Commit Graph

45340 Commits

Author SHA1 Message Date
Kevin Fenzi
e7c35d4d2b vmhost-x86-iso02: update mac addresses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 13:56:36 -08:00
James Antill
a3617c3707 updates+uptimes: Fix cmd assignment.
Signed-off-by: James Antill <james@and.org>
2025-12-12 16:05:29 -05:00
Kevin Fenzi
16ce599474 vmhost-x86-iso02: add to inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 12:58:15 -08:00
Kevin Fenzi
a81f88f031 vmhost-x86-iso02: update mac addresses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 12:55:07 -08:00
James Antill
f694f17101 updates+uptimes: Remove hosts that aren't in inventory on update. Help cmds.
Signed-off-by: James Antill <james@and.org>
2025-12-12 15:25:04 -05:00
Kevin Fenzi
4d82d65a9b haproxy: use datacenter name instead of hostname
The proxies in the new fedora-isolated vlan are in rdu3 and have rdu3
domain in their hostname, but they aren't strictly in the rdu3
datacenter for purposes of access. They do not have acls to directly
talk to backend applications from that vlan.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 10:51:40 -08:00
Kevin Fenzi
73c0c6214f proxy14: try and set it for a rdu3-iso datacenter
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 10:29:11 -08:00
Michal Konecny
9fb417b79a [proxy14] Fix typo in host_vars
This caused ticketkey playbook to fail and all proxies started alerting
about old age of ticketkey.
2025-12-12 10:52:14 +01:00
Kevin Fenzi
a3dbedb3e7 proxy14: adjust dns search path
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 21:06:44 -08:00
Kevin Fenzi
e6b034c4fa proxy14: sheesh
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 20:40:19 -08:00
Kevin Fenzi
f011ce0945 proxy14: and add the actual file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 20:27:34 -08:00
Kevin Fenzi
3b14bfc772 proxy14: move hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 20:25:20 -08:00
Kevin Fenzi
2d78574d7e smtp-mm-iso01 host vars to the correct name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 18:57:07 -08:00
Kevin Fenzi
76b28abb37 proxy14: vpn hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 18:56:48 -08:00
Kevin Fenzi
2ea32b924f proxies: update hostnames for proxy03/14
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 17:53:29 -08:00
Kevin Fenzi
117c334dae rename smtp-mm-cc-rdu01 to smtp-mm-iso01
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 17:13:39 -08:00
Kevin Fenzi
0498dd6bd9 proxy03: correct vmhost
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 17:11:40 -08:00
Kevin Fenzi
3b3399c6d8 proxy03 and proxy14 adjustments for rdu3 move
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 16:30:02 -08:00
Kevin Fenzi
eac03a251a download-iso01: adjust for new location
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:44:09 -08:00
Kevin Fenzi
4859a58b4b smtp-auth-iso01 and download-iso01: add vpn based hosts files.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:09:59 -08:00
Kevin Fenzi
1f055f415b download-iso01: add missing network info
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:06:38 -08:00
Kevin Fenzi
9fdcd69f80 download-cc-rdu01 becomes download-iso01.rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:02:59 -08:00
Kevin Fenzi
af10d77d68 smtp-auth-iso01: use rdu3 domain in name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:51:06 -08:00
Kevin Fenzi
8b85f0e197 vmhost-x86-iso04: add to inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:36:25 -08:00
Kevin Fenzi
b11f24402e vmhost-x86-iso04: fix mac addresses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:31:49 -08:00
Kevin Fenzi
8ccc39cb7d smtp-auth: fix vmhost
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:26:47 -08:00
Kevin Fenzi
7d4c52b418 smtp-auth-iso01: provision in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:24:14 -08:00
Kevin Fenzi
f1e7c95538 vmhost-x86-copr04: fix ipv6 address
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 12:51:36 -08:00
Kevin Fenzi
af85968a22 vmhost-p09-copr01: fix ipv6 config
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 12:51:00 -08:00
Kevin Fenzi
61866b9046 update rdu2-cc to rdu3 hardware
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 11:30:41 -08:00
Kevin Fenzi
f5e8dd2a9a proxies: move docs behind anubis too
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 10:46:49 -08:00
Kevin Fenzi
48d97a929d proxies: increase max workers to 3200
There's no log messages about it, but we have been seeing some odd
connection reset messages and collectd shows we are near the 2500 limit
we had.

So, bump this to 3200 (based on 8 cpus * 300 ).
If we need to bump this more, we probibly need to add cpus.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 10:21:27 -08:00
James Antill
5fe62a9b5f Fix typo for DNS search key.
Signed-off-by: James Antill <james@and.org>
2025-12-11 12:49:31 -05:00
Kevin Fenzi
56ce3d434c proxies: fix creates in shell call
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 08:49:43 -08:00
Greg Sutcliffe
d08b0f7814 Proxies: Fix indentation in proxy playbook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 16:45:19 +00:00
Greg Sutcliffe
e2bc07005c Zabbix: add external http connectivity checks to proxies
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 16:40:16 +00:00
Greg Sutcliffe
038ed9e151 Zabbix: add IPA http checks against the internal webserver
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 15:53:26 +00:00
Greg Sutcliffe
88c68a76c7 Zabbix: works better if you actually use the variable you defined
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:24:45 +00:00
Greg Sutcliffe
6a781776fe Zabbix: fix custom port for ssl check on api.ocp
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:17:16 +00:00
Greg Sutcliffe
482a22914a Zabbix: fix when clauses
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:09:34 +00:00
Greg Sutcliffe
7a96ab49e8 Zabbix: proxy playbook is erroring, add this new role elsewhere
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:07:13 +00:00
Greg Sutcliffe
56fc4590f7 Zabbix: try simpler role include
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 13:04:56 +00:00
Greg Sutcliffe
feee862e77 Zabbix: Add grab-bag of SSL checks to proxy01(.stg)
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 12:59:31 +00:00
Greg Sutcliffe
140a6eb752 Zabbix: Don't hardcode trigger hostnames
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 11:52:51 +00:00
Greg Sutcliffe
69fd257fd9 Zabbix: add external-check on Pagure certs
This is a POC on cert checks - it assigns an item to the Pagure host
(not via a template) but the actual check is executed on the Zabbix
server.

In reality, we should probably add LLD to certgetter01 for all the LE
certs, but this is a useful example for other cert types

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-12-11 11:47:02 +00:00
Pavel Raiskup
e6cbeaa3f9 copr-be: fix the expected string in frontend check 2025-12-11 08:49:37 +01:00
Pavel Raiskup
e0f9b863d1 copr-be: boost the x86 power a bit more in AWS
(we still don't have x86 hypervisors re-reacked)
2025-12-11 08:37:11 +01:00
Pavel Raiskup
2bab0054d8 copr-be: fix the frontend check after enabling Anubis 2025-12-11 08:34:38 +01:00
Pavel Raiskup
87a0161df3 copr-fe: anubis: pass through to all /repo/ routes 2025-12-11 08:12:49 +01:00
Kevin Fenzi
4b16351ce0 rdu2-cc to rdu3 dc move reorg
move all the rdu2-cc machines to rdu3, reconfigure things.

We will want to fill in a bit more info and check each of these before
using them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-10 14:02:52 -08:00