Commit Graph

11 Commits

Author SHA1 Message Date
Nils Philippsen
540f0fc967 ipa/client: enable for bugzilla2fedmsg in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00
Nils Philippsen
dbbf94a411 ipa/client: configure global shell access and sudo
Almost global anyway, i.e. inside the VPN.

The ipa/client-based shell access and sudo rules are only effective for
staging right now, the respective playbook bits are masked out for prod.

- Assign Ansible host groups to IPA host groups, the latter don't care
  about 'stg' in the name and use dashes rather than underscores.
- Distill shell access groups from fas_client_groups in group and host
  vars.
- Let all `sysadmin-*` groups in the previous list run anything via sudo
  in the host group (except bastion & batcave).
- Remove `fas_client_groups` from staging host and group vars.
- Remove sudoers from staging host and group vars if only `sysadmin-*`
  groups have shell access.
- Set up `ipa_client_shell_groups` on bastion to be a super set of the
  same on batcave.

Newly created IPA host groups:
- autosign
- badges
- basset
- bastion
- batcave
- blockerbugs
- bodhi
- bugzilla2fedmsg
- busgateway
- datagrepper
- dbserver
- dns
- fedimg
- github2fedmsg
- ipa
- kernel-qa
- kerneltest
- kojibuilder
- kojihub
- kojipkgs
- logging
- mailman
- memcached
- mirrormanager
- nagios
- notifs
- oci-registry
- odcs
- openqa
- openqa-workers
- osbs
- packages
- pdc-web
- pkgs
- proxies
- rabbitmq
- releng-compose
- resultsdb
- secondary
- sign-bridge
- sundries
- value
- wiki

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-02-01 22:23:41 +00:00
Kevin Fenzi
975d5e12d0 bugzilla2fedmsg: set username for non openshift install.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:16 +02:00
Kevin Fenzi
c7dc21edb4 Add suders to bugzilla2fedmsg 2019-01-23 13:53:53 +00:00
Nick Bebout
a6ad9e2c05 Add sysadmin-veteran everywhere sysadmin-noc is 2017-06-12 03:09:13 +00:00
Ralph Bean
564f1b9420 Give bugzilla2fedmsg two more threads. 2016-03-29 01:59:25 +00:00
Ralph Bean
47dfa809d5 Explicitly list all certs that can send the logger.log fedmsg message. 2015-12-03 19:30:08 +00:00
Ralph Bean
0fc93be4d2 Declare topics for bugzilla. 2015-06-12 18:31:49 +00:00
Ralph Bean
5fe015c46b Add CSI information for the bugzilla2fedmsg nodes. 2015-02-13 20:07:09 +00:00
Ralph Bean
e3f8c50b23 A role for bugzilla2fedmsg. 2014-06-24 14:32:06 +00:00
Ralph Bean
30628e89af Inventory stuff for bugzilla2fedmsg. 2014-06-20 20:17:46 +00:00