu2 +++ b/inventory/group_vars/download_rdu2 @@ -1,11 +1,10 @@ --- -datacenter: rdu -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -virt_install_command: "{{ virt_install_command_rhel6 }}" ansible_ifcfg_blocklist: true - +datacenter: rdu # nfs mount options, overrides the all/default nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=3" +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_rhel6 }}" diff --git a/inventory/group_vars/fedimg b/inventory/group_vars/fedimg index 0bb325e3e1..2501a59cb9 100644 --- a/inventory/group_vars/fedimg +++ b/inventory/group_vars/fedimg @@ -1,42 +1,34 @@ --- +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedimg.image.test + - fedimg.image.upload + - fedimg.image.copy + - fedimg.image.publish + group: fedmsg + owner: root + service: fedimg +# These people get told when something goes wrong. +fedmsg_error_recipients: + - sysadmin-fedimg-members@fedoraproject.org +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: fedimg lvm_size: 20000 mem_size: 6144 num_cpus: 2 - -testing: False - +primary_auth_source: ipa # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - tcp_ports: [ - # These are all for outgoing fedmsg. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, - 3007, 3008, 3009, 3010, 3011, 3012, 3013, -] - -primary_auth_source: ipa -ipa_host_group: fedimg -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- sysadmin-fedimg-members@fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fedimg - owner: root - group: fedmsg - can_send: - - fedimg.image.test - - fedimg.image.upload - - fedimg.image.copy - - fedimg.image.publish + # These are all for outgoing fedmsg. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013] +testing: False diff --git a/inventory/group_vars/fedimg_stg b/inventory/group_vars/fedimg_stg index c093a16fd8..70c007ffbb 100644 --- a/inventory/group_vars/fedimg_stg +++ b/inventory/group_vars/fedimg_stg @@ -1,44 +1,35 @@ --- +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fedimg.image.test + - fedimg.image.upload + - fedimg.image.copy + - fedimg.image.publish + group: fedmsg + owner: root + service: fedimg +fedmsg_debug_loopback: True +# These people get told when something goes wrong. +fedmsg_error_recipients: + - sysadmin-fedimg-members@fedoraproject.org +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: fedimg lvm_size: 20000 mem_size: 6144 num_cpus: 2 - -# Use infrastructure-tags-stg repo -testing: True - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - tcp_ports: [ - # These are all for outgoing fedmsg. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, - 3007, 3008, 3009, 3010, 3011, 3012, 3013, -] - -ipa_host_group: fedimg -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -fedmsg_debug_loopback: True - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- sysadmin-fedimg-members@fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fedimg - owner: root - group: fedmsg - can_send: - - fedimg.image.test - - fedimg.image.upload - - fedimg.image.copy - - fedimg.image.publish + # These are all for outgoing fedmsg. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013] +# Use infrastructure-tags-stg repo +testing: True diff --git a/inventory/group_vars/fedora_nightlies b/inventory/group_vars/fedora_nightlies index ad3592a777..6765235575 100644 --- a/inventory/group_vars/fedora_nightlies +++ b/inventory/group_vars/fedora_nightlies @@ -1,17 +1,15 @@ # we need this for our fedora-messaging consumer as it is not allowed # to create queues on the infra AMQP broker, by broker config -fedora_nightlies_amqp_passive: true - -# fedora-messaging job scheduler settings -fedora_nightlies_amqp_url: "amqps://openqa:@rabbitmq.fedoraproject.org/%2Fpubsub" fedora_nightlies_amqp_cacert: /etc/fedora-messaging/cacert.pem -fedora_nightlies_amqp_key: /etc/pki/fedora-messaging/openqa-key.pem fedora_nightlies_amqp_cert: /etc/pki/fedora-messaging/openqa-cert.pem -fedora_nightlies_amqp_queue: "openqa_fedora_nightlies" -fedora_nightlies_amqp_routing_keys: ["org.fedoraproject.prod.openqa.job.done", "org.fedoraproject.prod.pungi.compose.status.change"] -fedora_nightlies_amqp_html_file: /usr/share/openqa/public/nightlies.html fedora_nightlies_amqp_data_file: /usr/share/openqa/public/nightlies.json - +fedora_nightlies_amqp_html_file: /usr/share/openqa/public/nightlies.html +fedora_nightlies_amqp_key: /etc/pki/fedora-messaging/openqa-key.pem # fedora-messaging email error reporting settings fedora_nightlies_amqp_mailto: ["adamwill@fedoraproject.org"] +fedora_nightlies_amqp_passive: true +fedora_nightlies_amqp_queue: "openqa_fedora_nightlies" +fedora_nightlies_amqp_routing_keys: ["org.fedoraproject.prod.openqa.job.done", "org.fedoraproject.prod.pungi.compose.status.change"] fedora_nightlies_amqp_smtp: bastion +# fedora-messaging job scheduler settings +fedora_nightlies_amqp_url: "amqps://openqa:@rabbitmq.fedoraproject.org/%2Fpubsub" diff --git a/inventory/group_vars/github2fedmsg b/inventory/group_vars/github2fedmsg index 2078a906f3..232ce1bc0e 100644 --- a/inventory/group_vars/github2fedmsg +++ b/inventory/group_vars/github2fedmsg @@ -1,9 +1,66 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - github.commit_comment + - github.create + - github.delete + - github.fork + - github.gollum + - github.issue.assigned + - github.issue.closed + - github.issue.comment + - github.issue.edited + - github.issue.labeled + - github.issue.milestone + - github.issue.opened + - github.issue.reopened + - github.issue.unassigned + - github.issue.unlabeled + - github.label + - github.member + - github.page_build + - github.pull_request.assigned + - github.pull_request.closed + - github.pull_request.edited + - github.pull_request.labeled + - github.pull_request.opened + - github.pull_request_review + - github.pull_request_review_comment + - github.pull_request.review_requested + - github.pull_request.synchronize + - github.pull_request.unlabeled + - github.push + - github.release + - github.repository_vulnerability_alert + - github.star + - github.status + - github.team_add + - github.webhook + group: apache + owner: root + service: github2fedmsg +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran +ipa_host_group: github2fedmsg +ipa_host_group_desc: Bridge select GitHub repo events into bus messages lvm_size: 20000 mem_size: 2048 num_cpus: 2 - +primary_auth_source: ipa +tcp_ports: [80] +# for fedora-messaging +username: "github2fedmsg{{ env_suffix }}" # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -11,66 +68,3 @@ num_cpus: 2 wsgi_fedmsg_service: github2fedmsg wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: github2fedmsg -ipa_host_group_desc: Bridge select GitHub repo events into bus messages -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran - -# for fedora-messaging -username: "github2fedmsg{{ env_suffix }}" -deployment_type: prod - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: github2fedmsg - owner: root - group: apache - can_send: - - github.commit_comment - - github.create - - github.delete - - github.fork - - github.gollum - - github.issue.assigned - - github.issue.closed - - github.issue.comment - - github.issue.edited - - github.issue.labeled - - github.issue.milestone - - github.issue.opened - - github.issue.reopened - - github.issue.unassigned - - github.issue.unlabeled - - github.label - - github.member - - github.page_build - - github.pull_request.assigned - - github.pull_request.closed - - github.pull_request.edited - - github.pull_request.labeled - - github.pull_request.opened - - github.pull_request_review - - github.pull_request_review_comment - - github.pull_request.review_requested - - github.pull_request.synchronize - - github.pull_request.unlabeled - - github.push - - github.release - - github.repository_vulnerability_alert - - github.star - - github.status - - github.team_add - - github.webhook diff --git a/inventory/group_vars/github2fedmsg_stg b/inventory/group_vars/github2fedmsg_stg index 76ec796b90..641f8d3896 100644 --- a/inventory/group_vars/github2fedmsg_stg +++ b/inventory/group_vars/github2fedmsg_stg @@ -1,9 +1,65 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +deployment_type: stg +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - github.commit_comment + - github.create + - github.delete + - github.fork + - github.gollum + - github.issue.assigned + - github.issue.closed + - github.issue.comment + - github.issue.edited + - github.issue.labeled + - github.issue.milestone + - github.issue.opened + - github.issue.reopened + - github.issue.unassigned + - github.issue.unlabeled + - github.label + - github.member + - github.page_build + - github.pull_request.assigned + - github.pull_request.closed + - github.pull_request.edited + - github.pull_request.labeled + - github.pull_request.opened + - github.pull_request_review + - github.pull_request_review_comment + - github.pull_request.review_requested + - github.pull_request.synchronize + - github.pull_request.unlabeled + - github.push + - github.release + - github.repository_vulnerability_alert + - github.star + - github.status + - github.team_add + - github.webhook + group: apache + owner: root + service: github2fedmsg +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran +ipa_host_group: github2fedmsg +ipa_host_group_desc: Bridge select GitHub repo events into bus messages lvm_size: 20000 mem_size: 4096 num_cpus: 1 - +tcp_ports: [80] +# for fedora-messaging +username: "github2fedmsg{{ env_suffix }}" # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -11,65 +67,3 @@ num_cpus: 1 wsgi_fedmsg_service: github2fedmsg wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: github2fedmsg -ipa_host_group_desc: Bridge select GitHub repo events into bus messages -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran - -# for fedora-messaging -username: "github2fedmsg{{ env_suffix }}" -deployment_type: stg - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: github2fedmsg - owner: root - group: apache - can_send: - - github.commit_comment - - github.create - - github.delete - - github.fork - - github.gollum - - github.issue.assigned - - github.issue.closed - - github.issue.comment - - github.issue.edited - - github.issue.labeled - - github.issue.milestone - - github.issue.opened - - github.issue.reopened - - github.issue.unassigned - - github.issue.unlabeled - - github.label - - github.member - - github.page_build - - github.pull_request.assigned - - github.pull_request.closed - - github.pull_request.edited - - github.pull_request.labeled - - github.pull_request.opened - - github.pull_request_review - - github.pull_request_review_comment - - github.pull_request.review_requested - - github.pull_request.synchronize - - github.pull_request.unlabeled - - github.push - - github.release - - github.repository_vulnerability_alert - - github.star - - github.status - - github.team_add - - github.webhook diff --git a/inventory/group_vars/gnome_backups b/inventory/group_vars/gnome_backups index c4e6233ac2..2db8f325be 100644 --- a/inventory/group_vars/gnome_backups +++ b/inventory/group_vars/gnome_backups @@ -1,7 +1,7 @@ -freezes: False csi_purpose: GNOME Infrastructure Backups facility csi_relationship: | - Provides rdiff-backup based backups to all the GNOME Infrastructure - machines and services - - This machine mainly relies on the Red Hat sponsored NetApp assigned - to the GNOME Project where all the backups do reside + Provides rdiff-backup based backups to all the GNOME Infrastructure + machines and services + - This machine mainly relies on the Red Hat sponsored NetApp assigned + to the GNOME Project where all the backups do reside +freezes: False diff --git a/inventory/group_vars/greenwave b/inventory/group_vars/greenwave index 8cffbe6cc8..23865f1fd0 100644 --- a/inventory/group_vars/greenwave +++ b/inventory/group_vars/greenwave @@ -2,9 +2,8 @@ # XXX - this is not really a group of real hosts. # Instead, it represents an application in openshift. # See playbooks/openshift-apps/greenwave.yml - fedmsg_certs: -- service: greenwave - can_send: - - logger.log - - greenwave.decision.update + - can_send: + - logger.log + - greenwave.decision.update + service: greenwave diff --git a/inventory/group_vars/greenwave_stg b/inventory/group_vars/greenwave_stg index 110e51c1de..9cb417b264 100644 --- a/inventory/group_vars/greenwave_stg +++ b/inventory/group_vars/greenwave_stg @@ -2,11 +2,9 @@ # XXX - this is not really a group of real hosts. # Instead, it represents an application in openshift. # See playbooks/openshift-apps/greenwave.yml - -fedmsg_env: stg - fedmsg_certs: -- service: greenwave - can_send: - - logger.log - - greenwave.decision.update + - can_send: + - logger.log + - greenwave.decision.update + service: greenwave +fedmsg_env: stg diff --git a/inventory/group_vars/ipa b/inventory/group_vars/ipa index 707e412835..510f27516f 100644 --- a/inventory/group_vars/ipa +++ b/inventory/group_vars/ipa @@ -1,29 +1,21 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 8192 -num_cpus: 4 - -tcp_ports: [ 80, 88, 389, 443, 464, 636 ] -udp_ports: [ 88, 464 ] - -custom_rules: [ - '-A INPUT -p udp -m udp -s 10.3.0.0/16 --dport 53 -j ACCEPT' -] - -primary_auth_source: ipa +custom_rules: ['-A INPUT -p udp -m udp -s 10.3.0.0/16 --dport 53 -j ACCEPT'] +host_backup_targets: ['/var/lib/ipa/backup', '/var/log/dirsrv/slapd-FEDORAPROJECT-ORG'] +ipa_client_shell_groups: + - sysadmin-accounts +ipa_client_sudo_groups: + - sysadmin-accounts +ipa_dm_password: "{{ ipa_prod_dm_password }}" ipa_host_group: ipa ipa_host_group_desc: IPA service -ipa_client_shell_groups: -- sysadmin-accounts -ipa_client_sudo_groups: -- sysadmin-accounts - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - ipa_initial: false -ipa_dm_password: "{{ ipa_prod_dm_password }}" ipa_ldap_socket: ldapi://%2fvar%2frun%2fslapd-FEDORAPROJECT-ORG.socket - -host_backup_targets: ['/var/lib/ipa/backup', '/var/log/dirsrv/slapd-FEDORAPROJECT-ORG'] +lvm_size: 30000 +mem_size: 8192 +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 4 +primary_auth_source: ipa +tcp_ports: [80, 88, 389, 443, 464, 636] +udp_ports: [88, 464] diff --git a/inventory/group_vars/ipa_stg b/inventory/group_vars/ipa_stg index 05cdb9d204..26899b5aba 100644 --- a/inventory/group_vars/ipa_stg +++ b/inventory/group_vars/ipa_stg @@ -1,21 +1,17 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 8192 -num_cpus: 4 - -tcp_ports: [ 80, 88, 389, 443, 464, 636 ] -udp_ports: [ 88, 464 ] - +ipa_client_shell_groups: + - sysadmin-accounts +ipa_client_sudo_groups: + - sysadmin-accounts +ipa_dm_password: "{{ ipa_stg_dm_password }}" ipa_host_group: ipa ipa_host_group_desc: IPA service -ipa_client_shell_groups: -- sysadmin-accounts -ipa_client_sudo_groups: -- sysadmin-accounts - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - -ipa_dm_password: "{{ ipa_stg_dm_password }}" ipa_ldap_socket: ldapi://%2fvar%2frun%2fslapd-STG-FEDORAPROJECT-ORG.socket +lvm_size: 30000 +mem_size: 8192 +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 4 +tcp_ports: [80, 88, 389, 443, 464, 636] +udp_ports: [88, 464] diff --git a/inventory/group_vars/ipsilon b/inventory/group_vars/ipsilon index b9de511f10..b743634eaa 100644 --- a/inventory/group_vars/ipsilon +++ b/inventory/group_vars/ipsilon @@ -1,16 +1,12 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +ipa_host_group: ipsilon +ipa_host_group_desc: Ipsilon SSO application lvm_size: 20000 mem_size: 4096 num_cpus: 2 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 80, 443 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: ipsilon -ipa_host_group_desc: Ipsilon SSO application +tcp_ports: [80, 443] diff --git a/inventory/group_vars/ipsilon_stg b/inventory/group_vars/ipsilon_stg index e3c9fc2e83..924b9034de 100644 --- a/inventory/group_vars/ipsilon_stg +++ b/inventory/group_vars/ipsilon_stg @@ -1,16 +1,12 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +ipa_host_group: ipsilon +ipa_host_group_desc: Ipsilon SSO application lvm_size: 20000 mem_size: 4096 num_cpus: 2 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -proxy_tcp_ports: [ 80, 443 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: ipsilon -ipa_host_group_desc: Ipsilon SSO application +proxy_tcp_ports: [80, 443] diff --git a/inventory/group_vars/kernel_qa b/inventory/group_vars/kernel_qa index e45be2e386..0c06b9d269 100644 --- a/inventory/group_vars/kernel_qa +++ b/inventory/group_vars/kernel_qa @@ -1,12 +1,10 @@ --- +custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.122.0/24 --dport 2049 -j ACCEPT'] freezes: false -resolvconf: "{{ files }}/resolv.conf/iad2" - +ipa_client_shell_groups: + - sysadmin-kernel +ipa_client_sudo_groups: + - sysadmin-kernel ipa_host_group: kernel_qa ipa_host_group_desc: kernel test machines -ipa_client_shell_groups: -- sysadmin-kernel -ipa_client_sudo_groups: -- sysadmin-kernel - -custom_rules: [ '-A INPUT -p tcp -m tcp -s 192.168.122.0/24 --dport 2049 -j ACCEPT' ] +resolvconf: "{{ files }}/resolv.conf/iad2" diff --git a/inventory/group_vars/kerneltest b/inventory/group_vars/kerneltest index 8b5bfa3eb1..e5e68a7129 100644 --- a/inventory/group_vars/kerneltest +++ b/inventory/group_vars/kerneltest @@ -1,9 +1,30 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - kerneltest.release.edit + - kerneltest.release.new + - kerneltest.upload.new + group: apache + owner: root + service: kerneltest +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran +ipa_host_group: kerneltest lvm_size: 20000 mem_size: 4096 num_cpus: 2 - +primary_auth_source: ipa +tcp_ports: [80] # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -11,29 +32,3 @@ num_cpus: 2 wsgi_fedmsg_service: kerneltest wsgi_procs: 2 wsgi_threads: 1 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: kerneltest -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: kerneltest - owner: root - group: apache - can_send: - - kerneltest.release.edit - - kerneltest.release.new - - kerneltest.upload.new diff --git a/inventory/group_vars/koji b/inventory/group_vars/koji index 9c2a3ea370..2bc1838d01 100644 --- a/inventory/group_vars/koji +++ b/inventory/group_vars/koji @@ -1,56 +1,47 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 32768 -num_cpus: 16 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -tcp_ports: [ 80, 443, 111, 2049, - # These 8 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] - -udp_ports: [ 111, 2049 ] - custom_rules: [ - # Needed for keepalived - '-A INPUT -d 224.0.0.0/8 -j ACCEPT', - '-A INPUT -p vrrp -j ACCEPT', -] - -primary_auth_source: ipa -ipa_host_group: kojihub -ipa_host_group_desc: Koji Hub hosts -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - + # Needed for keepalived + '-A INPUT -d 224.0.0.0/8 -j ACCEPT', '-A INPUT -p vrrp -j ACCEPT'] +docker_registry: "candidate-registry.fedoraproject.org" # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: koji - owner: root - group: apache - can_send: - - buildsys.build.state.change - - buildsys.package.list.change - - buildsys.repo.done - - buildsys.repo.init - - buildsys.rpm.sign - - buildsys.tag - - buildsys.task.state.change - - buildsys.untag - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" -virt_install_command: "{{ virt_install_command_two_nic }}" - -osbs_url: "osbs.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" -source_registry: "registry.fedoraproject.org" -koji_root: "koji.fedoraproject.org/koji" + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - buildsys.build.state.change + - buildsys.package.list.change + - buildsys.repo.done + - buildsys.repo.init + - buildsys.rpm.sign + - buildsys.tag + - buildsys.task.state.change + - buildsys.untag + group: apache + owner: root + service: koji +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: kojihub +ipa_host_group_desc: Koji Hub hosts koji_hub: "koji.fedoraproject.org/kojihub" +koji_root: "koji.fedoraproject.org/koji" +lvm_size: 30000 +mem_size: 32768 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +num_cpus: 16 +osbs_url: "osbs.fedoraproject.org" +primary_auth_source: ipa +source_registry: "registry.fedoraproject.org" +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, 111, 2049, + # These 8 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] +udp_ports: [111, 2049] +virt_install_command: "{{ virt_install_command_two_nic }}" diff --git a/inventory/group_vars/koji_stg b/inventory/group_vars/koji_stg index 730e76a408..8b7a69b0a4 100644 --- a/inventory/group_vars/koji_stg +++ b/inventory/group_vars/koji_stg @@ -1,66 +1,55 @@ --- # Define resources for this group of hosts here. -lvm_size: 250000 -mem_size: 8192 -num_cpus: 8 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file -tcp_ports: [ 80, 443, 111, 2049, - # These 8 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] - -udp_ports: [ 111, 2049 ] - -ipa_host_group: kojihub -ipa_host_group_desc: Koji Hub hosts -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-osbs -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-osbs -- sysadmin-releng - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: koji - owner: root - group: apache - can_send: - - buildsys.build.state.change - - buildsys.package.list.change - - buildsys.repo.done - - buildsys.repo.init - - buildsys.rpm.sign - - buildsys.tag - - buildsys.task.state.change - - buildsys.untag - -# NOTE -- staging mounts read-only -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - -koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - -osbs_url: "osbs.stg.fedoraproject.org" -source_registry: "registry.stg.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" -koji_root: "koji.stg.fedoraproject.org/koji" -koji_hub: "koji.stg.fedoraproject.org/kojihub" - - # Add custom iptable rule to allow stage koji to talk to # osbs-dev.fedorainfracloud.org (will move to stage osbs later, this is for the # sake of testing). -custom_rules: [ - '-A OUTPUT -p tcp -m tcp -d 209.132.184.60 --dport 8443 -j ACCEPT' -] +custom_rules: ['-A OUTPUT -p tcp -m tcp -d 209.132.184.60 --dport 8443 -j ACCEPT'] +docker_registry: "candidate-registry.stg.fedoraproject.org" +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - buildsys.build.state.change + - buildsys.package.list.change + - buildsys.repo.done + - buildsys.repo.init + - buildsys.rpm.sign + - buildsys.tag + - buildsys.task.state.change + - buildsys.untag + group: apache + owner: root + service: koji +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-osbs + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-osbs + - sysadmin-releng +ipa_host_group: kojihub +ipa_host_group_desc: Koji Hub hosts +koji_hub: "koji.stg.fedoraproject.org/kojihub" +koji_root: "koji.stg.fedoraproject.org/koji" +koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.stg.fedoraproject.org/koji" +lvm_size: 250000 +mem_size: 8192 +# NOTE -- staging mounts read-only +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 8 +osbs_url: "osbs.stg.fedoraproject.org" +source_registry: "registry.stg.fedoraproject.org" +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, 111, 2049, + # These 8 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] +udp_ports: [111, 2049] diff --git a/inventory/group_vars/kojipkgs b/inventory/group_vars/kojipkgs index 1d295ff473..e11eea9d8d 100644 --- a/inventory/group_vars/kojipkgs +++ b/inventory/group_vars/kojipkgs @@ -1,47 +1,39 @@ --- # Define resources for this group of hosts here. -lvm_size: 50000 -mem_size: 98304 -max_mem_size: 98304 -num_cpus: 16 - -custom_rules: [ - # Need for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - ] - -tcp_ports: [80, 8080] - -primary_auth_source: ipa -ipa_host_group: kojipkgs -ipa_host_group_desc: Koji Packages hosts -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-releng - -varnish_group: kojipkgs - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admins - admin@fedoraproject.org csi_purpose: Cache packages from koji for builders and others csi_relationship: | - There are a few things running here: + There are a few things running here: - - apache web server and varnish caching proxy. + - apache web server and varnish caching proxy. - - This host relies on: - - koji nfs storage - - proxy01/10 to proxy requests to it. - - - Things that rely on this host: - - all koji builders/buildsystem - - koschei - - external users downloading packages from koji. + - This host relies on: + - koji nfs storage + - proxy01/10 to proxy requests to it. + - Things that rely on this host: + - all koji builders/buildsystem + - koschei + - external users downloading packages from koji. +# For the MOTD +csi_security_category: Moderate +custom_rules: [ + # Need for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: kojipkgs +ipa_host_group_desc: Koji Packages hosts +lvm_size: 50000 +max_mem_size: 98304 +mem_size: 98304 nagios_Check_Services: swap: false +num_cpus: 16 +primary_auth_source: ipa +tcp_ports: [80, 8080] +varnish_group: kojipkgs diff --git a/inventory/group_vars/logging b/inventory/group_vars/logging index 9a63a89566..2aa72c8217 100644 --- a/inventory/group_vars/logging +++ b/inventory/group_vars/logging @@ -1,13 +1,13 @@ --- -primary_auth_source: ipa +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-analysis + - sysadmin-logs + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-analysis + - sysadmin-logs ipa_host_group: logging ipa_host_group_desc: Logging hosts -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-analysis -- sysadmin-logs -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-analysis -- sysadmin-logs +primary_auth_source: ipa diff --git a/inventory/group_vars/mailman b/inventory/group_vars/mailman index ca246c2b6d..2eeb27e712 100644 --- a/inventory/group_vars/mailman +++ b/inventory/group_vars/mailman @@ -1,78 +1,68 @@ --- # common items for the releng-* boxes +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - mailman.receive + group: mailman + owner: mailman + service: mailman +ipa_client_shell_groups: + - sysadmin-tools +ipa_client_sudo_groups: + - sysadmin-tools +ipa_host_group: mailman +ipa_host_group_desc: Mailing list services lvm_size: 250000 -mem_size: 32768 +# Used by the mailman role +mailman_db_server: db01.iad2.fedoraproject.org +mailman_domains: + - lists.fedoraproject.org + - lists.fedorahosted.org + - lists.pagure.io +mailman_login: + facebook: + display_name: Facebook + provider: facebook + github: + display_name: GitHub + provider: github + gitlab: + display_name: GitLab + provider: gitlab + google: + display_name: Google + provider: google + stackexchange: + display_name: StackExchange + provider: stackexchange + twitter: + display_name: Twitter + provider: twitter max_mem_size: 32768 +mem_size: 32768 +nagios_Check_Services: + nrpe: true + swap: false +nrpe_check_postfix_queue_crit: 200 +# by default, the number of emails in queue before we whine +nrpe_check_postfix_queue_warn: 100 +nrpe_procs_crit: 500 +# Number of processes for nagios +nrpe_procs_warn: 300 num_cpus: 4 # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file -tcp_ports: [ - 25, 80, 443, - # For outgoing fedmsg - 3000, 3001, 3002, 3003, -] - -primary_auth_source: ipa -ipa_host_group: mailman -ipa_host_group_desc: Mailing list services -ipa_client_shell_groups: -- sysadmin-tools -ipa_client_sudo_groups: -- sysadmin-tools - -deployment_type: prod - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mailman - owner: mailman - group: mailman - can_send: - - mailman.receive - # Postfix main.cf postfix_group: mailman - -# Used by the mailman role -mailman_db_server: db01.iad2.fedoraproject.org -mailman_domains: -- lists.fedoraproject.org -- lists.fedorahosted.org -- lists.pagure.io -mailman_login: - gitlab: - display_name: GitLab - provider: gitlab - github: - display_name: GitHub - provider: github - twitter: - display_name: Twitter - provider: twitter - google: - display_name: Google - provider: google - facebook: - display_name: Facebook - provider: facebook - stackexchange: - display_name: StackExchange - provider: stackexchange - -# by default, the number of emails in queue before we whine -nrpe_check_postfix_queue_warn: 100 -nrpe_check_postfix_queue_crit: 200 - -# Number of processes for nagios -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - -nagios_Check_Services: - nrpe: true - swap: false +primary_auth_source: ipa +tcp_ports: [25, 80, 443, + # For outgoing fedmsg + 3000, 3001, 3002, 3003] diff --git a/inventory/group_vars/mailman_stg b/inventory/group_vars/mailman_stg index 23bff4a23e..16bde157b6 100644 --- a/inventory/group_vars/mailman_stg +++ b/inventory/group_vars/mailman_stg @@ -1,68 +1,60 @@ --- # common items for the releng-* boxes +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - mailman.receive + group: mailman + owner: mailman + service: mailman +ipa_client_shell_groups: + - sysadmin-tools +ipa_client_sudo_groups: + - sysadmin-tools +ipa_host_group: mailman +ipa_host_group_desc: Mailing list services lvm_size: 250000 +# Used by the mailman role +mailman_db_server: db01.stg.iad2.fedoraproject.org +mailman_domains: + - lists.stg.fedoraproject.org + - lists.stg.fedorahosted.org + - lists.stg.pagure.io +mailman_login: + facebook: + display_name: Facebook + provider: facebook + github: + display_name: GitHub + provider: github + gitlab: + display_name: GitLab + provider: gitlab + google: + display_name: Google + provider: google + stackexchange: + display_name: StackExchange + provider: stackexchange + twitter: + display_name: Twitter + provider: twitter mem_size: 4096 +nrpe_check_postfix_queue_crit: 50 +# by default, the number of emails in queue before we whine +nrpe_check_postfix_queue_warn: 20 num_cpus: 2 # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file -tcp_ports: [ - 25, 80, 443, - # For outbound fedmsg - 3000, 3001, 3002, 3003, -] - -ipa_host_group: mailman -ipa_host_group_desc: Mailing list services -ipa_client_shell_groups: -- sysadmin-tools -ipa_client_sudo_groups: -- sysadmin-tools - -deployment_type: prod - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mailman - owner: mailman - group: mailman - can_send: - - mailman.receive - # Postfix main.cf postfix_group: mailman-stg - -# Used by the mailman role -mailman_db_server: db01.stg.iad2.fedoraproject.org -mailman_domains: -- lists.stg.fedoraproject.org -- lists.stg.fedorahosted.org -- lists.stg.pagure.io -mailman_login: - gitlab: - display_name: GitLab - provider: gitlab - github: - display_name: GitHub - provider: github - twitter: - display_name: Twitter - provider: twitter - google: - display_name: Google - provider: google - facebook: - display_name: Facebook - provider: facebook - stackexchange: - display_name: StackExchange - provider: stackexchange - -# by default, the number of emails in queue before we whine -nrpe_check_postfix_queue_warn: 20 -nrpe_check_postfix_queue_crit: 50 +tcp_ports: [25, 80, 443, + # For outbound fedmsg + 3000, 3001, 3002, 3003] diff --git a/inventory/group_vars/maintainer_test b/inventory/group_vars/maintainer_test index f3cdae58ad..b8052cceb3 100644 --- a/inventory/group_vars/maintainer_test +++ b/inventory/group_vars/maintainer_test @@ -1,16 +1,15 @@ --- -freezes: false -sudoers: "{{ private }}/files/sudo/arm-packager-sudoers" -sudoers_main: nopasswd -datacenter: aws ansible_ifcfg_blocklist: true - -vpn: true -primary_auth_source: ipa +datacenter: aws +freezes: false +ipa_client_shell_groups: + - packager +ipa_client_sudo_nopasswd_groups: + - sysadmin-main + - packager ipa_host_group: maintainer_test ipa_host_group_desc: Test hosts for package maintainers -ipa_client_shell_groups: -- packager -ipa_client_sudo_nopasswd_groups: -- sysadmin-main -- packager +primary_auth_source: ipa +sudoers: "{{ private }}/files/sudo/arm-packager-sudoers" +sudoers_main: nopasswd +vpn: true diff --git a/inventory/group_vars/mbs b/inventory/group_vars/mbs index 7a5b609e98..832f2f3b8d 100644 --- a/inventory/group_vars/mbs +++ b/inventory/group_vars/mbs @@ -1,12 +1,12 @@ --- -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-releng + - sysadmin-mbs + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-releng + - sysadmin-mbs ipa_host_group: mbs ipa_host_group_desc: Modular Build Service hosts -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-releng -- sysadmin-mbs -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-releng -- sysadmin-mbs +primary_auth_source: ipa diff --git a/inventory/group_vars/mbs_backend b/inventory/group_vars/mbs_backend index b69bc74bfe..4e212c2f01 100644 --- a/inventory/group_vars/mbs_backend +++ b/inventory/group_vars/mbs_backend @@ -1,44 +1,36 @@ --- -lvm_size: 20000 -mem_size: 16384 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007 ] - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- ralph@fedoraproject.org -- jkaluza@fedoraproject.org -- fivaldi@fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: mbs - owner: root - group: fedmsg - can_send: - - mbs.module.state.change - - mbs.component.state.change - -# Wait a little bit longer than usual.. I'm not seeing messages from mbs backend -fedmsg_post_init_sleep: 1.5 - -# For the MOTD -csi_security_category: High csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org csi_purpose: Run the module-build-service fedmsg-hub backend (the scheduler) csi_relationship: | - The fedmsg-hub process running here is responsible for scheduling all rpm - builds in koji in response to requests submitted to the MBS API on the - mbs-frontend nodes. - - NOTE - this system has a KRB service principal with elevated koji privileges. + The fedmsg-hub process running here is responsible for scheduling all rpm + builds in koji in response to requests submitted to the MBS API on the + mbs-frontend nodes. + NOTE - this system has a KRB service principal with elevated koji privileges. +# For the MOTD +csi_security_category: High +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - mbs.module.state.change + - mbs.component.state.change + group: fedmsg + owner: root + service: mbs +# These people get told when something goes wrong. +fedmsg_error_recipients: + - ralph@fedoraproject.org + - jkaluza@fedoraproject.org + - fivaldi@fedoraproject.org +# Wait a little bit longer than usual.. I'm not seeing messages from mbs backend +fedmsg_post_init_sleep: 1.5 +lvm_size: 20000 mbs_broker_url: "amqps://mbs-private-queue{{ env_suffix }}@rabbitmq{{ env_suffix }}.fedoraproject.org//mbs-private-queue" +mbs_frontend: false mbs_num_workers: 3 mbs_systemd_wait_for_rabbitmq: true -mbs_frontend: false +mem_size: 16384 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] diff --git a/inventory/group_vars/mbs_backend_stg b/inventory/group_vars/mbs_backend_stg index 92b70f8541..267f31562d 100644 --- a/inventory/group_vars/mbs_backend_stg +++ b/inventory/group_vars/mbs_backend_stg @@ -1,41 +1,34 @@ --- -lvm_size: 20000 -mem_size: 4096 -num_cpus: 1 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007 ] - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- ralph@fedoraproject.org -- jkaluza@fedoraproject.org -- fivaldi@fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: mbs - owner: root - group: fedmsg - can_send: - - mbs.module.state.change - - mbs.component.state.change - -# For the MOTD -csi_security_category: High csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org csi_purpose: Run the module-build-service fedmsg-hub backend (the scheduler) csi_relationship: | - The fedmsg-hub process running here is responsible for scheduling all rpm - builds in koji in response to requests submitted to the MBS API on the - mbs-frontend nodes. - - NOTE - this system has a KRB service principal with elevated koji privileges. + The fedmsg-hub process running here is responsible for scheduling all rpm + builds in koji in response to requests submitted to the MBS API on the + mbs-frontend nodes. + NOTE - this system has a KRB service principal with elevated koji privileges. +# For the MOTD +csi_security_category: High +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - mbs.module.state.change + - mbs.component.state.change + group: fedmsg + owner: root + service: mbs +# These people get told when something goes wrong. +fedmsg_error_recipients: + - ralph@fedoraproject.org + - jkaluza@fedoraproject.org + - fivaldi@fedoraproject.org +lvm_size: 20000 mbs_broker_url: "amqps://mbs-private-queue{{ env_suffix }}@rabbitmq{{ env_suffix }}.fedoraproject.org//mbs-private-queue" +mbs_frontend: false mbs_num_workers: 3 mbs_systemd_wait_for_rabbitmq: true -mbs_frontend: false +mem_size: 4096 +num_cpus: 1 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] diff --git a/inventory/group_vars/mbs_frontend b/inventory/group_vars/mbs_frontend index f53918b36d..774fc776af 100644 --- a/inventory/group_vars/mbs_frontend +++ b/inventory/group_vars/mbs_frontend @@ -1,8 +1,35 @@ --- +csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org +csi_purpose: Run the module-build-service frontend API. +csi_relationship: | + The apache/mod_wsgi app is the only thing really running here + + This host relies on db01 for its database of activity (what module builds + are in flight?) + + It has no special credentials itself. When a module build it submitted, it + makes a note in the DB and publishes a fedmsg message. The mbs backend + nodes do all the work of talking to koji. +# For the MOTD +csi_security_category: Moderate +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - mbs.module.state.change + # Only the backend sends this message.. + #- mbs.component.state.change + group: fedmsg + owner: fedmsg + service: mbs lvm_size: 20000 +mbs_broker_url: "" +mbs_frontend: true +mbs_num_workers: 3 mem_size: 4096 num_cpus: 2 - +tcp_ports: [80] # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -10,36 +37,3 @@ num_cpus: 2 wsgi_fedmsg_service: mbs wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: mbs - owner: fedmsg - group: fedmsg - can_send: - - mbs.module.state.change - # Only the backend sends this message.. - #- mbs.component.state.change - -# For the MOTD -csi_security_category: Moderate -csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org -csi_purpose: Run the module-build-service frontend API. -csi_relationship: | - The apache/mod_wsgi app is the only thing really running here - - This host relies on db01 for its database of activity (what module builds - are in flight?) - - It has no special credentials itself. When a module build it submitted, it - makes a note in the DB and publishes a fedmsg message. The mbs backend - nodes do all the work of talking to koji. - -mbs_broker_url: "" -mbs_num_workers: 3 -mbs_frontend: true diff --git a/inventory/group_vars/mbs_frontend_stg b/inventory/group_vars/mbs_frontend_stg index e3e8ee2c51..53a377c3c5 100644 --- a/inventory/group_vars/mbs_frontend_stg +++ b/inventory/group_vars/mbs_frontend_stg @@ -1,8 +1,35 @@ --- +csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org +csi_purpose: Run the module-build-service frontend API. +csi_relationship: | + The apache/mod_wsgi app is the only thing really running here + + This host relies on db01 for its database of activity (what module builds + are in flight?) + + It has no special credentials itself. When a module build it submitted, it + makes a note in the DB and publishes a fedmsg message. The mbs backend + nodes do all the work of talking to koji. +# For the MOTD +csi_security_category: Moderate +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - mbs.module.state.change + # Only the backend sends this message.. + #- mbs.component.state.change + group: fedmsg + owner: fedmsg + service: mbs lvm_size: 20000 +mbs_broker_url: "" +mbs_frontend: true +mbs_num_workers: 3 mem_size: 4096 num_cpus: 1 - +tcp_ports: [80] # Definining these vars has a number of effects # 1) mod_wsgi is configured to use the vars for its own setup # 2) iptables opens enough ports for all threads for fedmsg @@ -10,36 +37,3 @@ num_cpus: 1 wsgi_fedmsg_service: mbs wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: mbs - owner: fedmsg - group: fedmsg - can_send: - - mbs.module.state.change - # Only the backend sends this message.. - #- mbs.component.state.change - -# For the MOTD -csi_security_category: Moderate -csi_primary_contact: Modularity WG - modularity-wg-members@fedoraproject.org -csi_purpose: Run the module-build-service frontend API. -csi_relationship: | - The apache/mod_wsgi app is the only thing really running here - - This host relies on db01 for its database of activity (what module builds - are in flight?) - - It has no special credentials itself. When a module build it submitted, it - makes a note in the DB and publishes a fedmsg message. The mbs backend - nodes do all the work of talking to koji. - -mbs_broker_url: "" -mbs_num_workers: 3 -mbs_frontend: true diff --git a/inventory/group_vars/mbs_stg b/inventory/group_vars/mbs_stg index 53ba595ba2..88e3993a38 100644 --- a/inventory/group_vars/mbs_stg +++ b/inventory/group_vars/mbs_stg @@ -1,11 +1,11 @@ --- +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-releng + - sysadmin-mbs + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-releng + - sysadmin-mbs ipa_host_group: mbs ipa_host_group_desc: Modular Build Service hosts -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-releng -- sysadmin-mbs -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-releng -- sysadmin-mbs diff --git a/inventory/group_vars/memcached b/inventory/group_vars/memcached index b87b9ee6bc..f76683a419 100644 --- a/inventory/group_vars/memcached +++ b/inventory/group_vars/memcached @@ -1,22 +1,18 @@ --- # Define resources for this group of hosts here. +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: memcached +ipa_host_group_desc: Distributed Memory Caching service lvm_size: 10000 mem_size: 8192 num_cpus: 2 - +primary_auth_source: ipa # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 11211 ] - - -primary_auth_source: ipa -ipa_host_group: memcached -ipa_host_group_desc: Distributed Memory Caching service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web +tcp_ports: [11211] diff --git a/inventory/group_vars/memcached_stg b/inventory/group_vars/memcached_stg index 46d3007520..11bda32514 100644 --- a/inventory/group_vars/memcached_stg +++ b/inventory/group_vars/memcached_stg @@ -1,20 +1,17 @@ --- # Define resources for this group of hosts here. +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: memcached +ipa_host_group_desc: Distributed Memory Caching service lvm_size: 10000 mem_size: 4096 num_cpus: 1 - # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [ 11211 ] - -ipa_host_group: memcached -ipa_host_group_desc: Distributed Memory Caching service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web +tcp_ports: [11211] diff --git a/inventory/group_vars/mm b/inventory/group_vars/mm index 85535f5318..e9f52599f6 100644 --- a/inventory/group_vars/mm +++ b/inventory/group_vars/mm @@ -1,16 +1,15 @@ --- # Define resources for this group of hosts here. -primary_auth_source: ipa +deployment_type: prod +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-noc + - sysadmin-web ipa_host_group: mirrormanager ipa_host_group_desc: Mirror Manager -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-noc -- sysadmin-web - -mm2_checkin: false -deployment_type: prod mirrormanager_db_host: 'db01' +mm2_checkin: false +primary_auth_source: ipa diff --git a/inventory/group_vars/mm_backend b/inventory/group_vars/mm_backend index d051a134af..88e3d5078d 100644 --- a/inventory/group_vars/mm_backend +++ b/inventory/group_vars/mm_backend @@ -1,22 +1,20 @@ --- -mem_size: 6144 - -fedmsg_certs: -- service: shell - alias: mirrormanager - owner: mirrormanager - group: sysadmin - can_send: - - mirrormanager.netblocks.get - - logger.log - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager backend cron tasks csi_relationship: | - TODO - we should document: + TODO - we should document: - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - alias: mirrormanager + can_send: + - mirrormanager.netblocks.get + - logger.log + group: sysadmin + owner: mirrormanager + service: shell +mem_size: 6144 diff --git a/inventory/group_vars/mm_backend_stg b/inventory/group_vars/mm_backend_stg index f609d31c62..f6c7b9adda 100644 --- a/inventory/group_vars/mm_backend_stg +++ b/inventory/group_vars/mm_backend_stg @@ -1,20 +1,18 @@ --- - -fedmsg_certs: -- service: shell - owner: mirrormanager - group: sysadmin - can_send: - - mirrormanager.netblocks.get - - logger.log - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager backend cron tasks csi_relationship: | - TODO - we should document: + TODO - we should document: - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - can_send: + - mirrormanager.netblocks.get + - logger.log + group: sysadmin + owner: mirrormanager + service: shell diff --git a/inventory/group_vars/mm_crawler b/inventory/group_vars/mm_crawler index a8fe3a0790..a5bd3f98ef 100644 --- a/inventory/group_vars/mm_crawler +++ b/inventory/group_vars/mm_crawler @@ -1,24 +1,21 @@ --- - -fedmsg_certs: -- service: shell - owner: mirrormanager - group: sysadmin - can_send: - - mirrormanager.crawler.complete - - mirrormanager.crawler.start - - logger.log - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager crawlers csi_relationship: | - TODO - we should document: - - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + TODO - we should document: + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - can_send: + - mirrormanager.crawler.complete + - mirrormanager.crawler.start + - logger.log + group: sysadmin + owner: mirrormanager + service: shell rsyncd_conf: "rsyncd.conf.crawler" -tcp_ports: [ 873 ] +tcp_ports: [873] diff --git a/inventory/group_vars/mm_crawler_stg b/inventory/group_vars/mm_crawler_stg index 7a02078271..2e3004bf01 100644 --- a/inventory/group_vars/mm_crawler_stg +++ b/inventory/group_vars/mm_crawler_stg @@ -1,21 +1,19 @@ --- - -fedmsg_certs: -- service: shell - owner: mirrormanager - group: sysadmin - can_send: - - mirrormanager.crawler.complete - - mirrormanager.crawler.start - - logger.log - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager crawlers csi_relationship: | - TODO - we should document: + TODO - we should document: - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - can_send: + - mirrormanager.crawler.complete + - mirrormanager.crawler.start + - logger.log + group: sysadmin + owner: mirrormanager + service: shell diff --git a/inventory/group_vars/mm_frontend b/inventory/group_vars/mm_frontend index 78d5aeb39f..8d61e72d08 100644 --- a/inventory/group_vars/mm_frontend +++ b/inventory/group_vars/mm_frontend @@ -1,30 +1,25 @@ --- -mem_size: 4096 - -tcp_ports: [ 80, - # These 2 ports are used by fedmsg. - # One for each wsgi thread. - 3000, 3001, - ] - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mirrormanager2 - owner: root - group: apache - - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager frontend WSGI app csi_relationship: | - TODO - we should document: + TODO - we should document: - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - group: apache + owner: root + service: mirrormanager2 +mem_size: 4096 +tcp_ports: [80, + # These 2 ports are used by fedmsg. + # One for each wsgi thread. + 3000, 3001] diff --git a/inventory/group_vars/mm_frontend_stg b/inventory/group_vars/mm_frontend_stg index 09c3909fab..502a165c3a 100644 --- a/inventory/group_vars/mm_frontend_stg +++ b/inventory/group_vars/mm_frontend_stg @@ -1,29 +1,24 @@ --- - -tcp_ports: [ 80, - # These 2 ports are used by fedmsg. - # One for each wsgi thread. - 3000, 3001, - ] - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mirrormanager2 - owner: root - group: apache - - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: Fedora admin - admin@fedoraproject.org csi_purpose: Run mirrormanager frontend WSGI app csi_relationship: | - TODO - we should document: + TODO - we should document: - * what kinds of processes run here - * what other services they depend on - * what other services depend on it + * what kinds of processes run here + * what other services they depend on + * what other services depend on it +# For the MOTD +csi_security_category: Moderate +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - group: apache + owner: root + service: mirrormanager2 +tcp_ports: [80, + # These 2 ports are used by fedmsg. + # One for each wsgi thread. + 3000, 3001] diff --git a/inventory/group_vars/mm_stg b/inventory/group_vars/mm_stg index a7515e6803..34dad0179b 100644 --- a/inventory/group_vars/mm_stg +++ b/inventory/group_vars/mm_stg @@ -1,15 +1,14 @@ --- # Define resources for this group of hosts here. +deployment_type: stg +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-noc + - sysadmin-web ipa_host_group: mirrormanager ipa_host_group_desc: Mirror Manager -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-noc -- sysadmin-web - -mm2_checkin: false -deployment_type: stg mirrormanager_db_host: 'db01.stg' +mm2_checkin: false diff --git a/inventory/group_vars/nagios b/inventory/group_vars/nagios index b3423e1500..6db857f912 100644 --- a/inventory/group_vars/nagios +++ b/inventory/group_vars/nagios @@ -1,42 +1,55 @@ --- -deployment_type: prod - -lvm_size: 20000 -mem_size: 2048 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443 ] - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: nagios - owner: root - group: nagios - can_send: - - nagios.host.state.change - - nagios.service.state.change - -primary_auth_source: ipa -ipa_host_group: nagios -ipa_host_group_desc: Nagios Monitoring -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-noc - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Monitoring system - +csi_security_category: High +deployment_type: prod +dns_external: + - ns-iad01.fedoraproject.org + - ns-iad02.fedoraproject.org + - ns02.fedoraproject.org + - ns05.fedoraproject.org +# When you have a group which comes up with empty members in all.cfg, it +# is because it contains all hosts which aren't pinganble. You may want +# to add that group to this list. Other items on this list are ones +# where it is an enormous group not needed. +# Exclude these ansible host groups in hostgroups/all.cfg +exclude_iad2_hostgroups: + - centos_ipa_client_stg + - zabbix_stg +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - nagios.host.state.change + - nagios.service.state.change + group: nagios + owner: root + service: nagios +#iad2_management_slowping: +# - ppc8-01-fsp.mgmt.fedoraproject.org +# - ppc8-02-fsp.mgmt.fedoraproject.org +# - ppc8-03-fsp.mgmt.fedoraproject.org +iad2_external: + - bastion01.fedoraproject.org + - bastion02.fedoraproject.org + - dl-iad01.fedoraproject.org + - dl-iad02.fedoraproject.org + - dl-iad03.fedoraproject.org + - dl-iad04.fedoraproject.org + - dl-iad05.fedoraproject.org + - infrastructure.fedoraproject.org + - koji.fedoraproject.org + - kojipkgs.fedoraproject.org + - ns-iad01.fedoraproject.org + - ns-iad02.fedoraproject.org + - pkgs.fedoraproject.org + - proxy01.fedoraproject.org + - proxy10.fedoraproject.org + - secondary01.fedoraproject.org # # This is a list of hosts which are in the IAD2 160 mgmt network # we do not have them in ansible because it tries to connect @@ -81,7 +94,6 @@ iad2_management_hosts: - vmhost-x86-05.mgmt.iad2.fedoraproject.org - vmhost-x86-06.mgmt.iad2.fedoraproject.org - vmhost-x86-07.mgmt.iad2.fedoraproject.org - # # These are management interfaces we only want # to test ping against. No http/https @@ -89,42 +101,17 @@ iad2_management_hosts: iad2_management_limited: - opengear01.mgmt.iad2.fedoraproject.org - sign-vault01.mgmt.iad2.fedoraproject.org - -#iad2_management_slowping: -# - ppc8-01-fsp.mgmt.fedoraproject.org -# - ppc8-02-fsp.mgmt.fedoraproject.org -# - ppc8-03-fsp.mgmt.fedoraproject.org - -iad2_external: - - bastion01.fedoraproject.org - - bastion02.fedoraproject.org - - dl-iad01.fedoraproject.org - - dl-iad02.fedoraproject.org - - dl-iad03.fedoraproject.org - - dl-iad04.fedoraproject.org - - dl-iad05.fedoraproject.org - - infrastructure.fedoraproject.org - - koji.fedoraproject.org - - kojipkgs.fedoraproject.org - - ns-iad01.fedoraproject.org - - ns-iad02.fedoraproject.org - - pkgs.fedoraproject.org - - proxy01.fedoraproject.org - - proxy10.fedoraproject.org - - secondary01.fedoraproject.org - -dns_external: - - ns-iad01.fedoraproject.org - - ns-iad02.fedoraproject.org - - ns02.fedoraproject.org - - ns05.fedoraproject.org - - -# When you have a group which comes up with empty members in all.cfg, it -# is because it contains all hosts which aren't pinganble. You may want -# to add that group to this list. Other items on this list are ones -# where it is an enormous group not needed. -# Exclude these ansible host groups in hostgroups/all.cfg -exclude_iad2_hostgroups: - - centos_ipa_client_stg - - zabbix_stg +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-noc +ipa_host_group: nagios +ipa_host_group_desc: Nagios Monitoring +lvm_size: 20000 +mem_size: 2048 +num_cpus: 2 +primary_auth_source: ipa +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443] diff --git a/inventory/group_vars/notifs b/inventory/group_vars/notifs index 21efee26b6..7ff3c81e35 100644 --- a/inventory/group_vars/notifs +++ b/inventory/group_vars/notifs @@ -1,10 +1,10 @@ --- -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer ipa_host_group: notifs ipa_host_group_desc: Fedora Notifications -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer +primary_auth_source: ipa diff --git a/inventory/group_vars/notifs_backend b/inventory/group_vars/notifs_backend index d75cc4cc8c..a089c7c291 100644 --- a/inventory/group_vars/notifs_backend +++ b/inventory/group_vars/notifs_backend @@ -1,37 +1,33 @@ --- # Define resources for this group of hosts here. -lvm_size: 65536 -mem_size: 24576 -max_mem_size: "{{ mem_size }}" -num_cpus: 8 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, 3004, 3005 ] - -# For performance measurement.. for now. This can be removed whenever. -fedmsg_loglevel: DEBUG deployment_type: prod - # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - # The shell cert needs to be allowed to send these too so it can do alembic - # upgrades that trigger messages. - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update - - logger.log -- service: fmn - owner: root - group: fedmsg - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update + - # The shell cert needs to be allowed to send these too so it can do alembic + # upgrades that trigger messages. + can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + group: fedmsg + owner: root + service: fmn +# For performance measurement.. for now. This can be removed whenever. +fedmsg_loglevel: DEBUG +lvm_size: 65536 +max_mem_size: "{{ mem_size }}" +mem_size: 24576 +num_cpus: 8 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005] diff --git a/inventory/group_vars/notifs_backend_stg b/inventory/group_vars/notifs_backend_stg index 4f6e4c08e1..16cc5ffc5e 100644 --- a/inventory/group_vars/notifs_backend_stg +++ b/inventory/group_vars/notifs_backend_stg @@ -1,34 +1,31 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 16384 -max_mem_size: "{{ mem_size }}" -num_cpus: 4 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 3000, 3001, 3002, 3003, 3004 ] - deployment_type: stg # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - # The shell cert needs to be allowed to send these too so it can do alembic - # upgrades that trigger messages. - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update - - logger.log -- service: fmn - owner: root - group: fedmsg - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update + - # The shell cert needs to be allowed to send these too so it can do alembic + # upgrades that trigger messages. + can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + group: fedmsg + owner: root + service: fmn +lvm_size: 20000 +max_mem_size: "{{ mem_size }}" +mem_size: 16384 +num_cpus: 4 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [3000, 3001, 3002, 3003, 3004] diff --git a/inventory/group_vars/notifs_stg b/inventory/group_vars/notifs_stg index e24391fe8d..5585ae79a5 100644 --- a/inventory/group_vars/notifs_stg +++ b/inventory/group_vars/notifs_stg @@ -1,11 +1,11 @@ --- +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran ipa_host_group: notifs ipa_host_group_desc: Fedora Notifications -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran diff --git a/inventory/group_vars/notifs_web b/inventory/group_vars/notifs_web index 786f06faec..13f0a0ac70 100644 --- a/inventory/group_vars/notifs_web +++ b/inventory/group_vars/notifs_web @@ -1,32 +1,27 @@ --- # Define resources for this group of hosts here. +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + group: apache + owner: root + service: fmn lvm_size: 20000 mem_size: 1024 num_cpus: 2 - +tcp_ports: [80] # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - wsgi_fedmsg_service: fmn wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -deployment_type: prod - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fmn - owner: root - group: apache - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update diff --git a/inventory/group_vars/notifs_web_stg b/inventory/group_vars/notifs_web_stg index 6ff3ccc32c..4c759dd349 100644 --- a/inventory/group_vars/notifs_web_stg +++ b/inventory/group_vars/notifs_web_stg @@ -1,32 +1,27 @@ --- # Define resources for this group of hosts here. +deployment_type: stg +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - fmn.filter.update + - fmn.preference.update + - fmn.rule.update + - fmn.confirmation.update + group: apache + owner: root + service: fmn lvm_size: 20000 mem_size: 1024 num_cpus: 2 - +tcp_ports: [80] # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - wsgi_fedmsg_service: fmn wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] - -deployment_type: stg - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: fmn - owner: root - group: apache - can_send: - - fmn.filter.update - - fmn.preference.update - - fmn.rule.update - - fmn.confirmation.update diff --git a/inventory/group_vars/nuancier b/inventory/group_vars/nuancier index c99b067d91..65c2c7f372 100644 --- a/inventory/group_vars/nuancier +++ b/inventory/group_vars/nuancier @@ -1,10 +1,10 @@ --- -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer ipa_host_group: nuancier ipa_host_group_desc: Supplementary Wallpaper Voting -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer +primary_auth_source: ipa diff --git a/inventory/group_vars/nuancier_stg b/inventory/group_vars/nuancier_stg index cd77dcb9ff..200ff0b800 100644 --- a/inventory/group_vars/nuancier_stg +++ b/inventory/group_vars/nuancier_stg @@ -1,9 +1,9 @@ --- +ipa_client_shell_groups: + - sysadmin-datanommer + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-datanommer ipa_host_group: nuancier ipa_host_group_desc: Supplementary Wallpaper Voting -ipa_client_shell_groups: -- sysadmin-datanommer -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-datanommer diff --git a/inventory/group_vars/oci_registry b/inventory/group_vars/oci_registry index 5e50d8ae6f..78f30a0008 100644 --- a/inventory/group_vars/oci_registry +++ b/inventory/group_vars/oci_registry @@ -1,13 +1,10 @@ --- - -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: oci-registry ipa_host_group_desc: OCI Registry service -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -tcp_ports: [ 5000 ] - nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +primary_auth_source: ipa +tcp_ports: [5000] diff --git a/inventory/group_vars/oci_registry_stg b/inventory/group_vars/oci_registry_stg index 196fe9c2ff..c572c30b13 100644 --- a/inventory/group_vars/oci_registry_stg +++ b/inventory/group_vars/oci_registry_stg @@ -1,12 +1,9 @@ --- +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: oci-registry ipa_host_group_desc: OCI Registry service -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -tcp_ports: [ 5000 ] - nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - +tcp_ports: [5000] diff --git a/inventory/group_vars/ocp b/inventory/group_vars/ocp index 36f36c2ce7..8d5a086ae5 100644 --- a/inventory/group_vars/ocp +++ b/inventory/group_vars/ocp @@ -1,8 +1,8 @@ --- -rhcos_version: 4.8.2 -ocp4: true -vpn: false nagios_Check_Services: - swap: false - nrpe: false mail: false + nrpe: false + swap: false +ocp4: true +rhcos_version: 4.8.2 +vpn: false diff --git a/inventory/group_vars/ocp_stg b/inventory/group_vars/ocp_stg index 36f36c2ce7..8d5a086ae5 100644 --- a/inventory/group_vars/ocp_stg +++ b/inventory/group_vars/ocp_stg @@ -1,8 +1,8 @@ --- -rhcos_version: 4.8.2 -ocp4: true -vpn: false nagios_Check_Services: - swap: false - nrpe: false mail: false + nrpe: false + swap: false +ocp4: true +rhcos_version: 4.8.2 +vpn: false diff --git a/inventory/group_vars/odcs b/inventory/group_vars/odcs index e5de772369..3785c4f543 100644 --- a/inventory/group_vars/odcs +++ b/inventory/group_vars/odcs @@ -1,71 +1,66 @@ -primary_auth_source: ipa +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-odcs + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-odcs + - sysadmin-releng ipa_host_group: odcs ipa_host_group_desc: On Demand Compose Service -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-odcs -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-odcs -- sysadmin-releng - -# Configs executed on releng backends must have "releng_" prefix. -odcs_raw_config_urls: - releng_fmc: - url: https://pagure.io/releng/fmc.git - config_filename: fedora-minimal-compose.conf - releng_jkaluza_test_config: - url: https://pagure.io/jkaluza-test-compose.git - config_filename: test.conf - eln: - url: https://pagure.io/pungi-fedora.git - config_filename: eln.conf - eln_jwboyer: - url: https://pagure.io/forks/jwboyer/pungi-fedora.git - config_filename: eln.conf - cccc: - url: https://pagure.io/fedora-ci/cccc-merged-configs.git - config_filename: cccc.conf - releng_compose_ci: - url: https://pagure.io/fedora-ci/compose-ci-pipeline.git - config_filename: compose_ci.conf - raw_config_wrapper: /etc/odcs/custom_compose_raw_config_wrapper.conf - -# Default queues for general ODCS backends. -odcs_celery_queues: -- pungi_composes -- cleanup - -odcs_celery_router_config: - routing_rules: - odcs.server.celery_tasks.generate_pungi_compose: - releng_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "releng_.*" - eln_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "eln.*" - cccc_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "cccc.*" - releng_pungi_composes: - source_type: [1, 2, 6, 7] # "tag", "module", "build", "pungi_compose" - owner: ["mohanboddu", "humaton"] - cleanup_task: odcs.server.celery_tasks.run_cleanup - default_queue: pungi_composes - +odcs_allowed_clients_groups: + eln-sig: {"raw_config_keys": ["eln", "cccc", "eln_jwboyer"], "source_types": ["tag", "module", "build", "raw_config"]} + packager: {"source_types": ["module"]} + pungi-devel: {} + sysadmin-odcs: {} odcs_allowed_clients_users: humaton: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} - mohanboddu: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} jkaluza: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} - releng-odcs@service: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} - osbs@service: {} + mohanboddu: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} # This is token used by CCCC service running on https://jenkins-fedora-infra.apps.ci.centos.org/job/cccc. odcs@service: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} -odcs_allowed_clients_groups: - sysadmin-odcs: {} - pungi-devel: {} - packager: {"source_types": ["module"]} - eln-sig: {"source_types": ["tag", "module", "build", "raw_config"], "raw_config_keys": ["eln", "cccc", "eln_jwboyer"]} - + osbs@service: {} + releng-odcs@service: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} +# Default queues for general ODCS backends. +odcs_celery_queues: + - pungi_composes + - cleanup +odcs_celery_router_config: + cleanup_task: odcs.server.celery_tasks.run_cleanup + default_queue: pungi_composes + routing_rules: + odcs.server.celery_tasks.generate_pungi_compose: + cccc_raw_pungi_composes: + source: "cccc.*" + source_type: 5 # "raw_config" + eln_raw_pungi_composes: + source: "eln.*" + source_type: 5 # "raw_config" + releng_pungi_composes: + owner: ["mohanboddu", "humaton"] + source_type: [1, 2, 6, 7] # "tag", "module", "build", "pungi_compose" + releng_raw_pungi_composes: + source: "releng_.*" + source_type: 5 # "raw_config" +# Configs executed on releng backends must have "releng_" prefix. +odcs_raw_config_urls: + cccc: + config_filename: cccc.conf + url: https://pagure.io/fedora-ci/cccc-merged-configs.git + eln: + config_filename: eln.conf + url: https://pagure.io/pungi-fedora.git + eln_jwboyer: + config_filename: eln.conf + url: https://pagure.io/forks/jwboyer/pungi-fedora.git + releng_compose_ci: + config_filename: compose_ci.conf + raw_config_wrapper: /etc/odcs/custom_compose_raw_config_wrapper.conf + url: https://pagure.io/fedora-ci/compose-ci-pipeline.git + releng_fmc: + config_filename: fedora-minimal-compose.conf + url: https://pagure.io/releng/fmc.git + releng_jkaluza_test_config: + config_filename: test.conf + url: https://pagure.io/jkaluza-test-compose.git +primary_auth_source: ipa diff --git a/inventory/group_vars/odcs_backend b/inventory/group_vars/odcs_backend index b5632e4167..90e684d01f 100644 --- a/inventory/group_vars/odcs_backend +++ b/inventory/group_vars/odcs_backend @@ -1,60 +1,46 @@ --- -lvm_size: 200000 -mem_size: 4096 -num_cpus: 2 - -freezes: true - -tcp_ports: [ - 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007, - # These ports all required for gluster - 111, 24007, 24008, 24009, 24010, 24011, - 49152, 49153, 49154, 49155, -] -# Also for gluster. -udp_ports: [ 111 ] - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- ralph@fedoraproject.org -- jkaluza@fedoraproject.org -- cqi@fedoraproject.org -- qwan@fedoraproject.org - -# NOTE -- read-only mount of /mnt/fedora_koji here. -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -fedmsg_hub_auto_restart: False - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: odcs - owner: odcs - group: fedmsg - can_send: - - odcs.compose.state-changed - -odcs_target_dir_url: https://odcs.fedoraproject.org/composes - -# For the MOTD -csi_security_category: Low csi_primary_contact: Factory 2 factory2-members@fedoraproject.org csi_purpose: Run the on-demand-compose-service backend scheduler. csi_relationship: | - There is an odcs backend process running here. + There is an odcs backend process running here. - The process is called `odcs-backend`. + The process is called `odcs-backend`. - This host: - - - relies on db01 for its database of activity (what composes have been - requested and what state are they in?) - - Uses pungi to compose repos of content. - - It also *provides* an nfs share used by odcs-frontend01. + This host: + - relies on db01 for its database of activity (what composes have been + requested and what state are they in?) + - Uses pungi to compose repos of content. + - It also *provides* an nfs share used by odcs-frontend01. +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - odcs.compose.state-changed + group: fedmsg + owner: odcs + service: odcs +# These people get told when something goes wrong. +fedmsg_error_recipients: + - ralph@fedoraproject.org + - jkaluza@fedoraproject.org + - cqi@fedoraproject.org + - qwan@fedoraproject.org +fedmsg_hub_auto_restart: False +freezes: true +lvm_size: 200000 +mem_size: 4096 nagios_Check_Services: odcs-celery-backend: true +# NOTE -- read-only mount of /mnt/fedora_koji here. +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 2 +odcs_target_dir_url: https://odcs.fedoraproject.org/composes +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, + # These ports all required for gluster + 111, 24007, 24008, 24009, 24010, 24011, 49152, 49153, 49154, 49155] +# Also for gluster. +udp_ports: [111] diff --git a/inventory/group_vars/odcs_backend_releng b/inventory/group_vars/odcs_backend_releng index 1f0dc6b7e0..d6454cf15b 100644 --- a/inventory/group_vars/odcs_backend_releng +++ b/inventory/group_vars/odcs_backend_releng @@ -1,6 +1,5 @@ -odcs_celery_queues: ["releng_raw_pungi_composes", "releng_pungi_composes", "cleanup", "eln_raw_pungi_composes", "cccc_raw_pungi_composes"] - fmc_queue_name: "fmc{{ env_suffix }}_composer" # Define the topics that our fedora-messaging queue should be subscribed to. fmc_routing_keys: - "org.fedoraproject.prod.buildsys.rpm.sign" +odcs_celery_queues: ["releng_raw_pungi_composes", "releng_pungi_composes", "cleanup", "eln_raw_pungi_composes", "cccc_raw_pungi_composes"] diff --git a/inventory/group_vars/odcs_backend_stg b/inventory/group_vars/odcs_backend_stg index 311b2447b2..2b9c079a99 100644 --- a/inventory/group_vars/odcs_backend_stg +++ b/inventory/group_vars/odcs_backend_stg @@ -1,60 +1,44 @@ --- -lvm_size: 40000 -mem_size: 2048 -num_cpus: 2 - -# Set this to True for the F28 release and onwards. -freezes: false - -tcp_ports: [ - 3000, 3001, 3002, 3003, - 3004, 3005, 3006, 3007, - # These ports all required for gluster - 111, 24007, 24008, 24009, 24010, 24011, - 49152, 49153, 49154, 49155, -] -# Also for gluster. -udp_ports: [ 111 ] - -# These people get told when something goes wrong. -fedmsg_error_recipients: -- ralph@fedoraproject.org -- jkaluza@fedoraproject.org -- cqi@fedoraproject.org -- qwan@fedoraproject.org - -datacenter: iad2 - -# NOTE -- read-only mount of /mnt/fedora_koji here. -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -fedmsg_hub_auto_restart: False - -odcs_allowed_source_types: ["tag", "module"] - -odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes - -# Handle all Celery queues on single staging backend. -odcs_celery_queues: ["releng_raw_pungi_composes", "releng_pungi_composes", "cleanup", "eln_raw_pungi_composes", "pungi_composes", "cccc_raw_pungi_composes"] - -# For the MOTD -csi_security_category: Low csi_primary_contact: Factory 2 factory2-members@fedoraproject.org csi_purpose: Run the on-demand-compose-service backend scheduler. csi_relationship: | - There is an odcs backend process running here. + There is an odcs backend process running here. - The process is called `odcs-backend`. + The process is called `odcs-backend`. - This host: - - - relies on db01 for its database of activity (what composes have been - requested and what state are they in?) - - Uses pungi to compose repos of content. - - It also *provides* an nfs share used by odcs-frontend01. + This host: + - relies on db01 for its database of activity (what composes have been + requested and what state are they in?) + - Uses pungi to compose repos of content. + - It also *provides* an nfs share used by odcs-frontend01. +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +datacenter: iad2 +# These people get told when something goes wrong. +fedmsg_error_recipients: + - ralph@fedoraproject.org + - jkaluza@fedoraproject.org + - cqi@fedoraproject.org + - qwan@fedoraproject.org +fedmsg_hub_auto_restart: False +# Set this to True for the F28 release and onwards. +freezes: false +lvm_size: 40000 +mem_size: 2048 nagios_Check_Services: odcs-celery-backend: true +# NOTE -- read-only mount of /mnt/fedora_koji here. +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 2 +odcs_allowed_source_types: ["tag", "module"] +# Handle all Celery queues on single staging backend. +odcs_celery_queues: ["releng_raw_pungi_composes", "releng_pungi_composes", "cleanup", "eln_raw_pungi_composes", "pungi_composes", "cccc_raw_pungi_composes"] +odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes +tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, + # These ports all required for gluster + 111, 24007, 24008, 24009, 24010, 24011, 49152, 49153, 49154, 49155] +# Also for gluster. +udp_ports: [111] diff --git a/inventory/group_vars/odcs_frontend b/inventory/group_vars/odcs_frontend index 7347444589..79dc77175e 100644 --- a/inventory/group_vars/odcs_frontend +++ b/inventory/group_vars/odcs_frontend @@ -1,52 +1,38 @@ --- -lvm_size: 30000 -mem_size: 2048 -num_cpus: 2 - -freezes: true - -# There vars are used to configure mod_wsgi -wsgi_procs: 2 -wsgi_threads: 2 - -tcp_ports: [ - 80, - # These ports all required for gluster - 111, 24007, 24008, 24009, 24010, 24011, - 49152, 49153, 49154, 49155, -] -# Also for gluster. -udp_ports: [ 111 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: odcs - owner: apache - group: apache - can_send: - - odcs.compose.state-changed - - -odcs_target_dir_url: https://odcs.fedoraproject.org/composes - -virt_install_command: "{{ virt_install_command_two_nic }}" - -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - -# For the MOTD -csi_security_category: Low csi_primary_contact: Factory 2 factory2-members@fedoraproject.org csi_purpose: Run the on-demand-compose-service frontend API. csi_relationship: | - The apache/mod_wsgi app is the only thing really running here + The apache/mod_wsgi app is the only thing really running here - This host: - - - relies on db01 for its database of activity (what composes have been - requested and what state are they in?) - - It also mounts an nfs shared provided by odcs-backend01. - - It provides http access to the compose contents on that nfs share. + This host: + - relies on db01 for its database of activity (what composes have been + requested and what state are they in?) + - It also mounts an nfs shared provided by odcs-backend01. + - It provides http access to the compose contents on that nfs share. +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - odcs.compose.state-changed + group: apache + owner: apache + service: odcs +freezes: true +lvm_size: 30000 +mem_size: 2048 +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 2 +odcs_target_dir_url: https://odcs.fedoraproject.org/composes +tcp_ports: [80, + # These ports all required for gluster + 111, 24007, 24008, 24009, 24010, 24011, 49152, 49153, 49154, 49155] +# Also for gluster. +udp_ports: [111] +virt_install_command: "{{ virt_install_command_two_nic }}" +# There vars are used to configure mod_wsgi +wsgi_procs: 2 +wsgi_threads: 2 diff --git a/inventory/group_vars/odcs_frontend_stg b/inventory/group_vars/odcs_frontend_stg index e927bb14ed..7cccfc1156 100644 --- a/inventory/group_vars/odcs_frontend_stg +++ b/inventory/group_vars/odcs_frontend_stg @@ -1,45 +1,32 @@ --- -lvm_size: 20000 -mem_size: 2048 -num_cpus: 2 - -# Set this to True for the F28 release and onwards. -freezes: false - -# There vars are used to configure mod_wsgi -wsgi_procs: 2 -wsgi_threads: 2 - -tcp_ports: [ - 80, - # These ports all required for gluster - 111, 24007, 24008, 24009, 24010, 24011, - 49152, 49153, 49154, 49155, -] -# Also for gluster. -udp_ports: [ 111 ] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -odcs_allowed_source_types: ["tag", "module"] - -odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes - -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" - - -# For the MOTD -csi_security_category: Low csi_primary_contact: Factory 2 factory2-members@fedoraproject.org csi_purpose: Run the on-demand-compose-service frontend API. csi_relationship: | - The apache/mod_wsgi app is the only thing really running here + The apache/mod_wsgi app is the only thing really running here - This host: - - - relies on db01 for its database of activity (what composes have been - requested and what state are they in?) - - It also mounts an nfs shared provided by odcs-backend01. - - It provides http access to the compose contents on that nfs share. + This host: + - relies on db01 for its database of activity (what composes have been + requested and what state are they in?) + - It also mounts an nfs shared provided by odcs-backend01. + - It provides http access to the compose contents on that nfs share. +# For the MOTD +csi_security_category: Low +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# Set this to True for the F28 release and onwards. +freezes: false +lvm_size: 20000 +mem_size: 2048 +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 2 +odcs_allowed_source_types: ["tag", "module"] +odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes +tcp_ports: [80, + # These ports all required for gluster + 111, 24007, 24008, 24009, 24010, 24011, 49152, 49153, 49154, 49155] +# Also for gluster. +udp_ports: [111] +# There vars are used to configure mod_wsgi +wsgi_procs: 2 +wsgi_threads: 2 diff --git a/inventory/group_vars/odcs_stg b/inventory/group_vars/odcs_stg index 4803938d95..ee076bea8c 100644 --- a/inventory/group_vars/odcs_stg +++ b/inventory/group_vars/odcs_stg @@ -1,60 +1,55 @@ +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-odcs + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-odcs + - sysadmin-releng ipa_host_group: odcs ipa_host_group_desc: On Demand Compose Service -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-odcs -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-odcs -- sysadmin-releng - -# Configs executed on releng backends must have "releng_" prefix. -odcs_raw_config_urls: - releng_fmc: - url: https://pagure.io/releng/fmc.git - config_filename: fedora-minimal-compose.conf - releng_jkaluza_test_config: - url: https://pagure.io/jkaluza-test-compose.git - config_filename: test.conf - eln: - url: https://pagure.io/pungi-fedora.git - config_filename: eln.conf - cccc: - url: https://pagure.io/fedora-ci/cccc-merged-configs.git - config_filename: cccc.conf - -# Default queues for general ODCS backends. -odcs_celery_queues: -- pungi_composes -- cleanup - -odcs_celery_router_config: - routing_rules: - odcs.server.celery_tasks.generate_pungi_compose: - releng_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "releng_.*" - eln_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "eln.*" - cccc_raw_pungi_composes: - source_type: 5 # "raw_config" - source: "cccc.*" - releng_pungi_composes: - source_type: [1, 2, 6, 7] # "tag", "module", "build", "pungi_compose" - owner: ["jkaluza", "mohanboddu", "humaton"] - cleanup_task: odcs.server.celery_tasks.run_cleanup - default_queue: pungi_composes - +odcs_allowed_clients_groups: + eln-sig: {"raw_config_keys": ["eln", "cccc"], "source_types": ["tag", "module", "build", "raw_config"]} + packager: {"source_types": ["module"]} + pungi-devel: {} + sysadmin-odcs: {} odcs_allowed_clients_users: humaton: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} - mohanboddu: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} jkaluza: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} + mohanboddu: {"source_types": ["tag", "module", "build", "raw_config"], "target_dirs": ["private"]} osbs@service: {} -odcs_allowed_clients_groups: - sysadmin-odcs: {} - pungi-devel: {} - packager: {"source_types": ["module"]} - eln-sig: {"source_types": ["tag", "module", "build", "raw_config"], "raw_config_keys": ["eln", "cccc"]} - +# Default queues for general ODCS backends. +odcs_celery_queues: + - pungi_composes + - cleanup +odcs_celery_router_config: + cleanup_task: odcs.server.celery_tasks.run_cleanup + default_queue: pungi_composes + routing_rules: + odcs.server.celery_tasks.generate_pungi_compose: + cccc_raw_pungi_composes: + source: "cccc.*" + source_type: 5 # "raw_config" + eln_raw_pungi_composes: + source: "eln.*" + source_type: 5 # "raw_config" + releng_pungi_composes: + owner: ["jkaluza", "mohanboddu", "humaton"] + source_type: [1, 2, 6, 7] # "tag", "module", "build", "pungi_compose" + releng_raw_pungi_composes: + source: "releng_.*" + source_type: 5 # "raw_config" +# Configs executed on releng backends must have "releng_" prefix. +odcs_raw_config_urls: + cccc: + config_filename: cccc.conf + url: https://pagure.io/fedora-ci/cccc-merged-configs.git + eln: + config_filename: eln.conf + url: https://pagure.io/pungi-fedora.git + releng_fmc: + config_filename: fedora-minimal-compose.conf + url: https://pagure.io/releng/fmc.git + releng_jkaluza_test_config: + config_filename: test.conf + url: https://pagure.io/jkaluza-test-compose.git diff --git a/inventory/group_vars/openqa b/inventory/group_vars/openqa index 709071778e..4c14ea06f5 100644 --- a/inventory/group_vars/openqa +++ b/inventory/group_vars/openqa @@ -1,33 +1,25 @@ # this is to enable nested virt, which we need for disk image creation -virt_install_command: "{{ virt_install_command_one_nic }} --cpu=host-passthrough,+vmx" - +deployment_type: prod external_hostname: openqa.fedoraproject.org - +freezes: false +openqa_compose_arches: x86_64,aarch64 openqa_dbname: openqa -openqa_dbuser: openqa openqa_dbpassword: "{{ prod_openqa_dbpassword }}" - -openqa_key: "{{ prod_openqa_apikey }}" -openqa_secret: "{{ prod_openqa_apisecret }}" - -openqa_webapi_plugins: FedoraMessaging FedoraUpdateRestart - +openqa_dbuser: openqa +openqa_env: production +openqa_env_prefix: # this is because openqa staging isn't really a staging host # we don't want to set env_suffix to stg on it because that may # break some other plays, but we do need the env suffix for the # fedora-messaging bits, so let's make our own openqa_env_suffix: -openqa_env_prefix: -openqa_env: production - -wikitcms_token: "{{ private }}/files/openidc/production/wikitcms.json" -openqa_wikitcms_hostname: fedoraproject.org -openqa_resultsdb_url: http://resultsdb01.iad2.fedoraproject.org/resultsdb_api/api/v2.0/ -openqa_compose_arches: x86_64,aarch64 -openqa_update_arches: ['x86_64'] - +openqa_key: "{{ prod_openqa_apikey }}" # all our workers need NFS access openqa_nfs_workers: "{{ groups['openqa_workers'] }}" - -deployment_type: prod -freezes: false +openqa_resultsdb_url: http://resultsdb01.iad2.fedoraproject.org/resultsdb_api/api/v2.0/ +openqa_secret: "{{ prod_openqa_apisecret }}" +openqa_update_arches: ['x86_64'] +openqa_webapi_plugins: FedoraMessaging FedoraUpdateRestart +openqa_wikitcms_hostname: fedoraproject.org +virt_install_command: "{{ virt_install_command_one_nic }} --cpu=host-passthrough,+vmx" +wikitcms_token: "{{ private }}/files/openidc/production/wikitcms.json" diff --git a/inventory/group_vars/openqa_lab b/inventory/group_vars/openqa_lab index 47f62a6c67..dcc7805c79 100644 --- a/inventory/group_vars/openqa_lab +++ b/inventory/group_vars/openqa_lab @@ -10,48 +10,37 @@ # be stg.fedoraproject.org # this is to enable nested virt, which we need for disk image creation -virt_install_command: "{{ virt_install_command_one_nic }} --cpu=host-passthrough,+vmx" - +deployment_type: stg external_hostname: openqa.stg.fedoraproject.org - -openqa_dbname: openqa-stg -openqa_dbuser: openqastg -openqa_dbpassword: "{{ stg_openqa_dbpassword }}" +# makes sure it sends stg not prod fedmsgs +fedmsg_env: stg +freezes: false +# FIXME: disable consumers that write to wiki until auth key +# is working again: +# https://pagure.io/fedora-infrastructure/issue/8381 +openqa_amqp_wiki_reporter_queue: openqa_assetsize_ppc: 300 - -openqa_key: "{{ stg_openqa_apikey }}" -openqa_secret: "{{ stg_openqa_apisecret }}" - -openqa_webapi_plugins: FedoraMessaging FedoraUpdateRestart - +openqa_compose_arches: x86_64,aarch64,ppc64le +openqa_dbname: openqa-stg +openqa_dbpassword: "{{ stg_openqa_dbpassword }}" +openqa_dbuser: openqastg +openqa_env: staging +openqa_env_prefix: stg- # this is because openqa staging isn't really a staging host # we don't want to set env_suffix to stg on it because that may # break some other plays, but we do need the env suffix for the # fedora-messaging bits, so let's make our own openqa_env_suffix: .stg -openqa_env_prefix: stg- -openqa_env: staging - +openqa_key: "{{ stg_openqa_apikey }}" +# all our workers need NFS access +openqa_nfs_workers: "{{ groups['openqa_lab_workers'] }}" # install openQA from updates-testing - this is staging, we live # ON THE EDGE (radical guitar riff) openqa_repo: updates-testing - -wikitcms_token: "{{ private }}/files/openidc/staging/wikitcms.json" -openqa_wikitcms_hostname: stg.fedoraproject.org openqa_resultsdb_url: http://resultsdb01.stg.iad2.fedoraproject.org/resultsdb_api/api/v2.0/ -openqa_compose_arches: x86_64,aarch64,ppc64le +openqa_secret: "{{ stg_openqa_apisecret }}" openqa_update_arches: ['x86_64', 'ppc64le'] - -# all our workers need NFS access -openqa_nfs_workers: "{{ groups['openqa_lab_workers'] }}" - -# FIXME: disable consumers that write to wiki until auth key -# is working again: -# https://pagure.io/fedora-infrastructure/issue/8381 -openqa_amqp_wiki_reporter_queue: - -deployment_type: stg -freezes: false - -# makes sure it sends stg not prod fedmsgs -fedmsg_env: stg +openqa_webapi_plugins: FedoraMessaging FedoraUpdateRestart +openqa_wikitcms_hostname: stg.fedoraproject.org +virt_install_command: "{{ virt_install_command_one_nic }} --cpu=host-passthrough,+vmx" +wikitcms_token: "{{ private }}/files/openidc/staging/wikitcms.json" diff --git a/inventory/group_vars/openqa_lab_workers b/inventory/group_vars/openqa_lab_workers index d92c1e1876..2de4f878e1 100644 --- a/inventory/group_vars/openqa_lab_workers +++ b/inventory/group_vars/openqa_lab_workers @@ -1,31 +1,26 @@ +deployment_type: stg +freezes: false gw: 10.3.174.254 -openqa_workers: 4 -openqa_hostname: openqa-lab01.iad2.fedoraproject.org -openqa_key: "{{ stg_openqa_apikey }}" -openqa_secret: "{{ stg_openqa_apisecret }}" - +ipa_client_shell_groups: + - sysadmin-qa +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: openqa-lab-workers +ipa_host_group_desc: OpenQA Lab worker hosts +openqa_env: staging +openqa_env_prefix: stg- # this is because openqa staging isn't really a staging host # we don't want to set env_suffix to stg on it because that may # break some other plays, but we do need the env suffix for the # fedora-messaging bits, so let's make our own openqa_env_suffix: .stg -openqa_env_prefix: stg- -openqa_env: staging - +openqa_hostname: openqa-lab01.iad2.fedoraproject.org +openqa_key: "{{ stg_openqa_apikey }}" +# we are all NFS workers for now at least +openqa_nfs_worker: true # install openQA and os-autoinst from updates-testing - this is # staging, we live ON THE EDGE (radical guitar riff) openqa_repo: updates-testing - -# we are all NFS workers for now at least -openqa_nfs_worker: true - -deployment_type: stg -freezes: false - +openqa_secret: "{{ stg_openqa_apisecret }}" +openqa_workers: 4 primary_auth_source: ipa -ipa_host_group: openqa-lab-workers -ipa_host_group_desc: OpenQA Lab worker hosts -ipa_client_shell_groups: -- sysadmin-qa -ipa_client_sudo_groups: -- sysadmin-qa diff --git a/inventory/group_vars/openqa_servers_common b/inventory/group_vars/openqa_servers_common index 8199ffc186..f3da9da35b 100644 --- a/inventory/group_vars/openqa_servers_common +++ b/inventory/group_vars/openqa_servers_common @@ -2,71 +2,57 @@ # openQA servers. these are mostly things that are set as variables # in the plays so we can change them over time and also so the plays # can be used for non-infra deployments. - -openqa_hostname: localhost -openqa_email: adamwill@fedoraproject.org -openqa_nickname: adamwill -openqa_fullname: Adam Williamson -openqa_userid: http://adamwill.id.fedoraproject.org/ - -openqa_assetsize: 500 -openqa_assetsize_aarch64: 300 -openqa_assetsize_updates: 200 - -# stg and prod use the same database server -openqa_dbhost: db-openqa01.iad2.fedoraproject.org - +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-qa + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: openqa-servers +ipa_host_group_desc: OpenQA servers +# fedora-messaging email error reporting settings +openqa_amqp_mailto: ["adamwill@fedoraproject.org", "lruzicka@fedoraproject.org"] # we need this for all our fedora-messaging consumers as they are not # allowed to create queues on the infra AMQP broker, by broker config openqa_amqp_passive: true - -# fedora-messaging publisher settings -openqa_amqp_publisher_prefix: org.fedoraproject.{{ fedmsg_env }} -openqa_amqp_publisher_url: "amqps://openqa{{ openqa_env_suffix }}:@rabbitmq{{ openqa_env_suffix }}.fedoraproject.org/%2Fpubsub" # openQA isn't very ssl-aware here, so we're abusing its URL construction # to stuff the cert and key values in here openqa_amqp_publisher_exchange: "amq.topic&cacertfile=/etc/fedora-messaging/{{ openqa_env_prefix }}cacert.pem&certfile=/etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-cert.pem&keyfile=/etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-key.pem" - +# fedora-messaging publisher settings +openqa_amqp_publisher_prefix: org.fedoraproject.{{ fedmsg_env }} +openqa_amqp_publisher_url: "amqps://openqa{{ openqa_env_suffix }}:@rabbitmq{{ openqa_env_suffix }}.fedoraproject.org/%2Fpubsub" +openqa_amqp_reporter_cacert: /etc/fedora-messaging/{{ openqa_env_prefix }}cacert.pem +openqa_amqp_reporter_cert: /etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-cert.pem +openqa_amqp_reporter_key: /etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-key.pem +# fedora-messaging reporter settings +openqa_amqp_reporter_url: "amqps://openqa{{ openqa_env_suffix }}:@rabbitmq{{ openqa_env_suffix }}.fedoraproject.org/%2Fpubsub" +# fedora-messaging resultsdb reporter settings +openqa_amqp_resultsdb_reporter_queue: "openqa{{ openqa_env_suffix }}_resultsdb_reporter" +openqa_amqp_resultsdb_reporter_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"] +openqa_amqp_scheduler_cacert: /etc/fedora-messaging/cacert.pem +openqa_amqp_scheduler_cert: /etc/pki/fedora-messaging/openqa-cert.pem +openqa_amqp_scheduler_key: /etc/pki/fedora-messaging/openqa-key.pem +openqa_amqp_scheduler_queue: "openqa{{ openqa_env_suffix }}_scheduler" +openqa_amqp_scheduler_routing_keys: ["org.fedoraproject.prod.pungi.compose.status.change", "org.fedoraproject.prod.bodhi.update.request.testing", "org.fedoraproject.prod.bodhi.update.edit"] # fedora-messaging job scheduler settings: most of these are the same # for prod and stg as they both must listen for prod messages. Only # the queue names differs openqa_amqp_scheduler_url: "amqps://openqa:@rabbitmq.fedoraproject.org/%2Fpubsub" -openqa_amqp_scheduler_cacert: /etc/fedora-messaging/cacert.pem -openqa_amqp_scheduler_key: /etc/pki/fedora-messaging/openqa-key.pem -openqa_amqp_scheduler_cert: /etc/pki/fedora-messaging/openqa-cert.pem -openqa_amqp_scheduler_queue: "openqa{{ openqa_env_suffix }}_scheduler" -openqa_amqp_scheduler_routing_keys: ["org.fedoraproject.prod.pungi.compose.status.change", - "org.fedoraproject.prod.bodhi.update.request.testing", - "org.fedoraproject.prod.bodhi.update.edit"] - -# fedora-messaging reporter settings -openqa_amqp_reporter_url: "amqps://openqa{{ openqa_env_suffix }}:@rabbitmq{{ openqa_env_suffix }}.fedoraproject.org/%2Fpubsub" -openqa_amqp_reporter_cacert: /etc/fedora-messaging/{{ openqa_env_prefix }}cacert.pem -openqa_amqp_reporter_key: /etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-key.pem -openqa_amqp_reporter_cert: /etc/pki/fedora-messaging/openqa{{ openqa_env_suffix }}-cert.pem - -# fedora-messaging resultsdb reporter settings -openqa_amqp_resultsdb_reporter_queue: "openqa{{ openqa_env_suffix }}_resultsdb_reporter" -openqa_amqp_resultsdb_reporter_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"] - +openqa_amqp_smtp: bastion # fedora-messaging wiki reporter settings openqa_amqp_wiki_reporter_queue: "openqa{{ openqa_env_suffix }}_wiki_reporter" openqa_amqp_wiki_reporter_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"] - -# fedora-messaging email error reporting settings -openqa_amqp_mailto: ["adamwill@fedoraproject.org", "lruzicka@fedoraproject.org"] -openqa_amqp_smtp: bastion - +openqa_assetsize: 500 +openqa_assetsize_aarch64: 300 +openqa_assetsize_updates: 200 +# stg and prod use the same database server +openqa_dbhost: db-openqa01.iad2.fedoraproject.org +openqa_email: adamwill@fedoraproject.org +openqa_fullname: Adam Williamson +openqa_hostname: localhost +openqa_nickname: adamwill +openqa_userid: http://adamwill.id.fedoraproject.org/ +primary_auth_source: ipa # http and NFS tcp_ports: [80, 2049] - -primary_auth_source: ipa -ipa_host_group: openqa-servers -ipa_host_group_desc: OpenQA servers -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-qa -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-qa diff --git a/inventory/group_vars/openqa_tap_workers b/inventory/group_vars/openqa_tap_workers index 95e1cde731..8976c6f9e5 100644 --- a/inventory/group_vars/openqa_tap_workers +++ b/inventory/group_vars/openqa_tap_workers @@ -1,17 +1,10 @@ -openqa_tap: true - +# firewall rules to allow openQA openvswitch guests to communicate +# uses interface definition from host vars +custom_rules: ['-A FORWARD -i br0 -j ACCEPT', '-A FORWARD -m state -i {{ openqa_tap_iface }} -o br0 --state RELATED,ESTABLISHED -j ACCEPT', '-A INPUT -i br0 -j ACCEPT'] # for iptables rules...maybe other stuff in future? both staging # and prod workers are in this group host_group: openqa-tap-workers - -# firewall rules to allow openQA openvswitch guests to communicate -# uses interface definition from host vars -custom_rules: [ - '-A FORWARD -i br0 -j ACCEPT', - '-A FORWARD -m state -i {{ openqa_tap_iface }} -o br0 --state RELATED,ESTABLISHED -j ACCEPT', - '-A INPUT -i br0 -j ACCEPT' -] nat_rules: [ - # masquerade for openQA openvswitch workers to reach the outside - '-A POSTROUTING -o {{ openqa_tap_iface }} -j MASQUERADE' - ] + # masquerade for openQA openvswitch workers to reach the outside + '-A POSTROUTING -o {{ openqa_tap_iface }} -j MASQUERADE'] +openqa_tap: true diff --git a/inventory/group_vars/openqa_workers b/inventory/group_vars/openqa_workers index 5ec254a2a2..ae6fe400e7 100644 --- a/inventory/group_vars/openqa_workers +++ b/inventory/group_vars/openqa_workers @@ -1,27 +1,23 @@ +deployment_type: prod +freezes: false gw: 10.5.124.254 -openqa_workers: 4 -openqa_hostname: openqa01.iad2.fedoraproject.org -openqa_key: "{{ prod_openqa_apikey }}" -openqa_secret: "{{ prod_openqa_apisecret }}" - +ipa_client_shell_groups: + - sysadmin-qa +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: openqa-workers +ipa_host_group_desc: OpenQA worker hosts +openqa_env: production +openqa_env_prefix: # this is because openqa staging isn't really a staging host # we don't want to set env_suffix to stg on it because that may # break some other plays, but we do need the env suffix for the # fedora-messaging bits, so let's make our own openqa_env_suffix: -openqa_env_prefix: -openqa_env: production - +openqa_hostname: openqa01.iad2.fedoraproject.org +openqa_key: "{{ prod_openqa_apikey }}" # we are all NFS workers for now at least openqa_nfs_worker: true - -deployment_type: prod -freezes: false - +openqa_secret: "{{ prod_openqa_apisecret }}" +openqa_workers: 4 primary_auth_source: ipa -ipa_host_group: openqa-workers -ipa_host_group_desc: OpenQA worker hosts -ipa_client_shell_groups: -- sysadmin-qa -ipa_client_sudo_groups: -- sysadmin-qa diff --git a/inventory/group_vars/openstack_compute b/inventory/group_vars/openstack_compute index f770f40e8e..50cbe748eb 100644 --- a/inventory/group_vars/openstack_compute +++ b/inventory/group_vars/openstack_compute @@ -1,6 +1,6 @@ --- -host_group: openstack-compute -nrpe_procs_warn: 1100 -nrpe_procs_crit: 1200 ansible_ifcfg_blocklist: true baseiptables: False +host_group: openstack-compute +nrpe_procs_crit: 1200 +nrpe_procs_warn: 1100 diff --git a/inventory/group_vars/os b/inventory/group_vars/os index 4601e8161f..eeabe8ea01 100644 --- a/inventory/group_vars/os +++ b/inventory/group_vars/os @@ -1,13 +1,12 @@ --- -host_group: os baseiptables: False -no_http2: True -nm_controlled_resolv: True +host_group: os +ipa_client_shell_groups: + - sysadmin-openshift +ipa_client_sudo_groups: + - sysadmin-openshift #openshift_ansible_upgrading: False ipa_host_group: openshift ipa_host_group_desc: OpenShift cluster - -ipa_client_shell_groups: -- sysadmin-openshift -ipa_client_sudo_groups: -- sysadmin-openshift +nm_controlled_resolv: True +no_http2: True diff --git a/inventory/group_vars/os_control b/inventory/group_vars/os_control index cd55a7ced5..32c032a32a 100644 --- a/inventory/group_vars/os_control +++ b/inventory/group_vars/os_control @@ -1,5 +1,3 @@ --- - -os_url: os.fedoraproject.org os_app_url: app.os.fedoraproject.org - +os_url: os.fedoraproject.org diff --git a/inventory/group_vars/os_control_stg b/inventory/group_vars/os_control_stg index 7394cd849b..bb10ecbd01 100644 --- a/inventory/group_vars/os_control_stg +++ b/inventory/group_vars/os_control_stg @@ -1,5 +1,3 @@ --- - -os_url: os.stg.fedoraproject.org os_app_url: app.os.stg.fedoraproject.org - +os_url: os.stg.fedoraproject.org diff --git a/inventory/group_vars/os_masters b/inventory/group_vars/os_masters index 19160c9d8b..1a34f53cbb 100644 --- a/inventory/group_vars/os_masters +++ b/inventory/group_vars/os_masters @@ -1,29 +1,26 @@ --- - -os_url: os.fedoraproject.org -os_app_url: app.os.fedoraproject.org -swap: false -nagios_Check_Services: - swap: false - nrpe: false - mail: false - +bodhi_openshift_pods: 1 # # Set some bodhi variables here. # Since they are used when running playbooks against the master nodes. # bodhi_version: "5.7.1" -bodhi_openshift_pods: 1 - +nagios_Check_Services: + mail: false + nrpe: false + swap: false +os_app_url: app.os.fedoraproject.org +os_url: os.fedoraproject.org # GDPR SAR related dictionary sar_openshift: # Name of the app release-monitoring: - # Location of the script - sar_script: /usr/local/bin/sar.py - # Output file on local machine - sar_output_file: anitya.json # Openshift namespace where the app runs openshift_namespace: release-monitoring # Name of openshift pod - will be used for label search openshift_pod: release-monitoring-web + # Output file on local machine + sar_output_file: anitya.json + # Location of the script + sar_script: /usr/local/bin/sar.py +swap: false diff --git a/inventory/group_vars/os_masters_stg b/inventory/group_vars/os_masters_stg index 77656d5cfa..bb9d3a2fb2 100644 --- a/inventory/group_vars/os_masters_stg +++ b/inventory/group_vars/os_masters_stg @@ -1,15 +1,12 @@ --- - -os_url: os.stg.fedoraproject.org -os_app_url: app.os.stg.fedoraproject.org - -nagios_Check_Services: - swap: false - nrpe: false - mail: false - +bodhi_openshift_pods: 1 # Set some bodhi variables here. # Since they are used when running playbooks against the master nodes. # bodhi_version: "5.7.1" -bodhi_openshift_pods: 1 +nagios_Check_Services: + mail: false + nrpe: false + swap: false +os_app_url: app.os.stg.fedoraproject.org +os_url: os.stg.fedoraproject.org diff --git a/inventory/group_vars/os_nodes b/inventory/group_vars/os_nodes index 16298ca729..7e7df732cb 100644 --- a/inventory/group_vars/os_nodes +++ b/inventory/group_vars/os_nodes @@ -1,9 +1,8 @@ --- - -os_url: os.fedoraproject.org -os_app_url: app.os.fedoraproject.org -swap: false nagios_Check_Services: - swap: false - nrpe: false mail: false + nrpe: false + swap: false +os_app_url: app.os.fedoraproject.org +os_url: os.fedoraproject.org +swap: false diff --git a/inventory/group_vars/os_nodes_stg b/inventory/group_vars/os_nodes_stg index 661aafd42b..891bdafa1f 100644 --- a/inventory/group_vars/os_nodes_stg +++ b/inventory/group_vars/os_nodes_stg @@ -1,9 +1,7 @@ --- - -os_url: os.stg.fedoraproject.org -os_app_url: app.os.stg.fedoraproject.org - nagios_Check_Services: - swap: false - nrpe: false mail: false + nrpe: false + swap: false +os_app_url: app.os.stg.fedoraproject.org +os_url: os.stg.fedoraproject.org diff --git a/inventory/group_vars/os_proxies b/inventory/group_vars/os_proxies index c75d4ce5b3..d5f013fc9a 100644 --- a/inventory/group_vars/os_proxies +++ b/inventory/group_vars/os_proxies @@ -1,24 +1,18 @@ --- +custom_rules: [ + # Needed for keepalived + '-A INPUT -d 224.0.0.0/8 -j ACCEPT', '-A INPUT -p vrrp -j ACCEPT', + # machinectl api + '-A INPUT -p tcp --dport 22623 --src 38.145.48.0/27 -j ACCEPT'] datacenter: cloud host_group: cloud lvm_size: 20000 mem_size: 8192 num_cpus: 4 - tcp_ports: [ - # For os routers - 80, - 443, - # For ks8 api - 6443, - # For haproxy status - 8080, -] - -custom_rules: [ - # Needed for keepalived - '-A INPUT -d 224.0.0.0/8 -j ACCEPT', - '-A INPUT -p vrrp -j ACCEPT', - # machinectl api - '-A INPUT -p tcp --dport 22623 --src 38.145.48.0/27 -j ACCEPT', -] + # For os routers + 80, 443, + # For ks8 api + 6443, + # For haproxy status + 8080] diff --git a/inventory/group_vars/os_stg b/inventory/group_vars/os_stg index 8a6c253899..5679d1358d 100644 --- a/inventory/group_vars/os_stg +++ b/inventory/group_vars/os_stg @@ -1,14 +1,13 @@ --- -host_group: os baseiptables: False -no_http2: False -nm_controlled_resolv: True +host_group: os +ipa_client_shell_groups: + - sysadmin-openshift +ipa_client_sudo_groups: + - sysadmin-openshift # Only define this when upgrading, otherwise comment it # openshift_ansible_upgrading: True ipa_host_group: openshift ipa_host_group_desc: OpenShift cluster - -ipa_client_shell_groups: -- sysadmin-openshift -ipa_client_sudo_groups: -- sysadmin-openshift +nm_controlled_resolv: True +no_http2: False diff --git a/inventory/group_vars/osbs b/inventory/group_vars/osbs index a6caceeff1..a69e42dd90 100644 --- a/inventory/group_vars/osbs +++ b/inventory/group_vars/osbs @@ -1,47 +1,36 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -num_cpus: 2 - -tcp_ports: [ 80, 443, 8443] - -sudoers: "{{ private }}/files/sudo/osbs-sudoers" - -primary_auth_source: ipa -ipa_host_group: osbs -ipa_host_group_desc: OpenShift Build Service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-osbs -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-osbs -- sysadmin-releng - +baseiptables: False docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org" docker_registry: "candidate-registry.fedoraproject.org" -source_registry: "registry.fedoraproject.org" - -osbs_url: "osbs.fedoraproject.org" -osbs_koji_username: "kojibuilder" - +# fedora container images required by buildroot +fedora_required_images: + - "fedora:latest" +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-osbs + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-osbs + - sysadmin-releng +ipa_host_group: osbs +ipa_host_group_desc: OpenShift Build Service koji_url: "koji.fedoraproject.org" - -osbs_client_conf_path: /etc/osbs.conf - -baseiptables: False - +lvm_size: 60000 +mem_size: 8192 +nm_controlled_resolv: True +num_cpus: 2 #openshift_ansible_upgrading: True # docker images required by OpenShift Origin openshift_required_images: - "openshift/origin-pod" - -# fedora container images required by buildroot -fedora_required_images: - - "fedora:latest" - -nm_controlled_resolv: True +osbs_client_conf_path: /etc/osbs.conf +osbs_koji_username: "kojibuilder" +osbs_url: "osbs.fedoraproject.org" +primary_auth_source: ipa +source_registry: "registry.fedoraproject.org" +sudoers: "{{ private }}/files/sudo/osbs-sudoers" +tcp_ports: [80, 443, 8443] diff --git a/inventory/group_vars/osbs_aarch64_masters b/inventory/group_vars/osbs_aarch64_masters index dea0441594..71a875c6d7 100644 --- a/inventory/group_vars/osbs_aarch64_masters +++ b/inventory/group_vars/osbs_aarch64_masters @@ -1,58 +1,42 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 -max_cpu: "{{ num_cpus }}" -virt_install_command: "{{ virt_install_command_aarch64_one_nic }}" - -tcp_ports: [ 80, 443, 8443] - -openshift_node_labels: {'region':'infra'} -openshift_schedulable: False - +#Docker command delegated host +composer: compose-x86-01.iad2.fedoraproject.org docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org" -source_registry: "registry.fedoraproject.org" docker_registry: "candidate-registry.fedoraproject.org" - -osbs_url: "osbs.fedoraproject.org" - koji_url: "koji.fedoraproject.org" - +lvm_size: 60000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 8192 +# Nagios configuration +nagios_Check_Services: + dhcpd: false + httpd: false + named: false + nrpe: true + sshd: true + swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'infra'} +openshift_schedulable: False osbs_client_conf_path: /etc/osbs.conf - -osbs_namespace: "osbs-fedora" -osbs_worker_namespace: worker - -osbs_worker_service_accounts: - - orchestrator - - builder - - -osbs_conf_sources_command: fedpkg sources - -osbs_orchestrator_cpu_limitrange: "95m" - -osbs_worker_default_nodeselector: "worker=true" -osbs_orchestrator_default_nodeselector: "orchestrator=true" - -osbs_conf_service_accounts: - - koji - - builder - osbs_conf_readwrite_users: - "system:serviceaccount:{{ osbs_namespace }}:default" - "system:serviceaccount:{{ osbs_namespace }}:builder" - -#Docker command delegated host -composer: compose-x86-01.iad2.fedoraproject.org - -# Nagios configuration -nagios_Check_Services: - nrpe: true - sshd: true - named: false - dhcpd: false - httpd: false - swap: false +osbs_conf_service_accounts: + - koji + - builder +osbs_conf_sources_command: fedpkg sources +osbs_namespace: "osbs-fedora" +osbs_orchestrator_cpu_limitrange: "95m" +osbs_orchestrator_default_nodeselector: "orchestrator=true" +osbs_url: "osbs.fedoraproject.org" +osbs_worker_default_nodeselector: "worker=true" +osbs_worker_namespace: worker +osbs_worker_service_accounts: + - orchestrator + - builder +source_registry: "registry.fedoraproject.org" +tcp_ports: [80, 443, 8443] +virt_install_command: "{{ virt_install_command_aarch64_one_nic }}" diff --git a/inventory/group_vars/osbs_aarch64_masters_stg b/inventory/group_vars/osbs_aarch64_masters_stg index d8df2ef5a8..87497fb7c1 100644 --- a/inventory/group_vars/osbs_aarch64_masters_stg +++ b/inventory/group_vars/osbs_aarch64_masters_stg @@ -1,58 +1,42 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 -max_cpu: "{{ num_cpus }}" -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - -tcp_ports: [ 80, 443, 8443] - -openshift_node_labels: {'region':'infra'} -openshift_schedulable: False - +#Docker command delegated host +composer: compose-x86-01.stg.iad2.fedoraproject.org docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org" -source_registry: "registry.stg.fedoraproject.org" docker_registry: "candidate-registry.stg.fedoraproject.org" - -osbs_url: "osbs.stg.fedoraproject.org" - koji_url: "koji.stg.fedoraproject.org" - +lvm_size: 60000 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 8192 +# Nagios configuration +nagios_Check_Services: + dhcpd: false + httpd: false + named: false + nrpe: true + sshd: true + swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'infra'} +openshift_schedulable: False osbs_client_conf_path: /etc/osbs.conf - -osbs_namespace: "osbs-fedora" -osbs_worker_namespace: worker - -osbs_worker_service_accounts: - - orchestrator - - builder - - -osbs_conf_sources_command: fedpkg sources - -osbs_orchestrator_cpu_limitrange: "95m" - -osbs_worker_default_nodeselector: "worker=true" -osbs_orchestrator_default_nodeselector: "orchestrator=true" - -osbs_conf_service_accounts: - - koji - - builder - osbs_conf_readwrite_users: - "system:serviceaccount:{{ osbs_namespace }}:default" - "system:serviceaccount:{{ osbs_namespace }}:builder" - -#Docker command delegated host -composer: compose-x86-01.stg.iad2.fedoraproject.org - -# Nagios configuration -nagios_Check_Services: - nrpe: true - sshd: true - named: false - dhcpd: false - httpd: false - swap: false +osbs_conf_service_accounts: + - koji + - builder +osbs_conf_sources_command: fedpkg sources +osbs_namespace: "osbs-fedora" +osbs_orchestrator_cpu_limitrange: "95m" +osbs_orchestrator_default_nodeselector: "orchestrator=true" +osbs_url: "osbs.stg.fedoraproject.org" +osbs_worker_default_nodeselector: "worker=true" +osbs_worker_namespace: worker +osbs_worker_service_accounts: + - orchestrator + - builder +source_registry: "registry.stg.fedoraproject.org" +tcp_ports: [80, 443, 8443] +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" diff --git a/inventory/group_vars/osbs_aarch64_node b/inventory/group_vars/osbs_aarch64_node index 25e2b11f3a..93bba6917d 100644 --- a/inventory/group_vars/osbs_aarch64_node +++ b/inventory/group_vars/osbs_aarch64_node @@ -1,20 +1,17 @@ --- # Define resources for this group of hosts here. lvm_size: 60000 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 max_cpu: "{{ num_cpus }}" -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - -tcp_ports: [ 80, 443, 8443, 10250] - -openshift_node_labels: {'region': 'primary', 'zone': 'default'} - +max_mem_size: "{{ mem_size }}" +mem_size: 8192 nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'primary', 'zone': 'default'} +tcp_ports: [80, 443, 8443, 10250] +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" diff --git a/inventory/group_vars/osbs_aarch64_nodes b/inventory/group_vars/osbs_aarch64_nodes index 25e2b11f3a..93bba6917d 100644 --- a/inventory/group_vars/osbs_aarch64_nodes +++ b/inventory/group_vars/osbs_aarch64_nodes @@ -1,20 +1,17 @@ --- # Define resources for this group of hosts here. lvm_size: 60000 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 max_cpu: "{{ num_cpus }}" -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - -tcp_ports: [ 80, 443, 8443, 10250] - -openshift_node_labels: {'region': 'primary', 'zone': 'default'} - +max_mem_size: "{{ mem_size }}" +mem_size: 8192 nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'primary', 'zone': 'default'} +tcp_ports: [80, 443, 8443, 10250] +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" diff --git a/inventory/group_vars/osbs_aarch64_nodes_stg b/inventory/group_vars/osbs_aarch64_nodes_stg index 25e2b11f3a..93bba6917d 100644 --- a/inventory/group_vars/osbs_aarch64_nodes_stg +++ b/inventory/group_vars/osbs_aarch64_nodes_stg @@ -1,20 +1,17 @@ --- # Define resources for this group of hosts here. lvm_size: 60000 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 max_cpu: "{{ num_cpus }}" -virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" - -tcp_ports: [ 80, 443, 8443, 10250] - -openshift_node_labels: {'region': 'primary', 'zone': 'default'} - +max_mem_size: "{{ mem_size }}" +mem_size: 8192 nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'primary', 'zone': 'default'} +tcp_ports: [80, 443, 8443, 10250] +virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" diff --git a/inventory/group_vars/osbs_control b/inventory/group_vars/osbs_control index 0910ee6999..d9e8269880 100644 --- a/inventory/group_vars/osbs_control +++ b/inventory/group_vars/osbs_control @@ -1,15 +1,13 @@ --- # Define resources for this group of hosts here. -sudoers: "{{ private }}/files/sudo/osbs-sudoers" - -# Variables used in the ansible-ansible-openshift-ansible role in osbs-cluster playbook -osbs_url: "osbs.fedoraproject.org" -inventory_filename: "cluster-inventory" -cluster_masters_group: "osbs_masters" -cluster_nodes_group: "osbs_nodes" -cluster_infra_group: "osbs_masters" - +aarch_infra_group: "osbs_aarch64_masters" # Aarch64 variables aarch_masters_group: "osbs_aarch64_masters" aarch_nodes_group: "osbs_aarch64_nodes" -aarch_infra_group: "osbs_aarch64_masters" +cluster_infra_group: "osbs_masters" +cluster_masters_group: "osbs_masters" +cluster_nodes_group: "osbs_nodes" +inventory_filename: "cluster-inventory" +# Variables used in the ansible-ansible-openshift-ansible role in osbs-cluster playbook +osbs_url: "osbs.fedoraproject.org" +sudoers: "{{ private }}/files/sudo/osbs-sudoers" diff --git a/inventory/group_vars/osbs_control_stg b/inventory/group_vars/osbs_control_stg index faca721a34..5ac199e9cd 100644 --- a/inventory/group_vars/osbs_control_stg +++ b/inventory/group_vars/osbs_control_stg @@ -2,13 +2,12 @@ # Define resources for this group of hosts here. # Variables used in the ansible-ansible-openshift-ansible role in osbs-cluster playbook -osbs_url: "osbs.stg.fedoraproject.org" -inventory_filename: "cluster-inventory-stg" -cluster_masters_group: "osbs_masters_stg" -cluster_nodes_group: "osbs_nodes_stg" -cluster_infra_group: "osbs_masters_stg" - +aarch_infra_group: "osbs_aarch64_masters_stg" # Aarch64 variables aarch_masters_group: "osbs_aarch64_masters_stg" aarch_nodes_group: "osbs_aarch64_nodes_stg" -aarch_infra_group: "osbs_aarch64_masters_stg" +cluster_infra_group: "osbs_masters_stg" +cluster_masters_group: "osbs_masters_stg" +cluster_nodes_group: "osbs_nodes_stg" +inventory_filename: "cluster-inventory-stg" +osbs_url: "osbs.stg.fedoraproject.org" diff --git a/inventory/group_vars/osbs_masters b/inventory/group_vars/osbs_masters index 669b19f21f..67e31ecd63 100644 --- a/inventory/group_vars/osbs_masters +++ b/inventory/group_vars/osbs_masters @@ -1,176 +1,134 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -num_cpus: 2 - -tcp_ports: [ 80, 443, 8443] - -docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org" -source_registry: "registry.fedoraproject.org" -docker_registry: "candidate-registry.fedoraproject.org" - -osbs_url: "osbs.fedoraproject.org" -osbs_koji_username: "kojibuilder" - -koji_url: "koji.fedoraproject.org" - -osbs_client_conf_path: /etc/osbs.conf - -openshift_node_labels: {'region':'infra'} -openshift_schedulable: False - -osbs_namespace: "osbs-fedora" -osbs_worker_namespace: worker - -osbs_worker_service_accounts: - - orchestrator - - builder - - -osbs_conf_sources_command: fedpkg sources - -osbs_orchestrator_cpu_limitrange: "95m" - -osbs_worker_default_nodeselector: "worker=true" -osbs_orchestrator_default_nodeselector: "orchestrator=true" - -osbs_conf_service_accounts: - - koji - - builder - -osbs_conf_readwrite_users: - - "system:serviceaccount:{{ osbs_namespace }}:default" - - "system:serviceaccount:{{ osbs_namespace }}:builder" - -osbs_conf_worker_clusters: - x86_64: - - name: x86_64 - max_concurrent_builds: 2 - openshift_url: "https://osbs.fedoraproject.org/" - verify_ssl: 'false' - - aarch64: - - name: aarch64 - max_concurrent_builds: 1 - openshift_url: "https://osbs-aarch64-master01.iad2.fedoraproject.org:8443/" - verify_ssl: 'false' - - -osbs_platform_descriptors: -- platform: x86_64 - architecture: amd64 - -- platform: aarch64 - architecture: arm64 - _osbs_reactor_config_map: - version: 1 + artifacts_allowed_domains: [] + #- download.devel.redhat.com/released + #- download.devel.redhat.com/devel/candidates - clusters: - x86_64: - - name: "x86_64" - max_concurrent_builds: 2 - enabled: True - - aarch64: - - name: "aarch64" + clusters: + aarch64: + - enabled: True max_concurrent_builds: 1 - enabled: True - - clusters_client_config_dir: "/var/run/secrets/atomic-reactor/client-config-secret" - - koji: - hub_url: "https://koji{{ env_suffix }}.fedoraproject.org/kojihub" - root_url: "https://koji{{ env_suffix }}.fedoraproject.org/" - auth: - krb_principal: "osbs/{{osbs_url}}@{{ ipa_realm }}" - krb_keytab_path: "FILE:/etc/krb5.osbs_{{ osbs_url }}.keytab" - - odcs: - api_url: "https://odcs{{ env_suffix }}.fedoraproject.org/api/1" - auth: - openidc_dir: "/var/run/secrets/atomic-reactor/odcs-oidc-secret" - signing_intents: - - name: unsigned - keys: [] - default_signing_intent: "unsigned" - - flatpak: - base_image: "registry.fedoraproject.org/flatpak-build-base:latest" - metadata: both - - image_labels: - vendor: "Fedora Project" - authoritative-source-url: "{{ source_registry }}" - distribution-scope: public - - image_equal_labels: - - ['description', 'io.k8s.description'] - openshift: - url: "https://{{ osbs_url }}" - insecure: true - build_json_dir: /usr/share/osbs - auth: - enable: True - - platform_descriptors: "{{ osbs_platform_descriptors }}" - - prefer_schema1_digest: False - - content_versions: + name: "aarch64" + x86_64: + - enabled: True + max_concurrent_builds: 2 + name: "x86_64" + clusters_client_config_dir: "/var/run/secrets/atomic-reactor/client-config-secret" + content_versions: - v2 - - registries: - - url: https://candidate-registry.fedoraproject.org/v2 - auth: + flatpak: + base_image: "registry.fedoraproject.org/flatpak-build-base:latest" + metadata: both + group_manifests: True + image_equal_labels: + - ['description', 'io.k8s.description'] + image_labels: + authoritative-source-url: "{{ source_registry }}" + distribution-scope: public + vendor: "Fedora Project" + koji: + auth: + krb_keytab_path: "FILE:/etc/krb5.osbs_{{ osbs_url }}.keytab" + krb_principal: "osbs/{{osbs_url}}@{{ ipa_realm }}" + hub_url: "https://koji{{ env_suffix }}.fedoraproject.org/kojihub" + root_url: "https://koji{{ env_suffix }}.fedoraproject.org/" + odcs: + api_url: "https://odcs{{ env_suffix }}.fedoraproject.org/api/1" + auth: + openidc_dir: "/var/run/secrets/atomic-reactor/odcs-oidc-secret" + default_signing_intent: "unsigned" + signing_intents: + - keys: [] + name: unsigned + openshift: + auth: + enable: True + build_json_dir: /usr/share/osbs + insecure: true + url: "https://{{ osbs_url }}" + platform_descriptors: "{{ osbs_platform_descriptors }}" + prefer_schema1_digest: False + registries: + - auth: cfg_path: /var/run/secrets/atomic-reactor/v2-registry-dockercfg - - source_registry: - url: "{{ source_registry }}" - insecure: True - - group_manifests: True - - sources_command: "{{ osbs_conf_sources_command }}" - - artifacts_allowed_domains: [] - #- download.devel.redhat.com/released - #- download.devel.redhat.com/devel/candidates - - required_secrets: + url: https://candidate-registry.fedoraproject.org/v2 + required_secrets: - v2-registry-dockercfg - odcs-oidc-secret - - worker_token_secrets: + skip_koji_check_for_base_image: True + source_registry: + insecure: True + url: "{{ source_registry }}" + sources_command: "{{ osbs_conf_sources_command }}" + version: 1 + worker_token_secrets: - x86-64-orchestrator - aarch64-orchestrator - client-config-secret - - skip_koji_check_for_base_image: True - _osbs_scratch_reactor_config_map_overrides: image_labels: distribution-scope: private - -osbs_reactor_config_maps: -- name: reactor-config-map - data: "{{ _osbs_reactor_config_map }}" -- name: reactor-config-map-scratch - data: > - {{ _osbs_reactor_config_map | - combine(_osbs_scratch_reactor_config_map_overrides, recursive=True) }} - -osbs_odcs_enabled: true - #Docker command delegated host composer: compose-x86-01.iad2.fedoraproject.org - +docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org" +docker_registry: "candidate-registry.fedoraproject.org" +koji_url: "koji.fedoraproject.org" +lvm_size: 60000 +mem_size: 8192 # Nagios configuration nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'infra'} +openshift_schedulable: False +osbs_client_conf_path: /etc/osbs.conf +osbs_conf_readwrite_users: + - "system:serviceaccount:{{ osbs_namespace }}:default" + - "system:serviceaccount:{{ osbs_namespace }}:builder" +osbs_conf_service_accounts: + - koji + - builder +osbs_conf_sources_command: fedpkg sources +osbs_conf_worker_clusters: + aarch64: + - max_concurrent_builds: 1 + name: aarch64 + openshift_url: "https://osbs-aarch64-master01.iad2.fedoraproject.org:8443/" + verify_ssl: 'false' + x86_64: + - max_concurrent_builds: 2 + name: x86_64 + openshift_url: "https://osbs.fedoraproject.org/" + verify_ssl: 'false' +osbs_koji_username: "kojibuilder" +osbs_namespace: "osbs-fedora" +osbs_odcs_enabled: true +osbs_orchestrator_cpu_limitrange: "95m" +osbs_orchestrator_default_nodeselector: "orchestrator=true" +osbs_platform_descriptors: + - architecture: amd64 + platform: x86_64 + - architecture: arm64 + platform: aarch64 +osbs_reactor_config_maps: + - data: "{{ _osbs_reactor_config_map }}" + name: reactor-config-map + - data: > + {{ _osbs_reactor_config_map | + + combine(_osbs_scratch_reactor_config_map_overrides, recursive=True) }} + name: reactor-config-map-scratch +osbs_url: "osbs.fedoraproject.org" +osbs_worker_default_nodeselector: "worker=true" +osbs_worker_namespace: worker +osbs_worker_service_accounts: + - orchestrator + - builder +source_registry: "registry.fedoraproject.org" +tcp_ports: [80, 443, 8443] diff --git a/inventory/group_vars/osbs_masters_stg b/inventory/group_vars/osbs_masters_stg index dd8a64dd29..1fd8c388c1 100644 --- a/inventory/group_vars/osbs_masters_stg +++ b/inventory/group_vars/osbs_masters_stg @@ -1,176 +1,134 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -num_cpus: 2 - - -tcp_ports: [ 80, 443, 8443] - -openshift_node_labels: {'region':'infra'} -openshift_schedulable: False - -docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org" -source_registry: "registry.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" - -osbs_url: "osbs.stg.fedoraproject.org" - -koji_url: "koji.stg.fedoraproject.org" - -osbs_client_conf_path: /etc/osbs.conf - -osbs_namespace: "osbs-fedora" -osbs_worker_namespace: worker - -osbs_worker_service_accounts: - - orchestrator - - builder - - -osbs_conf_sources_command: fedpkg sources - -osbs_orchestrator_cpu_limitrange: "95m" - -osbs_worker_default_nodeselector: "worker=true" -osbs_orchestrator_default_nodeselector: "orchestrator=true" - -osbs_conf_service_accounts: - - koji - - builder - -osbs_conf_readwrite_users: - - "system:serviceaccount:{{ osbs_namespace }}:default" - - "system:serviceaccount:{{ osbs_namespace }}:builder" - -osbs_conf_worker_clusters: - x86_64: - - name: x86_64 - max_concurrent_builds: 2 - openshift_url: "https://osbs-master01.stg.iad2.fedoraproject.org:8443" - verify_ssl: 'false' - - aarch64: - - name: aarch64 - max_concurrent_builds: 1 - openshift_url: "https://osbs-aarch64-master01.stg.iad2.fedoraproject.org:8443/" - verify_ssl: 'false' - -osbs_platform_descriptors: -- platform: x86_64 - architecture: amd64 - -- platform: aarch64 - architecture: arm64 - _osbs_reactor_config_map: - version: 1 + artifacts_allowed_domains: [] + #- download.devel.redhat.com/released + #- download.devel.redhat.com/devel/candidates - clusters: - x86_64: - - name: "x86_64" - max_concurrent_builds: 2 - enabled: True - - aarch64: - - name: "aarch64" + clusters: + aarch64: + - enabled: True max_concurrent_builds: 1 - enabled: True - - clusters_client_config_dir: "/var/run/secrets/atomic-reactor/client-config-secret" - - koji: - hub_url: "https://koji{{ env_suffix }}.fedoraproject.org/kojihub" - root_url: "https://koji{{ env_suffix }}.fedoraproject.org/" - auth: - krb_principal: "osbs/{{osbs_url}}@{{ ipa_realm }}" - krb_keytab_path: "FILE:/etc/krb5.osbs_{{ osbs_url }}.keytab" - - odcs: - api_url: "https://odcs{{ env_suffix }}.fedoraproject.org/api/1" - auth: - openidc_dir: "/var/run/secrets/atomic-reactor/odcs-oidc-secret" - signing_intents: - - name: unsigned - keys: [] - default_signing_intent: "unsigned" - - flatpak: - base_image: "registry.fedoraproject.org/flatpak-build-base:latest" - metadata: both - - image_labels: - vendor: "Fedora Project" - authoritative-source-url: "{{ source_registry }}" - distribution-scope: public - - image_equal_labels: - - ['description', 'io.k8s.description'] - openshift: - url: "https://{{ osbs_url }}" - insecure: true - build_json_dir: /usr/share/osbs - auth: - enable: True - - platform_descriptors: "{{ osbs_platform_descriptors }}" - - prefer_schema1_digest: False - - content_versions: + name: "aarch64" + x86_64: + - enabled: True + max_concurrent_builds: 2 + name: "x86_64" + clusters_client_config_dir: "/var/run/secrets/atomic-reactor/client-config-secret" + content_versions: - v2 - - registries: - - url: https://candidate-registry.stg.fedoraproject.org/v2 - insecure: False - auth: + flatpak: + base_image: "registry.fedoraproject.org/flatpak-build-base:latest" + metadata: both + group_manifests: True + image_equal_labels: + - ['description', 'io.k8s.description'] + image_labels: + authoritative-source-url: "{{ source_registry }}" + distribution-scope: public + vendor: "Fedora Project" + koji: + auth: + krb_keytab_path: "FILE:/etc/krb5.osbs_{{ osbs_url }}.keytab" + krb_principal: "osbs/{{osbs_url}}@{{ ipa_realm }}" + hub_url: "https://koji{{ env_suffix }}.fedoraproject.org/kojihub" + root_url: "https://koji{{ env_suffix }}.fedoraproject.org/" + odcs: + api_url: "https://odcs{{ env_suffix }}.fedoraproject.org/api/1" + auth: + openidc_dir: "/var/run/secrets/atomic-reactor/odcs-oidc-secret" + default_signing_intent: "unsigned" + signing_intents: + - keys: [] + name: unsigned + openshift: + auth: + enable: True + build_json_dir: /usr/share/osbs + insecure: true + url: "https://{{ osbs_url }}" + platform_descriptors: "{{ osbs_platform_descriptors }}" + prefer_schema1_digest: False + registries: + - auth: cfg_path: /var/run/secrets/atomic-reactor/v2-registry-dockercfg - - source_registry: - url: "{{ source_registry }}" - insecure: True - - group_manifests: True - - sources_command: "{{ osbs_conf_sources_command }}" - - artifacts_allowed_domains: [] - #- download.devel.redhat.com/released - #- download.devel.redhat.com/devel/candidates - - required_secrets: + insecure: False + url: https://candidate-registry.stg.fedoraproject.org/v2 + required_secrets: - v2-registry-dockercfg - odcs-oidc-secret - - worker_token_secrets: + skip_koji_check_for_base_image: True + source_registry: + insecure: True + url: "{{ source_registry }}" + sources_command: "{{ osbs_conf_sources_command }}" + version: 1 + worker_token_secrets: - x86-64-orchestrator - aarch64-orchestrator - client-config-secret - - skip_koji_check_for_base_image: True - _osbs_scratch_reactor_config_map_overrides: image_labels: distribution-scope: private - -osbs_reactor_config_maps: -- name: reactor-config-map - data: "{{ _osbs_reactor_config_map }}" -- name: reactor-config-map-scratch - data: > - {{ _osbs_reactor_config_map | - combine(_osbs_scratch_reactor_config_map_overrides, recursive=True) }} - -osbs_odcs_enabled: true - #Docker command delegated host composer: compose-x86-01.stg.iad2.fedoraproject.org - +docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org" +docker_registry: "candidate-registry.stg.fedoraproject.org" +koji_url: "koji.stg.fedoraproject.org" +lvm_size: 60000 +mem_size: 8192 # Nagios configuration nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'infra'} +openshift_schedulable: False +osbs_client_conf_path: /etc/osbs.conf +osbs_conf_readwrite_users: + - "system:serviceaccount:{{ osbs_namespace }}:default" + - "system:serviceaccount:{{ osbs_namespace }}:builder" +osbs_conf_service_accounts: + - koji + - builder +osbs_conf_sources_command: fedpkg sources +osbs_conf_worker_clusters: + aarch64: + - max_concurrent_builds: 1 + name: aarch64 + openshift_url: "https://osbs-aarch64-master01.stg.iad2.fedoraproject.org:8443/" + verify_ssl: 'false' + x86_64: + - max_concurrent_builds: 2 + name: x86_64 + openshift_url: "https://osbs-master01.stg.iad2.fedoraproject.org:8443" + verify_ssl: 'false' +osbs_namespace: "osbs-fedora" +osbs_odcs_enabled: true +osbs_orchestrator_cpu_limitrange: "95m" +osbs_orchestrator_default_nodeselector: "orchestrator=true" +osbs_platform_descriptors: + - architecture: amd64 + platform: x86_64 + - architecture: arm64 + platform: aarch64 +osbs_reactor_config_maps: + - data: "{{ _osbs_reactor_config_map }}" + name: reactor-config-map + - data: > + {{ _osbs_reactor_config_map | + + combine(_osbs_scratch_reactor_config_map_overrides, recursive=True) }} + name: reactor-config-map-scratch +osbs_url: "osbs.stg.fedoraproject.org" +osbs_worker_default_nodeselector: "worker=true" +osbs_worker_namespace: worker +osbs_worker_service_accounts: + - orchestrator + - builder +source_registry: "registry.fedoraproject.org" +tcp_ports: [80, 443, 8443] diff --git a/inventory/group_vars/osbs_nodes b/inventory/group_vars/osbs_nodes index 6771ea320b..b0ba8c8835 100644 --- a/inventory/group_vars/osbs_nodes +++ b/inventory/group_vars/osbs_nodes @@ -1,26 +1,20 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -num_cpus: 2 - -tcp_ports: [ 80, 443, 8443, 10250] - docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org" docker_registry: "candidate-registry.fedoraproject.org" -source_registry: "registry.fedoraproject.org" - -osbs_url: "osbs.fedoraproject.org" -osbs_koji_username: "kojibuilder" - koji_url: "koji.fedoraproject.org" - -osbs_client_conf_path: /etc/osbs.conf - +lvm_size: 60000 +mem_size: 8192 nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +osbs_client_conf_path: /etc/osbs.conf +osbs_koji_username: "kojibuilder" +osbs_url: "osbs.fedoraproject.org" +source_registry: "registry.fedoraproject.org" +tcp_ports: [80, 443, 8443, 10250] diff --git a/inventory/group_vars/osbs_nodes_stg b/inventory/group_vars/osbs_nodes_stg index fd8002c4e8..618dfb3858 100644 --- a/inventory/group_vars/osbs_nodes_stg +++ b/inventory/group_vars/osbs_nodes_stg @@ -2,16 +2,13 @@ # Define resources for this group of hosts here. lvm_size: 60000 mem_size: 8192 -num_cpus: 2 - -tcp_ports: [ 80, 443, 8443, 10250] - -openshift_node_labels: {'region': 'primary', 'zone': 'default'} - nagios_Check_Services: - nrpe: true - sshd: true - named: false dhcpd: false httpd: false + named: false + nrpe: true + sshd: true swap: false +num_cpus: 2 +openshift_node_labels: {'region': 'primary', 'zone': 'default'} +tcp_ports: [80, 443, 8443, 10250] diff --git a/inventory/group_vars/osbs_stg b/inventory/group_vars/osbs_stg index c96a062300..b0b05c5b4f 100644 --- a/inventory/group_vars/osbs_stg +++ b/inventory/group_vars/osbs_stg @@ -1,45 +1,33 @@ --- # Define resources for this group of hosts here. -lvm_size: 60000 -mem_size: 8192 -num_cpus: 2 - -tcp_ports: [ 80, 443, 8443] - -ipa_host_group: osbs -ipa_host_group_desc: OpenShift Build Service -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-osbs -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-osbs -- sysadmin-releng - -docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org" -source_registry: "registry.fedoraproject.org" -docker_registry: "candidate-registry.stg.fedoraproject.org" - -osbs_url: "osbs.stg.fedoraproject.org" -osbs_koji_username: "kojibuilder_stg" - -koji_url: "koji.stg.fedoraproject.org" - -osbs_client_conf_path: /etc/osbs.conf - baseiptables: False - -openshift_ansible_upgrading: True - -# docker images required by OpenShift Origin -openshift_required_images: - - "openshift/origin-pod" - +docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org" +docker_registry: "candidate-registry.stg.fedoraproject.org" # fedora container images required by buildroot fedora_required_images: - "fedora:latest" - +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-osbs + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-osbs + - sysadmin-releng +ipa_host_group: osbs +ipa_host_group_desc: OpenShift Build Service +koji_url: "koji.stg.fedoraproject.org" +lvm_size: 60000 +mem_size: 8192 nm_controlled_resolv: True - +num_cpus: 2 +openshift_ansible_upgrading: True +# docker images required by OpenShift Origin +openshift_required_images: + - "openshift/origin-pod" +osbs_client_conf_path: /etc/osbs.conf +osbs_koji_username: "kojibuilder_stg" +osbs_url: "osbs.stg.fedoraproject.org" +source_registry: "registry.fedoraproject.org" +tcp_ports: [80, 443, 8443] diff --git a/inventory/group_vars/packages b/inventory/group_vars/packages index 51330a7cf9..82c5011362 100644 --- a/inventory/group_vars/packages +++ b/inventory/group_vars/packages @@ -1,42 +1,35 @@ --- # Define resources for this group of hosts here. -lvm_size: 100000 -mem_size: 8192 -max_mem_size: 8192 -num_cpus: 4 - -tcp_ports: [ 80, 443, - # This is for glusterd - 6996, - # These 16 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, - 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] - # Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: packages -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-packages -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-noc -- sysadmin-packages -- sysadmin-veteran -- sysadmin-web - +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log - + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell freezes: false -pythonsitelib: /usr/lib/python2.7/site-packages - +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-packages + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-noc + - sysadmin-packages + - sysadmin-veteran + - sysadmin-web +ipa_host_group: packages +lvm_size: 100000 +max_mem_size: 8192 +mem_size: 8192 nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" +num_cpus: 4 +primary_auth_source: ipa +pythonsitelib: /usr/lib/python2.7/site-packages +tcp_ports: [80, 443, + # This is for glusterd + 6996, + # These 16 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] diff --git a/inventory/group_vars/packages_stg b/inventory/group_vars/packages_stg index 0537876d13..a36ae9aeb0 100644 --- a/inventory/group_vars/packages_stg +++ b/inventory/group_vars/packages_stg @@ -1,35 +1,29 @@ --- # Define resources for this group of hosts here. +# Neeed for rsync from log01 for logs. +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-packages + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-noc + - sysadmin-packages + - sysadmin-veteran + - sysadmin-web +ipa_host_group: packages lvm_size: 80000 mem_size: 4096 num_cpus: 4 - -tcp_ports: [ 80, 443, - # These 16 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, - 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] - -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - -ipa_host_group: packages -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-packages -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-noc -- sysadmin-packages -- sysadmin-veteran -- sysadmin-web - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log - pythonsitelib: /usr/lib/python2.7/site-packages +tcp_ports: [80, 443, + # These 16 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] diff --git a/inventory/group_vars/pagure b/inventory/group_vars/pagure index de2cdb88a4..9c45270745 100644 --- a/inventory/group_vars/pagure +++ b/inventory/group_vars/pagure @@ -1,98 +1,87 @@ --- # Define resources for this group of hosts here. -lvm_size: 750000 -mem_size: 49152 -max_mem_size: 131072 -num_cpus: 16 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 22, 25, 80, 443, - 8442, 8443, 8444, 8445, - # Used for the eventsource - 8088, - # This is for the pagure public fedmsg relay - 9940] - -stunnel_service: "eventsource" -stunnel_source_port: 8088 -stunnel_destination_port: 8080 - -sshd_config: ssh/sshd_config.pagure -sshd_keyhelper: true - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: pagure - owner: git - group: apache - can_send: - - pagure.git.receive - - pagure.issue.assigned.added - - pagure.issue.assigned.reset - - pagure.issue.comment.added - - pagure.issue.comment.edited - - pagure.issue.dependency.added - - pagure.issue.dependency.removed - - pagure.issue.drop - - pagure.issue.edit - - pagure.issue.new - - pagure.issue.tag.added - - pagure.issue.tag.removed - - pagure.project.deleted - - pagure.project.edit - - pagure.project.forked - - pagure.project.group.added - - pagure.project.new - - pagure.project.tag.edited - - pagure.project.tag.removed - - pagure.project.user.access.updated - - pagure.project.user.added - - pagure.pull-request.closed - - pagure.pull-request.comment.added - - pagure.pull-request.flag.added - - pagure.pull-request.flag.updated - - pagure.pull-request.new - - pagure.request.assigned.added - -fedmsg_prefix: io.pagure -fedmsg_env: prod - -primary_auth_source: ipa -ipa_host_group: pagure -ipa_host_group_desc: Pagure GIT Forge -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-web -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-web - -freezes: true -postfix_group: vpn.pagure -vpn: true - -host_backup_targets: ['/srv/git', '/var/www/releases'] -db_backup_dir: ['/backups'] -dbs_to_backup: ['pagure'] - -# For the MOTD -csi_security_category: Low csi_primary_contact: Fedora admins - admin@fedoraproject.org csi_purpose: Run the pagure instances for fedora csi_relationship: | - There are a few things running here: + There are a few things running here: - - The apache/mod_wsgi app for pagure + - The apache/mod_wsgi app for pagure - - This host relies on: - - A postgres db server running locally + - This host relies on: + - A postgres db server running locally - - Things that rely on this host: - - nothing currently + - Things that rely on this host: + - nothing currently +# For the MOTD +csi_security_category: Low +db_backup_dir: ['/backups'] +dbs_to_backup: ['pagure'] +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - pagure.git.receive + - pagure.issue.assigned.added + - pagure.issue.assigned.reset + - pagure.issue.comment.added + - pagure.issue.comment.edited + - pagure.issue.dependency.added + - pagure.issue.dependency.removed + - pagure.issue.drop + - pagure.issue.edit + - pagure.issue.new + - pagure.issue.tag.added + - pagure.issue.tag.removed + - pagure.project.deleted + - pagure.project.edit + - pagure.project.forked + - pagure.project.group.added + - pagure.project.new + - pagure.project.tag.edited + - pagure.project.tag.removed + - pagure.project.user.access.updated + - pagure.project.user.added + - pagure.pull-request.closed + - pagure.pull-request.comment.added + - pagure.pull-request.flag.added + - pagure.pull-request.flag.updated + - pagure.pull-request.new + - pagure.request.assigned.added + group: apache + owner: git + service: pagure +fedmsg_env: prod +fedmsg_prefix: io.pagure +freezes: true +host_backup_targets: ['/srv/git', '/var/www/releases'] +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-web + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: pagure +ipa_host_group_desc: Pagure GIT Forge +lvm_size: 750000 +max_mem_size: 131072 +mem_size: 49152 +num_cpus: 16 +postfix_group: vpn.pagure +primary_auth_source: ipa +sshd_config: ssh/sshd_config.pagure +sshd_keyhelper: true +stunnel_destination_port: 8080 +stunnel_service: "eventsource" +stunnel_source_port: 8088 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [22, 25, 80, 443, 8442, 8443, 8444, 8445, + # Used for the eventsource + 8088, + # This is for the pagure public fedmsg relay + 9940] +vpn: true diff --git a/inventory/group_vars/pagure_stg b/inventory/group_vars/pagure_stg index cb80900cbe..5db7f73d20 100644 --- a/inventory/group_vars/pagure_stg +++ b/inventory/group_vars/pagure_stg @@ -1,100 +1,90 @@ --- # Define resources for this group of hosts here. -lvm_size: 50000 -mem_size: 8192 -num_cpus: 4 +csi_primary_contact: Fedora admins - admin@fedoraproject.org +csi_purpose: Run the pagure instances for fedora +csi_relationship: | + There are a few things running here: -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file + - The apache/mod_wsgi app for pagure -tcp_ports: [ 22, 25, 80, 443, 9418, - # Used for the eventsource server - 8088, - # This is for the pagure public fedmsg relay - 9940] - -stunnel_service: "eventsource" -stunnel_source_port: 8088 -stunnel_destination_port: 8080 - -sshd_config: ssh/sshd_config.pagure -sshd_keyhelper: true + - This host relies on: + - A postgres db server running locally + - Things that rely on this host: + - nothing currently +# For the MOTD +csi_security_category: Low +env: pagure-staging # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: pagure - owner: git - group: apache - can_send: - - pagure.git.receive - - pagure.issue.assigned.added - - pagure.issue.assigned.reset - - pagure.issue.comment.added - - pagure.issue.comment.edited - - pagure.issue.dependency.added - - pagure.issue.dependency.removed - - pagure.issue.drop - - pagure.issue.edit - - pagure.issue.new - - pagure.issue.tag.added - - pagure.issue.tag.removed - - pagure.project.deleted - - pagure.project.edit - - pagure.project.forked - - pagure.project.group.added - - pagure.project.new - - pagure.project.tag.edited - - pagure.project.tag.removed - - pagure.project.user.access.updated - - pagure.project.user.added - - pagure.pull-request.closed - - pagure.pull-request.comment.added - - pagure.pull-request.flag.added - - pagure.pull-request.flag.updated - - pagure.pull-request.new - - pagure.request.assigned.added - -fedmsg_prefix: io.pagure + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - pagure.git.receive + - pagure.issue.assigned.added + - pagure.issue.assigned.reset + - pagure.issue.comment.added + - pagure.issue.comment.edited + - pagure.issue.dependency.added + - pagure.issue.dependency.removed + - pagure.issue.drop + - pagure.issue.edit + - pagure.issue.new + - pagure.issue.tag.added + - pagure.issue.tag.removed + - pagure.project.deleted + - pagure.project.edit + - pagure.project.forked + - pagure.project.group.added + - pagure.project.new + - pagure.project.tag.edited + - pagure.project.tag.removed + - pagure.project.user.access.updated + - pagure.project.user.added + - pagure.pull-request.closed + - pagure.pull-request.comment.added + - pagure.pull-request.flag.added + - pagure.pull-request.flag.updated + - pagure.pull-request.new + - pagure.request.assigned.added + group: apache + owner: git + service: pagure fedmsg_env: stg - -ipa_host_group: pagure -ipa_host_group_desc: Pagure GIT Forge -ipa_client_shell_groups: -- sysadmin-noc -- sysadmin-web -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-web - +fedmsg_prefix: io.pagure freezes: false -env: pagure-staging -postfix_group: vpn.pagure-stg -vpn: true - +git_basepath: /srv/git/repositories +git_daemon_user: git # Configuration for the git-daemon/server git_group: git git_port: 9418 git_server: /usr/libexec/git-core/git-daemon git_server_args: --export-all --syslog --inetd --verbose -git_basepath: /srv/git/repositories -git_daemon_user: git - -# For the MOTD -csi_security_category: Low -csi_primary_contact: Fedora admins - admin@fedoraproject.org -csi_purpose: Run the pagure instances for fedora -csi_relationship: | - There are a few things running here: - - - The apache/mod_wsgi app for pagure - - - This host relies on: - - A postgres db server running locally - - - Things that rely on this host: - - nothing currently +ipa_client_shell_groups: + - sysadmin-noc + - sysadmin-web + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: pagure +ipa_host_group_desc: Pagure GIT Forge +lvm_size: 50000 +mem_size: 8192 +num_cpus: 4 +postfix_group: vpn.pagure-stg +sshd_config: ssh/sshd_config.pagure +sshd_keyhelper: true +stunnel_destination_port: 8080 +stunnel_service: "eventsource" +stunnel_source_port: 8088 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [22, 25, 80, 443, 9418, + # Used for the eventsource server + 8088, + # This is for the pagure public fedmsg relay + 9940] +vpn: true diff --git a/inventory/group_vars/pdc_web b/inventory/group_vars/pdc_web index a4fad53748..ed8e3a9669 100644 --- a/inventory/group_vars/pdc_web +++ b/inventory/group_vars/pdc_web @@ -1,50 +1,42 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 8192 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -wsgi_fedmsg_service: pdc -wsgi_procs: 3 -wsgi_threads: 2 - -tcp_ports: [ 80 ] - -primary_auth_source: ipa +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - pdc.compose + - pdc.rpms + - pdc.images + group: apache + owner: root + service: pdc +ipa_client_shell_groups: + - sysadmin-mbs + - sysadmin-noc + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-mbs + - sysadmin-releng ipa_host_group: pdc-web ipa_host_group_desc: Product Definition Center web app -ipa_client_shell_groups: -- sysadmin-mbs -- sysadmin-noc -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-mbs -- sysadmin-releng - -deployment_type: prod - +lvm_size: 20000 +mem_size: 8192 +nagios_Check_Services: + swap: false +num_cpus: 2 # This just defines the CN of the saml2 cert we pull from the private repo # Don't be confused. The app is actually served at apps.stg.fp.o/pdc pdc_domain: pdc.fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: pdc - owner: root - group: apache - can_send: - - pdc.compose - - pdc.rpms - - pdc.images - -nagios_Check_Services: - swap: false +primary_auth_source: ipa +tcp_ports: [80] +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +wsgi_fedmsg_service: pdc +wsgi_procs: 3 +wsgi_threads: 2 diff --git a/inventory/group_vars/pdc_web_stg b/inventory/group_vars/pdc_web_stg index cdce4c7638..63b0e98d32 100644 --- a/inventory/group_vars/pdc_web_stg +++ b/inventory/group_vars/pdc_web_stg @@ -1,46 +1,39 @@ --- # Define resources for this group of hosts here. +deployment_type: stg +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - pdc.compose + - pdc.rpms + - pdc.images + group: apache + owner: root + service: pdc +ipa_client_shell_groups: + - sysadmin-mbs + - sysadmin-noc + - sysadmin-releng + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-mbs + - sysadmin-releng +ipa_host_group: pdc-web +ipa_host_group_desc: Product Definition Center web app lvm_size: 20000 mem_size: 4098 num_cpus: 1 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -wsgi_fedmsg_service: pdc -wsgi_procs: 2 -wsgi_threads: 2 - -tcp_ports: [ 80 ] - -ipa_host_group: pdc-web -ipa_host_group_desc: Product Definition Center web app -ipa_client_shell_groups: -- sysadmin-mbs -- sysadmin-noc -- sysadmin-releng -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-mbs -- sysadmin-releng - -deployment_type: stg - # This just defines the CN of the saml2 cert we pull from the private repo # Don't be confused. The app is actually served at apps.stg.fp.o/pdc pdc_domain: pdc.stg.fedoraproject.org - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: pdc - owner: root - group: apache - can_send: - - pdc.compose - - pdc.rpms - - pdc.images +tcp_ports: [80] +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +wsgi_fedmsg_service: pdc +wsgi_procs: 2 +wsgi_threads: 2 diff --git a/inventory/group_vars/people b/inventory/group_vars/people index 333a19d861..b66614cce6 100644 --- a/inventory/group_vars/people +++ b/inventory/group_vars/people @@ -1,57 +1,46 @@ --- +blocked_ips: [] clamscan_mailto: admin@fedoraproject.org clamscan_paths: -- /srv/ + - /srv/ +csi_primary_contact: Fedora admins - admin@fedoraproject.org +csi_purpose: Provide hosting space for Fedora contributors and Fedora Planet +csi_relationship: | + - shell accounts and web space for fedora contributors + - web space for personal yum repos + - shared space for small group/personal git repos + Please be aware that this is a shared server, and you should not upload + Private/Secret SSH or GPG keys onto this system. Any such keys found + will be deleted. +# For the MOTD +csi_security_category: Low # Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'] +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - planet.post.new + group: planet-user + owner: root + service: planet +git_basepath: / +git_daemon_user: nobody git_port: 9418 git_server: /usr/libexec/git-core/git-daemon git_server_args: --export-all --syslog --inetd --verbose -git_basepath: / -git_daemon_user: nobody - -primary_auth_source: ipa -ipa_host_group: people -ipa_host_group_desc: A place for people to host things # fedora-contributors is an umbrella group containing all others ipa_client_shell_groups: -- fedora-contributor + - fedora-contributor ipa_client_sudo_groups: -- sysadmin-tools - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: planet - owner: root - group: planet-user - can_send: - - planet.post.new - + - sysadmin-tools +ipa_host_group: people +ipa_host_group_desc: A place for people to host things +primary_auth_source: ipa # enable sftp for cotributors. sshd_sftp: true - vpn: true - -# For the MOTD -csi_security_category: Low -csi_primary_contact: Fedora admins - admin@fedoraproject.org -csi_purpose: Provide hosting space for Fedora contributors and Fedora Planet - -csi_relationship: | - - shell accounts and web space for fedora contributors - - web space for personal yum repos - - shared space for small group/personal git repos - - Please be aware that this is a shared server, and you should not upload - Private/Secret SSH or GPG keys onto this system. Any such keys found - will be deleted. - -blocked_ips: [ -] - diff --git a/inventory/group_vars/persistent_cloud b/inventory/group_vars/persistent_cloud index 954d613a97..8265770a2a 100644 --- a/inventory/group_vars/persistent_cloud +++ b/inventory/group_vars/persistent_cloud @@ -1,3 +1,3 @@ --- -freezes: false datacenter: cloud +freezes: false diff --git a/inventory/group_vars/pkgs b/inventory/group_vars/pkgs index 9df05c1138..890ba37c45 100644 --- a/inventory/group_vars/pkgs +++ b/inventory/group_vars/pkgs @@ -1,102 +1,95 @@ --- -lvm_size: 500000 -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - -tcp_ports: [ 80, 443 ] - +clamscan_excludes: + - clamav- + - amavisd-new-2.3.3.tar.gz + - bro-20080804.tgz + - mailman- + - sagator- + - nicotine + - fwsnort-1.0.6.tar.gz + - psad-2.1.7.tar.bz2 + - pymilter- + - linkchecker- + - julia-0.3.7.tar.gz + - jbossws-cxf-5.1.5.Final.zip + - wss4j-2.1.5-source-release.zip + - python-impacket-0.9.14-67fc19e.tar.gz + - gdk-pixbuf- +clamscan_mailto: admin@fedoraproject.org +clamscan_paths: + - /srv/cache/lookaside/pkgs # We have both celery (pagure_worker) and web thread wanting to send out fedmsg's. # To make things easy on the listening side (so avoid contention of binding ports), let's set the pkgs boxes to active fedmsg. fedmsg_active: True - +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - git.branch + - git.mass_branch.complete + - git.mass_branch.start + - logger.log + - pagure.git.receive + group: sysadmin + owner: root + service: shell + - can_send: + - git.receive + - pagure.git.receive + group: packager + owner: root + service: scm + - can_send: + - git.lookaside.new + group: apache + owner: root + service: lookaside + - can_send: + - pagure.git.receive + - pagure.issue.assigned.added + - pagure.issue.assigned.reset + - pagure.issue.comment.added + - pagure.issue.dependency.added + - pagure.issue.dependency.removed + - pagure.issue.edit + - pagure.issue.new + - pagure.issue.tag.added + - pagure.issue.tag.removed + - pagure.project.edit + - pagure.project.forked + - pagure.project.group.added + - pagure.project.new + - pagure.project.tag.edited + - pagure.project.tag.removed + - pagure.project.user.added + - pagure.project.user.removed + - pagure.pull-request.closed + - pagure.pull-request.comment.added + - pagure.pull-request.comment.edited + - pagure.pull-request.flag.added + - pagure.pull-request.flag.updated + - pagure.pull-request.new + - pagure.request.assigned.added + group: apache + owner: pagure + service: pagure +ipa_client_shell_groups: + - packager + - sysadmin-cvs + - sysadmin-main + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-cvs + - sysadmin-main +ipa_host_group: pkgs +lvm_size: 500000 +max_mem_size: 32768 +mem_size: 16384 +num_cpus: 8 +pagure_static_uid: 600 +primary_auth_source: ipa +sshd_keyhelper: true +tcp_ports: [80, 443] # There vars are used to configure mod_wsgi wsgi_procs: 6 wsgi_threads: 6 - -pagure_static_uid: 600 -sshd_keyhelper: true - -primary_auth_source: ipa -ipa_host_group: pkgs -ipa_client_shell_groups: -- packager -- sysadmin-cvs -- sysadmin-main -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-cvs -- sysadmin-main - -clamscan_mailto: admin@fedoraproject.org -clamscan_paths: -- /srv/cache/lookaside/pkgs -clamscan_excludes: -- clamav- -- amavisd-new-2.3.3.tar.gz -- bro-20080804.tgz -- mailman- -- sagator- -- nicotine -- fwsnort-1.0.6.tar.gz -- psad-2.1.7.tar.bz2 -- pymilter- -- linkchecker- -- julia-0.3.7.tar.gz -- jbossws-cxf-5.1.5.Final.zip -- wss4j-2.1.5-source-release.zip -- python-impacket-0.9.14-67fc19e.tar.gz -- gdk-pixbuf- - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - git.branch - - git.mass_branch.complete - - git.mass_branch.start - - logger.log - - pagure.git.receive -- service: scm - owner: root - group: packager - can_send: - - git.receive - - pagure.git.receive -- service: lookaside - owner: root - group: apache - can_send: - - git.lookaside.new -- service: pagure - owner: pagure - group: apache - can_send: - - pagure.git.receive - - pagure.issue.assigned.added - - pagure.issue.assigned.reset - - pagure.issue.comment.added - - pagure.issue.dependency.added - - pagure.issue.dependency.removed - - pagure.issue.edit - - pagure.issue.new - - pagure.issue.tag.added - - pagure.issue.tag.removed - - pagure.project.edit - - pagure.project.forked - - pagure.project.group.added - - pagure.project.new - - pagure.project.tag.edited - - pagure.project.tag.removed - - pagure.project.user.added - - pagure.project.user.removed - - pagure.pull-request.closed - - pagure.pull-request.comment.added - - pagure.pull-request.comment.edited - - pagure.pull-request.flag.added - - pagure.pull-request.flag.updated - - pagure.pull-request.new - - pagure.request.assigned.added diff --git a/inventory/group_vars/pkgs_stg b/inventory/group_vars/pkgs_stg index 69f53926a1..3c8345f60a 100644 --- a/inventory/group_vars/pkgs_stg +++ b/inventory/group_vars/pkgs_stg @@ -1,101 +1,94 @@ --- -lvm_size: 500000 -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - -tcp_ports: [ 80, 443, 8444, 8443, 8445 ] -# There vars are used to configure mod_wsgi -wsgi_procs: 4 -wsgi_threads: 4 - -pagure_static_uid: 600 - -# Configures ssh for git@ user -sshd_keyhelper: true - +clamscan_excludes: + - clamav- + - amavisd-new-2.3.3.tar.gz + - bro-20080804.tgz + - mailman- + - sagator- + - nicotine + - fwsnort-1.0.6.tar.gz + - psad-2.1.7.tar.bz2 + - pymilter- + - linkchecker- + - julia-0.3.7.tar.gz +clamscan_mailto: admin@fedoraproject.org +clamscan_paths: + - /srv/cache/lookaside/pkgs # We have both celery (pagure_worker) and web thread wanting to send out fedmsg's. # To make things easy on the listening side (so avoid contention of binding ports), let's set the pkgs boxes to active fedmsg. fedmsg_active: True - -ipa_host_group: pkgs -ipa_client_shell_groups: -- packager -- sysadmin-cvs -- sysadmin-main -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-cvs -- sysadmin-main - -clamscan_mailto: admin@fedoraproject.org -clamscan_paths: -- /srv/cache/lookaside/pkgs -clamscan_excludes: -- clamav- -- amavisd-new-2.3.3.tar.gz -- bro-20080804.tgz -- mailman- -- sagator- -- nicotine -- fwsnort-1.0.6.tar.gz -- psad-2.1.7.tar.bz2 -- pymilter- -- linkchecker- -- julia-0.3.7.tar.gz - # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log - - git.branch - - git.mass_branch.complete - - git.mass_branch.start - - pagure.git.receive -- service: scm - owner: root - group: packager - can_send: - - git.branch - - git.mass_branch.complete - - git.mass_branch.start - - git.receive - - pagure.git.receive -- service: lookaside - owner: root - group: apache - can_send: - - git.lookaside.new -- service: pagure - owner: pagure - group: apache - can_send: - - pagure.git.receive - - pagure.issue.assigned.added - - pagure.issue.assigned.reset - - pagure.issue.comment.added - - pagure.issue.dependency.added - - pagure.issue.dependency.removed - - pagure.issue.edit - - pagure.issue.new - - pagure.issue.tag.added - - pagure.issue.tag.removed - - pagure.project.edit - - pagure.project.forked - - pagure.project.group.added - - pagure.project.new - - pagure.project.tag.edited - - pagure.project.tag.removed - - pagure.project.user.added - - pagure.project.user.removed - - pagure.pull-request.closed - - pagure.pull-request.comment.added - - pagure.pull-request.comment.edited - - pagure.pull-request.flag.added - - pagure.pull-request.flag.updated - - pagure.pull-request.new - - pagure.request.assigned.added + - can_send: + - logger.log + - git.branch + - git.mass_branch.complete + - git.mass_branch.start + - pagure.git.receive + group: sysadmin + owner: root + service: shell + - can_send: + - git.branch + - git.mass_branch.complete + - git.mass_branch.start + - git.receive + - pagure.git.receive + group: packager + owner: root + service: scm + - can_send: + - git.lookaside.new + group: apache + owner: root + service: lookaside + - can_send: + - pagure.git.receive + - pagure.issue.assigned.added + - pagure.issue.assigned.reset + - pagure.issue.comment.added + - pagure.issue.dependency.added + - pagure.issue.dependency.removed + - pagure.issue.edit + - pagure.issue.new + - pagure.issue.tag.added + - pagure.issue.tag.removed + - pagure.project.edit + - pagure.project.forked + - pagure.project.group.added + - pagure.project.new + - pagure.project.tag.edited + - pagure.project.tag.removed + - pagure.project.user.added + - pagure.project.user.removed + - pagure.pull-request.closed + - pagure.pull-request.comment.added + - pagure.pull-request.comment.edited + - pagure.pull-request.flag.added + - pagure.pull-request.flag.updated + - pagure.pull-request.new + - pagure.request.assigned.added + group: apache + owner: pagure + service: pagure +ipa_client_shell_groups: + - packager + - sysadmin-cvs + - sysadmin-main + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-cvs + - sysadmin-main +ipa_host_group: pkgs +lvm_size: 500000 +max_mem_size: 32768 +mem_size: 16384 +num_cpus: 8 +pagure_static_uid: 600 +# Configures ssh for git@ user +sshd_keyhelper: true +tcp_ports: [80, 443, 8444, 8443, 8445] +# There vars are used to configure mod_wsgi +wsgi_procs: 4 +wsgi_threads: 4 diff --git a/inventory/group_vars/proxies b/inventory/group_vars/proxies index cd9823025c..d3c360385d 100644 --- a/inventory/group_vars/proxies +++ b/inventory/group_vars/proxies @@ -1,156 +1,97 @@ --- # Define resources for this group of hosts here. +blocked_ip_v6: [] +blocked_ips: ['14.102.69.78', '104.219.54.236', '103.38.177.2', '110.172.140.98', '183.80.131.253', '113.190.178.137', '115.76.39.108', '116.109.31.204', '209.64.155.56'] +collectd_apache: true +csi_primary_contact: Fedora Admins - admin@fedoraproject.org +csi_purpose: Provides frontend (reverse) proxy for most web applications +csi_relationship: | + Using Apache -> haproxy, these hosts contact app servers and + other various hosts to provide web applications at sites like + fedoraproject.org and admin.fedoraproject.org. The proxy servers are + balanced via dns and geoIP and are spread all over the place. +# For the MOTD +csi_security_category: Moderate +custom_rules: [ + # Need for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.181.102 --dport 873 -j ACCEPT', + # allow varnish from localhost + '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT', + # also allow varnish from internal for purge requests + '-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.0/24 --dport 6081 -j ACCEPT', + # Allow happinesspackets.fedorainfracloud.org to talk to inbound fedmsg relay. + '-A INPUT -p tcp -m tcp --dport 9941 -s 209.132.184.58 -j ACCEPT', + # Allow openqa01 to talk to the inbound fedmsg relay. + '-A INPUT -p tcp -m tcp --dport 9941 -s 10.3.174.0/24 -j ACCEPT', + # For Zanata + # See files/httpd/website_id_fp_o_zanata.conf for info + '-A INPUT -p tcp -m tcp --dport 44342 -s 209.132.183.252 -j ACCEPT', + # Allow ocp control plane hosts + '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.35 -j ACCEPT', # batcave01 + '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.123 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.124 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.125 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.126 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.65 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.123 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.124 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.125 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.126 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.65 -j ACCEPT'] +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: proxies +ipa_host_group_desc: Proxies between internal hosts and the Internet lvm_size: 50000 -mem_size: 8192 -num_cpus: 6 - # This is used in the httpd.conf to determine the value for serverlimit and # maxrequestworkers. On 8gb proxies, 900 seems fine. But on 4gb proxies, this # should be lowered in the host vars for that proxy. maxrequestworkers: 1500 - -tcp_ports: [ - # For apache, generally. - 80, - 443, - - # This is for TCP krb5 - 1088, - - # This is for RabbitMQ public access - 5671, - # This is for RabbitMQ internal-public access - 15671, - - # This is for the haproxy HTML stats page - # TODO -- there's no need for this to be wide open to the world. With this - # in place, you can visit https://apps.fedoraproject.org:8080 and get the - # haproxy stats page. We should close this and just have admins go through - # the apache reverseproxy at https://admin.fedoraproject.org/haproxy/proxy1 - 8080, - - # This is for TOTP - 8443, - - # For fedmsg websocket server over stunnel - 9939, - # For fedmsg raw zeromq socket (outbound) - 9940, - # 9941 is closed generally, is for the inbound fedmsg and is covered in - # custom_rules - ] -custom_rules: [ - # Need for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 209.132.181.102 --dport 873 -j ACCEPT', - - # allow varnish from localhost - '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT', - - # also allow varnish from internal for purge requests - '-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.0/24 --dport 6081 -j ACCEPT', - - # Allow happinesspackets.fedorainfracloud.org to talk to inbound fedmsg relay. - '-A INPUT -p tcp -m tcp --dport 9941 -s 209.132.184.58 -j ACCEPT', - - # Allow openqa01 to talk to the inbound fedmsg relay. - '-A INPUT -p tcp -m tcp --dport 9941 -s 10.3.174.0/24 -j ACCEPT', - - # For Zanata - # See files/httpd/website_id_fp_o_zanata.conf for info - '-A INPUT -p tcp -m tcp --dport 44342 -s 209.132.183.252 -j ACCEPT', - - # Allow ocp control plane hosts - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.35 -j ACCEPT', # batcave01 - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.120 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.121 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.122 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.123 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.124 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.125 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.126 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.65 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.120 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.121 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.122 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.123 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.124 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.125 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.126 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.65 -j ACCEPT', -] - +mem_size: 8192 nat_rules: [ - # For Zanata, redirect 443/tcp -> 43342/tcp for TLS reasons - # See files/httpd/website_id_fp_o_zanata.conf for info - '-A PREROUTING -s 209.132.183.252 -p tcp --dport 443 -j REDIRECT --to 44342' - ] - -blocked_ips: [ - '14.102.69.78', - '104.219.54.236', - '103.38.177.2', - '110.172.140.98', - '183.80.131.253', - '113.190.178.137', - '115.76.39.108', - '116.109.31.204', - '209.64.155.56', -] - - -blocked_ip_v6: [ -] - -primary_auth_source: ipa -ipa_host_group: proxies -ipa_host_group_desc: Proxies between internal hosts and the Internet -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web - -collectd_apache: true - -varnish_group: proxies - -postvpnservices: -- haproxy -- varnish - -# For the MOTD -csi_security_category: Moderate -csi_primary_contact: Fedora Admins - admin@fedoraproject.org -csi_purpose: Provides frontend (reverse) proxy for most web applications -csi_relationship: | - Using Apache -> haproxy, these hosts contact app servers and - other various hosts to provide web applications at sites like - fedoraproject.org and admin.fedoraproject.org. The proxy servers are - balanced via dns and geoIP and are spread all over the place. - -openshift_masters: -- os-master01.vpn.fedoraproject.org -- os-master02.vpn.fedoraproject.org -- os-master03.vpn.fedoraproject.org - -openshift_nodes: -- os-node01.vpn.fedoraproject.org -- os-node02.vpn.fedoraproject.org -- os-node03.vpn.fedoraproject.org - + # For Zanata, redirect 443/tcp -> 43342/tcp for TLS reasons + # See files/httpd/website_id_fp_o_zanata.conf for info + '-A PREROUTING -s 209.132.183.252 -p tcp --dport 443 -j REDIRECT --to 44342'] +num_cpus: 6 ocp_masters: -- bootstrap.ocp.iad2.fedoraproject.org -- ocp01.ocp.iad2.fedoraproject.org -- ocp02.ocp.iad2.fedoraproject.org -- ocp03.ocp.iad2.fedoraproject.org - + - bootstrap.ocp.iad2.fedoraproject.org + - ocp01.ocp.iad2.fedoraproject.org + - ocp02.ocp.iad2.fedoraproject.org + - ocp03.ocp.iad2.fedoraproject.org ocp_nodes: -- worker01.ocp.iad2.fedoraproject.org -- worker02.ocp.iad2.fedoraproject.org -- worker03.ocp.iad2.fedoraproject.org + - worker01.ocp.iad2.fedoraproject.org + - worker02.ocp.iad2.fedoraproject.org + - worker03.ocp.iad2.fedoraproject.org +openshift_masters: + - os-master01.vpn.fedoraproject.org + - os-master02.vpn.fedoraproject.org + - os-master03.vpn.fedoraproject.org +openshift_nodes: + - os-node01.vpn.fedoraproject.org + - os-node02.vpn.fedoraproject.org + - os-node03.vpn.fedoraproject.org +postvpnservices: + - haproxy + - varnish +primary_auth_source: ipa +tcp_ports: [ + # For apache, generally. + 80, 443, + # This is for TCP krb5 + 1088, + # This is for RabbitMQ public access + 5671, + # This is for RabbitMQ internal-public access + 15671, + # This is for the haproxy HTML stats page + # TODO -- there's no need for this to be wide open to the world. With this + # in place, you can visit https://apps.fedoraproject.org:8080 and get the + # haproxy stats page. We should close this and just have admins go through + # the apache reverseproxy at https://admin.fedoraproject.org/haproxy/proxy1 + 8080, + # This is for TOTP + 8443, + # For fedmsg websocket server over stunnel + 9939, + # For fedmsg raw zeromq socket (outbound) + 9940, + # 9941 is closed generally, is for the inbound fedmsg and is covered in + # custom_rules +] +varnish_group: proxies diff --git a/inventory/group_vars/proxies_stg b/inventory/group_vars/proxies_stg index 7a0d79c65c..c7c430e4f2 100644 --- a/inventory/group_vars/proxies_stg +++ b/inventory/group_vars/proxies_stg @@ -1,136 +1,93 @@ --- # Define resources for this group of hosts here. +collectd_apache: true +csi_primary_contact: Fedora Admins - admin@fedoraproject.org +csi_purpose: Provides frontend (reverse) proxy for most web applications +csi_relationship: | + Using Apache -> haproxy, these hosts contact app servers and + other various hosts to provide web applications at sites like + fedoraproject.org and admin.fedoraproject.org. The proxy servers are + balanced via dns and geoIP and are spread all over the place. +# For the MOTD +csi_security_category: Moderate +custom_rules: [ + # Need for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # allow varnish from localhost + '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT', + # also allow varnish from internal for purge requests + '-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.126.0/24 --dport 6081 -j ACCEPT', + # Allow stg.fedoramagazine.org running at vultr.com to talk inbound fedmsg + # Contact cydrobolt about the status of this. It hasn't hit prod status + # yet as of 2015-04-27 (threebean). + '-A INPUT -p tcp -m tcp --dport 9941 -s 104.207.133.220 -j ACCEPT', + # Allow resultsdb talk to the inbound fedmsg relay. + '-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.124.147 -j ACCEPT', + # Allow openqa to talk to the inbound fedmsg relay. + '-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.131.72 -j ACCEPT', + # Allow happinesspackets-stg.fedorainfracloud.org to talk to the inbound fedmsg relay + '-A INPUT -p tcp -m tcp --dport 9941 -s 209.132.184.123 -j ACCEPT', + # Allow ocp control plane hosts + '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.35 -j ACCEPT', # batcave01 + '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.123 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.50 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.123 -j ACCEPT'] +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web +ipa_host_group: proxies +ipa_host_group_desc: Proxies between internal hosts and the Internet lvm_size: 50000 -mem_size: 8192 -num_cpus: 2 - # This is used in the httpd.conf to determine the value for serverlimit and # maxrequestworkers. On 8gb proxies, 900 seems fine. But on 4gb proxies, this # should be lowered in the host vars for that proxy. maxrequestworkers: 900 - -tcp_ports: [ - # For apache, generally. - 80, - 443, - - # This is for TCP krb5 - 1088, - - # This is for RabbitMQ public access - 5671, - # This is for RabbitMQ internal-public access - 15671, - - # This is for the haproxy HTML stats page - # TODO -- there's no need for this to be wide open to the world. With this - # in place, you can visit https://apps.fedoraproject.org:8080 and get the - # haproxy stats page. We should close this and just have admins go through - # the apache reverseproxy at https://admin.fedoraproject.org/haproxy/proxy1 - 8080, - - # This is for TOTP - 8443, - - # For fedmsg websocket server over stunnel - 9939, - # For fedmsg raw zeromq socket (outbound) - 9940, - # 9941 is closed generally, is for the inbound fedmsg and is covered in - # custom_rules - ] -custom_rules: [ - # Need for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - - # allow varnish from localhost - '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT', - - # also allow varnish from internal for purge requests - '-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.126.0/24 --dport 6081 -j ACCEPT', - - # Allow stg.fedoramagazine.org running at vultr.com to talk inbound fedmsg - # Contact cydrobolt about the status of this. It hasn't hit prod status - # yet as of 2015-04-27 (threebean). - '-A INPUT -p tcp -m tcp --dport 9941 -s 104.207.133.220 -j ACCEPT', - - # Allow resultsdb talk to the inbound fedmsg relay. - '-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.124.147 -j ACCEPT', - - # Allow openqa to talk to the inbound fedmsg relay. - '-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.131.72 -j ACCEPT', - - # Allow happinesspackets-stg.fedorainfracloud.org to talk to the inbound fedmsg relay - '-A INPUT -p tcp -m tcp --dport 9941 -s 209.132.184.123 -j ACCEPT', - # Allow ocp control plane hosts - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.163.35 -j ACCEPT', # batcave01 - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.115 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.116 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.117 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.118 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.119 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.120 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.121 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.122 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.123 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 6443 -s 10.3.166.50 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.115 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.116 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.117 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.118 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.119 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.120 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.121 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.122 -j ACCEPT', - '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.123 -j ACCEPT', - ] - -ipa_host_group: proxies -ipa_host_group_desc: Proxies between internal hosts and the Internet -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web - -collectd_apache: true -varnish_group: proxies - -# For the MOTD -csi_security_category: Moderate -csi_primary_contact: Fedora Admins - admin@fedoraproject.org -csi_purpose: Provides frontend (reverse) proxy for most web applications -csi_relationship: | - Using Apache -> haproxy, these hosts contact app servers and - other various hosts to provide web applications at sites like - fedoraproject.org and admin.fedoraproject.org. The proxy servers are - balanced via dns and geoIP and are spread all over the place. - -openshift_masters: -- os-master01.stg.iad2.fedoraproject.org -- os-master02.stg.iad2.fedoraproject.org -- os-master03.stg.iad2.fedoraproject.org - -openshift_nodes: -- os-node01.stg.iad2.fedoraproject.org -- os-node02.stg.iad2.fedoraproject.org -- os-node03.stg.iad2.fedoraproject.org -- os-node04.stg.iad2.fedoraproject.org - +mem_size: 8192 +num_cpus: 2 ocp_masters_stg: -# - bootstrap.ocp.stg.iad2.fedoraproject.org -- ocp01.ocp.stg.iad2.fedoraproject.org -- ocp02.ocp.stg.iad2.fedoraproject.org -- ocp03.ocp.stg.iad2.fedoraproject.org - + # - bootstrap.ocp.stg.iad2.fedoraproject.org + - ocp01.ocp.stg.iad2.fedoraproject.org + - ocp02.ocp.stg.iad2.fedoraproject.org + - ocp03.ocp.stg.iad2.fedoraproject.org ocp_nodes_stg: -- worker01.ocp.stg.iad2.fedoraproject.org -- worker02.ocp.stg.iad2.fedoraproject.org -- worker03.ocp.stg.iad2.fedoraproject.org -- worker04.ocp.stg.iad2.fedoraproject.org -- worker05.ocp.stg.iad2.fedoraproject.org + - worker01.ocp.stg.iad2.fedoraproject.org + - worker02.ocp.stg.iad2.fedoraproject.org + - worker03.ocp.stg.iad2.fedoraproject.org + - worker04.ocp.stg.iad2.fedoraproject.org + - worker05.ocp.stg.iad2.fedoraproject.org +openshift_masters: + - os-master01.stg.iad2.fedoraproject.org + - os-master02.stg.iad2.fedoraproject.org + - os-master03.stg.iad2.fedoraproject.org +openshift_nodes: + - os-node01.stg.iad2.fedoraproject.org + - os-node02.stg.iad2.fedoraproject.org + - os-node03.stg.iad2.fedoraproject.org + - os-node04.stg.iad2.fedoraproject.org +tcp_ports: [ + # For apache, generally. + 80, 443, + # This is for TCP krb5 + 1088, + # This is for RabbitMQ public access + 5671, + # This is for RabbitMQ internal-public access + 15671, + # This is for the haproxy HTML stats page + # TODO -- there's no need for this to be wide open to the world. With this + # in place, you can visit https://apps.fedoraproject.org:8080 and get the + # haproxy stats page. We should close this and just have admins go through + # the apache reverseproxy at https://admin.fedoraproject.org/haproxy/proxy1 + 8080, + # This is for TOTP + 8443, + # For fedmsg websocket server over stunnel + 9939, + # For fedmsg raw zeromq socket (outbound) + 9940, + # 9941 is closed generally, is for the inbound fedmsg and is covered in + # custom_rules +] +varnish_group: proxies diff --git a/inventory/group_vars/rabbitmq b/inventory/group_vars/rabbitmq index b453a875f8..bc5218294c 100644 --- a/inventory/group_vars/rabbitmq +++ b/inventory/group_vars/rabbitmq @@ -1,43 +1,25 @@ --- -tcp_ports: [ - # https://www.rabbitmq.com/clustering.html#selinux-ports - # EPMD - 4369, - # AMQP - 5672, - 5671, - # CLI tools - 35672, - 35673, - 35674, - 35675, - 35676, - 35677, - 35678, - 35679, - 35680, - 35681, - 35682, - # HTTP API - #15672, -] - custom_rules: [ - # Neeed for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - # Inter-node traffic - '-A INPUT -p tcp -m tcp -s 10.3.163.78 --dport 25672 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.79 --dport 25672 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.80 --dport 25672 -j ACCEPT', -] - -primary_auth_source: ipa + # Neeed for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # Inter-node traffic + '-A INPUT -p tcp -m tcp -s 10.3.163.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.80 --dport 25672 -j ACCEPT'] ipa_host_group: rabbitmq ipa_host_group_desc: RabbitMQ service ipa_shell_groups: -- sysadmin-messaging + - sysadmin-messaging ipa_sudo_groups: -- sysadmin-messaging - + - sysadmin-messaging mem_size: 4096 +primary_auth_source: ipa +tcp_ports: [ + # https://www.rabbitmq.com/clustering.html#selinux-ports + # EPMD + 4369, + # AMQP + 5672, 5671, + # CLI tools + 35672, 35673, 35674, 35675, 35676, 35677, 35678, 35679, 35680, 35681, 35682, + # HTTP API + #15672, +] diff --git a/inventory/group_vars/rabbitmq_stg b/inventory/group_vars/rabbitmq_stg index 1fc25a5dbb..6a5a691d22 100644 --- a/inventory/group_vars/rabbitmq_stg +++ b/inventory/group_vars/rabbitmq_stg @@ -1,57 +1,35 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -datacenter: iad2 - -# Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 4096 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ - # https://www.rabbitmq.com/clustering.html#selinux-ports - # EPMD - 4369, - # AMQP - 5672, - 5671, - # CLI tools - 35672, - 35673, - 35674, - 35675, - 35676, - 35677, - 35678, - 35679, - 35680, - 35681, - 35682, - # HTTP API - #15672, -] - custom_rules: [ - # Neeed for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - # Inter-node traffic - '-A INPUT -p tcp -m tcp -s 10.3.166.78 --dport 25672 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.166.79 --dport 25672 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.166.80 --dport 25672 -j ACCEPT', -] - + # Neeed for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # Inter-node traffic + '-A INPUT -p tcp -m tcp -s 10.3.166.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.166.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.166.80 --dport 25672 -j ACCEPT'] +datacenter: iad2 +dns: 10.3.163.33 +gw: 10.3.166.254 ipa_host_group: rabbitmq ipa_host_group_desc: RabbitMQ service ipa_shell_groups: -- sysadmin-messaging + - sysadmin-messaging ipa_sudo_groups: -- sysadmin-messaging + - sysadmin-messaging +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# Define resources for this group of hosts here. +lvm_size: 20000 +mem_size: 4096 +nm: 255.255.255.0 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [ + # https://www.rabbitmq.com/clustering.html#selinux-ports + # EPMD + 4369, + # AMQP + 5672, 5671, + # CLI tools + 35672, 35673, 35674, 35675, 35676, 35677, 35678, 35679, 35680, 35681, 35682, + # HTTP API + #15672, +] diff --git a/inventory/group_vars/releng_compose b/inventory/group_vars/releng_compose index 43e9bc4654..037ae3c169 100644 --- a/inventory/group_vars/releng_compose +++ b/inventory/group_vars/releng_compose @@ -1,66 +1,57 @@ --- # common items for the releng-* boxes -lvm_size: 100000 -mem_size: 131072 -max_mem_size: "{{ mem_size }}" -num_cpus: 16 -virt_install_command: "{{ virt_install_command_two_nic_unsafe }}" - -nm: 255.255.255.0 -gw: 10.5.125.254 dns: 10.5.126.21 - -# With 16 cpus, theres a bunch more kernel threads -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -host_group: releng -freezes: true - -primary_auth_source: ipa -ipa_host_group: releng-compose -ipa_host_group_desc: Hosts running composes -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -# For the mock config -kojipkgs_url: kojipkgs.fedoraproject.org -kojihub_url: koji.fedoraproject.org/kojihub -kojihub_scheme: https - -# for kojid config -koji_server_url: "https://koji.fedoraproject.org/kojihub" -koji_weburl: "https://koji.fedoraproject.org/koji" -koji_topurl: "https://kojipkgs.fedoraproject.org/" - - # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: root - can_send: - - logger.log -- service: releng - owner: root - group: masher - can_send: - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.createiso.imagefail - - pungi.compose.createiso.imagedone - - pungi.compose.ostree - - compose.27.complete - - compose.27.start - - compose.28.complete - - compose.28.rsync.complete - - compose.28.rsync.start - - compose.28.start - - compose.29.complete - - compose.29.start + - can_send: + - logger.log + group: root + owner: root + service: shell + - can_send: + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.createiso.imagefail + - pungi.compose.createiso.imagedone + - pungi.compose.ostree + - compose.27.complete + - compose.27.start + - compose.28.complete + - compose.28.rsync.complete + - compose.28.rsync.start + - compose.28.start + - compose.29.complete + - compose.29.start + group: masher + owner: root + service: releng +freezes: true +gw: 10.5.125.254 +host_group: releng +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: releng-compose +ipa_host_group_desc: Hosts running composes +# for kojid config +koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" +koji_weburl: "https://koji.fedoraproject.org/koji" +kojihub_scheme: https +kojihub_url: koji.fedoraproject.org/kojihub +# For the mock config +kojipkgs_url: kojipkgs.fedoraproject.org +lvm_size: 100000 +max_mem_size: "{{ mem_size }}" +mem_size: 131072 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +# With 16 cpus, theres a bunch more kernel threads +nrpe_procs_warn: 900 +num_cpus: 16 +primary_auth_source: ipa +virt_install_command: "{{ virt_install_command_two_nic_unsafe }}" diff --git a/inventory/group_vars/releng_compose_stg b/inventory/group_vars/releng_compose_stg index e2318d5054..9610f56572 100644 --- a/inventory/group_vars/releng_compose_stg +++ b/inventory/group_vars/releng_compose_stg @@ -1,16 +1,13 @@ --- +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng ipa_host_group: releng-compose ipa_host_group_desc: Hosts running composes -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng - koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" -koji_weburl: "https://koji.stg.fedoraproject.org/koji" koji_topurl: "https://kojipkgs.fedoraproject.org/" - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - +koji_weburl: "https://koji.stg.fedoraproject.org/koji" mem_size: 8192 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" num_cpus: 4 diff --git a/inventory/group_vars/relvalconsumer b/inventory/group_vars/relvalconsumer index 2e8570c913..4f4bcd0ef9 100644 --- a/inventory/group_vars/relvalconsumer +++ b/inventory/group_vars/relvalconsumer @@ -1,5 +1,5 @@ # This var should never be set for more than one machine -relvalconsumer_prod: true # this one probably shouldn't either relvalconsumer_bugzilla_api_key: "{{ prod_relvalconsumer_bugzilla_secret_api_key }}" relvalconsumer_env_suffix: +relvalconsumer_prod: true diff --git a/inventory/group_vars/relvalconsumer_common b/inventory/group_vars/relvalconsumer_common index 30e49a5c7b..39b826d108 100644 --- a/inventory/group_vars/relvalconsumer_common +++ b/inventory/group_vars/relvalconsumer_common @@ -1,19 +1,17 @@ # we need this for our fedora-messaging consumer as it is not allowed # to create queues on the infra AMQP broker, by broker config +relvalamiconsumer_amqp_queue: "openqa_relvalamiconsumer{{ relvalconsumer_env_suffix }}" +relvalamiconsumer_amqp_routing_keys: ["org.fedoraproject.prod.fedimg.image.publish"] +relvalconsumer_amqp_cacert: /etc/fedora-messaging/cacert.pem +relvalconsumer_amqp_cert: /etc/pki/fedora-messaging/openqa-cert.pem +relvalconsumer_amqp_key: /etc/pki/fedora-messaging/openqa-key.pem +# fedora-messaging email error reporting settings +relvalconsumer_amqp_mailto: ["adamwill@fedoraproject.org", "lruzicka@fedoraproject.org"] relvalconsumer_amqp_passive: true - +relvalconsumer_amqp_queue: "openqa_relvalconsumer{{ relvalconsumer_env_suffix }}" +relvalconsumer_amqp_routing_keys: ["org.fedoraproject.prod.pungi.compose.status.change"] +relvalconsumer_amqp_smtp: bastion # fedora-messaging job scheduler settings: most of these are the same # for prod and stg as they both must listen for prod messages. Only # the queue names differs relvalconsumer_amqp_url: "amqps://openqa:@rabbitmq.fedoraproject.org/%2Fpubsub" -relvalconsumer_amqp_cacert: /etc/fedora-messaging/cacert.pem -relvalconsumer_amqp_key: /etc/pki/fedora-messaging/openqa-key.pem -relvalconsumer_amqp_cert: /etc/pki/fedora-messaging/openqa-cert.pem -relvalconsumer_amqp_queue: "openqa_relvalconsumer{{ relvalconsumer_env_suffix }}" -relvalconsumer_amqp_routing_keys: ["org.fedoraproject.prod.pungi.compose.status.change"] -relvalamiconsumer_amqp_queue: "openqa_relvalamiconsumer{{ relvalconsumer_env_suffix }}" -relvalamiconsumer_amqp_routing_keys: ["org.fedoraproject.prod.fedimg.image.publish"] - -# fedora-messaging email error reporting settings -relvalconsumer_amqp_mailto: ["adamwill@fedoraproject.org", "lruzicka@fedoraproject.org"] -relvalconsumer_amqp_smtp: bastion diff --git a/inventory/group_vars/relvalconsumer_test b/inventory/group_vars/relvalconsumer_test index 067d938fba..be348e3ac9 100644 --- a/inventory/group_vars/relvalconsumer_test +++ b/inventory/group_vars/relvalconsumer_test @@ -1,8 +1,7 @@ -relvalconsumer_prod: false -relvalconsumer_env_suffix: .test - +relvalamiconsumer_disabled: true # FIXME: disable consumers that write to wiki until auth key # is working again: # https://pagure.io/fedora-infrastructure/issue/8381 relvalconsumer_disabled: true -relvalamiconsumer_disabled: true +relvalconsumer_env_suffix: .test +relvalconsumer_prod: false diff --git a/inventory/group_vars/repospanner_temp b/inventory/group_vars/repospanner_temp index 00e40f7c7a..0b6b7db809 100644 --- a/inventory/group_vars/repospanner_temp +++ b/inventory/group_vars/repospanner_temp @@ -1,29 +1,17 @@ --- # Define resources for this group of hosts here. -lvm_size: 50000 -mem_size: 8192 -max_mem_size: 16348 -num_cpus: 8 - -# For the MOTD -csi_security_category: Low csi_primary_contact: admin@fedoraproject.org / sysadmin-main-members csi_purpose: repospanner git syncing host - -custom_rules: [ '-A INPUT -p tcp -m tcp -s 8.43.84.211 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 8.43.84.212 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 8.43.85.76 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 152.19.134.149 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 209.132.181.20 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 8.43.85.78 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 152.19.134.191 --dport 8443:8445 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 140.211.169.199 --dport 8443:8445 -j ACCEPT',] - +# For the MOTD +csi_security_category: Low +custom_rules: ['-A INPUT -p tcp -m tcp -s 8.43.84.211 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 8.43.84.212 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 8.43.85.76 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 152.19.134.149 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.181.20 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 8.43.85.78 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 152.19.134.191 --dport 8443:8445 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 140.211.169.199 --dport 8443:8445 -j ACCEPT'] +lvm_size: 50000 +max_mem_size: 16348 +mem_size: 8192 nagios_Check_Services: - nrpe: false mail: false + nrpe: false + ping: false sshd: false swap: false - ping: false - -## End of file +num_cpus: 8 diff --git a/inventory/group_vars/resultsdb_dev b/inventory/group_vars/resultsdb_dev index 179aed526a..51a102981b 100644 --- a/inventory/group_vars/resultsdb_dev +++ b/inventory/group_vars/resultsdb_dev @@ -2,16 +2,23 @@ ############################################################ # general information ############################################################ +allowed_hosts: + - 10.5.124 deployment_type: dev +execdb_db_host: "{{ execdb_db_host_machine }}" +############################################################ +# execdb details +############################################################ +execdb_db_host_machine: db-qa01.qa.fedoraproject.org +execdb_db_name: execdb_dev +execdb_db_password: "{{ dev_execdb_db_password }}" +execdb_db_port: 5432 +execdb_db_user: "{{ dev_execdb_db_user }}" +execdb_endpoint: 'execdb' +execdb_secret_key: "{{ dev_execdb_secret_key }}" external_hostname: taskotron-dev.fedoraproject.org -tcp_ports: [ 80, 443, "{{ resultsdb_db_port }}", "{{ execdb_db_port }}" ] - freezes: false - - - - - +resultsdb_db_host: "{{ resultsdb_db_host_machine }}" ############################################################ # resultsdb details ############################################################ @@ -20,47 +27,28 @@ freezes: false # that db is localhost relative to resultsdb # resultsdb_db_host_machine: db-qa01.qa.fedoraproject.org -resultsdb_db_host: "{{ resultsdb_db_host_machine }}" -resultsdb_db_port: 5432 -resultsdb_endpoint: 'resultsdb_api' resultsdb_db_name: resultsdb_dev -resultsdb_db_user: "{{ dev_resultsdb_db_user }}" resultsdb_db_password: "{{ dev_resultsdb_db_password }}" -resultsdb_secret_key: "{{ dev_resultsdb_secret_key }}" - -allowed_hosts: - - 10.5.124 - +resultsdb_db_port: 5432 +resultsdb_db_user: "{{ dev_resultsdb_db_user }}" +resultsdb_endpoint: 'resultsdb_api' ############################################################ # resultsdb-frontend details ############################################################ resultsdb_fe_endpoint: "resultsdb" resultsdb_frontend_secret_key: "{{ dev_resultsdb_frontend_secret_key }}" - - -############################################################ -# execdb details -############################################################ -execdb_db_host_machine: db-qa01.qa.fedoraproject.org -execdb_db_host: "{{ execdb_db_host_machine }}" -execdb_db_port: 5432 -execdb_endpoint: 'execdb' -execdb_db_name: execdb_dev -execdb_db_user: "{{ dev_execdb_db_user }}" -execdb_db_password: "{{ dev_execdb_db_password }}" -execdb_secret_key: "{{ dev_execdb_secret_key }}" - - +resultsdb_secret_key: "{{ dev_resultsdb_secret_key }}" +tcp_ports: [80, 443, "{{ resultsdb_db_port }}", "{{ execdb_db_port }}"] +vault_db_host: "{{ vault_db_host_machine }}" +vault_db_host_machine: db-qa01.qa.fedoraproject.org +vault_db_name: vault_dev +vault_db_password: "{{ dev_vault_db_password }}" +vault_db_port: 5432 +vault_db_user: "{{ dev_vault_db_user }}" +vault_endpoint: 'vault' +vault_masterkey: "{{dev_vault_masterkey}}" ############################################################ # vault details ############################################################ vault_public_url: "https://taskotron-dev.fedoraproject.org/vault" -vault_db_host_machine: db-qa01.qa.fedoraproject.org -vault_db_host: "{{ vault_db_host_machine }}" -vault_db_port: 5432 -vault_endpoint: 'vault' -vault_db_name: vault_dev -vault_db_user: "{{ dev_vault_db_user }}" -vault_db_password: "{{ dev_vault_db_password }}" vault_secret_key: "{{ dev_vault_secret_key }}" -vault_masterkey: "{{dev_vault_masterkey}}" diff --git a/inventory/group_vars/resultsdb_prod b/inventory/group_vars/resultsdb_prod index f41e1c23a6..9da659ac16 100644 --- a/inventory/group_vars/resultsdb_prod +++ b/inventory/group_vars/resultsdb_prod @@ -2,88 +2,72 @@ ############################################################ # general information ############################################################ +allowed_hosts: + - 10.3.160.0/19 deployment_type: prod -vpn: true +execdb_db_host: "{{ execdb_db_host_machine }}" +############################################################ +# execdb details +############################################################ +execdb_db_host_machine: db01.iad2.fedoraproject.org +execdb_db_name: execdb +execdb_db_password: "{{ prod_execdb_db_password }}" +execdb_db_port: 5432 +execdb_db_user: "{{ prod_execdb_db_user }}" +execdb_endpoint: 'execdb' +execdb_secret_key: "{{ prod_execdb_secret_key }}" external_hostname: taskotron.fedoraproject.org -tcp_ports: [ 80, 443, "{{ resultsdb_db_port }}" ] - +############################################################ +# fedmsg details +############################################################ +fedmsg_active: True +fedmsg_cert_prefix: resultsdb +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - taskotron.result.new + - resultsdb.result.new + group: apache + owner: root + service: resultsdb +ipa_client_shell_groups: + - sysadmin-qa +ipa_client_sudo_groups: + - sysadmin-qa +ipa_host_group: resultsdb +ipa_host_group_desc: ResultsDB application servers # common items for the releng-* boxes lvm_size: 50000 mem_size: 16384 +nrpe_procs_crit: 300 +nrpe_procs_warn: 250 num_cpus: 4 # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file primary_auth_source: ipa -ipa_host_group: resultsdb -ipa_host_group_desc: ResultsDB application servers -ipa_client_shell_groups: -- sysadmin-qa -ipa_client_sudo_groups: -- sysadmin-qa - -nrpe_procs_warn: 250 -nrpe_procs_crit: 300 - - - - - +resultsdb_db_host: "{{ resultsdb_db_host_machine }}" ############################################################ # resultsdb details ############################################################ # the db_host_machine bits are so that delegation continues to work, even if # that db is localhost relative to resultsdb - resultsdb_db_host_machine: db01.iad2.fedoraproject.org -resultsdb_db_host: "{{ resultsdb_db_host_machine }}" -resultsdb_db_port: 5432 -resultsdb_endpoint: 'resultsdb_api' resultsdb_db_name: resultsdb -resultsdb_db_user: "{{ prod_resultsdb_db_user }}" resultsdb_db_password: "{{ prod_resultsdb_db_password }}" -resultsdb_secret_key: "{{ prod_resultsdb_secret_key }}" - -allowed_hosts: - - 10.3.160.0/19 - - +resultsdb_db_port: 5432 +resultsdb_db_user: "{{ prod_resultsdb_db_user }}" +resultsdb_endpoint: 'resultsdb_api' ############################################################ # resultsdb-frontend details ############################################################ resultsdb_fe_endpoint: "resultsdb" resultsdb_frontend_secret_key: "{{ prod_resultsdb_frontend_secret_key }}" - - -############################################################ -# execdb details -############################################################ -execdb_db_host_machine: db01.iad2.fedoraproject.org -execdb_db_host: "{{ execdb_db_host_machine }}" -execdb_db_port: 5432 -execdb_endpoint: 'execdb' -execdb_db_name: execdb -execdb_db_user: "{{ prod_execdb_db_user }}" -execdb_db_password: "{{ prod_execdb_db_password }}" -execdb_secret_key: "{{ prod_execdb_secret_key }}" - - -############################################################ -# fedmsg details -############################################################ -fedmsg_active: True -fedmsg_cert_prefix: resultsdb - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: resultsdb - owner: root - group: apache - can_send: - - taskotron.result.new - - resultsdb.result.new +resultsdb_secret_key: "{{ prod_resultsdb_secret_key }}" +tcp_ports: [80, 443, "{{ resultsdb_db_port }}"] +vpn: true diff --git a/inventory/group_vars/resultsdb_stg b/inventory/group_vars/resultsdb_stg index 507cce9e38..e44d2b8c1f 100644 --- a/inventory/group_vars/resultsdb_stg +++ b/inventory/group_vars/resultsdb_stg @@ -2,82 +2,67 @@ ############################################################ # general information ############################################################ +allowed_hosts: + - 10.3.160.0/19 deployment_type: stg +execdb_db_host: "{{ execdb_db_host_machine }}" +############################################################ +# execdb details +############################################################ +execdb_db_host_machine: db-qa01.qa.fedoraproject.org +execdb_db_name: execdb_stg +execdb_db_password: "{{ stg_execdb_db_password }}" +execdb_db_port: 5432 +execdb_db_user: "{{ stg_execdb_db_user }}" +execdb_endpoint: 'execdb' +execdb_secret_key: "{{ stg_execdb_secret_key }}" external_hostname: taskotron.stg.fedoraproject.org -tcp_ports: [ 80, 443, "{{ resultsdb_db_port }}" ] - -freezes: false - - +############################################################ +# fedmsg details +############################################################ +fedmsg_active: True +fedmsg_cert_prefix: resultsdb +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - taskotron.result.new + - resultsdb.result.new + group: apache + owner: root + service: resultsdb # make sure we're using the stg fedsmg bus fedmsg_env: stg - +freezes: false +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-qa + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-qa ipa_host_group: resultsdb ipa_host_group_desc: ResultsDB application servers -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-qa -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-qa - +resultsdb_db_host: "{{ resultsdb_db_host_machine }}" ############################################################ # resultsdb details ############################################################ # the db_host_machine bits are so that delegation continues to work, even if # that db is localhost relative to resultsdb - resultsdb_db_host_machine: db01.stg.iad2.fedoraproject.org -resultsdb_db_host: "{{ resultsdb_db_host_machine }}" -resultsdb_db_port: 5432 -resultsdb_endpoint: 'resultsdb_api' resultsdb_db_name: resultsdb_stg -resultsdb_db_user: "{{ stg_resultsdb_db_user }}" resultsdb_db_password: "{{ stg_resultsdb_db_password }}" -resultsdb_secret_key: "{{ stg_resultsdb_secret_key }}" - -allowed_hosts: - - 10.3.160.0/19 - - - +resultsdb_db_port: 5432 +resultsdb_db_user: "{{ stg_resultsdb_db_user }}" +resultsdb_endpoint: 'resultsdb_api' ############################################################ # resultsdb-frontend details ############################################################ resultsdb_fe_endpoint: "resultsdb" resultsdb_frontend_secret_key: "{{ stg_resultsdb_frontend_secret_key }}" - - -############################################################ -# execdb details -############################################################ -execdb_db_host_machine: db-qa01.qa.fedoraproject.org -execdb_db_host: "{{ execdb_db_host_machine }}" -execdb_db_port: 5432 -execdb_endpoint: 'execdb' -execdb_db_name: execdb_stg -execdb_db_user: "{{ stg_execdb_db_user }}" -execdb_db_password: "{{ stg_execdb_db_password }}" -execdb_secret_key: "{{ stg_execdb_secret_key }}" - - -############################################################ -# fedmsg details -############################################################ -fedmsg_active: True -fedmsg_cert_prefix: resultsdb - -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: resultsdb - owner: root - group: apache - can_send: - - taskotron.result.new - - resultsdb.result.new +resultsdb_secret_key: "{{ stg_resultsdb_secret_key }}" +tcp_ports: [80, 443, "{{ resultsdb_db_port }}"] diff --git a/inventory/group_vars/retrace b/inventory/group_vars/retrace index 8f8e854e1d..1d39f674fd 100644 --- a/inventory/group_vars/retrace +++ b/inventory/group_vars/retrace @@ -1,59 +1,50 @@ --- -env: production - -primary_auth_source: ipa -ipa_host_group: retrace -ipa_host_group_desc: Retrace servers -ipa_client_shell_groups: -- retrace -ipa_client_sudo_groups: -- retrace - -vpn: true - -freezes: false ansible_ifcfg_blocklist: true - -tcp_ports: [ 80, 443 ] - custom_rules: -- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 2049 -j ACCEPT' -- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 5432 -j ACCEPT' - - -nrpe_procs_warn: 1800 -nrpe_procs_crit: 2000 - + - '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 2049 -j ACCEPT' + - '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 5432 -j ACCEPT' +env: production # Since retrace is on the qa network, it needs to actively connect to our # inbound relay. fedmsg_active: True fedmsg_cert_prefix: faf - # Declare fedmsg certs that should be put in /etc/pki/fedmsg/ # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: retrace - can_send: - - logger.log -- service: faf - owner: root - group: faf - can_send: - - faf.report.threshold1 - - faf.report.threshold10 - - faf.report.threshold100 - - faf.report.threshold1000 - - faf.report.threshold1000 - - faf.report.threshold10000 - - faf.report.threshold100000 - - faf.report.threshold1000000 - - faf.problem.threshold1 - - faf.problem.threshold10 - - faf.problem.threshold100 - - faf.problem.threshold1000 - - faf.problem.threshold1000 - - faf.problem.threshold10000 - - faf.problem.threshold100000 - - faf.problem.threshold1000000 + - can_send: + - logger.log + group: retrace + owner: root + service: shell + - can_send: + - faf.report.threshold1 + - faf.report.threshold10 + - faf.report.threshold100 + - faf.report.threshold1000 + - faf.report.threshold1000 + - faf.report.threshold10000 + - faf.report.threshold100000 + - faf.report.threshold1000000 + - faf.problem.threshold1 + - faf.problem.threshold10 + - faf.problem.threshold100 + - faf.problem.threshold1000 + - faf.problem.threshold1000 + - faf.problem.threshold10000 + - faf.problem.threshold100000 + - faf.problem.threshold1000000 + group: faf + owner: root + service: faf +freezes: false +ipa_client_shell_groups: + - retrace +ipa_client_sudo_groups: + - retrace +ipa_host_group: retrace +ipa_host_group_desc: Retrace servers +nrpe_procs_crit: 2000 +nrpe_procs_warn: 1800 +primary_auth_source: ipa +tcp_ports: [80, 443] +vpn: true diff --git a/inventory/group_vars/retrace_stg_aws b/inventory/group_vars/retrace_stg_aws index 92290aacf7..e3300dba18 100644 --- a/inventory/group_vars/retrace_stg_aws +++ b/inventory/group_vars/retrace_stg_aws @@ -1,14 +1,10 @@ --- env: staging - -vpn: true - -tcp_ports: [ 22, 80, 443 ] - -sudoers: "{{ private }}/files/sudo/arm-retrace-sudoers" -root_auth_users: msuchy mfabik mgrabovs mzidek - nagios_Check_Services: mail: false nrpe: false swap: false +root_auth_users: msuchy mfabik mgrabovs mzidek +sudoers: "{{ private }}/files/sudo/arm-retrace-sudoers" +tcp_ports: [22, 80, 443] +vpn: true diff --git a/inventory/group_vars/secondary b/inventory/group_vars/secondary index cd12c313a4..daf246297e 100644 --- a/inventory/group_vars/secondary +++ b/inventory/group_vars/secondary @@ -1,29 +1,26 @@ --- datacenter: iad2 -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -sshd_sftp: true - -# nfs mount options, overrides the all/default -nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=3" - host_group: secondary - -primary_auth_source: ipa +ipa_client_shell_groups: + - alt-k12linux + - alt-sugar + - altvideos + - fi-apprentice + - hosted-content + - mips-content + - qa-deltaisos + - s390_content + - sysadmin-noc + - sysadmin-veteran +ipa_client_sudo_groups: + - sysadmin-noc ipa_host_group: secondary ipa_host_group_desc: Serve secondary arch and archived releases -ipa_client_shell_groups: -- alt-k12linux -- alt-sugar -- altvideos -- fi-apprentice -- hosted-content -- mips-content -- qa-deltaisos -- s390_content -- sysadmin-noc -- sysadmin-veteran -ipa_client_sudo_groups: -- sysadmin-noc +# nfs mount options, overrides the all/default +nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=3" +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +primary_auth_source: ipa +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +sshd_sftp: true +tcp_ports: [80, 443, 873] diff --git a/inventory/group_vars/sign_bridge b/inventory/group_vars/sign_bridge index 08a1ec65bd..415611410b 100644 --- a/inventory/group_vars/sign_bridge +++ b/inventory/group_vars/sign_bridge @@ -1,17 +1,14 @@ --- freezes: true -postfix_group: sign - +ipa_client_shell_groups: + - sysadmin-releng +ipa_client_sudo_groups: + - sysadmin-releng +ipa_host_group: sign-bridge # Define resources for this group of hosts here. lvm_size: 50000 mem_size: 4096 num_cpus: 4 - -tcp_ports: [ 44333, 44334 ] - +postfix_group: sign primary_auth_source: ipa -ipa_host_group: sign-bridge -ipa_client_shell_groups: -- sysadmin-releng -ipa_client_sudo_groups: -- sysadmin-releng +tcp_ports: [44333, 44334] diff --git a/inventory/group_vars/sign_vault b/inventory/group_vars/sign_vault index b08eb6cbfb..3110214d92 100644 --- a/inventory/group_vars/sign_vault +++ b/inventory/group_vars/sign_vault @@ -1,11 +1,11 @@ --- -freezes: true -postfix_group: sign -host_group: sign ansible_ifcfg_blocklist: true +freezes: true +host_group: sign nagios_Check_Services: mail: false nrpe: false + ping: true sshd: false swap: false - ping: true +postfix_group: sign diff --git a/inventory/group_vars/smtp_mm b/inventory/group_vars/smtp_mm index 66e522f2fb..cbb3b69add 100644 --- a/inventory/group_vars/smtp_mm +++ b/inventory/group_vars/smtp_mm @@ -1,31 +1,26 @@ --- # Define resources for this group of hosts here. -lvm_size: 20000 -mem_size: 2048 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 25 ] - -primary_auth_source: ipa +ipa_client_shell_access: + - fi-apprentice + - sysadmin-noc + - sysadmin-tools + - sysadmin-veteran +ipa_client_sudo_access: + - sysadmin-noc + - sysadmin-tools + - sysadmin-veteran ipa_host_group: smtp_mm ipa_host_group_desc: SMTP servers -ipa_client_shell_access: -- fi-apprentice -- sysadmin-noc -- sysadmin-tools -- sysadmin-veteran -ipa_client_sudo_access: -- sysadmin-noc -- sysadmin-tools -- sysadmin-veteran - -postfix_transport_filename: transports.smtp-mm -postfix_group: smtp-mm -vpn: true - +lvm_size: 20000 +mem_size: 2048 nagios_Check_Services: - nrpe: true mail: false + nrpe: true +num_cpus: 2 +postfix_group: smtp-mm +postfix_transport_filename: transports.smtp-mm +primary_auth_source: ipa +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [25] +vpn: true diff --git a/inventory/group_vars/staging b/inventory/group_vars/staging index 3c41c9270e..786d6f5ea4 100644 --- a/inventory/group_vars/staging +++ b/inventory/group_vars/staging @@ -1,44 +1,38 @@ --- -freezes: false +deployment_type: stg env: staging env_prefix: stg. -env_suffix: .stg env_short: stg -host_group: staging - -# This is the wildcard certname for our stg proxies. -wildcard_cert_name: wildcard-2020.stg.fedoraproject.org -wildcard_cert_file: wildcard-2020.stg.fedoraproject.org.cert -wildcard_key_file: wildcard-2020.stg.fedoraproject.org.key -wildcard_int_file: wildcard-2020.stg.fedoraproject.org.intermediate.cert - -# This is the openshift wildcard cert for stg -os_wildcard_cert_name: wildcard-2021.app.os.stg.fedoraproject.org -os_wildcard_cert_file: wildcard-2021.app.os.stg.fedoraproject.org.cert -os_wildcard_key_file: wildcard-2021.app.os.stg.fedoraproject.org.key -os_wildcard_int_file: wildcard-2021.app.os.stg.fedoraproject.org.intermediate.cert - -# This is the openshift wildcard cert for ocp stg -ocp_wildcard_cert_name: wildcard-2021.apps.ocp.stg.fedoraproject.org -ocp_wildcard_cert_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.cert -ocp_wildcard_key_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.key -ocp_wildcard_int_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.intermediate.cert - -# This is the mirrors.stg.centos.org certs -mirrors_centos_org_cert_name: mirrors.stg.centos.org -mirrors_centos_org_cert_file: mirrors.stg.centos.org.cert -mirrors_centos_org_key_file: mirrors.stg.centos.org.key - -fedmsg_prefix: org.fedoraproject +env_suffix: .stg fedmsg_env: stg -deployment_type: stg - +fedmsg_prefix: org.fedoraproject +freezes: false +host_group: staging +ipa_admin_password: "{{ ipa_stg_admin_password }}" +ipa_realm: STG.FEDORAPROJECT.ORG # IPA details ipa_server: ipa01.stg.iad2.fedoraproject.org -ipa_realm: STG.FEDORAPROJECT.ORG -ipa_admin_password: "{{ ipa_stg_admin_password }}" -# RIP, FAS -primary_auth_source: ipa ipa_server_nodes: - ipa01.stg.iad2.fedoraproject.org - ipa02.stg.iad2.fedoraproject.org +mirrors_centos_org_cert_file: mirrors.stg.centos.org.cert +# This is the mirrors.stg.centos.org certs +mirrors_centos_org_cert_name: mirrors.stg.centos.org +mirrors_centos_org_key_file: mirrors.stg.centos.org.key +ocp_wildcard_cert_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.cert +# This is the openshift wildcard cert for ocp stg +ocp_wildcard_cert_name: wildcard-2021.apps.ocp.stg.fedoraproject.org +ocp_wildcard_int_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.intermediate.cert +ocp_wildcard_key_file: wildcard-2021.apps.ocp.stg.fedoraproject.org.key +os_wildcard_cert_file: wildcard-2021.app.os.stg.fedoraproject.org.cert +# This is the openshift wildcard cert for stg +os_wildcard_cert_name: wildcard-2021.app.os.stg.fedoraproject.org +os_wildcard_int_file: wildcard-2021.app.os.stg.fedoraproject.org.intermediate.cert +os_wildcard_key_file: wildcard-2021.app.os.stg.fedoraproject.org.key +# RIP, FAS +primary_auth_source: ipa +wildcard_cert_file: wildcard-2020.stg.fedoraproject.org.cert +# This is the wildcard certname for our stg proxies. +wildcard_cert_name: wildcard-2020.stg.fedoraproject.org +wildcard_int_file: wildcard-2020.stg.fedoraproject.org.intermediate.cert +wildcard_key_file: wildcard-2020.stg.fedoraproject.org.key diff --git a/inventory/group_vars/sundries b/inventory/group_vars/sundries index c9fec7bdfd..608bd7d5e7 100644 --- a/inventory/group_vars/sundries +++ b/inventory/group_vars/sundries @@ -1,34 +1,27 @@ --- # Define resources for this group of hosts here. -lvm_size: 50000 -mem_size: 2048 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 873 ] - -# This gets overridden by whichever node we want to run special cronjobs. -master_sundries_node: False - deployment_type: prod - -# A host group for rsync config -rsync_group: sundries - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - -primary_auth_source: ipa +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-releng + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-releng + - sysadmin-web ipa_host_group: sundries ipa_host_group_desc: Odds and ends -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-releng -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-releng -- sysadmin-web +lvm_size: 50000 +# This gets overridden by whichever node we want to run special cronjobs. +master_sundries_node: False +mem_size: 2048 +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 2 +primary_auth_source: ipa +# A host group for rsync config +rsync_group: sundries +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 873] diff --git a/inventory/group_vars/sundries_stg b/inventory/group_vars/sundries_stg index 3b759fbda6..322b6493a2 100644 --- a/inventory/group_vars/sundries_stg +++ b/inventory/group_vars/sundries_stg @@ -1,33 +1,26 @@ --- # Define resources for this group of hosts here. -lvm_size: 50000 -mem_size: 2048 -num_cpus: 2 - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 873 ] - -# This gets overridden by whichever node we want to run special cronjobs. -master_sundries_node: False - deployment_type: stg - -# A host group for rsync config -rsync_group: sundries-stg - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 - +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-releng + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-releng + - sysadmin-web ipa_host_group: sundries ipa_host_group_desc: Odds and ends -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-releng -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-releng -- sysadmin-web +lvm_size: 50000 +# This gets overridden by whichever node we want to run special cronjobs. +master_sundries_node: False +mem_size: 2048 +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 2 +# A host group for rsync config +rsync_group: sundries-stg +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 873] diff --git a/inventory/group_vars/tang b/inventory/group_vars/tang index 5c1457a004..2b5256557e 100644 --- a/inventory/group_vars/tang +++ b/inventory/group_vars/tang @@ -1,7 +1,5 @@ --- # for systems that do not match the above - specify the same parameter in # the host_vars/$hostname file - -tcp_ports: [80] - primary_auth_source: ipa +tcp_ports: [80] diff --git a/inventory/group_vars/torrent b/inventory/group_vars/torrent index a668fc6315..f9060dcb54 100644 --- a/inventory/group_vars/torrent +++ b/inventory/group_vars/torrent @@ -1,39 +1,36 @@ --- # Define resources for this group of hosts here. -lvm_size: 750000 -mem_size: 4096 -num_cpus: 2 - -tcp_ports: [ 53, 80, 443, 873, "6881:6999" ] -udp_ports: [ 53 ] - -primary_auth_source: ipa -ipa_host_group: torrent -ipa_host_group_desc: BitTorrent trackers -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -- torrent-cc -- torrentadmin -ipa_client_sudo_groups: -- sysadmin-web -- torrentadmin - -nrpe_procs_warn: 300 -nrpe_procs_crit: 500 -csi_security_category: Low csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Torrent master server for Fedora distribution csi_relationship: | - torrent01 is the master torrent server for Fedora releases - This host relies on: - - The virthost it's hosted on (ibiblio05.fedoraproject.org) - - FAS to authenticate users - - VPN connectivity + torrent01 is the master torrent server for Fedora releases + This host relies on: + - The virthost it's hosted on (ibiblio05.fedoraproject.org) + - FAS to authenticate users + - VPN connectivity - Things that rely on this host: - - If this host is down, Fedora will lose a release distribution channel - - The Apache that displays the torrent website - - This server also has opentracker+ running to gather statistics for our torrent + Things that rely on this host: + - If this host is down, Fedora will lose a release distribution channel + - The Apache that displays the torrent website + - This server also has opentracker+ running to gather statistics for our torrent +csi_security_category: Low +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web + - torrent-cc + - torrentadmin +ipa_client_sudo_groups: + - sysadmin-web + - torrentadmin +ipa_host_group: torrent +ipa_host_group_desc: BitTorrent trackers +lvm_size: 750000 +mem_size: 4096 +nrpe_procs_crit: 500 +nrpe_procs_warn: 300 +num_cpus: 2 +primary_auth_source: ipa +tcp_ports: [53, 80, 443, 873, "6881:6999"] +udp_ports: [53] diff --git a/inventory/group_vars/unbound b/inventory/group_vars/unbound index e7a6db9e91..26909ea388 100644 --- a/inventory/group_vars/unbound +++ b/inventory/group_vars/unbound @@ -1,23 +1,15 @@ --- +custom_rules: ['-A INPUT -p tcp -m tcp -s 209.132.184.0/24 --dport 53 -j ACCEPT', '-A INPUT -p udp -m udp -s 209.132.184.0/24 --dport 53 -j ACCEPT', '-A INPUT -p udp -m udp -s 38.145.48.0/23 --dport 53 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 38.145.48.0/23 --dport 53 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.181.0/24 --dport 53 -j ACCEPT', '-A INPUT -p udp -m udp -s 209.132.181.0/24 --dport 53 -j ACCEPT'] +freezes: false +ipa_client_shell_groups: + - sysadmin-dns +ipa_client_sudo_groups: + - sysadmin-dns +ipa_host_group: unbound +ipa_host_group_desc: Unbound caching DNS lvm_size: 10000 mem_size: 2048 num_cpus: 2 - -tcp_ports: [ 80, 443 ] -custom_rules: [ '-A INPUT -p tcp -m tcp -s 209.132.184.0/24 --dport 53 -j ACCEPT', - '-A INPUT -p udp -m udp -s 209.132.184.0/24 --dport 53 -j ACCEPT', - '-A INPUT -p udp -m udp -s 38.145.48.0/23 --dport 53 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 38.145.48.0/23 --dport 53 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 209.132.181.0/24 --dport 53 -j ACCEPT', - '-A INPUT -p udp -m udp -s 209.132.181.0/24 --dport 53 -j ACCEPT' ] - -primary_auth_source: ipa -ipa_host_group: unbound -ipa_host_group_desc: Unbound caching DNS -ipa_client_shell_groups: -- sysadmin-dns -ipa_client_sudo_groups: -- sysadmin-dns - -freezes: false postfix_group: vpn +primary_auth_source: ipa +tcp_ports: [80, 443] diff --git a/inventory/group_vars/value b/inventory/group_vars/value index 027cb5dc78..ce2880eb72 100644 --- a/inventory/group_vars/value +++ b/inventory/group_vars/value @@ -1,77 +1,66 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 6144 -num_cpus: 2 - -deployment_type: prod - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443, - # These 16 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, - 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] - -custom_rules: [ - # Needed for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - # Needed to let nagios on noc01 and noc02 pipe alerts to zodbot here - '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5050 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.20 --dport 5050 -j ACCEPT', - # batcave01 also needs access to announce commits. - '-A INPUT -p tcp -m tcp -s 10.3.163.35 --dport 5050 -j ACCEPT', -] - -primary_auth_source: ipa -ipa_host_group: value -ipa_host_group_desc: "Value added: IRC bots, message logging, etc." -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-mote -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-mote -- sysadmin-web - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: supybot - owner: root - group: daemon - can_send: - # cookies! - - irc.karma - # standard meetbot stuff - - meetbot.meeting.complete - - meetbot.meeting.start - - meetbot.meeting.topic.update - # meetbot line items - - meetbot.meeting.item.agreed - - meetbot.meeting.item.accepted - - meetbot.meeting.item.rejected - - meetbot.meeting.item.action - - meetbot.meeting.item.info - - meetbot.meeting.item.idea - - meetbot.meeting.item.help - - meetbot.meeting.item.link - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: mote admins - sysadmin-mote-members@fedoraproject.org csi_purpose: Hosts services which help facilitate communication over IRC and related mediums. csi_relationship: | - There are a couple things running here. + There are a couple things running here. - * zodbot, a supybot instance. See the zodbot SOP for more info. - * fedmsg-irc, our fedmsg to IRC relay. 'journalctl -u fedmsg-irc' - * mote, a webapp running behind httpd that serves meetbot log files. + * zodbot, a supybot instance. See the zodbot SOP for more info. + * fedmsg-irc, our fedmsg to IRC relay. 'journalctl -u fedmsg-irc' + * mote, a webapp running behind httpd that serves meetbot log files. +# For the MOTD +csi_security_category: Moderate +custom_rules: [ + # Needed for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # Needed to let nagios on noc01 and noc02 pipe alerts to zodbot here + '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5050 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.20 --dport 5050 -j ACCEPT', + # batcave01 also needs access to announce commits. + '-A INPUT -p tcp -m tcp -s 10.3.163.35 --dport 5050 -j ACCEPT'] +deployment_type: prod +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + # cookies! + - irc.karma + # standard meetbot stuff + - meetbot.meeting.complete + - meetbot.meeting.start + - meetbot.meeting.topic.update + # meetbot line items + - meetbot.meeting.item.agreed + - meetbot.meeting.item.accepted + - meetbot.meeting.item.rejected + - meetbot.meeting.item.action + - meetbot.meeting.item.info + - meetbot.meeting.item.idea + - meetbot.meeting.item.help + - meetbot.meeting.item.link + group: daemon + owner: root + service: supybot +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-mote + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-mote + - sysadmin-web +ipa_host_group: value +ipa_host_group_desc: "Value added: IRC bots, message logging, etc." +lvm_size: 30000 +mem_size: 6144 +num_cpus: 2 +primary_auth_source: ipa +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, + # These 16 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] diff --git a/inventory/group_vars/value_stg b/inventory/group_vars/value_stg index d5af22614e..a7b1ec4acf 100644 --- a/inventory/group_vars/value_stg +++ b/inventory/group_vars/value_stg @@ -1,78 +1,65 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 6144 -num_cpus: 2 - -deployment_type: stg - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443, - # These 16 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, - 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] - -custom_rules: [ - # Neeed for rsync from log01 for logs. - '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - # Needed to let nagios on noc01 and noc02 (noc01.stg) pipe alerts to zodbot here - '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5050 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.5.128.38 --dport 5050 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 152.19.134.192 --dport 5050 -j ACCEPT', - # batcave01 also needs access to announce commits. - '-A INPUT -p tcp -m tcp -s 10.5.126.23 --dport 5050 -j ACCEPT', -] - -ipa_host_group: value -ipa_host_group_desc: "Value added: IRC bots, message logging, etc." -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-mote -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-mote -- sysadmin-web - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: supybot - owner: root - group: daemon - can_send: - # cookies! - - irc.karma - # standard meetbot stuff - - meetbot.meeting.complete - - meetbot.meeting.start - - meetbot.meeting.topic.update - # meetbot line items - - meetbot.meeting.item.agreed - - meetbot.meeting.item.accepted - - meetbot.meeting.item.rejected - - meetbot.meeting.item.action - - meetbot.meeting.item.info - - meetbot.meeting.item.idea - - meetbot.meeting.item.help - - meetbot.meeting.item.link - - -# For the MOTD -csi_security_category: Moderate csi_primary_contact: mote admins - sysadmin-mote-members@fedoraproject.org csi_purpose: Hosts staging services which help facilitate communication over IRC and related mediums. csi_relationship: | - There are a couple things running here. + There are a couple things running here. - * ursabot, a supybot instance. See the zodbot SOP for more info. - * fedmsg-irc, our staging fedmsg to IRC relay. 'journalctl -u fedmsg-irc' - * mote, a webapp running behind httpd that serves meetbot log files. + * ursabot, a supybot instance. See the zodbot SOP for more info. + * fedmsg-irc, our staging fedmsg to IRC relay. 'journalctl -u fedmsg-irc' + * mote, a webapp running behind httpd that serves meetbot log files. +# For the MOTD +csi_security_category: Moderate +custom_rules: [ + # Neeed for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # Needed to let nagios on noc01 and noc02 (noc01.stg) pipe alerts to zodbot here + '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5050 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.128.38 --dport 5050 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 152.19.134.192 --dport 5050 -j ACCEPT', + # batcave01 also needs access to announce commits. + '-A INPUT -p tcp -m tcp -s 10.5.126.23 --dport 5050 -j ACCEPT'] +deployment_type: stg +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + # cookies! + - irc.karma + # standard meetbot stuff + - meetbot.meeting.complete + - meetbot.meeting.start + - meetbot.meeting.topic.update + # meetbot line items + - meetbot.meeting.item.agreed + - meetbot.meeting.item.accepted + - meetbot.meeting.item.rejected + - meetbot.meeting.item.action + - meetbot.meeting.item.info + - meetbot.meeting.item.idea + - meetbot.meeting.item.help + - meetbot.meeting.item.link + group: daemon + owner: root + service: supybot +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-mote + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-mote + - sysadmin-web +ipa_host_group: value +ipa_host_group_desc: "Value added: IRC bots, message logging, etc." +lvm_size: 30000 +mem_size: 6144 +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443, + # These 16 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015] diff --git a/inventory/group_vars/virthost b/inventory/group_vars/virthost index 76dfbe55bb..a72e8f3e5b 100644 --- a/inventory/group_vars/virthost +++ b/inventory/group_vars/virthost @@ -1,25 +1,20 @@ --- # iscsi initiator for netapp iscsi volume -netapp_nfs01_iscsi_name: iqn.1992-08.com.netapp:sn.1573980325:vf.f88732f4-106e-11e2-bc86-00a098162a28 -# iscsi portal for netapp iscsi volume -netapp_nfs01_iscsi_portal: 10.5.88.36 - -virthost: true -nrpe_procs_warn: 1400 -nrpe_procs_crit: 1500 - -# These variables are pushed into /etc/system_identification by the base role. -# Groups and individual hosts should override them with specific info. -# See http://infrastructure.fedoraproject.org/csi/security-policy/ - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: Host guest virtual machines. csi_relationship: | - - Guests on this host will be inaccessible if the host is down. - - This host will be required by any application with a virtual machine running on it, therefore, if this host is down those applications will be impacted. - + - Guests on this host will be inaccessible if the host is down. + - This host will be required by any application with a virtual machine running on it, therefore, if this host is down those applications will be impacted. +# These variables are pushed into /etc/system_identification by the base role. +# Groups and individual hosts should override them with specific info. +# See http://infrastructure.fedoraproject.org/csi/security-policy/ +csi_security_category: High nagios_Check_Services: raid: true - +netapp_nfs01_iscsi_name: iqn.1992-08.com.netapp:sn.1573980325:vf.f88732f4-106e-11e2-bc86-00a098162a28 +# iscsi portal for netapp iscsi volume +netapp_nfs01_iscsi_portal: 10.5.88.36 +nrpe_procs_crit: 1500 +nrpe_procs_warn: 1400 primary_auth_source: ipa +virthost: true diff --git a/inventory/group_vars/virthost_comm b/inventory/group_vars/virthost_comm index 9def4dba8f..62426783b6 100644 --- a/inventory/group_vars/virthost_comm +++ b/inventory/group_vars/virthost_comm @@ -1,5 +1,4 @@ --- -nrpe_procs_warn: 900 nrpe_procs_crit: 1000 - +nrpe_procs_warn: 900 virthost: true diff --git a/inventory/group_vars/virthost_communishift b/inventory/group_vars/virthost_communishift index 6b77803e67..ea2d1d771c 100644 --- a/inventory/group_vars/virthost_communishift +++ b/inventory/group_vars/virthost_communishift @@ -1,3 +1,3 @@ --- -virthost: true datacenter: cloud +virthost: true diff --git a/inventory/group_vars/waiverdb b/inventory/group_vars/waiverdb index c7e0d6f0a8..07a8272ff6 100644 --- a/inventory/group_vars/waiverdb +++ b/inventory/group_vars/waiverdb @@ -2,9 +2,8 @@ # XXX - this is not really a group of real hosts. # Instead, it represents an application in openshift. # See playbooks/openshift-apps/waiverdb.yml - fedmsg_certs: -- service: waiverdb - can_send: - - logger.log - - waiverdb.waiver.new + - can_send: + - logger.log + - waiverdb.waiver.new + service: waiverdb diff --git a/inventory/group_vars/waiverdb_stg b/inventory/group_vars/waiverdb_stg index ad2305c2e1..f876ba3a97 100644 --- a/inventory/group_vars/waiverdb_stg +++ b/inventory/group_vars/waiverdb_stg @@ -2,11 +2,9 @@ # XXX - this is not really a group of real hosts. # Instead, it represents an application in openshift. # See playbooks/openshift-apps/waiverdb.yml - -fedmsg_env: stg - fedmsg_certs: -- service: waiverdb - can_send: - - logger.log - - waiverdb.waiver.new + - can_send: + - logger.log + - waiverdb.waiver.new + service: waiverdb +fedmsg_env: stg diff --git a/inventory/group_vars/wiki b/inventory/group_vars/wiki index 74c07a80da..4bf0cc246c 100644 --- a/inventory/group_vars/wiki +++ b/inventory/group_vars/wiki @@ -1,55 +1,46 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 8192 -max_mem_size: 8192 -num_cpus: 4 - +csi_primary_contact: "#fedora-admin" +csi_purpose: Provides our wiki +csi_relationship: | + - There are multiple servers that this service requires. All proxy servers and Wiki 1 and 2. + - Wiki requires the proxy servers in order for traffic to pass to them + - If the Apache processes stop on wiki01 and wiki02 the wiki will not display + - The wiki also requires fas for log in purposes +csi_security_category: Moderate deployment_type: prod - -virt_install_command: "{{ virt_install_command_two_nic }}" - -tcp_ports: [ 80 ] - -primary_auth_source: ipa +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - wiki.article.edit + - wiki.upload.complete + group: apache + owner: root + service: mediawiki +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web ipa_host_group: wiki ipa_host_group_desc: Fedora Wiki -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web - +lvm_size: 30000 +max_mem_size: 8192 +mem_size: 8192 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +num_cpus: 4 +primary_auth_source: ipa +tcp_ports: [80] +virt_install_command: "{{ virt_install_command_two_nic }}" # mediawiki variables wikiname: "fp" wikipath: "wiki" -wpath: "w" wikiver: "mediawiki" - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mediawiki - owner: root - group: apache - can_send: - - wiki.article.edit - - wiki.upload.complete - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -csi_security_category: Moderate -csi_primary_contact: "#fedora-admin" -csi_purpose: Provides our wiki -csi_relationship: | - - There are multiple servers that this service requires. All proxy servers and Wiki 1 and 2. - - Wiki requires the proxy servers in order for traffic to pass to them - - If the Apache processes stop on wiki01 and wiki02 the wiki will not display - - The wiki also requires fas for log in purposes - +wpath: "w" diff --git a/inventory/group_vars/wiki_stg b/inventory/group_vars/wiki_stg index 99459abe4a..c02a283d60 100644 --- a/inventory/group_vars/wiki_stg +++ b/inventory/group_vars/wiki_stg @@ -1,41 +1,35 @@ --- # Define resources for this group of hosts here. -lvm_size: 30000 -mem_size: 4096 -num_cpus: 2 - deployment_type: stg - -tcp_ports: [ 80 ] - +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + - can_send: + - logger.log + group: sysadmin + owner: root + service: shell + - can_send: + - wiki.article.edit + - wiki.upload.complete + group: apache + owner: root + service: mediawiki +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-web +ipa_client_sudo_groups: + - sysadmin-web ipa_host_group: wiki ipa_host_group_desc: Fedora Wiki -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-web -ipa_client_sudo_groups: -- sysadmin-web - +lvm_size: 30000 +mem_size: 4096 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +num_cpus: 2 +tcp_ports: [80] # mediawiki variables wikiname: "fp" wikipath: "wiki" -wpath: "w" wikiver: "mediawiki" - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -- service: shell - owner: root - group: sysadmin - can_send: - - logger.log -- service: mediawiki - owner: root - group: apache - can_send: - - wiki.article.edit - - wiki.upload.complete - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +wpath: "w" diff --git a/inventory/group_vars/zabbix_stg b/inventory/group_vars/zabbix_stg index 9a4c9d7ba4..a6a0902742 100644 --- a/inventory/group_vars/zabbix_stg +++ b/inventory/group_vars/zabbix_stg @@ -1,33 +1,27 @@ --- # Define resources for this group of hosts here. -lvm_size: 100000 -mem_size: 8192 -num_cpus: 2 - -deployment_type: stg - -# for systems that do not match the above - specify the same parameter in -# the host_vars/$hostname file - -tcp_ports: [ 80, 443] - -ipa_host_group: zabbix -ipa_host_group_desc: Zabbix Network Monitoring -ipa_client_shell_groups: -- fi-apprentice -- sysadmin-noc -- sysadmin-veteran -- sysadmin-jenkins -ipa_client_sudo_groups: -- sysadmin-jenkins - -# For the MOTD -csi_security_category: [] csi_primary_contact: [] csi_purpose: [] csi_relationship: | - Test instance for zabbix server - + Test instance for zabbix server +# For the MOTD +csi_security_category: [] +deployment_type: stg +ipa_client_shell_groups: + - fi-apprentice + - sysadmin-noc + - sysadmin-veteran + - sysadmin-jenkins +ipa_client_sudo_groups: + - sysadmin-jenkins +ipa_host_group: zabbix +ipa_host_group_desc: Zabbix Network Monitoring +lvm_size: 100000 +mem_size: 8192 nagios_Can_Connect: false nagios_Check_Services: ping: false +num_cpus: 2 +# for systems that do not match the above - specify the same parameter in +# the host_vars/$hostname file +tcp_ports: [80, 443] diff --git a/inventory/host_vars/aarch64-test02.fedorainfracloud.org b/inventory/host_vars/aarch64-test02.fedorainfracloud.org index 93b24426b4..b0d0ca48f5 100644 --- a/inventory/host_vars/aarch64-test02.fedorainfracloud.org +++ b/inventory/host_vars/aarch64-test02.fedorainfracloud.org @@ -1,36 +1,25 @@ --- -vmhost: cloudvmhost-aarch64-01.fedorainfracloud.org -eth0_ip: 38.145.48.51 -nm: 255.255.254.0 -gw: 38.145.49.254 -dns: 8.8.8.8 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-31-ext-aarch64 -ks_repo: http://209.132.181.6/pub/fedora/linux/releases/31/Server/aarch64/os/ - -virt_install_command_one_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} - --autostart --noautoconsole --rng /dev/random - -volgroup: /dev/vg_guests -lvm_size: 140000 -mem_size: 40960 -max_mem_size: "{{ mem_size }}" -num_cpus: 5 datacenter: cloud - +dns: 8.8.8.8 +eth0_ip: 38.145.48.51 +gw: 38.145.49.254 +ks_repo: http://209.132.181.6/pub/fedora/linux/releases/31/Server/aarch64/os/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-31-ext-aarch64 +lvm_size: 140000 +max_mem_size: "{{ mem_size }}" +mem_size: 40960 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +nm: 255.255.254.0 +num_cpus: 5 +virt_install_command_one_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac_address }} --autostart --noautoconsole --rng /dev/random +vmhost: cloudvmhost-aarch64-01.fedorainfracloud.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/armv7-test01.fedorainfracloud.org b/inventory/host_vars/armv7-test01.fedorainfracloud.org index 8448d0af1b..aa10c2d457 100644 --- a/inventory/host_vars/armv7-test01.fedorainfracloud.org +++ b/inventory/host_vars/armv7-test01.fedorainfracloud.org @@ -1,32 +1,27 @@ --- -vmhost: vmhost-a64-cc01.rdu-cc.fedoraproject.org -eth0_ip: 8.43.85.52 -nm: 255.255.255.0 -gw: 8.43.85.254 -dns: 8.8.8.8 -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/armhfp/os/ - -libdir: /usr/lib -vpn: true - datacenter: rdu-cc - -virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" - -volgroup: /dev/vg_guests +dns: 8.8.8.8 +eth0_ip: 8.43.85.52 +gw: 8.43.85.254 +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/armhfp/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora +libdir: /usr/lib lvm_size: 140000 -mem_size: 40960 max_mem_size: "{{ mem_size }}" -num_cpus: 5 - +mem_size: 40960 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +nm: 255.255.255.0 +num_cpus: 5 +virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" +vmhost: vmhost-a64-cc01.rdu-cc.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/armv7-test02.fedorainfracloud.org b/inventory/host_vars/armv7-test02.fedorainfracloud.org index 8420bb2794..d038a27a79 100644 --- a/inventory/host_vars/armv7-test02.fedorainfracloud.org +++ b/inventory/host_vars/armv7-test02.fedorainfracloud.org @@ -1,33 +1,27 @@ --- -vmhost: vmhost-a64-cc01.rdu-cc.fedoraproject.org -eth0_ip: 8.43.85.53 -nm: 255.255.255.0 -gw: 8.43.85.254 -dns: 8.8.8.8 -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/armhfp/os/ - -libdir: /usr/lib - -vpn: true - datacenter: rdu-cc - -virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" - -volgroup: /dev/vg_guests +dns: 8.8.8.8 +eth0_ip: 8.43.85.53 +gw: 8.43.85.254 +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/armhfp/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora +libdir: /usr/lib lvm_size: 140000 -mem_size: 40960 max_mem_size: "{{ mem_size }}" -num_cpus: 5 - +mem_size: 40960 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +nm: 255.255.255.0 +num_cpus: 5 +virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" +vmhost: vmhost-a64-cc01.rdu-cc.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/autosign01.iad2.fedoraproject.org b/inventory/host_vars/autosign01.iad2.fedoraproject.org index 90a1a61a62..7bcd026186 100644 --- a/inventory/host_vars/autosign01.iad2.fedoraproject.org +++ b/inventory/host_vars/autosign01.iad2.fedoraproject.org @@ -1,39 +1,33 @@ --- datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eno1_ipv4: 10.3.169.28 -eno1_ipv4_nm: 24 eno1_ipv4_gw: 10.3.169.254 - +eno1_ipv4_nm: 24 +eno1_mac: "{{ mac1 }}" +has_ipv4: yes mac1: ec:f4:bb:d2:85:48 mac2: ec:f4:bb:d2:85:4a mac3: ec:f4:bb:d2:85:4c mac4: ec:f4:bb:d2:85:4d - -eno1_mac: "{{ mac1 }}" - network_connections: -- name: eno1 - mac: "{{ eno1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eno1_ipv4 }}/{{ eno1_ipv4_nm }}" - gateway4: "{{ eno1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eno1_ipv4 }}/{{ eno1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eno1_ipv4_gw }}" + mac: "{{ eno1_mac }}" + name: eno1 + state: up + type: ethernet diff --git a/inventory/host_vars/autosign01.stg.iad2.fedoraproject.org b/inventory/host_vars/autosign01.stg.iad2.fedoraproject.org index bb005576d4..e5313a617a 100644 --- a/inventory/host_vars/autosign01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/autosign01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.167.29 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/backup01.iad2.fedoraproject.org b/inventory/host_vars/backup01.iad2.fedoraproject.org index f73d32d1cb..0f39dcb7e5 100644 --- a/inventory/host_vars/backup01.iad2.fedoraproject.org +++ b/inventory/host_vars/backup01.iad2.fedoraproject.org @@ -1,44 +1,35 @@ --- -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -datacenter: iad2 - ansible_ifcfg_blocklist: true - -grokmirror_topdir: /fedora_backups/grokmirror -weblate_backup_topdir: /fedora_backups/misc/weblate - +datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eno1_ipv4: 10.3.163.40 -eno1_ipv4_nm: 24 eno1_ipv4_gw: 10.3.163.254 - -mac0: ec:f4:bb:d2:76:a0 - +eno1_ipv4_nm: 24 eno1_mac: "{{ mac0 }}" - +grokmirror_topdir: /fedora_backups/grokmirror +has_ipv4: yes +mac0: ec:f4:bb:d2:76:a0 network_connections: -- name: eno1 - mac: "{{ eno1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eno1_ipv4 }}/{{ eno1_ipv4_nm }}" - gateway4: "{{ eno1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eno1_ipv4 }}/{{ eno1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eno1_ipv4_gw }}" + mac: "{{ eno1_mac }}" + name: eno1 + state: up + type: ethernet +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +weblate_backup_topdir: /fedora_backups/misc/weblate diff --git a/inventory/host_vars/badges-backend01.iad2.fedoraproject.org b/inventory/host_vars/badges-backend01.iad2.fedoraproject.org index 0988dcbd00..4e2a4122d2 100644 --- a/inventory/host_vars/badges-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/badges-backend01.iad2.fedoraproject.org @@ -1,15 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.94 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.94 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +sar_output_file: badges.json # GDPR SAR variables sar_script: /usr/local/bin/get-sar-person-details sar_script_user: fedmsg -sar_output_file: badges.json +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/badges-backend01.stg.iad2.fedoraproject.org b/inventory/host_vars/badges-backend01.stg.iad2.fedoraproject.org index 91fb2d398e..0f6ca01c33 100644 --- a/inventory/host_vars/badges-backend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/badges-backend01.stg.iad2.fedoraproject.org @@ -1,15 +1,14 @@ --- +datacenter: iad2 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ipv4: 10.3.166.44 eth0_ipv4_gw: 10.3.166.254 eth0_ipv4_nm: 255.255.255.0 -vmhost: vmhost-x86-11.stg.iad2.fedoraproject.org -datacenter: iad2 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +sar_output_file: badges.json # GDPR SAR variables sar_script: /usr/local/bin/get-sar-person-details sar_script_user: fedmsg -sar_output_file: badges.json +vmhost: vmhost-x86-11.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/badges-web01.iad2.fedoraproject.org b/inventory/host_vars/badges-web01.iad2.fedoraproject.org index b2ff692101..857fc64acb 100644 --- a/inventory/host_vars/badges-web01.iad2.fedoraproject.org +++ b/inventory/host_vars/badges-web01.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.95 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.95 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/badges-web01.stg.iad2.fedoraproject.org b/inventory/host_vars/badges-web01.stg.iad2.fedoraproject.org index 6fd39f5da9..76d9eeb6c0 100644 --- a/inventory/host_vars/badges-web01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/badges-web01.stg.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- +datacenter: iad2 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ipv4: 10.3.166.65 eth0_ipv4_gw: 10.3.166.254 eth0_ipv4_nm: 255.255.255.0 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 vmhost: vmhost-x86-11.stg.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/bastion01.iad2.fedoraproject.org b/inventory/host_vars/bastion01.iad2.fedoraproject.org index e75b1a07f3..6427b0ee8c 100644 --- a/inventory/host_vars/bastion01.iad2.fedoraproject.org +++ b/inventory/host_vars/bastion01.iad2.fedoraproject.org @@ -1,19 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 8.8.8.8 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.31 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -vmhost: vmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 -vpn: false - +dns: 8.8.8.8 +eth0_ip: 10.3.163.31 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 ssh_hostnames: -- bastion.fedoraproject.org -- bastion01.fedoraproject.org + - bastion.fedoraproject.org + - bastion01.fedoraproject.org +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/bastion02.iad2.fedoraproject.org b/inventory/host_vars/bastion02.iad2.fedoraproject.org index 76357478c6..756b682795 100644 --- a/inventory/host_vars/bastion02.iad2.fedoraproject.org +++ b/inventory/host_vars/bastion02.iad2.fedoraproject.org @@ -1,19 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.32 - -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ - -vmhost: vmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 -vpn: false - +dns: 10.3.163.33 +eth0_ip: 10.3.163.32 +gw: 10.3.163.254 +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 ssh_hostnames: -- bastion.fedoraproject.org -- bastion02.fedoraproject.org + - bastion.fedoraproject.org + - bastion02.fedoraproject.org +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/bastion13.fedoraproject.org b/inventory/host_vars/bastion13.fedoraproject.org index cbaa2366d6..8476aa476c 100644 --- a/inventory/host_vars/bastion13.fedoraproject.org +++ b/inventory/host_vars/bastion13.fedoraproject.org @@ -1,31 +1,24 @@ --- -nm: 255.255.255.0 -gw: 172.31.2.254 +datacenter: rdu dns: 172.31.2.24 dns1: 172.31.2.24 #dns2: 8.8.4.4 -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://38.145.60.16/repo/rhel/RHEL8-x86_64/ - -vmhost: virthost-rdu01.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 172.31.2.21 eth0_nm: 255.255.255.0 - +gw: 172.31.2.254 +ks_repo: http://38.145.60.16/repo/rhel/RHEL8-x86_64/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-rhel-8-ext +max_mem_size: 32768 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn public_ip: 209.132.190.1 - # This is consumed by the roles/fedora-web/main role sponsor: redhat -datacenter: rdu -postfix_group: vpn +vmhost: virthost-rdu01.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - diff --git a/inventory/host_vars/batcave01.iad2.fedoraproject.org b/inventory/host_vars/batcave01.iad2.fedoraproject.org index 651b70abb2..9f3709bef7 100644 --- a/inventory/host_vars/batcave01.iad2.fedoraproject.org +++ b/inventory/host_vars/batcave01.iad2.fedoraproject.org @@ -1,24 +1,20 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.35 -vmhost: vmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.35 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +sar_output_file: koji.json #host_backup_targets: ['/git', '/mnt/fedora/app/attachments'] # GDPR SAR variables - koji sar_script: /usr/local/bin/koji_sar.py sar_script_user: root -sar_output_file: koji.json - # Add VPN host name as alt name for SSH cert. Useful when you need to # SSH into batcave through VPN, like from bastion in a different DC. ssh_hostnames: -- batcave01.vpn.fedoraproject.org + - batcave01.vpn.fedoraproject.org +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/batcave13.rdu2.fedoraproject.org b/inventory/host_vars/batcave13.rdu2.fedoraproject.org index d3f9bafe83..e65791c5a4 100644 --- a/inventory/host_vars/batcave13.rdu2.fedoraproject.org +++ b/inventory/host_vars/batcave13.rdu2.fedoraproject.org @@ -1,50 +1,40 @@ --- -nm: 255.255.255.0 -gw: 172.31.2.254 +ansible_ssh_common_args: '-o ProxyCommand="ssh -W %h:%p -q root@bastion13.fedoraproject.org"' +datacenter: rdu dns: 172.31.2.24 dns1: 172.31.2.24 #dns2: 8.8.4.4 -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://38.145.60.16/repo/rhel/RHEL8-x86_64/ - -vmhost: virthost-rdu01.fedoraproject.org -volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_two_nic }}" - eth0_ip: 172.31.2.25 eth0_nm: 255.255.255.0 - eth1_ip: 172.31.1.3 eth1_nm: 255.255.255.0 - +gw: 172.31.2.254 +ks_repo: http://38.145.60.16/repo/rhel/RHEL8-x86_64/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-rhel-8-ext +max_mem_size: 32768 +mem_size: 16384 +nagios_Can_Connect: false +nagios_Check_Services: + mail: false + nrpe: false + ping: false + sshd: false + swap: false +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn #public_ip: 209.132.190.2 # This is consumed by the roles/fedora-web/main role sponsor: redhat -datacenter: rdu -postfix_group: vpn -vpn: true - -nagios_Can_Connect: false - -nagios_Check_Services: - mail: false - nrpe: false - sshd: false - swap: false - ping: false - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - -ansible_ssh_common_args: '-o ProxyCommand="ssh -W %h:%p -q root@bastion13.fedoraproject.org"' - # Add VPN host name as alt namefor SSH cert. Useful when you need to # SSH into batcave through VPN, like from bastion in a different DC. ssh_hostnames: -- batcave13.vpn.fedoraproject.org + - batcave13.vpn.fedoraproject.org +virt_install_command: "{{ virt_install_command_two_nic }}" +vmhost: virthost-rdu01.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/bkernel01.iad2.fedoraproject.org b/inventory/host_vars/bkernel01.iad2.fedoraproject.org index 098877e3da..d01944a149 100644 --- a/inventory/host_vars/bkernel01.iad2.fedoraproject.org +++ b/inventory/host_vars/bkernel01.iad2.fedoraproject.org @@ -1,38 +1,31 @@ --- datacenter: iad2 - -resolvconf: "resolv.conf/iad2" - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.169.29 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - -mac0: d0:94:66:45:a7:e4 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: d0:94:66:45:a7:e4 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet +resolvconf: "resolv.conf/iad2" diff --git a/inventory/host_vars/bkernel02.iad2.fedoraproject.org b/inventory/host_vars/bkernel02.iad2.fedoraproject.org index e257075b35..18fd7cf0c5 100644 --- a/inventory/host_vars/bkernel02.iad2.fedoraproject.org +++ b/inventory/host_vars/bkernel02.iad2.fedoraproject.org @@ -1,38 +1,31 @@ --- datacenter: iad2 - -resolvconf: "resolv.conf/iad2" - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.169.30 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - -mac0: d0:94:66:45:8c:0f - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: d0:94:66:45:8c:0f network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet +resolvconf: "resolv.conf/iad2" diff --git a/inventory/host_vars/blockerbugs01.iad2.fedoraproject.org b/inventory/host_vars/blockerbugs01.iad2.fedoraproject.org index 4a6035ef9e..34c5ba62d0 100644 --- a/inventory/host_vars/blockerbugs01.iad2.fedoraproject.org +++ b/inventory/host_vars/blockerbugs01.iad2.fedoraproject.org @@ -1,17 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.88 -vmhost: vmhost-x86-07.iad2.fedoraproject.org +blockerbugs_db_host_machine: db01.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.88 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora # This is the master node in stg, so it runs the cron job master_blockerbugs_node: True - -blockerbugs_db_host_machine: db01.iad2.fedoraproject.org +nm: 255.255.255.0 +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/blockerbugs01.stg.iad2.fedoraproject.org b/inventory/host_vars/blockerbugs01.stg.iad2.fedoraproject.org index d0a4e6035e..a8ab094413 100644 --- a/inventory/host_vars/blockerbugs01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/blockerbugs01.stg.iad2.fedoraproject.org @@ -1,15 +1,12 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.37 -vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.37 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora # This is the master node in stg, so it runs the cron job master_blockerbugs_node: True +nm: 255.255.255.0 +vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/bodhi-backend01.iad2.fedoraproject.org b/inventory/host_vars/bodhi-backend01.iad2.fedoraproject.org index 5e2e50459d..7e188c2894 100644 --- a/inventory/host_vars/bodhi-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/bodhi-backend01.iad2.fedoraproject.org @@ -1,96 +1,89 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.101 -vmhost: bvmhost-x86-04.iad2.fedoraproject.org -mem_size: 98304 -max_mem_size: 98304 -num_cpus: 30 - -virt_install_command: "{{ virt_install_command_one_nic }}" - -datacenter: iad2 - # These set a config value in /etc/fedmsg.d/, see roles/bodhi2/base/ bodhi_masher_enabled: True -bodhi_updates_handler_enabled: False bodhi_signed_handler_enabled: False - -# GDPR SAR variables -sar_script: /usr/bin/bodhi-sar -sar_script_user: apache -sar_output_file: bodhi.json - -# These are consumed by a task in roles/fedmsg/base/main.yml -fedmsg_certs: -# These are certs for pungi -- service: releng - owner: apache - group: sysadmin-releng - can_send: - # new school pungi-koji stuff (ask dgilmore) - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.ostree - - releng.atomic.twoweek.begin - - releng.atomic.twoweek.complete -# These are certs for the masher to publish its own messages as it progresses. -- service: bodhi - owner: root - group: apache - can_send: - - bodhi.mashtask.complete - - bodhi.mashtask.mashing - - bodhi.mashtask.start - - bodhi.mashtask.sync.done - - bodhi.mashtask.sync.wait - - bodhi.ostree.compose.start - - bodhi.ostree.compose.fail - - bodhi.ostree.compose.finish - - bodhi.errata.publish - - bodhi.update.eject - - bodhi.update.complete.testing - - bodhi.update.complete.stable - - bodhi.update.request.testing - - bodhi.update.request.stable - - bodhi.update.request.batched - - bodhi.update.karma.threshold.reach - - bodhi.buildroot_override.untag - - bodhi.update.comment - - bodhi.update.requirements_met.stable -- service: ftpsync - owner: root - group: ftpsync - can_send: - - bodhi.updates.epel.sync - - bodhi.updates.fedora.sync - - -# For the MOTD -csi_security_category: Medium +bodhi_updates_handler_enabled: False csi_primary_contact: Releng Admins sysadmin-releng-members@fedoraproject.org csi_purpose: Run the Bodhi masher. csi_relationship: | - The mashing of repos here happens as part of the 'fedmsg-hub' daemon. Check - logs with 'journalctl -u fedmsg-hub'. Check the bodhi masher docs/code for - more detail on what it does: - https://github.com/fedora-infra/bodhi/blob/develop/bodhi/consumers/masher.py + The mashing of repos here happens as part of the 'fedmsg-hub' daemon. Check + logs with 'journalctl -u fedmsg-hub'. Check the bodhi masher docs/code for + more detail on what it does: + https://github.com/fedora-infra/bodhi/blob/develop/bodhi/consumers/masher.py - * This host relies on: - * db01 for its database, which is shares with the bodhi2 frontend nodes. - * An NFS mount of koji data in /mnt/koji/ - * The fedmsg bus for triggering mashes. - * XMLRPC calls to koji for tagging and untagging updates. - * bugzilla for posting comments about status changes - * the wiki for getting information about QA "Test Cases" - * taksotron (resultsdb) for getting status-check results (gating updates). + * This host relies on: + * db01 for its database, which is shares with the bodhi2 frontend nodes. + * An NFS mount of koji data in /mnt/koji/ + * The fedmsg bus for triggering mashes. + * XMLRPC calls to koji for tagging and untagging updates. + * bugzilla for posting comments about status changes + * the wiki for getting information about QA "Test Cases" + * taksotron (resultsdb) for getting status-check results (gating updates). - * No other systems rely directly on this host. Everything depends on it - indirectly for the creation of new updates repos (which get synced out to - the master mirror for distribution. + * No other systems rely directly on this host. Everything depends on it + indirectly for the creation of new updates repos (which get synced out to + the master mirror for distribution. +# For the MOTD +csi_security_category: Medium +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.101 +# These are consumed by a task in roles/fedmsg/base/main.yml +fedmsg_certs: + # These are certs for pungi + - can_send: + # new school pungi-koji stuff (ask dgilmore) + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.ostree + - releng.atomic.twoweek.begin + - releng.atomic.twoweek.complete + group: sysadmin-releng + owner: apache + service: releng + # These are certs for the masher to publish its own messages as it progresses. + - can_send: + - bodhi.mashtask.complete + - bodhi.mashtask.mashing + - bodhi.mashtask.start + - bodhi.mashtask.sync.done + - bodhi.mashtask.sync.wait + - bodhi.ostree.compose.start + - bodhi.ostree.compose.fail + - bodhi.ostree.compose.finish + - bodhi.errata.publish + - bodhi.update.eject + - bodhi.update.complete.testing + - bodhi.update.complete.stable + - bodhi.update.request.testing + - bodhi.update.request.stable + - bodhi.update.request.batched + - bodhi.update.karma.threshold.reach + - bodhi.buildroot_override.untag + - bodhi.update.comment + - bodhi.update.requirements_met.stable + group: apache + owner: root + service: bodhi + - can_send: + - bodhi.updates.epel.sync + - bodhi.updates.fedora.sync + group: ftpsync + owner: root + service: ftpsync +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +max_mem_size: 98304 +mem_size: 98304 +nm: 255.255.255.0 +num_cpus: 30 +sar_output_file: bodhi.json +# GDPR SAR variables +sar_script: /usr/bin/bodhi-sar +sar_script_user: apache +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/bodhi-backend01.stg.iad2.fedoraproject.org b/inventory/host_vars/bodhi-backend01.stg.iad2.fedoraproject.org index 01954bf5df..5f0c9852dd 100644 --- a/inventory/host_vars/bodhi-backend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bodhi-backend01.stg.iad2.fedoraproject.org @@ -1,28 +1,27 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -mac_address: 52:54:00:1c:40:15 eth0_ip: 10.3.167.32 -vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org - # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -# This first cert is used by the push-tool. releng members run it and it fires -# off a simple fedmsg message that the masher (running as fedmsg-hub) is -# listening for. It then does all the worker. -# These are certs for pungi -- service: releng - owner: apache - group: sysadmin-releng - can_send: - # new school pungi-koji stuff (ask dgilmore) - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - releng.atomic.twoweek.begin - - releng.atomic.twoweek.complete + # This first cert is used by the push-tool. releng members run it and it fires + # off a simple fedmsg message that the masher (running as fedmsg-hub) is + # listening for. It then does all the worker. + # These are certs for pungi + - can_send: + # new school pungi-koji stuff (ask dgilmore) + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - releng.atomic.twoweek.begin + - releng.atomic.twoweek.complete + group: sysadmin-releng + owner: apache + service: releng +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +mac_address: 52:54:00:1c:40:15 +nm: 255.255.255.0 +vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/bootstrap.ocp.iad2.fedoraproject.org b/inventory/host_vars/bootstrap.ocp.iad2.fedoraproject.org index 8a8c0e2c58..bc8767e818 100644 --- a/inventory/host_vars/bootstrap.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/bootstrap.ocp.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-04.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.126 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.126 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.163.65/rhcos/bootstrap.ign" rhcos_install_img_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.163.65/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/bootstrap.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/bootstrap.ocp.stg.iad2.fedoraproject.org index ad35f66081..73ff392fd5 100644 --- a/inventory/host_vars/bootstrap.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bootstrap.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.121 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.121 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: ens2 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/bootstrap.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: ens2 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/buildhw-a64-01.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-01.iad2.fedoraproject.org index 31ab58bc35..a5e5fb2354 100644 --- a/inventory/host_vars/buildhw-a64-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-01.iad2.fedoraproject.org @@ -1,31 +1,30 @@ --- -gw: 10.3.170.254 +datacenter: iad2 eth1_ip: 10.3.170.121 eth1_ipv4_gw: 10.3.170.254 -datacenter: iad2 - +gw: 10.3.170.254 network_connections: -- name: eth0 - type: ethernet - autoconnect: no - mac: 68:05:ca:8e:ab:e6 -- name: eth1 - state: up - type: ethernet - mac: 50:6b:4b:6b:08:50 - autoconnect: yes - ip: - address: 10.3.170.121/24 - gateway4: 10.3.170.254 - dns: - - 10.3.163.33 - - 10.3.163.34 - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth2 - mac: 50:6b:4b:6b:08:51 - type: ethernet - autoconnect: no + - autoconnect: no + mac: 68:05:ca:8e:ab:e6 + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: 10.3.170.121/24 + auto6: no + dhcp4: no + dns: + - 10.3.163.33 + - 10.3.163.34 + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: 10.3.170.254 + mac: 50:6b:4b:6b:08:50 + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: 50:6b:4b:6b:08:51 + name: eth2 + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-02.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-02.iad2.fedoraproject.org index d557c5212f..eef52b0b5f 100644 --- a/inventory/host_vars/buildhw-a64-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-02.iad2.fedoraproject.org @@ -2,43 +2,37 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth1_ipv4: 10.3.170.122 -eth1_ipv4_nm: 24 eth1_ipv4_gw: 10.3.170.254 - +eth1_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 00:1b:21:de:34:63 mac1: 50:6b:4b:6a:ec:90 mac2: 50:6b:4b:6a:ec:91 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: down - type: ethernet - -- name: eth1 - mac: "{{ mac1 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet + - mac: "{{ mac0 }}" + name: eth0 + state: down + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ mac1 }}" + name: eth1 + state: up + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-03.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-03.iad2.fedoraproject.org index 4944b70ccd..a041b09ef3 100644 --- a/inventory/host_vars/buildhw-a64-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-03.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.123 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 00:01:73:02:08:83 mac1: fe:2f:0f:b7:1c:1e mac2: e6:6d:96:cc:7a:cd mac3: d2:87:2a:46:d0:24 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-04.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-04.iad2.fedoraproject.org index 66b1aa405b..6e0f9cf87a 100644 --- a/inventory/host_vars/buildhw-a64-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-04.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.124 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 2c:59:e5:36:9a:53 mac1: a6:df:61:ff:e4:3f mac2: da:2c:8f:e7:99:2b mac3: c2:ac:ba:0d:8c:db - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-05.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-05.iad2.fedoraproject.org index eede7f4e50..58cd16c191 100644 --- a/inventory/host_vars/buildhw-a64-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-05.iad2.fedoraproject.org @@ -2,49 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.125 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 00:01:73:02:09:c3 mac1: ee:cb:e1:1b:27:6e mac2: f2:b7:9e:26:0d:9a mac3: ca:65:7a:c4:c8:83 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no - -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-06.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-06.iad2.fedoraproject.org index 332a53e4a5..d8d8ad4646 100644 --- a/inventory/host_vars/buildhw-a64-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-06.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.126 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 2c:59:e5:36:9a:51 mac1: ce:a6:3d:c6:22:51 mac2: 66:19:15:4e:89:56 mac3: 66:66:16:e5:59:df - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-07.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-07.iad2.fedoraproject.org index e49b2350d0..ac0d53c4c1 100644 --- a/inventory/host_vars/buildhw-a64-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-07.iad2.fedoraproject.org @@ -1,5 +1,5 @@ --- -gw: 10.3.170.254 +datacenter: iad2 eth0_ip: 10.3.170.127 eth0_ipv4_gw: 10.3.170.254 -datacenter: iad2 +gw: 10.3.170.254 diff --git a/inventory/host_vars/buildhw-a64-08.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-08.iad2.fedoraproject.org index 95dab10534..1d51799575 100644 --- a/inventory/host_vars/buildhw-a64-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-08.iad2.fedoraproject.org @@ -1,36 +1,30 @@ --- datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.170.128 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - -mac0: 2c:59:e5:36:9a:4f - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 2c:59:e5:36:9a:4f network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-09.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-09.iad2.fedoraproject.org index 472831da0a..86a9efd330 100644 --- a/inventory/host_vars/buildhw-a64-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-09.iad2.fedoraproject.org @@ -1,5 +1,5 @@ --- -gw: 10.3.170.254 +datacenter: iad2 eth0_ip: 10.3.170.129 eth0_ipv4_gw: 10.3.170.254 -datacenter: iad2 +gw: 10.3.170.254 diff --git a/inventory/host_vars/buildhw-a64-10.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-10.iad2.fedoraproject.org index 8f641f9fea..dbe339d91e 100644 --- a/inventory/host_vars/buildhw-a64-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-10.iad2.fedoraproject.org @@ -1,5 +1,5 @@ --- -gw: 10.3.170.254 +datacenter: iad2 eth0_ip: 10.3.170.130 eth0_ipv4_gw: 10.3.170.254 -datacenter: iad2 +gw: 10.3.170.254 diff --git a/inventory/host_vars/buildhw-a64-11.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-11.iad2.fedoraproject.org index 3c50a6a59b..fb66cbffd2 100644 --- a/inventory/host_vars/buildhw-a64-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-11.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.131 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 00:01:73:02:08:ff mac1: 72:a3:68:ad:39:05 mac2: 8a:93:68:8d:ca:cd mac3: ee:ef:b7:b9:28:8a - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-19.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-19.iad2.fedoraproject.org index 35bed53623..4298b17b79 100644 --- a/inventory/host_vars/buildhw-a64-19.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-19.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.139 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f4:e9:d4:cc:2f:f4 mac1: f4:e9:d4:cc:2f:f5 mac2: f4:e9:d4:f2:e7:f4 mac3: f4:e9:d4:f2:e7:f5 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-20.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-20.iad2.fedoraproject.org index 83e7f26c85..c63b08a6af 100644 --- a/inventory/host_vars/buildhw-a64-20.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-20.iad2.fedoraproject.org @@ -2,48 +2,42 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.170.140 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.170.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f4:e9:d4:cc:32:b2 mac1: f4:e9:d4:cc:32:b3 mac2: f4:e9:d4:f2:e9:6e mac3: f4:e9:d4:f2:e9:6f - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - -- name: eth2 - mac: "{{ mac2 }}" - state: down - type: ethernet - -- name: eth3 - mac: "{{ mac3 }}" - state: down - type: ethernet \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet + - mac: "{{ mac2 }}" + name: eth2 + state: down + type: ethernet + - mac: "{{ mac3 }}" + name: eth3 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-21.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-21.iad2.fedoraproject.org index 19ff081805..f4ee69e929 100644 --- a/inventory/host_vars/buildhw-a64-21.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-21.iad2.fedoraproject.org @@ -1,43 +1,40 @@ --- -freezes: true -nested: true dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth1_ipv4: 10.3.170.151 -eth1_ipv4_nm: 24 eth1_ipv4_gw: 10.3.170.254 - -mgmt_mac: "e8:6a:64:39:18:ef" -mgmt_ipv4: "10.3.160.114" +eth1_ipv4_nm: 24 +freezes: true +has_ipv4: yes mac0: 68:05:ca:8e:9b:86 mac1: 50:6b:4b:6a:b6:20 mac2: 50:6b:4b:6a:b6:21 - +mgmt_ipv4: "10.3.160.114" +mgmt_mac: "e8:6a:64:39:18:ef" +nested: true network_connections: -- name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: no -- name: eth1 - state: up - type: ethernet - autoconnect: yes - mac: "{{ mac1 }}" - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ mac2 }}" - type: ethernet - autoconnect: no + - autoconnect: no + mac: "{{ mac0 }}" + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ mac1 }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ mac2 }}" + name: eth2 + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-22.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-22.iad2.fedoraproject.org index e2aee802f2..adbae22870 100644 --- a/inventory/host_vars/buildhw-a64-22.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-22.iad2.fedoraproject.org @@ -1,43 +1,39 @@ --- -freezes: true - dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth1_ipv4: 10.3.170.152 -eth1_ipv4_nm: 24 eth1_ipv4_gw: 10.3.170.254 - -mgmt_mac: "E8:6A:64:39:18:73" -mgmt_ipv4: "10.3.160.116" +eth1_ipv4_nm: 24 +freezes: true +has_ipv4: yes mac0: 68:05:ca:8a:f0:29 mac1: 50:6b:4b:6a:eb:b0 mac2: 50:6b:4b:6a:eb:b1 - +mgmt_ipv4: "10.3.160.116" +mgmt_mac: "E8:6A:64:39:18:73" network_connections: -- name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: no -- name: eth1 - state: up - type: ethernet - autoconnect: yes - mac: "{{ mac1 }}" - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ mac2 }}" - type: ethernet - autoconnect: no + - autoconnect: no + mac: "{{ mac0 }}" + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ mac1 }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ mac2 }}" + name: eth2 + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-23.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-23.iad2.fedoraproject.org index c70f71124f..9ddcb41b76 100644 --- a/inventory/host_vars/buildhw-a64-23.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-23.iad2.fedoraproject.org @@ -1,43 +1,39 @@ --- -freezes: true - dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth1_ipv4: 10.3.170.153 -eth1_ipv4_nm: 24 eth1_ipv4_gw: 10.3.170.254 - -mgmt_mac: "E8:6A:64:39:19:67" -mgmt_ipv4: "10.3.160.117" +eth1_ipv4_nm: 24 +freezes: true +has_ipv4: yes mac0: 00:1b:21:dc:4e:32 mac1: 50:6b:4b:6a:ea:60 mac2: 50:6b:4b:6a:ea:61 - +mgmt_ipv4: "10.3.160.117" +mgmt_mac: "E8:6A:64:39:19:67" network_connections: -- name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: no -- name: eth1 - state: up - type: ethernet - autoconnect: yes - mac: "{{ mac1 }}" - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ mac2 }}" - type: ethernet - autoconnect: no + - autoconnect: no + mac: "{{ mac0 }}" + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ mac1 }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ mac2 }}" + name: eth2 + type: ethernet diff --git a/inventory/host_vars/buildhw-a64-24.iad2.fedoraproject.org b/inventory/host_vars/buildhw-a64-24.iad2.fedoraproject.org index 1e9a5d357a..16a3a141f5 100644 --- a/inventory/host_vars/buildhw-a64-24.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-a64-24.iad2.fedoraproject.org @@ -1,43 +1,40 @@ --- -freezes: true -nested: true dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth1_ipv4: 10.3.170.154 -eth1_ipv4_nm: 24 eth1_ipv4_gw: 10.3.170.254 - -mgmt_mac: "E8:6A:64:39:19:67" -mgmt_ipv4: "10.3.160.118" +eth1_ipv4_nm: 24 +freezes: true +has_ipv4: yes mac0: 68:05:CA:8E:98:C7 mac1: 50:6B:4B:6A:C4:90 mac2: 50:6B:4B:6A:C4:91 - +mgmt_ipv4: "10.3.160.118" +mgmt_mac: "E8:6A:64:39:19:67" +nested: true network_connections: -- name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: no -- name: eth1 - state: up - type: ethernet - autoconnect: yes - mac: "{{ mac1 }}" - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ mac2 }}" - type: ethernet - autoconnect: no + - autoconnect: no + mac: "{{ mac0 }}" + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ mac1 }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ mac2 }}" + name: eth2 + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-01.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-01.iad2.fedoraproject.org index bb33b39df5..b8e82d73aa 100644 --- a/inventory/host_vars/buildhw-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-01.iad2.fedoraproject.org @@ -1,32 +1,28 @@ --- datacenter: iad2 dns1: 10.3.163.33 - -has_ipv4: yes eth0_ipv4: 10.3.169.31 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:9e:61 mac1: 14:9e:cf:61:9e:64 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - type: ethernet - state: down + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-02.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-02.iad2.fedoraproject.org index d96ece23a4..35928e1e09 100644 --- a/inventory/host_vars/buildhw-x86-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-02.iad2.fedoraproject.org @@ -2,38 +2,34 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.32 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:9f:4f mac1: 14:9e:cf:61:9f:52 - network_connections: -- name: eth0 - persistent_state: present - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - persistent_state: present - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + persistent_state: present + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + persistent_state: present + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-03.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-03.iad2.fedoraproject.org index 880319cf5a..19c8d28318 100644 --- a/inventory/host_vars/buildhw-x86-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-03.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.33 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:9e:c9 mac1: 14:9e:cf:61:9e:cc - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-04.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-04.iad2.fedoraproject.org index f0eccbf05f..9bf4c642ec 100644 --- a/inventory/host_vars/buildhw-x86-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-04.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.34 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:a5:07 mac1: 14:9e:cf:61:a5:0a - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-05.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-05.iad2.fedoraproject.org index 0d041eedfb..7ccc1cec12 100644 --- a/inventory/host_vars/buildhw-x86-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-05.iad2.fedoraproject.org @@ -1,35 +1,31 @@ --- -eth0_ip: 10.3.169.35 -gw: 10.3.169.254 datacenter: iad2 -eth1_off: true -eth0_ipv4: 10.3.169.35 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.169.254 - -nm: 255.255.255.0 -dns1: 10.3.163.33 dns: 10.3.163.33 - +dns1: 10.3.163.33 +eth0_ip: 10.3.169.35 +eth0_ipv4: 10.3.169.35 +eth0_ipv4_gw: 10.3.169.254 +eth0_ipv4_nm: 24 +eth1_off: true +gw: 10.3.169.254 mac0: 14:9e:cf:61:9e:7b mac1: 14:9e:cf:61:9e:7e - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - type: ethernet - state: down - + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet +nm: 255.255.255.0 diff --git a/inventory/host_vars/buildhw-x86-06.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-06.iad2.fedoraproject.org index e8e58f4fdb..2fd2d78a8d 100644 --- a/inventory/host_vars/buildhw-x86-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-06.iad2.fedoraproject.org @@ -2,37 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.36 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:a0:bd mac1: 14:9e:cf:61:a0:c0 - - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-07.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-07.iad2.fedoraproject.org index c821c213b6..eefdc7576c 100644 --- a/inventory/host_vars/buildhw-x86-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-07.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.37 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:9e:e3 mac1: 14:9e:cf:61:9e:e6 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-08.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-08.iad2.fedoraproject.org index 76de0b4440..ccb6d6cd71 100644 --- a/inventory/host_vars/buildhw-x86-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-08.iad2.fedoraproject.org @@ -2,37 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.38 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: 14:9e:cf:61:a6:75 mac1: 14:9e:cf:61:a6:78 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes - + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-09.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-09.iad2.fedoraproject.org index 65912009c7..afec073086 100644 --- a/inventory/host_vars/buildhw-x86-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-09.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.39 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:26:e1 mac1: f8:ca:b8:f7:26:e4 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-10.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-10.iad2.fedoraproject.org index 6f7b8e8cab..2577bb642e 100644 --- a/inventory/host_vars/buildhw-x86-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-10.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.40 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:27:cf mac1: f8:ca:b8:f7:27:d2 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-11.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-11.iad2.fedoraproject.org index 44fda87729..dc2726785b 100644 --- a/inventory/host_vars/buildhw-x86-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-11.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.41 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:27:63 mac1: f8:ca:b8:f7:27:66 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-12.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-12.iad2.fedoraproject.org index 51eb4a2ce5..38a25e3351 100644 --- a/inventory/host_vars/buildhw-x86-12.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-12.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.42 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:2e:f5 mac1: f8:ca:b8:f7:2e:f8 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-13.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-13.iad2.fedoraproject.org index 3da42fc936..588908a93e 100644 --- a/inventory/host_vars/buildhw-x86-13.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-13.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.43 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:27:49 mac1: f8:ca:b8:f7:27:4c - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-14.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-14.iad2.fedoraproject.org index 670456ed95..4e84b82d8b 100644 --- a/inventory/host_vars/buildhw-x86-14.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-14.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.44 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:2d:87 mac1: f8:ca:b8:f7:2d:8a - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-15.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-15.iad2.fedoraproject.org index 777598b7e8..1d36b6c84e 100644 --- a/inventory/host_vars/buildhw-x86-15.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-15.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.45 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:26:fb mac1: f8:ca:b8:f7:26:fe - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildhw-x86-16.iad2.fedoraproject.org b/inventory/host_vars/buildhw-x86-16.iad2.fedoraproject.org index 925305bdfb..dc53f8a996 100644 --- a/inventory/host_vars/buildhw-x86-16.iad2.fedoraproject.org +++ b/inventory/host_vars/buildhw-x86-16.iad2.fedoraproject.org @@ -2,36 +2,32 @@ datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - -has_ipv4: yes eth0_ipv4: 10.3.169.46 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.169.254 - +eth0_ipv4_nm: 24 +has_ipv4: yes has_ipv6: no - mac0: f8:ca:b8:f7:29:3d mac1: f8:ca:b8:f7:29:40 - network_connections: -- name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ mac1 }}" - state: down - type: ethernet - autoconnect: yes \ No newline at end of file + - ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet + - autoconnect: yes + mac: "{{ mac1 }}" + name: eth1 + state: down + type: ethernet diff --git a/inventory/host_vars/buildvm-a32-01.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-01.iad2.fedoraproject.org index 341d204034..067d5096b0 100644 --- a/inventory/host_vars/buildvm-a32-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-01.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.61 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-01.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-01.stg.iad2.fedoraproject.org index 7ceea79b92..9a2023b5ba 100644 --- a/inventory/host_vars/buildvm-a32-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-01.stg.iad2.fedoraproject.org @@ -1,8 +1,6 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org - datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.46 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-02.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-02.iad2.fedoraproject.org index 7092480c8d..0d619159a4 100644 --- a/inventory/host_vars/buildvm-a32-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-02.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.62 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-02.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-02.stg.iad2.fedoraproject.org index e3078ca887..be268de320 100644 --- a/inventory/host_vars/buildvm-a32-02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-02.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.54 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-03.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-03.iad2.fedoraproject.org index 52913e6fbe..7d333c2225 100644 --- a/inventory/host_vars/buildvm-a32-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-03.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.63 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-03.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-03.stg.iad2.fedoraproject.org index 5dd87e7165..7d86db18a6 100644 --- a/inventory/host_vars/buildvm-a32-03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-03.stg.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org eth0_ip: 10.3.167.55 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-04.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-04.iad2.fedoraproject.org index 08dff18700..0b9b7f972a 100644 --- a/inventory/host_vars/buildvm-a32-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-04.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.64 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-05.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-05.iad2.fedoraproject.org index 0498937e6e..99462f41ac 100644 --- a/inventory/host_vars/buildvm-a32-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-05.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.65 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-06.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-06.iad2.fedoraproject.org index 289b87b8e3..7f052a8ca9 100644 --- a/inventory/host_vars/buildvm-a32-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-06.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.66 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-07.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-07.iad2.fedoraproject.org index 0ab0672e59..6e57519a62 100644 --- a/inventory/host_vars/buildvm-a32-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-07.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.67 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-08.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-08.iad2.fedoraproject.org index e74e900309..e9006adef3 100644 --- a/inventory/host_vars/buildvm-a32-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-08.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.68 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-09.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-09.iad2.fedoraproject.org index 6fd38a0d1c..b551f870cb 100644 --- a/inventory/host_vars/buildvm-a32-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-09.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.69 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-10.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-10.iad2.fedoraproject.org index 3b9903ecda..856b60337b 100644 --- a/inventory/host_vars/buildvm-a32-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-10.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.70 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-11.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-11.iad2.fedoraproject.org index 840854e470..ab579e02ac 100644 --- a/inventory/host_vars/buildvm-a32-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-11.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.71 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-12.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-12.iad2.fedoraproject.org index 7486f20a1e..bd635609b4 100644 --- a/inventory/host_vars/buildvm-a32-12.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-12.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.72 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-13.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-13.iad2.fedoraproject.org index c1b0e5b16f..5edc4a7f84 100644 --- a/inventory/host_vars/buildvm-a32-13.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-13.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.73 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-14.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-14.iad2.fedoraproject.org index fdec200cf4..f9a678309d 100644 --- a/inventory/host_vars/buildvm-a32-14.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-14.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.74 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-15.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-15.iad2.fedoraproject.org index 88368a9f88..36aebc9e6f 100644 --- a/inventory/host_vars/buildvm-a32-15.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-15.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.75 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-16.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-16.iad2.fedoraproject.org index 7a3c363a28..23339c9d71 100644 --- a/inventory/host_vars/buildvm-a32-16.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-16.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.76 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-17.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-17.iad2.fedoraproject.org index 5cee861ab7..9a6d9232f0 100644 --- a/inventory/host_vars/buildvm-a32-17.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-17.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.77 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-18.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-18.iad2.fedoraproject.org index 887adb0f8f..363ac28fc5 100644 --- a/inventory/host_vars/buildvm-a32-18.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-18.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.78 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-19.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-19.iad2.fedoraproject.org index a6310b8fa6..fb1f4fb2d9 100644 --- a/inventory/host_vars/buildvm-a32-19.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-19.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.79 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-20.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-20.iad2.fedoraproject.org index 0c0a175ca8..5fac51e741 100644 --- a/inventory/host_vars/buildvm-a32-20.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-20.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.80 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-21.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-21.iad2.fedoraproject.org index 7414236714..38c479c229 100644 --- a/inventory/host_vars/buildvm-a32-21.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-21.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.81 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-22.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-22.iad2.fedoraproject.org index fee6cb88d8..c9482a9cb8 100644 --- a/inventory/host_vars/buildvm-a32-22.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-22.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.82 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-23.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-23.iad2.fedoraproject.org index b88f116220..28a97686b0 100644 --- a/inventory/host_vars/buildvm-a32-23.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-23.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.83 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-24.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-24.iad2.fedoraproject.org index 7edac7c452..8dcbd9eecf 100644 --- a/inventory/host_vars/buildvm-a32-24.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-24.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.84 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-25.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-25.iad2.fedoraproject.org index 7bc5a4507a..1474d9b7d5 100644 --- a/inventory/host_vars/buildvm-a32-25.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-25.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.85 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-26.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-26.iad2.fedoraproject.org index 919a666e04..3d10821408 100644 --- a/inventory/host_vars/buildvm-a32-26.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-26.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.86 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-27.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-27.iad2.fedoraproject.org index a5173a1988..bd057a8562 100644 --- a/inventory/host_vars/buildvm-a32-27.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-27.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.87 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-28.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-28.iad2.fedoraproject.org index b3c54392d2..e10f974abd 100644 --- a/inventory/host_vars/buildvm-a32-28.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-28.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.88 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-29.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-29.iad2.fedoraproject.org index 5744376007..3bdf5e9c6a 100644 --- a/inventory/host_vars/buildvm-a32-29.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-29.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.89 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-30.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-30.iad2.fedoraproject.org index 008bc32cc9..21b65a96be 100644 --- a/inventory/host_vars/buildvm-a32-30.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-30.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.90 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-31.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-31.iad2.fedoraproject.org index 07469a25fd..edcd4c58d2 100644 --- a/inventory/host_vars/buildvm-a32-31.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-31.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.144 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-32.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-32.iad2.fedoraproject.org index 2c777a9546..ea9113f095 100644 --- a/inventory/host_vars/buildvm-a32-32.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-32.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.145 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a32-33.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a32-33.iad2.fedoraproject.org index dca4648728..410d0e98de 100644 --- a/inventory/host_vars/buildvm-a32-33.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a32-33.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.146 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-01.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-01.iad2.fedoraproject.org index 0538df2eae..82ee83983e 100644 --- a/inventory/host_vars/buildvm-a64-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-01.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.91 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-01.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-01.stg.iad2.fedoraproject.org index 6d2eb03485..0a0fb87a02 100644 --- a/inventory/host_vars/buildvm-a64-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-01.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.45 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-02.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-02.iad2.fedoraproject.org index 72bd09ebf6..9cd37ffbce 100644 --- a/inventory/host_vars/buildvm-a64-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-02.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.92 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-02.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-02.stg.iad2.fedoraproject.org index e8cccc155a..61a866b929 100644 --- a/inventory/host_vars/buildvm-a64-02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-02.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.52 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-03.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-03.iad2.fedoraproject.org index a5ca82678a..b89b595a7b 100644 --- a/inventory/host_vars/buildvm-a64-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-03.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.93 +vmhost: bvmhost-a64-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-03.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-03.stg.iad2.fedoraproject.org index ac81f04e70..05f8b0e38d 100644 --- a/inventory/host_vars/buildvm-a64-03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-03.stg.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org eth0_ip: 10.3.167.53 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-04.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-04.iad2.fedoraproject.org index b868bc953d..da95a13d89 100644 --- a/inventory/host_vars/buildvm-a64-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-04.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.94 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-05.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-05.iad2.fedoraproject.org index d676d3ac8f..cf0ae165df 100644 --- a/inventory/host_vars/buildvm-a64-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-05.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.95 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-06.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-06.iad2.fedoraproject.org index ffafaad4fd..b72c7caee1 100644 --- a/inventory/host_vars/buildvm-a64-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-06.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.96 +vmhost: bvmhost-a64-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-07.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-07.iad2.fedoraproject.org index 6e82d5de81..11faf9acc2 100644 --- a/inventory/host_vars/buildvm-a64-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-07.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.97 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-08.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-08.iad2.fedoraproject.org index 2d3120c696..956a35bf4d 100644 --- a/inventory/host_vars/buildvm-a64-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-08.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.98 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-09.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-09.iad2.fedoraproject.org index 3dd1edf897..c13c165ec5 100644 --- a/inventory/host_vars/buildvm-a64-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-09.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.99 +vmhost: bvmhost-a64-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-10.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-10.iad2.fedoraproject.org index 5921e5967b..52786cded1 100644 --- a/inventory/host_vars/buildvm-a64-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-10.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.100 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-11.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-11.iad2.fedoraproject.org index 5b606fe8ab..cf3c7902c1 100644 --- a/inventory/host_vars/buildvm-a64-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-11.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.101 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-12.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-12.iad2.fedoraproject.org index f8723bd0ad..bbc71e560f 100644 --- a/inventory/host_vars/buildvm-a64-12.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-12.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.102 +vmhost: bvmhost-a64-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-13.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-13.iad2.fedoraproject.org index f37342eff1..78c2dd3968 100644 --- a/inventory/host_vars/buildvm-a64-13.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-13.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.103 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-14.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-14.iad2.fedoraproject.org index 6b38e3c8df..fdc313dcfd 100644 --- a/inventory/host_vars/buildvm-a64-14.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-14.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.104 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-15.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-15.iad2.fedoraproject.org index 4a7649cfe9..80b5fff9a7 100644 --- a/inventory/host_vars/buildvm-a64-15.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-15.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-05.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.105 +vmhost: bvmhost-a64-05.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-16.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-16.iad2.fedoraproject.org index abe22bf19d..1c58f75899 100644 --- a/inventory/host_vars/buildvm-a64-16.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-16.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.106 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-17.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-17.iad2.fedoraproject.org index 4b4c7cfb56..f5674d2a97 100644 --- a/inventory/host_vars/buildvm-a64-17.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-17.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.107 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-18.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-18.iad2.fedoraproject.org index f15ed90599..0729fc2eb3 100644 --- a/inventory/host_vars/buildvm-a64-18.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-18.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-06.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.108 +vmhost: bvmhost-a64-06.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-19.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-19.iad2.fedoraproject.org index 4893581ebb..23cb13717b 100644 --- a/inventory/host_vars/buildvm-a64-19.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-19.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.109 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-20.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-20.iad2.fedoraproject.org index d16213a823..7c001d24f9 100644 --- a/inventory/host_vars/buildvm-a64-20.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-20.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.110 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-21.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-21.iad2.fedoraproject.org index 6b430ce0dd..f5d3f8d243 100644 --- a/inventory/host_vars/buildvm-a64-21.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-21.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-07.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.111 +vmhost: bvmhost-a64-07.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-22.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-22.iad2.fedoraproject.org index dcd1d471f0..a50c36673b 100644 --- a/inventory/host_vars/buildvm-a64-22.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-22.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.112 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-23.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-23.iad2.fedoraproject.org index 36c8987065..50d0e6383d 100644 --- a/inventory/host_vars/buildvm-a64-23.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-23.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.113 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-24.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-24.iad2.fedoraproject.org index 30558fcd36..6d9313c937 100644 --- a/inventory/host_vars/buildvm-a64-24.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-24.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-08.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.114 +vmhost: bvmhost-a64-08.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-25.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-25.iad2.fedoraproject.org index 7827a23848..1379e30300 100644 --- a/inventory/host_vars/buildvm-a64-25.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-25.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.115 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-26.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-26.iad2.fedoraproject.org index d8e151b048..e77b9b890c 100644 --- a/inventory/host_vars/buildvm-a64-26.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-26.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.116 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-27.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-27.iad2.fedoraproject.org index f6286f8742..6192cb52b2 100644 --- a/inventory/host_vars/buildvm-a64-27.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-27.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-09.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.117 +vmhost: bvmhost-a64-09.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-28.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-28.iad2.fedoraproject.org index 60489e2b6d..878ca4cf4c 100644 --- a/inventory/host_vars/buildvm-a64-28.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-28.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.118 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-29.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-29.iad2.fedoraproject.org index 1857952f3b..ccacdef374 100644 --- a/inventory/host_vars/buildvm-a64-29.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-29.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.119 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-30.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-30.iad2.fedoraproject.org index 8e4bbcbcf7..e1ebf81f76 100644 --- a/inventory/host_vars/buildvm-a64-30.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-30.iad2.fedoraproject.org @@ -1,3 +1,3 @@ --- -vmhost: bvmhost-a64-10.iad2.fedoraproject.org eth0_ip: 10.3.170.120 +vmhost: bvmhost-a64-10.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-31.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-31.iad2.fedoraproject.org index e0ff0fa77e..5f832d0df1 100644 --- a/inventory/host_vars/buildvm-a64-31.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-31.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.141 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-32.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-32.iad2.fedoraproject.org index dbeee1cd3c..207189e5a7 100644 --- a/inventory/host_vars/buildvm-a64-32.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-32.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.142 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-a64-33.iad2.fedoraproject.org b/inventory/host_vars/buildvm-a64-33.iad2.fedoraproject.org index d138a9ca3a..d439a81f4e 100644 --- a/inventory/host_vars/buildvm-a64-33.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-a64-33.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-a64-11.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.170.143 +vmhost: bvmhost-a64-11.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-aarch64-01.stg.arm.fedoraproject.org b/inventory/host_vars/buildvm-aarch64-01.stg.arm.fedoraproject.org index 8316181e99..7ceca336cd 100644 --- a/inventory/host_vars/buildvm-aarch64-01.stg.arm.fedoraproject.org +++ b/inventory/host_vars/buildvm-aarch64-01.stg.arm.fedoraproject.org @@ -1,12 +1,11 @@ --- -vmhost: buildvmhost-aarch64-18.arm.fedoraproject.org -mem_size: 24576 -max_mem_size: "{{ mem_size }}" -num_cpus: 4 -max_cpu: "{{ num_cpus }}" -volgroup: /dev/vg_guests - eth0_ip: 10.5.129.232 gw: 10.5.129.254 main_bridge: br0 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 24576 +num_cpus: 4 virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}" +vmhost: buildvmhost-aarch64-18.arm.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/buildvm-armv7-01.stg.arm.fedoraproject.org b/inventory/host_vars/buildvm-armv7-01.stg.arm.fedoraproject.org index 320f193729..cb0cd51e4f 100644 --- a/inventory/host_vars/buildvm-armv7-01.stg.arm.fedoraproject.org +++ b/inventory/host_vars/buildvm-armv7-01.stg.arm.fedoraproject.org @@ -1,12 +1,11 @@ --- -vmhost: buildvmhost-aarch64-18.arm.fedoraproject.org -mem_size: 24576 -max_mem_size: "{{ mem_size }}" -num_cpus: 4 -max_cpu: "{{ num_cpus }}" -volgroup: /dev/vg_guests - eth0_ip: 10.5.129.233 gw: 10.5.129.254 main_bridge: br0 +max_cpu: "{{ num_cpus }}" +max_mem_size: "{{ mem_size }}" +mem_size: 24576 +num_cpus: 4 virt_install_command: "{{ virt_install_command_armv7_one_nic_unsafe }}" +vmhost: buildvmhost-aarch64-18.arm.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/buildvm-ppc64le-01.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-01.iad2.fedoraproject.org index 6a2b7c587c..1694bf80a1 100644 --- a/inventory/host_vars/buildvm-ppc64le-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-01.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.41 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-01.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-01.stg.iad2.fedoraproject.org index a5658d7bc0..9ff321416f 100644 --- a/inventory/host_vars/buildvm-ppc64le-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-01.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.47 +vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-02.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-02.iad2.fedoraproject.org index 078a01e063..6773b64fd1 100644 --- a/inventory/host_vars/buildvm-ppc64le-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-02.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.42 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-02.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-02.stg.iad2.fedoraproject.org index 68ad40daf3..7548e64b75 100644 --- a/inventory/host_vars/buildvm-ppc64le-02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-02.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.48 +vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-03.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-03.iad2.fedoraproject.org index 460073c4cc..16b1d89de7 100644 --- a/inventory/host_vars/buildvm-ppc64le-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-03.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.43 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-03.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-03.stg.iad2.fedoraproject.org index 6b3edca54f..16900bbcc1 100644 --- a/inventory/host_vars/buildvm-ppc64le-03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-03.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.49 +vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-04.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-04.iad2.fedoraproject.org index 8e05e8c0ec..5edb64fcd5 100644 --- a/inventory/host_vars/buildvm-ppc64le-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-04.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.44 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-04.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-04.stg.iad2.fedoraproject.org index d339a91278..7a1befdcb7 100644 --- a/inventory/host_vars/buildvm-ppc64le-04.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-04.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.50 +vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-05.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-05.iad2.fedoraproject.org index ea108c0b49..0e2c4ee709 100644 --- a/inventory/host_vars/buildvm-ppc64le-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-05.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.45 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-05.stg.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-05.stg.iad2.fedoraproject.org index 1b113a95b4..06094f1718 100644 --- a/inventory/host_vars/buildvm-ppc64le-05.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-05.stg.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.167.51 +vmhost: bvmhost-p08-01.stg.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-06.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-06.iad2.fedoraproject.org index a3c3982681..2f869d9d3d 100644 --- a/inventory/host_vars/buildvm-ppc64le-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-06.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.46 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-07.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-07.iad2.fedoraproject.org index bf2b5982a9..24dff3d0ff 100644 --- a/inventory/host_vars/buildvm-ppc64le-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-07.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.47 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-08.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-08.iad2.fedoraproject.org index e72b067367..059cb2c793 100644 --- a/inventory/host_vars/buildvm-ppc64le-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-08.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.48 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-09.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-09.iad2.fedoraproject.org index f227cd6cfe..f281d27583 100644 --- a/inventory/host_vars/buildvm-ppc64le-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-09.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.49 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-10.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-10.iad2.fedoraproject.org index c94ea9923b..cc983ab048 100644 --- a/inventory/host_vars/buildvm-ppc64le-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-10.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-01.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.50 +vmhost: bvmhost-p09-01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-11.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-11.iad2.fedoraproject.org index 0092023dd2..5767e22278 100644 --- a/inventory/host_vars/buildvm-ppc64le-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-11.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.51 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-12.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-12.iad2.fedoraproject.org index d46d969ab1..41fe668b09 100644 --- a/inventory/host_vars/buildvm-ppc64le-12.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-12.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.52 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-13.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-13.iad2.fedoraproject.org index c3f6d494a2..a678a57b4e 100644 --- a/inventory/host_vars/buildvm-ppc64le-13.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-13.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.53 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-14.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-14.iad2.fedoraproject.org index b004583010..28fd2d5fdf 100644 --- a/inventory/host_vars/buildvm-ppc64le-14.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-14.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.54 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-15.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-15.iad2.fedoraproject.org index 9e01631945..3a5feb6443 100644 --- a/inventory/host_vars/buildvm-ppc64le-15.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-15.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.55 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-16.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-16.iad2.fedoraproject.org index c1585fa5cd..e336091301 100644 --- a/inventory/host_vars/buildvm-ppc64le-16.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-16.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.56 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-17.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-17.iad2.fedoraproject.org index eb29d2045d..028a126040 100644 --- a/inventory/host_vars/buildvm-ppc64le-17.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-17.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.57 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-18.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-18.iad2.fedoraproject.org index c01389b777..dfac11a99d 100644 --- a/inventory/host_vars/buildvm-ppc64le-18.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-18.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.58 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-19.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-19.iad2.fedoraproject.org index 2626225675..0d773de596 100644 --- a/inventory/host_vars/buildvm-ppc64le-19.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-19.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.59 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-20.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-20.iad2.fedoraproject.org index 4d7a3f3910..a9e6ea2b5c 100644 --- a/inventory/host_vars/buildvm-ppc64le-20.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-20.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-02.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.60 +vmhost: bvmhost-p09-02.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-21.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-21.iad2.fedoraproject.org index a66a619309..134ad14727 100644 --- a/inventory/host_vars/buildvm-ppc64le-21.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-21.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.61 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-22.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-22.iad2.fedoraproject.org index 72a1550ebe..13432fe7dd 100644 --- a/inventory/host_vars/buildvm-ppc64le-22.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-22.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.62 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-23.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-23.iad2.fedoraproject.org index 60aafdcf64..06fdc1b98a 100644 --- a/inventory/host_vars/buildvm-ppc64le-23.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-23.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.63 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-24.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-24.iad2.fedoraproject.org index 158ad3f056..9b21983bd3 100644 --- a/inventory/host_vars/buildvm-ppc64le-24.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-24.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.64 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-25.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-25.iad2.fedoraproject.org index 0bbabc8002..09157dcacb 100644 --- a/inventory/host_vars/buildvm-ppc64le-25.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-25.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.65 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-26.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-26.iad2.fedoraproject.org index e4d33ab5da..70148865e2 100644 --- a/inventory/host_vars/buildvm-ppc64le-26.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-26.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.66 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-27.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-27.iad2.fedoraproject.org index 30caf62d10..64be57c9dc 100644 --- a/inventory/host_vars/buildvm-ppc64le-27.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-27.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.67 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-28.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-28.iad2.fedoraproject.org index 3a8a329029..59ca0216db 100644 --- a/inventory/host_vars/buildvm-ppc64le-28.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-28.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.68 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-29.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-29.iad2.fedoraproject.org index 42c8c2f441..456fed4bbe 100644 --- a/inventory/host_vars/buildvm-ppc64le-29.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-29.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.69 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-30.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-30.iad2.fedoraproject.org index 3b9a05ef82..a7a5fdb0f0 100644 --- a/inventory/host_vars/buildvm-ppc64le-30.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-30.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-03.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.70 +vmhost: bvmhost-p09-03.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-31.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-31.iad2.fedoraproject.org index 476d83c057..e0fa08f31b 100644 --- a/inventory/host_vars/buildvm-ppc64le-31.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-31.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.71 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-32.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-32.iad2.fedoraproject.org index 6c6eb6bb27..e1ca6c2552 100644 --- a/inventory/host_vars/buildvm-ppc64le-32.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-32.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.72 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-33.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-33.iad2.fedoraproject.org index b740c8afe5..621238382b 100644 --- a/inventory/host_vars/buildvm-ppc64le-33.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-33.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.73 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-34.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-34.iad2.fedoraproject.org index ff55b23a5f..3e5e42d1b9 100644 --- a/inventory/host_vars/buildvm-ppc64le-34.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-34.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.74 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-35.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-35.iad2.fedoraproject.org index d41f796aab..803380fade 100644 --- a/inventory/host_vars/buildvm-ppc64le-35.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-35.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.75 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-36.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-36.iad2.fedoraproject.org index 2f4d18a29e..58d19fabda 100644 --- a/inventory/host_vars/buildvm-ppc64le-36.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-36.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.76 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-37.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-37.iad2.fedoraproject.org index ab688c4a7b..f58a619069 100644 --- a/inventory/host_vars/buildvm-ppc64le-37.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-37.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.77 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-38.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-38.iad2.fedoraproject.org index 8500559f4f..bd11ee8765 100644 --- a/inventory/host_vars/buildvm-ppc64le-38.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-38.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.78 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-39.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-39.iad2.fedoraproject.org index a48dea53ee..a1da4955bd 100644 --- a/inventory/host_vars/buildvm-ppc64le-39.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-39.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.79 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-ppc64le-40.iad2.fedoraproject.org b/inventory/host_vars/buildvm-ppc64le-40.iad2.fedoraproject.org index 01de5481b6..40791070c3 100644 --- a/inventory/host_vars/buildvm-ppc64le-40.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-ppc64le-40.iad2.fedoraproject.org @@ -1,7 +1,6 @@ --- -vmhost: bvmhost-p09-04.iad2.fedoraproject.org datacenter: iad2 dns1: 10.3.163.33 dns2: 10.3.163.34 - eth0_ip: 10.3.171.80 +vmhost: bvmhost-p09-04.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-s390x-01.stg.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-01.stg.s390.fedoraproject.org index 1251341066..1e21b57ac3 100644 --- a/inventory/host_vars/buildvm-s390x-01.stg.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-01.stg.s390.fedoraproject.org @@ -1,14 +1,14 @@ --- -varnish_group: s390kojipkgs -vmhost: buildvmhost-s390x-01.s390.fedoraproject.org +dns: 10.5.126.21 eth0_ipv4: 10.16.0.25 gw: 10.16.0.254 -mem_size: 8192 -max_mem_size: "{{ mem_size }}" -num_cpus: 2 lvm_size: 102400 main_bridge: vmbr -volgroup: /dev/fedora_linux_lpar_1 -dns: 10.5.126.21 +max_mem_size: "{{ mem_size }}" +mem_size: 8192 nm: 255.255.255.0 +num_cpus: 2 +varnish_group: s390kojipkgs virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}" +vmhost: buildvmhost-s390x-01.s390.fedoraproject.org +volgroup: /dev/fedora_linux_lpar_1 diff --git a/inventory/host_vars/buildvm-s390x-07.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-07.s390.fedoraproject.org index f7dd74d70c..7d2c2c282f 100644 --- a/inventory/host_vars/buildvm-s390x-07.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-07.s390.fedoraproject.org @@ -1,39 +1,33 @@ --- -varnish_group: s390kojipkgs - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes enc900_ipv4: 10.16.0.17 -enc900_ipv4_nm: 24 enc900_ipv4_gw: 10.16.0.254 -eth0_ip: 10.16.0.17 -nm: 255.255.255.0 -gw: 10.16.0.254 - -mac0: 02:d3:fa:02:00:08 - +enc900_ipv4_nm: 24 enc900_mac: "{{ mac0 }}" - +eth0_ip: 10.16.0.17 +gw: 10.16.0.254 +has_ipv4: yes +mac0: 02:d3:fa:02:00:08 network_connections: -- name: enc900 - mac: "{{ enc900_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ enc900_ipv4 }}/{{ enc900_ipv4_nm }}" - gateway4: "{{ enc900_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ enc900_ipv4 }}/{{ enc900_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ enc900_ipv4_gw }}" + mac: "{{ enc900_mac }}" + name: enc900 + state: up + type: ethernet +nm: 255.255.255.0 +varnish_group: s390kojipkgs diff --git a/inventory/host_vars/buildvm-s390x-15.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-15.s390.fedoraproject.org index 4f937f92c9..f308cf5b45 100644 --- a/inventory/host_vars/buildvm-s390x-15.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-15.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.26 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:a2:30:f8 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:a2:30:f8 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-16.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-16.s390.fedoraproject.org index 9a2b18dadd..d25a0ff761 100644 --- a/inventory/host_vars/buildvm-s390x-16.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-16.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.27 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:b9:2c:93 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:b9:2c:93 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-17.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-17.s390.fedoraproject.org index 6f594a626d..b1d9ec2b28 100644 --- a/inventory/host_vars/buildvm-s390x-17.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-17.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.28 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:aa:25:b9 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:aa:25:b9 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-18.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-18.s390.fedoraproject.org index 8e98f1afa0..c84ccfc38f 100644 --- a/inventory/host_vars/buildvm-s390x-18.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-18.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.29 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:db:57:e3 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:db:57:e3 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-19.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-19.s390.fedoraproject.org index 4649215ffe..f7636bc7e4 100644 --- a/inventory/host_vars/buildvm-s390x-19.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-19.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.30 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:c4:f2:4e - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:c4:f2:4e network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-20.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-20.s390.fedoraproject.org index 90b7e933d1..201f090c76 100644 --- a/inventory/host_vars/buildvm-s390x-20.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-20.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.31 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:74:95:f0 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:74:95:f0 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-21.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-21.s390.fedoraproject.org index de5c5a9cd7..9081bb2176 100644 --- a/inventory/host_vars/buildvm-s390x-21.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-21.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.32 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:42:6d:23 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:42:6d:23 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-22.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-22.s390.fedoraproject.org index ab661dac2a..9741bf5d20 100644 --- a/inventory/host_vars/buildvm-s390x-22.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-22.s390.fedoraproject.org @@ -1,32 +1,28 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.33 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes network_connections: -- name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-23.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-23.s390.fedoraproject.org index a04caf9169..04c372beed 100644 --- a/inventory/host_vars/buildvm-s390x-23.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-23.s390.fedoraproject.org @@ -1,34 +1,29 @@ --- dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.34 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:e1:13:8e - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:e1:13:8e network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-s390x-24.s390.fedoraproject.org b/inventory/host_vars/buildvm-s390x-24.s390.fedoraproject.org index 0545f5208b..b63706157d 100644 --- a/inventory/host_vars/buildvm-s390x-24.s390.fedoraproject.org +++ b/inventory/host_vars/buildvm-s390x-24.s390.fedoraproject.org @@ -1,37 +1,31 @@ --- # needed because this host has a varnish cache on it. -custom_rules: [ '-A INPUT -s 10.16.0.0/24 -p tcp -m tcp --dport 80 -j ACCEPT' ] - +custom_rules: ['-A INPUT -s 10.16.0.0/24 -p tcp -m tcp --dport 80 -j ACCEPT'] dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.16.0.35 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.16.0.254 - -mac0: 52:54:00:70:cc:a7 - +eth0_ipv4_nm: 24 eth0_mac: "{{ mac0 }}" - +has_ipv4: yes +mac0: 52:54:00:70:cc:a7 network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet diff --git a/inventory/host_vars/buildvm-x86-01.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-01.iad2.fedoraproject.org index 615db08f28..8ebe882d41 100644 --- a/inventory/host_vars/buildvm-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-01.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.51 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-02.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-02.iad2.fedoraproject.org index 49c2b09e19..cecef15655 100644 --- a/inventory/host_vars/buildvm-x86-02.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-02.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.52 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-03.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-03.iad2.fedoraproject.org index 5c41827192..801b500d12 100644 --- a/inventory/host_vars/buildvm-x86-03.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-03.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.53 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-04.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-04.iad2.fedoraproject.org index 255952c30c..97ad7eefa5 100644 --- a/inventory/host_vars/buildvm-x86-04.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-04.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.54 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-05.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-05.iad2.fedoraproject.org index b13fc23049..bcc0766d50 100644 --- a/inventory/host_vars/buildvm-x86-05.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-05.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.55 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-06.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-06.iad2.fedoraproject.org index 7e9d0be84b..3b96a28b26 100644 --- a/inventory/host_vars/buildvm-x86-06.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-06.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.56 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-07.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-07.iad2.fedoraproject.org index cf84d5f7ff..16c7b481fb 100644 --- a/inventory/host_vars/buildvm-x86-07.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-07.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.57 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-08.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-08.iad2.fedoraproject.org index 7946ef6061..cbeda60e7c 100644 --- a/inventory/host_vars/buildvm-x86-08.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-08.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.58 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-09.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-09.iad2.fedoraproject.org index 0523528700..0230589c77 100644 --- a/inventory/host_vars/buildvm-x86-09.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-09.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.59 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-10.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-10.iad2.fedoraproject.org index 40383c76cf..6d28311946 100644 --- a/inventory/host_vars/buildvm-x86-10.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-10.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.60 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-11.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-11.iad2.fedoraproject.org index 40825da7a9..8ca6139b19 100644 --- a/inventory/host_vars/buildvm-x86-11.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-11.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.61 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-12.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-12.iad2.fedoraproject.org index 1e406ae031..425fae6f5e 100644 --- a/inventory/host_vars/buildvm-x86-12.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-12.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.62 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-13.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-13.iad2.fedoraproject.org index e81c29bffa..5e043bb21d 100644 --- a/inventory/host_vars/buildvm-x86-13.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-13.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.63 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-14.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-14.iad2.fedoraproject.org index d15919b6a4..df28411951 100644 --- a/inventory/host_vars/buildvm-x86-14.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-14.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.64 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-15.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-15.iad2.fedoraproject.org index 253a59e6e3..04f123964b 100644 --- a/inventory/host_vars/buildvm-x86-15.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-15.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.65 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-16.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-16.iad2.fedoraproject.org index 3129aa43c9..31ba9b159c 100644 --- a/inventory/host_vars/buildvm-x86-16.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-16.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.66 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-06.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-17.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-17.iad2.fedoraproject.org index bc5d8bebf0..7e318bc266 100644 --- a/inventory/host_vars/buildvm-x86-17.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-17.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.67 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-18.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-18.iad2.fedoraproject.org index c8502419da..d894015291 100644 --- a/inventory/host_vars/buildvm-x86-18.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-18.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.68 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-19.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-19.iad2.fedoraproject.org index 170fe420ca..35508f2ff2 100644 --- a/inventory/host_vars/buildvm-x86-19.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-19.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.69 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-20.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-20.iad2.fedoraproject.org index 18c1683fa4..256795b695 100644 --- a/inventory/host_vars/buildvm-x86-20.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-20.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.70 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-21.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-21.iad2.fedoraproject.org index 67dc0a8ec8..e22efe92ef 100644 --- a/inventory/host_vars/buildvm-x86-21.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-21.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.71 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-22.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-22.iad2.fedoraproject.org index 64b67963b8..7ff7817a35 100644 --- a/inventory/host_vars/buildvm-x86-22.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-22.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.72 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-23.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-23.iad2.fedoraproject.org index dbdde8827d..baaeb9afd9 100644 --- a/inventory/host_vars/buildvm-x86-23.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-23.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.73 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-24.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-24.iad2.fedoraproject.org index 90fbafb144..7ed8122539 100644 --- a/inventory/host_vars/buildvm-x86-24.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-24.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.74 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-25.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-25.iad2.fedoraproject.org index 0167bbcbb5..f954c6cf65 100644 --- a/inventory/host_vars/buildvm-x86-25.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-25.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.75 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-26.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-26.iad2.fedoraproject.org index 27bde728b8..3fcd420d31 100644 --- a/inventory/host_vars/buildvm-x86-26.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-26.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.76 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-27.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-27.iad2.fedoraproject.org index 2afd377c92..7e17604641 100644 --- a/inventory/host_vars/buildvm-x86-27.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-27.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.77 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-28.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-28.iad2.fedoraproject.org index 503c370fd1..66b38c8a63 100644 --- a/inventory/host_vars/buildvm-x86-28.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-28.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.78 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-29.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-29.iad2.fedoraproject.org index 12d1cf0298..cbca503271 100644 --- a/inventory/host_vars/buildvm-x86-29.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-29.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.79 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-30.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-30.iad2.fedoraproject.org index 22aa8e9427..f956f16106 100644 --- a/inventory/host_vars/buildvm-x86-30.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-30.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.80 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-31.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-31.iad2.fedoraproject.org index c4a7694444..375cb8fc3f 100644 --- a/inventory/host_vars/buildvm-x86-31.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-31.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.81 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/buildvm-x86-32.iad2.fedoraproject.org b/inventory/host_vars/buildvm-x86-32.iad2.fedoraproject.org index 6269359e52..572490516a 100644 --- a/inventory/host_vars/buildvm-x86-32.iad2.fedoraproject.org +++ b/inventory/host_vars/buildvm-x86-32.iad2.fedoraproject.org @@ -3,6 +3,6 @@ datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.82 gw: 10.3.169.254 +ipa_server: ipa01.iad2.fedoraproject.org resolvconf: "resolv.conf/iad2" vmhost: bvmhost-x86-07.iad2.fedoraproject.org -ipa_server: ipa01.iad2.fedoraproject.org diff --git a/inventory/host_vars/busgateway01.iad2.fedoraproject.org b/inventory/host_vars/busgateway01.iad2.fedoraproject.org index 90b873ff64..b0054e32f9 100644 --- a/inventory/host_vars/busgateway01.iad2.fedoraproject.org +++ b/inventory/host_vars/busgateway01.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.163.46 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-05.iad2.fedoraproject.org - datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.46 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/busgateway01.stg.iad2.fedoraproject.org b/inventory/host_vars/busgateway01.stg.iad2.fedoraproject.org index 66ec7d194c..5798311888 100644 --- a/inventory/host_vars/busgateway01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/busgateway01.stg.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.166.38 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org - datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.38 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/bvmhost-a64-01.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-01.iad2.fedoraproject.org index 33277820e4..ecfc2006ae 100644 --- a/inventory/host_vars/bvmhost-a64-01.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-01.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.11 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.11 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:d3:c0 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-02.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-02.iad2.fedoraproject.org index 83fbf4edd5..4e618f358a 100644 --- a/inventory/host_vars/bvmhost-a64-02.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-02.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.12 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.12 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:c2:c0 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-03.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-03.iad2.fedoraproject.org index 86ee219a41..5ed152d6a7 100644 --- a/inventory/host_vars/bvmhost-a64-03.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-03.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.13 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.13 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6b:0a:40 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-04.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-04.iad2.fedoraproject.org index 7a31dd7776..bb5cea2c86 100644 --- a/inventory/host_vars/bvmhost-a64-04.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-04.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.14 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.14 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:b5:d0 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-05.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-05.iad2.fedoraproject.org index a92b0861d6..426f190fbc 100644 --- a/inventory/host_vars/bvmhost-a64-05.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-05.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.15 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.15 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:ef:70 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-06.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-06.iad2.fedoraproject.org index 6a8054f4eb..b2ffc66cb0 100644 --- a/inventory/host_vars/bvmhost-a64-06.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-06.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.16 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.16 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:ba:60 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-07.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-07.iad2.fedoraproject.org index a0bfc24192..c0b03a8190 100644 --- a/inventory/host_vars/bvmhost-a64-07.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-07.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.17 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6b:07:00 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-08.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-08.iad2.fedoraproject.org index 889bf3787f..b861bba5e2 100644 --- a/inventory/host_vars/bvmhost-a64-08.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-08.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.18 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.18 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:c2:00 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-09.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-09.iad2.fedoraproject.org index 6ec81197c7..7327512196 100644 --- a/inventory/host_vars/bvmhost-a64-09.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-09.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.170.19 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.19 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:c9:70 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-a64-10.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-a64-10.iad2.fedoraproject.org index c82a9a8910..ae34255bbb 100644 --- a/inventory/host_vars/bvmhost-a64-10.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-a64-10.iad2.fedoraproject.org @@ -1,42 +1,34 @@ --- +br0_ipv4: 10.3.170.20 +br0_ipv4_gw: 10.3.170.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.170.20 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.170.254 - mac1: 50:6b:4b:6a:dd:a0 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - - diff --git a/inventory/host_vars/bvmhost-p08-03.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p08-03.iad2.fedoraproject.org index 0748972bb9..ffecdfb9c9 100644 --- a/inventory/host_vars/bvmhost-p08-03.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p08-03.iad2.fedoraproject.org @@ -1,9 +1,7 @@ --- -datacenter: iad2 - +br0_dev: eth8 +br0_gw: 10.3.171.254 br0_ip: 10.3.171.13 br0_nm: 255.255.255.0 -br0_gw: 10.3.171.254 -br0_dev: eth8 - +datacenter: iad2 dns: 10.3.163.33 diff --git a/inventory/host_vars/bvmhost-p08-04.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p08-04.iad2.fedoraproject.org index 88a39106cc..2e6eaf0d89 100644 --- a/inventory/host_vars/bvmhost-p08-04.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p08-04.iad2.fedoraproject.org @@ -1,9 +1,7 @@ --- -datacenter: iad2 - +br0_dev: eth8 +br0_gw: 10.3.167.254 br0_ip: 10.3.167.15 br0_nm: 255.255.255.0 -br0_gw: 10.3.167.254 -br0_dev: eth8 - +datacenter: iad2 dns: 10.3.163.33 diff --git a/inventory/host_vars/bvmhost-p09-01.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p09-01.iad2.fedoraproject.org index b67b6723a5..1199f65eb2 100644 --- a/inventory/host_vars/bvmhost-p09-01.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p09-01.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.171.15 +br0_ipv4_gw: 10.3.171.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.171.15 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.171.254 - mac1: 40:a6:b7:18:8a:38 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-p09-02.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p09-02.iad2.fedoraproject.org index 32410dce80..5597d518c5 100644 --- a/inventory/host_vars/bvmhost-p09-02.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p09-02.iad2.fedoraproject.org @@ -1,42 +1,35 @@ --- +br0_ipv4: 10.3.171.16 +br0_ipv4_gw: 10.3.171.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac2 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.171.16 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.171.254 - mac1: ac:1f:6b:56:e9:11 mac2: 40:a6:b7:18:86:b4 - -br0_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-p09-03.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p09-03.iad2.fedoraproject.org index 69fd9711b7..72f72c8a82 100644 --- a/inventory/host_vars/bvmhost-p09-03.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p09-03.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.171.17 +br0_ipv4_gw: 10.3.171.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.171.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.171.254 - mac1: 40:a6:b7:18:85:74 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-p09-04.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-p09-04.iad2.fedoraproject.org index 681cff54b2..5797234bc8 100644 --- a/inventory/host_vars/bvmhost-p09-04.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-p09-04.iad2.fedoraproject.org @@ -1,42 +1,35 @@ --- +br0_ipv4: 10.3.171.18 +br0_ipv4_gw: 10.3.171.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac2 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.171.18 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.171.254 - mac1: 40:a6:b7:18:85:74 mac2: 40:a6:b7:18:86:c8 - -br0_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-01.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-01.iad2.fedoraproject.org index 25e3baf25b..3c93424280 100644 --- a/inventory/host_vars/bvmhost-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-01.iad2.fedoraproject.org @@ -1,41 +1,34 @@ --- +br0_ipv4: 10.3.169.11 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.11 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:b1:05:54 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-01.stg.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-01.stg.iad2.fedoraproject.org index 190ea20dd3..ca0dcfaab3 100644 --- a/inventory/host_vars/bvmhost-x86-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-01.stg.iad2.fedoraproject.org @@ -1,46 +1,39 @@ --- +br0_ipv4: 10.3.167.11 +br0_ipv4_gw: 10.3.167.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.167.11 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.167.254 - mac1: 24:6e:96:b1:56:24 mac2: 24:6e:96:b1:56:25 mac3: 24:6e:96:b1:56:20 mac4: 24:6e:96:b1:56:22 - -br0_port0_mac: "{{ mac3 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-02.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-02.iad2.fedoraproject.org index eacbb78d27..57d0691ae6 100644 --- a/inventory/host_vars/bvmhost-x86-02.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-02.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.12 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.12 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:b1:69:fe mac2: e4:43:4b:b1:6a:00 mac3: e4:43:4b:b1:6a:1e mac4: e4:43:4b:b1:6a:1f - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-02.stg.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-02.stg.iad2.fedoraproject.org index 5cd20bf5e2..7064035a5f 100644 --- a/inventory/host_vars/bvmhost-x86-02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-02.stg.iad2.fedoraproject.org @@ -1,46 +1,39 @@ --- +br0_ipv4: 10.3.167.12 +br0_ipv4_gw: 10.3.167.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.167.12 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.167.254 - mac1: ec:f4:bb:d9:56:10 mac2: ec:f4:bb:d9:56:12 mac3: ec:f4:bb:d9:56:14 mac4: ec:f4:bb:d9:56:15 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-03.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-03.iad2.fedoraproject.org index e424afab83..5a4e077b50 100644 --- a/inventory/host_vars/bvmhost-x86-03.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-03.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.13 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.13 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:b1:62:64 mac2: e4:43:4b:b1:62:66 mac3: e4:43:4b:b1:62:84 mac4: e4:43:4b:b1:62:85 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-03.stg.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-03.stg.iad2.fedoraproject.org index 335878b22c..6c02cb8bd4 100644 --- a/inventory/host_vars/bvmhost-x86-03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-03.stg.iad2.fedoraproject.org @@ -1,46 +1,39 @@ --- +br0_ipv4: 10.3.167.13 +br0_ipv4_gw: 10.3.167.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.167.13 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.167.254 - mac1: 24:6e:96:b1:c7:f4 mac2: 24:6e:96:b1:c7:f5 mac3: 24:6e:96:b1:c7:f0 mac4: 24:6e:96:b1:c7:f2 - -br0_port0_mac: "{{ mac3 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-04.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-04.iad2.fedoraproject.org index d309fec8d6..dc0dc50886 100644 --- a/inventory/host_vars/bvmhost-x86-04.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-04.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.14 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.14 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:b1:03:30 mac2: e4:43:4b:b1:03:32 mac3: e4:43:4b:b1:03:50 mac4: e4:43:4b:b1:03:51 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-04.stg.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-04.stg.iad2.fedoraproject.org index d9a0b4aeee..fc56f04588 100644 --- a/inventory/host_vars/bvmhost-x86-04.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-04.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.167.14 +br0_ipv4_gw: 10.3.167.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.167.14 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.167.254 - -mgmt_mac: "B8:2A:72:FC:EE:68" -mgmt_ipv4: 10.3.160.199 mac1: EC:F4:BB:D2:8F:00 mac2: EC:F4:BB:D2:8F:02 mac3: EC:F4:BB:D2:8F:04 mac4: EC:F4:BB:D2:8F:05 - -br0_port0_mac: "{{ mac1 }}" - +mgmt_ipv4: 10.3.160.199 +mgmt_mac: "B8:2A:72:FC:EE:68" +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/bvmhost-x86-05.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-05.iad2.fedoraproject.org index 01b88a9392..7518f12dcb 100644 --- a/inventory/host_vars/bvmhost-x86-05.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-05.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.15 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.15 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:ae:44:ee mac2: e4:43:4b:ae:44:f0 mac3: e4:43:4b:ae:45:0e mac4: e4:43:4b:ae:45:0f - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-05.stg.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-05.stg.iad2.fedoraproject.org index ff507946e8..5c3a32756d 100644 --- a/inventory/host_vars/bvmhost-x86-05.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-05.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.167.17 +br0_ipv4_gw: 10.3.167.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.167.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.167.254 - -mgmt_mac: "2c:ea:7f:f3:58:4e" -mgmt_ipv4: 10.3.160.157 mac1: E4:43:4B:F7:AC:CC mac2: E4:43:4B:F7:AC:CE mac3: E4:43:4B:F7:AC:EC mac4: E4:43:4B:F7:AC:ED - -br0_port0_mac: "{{ mac1 }}" - +mgmt_ipv4: 10.3.160.157 +mgmt_mac: "2c:ea:7f:f3:58:4e" +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/bvmhost-x86-06.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-06.iad2.fedoraproject.org index 811d18b868..8b0c7dbe68 100644 --- a/inventory/host_vars/bvmhost-x86-06.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-06.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.16 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.16 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:ac:e1:54 mac2: e4:43:4b:ac:e1:56 mac3: e4:43:4b:ac:e1:74 mac4: e4:43:4b:ac:e1:75 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-07.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-07.iad2.fedoraproject.org index 984ba14ded..7480f357cc 100644 --- a/inventory/host_vars/bvmhost-x86-07.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-07.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.17 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:b1:2b:52 mac2: e4:43:4b:b1:2b:54 mac3: e4:43:4b:b1:2b:72 mac4: e4:43:4b:b1:2b:73 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/bvmhost-x86-08.iad2.fedoraproject.org b/inventory/host_vars/bvmhost-x86-08.iad2.fedoraproject.org index 7fb040de1a..c0dbb8919c 100644 --- a/inventory/host_vars/bvmhost-x86-08.iad2.fedoraproject.org +++ b/inventory/host_vars/bvmhost-x86-08.iad2.fedoraproject.org @@ -1,44 +1,37 @@ --- +br0_ipv4: 10.3.169.18 +br0_ipv4_gw: 10.3.169.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac2 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.169.18 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.169.254 - mac1: e4:43:4b:24:19:96 mac2: e4:43:4b:24:19:76 mac3: e4:43:4b:24:19:97 mac4: e4:43:4b:24:19:78 - -br0_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/centos-ipa-client01.stg.iad2.fedoraproject.org b/inventory/host_vars/centos-ipa-client01.stg.iad2.fedoraproject.org index 7903d21380..9a50295ace 100644 --- a/inventory/host_vars/centos-ipa-client01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/centos-ipa-client01.stg.iad2.fedoraproject.org @@ -1,22 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.166.42 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-09.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.42 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 nagios_Can_Connect: false - nagios_Check_Services: mail: false nrpe: false + ping: false sshd: false swap: false - ping: false +nm: 255.255.255.0 +vmhost: vmhost-x86-09.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/centos-ipa-client02.stg.iad2.fedoraproject.org b/inventory/host_vars/centos-ipa-client02.stg.iad2.fedoraproject.org index 4ae2b1275f..c3810402ae 100644 --- a/inventory/host_vars/centos-ipa-client02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/centos-ipa-client02.stg.iad2.fedoraproject.org @@ -1,22 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.166.43 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.43 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 nagios_Can_Connect: false - nagios_Check_Services: mail: false nrpe: false + ping: false sshd: false swap: false - ping: false +nm: 255.255.255.0 +vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/certgetter01.iad2.fedoraproject.org b/inventory/host_vars/certgetter01.iad2.fedoraproject.org index bf644790fc..93b65ee21c 100644 --- a/inventory/host_vars/certgetter01.iad2.fedoraproject.org +++ b/inventory/host_vars/certgetter01.iad2.fedoraproject.org @@ -1,13 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.47 -vmhost: vmhost-x86-07.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.47 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora mem_size: 4096 +nm: 255.255.255.0 +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/certgetter01.stg.iad2.fedoraproject.org b/inventory/host_vars/certgetter01.stg.iad2.fedoraproject.org index b7803b4848..c2e3dc3a42 100644 --- a/inventory/host_vars/certgetter01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/certgetter01.stg.iad2.fedoraproject.org @@ -1,13 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.22 -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.22 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 mem_size: 4096 +nm: 255.255.255.0 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/cloud-noc-os01.rdu-cc.fedoraproject.org b/inventory/host_vars/cloud-noc-os01.rdu-cc.fedoraproject.org index 09bf05f045..39b3d18483 100644 --- a/inventory/host_vars/cloud-noc-os01.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/cloud-noc-os01.rdu-cc.fedoraproject.org @@ -1,94 +1,64 @@ --- -freezes: false - datacenter: rdu-cc -vmhost: vmhost-x86-cc05.rdu-cc.fedoraproject.org -volgroup: /dev/rhel_vmhost-x86-05 -mem_size: 8192 -num_cpus: 4 -lvm_size: 20000 - dns1: 8.8.8.8 dns2: 8.8.4.4 - -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ - -tcp_ports: ['67', '68'] -udp_ports: ['67','68','69'] - -vpn: true -has_ipv4: yes eth0_ipv4: 8.43.85.49 -eth0_ipv4_nm: 23 eth0_ipv4_gw: 8.43.85.254 +eth0_ipv4_nm: 23 eth1_ipv4: 172.23.1.3 eth1_ipv4_nm: 24 eth2_ipv4: 172.23.5.3 eth2_ipv4_nm: 24 - +freezes: false +has_ipv4: yes +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 mac0: 52:54:00:46:ed:ba mac1: 52:54:00:24:8e:bc mac2: 52:54:00:d6:ab:66 -public_hostname: cloud-noc-os01.rdu-cc.fedoraproject.org - +mem_size: 8192 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no dns: - - "{{ dns1 }}" - - "{{ dns2 }}" + - "{{ dns1 }}" + - "{{ dns2 }}" dns_search: - - rdu-cc.fedoraproject.org - - fedoraproject.org - dhcp4: no + - rdu-cc.fedoraproject.org + - fedoraproject.org + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" auto6: no - - name: eth1 + dhcp4: no mac: "{{ mac1 }}" + name: eth1 type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - dhcp4: no + - "{{ eth2_ipv4 }}/{{ eth2_ipv4_nm }}" auto6: no - - name: eth2 + dhcp4: no mac: "{{ mac2 }}" + name: eth2 type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth2_ipv4 }}/{{ eth2_ipv4_nm }}" - dhcp4: no - auto6: no - -virt_install_command: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns1 }} - ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none - ip={{ eth1_ipv4 }}:::{{ eth1_ipv4_nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac0 }} - --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac1 }} - --autostart --noautoconsole --watchdog default --rng /dev/random - -virt_install_command_two_nic: virt-install -n {{ inventory_hostname }} - --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio - --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} - --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x - 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=tty0 console=ttyS0 - hostname={{ inventory_hostname }} nameserver={{ dns }} - ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none - ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' - --network bridge={{ main_bridge }},model=virtio,mac={{ mac0 }} - --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac1 }} - --autostart --noautoconsole --watchdog default --rng /dev/random - +num_cpus: 4 +public_hostname: cloud-noc-os01.rdu-cc.fedoraproject.org +tcp_ports: ['67', '68'] +udp_ports: ['67', '68', '69'] +virt_install_command: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns1 }} ip={{ eth0_ipv4 }}::{{ eth0_ipv4_gw }}:{{ eth0_ipv4_nm }}:{{ inventory_hostname }}:eth0:none ip={{ eth1_ipv4 }}:::{{ eth1_ipv4_nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac0 }} --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac1 }} --autostart --noautoconsole --watchdog default --rng /dev/random +virt_install_command_two_nic: virt-install -n {{ inventory_hostname }} --memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio --disk bus=virtio,path={{ volgroup }}/{{ inventory_hostname }} --vcpus={{ num_cpus }},maxvcpus={{ max_cpu }} -l {{ ks_repo }} -x 'net.ifnames=0 ksdevice=eth0 ks={{ ks_url }} console=tty0 console=ttyS0 hostname={{ inventory_hostname }} nameserver={{ dns }} ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname_short }}-nfs:eth1:none' --network bridge={{ main_bridge }},model=virtio,mac={{ mac0 }} --network=bridge={{ nfs_bridge }},model=virtio,mac={{ mac1 }} --autostart --noautoconsole --watchdog default --rng /dev/random +vmhost: vmhost-x86-cc05.rdu-cc.fedoraproject.org +volgroup: /dev/rhel_vmhost-x86-05 +vpn: true diff --git a/inventory/host_vars/cloud-noc01.fedorainfracloud.org b/inventory/host_vars/cloud-noc01.fedorainfracloud.org index 9bae4d57c4..d74aad701d 100644 --- a/inventory/host_vars/cloud-noc01.fedorainfracloud.org +++ b/inventory/host_vars/cloud-noc01.fedorainfracloud.org @@ -1,42 +1,24 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 +custom_rules: ['-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 67 -j ACCEPT', '-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 68 -j ACCEPT', '-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 69 -j ACCEPT', '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 67 -j ACCEPT', '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 68 -j ACCEPT', '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 69 -j ACCEPT', '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 67 -j ACCEPT', '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 68 -j ACCEPT', '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 69 -j ACCEPT', '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 67 -j ACCEPT', '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 68 -j ACCEPT', '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 69 -j ACCEPT', '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 124 -j ACCEPT'] datacenter: cloud dns: 8.8.8.8 eth0_ip: 38.145.48.10 -gw: 38.145.49.254 -nm: 255.255.255.0 eth1_ip: 172.23.1.1 freezes: false +gw: 38.145.49.254 +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext +lvm_size: 20000 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 8 +public_hostname: cloud-noc01.fedorainfracloud.org resolvconf: "{{ files }}/resolv.conf/cloud-noc01.fedorainfracloud.org" - +tcp_ports: ['22'] +virt_install_command: "{{ virt_install_command_two_nic }}" vmhost: virthost-cloud01.fedorainfracloud.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_two_nic }}" -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: cloud-noc01.fedorainfracloud.org - - -tcp_ports: ['22'] -custom_rules: [ '-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 67 -j ACCEPT', - '-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 68 -j ACCEPT', - '-A INPUT -i eth0 -p tcp -m tcp -s 38.145.48.0/23 --dport 69 -j ACCEPT', - '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 67 -j ACCEPT', - '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 68 -j ACCEPT', - '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 69 -j ACCEPT', - '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 67 -j ACCEPT', - '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 68 -j ACCEPT', - '-A INPUT -i eth1 -p tcp -m tcp -s 172.23.0.0/23 --dport 69 -j ACCEPT', - '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 67 -j ACCEPT', - '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 68 -j ACCEPT', - '-A INPUT -i eth1 -p udp -m udp -s 172.23.0.0/23 --dport 69 -j ACCEPT', - '-A INPUT -i eth0 -p udp -m udp -s 38.145.48.0/23 --dport 124 -j ACCEPT' ] - diff --git a/inventory/host_vars/compose-branched01.iad2.fedoraproject.org b/inventory/host_vars/compose-branched01.iad2.fedoraproject.org index 36a7a43942..cd0a74091c 100644 --- a/inventory/host_vars/compose-branched01.iad2.fedoraproject.org +++ b/inventory/host_vars/compose-branched01.iad2.fedoraproject.org @@ -1,52 +1,46 @@ -vmhost: bvmhost-x86-02.iad2.fedoraproject.org -gw: 10.3.169.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.121 -volgroup: /dev/vg_guests -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/35/Server/x86_64/os/ - -datacenter: iad2 - -koji_hub_nfs: "fedora_koji" - -kojipkgs_url: kojipkgs.fedoraproject.org -kojihub_url: koji.fedoraproject.org/kojihub -kojihub_scheme: https - -freezes: true - -virt_install_command: "{{ virt_install_command_one_nic }}" - fedmsg_certs: -- service: releng - owner: root - group: sysadmin-releng - can_send: - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.createiso.imagefail - - pungi.compose.createiso.imagedone - - pungi.compose.ostree - - compose.branched.complete - - compose.branched.mash.complete - - compose.branched.mash.start - - compose.branched.image.complete - - compose.branched.image.start - - compose.branched.pungify.complete - - compose.branched.pungify.start - - compose.branched.rsync.complete - - compose.branched.rsync.start - - compose.branched.start - - compose.bikeshed.complete - - compose.bikeshed.mash.complete - - compose.bikeshed.mash.start - - compose.bikeshed.image.complete - - compose.bikeshed.image.start - - compose.bikeshed.pungify.complete - - compose.bikeshed.pungify.start - - compose.bikeshed.rsync.complete - - compose.bikeshed.rsync.start - - compose.bikeshed.start + - can_send: + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.createiso.imagefail + - pungi.compose.createiso.imagedone + - pungi.compose.ostree + - compose.branched.complete + - compose.branched.mash.complete + - compose.branched.mash.start + - compose.branched.image.complete + - compose.branched.image.start + - compose.branched.pungify.complete + - compose.branched.pungify.start + - compose.branched.rsync.complete + - compose.branched.rsync.start + - compose.branched.start + - compose.bikeshed.complete + - compose.bikeshed.mash.complete + - compose.bikeshed.mash.start + - compose.bikeshed.image.complete + - compose.bikeshed.image.start + - compose.bikeshed.pungify.complete + - compose.bikeshed.pungify.start + - compose.bikeshed.rsync.complete + - compose.bikeshed.rsync.start + - compose.bikeshed.start + group: sysadmin-releng + owner: root + service: releng +freezes: true +gw: 10.3.169.254 +koji_hub_nfs: "fedora_koji" +kojihub_scheme: https +kojihub_url: koji.fedoraproject.org/kojihub +kojipkgs_url: kojipkgs.fedoraproject.org +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/35/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/compose-iot01.iad2.fedoraproject.org b/inventory/host_vars/compose-iot01.iad2.fedoraproject.org index 6d3e3b5741..209535c3fa 100644 --- a/inventory/host_vars/compose-iot01.iad2.fedoraproject.org +++ b/inventory/host_vars/compose-iot01.iad2.fedoraproject.org @@ -1,40 +1,32 @@ --- -volgroup: /dev/vg_guests -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Everything/x86_64/os/ -mem_size: 32768 - -vmhost: bvmhost-x86-03.iad2.fedoraproject.org -eth0_ip: 10.3.169.122 -gw: 10.3.169.254 -main_bridge: br0 - datacenter: iad2 - - -koji_hub_nfs: "fedora_koji" - -sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" - -virt_install_command: "{{ virt_install_command_one_nic }}" - +eth0_ip: 10.3.169.122 +fedmsg_certs: + - can_send: + # new school pungi-koji stuff (ask dgilmore) + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.createiso.imagefail + - pungi.compose.createiso.imagedone + - pungi.compose.ostree + - compose.29.complete + - compose.29.start + - compose.29.rsync.start + - compose.29.rsync.complete + group: sysadmin-releng + owner: root + service: releng # This VM is the compose host for IoT Edition which isn't blocking, so it doesn't freeze freezes: false - -fedmsg_certs: -- service: releng - owner: root - group: sysadmin-releng - can_send: - # new school pungi-koji stuff (ask dgilmore) - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.createiso.imagefail - - pungi.compose.createiso.imagedone - - pungi.compose.ostree - - compose.29.complete - - compose.29.start - - compose.29.rsync.start - - compose.29.rsync.complete +gw: 10.3.169.254 +koji_hub_nfs: "fedora_koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Everything/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +main_bridge: br0 +mem_size: 32768 +sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/compose-rawhide01.iad2.fedoraproject.org b/inventory/host_vars/compose-rawhide01.iad2.fedoraproject.org index 092ac94a32..753cd11789 100644 --- a/inventory/host_vars/compose-rawhide01.iad2.fedoraproject.org +++ b/inventory/host_vars/compose-rawhide01.iad2.fedoraproject.org @@ -1,53 +1,47 @@ -vmhost: bvmhost-x86-03.iad2.fedoraproject.org -gw: 10.3.169.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.169.123 -volgroup: /dev/vg_guests -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/35/Server/x86_64/os/ - -datacenter: iad2 - -koji_hub_nfs: "fedora_koji" - -kojipkgs_url: kojipkgs.fedoraproject.org -kojihub_url: koji.fedoraproject.org/kojihub -kojihub_scheme: https - +fedmsg_certs: + - can_send: + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.createiso.imagefail + - pungi.compose.createiso.imagedone + - pungi.compose.ostree + - compose.rawhide.complete + - compose.rawhide.mash.complete + - compose.rawhide.mash.start + - compose.rawhide.image.complete + - compose.rawhide.image.start + - compose.rawhide.pungify.complete + - compose.rawhide.pungify.start + - compose.rawhide.rsync.complete + - compose.rawhide.rsync.start + - compose.rawhide.start + - compose.bikeshed.complete + - compose.bikeshed.mash.complete + - compose.bikeshed.mash.start + - compose.bikeshed.image.complete + - compose.bikeshed.image.start + - compose.bikeshed.pungify.complete + - compose.bikeshed.pungify.start + - compose.bikeshed.rsync.complete + - compose.bikeshed.rsync.start + - compose.bikeshed.start + group: sysadmin-releng + owner: root + service: releng # rawhide is never frozen, the compose box should not be so we can make needed changes freezes: false - +gw: 10.3.169.254 +koji_hub_nfs: "fedora_koji" +kojihub_scheme: https +kojihub_url: koji.fedoraproject.org/kojihub +kojipkgs_url: kojipkgs.fedoraproject.org +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/35/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora virt_install_command: "{{ virt_install_command_one_nic }}" - -fedmsg_certs: -- service: releng - owner: root - group: sysadmin-releng - can_send: - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.createiso.imagefail - - pungi.compose.createiso.imagedone - - pungi.compose.ostree - - compose.rawhide.complete - - compose.rawhide.mash.complete - - compose.rawhide.mash.start - - compose.rawhide.image.complete - - compose.rawhide.image.start - - compose.rawhide.pungify.complete - - compose.rawhide.pungify.start - - compose.rawhide.rsync.complete - - compose.rawhide.rsync.start - - compose.rawhide.start - - compose.bikeshed.complete - - compose.bikeshed.mash.complete - - compose.bikeshed.mash.start - - compose.bikeshed.image.complete - - compose.bikeshed.image.start - - compose.bikeshed.pungify.complete - - compose.bikeshed.pungify.start - - compose.bikeshed.rsync.complete - - compose.bikeshed.rsync.start - - compose.bikeshed.start +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/compose-x86-01.iad2.fedoraproject.org b/inventory/host_vars/compose-x86-01.iad2.fedoraproject.org index 9a0782607e..eac4cfde80 100644 --- a/inventory/host_vars/compose-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/compose-x86-01.iad2.fedoraproject.org @@ -1,68 +1,59 @@ -nm: 255.255.255.0 -gw: 10.3.169.254 +datacenter: iad2 dns: 10.3.163.33 - +eth0_ip: 10.3.169.124 +fedmsg_certs: + - can_send: + # two-week-atomic stuff (ask maxamillion) + - releng.atomic.twoweek.begin + - releng.atomic.twoweek.complete + # new school pungi-koji stuff (ask dgilmore) + - pungi.compose.phase.start + - pungi.compose.phase.stop + - pungi.compose.status.change + - pungi.compose.createiso.targets + - pungi.compose.createiso.imagefail + - pungi.compose.createiso.imagedone + - pungi.compose.ostree + # traditional old school compose stuff + - compose.branched.complete + - compose.branched.mash.complete + - compose.branched.mash.start + - compose.branched.image.complete + - compose.branched.image.start + - compose.branched.pungify.complete + - compose.branched.pungify.start + - compose.branched.rsync.complete + - compose.branched.rsync.start + - compose.branched.start + - compose.epelbeta.complete + - compose.rawhide.complete + - compose.rawhide.mash.complete + - compose.rawhide.mash.start + - compose.rawhide.image.complete + - compose.rawhide.image.start + - compose.rawhide.pungify.complete + - compose.rawhide.pungify.start + - compose.rawhide.rsync.complete + - compose.rawhide.rsync.start + - compose.rawhide.start + - compose.29.start + - compose.29.complete + group: sysadmin-releng + owner: root + service: releng +gw: 10.3.169.254 +koji_hub_nfs: "fedora_koji" +kojihub_scheme: https +kojihub_url: koji.fedoraproject.org/kojihub +kojipkgs_url: kojipkgs.fedoraproject.org +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora # # These are 64bit # libdir: /usr/lib64 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - lvm_size: 30000 - -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.124 -vmhost: bvmhost-x86-04.iad2.fedoraproject.org -datacenter: iad2 - - -koji_hub_nfs: "fedora_koji" - -kojipkgs_url: kojipkgs.fedoraproject.org -kojihub_url: koji.fedoraproject.org/kojihub -kojihub_scheme: https - +nm: 255.255.255.0 virt_install_command: "{{ virt_install_command_one_nic }}" - -fedmsg_certs: -- service: releng - owner: root - group: sysadmin-releng - can_send: - # two-week-atomic stuff (ask maxamillion) - - releng.atomic.twoweek.begin - - releng.atomic.twoweek.complete - # new school pungi-koji stuff (ask dgilmore) - - pungi.compose.phase.start - - pungi.compose.phase.stop - - pungi.compose.status.change - - pungi.compose.createiso.targets - - pungi.compose.createiso.imagefail - - pungi.compose.createiso.imagedone - - pungi.compose.ostree - # traditional old school compose stuff - - compose.branched.complete - - compose.branched.mash.complete - - compose.branched.mash.start - - compose.branched.image.complete - - compose.branched.image.start - - compose.branched.pungify.complete - - compose.branched.pungify.start - - compose.branched.rsync.complete - - compose.branched.rsync.start - - compose.branched.start - - compose.epelbeta.complete - - compose.rawhide.complete - - compose.rawhide.mash.complete - - compose.rawhide.mash.start - - compose.rawhide.image.complete - - compose.rawhide.image.start - - compose.rawhide.pungify.complete - - compose.rawhide.pungify.start - - compose.rawhide.rsync.complete - - compose.rawhide.rsync.start - - compose.rawhide.start - - compose.29.start - - compose.29.complete +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/compose-x86-01.stg.iad2.fedoraproject.org b/inventory/host_vars/compose-x86-01.stg.iad2.fedoraproject.org index 12eac61944..9ec5bdf5a3 100644 --- a/inventory/host_vars/compose-x86-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/compose-x86-01.stg.iad2.fedoraproject.org @@ -1,26 +1,21 @@ -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-34-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.33 -vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org datacenter: staging - -koji_hub_nfs: "fedora_koji" - -kojipkgs_url: kojipkgs.fedoraproject.org -kojihub_url: koji.stg.fedoraproject.org/kojihub -kojihub_scheme: http - +dns: 10.3.163.33 +eth0_ip: 10.3.167.33 # These are consumed by a task in roles/fedmsg/base/main.yml fedmsg_certs: -- service: shell - owner: root - group: root -- service: bodhi - owner: root - group: root + - group: root + owner: root + service: shell + - group: root + owner: root + service: bodhi +gw: 10.3.167.254 +koji_hub_nfs: "fedora_koji" +kojihub_scheme: http +kojihub_url: koji.stg.fedoraproject.org/kojihub +kojipkgs_url: kojipkgs.fedoraproject.org +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-34-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/copr-be-dev-temp.aws.fedoraproject.org b/inventory/host_vars/copr-be-dev-temp.aws.fedoraproject.org index 0ea9c35331..bbb1f5e14b 100644 --- a/inventory/host_vars/copr-be-dev-temp.aws.fedoraproject.org +++ b/inventory/host_vars/copr-be-dev-temp.aws.fedoraproject.org @@ -1,11 +1,11 @@ --- nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false diff --git a/inventory/host_vars/copr-be-dev.aws.fedoraproject.org b/inventory/host_vars/copr-be-dev.aws.fedoraproject.org index 760ccfc9d0..156f2a5f38 100644 --- a/inventory/host_vars/copr-be-dev.aws.fedoraproject.org +++ b/inventory/host_vars/copr-be-dev.aws.fedoraproject.org @@ -1,16 +1,14 @@ -swap_file_size_mb: 8192 -swap_file_path: /swap - hostbase: copr-be-dev- -public_ip: 18.208.10.131 - nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +public_ip: 18.208.10.131 +swap_file_path: /swap +swap_file_size_mb: 8192 diff --git a/inventory/host_vars/copr-be-dev.cloud.fedoraproject.org b/inventory/host_vars/copr-be-dev.cloud.fedoraproject.org index 4c0aca416f..c6feb4cffa 100644 --- a/inventory/host_vars/copr-be-dev.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-be-dev.cloud.fedoraproject.org @@ -1,46 +1,41 @@ --- -instance_type: ms1.xlarge -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,fedmsg-relay-persistent -zone: nova -hostbase: copr-be-dev- -public_ip: 209.132.184.53 -root_auth_users: msuchy pingou frostyx praiskup schlupov -description: copr dispatcher and repo server - dev instance -tcp_ports: ['22', '80', '443', '2003', '4001'] -# volumes: copr-be-dev-data -volumes: [ {volume_id: '09c74876-d691-487e-a54b-070b08e87719', device: '/dev/vdc'} ] - -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-be-dev +_copr_be_conf: copr-be.conf-dev cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" # coprdev-net - net-id: "a440568f-b90a-46af-8ca6-d8fa743a7e7a" - +# Copr vars +copr_hostbase: copr-be-dev +description: copr dispatcher and repo server - dev instance +hostbase: copr-be-dev- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.xlarge +# name of machine in OpenStack +inventory_instance_name: copr-be-dev +inventory_tenant: persistent +keypair: fedora-admin-20130801 # consumed by roles/messaging/base messaging: certificates: - - key: copr - username: copr - app_name: Copr build system - -# Copr vars -copr_hostbase: copr-be-dev -_copr_be_conf: copr-be.conf-dev - + - app_name: Copr build system + key: copr + username: copr # There is no python2 on F30 - nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.53 +root_auth_users: msuchy pingou frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,fedmsg-relay-persistent +tcp_ports: ['22', '80', '443', '2003', '4001'] +# volumes: copr-be-dev-data +volumes: [{device: '/dev/vdc', volume_id: '09c74876-d691-487e-a54b-070b08e87719'}] +zone: nova diff --git a/inventory/host_vars/copr-be-stg.fedorainfracloud.org b/inventory/host_vars/copr-be-stg.fedorainfracloud.org index 7f6ccc3cb8..2ecdc0412b 100644 --- a/inventory/host_vars/copr-be-stg.fedorainfracloud.org +++ b/inventory/host_vars/copr-be-stg.fedorainfracloud.org @@ -1,37 +1,34 @@ --- -instance_type: m1.xlarge -image: "{{ fedora28_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,fedmsg-relay-persistent -zone: nova -hostbase: copr-be-stg- -public_ip: 209.132.184.44 -root_auth_users: msuchy pingou frostyx praiskup schlupov -description: copr dispatcher and repo server - stg instance -tcp_ports: ['22', '80', '443', '2003', '4001'] -# volumes: copr-be-stg-data -volumes: [ {volume_id: 'a3325e22-bdc0-4eeb-bb73-45365ddb7a01', device: '/dev/vdc'} ] - -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-be-stg +_copr_be_conf: copr-be.conf-stg cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" # coprdev-net - net-id: "a440568f-b90a-46af-8ca6-d8fa743a7e7a" - # Copr vars copr_hostbase: copr-be-stg -_copr_be_conf: copr-be.conf-stg - +description: copr dispatcher and repo server - stg instance +hostbase: copr-be-stg- +image: "{{ fedora28_x86_64 }}" +instance_type: m1.xlarge +# name of machine in OpenStack +inventory_instance_name: copr-be-stg +inventory_tenant: persistent +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.44 +root_auth_users: msuchy pingou frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,fedmsg-relay-persistent +tcp_ports: ['22', '80', '443', '2003', '4001'] +# volumes: copr-be-stg-data +volumes: [{device: '/dev/vdc', volume_id: 'a3325e22-bdc0-4eeb-bb73-45365ddb7a01'}] +zone: nova diff --git a/inventory/host_vars/copr-be.aws.fedoraproject.org b/inventory/host_vars/copr-be.aws.fedoraproject.org index 743ed01379..5c51ebcb5f 100644 --- a/inventory/host_vars/copr-be.aws.fedoraproject.org +++ b/inventory/host_vars/copr-be.aws.fedoraproject.org @@ -1,16 +1,14 @@ -swap_file_size_mb: 16384 -swap_file_path: /swap - hostbase: copr-be- -public_ip: 52.44.175.77 - nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +public_ip: 52.44.175.77 +swap_file_path: /swap +swap_file_size_mb: 16384 diff --git a/inventory/host_vars/copr-be.cloud.fedoraproject.org b/inventory/host_vars/copr-be.cloud.fedoraproject.org index 949956466d..6331a24a08 100644 --- a/inventory/host_vars/copr-be.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-be.cloud.fedoraproject.org @@ -1,48 +1,43 @@ --- - -instance_type: ms1.xlarge -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent -zone: nova -hostbase: copr-be- -public_ip: 209.132.184.48 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr dispatcher and repo server -volumes: [ {volume_id: '63c3a40c-e228-417a-97a2-e2c34730bf3b', device: '/dev/vdc'} ] -inventory_tenant: persistent -inventory_instance_name: copr-be +_copr_be_conf: copr-be.conf cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" # copr-net - net-id: "24699649-0e05-4fd3-98a3-86a75ec49f6e" - -tcp_ports: [ 22, 80, 443, -# These 8 ports are used by fedmsg. One for each wsgi thread. - 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] - +# Copr vars +copr_hostbase: copr-be +description: copr dispatcher and repo server +host_backup_targets: ['/var/lib/copr/public_html/results'] +hostbase: copr-be- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.xlarge +inventory_instance_name: copr-be +inventory_tenant: persistent +keypair: fedora-admin-20130801 # consumed by roles/messaging/base messaging: certificates: - - key: copr - username: copr - app_name: Copr build system - -# Copr vars -copr_hostbase: copr-be - -host_backup_targets: ['/var/lib/copr/public_html/results'] -_copr_be_conf: copr-be.conf - + - app_name: Copr build system + key: copr + username: copr nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false # There is no python2 on F30 + +public_ip: 209.132.184.48 +root_auth_users: msuchy frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent +tcp_ports: [22, 80, 443, + # These 8 ports are used by fedmsg. One for each wsgi thread. + 3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007] +volumes: [{device: '/dev/vdc', volume_id: '63c3a40c-e228-417a-97a2-e2c34730bf3b'}] +zone: nova diff --git a/inventory/host_vars/copr-db-stg.aws.fedoraproject.org b/inventory/host_vars/copr-db-stg.aws.fedoraproject.org index 2ce3653852..7b87a398fb 100644 --- a/inventory/host_vars/copr-db-stg.aws.fedoraproject.org +++ b/inventory/host_vars/copr-db-stg.aws.fedoraproject.org @@ -1,49 +1,40 @@ --- -ansible_user: ec2-user -ansible_become_user: root ansible_become: yes - -datacenter: aws -inventory_hostname: "copr-db-stg.aws.fedoraproject.org" -inventory_instance_name: copr-db-stg - -nm_controlled_resolv: True +ansible_become_user: root ansible_ifcfg_blocklist: True - -swap_file_size_mb: 4096 -swap_file_path: /swap - -hostbase: copr-db-stg- -public_ip: 52.200.82.86 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr database - staging instance - +ansible_user: ec2-user # Copr vars copr_hostbase: copr-db-stg - -nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false - dhcpd: false - httpd: false - swap: false - ping: false - raid: false - # This is a generic list, monitored by collectd databases: -- coprdb - -# This is a more strict list of databases to backup every day -dbs_to_backup: -- coprdb - - + - coprdb +datacenter: aws db_backup_dir: ['/backups'] # Should be 0.25 of memory #shared_buffers: "16GB" # Should be 0.80 of memory #effective_cache_size: "50GB" #max_stack_depth: "6MB" + +# This is a more strict list of databases to backup every day +dbs_to_backup: + - coprdb +description: copr database - staging instance +hostbase: copr-db-stg- +inventory_hostname: "copr-db-stg.aws.fedoraproject.org" +inventory_instance_name: copr-db-stg +nagios_Check_Services: + dhcpd: false + httpd: false + mail: false + named: false + nrpe: false + ping: false + raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_ip: 52.200.82.86 +root_auth_users: msuchy frostyx praiskup schlupov +swap_file_path: /swap +swap_file_size_mb: 4096 diff --git a/inventory/host_vars/copr-dist-git-dev.aws.fedoraproject.org b/inventory/host_vars/copr-dist-git-dev.aws.fedoraproject.org index 611bfc854d..8d49f85c27 100644 --- a/inventory/host_vars/copr-dist-git-dev.aws.fedoraproject.org +++ b/inventory/host_vars/copr-dist-git-dev.aws.fedoraproject.org @@ -1,35 +1,30 @@ --- -ansible_ssh_user: fedora -ansible_become_user: root ansible_become: yes -datacenter: aws -inventory_hostname: "copr-dist-git-dev.aws.fedoraproject.org" -inventory_instance_name: copr-dist-git-dev -nm_controlled_resolv: True +ansible_become_user: root ansible_ifcfg_blocklist: True - -swap_file_size_mb: 2048 -swap_file_path: /swap - +ansible_ssh_user: fedora +# Copr vars +copr_hostbase: copr-dist-git-dev +datacenter: aws +description: copr dist git - dev instance #instance_type: t3a.medium #image: "{{ fedora31_x86_64 }}" #keypair: fedora-admin-20130801 hostbase: copr-dist-git-dev- -public_ip: 54.243.51.13 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr dist git - dev instance - - -# Copr vars -copr_hostbase: copr-dist-git-dev - +inventory_hostname: "copr-dist-git-dev.aws.fedoraproject.org" +inventory_instance_name: copr-dist-git-dev nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_ip: 54.243.51.13 +root_auth_users: msuchy frostyx praiskup schlupov +swap_file_path: /swap +swap_file_size_mb: 2048 diff --git a/inventory/host_vars/copr-dist-git-dev.fedorainfracloud.org b/inventory/host_vars/copr-dist-git-dev.fedorainfracloud.org index b8788afa31..e04a552ccb 100644 --- a/inventory/host_vars/copr-dist-git-dev.fedorainfracloud.org +++ b/inventory/host_vars/copr-dist-git-dev.fedorainfracloud.org @@ -1,34 +1,32 @@ --- -instance_type: ms1.small -image: "{{ fedora30_x86_64 }}" -#image: rhel7-20141015 -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-dist-git-dev- -public_ip: 209.132.184.179 -root_auth_users: ryanlerch pingou msuchy frostyx praiskup schlupov -description: dist-git for copr service - dev instance -tcp_ports: [22, 80, 443] -# volumes: copr-dist-git-dev -volumes: [ {volume_id: '64f21445-d758-4b19-8401-e497cd0ae012', device: '/dev/vdc'} ] -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-dist-git-dev cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-dist-git-dev - +description: dist-git for copr service - dev instance +hostbase: copr-dist-git-dev- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.small +# name of machine in OpenStack +inventory_instance_name: copr-dist-git-dev +inventory_tenant: persistent +#image: rhel7-20141015 +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.179 +root_auth_users: ryanlerch pingou msuchy frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +tcp_ports: [22, 80, 443] +# volumes: copr-dist-git-dev +volumes: [{device: '/dev/vdc', volume_id: '64f21445-d758-4b19-8401-e497cd0ae012'}] +zone: nova diff --git a/inventory/host_vars/copr-dist-git-stg.fedorainfracloud.org b/inventory/host_vars/copr-dist-git-stg.fedorainfracloud.org index 87bae490ca..a56dc6301c 100644 --- a/inventory/host_vars/copr-dist-git-stg.fedorainfracloud.org +++ b/inventory/host_vars/copr-dist-git-stg.fedorainfracloud.org @@ -1,33 +1,31 @@ --- -instance_type: ms1.small -image: "{{ fedora28_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-dist-git-stg- -public_ip: 209.132.184.57 -root_auth_users: ryanlerch pingou msuchy frostyx frostyx praiskup schlupov -description: dist-git for copr service - stg instance -tcp_ports: [22, 80, 443] -# volumes: copr-dist-git-stg -volumes: [ {volume_id: '0cb506b9-3931-47fa-b6d3-a0ad2614f221', device: '/dev/vdc'} ] -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-dist-git-stg cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-dist-git-stg - +description: dist-git for copr service - stg instance +hostbase: copr-dist-git-stg- +image: "{{ fedora28_x86_64 }}" +instance_type: ms1.small +# name of machine in OpenStack +inventory_instance_name: copr-dist-git-stg +inventory_tenant: persistent +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.57 +root_auth_users: ryanlerch pingou msuchy frostyx frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +tcp_ports: [22, 80, 443] +# volumes: copr-dist-git-stg +volumes: [{device: '/dev/vdc', volume_id: '0cb506b9-3931-47fa-b6d3-a0ad2614f221'}] +zone: nova diff --git a/inventory/host_vars/copr-dist-git.aws.fedoraproject.org b/inventory/host_vars/copr-dist-git.aws.fedoraproject.org index e2d5e87c36..a8866dc96a 100644 --- a/inventory/host_vars/copr-dist-git.aws.fedoraproject.org +++ b/inventory/host_vars/copr-dist-git.aws.fedoraproject.org @@ -1,13 +1,12 @@ --- -ansible_ssh_user: fedora -ansible_become_user: root ansible_become: yes -datacenter: aws -inventory_hostname: "copr-dist-git.aws.fedoraproject.org" -inventory_instance_name: copr-dist-git -nm_controlled_resolv: True +ansible_become_user: root ansible_ifcfg_blocklist: True - +ansible_ssh_user: fedora +# Copr vars +copr_hostbase: copr-dist-git +datacenter: aws +description: copr dist git - prod instance #swap_file_size_mb: 2048 #swap_file_path: /swap @@ -15,21 +14,18 @@ ansible_ifcfg_blocklist: True #image: "{{ fedora31_x86_64 }}" #keypair: fedora-admin-20130801 hostbase: copr-dist-git -public_ip: 3.89.184.181 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr dist git - prod instance - - -# Copr vars -copr_hostbase: copr-dist-git - +inventory_hostname: "copr-dist-git.aws.fedoraproject.org" +inventory_instance_name: copr-dist-git nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_ip: 3.89.184.181 +root_auth_users: msuchy frostyx praiskup schlupov diff --git a/inventory/host_vars/copr-dist-git.fedorainfracloud.org b/inventory/host_vars/copr-dist-git.fedorainfracloud.org index f9964a9409..db35eb0e0c 100644 --- a/inventory/host_vars/copr-dist-git.fedorainfracloud.org +++ b/inventory/host_vars/copr-dist-git.fedorainfracloud.org @@ -1,36 +1,34 @@ --- -instance_type: ms1.medium.bigswap -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-dist-git -public_ip: 209.132.184.163 -root_auth_users: msuchy frostyx praiskup schlupov -description: dist-git for copr service - prod instance -tcp_ports: [22, 80, 443] -# volumes: copr-dist-git, copr-dist-git-log -volumes: [ {volume_id: '0ee0735e-0ce5-4e4e-8f52-bc62bf4a0968', device: '/dev/vdc'}, {volume_id: 'e712828f-998f-49aa-85a6-aeb42a7d1843', device: '/dev/vdd'} ] -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-dist-git cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-dist-git - +description: dist-git for copr service - prod instance host_backup_targets: ['/var/lib/dist-git/git', '/var/lib/dist-git/cache'] - +hostbase: copr-dist-git +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.medium.bigswap +# name of machine in OpenStack +inventory_instance_name: copr-dist-git +inventory_tenant: persistent +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false # There is no python2 on F30 + +public_ip: 209.132.184.163 +root_auth_users: msuchy frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +tcp_ports: [22, 80, 443] +# volumes: copr-dist-git, copr-dist-git-log +volumes: [{device: '/dev/vdc', volume_id: '0ee0735e-0ce5-4e4e-8f52-bc62bf4a0968'}, {device: '/dev/vdd', volume_id: 'e712828f-998f-49aa-85a6-aeb42a7d1843'}] +zone: nova diff --git a/inventory/host_vars/copr-fe-dev.aws.fedoraproject.org b/inventory/host_vars/copr-fe-dev.aws.fedoraproject.org index effe613c93..95fc84badb 100644 --- a/inventory/host_vars/copr-fe-dev.aws.fedoraproject.org +++ b/inventory/host_vars/copr-fe-dev.aws.fedoraproject.org @@ -1,30 +1,25 @@ --- -datacenter: aws -inventory_hostname: "copr-fe-dev.aws.fedoraproject.org" -inventory_instance_name: copr-fe-dev -principal_alias: "HTTP/copr-fe-dev.cloud.fedoraproject.org@STG.FEDORAPROJECT.ORG" - -nm_controlled_resolv: True ansible_ifcfg_blocklist: True - -swap_file_size_mb: 4096 -swap_file_path: /swap - -hostbase: copr-fe-dev- -public_ip: 18.208.24.211 -root_auth_users: msuchy frostyx praiskup schlupov ttomecek -description: copr frontend - dev instance - # Copr vars copr_hostbase: copr-fe-dev - +datacenter: aws +description: copr frontend - dev instance +hostbase: copr-fe-dev- +inventory_hostname: "copr-fe-dev.aws.fedoraproject.org" +inventory_instance_name: copr-fe-dev nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +nm_controlled_resolv: True +principal_alias: "HTTP/copr-fe-dev.cloud.fedoraproject.org@STG.FEDORAPROJECT.ORG" +public_ip: 18.208.24.211 +root_auth_users: msuchy frostyx praiskup schlupov ttomecek +swap_file_path: /swap +swap_file_size_mb: 4096 diff --git a/inventory/host_vars/copr-fe-dev.cloud.fedoraproject.org b/inventory/host_vars/copr-fe-dev.cloud.fedoraproject.org index f3f763a029..2a589fa756 100644 --- a/inventory/host_vars/copr-fe-dev.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-fe-dev.cloud.fedoraproject.org @@ -1,35 +1,32 @@ --- -instance_type: m1.medium -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-fe-dev- -public_ip: 209.132.184.55 -root_auth_users: ryanlerch pingou msuchy frostyx praiskup schlupov -description: copr frontend server - dev instance -tcp_ports: [22, 80, 443] -# volumes: copr-fe-dev-db -volumes: [ {volume_id: 'c0f338f4-b59e-4b58-8f86-47011eaa0fab', device: '/dev/vdc'} ] -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-fe-dev cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-fe-dev - +description: copr frontend server - dev instance +hostbase: copr-fe-dev- +image: "{{ fedora30_x86_64 }}" +instance_type: m1.medium +# name of machine in OpenStack +inventory_instance_name: copr-fe-dev +inventory_tenant: persistent +keypair: fedora-admin-20130801 # There is no python2 on F30 - nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.55 +root_auth_users: ryanlerch pingou msuchy frostyx praiskup schlupov +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +tcp_ports: [22, 80, 443] +# volumes: copr-fe-dev-db +volumes: [{device: '/dev/vdc', volume_id: 'c0f338f4-b59e-4b58-8f86-47011eaa0fab'}] +zone: nova diff --git a/inventory/host_vars/copr-fe.aws.fedoraproject.org b/inventory/host_vars/copr-fe.aws.fedoraproject.org index 271967a59c..fa543ab46c 100644 --- a/inventory/host_vars/copr-fe.aws.fedoraproject.org +++ b/inventory/host_vars/copr-fe.aws.fedoraproject.org @@ -1,43 +1,34 @@ --- -datacenter: aws -inventory_hostname: "copr-fe.aws.fedoraproject.org" -inventory_instance_name: copr-fe - -nm_controlled_resolv: True ansible_ifcfg_blocklist: True - -swap_file_size_mb: 8192 -swap_file_path: /swap - -hostbase: copr-fe- -public_ip: 3.225.109.36 -root_auth_users: msuchy frostyx praiskup schlupov ttomecek -description: copr frontend server - prod instance - -# Copr vars -copr_hostbase: copr-fe - -# dbs to be backed up on this host -dbs_to_backup: -- coprdb - -db_backup_dir: ['/backups'] - -nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false - dhcpd: false - httpd: false - swap: false - ping: false - raid: false - # this overrides vars/Fedora.yml base_pkgs_erase: ['PackageKit*', 'sendmail', 'at'] - +# Copr vars +copr_hostbase: copr-fe +datacenter: aws +db_backup_dir: ['/backups'] +# dbs to be backed up on this host +dbs_to_backup: + - coprdb +description: copr frontend server - prod instance +hostbase: copr-fe- +inventory_hostname: "copr-fe.aws.fedoraproject.org" +inventory_instance_name: copr-fe +nagios_Check_Services: + dhcpd: false + httpd: false + mail: false + named: false + nrpe: true + ping: false + raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_ip: 3.225.109.36 +root_auth_users: msuchy frostyx praiskup schlupov ttomecek +sar_output_file: copr.json # GDPR SAR variables sar_script: /usr/share/copr/coprs_frontend/run/copr-gdpr-sar.sh sar_script_user: copr-fe -sar_output_file: copr.json +swap_file_path: /swap +swap_file_size_mb: 8192 diff --git a/inventory/host_vars/copr-fe.cloud.fedoraproject.org b/inventory/host_vars/copr-fe.cloud.fedoraproject.org index 643dcfb2ad..4b43933632 100644 --- a/inventory/host_vars/copr-fe.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-fe.cloud.fedoraproject.org @@ -1,47 +1,41 @@ --- # this overrides vars/Fedora.yml base_pkgs_erase: ['PackageKit*', 'sendmail', 'at'] - -instance_type: ms1.large -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent -zone: nova -hostbase: copr-fe- -public_ip: 209.132.184.54 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr frontend server - prod instance -tcp_ports: [22, 80, 443] -volumes: [ {volume_id: '8f790db7-8294-4d2b-8bae-7af5961ce0f8', device: '/dev/vdc'} ] -inventory_tenant: persistent -inventory_instance_name: copr-fe cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars - copr_hostbase: copr-fe - +db_backup_dir: ['/backups'] # dbs to be backed up on this host dbs_to_backup: -- coprdb - -db_backup_dir: ['/backups'] + - coprdb +description: copr frontend server - prod instance +hostbase: copr-fe- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.large +inventory_instance_name: copr-fe +inventory_tenant: persistent +keypair: fedora-admin-20130801 +nagios_Check_Services: + dhcpd: false + httpd: false + mail: false + named: false + nrpe: false + ping: false + raid: false + sshd: false + swap: false +# There is no python2 on F30 +public_ip: 209.132.184.54 +root_auth_users: msuchy frostyx praiskup schlupov +sar_output_file: copr.json # GDPR SAR variables sar_script: /usr/share/copr/coprs_frontend/run/copr-gdpr-sar.sh sar_script_user: copr-fe -sar_output_file: copr.json - -nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false - dhcpd: false - httpd: false - swap: false - ping: false - raid: false -# There is no python2 on F30 +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent +tcp_ports: [22, 80, 443] +volumes: [{device: '/dev/vdc', volume_id: '8f790db7-8294-4d2b-8bae-7af5961ce0f8'}] +zone: nova diff --git a/inventory/host_vars/copr-keygen-dev.aws.fedoraproject.org b/inventory/host_vars/copr-keygen-dev.aws.fedoraproject.org index b15b2b9dda..ca323e4aff 100644 --- a/inventory/host_vars/copr-keygen-dev.aws.fedoraproject.org +++ b/inventory/host_vars/copr-keygen-dev.aws.fedoraproject.org @@ -1,29 +1,27 @@ --- -ansible_ssh_user: fedora -ansible_become_user: root ansible_become: yes -datacenter: aws -inventory_hostname: "copr-keygen-dev.aws.fedoraproject.org" -inventory_instance_name: copr-keygen-dev -nm_controlled_resolv: True +ansible_become_user: root ansible_ifcfg_blocklist: True - +ansible_ssh_user: fedora +datacenter: aws +#volumes: [ {volume_id: '9e2b4c55-9ec3-4508-af46-a40f3a5bd982', device: '/dev/vdc'} ] +description: copr key gen and sign host - dev instance #instance_type: t3a.small #image: "{{ fedora31_x86_64 }}" #keypair: fedora-admin-20130801 hostbase: copr-keygen-dev- -public_ip: 54.225.23.248 -root_auth_users: msuchy frostyx praiskup schlupov -#volumes: [ {volume_id: '9e2b4c55-9ec3-4508-af46-a40f3a5bd982', device: '/dev/vdc'} ] -description: copr key gen and sign host - dev instance - +inventory_hostname: "copr-keygen-dev.aws.fedoraproject.org" +inventory_instance_name: copr-keygen-dev nagios_Check_Services: - mail: false - nrpe: true - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_ip: 54.225.23.248 +root_auth_users: msuchy frostyx praiskup schlupov diff --git a/inventory/host_vars/copr-keygen-dev.cloud.fedoraproject.org b/inventory/host_vars/copr-keygen-dev.cloud.fedoraproject.org index 5c524fe1d9..f461df18ae 100644 --- a/inventory/host_vars/copr-keygen-dev.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-keygen-dev.cloud.fedoraproject.org @@ -1,35 +1,31 @@ --- -instance_type: ms1.small -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -# todo: remove some security groups ? -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-keygen-dev- -public_ip: 209.132.184.46 -root_auth_users: msuchy frostyx praiskup schlupov -volumes: [ {volume_id: '9e2b4c55-9ec3-4508-af46-a40f3a5bd982', device: '/dev/vdc'} ] -description: copr key gen and sign host - dev instance - -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-keygen-dev cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-keygen-dev - +description: copr key gen and sign host - dev instance +hostbase: copr-keygen-dev- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.small +# name of machine in OpenStack +inventory_instance_name: copr-keygen-dev +inventory_tenant: persistent +keypair: fedora-admin-20130801 # There is no python2 on F30 - nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.46 +root_auth_users: msuchy frostyx praiskup schlupov +# todo: remove some security groups ? +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +volumes: [{device: '/dev/vdc', volume_id: '9e2b4c55-9ec3-4508-af46-a40f3a5bd982'}] +zone: nova diff --git a/inventory/host_vars/copr-keygen-stg.fedorainfracloud.org b/inventory/host_vars/copr-keygen-stg.fedorainfracloud.org index c334bb1d4e..1a99983f38 100644 --- a/inventory/host_vars/copr-keygen-stg.fedorainfracloud.org +++ b/inventory/host_vars/copr-keygen-stg.fedorainfracloud.org @@ -1,33 +1,30 @@ --- -instance_type: ms1.small -image: "{{ fedora28_x86_64 }}" -keypair: fedora-admin-20130801 -# todo: remove some security groups ? -security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent -zone: nova -hostbase: copr-keygen-stg- -public_ip: 209.132.184.56 -root_auth_users: msuchy frostyx praiskup schlupov -volumes: [ {volume_id: '5424ff3c-b1c6-4291-a0ed-2d30924f4f88', device: '/dev/vdc'} ] -description: copr keygen and sign host - stg instance - -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-keygen-stg cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - # Copr vars copr_hostbase: copr-keygen-stg - +description: copr keygen and sign host - stg instance +hostbase: copr-keygen-stg- +image: "{{ fedora28_x86_64 }}" +instance_type: ms1.small +# name of machine in OpenStack +inventory_instance_name: copr-keygen-stg +inventory_tenant: persistent +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +public_ip: 209.132.184.56 +root_auth_users: msuchy frostyx praiskup schlupov +# todo: remove some security groups ? +security_group: web-80-anywhere-persistent,web-443-anywhere-persistent,ssh-anywhere-persistent,default,all-icmp-persistent +volumes: [{device: '/dev/vdc', volume_id: '5424ff3c-b1c6-4291-a0ed-2d30924f4f88'}] +zone: nova diff --git a/inventory/host_vars/copr-keygen.aws.fedoraproject.org b/inventory/host_vars/copr-keygen.aws.fedoraproject.org index e092a83056..707ac5440e 100644 --- a/inventory/host_vars/copr-keygen.aws.fedoraproject.org +++ b/inventory/host_vars/copr-keygen.aws.fedoraproject.org @@ -1,29 +1,27 @@ --- -ansible_ssh_user: fedora -ansible_become_user: root ansible_become: yes -datacenter: aws -inventory_hostname: "copr-keygen.aws.fedoraproject.org" -inventory_instance_name: copr-keygen -nm_controlled_resolv: True +ansible_become_user: root ansible_ifcfg_blocklist: True +ansible_ssh_user: fedora +datacenter: aws db_backup_dir: ['/backup'] - +description: copr key gen and sign host - prod instance #instance_type: t3a.small #image: "{{ fedora31_x86_64 }}" #keypair: fedora-admin-20130801 hostbase: copr-keygen-dev- -public_ip: 54.83.48.73 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr key gen and sign host - prod instance - +inventory_hostname: "copr-keygen.aws.fedoraproject.org" +inventory_instance_name: copr-keygen nagios_Check_Services: - mail: false - nrpe: true - sshd: true - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: true ping: false raid: false + sshd: true + swap: false +nm_controlled_resolv: True +public_ip: 54.83.48.73 +root_auth_users: msuchy frostyx praiskup schlupov diff --git a/inventory/host_vars/copr-keygen.cloud.fedoraproject.org b/inventory/host_vars/copr-keygen.cloud.fedoraproject.org index 9eb05d9268..986fa6965e 100644 --- a/inventory/host_vars/copr-keygen.cloud.fedoraproject.org +++ b/inventory/host_vars/copr-keygen.cloud.fedoraproject.org @@ -1,39 +1,32 @@ --- -instance_type: ms1.small -image: "{{ fedora30_x86_64 }}" -keypair: fedora-admin-20130801 -zone: nova -hostbase: copr-keygen- -public_ip: 209.132.184.49 -root_auth_users: msuchy frostyx praiskup schlupov -description: copr key gen instance -volumes: [ {volume_id: '761175dc-daaf-48c0-be09-5799990f97a7', device: '/dev/vdc'} ] -# security_group: default -security_group: web-80-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,keygen-persistent - -inventory_tenant: persistent -# name of machine in OpenStack -inventory_instance_name: copr-keygen cloud_networks: # persistent-net - net-id: "67b77354-39a4-43de-b007-bb813ac5c35f" - - -host_backup_targets: ['/backup/'] -datacenter: cloud - # Copr vars copr_hostbase: copr-keygen - +datacenter: cloud +description: copr key gen instance +host_backup_targets: ['/backup/'] +hostbase: copr-keygen- +image: "{{ fedora30_x86_64 }}" +instance_type: ms1.small +# name of machine in OpenStack +inventory_instance_name: copr-keygen +inventory_tenant: persistent +keypair: fedora-admin-20130801 nagios_Check_Services: - mail: false - nrpe: false - sshd: true - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false - -# There is no python2 on F30 + sshd: true + swap: false +public_ip: 209.132.184.49 +root_auth_users: msuchy frostyx praiskup schlupov +# security_group: default +security_group: web-80-anywhere-persistent,ssh-anywhere-persistent,default,allow-nagios-persistent,keygen-persistent +volumes: [{device: '/dev/vdc', volume_id: '761175dc-daaf-48c0-be09-5799990f97a7'}] +zone: nova diff --git a/inventory/host_vars/datagrepper01.iad2.fedoraproject.org b/inventory/host_vars/datagrepper01.iad2.fedoraproject.org index 78a452378c..0e77839018 100644 --- a/inventory/host_vars/datagrepper01.iad2.fedoraproject.org +++ b/inventory/host_vars/datagrepper01.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - +dns: 10.3.163.33 eth0_ip: 10.3.163.48 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/datagrepper01.stg.iad2.fedoraproject.org b/inventory/host_vars/datagrepper01.stg.iad2.fedoraproject.org index cf45cee0df..d5ef4dffff 100644 --- a/inventory/host_vars/datagrepper01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/datagrepper01.stg.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - +dns: 10.3.163.33 eth0_ip: 10.3.166.60 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/datagrepper02.iad2.fedoraproject.org b/inventory/host_vars/datagrepper02.iad2.fedoraproject.org index 0e6e54df7a..b9ae47caf9 100644 --- a/inventory/host_vars/datagrepper02.iad2.fedoraproject.org +++ b/inventory/host_vars/datagrepper02.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - +dns: 10.3.163.33 eth0_ip: 10.3.163.103 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-datanommer01.iad2.fedoraproject.org b/inventory/host_vars/db-datanommer01.iad2.fedoraproject.org index 3996c36a27..b6bd8752fe 100644 --- a/inventory/host_vars/db-datanommer01.iad2.fedoraproject.org +++ b/inventory/host_vars/db-datanommer01.iad2.fedoraproject.org @@ -1,40 +1,33 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.43 -vmhost: vmhost-x86-07.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- datanommer - + - datanommer +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- datanommer - + - datanommer +dns: 10.3.163.33 +effective_cache_size: "12GB" +eth0_ip: 10.3.163.43 +gw: 10.3.163.254 +# kernel SHMMAX value +kernel_shmmax: 68719476736 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 # These are normally group variables, but in this case db servers are often different lvm_size: 1000000 mem_size: 65536 +nagios_Check_Services: + swap: false +nm: 255.255.255.0 num_cpus: 8 -tcp_ports: [ 5432, 443 ] - -# kernel SHMMAX value -kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] -shared_buffers: "4GB" -effective_cache_size: "12GB" - +sar_huge: true +sar_output_file: datagrepper.csv # GDPR SAR variables - datanommer/datagrepper sar_script: /usr/local/bin/datagrepper_sar.py sar_script_user: root -sar_output_file: datagrepper.csv -sar_huge: true - -nagios_Check_Services: - swap: false +shared_buffers: "4GB" +tcp_ports: [5432, 443] +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-datanommer01.stg.iad2.fedoraproject.org b/inventory/host_vars/db-datanommer01.stg.iad2.fedoraproject.org index 7498cfce52..dfdc80b311 100644 --- a/inventory/host_vars/db-datanommer01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/db-datanommer01.stg.iad2.fedoraproject.org @@ -1,38 +1,32 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.59 -vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- datanommer - + - datanommer +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- datanommer - -# These are normally group variables, but in this case db servers are often different -lvm_size: 1000000 -mem_size: 65536 -max_mem_size: 98304 -num_cpus: 8 -tcp_ports: [ 5432, 443 ] - + - datanommer +dns: 10.3.163.33 +effective_cache_size: "12GB" +eth0_ip: 10.3.166.59 +gw: 10.3.166.254 # kernel SHMMAX value kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] -shared_buffers: "4GB" -effective_cache_size: "12GB" - +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 1000000 +max_mem_size: 98304 +mem_size: 65536 +nm: 255.255.255.0 +num_cpus: 8 +sar_huge: true +sar_output_file: datagrepper.csv # GDPR SAR variables - datanommer/datagrepper sar_script: /usr/local/bin/datagrepper_sar.py sar_script_user: root -sar_output_file: datagrepper.csv -sar_huge: true +shared_buffers: "4GB" +tcp_ports: [5432, 443] +vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-datanommer02.iad2.fedoraproject.org b/inventory/host_vars/db-datanommer02.iad2.fedoraproject.org index 91d1de8eed..4a7a3f356e 100644 --- a/inventory/host_vars/db-datanommer02.iad2.fedoraproject.org +++ b/inventory/host_vars/db-datanommer02.iad2.fedoraproject.org @@ -1,43 +1,36 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.111 -vmhost: vmhost-x86-07.iad2.fedoraproject.org -datacenter: iad2 -eth0_ipv4: "{{eth0_ip}}" -eth0_ipv4_nm: "{{nm}}" -eth0_ipv4_gw: "{{gw}}" - # This is a generic list, monitored by collectd databases: -- datanommer - + - datanommer +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- datanommer - + - datanommer +dns: 10.3.163.33 +effective_cache_size: "12GB" +eth0_ip: 10.3.163.111 +eth0_ipv4: "{{eth0_ip}}" +eth0_ipv4_gw: "{{gw}}" +eth0_ipv4_nm: "{{nm}}" +gw: 10.3.163.254 +# kernel SHMMAX value +kernel_shmmax: 68719476736 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 # These are normally group variables, but in this case db servers are often different lvm_size: 1500g mem_size: 65536 +nagios_Check_Services: + swap: false +nm: 255.255.255.0 num_cpus: 8 -tcp_ports: [ 5432, 443 ] - -# kernel SHMMAX value -kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] -shared_buffers: "4GB" -effective_cache_size: "12GB" - +sar_huge: true +sar_output_file: datagrepper.csv # GDPR SAR variables - datanommer/datagrepper sar_script: /usr/local/bin/datagrepper_sar.py sar_script_user: root -sar_output_file: datagrepper.csv -sar_huge: true - -nagios_Check_Services: - swap: false +shared_buffers: "4GB" +tcp_ports: [5432, 443] +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-fas01.iad2.fedoraproject.org b/inventory/host_vars/db-fas01.iad2.fedoraproject.org index 3268f594fc..758a5941ef 100644 --- a/inventory/host_vars/db-fas01.iad2.fedoraproject.org +++ b/inventory/host_vars/db-fas01.iad2.fedoraproject.org @@ -1,52 +1,40 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.42 -vmhost: vmhost-x86-01.iad2.fedoraproject.org -datacenter: iad2 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -# This is a generic list, monitored by collectd -databases: -- fas2 - -# This is a more strict list, to be made publicly available -dbs_to_backup: -- fas2 - -# These are normally group variables, but in this case db servers are often different -lvm_size: 100000 -mem_size: 16384 -num_cpus: 8 - # # Only allow postgresql access from the frontend nodes and hosted. # custom_rules: [ - # Openshift nodes (egress policy will block connection from non-authorized projects) - '-A INPUT -p tcp -m tcp -s 10.3.163.69 --dport 5432 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.70 --dport 5432 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.71 --dport 5432 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.72 --dport 5432 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.73 --dport 5432 -j ACCEPT', - # noc01 needs to connect to check the db - '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5432 -j ACCEPT', - # Ipsilon VMs - '-A INPUT -p tcp -m tcp -s 10.3.163.105 --dport 5432 -j ACCEPT', - '-A INPUT -p tcp -m tcp -s 10.3.163.106 --dport 5432 -j ACCEPT', -] + # Openshift nodes (egress policy will block connection from non-authorized projects) + '-A INPUT -p tcp -m tcp -s 10.3.163.69 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.70 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.71 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.72 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.73 --dport 5432 -j ACCEPT', + # noc01 needs to connect to check the db + '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5432 -j ACCEPT', + # Ipsilon VMs + '-A INPUT -p tcp -m tcp -s 10.3.163.105 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.106 --dport 5432 -j ACCEPT'] +# This is a generic list, monitored by collectd +databases: + - fas2 +datacenter: iad2 +db_backup_dir: ['/backups'] +# This is a more strict list, to be made publicly available +dbs_to_backup: + - fas2 +dns: 10.3.163.33 +effective_cache_size: "6GB" +eth0_ip: 10.3.163.42 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext +# These are normally group variables, but in this case db servers are often different +lvm_size: 100000 +max_stack_depth: "4MB" +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 800 # # Large updates pushes cause lots of db threads doing the tag moves, so up this from default. # nrpe_procs_warn: 600 -nrpe_procs_crit: 800 - -db_backup_dir: ['/backups'] +num_cpus: 8 shared_buffers: "2GB" -effective_cache_size: "6GB" temp_buffers: "8MB" -max_stack_depth: "4MB" +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-fas01.stg.iad2.fedoraproject.org b/inventory/host_vars/db-fas01.stg.iad2.fedoraproject.org index aea46b5621..9bb4eeb44f 100644 --- a/inventory/host_vars/db-fas01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/db-fas01.stg.iad2.fedoraproject.org @@ -1,49 +1,42 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.34 -vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org -datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -# This is a generic list, monitored by collectd -databases: -- fas2 - -# This is a more strict list, to be made publicly available -dbs_to_backup: -- fas2 - -# These are normally group variables, but in this case db servers are often different -lvm_size: 30000 -mem_size: 4096 -num_cpus: 2 - # # Only allow postgresql access from the frontend node and ipsilon01.stg and # fas3-01.stg and openshift # custom_rules: -# - '-A INPUT -p tcp -m tcp -s 10.5.128.129 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.137 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.82 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.104 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.105 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.106 --dport 5432 -j ACCEPT' -# - '-A INPUT -p tcp -m tcp -s 10.5.128.107 --dport 5432 -j ACCEPT' -# TODO: lock it down more -- '-A INPUT -p tcp -m tcp -s 10.3.166.0/24 --dport 5432 -j ACCEPT' - + # - '-A INPUT -p tcp -m tcp -s 10.5.128.129 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.137 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.82 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.104 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.105 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.106 --dport 5432 -j ACCEPT' + # - '-A INPUT -p tcp -m tcp -s 10.5.128.107 --dport 5432 -j ACCEPT' + # TODO: lock it down more + - '-A INPUT -p tcp -m tcp -s 10.3.166.0/24 --dport 5432 -j ACCEPT' +# This is a generic list, monitored by collectd +databases: + - fas2 +datacenter: iad2 +db_backup_dir: ['/backups'] +# This is a more strict list, to be made publicly available +dbs_to_backup: + - fas2 +dns: 10.3.163.33 +effective_cache_size: "3GB" +eth0_ip: 10.3.166.34 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 30000 +mem_size: 4096 +nm: 255.255.255.0 +nrpe_procs_crit: 500 # # Large updates pushes cause lots of db threads doing the tag moves, so up this from default. # nrpe_procs_warn: 400 -nrpe_procs_crit: 500 - -db_backup_dir: ['/backups'] +num_cpus: 2 shared_buffers: "1GB" -effective_cache_size: "3GB" +vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-koji01.iad2.fedoraproject.org b/inventory/host_vars/db-koji01.iad2.fedoraproject.org index 358b381a08..7045144723 100644 --- a/inventory/host_vars/db-koji01.iad2.fedoraproject.org +++ b/inventory/host_vars/db-koji01.iad2.fedoraproject.org @@ -1,54 +1,40 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.103 -vmhost: bvmhost-x86-01.iad2.fedoraproject.org -datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -# This is a generic list, monitored by collectd -databases: -- koji - -# This is a more strict list, to be made publicly available -dbs_to_backup: -- koji - -# These are normally group variables, but in this case db servers are often different -lvm_size: 1500000 -mem_size: 131070 -num_cpus: 72 -max_cpu: 96 - -# kernel SHMMAX value -kernel_shmmax: 68719476736 - # # Only allow postgresql access from the frontend node. # -custom_rules: [ -'-A INPUT -p tcp -m tcp -s 10.3.169.104 --dport 5432 -j ACCEPT', -'-A INPUT -p tcp -m tcp -s 10.3.169.105 --dport 5432 -j ACCEPT', -'-A INPUT -p tcp -m tcp -s 10.3.169.10 --dport 5432 -j ACCEPT', -'-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5432 -j ACCEPT', -] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.169.104 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.169.105 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.169.10 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.10 --dport 5432 -j ACCEPT'] +# This is a generic list, monitored by collectd +databases: + - koji +datacenter: iad2 +db_backup_dir: ['/backups'] +# This is a more strict list, to be made publicly available +dbs_to_backup: + - koji +dns: 10.3.163.33 +effective_cache_size: "100GB" +eth0_ip: 10.3.169.103 +gw: 10.3.169.254 +# kernel SHMMAX value +kernel_shmmax: 68719476736 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 1500000 +max_cpu: 96 +max_parallel_maintenance_workers: 8 +max_parallel_workers: 64 +max_parallel_workers_per_gather: 32 +max_stack_depth: "6MB" +max_worker_processes: 64 +mem_size: 131070 +nm: 255.255.255.0 +nrpe_procs_crit: 700 # # Large updates pushes cause lots of db threads doing the tag moves, so up this from default. # nrpe_procs_warn: 600 -nrpe_procs_crit: 700 - -db_backup_dir: ['/backups'] +num_cpus: 72 shared_buffers: "32GB" -effective_cache_size: "100GB" -max_stack_depth: "6MB" - -max_worker_processes: 64 -max_parallel_workers_per_gather: 32 -max_parallel_maintenance_workers: 8 -max_parallel_workers: 64 +vmhost: bvmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-koji01.stg.iad2.fedoraproject.org b/inventory/host_vars/db-koji01.stg.iad2.fedoraproject.org index 4d1e252d1f..9765f1e2ad 100644 --- a/inventory/host_vars/db-koji01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/db-koji01.stg.iad2.fedoraproject.org @@ -1,40 +1,32 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.65 -#mac_address: 52:54:00:71:a6:eb -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -# This is a generic list, monitored by collectd -databases: -- koji - -# These are normally group variables, but in this case db servers are often different -lvm_size: 1500000 -mem_size: 16384 -max_mem_size: "{{ mem_size }}" -num_cpus: 8 - -# kernel SHMMAX value -kernel_shmmax: 68719476736 - # # Only allow postgresql access from the frontend node. # -custom_rules: [ - '-A INPUT -p tcp -m tcp -s 10.3.167.64 --dport 5432 -j ACCEPT', -] - +custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.167.64 --dport 5432 -j ACCEPT'] +# This is a generic list, monitored by collectd +databases: + - koji +datacenter: iad2 +dns: 10.3.163.33 +effective_cache_size: "12GB" +eth0_ip: 10.3.167.65 +gw: 10.3.167.254 +# kernel SHMMAX value +kernel_shmmax: 68719476736 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 1500000 +max_mem_size: "{{ mem_size }}" +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 700 # # Large updates pushes cause lots of db threads doing the tag moves, so up this from default. # nrpe_procs_warn: 600 -nrpe_procs_crit: 700 +num_cpus: 8 shared_buffers: "4GB" -effective_cache_size: "12GB" +#mac_address: 52:54:00:71:a6:eb +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-openqa01.iad2.fedoraproject.org b/inventory/host_vars/db-openqa01.iad2.fedoraproject.org index da15843883..c9b98fca71 100644 --- a/inventory/host_vars/db-openqa01.iad2.fedoraproject.org +++ b/inventory/host_vars/db-openqa01.iad2.fedoraproject.org @@ -1,38 +1,33 @@ --- -nm: 255.255.255.0 -gw: 10.3.174.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.174.51 -vmhost: qvmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- postgres -- openqa - + - postgres + - openqa +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- postgres -# these names are also stored as host vars 'openqa_dbname', -# make sure to keep in sync -- openqa -- openqa-stg - + - postgres + # these names are also stored as host vars 'openqa_dbname', + # make sure to keep in sync + - openqa + - openqa-stg +dns: 10.3.163.33 +effective_cache_size: "6GB" +eth0_ip: 10.3.174.51 +gw: 10.3.174.254 +host_backup_targets: ['/backups'] +# kernel SHMMAX value +kernel_shmmax: 68719476736 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 # These are normally group variables, but in this case db servers are often different lvm_size: 300000 mem_size: 16384 +nm: 255.255.255.0 num_cpus: 10 -tcp_ports: [ 5432, 443, 3306 ] -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - -# kernel SHMMAX value -kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] shared_buffers: "2GB" -effective_cache_size: "6GB" -host_backup_targets: ['/backups'] +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" +tcp_ports: [5432, 443, 3306] +vmhost: qvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-qa02.iad2.fedoraproject.org b/inventory/host_vars/db-qa02.iad2.fedoraproject.org index 672ab0770b..03deba9ae6 100644 --- a/inventory/host_vars/db-qa02.iad2.fedoraproject.org +++ b/inventory/host_vars/db-qa02.iad2.fedoraproject.org @@ -1,37 +1,30 @@ --- -nm: 255.255.255.0 -gw: 10.3.174.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.174.54 -vmhost: qvmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - - - # This is a generic list, monitored by collectd databases: -- resultsdb - + - resultsdb +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- postgres -- resultsdb - -# These are normally group variables, but in this case db servers are often different -lvm_size: 300000 -mem_size: 16384 -max_mem_size: "{{ mem_size * 2 }}" -num_cpus: 6 -tcp_ports: [ 5432, 443, 3306 ] -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - + - postgres + - resultsdb +dns: 10.3.163.33 +effective_cache_size: "6GB" +eth0_ip: 10.3.174.54 +gw: 10.3.174.254 +host_backup_targets: ['/backups'] # kernel SHMMAX value kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 300000 +max_mem_size: "{{ mem_size * 2 }}" +mem_size: 16384 +nm: 255.255.255.0 +num_cpus: 6 shared_buffers: "2GB" -effective_cache_size: "6GB" -host_backup_targets: ['/backups'] +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" +tcp_ports: [5432, 443, 3306] +vmhost: qvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db-qa03.iad2.fedoraproject.org b/inventory/host_vars/db-qa03.iad2.fedoraproject.org index ed7df7ef44..6d06170010 100644 --- a/inventory/host_vars/db-qa03.iad2.fedoraproject.org +++ b/inventory/host_vars/db-qa03.iad2.fedoraproject.org @@ -1,34 +1,29 @@ --- -nm: 255.255.255.0 -gw: 10.3.174.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.174.55 -vmhost: qvmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- postgres - + - postgres +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list, to be made publicly available dbs_to_backup: -- postgres - -# These are normally group variables, but in this case db servers are often different -lvm_size: 300000 -mem_size: 16384 -max_mem_size: "{{ mem_size * 2 }}" -num_cpus: 6 -tcp_ports: [ 5432, 443, 3306 ] -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - + - postgres +dns: 10.3.163.33 +effective_cache_size: "6GB" +eth0_ip: 10.3.174.55 +gw: 10.3.174.254 +host_backup_targets: ['/backups'] # kernel SHMMAX value kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 300000 +max_mem_size: "{{ mem_size * 2 }}" +mem_size: 16384 +nm: 255.255.255.0 +num_cpus: 6 shared_buffers: "2GB" -effective_cache_size: "6GB" -host_backup_targets: ['/backups'] +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" +tcp_ports: [5432, 443, 3306] +vmhost: qvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db01.iad2.fedoraproject.org b/inventory/host_vars/db01.iad2.fedoraproject.org index 33dfb11469..753e3d163f 100644 --- a/inventory/host_vars/db01.iad2.fedoraproject.org +++ b/inventory/host_vars/db01.iad2.fedoraproject.org @@ -1,85 +1,77 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.41 -vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -# This is a generic list, monitored by collectd -databases: -- anitya -- blockerbugs -- bodhi2 -- elections -- fedocal -- hyperkitty -- kerneltest -- koschei -- mailman -- mbs -- mirrormanager2 -- notifications -- nuancier_lite -- odcs -- pagure -- pdc -- tahrir -- waiverdb -- transtats -- resultsdb -- zezere - -# This is a more strict list of databases to backup every day -dbs_to_backup: -- anitya -- blockerbugs -- bodhi2 -- elections -- fedocal -- hyperkitty -- kerneltest -- koschei -- mailman -- mbs -- mirrormanager2 -- notifications -- nuancier_lite -- odcs -- pagure -- pdc -- tahrir -- waiverdb -- transtats -- resultsdb -- zezere - -# These are normally group variables, but in this case db servers are often different -lvm_size: 500000 -mem_size: 65536 -num_cpus: 24 - # # We should narrow this down at some point # -custom_rules: [ '-A INPUT -p tcp -m tcp --dport 5432 -j ACCEPT' ] - +custom_rules: ['-A INPUT -p tcp -m tcp --dport 5432 -j ACCEPT'] +# This is a generic list, monitored by collectd +databases: + - anitya + - blockerbugs + - bodhi2 + - elections + - fedocal + - hyperkitty + - kerneltest + - koschei + - mailman + - mbs + - mirrormanager2 + - notifications + - nuancier_lite + - odcs + - pagure + - pdc + - tahrir + - waiverdb + - transtats + - resultsdb + - zezere +datacenter: iad2 +db_backup_dir: ['/backups'] +# This is a more strict list of databases to backup every day +dbs_to_backup: + - anitya + - blockerbugs + - bodhi2 + - elections + - fedocal + - hyperkitty + - kerneltest + - koschei + - mailman + - mbs + - mirrormanager2 + - notifications + - nuancier_lite + - odcs + - pagure + - pdc + - tahrir + - waiverdb + - transtats + - resultsdb + - zezere +dns: 10.3.163.33 +# Should be 0.80 of memory +effective_cache_size: "50GB" +eth0_ip: 10.3.163.41 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +# These are normally group variables, but in this case db servers are often different +lvm_size: 500000 +max_stack_depth: "6MB" +mem_size: 65536 +nagios_Check_Services: + swap: false +nm: 255.255.255.0 +nrpe_procs_crit: 900 # # db01 handles lots of apps, could have many procs if they are busy. # nrpe_procs_warn: 800 -nrpe_procs_crit: 900 - -nagios_Check_Services: - swap: false - -db_backup_dir: ['/backups'] +num_cpus: 24 # Should be 0.25 of memory shared_buffers: "16GB" -# Should be 0.80 of memory -effective_cache_size: "50GB" -max_stack_depth: "6MB" +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db01.stg.iad2.fedoraproject.org b/inventory/host_vars/db01.stg.iad2.fedoraproject.org index 873648dcb2..ab40202d38 100644 --- a/inventory/host_vars/db01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/db01.stg.iad2.fedoraproject.org @@ -1,42 +1,38 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -eth0_ip: 10.3.166.32 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - -# This is a generic list, monitored by collectd -databases: -- askfedora -- blockerbugs -- bodhi -- elections -- fedocal -- kerneltest -- mailman -- mirrormanager -- notifications -- nuancier_lite -- tahrir - -# These are normally group variables, but in this case db servers are often different -lvm_size: 500000 -mem_size: 16384 -num_cpus: 4 - # # We should narrow this down at some point # -custom_rules: [ '-A INPUT -p tcp -m tcp --dport 5432 -j ACCEPT' ] - +custom_rules: ['-A INPUT -p tcp -m tcp --dport 5432 -j ACCEPT'] +# This is a generic list, monitored by collectd +databases: + - askfedora + - blockerbugs + - bodhi + - elections + - fedocal + - kerneltest + - mailman + - mirrormanager + - notifications + - nuancier_lite + - tahrir +datacenter: iad2 +dns: 10.3.163.33 +effective_cache_size: "12GB" +eth0_ip: 10.3.166.32 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 500000 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 900 # # db01 handles lots of apps, could have many procs if they are busy. # nrpe_procs_warn: 800 -nrpe_procs_crit: 900 +num_cpus: 4 shared_buffers: "4GB" -effective_cache_size: "12GB" +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db03.iad2.fedoraproject.org b/inventory/host_vars/db03.iad2.fedoraproject.org index 5968a981b5..6d713e2c27 100644 --- a/inventory/host_vars/db03.iad2.fedoraproject.org +++ b/inventory/host_vars/db03.iad2.fedoraproject.org @@ -1,34 +1,28 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.44 -vmhost: vmhost-x86-07.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- mysql -- fpo-mediawiki - + - mysql + - fpo-mediawiki +datacenter: iad2 +db_backup_dir: ['/backups'] # This is a more strict list of db to backup to /backups dbs_to_backup: -- fpo-mediawiki - -mariadb_root_password: "{{ db03_mysql_root_password }}" - -# These are normally group variables, but in this case db servers are often different -lvm_size: 300000 -mem_size: 8192 -num_cpus: 2 -tcp_ports: [ 5432, 443, 3306 ] - + - fpo-mediawiki +dns: 10.3.163.33 +eth0_ip: 10.3.163.44 +extra_enablerepos: '' +gw: 10.3.163.254 # kernel SHMMAX value kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +# These are normally group variables, but in this case db servers are often different +lvm_size: 300000 +mariadb_root_password: "{{ db03_mysql_root_password }}" +mem_size: 8192 +nm: 255.255.255.0 +num_cpus: 2 shared_buffers: "4GB" -extra_enablerepos: '' +tcp_ports: [5432, 443, 3306] +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/db03.stg.iad2.fedoraproject.org b/inventory/host_vars/db03.stg.iad2.fedoraproject.org index dd9add51da..1bccf1753f 100644 --- a/inventory/host_vars/db03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/db03.stg.iad2.fedoraproject.org @@ -1,32 +1,26 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.35 -vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org -datacenter: iad2 - # This is a generic list, monitored by collectd databases: -- postgres - -# This is a more strict list, to be made publicly available -#dbs_to_backup: - -mariadb_root_password: "{{ db03_stg_mysql_root_password }}" - -# These are normally group variables, but in this case db servers are often different -lvm_size: 300000 -mem_size: 8192 -num_cpus: 2 -tcp_ports: [ 5432, 443, 3306 ] - + - postgres +datacenter: iad2 +db_backup_dir: ['/backups'] +dns: 10.3.163.33 +eth0_ip: 10.3.166.35 +extra_enablerepos: '' +gw: 10.3.166.254 # kernel SHMMAX value kernel_shmmax: 68719476736 - -db_backup_dir: ['/backups'] +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +# These are normally group variables, but in this case db servers are often different +lvm_size: 300000 +# This is a more strict list, to be made publicly available +#dbs_to_backup: +mariadb_root_password: "{{ db03_stg_mysql_root_password }}" +mem_size: 8192 +nm: 255.255.255.0 +num_cpus: 2 shared_buffers: "4GB" -extra_enablerepos: '' +tcp_ports: [5432, 443, 3306] +vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/debuginfod01.iad2.fedoraproject.org b/inventory/host_vars/debuginfod01.iad2.fedoraproject.org index 56111c0648..bd5f0a0343 100644 --- a/inventory/host_vars/debuginfod01.iad2.fedoraproject.org +++ b/inventory/host_vars/debuginfod01.iad2.fedoraproject.org @@ -1,12 +1,12 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.109 -vmhost: vmhost-x86-06.iad2.fedoraproject.org datacenter: iad2 -virt_install_command: "{{ virt_install_command_one_nic }}" +dns: 10.3.163.33 +eth0_ip: 10.3.163.109 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33 +nm: 255.255.255.0 sar_script_user: root +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/debuginfod01.stg.iad2.fedoraproject.org b/inventory/host_vars/debuginfod01.stg.iad2.fedoraproject.org index 9503ebf0b0..20117d5bdc 100644 --- a/inventory/host_vars/debuginfod01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/debuginfod01.stg.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.62 -vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.62 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33 +nm: 255.255.255.0 +vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/dedicatedsolutions01.fedoraproject.org b/inventory/host_vars/dedicatedsolutions01.fedoraproject.org index a7e4b8cd7e..2d2eb0f74e 100644 --- a/inventory/host_vars/dedicatedsolutions01.fedoraproject.org +++ b/inventory/host_vars/dedicatedsolutions01.fedoraproject.org @@ -1,53 +1,44 @@ --- -datacenter: dedicatedsolutions -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -postfix_group: vpn -vpn: true - -dns1: 8.8.8.8 -dns2: 8.8.4.4 - -dns_search1: "vpn.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes br0_ipv4: 67.219.144.66 -br0_ipv4_nm: 29 br0_ipv4_gw: 67.219.144.65 - -has_ipv6: yes +br0_ipv4_nm: 29 br0_ipv6: "2604:1580:fe00:0:dead:beef:cafe:fe01" br0_ipv6_gw: "2604:1580:fe00::1" - -mac1: d8:d3:85:b8:d9:00 - br0_port0_mac: "{{ mac1 }}" - +datacenter: dedicatedsolutions +dns1: 8.8.8.8 +dns2: 8.8.4.4 +dns_search1: "vpn.fedoraproject.org" +dns_search2: "fedoraproject.org" +has_ipv4: yes +has_ipv6: yes +mac1: d8:d3:85:b8:d9:00 network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - \ No newline at end of file +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: vpn +virthost: true +vpn: true diff --git a/inventory/host_vars/dl01.iad2.fedoraproject.org b/inventory/host_vars/dl01.iad2.fedoraproject.org index c4512a3450..3b8e965ff7 100644 --- a/inventory/host_vars/dl01.iad2.fedoraproject.org +++ b/inventory/host_vars/dl01.iad2.fedoraproject.org @@ -1,27 +1,20 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.49 -datacenter: iad2 - - +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +public_hostname: dl-iad01.fedoraproject.org +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_one_nic }}" vmhost: vmhost-x86-03.iad2.fedoraproject.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -tcp_ports: [80, 443, 873] - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: dl-iad01.fedoraproject.org diff --git a/inventory/host_vars/dl02.iad2.fedoraproject.org b/inventory/host_vars/dl02.iad2.fedoraproject.org index ee3863f68f..5cef1839c4 100644 --- a/inventory/host_vars/dl02.iad2.fedoraproject.org +++ b/inventory/host_vars/dl02.iad2.fedoraproject.org @@ -1,28 +1,21 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.50 -datacenter: iad2 - - +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 +main_bridge: br0 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +public_hostname: dl-iad01.fedoraproject.org +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_one_nic }}" vmhost: vmhost-x86-04.iad2.fedoraproject.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -main_bridge: br0 - -tcp_ports: [80, 443, 873] - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: dl-iad01.fedoraproject.org diff --git a/inventory/host_vars/dl03.iad2.fedoraproject.org b/inventory/host_vars/dl03.iad2.fedoraproject.org index 32e4172f9e..43e9ed3d8e 100644 --- a/inventory/host_vars/dl03.iad2.fedoraproject.org +++ b/inventory/host_vars/dl03.iad2.fedoraproject.org @@ -1,28 +1,21 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.51 -datacenter: iad2 - - +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 +main_bridge: br0 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +public_hostname: dl-iad01.fedoraproject.org +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_one_nic }}" vmhost: vmhost-x86-05.iad2.fedoraproject.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -main_bridge: br0 - -tcp_ports: [80, 443, 873] - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: dl-iad01.fedoraproject.org diff --git a/inventory/host_vars/dl04.iad2.fedoraproject.org b/inventory/host_vars/dl04.iad2.fedoraproject.org index d36b2247c9..f13a567e3e 100644 --- a/inventory/host_vars/dl04.iad2.fedoraproject.org +++ b/inventory/host_vars/dl04.iad2.fedoraproject.org @@ -1,28 +1,21 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.85 -datacenter: iad2 - - +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 +main_bridge: br0 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +public_hostname: dl-iad01.fedoraproject.org +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_one_nic }}" vmhost: vmhost-x86-06.iad2.fedoraproject.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -main_bridge: br0 - -tcp_ports: [80, 443, 873] - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: dl-iad01.fedoraproject.org diff --git a/inventory/host_vars/dl05.iad2.fedoraproject.org b/inventory/host_vars/dl05.iad2.fedoraproject.org index fb4f9592b3..f37ef8c0b6 100644 --- a/inventory/host_vars/dl05.iad2.fedoraproject.org +++ b/inventory/host_vars/dl05.iad2.fedoraproject.org @@ -1,28 +1,21 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.84 -datacenter: iad2 - - +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +lvm_size: 20000 +main_bridge: br0 +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +public_hostname: dl-iad01.fedoraproject.org +tcp_ports: [80, 443, 873] +virt_install_command: "{{ virt_install_command_one_nic }}" vmhost: vmhost-x86-07.iad2.fedoraproject.org volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -main_bridge: br0 - -tcp_ports: [80, 443, 873] - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - vpn: false - -public_hostname: dl-iad01.fedoraproject.org diff --git a/inventory/host_vars/download-cc-rdu01.fedoraproject.org b/inventory/host_vars/download-cc-rdu01.fedoraproject.org index 249f3c57eb..d6dc177d40 100644 --- a/inventory/host_vars/download-cc-rdu01.fedoraproject.org +++ b/inventory/host_vars/download-cc-rdu01.fedoraproject.org @@ -1,36 +1,26 @@ --- -nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -vmhost: virthost-cc-rdu03.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 8.43.85.72 -eth0_nm: 255.255.255.0 - -has_ipv6: yes eth0_ipv6: "2620:52:3:1:dead:beef:cafe:fed1" eth0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - -datacenter: rdu-cc -postfix_group: vpn -vpn: true - -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 20480 +eth0_nm: 255.255.255.0 +gw: 8.43.85.254 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 20000 -num_cpus: 8 - mac_address: "52:54:00:30:a6:43" - +max_mem_size: 20480 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn public_hostname: download-cc-rdu01.fedoraproject.org +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +tcp_ports: [80, 443, 873] +vmhost: virthost-cc-rdu03.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/download-ib01.fedoraproject.org b/inventory/host_vars/download-ib01.fedoraproject.org index 7db851fa9c..85bcd9ec55 100644 --- a/inventory/host_vars/download-ib01.fedoraproject.org +++ b/inventory/host_vars/download-ib01.fedoraproject.org @@ -1,58 +1,48 @@ --- -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -vmhost: ibiblio01.fedoraproject.org -volgroup: /dev/vg_guests - -eth0_ipv4: 152.19.134.145 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed6" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" - datacenter: ibiblio -postfix_group: vpn -vpn: true - -tcp_ports: [80, 443, 873] -rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 4096 -max_mem_size: 20480 -lvm_size: 20000 -num_cpus: 8 - -public_hostname: download-ib01.fedoraproject.org - dns1: 152.2.21.1 dns2: 152.2.253.100 - dns_search1: vpn.fedoraproject.org dns_search2: fedoraproject.org - +eth0_ipv4: 152.19.134.145 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed6" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext +lvm_size: 20000 +max_mem_size: 20480 +mem_size: 4096 network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: download-ib01.fedoraproject.org +rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}" +tcp_ports: [80, 443, 873] +vmhost: ibiblio01.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/download-rdu01.fedoraproject.org b/inventory/host_vars/download-rdu01.fedoraproject.org index ae9403b6bb..ddb5611ca0 100644 --- a/inventory/host_vars/download-rdu01.fedoraproject.org +++ b/inventory/host_vars/download-rdu01.fedoraproject.org @@ -1,66 +1,57 @@ --- datacenter: rdu - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -postfix_group: vpn -vpn: true - -public_ip: 209.132.190.4 - +dns1: 172.31.2.24 +dns_search1: "vpn.fedoraproject.org" +dns_search2: "rdu2.fedoraproject.org" +dns_search3: "fedoraproject.org" +eth0_ipv4: 172.31.2.31 +eth0_ipv4_gw: 172.31.2.254 +eth0_ipv4_nm: 24 +eth1_ipv4: 172.31.1.1 +eth1_ipv4_gw: 172.31.1.254 +eth1_ipv4_nm: 24 +has_ipv4: yes +mac0: e4:1f:13:6a:e3:a0 nagios_Check_Services: mail: false nrpe: false ping: true - -public_hostname: download-rdu01.fedoraproject.org - -dns1: 172.31.2.24 - -dns_search1: "vpn.fedoraproject.org" -dns_search2: "rdu2.fedoraproject.org" -dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 172.31.2.31 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 172.31.2.254 -eth1_ipv4: 172.31.1.1 -eth1_ipv4_nm: 24 -eth1_ipv4_gw: 172.31.1.254 - -mac0: e4:1f:13:6a:e3:a0 - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no -- name: eth1 - state: down - type: ethernet - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet + - ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth1_ipv4_gw }}" + name: eth1 + state: down + type: ethernet +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: vpn +public_hostname: download-rdu01.fedoraproject.org +public_ip: 209.132.190.4 +vpn: true diff --git a/inventory/host_vars/el7-test.fedorainfracloud.org b/inventory/host_vars/el7-test.fedorainfracloud.org index 94698808d1..21df1001fa 100644 --- a/inventory/host_vars/el7-test.fedorainfracloud.org +++ b/inventory/host_vars/el7-test.fedorainfracloud.org @@ -1,19 +1,17 @@ --- -tcp_ports: [22] - +ansible_become: true +ansible_become_method: sudo +ansible_become_user: root +ansible_ssh_user: centos datacenter: aws nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false - -ansible_ssh_user: centos -ansible_become: true -ansible_become_user: root -ansible_become_method: sudo + sshd: false + swap: false +tcp_ports: [22] diff --git a/inventory/host_vars/el8-test.fedorainfracloud.org b/inventory/host_vars/el8-test.fedorainfracloud.org index a9358e0b0e..0818b417db 100644 --- a/inventory/host_vars/el8-test.fedorainfracloud.org +++ b/inventory/host_vars/el8-test.fedorainfracloud.org @@ -1,20 +1,18 @@ --- -tcp_ports: [22] - +ansible_become: true +ansible_become_method: sudo +ansible_become_user: root +ansible_ssh_user: centos +baseiptables: false datacenter: aws nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false - -ansible_ssh_user: centos -ansible_become: true -ansible_become_user: root -ansible_become_method: sudo -baseiptables: false + sshd: false + swap: false +tcp_ports: [22] diff --git a/inventory/host_vars/fedimg01.iad2.fedoraproject.org b/inventory/host_vars/fedimg01.iad2.fedoraproject.org index e4497c4bf0..4e41ad7ac9 100644 --- a/inventory/host_vars/fedimg01.iad2.fedoraproject.org +++ b/inventory/host_vars/fedimg01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.52 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 vmhost: vmhost-x86-02.iad2.fedoraproject.org volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.52 diff --git a/inventory/host_vars/fedocal01.iad2.fedoraproject.org b/inventory/host_vars/fedocal01.iad2.fedoraproject.org index e4130ade76..9132c71517 100644 --- a/inventory/host_vars/fedocal01.iad2.fedoraproject.org +++ b/inventory/host_vars/fedocal01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.97 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.97 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/fedocal02.iad2.fedoraproject.org b/inventory/host_vars/fedocal02.iad2.fedoraproject.org index 48d76caca2..4f2e498279 100644 --- a/inventory/host_vars/fedocal02.iad2.fedoraproject.org +++ b/inventory/host_vars/fedocal02.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.98 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.98 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/github2fedmsg01.iad2.fedoraproject.org b/inventory/host_vars/github2fedmsg01.iad2.fedoraproject.org index 6bebd64d3b..09d89ad020 100644 --- a/inventory/host_vars/github2fedmsg01.iad2.fedoraproject.org +++ b/inventory/host_vars/github2fedmsg01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.163.53 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/github2fedmsg01.stg.iad2.fedoraproject.org b/inventory/host_vars/github2fedmsg01.stg.iad2.fedoraproject.org index 8c977c4a4d..239fd894ad 100644 --- a/inventory/host_vars/github2fedmsg01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/github2fedmsg01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.166.39 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/host1plus01.fedoraproject.org b/inventory/host_vars/host1plus01.fedoraproject.org index f6b0614d40..dae70b4946 100644 --- a/inventory/host_vars/host1plus01.fedoraproject.org +++ b/inventory/host_vars/host1plus01.fedoraproject.org @@ -1,10 +1,10 @@ --- -datacenter: host1plus -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 br0_ip: 5.175.150.48 -br0_nm: 255.255.255.240 -has_ipv6: yes br0_ipv6: "2a00:d1a0:1::130" br0_ipv6_gw: "2a00:d1a0:1::1" +br0_nm: 255.255.255.240 +datacenter: host1plus +has_ipv6: yes +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virthost: true diff --git a/inventory/host_vars/ibiblio01.fedoraproject.org b/inventory/host_vars/ibiblio01.fedoraproject.org index c718200d5c..9b1bcdeeba 100644 --- a/inventory/host_vars/ibiblio01.fedoraproject.org +++ b/inventory/host_vars/ibiblio01.fedoraproject.org @@ -1,16 +1,15 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: ibiblio -nm: 255.255.255.128 -gw: 152.19.134.129 -dns: 8.8.8.8 br0_ip: 152.19.134.138 -br0_nm: 255.255.255.128 -has_ipv6: yes br0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fe01" -br0_ipv6_nm: 104 br0_ipv6_gw: "2600:2701:4000:5211::1" - +br0_ipv6_nm: 104 +br0_nm: 255.255.255.128 +datacenter: ibiblio +dns: 8.8.8.8 +gw: 152.19.134.129 +has_ipv6: yes +nm: 255.255.255.128 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 postfix_group: vpn vpn: true diff --git a/inventory/host_vars/ibiblio05.fedoraproject.org b/inventory/host_vars/ibiblio05.fedoraproject.org index c06f8fc3ba..1610f3b92b 100644 --- a/inventory/host_vars/ibiblio05.fedoraproject.org +++ b/inventory/host_vars/ibiblio05.fedoraproject.org @@ -1,16 +1,15 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: ibiblio -nm: 255.255.255.128 -gw: 152.19.134.129 -dns: 152.2.21.1 br0_ip: 152.19.134.137 -br0_nm: 255.255.255.128 -has_ipv6: yes br0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fe05/104" -br0_ipv6_nm: 104 br0_ipv6_gw: "2600:2701:4000:5211::1" - +br0_ipv6_nm: 104 +br0_nm: 255.255.255.128 +datacenter: ibiblio +dns: 152.2.21.1 +gw: 152.19.134.129 +has_ipv6: yes +nm: 255.255.255.128 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 postfix_group: vpn vpn: true diff --git a/inventory/host_vars/iddev.fedorainfracloud.org b/inventory/host_vars/iddev.fedorainfracloud.org index 9850d955d8..1273ace249 100644 --- a/inventory/host_vars/iddev.fedorainfracloud.org +++ b/inventory/host_vars/iddev.fedorainfracloud.org @@ -1,15 +1,14 @@ --- ansible_ifcfg_blocklist: true -tcp_ports: [22, 80, 443] - datacenter: aws nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false dhcpd: false httpd: false - swap: false + mail: false + named: false + nrpe: false ping: false raid: false + sshd: false + swap: false +tcp_ports: [22, 80, 443] diff --git a/inventory/host_vars/internetx01.fedoraproject.org b/inventory/host_vars/internetx01.fedoraproject.org index a704c2c1c5..69c905399d 100644 --- a/inventory/host_vars/internetx01.fedoraproject.org +++ b/inventory/host_vars/internetx01.fedoraproject.org @@ -1,13 +1,12 @@ --- -datacenter: internetx -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -postfix_group: vpn -vpn: true br0_ip: 85.236.55.4 -br0_nm: 255.255.255.240 -has_ipv6: yes br0_ipv6: "2001:4178:2:1269::10" br0_ipv6_gw: "2001:4178:2:1269::1" +br0_nm: 255.255.255.240 +datacenter: internetx +has_ipv6: yes +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: vpn +virthost: true +vpn: true diff --git a/inventory/host_vars/ipa01.iad2.fedoraproject.org b/inventory/host_vars/ipa01.iad2.fedoraproject.org index 1e53c4bb3a..35220fa990 100644 --- a/inventory/host_vars/ipa01.iad2.fedoraproject.org +++ b/inventory/host_vars/ipa01.iad2.fedoraproject.org @@ -1,11 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.54 -vmhost: vmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.54 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipa01.stg.iad2.fedoraproject.org b/inventory/host_vars/ipa01.stg.iad2.fedoraproject.org index e4ed03e0cc..014a6b8e86 100644 --- a/inventory/host_vars/ipa01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ipa01.stg.iad2.fedoraproject.org @@ -1,12 +1,12 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.21 -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.21 +gw: 10.3.166.254 ## REMEMBER ONLY SET THIS TO TRUE WHEN WIPING SYSTEM TO MINIMUM ipa_initial: false +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipa02.iad2.fedoraproject.org b/inventory/host_vars/ipa02.iad2.fedoraproject.org index b035eddd4b..4752caeaf1 100644 --- a/inventory/host_vars/ipa02.iad2.fedoraproject.org +++ b/inventory/host_vars/ipa02.iad2.fedoraproject.org @@ -1,11 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.55 -vmhost: vmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.55 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipa02.stg.iad2.fedoraproject.org b/inventory/host_vars/ipa02.stg.iad2.fedoraproject.org index c3fc212639..f97354bc25 100644 --- a/inventory/host_vars/ipa02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ipa02.stg.iad2.fedoraproject.org @@ -1,12 +1,12 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.63 -vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.63 +gw: 10.3.166.254 ## REMEMBER ONLY SET THIS TO TRUE WHEN WIPING SYSTEM TO MINIMUM ipa_initial: false +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipa03.iad2.fedoraproject.org b/inventory/host_vars/ipa03.iad2.fedoraproject.org index 8d48521749..790ae5b146 100644 --- a/inventory/host_vars/ipa03.iad2.fedoraproject.org +++ b/inventory/host_vars/ipa03.iad2.fedoraproject.org @@ -1,11 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.104 -vmhost: vmhost-x86-06.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.104 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipsilon01.iad2.fedoraproject.org b/inventory/host_vars/ipsilon01.iad2.fedoraproject.org index f8853fc74b..04ef260b9a 100644 --- a/inventory/host_vars/ipsilon01.iad2.fedoraproject.org +++ b/inventory/host_vars/ipsilon01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.105 -vmhost: vmhost-x86-07.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.105 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipsilon01.stg.iad2.fedoraproject.org b/inventory/host_vars/ipsilon01.stg.iad2.fedoraproject.org index 12b5e14ce0..1e7f346c41 100644 --- a/inventory/host_vars/ipsilon01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ipsilon01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.30 -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.30 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ipsilon02.iad2.fedoraproject.org b/inventory/host_vars/ipsilon02.iad2.fedoraproject.org index 779645980d..b4a842a0ac 100644 --- a/inventory/host_vars/ipsilon02.iad2.fedoraproject.org +++ b/inventory/host_vars/ipsilon02.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.106 -vmhost: vmhost-x86-06.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.106 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/kernel01.iad2.fedoraproject.org b/inventory/host_vars/kernel01.iad2.fedoraproject.org index b8c0f133e6..c4bac059f5 100644 --- a/inventory/host_vars/kernel01.iad2.fedoraproject.org +++ b/inventory/host_vars/kernel01.iad2.fedoraproject.org @@ -1,8 +1,7 @@ --- -nm: 255.255.255.0 -gw: 10.3.174.254 -eth0_ip: 10.3.174.129 -dns: 10.3.163.33 - datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.174.129 +gw: 10.3.174.254 +nm: 255.255.255.0 resolvconf: "resolv.conf/iad2" diff --git a/inventory/host_vars/kerneltest01.iad2.fedoraproject.org b/inventory/host_vars/kerneltest01.iad2.fedoraproject.org index 8aaf0888c4..5b3eb91a08 100644 --- a/inventory/host_vars/kerneltest01.iad2.fedoraproject.org +++ b/inventory/host_vars/kerneltest01.iad2.fedoraproject.org @@ -1,13 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-05.iad2.fedoraproject.org datacenter: iad2 -kerneltest_db_host: db01.iad2.fedoraproject.org - +dns: 10.3.163.33 eth0_ip: 10.3.163.90 +gw: 10.3.163.254 +kerneltest_db_host: db01.iad2.fedoraproject.org +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/koji01.iad2.fedoraproject.org b/inventory/host_vars/koji01.iad2.fedoraproject.org index edb6e6e1c6..1d174051cb 100644 --- a/inventory/host_vars/koji01.iad2.fedoraproject.org +++ b/inventory/host_vars/koji01.iad2.fedoraproject.org @@ -1,23 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.104 -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 -virt_install_command: "{{ virt_install_command_one_nic }}" - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.104 fedmsg_koji_instance: primary - -koji_topurl: "https://kojipkgs.fedoraproject.org/" +gw: 10.3.169.254 koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" koji_weburl: "https://koji.fedoraproject.org/koji" - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 # we need sftp here in order to support the sshfs mount on buildvm-s390x-01 sshd_sftp: true +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/koji01.stg.iad2.fedoraproject.org b/inventory/host_vars/koji01.stg.iad2.fedoraproject.org index 04dfb53ae6..a60e64a9f3 100644 --- a/inventory/host_vars/koji01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/koji01.stg.iad2.fedoraproject.org @@ -1,21 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-kojistg -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.64 -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.167.64 fedmsg_koji_instance: primary - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 1.5t - -koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" +gw: 10.3.167.254 koji_server_url: "https://koji.stg.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.stg.fedoraproject.org/" koji_weburl: "https://koji.stg.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-kojistg +lvm_size: 1.5t +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/koji02.iad2.fedoraproject.org b/inventory/host_vars/koji02.iad2.fedoraproject.org index a546880603..2fc87fe08b 100644 --- a/inventory/host_vars/koji02.iad2.fedoraproject.org +++ b/inventory/host_vars/koji02.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.105 -vmhost: bvmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 -virt_install_command: "{{ virt_install_command_one_nic }}" - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.105 fedmsg_koji_instance: primary - -koji_topurl: "https://kojipkgs.fedoraproject.org/" +gw: 10.3.169.254 koji_server_url: "https://koji.fedoraproject.org/kojihub" +koji_topurl: "https://kojipkgs.fedoraproject.org/" koji_weburl: "https://koji.fedoraproject.org/koji" +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/kojipkgs01.iad2.fedoraproject.org b/inventory/host_vars/kojipkgs01.iad2.fedoraproject.org index 344d4e2efd..8a75d7bb24 100644 --- a/inventory/host_vars/kojipkgs01.iad2.fedoraproject.org +++ b/inventory/host_vars/kojipkgs01.iad2.fedoraproject.org @@ -1,19 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.169.106 - -vmhost: bvmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +dns: 10.3.163.33 +eth0_ip: 10.3.169.106 +gw: 10.3.169.254 ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -nrpe_procs_warn: 900 +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 nrpe_procs_crit: 1000 - +nrpe_procs_warn: 900 virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/kojipkgs02.iad2.fedoraproject.org b/inventory/host_vars/kojipkgs02.iad2.fedoraproject.org index d7a3e47b73..ac545e6cb7 100644 --- a/inventory/host_vars/kojipkgs02.iad2.fedoraproject.org +++ b/inventory/host_vars/kojipkgs02.iad2.fedoraproject.org @@ -1,19 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.169.107 - -vmhost: bvmhost-x86-05.iad2.fedoraproject.org datacenter: iad2 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +dns: 10.3.163.33 +eth0_ip: 10.3.169.107 +gw: 10.3.169.254 ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -nrpe_procs_warn: 900 +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 nrpe_procs_crit: 1000 - +nrpe_procs_warn: 900 virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/log01.iad2.fedoraproject.org b/inventory/host_vars/log01.iad2.fedoraproject.org index 5cd0039d6c..3f0c08360d 100644 --- a/inventory/host_vars/log01.iad2.fedoraproject.org +++ b/inventory/host_vars/log01.iad2.fedoraproject.org @@ -1,26 +1,20 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.39 -vmhost: vmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - -tcp_ports: [ 80, 443, 514, 6514 ] -udp_ports: [ 514, 25826 ] -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.39 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext lvm_size: 1048576 mem_size: 16384 -num_cpus: 16 - #host_backup_targets: ['/var/log'] - nagios_Check_Services: swap: false +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +tcp_ports: [80, 443, 514, 6514] +udp_ports: [514, 25826] +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mailman01.iad2.fedoraproject.org b/inventory/host_vars/mailman01.iad2.fedoraproject.org index 34734b73af..5ae87066c3 100644 --- a/inventory/host_vars/mailman01.iad2.fedoraproject.org +++ b/inventory/host_vars/mailman01.iad2.fedoraproject.org @@ -1,16 +1,15 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.57 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.57 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 750000 - +nm: 255.255.255.0 +sar_output_file: mailinglists.json # GDPR SAR variables sar_script: /srv/webui/bin/mailman-sar.py sar_script_user: apache -sar_output_file: mailinglists.json +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mailman01.stg.iad2.fedoraproject.org b/inventory/host_vars/mailman01.stg.iad2.fedoraproject.org index 11ef90a918..34cab67fd5 100644 --- a/inventory/host_vars/mailman01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mailman01.stg.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.40 -vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.40 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mbs-backend01.iad2.fedoraproject.org b/inventory/host_vars/mbs-backend01.iad2.fedoraproject.org index f92dcc9c88..7779b7a921 100644 --- a/inventory/host_vars/mbs-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/mbs-backend01.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.108 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.108 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mbs-backend01.stg.iad2.fedoraproject.org b/inventory/host_vars/mbs-backend01.stg.iad2.fedoraproject.org index 3f7168abe3..9c78eb983b 100644 --- a/inventory/host_vars/mbs-backend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mbs-backend01.stg.iad2.fedoraproject.org @@ -1,11 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.30 -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.30 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mbs-frontend01.iad2.fedoraproject.org b/inventory/host_vars/mbs-frontend01.iad2.fedoraproject.org index 1acc007689..263c5fa78c 100644 --- a/inventory/host_vars/mbs-frontend01.iad2.fedoraproject.org +++ b/inventory/host_vars/mbs-frontend01.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.109 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.109 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mbs-frontend01.stg.iad2.fedoraproject.org b/inventory/host_vars/mbs-frontend01.stg.iad2.fedoraproject.org index d31e24847a..304ae67b28 100644 --- a/inventory/host_vars/mbs-frontend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mbs-frontend01.stg.iad2.fedoraproject.org @@ -1,11 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.31 -vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.31 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/memcached01.iad2.fedoraproject.org b/inventory/host_vars/memcached01.iad2.fedoraproject.org index 61938ff27f..d3102fbd5e 100644 --- a/inventory/host_vars/memcached01.iad2.fedoraproject.org +++ b/inventory/host_vars/memcached01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.163.59 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/memcached01.stg.iad2.fedoraproject.org b/inventory/host_vars/memcached01.stg.iad2.fedoraproject.org index 179dc3e9cd..ca7d17f1ad 100644 --- a/inventory/host_vars/memcached01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/memcached01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.166.41 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-backend01.iad2.fedoraproject.org b/inventory/host_vars/mm-backend01.iad2.fedoraproject.org index a3f7c8d761..cedb9bcb72 100644 --- a/inventory/host_vars/mm-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-backend01.iad2.fedoraproject.org @@ -1,17 +1,16 @@ --- -lvm_size: 20000 -num_cpus: 2 -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.60 -vmhost: vmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 -mem_size: 16384 +dns: 10.3.163.33 +eth0_ip: 10.3.163.60 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +lvm_size: 20000 max_mem_size: 16384 - +mem_size: 16384 # nfs mount options, overrides the all/default nfs_mount_opts: "ro,hard,bg,intr,nodev,nosuid,nfsvers=3" +nm: 255.255.255.0 +num_cpus: 2 +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-backend01.stg.iad2.fedoraproject.org b/inventory/host_vars/mm-backend01.stg.iad2.fedoraproject.org index 686b7aab3a..8be5f66b76 100644 --- a/inventory/host_vars/mm-backend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-backend01.stg.iad2.fedoraproject.org @@ -1,17 +1,16 @@ --- -lvm_size: 20000 -num_cpus: 2 -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.25 -vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org datacenter: iad2 -mem_size: 16384 +dns: 10.3.163.33 +eth0_ip: 10.3.166.25 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +lvm_size: 20000 max_mem_size: 16384 - +mem_size: 16384 # nfs mount options, overrides the all/default nfs_mount_opts: "ro,hard,bg,intr,nodev,nosuid,nfsvers=3" +nm: 255.255.255.0 +num_cpus: 2 +vmhost: vmhost-x86-10.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-crawler01.iad2.fedoraproject.org b/inventory/host_vars/mm-crawler01.iad2.fedoraproject.org index d253723821..8d18ebf12e 100644 --- a/inventory/host_vars/mm-crawler01.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-crawler01.iad2.fedoraproject.org @@ -1,13 +1,13 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.62 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 20000 mem_size: 40960 -num_cpus: 4 nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.62 +num_cpus: 4 vmhost: vmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-crawler01.stg.iad2.fedoraproject.org b/inventory/host_vars/mm-crawler01.stg.iad2.fedoraproject.org index 8e515b9f4f..3ccc678955 100644 --- a/inventory/host_vars/mm-crawler01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-crawler01.stg.iad2.fedoraproject.org @@ -1,14 +1,14 @@ --- -lvm_size: 20000 -mem_size: 40960 -max_mem_size: 65536 -num_cpus: 4 -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.26 -vmhost: vmhost-x86-09.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.26 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +lvm_size: 20000 +max_mem_size: 65536 +mem_size: 40960 +nm: 255.255.255.0 +num_cpus: 4 +vmhost: vmhost-x86-09.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-crawler02.iad2.fedoraproject.org b/inventory/host_vars/mm-crawler02.iad2.fedoraproject.org index 33dc72e57b..c70dab4b34 100644 --- a/inventory/host_vars/mm-crawler02.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-crawler02.iad2.fedoraproject.org @@ -1,13 +1,13 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.96 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 20000 mem_size: 40960 -num_cpus: 4 nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.96 +num_cpus: 4 vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-frontend-checkin01.iad2.fedoraproject.org b/inventory/host_vars/mm-frontend-checkin01.iad2.fedoraproject.org index 838685496c..d6a142c444 100644 --- a/inventory/host_vars/mm-frontend-checkin01.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-frontend-checkin01.iad2.fedoraproject.org @@ -1,25 +1,22 @@ --- -lvm_size: 20000 -mem_size: 8192 -num_cpus: 2 -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.91 -vmhost: vmhost-x86-04.iad2.fedoraproject.org -datacenter: iad2 - -tcp_ports: [ 80, 443 ] -fedmsg_certs: [] - -mm2_checkin: true - -csi_security_category: High csi_primary_contact: Fedora Admins - admin@fedoraproject.org csi_purpose: MirrorManager Checkin endpoint csi_relationship: | - Has a very restricted set of in/out communication allowed, due to - special circumstances. For details, ask puiterwijk. + Has a very restricted set of in/out communication allowed, due to + special circumstances. For details, ask puiterwijk. +csi_security_category: High +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.91 +fedmsg_certs: [] +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +lvm_size: 20000 +mem_size: 8192 +mm2_checkin: true +nm: 255.255.255.0 +num_cpus: 2 +tcp_ports: [80, 443] +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-frontend01.iad2.fedoraproject.org b/inventory/host_vars/mm-frontend01.iad2.fedoraproject.org index 69f3fcd2eb..4cf2741cb2 100644 --- a/inventory/host_vars/mm-frontend01.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-frontend01.iad2.fedoraproject.org @@ -1,15 +1,14 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.61 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 20000 mem_size: 8192 -num_cpus: 2 nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.61 +num_cpus: 2 +tcp_ports: [80, 443] vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 - -tcp_ports: [ 80, 443 ] +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/mm-frontend01.stg.iad2.fedoraproject.org b/inventory/host_vars/mm-frontend01.stg.iad2.fedoraproject.org index 9d908ea9d2..e00d4bbc2c 100644 --- a/inventory/host_vars/mm-frontend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/mm-frontend01.stg.iad2.fedoraproject.org @@ -1,15 +1,14 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.27 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 20000 mem_size: 8192 -num_cpus: 2 nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.27 +num_cpus: 2 +tcp_ports: [80, 443] vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org -datacenter: iad2 - -tcp_ports: [ 80, 443 ] +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/noc01.iad2.fedoraproject.org b/inventory/host_vars/noc01.iad2.fedoraproject.org index 5b2bb9fd11..7dd87f1127 100644 --- a/inventory/host_vars/noc01.iad2.fedoraproject.org +++ b/inventory/host_vars/noc01.iad2.fedoraproject.org @@ -1,27 +1,19 @@ --- -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.10 -vmhost: vmhost-x86-02.iad2.fedoraproject.org - -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - +custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.1.20 --dport 5666 -j ACCEPT'] datacenter: iad2 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +dns: 10.3.163.33 +eth0_ip: 10.3.163.10 +gw: 10.3.163.254 ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext # Define resources for this group of hosts here. lvm_size: 20000 mem_size: 8192 -num_cpus: 4 - -tcp_ports: ['22', '80', '443', '67', '68'] -udp_ports: ['67','68','69'] -custom_rules: [ - '-A INPUT -p tcp -m tcp -s 192.168.1.20 --dport 5666 -j ACCEPT', -] - -nagios_srcdir: 'nagios' nagios_location: 'iad2_internal' +nagios_srcdir: 'nagios' +nm: 255.255.255.0 +num_cpus: 4 +tcp_ports: ['22', '80', '443', '67', '68'] +udp_ports: ['67', '68', '69'] +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/noc02.fedoraproject.org b/inventory/host_vars/noc02.fedoraproject.org index 9f49586797..003e663031 100644 --- a/inventory/host_vars/noc02.fedoraproject.org +++ b/inventory/host_vars/noc02.fedoraproject.org @@ -1,61 +1,55 @@ --- -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests +csi_relationship: | + noc02 is the external monitoring nagios instance. + + * This host relies on: + - the virthost it's hosted on (ibiblio04.fedoraproject.org) + - FAS to authenticate users + - VPN connectivity + + * Things that rely on this host: + - Infrastructure team to be awair of the infra status. operations control process will be affected + - if this host is down, it will be difficult to know the status of infra and provide reactive/proactive support +datacenter: ibiblio +dns1: 152.2.21.1 +dns2: 152.2.253.100 +dns_search1: vpn.fedoraproject.org +dns_search2: fedoraproject.org eth0_ipv4: 152.19.134.192 -has_ipv6: yes +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed9" -eth0_ipv6_nm: 104 eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext +nagios_location: 'external' +nagios_srcdir: 'nagios' +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + gateway6: "{{ eth0_ipv6_gw }}" + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +postfix_group: vpn postfix_maincf: "postfix/main.cf/main.cf.noc02.fedoraproject.org" postfix_mastercf: "postfix/master.cf/master.cf.noc02.fedoraproject.org" postfix_transport_filename: transports.noc02.fedoraproject.org - -dns1: 152.2.21.1 -dns2: 152.2.253.100 - -dns_search1: vpn.fedoraproject.org -dns_search2: fedoraproject.org - -network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - vmhost: ibiblio01.fedoraproject.org -datacenter: ibiblio -postfix_group: vpn +volgroup: /dev/vg_guests vpn: true -csi_relationship: | - noc02 is the external monitoring nagios instance. - - * This host relies on: - - the virthost it's hosted on (ibiblio04.fedoraproject.org) - - FAS to authenticate users - - VPN connectivity - - * Things that rely on this host: - - Infrastructure team to be awair of the infra status. operations control process will be affected - - if this host is down, it will be difficult to know the status of infra and provide reactive/proactive support - -nagios_srcdir: 'nagios' -nagios_location: 'external' - diff --git a/inventory/host_vars/notifs-backend01.iad2.fedoraproject.org b/inventory/host_vars/notifs-backend01.iad2.fedoraproject.org index d5cec93e0c..8d9bef3e31 100644 --- a/inventory/host_vars/notifs-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/notifs-backend01.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.63 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-27 -ks_repo: http://10.3.163.35/pub/archive/fedora/linux/releases/27/Server/x86_64/os/ - -vmhost: vmhost-x86-06.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.63 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/archive/fedora/linux/releases/27/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-27 +nm: 255.255.255.0 +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/notifs-backend02.iad2.fedoraproject.org b/inventory/host_vars/notifs-backend02.iad2.fedoraproject.org index 5dd483d5d3..b8bb55988b 100644 --- a/inventory/host_vars/notifs-backend02.iad2.fedoraproject.org +++ b/inventory/host_vars/notifs-backend02.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.107 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -vmhost: vmhost-x86-05.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.107 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/notifs-web01.iad2.fedoraproject.org b/inventory/host_vars/notifs-web01.iad2.fedoraproject.org index b259417e45..442b447dbe 100644 --- a/inventory/host_vars/notifs-web01.iad2.fedoraproject.org +++ b/inventory/host_vars/notifs-web01.iad2.fedoraproject.org @@ -1,20 +1,18 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.64 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 20000 mem_size: 8192 -num_cpus: 2 nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.64 -vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 - -tcp_ports: [ 80, 443 ] - +num_cpus: 2 +sar_output_file: fmn.json # GDPR SAR variables sar_script: /usr/local/bin/fmn-sar.py sar_script_user: apache -sar_output_file: fmn.json +tcp_ports: [80, 443] +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/notifs-web02.iad2.fedoraproject.org b/inventory/host_vars/notifs-web02.iad2.fedoraproject.org index 817553d750..ffb27fe4cf 100644 --- a/inventory/host_vars/notifs-web02.iad2.fedoraproject.org +++ b/inventory/host_vars/notifs-web02.iad2.fedoraproject.org @@ -1,20 +1,18 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.108 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 20000 mem_size: 8192 -num_cpus: 2 nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.108 -vmhost: vmhost-x86-04.iad2.fedoraproject.org -datacenter: iad2 - -tcp_ports: [ 80, 443 ] - +num_cpus: 2 +sar_output_file: fmn.json # GDPR SAR variables sar_script: /usr/local/bin/fmn-sar.py sar_script_user: apache -sar_output_file: fmn.json +tcp_ports: [80, 443] +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ns01.iad2.fedoraproject.org b/inventory/host_vars/ns01.iad2.fedoraproject.org index 2639fdbe57..7a9b7f4e91 100644 --- a/inventory/host_vars/ns01.iad2.fedoraproject.org +++ b/inventory/host_vars/ns01.iad2.fedoraproject.org @@ -1,15 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -vmhost: vmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.33 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ns02.fedoraproject.org b/inventory/host_vars/ns02.fedoraproject.org index 664b657853..5928c06c9f 100644 --- a/inventory/host_vars/ns02.fedoraproject.org +++ b/inventory/host_vars/ns02.fedoraproject.org @@ -1,61 +1,52 @@ --- -volgroup: /dev/vg_guests +csi_relationship: |2 + ns02 is a master dns server. + It serves about every domain under fedoraproject, fedo*, as well as others, both forward and reverse. -eth0_ipv4: 152.19.134.139 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed7" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" + * This host relies on: + - The virthost it's hosted on (ibiblio05.fedoraproject.org) + - batcave for dns git and keys + - connectivity to maxmind to create geoIP dns acl -postfix_group: vpn -vpn: true - -vmhost: ibiblio05.fedoraproject.org + * Things that rely on this host: + - The Internet/Community to resolve everything related to fedora and reverse-IP for allocated subnets + - If this host is down, dns queries will slow down by the portion of this host to the total name servers responsible for the same domain set. + - secodary/slave dns servers datacenter: ibiblio - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - dns1: 152.2.21.1 dns2: 152.2.253.100 - dns_search1: vpn.fedoraproject.org dns_search2: fedoraproject.org - +eth0_ipv4: 152.19.134.139 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed7" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -csi_relationship: | - - ns02 is a master dns server. - It serves about every domain under fedoraproject, fedo*, as well as others, both forward and reverse. - - * This host relies on: - - The virthost it's hosted on (ibiblio05.fedoraproject.org) - - batcave for dns git and keys - - connectivity to maxmind to create geoIP dns acl - - * Things that rely on this host: - - The Internet/Community to resolve everything related to fedora and reverse-IP for allocated subnets - - If this host is down, dns queries will slow down by the portion of this host to the total name servers responsible for the same domain set. - - secodary/slave dns servers + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +postfix_group: vpn +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/ns02.iad2.fedoraproject.org b/inventory/host_vars/ns02.iad2.fedoraproject.org index e28d4378bc..b02e96964d 100644 --- a/inventory/host_vars/ns02.iad2.fedoraproject.org +++ b/inventory/host_vars/ns02.iad2.fedoraproject.org @@ -1,15 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -volgroup: /dev/vg_guests - -eth0_ip: 10.3.163.34 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -vmhost: vmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.34 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ns05.fedoraproject.org b/inventory/host_vars/ns05.fedoraproject.org index 9c10eee49e..0657c22b39 100644 --- a/inventory/host_vars/ns05.fedoraproject.org +++ b/inventory/host_vars/ns05.fedoraproject.org @@ -1,36 +1,29 @@ --- -nm: 255.255.255.240 -gw: 85.236.55.1 +csi_relationship: |2 + ns05 is a master dns server. + It serves about every domain under fedoraproject, fedo*, as well as others, both forward and reverse. + + * This host relies on: + - The virthost it's hosted on (internetx01.fedoraproject.org) + - batcave for dns git and keys + - connectivity to maxmind to create geoIP dns acl + + * Things that rely on this host: + - The Internet/Community to resolve everything related to fedora and reverse-IP for allocated subnets + - If this host is down, dns queries will slow down by the portion of this host to the total name servers responsible for the same domain set. + - secodary/slave dns servers +datacenter: internetx dns: 62.116.130.3 - -volgroup: /dev/vg_Server - -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ - eth0_ip: 85.236.55.10 -eth0_nm: 255.255.255.240 -has_ipv6: yes eth0_ipv6: "2001:4178:2:1269:dead:beef:cafe:fed5" eth0_ipv6_gw: "2001:4178:2:1269::1" - +eth0_nm: 255.255.255.240 +gw: 85.236.55.1 +has_ipv6: yes +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext +nm: 255.255.255.240 postfix_group: vpn -vpn: true - vmhost: internetx01.fedoraproject.org -datacenter: internetx - -csi_relationship: | - - ns05 is a master dns server. - It serves about every domain under fedoraproject, fedo*, as well as others, both forward and reverse. - - * This host relies on: - - The virthost it's hosted on (internetx01.fedoraproject.org) - - batcave for dns git and keys - - connectivity to maxmind to create geoIP dns acl - - * Things that rely on this host: - - The Internet/Community to resolve everything related to fedora and reverse-IP for allocated subnets - - If this host is down, dns queries will slow down by the portion of this host to the total name servers responsible for the same domain set. - - secodary/slave dns servers +volgroup: /dev/vg_Server +vpn: true diff --git a/inventory/host_vars/ns13.rdu2.fedoraproject.org b/inventory/host_vars/ns13.rdu2.fedoraproject.org index 126bc4925a..150dccad9d 100644 --- a/inventory/host_vars/ns13.rdu2.fedoraproject.org +++ b/inventory/host_vars/ns13.rdu2.fedoraproject.org @@ -1,36 +1,27 @@ --- -nm: 255.255.255.0 -gw: 172.31.2.254 +ansible_ssh_common_args: '-o ProxyCommand="ssh -W %h:%p -q root@bastion13.fedoraproject.org"' +datacenter: rdu dns: 8.8.8.8 dns1: 8.8.8.8 dns2: 8.8.4.4 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -vmhost: virthost-rdu01.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 172.31.2.24 eth0_nm: 255.255.255.0 - -public_ip: 209.132.190.1 - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat -datacenter: rdu -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -ansible_ssh_common_args: '-o ProxyCommand="ssh -W %h:%p -q root@bastion13.fedoraproject.org"' - +gw: 172.31.2.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext nagios_Can_Connect: false - nagios_Check_Services: - nrpe: false mail: false + nrpe: false + ping: false sshd: false swap: false - ping: false +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +public_ip: 209.132.190.1 +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: virthost-rdu01.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/nuancier01.iad2.fedoraproject.org b/inventory/host_vars/nuancier01.iad2.fedoraproject.org index 5d5bd31322..2b65616628 100644 --- a/inventory/host_vars/nuancier01.iad2.fedoraproject.org +++ b/inventory/host_vars/nuancier01.iad2.fedoraproject.org @@ -1,17 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.99 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.99 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +tcp_ports: [80] +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] diff --git a/inventory/host_vars/nuancier02.iad2.fedoraproject.org b/inventory/host_vars/nuancier02.iad2.fedoraproject.org index e51c3b4ee4..b2b545dae0 100644 --- a/inventory/host_vars/nuancier02.iad2.fedoraproject.org +++ b/inventory/host_vars/nuancier02.iad2.fedoraproject.org @@ -1,17 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.100 -vmhost: vmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.163.100 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +tcp_ports: [80] +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests wsgi_procs: 2 wsgi_threads: 2 - -tcp_ports: [ 80 ] diff --git a/inventory/host_vars/oci-candidate-registry01.iad2.fedoraproject.org b/inventory/host_vars/oci-candidate-registry01.iad2.fedoraproject.org index 15b384577b..16a4ae5ee6 100644 --- a/inventory/host_vars/oci-candidate-registry01.iad2.fedoraproject.org +++ b/inventory/host_vars/oci-candidate-registry01.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.102 -vmhost: bvmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.102 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 750g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/oci-candidate-registry01.stg.iad2.fedoraproject.org b/inventory/host_vars/oci-candidate-registry01.stg.iad2.fedoraproject.org index c4f703e7fd..f22c78500d 100644 --- a/inventory/host_vars/oci-candidate-registry01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/oci-candidate-registry01.stg.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.34 -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.167.34 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 120g -mem_size: 8192 max_mem_size: 16384 +mem_size: 8192 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/oci-registry01.iad2.fedoraproject.org b/inventory/host_vars/oci-registry01.iad2.fedoraproject.org index c2f017aa1a..06e6f7f090 100644 --- a/inventory/host_vars/oci-registry01.iad2.fedoraproject.org +++ b/inventory/host_vars/oci-registry01.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.119 -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.119 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/oci-registry01.stg.iad2.fedoraproject.org b/inventory/host_vars/oci-registry01.stg.iad2.fedoraproject.org index 27cd6a70f1..58eec9937d 100644 --- a/inventory/host_vars/oci-registry01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/oci-registry01.stg.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.35 -vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.167.35 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 120g -mem_size: 8192 max_mem_size: 16384 +mem_size: 8192 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/oci-registry02.iad2.fedoraproject.org b/inventory/host_vars/oci-registry02.iad2.fedoraproject.org index bb2ec4c68c..4f094d9e93 100644 --- a/inventory/host_vars/oci-registry02.iad2.fedoraproject.org +++ b/inventory/host_vars/oci-registry02.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.127 -vmhost: bvmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.127 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ocp01.ocp.iad2.fedoraproject.org b/inventory/host_vars/ocp01.ocp.iad2.fedoraproject.org index d964a6e3d6..db26908a3f 100644 --- a/inventory/host_vars/ocp01.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp01.ocp.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-04.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.120 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.120 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.163.65/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.163.65/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/ocp01.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/ocp01.ocp.stg.iad2.fedoraproject.org index 30572a6cdd..b3cafcbe1f 100644 --- a/inventory/host_vars/ocp01.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp01.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.115 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.115 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/ocp02.ocp.iad2.fedoraproject.org b/inventory/host_vars/ocp02.ocp.iad2.fedoraproject.org index 78d0d4424e..2aeba843f2 100644 --- a/inventory/host_vars/ocp02.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp02.ocp.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-05.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.121 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.121 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.163.65/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.163.65/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/ocp02.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/ocp02.ocp.stg.iad2.fedoraproject.org index 9055eda7a3..dba2347b6d 100644 --- a/inventory/host_vars/ocp02.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp02.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.116 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.116 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/ocp03.ocp.iad2.fedoraproject.org b/inventory/host_vars/ocp03.ocp.iad2.fedoraproject.org index ffc859888e..e6ab47d8f8 100644 --- a/inventory/host_vars/ocp03.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp03.ocp.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-06.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.122 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.122 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.163.65/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.163.65/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/ocp03.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/ocp03.ocp.stg.iad2.fedoraproject.org index 8d44be51b4..d3cb25da0a 100644 --- a/inventory/host_vars/ocp03.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/ocp03.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.117 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.117 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/controlplane.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/odcs-backend-releng01.iad2.fedoraproject.org b/inventory/host_vars/odcs-backend-releng01.iad2.fedoraproject.org index 535c9b1d2e..08cf6c7e74 100644 --- a/inventory/host_vars/odcs-backend-releng01.iad2.fedoraproject.org +++ b/inventory/host_vars/odcs-backend-releng01.iad2.fedoraproject.org @@ -1,18 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ - -eth0_ip: 10.3.169.130 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-08.iad2.fedoraproject.org - datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.130 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 lvm_size: 200000 mem_size: 65536 +nm: 255.255.255.0 num_cpus: 16 +vmhost: bvmhost-x86-08.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/odcs-backend01.iad2.fedoraproject.org b/inventory/host_vars/odcs-backend01.iad2.fedoraproject.org index 4749b4efa7..9f7bfe1525 100644 --- a/inventory/host_vars/odcs-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/odcs-backend01.iad2.fedoraproject.org @@ -1,16 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.169.110 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-03.iad2.fedoraproject.org - datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.110 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/odcs-backend01.stg.iad2.fedoraproject.org b/inventory/host_vars/odcs-backend01.stg.iad2.fedoraproject.org index 74b3ef035f..38ac1ca395 100644 --- a/inventory/host_vars/odcs-backend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/odcs-backend01.stg.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.167.36 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.167.36 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/odcs-frontend01.iad2.fedoraproject.org b/inventory/host_vars/odcs-frontend01.iad2.fedoraproject.org index 74280c550b..3e64495dad 100644 --- a/inventory/host_vars/odcs-frontend01.iad2.fedoraproject.org +++ b/inventory/host_vars/odcs-frontend01.iad2.fedoraproject.org @@ -1,16 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.169.111 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-04.iad2.fedoraproject.org - datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.111 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/odcs-frontend01.stg.iad2.fedoraproject.org b/inventory/host_vars/odcs-frontend01.stg.iad2.fedoraproject.org index ac38ad7160..a9305a0aef 100644 --- a/inventory/host_vars/odcs-frontend01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/odcs-frontend01.stg.iad2.fedoraproject.org @@ -1,14 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -eth0_ip: 10.3.167.37 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org - datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.37 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/openqa-a64-worker01.iad2.fedoraproject.org b/inventory/host_vars/openqa-a64-worker01.iad2.fedoraproject.org index 4ba5d0b512..bd28ca4bb6 100644 --- a/inventory/host_vars/openqa-a64-worker01.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-a64-worker01.iad2.fedoraproject.org @@ -1,4 +1,15 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_mac: "{{ mac1 }}" +eth1_ipv4: 10.3.174.61 +eth1_ipv4_gw: 10.3.174.254 +eth1_ipv4_nm: 24 +eth1_mac: "{{ mac2 }}" +eth2_mac: "{{ mac3 }}" freezes: false # eth0 is disabled/nothing # eth1 is active network @@ -6,73 +17,49 @@ freezes: false # NOTE network configuration beyond the scope of linux-system-roles on # this host is performed by the openqa/worker role -datacenter: iad2 - +has_ipv4: yes mac1: 00:1b:21:e0:78:b2 mac2: 50:6b:4b:7f:96:30 mac3: 50:6b:4b:7f:96:31 - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -eth0_mac: "{{ mac1 }}" - -eth1_ipv4: 10.3.174.61 -eth1_ipv4_nm: 24 -eth1_ipv4_gw: 10.3.174.254 -eth1_mac: "{{ mac2 }}" - -eth2_mac: "{{ mac3 }}" - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: down - type: ethernet - autoconnect: no -- name: eth1 - mac: "{{ eth1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ eth2_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 250 + - autoconnect: no + mac: "{{ eth0_mac }}" + name: eth0 + state: down + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ eth1_mac }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ eth2_mac }}" + name: eth2 + state: down + type: ethernet nrpe_procs_crit: 300 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - +nrpe_procs_warn: 250 +# has an HW RNG, so let's have rngd +openqa_rngd: true openqa_tap_iface: eth1 - # this is a powerful machine, can handle more openQA workers openqa_workers: 15 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: # $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002; # so for worker 1 it's 20012, for worker 2 it's 20022, etc etc tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153'] - -# has an HW RNG, so let's have rngd -openqa_rngd: true diff --git a/inventory/host_vars/openqa-a64-worker02.iad2.fedoraproject.org b/inventory/host_vars/openqa-a64-worker02.iad2.fedoraproject.org index 3c4d2d4051..e9729f9bd7 100644 --- a/inventory/host_vars/openqa-a64-worker02.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-a64-worker02.iad2.fedoraproject.org @@ -1,4 +1,15 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_mac: "{{ mac1 }}" +eth1_ipv4: 10.3.174.62 +eth1_ipv4_gw: 10.3.174.254 +eth1_ipv4_nm: 24 +eth1_mac: "{{ mac2 }}" +eth2_mac: "{{ mac3 }}" freezes: false # eth0 is disabled/nothing # eth1 is active network @@ -6,73 +17,49 @@ freezes: false # NOTE network configuration beyond the scope of linux-system-roles on # this host is performed by the openqa/worker role -datacenter: iad2 - +has_ipv4: yes mac1: 00:1b:21:e0:6a:72 mac2: 50:6b:4b:7f:a8:b0 mac3: 50:6b:4b:7f:a8:b1 - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -eth0_mac: "{{ mac1 }}" - -eth1_ipv4: 10.3.174.62 -eth1_ipv4_nm: 24 -eth1_ipv4_gw: 10.3.174.254 -eth1_mac: "{{ mac2 }}" - -eth2_mac: "{{ mac3 }}" - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: down - type: ethernet - autoconnect: no -- name: eth1 - mac: "{{ eth1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ eth2_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 250 + - autoconnect: no + mac: "{{ eth0_mac }}" + name: eth0 + state: down + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ eth1_mac }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ eth2_mac }}" + name: eth2 + state: down + type: ethernet nrpe_procs_crit: 300 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - +nrpe_procs_warn: 250 +# has an HW RNG, so let's have rngd +openqa_rngd: true openqa_tap_iface: eth1 - # this is a powerful machine, can handle more openQA workers openqa_workers: 15 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: # $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002; # so for worker 1 it's 20012, for worker 2 it's 20022, etc etc tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153'] - -# has an HW RNG, so let's have rngd -openqa_rngd: true diff --git a/inventory/host_vars/openqa-a64-worker03.iad2.fedoraproject.org b/inventory/host_vars/openqa-a64-worker03.iad2.fedoraproject.org index 03d471e66f..707527e139 100644 --- a/inventory/host_vars/openqa-a64-worker03.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-a64-worker03.iad2.fedoraproject.org @@ -1,76 +1,63 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_mac: "{{ mac1 }}" +eth1_ipv4: 10.3.174.63 +eth1_ipv4_gw: 10.3.174.254 +eth1_ipv4_nm: 24 +eth1_mac: "{{ mac2 }}" +eth2_mac: "{{ mac3 }}" freezes: false # eth0 is disabled/nothing # eth1 is active network # eth2 is disabled/nothing -datacenter: iad2 - +has_ipv4: yes mac1: 00:1b:21:e0:6e:5b mac2: 50:6b:4b:7f:98:30 mac3: 50:6b:4b:7f:98:31 - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -eth0_mac: "{{ mac1 }}" - -eth1_ipv4: 10.3.174.63 -eth1_ipv4_nm: 24 -eth1_ipv4_gw: 10.3.174.254 -eth1_mac: "{{ mac2 }}" - -eth2_mac: "{{ mac3 }}" - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: down - type: ethernet - autoconnect: no -- name: eth1 - mac: "{{ eth1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" - gateway4: "{{ eth1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: eth2 - mac: "{{ eth2_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 250 + - autoconnect: no + mac: "{{ eth0_mac }}" + name: eth0 + state: down + type: ethernet + - autoconnect: yes + ip: + address: + - "{{ eth1_ipv4 }}/{{ eth1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth1_ipv4_gw }}" + mac: "{{ eth1_mac }}" + name: eth1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ eth2_mac }}" + name: eth2 + state: down + type: ethernet nrpe_procs_crit: 300 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - +nrpe_procs_warn: 250 +# has an HW RNG, so let's have rngd +openqa_rngd: true openqa_tap_iface: eth1 - # this is a powerful machine, can handle more openQA workers openqa_workers: 15 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: # $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002; # so for worker 1 it's 20012, for worker 2 it's 20022, etc etc tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153'] - -# has an HW RNG, so let's have rngd -openqa_rngd: true diff --git a/inventory/host_vars/openqa-lab01.iad2.fedoraproject.org b/inventory/host_vars/openqa-lab01.iad2.fedoraproject.org index 68b5ea68b8..e13bda2548 100644 --- a/inventory/host_vars/openqa-lab01.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-lab01.iad2.fedoraproject.org @@ -2,32 +2,25 @@ ############################################################ # networking ############################################################ - -nm: 255.255.255.0 -gw: 10.3.174.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.174.57 - +gw: 10.3.174.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ ############################################################ # install ############################################################ - ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ -volgroup: /dev/vg_guests -vmhost: qvmhost-x86-01.iad2.fedoraproject.org -datacenter: iad2 - ############################################################ # virtual machine ############################################################ - - lvm_size: 1750000 -mem_size: 262144 -max_mem_size: 383216 -num_cpus: 60 max_cpu: 60 - -nrpe_procs_warn: 1000 +max_mem_size: 383216 +mem_size: 262144 +nm: 255.255.255.0 nrpe_procs_crit: 1200 +nrpe_procs_warn: 1000 +num_cpus: 60 +vmhost: qvmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/openqa-p09-worker01.iad2.fedoraproject.org b/inventory/host_vars/openqa-p09-worker01.iad2.fedoraproject.org index e537c6681b..c9357a0adf 100644 --- a/inventory/host_vars/openqa-p09-worker01.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-p09-worker01.iad2.fedoraproject.org @@ -1,4 +1,15 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_ipv4: 10.3.174.42 +eth0_ipv4_gw: 10.3.174.254 +eth0_ipv4_nm: 24 +eth0_mac: "{{ mac1 }}" +eth1_mac: "{{ mac2 }}" +eth2_mac: "{{ mac3 }}" freezes: false # eth0 is default network # eth1 is disabled/nothing @@ -6,73 +17,49 @@ freezes: false # NOTE network configuration beyond the scope of linux-system-roles on # this host is performed by the openqa/worker role -datacenter: iad2 - +has_ipv4: yes mac1: 40:a6:b7:18:87:24 mac2: 40:a6:b7:18:87:25 mac3: ac:1f:6b:56:e5:90 - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -eth0_ipv4: 10.3.174.42 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.174.254 -eth0_mac: "{{ mac1 }}" - -eth1_mac: "{{ mac2 }}" - -eth2_mac: "{{ mac3 }}" - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ eth1_mac }}" - state: down - type: ethernet - autoconnect: no -- name: eth2 - mac: "{{ eth2_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 250 + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet + - autoconnect: no + mac: "{{ eth1_mac }}" + name: eth1 + state: down + type: ethernet + - autoconnect: no + mac: "{{ eth2_mac }}" + name: eth2 + state: down + type: ethernet nrpe_procs_crit: 300 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - +nrpe_procs_warn: 250 +# has an HW RNG, so let's have rngd +openqa_rngd: true openqa_tap_iface: eth0 - # this is a powerful machine, can handle more openQA workers openqa_workers: 15 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: # $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002; # so for worker 1 it's 20012, for worker 2 it's 20022, etc etc tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153'] - -# has an HW RNG, so let's have rngd -openqa_rngd: true diff --git a/inventory/host_vars/openqa-p09-worker02.iad2.fedoraproject.org b/inventory/host_vars/openqa-p09-worker02.iad2.fedoraproject.org index 681fb7cc5a..8a6fa99b32 100644 --- a/inventory/host_vars/openqa-p09-worker02.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-p09-worker02.iad2.fedoraproject.org @@ -1,76 +1,63 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_ipv4: 10.3.174.43 +eth0_ipv4_gw: 10.3.174.254 +eth0_ipv4_nm: 24 +eth0_mac: "{{ mac1 }}" +eth1_mac: "{{ mac2 }}" +eth2_mac: "{{ mac3 }}" freezes: false # eth0 is default network # eth1 is disabled/nothing # eth2 is disabled/nothing -datacenter: iad2 - +has_ipv4: yes mac1: 40:a6:b7:18:86:b8 mac2: 40:a6:b7:18:86:b9 mac3: ac:1f:6b:59:70:6e - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -eth0_ipv4: 10.3.174.43 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.174.254 -eth0_mac: "{{ mac1 }}" - -eth1_mac: "{{ mac2 }}" - -eth2_mac: "{{ mac3 }}" - network_connections: -- name: eth0 - mac: "{{ eth0_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: eth1 - mac: "{{ eth1_mac }}" - state: down - type: ethernet - autoconnect: no -- name: eth2 - mac: "{{ eth2_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 250 + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ eth0_mac }}" + name: eth0 + state: up + type: ethernet + - autoconnect: no + mac: "{{ eth1_mac }}" + name: eth1 + state: down + type: ethernet + - autoconnect: no + mac: "{{ eth2_mac }}" + name: eth2 + state: down + type: ethernet nrpe_procs_crit: 300 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - +nrpe_procs_warn: 250 +# has an HW RNG, so let's have rngd +openqa_rngd: true openqa_tap_iface: eth0 - # this is a powerful machine, can handle more openQA workers openqa_workers: 15 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: # $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002; # so for worker 1 it's 20012, for worker 2 it's 20022, etc etc tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153'] - -# has an HW RNG, so let's have rngd -openqa_rngd: true diff --git a/inventory/host_vars/openqa-x86-worker01.iad2.fedoraproject.org b/inventory/host_vars/openqa-x86-worker01.iad2.fedoraproject.org index 8c274dc8cf..5fa54135af 100644 --- a/inventory/host_vars/openqa-x86-worker01.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-x86-worker01.iad2.fedoraproject.org @@ -1,4 +1,16 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +em1_ipv4: 10.3.174.21 +em1_ipv4_gw: 10.3.174.254 +em1_ipv4_nm: 24 +em1_mac: "{{ mac1 }}" +em2_mac: "{{ mac2 }}" +em3_mac: "{{ mac3 }}" +em4_mac: "{{ mac4 }}" freezes: false # em1 is default network # em2 is disabled/nothing @@ -7,78 +19,52 @@ freezes: false # NOTE network configuration beyond the scope of linux-system-roles on # this host is performed by the openqa/worker role -datacenter: iad2 - +has_ipv4: yes mac1: e4:43:4b:a7:98:66 mac2: e4:43:4b:a7:98:68 mac3: e4:43:4b:a7:98:86 mac4: e4:43:4b:a7:98:87 - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -em1_ipv4: 10.3.174.21 -em1_ipv4_nm: 24 -em1_ipv4_gw: 10.3.174.254 -em1_mac: "{{ mac1 }}" - -em2_mac: "{{ mac2 }}" - -em3_mac: "{{ mac3 }}" - -em4_mac: "{{ mac4 }}" - network_connections: -- name: em1 - mac: "{{ em1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" - gateway4: "{{ em1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: em2 - mac: "{{ em2_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em3 - mac: "{{ em3_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em4 - mac: "{{ em4_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 1400 + - autoconnect: yes + ip: + address: + - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ em1_ipv4_gw }}" + mac: "{{ em1_mac }}" + name: em1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ em2_mac }}" + name: em2 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em3_mac }}" + name: em3 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em4_mac }}" + name: em4 + state: down + type: ethernet nrpe_procs_crit: 1600 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - -openqa_tap_iface: em1 - +nrpe_procs_warn: 1400 # Has a hardware RNG openqa_rngd: true - +openqa_tap_iface: em1 # this is a powerful machine, can handle more openQA workers openqa_workers: 30 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: diff --git a/inventory/host_vars/openqa-x86-worker02.iad2.fedoraproject.org b/inventory/host_vars/openqa-x86-worker02.iad2.fedoraproject.org index c97cc86126..51e62a0b8f 100644 --- a/inventory/host_vars/openqa-x86-worker02.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-x86-worker02.iad2.fedoraproject.org @@ -1,82 +1,68 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +em1_ipv4: 10.3.174.22 +em1_ipv4_gw: 10.3.174.254 +em1_ipv4_nm: 24 +em1_mac: "{{ mac1 }}" +em2_mac: "{{ mac2 }}" +em3_mac: "{{ mac3 }}" +em4_mac: "{{ mac4 }}" freezes: false # em1 is default network # em2 is disabled/nothing # em3 is disabled/nothing # em4 is disabled/nothing -datacenter: iad2 - +has_ipv4: yes mac1: e4:43:4b:23:e8:cc mac2: e4:43:4b:23:e8:ce mac3: e4:43:4b:23:e8:ec mac4: e4:43:4b:23:e8:ed - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -em1_ipv4: 10.3.174.22 -em1_ipv4_nm: 24 -em1_ipv4_gw: 10.3.174.254 -em1_mac: "{{ mac1 }}" - -em2_mac: "{{ mac2 }}" - -em3_mac: "{{ mac3 }}" - -em4_mac: "{{ mac4 }}" - network_connections: -- name: em1 - mac: "{{ em1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" - gateway4: "{{ em1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: em2 - mac: "{{ em2_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em3 - mac: "{{ em3_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em4 - mac: "{{ em4_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 1400 + - autoconnect: yes + ip: + address: + - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ em1_ipv4_gw }}" + mac: "{{ em1_mac }}" + name: em1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ em2_mac }}" + name: em2 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em3_mac }}" + name: em3 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em4_mac }}" + name: em4 + state: down + type: ethernet nrpe_procs_crit: 1600 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - -openqa_tap_iface: em1 - +nrpe_procs_warn: 1400 # Has a hardware RNG openqa_rngd: true - +openqa_tap_iface: em1 # this is a powerful machine, can handle more openQA workers openqa_workers: 30 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: diff --git a/inventory/host_vars/openqa-x86-worker04.iad2.fedoraproject.org b/inventory/host_vars/openqa-x86-worker04.iad2.fedoraproject.org index b08937224f..4bca4a42b7 100644 --- a/inventory/host_vars/openqa-x86-worker04.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa-x86-worker04.iad2.fedoraproject.org @@ -1,4 +1,16 @@ --- +datacenter: iad2 +dns1: 10.3.163.33 +dns2: 10.3.163.34 +dns_search1: "iad2.fedoraproject.org" +dns_search2: "fedoraproject.org" +em1_ipv4: 10.3.174.24 +em1_ipv4_gw: 10.3.174.254 +em1_ipv4_nm: 24 +em1_mac: "{{ mac1 }}" +em2_mac: "{{ mac2 }}" +em3_mac: "{{ mac3 }}" +em4_mac: "{{ mac4 }}" freezes: false # em1 is default network # em2 is disabled/nothing @@ -7,78 +19,52 @@ freezes: false # NOTE network configuration beyond the scope of linux-system-roles on # this host is performed by the openqa/worker role -datacenter: iad2 - +has_ipv4: yes mac1: e4:43:4b:24:10:aa mac2: e4:43:4b:24:10:ca mac3: e4:43:4b:24:10:ac mac4: e4:43:4b:24:10:cb - -dns1: 10.3.163.33 -dns2: 10.3.163.34 - -dns_search1: "iad2.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes - -em1_ipv4: 10.3.174.24 -em1_ipv4_nm: 24 -em1_ipv4_gw: 10.3.174.254 -em1_mac: "{{ mac1 }}" - -em2_mac: "{{ mac2 }}" - -em3_mac: "{{ mac3 }}" - -em4_mac: "{{ mac4 }}" - network_connections: -- name: em1 - mac: "{{ em1_mac }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" - gateway4: "{{ em1_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no -- name: em2 - mac: "{{ em2_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em3 - mac: "{{ em3_mac }}" - state: down - type: ethernet - autoconnect: no -- name: em4 - mac: "{{ em4_mac }}" - state: down - type: ethernet - autoconnect: no - -nrpe_procs_warn: 1400 + - autoconnect: yes + ip: + address: + - "{{ em1_ipv4 }}/{{ em1_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ em1_ipv4_gw }}" + mac: "{{ em1_mac }}" + name: em1 + state: up + type: ethernet + - autoconnect: no + mac: "{{ em2_mac }}" + name: em2 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em3_mac }}" + name: em3 + state: down + type: ethernet + - autoconnect: no + mac: "{{ em4_mac }}" + name: em4 + state: down + type: ethernet nrpe_procs_crit: 1600 - -sudoers: "{{ private }}/files/sudo/qavirt-sudoers" - -openqa_tap_iface: em1 - +nrpe_procs_warn: 1400 # Has a hardware RNG openqa_rngd: true - +openqa_tap_iface: em1 # this is a powerful machine, can handle more openQA workers openqa_workers: 20 +sudoers: "{{ private }}/files/sudo/qavirt-sudoers" # firewall ports for server->worker websockets connections # this port is 'QEMUPORT plus 1' # QEMUPORT is: diff --git a/inventory/host_vars/openqa01.iad2.fedoraproject.org b/inventory/host_vars/openqa01.iad2.fedoraproject.org index a15f513945..6753232609 100644 --- a/inventory/host_vars/openqa01.iad2.fedoraproject.org +++ b/inventory/host_vars/openqa01.iad2.fedoraproject.org @@ -2,30 +2,23 @@ ############################################################ # networking ############################################################ - -nm: 255.255.255.0 -gw: 10.3.174.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.174.52 - +gw: 10.3.174.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ ############################################################ # install ############################################################ - ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-32-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/32/Server/x86_64/os/ -volgroup: /dev/vg_guests -vmhost: qvmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - ############################################################ # virtual machine ############################################################ - - lvm_size: 800000 mem_size: 16384 -num_cpus: 8 - -nrpe_procs_warn: 250 +nm: 255.255.255.0 nrpe_procs_crit: 300 +nrpe_procs_warn: 250 +num_cpus: 8 +vmhost: qvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-control01.iad2.fedoraproject.org b/inventory/host_vars/os-control01.iad2.fedoraproject.org index e99efb69b6..f2c35d5e8a 100644 --- a/inventory/host_vars/os-control01.iad2.fedoraproject.org +++ b/inventory/host_vars/os-control01.iad2.fedoraproject.org @@ -1,25 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.65 -vmhost: vmhost-x86-01.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: true -vpn: false - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.65 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-control01.stg.iad2.fedoraproject.org b/inventory/host_vars/os-control01.stg.iad2.fedoraproject.org index b1764193ab..1cf7200f70 100644 --- a/inventory/host_vars/os-control01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-control01.stg.iad2.fedoraproject.org @@ -1,16 +1,13 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.50 -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +baseiptables: true datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.50 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 lvm_size: 100g mem_size: 4096 - -baseiptables: true +nm: 255.255.255.0 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-master01.iad2.fedoraproject.org b/inventory/host_vars/os-master01.iad2.fedoraproject.org index c1797ed8d0..f25e40fc73 100644 --- a/inventory/host_vars/os-master01.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master01.iad2.fedoraproject.org @@ -1,25 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.66 -vmhost: vmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.66 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-master01.stg.iad2.fedoraproject.org b/inventory/host_vars/os-master01.stg.iad2.fedoraproject.org index 493bad73ad..8a3a0eb941 100644 --- a/inventory/host_vars/os-master01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master01.stg.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.51 -vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.51 +gw: 10.3.166.254 host_group: os-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: vmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-master02.iad2.fedoraproject.org b/inventory/host_vars/os-master02.iad2.fedoraproject.org index 556e205216..1d2fc7826b 100644 --- a/inventory/host_vars/os-master02.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master02.iad2.fedoraproject.org @@ -1,25 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.67 -vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.67 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-master02.stg.iad2.fedoraproject.org b/inventory/host_vars/os-master02.stg.iad2.fedoraproject.org index a4c139e412..cecf11c227 100644 --- a/inventory/host_vars/os-master02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master02.stg.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.52 -vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.52 +gw: 10.3.166.254 host_group: os-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-master03.iad2.fedoraproject.org b/inventory/host_vars/os-master03.iad2.fedoraproject.org index 3c9b568bf1..0d57fe8c80 100644 --- a/inventory/host_vars/os-master03.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master03.iad2.fedoraproject.org @@ -1,25 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.68 -vmhost: vmhost-x86-04.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.68 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-master03.stg.iad2.fedoraproject.org b/inventory/host_vars/os-master03.stg.iad2.fedoraproject.org index 2fde585d11..a64b8feeb4 100644 --- a/inventory/host_vars/os-master03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-master03.stg.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.53 -vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.53 +gw: 10.3.166.254 host_group: os-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-node01.iad2.fedoraproject.org b/inventory/host_vars/os-node01.iad2.fedoraproject.org index 6727cf6967..87971cc4f4 100644 --- a/inventory/host_vars/os-node01.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node01.iad2.fedoraproject.org @@ -1,26 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.69 -vmhost: vmhost-x86-05.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -mem_size: 24576 -max_mem_size: 24576 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.69 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g +max_mem_size: 24576 +mem_size: 24576 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-node01.stg.iad2.fedoraproject.org b/inventory/host_vars/os-node01.stg.iad2.fedoraproject.org index 0f741fcf44..66f2952a32 100644 --- a/inventory/host_vars/os-node01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node01.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.54 -vmhost: vmhost-x86-04.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 120g -mem_size: 49152 -max_mem_size: 73728 -num_cpus: 16 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.54 +gw: 10.3.166.254 host_group: os-stg +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 +lvm_size: 120g +max_mem_size: 73728 +mem_size: 49152 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +vmhost: vmhost-x86-04.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-node02.iad2.fedoraproject.org b/inventory/host_vars/os-node02.iad2.fedoraproject.org index 26aca99b74..33602831de 100644 --- a/inventory/host_vars/os-node02.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node02.iad2.fedoraproject.org @@ -1,26 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.70 -vmhost: vmhost-x86-06.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -mem_size: 24576 -max_mem_size: 24576 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.70 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g +max_mem_size: 24576 +mem_size: 24576 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-node02.stg.iad2.fedoraproject.org b/inventory/host_vars/os-node02.stg.iad2.fedoraproject.org index 06546b3863..9d59a62eb4 100644 --- a/inventory/host_vars/os-node02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node02.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.55 -vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 120g -mem_size: 49152 -max_mem_size: 73728 -num_cpus: 16 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.55 +gw: 10.3.166.254 host_group: os-stg +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 +lvm_size: 120g +max_mem_size: 73728 +mem_size: 49152 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-node03.iad2.fedoraproject.org b/inventory/host_vars/os-node03.iad2.fedoraproject.org index 2ac7fbf88a..b599c99df6 100644 --- a/inventory/host_vars/os-node03.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node03.iad2.fedoraproject.org @@ -1,26 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.71 -vmhost: vmhost-x86-07.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -mem_size: 24576 -max_mem_size: 24576 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.71 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g +max_mem_size: 24576 +mem_size: 24576 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-07.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-node03.stg.iad2.fedoraproject.org b/inventory/host_vars/os-node03.stg.iad2.fedoraproject.org index 018a71cd8a..7160b01556 100644 --- a/inventory/host_vars/os-node03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node03.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.56 -vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 120g -mem_size: 49152 -max_mem_size: 73728 -num_cpus: 16 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.56 +gw: 10.3.166.254 host_group: os-stg +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 +lvm_size: 120g +max_mem_size: 73728 +mem_size: 49152 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-node04.iad2.fedoraproject.org b/inventory/host_vars/os-node04.iad2.fedoraproject.org index c108014115..f930a3c85b 100644 --- a/inventory/host_vars/os-node04.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node04.iad2.fedoraproject.org @@ -1,26 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.72 -vmhost: vmhost-x86-01.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -mem_size: 24576 -max_mem_size: 24576 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.72 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g +max_mem_size: 24576 +mem_size: 24576 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-node04.stg.iad2.fedoraproject.org b/inventory/host_vars/os-node04.stg.iad2.fedoraproject.org index 2020768e56..45fcc959f6 100644 --- a/inventory/host_vars/os-node04.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node04.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.57 -vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 120g -mem_size: 49152 -max_mem_size: 73728 -num_cpus: 16 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.57 +gw: 10.3.166.254 host_group: os-stg +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 +lvm_size: 120g +max_mem_size: 73728 +mem_size: 49152 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-node05.iad2.fedoraproject.org b/inventory/host_vars/os-node05.iad2.fedoraproject.org index 09b89769f8..c50a206d35 100644 --- a/inventory/host_vars/os-node05.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node05.iad2.fedoraproject.org @@ -1,26 +1,19 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.73 -vmhost: vmhost-x86-02.iad2.fedoraproject.org -datacenter: iad2 - baseiptables: false -vpn: false - -mem_size: 24576 -max_mem_size: 24576 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.73 +gw: 10.3.163.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext lvm_size: 120g +max_mem_size: 24576 +mem_size: 24576 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - resolvconf: "resolv.conf/iad2" +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-node05.stg.iad2.fedoraproject.org b/inventory/host_vars/os-node05.stg.iad2.fedoraproject.org index 15933dae1c..b4e3e8b26e 100644 --- a/inventory/host_vars/os-node05.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/os-node05.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.58 -vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -lvm_size: 120g -mem_size: 49152 -max_mem_size: 73728 -num_cpus: 16 - +dns: 10.3.163.33 +eth0_ip: 10.3.166.58 +gw: 10.3.166.254 host_group: os-stg +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 +lvm_size: 120g +max_mem_size: 73728 +mem_size: 49152 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +num_cpus: 16 +vmhost: vmhost-x86-08.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/os-proxy01.fedorainfracloud.org b/inventory/host_vars/os-proxy01.fedorainfracloud.org index d4372d4023..ff5147bd88 100644 --- a/inventory/host_vars/os-proxy01.fedorainfracloud.org +++ b/inventory/host_vars/os-proxy01.fedorainfracloud.org @@ -1,30 +1,23 @@ --- -nm: 255.255.254.0 -gw: 38.145.49.254 dns: 8.8.8.8 -num_cpus: 4 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-29-ext -ks_repo: http://209.132.181.6/pub/fedora/linux/releases/29/Server/x86_64/os/ - -vmhost: virthost-os01.fedorainfracloud.org -volgroup: /dev/vg_guests - eth0_ip: 38.145.48.42 - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -vpn: false - -# Keepalived variables for os -keepalived_interface: eth0 -keepalived_priority: 100 -keepalived_ipaddress: 38.145.48.40 -keepalived_routerid: 20 - +gw: 38.145.49.254 # Keepalived variables for app.os keepalived2_interface: eth0 -keepalived2_priority: 50 keepalived2_ipaddress: 38.145.48.41 +keepalived2_priority: 50 keepalived2_routerid: 25 +# Keepalived variables for os +keepalived_interface: eth0 +keepalived_ipaddress: 38.145.48.40 +keepalived_priority: 100 +keepalived_routerid: 20 +ks_repo: http://209.132.181.6/pub/fedora/linux/releases/29/Server/x86_64/os/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-29-ext +nm: 255.255.254.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 +vmhost: virthost-os01.fedorainfracloud.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/os-proxy02.fedorainfracloud.org b/inventory/host_vars/os-proxy02.fedorainfracloud.org index 48722374eb..b01d980658 100644 --- a/inventory/host_vars/os-proxy02.fedorainfracloud.org +++ b/inventory/host_vars/os-proxy02.fedorainfracloud.org @@ -1,30 +1,23 @@ --- -nm: 255.255.254.0 -gw: 38.145.49.254 dns: 8.8.8.8 -num_cpus: 4 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-31-ext -ks_repo: http://209.132.181.6/pub/fedora/linux/releases/31/Server/x86_64/os/ - -vmhost: virthost-os03.fedorainfracloud.org -volgroup: /dev/vg_guests - eth0_ip: 38.145.48.43 - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -vpn: false - -# Keepalived variables for os -keepalived_interface: eth0 -keepalived_priority: 50 -keepalived_ipaddress: 38.145.48.40 -keepalived_routerid: 20 - +gw: 38.145.49.254 # Keepalived variables for app.os keepalived2_interface: eth0 -keepalived2_priority: 100 keepalived2_ipaddress: 38.145.48.41 +keepalived2_priority: 100 keepalived2_routerid: 25 +# Keepalived variables for os +keepalived_interface: eth0 +keepalived_ipaddress: 38.145.48.40 +keepalived_priority: 50 +keepalived_routerid: 20 +ks_repo: http://209.132.181.6/pub/fedora/linux/releases/31/Server/x86_64/os/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-fedora-31-ext +nm: 255.255.254.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 +vmhost: virthost-os03.fedorainfracloud.org +volgroup: /dev/vg_guests +vpn: false diff --git a/inventory/host_vars/osbs-aarch64-master01.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-master01.iad2.fedoraproject.org index efcbca8455..261eb4b130 100644 --- a/inventory/host_vars/osbs-aarch64-master01.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-master01.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.170.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.170.147 -vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.170.147 +gw: 10.3.170.254 host_group: osbs-aarch64-masters - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - +vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-aarch64-master01.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-master01.stg.iad2.fedoraproject.org index aea7676df2..25294699b7 100644 --- a/inventory/host_vars/osbs-aarch64-master01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-master01.stg.iad2.fedoraproject.org @@ -1,20 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.42 -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.42 +gw: 10.3.167.254 host_group: osbs-aarch64-masters-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-aarch64-node01.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-node01.iad2.fedoraproject.org index c556a33df7..4cada81823 100644 --- a/inventory/host_vars/osbs-aarch64-node01.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-node01.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.170.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.170.148 -vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.170.148 +gw: 10.3.170.254 host_group: osbs-aarch64-nodes - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-aarch64-node01.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-node01.stg.iad2.fedoraproject.org index 898cea7719..a29af94ab0 100644 --- a/inventory/host_vars/osbs-aarch64-node01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-node01.stg.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.43 -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.43 +gw: 10.3.167.254 host_group: osbs-aarch64-nodes-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-aarch64-node02.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-node02.iad2.fedoraproject.org index a51e2e10e4..b37bc975ad 100644 --- a/inventory/host_vars/osbs-aarch64-node02.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-node02.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.170.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.170.149 -vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.170.149 +gw: 10.3.170.254 host_group: osbs-aarch64-nodes - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-a64-osbs-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-aarch64-node02.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-aarch64-node02.stg.iad2.fedoraproject.org index ced6438ad0..14835d7147 100644 --- a/inventory/host_vars/osbs-aarch64-node02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-aarch64-node02.stg.iad2.fedoraproject.org @@ -1,19 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.167.44 -vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.44 +gw: 10.3.167.254 host_group: osbs-aarch64-nodes-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/33/Everything/aarch64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-33-aarch64-osbs lvm_size: 60g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-a64-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-control01.iad2.fedoraproject.org b/inventory/host_vars/osbs-control01.iad2.fedoraproject.org index 7705a78660..16a4bc6ffd 100644 --- a/inventory/host_vars/osbs-control01.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-control01.iad2.fedoraproject.org @@ -1,19 +1,15 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.112 -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - -mem_size: 4096 +dns: 10.3.163.33 +eth0_ip: 10.3.169.112 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 max_mem_size: 4096 - +mem_size: 4096 nagios_Check_Services: - nrpe: false mail: false + nrpe: false +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-control01.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-control01.stg.iad2.fedoraproject.org index 36df3aec99..613810b840 100644 --- a/inventory/host_vars/osbs-control01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-control01.stg.iad2.fedoraproject.org @@ -1,15 +1,12 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.167.38 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +gw: 10.3.167.254 ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - -mem_size: 4096 +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 max_mem_size: 4096 +mem_size: 4096 +nm: 255.255.255.0 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-master01.iad2.fedoraproject.org b/inventory/host_vars/osbs-master01.iad2.fedoraproject.org index a443e5516e..00a16713d0 100644 --- a/inventory/host_vars/osbs-master01.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-master01.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.113 -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.113 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-master01.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-master01.stg.iad2.fedoraproject.org index 7fe16ad35e..fe26b56ff7 100644 --- a/inventory/host_vars/osbs-master01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-master01.stg.iad2.fedoraproject.org @@ -1,22 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.167.39 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - +gw: 10.3.167.254 host_group: osbs-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-node01.iad2.fedoraproject.org b/inventory/host_vars/osbs-node01.iad2.fedoraproject.org index 6fd80ba66a..702cfaec69 100644 --- a/inventory/host_vars/osbs-node01.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-node01.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.114 -vmhost: bvmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.114 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 240g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-node01.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-node01.stg.iad2.fedoraproject.org index a75ccf6fa2..5536867d07 100644 --- a/inventory/host_vars/osbs-node01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-node01.stg.iad2.fedoraproject.org @@ -1,22 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.167.40 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - +gw: 10.3.167.254 host_group: osbs-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-node02.iad2.fedoraproject.org b/inventory/host_vars/osbs-node02.iad2.fedoraproject.org index 51ab30b6e5..d7b6ee7625 100644 --- a/inventory/host_vars/osbs-node02.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-node02.iad2.fedoraproject.org @@ -1,18 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.169.115 -vmhost: bvmhost-x86-05.iad2.fedoraproject.org datacenter: iad2 - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.115 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 240g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osbs-node02.stg.iad2.fedoraproject.org b/inventory/host_vars/osbs-node02.stg.iad2.fedoraproject.org index ea7fbcc285..47d74addbc 100644 --- a/inventory/host_vars/osbs-node02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/osbs-node02.stg.iad2.fedoraproject.org @@ -1,22 +1,17 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.167.41 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org -datacenter: iad2 - +gw: 10.3.167.254 host_group: osbs-stg - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-osbs-iad2 lvm_size: 120g -mem_size: 16384 max_mem_size: 16384 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 +vmhost: bvmhost-x86-01.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/osuosl01.fedoraproject.org b/inventory/host_vars/osuosl01.fedoraproject.org index 28a2944986..6af792c6f1 100644 --- a/inventory/host_vars/osuosl01.fedoraproject.org +++ b/inventory/host_vars/osuosl01.fedoraproject.org @@ -1,7 +1,7 @@ --- -datacenter: osuosl -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 br0_ip: 140.211.169.194 br0_nm: 255.255.255.128 +datacenter: osuosl +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virthost: true diff --git a/inventory/host_vars/osuosl02.fedoraproject.org b/inventory/host_vars/osuosl02.fedoraproject.org index 00b2185a42..2acf648a16 100644 --- a/inventory/host_vars/osuosl02.fedoraproject.org +++ b/inventory/host_vars/osuosl02.fedoraproject.org @@ -1,7 +1,7 @@ --- -datacenter: osuosl -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 br0_ip: 140.211.169.195 br0_nm: 140.211.169.194 +datacenter: osuosl +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virthost: true diff --git a/inventory/host_vars/osuosl03.fedoraproject.org b/inventory/host_vars/osuosl03.fedoraproject.org index bd2106abc3..fdeeadc694 100644 --- a/inventory/host_vars/osuosl03.fedoraproject.org +++ b/inventory/host_vars/osuosl03.fedoraproject.org @@ -1,7 +1,7 @@ --- -datacenter: osuosl -virthost: true -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 br0_ip: 140.211.169.200 br0_nm: 140.211.169.195 +datacenter: osuosl +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +virthost: true diff --git a/inventory/host_vars/pagure-stg01.fedoraproject.org b/inventory/host_vars/pagure-stg01.fedoraproject.org index 1cbba9d33b..0861da012b 100644 --- a/inventory/host_vars/pagure-stg01.fedoraproject.org +++ b/inventory/host_vars/pagure-stg01.fedoraproject.org @@ -1,32 +1,23 @@ --- -nm: 255.255.255.0 +datacenter: rdu-cc dns: 8.8.8.8 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - -volgroup: /dev/vg_server - -eth0_nm: 255.255.255.0 +effective_cache_size: "6GB" eth0_ip: 8.43.85.77 -gw: 8.43.85.254 - -has_ipv6: yes eth0_ipv6: "2620:52:3:1:dead:beef:cafe:fed3" eth0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - -vmhost: virthost-cc-rdu02.fedoraproject.org -datacenter: rdu-cc - +eth0_nm: 255.255.255.0 +gw: 8.43.85.254 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +nm: 255.255.255.0 +# DB host: +pagure_db_host: 127.0.0.1 # # PostgreSQL configuration # - shared_buffers: "2GB" -effective_cache_size: "6GB" - ssh_hostnames: -- stg.pagure.io - -# DB host: -pagure_db_host: 127.0.0.1 + - stg.pagure.io +vmhost: virthost-cc-rdu02.fedoraproject.org +volgroup: /dev/vg_server diff --git a/inventory/host_vars/pagure02.fedoraproject.org b/inventory/host_vars/pagure02.fedoraproject.org index cff919404c..1dc809ed7d 100644 --- a/inventory/host_vars/pagure02.fedoraproject.org +++ b/inventory/host_vars/pagure02.fedoraproject.org @@ -1,41 +1,31 @@ --- -nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 - -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ - -volgroup: /dev/vg_guests - +effective_cache_size: 1 eth0_ip: 8.43.85.76 -eth0_nm: 255.255.255.0 -has_ipv6: yes eth0_ipv6: "2620:52:3:1:dead:beef:cafe:fed8" eth0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - -vmhost: virthost-cc-rdu02.fedoraproject.org -datacenter: rdu-cc - -# -# PostgreSQL configuration -# - -shared_buffers: "512MB" -effective_cache_size: 1 -temp_buffers: "8MB" +eth0_nm: 255.255.255.0 +gw: 8.43.85.254 +has_ipv6: yes +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-ext max_stack_depth: "4MB" - -ssh_hostnames: -- pagure.io - +nagios_Check_Services: + swap: false +nm: 255.255.255.0 +# DB used: +pagure_db_host: 127.0.0.1 +sar_output_file: pagure.json # GDPR SAR variables - datanommer/datagrepper sar_script: /usr/local/bin/pagure_sar.py sar_script_user: git -sar_output_file: pagure.json - -# DB used: -pagure_db_host: 127.0.0.1 - -nagios_Check_Services: - swap: false +# +# PostgreSQL configuration +# +shared_buffers: "512MB" +ssh_hostnames: + - pagure.io +temp_buffers: "8MB" +vmhost: virthost-cc-rdu02.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-backend01.iad2.fedoraproject.org b/inventory/host_vars/pdc-backend01.iad2.fedoraproject.org index e3812fc900..b13582b99e 100644 --- a/inventory/host_vars/pdc-backend01.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-backend01.iad2.fedoraproject.org @@ -1,18 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.117 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-01.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.117 # These people get told when something goes wrong. fedmsg_error_recipients: -- ralph@fedoraproject.org -- mohanboddu@fedoraproject.org + - ralph@fedoraproject.org + - mohanboddu@fedoraproject.org +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-01.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-backend02.iad2.fedoraproject.org b/inventory/host_vars/pdc-backend02.iad2.fedoraproject.org index cf19e8f116..4760d08feb 100644 --- a/inventory/host_vars/pdc-backend02.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-backend02.iad2.fedoraproject.org @@ -1,20 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.125 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-05.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.125 # These people get told when something goes wrong. fedmsg_error_recipients: -- ralph@fedoraproject.org -- mprahl@redhat.com -- jkaluza@redhat.com -- fvalder@redhat.com + - ralph@fedoraproject.org + - mprahl@redhat.com + - jkaluza@redhat.com + - fvalder@redhat.com +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-backend03.iad2.fedoraproject.org b/inventory/host_vars/pdc-backend03.iad2.fedoraproject.org index 31cdd7014a..099eed81fa 100644 --- a/inventory/host_vars/pdc-backend03.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-backend03.iad2.fedoraproject.org @@ -1,20 +1,16 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.126 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 +eth0_ip: 10.3.169.126 # These people get told when something goes wrong. fedmsg_error_recipients: -- ralph@fedoraproject.org -- mprahl@redhat.com -- jkaluza@redhat.com -- fvalder@redhat.com + - ralph@fedoraproject.org + - mprahl@redhat.com + - jkaluza@redhat.com + - fvalder@redhat.com +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-web01.iad2.fedoraproject.org b/inventory/host_vars/pdc-web01.iad2.fedoraproject.org index 763fc14866..6ed46cdcdb 100644 --- a/inventory/host_vars/pdc-web01.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-web01.iad2.fedoraproject.org @@ -1,14 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.118 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.118 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 mem_size: 32768 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-web01.stg.iad2.fedoraproject.org b/inventory/host_vars/pdc-web01.stg.iad2.fedoraproject.org index 6e3c3bdd93..0f5625264a 100644 --- a/inventory/host_vars/pdc-web01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-web01.stg.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.167.26 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.26 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pdc-web02.iad2.fedoraproject.org b/inventory/host_vars/pdc-web02.iad2.fedoraproject.org index 62bdcd10b2..ca9542d4f5 100644 --- a/inventory/host_vars/pdc-web02.iad2.fedoraproject.org +++ b/inventory/host_vars/pdc-web02.iad2.fedoraproject.org @@ -1,14 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ - -eth0_ip: 10.3.169.129 - -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.129 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 mem_size: 32768 +nm: 255.255.255.0 +vmhost: bvmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/people02.fedoraproject.org b/inventory/host_vars/people02.fedoraproject.org index 937d22b440..fa2ba9e58e 100644 --- a/inventory/host_vars/people02.fedoraproject.org +++ b/inventory/host_vars/people02.fedoraproject.org @@ -1,67 +1,56 @@ --- +datacenter: ibiblio +dns1: 152.2.21.1 +dns2: 152.2.253.100 +dns_search1: vpn.fedoraproject.org +dns_search2: fedoraproject.org +eth0_ipv4: 152.19.134.199 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:00a7:9474" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +fedmsg_fqdn: people01.vpn.fedoraproject.org freezes: false #host_backup_targets: ['/srv/web'] -volgroup: /dev/vg_guests -eth0_ipv4: 152.19.134.199 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:00a7:9474" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-people ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ -postfix_group: vpn -vpn: true -vmhost: ibiblio05.fedoraproject.org -datacenter: ibiblio - -fedmsg_fqdn: people01.vpn.fedoraproject.org - -tcp_ports: [80, 443, 9418, 873] - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-people lvm_size: 1t mem_size: 8192 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + gateway6: "{{ eth0_ipv6_gw }}" + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 num_cpus: 4 - +postfix_group: vpn rsyncd_conf: "rsyncd.conf.people01.fedoraproject.org" - -ssh_hostnames: -- fedorapeople.org - +sar_output_file: "fedora_people.xml" # GDPR SAR vars sar_script: "/usr/bin/tree /home/fedora/$SAR_USERNAME -DFgXfpsu --timefmt %Y-%m-%dT%H:%M:%SZ" sar_script_user: "root" -sar_output_file: "fedora_people.xml" - -dns1: 152.2.21.1 -dns2: 152.2.253.100 - -dns_search1: vpn.fedoraproject.org -dns_search2: fedoraproject.org - -network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no +ssh_hostnames: + - fedorapeople.org +tcp_ports: [80, 443, 9418, 873] +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/pkgs01.iad2.fedoraproject.org b/inventory/host_vars/pkgs01.iad2.fedoraproject.org index 91ebbba9fa..e55ce27e7c 100644 --- a/inventory/host_vars/pkgs01.iad2.fedoraproject.org +++ b/inventory/host_vars/pkgs01.iad2.fedoraproject.org @@ -1,34 +1,26 @@ --- -eth0_ip: 10.3.169.116 -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-05.iad2.fedoraproject.org -datacenter: iad2 - -mem_size: 16384 -num_cpus: 8 - -host_backup_targets: ['/srv/cache/lookaside'] -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -ssh_hostnames: -- pkgs.fedoraproject.org - additional_host_keytabs: -- pkgs.fedoraproject.org - -nrpe_procs_warn: 500 + - pkgs.fedoraproject.org +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.169.116 +gw: 10.3.169.254 +host_backup_targets: ['/srv/cache/lookaside'] +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +mem_size: 16384 +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nm: 255.255.255.0 nrpe_procs_crit: 600 - +nrpe_procs_warn: 500 +num_cpus: 8 +# DB used by pagure +pagure_db_host: db01.iad2.fedoraproject.org +sar_output_file: dist_git.json # GDPR SAR variables - dist_dit sar_script: /usr/local/bin/pagure_sar.py sar_script_user: root -sar_output_file: dist_git.json - -# DB used by pagure -pagure_db_host: db01.iad2.fedoraproject.org - +ssh_hostnames: + - pkgs.fedoraproject.org +vmhost: bvmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/pkgs01.stg.iad2.fedoraproject.org b/inventory/host_vars/pkgs01.stg.iad2.fedoraproject.org index 5d96b1b1f9..bf9f4f4622 100644 --- a/inventory/host_vars/pkgs01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/pkgs01.stg.iad2.fedoraproject.org @@ -1,19 +1,16 @@ --- -eth0_ip: 10.3.167.74 -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org -datacenter: iad2 - -ssh_hostnames: -- pkgs.stg.fedoraproject.org - # temp fix to get htis box working baseiptables: False - +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.167.74 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 # DB used by pagure pagure_db_host: db01.stg.iad2.fedoraproject.org +ssh_hostnames: + - pkgs.stg.fedoraproject.org +vmhost: bvmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/ppc64le-test.fedorainfracloud.org b/inventory/host_vars/ppc64le-test.fedorainfracloud.org index bbe76af3bd..191cc20db8 100644 --- a/inventory/host_vars/ppc64le-test.fedorainfracloud.org +++ b/inventory/host_vars/ppc64le-test.fedorainfracloud.org @@ -1,5 +1,4 @@ --- nagios_Can_Connect: false - nagios_Check_Services: nrpe: false diff --git a/inventory/host_vars/proxy01.iad2.fedoraproject.org b/inventory/host_vars/proxy01.iad2.fedoraproject.org index 0d9a1508c6..a3a3bab043 100644 --- a/inventory/host_vars/proxy01.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy01.iad2.fedoraproject.org @@ -1,53 +1,42 @@ --- -freezes: true - datacenter: iad2 - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: vmhost-x86-02.iad2.fedoraproject.org -volgroup: /dev/vg_guests -num_cpus: 8 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "vpn.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.163.74 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.163.254 - +eth0_ipv4_nm: 24 +freezes: true +has_ipv4: yes +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora mac0: 52:54:00:76:9f:85 - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy01.stg.iad2.fedoraproject.org b/inventory/host_vars/proxy01.stg.iad2.fedoraproject.org index ce22abe725..b9ddbbdc67 100644 --- a/inventory/host_vars/proxy01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy01.stg.iad2.fedoraproject.org @@ -1,20 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 10.3.166.74 - +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 # This is consumed by the roles/fedora-web/main role sponsor: redhat - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - +vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: false diff --git a/inventory/host_vars/proxy02.fedoraproject.org b/inventory/host_vars/proxy02.fedoraproject.org index 9b135557a0..37229c16a9 100644 --- a/inventory/host_vars/proxy02.fedoraproject.org +++ b/inventory/host_vars/proxy02.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: internetx - -# This is consumed by the roles/fedora-web/main role -sponsor: internetx - -vmhost: internetx01.fedoraproject.org -volgroup: /dev/vg_Server - -mem_size: 8192 -max_mem_size: 8192 -num_cpus: 6 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 85.236.55.6 -eth0_ipv4_nm: 28 eth0_ipv4_gw: 85.236.55.1 - -has_ipv6: true +eth0_ipv4_nm: 28 eth0_ipv6: "2001:4178:2:1269::fed2" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2001:4178:2:1269::1" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: true +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: 52:54:00:8c:7c:1b -public_hostname: proxy02.fedoraproject.org - +max_mem_size: 8192 +mem_size: 8192 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 6 +postfix_group: vpn +public_hostname: proxy02.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: internetx +vmhost: internetx01.fedoraproject.org +volgroup: /dev/vg_Server +vpn: true diff --git a/inventory/host_vars/proxy02.stg.iad2.fedoraproject.org b/inventory/host_vars/proxy02.stg.iad2.fedoraproject.org index 86f421f7c0..a2874ec4a8 100644 --- a/inventory/host_vars/proxy02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy02.stg.iad2.fedoraproject.org @@ -1,21 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - - -vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 10.3.166.75 - +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 # This is consumed by the roles/fedora-web/main role sponsor: redhat - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - +vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: false diff --git a/inventory/host_vars/proxy03.fedoraproject.org b/inventory/host_vars/proxy03.fedoraproject.org index 925e077327..26e76775e6 100644 --- a/inventory/host_vars/proxy03.fedoraproject.org +++ b/inventory/host_vars/proxy03.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: rdu-cc - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: virthost-cc-rdu02.fedoraproject.org -volgroup: /dev/vg_guests - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 8.43.85.73 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 8.43.85.254 - -has_ipv6: true +eth0_ipv4_nm: 24 eth0_ipv6: "2620:52:3:1:dead:beef:cafe:fed6" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: true +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: "52:54:00:c1:18:c6" -public_hostname: proxy03.fedoraproject.org - +max_mem_size: 32768 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy03.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: virthost-cc-rdu02.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy04.fedoraproject.org b/inventory/host_vars/proxy04.fedoraproject.org index d06eb262f4..d5844f3296 100644 --- a/inventory/host_vars/proxy04.fedoraproject.org +++ b/inventory/host_vars/proxy04.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: ibiblio - -# This is consumed by the roles/fedora-web/main role -sponsor: ibiblio - -vmhost: ibiblio01.fedoraproject.org -volgroup: /dev/vg_guests - -mem_size: 16384 -max_mem_size: 20000 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 152.2.21.1 dns2: 152.2.153.100 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 152.19.134.142 -eth0_ipv4_nm: 25 eth0_ipv4_gw: 152.19.134.129 - -has_ipv6: yes +eth0_ipv4_nm: 25 eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed3" -eth0_ipv6_nm: 104 eth0_ipv6_gw: "2600:2701:4000:5211::1" - +eth0_ipv6_nm: 104 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: "52:54:00:e3:bb:8f" -public_hostname: proxy04.fedoraproject.org - +max_mem_size: 20000 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy04.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: ibiblio +vmhost: ibiblio01.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy05.fedoraproject.org b/inventory/host_vars/proxy05.fedoraproject.org index 8f2d33a6ce..e059a36d63 100644 --- a/inventory/host_vars/proxy05.fedoraproject.org +++ b/inventory/host_vars/proxy05.fedoraproject.org @@ -1,56 +1,46 @@ --- -freezes: true - datacenter: host1plus - +dns1: 8.8.8.8 +dns2: 8.8.4.4 +dns_search1: "vpn.fedoraproject.org" +dns_search2: "fedoraproject.org" +eth0_ipv4: 185.141.165.254 +eth0_ipv4_gw: 185.141.164.1 +eth0_ipv4_nm: 23 +freezes: true +has_ipv4: yes +mac0: "06:5b:86:00:06:60" +nagios_Check_Services: + dhcpd: false + httpd: true + named: false + nrpe: true + sshd: true + swap: false +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + type: ethernet +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn +public_hostname: proxy05.fedoraproject.org # This is now a cloud instance provided by host1plus # vmhost: none # This is consumed by the roles/fedora-web/main role sponsor: host1plus - -dns1: 8.8.8.8 -dns2: 8.8.4.4 - -dns_search1: "vpn.fedoraproject.org" -dns_search2: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 185.141.165.254 -eth0_ipv4_nm: 23 -eth0_ipv4_gw: 185.141.164.1 - -mac0: "06:5b:86:00:06:60" -public_hostname: proxy05.fedoraproject.org - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -nagios_Check_Services: - nrpe: true - sshd: true - named: false - dhcpd: false - httpd: true - swap: false diff --git a/inventory/host_vars/proxy06.fedoraproject.org b/inventory/host_vars/proxy06.fedoraproject.org index 6b54bc6564..0bfd99c650 100644 --- a/inventory/host_vars/proxy06.fedoraproject.org +++ b/inventory/host_vars/proxy06.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: osuosl - -# This is consumed by the roles/fedora-web/main role -sponsor: osuosl - -vmhost: osuosl01.fedoraproject.org -volgroup: /dev/vg_guests - -mem_size: 16384 -max_mem_size: 20000 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 140.211.169.196 -eth0_ipv4_nm: 26 eth0_ipv4_gw: 140.211.169.193 - -has_ipv6: yes +eth0_ipv4_nm: 26 eth0_ipv6: "2605:bc80:3010:600:dead:beef:cafe:fed9" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2605:bc80:3010:600::1" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: 52:54:00:fd:23:7f -public_hostname: proxy06.fedoraproject.org - +max_mem_size: 20000 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy06.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: osuosl +vmhost: osuosl01.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy07.fedoraproject.org b/inventory/host_vars/proxy07.fedoraproject.org index 73566a6838..854d879276 100644 --- a/inventory/host_vars/proxy07.fedoraproject.org +++ b/inventory/host_vars/proxy07.fedoraproject.org @@ -1,17 +1,15 @@ --- -nm: 255.255.255.0 -gw: 174.141.234.1 +datacenter: bodhost dns: 8.8.8.8 - -eth0_ip: 174.141.234.172 -eth0_nm: 255.255.255.0 dns1: 8.8.8.8 dns2: 8.8.4.4 +eth0_ip: 174.141.234.172 +eth0_nm: 255.255.255.0 +gw: 174.141.234.1 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn # This is consumed by the roles/fedora-web/main role sponsor: bodhost -datacenter: bodhost -postfix_group: vpn - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 vpn: true diff --git a/inventory/host_vars/proxy09.fedoraproject.org b/inventory/host_vars/proxy09.fedoraproject.org index 8c0f2ed574..934e481ada 100644 --- a/inventory/host_vars/proxy09.fedoraproject.org +++ b/inventory/host_vars/proxy09.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: osuosl - -# This is consumed by the roles/fedora-web/main role -sponsor: osuosl - -vmhost: osuosl02.fedoraproject.org -volgroup: /dev/vg_guests - -mem_size: 16384 -max_mem_size: 20000 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 140.211.169.206 -eth0_ipv4_nm: 26 eth0_ipv4_gw: 140.211.169.193 - -has_ipv6: yes +eth0_ipv4_nm: 26 eth0_ipv6: "2605:bc80:3010:600:dead:beef:cafe:feda" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2605:bc80:3010:600::1" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: 52:54:00:67:b2:6f -public_hostname: proxy09.fedoraproject.org - +max_mem_size: 20000 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy09.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: osuosl +vmhost: osuosl02.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy10.iad2.fedoraproject.org b/inventory/host_vars/proxy10.iad2.fedoraproject.org index 68ab99e111..9cf83bd81f 100644 --- a/inventory/host_vars/proxy10.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy10.iad2.fedoraproject.org @@ -1,53 +1,42 @@ --- -freezes: true - datacenter: iad2 - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: vmhost-x86-05.iad2.fedoraproject.org -volgroup: /dev/vg_guests -num_cpus: 8 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "vpn.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.163.75 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.163.254 - +eth0_ipv4_nm: 24 +freezes: true +has_ipv4: yes +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora mac0: 52:54:00:55:8d:ca - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet nrpe_procs_crit: 1400 - +nrpe_procs_warn: 1200 +num_cpus: 8 +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/proxy101.iad2.fedoraproject.org b/inventory/host_vars/proxy101.iad2.fedoraproject.org index 13aec17437..8120d43bba 100644 --- a/inventory/host_vars/proxy101.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy101.iad2.fedoraproject.org @@ -1,52 +1,41 @@ --- -freezes: true - datacenter: iad2 - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: vmhost-x86-02.iad2.fedoraproject.org -volgroup: /dev/vg_guests - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "vpn.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.163.76 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.163.254 - +eth0_ipv4_nm: 24 +freezes: true +has_ipv4: yes +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora mac0: 52:54:00:1F:48:0A - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet nrpe_procs_crit: 1400 - +nrpe_procs_warn: 1200 +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/proxy11.fedoraproject.org b/inventory/host_vars/proxy11.fedoraproject.org index f46fec64a2..6a1324881e 100644 --- a/inventory/host_vars/proxy11.fedoraproject.org +++ b/inventory/host_vars/proxy11.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: dedicatedsolutions - -# This is consumed by the roles/fedora-web/main role -sponsor: dedicatedsolutions - -vmhost: dedicatedsolutions01.fedoraproject.org -volgroup: /dev/vg_virthost - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 10 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 67.219.144.68 -eth0_ipv4_nm: 28 eth0_ipv4_gw: 67.219.144.65 - -has_ipv6: yes +eth0_ipv4_nm: 28 eth0_ipv6: "2604:1580:fe00:0:dead:beef:cafe:fed1" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2604:1580:fe00::1" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: "52:54:00:96:fb:f7" -public_hostname: proxy11.fedoraproject.org - +max_mem_size: 32768 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 10 +postfix_group: vpn +public_hostname: proxy11.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: dedicatedsolutions +vmhost: dedicatedsolutions01.fedoraproject.org +volgroup: /dev/vg_virthost +vpn: true diff --git a/inventory/host_vars/proxy110.iad2.fedoraproject.org b/inventory/host_vars/proxy110.iad2.fedoraproject.org index a9ae4f40d5..dfb67efe95 100644 --- a/inventory/host_vars/proxy110.iad2.fedoraproject.org +++ b/inventory/host_vars/proxy110.iad2.fedoraproject.org @@ -1,53 +1,41 @@ --- - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ - -freezes: true - datacenter: iad2 - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: vmhost-x86-06.iad2.fedoraproject.org -volgroup: /dev/vg_guests - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "vpn.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 10.3.163.77 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 10.3.163.254 - +eth0_ipv4_nm: 24 +freezes: true +has_ipv4: yes +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora mac0: 52:54:00:04:49:7a - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet nrpe_procs_crit: 1400 - +nrpe_procs_warn: 1200 +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/proxy12.fedoraproject.org b/inventory/host_vars/proxy12.fedoraproject.org index b79a9e14be..80c4dc178b 100644 --- a/inventory/host_vars/proxy12.fedoraproject.org +++ b/inventory/host_vars/proxy12.fedoraproject.org @@ -1,63 +1,50 @@ --- -freezes: true - datacenter: ibiblio - -# This is consumed by the roles/fedora-web/main role -sponsor: ibiblio - -vmhost: ibiblio05.fedoraproject.org -volgroup: /dev/vg_guests - -mem_size: 16384 -max_mem_size: 20000 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns1: 152.2.21.1 dns2: 152.2.153.100 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 152.19.134.198 -eth0_ipv4_nm: 25 eth0_ipv4_gw: 152.19.134.129 - -has_ipv6: yes +eth0_ipv4_nm: 25 eth0_ipv6: "2600:2701:4000:5211:dead:beef:00da:bbd8" -eth0_ipv6_nm: 104 eth0_ipv6_gw: "2600:2701:4000:5211::1" - +eth0_ipv6_nm: 104 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: "52:54:00:84:5d:9f" -public_hostname: proxy12.fedoraproject.org - +max_mem_size: 20000 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ mac0 }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ mac0 }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy12.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: ibiblio +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/proxy13.fedoraproject.org b/inventory/host_vars/proxy13.fedoraproject.org index 5676572714..f4f59177ab 100644 --- a/inventory/host_vars/proxy13.fedoraproject.org +++ b/inventory/host_vars/proxy13.fedoraproject.org @@ -1,30 +1,23 @@ --- -nm: 255.255.255.0 -gw: 172.31.2.254 +datacenter: rdu dns: 8.8.8.8 dns1: 8.8.8.8 dns2: 8.8.4.4 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - -vmhost: virthost-rdu01.fedoraproject.org -volgroup: /dev/vg_guests - eth0_ip: 172.31.2.22 eth0_nm: 255.255.255.0 - +gw: 172.31.2.254 +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora +max_mem_size: 32768 +mem_size: 16384 +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn public_ip: 209.132.190.2 - # This is consumed by the roles/fedora-web/main role sponsor: redhat -datacenter: rdu -postfix_group: vpn +vmhost: virthost-rdu01.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 diff --git a/inventory/host_vars/proxy14.fedoraproject.org b/inventory/host_vars/proxy14.fedoraproject.org index c704547b41..9386aee39c 100644 --- a/inventory/host_vars/proxy14.fedoraproject.org +++ b/inventory/host_vars/proxy14.fedoraproject.org @@ -1,64 +1,51 @@ --- -freezes: true - datacenter: rdu-cc - -# This is consumed by the roles/fedora-web/main role -sponsor: redhat - -vmhost: vmhost-x86-cc05.rdu-cc.fedoraproject.org -volgroup: /dev/rhel_vmhost-x86-05 - -mem_size: 16384 -max_mem_size: 32768 -num_cpus: 8 - -ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora -ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ - dns: 8.8.8.8 dns1: 8.8.8.8 dns2: 8.8.4.4 - dns_search1: "vpn.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes eth0_ipv4: 8.43.85.67 -eth0_ipv4_nm: 24 eth0_ipv4_gw: 8.43.85.254 - -has_ipv6: yes +eth0_ipv4_nm: 24 eth0_ipv6: "2620:52:3:1:dead:beef:cafe:fed7" -eth0_ipv6_nm: 64 eth0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - +eth0_ipv6_nm: 64 +freezes: true +has_ipv4: yes +has_ipv6: yes +ks_repo: http://38.145.60.16/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://38.145.60.16/repo/rhel/ks/kvm-fedora mac0: "52:54:00:19:67:0C" -public_hostname: proxy14.fedoraproject.org - +max_mem_size: 32768 +mem_size: 16384 network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 8 +postfix_group: vpn +public_hostname: proxy14.fedoraproject.org +# This is consumed by the roles/fedora-web/main role +sponsor: redhat +vmhost: vmhost-x86-cc05.rdu-cc.fedoraproject.org +volgroup: /dev/rhel_vmhost-x86-05 +vpn: true diff --git a/inventory/host_vars/proxy30.fedoraproject.org b/inventory/host_vars/proxy30.fedoraproject.org index 20b632949f..1772e256de 100644 --- a/inventory/host_vars/proxy30.fedoraproject.org +++ b/inventory/host_vars/proxy30.fedoraproject.org @@ -2,15 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.250.126.156 +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy31.fedoraproject.org b/inventory/host_vars/proxy31.fedoraproject.org index 46f7e0f822..d458ac3722 100644 --- a/inventory/host_vars/proxy31.fedoraproject.org +++ b/inventory/host_vars/proxy31.fedoraproject.org @@ -2,15 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.125.120.8 +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy32.fedoraproject.org b/inventory/host_vars/proxy32.fedoraproject.org index e34dbdb740..41a584539e 100644 --- a/inventory/host_vars/proxy32.fedoraproject.org +++ b/inventory/host_vars/proxy32.fedoraproject.org @@ -2,15 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 18.185.136.17 +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy33.fedoraproject.org b/inventory/host_vars/proxy33.fedoraproject.org index e4e82d7b90..ec986b44f0 100644 --- a/inventory/host_vars/proxy33.fedoraproject.org +++ b/inventory/host_vars/proxy33.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.244.113.71 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy34.fedoraproject.org b/inventory/host_vars/proxy34.fedoraproject.org index be695d46b6..b0fe3ef6ba 100644 --- a/inventory/host_vars/proxy34.fedoraproject.org +++ b/inventory/host_vars/proxy34.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 18.230.149.104 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy35.fedoraproject.org b/inventory/host_vars/proxy35.fedoraproject.org index ada4971ae0..03dbe02f51 100644 --- a/inventory/host_vars/proxy35.fedoraproject.org +++ b/inventory/host_vars/proxy35.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 18.133.140.134 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy36.fedoraproject.org b/inventory/host_vars/proxy36.fedoraproject.org index b20ca841e8..7590bbc701 100644 --- a/inventory/host_vars/proxy36.fedoraproject.org +++ b/inventory/host_vars/proxy36.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 18.159.254.57 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy37.fedoraproject.org b/inventory/host_vars/proxy37.fedoraproject.org index 43f0262b20..7d2bd7393b 100644 --- a/inventory/host_vars/proxy37.fedoraproject.org +++ b/inventory/host_vars/proxy37.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.233.183.170 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy38.fedoraproject.org b/inventory/host_vars/proxy38.fedoraproject.org index 560be935a4..8f12c87b23 100644 --- a/inventory/host_vars/proxy38.fedoraproject.org +++ b/inventory/host_vars/proxy38.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.212.21.54 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy39.fedoraproject.org b/inventory/host_vars/proxy39.fedoraproject.org index 43be23a207..e270857cf7 100644 --- a/inventory/host_vars/proxy39.fedoraproject.org +++ b/inventory/host_vars/proxy39.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 13.245.77.95 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/proxy40.fedoraproject.org b/inventory/host_vars/proxy40.fedoraproject.org index 28462dcc86..5948d517b1 100644 --- a/inventory/host_vars/proxy40.fedoraproject.org +++ b/inventory/host_vars/proxy40.fedoraproject.org @@ -2,16 +2,12 @@ # Skipping all the network stuff. Amazon does that all via DHCP. # This is consumed by the roles/fedora-web/main role -sponsor: amazon datacenter: aws -postfix_group: vpn -vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 - nagios_Check_Services: swap: false - +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +postfix_group: vpn public_ip: 15.228.51.95 - +sponsor: amazon +vpn: true diff --git a/inventory/host_vars/qvmhost-x86-01.iad2.fedoraproject.org b/inventory/host_vars/qvmhost-x86-01.iad2.fedoraproject.org index d4145a59a6..7e18e807e0 100644 --- a/inventory/host_vars/qvmhost-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/qvmhost-x86-01.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- -datacenter: iad2 - +br0_dev: eno1 +br0_gw: 10.3.174.254 br0_ip: 10.3.174.11 br0_nm: 255.255.255.0 -br0_gw: 10.3.174.254 -br0_dev: eno1 - +br0_port0_mac: "{{ mac1 }}" +datacenter: iad2 dns: 10.3.163.33 - mac1: e4:43:4b:a8:c1:fe mac2: e4:43:4b:a8:c2:00 mac3: e4:43:4b:a8:c2:1e mac4: e4:43:4b:a8:c2:1f - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ip }}/24" - gateway4: "{{ br0_gw }}" - dns: - - 10.3.163.33 - - 10.3.163.34 - dns_search: - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no + - "{{ br0_ip }}/24" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - 10.3.163.33 + - 10.3.163.34 + dns_search: + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ br0_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - diff --git a/inventory/host_vars/qvmhost-x86-02.iad2.fedoraproject.org b/inventory/host_vars/qvmhost-x86-02.iad2.fedoraproject.org index 43f5435783..b99901cecd 100644 --- a/inventory/host_vars/qvmhost-x86-02.iad2.fedoraproject.org +++ b/inventory/host_vars/qvmhost-x86-02.iad2.fedoraproject.org @@ -1,13 +1,10 @@ --- -datacenter: iad2 - +br0_dev: eno1 +br0_gw: 10.3.174.254 br0_ip: 10.3.174.12 br0_nm: 255.255.255.0 -br0_gw: 10.3.174.254 -br0_dev: eno1 - +datacenter: iad2 dns: 10.3.163.33 - mac1: e4:43:4b:a8:b3:0e mac2: e4:43:4b:a8:b3:10 mac3: e4:43:4b:a8:b3:2e diff --git a/inventory/host_vars/rabbitmq01.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq01.iad2.fedoraproject.org index 474a5c6209..368c6fe302 100644 --- a/inventory/host_vars/rabbitmq01.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq01.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -volgroup: /dev/vg_guests -vmhost: vmhost-x86-02.iad2.fedoraproject.org -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +datacenter: iad2 +dns: 10.3.163.33 eth0_ip: 10.3.163.78 gw: 10.3.163.254 -dns: 10.3.163.33 -datacenter: iad2 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 nm: 255.255.255.0 +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/rabbitmq01.stg.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq01.stg.iad2.fedoraproject.org index 712ff37501..ea6e99b3c0 100644 --- a/inventory/host_vars/rabbitmq01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq01.stg.iad2.fedoraproject.org @@ -1,4 +1,4 @@ --- -volgroup: /dev/vg_guests eth0_ip: 10.3.166.78 vmhost: vmhost-x86-03.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/rabbitmq02.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq02.iad2.fedoraproject.org index 780c0d9431..42ec82a313 100644 --- a/inventory/host_vars/rabbitmq02.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq02.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -volgroup: /dev/vg_guests -vmhost: vmhost-x86-03.iad2.fedoraproject.org -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +datacenter: iad2 +dns: 10.3.163.33 eth0_ip: 10.3.163.79 gw: 10.3.163.254 -dns: 10.3.163.33 -datacenter: iad2 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 nm: 255.255.255.0 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/rabbitmq02.stg.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq02.stg.iad2.fedoraproject.org index 94e16e4b29..e7dc5428a0 100644 --- a/inventory/host_vars/rabbitmq02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq02.stg.iad2.fedoraproject.org @@ -1,4 +1,4 @@ --- -volgroup: /dev/vg_guests eth0_ip: 10.3.166.79 vmhost: vmhost-x86-04.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/rabbitmq03.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq03.iad2.fedoraproject.org index dfe0acf023..8a4bf3c41a 100644 --- a/inventory/host_vars/rabbitmq03.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq03.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -volgroup: /dev/vg_guests -vmhost: vmhost-x86-04.iad2.fedoraproject.org -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +datacenter: iad2 +dns: 10.3.163.33 eth0_ip: 10.3.163.80 gw: 10.3.163.254 -dns: 10.3.163.33 -datacenter: iad2 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/rabbitmq03.stg.iad2.fedoraproject.org b/inventory/host_vars/rabbitmq03.stg.iad2.fedoraproject.org index 05dd6d3621..4bbee50ce1 100644 --- a/inventory/host_vars/rabbitmq03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/rabbitmq03.stg.iad2.fedoraproject.org @@ -1,4 +1,4 @@ --- -volgroup: /dev/vg_guests eth0_ip: 10.3.166.80 vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/resultsdb01.iad2.fedoraproject.org b/inventory/host_vars/resultsdb01.iad2.fedoraproject.org index e376b16074..25791fc0f5 100644 --- a/inventory/host_vars/resultsdb01.iad2.fedoraproject.org +++ b/inventory/host_vars/resultsdb01.iad2.fedoraproject.org @@ -2,28 +2,22 @@ ############################################################ # networking ############################################################ - -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.163.89 - +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/31/Server/x86_64/os/ ############################################################ # install ############################################################ - ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-31-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/31/Server/x86_64/os/ - -volgroup: /dev/vg_guests -datacenter: iad2 -vmhost: vmhost-x86-05.iad2.fedoraproject.org - ############################################################ # virtual machine ############################################################ - lvm_size: 50000 mem_size: 16384 +nm: 255.255.255.0 num_cpus: 4 sudoers: "{{ private }}/files/sudo/qavirt-sudoers" +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/resultsdb01.stg.iad2.fedoraproject.org b/inventory/host_vars/resultsdb01.stg.iad2.fedoraproject.org index f6d55de2e3..98be2e321c 100644 --- a/inventory/host_vars/resultsdb01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/resultsdb01.stg.iad2.fedoraproject.org @@ -2,27 +2,21 @@ ############################################################ # networking ############################################################ - -nm: 255.255.255.0 -gw: 10.3.166.254 +datacenter: iad2 dns: 10.3.163.33 eth0_ip: 10.3.166.36 - +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/31/Server/x86_64/os/ ############################################################ # install ############################################################ - ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora-31-iad2 -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/31/Server/x86_64/os/ - -volgroup: /dev/vg_guests -datacenter: iad2 -vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org - ############################################################ # virtual machine ############################################################ - lvm_size: 50000 mem_size: 16384 +nm: 255.255.255.0 num_cpus: 4 +vmhost: vmhost-x86-05.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/retrace-stg.aws.fedoraproject.org b/inventory/host_vars/retrace-stg.aws.fedoraproject.org index 592ad80da6..e9e32e68ac 100644 --- a/inventory/host_vars/retrace-stg.aws.fedoraproject.org +++ b/inventory/host_vars/retrace-stg.aws.fedoraproject.org @@ -2,92 +2,84 @@ #ansible_ssh_user: ec2-user #ansible_become_user: root #ansible_become: yes -nm_controlled_resolv: True ansible_ifcfg_blocklist: True -public_ip: 3.228.218.234 datacenter: aws -vpn: True - -public_hostname: retrace-stg.aws.fedoraproject.org -faf_server_name: retrace-stg.aws.fedoraproject.org/faf -rs_use_faf_packages: true - -# Staging only has a little storage, so we only support one release at a time. -rs_internal_fedora_vers: [34] -rs_internal_fedora_vers_removed: [31, 32, 33, rawhide] -rs_internal_centos_vers: [] -rs_internal_arch_list: [source, x86_64] - -# List of supported operating systems -faf_opsys_list: - - fedora - - centos - # Clean-up packages of following EOLed operating systems eol_opsys: [] # When not empty, the array should have the following form: # - { opsys: "Fedora", release: "36" } +# List of supported operating systems +faf_opsys_list: + - fedora + - centos +faf_repos: + - arch: 'src' + name: 'fedora-34-source' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/source/tree/' + - arch: 'x86_64' + name: 'fedora-34-x86_64' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/os/' + - arch: 'x86_64' + name: 'fedora-34-x86_64-debug' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/debug/tree/' + - arch: 'x86_64' + name: 'fedora-34-x86_64-updates' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/' + - arch: 'x86_64' + name: 'fedora-34-x86_64-updates-debug' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/debug/' + - arch: 'x86_64' + name: 'fedora-34-x86_64-testing' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/' + - arch: 'x86_64' + name: 'fedora-34-x86_64-testing-debug' + opsys: 'Fedora 34' + url: + - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/debug/' +faf_server_name: retrace-stg.aws.fedoraproject.org/faf +# consumed by roles/copr/certbot +letsencrypt: + certificates: + retrace-stg.aws.fedoraproject.org: + challenge_dir: /var/www/html + domains: + - retrace-stg.aws.fedoraproject.org + mail: mfabik@redhat.com + predefined_deploy_script: httpd +nagios_Check_Services: + dhcpd: false + httpd: false + mail: false + named: false + nrpe: false + ping: false + raid: false + sshd: false + swap: false +nm_controlled_resolv: True +public_hostname: retrace-stg.aws.fedoraproject.org +public_ip: 3.228.218.234 +rs_internal_arch_list: [source, x86_64] +rs_internal_centos_vers: [] +# Staging only has a little storage, so we only support one release at a time. +rs_internal_fedora_vers: [34] +rs_internal_fedora_vers_removed: [31, 32, 33, rawhide] +rs_use_faf_packages: true +sar_output_file: faf.json # GDPR SAR variables sar_script: '/usr/bin/faf sar' sar_script_user: faf -sar_output_file: faf.json - -# consumed by roles/copr/certbot -letsencrypt: - predefined_deploy_script: httpd - certificates: - retrace-stg.aws.fedoraproject.org: - domains: - - retrace-stg.aws.fedoraproject.org - challenge_dir: /var/www/html - mail: mfabik@redhat.com - -nagios_Check_Services: - mail: false - nrpe: false - sshd: false - named: false - dhcpd: false - httpd: false - swap: false - ping: false - raid: false - -faf_repos: - - name: 'fedora-34-source' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/source/tree/' - arch: 'src' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/os/' - arch: 'x86_64' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-debug' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/debug/tree/' - arch: 'x86_64' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-updates' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/' - arch: 'x86_64' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-updates-debug' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/debug/' - arch: 'x86_64' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-testing' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/' - arch: 'x86_64' - opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-testing-debug' - url: - - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/debug/' - arch: 'x86_64' - opsys: 'Fedora 34' -... +vpn: True diff --git a/inventory/host_vars/retrace03.rdu-cc.fedoraproject.org b/inventory/host_vars/retrace03.rdu-cc.fedoraproject.org index b5c9283f17..eb447cbd51 100644 --- a/inventory/host_vars/retrace03.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/retrace03.rdu-cc.fedoraproject.org @@ -1,174 +1,167 @@ --- datacenter: rdu-cc -public_hostname: retrace03.rdu-cc.fedoraproject.org -faf_server_name: retrace.fedoraproject.org/faf -rs_use_faf_packages: true - -# we do not have enough storage on stg -rs_internal_fedora_vers: [33, 34, 35, rawhide] -rs_internal_fedora_vers_removed: [30, 31, 32] -rs_internal_centos_vers: [7, 8] -rs_internal_arch_list: [source, x86_64] - -# consumed by roles/copr/certbot -letsencrypt: - predefined_deploy_script: httpd - certificates: - retrace03.rdu-cc.fedoraproject.org: - domains: - - retrace03.rdu-cc.fedoraproject.org - - retrace.fedoraproject.org - challenge_dir: /var/www/html - mail: msuchy@redhat.com - -nagios_Check_Services: - nrpe: true - sshd: true - named: false - dhcpd: false - httpd: false - swap: false - -# List of supported operating systems -faf_opsys_list: - - fedora - - centos - # Clean-up packages of following EOLed operating systems eol_opsys: [] # When not empty, the array should have the following form: # - { opsys: "Fedora", release: "36" } -# GDPR SAR variables -sar_script: '/usr/bin/faf sar' -sar_script_user: faf -sar_output_file: faf.json - +# List of supported operating systems +faf_opsys_list: + - fedora + - centos faf_repos: # Fedora 33 repositories ------------------------------------------------ - - name: 'fedora-33-source' + - arch: 'src' + name: 'fedora-33-source' + opsys: 'Fedora 33' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/33/Everything/source/tree/' - arch: 'src' + - arch: 'x86_64' + name: 'fedora-33-x86_64' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/33/Everything/x86_64/os/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-33-x86_64-debug' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/33/Everything/x86_64/debug/tree/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-33-x86_64-testing-debug' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64-testing-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/33/Everything/x86_64/debug/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-33-x86_64-testing' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64-testing' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/33/Everything/x86_64/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-33-x86_64-updates-debug' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64-updates-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/33/Everything/x86_64/debug/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-33-x86_64-updates' opsys: 'Fedora 33' - - name: 'fedora-33-x86_64-updates' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/33/Everything/x86_64/' - arch: 'x86_64' - opsys: 'Fedora 33' # Fedora 34 repositories ------------------------------------------------ - - name: 'fedora-34-source' + - arch: 'src' + name: 'fedora-34-source' + opsys: 'Fedora 34' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/source/tree/' - arch: 'src' + - arch: 'x86_64' + name: 'fedora-34-x86_64' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/os/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-34-x86_64-debug' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/34/Everything/x86_64/debug/tree/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-34-x86_64-updates' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-updates' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-34-x86_64-updates-debug' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-updates-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/34/Everything/x86_64/debug/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-34-x86_64-testing' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-testing' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-34-x86_64-testing-debug' opsys: 'Fedora 34' - - name: 'fedora-34-x86_64-testing-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/34/Everything/x86_64/debug/' - arch: 'x86_64' - opsys: 'Fedora 34' # Fedora 35 repositories ------------------------------------------------ - - name: 'fedora-35-source' + - arch: 'src' + name: 'fedora-35-source' + opsys: 'Fedora 35' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/35/Everything/source/tree/' - 'http://dl01.fedoraproject.org/pub/fedora/linux/development/35/Everything/source/tree/' - arch: 'src' + - arch: 'x86_64' + name: 'fedora-35-x86_64' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/35/Everything/x86_64/os/' - 'http://dl01.fedoraproject.org/pub/fedora/linux/development/35/Everything/x86_64/os/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-35-x86_64-debug' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/releases/35/Everything/x86_64/debug/tree/' - 'http://dl01.fedoraproject.org/pub/fedora/linux/development/35/Everything/x86_64/debug/tree/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-35-x86_64-testing-debug' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64-testing-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/35/Everything/x86_64/debug/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-35-x86_64-testing' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64-testing' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/testing/35/Everything/x86_64/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-35-x86_64-updates-debug' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64-updates-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/35/Everything/x86_64/debug/' - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-35-x86_64-updates' opsys: 'Fedora 35' - - name: 'fedora-35-x86_64-updates' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/updates/35/Everything/x86_64/' - arch: 'x86_64' - opsys: 'Fedora 35' # Fedora Rawhide repositories ------------------------------------------- - - name: 'fedora-rawhide-source' + - arch: 'src' + name: 'fedora-rawhide-source' + opsys: 'Fedora Rawhide' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/source/tree/' - arch: 'src' + - arch: 'x86_64' + name: 'fedora-rawhide-x86_64' opsys: 'Fedora Rawhide' - - name: 'fedora-rawhide-x86_64' url: - arch: 'x86_64' + - arch: 'x86_64' + name: 'fedora-rawhide-x86_64-debug' opsys: 'Fedora Rawhide' - - name: 'fedora-rawhide-x86_64-debug' url: - 'http://dl01.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/debug/tree/' - arch: 'x86_64' - opsys: 'Fedora Rawhide' -... +faf_server_name: retrace.fedoraproject.org/faf +# consumed by roles/copr/certbot +letsencrypt: + certificates: + retrace03.rdu-cc.fedoraproject.org: + challenge_dir: /var/www/html + domains: + - retrace03.rdu-cc.fedoraproject.org + - retrace.fedoraproject.org + mail: msuchy@redhat.com + predefined_deploy_script: httpd +nagios_Check_Services: + dhcpd: false + httpd: false + named: false + nrpe: true + sshd: true + swap: false +public_hostname: retrace03.rdu-cc.fedoraproject.org +rs_internal_arch_list: [source, x86_64] +rs_internal_centos_vers: [7, 8] +# we do not have enough storage on stg +rs_internal_fedora_vers: [33, 34, 35, rawhide] +rs_internal_fedora_vers_removed: [30, 31, 32] +rs_use_faf_packages: true +sar_output_file: faf.json +# GDPR SAR variables +sar_script: '/usr/bin/faf sar' +sar_script_user: faf diff --git a/inventory/host_vars/secondary01.iad2.fedoraproject.org b/inventory/host_vars/secondary01.iad2.fedoraproject.org index 14528ad84f..343f98e052 100644 --- a/inventory/host_vars/secondary01.iad2.fedoraproject.org +++ b/inventory/host_vars/secondary01.iad2.fedoraproject.org @@ -1,19 +1,14 @@ --- +datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.86 +gw: 10.3.163.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 lvm_size: 40000 mem_size: 10240 -num_cpus: 4 - nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ - -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.86 - -vmhost: vmhost-x86-03.iad2.fedoraproject.org -datacenter: iad2 - +num_cpus: 4 public_hostname: secondary01.fedoraproject.org +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/sign-bridge01.iad2.fedoraproject.org b/inventory/host_vars/sign-bridge01.iad2.fedoraproject.org index 1c7b52bea8..251507d6b4 100644 --- a/inventory/host_vars/sign-bridge01.iad2.fedoraproject.org +++ b/inventory/host_vars/sign-bridge01.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.169.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-03.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.169.120 +gw: 10.3.169.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/sign-bridge01.stg.iad2.fedoraproject.org b/inventory/host_vars/sign-bridge01.stg.iad2.fedoraproject.org index 6778e775c3..b956c03c97 100644 --- a/inventory/host_vars/sign-bridge01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/sign-bridge01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.167.27 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/sign-vault01.iad2.fedoraproject.org b/inventory/host_vars/sign-vault01.iad2.fedoraproject.org index 02bbfe1916..8550e75b53 100644 --- a/inventory/host_vars/sign-vault01.iad2.fedoraproject.org +++ b/inventory/host_vars/sign-vault01.iad2.fedoraproject.org @@ -1,8 +1,6 @@ --- br0_dev: eno1 - -br0_ip: 10.3.169.26 br0_gw: 10.3.169.254 -br0_nm: 255.255.255.0 - +br0_ip: 10.3.169.26 +br0_nm: 255.255.255.0 dns: 10.3.163.33 diff --git a/inventory/host_vars/sign-vault01.stg.iad2.fedoraproject.org b/inventory/host_vars/sign-vault01.stg.iad2.fedoraproject.org index f68c0b9a2d..511e6d3811 100644 --- a/inventory/host_vars/sign-vault01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/sign-vault01.stg.iad2.fedoraproject.org @@ -1,12 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.167.254 -dns: 10.3.163.33 - -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 - +dns: 10.3.163.33 eth0_ip: 10.3.167.28 +gw: 10.3.167.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: bvmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/smtp-mm-cc-rdu01.fedoraproject.org b/inventory/host_vars/smtp-mm-cc-rdu01.fedoraproject.org index 66e666eac2..7d63ae6822 100644 --- a/inventory/host_vars/smtp-mm-cc-rdu01.fedoraproject.org +++ b/inventory/host_vars/smtp-mm-cc-rdu01.fedoraproject.org @@ -1,15 +1,12 @@ --- -nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 1.1.1.1 - -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ - eth0_ip: 8.43.85.70 eth0_nm: 255.255.255.0 - -volgroup: /dev/vg_guests +gw: 8.43.85.254 +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext +nm: 255.255.255.0 vmhost: virthost-cc-rdu01.fedoraproject.org -datacenter: rdu-cc +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/smtp-mm-ib01.fedoraproject.org b/inventory/host_vars/smtp-mm-ib01.fedoraproject.org index 910c905353..36856d4bd5 100644 --- a/inventory/host_vars/smtp-mm-ib01.fedoraproject.org +++ b/inventory/host_vars/smtp-mm-ib01.fedoraproject.org @@ -1,41 +1,37 @@ --- -volgroup: /dev/vg_guests -eth0_ipv4: 152.19.134.143 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:0058:5c17" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" - -vmhost: ibiblio05.fedoraproject.org datacenter: ibiblio -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - dns1: 152.2.21.1 dns2: 152.2.253.100 - dns_search1: vpn.fedoraproject.org dns_search2: fedoraproject.org - +eth0_ipv4: 152.19.134.143 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:0058:5c17" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/smtp-mm-osuosl01.fedoraproject.org b/inventory/host_vars/smtp-mm-osuosl01.fedoraproject.org index 67067e4d3b..5b6d786e8b 100644 --- a/inventory/host_vars/smtp-mm-osuosl01.fedoraproject.org +++ b/inventory/host_vars/smtp-mm-osuosl01.fedoraproject.org @@ -1,16 +1,15 @@ --- -nm: 255.255.255.192 -gw: 140.211.169.193 +datacenter: osuosl dns: 8.8.8.8 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 140.211.169.205 -eth0_nm: 255.255.255.128 -has_ipv6: yes eth0_ipv6: "2605:bc80:3010:600:dead:beef:cafe:fedb" eth0_ipv6_gw: "2605:bc80:3010:600::1" - +eth0_nm: 255.255.255.128 +gw: 140.211.169.193 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext +nm: 255.255.255.192 vmhost: osuosl02.fedoraproject.org -datacenter: osuosl +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/storinator01.rdu-cc.fedoraproject.org b/inventory/host_vars/storinator01.rdu-cc.fedoraproject.org index 56e7536078..091fe40a25 100644 --- a/inventory/host_vars/storinator01.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/storinator01.rdu-cc.fedoraproject.org @@ -1,26 +1,19 @@ --- # this box is not currently mission critical -freezes: false - -# this box mounts a large share from the netapp to store combined http -# logs from the proxies. - -nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - -# general configs -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 - eth0_ip: 8.43.85.62 eth0_nm: 255.255.255.0 eth2_ip: 172.23.5.25 eth2_nm: 255.255.255.0 - -tcp_ports_eth2: [ 111, 2049 ] -udp_ports_eth2: [ 111, 2049 ] - +freezes: false +gw: 8.43.85.254 +# this box mounts a large share from the netapp to store combined http +# logs from the proxies. +nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" +nrpe_procs_crit: 1000 +# general configs +nrpe_procs_warn: 900 +tcp_ports_eth2: [111, 2049] +udp_ports_eth2: [111, 2049] vpn: true -datacenter: rdu-cc diff --git a/inventory/host_vars/sundries01.iad2.fedoraproject.org b/inventory/host_vars/sundries01.iad2.fedoraproject.org index 64f76f80c0..5a18400fc1 100644 --- a/inventory/host_vars/sundries01.iad2.fedoraproject.org +++ b/inventory/host_vars/sundries01.iad2.fedoraproject.org @@ -1,18 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.81 -datacenter: iad2 - - -vmhost: vmhost-x86-03.iad2.fedoraproject.org -volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-iad2 +gw: 10.3.163.254 ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ - +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-iad2 # This overrides a group var and lets the playbook know that we should # install special cron jobs here. master_sundries_node: True - +nm: 255.255.255.0 +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/sundries01.stg.iad2.fedoraproject.org b/inventory/host_vars/sundries01.stg.iad2.fedoraproject.org index c821f08c65..35220a9a18 100644 --- a/inventory/host_vars/sundries01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/sundries01.stg.iad2.fedoraproject.org @@ -1,14 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.33 -vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.33 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 # This overrides a group var and lets the playbook know that we should # install special cron jobs here. master_sundries_node: True mirrorlist_procs: 45 +nm: 255.255.255.0 +vmhost: vmhost-x86-02.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/sundries02.iad2.fedoraproject.org b/inventory/host_vars/sundries02.iad2.fedoraproject.org index 3f785e442a..13dc7db93c 100644 --- a/inventory/host_vars/sundries02.iad2.fedoraproject.org +++ b/inventory/host_vars/sundries02.iad2.fedoraproject.org @@ -1,18 +1,14 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 +datacenter: iad2 dns: 10.3.163.34 eth0_ip: 10.3.163.101 -datacenter: iad2 - - -vmhost: vmhost-x86-05.iad2.fedoraproject.org -volgroup: /dev/vg_guests -virt_install_command: "{{ virt_install_command_one_nic }}" -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-iad2 +gw: 10.3.163.254 ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ - +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-iad2 # This overrides a group var and lets the playbook know that we should # install special cron jobs here. master_sundries_node: True - +nm: 255.255.255.0 +virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: vmhost-x86-05.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/tang01.iad2.fedoraproject.org b/inventory/host_vars/tang01.iad2.fedoraproject.org index b2154241fd..8082bd0587 100644 --- a/inventory/host_vars/tang01.iad2.fedoraproject.org +++ b/inventory/host_vars/tang01.iad2.fedoraproject.org @@ -1,18 +1,14 @@ --- -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.37 -vmhost: vmhost-x86-02.iad2.fedoraproject.org - -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - datacenter: iad2 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +dns: 10.3.163.33 +eth0_ip: 10.3.163.37 +gw: 10.3.163.254 ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext # Define resources for this group of hosts here. lvm_size: 20000 mem_size: 4096 +nm: 255.255.255.0 num_cpus: 2 +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/tang02.iad2.fedoraproject.org b/inventory/host_vars/tang02.iad2.fedoraproject.org index 4c0b236282..2e0fc98d8a 100644 --- a/inventory/host_vars/tang02.iad2.fedoraproject.org +++ b/inventory/host_vars/tang02.iad2.fedoraproject.org @@ -1,18 +1,14 @@ --- -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.38 -vmhost: vmhost-x86-03.iad2.fedoraproject.org - -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 - datacenter: iad2 - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext +dns: 10.3.163.33 +eth0_ip: 10.3.163.38 +gw: 10.3.163.254 ks_repo: http://209.132.181.6/repo/rhel/RHEL8-x86_64/ - +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-8-ext # Define resources for this group of hosts here. lvm_size: 20000 mem_size: 4096 +nm: 255.255.255.0 num_cpus: 2 +vmhost: vmhost-x86-03.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/torrent02.fedoraproject.org b/inventory/host_vars/torrent02.fedoraproject.org index a5ad806851..4d5bb68fd6 100644 --- a/inventory/host_vars/torrent02.fedoraproject.org +++ b/inventory/host_vars/torrent02.fedoraproject.org @@ -1,60 +1,51 @@ --- -volgroup: /dev/vg_guests - -eth0_ipv4: 152.19.134.148 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed7" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" - -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ - -postfix_group: vpn -vpn: true - -ssh_hostnames: -- torrent.fedoraproject.org - -vmhost: ibiblio05.fedoraproject.org -datacenter: ibiblio csi_relationship: | - torrent02 is the master torrent server for Fedora releases + torrent02 is the master torrent server for Fedora releases - * This host relies on: - - the virthost it's hosted on (ibiblio05.fedoraproject.org) - - FAS to authenticate users - - VPN connectivity - - * Things that rely on this host: - - if this host is down, Fedora will lose a release distribution channel + * This host relies on: + - the virthost it's hosted on (ibiblio05.fedoraproject.org) + - FAS to authenticate users + - VPN connectivity + * Things that rely on this host: + - if this host is down, Fedora will lose a release distribution channel +datacenter: ibiblio dns1: 152.2.21.1 dns2: 152.2.253.100 - dns_search1: vpn.fedoraproject.org dns_search2: fedoraproject.org - +eth0_ipv4: 152.19.134.148 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed7" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +postfix_group: vpn +ssh_hostnames: + - torrent.fedoraproject.org +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/unbound-cc-rdu01.fedoraproject.org b/inventory/host_vars/unbound-cc-rdu01.fedoraproject.org index 3c12930616..9be5a95e04 100644 --- a/inventory/host_vars/unbound-cc-rdu01.fedoraproject.org +++ b/inventory/host_vars/unbound-cc-rdu01.fedoraproject.org @@ -1,12 +1,12 @@ --- -nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 -ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 8.43.85.74 eth0_nm: 255.255.255.0 +gw: 8.43.85.254 +ks_repo: http://209.132.181.6/repo/rhel/RHEL7-x86_64/ +ks_url: http://209.132.181.6/repo/rhel/ks/kvm-rhel-7-ext +nm: 255.255.255.0 vmhost: virthost-cc-rdu02.fedoraproject.org -datacenter: rdu-cc +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/unbound-ib01.fedoraproject.org b/inventory/host_vars/unbound-ib01.fedoraproject.org index 358f17bb3e..9e0e1a65be 100644 --- a/inventory/host_vars/unbound-ib01.fedoraproject.org +++ b/inventory/host_vars/unbound-ib01.fedoraproject.org @@ -1,43 +1,39 @@ --- -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ipv4: 152.19.134.150 -eth0_ipv4_nm: 25 -eth0_ipv4_gw: 152.19.134.129 -has_ipv6: yes -eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed1" -eth0_ipv6_nm: 104 -eth0_ipv6_gw: "2600:2701:4000:5211::1" -vmhost: ibiblio05.fedoraproject.org datacenter: ibiblio -postfix_group: vpn -vpn: true - dns1: 152.2.21.1 dns2: 152.2.253.100 - dns_search1: vpn.fedoraproject.org dns_search2: fedoraproject.org - +eth0_ipv4: 152.19.134.150 +eth0_ipv4_gw: 152.19.134.129 +eth0_ipv4_nm: 25 +eth0_ipv6: "2600:2701:4000:5211:dead:beef:00fe:fed1" +eth0_ipv6_gw: "2600:2701:4000:5211::1" +eth0_ipv6_nm: 104 +has_ipv6: yes +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext network_connections: - - name: eth0 - mac: "{{ ansible_default_ipv4.macaddress }}" - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + - "{{ eth0_ipv6 }}/{{ eth0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + - 2001:4860:4860::8888 + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" gateway4: "{{ eth0_ipv4_gw }}" gateway6: "{{ eth0_ipv6_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - - 2001:4860:4860::8888 - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no - auto6: no - + mac: "{{ ansible_default_ipv4.macaddress }}" + name: eth0 + type: ethernet +postfix_group: vpn +vmhost: ibiblio05.fedoraproject.org +volgroup: /dev/vg_guests +vpn: true diff --git a/inventory/host_vars/unbound-osuosl01.fedoraproject.org b/inventory/host_vars/unbound-osuosl01.fedoraproject.org index d807da6c85..c88c873b1b 100644 --- a/inventory/host_vars/unbound-osuosl01.fedoraproject.org +++ b/inventory/host_vars/unbound-osuosl01.fedoraproject.org @@ -1,13 +1,13 @@ --- -nm: 255.255.255.128 -gw: 140.211.169.193 +datacenter: osuosl dns: 8.8.8.8 -ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext -ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 140.211.169.201 eth0_nm: 255.255.255.128 -vmhost: osuosl02.fedoraproject.org -datacenter: osuosl +gw: 140.211.169.193 +ks_repo: http://infrastructure.fedoraproject.org/repo/rhel/RHEL7-x86_64/ +ks_url: http://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-7-ext +nm: 255.255.255.128 postfix_group: vpn +vmhost: osuosl02.fedoraproject.org +volgroup: /dev/vg_guests vpn: true diff --git a/inventory/host_vars/value01.iad2.fedoraproject.org b/inventory/host_vars/value01.iad2.fedoraproject.org index 47889b5821..31328c45a6 100644 --- a/inventory/host_vars/value01.iad2.fedoraproject.org +++ b/inventory/host_vars/value01.iad2.fedoraproject.org @@ -1,18 +1,15 @@ --- -nm: 255.255.255.0 -gw: 10.3.163.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.163.82 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.163.82 +gw: 10.3.163.254 host_backup_targets: ['/srv', '/var/lib/zodbot'] - - +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 +sar_output_file: meetbot.json # GDPR SAR variables - meetbot sar_script: /usr/local/bin/meetbot_sar.py sar_script_user: root -sar_output_file: meetbot.json - +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/value01.stg.iad2.fedoraproject.org b/inventory/host_vars/value01.stg.iad2.fedoraproject.org index 377733985a..472deb6e38 100644 --- a/inventory/host_vars/value01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/value01.stg.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 +datacenter: iad2 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 10.3.166.23 eth0_nm: 255.255.255.0 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL7-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-7-iad2 +nm: 255.255.255.0 vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/value02.iad2.fedoraproject.org b/inventory/host_vars/value02.iad2.fedoraproject.org index b0431365b7..73887dfa94 100644 --- a/inventory/host_vars/value02.iad2.fedoraproject.org +++ b/inventory/host_vars/value02.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -nm: 255.255.255.0 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests -eth0_ipv4: 10.3.163.110 -eth0_ipv4_nm: 255.255.255.0 -eth0_ipv4_gw: 10.3.163.254 -vmhost: vmhost-x86-04.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ipv4: 10.3.163.110 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 255.255.255.0 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 +vmhost: vmhost-x86-04.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/value02.stg.iad2.fedoraproject.org b/inventory/host_vars/value02.stg.iad2.fedoraproject.org index 287a1aadfa..139abe3c1c 100644 --- a/inventory/host_vars/value02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/value02.stg.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 +datacenter: iad2 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 10.3.166.64 eth0_nm: 255.255.255.0 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/virthost-cc-rdu01.fedoraproject.org b/inventory/host_vars/virthost-cc-rdu01.fedoraproject.org index b886e4aae2..cf8e1f0609 100644 --- a/inventory/host_vars/virthost-cc-rdu01.fedoraproject.org +++ b/inventory/host_vars/virthost-cc-rdu01.fedoraproject.org @@ -1,10 +1,10 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: rdu-cc br0_ip: 8.43.85.65 br0_nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 +gw: 8.43.85.254 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 postfix_group: vpn vpn: true diff --git a/inventory/host_vars/virthost-cc-rdu02.fedoraproject.org b/inventory/host_vars/virthost-cc-rdu02.fedoraproject.org index 0d1b62a112..d2561e05ba 100644 --- a/inventory/host_vars/virthost-cc-rdu02.fedoraproject.org +++ b/inventory/host_vars/virthost-cc-rdu02.fedoraproject.org @@ -1,10 +1,10 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: rdu-cc br0_ip: 8.43.85.66 br0_nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 +gw: 8.43.85.254 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 postfix_group: vpn vpn: true diff --git a/inventory/host_vars/virthost-cc-rdu03.fedoraproject.org b/inventory/host_vars/virthost-cc-rdu03.fedoraproject.org index c7da4c7516..7358cb9efc 100644 --- a/inventory/host_vars/virthost-cc-rdu03.fedoraproject.org +++ b/inventory/host_vars/virthost-cc-rdu03.fedoraproject.org @@ -1,10 +1,10 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: rdu-cc br0_ip: 8.43.85.64 br0_nm: 255.255.255.0 -gw: 8.43.85.254 +datacenter: rdu-cc dns: 8.8.8.8 +gw: 8.43.85.254 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 postfix_group: vpn vpn: true diff --git a/inventory/host_vars/virthost-cloud01.fedorainfracloud.org b/inventory/host_vars/virthost-cloud01.fedorainfracloud.org index c9cb44edaa..d633b7be92 100644 --- a/inventory/host_vars/virthost-cloud01.fedorainfracloud.org +++ b/inventory/host_vars/virthost-cloud01.fedorainfracloud.org @@ -1,14 +1,13 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: cloud br0_ip: 38.145.48.5 br0_nm: 255.255.254.0 br1_ip: 172.24.0.17 br1_nm: 255.255.254.0 -gw: 8.43.49.254 +datacenter: cloud dns: 8.8.8.8 - -vpn: false -postfix_group: cloud freezes: false +gw: 8.43.49.254 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: cloud +vpn: false diff --git a/inventory/host_vars/virthost-rdu01.fedoraproject.org b/inventory/host_vars/virthost-rdu01.fedoraproject.org index 50b5998788..df1d7430ff 100644 --- a/inventory/host_vars/virthost-rdu01.fedoraproject.org +++ b/inventory/host_vars/virthost-rdu01.fedoraproject.org @@ -1,19 +1,17 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: rdu -nm: 255.255.255.0 -gw: 172.31.2.254 -dns: 8.8.8.8 -postfix_group: vpn br0_ip: 172.31.2.11 br0_nm: 255.255.255.0 br1_ip: 172.31.1.2 br1_nm: 255.255.255.0 -vpn: true - -public_ip: 209.132.190.11 - +datacenter: rdu +dns: 8.8.8.8 +gw: 172.31.2.254 nagios_Check_Services: - nrpe: false mail: false + nrpe: false +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: vpn +public_ip: 209.132.190.11 +vpn: true diff --git a/inventory/host_vars/virthost-rdu02.fedoraproject.org b/inventory/host_vars/virthost-rdu02.fedoraproject.org index 73b582c8b5..5315da7816 100644 --- a/inventory/host_vars/virthost-rdu02.fedoraproject.org +++ b/inventory/host_vars/virthost-rdu02.fedoraproject.org @@ -1,15 +1,14 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 -datacenter: rdu -nm: 255.255.255.0 -gw: 172.31.2.254 -dns: 8.8.8.8 -postfix_group: vpn br0_ip: 172.31.2.12 br0_nm: 255.255.255.0 +datacenter: rdu +dns: 8.8.8.8 +gw: 172.31.2.254 +nm: 255.255.255.0 +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: vpn +public_ip: 209.132.190.12 #br1_ip: 172.31.1.2 #br1_nm: 255.255.255.0 vpn: true - -public_ip: 209.132.190.12 diff --git a/inventory/host_vars/vmhost-a64-cc01.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-a64-cc01.rdu-cc.fedoraproject.org index f99f1abf97..1a66335bd5 100644 --- a/inventory/host_vars/vmhost-a64-cc01.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-a64-cc01.rdu-cc.fedoraproject.org @@ -1,45 +1,38 @@ --- -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 +br0_ipv4: 8.43.85.69 +br0_ipv4_gw: 8.43.85.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: rdu-cc - dns1: 8.8.8.8 - dns_search1: "rdu-cc.fedoraproject.org" dns_search2: "fedoraproject.org" - -has_ipv4: yes -br0_ipv4: 8.43.85.69 -br0_ipv4_nm: 24 -br0_ipv4_gw: 8.43.85.254 - -mac1: 68:05:ca:8a:f2:05 - -br0_port0_mac: "{{ mac1 }}" - -vpn: true -postfix_group: cloud freezes: false - +has_ipv4: yes +mac1: 68:05:ca:8a:f2:05 network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: cloud +vpn: true diff --git a/inventory/host_vars/vmhost-ocp01.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-ocp01.stg.iad2.fedoraproject.org index be39d9ccb6..06fdddc27b 100644 --- a/inventory/host_vars/vmhost-ocp01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-ocp01.stg.iad2.fedoraproject.org @@ -1,9 +1,9 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true -dns: 10.3.163.33 +br0_dev: eno1 br0_gw: 10.3.166.254 br0_ip: 10.3.166.90 br0_nm: 255.255.255.0 -br0_dev: eno1 +dns: 10.3.163.33 +freezes: false +nested: true diff --git a/inventory/host_vars/vmhost-ocp02.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-ocp02.stg.iad2.fedoraproject.org index 490401d591..b0cbcd3b3c 100644 --- a/inventory/host_vars/vmhost-ocp02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-ocp02.stg.iad2.fedoraproject.org @@ -1,9 +1,9 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true -dns: 10.3.163.33 +br0_dev: eno1 br0_gw: 10.3.166.254 br0_ip: 10.3.166.91 br0_nm: 255.255.255.0 -br0_dev: eno1 +dns: 10.3.163.33 +freezes: false +nested: true diff --git a/inventory/host_vars/vmhost-ocp03.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-ocp03.stg.iad2.fedoraproject.org index 4e6efa586d..36b7f64b8c 100644 --- a/inventory/host_vars/vmhost-ocp03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-ocp03.stg.iad2.fedoraproject.org @@ -1,9 +1,9 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true -dns: 10.3.163.33 +br0_dev: eno1 br0_gw: 10.3.166.254 br0_ip: 10.3.166.92 br0_nm: 255.255.255.0 -br0_dev: eno1 +dns: 10.3.163.33 +freezes: false +nested: true diff --git a/inventory/host_vars/vmhost-ocp04.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-ocp04.stg.iad2.fedoraproject.org index 25dcab9792..5235b98ab2 100644 --- a/inventory/host_vars/vmhost-ocp04.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-ocp04.stg.iad2.fedoraproject.org @@ -1,9 +1,9 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true -dns: 10.3.163.33 +br0_dev: eno1 br0_gw: 10.3.166.254 br0_ip: 10.3.166.93 br0_nm: 255.255.255.0 -br0_dev: eno1 +dns: 10.3.163.33 +freezes: false +nested: true diff --git a/inventory/host_vars/vmhost-p08-copr01.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-p08-copr01.rdu-cc.fedoraproject.org index 094bf89596..9b7e8bc9f6 100644 --- a/inventory/host_vars/vmhost-p08-copr01.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-p08-copr01.rdu-cc.fedoraproject.org @@ -1,21 +1,19 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.55 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" +br0_ipv4_nm: 24 +br0_ipv6: "2620:52:3:1:dead:beef:cafe:c007" +br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac4 }}" br1_ipv4: 172.23.5.101 br1_ipv4_nm: 24 - +br1_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes has_ipv6: yes -br0_ipv6: "2620:52:3:1:dead:beef:cafe:c007" -br0_ipv6_nm: 64 -br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - mac0: "40:f2:e9:5d:52:70" mac1: "40:f2:e9:5d:52:71" mac2: "40:f2:e9:5d:52:72" @@ -24,47 +22,43 @@ mac4: "40:f2:e9:5d:50:f8" mac5: "40:f2:e9:5d:50:f9" mac6: "40:f2:e9:5d:50:fa" mac7: "40:f2:e9:5d:50:fb" - -br0_port0_mac: "{{ mac4 }}" -br1_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 - state: up - type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - - name: br1 + name: br0 state: up type: bridge - autoconnect: yes - ip: - address: - - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br1-port0 + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" + auto6: no + dhcp4: no + name: br1 + state: up + type: bridge + - mac: "{{ br1_port0_mac }}" master: br1 - mac: "{{ br1_port0_mac }}" + name: br1-port0 + state: up + type: ethernet diff --git a/inventory/host_vars/vmhost-p08-copr02.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-p08-copr02.rdu-cc.fedoraproject.org index 39d67523c7..e06f42ee28 100644 --- a/inventory/host_vars/vmhost-p08-copr02.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-p08-copr02.rdu-cc.fedoraproject.org @@ -1,21 +1,19 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.54 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" +br0_ipv4_nm: 24 +br0_ipv6: "2620:52:3:1:dead:beef:cafe:c008" +br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac4 }}" br1_ipv4: 172.23.5.117 br1_ipv4_nm: 24 - +br1_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes has_ipv6: yes -br0_ipv6: "2620:52:3:1:dead:beef:cafe:c008" -br0_ipv6_nm: 64 -br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - mac0: "40:f2:e9:5d:53:64" mac1: "40:f2:e9:5d:53:65" mac2: "40:f2:e9:5d:53:66" @@ -24,47 +22,43 @@ mac4: "40:f2:e9:5d:53:5c" mac5: "40:f2:e9:5d:53:5d" mac6: "40:f2:e9:5d:53:5e" mac7: "40:f2:e9:5d:53:5f" - -br0_port0_mac: "{{ mac4 }}" -br1_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 - state: up - type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - - name: br1 + name: br0 state: up type: bridge - autoconnect: yes - ip: - address: - - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br1-port0 + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" + auto6: no + dhcp4: no + name: br1 + state: up + type: bridge + - mac: "{{ br1_port0_mac }}" master: br1 - mac: "{{ br1_port0_mac }}" + name: br1-port0 + state: up + type: ethernet diff --git a/inventory/host_vars/vmhost-x86-01.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-01.iad2.fedoraproject.org index dccf743ac4..6de8f43460 100644 --- a/inventory/host_vars/vmhost-x86-01.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-01.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.11 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.11 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:b1:70:88 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-01.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-01.stg.iad2.fedoraproject.org index ae111bcb0e..743e037606 100644 --- a/inventory/host_vars/vmhost-x86-01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-01.stg.iad2.fedoraproject.org @@ -1,54 +1,47 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.11 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.11 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - -install_noc: noc01.iad2.fedoraproject.org -install_mac: 24-6E-96-B1-C7-F4 # Inside this, expect /vmlinuz and /initrd.img install_binpath: /uefi/x86_64/el8 install_ks: http://10.5.126.23/repo/rhel/ks/hardware-rhel-8-08disk +install_mac: 24-6E-96-B1-C7-F4 +install_noc: noc01.iad2.fedoraproject.org install_repo: http://10.5.126.23/repo/rhel/RHEL8-x86_64/ - mac1: ec:f4:bb:d2:85:ec mac2: ec:f4:bb:d2:85:ed mac3: ec:f4:bb:d2:85:e8 mac4: ec:f4:bb:d2:85:ea - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-02.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-02.iad2.fedoraproject.org index 413a5f1f5a..8a2bc0d248 100644 --- a/inventory/host_vars/vmhost-x86-02.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-02.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.12 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.12 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:ba:e8:44 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-02.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-02.stg.iad2.fedoraproject.org index 03110c9bcd..e6785faea8 100644 --- a/inventory/host_vars/vmhost-x86-02.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-02.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.12 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.12 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 24:6e:96:13:ed:dc mac2: 24:6e:96:13:ed:dd mac3: 24:6e:96:13:ed:d8 mac4: 24:6e:96:13:ed:da - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-03.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-03.iad2.fedoraproject.org index d639873737..c52bfd731d 100644 --- a/inventory/host_vars/vmhost-x86-03.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-03.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.13 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.13 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:b1:28:cc - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-03.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-03.stg.iad2.fedoraproject.org index 5fb39e1a92..39f1236600 100644 --- a/inventory/host_vars/vmhost-x86-03.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-03.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.13 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.13 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 24:6e:96:05:d9:fc mac2: 24:6e:96:05:d9:fd mac3: 24:6e:96:05:d9:f8 mac4: 24:6e:96:05:d9:fa - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-04.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-04.iad2.fedoraproject.org index ddb8dfcf95..318de91ac8 100644 --- a/inventory/host_vars/vmhost-x86-04.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-04.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.14 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.14 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:b1:62:a8 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-04.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-04.stg.iad2.fedoraproject.org index c0103488f3..206df77c3a 100644 --- a/inventory/host_vars/vmhost-x86-04.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-04.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.14 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.14 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 24:6e:96:05:d7:84 mac2: 24:6e:96:05:d7:85 mac3: 24:6e:96:05:d7:80 mac4: 24:6e:96:05:d7:82 - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-05.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-05.iad2.fedoraproject.org index f4d3a2a7a0..4f07301a05 100644 --- a/inventory/host_vars/vmhost-x86-05.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-05.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.15 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.15 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:ae:4b:b8 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-05.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-05.stg.iad2.fedoraproject.org index 10c0626bcf..2dec4889d4 100644 --- a/inventory/host_vars/vmhost-x86-05.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-05.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.15 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac5 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.15 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 18:66:da:f7:7a:58 mac2: 18:66:da:f7:7a:59 mac3: 18:66:da:f7:7a:5a mac4: 18:66:da:f7:7a:5b mac5: a0:36:9f:de:88:28 mac6: a0:36:9f:de:88:2a - -br0_port0_mac: "{{ mac5 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-06.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-06.iad2.fedoraproject.org index a90c8a9a51..59b8726816 100644 --- a/inventory/host_vars/vmhost-x86-06.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-06.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.16 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.16 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:b1:28:ee - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-06.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-06.stg.iad2.fedoraproject.org index 869ed2198f..7fb9a94f8c 100644 --- a/inventory/host_vars/vmhost-x86-06.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-06.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.16 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac5 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.16 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 18:66:da:f7:61:58 mac2: 18:66:da:f7:61:59 mac3: 18:66:da:f7:61:5a mac4: 18:66:da:f7:61:5b mac5: a0:36:9f:de:85:bc mac6: a0:36:9f:de:85:be - -br0_port0_mac: "{{ mac5 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-07.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-07.iad2.fedoraproject.org index e9c201b9be..582d9b1748 100644 --- a/inventory/host_vars/vmhost-x86-07.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-07.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.17 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: e4:43:4b:22:ce:ca - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-07.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-07.stg.iad2.fedoraproject.org index 2110fc1ea1..7b28e46333 100644 --- a/inventory/host_vars/vmhost-x86-07.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-07.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.17 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac4 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.17 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 80:18:44:de:4d:fc mac2: 80:18:44:de:4d:fd mac3: 80:18:44:de:4d:fe mac4: a0:36:9f:f1:83:e0 mac5: 80:18:44:de:4d:ff mac6: a0:36:9f:f1:83:e2 - -br0_port0_mac: "{{ mac4 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-08.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-08.iad2.fedoraproject.org index a8702bfdc0..99cb7e4408 100644 --- a/inventory/host_vars/vmhost-x86-08.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-08.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.28 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.28 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac1: 24:6e:96:b1:61:f8 - -br0_port0_mac: "{{ mac1 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-08.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-08.stg.iad2.fedoraproject.org index 0378304fb9..5846a5fd2d 100644 --- a/inventory/host_vars/vmhost-x86-08.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-08.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.18 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.18 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: 24:6e:96:c1:6e:bc mac2: 24:6e:96:c1:6e:bd mac3: 24:6e:96:c1:6e:b8 mac4: 24:6e:96:c1:6e:ba - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-09.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-09.iad2.fedoraproject.org index 1b54ad9b8e..d4c800db1f 100644 --- a/inventory/host_vars/vmhost-x86-09.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-09.iad2.fedoraproject.org @@ -1,40 +1,34 @@ --- +br0_ipv4: 10.3.163.29 +br0_ipv4_gw: 10.3.163.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac2 }}" datacenter: iad2 - dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search2: "fedoraproject.org" - has_ipv4: yes -br0_ipv4: 10.3.163.29 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.163.254 - mac2: 24:6e:96:b1:61:c0 - -br0_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-09.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-09.stg.iad2.fedoraproject.org index dcd7b92fc9..51444718eb 100644 --- a/inventory/host_vars/vmhost-x86-09.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-09.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.19 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.19 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: ec:f4:bb:e1:c8:f4 mac2: ec:f4:bb:e1:c8:f5 mac3: ec:f4:bb:e1:c8:f0 mac4: ec:f4:bb:e1:c8:f2 - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-10.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-10.stg.iad2.fedoraproject.org index 36be75f66c..19a65de977 100644 --- a/inventory/host_vars/vmhost-x86-10.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-10.stg.iad2.fedoraproject.org @@ -1,47 +1,41 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.20 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac3 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.20 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - mac1: ec:f4:bb:e1:cb:8c mac2: ec:f4:bb:e1:cb:8d mac3: ec:f4:bb:e1:cb:88 mac4: ec:f4:bb:e1:cb:8a - -br0_port0_mac: "{{ mac3 }}" - +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-11.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-11.stg.iad2.fedoraproject.org index d2b7465f9d..9233d858b8 100644 --- a/inventory/host_vars/vmhost-x86-11.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-11.stg.iad2.fedoraproject.org @@ -1,49 +1,43 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true - +br0_ipv4: 10.3.166.28 +br0_ipv4_gw: 10.3.166.254 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search2: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - +freezes: false has_ipv4: yes -br0_ipv4: 10.3.166.28 -br0_ipv4_nm: 24 -br0_ipv4_gw: 10.3.166.254 - -mgmt_mac: 2c:ea:7f:f3:6c:be -mgmt_ipv4: 10.3.160.46 mac1: E4:43:4B:F7:B7:B8 mac2: E4:43:4B:F7:B7:BA mac3: E4:43:4B:F7:B7:D8 mac4: E4:43:4B:F7:B7:D9 - -br0_port0_mac: "{{ mac1 }}" - +mgmt_ipv4: 10.3.160.46 +mgmt_mac: 2c:ea:7f:f3:6c:be +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-12.stg.iad2.fedoraproject.org b/inventory/host_vars/vmhost-x86-12.stg.iad2.fedoraproject.org index 8f791e2272..4e2a05625c 100644 --- a/inventory/host_vars/vmhost-x86-12.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-12.stg.iad2.fedoraproject.org @@ -1,42 +1,38 @@ --- # This virthost only has stg instances, so it doesn't freeze -freezes: false -nested: true -dns: 10.3.163.33 - -has_ipv4: yes br0_ipv4: 10.3.166.29 -br0_ipv4_nm: 24 br0_ipv4_gw: 10.3.166.254 - -mgmt_mac: 2c:ea:7f:f3:82:fc -mgmt_ipv4: 10.3.160.47 +br0_ipv4_nm: 24 +br0_port0_mac: "{{ mac1 }}" +dns: 10.3.163.33 +freezes: false +has_ipv4: yes mac1: E4:43:4B:F7:AD:10 mac2: E4:43:4B:F7:AD:12 mac3: E4:43:4B:F7:AD:30 mac4: E4:43:4B:F7:AD:31 - -br0_port0_mac: "{{ mac1 }}" - +mgmt_ipv4: 10.3.160.47 +mgmt_mac: 2c:ea:7f:f3:82:fc +nested: true network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - gateway4: "{{ br0_ipv4_gw }}" - dns: - - "{{ dns }}" - dns_search: - - stg.iad2.fedoraproject.org - - iad2.fedoraproject.org - - fedoraproject.org - dhcp4: no + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" auto6: no - - name: br0-port0 + dhcp4: no + dns: + - "{{ dns }}" + dns_search: + - stg.iad2.fedoraproject.org + - iad2.fedoraproject.org + - fedoraproject.org + gateway4: "{{ br0_ipv4_gw }}" + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-cc05.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-cc05.rdu-cc.fedoraproject.org index cdb28d42be..5cea3432a7 100644 --- a/inventory/host_vars/vmhost-x86-cc05.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-cc05.rdu-cc.fedoraproject.org @@ -1,90 +1,82 @@ --- -datacenter: rdu-cc - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -vpn: true -postfix_group: cloud -freezes: false - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.84 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" +br0_ipv4_nm: 24 +br0_ipv6: "2620:52:3:1:dead:beef:cafe:f005" +br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" br1_ipv4: 172.23.1.1 br1_ipv4_nm: 24 +br1_port0_mac: "{{ mac1 }}" br2_ipv4: 172.23.5.1 br2_ipv4_nm: 24 - +br2_port0_mac: "{{ mac2 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +freezes: false +gw: 8.43.85.254 +has_ipv4: yes has_ipv6: yes -br0_ipv6: "2620:52:3:1:dead:beef:cafe:f005" -br0_ipv6_nm: 64 -br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - mac0: "ec:f4:bb:d2:97:7c" mac1: "ec:f4:bb:d2:97:7d" mac2: "ec:f4:bb:d2:97:78" mac3: "ec:f4:bb:d2:97:7a" - -br0_port0_mac: "{{ mac0 }}" -br1_port0_mac: "{{ mac1 }}" -br2_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 state: up - type: ethernet + type: bridge + - mac: "{{ br0_port0_mac }}" master: br0 - mac: "{{ br0_port0_mac }}" - - name: br1 - state: up - type: bridge - autoconnect: yes - ip: - address: - - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br1-port0 + name: br0-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" + auto6: no + dhcp4: no + name: br1 + state: up + type: bridge + - mac: "{{ br1_port0_mac }}" master: br1 - mac: "{{ br1_port0_mac }}" - - name: br2 - state: up - type: bridge - autoconnect: yes - ip: - address: - - "{{ br2_ipv4 }}/{{ br2_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br2-port0 + name: br1-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br2_ipv4 }}/{{ br2_ipv4_nm }}" + auto6: no + dhcp4: no + name: br2 + state: up + type: bridge + - mac: "{{ br2_port0_mac }}" master: br2 - mac: "{{ br2_port0_mac }}" + name: br2-port0 + state: up + type: ethernet +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: cloud +vpn: true diff --git a/inventory/host_vars/vmhost-x86-cc06.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-cc06.rdu-cc.fedoraproject.org index 10605a25e6..e564f18500 100644 --- a/inventory/host_vars/vmhost-x86-cc06.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-cc06.rdu-cc.fedoraproject.org @@ -1,90 +1,82 @@ --- -datacenter: rdu-cc - -nrpe_procs_warn: 900 -nrpe_procs_crit: 1000 - -vpn: true -postfix_group: cloud -freezes: false - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.85 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" +br0_ipv4_nm: 24 +br0_ipv6: "2620:52:3:1:dead:beef:cafe:f006" +br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" br1_ipv4: 172.23.1.2 br1_ipv4_nm: 24 +br1_port0_mac: "{{ mac1 }}" br2_ipv4: 172.23.5.2 br2_ipv4_nm: 24 - +br2_port0_mac: "{{ mac2 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +freezes: false +gw: 8.43.85.254 +has_ipv4: yes has_ipv6: yes -br0_ipv6: "2620:52:3:1:dead:beef:cafe:f006" -br0_ipv6_nm: 64 -br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - mac0: "ec:f4:bb:cd:aa:a4" mac1: "ec:f4:bb:cd:aa:a5" mac2: "ec:f4:bb:cd:aa:a0" mac3: "ec:f4:bb:cd:aa:a2" - -br0_port0_mac: "{{ mac0 }}" -br1_port0_mac: "{{ mac1 }}" -br2_port0_mac: "{{ mac2 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 state: up - type: ethernet + type: bridge + - mac: "{{ br0_port0_mac }}" master: br0 - mac: "{{ br0_port0_mac }}" - - name: br1 - state: up - type: bridge - autoconnect: yes - ip: - address: - - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br1-port0 + name: br0-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br1_ipv4 }}/{{ br1_ipv4_nm }}" + auto6: no + dhcp4: no + name: br1 + state: up + type: bridge + - mac: "{{ br1_port0_mac }}" master: br1 - mac: "{{ br1_port0_mac }}" - - name: br2 - state: up - type: bridge - autoconnect: yes - ip: - address: - - "{{ br2_ipv4 }}/{{ br2_ipv4_nm }}" - dhcp4: no - auto6: no - - name: br2-port0 + name: br1-port0 state: up type: ethernet + - autoconnect: yes + ip: + address: + - "{{ br2_ipv4 }}/{{ br2_ipv4_nm }}" + auto6: no + dhcp4: no + name: br2 + state: up + type: bridge + - mac: "{{ br2_port0_mac }}" master: br2 - mac: "{{ br2_port0_mac }}" + name: br2-port0 + state: up + type: ethernet +nrpe_procs_crit: 1000 +nrpe_procs_warn: 900 +postfix_group: cloud +vpn: true diff --git a/inventory/host_vars/vmhost-x86-copr01.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-copr01.rdu-cc.fedoraproject.org index 0fdbff9617..8cf9ec2eca 100644 --- a/inventory/host_vars/vmhost-x86-copr01.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-copr01.rdu-cc.fedoraproject.org @@ -1,19 +1,16 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.57 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" - -has_ipv6: yes +br0_ipv4_nm: 24 br0_ipv6: "2620:52:3:1:dead:beef:cafe:c001" -br0_ipv6_nm: 64 br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes +has_ipv6: yes mac0: "f4:02:70:d0:05:00" mac1: "f4:02:70:d0:05:01" mac2: "b0:26:28:d1:df:00" @@ -22,32 +19,29 @@ mac4: "b4:96:91:63:3b:e8" mac5: "b4:96:91:63:3b:e9" mac6: "b4:96:91:63:3b:ea" mac7: "b4:96:91:63:3b:eb" - -br0_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-copr02.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-copr02.rdu-cc.fedoraproject.org index 67d6a43723..5fbaa0045e 100644 --- a/inventory/host_vars/vmhost-x86-copr02.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-copr02.rdu-cc.fedoraproject.org @@ -1,54 +1,45 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.58 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" - -has_ipv6: yes +br0_ipv4_nm: 24 br0_ipv6: "2620:52:3:1:dead:beef:cafe:c002" -br0_ipv6_nm: 64 br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - - +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes +has_ipv6: yes mac0: "f4:02:70:d0:04:5e" mac1: "f4:02:70:d0:04:5f" mac2: "b4:96:91:63:3b:9c" mac3: "b4:96:91:63:3b:9d" mac4: "b4:96:91:63:3b:9e" mac5: "b4:96:91:63:3b:9f" - -br0_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" - - diff --git a/inventory/host_vars/vmhost-x86-copr03.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-copr03.rdu-cc.fedoraproject.org index 160efaa34f..0728261108 100644 --- a/inventory/host_vars/vmhost-x86-copr03.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-copr03.rdu-cc.fedoraproject.org @@ -1,19 +1,16 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.59 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" - -has_ipv6: yes +br0_ipv4_nm: 24 br0_ipv6: "2620:52:3:1:dead:beef:cafe:c003" -br0_ipv6_nm: 64 br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes +has_ipv6: yes mac0: "f4:02:70:d3:42:48" mac1: "f4:02:70:d3:42:49" mac2: "b0:26:28:d1:dd:c0" @@ -22,32 +19,29 @@ mac4: "b4:96:91:63:3b:50" mac5: "b4:96:91:63:3b:51" mac6: "b4:96:91:63:3b:52" mac7: "b4:96:91:63:3b:53" - -br0_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/vmhost-x86-copr04.rdu-cc.fedoraproject.org b/inventory/host_vars/vmhost-x86-copr04.rdu-cc.fedoraproject.org index c6f0854d8f..9c9090f2cc 100644 --- a/inventory/host_vars/vmhost-x86-copr04.rdu-cc.fedoraproject.org +++ b/inventory/host_vars/vmhost-x86-copr04.rdu-cc.fedoraproject.org @@ -1,19 +1,16 @@ --- -datacenter: rdu-cc - -gw: 8.43.85.254 -dns: 8.8.8.8 - -has_ipv4: yes br0_ipv4: 8.43.85.60 -br0_ipv4_nm: 24 br0_ipv4_gw: "{{ gw }}" - -has_ipv6: yes +br0_ipv4_nm: 24 br0_ipv6: "2620:52:3:1:dead:beef:cafe:c004" -br0_ipv6_nm: 64 br0_ipv6_gw: "2620:52:3:1:ffff:ffff:ffff:fffe" - +br0_ipv6_nm: 64 +br0_port0_mac: "{{ mac0 }}" +datacenter: rdu-cc +dns: 8.8.8.8 +gw: 8.43.85.254 +has_ipv4: yes +has_ipv6: yes mac0: "70:b5:e8:d0:a4:06" mac1: "70:b5:e8:d0:a4:07" mac2: "b0:26:28:d1:e0:f0" @@ -22,32 +19,29 @@ mac4: "b4:96:91:63:3a:a0" mac5: "b4:96:91:63:3a:a1" mac6: "b4:96:91:63:3a:a2" mac7: "b4:96:91:63:3a:a3" - -br0_port0_mac: "{{ mac0 }}" - network_connections: - - name: br0 - state: up - type: bridge - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" - - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + - "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}" + - "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}" + auto6: no + dhcp4: no + dns: + - 8.8.8.8 + - 8.8.4.4 + - 2001:4860:4860::8888 + dns_search: + - fedoraproject.org + - vpn.fedoraproject.org + - rdu-cc.fedoraproject.org gateway4: "{{ br0_ipv4_gw }}" gateway6: "{{ br0_ipv6_gw }}" - dns: - - 8.8.8.8 - - 8.8.4.4 - - 2001:4860:4860::8888 - dns_search: - - fedoraproject.org - - vpn.fedoraproject.org - - rdu-cc.fedoraproject.org - dhcp4: no - auto6: no - - name: br0-port0 + name: br0 + state: up + type: bridge + - mac: "{{ br0_port0_mac }}" + master: br0 + name: br0-port0 state: up type: ethernet - master: br0 - mac: "{{ br0_port0_mac }}" diff --git a/inventory/host_vars/wiki01.iad2.fedoraproject.org b/inventory/host_vars/wiki01.iad2.fedoraproject.org index 8f65cf4c18..c9eeba1a67 100644 --- a/inventory/host_vars/wiki01.iad2.fedoraproject.org +++ b/inventory/host_vars/wiki01.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ipv4: 10.3.163.83 -eth0_ipv4_nm: 255.255.255.0 -eth0_ipv4_gw: 10.3.163.254 -vmhost: vmhost-x86-02.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ipv4: 10.3.163.83 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 255.255.255.0 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: vmhost-x86-02.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/wiki01.stg.iad2.fedoraproject.org b/inventory/host_vars/wiki01.stg.iad2.fedoraproject.org index 789ea639b8..150b319e83 100644 --- a/inventory/host_vars/wiki01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/wiki01.stg.iad2.fedoraproject.org @@ -1,10 +1,10 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ip: 10.3.166.24 -vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ip: 10.3.166.24 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora +nm: 255.255.255.0 +vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/wiki02.iad2.fedoraproject.org b/inventory/host_vars/wiki02.iad2.fedoraproject.org index 24164da332..eee36500d3 100644 --- a/inventory/host_vars/wiki02.iad2.fedoraproject.org +++ b/inventory/host_vars/wiki02.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora -ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ -volgroup: /dev/vg_guests -eth0_ipv4: 10.3.163.102 -eth0_ipv4_nm: 255.255.255.0 -eth0_ipv4_gw: 10.3.163.254 -vmhost: vmhost-x86-06.iad2.fedoraproject.org datacenter: iad2 +dns: 10.3.163.33 +eth0_ipv4: 10.3.163.102 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 255.255.255.0 +ks_repo: http://10.3.163.35/pub/fedora/linux/releases/34/Server/x86_64/os/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-fedora virt_install_command: "{{ virt_install_command_one_nic }}" +vmhost: vmhost-x86-06.iad2.fedoraproject.org +volgroup: /dev/vg_guests diff --git a/inventory/host_vars/worker01.ocp.iad2.fedoraproject.org b/inventory/host_vars/worker01.ocp.iad2.fedoraproject.org index 843797ff1e..7d0d1ab6b8 100644 --- a/inventory/host_vars/worker01.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/worker01.ocp.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: true - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.123 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.123 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: true gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno34 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A3:C9" - -rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.163.65/rhcos/" -rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno34 +rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.163.65/rhcos/" +rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker01.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/worker01.ocp.stg.iad2.fedoraproject.org index e56cab39b0..e2fe7ebae7 100644 --- a/inventory/host_vars/worker01.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/worker01.ocp.stg.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: false - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.118 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.118 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno1 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A2:AC" - -rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.166.50/rhcos/" -rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno1 +rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.166.50/rhcos/" +rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker02.ocp.iad2.fedoraproject.org b/inventory/host_vars/worker02.ocp.iad2.fedoraproject.org index 07b4f385d7..29722340f6 100644 --- a/inventory/host_vars/worker02.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/worker02.ocp.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: true - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.124 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.124 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: true gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno33 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A2:90" - -rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.163.65/rhcos/" -rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno33 +rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.163.65/rhcos/" +rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker02.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/worker02.ocp.stg.iad2.fedoraproject.org index a7a42bc7f8..0feded5cb5 100644 --- a/inventory/host_vars/worker02.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/worker02.ocp.stg.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: false - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.119 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.119 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno1 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A3:24" - -rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.166.50/rhcos/" -rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno1 +rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.166.50/rhcos/" +rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker03.ocp.iad2.fedoraproject.org b/inventory/host_vars/worker03.ocp.iad2.fedoraproject.org index 4add7fb2c9..30cc363514 100644 --- a/inventory/host_vars/worker03.ocp.iad2.fedoraproject.org +++ b/inventory/host_vars/worker03.ocp.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: true - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.163.125 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.163.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.163.125 +eth0_ipv4_gw: 10.3.163.254 +eth0_ipv4_nm: 24 +freezes: true gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno33 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A7:4C" - -rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.163.65/rhcos/" -rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno33 +rhcos_ignition_file_url: "http://10.3.163.65/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.163.165/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.163.65/rhcos/" +rhcos_kernel_url: "http://10.3.163.65/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker03.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/worker03.ocp.stg.iad2.fedoraproject.org index 63329665dc..f816ac2a53 100644 --- a/inventory/host_vars/worker03.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/worker03.ocp.stg.iad2.fedoraproject.org @@ -1,57 +1,47 @@ --- -freezes: false - -datacenter: iad2 - arch: x86_64 - +datacenter: iad2 +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.120 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.120 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - -pxe_bootdev: eno1 +has_ipv4: yes install_dev: /dev/sda mac0: "68:05:CA:CE:A5:10" - -rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" -rhcos_install_url: "http://10.3.166.50/rhcos/" -rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" -rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" -rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" -rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" - network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes + - autoconnect: yes ip: address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" auto6: no - -vpn: true - -nrpe_procs_warn: 1200 + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +pxe_bootdev: eno1 +rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" +rhcos_initrd_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" +rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" +rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" +rhcos_install_url: "http://10.3.166.50/rhcos/" +rhcos_kernel_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-kernel.x86_64" +vpn: true diff --git a/inventory/host_vars/worker04.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/worker04.ocp.stg.iad2.fedoraproject.org index 09ea779459..f70b84467d 100644 --- a/inventory/host_vars/worker04.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/worker04.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.122 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.122 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-06.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/worker05.ocp.stg.iad2.fedoraproject.org b/inventory/host_vars/worker05.ocp.stg.iad2.fedoraproject.org index f5827c461b..24f290d2eb 100644 --- a/inventory/host_vars/worker05.ocp.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/worker05.ocp.stg.iad2.fedoraproject.org @@ -1,60 +1,49 @@ --- -freezes: false - datacenter: iad2 - -vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org -volgroup: /dev/vg_guests -lvm_size: 120g -mem_size: 16384 -max_mem_size: 16384 -num_cpus: 4 - +dns: "{{ dns1 }}" dns1: 10.3.163.33 dns2: 10.3.163.34 - dns_search1: "stg.iad2.fedoraproject.org" dns_search3: "fedoraproject.org" - -has_ipv4: yes -eth0_ipv4: 10.3.166.123 -eth0_ipv4_nm: 24 -eth0_ipv4_gw: 10.3.166.254 eth0_ip: "{{eth0_ipv4}}" -nm: 255.255.255.0 +eth0_ipv4: 10.3.166.123 +eth0_ipv4_gw: 10.3.166.254 +eth0_ipv4_nm: 24 +freezes: false gw: "{{ eth0_ipv4_gw }}" -dns: "{{ dns1 }}" - +has_ipv4: yes +lvm_size: 120g mac0: "{{ ansible_default_ipv4.macaddress }}" - +max_mem_size: 16384 +mem_size: 16384 +network_connections: + - autoconnect: yes + ip: + address: + - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" + auto6: no + dhcp4: no + dns: + - "{{ dns1 }}" + - "{{ dns2 }}" + dns_search: + - "{{ dns_search1 }}" + - "{{ dns_search2 }}" + - "{{ dns_search3 }}" + gateway4: "{{ eth0_ipv4_gw }}" + mac: "{{ mac0 }}" + name: eth0 + state: up + type: ethernet +nm: 255.255.255.0 +nrpe_procs_crit: 1400 +nrpe_procs_warn: 1200 +num_cpus: 4 rhcos_ignition_file_url: "http://10.3.166.50/rhcos/worker.ign" rhcos_install_img_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-metal.x86_64.raw.gz" rhcos_install_rootfs_url: "http://10.3.166.50/rhcos/rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" rhcos_install_url: "http://10.3.166.50/rhcos/" - virt_install_command: "{{ virt_install_command_pxe_rhcos }}" - -network_connections: - - name: eth0 - mac: "{{ mac0 }}" - state: up - type: ethernet - autoconnect: yes - ip: - address: - - "{{ eth0_ipv4 }}/{{ eth0_ipv4_nm }}" - gateway4: "{{ eth0_ipv4_gw }}" - dns: - - "{{ dns1 }}" - - "{{ dns2 }}" - dns_search: - - "{{ dns_search1 }}" - - "{{ dns_search2 }}" - - "{{ dns_search3 }}" - dhcp4: no - auto6: no - +vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org +volgroup: /dev/vg_guests vpn: true - -nrpe_procs_warn: 1200 -nrpe_procs_crit: 1400 diff --git a/inventory/host_vars/zabbix01.stg.iad2.fedoraproject.org b/inventory/host_vars/zabbix01.stg.iad2.fedoraproject.org index 63e723be0a..54c007fa10 100644 --- a/inventory/host_vars/zabbix01.stg.iad2.fedoraproject.org +++ b/inventory/host_vars/zabbix01.stg.iad2.fedoraproject.org @@ -1,11 +1,11 @@ --- -nm: 255.255.255.0 -gw: 10.3.166.254 +datacenter: iad2 dns: 10.3.163.33 -ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 -ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ -volgroup: /dev/vg_guests eth0_ip: 10.3.166.61 eth0_nm: 255.255.255.0 +gw: 10.3.166.254 +ks_repo: http://10.3.163.35/repo/rhel/RHEL8-x86_64/ +ks_url: http://10.3.163.35/repo/rhel/ks/kvm-rhel-8-iad2 +nm: 255.255.255.0 vmhost: vmhost-x86-07.stg.iad2.fedoraproject.org -datacenter: iad2 +volgroup: /dev/vg_guests