Commit Graph

4228 Commits

Author SHA1 Message Date
James Antill
03865d03b3 batcave: Move from mirror_pagure_ansible to mirror_forge_ansible.
Signed-off-by: James Antill <james@and.org>
2026-02-16 18:17:13 -05:00
Pavel Raiskup
55f225d428 copr-hv: typofix 2026-02-16 08:11:22 +01:00
Pavel Raiskup
7faef4610c copr-hv: tag the Copr-specific role 2026-02-16 08:09:51 +01:00
David Kirwan
ec59933a54 adding os-control01 to backups01 management
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-01-28 13:49:54 +00:00
Kevin Fenzi
9717d920af anubis: rename anubis-el8 to anubis-el and see about enabling on download
Looks like the scrapers are hitting the download servers now.
So, look at setting up an anubis pod there like we did for pagure.
anubis package isn't available for epel9, so we just use the container.

Will test this with dl01 and tweak until it's working.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-22 08:50:34 -08:00
James Antill
bded16fdab stg.pagure.io: Test against pagure-staging. Also change prod. test.
Signed-off-by: James Antill <james@and.org>
2026-01-16 15:07:45 -05:00
Kevin Fenzi
eac03a251a download-iso01: adjust for new location
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:44:09 -08:00
Kevin Fenzi
56ce3d434c proxies: fix creates in shell call
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 08:49:43 -08:00
Greg Sutcliffe
d08b0f7814 Proxies: Fix indentation in proxy playbook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 16:45:19 +00:00
Greg Sutcliffe
e2bc07005c Zabbix: add external http connectivity checks to proxies
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 16:40:16 +00:00
Greg Sutcliffe
7a96ab49e8 Zabbix: proxy playbook is erroring, add this new role elsewhere
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:07:13 +00:00
Greg Sutcliffe
56fc4590f7 Zabbix: try simpler role include
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:04:56 +00:00
Greg Sutcliffe
feee862e77 Zabbix: Add grab-bag of SSL checks to proxy01(.stg)
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 12:59:31 +00:00
Pavel Raiskup
17fc107bac copr-be: disable storinator backups (the server is being moved) 2025-12-10 09:18:30 +01:00
Kevin Fenzi
452cb142ac virthost: install collectd on fedora based virthosts
collectd would be nice on bvmhost-p10-01/02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-09 15:40:08 -08:00
Kevin Fenzi
79c110457c proxies: do not sync docs if they are already synced
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-09 11:33:19 -08:00
Greg Sutcliffe
8bea488272 Zabbix: Add Datanommer monitoring to noc01
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-09 16:59:35 +00:00
Gregory Bartholomew
bfcd857278 retire legacy fedora websites repo phase 2
Signed-off-by: Gregory Bartholomew <gregory.lee.bartholomew@gmail.com>
2025-12-04 20:48:05 +00:00
Kevin Fenzi
70c964ed9b pagure02: fare thee well.
We have moved to pagure01, retire pagure02

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-03 16:20:22 -08:00
Kevin Fenzi
91ca2a6bf3 pagure-stg01: say fare thee well
We have moved over to pagure-stg02 now in rdu3, so retire this vm.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-02 14:28:06 -08:00
Greg Sutcliffe
b462567522 Firmware: add a proxy to reach downloads.dell.com
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-11-20 13:58:07 +00:00
Gregory Bartholomew
c509e526fb retire legacy fedora websites repo phase 1
Signed-off-by: Gregory Bartholomew <gregory.lee.bartholomew@gmail.com>
2025-11-14 18:31:40 +00:00
Michal Konecny
a75f88d99d [ipa] Fix staging audit tasks
It seems like somebody just copied the production tasks for staging
without changing the LDAP domain, which caused the staging task to fail.
This commit is fixing that. And tagging the related tasks as well.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-11-14 09:52:16 +01:00
Kevin Fenzi
099d86607b buildvm: add buildvm_s390x_stg to groups we virt install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-11-04 17:43:20 -08:00
Kevin Fenzi
914ac1e646 virthost: no serial on power10 lpars
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-11-04 12:34:55 -08:00
Kevin Fenzi
3b00ae4c60 virthost: setup iscsi on all bvmhost-p10s
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-11-04 11:42:20 -08:00
Kevin Fenzi
57f4a541a0 buildhw-p10-02.stg: add new power10 stg lpar
This isn't really a 'buildhw', but it's pretty close.
It's an lpar on a power10 box.

I'm making it a hw builder in staging because if we tried to make
it a bvmhost and put vm's on it, we would need to setup macvtap, which
would be fine, but extra complication where we don't really need it in
staging currently.

01 will be created once we reconfigure the one thats currently serving
as bvmhost-p10-01. Which will happen after we move 1/2 the builders
off to a new bvmhost-p10-02 lpar on this same second power10.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-11-03 16:29:11 -08:00
Kevin Fenzi
7d459bcfd0 ipa: enable audit logs on ipa01/ipa01.stg
We had this set before the dc move in iad2, but we didn't ever setup the
config to enable it in rdu3.

This should do that.

Note that I have already manually enabled it, and this should just
ensure that it's enabled if we reinstall or move to the next datacenter.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-30 18:48:45 +00:00
Aurélien Bompard
cb4cb65387 IPA-tuura: configure sssd ourselves
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-23 18:05:53 +02:00
Aurélien Bompard
9e8f678437 IPA-tuura: dont use the httpd/mod_ssl role
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-22 13:53:15 +02:00
Aurélien Bompard
dc87c6ded8 Deploy IPA-tuura directly in the VM
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-22 13:39:50 +02:00
Kevin Fenzi
210e8b3e16 copr-hypervisor: fix missing name=
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-21 13:53:50 -07:00
Kevin Fenzi
095d5d0cca copr-hypervisor: fix indentation
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-21 13:49:12 -07:00
Kevin Fenzi
d2b4bbd372 copr-hypervisor / p09: add nbde handling in rdu3
This adds network block device encryption to the 3 (so far) power9's in
rdu3. This will allow them to unlock encrypted partitions from our
tang server(s).

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-21 13:46:06 -07:00
Aurélien Bompard
0feed3e810 IPAtuura: fix login IPA rule
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-21 17:32:37 +02:00
Aurélien Bompard
8206161d13 Configure authentication in IPA for IPA-tuura
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-21 17:26:08 +02:00
Aurélien Bompard
8de72a0f0c Use our postgresql server for IPA-tuura
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-21 16:12:10 +02:00
Aurélien Bompard
5dd03158f9 ipatuura01: make it an IPA client
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-16 15:28:49 +02:00
Aurélien Bompard
fb967d743a IPA-tuura: add role
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-14 15:46:02 +02:00
Greg Sutcliffe
9b38df0550 Certs: Use renewed *.fedorapeople.org cert
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-10-07 22:00:26 +01:00
James Antill
12cc938618 kojipkgs: Add rsyncd role for transfering log files. issue#12833
Signed-off-by: James Antill <james@and.org>
2025-10-06 16:13:02 -04:00
Kevin Fenzi
271598a0b6 virthost: collectd is not available in epel10 yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-06 08:21:48 -07:00
Kevin Fenzi
34f41fe5f4 ipatura: enable nagios_client
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-10-04 16:47:59 -07:00
Aurélien Bompard
fdfddc6e1f First of a probably long line of fixes to the ipa-tuura playbook
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-03 15:15:59 +02:00
Aurélien Bompard
991a0a81eb Add the new VM for IPA-tuura
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-10-03 14:50:34 +02:00
Greg Sutcliffe
cf9f2d9442 Zabbix: Add copr-* hosts to zabbix role
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-09-29 17:10:08 +01:00
Pavel Raiskup
d217ab4b30 logdetective: another workaround
Skip the whole include.
2025-09-29 17:04:07 +02:00
Pavel Raiskup
a1194d943e logdetective: try to work-around buggy zabbix base/ role 2025-09-29 17:00:07 +02:00
Kevin Fenzi
07eef522f4 proxies: drop tag on the task
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-09-24 17:11:43 -07:00
Kevin Fenzi
c8f5519169 proxies: set local_port_range to under 32k
This works around a weird problem in rdu3. Proxies have connections to
kojipkgs timeout if the local port is over 32k. We aren't sure why this
happens yet, but this seems to work around the problem for now.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-09-24 17:08:02 -07:00