Commit Graph

43401 Commits

Author SHA1 Message Date
Kevin Fenzi
7ccc6eedf7 kickstarts: add a 6disk aarch64 kickstart
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 19:01:35 -07:00
Kevin Fenzi
f8a4c47114 autosign01.rdu3: correct mac address
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 18:28:20 -07:00
Kevin Fenzi
f98d489d1c kickstarts: fix 06 disk virthost install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 17:13:53 -07:00
Kevin Fenzi
2d71695c8d autosign01.rdu3: install autosign01 in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 16:58:00 -07:00
Kevin Fenzi
ba3f974983 bastion02: add host vars
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 16:40:21 -07:00
Kevin Fenzi
49370a3a4b add a bastion02.rdu3 in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 16:38:40 -07:00
Kevin Fenzi
cc75154d1e sundries02.rdu3: use correct ip instead of duplicating sundries01s
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 16:23:25 -07:00
Kevin Fenzi
1ec215d64e sundries / rdu3: 2g of memory is not enough anymore
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 15:22:21 -07:00
Pedro Moura
48b9bfba2f proxies / rdu3: updated repo link to use f42 and removed vmhost-x86-09.stg.rdu3
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2025-06-17 19:20:40 +00:00
Pedro Moura
adb0a1ed72 proxies / rdu3: add rdu3 stg proxies and vmhost
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2025-06-17 19:20:40 +00:00
Kevin Fenzi
634b116925 virt-install: use dns1 and dns2 for dns servers for virt-installs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 11:53:10 -07:00
Kevin Fenzi
d9b910c058 sundries01/02.rdu3: it is always dns
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 11:34:27 -07:00
Kevin Fenzi
47d2d39da7 sundries02.rdu3: move this to another vmhost
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 11:26:22 -07:00
Kevin Fenzi
37a5420e63 sundries01/02.rdu3: put them on the rdu3 virthost
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 11:16:57 -07:00
Kevin Fenzi
7bf5502e46 sundries01/02.rdu3: add rdu3 sundries servers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 11:15:31 -07:00
Kevin Fenzi
c3adee12ba secondary01.rdu3: setup initial secondary in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-17 09:40:53 -07:00
Greg Sutcliffe
a7857a6879 DHCPd: Add missing semicolon to previous commit
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-06-17 17:22:12 +01:00
Greg Sutcliffe
cac847a029 DHCPd: Add Power10 bvm host IP
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-06-17 17:14:24 +01:00
Mattia Verga
ef6ce0f419 bodhi: stop using pyramid_sawing in stg
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2025-06-17 15:29:05 +00:00
Michal Konecny
9ba38f3920 [ipa] Copy the network config from another VM
I copied the config from os-control01.stg.rdu3, which is already running
on one of the vmhost in RDU3.
2025-06-17 15:06:50 +02:00
Michal Konecny
bc9a1dc6be [ipa] Add correct network conf for RDU3 2025-06-17 12:31:22 +00:00
Greg Sutcliffe
974e46205a DHCPd: use the correct macs for bond0 in bvm*stg.rdu3
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-06-17 13:28:39 +01:00
Michal Konecny
fffd672b80 [ipa] Distribute the VMs across different hosts
Let's not have all the VMs in one place in case any VM host has issues.
2025-06-17 10:26:36 +00:00
Michal Konecny
9ade63d3ba [ipa/server] Remove KRA role from deployment
We never used the KRA vault in IPA, so let's remove it till we really
have usage for it.
2025-06-17 10:17:38 +00:00
David Kirwan
a8ffee5c2d forgejo: disable valkey deployment until implmentation finished
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-06-17 11:14:10 +01:00
Mikolaj Izdebski
936cd913f1 Koschei: Increase frontend CPU and memory requests/limits 2025-06-17 07:47:54 +02:00
Kevin Fenzi
37c4da574d kickstarts: add a first cut at a power10 fedora42 kickstart
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 17:35:23 -07:00
Kevin Fenzi
a99cb9a8d4 ns02.rdu3: add another nameserver in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 15:46:15 -07:00
Kevin Fenzi
03656f0288 proxies / rdu3: make most proxies use vpn but rdu3 goes direct
We need this because the cluster needs to be able to access api in order
to pull images, etc. So, in rdu3 proxies we go direct to the cluster
nodes, but in all the other proxies we go via the vpn.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 15:42:12 -07:00
Kevin Fenzi
c3b66efa9f download/rdu3: also try nfs mounts in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 14:16:23 -07:00
Kevin Fenzi
f9c8e842b7 download / rdu3: add rdu3 download servers
This will allow us to test ro mounts from the rdu3 netapp.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 14:02:36 -07:00
Kevin Fenzi
0194b383af proxies: switch rdu3 openshift balancers to use direct path instead of vpn
We need the rdu3 proxies to directly talk to the openshift compute
nodes, as it needs this to work to pull images.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 13:56:27 -07:00
Kevin Fenzi
b7abca9804 proxies: default ocp4_rdu3 to false for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 12:26:55 -07:00
Kevin Fenzi
a6c096617b proxies: openshift rdu3
So, we renamed the cluster with the ocp-rdu3 name, so drop all this
special handling. All the proxies should be able to reach it by that
name and via the vpn endpoints it has.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 11:10:08 -07:00
Frank Ch. Eigler
5fe5b189f1 debuginfod /etc/sysconfig: include fcNNappXX flatpak-bound RPMs
These are legitimate RPMs that are wrapped into flatpaks.  Previous
debuginfod regex excluded the "appXX" variant builds; this includes
them.  Yeah, the index becomes bigger but bearable on the current
servers.
2025-06-16 17:45:52 +00:00
Kevin Fenzi
23d71ae40f proxies / rdu3: set rdu3 proxies to proxy to the rdu3 openshift cluster
The iad2 and rdu3 openshift clusters have the same name
(yes, I know, I was trying to be clever!)
So, in rdu3 we want *.apps.ocp.fedoraproject.org to proxy to the rdu3
cluster and everywhere else to the iad2 cluster (until we move).
This should point proxy01.rdu3 and proxy10.rdu3 the right way.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 09:42:55 -07:00
Kevin Fenzi
5df8dacfff proxies: add rdu3 proxies to mirrorlist_proxies to get mirrorlist updates
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-16 09:22:33 -07:00
Greg Sutcliffe
b6911ab4f1 DNS: fix dns search for new stg (b)vmhosts in rdu3
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-06-16 16:47:42 +01:00
Kevin Fenzi
5361223938 openvpn: set ccd files for rdu3 worker nodes, add them to the var so proxies will use them, still need to get openvpn working on workers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 16:57:28 -07:00
Kevin Fenzi
2bfc27b0bc openshift/openvpn/rdu3: try and pull from quay.io for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 16:30:29 -07:00
Kevin Fenzi
3b9ab3fdbe openshift / openvpn: default mode is an int32?
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 15:25:12 -07:00
Kevin Fenzi
aee0358409 openshift / openvpn: fix typo/syntax
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 15:21:38 -07:00
Kevin Fenzi
b07a636045 openshift / openvpn: also run on rdu3 control host
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 15:17:34 -07:00
Kevin Fenzi
fd99080952 openshift / openvpn: setup things to deploy openvpn on rdu3 nodes
Add the rest of the rdu3 workers in and setup openvpn role to setup on
them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-15 15:15:31 -07:00
Kevin Fenzi
3f726efdbf proxies / rdu3: add service ca to web bundle
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 15:09:49 -07:00
Kevin Fenzi
880e83dd43 proxies / rdu3: fix ca filename
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 14:51:21 -07:00
Kevin Fenzi
dceab488bd proxies: change the nft rules instead of the no longer used iptables
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 14:33:18 -07:00
Kevin Fenzi
e7e6db8d8d proxies: rename ocp4-rdu3 to ocp4_rdu3 to hopefully get jinja2 to leave it alone
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 14:30:00 -07:00
Kevin Fenzi
6120b860a6 haproxy: also install ocp ca cert in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 13:53:40 -07:00
Kevin Fenzi
2f25595228 proxies / rdu3: perhaps destname cannot have a . in it
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 13:40:37 -07:00