Commit Graph

31 Commits

Author SHA1 Message Date
Kevin Fenzi
ebd01fab62 robosignatory: small fixes
Fix the fedora-41 key, had too many characters there.
Also, the add-key script needs to be readable by the robosignatory user,
so it can't be mode 711.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-02-08 15:35:31 -08:00
Kevin Fenzi
c764d1ea86 autosign: adjust playbooks for prod
We need to setup things in prod slightly differently, using keyctl.
Copy in the service and scripts.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-01-30 09:33:45 -08:00
Aurélien Bompard
6ed2d3ab2d Robosig: restart on config changes
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-06-27 18:23:40 +02:00
Patrick Uiterwijk
9b0bddf050 Update robosignatory role for py3
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-06-10 10:08:51 +02:00
Patrick Uiterwijk
f30c881bf5 Use tmpfiles for the ask-password ACL
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-06-10 09:58:24 +02:00
Patrick Uiterwijk
f5d9df89ac Allow robosignatory to use systemd-ask-password
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-06-10 09:30:29 +02:00
Patrick Uiterwijk
0abfb431da Revert "Temporarily don't install python2-robosig"
This reverts commit 6bb193ba14.
2020-06-09 21:57:26 +02:00
Patrick Uiterwijk
6bb193ba14 Temporarily don't install python2-robosig
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-06-09 21:56:22 +02:00
Kevin Fenzi
9bc3ceb2a2 robosignatory: uid/gid change for autosign
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:28 +02:00
Kevin Fenzi
7972e75131 robosign: only use fm-message service in stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:25 +02:00
Kevin Fenzi
b484b4038d robosignatory: add a tag for just updating the config
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:23 +02:00
Kevin Fenzi
c55fd61bb8 robosignatory: Use gid 988 for robosignatory group.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:12 +02:00
Aurélien Bompard
2149c1ffb3 Fix ownership of files in the sigul directory
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-04-24 21:34:12 +02:00
Aurélien Bompard
a6a33d14e5 Robosignatory: install fedora-messaging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-04-24 21:34:12 +02:00
Kevin Fenzi
c0c05799b7 robosignatory: add group first before user.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:11 +02:00
Aurélien Bompard
46914eae7b Update Robosignatory
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-04-24 21:34:11 +02:00
Patrick Uiterwijk
7608ce4d49 Fix up robosig koji conf in stg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2019-07-03 13:39:02 +00:00
Patrick Uiterwijk
adcbf72f03 Packageize this, packageize that, packageize the world
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-08 22:25:52 +00:00
Patrick Uiterwijk
2c916ebfe2 This dir is in the package
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-05-09 18:10:40 +00:00
Patrick Uiterwijk
cc13dcaacf Add sigul pkg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-05-09 18:10:03 +00:00
Patrick Uiterwijk
0e5508d13a Add sigul dir
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-05-09 17:59:08 +00:00
Patrick Uiterwijk
4b4782a8ff No cert needed for robosignatory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-12-11 20:53:33 +00:00
Patrick Uiterwijk
1b4e469a96 Add sigul configuration for autosign
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-10-17 09:37:36 +00:00
Patrick Uiterwijk
405d4b5093 Add robosignatory tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-27 00:17:40 +00:00
Patrick Uiterwijk
2fb4b617f3 Autosign f26-pending -> f26
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-26 16:01:41 +00:00
Patrick Uiterwijk
4f239c979b TPM stuff is needed by autosign
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 19:56:09 +00:00
Patrick Uiterwijk
d66260bc46 Add koji config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 18:51:08 +00:00
Patrick Uiterwijk
467bc9ca40 I really cant do filesystem locations
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 18:41:10 +00:00
Patrick Uiterwijk
7da95bb7c7 Fix typo
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 18:39:16 +00:00
Patrick Uiterwijk
a7371ea44b Create koji cert for autosign
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 18:35:14 +00:00
Patrick Uiterwijk
75d3a06353 Add robosignatory plays
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2016-09-14 16:38:08 +00:00