Kevin Fenzi
d89d391f87
anubis-el: restart on bot policy changes
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 15:22:02 -08:00
James Antill
0633cda299
updates+uptimes: Minor UI tweaks, less hacky sort.
...
Signed-off-by: James Antill <james@and.org >
2026-02-10 17:21:18 -05:00
James Antill
a0cab4f3cc
mirror_from_forge: Add mirror_from_forge role, based on mirror_from_pagure.
...
Signed-off-by: James Antill <james@and.org >
2026-02-10 17:19:28 -05:00
Kevin Fenzi
8b94d9a7ce
anubis-el: try and match without quotes
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 14:13:05 -08:00
Diego Herrera
3a42bab039
Reenable Centos10 sync for EPEL 10.2 mass branching
...
Signed-off-by: Diego Herrera <dherrera@redhat.com >
2026-02-10 18:13:35 -03:00
Kevin Fenzi
c62e1573f7
storinator01: use same vpn ip as it did in rdu-cc
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 11:11:39 -08:00
Kevin Fenzi
599656a420
storinator01: add hosts file for rdu3 iso
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 10:29:28 -08:00
Kevin Fenzi
7e6d17307a
storinator01: update mac addresses
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 10:22:38 -08:00
Kevin Fenzi
53a6ce24f3
anubis: switch this to just allowing CloudFront
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 08:26:42 -08:00
Kevin Fenzi
e401686427
anubis: switch this to just allowing all repodata
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 07:58:07 -08:00
Kevin Fenzi
145e6794fb
anubis: allow .zck files universally on el as well
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 07:54:59 -08:00
Kevin Fenzi
5615d1b036
anubis: allow .zck files universally
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-10 07:52:53 -08:00
Aurélien Bompard
90ed56ae7b
bugzilla2fedmsg: rebase on RHEL9 + Python 3.11
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org >
2026-02-10 15:29:44 +01:00
Aurélien Bompard
d10f2fe3bc
bugzilla2fedmsg: update the staging deployment config for the Kafka port
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org >
2026-02-10 14:58:12 +01:00
Angel Cervera Roldan
59debdda2c
Update playbooks/openshift-apps/fedora-coreos-pipeline.yml
2026-02-10 13:42:04 +00:00
Jiri Podivin
11d11c214e
Skipping ansible-lint rules, in cases when it makes sense
...
Signed-off-by: Jiri Podivin <jpodivin@redhat.com >
2026-02-10 10:23:23 +01:00
Jiri Podivin
28d40d6e0b
Resolving style issues of the logdetective role
...
Signed-off-by: Jiri Podivin <jpodivin@redhat.com >
2026-02-10 10:23:23 +01:00
Jiri Podivin
34eaee695e
Opening 8090 port for communication with packit interface server
...
Signed-off-by: Jiri Podivin <jpodivin@redhat.com >
2026-02-10 10:23:23 +01:00
Kevin Fenzi
24ea94601d
vmhost-x86-copr01/02/03: stop removing nftables
...
These hosts are rhel10 now and removing nftables takes out the entire
libvirt stack as it doesn't support iptables anymore.
This results in base removing libvirt and the hypervisor role
re-installing it every playbook run. It also means the network doesn't
work on guests at all.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-09 15:08:28 -08:00
Kevin Fenzi
faff0d9e0f
vmhost-p09-copr01: not encrypted yet, needs reinstall
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-09 13:34:35 -08:00
Jaroslav Groman
09859d9acc
Update source branch for Quality apps in staging OpenShift
...
Signed-off-by: Jaroslav Groman <jgroman@redhat.com >
2026-02-09 20:55:08 +00:00
Kevin Fenzi
991273d7f1
copr_hypervisors: enable nbde on all of them
...
The x86 ones are now in rdu3 and reinstalled with rhel10.
All the power9 ones are in rdu3 and reinstalled.
So, we should just enable nbde on all of them.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-09 11:30:46 -08:00
Ryan Lerch
080db33424
turn of new projects UI for production
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-09 12:37:51 +10:00
Pavel Raiskup
30c0defe44
copr-backend: more verbose machine termination
2026-02-07 21:08:10 +01:00
Kevin Fenzi
a9acbd4c0e
bodhi/openshift: restore dropped cd to the right directory
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-06 10:17:14 -08:00
Kevin Fenzi
dc3fda7f45
bodhi/openshift: fix missing /
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-06 09:59:07 -08:00
Kevin Fenzi
9503d8df11
bodhi / openshift: adjust critpath to pull from forge instead of pagure.io
...
releng moved things from pagure.io/releng to
forge.fedoraproject.org/releng/tooling
Adjust this cron to do likewise.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-02-06 09:54:04 -08:00
Greg Sutcliffe
1324b1e72a
Add more CPU to proxy11 to help with httpd alerts
...
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org >
2026-02-06 14:03:41 +00:00
Patrik Polakovič
46fbcc5567
Branch Fedora 44 from Rawhide
...
Signed-off-by: Patrik Polakovič <patrik@alphamail.org >
2026-02-05 19:10:58 +00:00
Greg Sutcliffe
0bb245c653
Zabbix | Rabbit: Fix hardcoded STG entry in zabbix agent drop-in
...
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org >
2026-02-05 11:12:42 +00:00
Miroslav Suchý
6092f3bdb2
set swappiness to 10 for copr machines
2026-02-04 20:45:38 +01:00
Ryan Lerch
1d6aa6f15a
[webhook2fm] fix typo from 8a61479d64
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-04 11:18:10 +10:00
Ryan Lerch
8a61479d64
[webhook2fm] update staging rediurect URIs
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-04 11:06:52 +10:00
Ryan Lerch
a36c5a7a16
[forge] add staging ips to webhook ALLOWED_HOST_LIST settings
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-04 10:21:35 +10:00
Ryan Lerch
a425f8715f
[forge] set default merge style to rebase
...
fixes : forge/forge#353
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-04 09:24:20 +10:00
Ryan Lerch
6aab5d6da0
[forge] update ALLOWED_HOST_LIST for webhooks to include internal ips
...
fixes : forge/forge#368
Signed-off-by: Ryan Lerch <rlerch@redhat.com >
2026-02-04 09:20:26 +10:00
Pavel Raiskup
8e09c0498e
copr-be: keep one machine running for Kevin's debugging
2026-02-02 16:55:54 +01:00
Gregory Bartholomew
502f7c6273
openshift-apps/websites: requesting access for glb
...
Signed-off-by: Gregory Bartholomew <gregory.lee.bartholomew@gmail.com >
2026-02-01 11:19:51 -06:00
Kevin Fenzi
39563d49fe
noc-cc01 is no more
...
Remove it from main and remove it's playbook.
It was already removed from anisible.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-31 16:40:52 -08:00
Kevin Fenzi
29a00a8986
bastion: fix conditional for ssh tcpforwarding
...
I copy pasted this and left a 'not' in there that made this backwards.
Fix the conditional.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-31 08:20:16 -08:00
Kevin Fenzi
423f7c0c52
pagure / dist-git: drop hotfix that was pulled into rpm
...
We pulled this fix into the epel8 rpm we are using, so we shouldn't try
and apply it here also.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-31 08:18:00 -08:00
Kevin Fenzi
46ceb38264
vmhost-x86-copr02: update mac addresses
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 20:26:15 -08:00
Kevin Fenzi
c86adb0115
vmhost-x86-copr01: update mac addesses
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 13:59:30 -08:00
Kevin Fenzi
ab01301f5c
inventory: update to reflect machines that moved from f42 to f43
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 11:36:47 -08:00
Kevin Fenzi
c0f13a07e1
generate-updates-per-host: try explicitly disabling become
...
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 11:18:19 -08:00
Kevin Fenzi
278d9427f8
bastion: allow ssh tcp forwarding on bastion hosts
...
We need this in order to be able to use them as jumphosts with ssh.
Without it, there's no easy way to get to any internal machines.
Just enable it here and leave the default off.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 11:16:01 -08:00
Kevin Fenzi
3d68919779
updates/uptimes: use user root
...
Some hosts don't seem to be setup right for sudo/become (copr mostly).
Just use root like our normal ansible stuff does.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 11:01:28 -08:00
Kevin Fenzi
0b261fc507
inventory: re-enable proxy05
...
We still aren't able to get to mgmt on this host, but it's up and
operating normally, so we might as well use it for now.
If it goes down we can remove it again.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 10:37:59 -08:00
Kevin Fenzi
5091fd4373
ocp-rdu3: retire this host/proxy/cert now that we are moved
...
There's no need to keep ocp-rdu3 around anymore, we only used
it when we were moving datacenters last year.
Signed-off-by: Kevin Fenzi <kevin@scrye.com >
2026-01-30 10:35:10 -08:00
Kevin Fenzi
1bf508dc18
Revert "[robosignatory] Increase the prefetch value"
...
This reverts commit 4fdd0c9fca .
This causes robosignatory's priorities to not work.
We want to handle some requests before others, but if we prefetch 25 of
them, there could any mix of requests and we wouldn't process the most
important ones first.
2026-01-30 09:39:58 -08:00