Commit Graph

40597 Commits

Author SHA1 Message Date
Miroslav Suchý
fe8b6dca4f copr: cleanup copr.conf 2024-04-02 10:29:14 +02:00
Siteshwar Vashisht
2274dadb07 openscanhub: use ServerName instead of ServerAlias
... in the httpd configurations.

The httpd container requires it to reliably determine server's fully
qualified domain name.

Signed-off-by: Siteshwar Vashisht <svashisht@redhat.com>
2024-04-02 01:02:46 +00:00
Leo Puvilland
be00c5f65e Create communishift namespace for lrossett
Signed-off-by: Leo Puvilland <leo@craftcat.dev>
2024-04-02 00:59:14 +00:00
Kevin Fenzi
ec87251934 kerneltest: remove stray group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 17:42:15 -07:00
Kevin Fenzi
e037bf02f7 kerneltest: moved to OpenShift
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 17:41:06 -07:00
Kevin Fenzi
1b189b7270 kojipkgs01: move to f39
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 14:54:13 -07:00
Kevin Fenzi
361e161dc1 kojipkgs02: move to f39
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 13:56:49 -07:00
Kevin Fenzi
d06b9e1c17 koji: hubs are fedora 39 now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 12:23:08 -07:00
Kevin Fenzi
8feca5885b Revert "Reapply "Don't send a fedora-messaging message from the Pagure git hook""
This reverts commit 26358b62a2.

So, this broke the toddler that handles package retirements. ;(

It seems it was commited on feb 20th, but not actually pushed out until
March 4th. At that point, retirements stop. ;(

I think it's getting the new git pagure messages, but they don't
contain the information it expects so it just drops them.

We will need to adjust toddlers before we can re-drop this.
2024-04-01 11:19:00 -07:00
Kevin Fenzi
41764dcee3 bodhi / staging: drop db patch for now because fedora 39 does not use the same python
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 09:39:26 -07:00
Kevin Fenzi
998959d683 rkhunter: adjust some paramters to avoid false positives
zabbix_agent uses shm (and a fair bit of it), so bump that check up all
around.
Change the ipa whitelist, as it's changed files in new ipa.
There's no longer a system subdir involved.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-04-01 09:28:54 -07:00
Kevin Fenzi
1c7f6efea0 dns: fix syntax
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-30 14:36:42 -07:00
Kevin Fenzi
5b578f0aed dns: remove obsolete dnssec directive
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-30 14:20:12 -07:00
Kevin Fenzi
4c113b98bf batcave01: we do not want the old rhel7 openshift repo
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-30 13:01:19 -07:00
Kevin Fenzi
55eb782582 koji_hub: also show kiwi jobs in search dropdown
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-29 10:37:24 -07:00
Kevin Fenzi
7aa571d30a ipa: 50G disks by default
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-29 10:35:01 -07:00
Aurélien Bompard
3e413fbee4 Badges: set the KRB env vars for cronjobs
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2024-03-29 15:51:52 +01:00
Aurélien Bompard
4b4d2ef5dd MM: check propagation every 4 hours like currently
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2024-03-29 12:14:11 +01:00
Kevin Fenzi
fb96a8b840 os-control: this is not an external machine
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 18:14:03 -07:00
Kevin Fenzi
ff530d4995 os-control01: move prod to rhel9 too
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 18:05:59 -07:00
Kevin Fenzi
632de6325e os-control: fix the virt-install
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 17:15:28 -07:00
Kevin Fenzi
28bca8208d os-control: re-add a playbook and move to rhel9 in staging
We accidentally dropped the os-control playbook, since it was part of
the openshift 3.11 cluster playbooks. So, re-add that here, and move
staging over to rhel9.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 17:12:37 -07:00
Aurélien Bompard
e613cb8510 Badges: fedbadges actually sends messages
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2024-03-28 23:12:14 +01:00
Kevin Fenzi
c84b99223c osbs: raise a glass for it's service
This removes osbs and allmost all it's associated playbooks and files.

It served long and well, but we no longer need it.
flatpaks are building with a koji-flatpak plugin.
base/minimal/toolbox containers are building with kiwi.
We aren't building any other containers right now, and we did they could
be added to kiwi.

This is the end of an era... I look with nostolga on
ansible-ansible-openshift-ansible (a role to setup ansible on a control
host and run it from our ansible).

Good bye osbs!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-28 12:52:07 -07:00
Pedro Moura
8fb54fb26e Planet: Add PVC in playbook
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2024-03-28 17:57:57 +00:00
Michal Konecny
ee58290fdb [mailman3] Redirect to hyperkitty if nothing is specified
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-28 16:25:40 +01:00
Michal Konecny
0079d06eea [mailman3] Add missing SELinux policies
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-28 16:23:19 +01:00
Michal Konecny
19fe021877 [mailman3] Fix the http request header
Apache was adding host name to X-Forwarded-Host, but this was already filled by
Fedora proxy and it caused to duplicate the domain. Disabling proxy headers in
apache solves the situation.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-28 16:15:34 +01:00
Michal Konecny
96b5e73a99 [mailman3] Add compress step
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-28 16:09:44 +01:00
Aurélien Bompard
5c88ef738b Adjust for Python 3.12 and distutils being removed
Fixes: https://pagure.io/fedora-infrastructure/issue/11850

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2024-03-28 11:34:21 +01:00
Kevin Fenzi
b8eb3ae2bd bvmhost-p09: increase max_procs for nagios a lot
These machines on recent kernels often have a LOT of processes.
They are ok, they just spawn a lot of threads for things like storage
and virtual guests. There's no point in alerting on this, it happens all
the time and the machines are fine.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 18:17:13 -07:00
Kevin Fenzi
c5f2475537 batcave: renew proxy letsencrypt certs weekly
We occasionally run into problems with certs that aren't renewed in time
or are close to expiring. Just running the proxies playbook will renew
them, but in freezes or the like sometimes there's a long time period
where we don't run that playbook.

So, lets just run weekly with the right tag. This should renew any cert
thats close to expiring.

The job shouldn't normally output anything, but if there's errors it
will email them to admin@

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 17:29:48 -07:00
Nils Philippsen
5310a60518 [toddlers] Fix typo in routing key
Signed-off-by: Nils Philippsen <nils@redhat.com>
2024-03-27 22:59:43 +00:00
Mattia Verga
5a08866473 bodhi: use f39 in staging base images
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2024-03-27 22:57:31 +00:00
Patrik Polakovič
0d507b06ca Add EPEL9 to robosignatory config
Signed-off-by: Patrik Polakovič <ppolakov@redhat.com>
2024-03-27 22:46:17 +00:00
Kevin Fenzi
b7294036cc pagure / dist-git: add staging conditional for testing
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 15:33:46 -07:00
Maja Massarini
5e046c04a6 pagure: add descriptions for new available pull_request acls
Related with commit 1efcf8a90b
We need to update the acls table with their descriptions.

pagure/cli/admin.py update-acls

The above command can update the table and it looks for descriptions in the ACLS config variable.
2024-03-27 22:12:32 +00:00
Timothée Ravier
a39bb343fa bodhi2/backend/templates/pungi.rpm: Update comments 2024-03-27 22:07:29 +00:00
Kevin Fenzi
33513b358e flatpak-cache: disable certbot on this site for now
Right now we are still trying to get this site working, and it's doing
passthough, so letsencrypt won't work. So, lets just disable it for now.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 14:54:09 -07:00
Kevin Fenzi
bc745fe824 website: try tagging the letsencrypt include_role
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 13:37:21 -07:00
Kevin Fenzi
df29534e6b ipsilon01: move to f39 also
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 13:30:52 -07:00
Kevin Fenzi
a2fec37413 ipsilon02: move to f39
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 12:46:05 -07:00
Kevin Fenzi
c45521fcb5 batcave01: patch the uri module to work on fedora targets
The ansible-core-2.14.x in rhel9 (using python 3.9 now) can't handle
running uri module on fedora (python-3.12) without erroring.
There's a backported fix in 2.15, but until thats in rhel9, this will
keep hitting us.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 12:00:19 -07:00
Kevin Fenzi
dd47ce23b9 f37-test: remove from duplicated cloud inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 11:41:41 -07:00
Kevin Fenzi
250067ff89 ipsilon01.stg: reinstall with f39
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 09:39:59 -07:00
Kevin Fenzi
c3acfd494d f37-test: retire as f37 is eol
This maintainer test machine should be retired since f37 is eol.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 09:16:01 -07:00
Kevin Fenzi
a0b24547fe F40 Beta freeze over
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2024-03-27 09:13:22 -07:00
Michal Konecny
143243ef45 [mailman3] Fix the urls.py error
This is fixing the error `django.core.exceptions.ImproperlyConfigured: Passing a 3-tuple to include() is not supported. Pass a 2-tuple containing the list of patterns and app_name, and provide the namespace argument to include() instead.`

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-27 16:36:16 +01:00
Michal Konecny
a47cab5804 [mailman3] Use the correct ansible module
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-27 16:20:28 +01:00
Michal Konecny
df0c21ed89 [mailman3] Remove SSL apache conf
The SSL is handled by proxies we don't need to handle it on the machine itself.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2024-03-27 16:01:58 +01:00