Commit Graph

15347 Commits

Author SHA1 Message Date
Kevin Fenzi
4e51f101be base: Just change this to run on rhel7 and rhel6 only with yum. The next task works for fedora hosts.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-08 20:55:09 +00:00
Kevin Fenzi
fef0fcbc0e base: fix initial libselinux task to not run on python3 hosts as package: doesn't work there.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-08 20:51:14 +00:00
Kevin Fenzi
3359779879 nfs/client: exempt koji01.stg from the nfs route as well.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-08 20:18:38 +00:00
Patrick Uiterwijk
0c7449ea1d Add sslciphers tags
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-08 21:41:17 +02:00
Kevin Fenzi
9f4bf69eae pagure / src.fp.o: Drop fedora-altarch, as it's not used. Add cvsadmin as we want them to have access to everything.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-08 19:26:32 +00:00
Patrick Uiterwijk
5080bfbee2 basessh: sandbox privsep is not supported on el6
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-08 19:13:21 +02:00
Patrick Uiterwijk
9b09d4d5d0 basessh: Fix EL6 detection logic
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-08 19:11:40 +02:00
Patrick Uiterwijk
27a21881d4 basessh: Make keyhelper explicit
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-08 18:56:03 +02:00
Patrick Uiterwijk
4f3c609815 basessh: Migrate sshd config to single template and strengthen ciphers
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-08 18:51:31 +02:00
Mikolaj Izdebski
1655385dfb koschei/backend: Fix refreshing of dist-git groups 2019-04-08 17:02:20 +02:00
Mikolaj Izdebski
913a8f8efa koji_hub: Fix syntax error in tag policy 2019-04-08 16:32:40 +02:00
Pierre-Yves Chibon
30f7f775b4 Have pagure log commits on all branches
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2019-04-08 12:24:27 +02:00
Kevin Fenzi
43c318a288 dnf-automatic: stdout seems to always be defined, even if empty. Switch to looking at the return code.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-06 21:56:33 +00:00
Kevin Fenzi
bedfc92290 epylog: weed out more things that we see all the time.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-06 16:53:36 +00:00
Kevin Fenzi
b9100fd1ac repospanner: Set hosts entry for fedora03 (repospanner01.phx) so it can talk to itself over lo instead of hairpin
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-06 16:30:00 +00:00
Kevin Fenzi
b6a8c7d5e5 base: only install policycoreutils-python-utils on f28+
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-05 22:42:43 +00:00
Patrick Uiterwijk
1bb89a3799 Add aws-docs
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-05 22:21:15 +02:00
Stephen Smoogen
194b0058c6 remove retrace02 from inventory and files. Leave mgmt as it is still plugged in and may show up. 2019-04-05 19:19:58 +00:00
Patrick Uiterwijk
e4aed9c9f2 Delete object file from disk
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-05 21:07:38 +02:00
Patrick Uiterwijk
dc591da083 Add openshift/object-delete role
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-05 21:05:46 +02:00
Clement Verna
a557b6c166 Greenwave: Add a comment to explain why we use prod koji in stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 16:04:04 +02:00
Pierre-Yves Chibon
25b12364ea greenwave: Include the topic_prefix in fedora-messaging's config 2019-04-05 15:19:20 +02:00
Clement Verna
acdecfd3ac Greenwave: Use fedora-messaging to publish messages in stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 14:53:19 +02:00
Clement Verna
bb0f922dc4 Greenwave: Point stg to use prod koji for temporary test
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 14:20:03 +02:00
Clement Verna
11ccd305fe Greenwave: Use greenwave.fp.o url instead of the app.os.fp.o
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 13:51:51 +02:00
Clement Verna
2d83bce1e6 Greenwave: use the correct greenwave URL in stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 13:37:14 +02:00
Clement Verna
ead3c8a64d Greenwave: use the correct url to get decision
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-05 13:30:52 +02:00
Pierre-Yves Chibon
4b8f8b16f5 greenwave: Allow considering dist.rpmgrill in stg
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2019-04-05 13:20:41 +02:00
Miroslav Suchý
1a36d53dd2 retrace: pull-associates no longer have --opsys-release 2019-04-05 12:23:57 +02:00
Miroslav Suchý
a1b93dd589 retrace: two cronjob cannot have the same name 2019-04-05 12:23:57 +02:00
Pierre-Yves Chibon
66f016c725 greenwave: Split the configmap into multiple files, easier to edit/review
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2019-04-05 11:32:29 +02:00
Miroslav Suchý
4b4fed942c copr: install our lograte for httpd
with rotate 5
otherwise old logs get deleted
2019-04-05 10:08:44 +02:00
Jakub Kadlčík
f8060b5a90 Allow 'copr' user to run 'sign' command
See https://pagure.io/copr/copr/issue/636

By default only root can run the `sign` command. This
check is applied within obs-signd code. We need to
allow regular user in the config, see `man sign.conf`.

Also /usr/bin/sign is owned by root:obsrun with
-rwsr-x--- hence we need to add a user to the obsrun group.
2019-04-05 09:52:28 +02:00
Miroslav Suchý
478e356787 copr: make sure crond is running 2019-04-05 09:50:00 +02:00
Miroslav Suchý
2473d37473 retrace: use rabbitmq proxy 2019-04-05 09:03:50 +02:00
Jeremy Cline
9e7074570c rabbitmq_cluster: Create the public vhost before the admin user
The admin user needs access to the public vhost, but it needs to exist
first.
2019-04-04 23:04:55 +00:00
Kevin Fenzi
4cd704e5fc syncHttpLogs.sh: remove also proxy07, which no longer exists.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-04 22:04:38 +00:00
Patrick Uiterwijk
c7debaf72d Add proxy101/110 to syncHttpLogs
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-04 23:46:02 +02:00
Patrick Uiterwijk
7e77debb8f Register aws-infra with Ipsilon
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-04 23:25:35 +02:00
Patrick Uiterwijk
7eb1a3e749 repoSpanner: add forgotten slash for creates: check
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-04-04 23:22:43 +02:00
Mohan Boddu
3f8eef498b Adding coreos-continuous permissions to koji hub policy
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2019-04-04 14:13:39 +00:00
Martin Kutlak
06f22add98 Migrate faf from fedmsg to fedora-messging
Signed-off-by: Martin Kutlak <mkutlak@redhat.com>
2019-04-04 15:13:14 +02:00
Mikolaj Izdebski
c00b7bccfc koschei/backend: Add dynamic stewardship-sig group (#7687) 2019-04-04 13:54:51 +02:00
Mikolaj Izdebski
92fda44f20 koschei-refresh-distgit-group: Make it possible to replace group contents 2019-04-04 13:52:51 +02:00
Kevin Fenzi
9289585d21 kojipkgs role: disable welcome.conf as it messes with haproxy heelth checks
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-04-03 17:15:30 +00:00
Pierre-Yves Chibon
2b37c83ae3 distgit/pagure: Increase the cross-project ACLs
This just makes pagure accept to generate project-less API tokens
with these two ACLs.

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2019-04-03 11:50:08 +02:00
Clement Verna
83a7c00ed0 Greenwave: Update policies in stg with fedora-31
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-03 11:36:20 +02:00
Clement Verna
3489800151 Greenwave: try to set fedora-messaging root logger to DEBUG
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-03 11:13:20 +02:00
Clement Verna
17da1591ae Greenwave: Use debug log level in the fedora-messaging consumer
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-03 11:00:11 +02:00
Clement Verna
40e1b382a4 Greenwave: use the correct topic for waiverdb messages
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-03 10:30:57 +02:00