Commit Graph

385 Commits

Author SHA1 Message Date
Kevin Fenzi
b53014c3a4 haproxy / switch pkgs to rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-07-01 10:59:26 -07:00
James Antill
ea5ca95c57 Change iad2 things to rdu3 for zabbix. Namely haproxy/agent.
Signed-off-by: James Antill <james@and.org>
2025-07-01 13:29:08 -04:00
Francois Andrieu
80f922c6ff replace iad2 ocp-stg certificate with rdu3 2025-06-27 16:49:04 +00:00
Aurélien Bompard
38d138e9e0 Relay RabbitMQ on the proxies in RDU3
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-06-27 14:32:48 +02:00
Kevin Fenzi
9ef0759ca2 haproxy: enable src and kojipkgs in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-26 15:26:10 -07:00
Kevin Fenzi
643aaadb8e openshift / stg / rdu3: add cluster cert and point ocp to it
This will break things in not rdu3, but we are moving staging tomorrow
anyhow. So, just running this on rdu3 staging for now.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-25 20:03:08 -07:00
Kevin Fenzi
41dcbe734f haproxy: correct bootstrap hostname
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-24 14:40:16 -07:00
Kevin Fenzi
a5e3b32175 haproxy: add stg rdu3 openshift apis
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-24 14:36:30 -07:00
Kevin Fenzi
a1a16698ab proxies / openshift / rdu3: just copy the iad2 stg ocp cert for now, will replace with new cert once staging cluster is up
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-20 09:57:06 -07:00
Kevin Fenzi
07d410c5d7 haproxy: drop bootstrap node for prod rdu3 openshift
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-19 11:16:55 -07:00
Kevin Fenzi
3f726efdbf proxies / rdu3: add service ca to web bundle
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 15:09:49 -07:00
Kevin Fenzi
6120b860a6 haproxy: also install ocp ca cert in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 13:53:40 -07:00
Kevin Fenzi
43b150af7a haproxy: add prod rdu3 openshift ca
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-14 09:36:21 -07:00
Kevin Fenzi
eb3178f55d openshift in prod rdu3: initial cut at setting up control plane
Added host vars for all the control plane vm's and bootstrap node.
Set latest version for downloading and setting things up.
Setup haproxy in rdu3 prod to load balance the ocp api and internal api.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-12 14:33:37 -07:00
Michal Konecny
6428f8f772 Sunset github2fedmsg and fedmsg
This commit is removing all the fedmsg related stuff from ansible
repository.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-02-13 10:08:51 +00:00
Michal Konecny
2ec055db6f Use first uppercase letter for all handlers
This will unify all the handlers to use first uppercase letter for
ansible-lint to stop complaining.

I went through all `notify:` occurrences and fixed them by running
```
set TEXT "text_to_replace"; set REPLACEMENT "replacement_text"; git grep
-rlz "$TEXT" . | xargs -0 sed -i "s/$TEXT/$REPLACEMENT/g"
```

Then I went through all the changes and removed the ones that wasn't
expected to be changed.

Fixes https://pagure.io/fedora-infrastructure/issue/12391

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-02-10 20:31:49 +00:00
Ryan Lerch
47c68f478d ansiblelint fixes - fqcn[action-core] - template to ansible.builtin.template
Replaces references to template: with ansible.builtin.template

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 11:30:29 +10:00
Ryan Lerch
3c41882bb0 ansiblelint fixes - fqcn[action-core] - shell to ansible.builtin.shell
Replaces references to shell: with ansible.builtin.shell

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 11:29:10 +10:00
Ryan Lerch
25391e95b7 ansiblelint fixes - fqcn[action-core] - package to ansible.builtin.package
Replaces many references to  package: with ansible.builtin.package

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 11:28:00 +10:00
Ryan Lerch
462176464b ansiblelint fixes-- fqcn[action-core] - command to ansible.builtin.command
Replaces many references to  command: with ansible.builtin.command

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 11:26:47 +10:00
Ryan Lerch
6a3816dfdc ansiblelint fixes-- fqcn[action-core] - copy to ansible.builtin.copy
Replaces many references to 'copy' with ansible.builtin.copy

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 10:43:31 +10:00
Ryan Lerch
62952df107 ansiblelint fixes-- fqcn[action-core] - file to ansible.builtin.file
Replaces many references to  file: with ansible.builtin.file

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-15 10:41:52 +10:00
Ryan Lerch
691adee6ee Fix name[casing] ansible-lint issues
fix 1900 failures of the following case issue:

`name[casing]: All names should start with an uppercase letter.`

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-14 20:20:07 +10:00
Kevin Fenzi
55056c677e haproxy: remove a bunch of services that moved to openshift or went away
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-12-08 12:36:13 -08:00
Kevin Fenzi
659c9c719a openshift / haproxy: add service ca to trusted bundle
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-12-08 09:28:46 -08:00
Francois Andrieu
89a8e33677 haproxy: add the openshift-service CA cert to the CA bundle 2024-12-08 00:34:27 +01:00
Ryan Lerch
89f6f1fc32 Fix majority of remaining yamllint warnings and errors
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2024-11-28 17:31:45 +10:00
Kevin Fenzi
e3e2cb1d93 odcs: retire service ( infra 12192 )
Time to retire ODCS. ELN is moved off and that was the last thing using
it. Thanks for all the service ODCS!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-09-24 18:21:51 +00:00
Kevin Fenzi
c4024c4aa4 pdc: fare thee well!
This commit retires pdc from ansible.
The website should get redirected to a wiki page about the retirement.
If for some reason we need to bring things back, the vm's will still
have their disks and xml saved off so we can bring it back.
Would need to revert this, run proxy playbooks and do a little cleanup
on the redirect, then bring the vm's back up.
Hopefully we don't have to.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-08-02 13:39:15 -07:00
Kevin Fenzi
d11f9c5ced epel7 retirement
Drop epel7 all the places in ansible where it is and makes sense.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-07-03 20:00:59 +00:00
Kevin Fenzi
d366194a22 module-build-service (mbs): retire service
With the EOL of Fedora 38 yesterday, we are no longer building any
modules and can retire our module build service.

Note that toddlers needs to be adjusted still, that will happen after
this.

Thanks for all the modules!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-05-22 13:38:53 -07:00
Kevin Fenzi
194213a6bf Revert "haproxy: set keepalive mode for kojipkgs"
This reverts commit fa729a6210.

See https://pagure.io/releng/issue/11439

Lets revert this to check on the rpm-ostree retry fix.
2024-05-07 11:21:47 -07:00
Kevin Fenzi
c84b99223c osbs: raise a glass for it's service
This removes osbs and allmost all it's associated playbooks and files.

It served long and well, but we no longer need it.
flatpaks are building with a koji-flatpak plugin.
base/minimal/toolbox containers are building with kiwi.
We aren't building any other containers right now, and we did they could
be added to kiwi.

This is the end of an era... I look with nostolga on
ansible-ansible-openshift-ansible (a role to setup ansible on a control
host and run it from our ansible).

Good bye osbs!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 12:52:07 -07:00
Kevin Fenzi
fa729a6210 haproxy: set keepalive mode for kojipkgs
We are hitting a sporadic and anoying 502 error with ostree pulls.
see https://pagure.io/releng/issue/11439

The problem seems to be between haproxy and varnish on kojipkgs01.

We set the httpclose option in haproxy globally, which closes
connections as soon as it thinks they are done.
Setting this option 'httpkeepalive' will keep connections alive
and handle the case of lots of fast connections downloading small
objects much better.

Sadly, we don't have a way to test this in staging, so we would need to
test in prod and roll back if there's problems.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-15 11:57:46 -07:00
Nick Bebout
b5d0a51ae9 Revert "Reapply "Change ipa01-backend to actually point to ipa02""
This reverts commit d28ebf8cb5.
2024-01-25 11:23:03 -06:00
Nick Bebout
d28ebf8cb5 Reapply "Change ipa01-backend to actually point to ipa02"
This reverts commit 7b71471851.
2024-01-25 08:50:46 -06:00
Nick Bebout
7b71471851 Revert "Change ipa01-backend to actually point to ipa02"
This reverts commit b64524ec9a.
2024-01-24 16:17:57 -06:00
Nick Bebout
b64524ec9a Change ipa01-backend to actually point to ipa02 2024-01-23 16:06:05 -06:00
Kevin Fenzi
20dc948173 notifs (old fmn): retire
We are retiring this in favor of the new service.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-15 12:28:28 -08:00
Kevin Fenzi
af8f9531a9 haproxy: fix issue with non iad2 proxies
Turns out zabbix is only in iad2, so we need to not set it up on non
iad2 proxies.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-15 11:14:27 -08:00
Kevin Fenzi
a60ca7159f nuancier: retire and remove from ansible
See https://pagure.io/fedora-infrastructure/issue/11371
This service is retired.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-15 10:44:00 -08:00
David Kirwan
6461430ae3 zabbix: remove conditions on zabbix configration
Rename host zabbix/zabbix.stg to zabbix01

Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-11-15 08:10:44 +00:00
Kevin Fenzi
9b42cd8cbf haproxy: fix template typo
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-13 13:53:56 -08:00
David Kirwan
8b0581bcad zabbix: haproxy config reworking
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-11-09 14:52:30 +00:00
David Kirwan
ee3bac3470 zabbix: haproxy config zabbix production
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-11-09 14:04:13 +00:00
Kevin Fenzi
50c61979f0 Revert "zabbix: Add configuration for zabbix prod to haproxy"
This reverts commit d7b20fa114.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-11-07 06:16:29 -08:00
David Kirwan
d7b20fa114 zabbix: Add configuration for zabbix prod to haproxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-11-07 07:49:31 +00:00
Francois Andrieu
ce45b1775e ocp: renew internal ingress certificates 2023-08-11 12:50:57 +02:00
Aurélien Bompard
74988bf1ff Old FMN: update the heartbeat location
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-04-26 11:32:52 +02:00
Kevin Fenzi
36b489bce2 haproxy: adjust content size to 503 page
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-04-04 07:50:02 -07:00