Commit Graph

34718 Commits

Author SHA1 Message Date
Ryan Lerch
31cc6b81ae update bodhi upgrade migration bool phx2 -> iad2
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-04-19 09:15:42 +10:00
Ryan Lerch
44ba9627eb prepare for deploying bodhi 5.7.0 to staging
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-04-19 08:40:39 +10:00
Ryan Lerch
9a11a95feb remove batcave's retrieve-security-question.py
Removes the batcave script, retrieve-security-question.py
which is no longer needed with Noggin / FreeIPA-FAS

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-04-19 08:38:25 +10:00
Kevin Fenzi
c902575f49 openvpn / base: clean up more RedHat and el6 conditionals
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 14:32:36 -07:00
Kevin Fenzi
c0eba5712b openvpn /client: drop another unneeded conditional
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 14:25:17 -07:00
Kevin Fenzi
519b756751 openvpn / client: drop another unneeded conditional
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 14:20:19 -07:00
Kevin Fenzi
9403ed2309 openvpn / client: drop tons of old cruft for el6 and old openvpn
We had a bunch of old el6 conditionals in here, and we have 0 el6
machines. We also now have some CentOS instances, so we shouldn't check
for RedHat or Fedora anymore. Also, everything is using the newer
openvpn now so no need to make sure the old one is stopped.
This should not affect the vast majority of hosts, but it should allow
the el7/el8-test instances vpns to actually work.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 14:09:33 -07:00
Kevin Fenzi
548e3b5332 maintainer-test / copr-hypervisor: clean up playbook and variables.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 13:03:25 -07:00
Kevin Fenzi
8a59695693 Add maintainer_test and copr vmhosts to vpn
We need to add these hosts to the vpn to use ipa for auth on them.
They are in the 192.168.100 network, which is the 'more restricted'
subnet of vpn. After the freeze we will probibly want to lock this down
more with a rule on all hosts except ipa* to reject everything from
them. In the mean time the firewall rules blocking most things should be
ok for now.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-16 11:38:26 -07:00
Kevin Fenzi
eddb753a8a bodhi-backend: mount new fedora_ftp_archive volume here
We need this volume here also because this is where the cron job that
calculates the DIRECTORY_SIZES.txt file lives.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-15 15:45:26 -07:00
Mark O'Brien
cba637c5c2 ipa: otp script fix dest name 2021-04-15 21:01:46 +01:00
Kevin Fenzi
fd72c22857 Freeze break request: move /pub/archive from fedora_ftp to fedora_ftp_archive volume
Our fedora_ftp volume is on an SSD aggregate thats running out of space.
So, lets move /pub/archive (17TB) off it on to it's own volume on a
SAS aggregate. archive gets less traffic that other releases, so it
shouldn't be a problem. This will mean however when we archive a release
it will cause a bunch of deletes and re-downloads for mirrors because we
can no longer hardlink content over and then delete it, but there is no
help for that.

I will also notify mirror-admins list about this pending action.
There shouldn't be any short term issues.

Once this PR is merged, we need to run playbooks, then go to a host with
rw access to fedora_ftp and rm the archive tree on it.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-15 19:53:08 +00:00
Mark O'Brien
d3927bb3c9 ipa: otp script add tags 2021-04-15 20:29:58 +01:00
Mark O'Brien
ecf0dadc3b add script 2021-04-15 18:23:12 +00:00
Mark O'Brien
b8515e6bce ipa: add script to check which sysadmins do not have otp tokens 2021-04-15 18:23:12 +00:00
Mark O'Brien
8091926e71 ipa: add second stg server 2021-04-15 15:35:08 +01:00
Pavel Raiskup
41580c6a22 copr-vmhost: try to fix sudo 2021-04-15 10:56:01 +02:00
Mohan Boddu
c062941d0a Revert "bodhi / backend: fesco wants to keep 3 days to stable until final"
Now that F33 is released, we should revert back to original.

Fixes: https://pagure.io/releng/issue/10087

This reverts commit df8e13732d.
2021-04-12 19:26:55 +00:00
Michael Scherer
535b396f95 Add the role for translation on sundries 2021-04-12 19:18:38 +00:00
Stephen Coady
88b6b0e0b6 2 bug fixes in the fasjson email aliases script
Signed-off-by: Stephen Coady <scoady@redhat.com>
2021-04-12 19:14:10 +00:00
Kevin Fenzi
5a7bf06620 buildvm-ppc64le: update mac addresses on hosts being reinstalled after bvmhost-p09-02 raid rebuild
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-12 08:30:31 -07:00
Kevin Fenzi
db93fb75cc buildvm-ppc64le: need eth0_ip for now for installs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-12 08:05:26 -07:00
Nick Bebout
457622b732 Remove people who didn't respond to sysadmin-badges ticket from tahrir.admin 2021-04-10 20:14:05 -05:00
Kevin Fenzi
e3e490786c koji_builder / staging: drop ntp/ntpdate for f34
Split out the koji_builder package installs so we can drop ntp/ntpdate
for f34 (they were replaced by ntpsec and we use chrony anyhow).
After we move prod to f34 we should merge these back.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-09 10:21:40 -07:00
František Zatloukal
599ead04f3 testdays: use resultsdb from develop instead of a separate branch 2021-04-09 14:59:47 +02:00
Pavel Raiskup
4406d8dfeb copr-frontend: restart apache on service file change 2021-04-09 14:09:26 +02:00
Pavel Raiskup
8513861bb8 copr-frontend: keep httpd going on child's OOM kill 2021-04-09 14:04:46 +02:00
Pierre-Yves Chibon
d4894b011c proxies: redirect apps.fp.o/calendar to calendar.fp.o in openshift
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-04-09 09:37:51 +02:00
Kevin Fenzi
cc736849e2 ipa/client: split out prod and stg ipa user/group ignore file
We need to also add mock to sssd ignore groups/users, but for now since
we are frozen, only do this in staging. After freeze, we should merge
this back into one file.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 17:15:51 -07:00
Kevin Fenzi
5c397154fc buildvm-a32-01.stg: new install, new mac
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 15:44:37 -07:00
Kevin Fenzi
e9966e543c virt-install: use inst. in front of anaconda parameters
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 15:28:44 -07:00
Kevin Fenzi
18bc52df65 buildvm-a32-01.stg: f34 is not released yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 14:55:09 -07:00
Frank Ch. Eigler
77d79cfe8a debuginfod proxy: fix ProxyPassReverse typo (no proxyopts there) 2021-04-08 21:53:30 +00:00
Kevin Fenzi
1d57a07876 buildvm-a32-01.stg: need to define eth0_ip also for virt-install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 14:51:25 -07:00
Kevin Fenzi
469cc3e027 buildvm-a32-01.stg: switch to f34 and see if OOM bug is still there
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 14:47:21 -07:00
Kevin Fenzi
596af2682b Default x_forward to false to make last commit work
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-08 14:12:39 -07:00
Frank Ch. Eigler
a93b8d24c0 debuginfod proxies: enable gzip
elf/dwarf/source-code data from debuginfod is highly compressible.
Let's trade proxy CPU for reduce network traffic.
2021-04-08 20:58:52 +00:00
Frank Ch. Eigler
c37d51d236 proxies/debuginfod: allow proxyopts
debuginfod can take O(60s) to run certain webapi queries, so the httpd
mod_proxy default timeouts are too short.  Introduce an ansible
variable "proxyopts", expanded into the httpd ProxyPass and
ProxyPassReverse configuration lines.  Default to "", but set it
with pretty generous limits for debuginfod only.
2021-04-08 20:58:52 +00:00
Adam Williamson
61af6f34ca openQA: update server config (disable audit, tweak cleanup)
We never use the auditing stuff, so let's turn it off (and set
short limits for audit event duration so we can run the cleanup
and get rid of existing audit events). Let's also use the new
setting that only runs asset cleanup if free space is low.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-04-08 09:24:23 -07:00
Adam Williamson
a889649c46 openqa: bump asset size allocations a bit
We have more space on the IAD servers, so let's use it.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-04-08 09:24:23 -07:00
František Zatloukal
1b362400f5 oraculum: Increase timeouts of probes 2021-04-08 12:00:41 +02:00
Pierre-Yves Chibon
26ca32d11d people: Do not try to chown the file, the cron already runs as apache
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-04-07 19:46:44 +00:00
Pierre-Yves Chibon
692647ed86 people: when making the people page account for home directory we can't get into
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-04-07 19:46:44 +00:00
Kevin Fenzi
cb4524e34f releng-compose / compose-rawhide: add mount for ftp archive volume
We are going to sync the contents from fedora_ftp/pub/archive over to
fedora_ftp_archive volume. This will free up 17TB or so on the SSD
aggregate that fedora_ftp is on.

This will mean more mirror churn when we archive old releases, but
there's not much else we can do besides this or more ssd storage.

This is ok to do during freeze as compose-rawhide is not frozen. :)

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-04-07 12:43:18 -07:00
Stephen Smoogen
a67c6ed272 Did not read pspaceks comment correctly. If we were running fedora on nameservers we could go to 100k. For EL8/7 we can go to 1000
Signed-off-by: Stephen Smoogen <smooge@smoogespace.com>
2021-04-07 10:40:45 -04:00
Stephen Smoogen
a81783e13e Update per pspacek to 100k TCP connections
Signed-off-by: Stephen Smoogen <smooge@smoogespace.com>
2021-04-07 10:32:16 -04:00
Stephen Smoogen
764ef65e98 Change named settings for tcp connections
In order to try and fix the number of TCP connections allowed to get
to the dns servers by increasing from the default 100 to 1000. This
will hopefully help fix the issue in
https://pagure.io/fedora-infrastructure/issue/9850 where the name
servers are not able to answer TCP connections after a while.

Signed-off-by: Stephen Smoogen <smooge@smoogespace.com>
2021-04-07 14:27:29 +00:00
František Zatloukal
5323f6d5fc oraculum: Set workers back to 8 per container 2021-04-07 12:36:52 +02:00
Pierre-Yves Chibon
26bfef7853 fedocal: build in staging from the staging branch again
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-04-07 12:12:47 +02:00
František Zatloukal
b05efc7091 oraculum: Try 1 worker per container 2021-04-07 12:06:43 +02:00