Commit Graph

7682 Commits

Author SHA1 Message Date
Kevin Fenzi
29f31df142 pagure-stg01 is also on the vpn
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-25 14:16:03 -07:00
Kevin Fenzi
8101073e8e pagure: pagure is on the vpn
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-25 14:11:11 -07:00
Kevin Fenzi
1e5aefcc52 ipa03: fix ip address for ipa03
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-25 14:07:13 -07:00
Kevin Fenzi
b0d1ea96da bastion: add fasjson_url for fasjson role
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-25 13:47:05 -07:00
Kevin Fenzi
ddf53bdbdf inventory: add copr-db-stg to cloud_aws group to make nagios happy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-25 09:52:57 -07:00
Nils Philippsen
46b3fb9390 ipa/client: Revamp combining shell groups
The previous implementation didn't work because of a chicken-and-egg
problem: To add the batcave shell groups to those specifically for
bastion, it needs to look them up, but they aren't set yet (probably
because `batcave` comes after `bastion`).

Now, one can (optionally) set `ipa_client_shell_groups_inherit_from`, a
list of Ansible group names whose `ipa_client_shell_groups` will be
combined with that of the host itself. This is more robust because it's
done late, after variables are set from the inventory.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-25 13:53:21 +01:00
Nils Philippsen
72b940d31a ipa/client: stopgap for shell groups on bastion
Evaluating ipa_client_shell_group from another group won't work this
way. Hardcode the list until we have a better solution.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 23:56:14 +01:00
Stephen Smoogen
16ee589eee up the number of cpus for the systems in the group. add 2GB more ram also 2021-03-24 18:36:48 -04:00
Stephen Smoogen
a3fd2875c2 attempt to add sysadmin-qa so that adamw can get some f*ing work done 2021-03-24 15:10:14 -04:00
Kevin Fenzi
fadfa83427 inventory / group / oci_registry: clear out duplicate variables
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-24 11:49:22 -07:00
Nils Philippsen
0ad057a285 VPN hosts: Don't enroll with ipa03 for now
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 18:33:09 +01:00
Nils Philippsen
28cc2e8d93 ipa/client: specify ipa server when enrolling VPN hosts
This is needed for clients that cannot access the internal DNS
where IPA servers are announced.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 18:18:55 +01:00
Kevin Fenzi
56cbb0beb8 ipa: make sure we open ports 88 and 464 UDP
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-24 06:32:49 -07:00
Nils Philippsen
717b89b8ad ipa/client: enable for wiki in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
a706cd8459 ipa/client: enable for vmhost_copr in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
65e0ea5d96 ipa/client: enable for virthost in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
fa72446395 ipa/client: enable for value in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
36cb1aaba7 ipa/client: enable for unbound in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
29aa38add0 ipa/client: enable for torrent in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
286af1a769 ipa/client: enable for tang in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
c0a7ba202b ipa/client: enable for sundries in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
6c5b779488 ipa/client: enable for smtp_mm in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
06ec929ead ipa/client: enable for sign_bridge in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
8463ae106f ipa/client: enable for retrace in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
d34b4ff501 ipa/client: enable for resultsdb in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
e3ee5d6da8 ipa/client: enable for releng_compose in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
6b419af83e ipa/client: enable for rabbitmq in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
6275b90b0d ipa/client: enable for proxies in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
9195c2d39a ipa/client: enable for pkgs in prod
...and grant shell access to the packager group.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
8b6c9a19cf ipa/client: enable for pdc_web in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
a4061e6bbc ipa/client: enable for pagure in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
bd01967b92 ipa/client: enable for packages in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
bc6c2d4edd ipa/client: enable for osbs in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
6fcbc946ee ipa/client: enable for openqa in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
202715dbc8 ipa/client: enable for odcs in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
40a5fed45e ipa/client: enable for oci_registry in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
b0eb4e6c82 ipa/client: enable for nuancier in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
49cafcccf4 ipa/client: enable for notifs in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
77c3daa9b7 ipa/client: enable for nagios in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
79a6fe36da ipa/client: enable for mirrormanager in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
5ca0478f55 ipa/client: enable for memcached in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
7cf64ad1f6 ipa/client: enable for mbs in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
3fd14610c6 ipa/client: enable for mailman in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
323cec75df ipa/client: enable for logging in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
4fd9a03c88 ipa/client: enable for koji, kojipkgs in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
9a7a006fac ipa/client: enable for kerneltest in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
e4f2e1a3a5 ipa/client: enable for kernel-qa in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
006b2246b1 ipa/client: enable for ipa in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
07dcdf1024 ipa/client: enable for github2fedmsg in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
cf73a8360a ipa/client: enable for fedocal in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00