Commit Graph

43091 Commits

Author SHA1 Message Date
Kevin Fenzi
e968d706e7 riscv-koji: drop secure-boot policies as they are not needed in the secondary koji
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-09 12:30:43 -07:00
Jiri Kyjovsky
032d277d75 copr: fix names of deployed jinja templates 2025-06-09 17:37:57 +02:00
Jiri Kyjovsky
88ab5981b7 copr: configure ppowerful p09 osuosl builders 2025-06-09 16:48:31 +02:00
Lukas Brabec
8461d23f1d Add kparal as appowner to FQA apps 2025-06-09 16:44:46 +02:00
Jakub Kadlcik
ea8a3d1751 copr-be: upgrade builder images to F42 (bootc) 2025-06-08 14:27:20 +02:00
Jakub Kadlcik
c1f845fe80 copr-be-dev: remove old, commented-out builder images
Not worth tracking n-0 and n-1 images for the STG instance. In the rare
situation when rolling-back is needed, we have a git history. Also, we cannot
remove the older images from AWS just yet, because they are still referenced by
n-1 comment in the production config. That's why I am leaving the
warning only in production.
2025-06-08 13:53:53 +02:00
Jakub Kadlcik
f70276591f copr-be-dev: update x86_64 builder images
The previous ones didn't spawn because of a missing swap for some reason
2025-06-06 07:32:53 +02:00
Adam Williamson
c58b603416 check-compose: set up subvariant error emails for ELN
And get rid of the ancient "AtomicHost" one that's doing nobody
any good.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2025-06-05 16:38:46 -07:00
Jakub Kadlcik
5018033454 copr-be-dev: fresh set of copr-builder bootc images 2025-06-04 12:26:40 +02:00
Michal Konecny
302e329a54 [ipsilon] Remove secret from w2fm entry for staging
w2fm doesn't need a secret as it's client application and doesn't use SSO.
2025-06-03 16:33:36 +02:00
Miroslav Suchý
b97096743e bump up number of reserved instances 2025-06-03 16:11:35 +02:00
Josef Skladanka
12c5eddbcf Testdays - set DC replicas to 0 2025-06-03 12:52:02 +02:00
Lenka Segura
ce4b784133 [toddlers] Update toddler name of cleaning_packager_groups
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2025-06-02 14:52:58 +00:00
Kevin Fenzi
c12a1cb27d pagure: drop fedora-infra forks for now as crawlers are hammering the crap out of pagure over them
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-02 07:43:30 -07:00
Kevin Fenzi
b1c844e6d3 proxies / koji: block buildroot and rpminfo for now as scrapers are beating things up on them
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-02 07:42:37 -07:00
Aurélien Bompard
bcd821a69f Fix typo
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-06-02 14:30:01 +02:00
Kevin Fenzi
f136cfec2a mariadb: set single-transaction on backups
We are seeing the backups here cause the wiki to become unresponsive.
This might help it out and prevent it locking things while doing the
backups.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-06-01 08:02:12 -07:00
Kevin Fenzi
2cc8fabdbf virthost: no collectd client packages on rhel10 yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 20:06:07 -07:00
Kevin Fenzi
56c8dcc832 virthost: no zabbix client packages on rhel10 yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 19:56:43 -07:00
Kevin Fenzi
1052da754a virthost: no nagios client packages on rhel10 yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 19:49:57 -07:00
Kevin Fenzi
8f0ce956eb virthost: no rkhunter on rhel10 yet
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 19:43:30 -07:00
Kevin Fenzi
8494306377 repos: we have not yet setup epel10 infra tags and need to
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 19:29:26 -07:00
Kevin Fenzi
59cc796960 repos: add rhel10.repo and epel10.repo for rhel10 hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:58:07 -07:00
Kevin Fenzi
ea63e24fc2 vmhost-x86-02.rdu3 enters the ring
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:55:38 -07:00
Kevin Fenzi
fe94cbe274 kickstarts: add rhel10 post script
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:38:52 -07:00
Kevin Fenzi
d4ab1ab9b8 kickstarts: dhclient is no more in rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:35:39 -07:00
Kevin Fenzi
c6c6e2ec3c kickstarts: auth has been removed
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:27:00 -07:00
Kevin Fenzi
6c6e0461cd kickstarts: actually install the kickstart to be useable
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:24:19 -07:00
Kevin Fenzi
7c2ce45f4f kickstarts: add rhel 10 initial kickstarts
This is based on the rhel9 one, and likely will require adjusting.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:12:43 -07:00
Kevin Fenzi
ec71d98801 db03.iad2: double cpus to 8
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 18:09:49 -07:00
Kevin Fenzi
ec28dcbcb9 os-control: install unzip and tar as they are used later in playbooks
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 17:15:48 -07:00
Kevin Fenzi
105b8d394f os-control01.stf.rdu3: override dns for virt-install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 16:58:47 -07:00
Kevin Fenzi
8ffd2aef29 nagios: update gateways for iad2/rdu3, they need to be one hop up from the actual external ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 16:45:19 -07:00
Kevin Fenzi
1132f16d8a os-control01.stg.rdu3: use correct nameservers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 16:34:30 -07:00
Adam Williamson
4c997fbe70 Enable nftables on openQA prod workers
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2025-05-30 14:52:42 -07:00
Mark Rosenbaum
7a10ef14d3 Added Nagios rdu3 configs 2025-05-30 17:24:36 +00:00
Kevin Fenzi
836d79193c pagure: update ansible for latest blocks from ai
Update the latest project blocks that were added.

Also, extend the bot block to docs.pagure.io, which was
being hammered by scrapers.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 10:02:24 -07:00
Kevin Fenzi
77384338e5 os-control.stg.rdu3: add new staging os control host to rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-30 09:38:41 -07:00
Kevin Fenzi
07c894ea21 pkgs: drop recursive call to facl setting
In a0046b5b4b there was a bunch of fixes for ansible lint to the
distgit/pagure roles.

However, it seems like a
recursive: true
was added to the facl call, when it wasn't present before.

I noticed this when my playbook run on pkgs was running for several
hours. ;(

I don't think there's any reason to run this recursively,
as permissions should inherit from the top level one and have always
worked without it.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 15:28:21 -07:00
Kevin Fenzi
3b3dfae944 os-control.rdu3: add openshift control vm
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 14:53:57 -07:00
Kevin Fenzi
f9e5b67953 kickstarts: fix a syntax error
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 14:11:50 -07:00
Kevin Fenzi
e5b1bc8e52 vmhost-x86-01.stg.rdu3: add to ansible
New staging virthost in rdu3

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 14:02:03 -07:00
Kevin Fenzi
0d5abc773c dns: drop duplicate zone entry
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 13:48:12 -07:00
Kevin Fenzi
93bb03acc6 add stg.rdu3 zone to nameservers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 13:37:39 -07:00
Kevin Fenzi
ed701ebbf3 kickstarts: some misc improvements
Move the vnc password into ansible-private and change it
Set post script to pull via https instead of http.
http gets redirected and curl doesn't follow the redirect by default.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 13:29:57 -07:00
Kevin Fenzi
cf68c038f5 openvpn / ccd: add ccd file for proxy01.rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 12:02:04 -07:00
Kevin Fenzi
1ab76f84c8 fedora-web: move sync script to /usr/local/bin
In f42+, there's no longer a /usr/local/sbin, everything should be in
/usr/local/bin. Move this last script there.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-05-29 11:16:17 -07:00
Greg Sutcliffe
f2c9d257c1 DHCPd: Semicolons matter 2025-05-29 17:27:05 +01:00
Greg Sutcliffe
224c5ef15c DHCPd: Get the UEFI shimname right 2025-05-29 17:20:54 +01:00
Greg Sutcliffe
13d746e528 DHCPd: Update leftover iad2 ranges to rdu3 2025-05-29 17:07:05 +01:00