Patrick Uiterwijk
e35e850ad3
Merge branch 'openvpn_handler' of /git/ansible into openvpn_handler
2014-08-02 15:00:10 +00:00
Patrick Uiterwijk
2c5755dbc4
Add nagios to trusted openid roots
2014-08-02 15:00:06 +00:00
Pierre-Yves Chibon
8406c182ef
Add openvpn handler for Fedora 20+
2014-08-01 12:58:11 +02:00
Pierre-Yves Chibon
b34999e1f4
Add the logic to enable the openvpn server on EL6, EL7 and Fedora in the client and the server
2014-08-01 12:39:43 +02:00
Pierre-Yves Chibon
7f30c0fc7a
Adjust the openvpn handler automatically to the distribution used
2014-08-01 12:35:11 +02:00
Pierre-Yves Chibon
00e9c9737f
Add an openvpn handler for EL6
2014-08-01 12:35:11 +02:00
Pierre-Yves Chibon
92dab2a497
Clean openvpn server files that were doing nothing in the client
2014-08-01 12:31:37 +02:00
Pierre-Yves Chibon
6878e49796
Fix the files list in the openvpn/client role
2014-08-01 12:22:10 +02:00
Pierre-Yves Chibon
3aa0127662
Dependencies between roles are marked in the meta folder not the tasks one
2014-08-01 12:16:09 +02:00
Pierre-Yves Chibon
901624caea
Mark the openvpn client and server as requesting the openvpn base role
2014-08-01 12:10:06 +02:00
Pierre-Yves Chibon
e5ff3b586e
Start the port to ansible of openvpn
2014-07-31 22:37:58 +02:00
Kevin Fenzi
0f302056a3
Adjust this weed entry to match any line in dhclient.c
2014-07-31 15:35:13 +00:00
Pierre-Yves Chibon
5da315864c
Create a new module: packager_alias containing the scripts to create the <pkg>-owner aliases
2014-07-31 13:34:53 +02:00
Kevin Fenzi
e2e9cb38d2
Add collectd to keys too
2014-07-31 04:36:37 +00:00
Kevin Fenzi
d2f74f359e
These are gone now.
2014-07-31 00:16:00 +00:00
Kevin Fenzi
445af9594c
Make sure we enable iptables.
2014-07-31 00:06:34 +00:00
Kevin Fenzi
5e445ec964
Add db-qa01 to backups. Set it to backup some dbs.
2014-07-30 21:31:00 +00:00
Ricky Elrod
fe359becaa
noc01 not noc1
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-29 21:57:34 +00:00
Ricky Elrod
a2aaeabe91
define this handler
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-29 21:46:38 +00:00
Ricky Elrod
333383240d
only install rsyncd on noc01, I think
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-29 21:26:34 +00:00
Ricky Elrod
8b59c4a93f
This needs libsemanage-python
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-29 21:24:48 +00:00
Ricky Elrod
c7bee7cb55
noc02 host_vars
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-29 20:21:30 +00:00
Kevin Fenzi
29ea9e6d8b
virthost02 was retired last week.
2014-07-28 22:18:52 +00:00
Ricky Elrod
a98ac219d8
heh
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-28 21:59:13 +00:00
Kevin Fenzi
0a613af025
Need 755 here.
2014-07-28 21:32:35 +00:00
Kevin Fenzi
9175ca5193
Try this
2014-07-28 21:25:27 +00:00
Kevin Fenzi
698358bc45
Tweak for selinux
2014-07-28 21:09:39 +00:00
Kevin Fenzi
31e6d3c73b
Pull pager.py from private.
2014-07-28 20:55:33 +00:00
Kevin Fenzi
c0ec391612
(re)add pager app. Might be handy at some point.
2014-07-28 20:29:21 +00:00
Kevin Fenzi
75e072a7a5
Move fasClient runs to every 30min instead of every 10min.
2014-07-28 20:10:12 +00:00
Kevin Fenzi
a6f4ff7fa0
Don't double copy nagios plugins on noc servers.
2014-07-28 19:38:31 +00:00
Till Maas
72d4d67610
autosign: Update sign-bridge1 to new IP
2014-07-28 21:03:57 +02:00
Kevin Fenzi
ffd7fa49c7
Weed out some collectd noise from busgateway
2014-07-28 14:29:21 +00:00
Ricky Elrod
13b0802e2a
Fix /var/android perms
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-28 11:56:16 +00:00
Kevin Fenzi
bc6aebf1ff
Add this back too
2014-07-27 22:47:41 +00:00
Kevin Fenzi
f31d4c0ba2
Odd. Reverting back.
2014-07-27 22:22:20 +00:00
Kevin Fenzi
d62c75acde
Confirm this is the problem
2014-07-27 22:16:10 +00:00
Kevin Fenzi
733b80f9ac
More fun with quoting.
2014-07-27 22:14:34 +00:00
Ralph Bean
1ccd58f23e
Typofix.
2014-07-25 16:03:30 +00:00
Ralph Bean
f64f9ea208
Revert "Turns out that staging fabric is not going to be accesible from where we sit."
...
This reverts commit 6f1cc1d305 .
2014-07-25 15:59:06 +00:00
Kevin Fenzi
9dcc85c283
Revert this back to normal and see if it works now.
2014-07-25 04:27:38 +00:00
Ralph Bean
546cf7e89b
This group got renamed.
2014-07-24 21:18:38 +00:00
Ralph Bean
3b8ce49793
Ouroboros.
...
Don't let datanommer read in a backlog from itself.
2014-07-24 20:48:38 +00:00
Ralph Bean
de7dca1364
No comment.
2014-07-24 20:33:56 +00:00
Ralph Bean
ce1b8f91e5
Try to make /var/run/fedmsg generally accesible to nrpe.
2014-07-24 20:17:16 +00:00
Ralph Bean
e5e380857e
Ignore these errors.
2014-07-24 19:57:05 +00:00
Ralph Bean
0d1dbc4c1b
Same trick for the guests.
2014-07-24 19:13:48 +00:00
Stephen Smoogen
db9bf35f47
Hey look ma.. dhcp ranges are cool.
2014-07-24 17:29:08 +00:00
Kevin Fenzi
69670dabd3
Switch this back to copy for now
2014-07-24 17:26:26 +00:00
Kevin Fenzi
0cfbc53db9
Add time in here.
2014-07-24 03:43:26 +00:00
Kevin Fenzi
097b7feda6
Try this.
2014-07-24 02:30:25 +00:00
Kevin Fenzi
cad5b1a9ff
Try this using 's
2014-07-23 23:22:23 +00:00
Kevin Fenzi
44bf4608ca
How about this
2014-07-23 23:15:10 +00:00
Kevin Fenzi
f36314fc7e
Try this
2014-07-23 23:08:57 +00:00
Kevin Fenzi
ac3b23dd67
Fix typo
2014-07-23 23:04:08 +00:00
Kevin Fenzi
aab3e5d55a
See if this makes noc playbook any faster.
2014-07-23 23:02:43 +00:00
Kevin Fenzi
50b6fcacc0
Add a dynamic range here for new devices.
2014-07-23 22:41:44 +00:00
Stephen Smoogen
94d591cc88
maybe this makes ports for dhcp?
2014-07-23 22:13:33 +00:00
Ralph Bean
f740aa1612
Knock this down while twisted still has the default threadpool size.
2014-07-23 20:43:34 +00:00
Ralph Bean
0d380575a9
Remove old references to app0\* from the fedmsg config.
2014-07-23 20:34:12 +00:00
Ralph Bean
473ce2c403
Also, open ports for fedmsg on the mailman boxes.
2014-07-23 16:41:37 +00:00
Ralph Bean
dee6e6b9a2
Give mailman01 an extra fedmsg endpoint.
2014-07-23 16:39:47 +00:00
Tim Flink
ff9a4beb60
fixing taskotron-prod urls
2014-07-23 13:24:22 +00:00
Kevin Fenzi
296f682df5
Revert "Try reverting this."
...
This reverts commit e0ca22fea7 .
2014-07-23 03:48:48 +00:00
Kevin Fenzi
20413aa848
Revert "Try this again."
...
This reverts commit 8c6b225bbd .
2014-07-23 03:48:47 +00:00
Kevin Fenzi
52b27cf228
Revert "And try this too"
...
This reverts commit 4c99cd8f23 .
2014-07-23 03:48:21 +00:00
Kevin Fenzi
4c99cd8f23
And try this too
2014-07-23 03:47:04 +00:00
Kevin Fenzi
8c6b225bbd
Try this again.
2014-07-23 03:45:49 +00:00
Kevin Fenzi
e0ca22fea7
Try reverting this.
2014-07-23 03:44:05 +00:00
Kevin Fenzi
7c7ee7b374
Fix parent for releng04
2014-07-22 23:44:24 +00:00
Kevin Fenzi
6e18fe5959
More fixing.
2014-07-22 23:36:28 +00:00
Kevin Fenzi
ca9e22c3ff
Another stray mention of a host
2014-07-22 23:25:47 +00:00
Kevin Fenzi
6f21a49000
Another fix.
2014-07-22 23:21:24 +00:00
Kevin Fenzi
de34dd16dc
Add tag to nagios config copy
2014-07-22 23:18:15 +00:00
Stephen Smoogen
900c737824
and then we added portmap so nfs would work
2014-07-22 23:17:14 +00:00
Kevin Fenzi
1f962863f7
Another fix
2014-07-22 23:16:45 +00:00
Kevin Fenzi
7b4086ce60
Add https services for mgmt in
2014-07-22 23:14:46 +00:00
Kevin Fenzi
9734900cbe
Drop bvirthost01/05 and virthost02
2014-07-22 23:10:04 +00:00
Kevin Fenzi
54ea4a002b
Add vh16/17/18 and mgmt
2014-07-22 22:59:55 +00:00
Kevin Fenzi
4cd8e39470
Missed a file.
2014-07-22 22:42:09 +00:00
Kevin Fenzi
5ef08ef4da
Take a stab at adjusting for new mgmt network in nagios
2014-07-22 22:33:32 +00:00
Tim Flink
d4fd714e15
putting newline back into resultsdb_frontend settings so that it renders properly
2014-07-22 16:02:27 +00:00
Martin Krizek
8dd0c9036c
taskotron add buildmaster_pubkey to prod-clients
2014-07-22 15:07:38 +00:00
Tim Flink
79d47f4978
adding prod vars to buildslave's buildbot.tac
2014-07-22 14:57:51 +00:00
Martin Krizek
f40dbffcf2
taskotron buildslave: fix ownership of known_hosts
2014-07-22 14:38:46 +00:00
Martin Krizek
739c6d0376
taskotron-prod add buildslave_ssh_pubkey
2014-07-22 14:18:58 +00:00
Martin Krizek
70e03463ee
taskotron: add MAILFROM in fetch_activity's cron job
2014-07-22 13:27:03 +00:00
Martin Krizek
1d5bb2462e
buildbot taskotron.master: include taskname in the mail notifier subject
2014-07-22 12:49:53 +00:00
Tim Flink
76ebfdd7ab
production doesn't need fakefedorainfra
2014-07-22 02:32:21 +00:00
Tim Flink
a12d3b0fc0
adding missing taskotron_docs var to taskotron-prod
2014-07-22 01:59:05 +00:00
Toshio くらとみ
9de3c0285d
Cross your fingers
2014-07-22 00:49:52 +00:00
Toshio くらとみ
ad7919d864
Try this one... I think I might have to quote the literal "="'s though
2014-07-22 00:46:26 +00:00
Toshio くらとみ
eba5f504c4
Revert the previous -- we're closer but that's not quite it
2014-07-22 00:39:17 +00:00
Toshio くらとみ
8ba153a1a5
Seems like we're getting closer
2014-07-22 00:27:01 +00:00
Toshio くらとみ
762ec15502
Try number 2
2014-07-22 00:19:24 +00:00
Toshio くらとみ
22f485e764
Let's start trying some different syntaxes to quote vars
2014-07-22 00:16:53 +00:00
Kevin Fenzi
71bc9cb42b
Actually set the host base
2014-07-21 23:38:49 +00:00
Kevin Fenzi
4150ea1483
Fix this hopefully now.
2014-07-21 23:34:36 +00:00
Kevin Fenzi
0b5879584a
Tweak this some.
2014-07-21 23:33:16 +00:00
Kevin Fenzi
8e2d982130
User is fedora here.
2014-07-21 23:26:39 +00:00
Kevin Fenzi
ed7b1f7d9e
Adjust playbook
2014-07-21 23:24:21 +00:00
Kevin Fenzi
d2c6440ca8
Use the right frigging keypair
2014-07-21 23:20:22 +00:00
Tim Flink
1357718019
reverting quoting changes to virt_install_command in group_vars/all
2014-07-21 23:05:31 +00:00
Tim Flink
206f24ac6b
trying another combination of quotes in an attempt to make ansible happy
2014-07-21 22:46:44 +00:00
Tim Flink
bb460b8ff0
use single quotes around virt-install command in an attempt to keep ansible from parsing it
2014-07-21 22:36:02 +00:00
Tim Flink
83540dd5fa
quoting virt-install command for new verison of ansible
2014-07-21 22:26:25 +00:00
Kevin Fenzi
7507139e92
Add koschei cloud instance for testing - ticket 4449
2014-07-21 22:07:16 +00:00
Tim Flink
70a2508f8f
adding taskotron-prod-clients and initial settings for prod environment
2014-07-21 20:58:01 +00:00
Aurélien Bompard
63a56a4532
Mailman: avoid DB lockups on parallel servers
2014-07-21 19:02:28 +00:00
Kevin Fenzi
ed9990e17b
Add qa06
2014-07-21 18:31:48 +00:00
Kevin Fenzi
d9ce6b13ce
Drop monitor.
2014-07-21 18:07:28 +00:00
Aurélien Bompard
9676c5befb
Align mailman's main.cf with the standard one
2014-07-21 17:56:14 +00:00
Aurélien Bompard
5d57028fd6
Set the postfix group for mailman servers
2014-07-21 17:52:39 +00:00
Aurélien Bompard
515576b016
Revert "Add optional dependency" (useless)
...
This reverts commit 51bc270346 .
2014-07-21 16:57:37 +00:00
Kevin Fenzi
3d23b94dd1
Adjust weed to drop these anoying collectd messages from busgateway
2014-07-21 16:41:18 +00:00
Aurélien Bompard
51bc270346
Add optional dependency
2014-07-21 16:03:49 +00:00
Aurélien Bompard
786d325a79
Move mailman's postfix config to the base role
2014-07-21 16:03:49 +00:00
Kevin Fenzi
06b2f232a8
Switch backups to backup log01 instead of log02
2014-07-21 15:48:18 +00:00
Pierre-Yves Chibon
9a6cd71777
Fix the FAS url in stg
2014-07-21 16:47:58 +02:00
Kevin Fenzi
7bb42d3c99
Just gzip here, xz confuses epylog.
2014-07-21 14:28:30 +00:00
Kevin Fenzi
7a666b0de6
Also allow rsync from log01 to pull http logs on noc01
2014-07-21 14:17:42 +00:00
Tim Flink
7bab60be7d
adding trailing / to links in buildmaster config to fix generated links in emails
2014-07-21 13:52:25 +00:00
Tim Flink
b6f087bc8e
fedmsg-hub needs to be restarted after changing taskotron-trigger config
2014-07-21 12:11:12 +00:00
Tim Flink
4118fdb718
fixing resultsdb_url for taskotron-stg
2014-07-21 11:44:45 +00:00
Tim Flink
64e2dd4132
updating taskotron trigger config to use correct values
2014-07-21 11:29:47 +00:00
Kevin Fenzi
7c4e179ebf
Add tftp server for noc01 firewall
2014-07-20 03:32:50 +00:00
Kevin Fenzi
566b253f5b
Adjust for rhel7
2014-07-20 01:34:41 +00:00
Kevin Fenzi
2df32922c8
Also use only one dns server
2014-07-20 00:54:44 +00:00
Kevin Fenzi
5b34e3274a
Drop this old virt-install group var and use the global one.
2014-07-20 00:54:12 +00:00
Kevin Fenzi
594020f1d6
Set this to be the group name
2014-07-20 00:53:14 +00:00
Kevin Fenzi
473636ca4c
These are vpn
2014-07-19 23:48:02 +00:00
Kevin Fenzi
5ab781961a
Bump this timeout way up.
2014-07-19 23:41:52 +00:00
Kevin Fenzi
193e645fbd
So why is dns anoying on installs.
2014-07-19 23:10:19 +00:00
Kevin Fenzi
93120cf9b9
Add keys02 and unbound-osuosl01
2014-07-19 23:07:34 +00:00
Kevin Fenzi
87e79d7cfc
Allow noc02 to talk to nrpe on noc01 over the vpn.
2014-07-19 20:05:36 +00:00
Kevin Fenzi
284c0bf188
Setup rrdtool collectd config
2014-07-19 18:32:56 +00:00
Kevin Fenzi
f634818cf3
Fix wrong dir
2014-07-19 17:43:39 +00:00
Kevin Fenzi
0c6f700f62
Add log01 merged file check nrpe command
2014-07-19 17:32:11 +00:00
Kevin Fenzi
2cfdd4bff9
Add log01 here.
2014-07-19 16:39:15 +00:00
Kevin Fenzi
9455539d36
Move this check to log01
2014-07-19 16:23:14 +00:00
Kevin Fenzi
6b1411b072
Fix up nrpe.cfg race condition on noc
2014-07-19 16:21:51 +00:00
Kevin Fenzi
a8775ae19b
Set this to vpn postfix
2014-07-19 15:58:53 +00:00
Ralph Bean
fc58f89ab9
Typo.
2014-07-19 13:29:35 +00:00
Ralph Bean
9e85f042a8
Turn on multi-threading for FMN backend.
2014-07-19 13:19:43 +00:00
Ralph Bean
1fdb343941
Only install this on rhel7 boxen.
2014-07-19 01:47:41 +00:00
Tim Flink
2a0d9f6646
fixing typo and missing link on taskotron frontpage for stg and dev
2014-07-18 23:53:41 +00:00
Tim Flink
f36b32b5b6
fixing typo in buildmaster configuration
2014-07-18 22:35:49 +00:00
Tim Flink
427480c594
adding mail status notifications to taskotron buildmaster
2014-07-18 22:26:27 +00:00
Kevin Fenzi
b5ea5af7f5
Fix this directory
2014-07-18 21:13:27 +00:00
Kevin Fenzi
dfd7b14575
Add the proper ping.conf for collectd server.
2014-07-18 21:09:38 +00:00
Kevin Fenzi
2276f25345
Forgot to comment these out.
2014-07-18 20:44:36 +00:00
Kevin Fenzi
5c87555862
Merge branch 'master' of /git/ansible
2014-07-18 20:42:30 +00:00
Ricky Elrod
84f5005104
lib -> lib64
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-18 20:42:10 +00:00
Kevin Fenzi
92549b5c05
Enter log01, bravest of the brave
2014-07-18 20:42:00 +00:00
Kevin Fenzi
10c4c85a53
Fix path to check_dig
2014-07-18 20:32:22 +00:00
Kevin Fenzi
a7c3271b6b
Set sb07 to use vpn for postfix
2014-07-18 20:25:14 +00:00
Ralph Bean
620beb87f3
Don't forget the unix_stream_socket.
2014-07-18 20:09:24 +00:00
Kevin Fenzi
dc234b10bf
How about making this use lib64. ;)
2014-07-18 20:07:55 +00:00
Ralph Bean
7d0161c9fa
Readin', and writin', and getattrin'
2014-07-18 20:06:55 +00:00
Ralph Bean
e0bbc8fe6e
And.. talk to the sock.
2014-07-18 20:03:55 +00:00
Ralph Bean
28bd3996a7
This has to be the last one..
2014-07-18 20:00:58 +00:00
Ralph Bean
8ef047dc5b
Furthermore.
2014-07-18 19:53:12 +00:00
Ralph Bean
507a1492ae
Also, this.
2014-07-18 19:46:33 +00:00
Ralph Bean
72f79922ae
Add selinux module for collectd.
2014-07-18 19:38:09 +00:00
Kevin Fenzi
862c814690
We also need this port for collectd
2014-07-18 18:41:06 +00:00
Kevin Fenzi
8019968f01
Add syncHttpLogs to log01
2014-07-18 18:33:57 +00:00
Kevin Fenzi
de7f7ab079
Add a v4-v5 collectd migration config
2014-07-18 18:15:28 +00:00
Kevin Fenzi
d0b258c33e
This should be using copy
2014-07-18 18:09:46 +00:00
Kevin Fenzi
3e78a078b1
Do this the other way
2014-07-18 18:06:12 +00:00
Ralph Bean
d87df7ff61
Apparently this is how you make default vars for roles.
2014-07-18 18:04:09 +00:00
Ralph Bean
ebe32c7bef
Give a default value.
2014-07-18 18:04:09 +00:00
Kevin Fenzi
c16e810e4a
Fix double modules in path.
2014-07-18 18:01:04 +00:00
Kevin Fenzi
4e6a4357e0
Fix missing a typo
2014-07-18 17:58:58 +00:00
Kevin Fenzi
9323f33c73
Add path
2014-07-18 17:56:55 +00:00
Kevin Fenzi
7efe08a558
Add epylog role to log01.
2014-07-18 17:50:29 +00:00
Ralph Bean
8adb643de6
Provide backlog options for the new fedmsg feature.
2014-07-18 17:45:04 +00:00
Kevin Fenzi
b137f536cf
Add rsync open on atomic01
2014-07-18 17:40:03 +00:00
Kevin Fenzi
d8be30c7ed
Set download-ib02 to use bastion vpn for mail.
2014-07-18 17:15:16 +00:00
Kevin Fenzi
b185a927b8
Add rsyncd to noc01 so we can rsync httpd logs off it.
2014-07-18 16:46:40 +00:00
Patrick Uiterwijk
6d2728e00d
Re-add this, as this is fixed in 3.0.5+
2014-07-18 15:58:57 +00:00
Ralph Bean
5ae57c7161
Open up that vpn port for busgateway's relay.
2014-07-18 15:40:08 +00:00
Patrick Uiterwijk
b0990fee36
This needs some small changes
2014-07-18 09:06:42 +00:00
Ralph Bean
0b46561764
Again with the file and the present.
2014-07-17 21:25:41 +00:00
Ralph Bean
02f193e30f
Make sure nrpe can talk to the monitoring sockets of fedmsg daemons.
2014-07-17 21:22:21 +00:00
Ralph Bean
e0e78585a7
Reduce fedmsg loglevel.
2014-07-17 21:03:50 +00:00
Tim Flink
b6ea396501
fixing db access for stg fake_fedorainfra
2014-07-17 20:18:39 +00:00
Ricky Elrod
20e83a28c0
started
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 20:06:24 +00:00
Ricky Elrod
4a9a78b08f
nuke more nsca
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 20:02:47 +00:00
Ricky Elrod
488b61e5c5
I am really, really bad at this. :(
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 20:02:11 +00:00
Ricky Elrod
0f9b24aea5
Merge branch 'master' of /git/ansible
2014-07-17 19:56:21 +00:00
Ricky Elrod
ad82a12c1d
add missing services to start/autostart
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 19:56:10 +00:00
Ralph Bean
8acd523425
NRPE selinux policy.
2014-07-17 19:48:15 +00:00
Ricky Elrod
e106a24f23
Merge branch 'master' of /git/ansible
2014-07-17 19:47:39 +00:00
Ricky Elrod
39e2f50025
Everything hates me
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 19:47:35 +00:00
Tim Flink
a9da3b7e11
fixing urls for taskotron-stg-clients
2014-07-17 19:45:43 +00:00
Ricky Elrod
337597653d
let it rain, let it pour. Enable rsyslog and postfix
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 19:44:08 +00:00
Ricky Elrod
20fde1a5b1
Merge branch 'master' of /git/ansible
2014-07-17 19:37:09 +00:00
Ricky Elrod
3c234f36a4
fix auth stuff here
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 19:37:04 +00:00
Ralph Bean
9048203023
Strip off our nice new logging prefix here.
2014-07-17 19:28:25 +00:00
Ralph Bean
28776f10ba
{{libdir}}
2014-07-17 19:25:09 +00:00
Ralph Bean
8999dc9717
Datanommer history nagios checks.
2014-07-17 19:19:16 +00:00
Ralph Bean
a411c40da9
s/present/file/
2014-07-17 19:12:53 +00:00
Ralph Bean
4392717e7c
Try setting permissions on the monitoring socket for fedmsg-hub.
2014-07-17 19:11:10 +00:00
Ricky Elrod
d4d7bb25e5
Merge branch 'master' of /git/ansible
2014-07-17 19:04:01 +00:00
Ricky Elrod
2496977ce7
nuke
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 19:03:57 +00:00
Tim Flink
af615db01b
adding buildmaster pubkey for taskotron stg clients
2014-07-17 18:50:11 +00:00
Tim Flink
e5ec6ba281
start and enable fedmsg-hub for taskotron-trigger
2014-07-17 18:43:02 +00:00
Ralph Bean
532004d77b
Replace the fedmsg-gateway service file with our own to do resource limits the systemd way.
2014-07-17 18:36:07 +00:00
Ricky Elrod
0db611db0b
tcp_ports
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 18:07:46 +00:00
Ricky Elrod
6925a2cdef
do a sync of nagios/hosts from puppet
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 17:25:39 +00:00
Ricky Elrod
03b9e61ecd
widen host selector
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 17:23:35 +00:00
Ricky Elrod
6c365ae1c3
noc03 -> noc01
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 17:22:39 +00:00
Tim Flink
cf3a5f8e84
fixing fake_fedorainfra settings to work with more than just dev
2014-07-17 17:15:26 +00:00
Ralph Bean
ed8420c706
Right. Except for staging...
2014-07-17 15:39:51 +00:00
Ralph Bean
f37014f246
Gotta get on that vpn.
2014-07-17 15:35:39 +00:00
Ralph Bean
e14e123d9a
Add the prod node to the mix.
2014-07-17 15:04:17 +00:00
Miroslav Suchý
33d5b0d2aa
put admin.fedoraproject.org/voting on trusted list of fedora openID
...
so user, who is going to vote, does not need to approve/reject review of authorization details
2014-07-17 10:01:07 +00:00
Miroslav Suchý
16d5a369a0
revert 602405b5 - copr is on F20 and does not need hotfix any more
2014-07-17 09:57:52 +00:00
Miroslav Suchý
fc85af9aba
install python-novaclient
...
we need this for playbooks to spin up/terminate VM
2014-07-17 09:57:52 +00:00
Ralph Bean
60d2ee61db
Name these, just so they look symmetrical.
2014-07-17 02:07:00 +00:00
Ralph Bean
f71a60936b
Enable datanommer again.
2014-07-17 02:06:32 +00:00
Ralph Bean
45e5b2536f
Yes. PY2 is the same as 'not PY3'.
2014-07-17 01:52:44 +00:00
Ralph Bean
21d378da97
Have to restart here too..
2014-07-17 01:47:11 +00:00
Ralph Bean
4464657024
Websocket server config.
2014-07-17 01:40:44 +00:00
Ralph Bean
9877feee45
Add a datanommer role for busgateway01 staging.
2014-07-17 01:22:12 +00:00
Ricky Elrod
d7073bd80b
Make nagios-external maybe work
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-17 00:52:41 +00:00
Ralph Bean
f01107d0bf
Also, this port.
2014-07-16 23:10:59 +00:00
Ralph Bean
3954235b9b
Open some ports for those fedmsg services.
2014-07-16 23:00:47 +00:00
Ralph Bean
f889df3727
Try setting up relay and gateway on new busgateway01.
2014-07-16 22:56:32 +00:00
Kevin Fenzi
c53b02cf35
Allow us to look at collectd
2014-07-16 22:29:42 +00:00
Kevin Fenzi
59df5e6b4b
Setup logrotate for merged logs.
2014-07-16 22:10:52 +00:00
Kevin Fenzi
652e84ff8d
Add vpn
2014-07-16 21:54:27 +00:00
Kevin Fenzi
a7d016c2b3
aa!
2014-07-16 21:45:41 +00:00
Kevin Fenzi
be0803de15
Bad dns. No doughnut.
2014-07-16 21:24:03 +00:00
Kevin Fenzi
3bd7212bd4
Might hate 2 dns servers here.
2014-07-16 21:18:50 +00:00
Kevin Fenzi
d7df76a1f8
Just use the default virt-install, can add disk later.
2014-07-16 21:04:59 +00:00
Kevin Fenzi
d445a1df19
First rough cut at a logserver setup. Will need lots more tweaking.
2014-07-16 21:01:29 +00:00
Dennis Gilmore
061a72dae4
symlink /srv/pungi on relase composeboxes
2014-07-16 20:16:16 +00:00
Ralph Bean
8068a89108
copy/pasta artifact.
2014-07-16 20:11:41 +00:00
Ralph Bean
a42891fc64
A playbook for busgateway01.
2014-07-16 20:09:08 +00:00
Ralph Bean
ffa767153f
Add ansible inventory stuff for busgateway01.
2014-07-16 20:06:55 +00:00
Kevin Fenzi
ffa0bce058
Move to sign-bridge01
2014-07-16 15:39:15 +00:00
Kevin Fenzi
13b58b41c1
Add repos and 2fa to sign-bridge
2014-07-16 15:28:46 +00:00
Pierre-Yves Chibon
0da020781c
Move the nuancier wsgi file into /var/www
2014-07-16 10:47:55 +02:00
Pierre-Yves Chibon
d38f03ca64
Make public the daily backup of pkgdb2
2014-07-15 22:56:52 +02:00
Kevin Fenzi
7e8a49b989
Add a gpg1 link
2014-07-15 18:46:46 +00:00
Kevin Fenzi
0b7a7bfcc4
Drop this part, it's done in the hosts role.
2014-07-15 18:39:34 +00:00
Kevin Fenzi
76db690075
-1
2014-07-15 18:37:43 +00:00
Ralph Bean
d600f85601
Remove retired packages from tagger with a cronjob.
2014-07-15 18:27:27 +00:00
Kevin Fenzi
dedec7b357
Fix ip for admin
2014-07-15 18:10:08 +00:00
Kevin Fenzi
475257aad6
Clean up vars to be more correct.
2014-07-15 17:15:45 +00:00
Kevin Fenzi
d2b53039fd
Add a sign-bridge01 and move around some sign stuff
2014-07-15 17:13:55 +00:00
Ralph Bean
f21c4c004f
New thresholds for fmn.
2014-07-15 13:34:05 +00:00
Miroslav Suchý
0af5712b07
enable one more file
2014-07-15 10:39:10 +00:00
Miroslav Suchý
199ca80a62
disable temporary
2014-07-15 10:33:08 +00:00
Miroslav Suchý
1353f8b148
copr-be-dev should be on F20 now
2014-07-15 10:19:42 +00:00
Kevin Fenzi
4bd5ce457e
memcached03/04 are no more.
2014-07-15 04:12:50 +00:00
Kevin Fenzi
abedfb7cc8
Switch stuff over to new memcached
2014-07-14 22:16:47 +00:00
Kevin Fenzi
6476f0254d
Leave memcached03/04 in hosts for stg for now.
2014-07-14 22:10:53 +00:00
Kevin Fenzi
932ad658d9
Add memcached to master.yml
2014-07-14 22:08:18 +00:00
Kevin Fenzi
232be783ca
Fold a bunch of staging hosts files into a common one, add hosts tag to role.
2014-07-14 22:06:05 +00:00
Kevin Fenzi
e26d017034
Use correct net
2014-07-14 21:43:31 +00:00
Kevin Fenzi
77897bacc7
memcached01/02 reborn as rhel7 and with much ansible.
2014-07-14 21:23:23 +00:00
Ricky Elrod
9e57170d2d
Merge branch 'master' of /git/ansible
2014-07-14 20:06:39 +00:00
Ricky Elrod
17389159f9
remove the tag, it worked \o/
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 20:06:37 +00:00
Kevin Fenzi
00a2222002
paste02 has moved to vh18
2014-07-14 20:04:48 +00:00
Ricky Elrod
a7574c74b1
tag it temporarily so I can run just that task
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 20:04:16 +00:00
Ricky Elrod
faa1a38a13
Does this do what I want?
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 20:03:35 +00:00
Ricky Elrod
6408447ffc
Merge branch 'master' of /git/ansible
2014-07-14 19:33:40 +00:00
Ricky Elrod
9bc474e30a
live in the modern age
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 19:33:05 +00:00
Ralph Bean
9168bb8f3e
Make a home for badge stls.
2014-07-14 18:16:42 +00:00
Tim Flink
ce0f825ce7
fixing external hostname for taskotron-dev
2014-07-14 13:40:37 +00:00
Tim Flink
892dec6138
relative links don't need a hostname
2014-07-14 13:40:37 +00:00
Miroslav Suchý
504b24ebce
install postfix on copr-fe
...
so we get emails about tracebacks
2014-07-14 13:35:03 +00:00
Tim Flink
79fdf11a1c
updating taskotron landingpage to work with new resultsdb endpoints
2014-07-14 13:29:09 +00:00
Tim Flink
95901b885b
fixing resultsdb_frontend_url to work with dev proxy config
2014-07-14 13:29:09 +00:00
Ralph Bean
9a67e35a9e
Take sysadmin-main out of pkgdb admin list in staging for testing.
2014-07-14 13:19:21 +00:00
Tim Flink
4a37544c3f
adding dev/stg/prod configs for buildmaster user
2014-07-14 13:17:34 +00:00
Tim Flink
38b2a5fc75
fixing taskotron-dev proxy settings for resultsdb and resultsdb_frontend
2014-07-14 12:59:02 +00:00
Miroslav Suchý
575ea5135a
add fedora-21 to copr
...
temporary - untill it arrive to mock
2014-07-14 11:06:54 +00:00
Patrick Uiterwijk
8fe6c7b8a7
Cleanup the database whenever the FedOAuth playbook is ran
2014-07-14 04:33:04 +00:00
Ricky Elrod
a6292ac0ff
install nagios-plugins and mod_auth_openid
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 01:39:34 +00:00
Ricky Elrod
e678b0bb5d
openid auth
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 01:37:05 +00:00
Ricky Elrod
c1aca5f215
enable 2fa because it makes my life easier
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-14 00:04:50 +00:00
Kevin Fenzi
eeb920aa1b
Need to be able to send mail from wiki for watched pages.
2014-07-13 21:15:32 +00:00
Ralph Bean
a3d8da8bc8
openvpn_client_7
2014-07-11 18:37:03 +00:00
Ricky Elrod
6080c9797f
shut up rsyslog too
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 18:29:51 +00:00
Ralph Bean
1aeb0804f0
host_vars for datagrepper prod nodes.
2014-07-11 18:05:09 +00:00
Ralph Bean
75d15c979b
Nuke datagrepper02.stg.phx2.fedoraproject.org
2014-07-11 17:44:53 +00:00
Kevin Fenzi
aac580fc16
Update rhel7 repo for extras and ha
2014-07-11 17:32:03 +00:00
Ralph Bean
b8b2bcffbf
Copy/pasta fix.
2014-07-11 17:07:28 +00:00
Ralph Bean
3e7d62dcba
Remove bum default config files.
2014-07-11 17:02:52 +00:00
Ralph Bean
5d2b16883b
Use db-datanommer fqdn.
2014-07-11 17:01:36 +00:00
Ralph Bean
e2ac16bd44
modern apache syntax.
2014-07-11 16:57:14 +00:00
Ralph Bean
9c622ee19f
datagrepper role has to come after mod_wsgi.
2014-07-11 16:45:52 +00:00
Ralph Bean
24a8a2517d
No more. No less.
2014-07-11 16:43:44 +00:00
Ralph Bean
c81dd3b8a4
Correct this.
2014-07-11 16:37:29 +00:00
Kevin Fenzi
71ff6c7606
Fix hostnaame typo
2014-07-11 00:50:08 +00:00
Ricky Elrod
f095a51ee2
shut postfix up
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 00:32:22 +00:00
Ricky Elrod
1c740934fa
make it reachable
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 00:22:06 +00:00
Ricky Elrod
3d755e0e5e
delete unused files lost in a sync from puppet
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 00:20:41 +00:00
Ricky Elrod
4ee9d202d6
_7
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 00:12:49 +00:00
Ricky Elrod
4ecee79069
openvpn
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-11 00:06:06 +00:00
Ricky Elrod
e85e55799b
vg_virthost
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 23:31:57 +00:00
Ricky Elrod
22d0aef540
move to vh17
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 23:29:52 +00:00
Ricky Elrod
8b4c232a07
make perms right
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 23:17:17 +00:00
Ricky Elrod
d9e9601769
sync nagios files from puppet
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 23:08:02 +00:00
Ricky Elrod
240396e373
noc03
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 22:46:58 +00:00
Ricky Elrod
0651a975c9
Merge branch 'master' of /git/ansible
2014-07-10 22:35:25 +00:00
Ricky Elrod
9a86673a66
nagios_phx2.yml -> noc.yml
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 22:35:18 +00:00
Ricky Elrod
9c88922b64
add tftp_server/dhcp_server to noc playbook
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-10 22:35:00 +00:00
Kevin Fenzi
e6e34b17f6
Add dhcp01 to ansible
2014-07-10 22:33:46 +00:00
Kevin Fenzi
e280dd0802
Add a tftp_server role for noc/dhcp01
2014-07-10 22:14:09 +00:00
Kevin Fenzi
9117585832
Add a dhcp_server role for noc and dhcp01
2014-07-10 22:00:31 +00:00
Kevin Fenzi
d574410f96
Fix indexing to show full filename. Ticket 4446
2014-07-10 20:28:12 +00:00
Ralph Bean
074dd3f17a
Try using a jinja2 "default" filter.
2014-07-10 19:11:31 +00:00
Ralph Bean
ab65c8aeb7
I wonder.
2014-07-10 18:57:29 +00:00
Ralph Bean
1cd54af996
Base fedmsg setup for jenkins.
2014-07-10 18:41:14 +00:00
Kevin Fenzi
88335f85de
Adjust openvpn rules for rhel7
2014-07-10 17:43:14 +00:00
Kevin Fenzi
46c93a62ba
Try this
2014-07-10 17:08:06 +00:00
Kevin Fenzi
b192824544
switch download-ib02 to rhel7
2014-07-10 17:01:08 +00:00
Tim Flink
c099623e88
fixing taskotron-client14 host vars, 13 != 14
2014-07-10 11:37:10 +00:00
Tim Flink
746666b5f5
fixing deployment_type for taskotron-stg-clients
2014-07-10 11:21:58 +00:00
Kevin Fenzi
9b0e41d4c6
nfs01 is gone
2014-07-10 03:27:59 +00:00
Kevin Fenzi
80cf0691ad
Collapse this down so it's idempotent
2014-07-10 02:30:38 +00:00
Stephen Smoogen
d0327f7da9
and we can use the original item
2014-07-10 02:05:17 +00:00
Stephen Smoogen
66aaad9432
adding initial log01
2014-07-10 02:02:35 +00:00
Ricky Elrod
ebd48d6a94
do (re)starting after applying config changes, when it makes sense
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 21:49:22 +00:00
Ricky Elrod
0d66229c57
does this do what I want?
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 21:45:07 +00:00
Ricky Elrod
d5ad84c3fe
copy not file :(
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 21:28:49 +00:00
Kevin Fenzi
e067bd485b
Merge branch 'master' of /git/ansible
2014-07-09 21:26:36 +00:00
Kevin Fenzi
ba0af98867
Add osuosl03
2014-07-09 21:26:28 +00:00
Patrick Uiterwijk
dccb497fd5
Enable new feature where we send the email alias in case of CLA signed
2014-07-09 21:26:26 +00:00
Ricky Elrod
31ac4a14d4
comment out more xmpp stuff for now
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 21:13:16 +00:00
Ricky Elrod
19274ca96f
use the right key from ansible-private
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 21:07:08 +00:00
Ricky Elrod
06ede132fe
nagils? wtf is a nagils? :)
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:36:08 +00:00
Ricky Elrod
8f8bf55242
comment out the service too
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:33:29 +00:00
Ricky Elrod
267de66138
no nsca either, this might take a while :P
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:25:33 +00:00
Ricky Elrod
ba98ab357a
no python-xmpp in rhel7 :(
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:22:53 +00:00
Ricky Elrod
91166fb5bf
typos are not valid, who knew?
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:16:04 +00:00
Ricky Elrod
48fbcd4978
groups are not users, who knew?
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 20:15:25 +00:00
Ricky Elrod
3f300be3bc
same with vpn
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 19:59:11 +00:00
Ricky Elrod
d52b639f48
disable 2fa because this is just a test and not worth making keys for
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 19:54:36 +00:00
Ricky Elrod
8ebc4720d5
steal nirik's denyhosts conditional ;)
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 19:50:32 +00:00
Kevin Fenzi
527db9d666
Conditionalize the rhel6/7 openvpn task
2014-07-09 19:38:05 +00:00
Kevin Fenzi
deb9cbf62a
Denyhosts conditional
2014-07-09 19:30:16 +00:00
Ricky Elrod
e645400139
I'm not sure if we need this yet
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 19:19:34 +00:00
Ricky Elrod
63ea5ed163
Merge branch 'master' of /git/ansible
2014-07-09 19:12:14 +00:00
Ricky Elrod
c6c87a42ef
no denyhosts for now :(
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 19:12:06 +00:00
Kevin Fenzi
b4439ab453
Use the actual right ip
2014-07-09 19:05:12 +00:00
Ricky Elrod
7886c719d2
Merge branch 'master' of /git/ansible
2014-07-09 18:57:08 +00:00
Ricky Elrod
c3944e49da
try using the ip instead of infra.fp.o
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 18:56:58 +00:00
Kevin Fenzi
2d5fa6203c
Fine then mr dns server.
2014-07-09 18:39:45 +00:00
Kevin Fenzi
d1a9dda953
This should be , seperated.
2014-07-09 18:37:08 +00:00
Ricky Elrod
b5ed94dc05
Merge branch 'master' of /git/ansible
2014-07-09 18:33:42 +00:00
Ricky Elrod
55ffb6ed64
Add missing group_vars because I am an idiot
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-09 18:33:36 +00:00
Kevin Fenzi
ba6a82a964
Set this to external
2014-07-09 18:27:27 +00:00
Kevin Fenzi
7ee37d676b
Move a smtp-mm from telia over to coloamer
2014-07-09 18:04:40 +00:00
Kevin Fenzi
97889ca566
ok, try this longer way
2014-07-09 16:47:10 +00:00
Kevin Fenzi
ce4a22cf64
Tweak rootpw for composer hosts with different one.
2014-07-09 16:45:29 +00:00
Ralph Bean
17e47c5372
Make kickstarts explicit for bz2fm.
2014-07-09 15:29:52 +00:00
Ralph Bean
351486cdcd
Add fedimg to the master playbook.
2014-07-09 14:54:13 +00:00
Ralph Bean
de29af9cc9
Make bugzilla2fedmsg01 real.
2014-07-09 14:48:13 +00:00
Ralph Bean
f211a91092
fedmsg endpoints and certs for fedimg01.
2014-07-09 14:15:47 +00:00
Ralph Bean
d0768d6357
Right. denyhosts.
2014-07-09 14:08:09 +00:00
Ralph Bean
ae5c56a79c
Initial playbook for fedimg.
2014-07-09 13:56:44 +00:00
Ralph Bean
b5d38d0960
Inventory entries for new fedimg01 nodes.
2014-07-09 13:48:23 +00:00
Dennis Gilmore
20a9d05455
point branched configs at f21 repos
2014-07-09 03:32:30 +00:00
Ricky Elrod
a103f51f2b
Sync nagios files from puppet
...
Until we switch over to this, use this to sync:
rsync -avr ~/puppet/modules/nagios/files .
2014-07-08 23:06:32 +00:00
Ricky Elrod
49521dc1ff
get noc03.phx2 ready to exist
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-08 23:01:29 +00:00
Kevin Fenzi
ea8a59df40
Add some lovely openvpn
2014-07-08 22:09:09 +00:00
Kevin Fenzi
2bd0eb9031
Move fedmsg setup last.
2014-07-08 21:51:48 +00:00
Kevin Fenzi
54aa9c8226
Need the nfs mounts before the releng role runs
2014-07-08 21:25:53 +00:00
Kevin Fenzi
8346166c90
drop nfs stuff from releng, add nfs/client to compose machines.
2014-07-08 21:22:19 +00:00
Kevin Fenzi
75be449044
Move releng_config to a role so we can add masher user before fedmsg.
2014-07-08 20:36:26 +00:00
Kevin Fenzi
65760320e7
Just move these over to local storage for now.
2014-07-08 20:33:45 +00:00
Tim Flink
d982debd19
adding apache task to resultsdb01.qa
2014-07-08 20:04:39 +00:00
Tim Flink
33c6b8b6d7
adding sudoers to taskotron01.qa and resultsdb01.qa
2014-07-08 19:55:17 +00:00
Tim Flink
6044b0ace2
fixing lvname for taskotron01.qa on virthost-comm02
2014-07-08 19:27:34 +00:00
Kevin Fenzi
d572ce7875
Move this stuff into the group file to save some duplication.
2014-07-08 19:08:15 +00:00
Kevin Fenzi
7733ced65f
Rename this to composers
2014-07-08 19:00:07 +00:00
Kevin Fenzi
8482fd40ac
Rename releng01/02 to branched-composer and rawhide-composer.
2014-07-08 18:28:06 +00:00
Tim Flink
9e8ae648ab
moving taskotron01.qa to virthost-comm02.qa
2014-07-08 18:07:35 +00:00
Ralph Bean
b51c07d83e
No denyhosts for rhel7.
2014-07-08 17:58:51 +00:00
Tim Flink
1b0b262e47
adding the rest of the things for taskotron-prod and resultsdb-prod
2014-07-08 17:51:06 +00:00
Ralph Bean
86f587fdae
Hosts is a role, not a task these days.
2014-07-08 17:35:34 +00:00
Ralph Bean
1181dc6835
More these to a "templates/" dir.
2014-07-08 17:30:23 +00:00
Tim Flink
405fdaa536
preparing for taskotron production setup
2014-07-08 17:26:56 +00:00
Ralph Bean
a07d60886b
Add host_vars for datagrepper01 and 02 as they stand.
2014-07-08 16:44:25 +00:00
Ralph Bean
796a28899b
Comment out datagrepper gluster stuff.
2014-07-08 16:10:06 +00:00
Ralph Bean
5b23aa818f
Adjust ansible group stuff for datagrepper.
2014-07-08 15:41:03 +00:00
Ralph Bean
d6962cc9d3
Comment out fedmsg-hub datagrepper stuff for now.
2014-07-08 15:37:21 +00:00
Aditya adimania Patawari
e470c9948e
Initial port of datagrepper from puppet to ansible.
...
https://fedorahosted.org/fedora-infrastructure/ticket/4393
2014-07-08 15:35:43 +00:00
Stephen Smoogen
d3a7ea1fa7
The hobbits are trickzie and stuck variables in group not host
2014-07-08 15:20:29 +00:00
Tim Flink
7683b86364
updating resultsdb-stg endpoints
2014-07-08 04:17:42 +00:00
Tim Flink
dfc58e678c
fixing db permissions setting for resultsdb-backend
2014-07-08 04:10:19 +00:00
Tim Flink
fcadde2964
fixing resultsdb config for db user in dev/stg/prod
2014-07-08 04:04:37 +00:00
Tim Flink
c194a19fcb
changed taskotron-stg deployment type to stg
2014-07-08 02:17:55 +00:00
Kevin Fenzi
654ecad3db
Drop this for now too
2014-07-08 01:37:46 +00:00
Kevin Fenzi
7d4d26e557
Drop taskotron-stg01 from staging.
2014-07-08 01:35:01 +00:00
Tim Flink
b96683556d
updating taskotron buildbot roles with stg config values
2014-07-08 00:15:15 +00:00
Tim Flink
6d682cdb1b
fixing db name and variable use for taskotron-dev buildmaster
2014-07-08 00:05:47 +00:00
Tim Flink
ba0ef5deba
changing stg db names to match existing convention
2014-07-07 22:25:19 +00:00
Tim Flink
cc5ae5cdf3
adding deployment_type to resultsdb-stg
2014-07-07 22:22:46 +00:00
Tim Flink
31e9b226d6
updating restultsdb-stg db name for dev/stg/prod naming
2014-07-07 22:17:23 +00:00
Tim Flink
3aa0490f75
updating buildmaster ip for taskotron-stg-clients
2014-07-07 22:17:23 +00:00
Tim Flink
0637e35371
updating taskotron-stg01's clients
2014-07-07 22:17:23 +00:00
Kevin Fenzi
d5fc8e3301
taskotron-stg01 is a special snowflake. ;)
2014-07-07 22:09:10 +00:00
Tim Flink
8149370aa5
adding the other taskotron-stg-clients back into inventory
2014-07-07 21:40:28 +00:00
Tim Flink
76b7e74b0d
renaming virt26-29.qa to taskotron-client26-29.qa
2014-07-07 20:12:15 +00:00
Tim Flink
a814a75254
specifying num_cpus and mem_size for taskotron clients
2014-07-07 20:02:28 +00:00
Kevin Fenzi
345dcd70e5
Name this right.
2014-07-07 19:53:54 +00:00
Kevin Fenzi
a4bd562e87
Add a hosts file for taskotron-stg01
2014-07-07 19:47:31 +00:00
Tim Flink
6f85dfb50c
moving resultsdb and resultsdb_frontend to separated endpoints for proxying
2014-07-07 19:39:58 +00:00
Tim Flink
270871cdf0
removing duplicated group from inventory
2014-07-07 19:22:55 +00:00
Tim Flink
8e7a4bd62f
fixing inventory for taskotron-stg
2014-07-07 19:18:54 +00:00
Kevin Fenzi
27a171a040
stg playbook should run against stg.
2014-07-07 19:18:25 +00:00
Kevin Fenzi
ea7647db08
Move taskotron-stg01 to new ip
2014-07-07 19:10:17 +00:00
Tim Flink
596c0a7b0e
adding taskotron-stg group for stg taskotron master
2014-07-07 19:00:59 +00:00
Tim Flink
88d1390a17
updating reverse proxy config for resultsdb to send X-Script-Name
2014-07-07 18:32:53 +00:00
Kevin Fenzi
cd657f2794
Drop this too
2014-07-07 17:29:55 +00:00
Kevin Fenzi
3a52dc1ac4
ok, just do this for now.
2014-07-07 17:17:39 +00:00
Kevin Fenzi
430bdb591a
Revert "Revert "That doesn't work, lets try this.""
...
This reverts commit 362710ffa8 .
2014-07-07 17:11:56 +00:00
Ricky Elrod
649108c0c3
work so far on nagios_server role.
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2014-07-07 17:09:38 +00:00
Ricky Elrod
4ee5939b13
in progress
2014-07-07 17:00:27 +00:00
Kevin Fenzi
362710ffa8
Revert "That doesn't work, lets try this."
...
This reverts commit 0a33ecd4e3 .
2014-07-07 16:55:04 +00:00
Kevin Fenzi
0a33ecd4e3
That doesn't work, lets try this.
2014-07-07 16:44:36 +00:00
Kevin Fenzi
2123ca949c
Make virt-instance-create more clear on where it's doing things.
2014-07-07 16:41:09 +00:00
Tim Flink
e81fa93478
changing taskotron-stg-clients inventory to the last remaining client
2014-07-07 15:24:58 +00:00
Ralph Bean
e6e6a957d1
This could be either kind of error.
2014-07-07 15:12:56 +00:00
Tim Flink
78b92983ca
backing taskotron-stg-clients off to 2 hosts so ansible has a better chance of connecting to everything instead of failing
2014-07-07 14:44:37 +00:00
Tim Flink
4f2438ad2e
changing taskotron-stg-clients again, trying 3 hosts this time
2014-07-07 14:36:04 +00:00
Tim Flink
f78179dbc2
changing taskotron-stg-clients to a different set of 2 hosts to workaround an ssh connection issue
2014-07-07 14:22:18 +00:00
Ralph Bean
558c50965e
Cert and endpoint setup for fmn backend.
2014-07-07 14:20:38 +00:00
Tim Flink
7a940b5b04
limiting taskotron-stg-clients to 2 hosts while triaging setup issues
2014-07-07 14:06:23 +00:00
Kevin Fenzi
2032b6396a
Narrow this forward to only valid ips at site.
2014-07-05 21:33:31 +00:00
Kevin Fenzi
692458e19e
coloamer01 is a virthost
2014-07-05 21:25:38 +00:00
Kevin Fenzi
a326c9e867
Just add this for now to get rid of ssh noise at coloamer01
2014-07-05 21:11:59 +00:00
Kevin Fenzi
61e65a9026
Add nagios_client tag to nagios_client role
2014-07-05 17:05:14 +00:00
Kevin Fenzi
bc187c07d8
Adjust base nrpe values. RHEL7 has more threads.
2014-07-04 15:15:25 +00:00
Ralph Bean
51e097143c
Make psutil features of our fedmsg config optional for mod_wsgi on rhel7.
2014-07-04 04:35:27 +00:00
Tim Flink
3f6fb1677f
adding taskotron-stg-clients
2014-07-04 04:12:31 +00:00
Tim Flink
5e13b61d11
adding sudoers to qa virthosts
2014-07-04 03:28:51 +00:00
Tim Flink
71e762b432
another small change to a link on the taskotron landing page
2014-07-04 03:20:03 +00:00
Tim Flink
05ff9f89fe
another small html fix to the taskotron landing page, hopefully the last one
2014-07-04 03:12:42 +00:00
Tim Flink
39d0f8927c
fixing invalid html in taskotron landing page
2014-07-04 03:01:31 +00:00
Tim Flink
df809c8e1e
adding link to fake_fedorainfra for dev and stg taskotron landing page
2014-07-04 02:57:34 +00:00
Tim Flink
42c3bfa136
updating ip for fakefedorainfra endpoint
2014-07-04 02:42:27 +00:00
Tim Flink
f43909c5aa
disabling file logging and setting db host for fake_fedorainfra
2014-07-04 02:38:50 +00:00
Tim Flink
3c6188ca36
adding qa04.qa, qa05.qa as virthosts
2014-07-03 23:33:59 +00:00
Tim Flink
fc174ca555
removing stray / from landingpage
2014-07-03 22:44:56 +00:00
Tim Flink
c7cc1b0ef2
make sure that the buildmaster's pubkey is known to taskotron clients
2014-07-03 22:33:46 +00:00
Tim Flink
ba09165152
updating buildmaster ip for master config on taskotron-dev
2014-07-03 22:22:51 +00:00
Tim Flink
c97377d262
fixing landing page link for taskotron-dev
2014-07-03 22:16:15 +00:00
Tim Flink
931b1979d5
updating buildmaster ip for taskotron-dev-clients
2014-07-03 21:33:33 +00:00
Kevin Fenzi
7113f43507
Add datacenter and resolv.conf for coloamer
2014-07-03 21:29:56 +00:00
Kevin Fenzi
af420851cc
Switch coloamer01 over to ansible
2014-07-03 21:12:10 +00:00
Kevin Fenzi
7fd9aaf2d8
Switch ip to one with an external mapping
2014-07-03 20:31:38 +00:00
Tim Flink
d10f4a5e9b
adjusting conditionals for slightly different use of is_rhel and is_fedora
2014-07-03 19:36:02 +00:00
Tim Flink
32a7e4163b
fixing path to ssl certs for ssl-taskotron
2014-07-03 19:20:55 +00:00
Tim Flink
741b71b7e2
adding variable for fakefedorainfra endpoint
2014-07-03 19:09:10 +00:00
Tim Flink
daa867504e
missed a reference to wrong fakefedorainfra db name var
2014-07-03 19:04:53 +00:00
Tim Flink
fc4fcbc442
fixing fakefedorainfra db name variable
2014-07-03 19:01:41 +00:00
Tim Flink
45ca4043ac
adding local ssl role for taskotron-dev
2014-07-03 18:56:59 +00:00
Tim Flink
befd796809
changing virt27.qa to be a 32 bit host
2014-07-03 18:33:00 +00:00
Tim Flink
298cd36c65
adding libdir for virt27 since it's an i386 host
2014-07-03 17:29:10 +00:00
Kevin Fenzi
84212e5e66
Lets see if this is a bit cleaner and more ansibley
2014-07-03 16:37:35 +00:00
Kevin Fenzi
ece93a1936
Add port 80 to allowed here.
2014-07-03 16:08:15 +00:00
Tim Flink
ed947449af
adding 32 bit support to yumrepos task and changing virt29 to i386
2014-07-03 15:52:44 +00:00
Tim Flink
8465d6243a
adding fake_fedorainfra role for taskotron
2014-07-03 14:58:59 +00:00
Tim Flink
db80839ca3
re-adding virt27-29.qa to inventory
2014-07-03 14:30:33 +00:00
Tim Flink
d2756dbd04
changing buildslave setup tasks to use sudo and buildslave user
2014-07-03 14:20:11 +00:00
Kevin Fenzi
b82c153329
Set all taskotron-dev-clients to use qavirt-sudoers
2014-07-03 14:10:00 +00:00
Tim Flink
f445cb7273
missed a variable conversion in buildslave-configure when moving the role from qa's repo
2014-07-03 13:53:06 +00:00
Tim Flink
3d12d96573
fixing path to ssh key in private files
2014-07-03 13:49:31 +00:00
Tim Flink
a3aa563c0f
updating buildslave configuration for infra playbook and adding required variables
2014-07-03 13:44:56 +00:00
Tim Flink
a011b1d485
adding buildslave-configure role to taskotron-dev-clients
2014-07-03 13:31:18 +00:00
Tim Flink
f10c066687
correcting buildmaster ip for taskotron-dev
2014-07-03 13:25:25 +00:00
Tim Flink
100f0ec463
adding buildslave-configure role and dev-buildslave ssh key info
2014-07-03 13:15:56 +00:00
Tim Flink
a68eab1ee0
opening buildslave port on taskotron-dev and taskotron-dev-clients
2014-07-03 12:08:22 +00:00
Tim Flink
5eee03b50c
adding buildslave role for taskotron-clients
2014-07-03 12:01:44 +00:00
Tim Flink
094c65d74f
adding deployment_type to taskotron-dev-clients
2014-07-03 11:56:00 +00:00
Tim Flink
7d3f25b14e
adjusting taskotron.yaml template for different dev/stg/prod passwords
2014-07-03 11:53:47 +00:00
Pierre-Yves Chibon
8b425b4920
The package is called devscripts-minimal and is only on Fedora
2014-07-03 13:51:29 +02:00
Pierre-Yves Chibon
28ae26a12b
Add a couple of dependencies for FedoraReview on jenkins
2014-07-03 13:51:29 +02:00
Tim Flink
6f4724807f
adding more missing values to taskotron-dev-clients inventory
2014-07-03 11:48:36 +00:00
Tim Flink
238c67e06c
adding missing values to taskotron-dev-clients inventory file
2014-07-03 11:46:13 +00:00
Tim Flink
2be9e18a1b
adding taskotron-client role
2014-07-03 11:37:02 +00:00
Tim Flink
94902fd02d
removing virt27-29 from inventory for now so the playbook will run
2014-07-03 11:23:18 +00:00
Miroslav Suchý
15e38bd417
give asamalik access to copr prod
...
he can be my backup when I am on vacation
2014-07-03 09:48:13 +00:00
Tim Flink
f01a8bc452
adding virt27-29.qa to inventory as taskotron-dev clients
2014-07-03 02:19:42 +00:00
Tim Flink
3399b44ef8
fixing apache conf file for taskotron-proxy
2014-07-03 02:09:32 +00:00
Tim Flink
b797671b6a
adding taskotron-proxy role for dev
2014-07-03 02:00:26 +00:00
Tim Flink
98aa091262
adding taskotron-frontend role
2014-07-03 01:49:20 +00:00
Ralph Bean
5fb2d93941
Update kerneltest seboolean to let fedmsg send error emails.
2014-07-03 00:36:48 +00:00
Ralph Bean
c8728f2c84
These look like log files, not static files.
2014-07-03 00:36:11 +00:00
Tim Flink
fa25c2e930
adding sysadmin-main to fas client groups for resultsdb-dev
2014-07-02 23:31:39 +00:00
Tim Flink
6da163d424
finishing the separation of resultsdb stuff from base infra stuff on resultsdb-dev
2014-07-02 23:25:52 +00:00
Tim Flink
be6aa3c980
refactoring resultsdb-dev to separate resultsdb from base infra stuff
2014-07-02 23:21:40 +00:00
Tim Flink
edf6e65d18
adding libsemanage-python to resultsdb-backend deps
2014-07-02 22:18:53 +00:00
Kevin Fenzi
c65c0dcf4b
Add rsyncd for logs to value
2014-07-02 19:27:28 +00:00
Tim Flink
60c0eb8e34
adding missing taskotron vars for fetch_activity script
2014-07-02 17:11:56 +00:00
Tim Flink
3eea166258
adding missing files from taskotron-trigger role
2014-07-02 17:07:41 +00:00
Tim Flink
9c6176d03a
not using taskotron-copr anymore
2014-07-02 17:02:45 +00:00
Tim Flink
ff6fbba5ea
adding taskotron-trigger role and updating taskotron-dev playbook
2014-07-02 16:57:33 +00:00
Kevin Fenzi
2afb547c5e
Drop all the staging stuff from this hosts file
2014-07-02 16:04:51 +00:00
Pierre-Yves Chibon
47f6f7e75a
Actually make a difference between el6 and 7
2014-07-02 17:54:46 +02:00
Pierre-Yves Chibon
6dab7a5edb
Change the SELinux type of the logs folder
2014-07-02 17:47:58 +02:00
Pierre-Yves Chibon
20e5a15d8c
Fix formatting
2014-07-02 17:38:51 +02:00
Pierre-Yves Chibon
2a144e3c5e
Try some SELinux woodoo for the logs folder
2014-07-02 17:37:42 +02:00
Tim Flink
174c5c1b03
adding resultsdb-dev group to inventory
2014-07-02 15:36:37 +00:00
Tim Flink
d3d7f2cbea
refactoring resultsdb to support different credentials for dev/stg/prod
2014-07-02 15:36:37 +00:00
Pierre-Yves Chibon
dcec1c12cc
Allow kerneltest01 to create the kerneltest db
2014-07-02 17:30:05 +02:00
Pierre-Yves Chibon
0053bd3685
Add the hosts file for kerneltest01
2014-07-02 17:22:27 +02:00
Tim Flink
5d7e9d9162
adding python-psycopg2 package to taskotron for buildbot
2014-07-02 15:09:48 +00:00
Tim Flink
533ff34228
correcting use of sudo so that buildmaster stuff is created with correct user
2014-07-02 15:04:11 +00:00
Tim Flink
78027017f3
removing dev_ prefix from stuff that's not needed in taskmaster config
2014-07-02 14:42:02 +00:00
Tim Flink
ed342bc4e1
fixing hostname variables for taskotron master config
2014-07-02 14:35:05 +00:00
Pierre-Yves Chibon
81ad59c918
Adjust the path to the static file for el6 vs others
2014-07-02 16:17:20 +02:00
Tim Flink
f3ceded008
fixing password variable names for taskotron-dev buildmaster config
2014-07-02 13:49:07 +00:00
Tim Flink
2d7fb37eda
adding fas_client_groups to virt26.qa
2014-07-02 13:24:20 +00:00
Aurélien Bompard
a65f6b3035
Mailman: merge changes in urls.py
2014-07-02 09:20:40 +00:00
Tim Flink
a85f0418eb
removing virt27-29.qa from inventory as they haven't been added yet
2014-07-02 01:36:26 +00:00
Tim Flink
7bae1c1edf
adding taskotron-dev-clients vars and virt26.qa
2014-07-02 01:33:16 +00:00
Tim Flink
976f1d4390
adding taskotron-dev-clients to inventory and group playbooks
2014-07-02 01:13:24 +00:00
Kevin Fenzi
be9ed8627a
Add sysadmin-qa
2014-07-02 00:47:11 +00:00
Kevin Fenzi
a8ca28be33
Add qa07.qa to virthost playbook
2014-07-01 23:20:43 +00:00
Tim Flink
eef6cb931a
adding qa07.qa to inventory as virthost
2014-07-01 23:08:02 +00:00
Kevin Fenzi
41390a2b6c
Setup kerneltest01 prod node.
2014-07-01 21:41:38 +00:00
Kevin Fenzi
12d490f862
Fix kerneltest hosts
2014-07-01 21:31:04 +00:00
Kevin Fenzi
fff81da2b7
Drop denyhosts and we will use openvpn 7 in prod
2014-07-01 21:26:54 +00:00
Kevin Fenzi
0dc47ea8bf
Switch kerneltest01.stg over to rhel7
2014-07-01 21:15:10 +00:00
Tim Flink
b12d1b21ec
fixing buildmaster password variable name
2014-07-01 20:41:28 +00:00
Kevin Fenzi
fbeeb394bb
Switch mailman to rhel7 openvpn task
2014-07-01 17:25:56 +00:00
Tim Flink
6b862c20e9
switch on deployment_type to use different credentials for dev/stg/prod
2014-07-01 16:38:34 +00:00
Tim Flink
6ef414a4af
fixing template paths for buildmaster-configure
2014-07-01 16:28:39 +00:00
Tim Flink
53b0aef6b6
adding buildmaster-configre role
2014-07-01 16:25:00 +00:00
Tim Flink
be713e161c
adding ssh pubkey to taskotron-dev
2014-07-01 16:24:07 +00:00
Tim Flink
e66815ccc4
adding grokmirror role and using in taskotron-dev
2014-07-01 14:34:54 +00:00
Tim Flink
f0f19bbaa2
correcting buildmaster db name in buildmaster role
2014-07-01 14:29:52 +00:00
Tim Flink
e6e4b14086
changing taskotron-dev playbook to use taskotron-dev group
2014-07-01 14:28:27 +00:00
Tim Flink
a879f25ab9
moving roles around so apache is installed before taskotron is configured
2014-07-01 14:24:15 +00:00
Kevin Fenzi
c3e7188331
Bump number of procs for nagios
2014-07-01 02:58:12 +00:00
Kevin Fenzi
4b8d023f8f
Tweak openvpn
2014-06-30 23:18:24 +00:00
Kevin Fenzi
29b7909f9e
Set the right datacenter here.
2014-06-30 23:08:21 +00:00
Kevin Fenzi
a59d2f4032
Add serverbeach07
2014-06-30 22:59:57 +00:00
Kevin Fenzi
ecc3926fad
Try this for hostname
2014-06-30 22:05:36 +00:00
Kevin Fenzi
401ac631b2
This is inventory_hostname.
2014-06-30 21:52:40 +00:00
Kevin Fenzi
2b467bc572
ok, try this to handle the openvpn differences
2014-06-30 21:32:34 +00:00
Kevin Fenzi
113e7b8479
Lets see if we can be clever here with openvpn service differences.
2014-06-30 21:12:06 +00:00
Kevin Fenzi
4331dd3d90
Give this a try for rhel7 hosts.
2014-06-30 20:56:10 +00:00
Kevin Fenzi
0d962b4ee5
Drop denyhosts
2014-06-30 20:36:48 +00:00
Kevin Fenzi
92dd36ed87
Switch unbound-ib01 to rhel7
2014-06-30 19:53:07 +00:00
Kevin Fenzi
3adfbf8a07
Drop these for now.
2014-06-30 18:21:08 +00:00
Kevin Fenzi
0c58d4f235
Add an ibms group, add some more hosts
2014-06-30 18:18:03 +00:00
Kevin Fenzi
97c02a39df
Add a cisco-ucs group for that hw
2014-06-30 18:12:02 +00:00
Kevin Fenzi
d97fe01844
Fix hostname
2014-06-30 18:04:08 +00:00
Kevin Fenzi
1c507e82b6
Add some hardware groups to allow easy query for kinds of servers
2014-06-30 18:02:43 +00:00
Ralph Bean
3d7eb0c72b
Catch and ignore fedmsg warnings about multiple initializations.
2014-06-30 14:44:52 +00:00
Kevin Fenzi
516dcf6dc8
Add a top level master playbook that has all group/hosts playbooks included.
2014-06-30 14:36:29 +00:00
Kevin Fenzi
9b08694d30
Switch this to xz. bzip2 isn't installed by default in rhel7 and xz is better anyhow.
2014-06-30 14:10:08 +00:00
Kevin Fenzi
9e873f226d
Fix mispaste
2014-06-29 17:49:30 +00:00
Kevin Fenzi
580158b7a6
Set apache logrotate on all the ansible hosts right.
2014-06-29 17:38:02 +00:00
Kevin Fenzi
34432689a6
Tweak case
2014-06-29 17:37:15 +00:00
Kevin Fenzi
6a94cbdbc7
Set vms to autostart when installed. Tweak timeouts.
2014-06-27 20:08:54 +00:00
Kevin Fenzi
2c6b628311
This should work for both rhel6 and rhel7 virthosts (with a slight delay)
2014-06-27 19:54:12 +00:00
Kevin Fenzi
bc5e431cb6
This should be internal bastion also.
2014-06-27 17:50:47 +00:00
Aurélien Bompard
df93f3504e
Mailman: send me an email on errors
2014-06-27 07:23:24 +00:00
Tim Flink
c41c2986ef
changing inventory groups around so taskotron-dev gets group vars, created virtual inventory group for taskotron
2014-06-26 18:24:01 +00:00
Tim Flink
64baa1b0f6
adding libsemanage-python to required packages for buildmaster to do selinux changes
2014-06-26 18:20:06 +00:00
Tim Flink
158d479d4e
removing firewall changes in buildmaster playbook, handled elsewhere
2014-06-26 18:17:34 +00:00
Tim Flink
6f52f5a6d5
enabling buildmaster role for taskotron-dev
2014-06-26 18:14:06 +00:00
Tim Flink
b896c439da
adding buildmaster role for taskotron
2014-06-26 18:08:18 +00:00
Pierre-Yves Chibon
ce3175fdbb
Document that the el6_templ_instance playbook might require -c paramiko
2014-06-26 16:46:41 +02:00
Aurélien Bompard
8c9f7f86c5
Mailman: small fixes
2014-06-26 09:43:42 +00:00
Aurélien Bompard
cbd8a3556b
Mailman: add RPM GPG key
2014-06-26 09:24:34 +00:00
Aurélien Bompard
333134e22f
Mailman: add HK repo
2014-06-26 09:09:01 +00:00
Kevin Fenzi
34512eb0cf
Adjust nfs client for rhel7
2014-06-26 03:11:26 +00:00
Kevin Fenzi
a592473f41
Adjust hosts.
2014-06-25 23:02:08 +00:00
Tim Flink
d2b7f02be3
commenting out buildmaster config for taskotron-dev as the required bits aren't ready yet
2014-06-25 23:00:21 +00:00
Kevin Fenzi
5db70eb63c
Another attempt to fix this up.
2014-06-25 22:10:36 +00:00
Kevin Fenzi
553599e2aa
Switch this as well.
2014-06-25 22:07:53 +00:00
Kevin Fenzi
3c84f16e31
Work around ansible issue 6109
2014-06-25 22:05:26 +00:00
Kevin Fenzi
bd04c17890
Switch this back
2014-06-25 21:57:51 +00:00
Kevin Fenzi
2959a10def
See if this is a template bug.
2014-06-25 21:55:37 +00:00
Tim Flink
e828212cf1
adding resultsdb-dev group and resultsdb-dev01.qa host
2014-06-25 21:45:15 +00:00
Kevin Fenzi
6f40c0701b
Does this work?
2014-06-25 21:44:51 +00:00
Kevin Fenzi
746111d59b
This is xfs on rhel7
2014-06-25 21:03:36 +00:00
Kevin Fenzi
8ca70c59d1
Merge branch 'master' of /git/ansible
2014-06-25 20:41:55 +00:00
Kevin Fenzi
ef7c77bccd
We need cloud-utils for growpart apparently
2014-06-25 20:41:28 +00:00
Tim Flink
9d4d6982e5
initial inventory files and playbook for taskotron-dev, updated host_vars for taskotron-dev01.qa
2014-06-25 20:35:16 +00:00
Miroslav Suchý
22ea034121
add tmpfs to copr-be
2014-06-25 20:29:24 +00:00
Kevin Fenzi
bf6e2b560f
Don't need sudo here.
2014-06-25 20:28:15 +00:00
Kevin Fenzi
71e0a760a3
Next image please
2014-06-25 20:22:13 +00:00
Kevin Fenzi
2121eb8a30
el7 cloud
2014-06-25 20:21:37 +00:00
Ralph Bean
06a27353e9
Add new copr-be hostname.
2014-06-25 20:03:36 +00:00
Luke Macken
450297622e
bodhi: add 'packager' to the admin groups in stg to make it easier to test with rube
2014-06-25 19:28:04 +00:00
Tim Flink
41f542946e
adding blank line to resultsdb.conf to force newline in rendered template, fixing syntax error
2014-06-25 18:32:08 +00:00
Tim Flink
3e4a477540
restricting non-GET requests to resultsdb to qa network
2014-06-25 18:03:27 +00:00
Kevin Fenzi
32e2d0f324
Add a datacenter main.cf for phx2 hosts.
2014-06-25 03:26:55 +00:00
Till Maas
f2e70cac15
autosign: define host_group var
2014-06-24 23:57:39 +02:00
Kevin Fenzi
97c83f730b
Will have to sort openvpn start in rhel7/fedora soon.
2014-06-24 21:51:58 +00:00
Kevin Fenzi
9405324127
Conditionalize denyhosts for rhel7
2014-06-24 21:46:54 +00:00
Till Maas
0e9035e934
Add hosts role as dependency for autosigner
2014-06-24 23:41:56 +02:00
Kevin Fenzi
ea0d907044
Try this with ip
2014-06-24 21:36:13 +00:00
Kevin Fenzi
6fb0f86d59
Reinstall mailman prod instances as rhel7.
2014-06-24 21:12:14 +00:00
Pierre-Yves Chibon
6705ef8814
The F18 builders is out of the jenkins corner
2014-06-24 21:44:33 +02:00
Pierre-Yves Chibon
2ab6f1ada9
Drop the F18 builders from jenkins' config
2014-06-24 21:43:30 +02:00
Kevin Fenzi
ce5f9b8148
Set sudo: false globally.
2014-06-24 19:41:10 +00:00
Kevin Fenzi
261bf76f21
Revert "Move bugzilla2fedmsg01.stg to new vh18 to test rhel7 as vh" and move it back
...
This reverts commit 61649f6d06 .
2014-06-24 19:23:39 +00:00
Kevin Fenzi
e6fa8a217d
Drop rhel config here, rhel7 is like fedora for this.
2014-06-24 19:03:48 +00:00
Kevin Fenzi
c4960cd997
Drop releng repo entirely, replace with builder repo
2014-06-24 18:40:18 +00:00
Kevin Fenzi
eafe2c9c9e
selinux in rhel7 doesn't like /var/tmp for a homedir, unset that
2014-06-24 18:29:38 +00:00
Kevin Fenzi
92e0239c16
On new rhel7 virthosts allow forwarding.
2014-06-24 18:09:58 +00:00
Luke Macken
b108e4f631
bodhi: Don't store cookies and tokens persistently on disk
2014-06-24 17:40:51 +00:00
Luke Macken
546cc4b07c
bodhi: use the partner-bugzilla in staging
2014-06-24 17:40:51 +00:00
Kevin Fenzi
66892b818a
Need a eth1 ip
2014-06-24 17:38:52 +00:00
Kevin Fenzi
5571149cdc
Move releng02 to rhel7 and move it to bvirthost06 (also rhel7)
2014-06-24 17:36:11 +00:00
Luke Macken
10cad3d5d7
bodhi.stg: point to koji.stg's IP directly
2014-06-24 16:15:21 +00:00
Ralph Bean
b0d6611fb2
...but you can call me "bugzilla".
2014-06-24 15:56:08 +00:00
Ralph Bean
5933a1c822
Directories shmirectories.
2014-06-24 15:49:40 +00:00
Ralph Bean
6f1cc1d305
Turns out that staging fabric is not going to be accesible from where we sit.
2014-06-24 15:37:34 +00:00
Ralph Bean
23e34f9c0f
Ensure some directories exist.
2014-06-24 15:20:33 +00:00
Ralph Bean
ab06396de6
Get the config file name right.
2014-06-24 15:20:33 +00:00
Luke Macken
1b01a5f0bf
Point bodhi.stg at koji.stg
2014-06-24 15:14:29 +00:00
Ralph Bean
265f7d478f
Look for certs in all the right places.
2014-06-24 15:12:53 +00:00
Ralph Bean
63946c704e
Moksha wants this file to be /etc/moksha/production.ini.
2014-06-24 14:47:10 +00:00
Ralph Bean
daabcf3935
Typofix mark II.
2014-06-24 14:39:48 +00:00
Ralph Bean
25a565ab9c
Typofix.
2014-06-24 14:36:01 +00:00
Ralph Bean
e3f8c50b23
A role for bugzilla2fedmsg.
2014-06-24 14:32:06 +00:00
Patrick Uiterwijk
c760b15d9f
Increase the reauth_timeout for FedOAuth from 5 to 15 minutes
2014-06-24 13:24:57 +00:00
Pierre-Yves Chibon
471341994c
Backport upstream fixes to find out/list properly the retired packages
2014-06-24 13:05:45 +02:00
Pierre-Yves Chibon
a97ebde1d1
Deactivate fedora_owner_change in sundries-staging
2014-06-24 11:36:32 +02:00
Kevin Fenzi
c96d78df7c
Move autosign01 over to new bvirthost08, clean up some denyhosts role includes
2014-06-23 23:32:21 +00:00
Kevin Fenzi
556bc48a52
These need quotes
2014-06-23 21:51:16 +00:00
Luke Macken
4d5e76d6b4
Hook bodhi.stg up to pkgdb.stg
2014-06-23 21:17:08 +00:00
Patrick Uiterwijk
5a76530849
This check for rpmdir defined already existed
2014-06-23 21:06:59 +00:00
Patrick Uiterwijk
0882689603
Error out if rhel version is not specified
2014-06-23 21:05:58 +00:00
Patrick Uiterwijk
049c6c3bba
Merge branch 'master' of /git/ansible
2014-06-23 20:59:57 +00:00
Patrick Uiterwijk
0329333a7f
Add rhel=6 or rhel=7 argument to sign-and-import
2014-06-23 20:59:41 +00:00
Ralph Bean
e4c35eb494
Add generic fedmsg config for bugzilla2fedmsg.
2014-06-23 20:22:09 +00:00
Kevin Fenzi
7bbe3e048c
Also allow /srv/web/
2014-06-23 19:25:51 +00:00
Kevin Fenzi
e5862ccf2e
Adjust download apache conf to work with 2.2 or 2.4
2014-06-23 19:08:46 +00:00
Kevin Fenzi
80e8bb0ff1
Also this isn't around on rhel/epel7 yet either.
2014-06-23 18:38:13 +00:00
Kevin Fenzi
cf1c33fdd6
No denyhosts for rhel7
2014-06-23 18:33:54 +00:00
Patrick Uiterwijk
0375c66a20
Merge branch 'master' of /git/ansible
2014-06-23 18:27:50 +00:00
Dennis Gilmore
3c529d3eee
send branched and rawhide cron output to releng-cron list
2014-06-23 18:06:09 +00:00
Miroslav Suchý
be7168c794
substitute only some vars during deployment on copr
2014-06-23 15:23:02 +00:00
Kevin Fenzi
e6e759d969
Run rkhunter --propupd when installing or updating it's config
2014-06-23 04:09:25 +00:00
Kevin Fenzi
1ebbc5ffce
Stay newline
2014-06-23 03:21:11 +00:00
Kevin Fenzi
0de1159087
These may need quoted?
2014-06-23 02:27:45 +00:00
Kevin Fenzi
5c3d38c357
Add a profile thing for a few runs.
2014-06-23 02:05:35 +00:00
Kevin Fenzi
3a0d2d4483
Fix paths
2014-06-23 01:01:24 +00:00
Kevin Fenzi
800c03d37e
Move hosts to a role and put it before fas_client so initial runs can find admin.
2014-06-23 00:49:31 +00:00
Kevin Fenzi
7c51d2e497
Add a fas_client for only initial installs
2014-06-22 23:01:05 +00:00
Kevin Fenzi
8764d6afa2
virt-install is in path and in a different place in rhel7
2014-06-22 22:46:23 +00:00
Kevin Fenzi
61649f6d06
Move bugzilla2fedmsg01.stg to new vh18 to test rhel7 as vh
2014-06-22 22:43:18 +00:00
Patrick Uiterwijk
b48a8fc88a
Merge branch 'master' of /git/ansible
2014-06-22 00:58:04 +00:00
Patrick Uiterwijk
c3a57dcaee
Move FedOAuth 3 to production
2014-06-22 00:57:52 +00:00
Patrick Uiterwijk
bbd9f21b9a
Move FedOAuth 3 to production
2014-06-22 00:43:13 +00:00
Kevin Fenzi
9ac7e0dd64
Disable bugzilla2fedmsg prod instances so the check/diff script can run. Comment a few items.
2014-06-21 16:06:45 +00:00
Kevin Fenzi
3b40f9c1ab
Initial sshd_config for rhel7
2014-06-21 01:20:35 +00:00
Kevin Fenzi
861ecc7c2f
We do want this on all hosts.
2014-06-21 00:02:32 +00:00
Kevin Fenzi
b3a4f7fdaf
No nss_db on rhel7
2014-06-20 23:55:08 +00:00
Kevin Fenzi
6cab3284fc
Some package naming changes
2014-06-20 23:26:54 +00:00
Kevin Fenzi
8a608531a0
Add rhel7/epel7 to yumrepos task
2014-06-20 23:18:51 +00:00
Kevin Fenzi
ddefe1d6c2
Just do this for now.
2014-06-20 23:06:25 +00:00
Kevin Fenzi
c1839d9f64
rkhunter isn't in epel7 yet, need to fix that.
2014-06-20 23:04:08 +00:00
Kevin Fenzi
a81c6dee27
Have to use the internal ip here.
2014-06-20 22:51:03 +00:00
Patrick Uiterwijk
5b0d410ef9
github2fedmsg is trusted
2014-06-20 20:53:56 +00:00
Ralph Bean
4243fab91f
Stub of a playbook for bugzilla2fedmsg.
2014-06-20 20:40:01 +00:00
Ralph Bean
292e2c745e
I always forget to add hosts to the [staging] group.
2014-06-20 20:19:40 +00:00
Ralph Bean
30628e89af
Inventory stuff for bugzilla2fedmsg.
2014-06-20 20:17:46 +00:00
Kevin Fenzi
f9cb68c597
Switch default to rhel7. ;)
2014-06-20 19:46:35 +00:00
Kevin Fenzi
11772691a3
Update copr fe ip
2014-06-20 14:41:23 +00:00
Miroslav Suchý
936a55d647
correct path
2014-06-20 14:19:35 +00:00
Miroslav Suchý
2236b0963a
Revert "return back to F19"
...
This reverts commit a0015519c0 .
2014-06-20 14:08:11 +00:00
Miroslav Suchý
a0015519c0
return back to F19
2014-06-20 14:01:48 +00:00
Miroslav Suchý
44335a4498
return back original ip
2014-06-20 09:38:32 +00:00
Miroslav Suchý
3842c6ecd9
try to log in as fedora user
2014-06-20 09:25:06 +00:00
Miroslav Suchý
902dc56d64
use f20 copr repo
2014-06-20 09:22:02 +00:00
Miroslav Suchý
9c12b86607
one more try
2014-06-20 09:18:37 +00:00
Miroslav Suchý
8b8c2b3a81
we can use our own repo, if we deploy hosts file first
2014-06-20 09:14:04 +00:00
Miroslav Suchý
aa8c988160
revert back to original ip
...
it did now work with new one neither
2014-06-20 09:13:03 +00:00
Miroslav Suchý
2f0e35a13c
add 209.132.184.150 alias
2014-06-20 09:10:39 +00:00
Miroslav Suchý
f25f510cb2
hotfix is no longer needed on F20
2014-06-20 09:08:59 +00:00
Miroslav Suchý
50c2ee25ec
try this
2014-06-20 09:07:08 +00:00
Miroslav Suchý
c46e1bcd23
try this
2014-06-20 09:05:56 +00:00
Miroslav Suchý
5fee77521a
try this
2014-06-20 09:05:34 +00:00
Miroslav Suchý
1bee103535
try to workaround old entry in known_hosts
2014-06-20 09:04:21 +00:00
Miroslav Suchý
c107f6f4ba
upgrade copr to F20
2014-06-20 07:49:24 +00:00
Tim Flink
49bc0d2076
adding buildslave port 9989/tcp to taskotron group
2014-06-19 20:59:17 +00:00
Ralph Bean
37f095a18a
Update trusted openid string for badges in stg.
2014-06-19 19:00:51 +00:00
Kevin Fenzi
1a73d2bf10
See if this fixes the 'unreachable' on cloud playbooks in the check/diff runs.
2014-06-19 18:15:53 +00:00
Ralph Bean
75d441496c
Monitor backlog of fedmsg-irc with collectd.
2014-06-19 17:39:55 +00:00
Miroslav Suchý
7201111545
switch copr playbooks from ec2 to nova module
...
Because of https://fedorahosted.org/fedora-infrastructure/ticket/4397
2014-06-19 14:03:19 +00:00
Pierre-Yves Chibon
7462db1de6
Update endpoint name for kerneltest
2014-06-19 08:39:32 +02:00
Pierre-Yves Chibon
1cd6f37735
Fix ssl.py for kerneltest
2014-06-19 07:59:47 +02:00
Kevin Fenzi
8ad1279b1d
Add copr-be to the fedmsgupdate playbook
2014-06-18 20:08:03 +00:00
Kevin Fenzi
c8a28a9e49
Try and see if this works.
2014-06-18 20:04:19 +00:00
Kevin Fenzi
5674733acb
Reorg copr-be playbook a bit. Use fedmsg/base for all fedmsg. Use iptables template for iptables instead of lokkit.
2014-06-18 19:54:10 +00:00
Pierre-Yves Chibon
710ec26471
Move the kerneltest api key to the private repo - and create one
2014-06-18 19:06:16 +02:00
Pierre-Yves Chibon
34af155cab
Add text/x-log as an allowed mimetype
2014-06-18 19:06:16 +02:00
Kevin Fenzi
99a5d148c0
Take out the cloud hosts again, they don't use fedmsg/base
2014-06-18 15:55:12 +00:00
Kevin Fenzi
2d3c9cb629
Correct path
2014-06-18 15:50:59 +00:00
Kevin Fenzi
059314b3ab
Update fedmsgupdate playbook with all the missing groups/hosts that need fedmsg updates
2014-06-18 15:49:23 +00:00
Ralph Bean
094b960519
Start standing up github2fedmsg01.
2014-06-18 15:33:28 +00:00
Aurélien Bompard
851fa2f1d8
Mailman post-update script: less verbose output
2014-06-18 15:12:25 +00:00
Ralph Bean
ac4c54b1c7
Reduce the oauth scope for github2fedmsg.
2014-06-18 14:02:22 +00:00
Pierre-Yves Chibon
8bd76d754e
Fix the link to the static folder for kerneltest
2014-06-18 08:46:29 +02:00
Kevin Fenzi
c79320ddf1
Re-enable Greek in ask per request.
2014-06-17 21:31:57 +00:00
Patrick Uiterwijk
218f4450df
Only request permissions for the public repos
2014-06-17 21:01:06 +00:00
Ralph Bean
cecbe69723
Fix tw2 resources prefix.
2014-06-17 16:57:44 +00:00
Pierre-Yves Chibon
3faf7d48c4
Add a hosts file for kerneltest01.stg
2014-06-17 18:37:01 +02:00
Pierre-Yves Chibon
12222f4735
Fix indentation
2014-06-17 18:24:31 +02:00
Pierre-Yves Chibon
03a1c9dfca
Activate the kerneltest role in its playbook
2014-06-17 18:00:54 +02:00
Pierre-Yves Chibon
7bb064b89d
Add the kerneltest role
2014-06-17 17:52:59 +02:00
Ralph Bean
921e313c2d
Add hosts files for the gh2fm nodes.
2014-06-17 13:50:36 +00:00
Ralph Bean
ea71e3ad84
This is just not how its done.
2014-06-17 13:33:40 +00:00
Ralph Bean
6414533b5a
Another try at github2fedmsg creds.
2014-06-17 13:24:15 +00:00
Ralph Bean
27decc5401
More directories.
2014-06-16 20:41:48 +00:00
Ralph Bean
ae4389b482
Just.. run as apache.
2014-06-16 20:38:52 +00:00
Ralph Bean
db643ca928
Make this dir.
2014-06-16 20:35:31 +00:00
Ralph Bean
656f31725a
dedent.
2014-06-16 20:31:02 +00:00
Ralph Bean
0458fc105b
Start of a github2fedmsg role.
2014-06-16 20:20:21 +00:00
Ralph Bean
20b6ff52b1
Add endpoints and fedmsg cert declarations for github2fedmsg and kerneltest.
2014-06-16 18:47:15 +00:00
Ralph Bean
da3d99b727
Playbooks for github2fedmsg and kerneltest.
2014-06-16 18:42:15 +00:00
Ralph Bean
1d85f9756d
Add these two to the staging group.
2014-06-16 18:36:21 +00:00
Ralph Bean
4824e11a50
Vars for github2fedmsg and kerneltest (just staging).
2014-06-16 17:57:30 +00:00
Pierre-Yves Chibon
702f054a08
Same thing for stg
2014-06-16 19:30:21 +02:00
Aurélien Bompard
f3a3930982
Fix command line options
2014-06-16 17:29:06 +00:00
Pierre-Yves Chibon
b7da286f26
Open the ports required for fedmsg
2014-06-16 19:24:10 +02:00
Pierre-Yves Chibon
24ff45dd14
Increase the number of port for fedmsg on elections
2014-06-16 19:18:13 +02:00
Pierre-Yves Chibon
cb7098dc1d
fedmsg certs are <service>-<app> not <service>.<app>, should help finding the cert
2014-06-16 18:10:34 +02:00
Aurélien Bompard
abedc457f9
Fix OpenID bug
2014-06-16 16:07:22 +00:00
Aurélien Bompard
6adbf5b2e3
Commit forgotten file
2014-06-16 16:07:22 +00:00
Pierre-Yves Chibon
55c6574dc6
Install the fedmsg cert in stg as well
2014-06-16 18:04:39 +02:00
Pierre-Yves Chibon
ba53d13d85
Add the missing bits to get the fedmsg certs installed correctly
2014-06-16 17:59:34 +02:00
Pierre-Yves Chibon
7a1c15fe3d
Lists fedora_elections and shell in ssl.py
2014-06-16 17:48:35 +02:00
Pierre-Yves Chibon
c71811ac96
Add endpoint-elections creating the corresponding endpoints for fedmsg
2014-06-16 17:17:18 +02:00
Pierre-Yves Chibon
5090896d2a
Enable fedmsg on the elections boxes
2014-06-16 16:53:15 +02:00
Patrick Uiterwijk
8b7e8f1d12
Make pkgdb2 stg use fedoauth stg
2014-06-16 14:37:07 +00:00
Patrick Uiterwijk
c99a5c03e2
Make stg fedocal use stg fedoauth
2014-06-16 14:21:31 +00:00
Kevin Fenzi
48df03e436
Need handlers here too.
2014-06-16 01:22:40 +00:00
Kevin Fenzi
3215feb17a
Fix postfix task
2014-06-16 01:10:58 +00:00
Patrick Uiterwijk
e7819fba76
Also sign for id.(stg.)fp.o
2014-06-15 20:29:37 +00:00
Patrick Uiterwijk
1658964066
FedOAuth sends emails with errors
2014-06-15 20:02:51 +00:00
Patrick Uiterwijk
362439e698
Another log fix
2014-06-15 19:47:02 +00:00
Patrick Uiterwijk
703682e031
Correct formatter reference
2014-06-15 19:45:49 +00:00
Patrick Uiterwijk
5e211359fd
We put this in /etc/fedoauth
2014-06-15 19:44:36 +00:00
Patrick Uiterwijk
32be316aee
Revert "Make ansible use infrastructure-testing whenever we run on staging"
...
This reverts commit 1dbb5fdfe7 .
2014-06-15 19:41:11 +00:00
Patrick Uiterwijk
1dbb5fdfe7
Make ansible use infrastructure-testing whenever we run on staging
2014-06-15 19:38:45 +00:00
Patrick Uiterwijk
137d5ebacd
Merge branch 'master' of /git/ansible
2014-06-15 19:15:29 +00:00
Patrick Uiterwijk
21641b2e55
Add fedoauth-stg for FedOAuth 3.0
2014-06-15 19:15:14 +00:00
Kevin Fenzi
5388cb70a8
Conditionalize wiki auth for staging
2014-06-15 18:41:57 +00:00
Kevin Fenzi
ffba0668c2
Typo I think.
2014-06-15 18:21:54 +00:00
Kevin Fenzi
fb53d6607b
Drop download-ib01 from inventory
2014-06-15 15:58:37 +00:00
Kevin Fenzi
ef4a44c44c
Convert sudo to a role so we can include it before roles/plays that use sudo.
2014-06-14 20:58:52 +00:00
Kevin Fenzi
7ade030063
Set sudo false as we don't use it many places and this is needed for controlpersist
2014-06-14 20:30:13 +00:00
Kevin Fenzi
1aacd08ec5
Paren
2014-06-12 21:35:23 +00:00
Kevin Fenzi
8ff12d1151
Change this one back
2014-06-12 21:21:44 +00:00
Kevin Fenzi
cb7c5c456a
Once again with less aaaaa
2014-06-12 21:07:35 +00:00
Kevin Fenzi
411a2778b6
Lets try and go back
2014-06-12 21:06:42 +00:00
Kevin Fenzi
549c077b4e
Shot to the heart and you're to blame...
2014-06-12 20:59:48 +00:00
Kevin Fenzi
0108c26ca9
I just don't get it
2014-06-12 20:54:37 +00:00
Kevin Fenzi
ada496fc31
grasping at straws
2014-06-12 20:27:03 +00:00
Kevin Fenzi
ec81bc3bad
Try this one
2014-06-12 20:25:02 +00:00
Kevin Fenzi
e6f926f79c
Perhaps this makes it happy?
2014-06-12 20:22:10 +00:00
Kevin Fenzi
05dfa804d9
Drop this variable, we aren't really using it right now.
2014-06-12 20:20:18 +00:00
Kevin Fenzi
1db6e15594
This is in a subdir
2014-06-12 20:17:17 +00:00
Kevin Fenzi
3947d129f2
Change all the old first_available_file to with_first_found
2014-06-12 20:15:37 +00:00
Ralph Bean
30be2d482f
Make fedora login the default login for fmn.
2014-06-12 16:54:48 +00:00
Ralph Bean
bcaca8469a
Restrict readership.
2014-06-12 15:36:49 +00:00
Luke Macken
080a9cd52f
Use the admin.stg FAS url in the bodhi staging config
2014-06-12 15:08:20 +00:00
Ralph Bean
0d78cf7ba3
Adjust backlog thresholds for fmn again.
2014-06-12 12:23:50 +00:00
Ralph Bean
fde211bc21
Open ports for fedmsg on notifs-web nodes.
2014-06-11 19:18:13 +00:00
Ralph Bean
9229a5cd19
Typofixes.
2014-06-11 19:13:22 +00:00
Ralph Bean
ba96640054
Add fedmsg declarations for new fmn.web messages.
2014-06-11 19:01:59 +00:00
Ralph Bean
b165d0f907
Adjust warning and crit thresholds for fedmsg backlog checks.
2014-06-11 18:49:19 +00:00
Ralph Bean
0935e38cae
Crank up the fmn expiry time.
2014-06-11 18:36:52 +00:00
Stephen Smoogen
991d343802
By accelerating U235 together very fast one can get atomix boom.
2014-06-11 17:48:22 +00:00
Kevin Fenzi
b23d1c39d6
No sysadmin on releng02
2014-06-11 16:37:20 +00:00
Kevin Fenzi
32d0639a48
Drop this bit, it's pulled in alredy and is out of date.
2014-06-11 16:31:36 +00:00
Kevin Fenzi
115272477a
Nuke duplicate fedmsg setup in releng_config task, move to using fedmsg/base role.
2014-06-11 16:17:00 +00:00
Stephen Smoogen
0ebc8607db
Merge branch 'master' of /git/ansible
2014-06-11 16:12:15 +00:00
Stephen Smoogen
b80e127aed
let us try another fix for the download-ib box
2014-06-11 16:12:10 +00:00
Kevin Fenzi
363d63bca5
Nuke value03 from inventory and add value01 to backups
2014-06-11 16:10:10 +00:00
Kevin Fenzi
b87a81e522
Repoint this to kojipkgs. Will fix to final later when we have it setup.
2014-06-11 14:55:37 +00:00
Ralph Bean
3bd8b1ffa3
fmn.web needs to know about this too.
2014-06-11 13:35:03 +00:00
Ralph Bean
ffa3c11951
Add new fmn config values.
2014-06-11 13:28:21 +00:00
Stephen Smoogen
cdaddbae51
I forgot to correct a commnet last night
2014-06-11 13:19:49 +00:00
Ralph Bean
ba59a84a30
Add forgotten reference.
2014-06-11 12:58:50 +00:00
Ralph Bean
afe872aa83
Add the supybot plugin check script in from puppet.
2014-06-11 12:38:43 +00:00
Ralph Bean
daceb9dd99
Copy some more fedmsg proc checks over from puppet.
2014-06-11 12:35:58 +00:00
Stephen Smoogen
a442e735c9
fix download cron job from hourly to daily
2014-06-11 00:43:55 +00:00
Stephen Smoogen
3078d40cd5
give access to enchilada0 to ib02
2014-06-10 22:48:25 +00:00
Stephen Smoogen
c06953d240
Merge branch 'master' of /git/ansible
2014-06-10 22:40:17 +00:00
Kevin Fenzi
a2749fddc9
Bump memory for value staging too.
2014-06-10 19:31:08 +00:00
Kevin Fenzi
e555b5d86e
Make prod value have more memory
2014-06-10 19:01:12 +00:00
Kevin Fenzi
e2d50e402c
Add port 5050 to be allowed for supybot notices.
2014-06-10 18:35:57 +00:00
Ralph Bean
32bc3a550a
Fix meetbot apache icons.
2014-06-10 18:33:25 +00:00
Ralph Bean
098c314b8d
Fix fat-finger error.
2014-06-10 17:31:02 +00:00
Kevin Fenzi
ccf803d162
Add value here too
2014-06-10 17:26:57 +00:00
Ralph Bean
46bd093586
app0* stuff gone from fedmsg config, now.
2014-06-10 17:25:10 +00:00
Ralph Bean
43b0cb1117
Bodhi is no longer on app*
2014-06-10 17:23:38 +00:00
Ralph Bean
acdb55f560
Ditch the old value03.
2014-06-10 17:21:48 +00:00
Ralph Bean
c6c9fe0a3e
Supply a staging URL for staging fedmsg-irc.
2014-06-10 16:52:43 +00:00
Kevin Fenzi
8a2b0c0458
Add package for pretty printing infra messages for fedmsg-irc
2014-06-10 16:21:04 +00:00
Pierre-Yves Chibon
2354972b0c
Use stg FAS in stg, not in prod
2014-06-10 14:05:03 +02:00
Pierre-Yves Chibon
1bf258e736
Yet another one...
2014-06-10 13:31:38 +02:00
Pierre-Yves Chibon
d8b058042a
grmbl at typos
2014-06-10 13:28:14 +02:00
Pierre-Yves Chibon
f86cd0c693
Fix the location of the alembic.ini file
2014-06-10 13:25:22 +02:00
Pierre-Yves Chibon
9b117ba2ae
Install the alembic.ini file
2014-06-10 13:21:11 +02:00
Pierre-Yves Chibon
25f12fdeab
Add the alembic.ini file for elections
2014-06-10 13:10:00 +02:00
Pierre-Yves Chibon
a5ba2ac4c3
Activate bugzilla notifications in prod
2014-06-10 09:33:11 +02:00
Pierre-Yves Chibon
21b6900ab5
Configuration requires quotes
2014-06-10 09:28:08 +02:00
Pierre-Yves Chibon
04c4ddce24
Add bugzilla credentials
2014-06-10 09:22:55 +02:00
Ralph Bean
fb4d78d5e2
Supybot fedmsg bits for value01.
2014-06-10 02:44:45 +00:00
Kevin Fenzi
1ded20423c
A few tweaks for the web side.
2014-06-09 22:41:36 +00:00
Stephen Smoogen
3813e2804c
Merge branch 'master' of /git/ansible
2014-06-09 22:10:39 +00:00
Kevin Fenzi
7963c79482
Also add to inventory
2014-06-09 21:59:24 +00:00
Kevin Fenzi
89d8bfb644
Add value01 prod node
2014-06-09 21:58:12 +00:00
Kevin Fenzi
898446d403
Add supybot-fedmsg
2014-06-09 21:01:15 +00:00
Kevin Fenzi
78f9ddd663
Setup some more things.
2014-06-09 20:48:49 +00:00
Kevin Fenzi
734dff3656
Fix template more.
2014-06-09 20:23:08 +00:00
Kevin Fenzi
dea24de888
Actually fix templates to be jinja2
2014-06-09 20:10:06 +00:00
Kevin Fenzi
b50688221e
Add some notifies here.
2014-06-09 20:06:12 +00:00
Kevin Fenzi
8a91ad5190
No vpn needed in stg
2014-06-09 20:00:28 +00:00
Kevin Fenzi
99fa9428f4
Fix typo
2014-06-09 19:54:50 +00:00
Kevin Fenzi
6e9746864e
First cut at value01.stg migation to ansible
2014-06-09 19:26:35 +00:00
Tim Flink
f13a334165
setting httpd_can_network_connect_db sebool for resultsdb-backend role
2014-06-09 19:20:02 +00:00
Kevin Fenzi
86f1fa1ccc
Add python-psycopg2 to resultsdb-backend
2014-06-09 17:13:41 +00:00
Tim Flink
795cab4d2d
fixing resultsdb db init to use PROD settings and pick up the correct config file
2014-06-09 17:10:14 +00:00
Kevin Fenzi
bb5074e568
See if this changes anything.
2014-06-09 17:00:49 +00:00
Miroslav Suchý
e4b36f9e5d
install latest mock and latest glib2
...
due createrepo_c
2014-06-09 13:47:57 +00:00
Miroslav Suchý
d6d6148e84
check for forgotten instnces only once per day
2014-06-09 11:52:02 +00:00
Kevin Fenzi
7dcbcdd2d7
Fix ssh args here too.
2014-06-08 01:37:12 +00:00
Stephen Smoogen
e22a5a7e3c
Base stuff for atomic server?
2014-06-06 02:29:19 +00:00
Tim Flink
d63fc93ab2
quoting port value for postgresql db port on resultsdb-stg
2014-06-05 03:51:08 +00:00
Tim Flink
7732878e6b
adding resultsdb database init to resultsdb-backend role
2014-06-05 03:47:29 +00:00
Tim Flink
f565b6075a
fixing hosts inventory group for resultsdb-stg group playbook
2014-06-05 03:38:09 +00:00
Tim Flink
3ce2a2a84a
cleaning up a commented out variable and the variable name for resultsdb-frontend flask secret key
2014-06-05 03:38:09 +00:00
Kevin Fenzi
0e36d58943
Added these in private
2014-06-05 03:32:58 +00:00
Tim Flink
61152b0522
adding resultsdb-stg01 host, resultsdb-stg group, resultsdb backend and frontend roles
2014-06-05 03:22:07 +00:00
Kevin Fenzi
4f9806ff3c
Drop this from stg group for now.
2014-06-05 02:57:01 +00:00
Kevin Fenzi
e02f8d1a14
Set this to a default db.
2014-06-05 02:46:46 +00:00
Kevin Fenzi
5e7a0897bd
Add a db-qa01.qa instance
2014-06-05 02:28:10 +00:00
Ralph Bean
241b37ecfb
app01 is no longer a fedmsg thing.
2014-06-05 01:08:07 +00:00
Stephen Smoogen
64e3d51b79
I can write code.. reading si a different matter
2014-06-05 00:22:52 +00:00
Stephen Smoogen
52ae7d3ccb
ok lets see if I can do a cron job without breaking stuff
2014-06-05 00:18:14 +00:00
Stephen Smoogen
45e512ab3f
add a cron hourly script
2014-06-05 00:05:04 +00:00
Stephen Smoogen
9a80b5ddf4
and lo, I forgot to add stuff
2014-06-04 21:26:08 +00:00
Kevin Fenzi
6a5cbde529
Fix typo
2014-06-04 20:39:26 +00:00
Kevin Fenzi
4b16ad20fe
Add nfsv4 port
2014-06-04 19:08:29 +00:00
Kevin Fenzi
33d094ad7f
koji also uses builder root
2014-06-04 18:57:34 +00:00
Kevin Fenzi
13b04a2b10
Add nfs mounts for staging buildsys
2014-06-04 18:51:53 +00:00
Ralph Bean
50738d3b00
Tell selinux that koji-hub can fedmsg.
2014-06-04 18:46:37 +00:00
Kevin Fenzi
3fb766611d
Use fqdn
2014-06-04 18:35:26 +00:00
Kevin Fenzi
7e5eaad4be
tags, not tag
2014-06-04 18:17:39 +00:00
Kevin Fenzi
80d408dede
Add nfs-server and make koji01.stg use it.
2014-06-04 18:14:49 +00:00
Kevin Fenzi
06bd8dfd92
Reorg the nfs role to have client and server as subroles.
2014-06-04 18:07:59 +00:00
Kevin Fenzi
068c567cd1
Update hosts for koji01.stg
2014-06-04 17:19:50 +00:00
Aurélien Bompard
016f57639a
Mailman: fix BrowserID login
2014-06-04 15:52:46 +00:00
Kevin Fenzi
5233dee358
Follow symlinks here.
2014-06-04 02:32:51 +00:00
Kevin Fenzi
f0ba60ed4b
Allow fedmsg and 80/443 on koji01.stg
2014-06-04 01:40:54 +00:00
Kevin Fenzi
2798e5d55a
Add dirs.
2014-06-04 01:16:20 +00:00
Kevin Fenzi
efa3078104
Use stg-koji.conf on stg builders
2014-06-04 01:03:23 +00:00
Kevin Fenzi
6ac6128d89
Fix this so it works.
2014-06-04 00:43:10 +00:00
Kevin Fenzi
41a25dfacc
Add koji_builder only on stg hub
2014-06-04 00:40:47 +00:00
Stephen Smoogen
6c290c6106
ok special super powers away.
2014-06-03 19:53:26 +00:00
Kevin Fenzi
252f477ca5
Don't do this link on stg builders.
2014-06-03 19:50:03 +00:00
Kevin Fenzi
0b0c0a813b
Set datacenter here.
2014-06-03 19:45:08 +00:00
Kevin Fenzi
ffbf76728a
Another way to shave that feline
2014-06-03 19:43:12 +00:00
Kevin Fenzi
cf2e7fedd1
ok, how about this?
2014-06-03 19:40:31 +00:00
Kevin Fenzi
23985c3763
How about this try
2014-06-03 19:37:53 +00:00
Kevin Fenzi
2edf55cbdd
Try this
2014-06-03 19:34:55 +00:00
Kevin Fenzi
8f9fbde54b
Try some grouping action.
2014-06-03 19:32:06 +00:00
Kevin Fenzi
f4b0150134
Try this to not do koji mount in stg
2014-06-03 19:29:39 +00:00
Kevin Fenzi
05193faeee
Don't do a eth1 in stg
2014-06-03 19:02:39 +00:00
Kevin Fenzi
31323edffa
fix vm host
2014-06-03 19:01:06 +00:00
Kevin Fenzi
a75bc8649b
Add a buildvm-01.stg
2014-06-03 18:56:30 +00:00
Kevin Fenzi
abae4d81d4
64 bit host, but still using lib since it's noarch I guess.
2014-06-03 18:37:22 +00:00
Kevin Fenzi
9688eff246
Add koji-hub-plugins
2014-06-03 18:34:47 +00:00
Kevin Fenzi
12849b9d1b
This is a 64bit host
2014-06-03 18:17:40 +00:00
Kevin Fenzi
9011f742c3
Add some fedmsg config
2014-06-03 18:17:01 +00:00
Kevin Fenzi
c2eaa4f2dc
Add fedmsg and fedmsg koji plugin
2014-06-03 18:10:46 +00:00
Kevin Fenzi
b21b7ce546
Adjust hosts for koji01.stg
2014-06-03 17:58:07 +00:00
Kevin Fenzi
429487b663
Add web.conf
2014-06-03 17:49:56 +00:00
Kevin Fenzi
5c1717c10f
Add update crl script
2014-06-03 16:39:22 +00:00
Kevin Fenzi
c9802284cd
Fix some paths
2014-06-03 16:34:36 +00:00
Kevin Fenzi
d0a0ca74d1
ssl certorama
2014-06-03 16:31:57 +00:00
Kevin Fenzi
7433201bb6
Fix ssl for staging.
2014-06-03 16:18:27 +00:00
Kevin Fenzi
2f0b27b806
Fix filename
2014-06-03 16:11:46 +00:00
Kevin Fenzi
cfb0ebe8a4
Fix typo
2014-06-03 16:10:11 +00:00
Kevin Fenzi
a6b89d99aa
Copy, not file.
2014-06-03 16:03:36 +00:00
Kevin Fenzi
18f8dd15bc
Add a bunch of koji web config files.
2014-06-03 16:01:33 +00:00
Kevin Fenzi
967bc12995
Add koji hub template
2014-06-03 15:38:36 +00:00
Aurélien Bompard
a116e1e34d
Mailman: add unit tests, and adatp to recent code changes
2014-06-03 13:36:16 +00:00
Kevin Fenzi
aaa825588e
Add 'base' tag to all base tasks so we can run playbooks with --skip-tags=base to avoid base
2014-06-02 23:26:32 +00:00
Kevin Fenzi
9b3781ae81
This is a copy, duh
2014-06-02 23:23:11 +00:00
Kevin Fenzi
813f60a03a
Try this
2014-06-02 23:18:10 +00:00
Kevin Fenzi
abb904688a
Add some more from todo
2014-06-02 23:13:55 +00:00
Kevin Fenzi
9dd996d208
Fix some typos
2014-06-02 23:07:22 +00:00
Kevin Fenzi
0c358d9b68
Fix gateway
2014-06-02 23:05:58 +00:00
Kevin Fenzi
3acf51a6f0
Clean up some
2014-06-02 23:05:00 +00:00
Kevin Fenzi
c33f8914be
First cut at moving koji01 over to ansible.
2014-06-02 22:40:27 +00:00
Miroslav Suchý
a54ef3bae8
RHBZ 1102788 - Increase number of file descriptors on the build machine
2014-06-02 11:54:24 +00:00
Till Maas
d212c97757
add autosign hosts file
2014-06-01 13:04:21 +02:00
Till Maas
aae8715ab4
autosigner: Install more fedmsg related packages
2014-06-01 12:53:01 +02:00
Pierre-Yves Chibon
4e9eb5d7a9
Import upstream fix fixing broken links
2014-06-01 07:51:28 +00:00
Kevin Fenzi
fd590b2e4e
The openvpn crl isn't needed on clients.
2014-05-31 16:54:39 +00:00
Stephen Smoogen
9a96b7c008
make it use a kickstart that wont make a 2750GB / drive
2014-05-30 22:28:57 +00:00
Till Maas
2f97e1d19e
autosigner: Install fedmsg
2014-05-30 20:40:49 +02:00
Stephen Smoogen
7f00c656fb
duh.. ips dont work here
2014-05-30 17:55:49 +00:00
Stephen Smoogen
5948aab0be
well why does this work everywhere else?
2014-05-30 17:54:17 +00:00
Till Maas
682a04b292
Add autosigner role
...
- Move builder infrastructure repo to own role
- Add initial tasks to autosigner role
2014-05-30 17:16:06 +00:00
Dennis Gilmore
979fcada2a
cleanup the pungi mash configs a bit
2014-05-30 17:16:01 +00:00
Ralph Bean
9f13037ffc
Update releng fedmsg to use the new relay.
...
Not sure why this is separate.
2014-05-30 16:30:22 +00:00
Kevin Fenzi
504514d62e
Some bkernel role fixes
2014-05-30 16:29:04 +00:00
Ralph Bean
6c0308b707
Conditional check for persistent-cloud group members.
2014-05-30 16:14:28 +00:00
Pierre-Yves Chibon
2c40e94fb1
sysadmin-cvs is only for shell access, pkgdb uses cvsadmin
2014-05-30 15:23:43 +02:00
Miroslav Suchý
727ae15ed3
sync up copr-fe-dev playbook with copr-fe
2014-05-30 11:19:40 +00:00
Aurélien Bompard
960d87f8ca
Mailman: create a HK DB for unit testing
2014-05-30 08:13:00 +00:00
Stephen Smoogen
2f9b7871ea
lets see if I can build a new download box
2014-05-30 02:15:46 +00:00
Stephen Smoogen
ab655882cc
hey lets see if I can break another box
2014-05-29 23:03:01 +00:00
Stephen Smoogen
cd9c250f90
add -ib02 to our mix.
2014-05-29 21:21:56 +00:00
Stephen Smoogen
1bbd8a1b28
we have all dl-rdu boxes rebuilt and ready for ansible
2014-05-29 18:28:03 +00:00
Kevin Fenzi
dda7a6165b
Set facls for pesign to work with mock
2014-05-29 17:33:41 +00:00
Ralph Bean
1b20c92541
One more tweak.
2014-05-29 16:51:04 +00:00
Ralph Bean
20eef15011
This is probably more right.
2014-05-29 16:46:40 +00:00
Ralph Bean
19557d5735
In Soviet Russia, Ruby joins YOU!
2014-05-29 16:40:25 +00:00
Kevin Fenzi
0365b73da2
Don't set default root bw for bkernel, they have their own.
2014-05-29 16:38:04 +00:00
Ralph Bean
e258bae727
Collectd+postgres for db-datanommer01
2014-05-29 16:36:43 +00:00
Kevin Fenzi
ad799abed9
Fold bkernel into buildhw with it's own role.
2014-05-29 16:24:09 +00:00
Pierre-Yves Chibon
86742b2fa4
Drop the email notifications on stg
2014-05-29 17:26:57 +02:00
Stephen Smoogen
be679b600b
and now we have 2 boxes ansibled
2014-05-29 01:10:12 +00:00
Kevin Fenzi
b91e4fd911
Try this in the second play
2014-05-28 19:57:14 +00:00
Kevin Fenzi
4aa96f63d6
Try this is end the owner/group flip flops.
2014-05-28 19:08:20 +00:00
Kevin Fenzi
8c2bbb792d
I think this is causing it to change all the time.
2014-05-28 18:56:49 +00:00
Kevin Fenzi
1b4c8822f6
Make this idempotent for compose-x86-02
2014-05-28 18:32:22 +00:00
Kevin Fenzi
c8d85b011b
Adjust this and add a note.
2014-05-28 18:00:01 +00:00
Kevin Fenzi
95ef483354
Add a playbook with all the fedmsg using playbooks in it, so you can run it with -t fedmsgdupdate and just update fedmsg endpoints
2014-05-28 17:58:51 +00:00
Kevin Fenzi
e181500314
Add a tag to this fedmsg.d config that changes somewhat often so we can just run it.
2014-05-28 17:24:06 +00:00
Stephen Smoogen
059d296b2f
actimeo is its name.
2014-05-28 16:49:46 +00:00
Stephen Smoogen
7c09009d08
we call it rdu2 sometimes but it really is only one we care about.
2014-05-27 23:35:27 +00:00
Stephen Smoogen
90ccf9c5a1
ok maybe a newline will fix it.?.
2014-05-27 23:00:30 +00:00
Stephen Smoogen
58be119242
write code like yoda, we must
2014-05-27 22:50:47 +00:00
Stephen Smoogen
b8197212cb
well that went as well as expected. lets try with hands this time.
2014-05-27 22:46:21 +00:00
Stephen Smoogen
1d7d5ea567
Hey look ma, no hands!
2014-05-27 22:42:54 +00:00
Kevin Fenzi
9daa623bc4
Fix this to work with --check/--diff runs.
2014-05-27 22:26:23 +00:00
Kevin Fenzi
f05fe5e864
Fix log file path
2014-05-27 21:05:42 +00:00
Kevin Fenzi
8e69a8a2d0
Enable send_unaswered_question_reminders in ask.
2014-05-27 21:02:37 +00:00
Stephen Smoogen
eeaa9e5d36
chainsaw
2014-05-27 20:55:09 +00:00
Stephen Smoogen
ac9fe6ca02
lets try this and see if ansible likes this better.
2014-05-27 20:53:53 +00:00
Stephen Smoogen
a04e4bd839
Merge branch 'master' of /git/ansible
2014-05-27 20:00:04 +00:00
Stephen Smoogen
d7c1a29e0a
lets try breaking out download a bit
2014-05-27 20:00:00 +00:00
Ralph Bean
8322306912
Get the fedmsg crl directly from proxy01.stg in staging.
2014-05-27 19:31:01 +00:00
Ralph Bean
49831e2c17
Point fedmsg-logger at busgateway01 now.
2014-05-27 18:22:34 +00:00
Kevin Fenzi
8906975d33
Fix these log touch plays to also be idempotent
2014-05-27 18:15:04 +00:00
Kevin Fenzi
6f947cd9ec
Fix this to be idempotent
2014-05-27 18:06:47 +00:00
Till Maas
bb84dd36de
fetch-ssh-keys: mode +x
2014-05-24 09:47:54 +02:00
Kevin Fenzi
9460e6b386
And clean app up from these places too.
2014-05-23 22:34:26 +00:00
Kevin Fenzi
45a5c04dcd
Drop apps from inventory
2014-05-23 22:33:43 +00:00
Kevin Fenzi
64b4cf7614
This task doesn't exist anymore
2014-05-23 22:28:21 +00:00
Kevin Fenzi
165973baf4
Fix missing "
2014-05-23 22:23:33 +00:00
Kevin Fenzi
042eb241e0
Fix elections, add a fallback stg hosts file.
2014-05-23 20:35:45 +00:00
Kevin Fenzi
aa559651d5
/dev/null the easyfix cron output for now.
2014-05-23 20:31:46 +00:00
Kevin Fenzi
4bfcfcd28b
Add hosts file for gallery01.stg
2014-05-23 20:30:48 +00:00
Kevin Fenzi
60c9a31a30
This needs to be staging, not stg
2014-05-23 19:19:48 +00:00
Kevin Fenzi
0944682e24
No denyhosts for f20 hosts for now, add manual monitor playbook.
2014-05-23 18:38:30 +00:00
Kevin Fenzi
83e93d6a10
Add monitor.qa and taskotron-dev01.qa
2014-05-23 18:10:08 +00:00
Kevin Fenzi
fe8ffbbb27
Drop denyhosts from these for now.
2014-05-23 17:51:21 +00:00
Kevin Fenzi
9f4568e3ae
Drop ksdevice and adjust for f20 on these
2014-05-23 17:34:25 +00:00
Kevin Fenzi
336e13bc7b
Add qadevel/qadevel-stg and autosign
2014-05-23 16:48:59 +00:00
Aurélien Bompard
0c76d40590
Adapt HyperKitty config file to the lastest changes
2014-05-23 02:46:15 +00:00
Stephen Smoogen
c32cf9e0a7
ok lets try this chickbone
2014-05-22 23:25:57 +00:00
Kevin Fenzi
0a4b6b3eeb
Merge branch 'master' of /git/ansible
2014-05-22 21:32:05 +00:00
Kevin Fenzi
909f20d063
up sundries procs and drop app05/app08 from inventory
2014-05-22 21:31:44 +00:00
Pierre-Yves Chibon
f40e8537b5
Add the SITE_ROOT for pkgdb2 1.8.2
2014-05-22 23:24:48 +02:00
Kevin Fenzi
5e89f8edf2
Tweak selinux contexts for freemedia
2014-05-22 19:28:51 +00:00
Kevin Fenzi
bff07f007a
Also we need to install php
2014-05-22 19:12:43 +00:00
janeznemanic
f2050a69ec
Add freemedia role.
2014-05-22 19:05:42 +00:00
Kevin Fenzi
4a2db2ad3c
Fix buffet0 in ansible too
2014-05-22 17:39:13 +00:00
Ralph Bean
b90bf85b3d
Bump the zmq timeout on these nagios checks.
2014-05-22 14:56:48 +00:00
Kevin Fenzi
da642af5fd
Fix up staging group
2014-05-22 01:09:49 +00:00
Kevin Fenzi
8bc7d8d773
Add gallery01.stg to the stg group
2014-05-22 01:00:28 +00:00
Stephen Smoogen
c087d147c7
Merge branch 'master' of /git/ansible
2014-05-21 22:48:45 +00:00
Stephen Smoogen
f6e1c1cb1c
change the nfs option to have longer actimeo on dl servers
2014-05-21 22:48:39 +00:00
Kevin Fenzi
c6a38231ab
Try adding arm04-builder22 back in
2014-05-21 21:53:41 +00:00
Stephen Smoogen
92072f0461
And now we are back to 5 download servers
2014-05-21 21:29:25 +00:00
Kevin Fenzi
e5ddbcea29
Set nrpe procs higher on the new download servers.
2014-05-21 20:47:25 +00:00
Ricky Elrod
d3291aaf85
Merge branch 'master' of /git/ansible
2014-05-21 19:48:55 +00:00
Ricky Elrod
5703b88f03
create /srv/web directory
2014-05-21 19:48:46 +00:00
Ralph Bean
a75f28b510
Remove busmon.
2014-05-21 19:00:37 +00:00
Stephen Smoogen
19ec8df9af
Temp removing dl06
2014-05-21 18:45:26 +00:00
Stephen Smoogen
2858cce6f6
Merge branch 'master' of /git/ansible
2014-05-21 18:43:20 +00:00
Kevin Fenzi
af011162e3
Add db connect bool for mm frontend
2014-05-21 17:57:45 +00:00
Kevin Fenzi
8fc6694c5f
Set some sebools on sundries.
2014-05-21 17:38:51 +00:00
Kevin Fenzi
3333d00a59
Just call this mirrormanager.conf
2014-05-21 17:28:36 +00:00
Kevin Fenzi
eb7371b560
Try this.
2014-05-21 17:22:07 +00:00
Kevin Fenzi
41d2bcc729
Fix end to endif
2014-05-21 17:07:59 +00:00
Kevin Fenzi
dd45f8c109
Fix stray =
2014-05-21 17:05:13 +00:00
Kevin Fenzi
317360d13b
Fix template.
2014-05-21 16:59:25 +00:00
Kevin Fenzi
6bc2f3f623
Also add to playbook.
2014-05-21 16:51:24 +00:00
janeznemanic
829c097e9d
Add mirrormanager role
2014-05-21 16:50:40 +00:00
Kevin Fenzi
1f92636069
This cron also has to be 644
2014-05-21 16:06:44 +00:00
Kevin Fenzi
21ba0ac487
Cron has to be 644
2014-05-21 16:01:48 +00:00
Kevin Fenzi
ec4b02c539
In staging, host_group is automagically staging, so use rsync_group instead here.
2014-05-21 15:47:07 +00:00
Ricky Elrod
8d3223e0dd
Merge branch 'master' of /git/ansible
2014-05-21 13:06:22 +00:00
Ricky Elrod
02ef0ba713
Unhardcode path to rpm. Thanks ProT-0-TypE!
2014-05-21 13:06:17 +00:00
Pierre-Yves Chibon
27ed359f9a
The /pkgdb/ is not needed
2014-05-21 09:36:01 +02:00
Pierre-Yves Chibon
06735a2f86
Add the SITE_URL configuration to pkgdb2
2014-05-21 09:29:37 +02:00
Kevin Fenzi
c441747d54
Add needs-reboot.py as a common script.
2014-05-20 20:09:47 +00:00
Ralph Bean
d6bd38f58c
Make fedora-packages use staging urls where appropriate.
2014-05-20 20:08:41 +00:00
Ralph Bean
3eb1d43fe2
Point staging pkgdb urls at staging pkgdb2.
2014-05-20 18:49:47 +00:00
Stephen Smoogen
4e0d6d5991
Merge branch 'master' of /git/ansible
2014-05-20 16:56:14 +00:00
Kevin Fenzi
6944f0b8d4
We need a master sundries in stg too
2014-05-19 23:36:53 +00:00
Kevin Fenzi
3c4bed5b96
More easyfix tweaks.
2014-05-19 23:31:39 +00:00
Kevin Fenzi
0ba6c1244b
Need python-bugzilla for easyfix
2014-05-19 23:26:30 +00:00
Kevin Fenzi
a41d855530
Add rsyncd setup for sundries so proxies can pull easyfix from it instead of apps
2014-05-19 23:17:42 +00:00
Kevin Fenzi
79f507271b
And here too
2014-05-19 19:41:40 +00:00
Kevin Fenzi
efe74a6c90
Add admin.stg here.
2014-05-19 19:38:00 +00:00
Kevin Fenzi
929505850c
Add a mailman01.stg hosts file with correct entries.
2014-05-19 18:57:53 +00:00
Kevin Fenzi
a47859cb26
Speeling is fun.
2014-05-19 18:24:41 +00:00
Kevin Fenzi
95733ac284
More missed accelerates
2014-05-19 18:21:11 +00:00
Kevin Fenzi
b1ac6680ba
Missed an accelerated.
2014-05-19 17:29:12 +00:00
Kevin Fenzi
12090a21fd
Update fas url for stg now that the cert is fixed.
2014-05-19 17:19:23 +00:00
Kevin Fenzi
06e12bdb8b
Fix fedocal production hosts files.
2014-05-19 16:53:45 +00:00
Kevin Fenzi
fbebe1ebc2
Add a serverbeach resolv.conf skeleton
2014-05-19 15:42:48 +00:00
Kevin Fenzi
25dc54212b
Set accelerate to false by default, override with -e acclerated=True for your playbook runs.
2014-05-19 15:22:24 +00:00
Kevin Fenzi
7ba907d5ce
Move mirrorlist wsgi config to a template and set processes different for mirrorlist-serverbeach.
2014-05-19 14:48:57 +00:00
Ralph Bean
7b84ea9663
Also, improve the other two new fedmsg checks.
2014-05-19 14:26:38 +00:00
Ralph Bean
fb03577eea
Make the fedmsg check producers/consumers check a little smarter.
2014-05-19 14:20:21 +00:00
Pierre-Yves Chibon
d3af060dfa
Cut out accelerate from the sundries playbook
2014-05-19 12:32:28 +02:00
Pierre-Yves Chibon
d20ffe58ff
Re-establish running the cron every Monday at 10am
2014-05-19 12:31:30 +02:00
Pierre-Yves Chibon
74706bf93a
Update the fedora-owner-change.py script to the latest version from upstream
...
This makes it work with both pkgdb1 and pkgdb2 fedmsg messages
2014-05-19 12:29:04 +02:00
Stephen Smoogen
64478331da
and before we run into another problem make sure apache can read the public file.
2014-05-16 23:54:35 +00:00
Stephen Smoogen
24ed0ae145
try to get some of the directories correct
2014-05-16 23:52:52 +00:00
Stephen Smoogen
2b464ac498
do we need a generic role for ssl?
2014-05-16 23:41:24 +00:00
Stephen Smoogen
7cbd6611fa
ok lets try getting back to our original problem.
2014-05-16 23:23:16 +00:00
Stephen Smoogen
84839ad928
ok using a tmp inventory file was my problem. my bad.
2014-05-16 22:53:55 +00:00
Stephen Smoogen
d52f39215a
flailing
2014-05-16 22:11:42 +00:00
Stephen Smoogen
f4fc902768
msg: Destination directory {{libdir | /usr/lib64}}/nagios/plugins does not exist
2014-05-16 21:56:12 +00:00
Stephen Smoogen
1a80191e6f
ok this had better work.. maybe.. the books says so.
2014-05-16 21:51:48 +00:00
Stephen Smoogen
6c8f110b5a
ok this had better work.. maybe.
2014-05-16 21:48:55 +00:00
Stephen Smoogen
963d0918ac
try moving stuff down a tree
2014-05-16 21:08:14 +00:00
Kevin Fenzi
22b531e5b3
Clean up this some more.
2014-05-16 20:18:40 +00:00
Kevin Fenzi
51173a59b8
No d on nfs-idmap on fedora
2014-05-16 19:54:05 +00:00
Kevin Fenzi
ac17a003b7
Tweak nfs client role
2014-05-16 19:40:50 +00:00
Kevin Fenzi
47185c520d
Make everything doing nfs mounts use the nfs_client role.
2014-05-16 19:35:56 +00:00
Kevin Fenzi
b22e1be972
Perhaps quotes are confusing it here.
2014-05-16 18:55:03 +00:00
Kevin Fenzi
bcca815b46
Make sure rsyncd log file exists
2014-05-16 18:47:10 +00:00
Kevin Fenzi
ae9210bd07
Try reordering this
2014-05-16 18:42:06 +00:00
Kevin Fenzi
e1a97d5d8d
Also need libsemanage-python
2014-05-16 18:37:41 +00:00
Kevin Fenzi
e6ee48e002
need a state here.
2014-05-16 18:34:15 +00:00
Kevin Fenzi
44cd3f7423
Add another url to blacklist for paste.
2014-05-16 15:43:13 +00:00
Kevin Fenzi
061b5eb734
Make this task work with rhel and fedora releng hosts.
2014-05-16 15:27:40 +00:00
Kevin Fenzi
e01a829c2d
Fix which virthost releng02 is on.
2014-05-16 15:20:45 +00:00
Kevin Fenzi
d830e268ae
Add pyliblzma to releng machines to deal with rawhide repodata
2014-05-16 15:18:09 +00:00
Miroslav Suchý
3113ef2232
add pyliblzma so yum can handle packages xz compression
2014-05-16 12:10:29 +00:00
Ralph Bean
ab78ddd39a
Use correct consumer name for datanommer.
2014-05-15 21:06:32 +00:00
Kevin Fenzi
75ccc28e69
Add port 80 here
2014-05-15 19:41:39 +00:00
Kevin Fenzi
4df7a8e3ad
Add some vpn to docs-backend
2014-05-15 19:22:22 +00:00
Ralph Bean
fa3d33bbd4
Use correct pkgdb2 url for fmn.
2014-05-15 14:30:11 +00:00
Pierre-Yves Chibon
a8f610b17d
Let's have pkgdb send email as pkgdb
2014-05-15 08:22:12 +02:00
Ricky Elrod
1dccbe021f
Move custom vars to group_vars/download
2014-05-15 04:02:22 +00:00
Ricky Elrod
b5cbb782ec
fix it this way instead
2014-05-15 03:50:14 +00:00
Ricky Elrod
f630159e9f
udp_ports: []
2014-05-15 03:47:55 +00:00
Ricky Elrod
943ab92f33
here too
2014-05-15 03:44:59 +00:00
Ricky Elrod
8d78731cc5
accelerate: False for now
2014-05-15 03:44:16 +00:00
Ricky Elrod
a2a2a98ec9
open ports
2014-05-15 03:36:43 +00:00
Ricky Elrod
989f4f1e6b
More downloadXX fun
2014-05-15 03:31:02 +00:00
Kevin Fenzi
e5ed01f1ae
It's base here.
2014-05-15 02:31:36 +00:00
Kevin Fenzi
d0708ab507
Add collectd to pkgdb instances too
2014-05-15 02:29:50 +00:00
Patrick Uiterwijk
e30907f145
Pkgdb now also uses openid
2014-05-14 22:14:18 +00:00
Ralph Bean
4c523d32c0
Use "pkgdb2" as a fedmsg key.
2014-05-14 22:08:31 +00:00
Pierre-Yves Chibon
bcf935d5fe
Add scm-commits in Cc to all emails
2014-05-14 21:55:37 +00:00
Ralph Bean
50544699e0
Declare the pkgdb0* shell cert.
2014-05-14 21:44:49 +00:00
Kevin Fenzi
16daf5eae8
Try setting this for postfix
2014-05-14 21:37:30 +00:00
Pierre-Yves Chibon
954db292d1
Disable accelerate on the pkgdb playbook for now
2014-05-14 23:25:06 +02:00
Pierre-Yves Chibon
7c3ad83ce9
Active pkgdb2 email and don't check ssl cert on stg
2014-05-14 22:03:53 +02:00
Pierre-Yves Chibon
4bd31cf881
Allow pkgdb2 to send emails
2014-05-14 22:01:15 +02:00
Ralph Bean
1f8f67a12b
Add koji to /etc/hosts for tagger.
2014-05-14 19:25:13 +00:00
Kevin Fenzi
d16754d38c
Fix hosts on pkgdb01/02
2014-05-14 18:49:21 +00:00
Ralph Bean
26e208a47e
Apparently tagger needs this for its cronjobs.
2014-05-14 18:02:42 +00:00
Kevin Fenzi
f7a48895a6
Add correct group to buildhw to get the right hosts file
2014-05-14 17:42:35 +00:00
Ralph Bean
9ce3c8f0cf
Tell fmn to talk pkgdb2 api.
2014-05-14 16:09:22 +00:00
Ralph Bean
b30b347508
Tell badges to talk pkgdb2 api.
2014-05-14 16:09:13 +00:00
Ralph Bean
27b3cbc4eb
One more spot for pkgdb in the fedmsg config.
2014-05-14 16:05:20 +00:00
Ralph Bean
afbe9406dc
pkgdb2 fedmsg config.
2014-05-14 15:54:30 +00:00
Stephen Smoogen
bd09bf39fe
Merge branch 'master' of /git/ansible
2014-05-13 22:41:48 +00:00
Stephen Smoogen
046f54a780
Add the extra download boxes
2014-05-13 22:41:41 +00:00
Kevin Fenzi
5e3229d410
Add pkgdb01/02 prod nodes
2014-05-13 20:34:07 +00:00
Kevin Fenzi
79a32d4581
Move old bc02 blades to all be buildhw
2014-05-13 17:27:29 +00:00
Pierre-Yves Chibon
edea554550
Add missing file for easyfix
2014-05-13 19:12:13 +02:00
Pierre-Yves Chibon
945cc29f8e
Adjust the fedora-owner-change cron and script for testing in real condition
2014-05-13 18:38:44 +02:00
Pierre-Yves Chibon
ea0e074316
Run the fedora_owner_change cron on the sundry master
2014-05-13 18:37:07 +02:00
Pierre-Yves Chibon
14f0d2b628
Add the fedora_owner_change role
2014-05-13 18:35:49 +02:00
Pierre-Yves Chibon
6d11d19427
Have the sundries host run the easyfix cron
2014-05-13 12:40:21 +02:00
Pierre-Yves Chibon
4dd6ab1429
Simplify the copy instruction a little
2014-05-13 12:39:19 +02:00
Pierre-Yves Chibon
8cb2345e5d
Add first work on the easyfix role
...
This still requires some work:
- It has no playbook
- It is missing the proxy bits
- configuration of the proxies themselves
- cron job copying the files from the app running the cron job onto
the proxies
2014-05-13 12:36:57 +02:00
Pete Travis
212918325a
busy repo merge, no conflicts, I promise
2014-05-12 17:38:10 -06:00
Pete Travis
3490c3a772
closing quotes
2014-05-12 17:36:47 -06:00
Pete Travis
846d8c9089
Here's to learning from foolish mistakes
2014-05-12 22:25:37 +00:00
Pete Travis
c5fcdc4cc2
Publican needs an empty sqlite db, or interactive setup that we aren't interested in performing
2014-05-12 16:21:20 -06:00
Pete Travis
0f96ffb42f
when all you have is a hammer, all your horizontal line characters end up flattened
2014-05-12 22:14:00 +00:00
Pete Travis
c00f70f332
herding templates
2014-05-12 22:10:15 +00:00
Pete Travis
7de92cedc1
cronjobs need names
2014-05-12 22:06:49 +00:00
Pete Travis
f18010f21d
herding files
2014-05-12 16:03:29 -06:00
Kevin Fenzi
d367982cba
Move publican stuff to another play
2014-05-12 21:52:10 +00:00
Kevin Fenzi
092004acaa
Tweak role
2014-05-12 21:46:28 +00:00
Kevin Fenzi
68e757521d
Add hosts file for docs backend
2014-05-12 21:43:16 +00:00
Kevin Fenzi
b56f068125
virthost11 is no more.
2014-05-12 21:35:38 +00:00
Pete Travis
085acaa45f
ansible_managed does not give away #s for free
2014-05-12 21:33:25 +00:00
Pete Travis
b1e67b8c58
fixing some sloppy quoting
2014-05-12 21:28:16 +00:00
Pete Travis
2b36f84bdd
The shift key must have stuck. Yeah, that's it.
2014-05-12 21:25:03 +00:00
Pete Travis
87597c7fa6
Get fedwatch from epel, not copr
2014-05-12 21:19:52 +00:00
Pete Travis
6732449f55
colons for vars!
2014-05-12 21:16:21 +00:00
Pete Travis
5ed13b7bbc
Courtesy merge; remember to pull before you commit, Pete!
2014-05-12 15:05:31 -06:00
Pete Travis
ae492e0402
Initial working configuration for docs backend
2014-05-12 15:05:03 -06:00
Ralph Bean
e87b4635b8
Cast to an int, otherwise error condition is never met.
2014-05-12 20:25:29 +00:00
Pierre-Yves Chibon
b8ef359849
Ask SELinux to let apache send emails
2014-05-12 20:05:44 +02:00
Ralph Bean
42fda730da
Have to actually copy the new pieces out.
2014-05-12 17:26:22 +00:00
Kevin Fenzi
343932b96d
Re-add these three socs
2014-05-12 17:21:08 +00:00
Ralph Bean
c96195506a
Introduce new fedmsg nagios checks from Janez Nemanic.
...
See https://fedorahosted.org/fedora-infrastructure/ticket/4044
2014-05-12 16:43:09 +00:00
Pierre-Yves Chibon
78237338b3
re-disable accelerate in the nuancier playbook
...
This reverts commit bb74057acd .
2014-05-12 18:09:51 +02:00
Pierre-Yves Chibon
bb74057acd
Revert "disable accelerate in the nuancier playbook"
...
This reverts commit d9b9af1ed5 .
2014-05-12 17:46:18 +02:00
Kevin Fenzi
fcbbe7f339
Just 2 qa and packager socs
2014-05-11 19:36:56 +00:00
Kevin Fenzi
96427b693f
Don't need statd
2014-05-11 16:11:13 +00:00
Kevin Fenzi
63f74db484
Adjust releng config a bit
2014-05-11 15:57:52 +00:00
Jamie Nguyen
20ec6c9a34
Fix link to badges fan.
2014-05-11 14:17:39 +00:00
Patrick Uiterwijk
573f54f9a8
This file seems to have been removed from upstream.
...
The file started with this in the last few releases:
* This file contains ancient db-related functions that have been deprecated. Do
* not use them. Please find the appropriate replacements.
2014-05-11 13:11:07 +00:00
Patrick Uiterwijk
5d089b9f0d
Adding some icons back that weren't transferred over to ansible from app0* to wiki
2014-05-11 12:50:41 +00:00
Kevin Fenzi
ed01966260
Put buildvm-27 on the right virthost
2014-05-11 04:46:00 +00:00
Kevin Fenzi
340ca5c862
Update arm02 builders
2014-05-10 23:05:11 +00:00
Kevin Fenzi
e6f46c068b
Fix arm packager sudoers
2014-05-10 22:45:24 +00:00
Kevin Fenzi
779d5d575e
Move buildvm's to new blade buildvmhosts.
2014-05-10 18:20:37 +00:00
Kevin Fenzi
8110c03c1f
This task moved to a role.
2014-05-10 17:35:23 +00:00
Dennis Gilmore
582aeca228
move the group the compose box is in
2014-05-10 04:09:14 +00:00
Dennis Gilmore
4e3c8fa62e
add rawhide x86_64 compose config. update the others to include pungi
2014-05-10 03:54:49 +00:00
Kevin Fenzi
681febf884
Re-add fixed arm04 socs
2014-05-10 00:52:57 +00:00
Kevin Fenzi
023cbdc347
Add variables for arm retrace soc
2014-05-09 21:23:18 +00:00
Kevin Fenzi
136a023187
Don't need koji config here on retrace
2014-05-09 20:59:34 +00:00
Kevin Fenzi
2c5b326f75
Reorder this some.
2014-05-09 20:54:31 +00:00
Kevin Fenzi
60ff17bcea
Add a arm-retrace playbook.
2014-05-09 20:42:29 +00:00
Kevin Fenzi
a28f4efc86
It's just arm-releng here.
2014-05-09 20:40:59 +00:00
Kevin Fenzi
ad8b1733cb
Move things around a bit more.
2014-05-09 19:59:45 +00:00
Kevin Fenzi
0fb40d4ddd
Adjust for new arm releng and retrace and fixed arm01 socs
2014-05-09 19:30:14 +00:00
Kevin Fenzi
72e2521a90
Bump serial up on backups
2014-05-09 01:44:38 +00:00
Ralph Bean
2856e06c0f
This might just be fixed.
2014-05-08 21:24:47 +00:00
Ralph Bean
09b268e69c
Debug fedmsg callback_plugin.
2014-05-08 21:21:35 +00:00
Kevin Fenzi
2d3bd45979
Move a bunch of vms to virthost16
2014-05-08 19:57:31 +00:00
Ricky Elrod
e9e8a1ab90
Start of download-server port to ansible. Still needs httpd config (esp. ssl certs) and rsync server stuff I think
2014-05-07 20:35:42 +00:00
Stephen Smoogen
929a4e2161
let us add virthost17 and virthost18. really this time
2014-05-05 20:00:12 +00:00
Miroslav Suchý
e41a87ada3
deploy /etc/hosts with internal IPs from Fedora Cloud
2014-05-05 13:19:13 +00:00
Patrick Uiterwijk
3349c7b8ac
Revert "We now remove everyone from the whitelist for now."
...
This reverts commit 8b2961af2b .
2014-05-03 03:12:26 +00:00
Ralph Bean
602405b522
Update copr hotfix.
2014-05-03 01:44:20 +00:00
Ralph Bean
4e953c7f7d
Wrong directory, there...
2014-05-03 01:23:02 +00:00
Ralph Bean
30aadc78c4
Hotfix copr-fe for Covert Redirect.
2014-05-03 01:21:02 +00:00
Patrick Uiterwijk
8b2961af2b
We now remove everyone from the whitelist for now.
...
They will be re-enabled as we check the for vulnerability level to the covert redirect bug.
2014-05-02 22:41:49 +00:00
Pierre-Yves Chibon
d9b9af1ed5
disable accelerate in the nuancier playbook
2014-05-02 14:52:22 +00:00
Pierre-Yves Chibon
72f6fc5936
Enable email notifications on nuancier
2014-05-02 16:47:08 +02:00
Stephen Smoogen
8903ac17c2
what if we just all got along
2014-05-01 23:48:35 +00:00
Ralph Bean
5ea889e578
Playbook to free up port 5099 when it gets stuck.
2014-05-01 20:24:44 +00:00
Kevin Fenzi
22b56a5341
Make wiki instances 4gb mem in production.
2014-05-01 14:55:01 +00:00
Stephen Smoogen
0f551202dc
turn off accelerate for initial run.
2014-04-30 23:25:16 +00:00
Stephen Smoogen
fa255c12a0
add a bunch of bvirthosts
2014-04-30 23:02:01 +00:00
Ralph Bean
a0f2968311
Also, monitor here.
2014-04-30 20:42:56 +00:00
Ralph Bean
4a229675ef
Use fqdn, I guess..
2014-04-30 19:32:35 +00:00
Ralph Bean
44fa065f03
Whoopsy-daisy.
2014-04-30 19:29:23 +00:00
Ralph Bean
21f6600811
Ridiculous, but collectd exec plugins cannot accept arguments.
...
So we have to template our script and "hardcode" the process we want to
monitor there.
2014-04-30 19:25:20 +00:00
Ralph Bean
b5f6044085
Stub of a collectd role for fedmsg process health.
2014-04-30 16:04:47 +00:00
Ricky Elrod
26b3dffd89
Add 3 missing packages to global_pkgs_inst, from global.pp in puppet
2014-04-29 23:39:20 +00:00
Ralph Bean
c6719dda6b
A playbook for undoing yum history of certain packages.
2014-04-29 17:10:14 +00:00
Kevin Fenzi
641330e0ab
Move mirrorlist-ibiblio over to ibiblio04
2014-04-28 20:47:22 +00:00
Kevin Fenzi
de4c869426
Move unbound-ib01 over to ibibli04
2014-04-28 19:29:57 +00:00
Ralph Bean
3f3e3d0529
Flip the switch.
2014-04-28 18:53:42 +00:00
Ralph Bean
88caeca291
Use fromaddress consistently.
2014-04-28 18:14:01 +00:00
Ralph Bean
b91249e215
Get the mail server name right..
2014-04-28 18:01:42 +00:00
Ralph Bean
640c82d25e
Little errors..
2014-04-28 17:46:30 +00:00
Ralph Bean
6b422251b4
Ansible syntax...
2014-04-28 17:39:50 +00:00
Ralph Bean
9201c4ab58
Ensure we can write to our own log file.
2014-04-28 17:37:22 +00:00
Ralph Bean
93a8277bb3
We don't actually need all that junk.
2014-04-28 17:34:44 +00:00
Ralph Bean
1e72a96097
Try deploying this koji reminder email thing.
2014-04-28 17:26:38 +00:00
Ralph Bean
3b3614795c
Use semicolon instead of colon here.
2014-04-28 17:13:04 +00:00
Ralph Bean
e85878d802
Use process name instead of pid for fedmsg monitoring socket filename.
2014-04-28 13:46:20 +00:00
Dennis Gilmore
c71162ec08
make sure the chroot for comoose includes the f21 buildroot
2014-04-28 05:53:20 +00:00
Kevin Fenzi
f92e040821
Correct path
2014-04-24 21:53:13 +00:00
Kevin Fenzi
aab9defc22
Use correct key here too
2014-04-24 21:48:05 +00:00
Kevin Fenzi
93bbd6331c
Fix up ssl keys
2014-04-24 21:39:01 +00:00
Kevin Fenzi
1ec4774eb3
Fix stray with_items
2014-04-24 21:33:36 +00:00
Kevin Fenzi
52c9e9a08d
Move keyserver to a role. Thanks misc!
2014-04-24 20:37:51 +00:00
Kevin Fenzi
0982cd46a9
Make nfs mount a variable and set it to use rw on wiki instances.
2014-04-24 19:21:59 +00:00
Ralph Bean
9216d087ea
Add configuration for hub health monitoring.
2014-04-24 18:14:39 +00:00
Kevin Fenzi
f7fe96ff1e
Also make iscsi client datacenter dependent
2014-04-24 03:15:54 +00:00
Kevin Fenzi
ed6908d6ee
Add openvpn for non phx2 virthosts
2014-04-24 03:01:47 +00:00
Kevin Fenzi
560fd68cea
Add ibiblio04
2014-04-24 01:58:21 +00:00
Kevin Fenzi
3909469705
Add collectd to paste
2014-04-23 20:35:38 +00:00
Kevin Fenzi
8dfb920b82
Add collectd to wiki and sundries.
2014-04-23 20:28:44 +00:00
Ralph Bean
dc715da4dd
Gotta have the handlers here too.. also.
2014-04-23 15:14:44 +00:00
Ralph Bean
ad2a2f71c4
Gotta have the handlers here too..
2014-04-23 14:48:34 +00:00
Ralph Bean
2a3edca20c
And, yes, an seboolean too.
2014-04-23 13:36:15 +00:00
Ralph Bean
41d35aba00
Add some restart statements so things take effect how we want.
2014-04-23 13:32:16 +00:00
Ralph Bean
78a35fe77b
Point wiki at new nfs mount dir.
...
Under the rule of puppet, the app servers mounted this nfs share at
/srv/web/attachments but the new ansible nfs_client role has us mounting it at
/mnt/web/attachments. Here, I'm just adjusting the wiki config to look for
uploaded content at that new location. This assumes we want to stick with /mnt/
over /srv/.
2014-04-23 13:27:23 +00:00
Ralph Bean
e551044685
Complain if we can't read the mirrormanager/mirroradmins list.
2014-04-22 23:14:13 +00:00
Kevin Fenzi
787621021c
Fix dell vmhosts to not use multipath for local disk.
2014-04-22 21:38:48 +00:00
Kevin Fenzi
d90a53d4db
Update keyserver ssl certs.
2014-04-22 20:34:23 +00:00
Kevin Fenzi
90ddd2da30
Add vpn to sundries servers
2014-04-22 18:59:32 +00:00
Kevin Fenzi
6f27363b3f
We need python-paste-deploy apparently.
2014-04-22 18:41:11 +00:00
Kevin Fenzi
a7891e476c
Add geoip-city-wsgi to sundries servers. Thanks janeznemanic. Ticket 4291
2014-04-22 17:22:44 +00:00
Ralph Bean
325f5e8205
Adjust fedmsg authz policy for new wiki hosts.
2014-04-22 16:18:48 +00:00
Ralph Bean
dd64cc79b6
Change cert declaration for the wiki over to the new host(s).
2014-04-22 16:11:19 +00:00
Kevin Fenzi
11c9418ffe
Add fedmsg stuff to wiki instances
2014-04-22 15:46:11 +00:00
Kevin Fenzi
7d9eb0c836
Add vpn to wiki01/02
2014-04-22 15:21:42 +00:00
Kevin Fenzi
b82b1b17b5
Update nfs ip's on wiki instances
2014-04-22 15:01:24 +00:00
Kevin Fenzi
2675b647ee
Try this to fix selinux.
2014-04-21 20:53:20 +00:00
Kevin Fenzi
c95974dad4
Try these bools
2014-04-21 20:42:07 +00:00
Kevin Fenzi
de075a961b
Fix memcached for stg
2014-04-21 20:28:52 +00:00
Kevin Fenzi
0705cf0c67
Name the hosts file right.
2014-04-21 20:12:07 +00:00
Kevin Fenzi
5c3ffb40d0
We want the stg db in stg
2014-04-21 20:09:08 +00:00
Kevin Fenzi
6f792af873
Wants to be named -wiki there for the directory
2014-04-21 20:01:17 +00:00
Kevin Fenzi
c2f17158cd
Fix typo
2014-04-21 19:56:29 +00:00
Kevin Fenzi
2b7871a813
It's both.
2014-04-21 19:52:08 +00:00
Kevin Fenzi
23d940f2d5
it's wikipath
2014-04-21 19:47:42 +00:00
Kevin Fenzi
ca2609625a
Add wpath of w
2014-04-21 19:45:30 +00:00
Kevin Fenzi
12d40c6a7c
This may not be needed.
2014-04-21 19:37:11 +00:00
Kevin Fenzi
6b4d986696
Fix template
2014-04-21 19:31:29 +00:00
Kevin Fenzi
1d314d184f
Don't need this part
2014-04-21 19:28:57 +00:00
Kevin Fenzi
cdb9d3d187
And also rpcbind
2014-04-21 19:17:51 +00:00
Kevin Fenzi
35b98f114f
And we need nfslock
2014-04-21 19:14:44 +00:00
Kevin Fenzi
f61c9d4d31
Need nfs-utils
2014-04-21 19:11:10 +00:00
Kevin Fenzi
5126c3a7b2
This is staging. Sheesh
2014-04-21 19:07:04 +00:00
Kevin Fenzi
2454e84d09
Stab at using nfs_client role for nfs mounts
2014-04-21 19:00:03 +00:00
Kevin Fenzi
c2b06a44fc
mediawiki role for wiki servers. Thanks adimania. ticket 4257
2014-04-21 18:10:28 +00:00
Kevin Fenzi
fdc6e69e04
Add simple copy for datanommer db dump to public space on lockbox01
2014-04-17 20:29:06 +00:00
Kevin Fenzi
7ce3dfbe2a
Set mirrorlists to only process requests on vpn or local network interface
2014-04-16 00:38:07 +00:00
Kevin Fenzi
805acea1a2
Another tweak
2014-04-15 23:27:36 +00:00
Kevin Fenzi
aacca4aeff
Update inventory some.
2014-04-15 23:26:44 +00:00
Pierre-Yves Chibon
ef0eb23fc1
1.50 might requires quotes otherwise it's converted to 1.5
2014-04-15 17:01:35 +02:00
Pierre-Yves Chibon
c44160604e
Update jenkins plugins
2014-04-15 16:45:25 +02:00
Kevin Fenzi
ff604a1414
Disable some little used languages in production askbot
2014-04-13 21:23:55 +00:00
Kevin Fenzi
18f7c28f9c
Nuke some old postfix config for machines that no longer exist.
2014-04-13 20:54:36 +00:00
Pierre-Yves Chibon
4295ba9dc5
[pkgdb2] Remove the http to https apache rewrite rule, we don't use it
2014-04-11 16:52:52 +02:00
Miroslav Suchý
85539d014b
with recent ansible this is in column 33
...
I should parse it more inteligent :(
2014-04-11 12:31:39 +00:00
Miroslav Suchý
4f92195d8a
add SEND_MAIL variable so copr can send emails
2014-04-10 10:08:18 +00:00
Miroslav Suchý
6ac3dcc402
move common scripts lower in manifest
2014-04-10 06:59:40 +00:00
Kevin Fenzi
cd90b45b19
I should really get soom sleep sometime.
2014-04-09 20:10:26 +00:00
Kevin Fenzi
d36ceaefe0
Fix broken template
2014-04-09 20:05:23 +00:00
Kevin Fenzi
55c3d58b50
Make arm03-qa03 to packager00
2014-04-09 16:37:06 +00:00
Pierre-Yves Chibon
7da5071850
Use port 80 in elections
2014-04-09 18:42:22 +02:00
Kevin Fenzi
2081b7b47d
Add apprentice to mirrorlists.
2014-04-09 02:17:28 +00:00
Pierre-Yves Chibon
7785aeefcc
Try to fix login for elections in stg
2014-04-08 21:02:19 +02:00
Pierre-Yves Chibon
afd4a8c207
Try to fix login on pkgdb2 in stg
2014-04-08 20:56:08 +02:00
Kevin Fenzi
8835676e6d
Port 80 needs open here, not 443.
2014-04-08 16:08:16 +00:00
Pierre-Yves Chibon
3f2a46e642
Fix link the wsgi in the apache config
2014-04-08 17:24:31 +02:00
Pierre-Yves Chibon
65e504604d
Put the wsgi file at the right place
2014-04-08 17:16:35 +02:00
Pierre-Yves Chibon
83bfab900c
Fix indentation
2014-04-08 16:25:54 +02:00
Pierre-Yves Chibon
f3ea75e128
Update the elections playbook to include the new elections role
2014-04-08 16:23:30 +02:00
Pierre-Yves Chibon
7843f7378e
Add roles and hosts files for elections0{1,2,1.stg}
2014-04-08 16:23:06 +02:00
Kevin Fenzi
7853a77399
Fix typo
2014-04-07 21:19:37 +00:00
Kevin Fenzi
54ad91db96
Rename taskotron-dev01 to taskotron-stg01 and reinstall with f20
2014-04-07 21:17:36 +00:00
Kevin Fenzi
6362df7043
This is fedmsg/base
2014-04-07 19:52:21 +00:00
Kevin Fenzi
ec2c79b4fd
Add new wiki instances.
2014-04-07 19:50:57 +00:00
Kevin Fenzi
42e03a1ab7
Don't install oz on ppc builders.
2014-04-07 18:20:37 +00:00
Kevin Fenzi
f3dc0330de
Turns out, we do need cronie now with oz/imagefactory, etc
2014-04-07 16:52:16 +00:00
Andrea Veri
cb03e55b02
GNOME Backups: make sure pentagon.gimp.org has its own entry on ssh's config file
2014-04-07 13:50:11 +00:00
Ralph Bean
5b9a2bff2f
sqlalchemy prefers "postgresql" to "postgres".
2014-04-06 16:54:39 +00:00
Dennis Gilmore
ef70c3164c
add setup and packages needed for oz/imagefactory to work
2014-04-05 15:55:30 +00:00
Kevin Fenzi
ba3d99eb3a
Add prod instances too
2014-04-04 17:25:36 +00:00
Kevin Fenzi
e5c3bda671
Add sundries staging server.
2014-04-04 17:02:16 +00:00
Tim Flink
cceec52e2f
adding port 80 to lockbox-comm01.qa for ks hosting
2014-04-03 22:02:34 +00:00
Tim Flink
8d26c2ffe5
adding udp port 69 for tftp and tcp port 8000 for beaker on beaker lab controller group
2014-04-03 22:00:05 +00:00
Ralph Bean
8ccc0622dc
New playbook to restart fedmsg services.
2014-04-02 01:35:16 +00:00
Ralph Bean
d837c5e263
Add a new group for hosts that have a fedmsg-hub running.
2014-04-02 01:33:59 +00:00
Dennis Gilmore
6d367db7a9
arm is primary arch now
2014-04-01 23:31:16 +00:00
Ralph Bean
7a0c7cd998
Add the i386 repo to sign_and_import.
2014-04-01 15:14:06 +00:00
Miroslav Suchý
51d3376a86
put chain CA cert in copr-be as well
2014-04-01 13:45:58 +00:00
Miroslav Suchý
aa38d2bfc0
only redefine restart httpd
2014-04-01 13:24:52 +00:00
Miroslav Suchý
dbe4180044
Revert "do not use common restart file"
...
This reverts commit d06a71182c .
2014-04-01 13:24:10 +00:00
Miroslav Suchý
d06a71182c
do not use common restart file
...
otherwise we will get /usr/local/bin/conditional-restart.sh - No such file or directory
2014-04-01 13:18:46 +00:00
Miroslav Suchý
57963bdef1
put ssl chain in apache config
2014-04-01 13:13:10 +00:00
Miroslav Suchý
f21ccbac8b
deploy ssl cert on copr-fe
2014-04-01 12:35:27 +00:00
Miroslav Suchý
eb0b8c4c2f
those are strings
...
this is really python code, not ini file
2014-04-01 09:17:07 +00:00
Kevin Fenzi
a4db8800de
Fix unbound name in the playbook.
2014-03-31 22:47:37 +00:00
Kevin Fenzi
384ff623b9
This shouldn't be starts with, but find
2014-03-31 19:32:04 +00:00
Kevin Fenzi
72e6cb43ef
Add some exists whitelists for things we check but don't install on all machines.
2014-03-31 18:14:04 +00:00
Miroslav Suchý
2846ce5933
restart httpd after ssl cert are deployed
2014-03-31 12:42:50 +00:00
Miroslav Suchý
c3e084e6d6
install lokkit command
2014-03-31 12:29:02 +00:00
Miroslav Suchý
605a98ea04
install ssl cert to copr-fe-dev
2014-03-31 12:17:03 +00:00
Miroslav Suchý
b588b902db
install latest version of packages
2014-03-31 12:17:02 +00:00
Miroslav Suchý
c4e510395e
sync up copr-dev with copr
2014-03-31 12:17:02 +00:00
Kevin Fenzi
e90b54c764
Bump up nrpe limits on mirrorlists.
2014-03-29 18:38:03 +00:00
Kevin Fenzi
4542efa777
Add missing supervisord handler
2014-03-28 18:36:24 +00:00
Kevin Fenzi
fdbd65bce3
Sadly disable accelerate here since sb network is weird.
2014-03-28 18:26:34 +00:00
Kevin Fenzi
c6ef1dcc1f
ok. This might work for sb installs.
2014-03-28 17:57:07 +00:00
Kevin Fenzi
f784401d10
Try this in case this is a dns issue
2014-03-28 17:26:18 +00:00
Kevin Fenzi
eee6c15e08
Add a mirrorlist-serverbeach.
2014-03-28 17:19:08 +00:00
Kevin Fenzi
3344263078
Perhaps this needs quotes
2014-03-28 15:07:34 +00:00
Kevin Fenzi
b26adb82f8
Try this.
2014-03-28 14:41:00 +00:00
Pierre-Yves Chibon
51fb9f824c
Dia is not available on EL7
2014-03-28 13:33:28 +01:00
Pierre-Yves Chibon
ebd3b09fea
Add dia to the jenkins builder
2014-03-28 13:29:21 +01:00
Ralph Bean
7f8fb37e7f
New fmn.rules wants this config value.
2014-03-27 20:52:07 +00:00
Miroslav Suchý
8504ad36d5
check forgotten VM more often
2014-03-27 08:36:06 +00:00
Andrea Veri
99937ccc9a
Add pentagon.gimp.org to the backups rotation
2014-03-26 16:30:59 +00:00
Ralph Bean
e3812c7ddb
Correct a typo.
2014-03-24 19:30:09 +00:00
Ralph Bean
5e5bf675a6
Add new ftpsync certs.
2014-03-24 17:54:46 +00:00
Ralph Bean
8ed419da16
Make sure these are all owned by apache.
2014-03-24 17:51:07 +00:00
Nick Bebout
7410320e1b
Update sks membership file
2014-03-23 13:24:17 +00:00
Nick Bebout
bf69b2db36
Update sks membership file
2014-03-23 13:04:44 +00:00
Nick Bebout
ae82fa466f
Remove old sks servers from membership file for sks
2014-03-22 16:36:44 +00:00
Aurélien Bompard
502c8f60d3
HyperKitty: fix relative login URLs
2014-03-22 14:43:47 +00:00
Aurélien Bompard
188978aad6
Mailman: fix pg_hba perms and improve import script
2014-03-22 14:43:47 +00:00
Stephen Smoogen
750c09b4c9
OK Lets put it all back like it was. Do we go back to old error?
2014-03-21 22:30:07 +00:00
Stephen Smoogen
bd1fb61391
Well I can only break it worse.
2014-03-21 22:16:19 +00:00
Stephen Smoogen
5a056c05f0
Hey lets see if this fixes the stuff I broke.
2014-03-21 22:08:33 +00:00
Stephen Smoogen
e68eaf268e
Hey lets see if this breaks stuff.
2014-03-21 21:59:56 +00:00
Aurélien Bompard
775df5a634
Mailman: also allow Arquillian
2014-03-21 21:29:15 +00:00
Aurélien Bompard
a1588faa10
Mailman: allow Apache to access the full-text index
2014-03-21 21:29:15 +00:00
Ralph Bean
6f64dc8195
Restart services here.
2014-03-21 18:30:56 +00:00
Ralph Bean
9c1a973c21
Use that new role.
2014-03-21 16:08:06 +00:00
Ralph Bean
cd4f128bc9
Whoops.. not a template.
2014-03-21 15:46:44 +00:00
Ralph Bean
47cea5b469
Add a role for collectd/fcomm-queue
2014-03-21 15:32:28 +00:00
Ralph Bean
655d015200
Add some hosts to collectd which were not there before.
2014-03-21 13:46:16 +00:00
Ralph Bean
573454af79
Renamespace the collectd role to collectd/base
2014-03-21 13:46:06 +00:00
Stephen Smoogen
670dc663a2
make a playbook just to run rkhunter for boxes which didnt before
2014-03-20 20:10:40 +00:00
Miroslav Suchý
017df9ea44
[frontend] let apache log in default location
2014-03-20 13:47:03 +00:00
Miroslav Suchý
8ab71b2fbf
check daily for left over VM of builders an remove them
2014-03-19 13:17:40 +00:00
Kevin Fenzi
eb01713605
Tweak syntax
2014-03-18 18:44:05 +00:00
Kevin Fenzi
ea462e26dd
taskbot is taskotron
2014-03-18 01:20:46 +00:00
Tim Flink
c3707ce75c
fixing httpd group for kickstart serving dir and moving httpd package installation to a more appropriate place
2014-03-17 21:58:04 +00:00
Kevin Fenzi
b4a4b3f70a
Add hosts there.
2014-03-17 21:49:52 +00:00
Tim Flink
e9290ad137
fixing syntax error in with_items variable
2014-03-17 21:45:41 +00:00
Tim Flink
116b6456cc
adding local git repository creation, ansible working directory and ks hosting directory to lockbox group playbook, required variables for lockbox-comm01.qa
2014-03-17 21:22:39 +00:00
Tim Flink
76c9a0d6d4
adding ansible config to ansible-server role
2014-03-17 21:21:04 +00:00
Kevin Fenzi
5c0005b7c4
Add rsyncd to a bunch of app servers so we can archive their logs.
2014-03-17 16:31:27 +00:00
Kevin Fenzi
38f0c628ba
Kinda need xinetd as well.
2014-03-17 16:11:23 +00:00
Kevin Fenzi
36cc6f7cb1
Tweak service
2014-03-17 16:09:11 +00:00
Kevin Fenzi
eef86d5b91
These should be named default.
2014-03-17 16:06:51 +00:00
Kevin Fenzi
32119b6bc1
Add iptables rules for rsync for logs.
2014-03-17 16:02:47 +00:00
Kevin Fenzi
7316ef1ca3
Add a rsyncd role. For now just to sync logs to log02, but can be extended to download later.
2014-03-17 15:55:26 +00:00
Miroslav Suchý
6e0c36316b
more s removing
2014-03-17 14:50:29 +00:00
Miroslav Suchý
1f87116909
make > works
...
addressing:
NOTIFIED: [concate ssl certs] *************************************************
failed: [209.132.184.142] => {"changed": true, "cmd": ["cat", "/etc/lighttpd/coprs-be.fedoraproject.org.key", "/etc/lighttpd/coprs-be.fedoraproject.org.crt", ">", "/etc/lighttpd/coprs-be.fedoraproject.org.pem"], "delta": "0:00:00.004867", "end": "2014-03-17 14:03:52.702756", "rc": 1, "start": "2014-03-17 14:03:52.697889"}
stderr: cat: >: No such file or directory
2014-03-17 14:15:39 +00:00
Miroslav Suchý
ae3d4ec14a
more s removing
2014-03-17 14:11:43 +00:00
Miroslav Suchý
b29072d04b
no s and the path should work
...
addressing:
TASK: [copy httpd ssl certificates] *******************************************
failed: [209.132.184.142] => (item=coprs-be.fedoraproject.org.key) => {"failed": true, "item": "coprs-be.fedoraproject.org.key"}
msg: could not find src=/var/lib/puppet/git/configs/secure/httpd/coprs-be.fedoraproject.org.key
failed: [209.132.184.142] => (item=coprs-be.fedoraproject.org.crt) => {"failed": true, "item": "coprs-be.fedoraproject.org.crt"}
msg: could not find src=/var/lib/puppet/git/configs/secure/httpd/coprs-be.fedoraproject.org.crt
2014-03-17 14:01:12 +00:00
Miroslav Suchý
c10cf5c31a
revert b4288cd9d3 as ssl should be now ok
2014-03-17 13:53:00 +00:00
Miroslav Suchý
53afc0ba6c
include common scripts
...
required for fedmsg
2014-03-17 13:38:20 +00:00
Kevin Fenzi
d6661af88c
No pyflakes on el7 either yet
2014-03-15 18:35:32 +00:00
Kevin Fenzi
edb5a411b3
Fix fedora conditional.
2014-03-15 18:13:42 +00:00
Kevin Fenzi
7600552d5a
Move packages not available on el7 out to their own play
2014-03-15 18:07:02 +00:00
Pierre-Yves Chibon
363a1f6c16
Add the EL7-beta builder to jenkins
2014-03-15 18:58:45 +01:00
Kevin Fenzi
bff8babaeb
Just switch to with_first_found.
2014-03-15 17:48:46 +00:00
Kevin Fenzi
3c02ad10f5
Strange
2014-03-15 17:42:13 +00:00
Kevin Fenzi
67e8e879f9
Another attempt
2014-03-15 17:41:17 +00:00
Kevin Fenzi
4d8b4349f8
Hum.
2014-03-15 17:39:25 +00:00
Kevin Fenzi
e9c7518fc4
Oh yeah, no :s in debugs
2014-03-15 17:35:40 +00:00
Kevin Fenzi
7271053a57
Debug a bit
2014-03-15 17:34:48 +00:00
Kevin Fenzi
657ef06046
What happens if we do this?
2014-03-15 17:31:04 +00:00
Kevin Fenzi
8949120a8d
Typo
2014-03-15 16:48:51 +00:00
Kevin Fenzi
15eae91b61
Add el7b jenkins builder, clean up image names, etc
2014-03-15 16:43:35 +00:00
Kevin Fenzi
aa550d22e1
Second volume on jenkins instance
2014-03-15 16:26:36 +00:00
Ralph Bean
4aa5b04eb3
Path fixes.
2014-03-14 20:08:26 +00:00
Ralph Bean
ab1e54e54c
Add some nagios client configuration for the new packages03,4 nodes.
2014-03-14 19:44:56 +00:00
Ralph Bean
08f98b1159
Also, remove these from inventory.
2014-03-14 19:18:06 +00:00
Ralph Bean
31c4afd59c
Remove references to the old fedora-packages nodes.
2014-03-14 19:15:10 +00:00
Ralph Bean
5c65c352da
Copy over an icon too.
2014-03-14 18:59:59 +00:00
Ralph Bean
5033c42e7d
Turns out there's an selinux boolean for that.
2014-03-14 18:35:17 +00:00
Ralph Bean
95bba586ed
Throw in policycoreutils-python for old hosts that don't have semanage from the kickstart yet.
2014-03-14 15:59:20 +00:00
Ralph Bean
9102d7a199
Renamespace the notifs roles.
2014-03-14 15:53:53 +00:00
Ralph Bean
b7ecaf2b6f
Renamespace the badges role.
2014-03-14 15:52:42 +00:00
Ralph Bean
b3c2147230
Also, fedmsg-hub.
2014-03-14 15:49:18 +00:00
Ralph Bean
edbc9b21cf
Renamespace the fedmsg module.
2014-03-14 15:47:11 +00:00
Ralph Bean
cd9ecb0e8b
Add a newline to test conditional restart.
2014-03-14 15:36:14 +00:00
Ralph Bean
fb6ee8bd49
Try out this conditional restart stuff.
2014-03-14 15:30:32 +00:00
Ralph Bean
38126d44e5
Add a script to query selinux status of our inventory.
2014-03-14 14:35:33 +00:00
Ralph Bean
ea26aa434a
Sigh.. point fedora-packages staging at pkgdb prod.
2014-03-14 14:21:59 +00:00
Ralph Bean
c327063a62
selinux fiddling.
2014-03-13 19:14:30 +00:00
Ralph Bean
2847eda4dd
There is something wonky in the ansible directory logic here.
2014-03-13 19:08:36 +00:00
Ralph Bean
1f61dad229
Selinux stuff for fedora-packages.
2014-03-13 19:04:24 +00:00
Ralph Bean
9b5743fa91
This actually takes a hojillion years.
2014-03-13 18:48:57 +00:00
Ralph Bean
d7f9e610c8
A playbook for rebuilding the fedora-packages xapian search index.
2014-03-13 16:48:59 +00:00
Ralph Bean
8057e2231e
Have staging fedora-packages actually slurp its build list from prod.
2014-03-13 16:27:51 +00:00
Ralph Bean
63c04540e8
Only try to mount the gluster dir if it doesn't already exist. Weird.
2014-03-13 15:59:22 +00:00
Ralph Bean
340455d65d
Add hosts files for the new fedora-packages nodes.
2014-03-13 15:37:16 +00:00
Pierre-Yves Chibon
7f0589cf2c
Move fedocal.wsgi to /var/www
...
This so that it does not conflict with the .wsgi file installed by
the RPM, so when we update the fedocal package we don't have to
re-run the complete playbook, restarting apache is enough
2014-03-13 16:01:52 +01:00
Pierre-Yves Chibon
e330f794ca
Adjust task description to what the task does
2014-03-13 15:58:07 +01:00
Ralph Bean
0391c56cfd
Beef up the new packages nodes to match the existing ones.
2014-03-13 13:32:04 +00:00
Ralph Bean
a86f60f6f1
Juggle some stuff in the packages role.
2014-03-13 13:32:04 +00:00
Kevin Fenzi
6ca7454715
More inventory tweaking
2014-03-13 00:54:14 +00:00
Kevin Fenzi
62f334cefc
Update inventory
2014-03-13 00:23:46 +00:00
Ralph Bean
4d785e5f38
Syntax error..
2014-03-12 21:04:33 +00:00
Ralph Bean
ea29d4887e
Really, this should happen last.
2014-03-12 21:03:38 +00:00
Ralph Bean
aacd92b220
Split up gluster so that restart can happen inbetween.
2014-03-12 21:03:02 +00:00
Ralph Bean
51d941bab3
These should not be readable.
2014-03-12 20:55:25 +00:00
Ralph Bean
4cafa55c97
Open a port for glusterd.
2014-03-12 20:53:16 +00:00
Ralph Bean
2d8c481b0c
Also, this.
2014-03-12 20:30:58 +00:00
Ralph Bean
3454717036
Setup gluster for fedora-packages new prod nodes, maybe?
2014-03-12 20:27:13 +00:00
Stephen Smoogen
49cb6d0bf8
a job to remove postfix not-so-zombie undead processes
2014-03-12 20:22:56 +00:00
Ralph Bean
f8fb27b666
Add the indexer configuration for new fedora-packages nodes.
2014-03-12 19:00:39 +00:00
Ralph Bean
f0e82d53af
fedora-packages role
2014-03-12 18:44:30 +00:00
Kevin Fenzi
c00ab836f6
Drop local yum ansible module to test something.
2014-03-12 17:20:41 +00:00
Luke Macken
5bf9f736c1
Tag the bodhi matchpathcon command with 'config' to be consistent
2014-03-11 18:48:12 +00:00
Luke Macken
d9f82bdd7f
Set the SELinux context of /var/tmp/bodhi-bz.cookie to httpd_tmp_t
2014-03-11 18:41:58 +00:00
Ralph Bean
1ca82167e0
Correct a typo in the packages03.stg host_vars file.
2014-03-11 18:36:29 +00:00
Ralph Bean
f9b650e43d
Declare fedmsg certs for the new packages nodes.
2014-03-11 16:31:59 +00:00
Pierre-Yves Chibon
18ed279955
Comment out the packages01 and 02 for the moment
2014-03-11 17:22:45 +01:00
Ralph Bean
b59f049b32
playbook skeleton for the fedora-packages group.
2014-03-11 16:20:29 +00:00
Pierre-Yves Chibon
7b846b3b26
Add packages03 and 04 to the packages group and packages03.stg to packages-stg group
2014-03-11 17:19:44 +01:00
Pierre-Yves Chibon
100fef7a1f
Update the packages group_vars to be more classic
2014-03-11 17:16:46 +01:00
Ralph Bean
c9fed9ac88
host_vars for the new fedora-packages nodes.
2014-03-11 16:16:07 +00:00
Pierre-Yves Chibon
2f214fbdda
Add the packages-stg group_vars
2014-03-11 17:14:30 +01:00
Pierre-Yves Chibon
c91d623cb1
Fix the static folder
2014-03-10 20:46:13 +01:00
Pierre-Yves Chibon
0d22fb78f5
Fix the variable names in the alembic.ini of pkgdb2
2014-03-10 20:13:47 +01:00
Pierre-Yves Chibon
91e5fa6362
There are two files to fix...
2014-03-10 20:10:36 +01:00
Pierre-Yves Chibon
0eb6156492
Use the Third party user to connect to FAS and use fas.stg in stg
2014-03-10 20:06:30 +01:00
Pierre-Yves Chibon
cbd71c0156
Add pkgdb01.stg in the staging group
2014-03-10 19:16:20 +01:00
Pierre-Yves Chibon
df2763a613
The role is pkgdb2 not pkgdb
2014-03-10 19:14:50 +01:00
Pierre-Yves Chibon
fc2e48c4c9
Add first work on the pkgdb2 playbook and role
2014-03-10 19:12:22 +01:00
Pierre-Yves Chibon
e851ba528e
Add hosts files for the pkgdb2 hosts
2014-03-10 18:51:35 +01:00
Ralph Bean
aaf6e48462
It just needs to exist with those perms.
2014-03-10 17:29:28 +00:00
Ralph Bean
194a7f8061
file expects dest, not path.. maybe?
2014-03-10 17:23:10 +00:00
Kevin Fenzi
6239babc5f
Revert "Add smtp check for smtp-mm machines."
...
This reverts commit 79a60f2ffb .
2014-03-10 17:17:34 +00:00
Kevin Fenzi
3fab742355
Revert "Add config for check_smtp nrpe check"
...
This reverts commit ead7e91667 .
2014-03-10 17:17:29 +00:00
Kevin Fenzi
ead7e91667
Add config for check_smtp nrpe check
2014-03-10 16:58:31 +00:00
Kevin Fenzi
79a60f2ffb
Add smtp check for smtp-mm machines.
2014-03-10 16:40:02 +00:00
Pierre-Yves Chibon
96c7c81e9d
Add group_vars and host_vars for pkgdb hosts
2014-03-10 17:07:47 +01:00
Ralph Bean
fdd13438e8
Two new fas badges.
2014-03-10 15:53:50 +00:00
Pierre-Yves Chibon
732ce7bd59
Add the pkgdb hosts
2014-03-10 15:45:00 +00:00
Pierre-Yves Chibon
99bf4903eb
The pkgdb group should contain pkgdb hosts, pkgs is in pkgs
2014-03-10 15:43:37 +00:00
Ralph Bean
9187e936a6
Fix incorrect volgroup for tagger prod nodes.
2014-03-10 15:24:37 +00:00
Ralph Bean
4f5a36a9c4
Fix a fedoauth typo for staging.
2014-03-10 15:16:19 +00:00
Ralph Bean
870ff71cda
Oh.. its a dict. This should do it.
2014-03-07 22:02:14 +00:00
Kevin Fenzi
9a540a7e5f
Set the right selinux context on the bodhi bz cookie file
2014-03-07 21:44:23 +00:00
Ralph Bean
d853ff6f60
fedmsg config changes for tagger on new nodes.
2014-03-07 21:38:41 +00:00
Ralph Bean
2cc6cb4bc4
Other tagger things.
2014-03-07 21:12:31 +00:00
Kevin Fenzi
374b3c0213
So long openid01/02. Thanks for your service.
2014-03-07 21:01:35 +00:00
Ralph Bean
c56bf536c6
/etc/hosts entry for tagger_db
2014-03-07 21:00:53 +00:00
Ralph Bean
7eead0cc5b
host_var for installing the tagger cronjob.
2014-03-07 21:00:35 +00:00
Ralph Bean
77206ad366
Include handlers for tagger.
2014-03-07 20:51:27 +00:00
Ralph Bean
f65142fdde
Trying out a tagger role.
2014-03-07 20:41:36 +00:00
Luke Macken
f8213302ba
Add /etc/hosts files for bodhi01 and bodhi02
2014-03-07 18:51:50 +00:00
Kevin Fenzi
08c90dc108
No need for hfs kmod on ppc
2014-03-07 17:42:40 +00:00
Ralph Bean
a9e1c949a1
Add bodhi01,2 to the fedmsg routing policy.
2014-03-07 15:51:26 +00:00
Ralph Bean
3c2c1d7e31
Move the fedmsg routing_policy into its own file just like we have in the puppet repo.
2014-03-07 15:47:09 +00:00
Ralph Bean
bd7ddf1184
Add bodhi02 to the fedmsg endpoints list.
2014-03-07 15:43:47 +00:00
Luke Macken
16a16f0128
Add bodhi02 to the fedmsg ssl.py
2014-03-05 21:43:41 +00:00
Kevin Fenzi
058b9b22ee
Drop 2 of the 3 duplicate fedocal01.stg
2014-03-05 16:53:18 +00:00
Ralph Bean
ff89cb7831
Start adding new nodes for tagger.
2014-03-05 16:28:49 +00:00
Kevin Fenzi
a02183f703
Space, the final frontier
2014-03-04 19:48:17 +00:00
Kevin Fenzi
6b625f7d8c
We should default to bastion as relayhost here.
2014-03-04 19:45:59 +00:00
Kevin Fenzi
e3f29de73e
Fix volume group
2014-03-04 18:52:41 +00:00
Kevin Fenzi
7344502d02
Also update the is_fedora use
2014-03-04 18:49:00 +00:00
Kevin Fenzi
f927b0d907
Update this to use 'is defined'
2014-03-04 18:47:58 +00:00
Kevin Fenzi
8426c1d603
Revert "Is this a bool?"
...
This reverts commit 5f7adb7541 .
2014-03-04 18:43:34 +00:00
Kevin Fenzi
5f7adb7541
Is this a bool?
2014-03-04 18:42:31 +00:00
Ralph Bean
5ef18adff1
Copy-pasta typo.
2014-03-04 18:36:55 +00:00
Kevin Fenzi
a6c0087034
Adjust this openvpn thing
2014-03-04 18:35:14 +00:00
Ralph Bean
d999ac12ff
Actually, every other day is fine.
2014-03-04 18:35:07 +00:00
Ralph Bean
3981351bac
Only run this cronjob once a day.
2014-03-04 18:34:10 +00:00
Ralph Bean
534e7e93f8
Add cache information for the badges backend.
2014-03-04 18:31:59 +00:00
Kevin Fenzi
c0e4d0705a
Fix volume group
2014-03-04 17:43:17 +00:00
Pierre-Yves Chibon
59e309053e
Restrict the fedocal cron job on fedocal02 and fedocal01.stg
2014-03-04 18:28:18 +01:00
Ralph Bean
7f0daf0108
Add the dg nodes to the staging list. they were forgotten.
2014-03-04 16:50:44 +00:00
Pierre-Yves Chibon
682fbe86e9
Specify the APP_URL in fedocal, and different for stg and prod
2014-03-04 13:14:05 +01:00
Pierre-Yves Chibon
68ccfbf89b
Change yum clean expired-cache to yum clean all
2014-03-04 11:09:40 +01:00
Kevin Fenzi
d8a302bec0
comma comma
2014-03-04 00:57:23 +00:00
Kevin Fenzi
7b881308fb
Fix up groups
2014-03-04 00:40:17 +00:00
Kevin Fenzi
148e644647
Use correct main.cf for smtp-mm
2014-03-04 00:32:51 +00:00
Kevin Fenzi
afc2c7cd09
No need to run iptables as a task, it's in base.
2014-03-04 00:22:38 +00:00
Kevin Fenzi
d76240de1d
Don't need to redo this as there's a handler for it.
2014-03-04 00:17:24 +00:00
Kevin Fenzi
cab63ff16b
Try cleaning this up some.
2014-03-04 00:08:48 +00:00
Kevin Fenzi
fcbc5ddd46
Collectd is now a role.
2014-03-03 20:10:49 +00:00
Kevin Fenzi
ba984fcb0b
Fix inventory
2014-03-03 20:00:33 +00:00
Kevin Fenzi
a93685dadb
This is on 02
2014-03-03 19:59:38 +00:00
Kevin Fenzi
ead7662594
Migrate smtp-mm machines over to ansible. Ticket 4219. Thanks janeznemanic!
2014-03-03 19:51:44 +00:00
Ralph Bean
98c6f2ed59
Move nuancier+fedmsg semanage port stuff over to the base fedmsg module.
2014-03-03 17:02:58 +00:00
Ralph Bean
dc9e28cd43
Update fedmsg selinux module to allow new logging stuff.
2014-03-03 16:49:34 +00:00
Kevin Fenzi
72f327b1dd
This config needs to be readable by apache to get db connect info.
2014-03-02 19:48:39 +00:00
Kevin Fenzi
e78f2428bd
Fix template
2014-03-02 19:37:53 +00:00
Kevin Fenzi
2996177350
Fix path
2014-03-02 19:08:18 +00:00
Kevin Fenzi
6a2ff13321
No need to include handlers here.
2014-03-02 19:01:18 +00:00
Kevin Fenzi
c76f5b8c66
Add paste to ansible. Ticket 4231. Thanks adimania
2014-03-02 18:58:37 +00:00
Patrick Uiterwijk
c3a5f73b6a
Fix bug in fedoauth by disabling remote_addr checking
2014-03-01 14:03:17 +00:00
Kevin Fenzi
cebefb9ad1
Fix this so it works when it's not defined.
2014-03-01 00:18:44 +00:00
Kevin Fenzi
cfdba2b43b
Work around local4 syslog issue with mirrorlists for now.
2014-02-28 23:21:00 +00:00
Kevin Fenzi
7d904a3693
Drop 2fa from arm-packager too
2014-02-28 22:58:27 +00:00
Kevin Fenzi
75a68ab596
Switch back to this setup
2014-02-28 21:12:03 +00:00
Kevin Fenzi
c6e71f899a
Grrrrr. - is not valid in a variable name
2014-02-28 21:00:21 +00:00
Kevin Fenzi
3cf121fd11
Should be single quotes.
2014-02-28 20:57:16 +00:00
Kevin Fenzi
3c4dc7fdbe
Variable headache
2014-02-28 20:49:10 +00:00
Kevin Fenzi
9af221956a
Try this tack
2014-02-28 20:43:43 +00:00
Kevin Fenzi
9b8cbe9780
A bit more cleanup, perhaps this will actually work.
2014-02-28 20:41:33 +00:00
Kevin Fenzi
5ca8240091
Move this up a tad
2014-02-28 20:32:43 +00:00
Kevin Fenzi
d63857dbc9
Setup things so arm03 socs get nopasswd sudo so we don't need 2fa there.
2014-02-28 20:23:05 +00:00
Kevin Fenzi
dab647e6ba
Put arm packager/qa in the cloud resolv.conf group.
2014-02-28 19:40:01 +00:00
Kevin Fenzi
1b19b5e7e3
Don't setup internal repos for arm03 anymore.
2014-02-28 19:36:41 +00:00
Kevin Fenzi
d4a4c0a8c6
Add qa group to arm-qa socs
2014-02-28 19:34:00 +00:00
Kevin Fenzi
f5ff614091
To the cloud!
2014-02-28 18:52:31 +00:00
Ralph Bean
15a4966388
Add new "Rock the Web" badge to the oldschoolery cronjob.
2014-02-28 14:00:04 +00:00
Ralph Bean
510973e1cd
Determine process at log-time, not startup-time.
...
This is because things like the fedmsg-hub are daemons, and will double-fork
into the background. If we determine the process at startup time, that original
process is long dead by the time we get to the first log statement.
2014-02-27 15:05:34 +00:00
Ralph Bean
0b54cd4623
Make that ContextInjector thing jsonifiable.
2014-02-27 15:01:09 +00:00
Ralph Bean
187b690d73
That new logging stuff requires python-psutil.
2014-02-27 14:48:49 +00:00
Ralph Bean
1b875b543f
Add lots of context to fedmsg error emails.
2014-02-27 14:40:40 +00:00
Miroslav Suchý
fc0631df17
replace ${ with {{
2014-02-27 11:42:18 +00:00
Miroslav Suchý
980ba44c59
replace $FILE with lookup() to get rid of obsolete warning
2014-02-27 11:41:31 +00:00
Miroslav Suchý
ddb56522fb
let the ssh allow to connect
2014-02-27 10:53:02 +00:00
Pierre-Yves Chibon
4d7c868992
Split even more the gluster volume creation for stg/prod
2014-02-26 09:16:22 +01:00
Pierre-Yves Chibon
64ecf0e3d6
Distinguish the stg and prod gluster volumes for nuancier
2014-02-26 09:10:22 +01:00
Pierre-Yves Chibon
417152c1e4
Fix the hosts line in the nuancier playbook
2014-02-26 09:02:10 +01:00
Pierre-Yves Chibon
93c19c2c15
Should specify the gluster servers
2014-02-26 08:46:32 +01:00
Pierre-Yves Chibon
f0c436ffae
Fix small typo
2014-02-26 08:42:51 +01:00
Pierre-Yves Chibon
e0e32549ff
Add the gluster volume to nuancier prod as well
2014-02-26 08:42:39 +01:00
Kevin Fenzi
e352bce2b5
Enabling openvpn in fedora is sadly more complex.
2014-02-25 18:58:06 +00:00
Kevin Fenzi
a62df97226
Only in prod tho
2014-02-25 17:20:19 +00:00
Kevin Fenzi
dcf9a500dc
Add openvpn to mailman instances
2014-02-25 17:19:48 +00:00
Kevin Fenzi
a17ece53c6
Fix transient cloud playbooks to use fedora user with sudo to get around stupid disable root default
2014-02-24 21:50:49 +00:00
Ralph Bean
798c1e0f5e
Use that fedmsg error mailer elsewhere.
2014-02-24 20:00:19 +00:00
Ralph Bean
ad28ec6b08
fedmsg error logs work.
2014-02-24 19:59:27 +00:00
Ralph Bean
efb59e9f60
Try out mailing fedmsg errors in staging.
2014-02-24 19:38:48 +00:00
Kevin Fenzi
40a3a9381b
Move fedmsg client role after bodhi roles, so the bodhi group exists.
2014-02-22 19:03:54 +00:00
Kevin Fenzi
81acc097a6
Fix ip address
2014-02-22 18:51:24 +00:00
Luke Macken
9601a54691
More tweaks to bodhi's logging configuration. No more local logs.
2014-02-21 18:59:57 +00:00
Ralph Bean
b109b8214c
Increase memory on the notifs backend to try and stop the locking.
2014-02-21 17:23:49 +00:00
Stephen Smoogen
2966e0e5c1
make log04 go. make us strong.
2014-02-21 01:24:46 +00:00
Luke Macken
ec5cdb299d
Ship bodhi logs to the SysLogHandler
2014-02-21 00:54:55 +00:00
Luke Macken
0cb68445f4
s/environment/env in the bodhi-prod.cfg.j2 template
2014-02-20 21:32:25 +00:00
Luke Macken
e73bce104f
Enable the httpd_can_network_connect SELinux boolean for bodhi.
2014-02-20 21:04:16 +00:00
Luke Macken
989f42018a
Set the fedmsg_cert group to bodhi instead of apache
2014-02-20 20:50:16 +00:00
Luke Macken
fc78e7cad5
Add bodhi01 to the fedmsg ssl.py
2014-02-20 20:44:48 +00:00
Luke Macken
75260593b2
Add bodhi01 to our fedmsg endpoints.py
2014-02-20 20:14:06 +00:00
Ralph Bean
6683f7768b
Let summershum talk to the pkgs.fp.o box internally.
2014-02-20 18:46:45 +00:00
Kevin Fenzi
b4288cd9d3
Disable copr-be certs copying until we can sort them out.
2014-02-20 18:39:05 +00:00
Kevin Fenzi
48ed2666c8
iptables is in base
2014-02-19 23:06:46 +00:00
Kevin Fenzi
5d29bc1345
Setup a staging host_group and use resolv.conf for it.
2014-02-19 23:00:43 +00:00
Kevin Fenzi
f3cc32e50e
Add staging group variables for bodhi too
2014-02-19 22:40:15 +00:00
Kevin Fenzi
c80775684e
We need to connect to db as well.
2014-02-19 22:19:22 +00:00
Kevin Fenzi
4eaaaccb57
Add bodhi01.stg to staging group
2014-02-19 22:05:18 +00:00
Kevin Fenzi
253a86f410
Try this.
2014-02-19 22:01:17 +00:00
Kevin Fenzi
fefc75b3d1
Use copy here instead of file.
2014-02-19 21:57:59 +00:00
Kevin Fenzi
b19c53d31c
This is a j2 template now.
2014-02-19 21:45:50 +00:00
Kevin Fenzi
2d93c017e0
It may be we don't need nfs role here.
2014-02-19 21:40:22 +00:00
Kevin Fenzi
09061fb7cb
oooooo
2014-02-19 21:18:57 +00:00
Kevin Fenzi
b5695062c3
The humble quote
2014-02-19 21:16:18 +00:00
Kevin Fenzi
769efe6ab8
First cut at bodhi app migration to ansible. Thanks janeznemanic. Ticket 4193
2014-02-19 21:07:16 +00:00
Ralph Bean
7dc3900f4c
Add pkgs to /etc/hosts for stg summershum.
2014-02-19 19:14:19 +00:00
Ralph Bean
87c60aa4cb
Add sqlalchemy0.8 in for summershum.
2014-02-19 18:03:58 +00:00
Ralph Bean
03394a1591
Move fedmsg to its own play here.
2014-02-19 17:46:10 +00:00
Ralph Bean
d903e76839
A stab at summershum deployment.
2014-02-19 17:25:58 +00:00
Andrea Veri
b7060c4f29
GNOME Backups: do not backup dialog yet, no relevant data is there at all now
2014-02-19 10:54:40 +00:00
Andrea Veri
466b5c4766
GNOME Backups: drop drawable from the backups set, add dialog
2014-02-19 08:58:01 +00:00
Kevin Fenzi
01f14e4619
Add unbound to collectd
2014-02-18 00:57:14 +00:00
Kevin Fenzi
02fbe41f0e
Clean up new collectd role
2014-02-18 00:49:22 +00:00
Kevin Fenzi
cd5b9dd331
Move collectd to a role instead of a task.
2014-02-18 00:46:12 +00:00
Kevin Fenzi
dc701de264
Add collectd to ask.
2014-02-18 00:36:03 +00:00
Kevin Fenzi
ae53fe801e
Up nrpe limits.
2014-02-18 00:10:12 +00:00
Kevin Fenzi
cae3b20c6e
Update inventory
2014-02-18 00:07:10 +00:00
Kevin Fenzi
92b5026916
Add virthost03 into the ansible mix too.
2014-02-17 21:15:33 +00:00
Kevin Fenzi
3e3e4e45c3
Add new virthost01 to the party.
2014-02-17 19:53:13 +00:00
Kevin Fenzi
cf203246cf
Drop releng02 back down to 16G
2014-02-17 19:11:57 +00:00
Patrick Uiterwijk
f8b435c912
Stg uses the stg key
2014-02-16 21:24:59 +00:00
Patrick Uiterwijk
04a8e4a7c8
Merge branch 'master' of /git/ansible
2014-02-16 21:19:20 +00:00
Patrick Uiterwijk
392ee5a552
Consolidate prod and stg configs
2014-02-16 21:19:10 +00:00
Kevin Fenzi
9abd23ce3b
Add fedmsg ports to ask firewall
2014-02-16 16:51:40 +00:00
Kevin Fenzi
e7239cb2f0
Clean up some blank lines in cron.d jobs.
2014-02-16 16:00:01 +00:00
Kevin Fenzi
393b32872d
Add collectd to releng02
2014-02-16 15:54:54 +00:00
Ralph Bean
927f04759f
Reduce libravatar badge check frequency.
2014-02-16 01:54:59 +00:00
Kevin Fenzi
5b7b9595b2
We must allow port 80 here.
2014-02-15 19:20:31 +00:00
Kevin Fenzi
3c4b6f911c
Fix ask favicon. Ticket 4233
2014-02-15 18:49:32 +00:00
Patrick Uiterwijk
3df290581e
This is invalid
2014-02-15 18:44:50 +00:00
Patrick Uiterwijk
094f81da8c
Add FAS_HANDLE_GROUPS_MAGIC_VALUE
2014-02-15 18:43:15 +00:00
Andrea Veri
63092472d0
GNOME Backups: vbox is soon gonna be rebuilt with RHEL 7, drop it from the backups set and preserve the current backups as future reference
2014-02-15 15:05:42 +00:00
Andrea Veri
f26437b1f1
Merge branch 'master' of /git/ansible
2014-02-15 15:03:54 +00:00
Andrea Veri
c1bd6a1c66
GNOME Backups: add the new machines (accelerator, range) to the backups set
2014-02-15 15:03:30 +00:00
Patrick Uiterwijk
51a4bc5498
Only run db creation on the primary nodes so that we dont get race conditions
2014-02-14 22:17:31 +00:00
Patrick Uiterwijk
a0a41c33a8
Apparantly they should be colons
2014-02-14 21:31:37 +00:00
Patrick Uiterwijk
e43e7b564b
on vh07 its apparantly vg_guests00
2014-02-14 21:31:08 +00:00
Patrick Uiterwijk
b152789b19
These are semicolons
2014-02-14 21:27:17 +00:00
Patrick Uiterwijk
ca9e882b21
Create prod fedoauth config
2014-02-14 21:24:51 +00:00
Kevin Fenzi
e3dc33b618
Adjust nrpe on releng02
2014-02-14 21:18:37 +00:00
Patrick Uiterwijk
fce243ad3a
Deploy to prod as well
2014-02-14 21:18:10 +00:00
Patrick Uiterwijk
f9394aeb70
Merge branch 'master' of /git/ansible
2014-02-14 21:17:11 +00:00
Patrick Uiterwijk
881cd2a35c
Add fedoauth0{1,2}.phx
2014-02-14 21:17:05 +00:00
Kevin Fenzi
9ad1edf9dd
There's a dash here.
2014-02-14 21:13:32 +00:00
Kevin Fenzi
86b93efb5e
Move releng02 over to buildvmhost12 to see if it makes rawhide better.
2014-02-14 20:57:04 +00:00
Kevin Fenzi
ef7ed004ab
Add a cron job to delete unused ask tags every day. Ticket 4230
2014-02-14 18:16:00 +00:00
Patrick Uiterwijk
315fb71922
Add the OpenID issuer configuration
2014-02-14 14:07:39 +01:00
Pierre-Yves Chibon
250c7e921c
Use a more ansible-y syntax rather than jinja's
2014-02-13 21:51:02 +01:00
Pierre-Yves Chibon
c664301bd7
Don't move the rpm/srpm if running in testing
2014-02-13 21:46:47 +01:00
Pierre-Yves Chibon
878152cbeb
Always run yum clean expire-cache
2014-02-13 21:45:21 +01:00
Kevin Fenzi
4038277568
Update inventory.
2014-02-13 18:01:04 +00:00
Pierre-Yves Chibon
de4c5f6d3c
Enable the infrastructure-testing repo is testing is on
2014-02-13 08:52:19 +01:00
Ralph Bean
00acd2a211
Add it to the mapping, too.
2014-02-13 02:17:07 +00:00
Ralph Bean
9dc037d36e
Add the ambassadors sponsors badge to the oldschool cronjob.
2014-02-13 01:50:59 +00:00
Kevin Fenzi
54d9911f91
Move to 10min for vhost_reboot timeout.
2014-02-12 21:38:15 +00:00
Ralph Bean
6eb8225f04
Fix another typo in the oldschool badges cronjob.
2014-02-12 14:59:59 +00:00
Ralph Bean
c6911d8699
Fix syntaxerror in one of the badges cronjobs.
2014-02-12 14:20:53 +00:00
Kevin Fenzi
253c99a2d8
Add resolv.conf for tummy and telia datacenters
2014-02-12 04:25:31 +00:00
Ralph Bean
f03b006ce8
Add the videographers badge to the oldschool script.
2014-02-11 21:31:33 +00:00
Luke Macken
ca7a14d04a
Add a missing quote to the extra-vars argument
2014-02-11 21:22:22 +00:00
Kevin Fenzi
5912f8b204
Restart nrpe on these 2 plays as well.
2014-02-11 20:29:56 +00:00
Kevin Fenzi
1dd4281772
Fix filenames
2014-02-11 20:26:53 +00:00
Kevin Fenzi
749c6b9930
Use correct names.
2014-02-11 20:00:37 +00:00
Kevin Fenzi
64cd952dac
Split these out for now.
2014-02-11 19:58:15 +00:00
Kevin Fenzi
83c31d8487
This is a string
2014-02-11 19:50:10 +00:00
Kevin Fenzi
3f8e31d61a
Indentation
2014-02-11 19:49:24 +00:00
Kevin Fenzi
d9b48ab356
Make these conditional on unbound and not phx2
2014-02-11 19:47:25 +00:00
Kevin Fenzi
faf7ba49d9
Add checks for unbound instances
2014-02-11 19:42:51 +00:00
Kevin Fenzi
b77a905a91
Add service enable/start to unbound role.
2014-02-11 18:24:39 +00:00
Kevin Fenzi
d02bcdc3b9
Install policycoreutils-python as well for semanage
2014-02-11 18:06:45 +00:00
Kevin Fenzi
ea6c98fcf0
Fix up unbound.conf copy
2014-02-11 18:02:34 +00:00
Kevin Fenzi
72b18e1951
Fix in all the places.
2014-02-11 17:32:54 +00:00
Kevin Fenzi
4b942afaf9
Just call the group unbound.
2014-02-11 17:32:25 +00:00
Kevin Fenzi
1c64975234
Add unbound role/instances migrated from puppet. Ticket 4198. Thanks adimania!
2014-02-11 17:25:56 +00:00
Pierre-Yves Chibon
e2ac4fe440
Found where the latest Warnings plugin is available
2014-02-11 17:44:05 +01:00
Pierre-Yves Chibon
b52b740104
Add support for the testing repo to the update_packages playbook
2014-02-11 13:31:05 +00:00
Pierre-Yves Chibon
d9ef700395
Update the pyflakes warning plugin
2014-02-11 14:01:23 +01:00
Pierre-Yves Chibon
7d4804ea50
Apparently the F20 builder was missing from the config file
2014-02-11 12:10:24 +01:00
Pierre-Yves Chibon
308bc82719
csv != cvs - explains the 404 error we were getting
2014-02-11 11:25:17 +01:00
Pierre-Yves Chibon
7198cc27a5
Restart jenkins after having install the plugins
2014-02-11 11:21:32 +01:00
Pierre-Yves Chibon
d95ad3e069
Add the warnings plugin to the ansible playbook
2014-02-11 10:43:48 +01:00
Patrick Uiterwijk
86ee70934f
Merge branch 'master' of /git/ansible
2014-02-10 21:11:49 +00:00
Patrick Uiterwijk
a8ac414ab5
Fix this by using lower() before compare
2014-02-10 21:11:39 +00:00
Aurélien Bompard
ce990461f9
Mailman: small fixes
2014-02-10 19:22:26 +00:00
Kevin Fenzi
2b7198bd76
Move badges-web02 to vh15
2014-02-10 18:39:26 +00:00
Ralph Bean
03a1ca0abd
Add trusted_openid patterns for badges.
2014-02-09 23:54:46 +00:00
Pierre-Yves Chibon
f327ef20c5
We need to declare the variable to override it in the cli
2014-02-10 00:04:51 +01:00
Pierre-Yves Chibon
0f7714cb1b
Add support for signing and importing into the testing repository
2014-02-09 22:45:44 +00:00
Patrick Uiterwijk
cb5db8c149
We sign for stg.fp.o, not id.stg.fp.o
2014-02-09 21:04:39 +00:00
Patrick Uiterwijk
a29a44b87e
It runs as fedoauth, so that user needs access to the config
2014-02-09 20:49:51 +00:00
Patrick Uiterwijk
3a0703ad54
Use stg db host for stg
2014-02-09 20:44:07 +00:00
Patrick Uiterwijk
38fae33b5d
Make the keys private
2014-02-09 20:39:27 +00:00
Patrick Uiterwijk
9c3287314b
Lets make a seperation between prod and stg in file names
2014-02-09 20:34:25 +00:00
Patrick Uiterwijk
cfe9665a68
Correct this to use the right variable
2014-02-09 20:32:20 +00:00
Patrick Uiterwijk
cbe4eb0e1c
fedoauth01.stg is stg
2014-02-09 20:28:49 +00:00
Patrick Uiterwijk
f1001050a4
This is fedoauth
2014-02-09 18:20:08 +00:00
Patrick Uiterwijk
37d085b24f
Using db-fas01
2014-02-09 18:15:12 +00:00
Patrick Uiterwijk
faaa683e40
Add fedoauth
2014-02-09 18:14:16 +00:00
Patrick Uiterwijk
aa91fc61bb
Add fedoauth
2014-02-09 17:37:13 +00:00
Nick Bebout
3f8111283a
Merge branch 'master' of /git/ansible
2014-02-09 14:28:11 +00:00
Nick Bebout
e424c4c5a0
Add sysadmin-docs to docs-backend group
2014-02-09 14:27:51 +00:00
Pierre-Yves Chibon
ea8147c1d0
Turn on boolean to allow apache on fuse
2014-02-09 09:05:54 +01:00
Pierre-Yves Chibon
554e8caa74
Try to update only one folder
2014-02-09 02:04:16 +01:00
Pierre-Yves Chibon
b7f463b041
Skip the folder creation for now
2014-02-09 02:01:48 +01:00
Pierre-Yves Chibon
b7cef497a0
Make the glusterfs folder accessible by apache
2014-02-09 01:58:49 +01:00
Pierre-Yves Chibon
6c3275fc84
Fix the creation of the pictures and cache folders for nuancier and fix their permissions
2014-02-09 01:57:50 +01:00
Pierre-Yves Chibon
de4b5bf97f
Update the picture folder for nuancier to the glusterfs volume
2014-02-09 01:09:03 +01:00
Pierre-Yves Chibon
c3552250af
Actually install the alembic.ini file and python-alembic
2014-02-08 16:19:24 +00:00
Pierre-Yves Chibon
7d5aa7afe8
Add and install the alembic.ini file
2014-02-08 16:17:06 +00:00
Pierre-Yves Chibon
c6c96c57bb
More changes from nuancier-lite -> nuancier
2014-02-08 15:58:34 +00:00
Pierre-Yves Chibon
7011ce0e14
Stg is rolling out on nuancier not nuancier-lite
2014-02-08 15:56:00 +00:00
Pierre-Yves Chibon
d8f1b5b886
Restart gluster if we created the directory
2014-02-07 23:58:06 +01:00
Pierre-Yves Chibon
eae98a55da
Ask nicely that they are directory
2014-02-07 23:53:41 +01:00
Pierre-Yves Chibon
70fdcdc594
Add port 6996 on nuancier and nuancier-stg
2014-02-07 23:37:48 +01:00
Pierre-Yves Chibon
db7116ca33
Really jinja, 1?
2014-02-07 23:31:36 +01:00
Pierre-Yves Chibon
2fa4233e67
Ruby hacks does not work on python
2014-02-07 23:29:52 +01:00
Pierre-Yves Chibon
e5fe0ff6d9
She said she needed space
2014-02-07 23:27:36 +01:00
Pierre-Yves Chibon
280c773ae7
Jinja and yaml are fun together
2014-02-07 23:25:16 +01:00
Pierre-Yves Chibon
06990b2234
Give it some space
2014-02-07 23:23:37 +01:00
Pierre-Yves Chibon
d032393f52
Remove for now
2014-02-07 23:17:59 +01:00
Pierre-Yves Chibon
167e776d36
Let's comment it out for now
2014-02-07 23:16:44 +01:00
Pierre-Yves Chibon
1bc4c1a406
Specify where to do the mount
2014-02-07 23:12:50 +01:00
Ralph Bean
0b30787631
Well that didn't work.
2014-02-07 22:03:46 +00:00
Ralph Bean
75799a5f32
Use some hostvars trickery.
2014-02-07 22:02:16 +00:00
Ralph Bean
ff73e633e8
Fix some more jinja errors and use ansible_ssh_host over ansible_hostname.
2014-02-07 21:58:33 +00:00
Ralph Bean
c983f6202b
Restrictive jinja disallowed "len()"
2014-02-07 21:55:47 +00:00
Ralph Bean
f38b34d8c4
Add a handler to restart glusterd.
2014-02-07 21:54:15 +00:00
Ralph Bean
e462a294ec
Construct this correctly.
2014-02-07 21:50:17 +00:00
Ralph Bean
b070ef772b
Supply a "name".
2014-02-07 21:48:53 +00:00
Ralph Bean
3de2b17204
Quote those.
2014-02-07 21:42:33 +00:00
Ralph Bean
8a61b7791a
Remove indentation.
2014-02-07 21:41:47 +00:00
Ralph Bean
55b08d5a52
First stab at a gluster role for the nuancier staging nodes.
2014-02-07 21:36:24 +00:00
Kevin Fenzi
00de58c594
Fix copypasta
2014-02-06 21:22:09 +00:00
Kevin Fenzi
5dcb09537d
Add bodhi.dev cloud instance
2014-02-06 21:14:12 +00:00
Kevin Fenzi
77c7ea987f
Adjust services for rhel buildhw
2014-02-06 17:53:16 +00:00
Kevin Fenzi
902afe8a72
Only check grub1 on x86 hw, not ppc
2014-02-06 17:26:32 +00:00
Kevin Fenzi
cddcb75d84
This isn't defined on arm
2014-02-06 17:18:07 +00:00
Kevin Fenzi
d2ba50fc29
No grub2 on arm
2014-02-06 17:09:46 +00:00
Kevin Fenzi
6e4e48d8b3
It's conf with grub1
2014-02-06 17:04:04 +00:00
Kevin Fenzi
7dc5b9151e
Need to sort this out, but this should work fine for now.
2014-02-06 17:02:18 +00:00
Kevin Fenzi
d2ea2b1e63
Pull builder kernel task into koji_builder role.
2014-02-06 16:57:18 +00:00
Stephen Smoogen
417471d978
Now remove proxy05/proxy5 app06/app6 from ansible.
2014-02-04 20:59:01 +00:00
Kevin Fenzi
25e545ed5d
Enable Hungarian in ask production. Ticket 4214
2014-02-04 19:07:07 +00:00
Aurélien Bompard
15503efdc9
Mailman: don't auto-redirect to SSL
...
In the Fedora infra, SSL is handled by the proxy and we can't detect it.
2014-02-04 09:04:44 +00:00
Kevin Fenzi
e9faa5079e
Fix this up some.
2014-02-04 00:06:09 +00:00
Kevin Fenzi
234f2825be
Add semanage for ports
2014-02-03 23:56:49 +00:00
Kevin Fenzi
1d85587606
Enable hungarian in ask.stg to test.
2014-02-03 22:55:28 +00:00
Ralph Bean
da287c5f1c
Use chat.freenode.net over irc.freenode.net.
2014-02-03 22:03:01 +00:00
Ralph Bean
578365bc34
Bump fedmsg endpoints for fas and pkgdb to agree with the number of wsgi processes.
2014-02-03 22:01:17 +00:00
Patrick Uiterwijk
a941b10d63
Add hotfix for python-openid
2014-02-03 19:50:52 +00:00
Patrick Uiterwijk
ecf064d030
Merge branch 'master' of /git/ansible
2014-02-03 19:46:34 +00:00
Kevin Fenzi
2caf90aed2
Enable Simplified Chinese in production. Ticket 4208.
2014-02-03 17:15:26 +00:00
Matt Domsch
5ab222ea2a
use mirrorlist-server.conf from v1.4.4
2014-02-03 16:23:21 +00:00
Aurélien Bompard
d4ca13001a
Mailman: sudo requires a tty
2014-02-03 12:05:03 +00:00
Aurélien Bompard
42c77051f4
Use the new variable substitution syntax
2014-02-03 11:33:29 +00:00
Aurélien Bompard
b64262922c
Install psycopg2 on the DB servers
2014-02-03 11:31:37 +00:00
Aurélien Bompard
159115f3d3
Mailman: the DB server is different in stg and prod
2014-02-03 11:11:21 +00:00
Miroslav Suchý
999677b572
define buildsys macros
...
for some reason buildsys-macros is not installed in default buildroot
it works localy, but not in Copr. I spent a lot of time debuging it
But enough is enough. Lets solve it this way.
2014-02-03 09:55:32 +00:00
Kevin Fenzi
d83256b106
Make the ansible check diff run serial instead of parallel.
2014-02-03 05:04:01 +00:00
Kevin Fenzi
4a9ee86575
Adjust ask01.stg zh locale.
2014-02-01 17:43:40 +00:00
Kevin Fenzi
438aca0049
Give up for now.
2014-02-01 00:10:25 +00:00
Kevin Fenzi
3325113b5e
Single quotes?
2014-02-01 00:10:02 +00:00
Kevin Fenzi
0768a03c57
Back to this to test more.
2014-02-01 00:08:44 +00:00
Kevin Fenzi
7fa2e11fa5
One last try
2014-01-31 23:51:11 +00:00
Kevin Fenzi
15f596183f
Perhaps this
2014-01-31 23:42:08 +00:00
Kevin Fenzi
203aff15b9
This is silly, but try it anyhow.
2014-01-31 23:37:44 +00:00
Kevin Fenzi
5ee49f57fb
This should just be zh I think.
2014-01-31 22:31:33 +00:00
Kevin Fenzi
16f3769117
Add armpkgs to hosts for arm builders.
2014-01-31 18:32:58 +00:00
Kevin Fenzi
8baa7720e7
Adjust backup excludes to be more right.
2014-01-31 16:10:47 +00:00
Pierre-Yves Chibon
274d7993ce
Instead of keeping the jenkins plugins in git, let's download them and check their sha256
2014-01-30 19:19:16 +01:00
Aurélien Bompard
7da961cc1c
Mailman: small fixes discovered with lists-dev
2014-01-30 10:42:02 +00:00
Kevin Fenzi
4effa2c2c0
Do not backup the git_seed stuff on pkgs01
2014-01-30 04:21:15 +00:00
Ralph Bean
789e1d7814
Disable this relay endpoint since apparently copr-be.cloud can find it.
2014-01-29 22:01:37 +00:00
Miroslav Suchý
f33ed0f4fc
enable fedmsg on copr-be
2014-01-29 21:59:55 +00:00
Ralph Bean
99286867db
Need this for lokkit on f19.
2014-01-29 21:33:27 +00:00
Ralph Bean
1ca4f5ed0d
Fix copr fedmsg cert name.
2014-01-29 21:16:33 +00:00
Ralph Bean
ed9133b7c0
Reduce avatar cache expiry (badges)
2014-01-29 19:38:41 +00:00
Patrick Uiterwijk
f1aa4ab7c1
Hotfix python-openid
2014-01-29 01:11:17 +00:00
Patrick Uiterwijk
3dad76a61e
Merge branch 'master' of /git/ansible
2014-01-29 01:10:40 +00:00
Patrick Uiterwijk
14dc12d5c9
Prepare for python-openid hotfix
2014-01-29 01:10:21 +00:00
Ralph Bean
eb66da624b
s/semanage/semodule/
2014-01-28 19:57:21 +00:00
Ralph Bean
091a117c4f
A custom selinux module for fedmsg.
2014-01-28 19:51:26 +00:00
Ralph Bean
e05439c3c6
Add fedocal fedmsg endpoints.
2014-01-28 18:51:52 +00:00
janez.nemanic
79773578b5
Add pyflakes parser to jenkins
2014-01-28 08:32:59 +01:00
Kevin Fenzi
68be0f0f3c
Drop accel from buildhw, the arm network isn't allowing it.
2014-01-27 23:57:45 +00:00
Kevin Fenzi
5e73d51832
More hackery
2014-01-27 16:57:37 +00:00
Kevin Fenzi
7461ae9870
Gross hack for now until I figure a better way to share this
2014-01-27 16:37:42 +00:00
Kevin Fenzi
46e456de79
Dont add netapp route on arm machines.
2014-01-26 01:57:30 +00:00
Kevin Fenzi
b02fc093b2
Move ) to the right place.
2014-01-26 01:36:43 +00:00
Kevin Fenzi
28c71b2501
Exclude arm here too.
2014-01-26 01:30:36 +00:00
Kevin Fenzi
1a7fefbe68
Fix typo with arm repos
2014-01-26 01:10:38 +00:00
Kevin Fenzi
f2799983ec
Change this to just running.
2014-01-25 19:42:21 +00:00
Kevin Fenzi
f1e5089967
Move kojid restart to after hosts file setup task
2014-01-25 19:39:56 +00:00
Kevin Fenzi
1ec4410d43
Drop some iptables restarting thats not needed.
2014-01-25 19:29:37 +00:00
Kevin Fenzi
0c3a84f841
Add kojid handler
2014-01-25 19:24:19 +00:00
Kevin Fenzi
18a98f6ed1
FIx typo
2014-01-25 19:14:03 +00:00
Kevin Fenzi
e1b2563940
Move base_builder task over to a new koji_builder role and clean up.
2014-01-25 19:12:29 +00:00
Kevin Fenzi
cf270b1f6e
d it's got a d
2014-01-25 18:47:42 +00:00
Kevin Fenzi
4ce16944b9
More cleanup, audit and rsyslog
2014-01-25 18:45:57 +00:00
Kevin Fenzi
2d9e1d1f10
rpcbind is static in f20, no need to enable it.
2014-01-25 18:19:23 +00:00
Kevin Fenzi
5dd9b5f4a9
More tweaking to the buildvm tasks
2014-01-25 18:14:15 +00:00
Kevin Fenzi
0542974bab
Try this on conditionals.
2014-01-25 18:04:45 +00:00
Kevin Fenzi
9d77ed603e
Notify rsyslog on adding new rsyslog.d snippets.
2014-01-25 18:04:30 +00:00
Kevin Fenzi
9c0addf17c
More cleanup, use fileglob
2014-01-25 17:57:18 +00:00
Kevin Fenzi
3dbc402ec4
These are in a subdir.
2014-01-25 17:50:43 +00:00
Kevin Fenzi
0844a05bf0
Rework rsyslog stuff. Use default dist /etc/rsyslog.conf, add our stuff to /etc/rsyslog.d
2014-01-25 17:45:38 +00:00
Kevin Fenzi
899cff9492
Some more cleanup.
2014-01-24 23:51:45 +00:00
Kevin Fenzi
0f3395189e
Another attempt
2014-01-24 23:46:07 +00:00
Kevin Fenzi
fd6119bd4d
Still ssh keys comments issues. :(
2014-01-24 23:39:35 +00:00
Kevin Fenzi
dfa9e5339e
More idempotent
2014-01-24 23:37:08 +00:00
Kevin Fenzi
d17fd8236a
Work around this for now.
2014-01-24 23:26:03 +00:00
Kevin Fenzi
31a46523a1
Add yum repos setup to buildvm's
2014-01-24 22:49:01 +00:00
Kevin Fenzi
588722a9e8
Cull global packages, add ansible accel mode to kojibuilders.
2014-01-24 22:27:34 +00:00
Kevin Fenzi
de9c00f1ba
Switch buildvm's over to f20 for reinstalling.
2014-01-24 21:34:24 +00:00
Ralph Bean
03be7b46c9
Add symlink for fmn.web fedora theme.
2014-01-24 21:17:50 +00:00
Ralph Bean
54d88840d5
Add an nrpe command definition for checking the presence of the fedmsg hub.
2014-01-24 20:55:33 +00:00
Ralph Bean
d6afd943b2
No need for notifs backend to be on the vpn.
2014-01-24 20:04:18 +00:00
Ralph Bean
060f9f2eb9
hosts files for fmn prod nodes.
2014-01-24 19:50:40 +00:00
Ralph Bean
b7ff972cbd
Host definitions for the fmn prod nodes.
2014-01-24 19:47:15 +00:00
Kevin Fenzi
0494a018a6
Add simple script that runs --check --diff playbook runs on all hosts/groups.
2014-01-24 16:59:46 +00:00
Kevin Fenzi
083b631c29
Remove debug_env role from ask now.
2014-01-24 16:43:57 +00:00
Kevin Fenzi
49c42fc8b2
Adjust role
2014-01-24 16:40:58 +00:00
Kevin Fenzi
79bd4c3a21
Test debug_env
2014-01-24 16:35:42 +00:00
Kevin Fenzi
389600314b
only_if is going bye bye.
2014-01-24 16:34:05 +00:00
Kevin Fenzi
4e127e63ed
Add debug_env role for debugging needs down the road.
2014-01-24 16:31:33 +00:00
Kevin Fenzi
76eb4b0f04
Sadly, this will not work. :(
2014-01-24 16:30:23 +00:00
Kevin Fenzi
76951c0b1d
Test a roles_path idea.
2014-01-24 16:25:53 +00:00
Miroslav Suchý
89a74383d7
add releasever - BZ 1056039
2014-01-24 08:39:42 +00:00
Ralph Bean
324721e3f3
Disable alternative openids for fmn for now.
2014-01-23 21:41:59 +00:00
Ralph Bean
3b179a2ce6
Remove bogus config.
2014-01-23 21:34:32 +00:00
Ralph Bean
d40a72f7f5
Initialize fmn logging.
2014-01-23 21:23:53 +00:00
Ralph Bean
75d3b045fc
Add these two, too.
2014-01-23 21:08:59 +00:00
Ralph Bean
1a791a6e0e
Point the fmn frontend at datanommer.
2014-01-23 21:06:02 +00:00
Kevin Fenzi
58b8b85ef0
Move fedmsg_base role to the last one to allow ownership of keys files to work right hopefully.
2014-01-23 18:15:18 +00:00
Kevin Fenzi
206ed3f776
Now that we have roles_path, drop the long path on all the roles.
2014-01-23 17:12:40 +00:00
Kevin Fenzi
406474a374
Move the kernel-qa playbook to manual. The kernel team manages those day to day.
2014-01-23 17:00:26 +00:00
Kevin Fenzi
dfbd43862b
Disable releng01 for now, since we have no branched.
2014-01-23 16:39:26 +00:00
Kevin Fenzi
de1c4695d4
Fix syntax errors in copr-be playbook
2014-01-23 16:25:27 +00:00
Miroslav Suchý
3b4edc4ade
fine tune SpareServers on copr-fe and allow server-status
...
so I can see what is happening there
2014-01-23 12:13:11 +00:00
Ralph Bean
a692918cbb
Supply fas credentials to the fmn backend.
...
..so that it can build a cache of fas usernames to ircnicks.
2014-01-23 01:51:31 +00:00
Kevin Fenzi
957851378e
Fix up these too.
2014-01-22 21:53:50 +00:00
Kevin Fenzi
18ec0ff132
equality
2014-01-22 21:51:53 +00:00
Kevin Fenzi
1a1f1fb2ca
Try to clean this up so it doesn't show failed or changed when it isn't
2014-01-22 21:50:52 +00:00
Kevin Fenzi
5a58c171f8
Lets make this a _ to be nicer
2014-01-22 21:16:39 +00:00
Ralph Bean
474fef8661
Try to silence fedmsg for --check runs.
2014-01-22 20:48:05 +00:00
Kevin Fenzi
ffcff93ce8
Add check diff to ansible logging
2014-01-22 20:32:05 +00:00
Kevin Fenzi
dfd57eb6ce
Enable greek and indonesian on ask.fedora production site
2014-01-22 20:13:53 +00:00
Miroslav Suchý
95f02d8990
fix ownership of copr-be.conf and typo in generating pem file
2014-01-22 19:23:43 +00:00
Miroslav Suchý
72e1714301
add missing handlers
2014-01-22 16:39:08 +00:00
Miroslav Suchý
ec955a7b2e
add patched scl-utils to builder repo
2014-01-22 16:35:11 +00:00
Miroslav Suchý
c323027b81
add coprs admin to .forward
2014-01-22 16:35:11 +00:00
Ralph Bean
782e80bc50
Modernize vars in fmn roles.
2014-01-22 16:12:24 +00:00
Ralph Bean
b4ea2a7bcd
Cache settings for the fmn backend.
2014-01-22 16:06:41 +00:00
Miroslav Suchý
ea1dc27076
deploy real cers on copr-be
2014-01-22 15:44:40 +00:00
Aurélien Bompard
7c40bb7e8a
lists-dev: setenforce and fix aliases perms
2014-01-22 10:38:47 +00:00
Kevin Fenzi
693f1ca2d0
Add ansible-server role
2014-01-21 19:55:59 +00:00
Kevin Fenzi
2e909f8205
Add pt-br to production askbot.
2014-01-21 19:35:55 +00:00
Kevin Fenzi
821aae5366
Setup basic lockbox-comm01.qa instance.
2014-01-21 19:27:36 +00:00
Kevin Fenzi
3a196043c6
It's lower case br
2014-01-21 18:16:25 +00:00
Kevin Fenzi
c47880a60f
Add some languages to staging to test
2014-01-21 18:11:35 +00:00
Kevin Fenzi
da98f8f0f3
Try a hotfix for the broken feedback issue.
2014-01-21 18:00:36 +00:00
Kevin Fenzi
7b8a7104bf
Add a askbot hotfix file.
2014-01-21 17:59:52 +00:00
Miroslav Suchý
9457dd2760
add dist tag and rhel7 to el7 mock config
2014-01-21 13:50:43 +00:00
Kevin Fenzi
e6c2d426b3
Add some more sebooleans for ask
2014-01-21 00:28:17 +00:00
Kevin Fenzi
dce6baa832
Hacky workaround for icon issue with fedora openid
2014-01-20 23:44:40 +00:00
Kevin Fenzi
1dc3f79b86
Add ask01 to ansible too.
2014-01-20 22:58:53 +00:00
Kevin Fenzi
116e7006ec
Add memcache sebool
2014-01-20 22:33:12 +00:00
Miroslav Suchý
dbe1e5df67
apply change to mock epel5 config
...
mock in epel6 changed, and we need this change (takend from F20 config of mock)
to successfuly build el5 package
addressing:
DEBUG util.py:281: error: cannot write to %sourcedir /usr/src/redhat/SOURCES
2014-01-20 20:53:58 +00:00
Aurélien Bompard
023eded377
Fix a YAML syntax problem, at last
2014-01-20 19:01:32 +00:00
Kevin Fenzi
e5aad94914
Add mailman01/02 to production.
2014-01-20 19:01:12 +00:00
Aurélien Bompard
51024371d3
Mailman: update the variable substitution syntax
2014-01-20 18:55:55 +00:00
Aurélien Bompard
2ef37ad740
Fix a YAML syntax problem
2014-01-20 18:47:46 +00:00
Aurélien Bompard
697b3eddb7
Mailman: improve post-update script
2014-01-20 18:37:43 +00:00
Kevin Fenzi
fd38240f90
Commit ask02 stuff to ansible.
2014-01-20 18:13:56 +00:00
Aurélien Bompard
2e2100319f
Mailman: parametrize the role
2014-01-20 17:56:53 +00:00
Kevin Fenzi
193d5c8337
Fix this lang thing the correct way.
2014-01-20 17:26:28 +00:00
Kevin Fenzi
2bf861fb4d
Immport gettext
2014-01-20 17:21:59 +00:00
Kevin Fenzi
7b38b40873
Fix languages setting for askbot
2014-01-20 17:15:16 +00:00
Kevin Fenzi
935277bfea
Adjust settings template some. Put stg/prod changes in one place.
2014-01-19 22:16:50 +00:00
Kevin Fenzi
55a3e42c62
Add cron to delete old undelivered emails. Add subset of languages we want to support.
2014-01-19 21:37:14 +00:00
Kevin Fenzi
f2f2093bd2
Add settings needed for multi lang support
2014-01-18 18:43:51 +00:00
Kevin Fenzi
785ce4ff87
Run collectstatic before trying to apply hotfixes.
2014-01-17 18:59:43 +00:00
Kevin Fenzi
6822f97cda
Turns out we can disable identi.ca via settings.
...
Also re-add cache timeout because it complains about it.
2014-01-17 18:28:53 +00:00
Kevin Fenzi
52f4cbe590
See if this gets rid of the identica share button.
2014-01-17 18:19:54 +00:00
Kevin Fenzi
dfcac4ffa6
Remove identa.ca from ask.stg hopefully.
2014-01-17 18:09:15 +00:00
Kevin Fenzi
56cde2b40a
Add this too for askbot
2014-01-17 18:01:36 +00:00
Kevin Fenzi
7f257b854d
askbot still does need this one. ;(
2014-01-17 17:56:46 +00:00
Aurélien Bompard
1fd81df74a
mailman: typo
2014-01-17 17:56:30 +00:00
Kevin Fenzi
429725e69e
Update settings to rid ourselves of depreciation notices.
2014-01-17 17:52:28 +00:00
Aurélien Bompard
48d9ebf522
lists-dev: add missing handler
2014-01-17 17:50:56 +00:00
Aurélien Bompard
c6852a889a
Make the lists-dev playbook closer to the mailman group
2014-01-17 17:17:28 +00:00
Aurélien Bompard
a43be7abbb
Use the new-style variable substitution
2014-01-17 16:09:57 +00:00
Aurélien Bompard
e66c937bf5
Fix the URL to the repo file
2014-01-17 16:05:28 +00:00
Aurélien Bompard
603ea16820
Fix a syntax error, yet again
2014-01-17 16:02:18 +00:00
Aurélien Bompard
34c38adfe0
Fix a syntax error, again
2014-01-17 15:39:23 +00:00
Aurélien Bompard
47e672cf38
Fix a syntax error
2014-01-17 15:37:40 +00:00
Ralph Bean
5e51be733b
Correct the logic for checking group membership when awarding old group badges.
...
Reviewed by Patrick Uiterwijk.
2014-01-17 15:01:46 +00:00
Aurélien Bompard
13b6d6f85a
Uniformize indentation (whitespaces only)
2014-01-17 11:10:54 +00:00
Aurélien Bompard
eefdd1b23c
Minor syntax fixes
2014-01-17 11:01:27 +00:00
Aurélien Bompard
b2e8e6020a
Use the mailman role for lists-dev
2014-01-17 11:01:27 +00:00
Kevin Fenzi
17f003db5b
Drop user data here too.
2014-01-17 04:43:49 +00:00
Kevin Fenzi
1f0ee84997
apache group on the askbot cert
2014-01-16 22:24:11 +00:00
Kevin Fenzi
805310c8f3
Add fedmsg certs for ask01.stg
2014-01-16 22:21:09 +00:00
Kevin Fenzi
7b90a538ea
ask01.stg fixes. Add fedmsg_base, fix settings to include celery for now.
2014-01-16 22:12:53 +00:00
Ralph Bean
25a1b7b53c
Add the new ronin badge to the oldschool script.
2014-01-16 15:40:20 +00:00
Ralph Bean
50a49a5378
Modernize variables in the badges-frontend role.
2014-01-16 14:56:14 +00:00
Kevin Fenzi
5e61d476e9
Remove user_data until I can figure out how to make it work.
2014-01-15 16:50:37 +00:00
Kevin Fenzi
d022f58e94
Incease size of lists-dev and make f19 instance
2014-01-15 16:30:46 +00:00
Miroslav Suchý
08b3569ed6
setup copr-fe to use https
...
selfigned certs, not stored here.
It will be replaced in matter of days by properly signed certs, which we store in private repo
2014-01-15 13:32:05 +00:00
Miroslav Suchý
b1dfce5353
setup copr-be to use https
...
selfigned certs, not stored here.
It will be replaced in matter of days by properly signed certs, which we store in private repo
2014-01-15 13:32:05 +00:00
Andrea Veri
c381898d11
GNOME Backups: drop legacy ansible variables and make sure every description has GNOME in it to avoid misunderstandings
2014-01-14 18:26:57 +00:00
Andrea Veri
ad8b05b155
GNOME Backups: drawable.gnome.org has no public IP anymore, make sure rdiff-backup forwards his agent through bastion
2014-01-14 18:12:51 +00:00
Miroslav Suchý
457decc25f
[copr] add epel7 config
2014-01-14 11:31:35 +00:00
Aurélien Bompard
7b744d074e
Mailman: sync with recent developments
2014-01-14 07:56:52 +00:00
Kevin Fenzi
869a1965b3
Nuke bacula.
2014-01-13 20:12:26 +00:00
Kevin Fenzi
c67dc5f94c
Add db-datanommer01 to backups on backup03
2014-01-13 20:06:40 +00:00
Ralph Bean
5e32fe5643
Move postgres backup cron task inside a bash flavored script.
2014-01-13 16:16:27 +00:00
Kevin Fenzi
a41fb3da66
Use the right owner/group this time. ;)
2014-01-10 22:20:37 +00:00
Kevin Fenzi
d350b9bc66
Fix initial log ownership for ask
2014-01-10 22:18:27 +00:00
Kevin Fenzi
d15b70251a
Pull askbot from epel-testing for now.
2014-01-10 21:50:12 +00:00
Ralph Bean
12b88b57a1
Cron backups for db-datanommer01.
2014-01-10 21:29:20 +00:00
Ralph Bean
18100deb21
Remove unused pg_hba.conf.j2 file.
2014-01-10 21:27:45 +00:00
Ralph Bean
db6fdf9bb0
Add a second config file for postgresql.
2014-01-10 20:52:18 +00:00
Ralph Bean
c1a97c4a40
Add a postgres config to the postgres role.
2014-01-10 20:40:08 +00:00
Ralph Bean
62066cdc08
Point badges backend at the new datanommer db host.
2014-01-10 20:12:14 +00:00
Kevin Fenzi
ed25d05c43
Move group variables into host in this case.
2014-01-10 19:01:52 +00:00
Kevin Fenzi
8cc4c30647
Add db-datanommer01, clean up postgres playbooks to be generic and not koji specific.
2014-01-10 18:56:25 +00:00
Toshio くらとみ
7a3df53822
Merge branch 'master' of /git/ansible
2014-01-09 21:00:06 +00:00
Toshio くらとみ
741ee1ce5f
Remove the files implementing python-fedora hotfixes. They're all in the latest packages
2014-01-09 20:59:46 +00:00
Kevin Fenzi
b306589264
Add datagrepper02 to inventory
2014-01-09 20:56:53 +00:00
Kevin Fenzi
7488893d21
Setup hosts for ask01 and tweak template.
2014-01-09 20:50:59 +00:00
Toshio くらとみ
c3ed8a0145
Remove python-fedora hotfixes
2014-01-09 20:47:26 +00:00
Kevin Fenzi
afb69f368a
Add booleans for db connect to ask
2014-01-09 20:23:08 +00:00
Kevin Fenzi
0d1addb56e
Update settings.
2014-01-09 20:21:20 +00:00
Kevin Fenzi
9f3511ff1d
Fix settings.py permissions on ask01.stg.
2014-01-09 19:51:35 +00:00
Ralph Bean
c14eb4b78f
Remove fedmsg endpoints for the old trac plugin.
2014-01-09 17:33:34 +00:00
Kevin Fenzi
2f0c72bf3b
Another correction
2014-01-09 17:30:57 +00:00
Kevin Fenzi
2511d5ef8b
Fix path to use the configured static content
2014-01-09 17:29:22 +00:00
Kevin Fenzi
4215e7099f
askbot is noarch too. dho.
2014-01-09 17:27:14 +00:00
Kevin Fenzi
bc649da212
Adjust for noarch python modulles, add some more packages that need to be installed.
2014-01-09 17:24:49 +00:00
Kevin Fenzi
2ec4227667
These may not be needed anymore, comment them out for now.
2014-01-09 17:21:05 +00:00
Kevin Fenzi
9be90c30bf
64 screaming bits
2014-01-09 17:19:05 +00:00
Kevin Fenzi
5a9f82f374
Merge branch 'master' of /git/ansible
2014-01-09 17:16:39 +00:00
Ralph Bean
ec5445bf17
Fix up the sign_and_import playbook.
2014-01-09 17:16:30 +00:00
Kevin Fenzi
a189e3c9c2
We need compressor too
2014-01-09 17:16:28 +00:00
Kevin Fenzi
ad5da94197
It's endif in jinja2
2014-01-09 17:12:15 +00:00
Kevin Fenzi
7e3d5a3062
Missed a few :s
2014-01-09 16:57:49 +00:00
Kevin Fenzi
026a6f8919
ansible doesn't like : in names. :)
2014-01-09 16:57:13 +00:00
Kevin Fenzi
c9e3508451
Add ask01.stg and first cut at ask playbook and roles to ansible.
2014-01-09 16:50:45 +00:00
Miroslav Suchý
38c8cc5553
use new ansible syntax
...
addressing:
[DEPRECATION WARNING]: Legacy variable substitution, such as using ${foo} or
$foo instead of {{ foo }} is currently valid but will be phased out and has
been out of favor since version 1.2. This is the last of legacy features on our
deprecation list. You may continue to use this if you have specific needs for
now. This feature will be removed in version 1.6. Deprecation warnings can be
disabled by setting deprecation_warnings=False in ansible.cfg.
2014-01-09 11:15:10 +00:00
Kevin Fenzi
835b45100a
Move credentials over to private
2014-01-09 01:13:34 +00:00
Till Maas
6155d32d7d
Add fetch-ssh-keys
2014-01-08 23:40:52 +01:00
Kevin Fenzi
b9ff6d133d
Revert "Move accelerate: true to global vars."
...
This reverts commit 0953ea5efa .
Looks like this doesn't work as a var, and accel might just get dropped in favor of new ssh soon.
2014-01-08 20:35:05 +00:00
Kevin Fenzi
0953ea5efa
Move accelerate: true to global vars.
2014-01-08 19:28:00 +00:00
Kevin Fenzi
136866729f
Clean up some more old syntax
2014-01-08 17:42:18 +00:00
Ralph Bean
a97ce78813
More syntax modernization.
2014-01-08 16:29:20 +00:00
Ralph Bean
a44d82f494
Remove temporary debugging.
2014-01-08 16:27:08 +00:00
Kevin Fenzi
2718b39cba
Bump badges-backend to 6gb ram
2014-01-08 01:15:49 +00:00
Ralph Bean
ea1cf51810
Some fixes for that new "badge off" badge.
2014-01-07 21:12:38 +00:00
Ralph Bean
b5207ad26d
Add cronjob for awarding the "Badge Off" badge.
2014-01-07 21:03:20 +00:00
Kevin Fenzi
c377d22903
Try and make it so growpart doesn't show changed if it didn't change anything.
2014-01-07 19:54:00 +00:00
Kevin Fenzi
fc61ec5770
More quotes
2014-01-07 19:23:02 +00:00
Kevin Fenzi
803cc22ef7
Quote: one who says something witty will be remembered forever - anonymous
2014-01-07 19:05:18 +00:00
Kevin Fenzi
ab21a8dc9f
Clean up host_vars. Move everything to new ssh key, fix old syntax.
2014-01-07 19:02:48 +00:00
Kevin Fenzi
9dc34181ba
Add elections01.stg to staging and sort group
2014-01-07 17:25:16 +00:00
Kevin Fenzi
18ae748d02
Add a manual playbooks subdir for playbooks that are only ever manually run.
2014-01-07 17:16:22 +00:00
Kevin Fenzi
cc7c6d6b09
Fix a stray old variable syntax
2014-01-07 17:16:04 +00:00
Kevin Fenzi
a06d5544bd
Correct name
2014-01-07 17:14:13 +00:00
Kevin Fenzi
c8ad333687
Add elections to ansible
2014-01-07 17:12:09 +00:00
Kevin Fenzi
e53ee4327f
Add noc01 external ip to denyhosts whitelist
2014-01-07 03:29:40 +00:00
Kevin Fenzi
6b04cd0a7f
Up the nrpe limits to stop the pile of alerting
2014-01-07 03:19:21 +00:00
Kevin Fenzi
740ce5dc7c
Another attempt
2014-01-07 00:55:33 +00:00
Kevin Fenzi
3631e708b8
Another stab, perhaps json?
2014-01-07 00:49:59 +00:00
Kevin Fenzi
134572d9cc
Try this one for user_data
2014-01-07 00:38:22 +00:00
Toshio くらとみ
f3ef23eebf
Disable python-fedora hotfix of nuancier in stg
2014-01-06 23:06:43 +00:00
Toshio くらとみ
2389fa4bea
Disable python-fedora hotfix for fedocal in stg
2014-01-06 23:05:06 +00:00
Toshio くらとみ
688d37edfe
Make python-fedora hotfix only apply to prod (update in stg shouldn't need it)
2014-01-06 23:02:54 +00:00
Kevin Fenzi
e1b50b3a35
Another attempt
2014-01-06 22:58:33 +00:00
Kevin Fenzi
041fc44463
How about this one?
2014-01-06 22:56:57 +00:00
Kevin Fenzi
bf99a15cb0
Lets try this.
2014-01-06 22:53:35 +00:00
Kevin Fenzi
e2c77afff8
Another tweak
2014-01-06 22:44:30 +00:00
Kevin Fenzi
cd10ff31da
Add some more vars
2014-01-06 22:42:09 +00:00
Kevin Fenzi
d9f4c98b8d
Try this
2014-01-06 22:38:15 +00:00
Kevin Fenzi
3ba97ea0be
Add a f20 temp instance playbook
2014-01-06 22:35:41 +00:00
Kevin Fenzi
50a046f114
Also add to transient cloud
2014-01-06 22:34:10 +00:00
Kevin Fenzi
e408633b86
Stab at disabling the anoying login as fedora junk in fedora cloud images.
2014-01-06 22:33:00 +00:00
Kevin Fenzi
e8da1a05a0
Remove comment from keys names for ansible bug
2014-01-06 22:26:45 +00:00
Kevin Fenzi
a6ea02adc1
Work around ansible bug 5432
2014-01-06 22:23:07 +00:00
Kevin Fenzi
d5cd46afde
logstash to f20, use new correct keys
2014-01-06 22:03:47 +00:00
Ralph Bean
9d903a70f1
Further bugfixes to the lifecycle cronjob.
2014-01-06 21:30:58 +00:00
Ralph Bean
c45f1781cd
Two typofixes to the lifecycle cronjob.
2014-01-06 21:11:30 +00:00
Ralph Bean
b563090860
Cronjob to award the fas "lifecycle" badges.
2014-01-06 20:35:26 +00:00
Andrea Veri
dd4aa27279
GNOME Backups: drop the --force flag, the first rdiff-backup run will end soon with success
2014-01-06 19:40:37 +00:00
Kevin Fenzi
2e957cf3db
Typo city, welcome to monday. :)
2014-01-06 18:53:28 +00:00
Kevin Fenzi
1b8e616ad4
rename taskbot to taskotron
2014-01-06 18:33:51 +00:00
Kevin Fenzi
b929678ff1
Hard code vars_path for now.
2014-01-06 18:22:18 +00:00
Kevin Fenzi
16b0f71f3a
Try this
2014-01-06 17:52:58 +00:00
Kevin Fenzi
67bc3b4920
vars is reserved, use vars_path for variable path
2014-01-06 17:49:22 +00:00
Kevin Fenzi
86fff66e19
Merge branch 'master' of /git/ansible
2014-01-06 17:34:58 +00:00
Kevin Fenzi
7fdc2ab99b
Add default el6 sshd_config for now.
2014-01-06 17:34:44 +00:00
Ralph Bean
f35f4d1b5d
Simplify that.
2014-01-06 17:34:43 +00:00
Ralph Bean
b6e8baff43
Add some temporary debugging.
2014-01-06 17:33:51 +00:00
Miroslav Suchý
e0f417425f
give sgallagh and nb access to copr machines
2014-01-06 14:05:55 +00:00
Kevin Fenzi
7ca9dcb3af
Tweak role
2014-01-02 02:16:51 +00:00
Kevin Fenzi
ecf8920ade
When defined
2014-01-02 00:42:12 +00:00
Kevin Fenzi
e286673702
Fix typo and put arm-qa playbook back to the way it was.
2014-01-01 23:59:20 +00:00
Kevin Fenzi
b5cdb8576e
Huh. Try this again
2014-01-01 23:30:30 +00:00
Kevin Fenzi
131c180dc8
That didn't work
2014-01-01 22:35:08 +00:00
Kevin Fenzi
27f614f9fe
Another stab at it.
2014-01-01 22:34:00 +00:00
Kevin Fenzi
7e79ed0c8e
Try this to work around the expansion issue
2014-01-01 22:32:10 +00:00
Kevin Fenzi
747eff6066
ok, why doesn't this work?
2014-01-01 22:24:12 +00:00
Kevin Fenzi
136810fe96
Fix up all the group vars to use new variable syntaax
2014-01-01 22:22:38 +00:00
Kevin Fenzi
a356dd16eb
Fix global vars, work around an include issue
2014-01-01 21:53:09 +00:00
Kevin Fenzi
7d0c6432af
Need a 18 one of these for another few weeks.
2014-01-01 21:44:54 +00:00
Kevin Fenzi
4bd90f8e28
Fix some more syntax
2014-01-01 21:33:06 +00:00
Kevin Fenzi
d507b1e116
Fix path to files
2014-01-01 21:07:56 +00:00
Kevin Fenzi
79a0601421
Space issues.
2014-01-01 21:02:53 +00:00
Kevin Fenzi
342a22a5a3
We should merge this with base role or figure out a better way.
2014-01-01 20:54:28 +00:00
Kevin Fenzi
b25c32c5da
This has to be expanded. Try this syntax
2014-01-01 20:45:59 +00:00
Kevin Fenzi
063f293ba8
Always run growpart on check because we use the result.
2014-01-01 20:41:26 +00:00
Kevin Fenzi
72478b0264
Tweak for loop syntax
2014-01-01 20:20:12 +00:00
Kevin Fenzi
4af3a2ec32
ERROR: chdir is not a legal parameter in an Ansible task or handler
2014-01-01 20:18:49 +00:00
Kevin Fenzi
aa37f25b54
Missed a few
2014-01-01 20:16:13 +00:00
Kevin Fenzi
1cb3f6ea7c
Some $'s missed
2014-01-01 20:15:17 +00:00
Kevin Fenzi
448b0bceb7
More with_fileglob fixes.
2014-01-01 20:12:53 +00:00
Kevin Fenzi
cbec442404
Fix some with_fileglob instances
2014-01-01 20:08:08 +00:00
Kevin Fenzi
3c41b15f12
When_set is going away, use when
2014-01-01 20:06:11 +00:00
Kevin Fenzi
af5c168225
Another loop fix
2014-01-01 20:03:52 +00:00
Kevin Fenzi
906159139e
Space: the final fronteer
2014-01-01 20:00:06 +00:00
Kevin Fenzi
97d6175943
Another loop syntax tweak
2014-01-01 19:59:25 +00:00
Kevin Fenzi
ee076869ff
Fix another loop
2014-01-01 19:55:23 +00:00
Kevin Fenzi
a974723992
Clean up syntax some
2014-01-01 19:54:23 +00:00
Kevin Fenzi
b30d7946c0
Another one
2014-01-01 19:47:31 +00:00
Kevin Fenzi
1889fb51ff
Also no {{ in with_pipe, variable are bare there too
2014-01-01 19:45:46 +00:00
Kevin Fenzi
2fe69599f5
Don't use {{ in when, variables are bare there.
2014-01-01 19:39:48 +00:00
Kevin Fenzi
f7d56ff2b1
Fix old variable usage. Patch from janeznemanic. Thanks!
2014-01-01 19:15:11 +00:00
Andrea Veri
d011bbde2c
GNOME Backups: make use of the --exclude-globbing-filelist flag
2013-12-30 14:15:15 +00:00
Andrea Veri
14d3f07415
GNOME Backups: drop the logs directory, we wont need you anymore
2013-12-28 19:41:05 +00:00
Andrea Veri
8db1d1e0b6
GNOME Backups: exclude /selinux and /sys as well
2013-12-28 19:01:43 +00:00
Andrea Veri
1ab8be272c
GNOME Backups: exclude /proc directly with --exclude
2013-12-28 19:00:58 +00:00
Andrea Veri
d630c3da15
GNOME Backups: double-quotes on the mail call
2013-12-28 18:57:09 +00:00
Andrea Veri
763cd06206
GNOME Backups: dont cd at all into the target directory but provide the correct target to the rdiff-backup call itself
2013-12-28 18:41:52 +00:00
Andrea Veri
6f971d8d8f
GNOME Backups: add the missing colon to the rdiff-backup command and make sure emails do get a subject generated for each machine backup
2013-12-28 18:08:16 +00:00
Kevin Fenzi
bb7dd14696
Lets make this faster
2013-12-28 18:00:19 +00:00
Andrea Veri
7258e676a6
GNOME Backups: don't assign the rdiff-backup's schemas to a variable
2013-12-28 17:58:47 +00:00
Andrea Veri
f90a3fbda5
GNOME Backups: convert the backup script to use rdiff-backup
2013-12-28 17:46:06 +00:00
Andrea Veri
3a3c0025cc
GNOME Backups: make sure the ProxyCommands knows about the custom ssh_config file we introduced recently
2013-12-23 16:36:53 +00:00
Andrea Veri
64fa1cd362
GNOME Backups: mode 0600 on the SSH config file
2013-12-23 16:15:17 +00:00
Andrea Veri
002135eb99
Move some of the configurations bits on the SSH config file and drop them from the backup script
2013-12-23 16:08:29 +00:00
Andrea Veri
af5aa06684
Add an SSH configuration file for the IPless machines @ GNOME backups
2013-12-23 16:04:32 +00:00
Andrea Veri
5b4564acd4
Merge the IPless machines into the global list of boxes to backup, also add an ssh_config file and populate it with ProxyCommand
2013-12-23 15:08:37 +00:00
Kevin Fenzi
6059906447
Fix rkhunter template for arm-qa machines that has been wrong for a long time.
2013-12-21 16:45:19 +00:00
Stephen Smoogen
5e7d24235d
Added host_update box
2013-12-20 21:47:29 +00:00
Kevin Fenzi
e0fae8047a
Space the final fronteer...
2013-12-20 21:12:26 +00:00
Ricky Elrod
1099884833
Fix deprecation warning
2013-12-20 20:02:19 +00:00
Ricky Elrod
8847d77310
Fix this too
2013-12-20 18:22:31 +00:00
Kevin Fenzi
773d8960ae
Need to include vars here if we are using them.
2013-12-20 18:17:02 +00:00
Pierre-Yves Chibon
acf3179581
Add context to the nuancier wsgi file
2013-12-20 17:29:22 +00:00
Pierre-Yves Chibon
0b6c42dcbf
Typo ftw
2013-12-20 17:01:53 +00:00
Pierre-Yves Chibon
ae2df0d7e8
Allow apache to read/use static content
2013-12-20 17:00:16 +00:00
Kevin Fenzi
96a2ed93d2
Adjust gnome-backups to use lock-wrapper
2013-12-20 14:21:37 +00:00
Stephen Smoogen
f16181a2f3
Hey ma. I think I broke my leg. Should this white thing be sticking out?
2013-12-20 01:17:06 +00:00
Ricky Elrod
faa0561ffb
Attempt to run the restart_unbound sequence on reboot if necessary.
2013-12-20 00:46:24 +00:00
Kevin Fenzi
efae484554
Workaround socket thing
2013-12-19 21:07:50 +00:00
Kevin Fenzi
792d904739
Try adding some parameters here.
2013-12-19 20:40:28 +00:00
Kevin Fenzi
d13c8a1adf
:
2013-12-19 20:27:50 +00:00
Kevin Fenzi
9ba0e4ef20
Lets try this to fix issues
2013-12-19 20:25:13 +00:00
Ralph Bean
a6723c336d
Add forgotten import.
2013-12-19 16:18:48 +00:00
Ralph Bean
81437a7caf
Forgot this.
2013-12-19 16:09:02 +00:00
Ralph Bean
efa041d89d
Add person if they do not exist.
2013-12-19 16:00:32 +00:00
Ralph Bean
0a836bf6af
Cronjob for awarding the mirror badge.
2013-12-19 15:56:55 +00:00
Ralph Bean
a9bc26b963
Correct smtp host for notifs backend.
2013-12-16 18:54:48 +00:00
root
33c3b190a1
Fix path to the key
2013-12-15 21:11:28 +00:00
Patrick Uiterwijk
d3f7fb49ba
Close the if and put lockfile in home
2013-12-15 20:58:43 +00:00
Patrick Uiterwijk
7f78117fea
Add locking into GNOME backup script
2013-12-14 14:11:06 +00:00
Patrick Uiterwijk
a84df969da
This should only run once an hour....
2013-12-14 14:02:47 +00:00
Patrick Uiterwijk
1ab1d5bb38
More typos in the script...
2013-12-13 22:57:28 +00:00
Patrick Uiterwijk
f5c5807cee
Bash is doing some weird expansion
2013-12-13 22:54:46 +00:00
Patrick Uiterwijk
0145714f29
Options need to be here as well....
2013-12-13 22:28:22 +00:00
Patrick Uiterwijk
bd8f37aa8a
Merge branch 'master' of /git/ansible
2013-12-13 21:57:29 +00:00
Patrick Uiterwijk
e0cb3edb43
Fix some errors
2013-12-13 21:56:56 +00:00
Andrea Veri
45a09b21ed
Fix typo
2013-12-13 21:40:06 +00:00
Andrea Veri
583c0b729d
Drop the quotes before the loop
2013-12-13 21:39:17 +00:00
Andrea Veri
325cd11b3d
Do the same on the ipless boxes
2013-12-13 21:32:15 +00:00
Andrea Veri
7d54eb0775
Put all the machines on the same line
2013-12-13 21:29:32 +00:00
Patrick Uiterwijk
21934951c2
This should be underscore...
2013-12-13 21:16:48 +00:00
Patrick Uiterwijk
68eb24188b
Ansible is being annoying (selinux on nfs is not funny)
2013-12-13 21:14:23 +00:00
Andrea Veri
3687b44a84
We want the root user to access the machines
2013-12-13 20:42:36 +00:00
Patrick Uiterwijk
6c42b2420a
it's fedora_backups
2013-12-13 20:36:57 +00:00
Andrea Veri
e22f764ae2
Add the backup.sh file for the GNOME nightly backups
2013-12-13 20:21:14 +00:00
Andrea Veri
5392e2966f
Add the needed setup for the nightly GNOME backups to happen
2013-12-13 20:14:20 +00:00
Ralph Bean
3ee79e5e24
Add gcm vars for notifs backend.
2013-12-13 16:55:15 +00:00
Ricky Elrod
b6c1c67545
add fail2ban because access_log spam is annoying
2013-12-12 22:26:10 +00:00
Pierre-Yves Chibon
56d6699804
Add one more dependency to install on the builder
2013-12-12 16:37:04 +01:00
Ralph Bean
3e20afa366
pull in prod messages to test fmn in stg.
2013-12-12 04:44:53 +00:00
Ralph Bean
0d4daa0d8c
It's not enough to simple say that we're skipping. We have to actually skip.
2013-12-11 19:07:45 +00:00
Ralph Bean
1161cb2c64
Avoid awarding the badge multiple times.
2013-12-11 18:50:13 +00:00
Ralph Bean
97cca8dab9
More careful with results.
2013-12-11 18:36:04 +00:00
Ralph Bean
b4fa4af74a
Update hosts file for badges-backend.
2013-12-11 18:27:04 +00:00
Ralph Bean
77da05b75b
Set sqlalchemy version constraint for setuptools.
2013-12-11 18:11:27 +00:00
Ralph Bean
ddc86bcaf3
Rename.
2013-12-11 18:04:53 +00:00
Ralph Bean
2acec935fa
Scripts, cron, and config for the flock paparazzi badge.
2013-12-11 18:04:22 +00:00
Ralph Bean
9835360d33
Require libsemanage-python.
2013-12-11 17:45:55 +00:00
Kevin Fenzi
173dbbb4b9
Dho. Helps to save the file you are editing.
2013-12-10 19:56:17 +00:00
Ralph Bean
ef4aba69a0
Quote that.
2013-12-10 19:50:29 +00:00
Kevin Fenzi
e20ea5e6cc
Update size on f19 jenkins. Make f20 builder.
2013-12-10 19:47:59 +00:00
Ralph Bean
e941d65c5e
Correct directory.
2013-12-10 19:43:25 +00:00
Ralph Bean
dbf61f1fbf
Some configuration for the fmn frontend.
2013-12-10 19:41:42 +00:00
Ralph Bean
3ae23a63c5
Enable logging for fmn backend.
2013-12-10 18:56:54 +00:00
Ralph Bean
13330ad4eb
First stab at the notifications backend role.
2013-12-10 17:30:59 +00:00
Ralph Bean
b3f6aa6dac
Include libsemanage-python.
2013-12-10 17:04:15 +00:00
Ralph Bean
c9b28d8981
Ensure selinux lets notifs httpd talk to postgres.
2013-12-10 16:21:30 +00:00
Stephen Smoogen
815376cf32
Hey ma, I am moving hosts.
2013-12-09 22:24:18 +00:00
Ralph Bean
c23e9730fc
Apply selinux type to fmn static files.
2013-12-09 21:49:22 +00:00
Ralph Bean
c468d67ff7
seboolean form httpd->postgres.
2013-12-09 20:33:18 +00:00
Ralph Bean
f472d0bcb4
Change notifs db name.
2013-12-09 19:52:44 +00:00
Ralph Bean
41a1de454a
Hosts files for notifications staging nodes.
2013-12-09 19:37:53 +00:00
Ralph Bean
bc90ec2749
URL prefix for the notifs app.
2013-12-09 19:30:49 +00:00
Ralph Bean
ac29c19dd5
Move about.rst to the right place.
2013-12-09 19:15:51 +00:00
Ralph Bean
e5513c242f
Copy sitedocs for fmn.web.
2013-12-09 19:05:57 +00:00
Ralph Bean
ebae481ad8
2. psycopg2.
2013-12-09 18:57:42 +00:00
Ralph Bean
2e5f6a7404
Need psycopg2 there.
2013-12-09 18:46:54 +00:00
Ralph Bean
bd1b623111
Copy/pasta artifact.
2013-12-09 18:34:39 +00:00
Ralph Bean
9d36f8a375
First stab at a notifs-frontend role for staging.
2013-12-09 18:33:56 +00:00
Ralph Bean
35a6f991bf
Flip sign_and_import back to point at the testing repo.
2013-12-09 18:17:24 +00:00
Aurélien Bompard
1e0dda64d1
Use Memcached as the Django cache
2013-12-06 16:56:46 +00:00
Aurélien Bompard
1e07f9075f
SELinux fixes
2013-12-06 16:56:46 +00:00
Aurélien Bompard
e2cd562825
Don't always refresh the cache on import
2013-12-06 16:56:46 +00:00
Aurélien Bompard
590a669f05
Install the cache cronjob
2013-12-06 16:56:46 +00:00
Aurélien Bompard
13f3afebad
Redirect to the list index from the server's front page
2013-12-06 16:56:46 +00:00
Aurélien Bompard
f2f6f56a98
Autodetect when logs should be reopen
2013-12-06 16:56:46 +00:00
Aurélien Bompard
7429218a4b
Upstream modification
2013-12-06 16:56:46 +00:00
Kevin Fenzi
68af71f0b4
Set buildvm-27 (not in production/existance) to use the test fedora 20 kickstart
2013-12-05 21:39:04 +00:00
Ralph Bean
2076a56e79
Only retroactively award badges to people who are actually approved in certain groups. Duh.
2013-12-03 14:19:39 +00:00
Miroslav Suchý
baa241b9de
copr - do not overwrite mockchain
...
we use updated mock(chain) from repo where it is properly build patched version
2013-11-28 08:53:38 +00:00
Nick Bebout
4c8643b4eb
Add zimmermann.mayfirst.org to SKS membership
2013-11-27 21:41:10 +00:00
Miroslav Suchý
02add69aaf
add patched mock to Copr builders
...
until this bugs are fixed in distribution
2013-11-27 08:01:34 +00:00
Kevin Fenzi
27db174cff
Make ntpdate a global
2013-11-26 00:14:24 +00:00
Kevin Fenzi
c966c9aaff
No more bacula
2013-11-25 22:16:42 +00:00
Kevin Fenzi
29864b8d57
Add accel, clean up old fireball stuff
2013-11-25 21:25:33 +00:00
Kevin Fenzi
a7350d64a5
Add libsemanage-python to nuancier
2013-11-25 21:01:49 +00:00
Kevin Fenzi
9017d6c2ff
Make keyserver playbook accelerated
2013-11-25 21:01:33 +00:00
Kevin Fenzi
0814f8c6f6
One too many (s
2013-11-25 19:39:00 +00:00
Kevin Fenzi
69a5e8e572
Accelerate all the things.
2013-11-25 19:31:25 +00:00
Kevin Fenzi
4ea8fb7509
Nuke some more only_if stragglers
2013-11-25 19:10:22 +00:00
Kevin Fenzi
f0a29df52d
Goodbye only_if... when is the new thing.
2013-11-25 19:05:48 +00:00
Kevin Fenzi
e18d833494
Perhaps we need to group this.
2013-11-25 18:57:16 +00:00
Kevin Fenzi
3667001df1
Update base playbook to not set rootpw on releng and add accel stuff in iptables for releng.
2013-11-25 18:48:47 +00:00
Kevin Fenzi
0dd87ee096
Fix hosts in the second play too.
2013-11-25 18:43:22 +00:00
Kevin Fenzi
494ec1033e
See if this gets check mode happy with the libvirt call
2013-11-25 18:41:58 +00:00
Kevin Fenzi
f1d4e575f0
And of course it needs to be quoted.
2013-11-25 18:37:51 +00:00
Kevin Fenzi
1043af18d2
vhost is a variable too
2013-11-25 18:36:54 +00:00
Kevin Fenzi
5e6941493d
Update syntax
2013-11-25 18:33:35 +00:00
Kevin Fenzi
1cb8b9a6e7
This playbook is only for releng01/02 for now.
2013-11-25 18:26:09 +00:00
Kevin Fenzi
3d1ae260e5
Just the facts mam
2013-11-25 18:13:25 +00:00
Kevin Fenzi
41aa28ceb8
Add bkernel group vars
2013-11-25 18:11:52 +00:00
Kevin Fenzi
9a54539814
Fix up bkernel playbooks some more. Use base role.
2013-11-25 18:08:13 +00:00
Kevin Fenzi
cf55b4ecad
Fix typo
2013-11-25 17:58:20 +00:00
Ralph Bean
4391055257
First try at fmn playbooks.
2013-11-25 17:39:28 +00:00
Ralph Bean
e4cc2e8ba3
Forgot the actual inventory entries.
2013-11-25 17:35:56 +00:00
Ralph Bean
e94575305b
Inventory entries for notifications stg machines.
2013-11-25 17:32:50 +00:00
Kevin Fenzi
d160697c21
Fix up some buildvm stuff
2013-11-23 20:39:26 +00:00
Stephen Smoogen
c165cf7746
Merge branch 'master' of /git/ansible
...
Conflicts:
playbooks/vhost_update.yml
2013-11-22 22:11:49 +00:00
Stephen Smoogen
0e55c85cbf
Ok this works for vhost08
2013-11-22 22:03:52 +00:00
Kevin Fenzi
5e3dd3803f
Hacky little script to restart unbound (it doesn't start on boot due to selinux issues)
2013-11-22 16:21:31 +00:00
Pierre-Yves Chibon
804d2948dd
Reduce the verbosity of sqlalchemy in the logs
2013-11-22 11:11:44 +01:00
Kevin Fenzi
07c21f1a16
Perhaps it hates the newlines
2013-11-22 00:09:29 +00:00
Kevin Fenzi
4164ec60b8
Not!
2013-11-21 22:41:51 +00:00
Kevin Fenzi
c53b368450
More fixes
2013-11-21 22:07:02 +00:00
Kevin Fenzi
33ddc75b18
Fix syntax on reboot playbook
2013-11-21 22:02:15 +00:00
Kevin Fenzi
8462c0407e
Update for current syntax, reorder, add serverbeach thing.
2013-11-21 21:52:05 +00:00
Kevin Fenzi
04498829a1
Fix up for new syntax and make faster.
2013-11-21 21:37:43 +00:00
Kevin Fenzi
fd8d810fda
Add a ntpdate after the vhost comes back up.
2013-11-21 20:36:36 +00:00
Kevin Fenzi
682d67a5ad
Try and fix this stg downtime issue.
2013-11-21 20:19:48 +00:00
Ralph Bean
2f6fd14d58
Aim sign_and_import at the prod infra repo for now.
2013-11-21 10:24:49 +00:00
Ralph Bean
45932af564
Try to wait for downed vguests in parallel.
2013-11-21 10:24:17 +00:00
Kevin Fenzi
6693c72a45
Increase downtime to 30min
2013-11-19 19:53:27 +00:00
Ralph Bean
82deb4e6ff
Revert "Reduce cache time to workaround heartbeat issue for now."
...
This reverts commit 507701dd15 .
2013-11-18 21:28:17 +00:00
Ralph Bean
507701dd15
Reduce cache time to workaround heartbeat issue for now.
2013-11-18 20:50:31 +00:00
Kevin Fenzi
4de2ecac8b
Don't set rootpw on build* machines, it's set later in their playbooks
2013-11-18 20:32:54 +00:00
Kevin Fenzi
abd631df2b
Move the netapp storage route to a handler
2013-11-18 20:32:28 +00:00
Kevin Fenzi
01869f4cdb
Move 07/08/09
2013-11-18 19:33:48 +00:00
Kevin Fenzi
48abe3fbbe
How about this?
2013-11-18 19:19:07 +00:00
Kevin Fenzi
8f46c63f59
Try and convert this to new syntax. Hope it works.
2013-11-18 19:13:20 +00:00
Kevin Fenzi
063550bb38
Move 04/05/06
2013-11-18 18:46:17 +00:00
Kevin Fenzi
0ef5203ea2
Move builvm-02/03 too
2013-11-18 18:24:08 +00:00
Kevin Fenzi
04495398e4
Move buildvm-01 over to new buildvmhost-10
2013-11-18 18:10:29 +00:00
Aurélien Bompard
7bae9777c4
mailman: fix SELinux context issues
...
And run the post-update script in a yum-post-transaction action.
2013-11-15 16:57:35 +00:00
Dennis Gilmore
71dbd1453b
fixup koji.conf
2013-11-15 14:30:34 +00:00
Pierre-Yves Chibon
76b42846cd
Add /etc/hosts files for fedocal
2013-11-14 19:22:23 +01:00
Pierre-Yves Chibon
dfb97356be
Enable the fedocal playbook on fedocal - prod
2013-11-14 18:51:45 +01:00
Pierre-Yves Chibon
6284895aaf
Update virtualhost and vgroup for fedocal01 and fedocal02
2013-11-14 18:50:27 +01:00
Dennis Gilmore
7f7882c65f
kickoff buildbranched and build rawhide earlier
2013-11-14 15:41:47 +00:00
Dennis Gilmore
2088e559c8
start rawhide an hour earlier
2013-11-14 15:41:47 +00:00
Pierre-Yves Chibon
a93b1e8204
Add host_vars files for fedocal01/02 in prod
2013-11-14 15:07:15 +01:00
Miroslav Suchý
aedf904ccf
copr - write IP address to stdout
2013-11-14 08:32:22 +00:00
Dennis Gilmore
8c1048b8a1
make sure compose boxes have ksflatten
2013-11-13 23:28:17 +00:00
Dennis Gilmore
d9fa9cd113
make sure the masher cert and koji cacerts are available on compose boxes
...
make sure koji.conf uses the certs
2013-11-13 23:18:53 +00:00
Kevin Fenzi
c07c7e30c7
Add wiki attachments to be backed up by rdiff-backup
2013-11-13 21:52:58 +00:00
Pierre-Yves Chibon
11dffeb8ab
Add tito on the Fedora nodes
2013-11-13 14:59:37 +01:00
Dennis Gilmore
7ad6d08614
make sure uboot-tools is in on arm chroots, dont install joe
2013-11-12 22:30:08 +00:00
Ralph Bean
ab4fc88277
Add fedmsg cert declarations for fedocal.
2013-11-12 21:37:15 +00:00
Pierre-Yves Chibon
429a3de480
Fix typo, fedocal does not use the nuancier database
2013-11-12 19:32:36 +01:00
Pierre-Yves Chibon
3da54da606
Add libsemanage-python on fedocal
2013-11-12 19:23:04 +01:00
Pierre-Yves Chibon
81b6046710
Ignore the DB creation part for now
2013-11-12 19:12:47 +01:00
Pierre-Yves Chibon
94756d80a9
Wrong name format for the hosts file on fedocal01.stg
2013-11-12 19:06:05 +01:00
Pierre-Yves Chibon
d747341f14
Add a hosts file for fedocal01.stg
2013-11-12 18:16:05 +01:00
Pierre-Yves Chibon
9da7b06b8d
Add the fedocal01.stg host_vars file
2013-11-12 17:25:57 +01:00
Pierre-Yves Chibon
b14f5a4a0b
list fedocal-stg as a staging node
2013-11-12 16:50:40 +01:00
Pierre-Yves Chibon
66b107d0d5
Add the fedocal group_vars files
2013-11-12 16:49:04 +01:00
Pierre-Yves Chibon
1f96795e5b
Add fedocal-stg to the inventory
2013-11-12 16:36:54 +01:00
Pierre-Yves Chibon
3fc278dadb
Update files part of fedocal configuration
2013-11-12 15:34:33 +00:00
Pierre-Yves Chibon
69de001b01
Add first elements for fedocal in ansible
2013-11-12 16:15:59 +01:00
Miroslav Suchý
7798d5b5c0
forward emails to root on copr machines to me
2013-11-11 16:35:52 +00:00
Miroslav Suchý
cecfac8454
add copr.conf
2013-11-11 16:25:46 +00:00
Miroslav Suchý
fe702d32ea
open ports 22, 80, 443 on coprs machines
2013-11-11 15:12:22 +00:00
Miroslav Suchý
dd111ea27e
could not use external ip
...
due routing set up in fedora instance of open stack. We have to use internal ip.
2013-11-11 15:12:22 +00:00
Miroslav Suchý
5dc0a7cdcb
add in copr config passwords from private variables
2013-11-11 15:12:22 +00:00
Ralph Bean
7123aa80ca
Only use proxy01 for incoming fedmsg.
2013-11-08 19:00:45 +00:00
Ralph Bean
99f5adf002
Add link to upstream ticket in a comment.
2013-11-08 19:00:45 +00:00
Miroslav Suchý
df81d82756
add fedora 20 mock config
...
mock in epel does not have this, add it manually
2013-11-08 16:07:24 +00:00
Ralph Bean
bd75546240
List the external proxy in fedmsg's relay_inbound.
2013-11-08 15:19:57 +00:00
Ralph Bean
f390c09c3f
Use correct cert-prefix and hostname for copr-be fedmsg cert declaration.
2013-11-08 14:58:33 +00:00
Ralph Bean
4648705142
Comment out the fedmsg_certs var for copr-be.
2013-11-08 14:51:56 +00:00
Ralph Bean
c3097c760c
Handle fedmsg keys explicitly at the end of the copr-be playbook.
2013-11-08 14:49:54 +00:00
Ralph Bean
85b05e9368
Try passing ansible_fqdn directly to the role as an argument.
2013-11-08 14:46:16 +00:00
Ralph Bean
b0efbaa648
Remove reference to the fedmsg "shell" cert for copr-be.
2013-11-08 14:44:24 +00:00
Ralph Bean
72f06125c9
Try redefining ansible_fqdn in the copr-be playbook.
2013-11-08 14:43:30 +00:00
Ralph Bean
f87358058a
Add copr-be fedmsg cert declaration.
2013-11-08 14:36:17 +00:00
Miroslav Suchý
17ebf01809
add fedmsg roles to copr-be playbook
2013-11-08 14:31:24 +00:00
Miroslav Suchý
e3bbd59544
add fedmsg certs to copr-be
2013-11-08 14:27:13 +00:00
Aurélien Bompard
f4b462668d
mailman: fix SELinux-related problems
2013-11-08 09:12:56 +00:00
Aurélien Bompard
40d85f141a
mailman: fix domain names in the postfix config
2013-11-08 08:32:23 +00:00
Aurélien Bompard
d66182fb66
mailman: don't put apache conf outside /etc/httpd
...
...or selinux won't be happy
2013-11-08 08:26:59 +00:00
Ralph Bean
d808f3b70f
Comment out the post update task for now.
2013-11-07 16:45:45 +00:00
Ralph Bean
1632b1e855
Move the fedmsg role after the mailman one.
2013-11-07 16:40:54 +00:00
Kevin Fenzi
f43489746f
Bump size up to 250G and set accel mode for mailman01.stg
2013-11-07 16:25:01 +00:00
Ralph Bean
c5e6012cc7
Add mailman01.stg to the [staging] group.
2013-11-07 15:58:26 +00:00
Ralph Bean
c06416d746
Typofix to mailman fedmsg endpoint definition.
2013-11-07 15:52:28 +00:00
Ralph Bean
13eacb75ab
Add that fedmsg role back in.
2013-11-07 15:49:25 +00:00
Ralph Bean
8e258ed3c5
Temporarily remove the fedmsg role.
2013-11-07 15:21:59 +00:00
Ralph Bean
6a9865150b
Add the fedmsg role to the mailman playbook.
2013-11-07 14:41:40 +00:00
Ralph Bean
ba9027ef15
fedmsg for mailman01.stg.
2013-11-07 14:37:15 +00:00
Ralph Bean
3e466a7cf3
Add sysadmin-main as a fas client group for mailman nodes.
2013-11-07 14:32:49 +00:00
Aurélien Bompard
40f480d1aa
mailman: a few fixes
2013-11-07 13:48:59 +00:00
Patrick Uiterwijk
0f804a78de
Master needs git for git polling
2013-11-06 19:01:08 +00:00
Patrick Uiterwijk
0f18e74b42
Add some packages to jenkins for Cockpit
2013-11-06 18:12:49 +00:00
Miroslav Suchý
78456d395a
copr-be do not use that 200 GB volume anymore
2013-11-06 10:06:35 +00:00
Miroslav Suchý
c5b7657d4d
add 800 GB volume to copr-be
2013-11-06 10:06:35 +00:00
Miroslav Suchý
12f4c14bf3
secure copr with fail2ban
2013-11-06 10:06:35 +00:00
Kevin Fenzi
91ea3da106
Set back to BuildGuests
2013-11-06 04:20:47 +00:00
Kevin Fenzi
b54be7e34f
Try a local hw version now.
2013-11-06 01:57:36 +00:00
Kevin Fenzi
8bbb60bb4a
Put this on the other iscsi volume for testing.
2013-11-05 23:05:03 +00:00
Kevin Fenzi
6c162cc357
Fix conditional
2013-11-05 20:49:27 +00:00
Kevin Fenzi
b680031fbe
Add a buildvm-27 to test with on new blade server.
2013-11-04 21:51:42 +00:00
Tim Flink
5a2089059a
configuring backups for qadevel.cloud.fedoraproject.org
2013-11-01 22:00:16 +00:00
Kevin Fenzi
15d4338a74
Right, try this
2013-10-31 17:32:36 +00:00
Kevin Fenzi
d3ed2cdf29
Are we having fun yet?
2013-10-31 17:28:08 +00:00
Kevin Fenzi
db4bf82053
Further adventures
2013-10-31 17:26:06 +00:00
Kevin Fenzi
864048c600
More fun
2013-10-31 17:23:14 +00:00
Kevin Fenzi
664dbb7f79
Ok, lets try this one instead
2013-10-31 17:14:37 +00:00
Kevin Fenzi
6401b15958
Double quotes?
2013-10-31 17:07:59 +00:00
Kevin Fenzi
1320997020
Try this conditional
2013-10-31 17:04:36 +00:00
Kevin Fenzi
88141db150
Add other netapp iscsi for buildvmhosts only.
2013-10-31 16:52:29 +00:00
Kevin Fenzi
4c9c64032e
Re-enable pkgs /srv backups, it was a trailing slash issue.
2013-10-30 14:02:05 +00:00
Kevin Fenzi
3353e6dcfe
This is still not right, disable again.
2013-10-29 21:55:39 +00:00
Kevin Fenzi
ef0816e76b
Add _other_ netapp iscsi for this.
2013-10-29 20:56:46 +00:00
Pierre-Yves Chibon
bb1a968a5f
New plugin required by the git plugin
2013-10-29 13:36:34 +01:00
Pierre-Yves Chibon
8c8d69be2a
Add pycairo-devel and gtk3-devel on builders
2013-10-29 13:09:11 +01:00
Kevin Fenzi
b959693e2b
Exclude all .snapshot dirs from rdiff-backups
2013-10-28 17:46:46 +00:00
Kevin Fenzi
d081700166
Readd /srv backup on pkgs01 since the backup dir is fixed now.
2013-10-28 16:21:41 +00:00
Pierre-Yves Chibon
087a4d3042
Let's try to specify the resolv.conf to use
2013-10-28 15:30:47 +01:00
Pierre-Yves Chibon
4550c762a4
Fix indentation
2013-10-28 15:19:10 +01:00
Pierre-Yves Chibon
68f1dcf589
Replace IP by host group - let's see if that helps for the resolv.conf
2013-10-28 15:18:29 +01:00
Pierre-Yves Chibon
02d18fbcb5
Update jenkins' plugins
2013-10-28 15:11:37 +01:00
Pierre-Yves Chibon
bd4fef12fc
Add the new builder to jenkins
2013-10-28 11:42:48 +00:00
Pierre-Yves Chibon
5306d96489
Apparently emi identifiers are in fact ami
2013-10-28 11:26:41 +00:00
Pierre-Yves Chibon
6b2c0c6c69
Move extra vars
2013-10-28 12:16:27 +01:00
Pierre-Yves Chibon
46646b2b96
Add more variable to create the instances
2013-10-28 11:47:18 +01:00
Pierre-Yves Chibon
7a6ede545a
Remove duplicated task
2013-10-28 11:39:42 +01:00
Pierre-Yves Chibon
255b683db1
Try adding a F19 builder to jenkins
2013-10-28 11:17:49 +01:00
Pierre-Yves Chibon
1749b4edf3
Update postfix on jenkins master to its own configuration file
...
Bastion is not accessible internally for the cloud instances which
thus cannot use it as relay to send emails. This change create a
dedicated postfix configuration file to be used by jenkins telling
it not to use a relay but to send the emails directly.
2013-10-28 09:38:40 +00:00
Aurélien Bompard
39d7e899cd
mailman: path fix again
2013-10-28 08:21:06 +00:00
Ralph Bean
6f434565fd
Add python-rdflib for the badges frontend.
2013-10-26 02:24:53 +00:00
Kevin Fenzi
d289b06d37
Have to rm the file, just commenting doesn't work.
2013-10-25 22:47:04 +00:00
Kevin Fenzi
c223eaadd5
Don't backup /srv on pkgs right now, trying to fix it's backup.
2013-10-25 21:27:35 +00:00
Kevin Fenzi
cb7dee0e9e
chdir is a argument to command module
2013-10-25 17:38:06 +00:00
Aurélien Bompard
344366a538
mailman: fix the path in a script
2013-10-25 14:23:16 +00:00
Aurélien Bompard
5264983303
lists-dev: enable services by default
2013-10-25 13:53:10 +00:00
Aurélien Bompard
8cff41661a
Tested the mailman 2->3 migration
2013-10-25 12:23:50 +00:00
Miroslav Suchý
1b5f78cd49
update host variable for copr
...
use f19
update keypair on copr-fe
volume vol-00000007 on copr-be is no longer needed (former /srv/copr-work)
2013-10-25 09:49:40 +00:00
Miroslav Suchý
2a1aa83748
update copr-fe.cloud.fedoraproject.org.yml
...
copy copr-fe-dev to copr-fe, but preserve mount points
2013-10-25 09:40:51 +00:00
Miroslav Suchý
366ff69c67
update copr-be.cloud.fedoraproject.org.yml
...
copy copr-be-dev to copr-be, but preserve mount points
and remove /srv/copr-work which is no longer needed
2013-10-25 09:32:31 +00:00
Kevin Fenzi
ee8363b971
Drop aarch64 koji hub and db server. They are just going to use the arm koji.
2013-10-22 19:37:05 +00:00
Ralph Bean
fa75ca9b35
Set up sign_and_import.yml to point at the testing repo for the freeze.
2013-10-22 18:20:15 +00:00
Pierre-Yves Chibon
8ab3080dc2
Add postgresql-devel to builders
2013-10-22 15:13:50 +02:00
Pierre-Yves Chibon
7876109563
add python-psycopg2 as requirement for jenkins
2013-10-22 11:39:46 +02:00
Kevin Fenzi
2917423cfa
Add correct volume name here.
2013-10-18 21:16:26 +00:00
Miroslav Suchý
966efcc06e
umask result dir with 0000
2013-10-17 07:47:54 +00:00
Pierre-Yves Chibon
bc99cf9a48
Add example for icmp
2013-10-16 21:09:20 +02:00
Miroslav Suchý
8b7ebbe5d9
document is just public_html, /result is referenced relative to it
2013-10-16 13:26:45 +00:00
Pierre-Yves Chibon
5ea98d6f9d
Apparently order matters
2013-10-16 12:00:11 +02:00
Miroslav Suchý
915d874b1b
install selinux before adding additional repos
...
and well install all base packages before adding additional repos
addressing:
TASK: [add repos] *************************************************************
failed: [172.16.3.4] => (item=builder.repo) => {"failed": true, "item": "builder.repo"}
msg: Aborting, target uses selinux but python bindings (libselinux-python) aren't installed!
2013-10-15 13:38:55 +00:00
Patrick Uiterwijk
c3da3d408c
Add python-selinux to copr builders
2013-10-15 11:56:53 +00:00
Miroslav Suchý
0661687464
create empty known_hosts
...
adressing warings from ansible:
previous known host file not found
2013-10-15 11:52:46 +00:00
Miroslav Suchý
49badcc891
do not use known_hosts
...
we connect just to builders, and key there change
paramiko ignore .ssh/config but obey host_key_checking
Unless it make some problem later, I would rather use ssh for transport
so it is the same as I use in debugging.
2013-10-15 09:25:26 +00:00
Ralph Bean
3dbdfde65c
Move fedmsg_base stuff from a task to a role.
...
Submitted by janeznemanic for
https://fedorahosted.org/fedora-infrastructure/ticket/4011
2013-10-15 03:40:57 +00:00
Stephen Smoogen
c7eba1f37b
ooops no trailing :
2013-10-14 20:23:23 +00:00
Stephen Smoogen
6e4e1ea554
So let us see how many builders can build.
2013-10-14 20:10:56 +00:00
Kevin Fenzi
172f73275f
Move this from using a target to a regular hostlist. Add hosts we have moved to ansible.
2013-10-14 20:06:00 +00:00
Patrick Uiterwijk
fa09b80aee
Do jenkins as well
2013-10-14 17:33:10 +00:00
Patrick Uiterwijk
b9d8de2061
Add cloud group and resolv.conf
2013-10-14 17:29:13 +00:00
Pierre-Yves Chibon
545d915207
Update the nuancier playbook
...
- Remove hotfix which are now included in 0.1.2
- Let the playbook set the SELinux boolean since the dependency is now installed
by role/base
2013-10-14 19:01:00 +02:00
Pierre-Yves Chibon
0a63a867c0
Remove duplicate action, libselinux-python is install 2 tasks below
2013-10-14 18:45:50 +02:00
Pierre-Yves Chibon
4c6b323d3e
Replace the postfix task by using the base role
2013-10-14 18:43:29 +02:00
Pierre-Yves Chibon
29a3b73a70
Make sure required package are installed
2013-10-14 18:21:44 +02:00
Pierre-Yves Chibon
db06546855
Replace only_if by when
2013-10-14 18:07:46 +02:00
Pierre-Yves Chibon
ebd347f0b0
Update packages to be installed on the builder
2013-10-14 17:46:51 +02:00
Patrick Uiterwijk
db6c34e8dd
Update to new syntax
2013-10-13 23:13:13 +00:00
Patrick Uiterwijk
89214e0649
Add a hotfix
2013-10-13 23:05:17 +00:00
Patrick Uiterwijk
fbcca88364
Reorder this to test
2013-10-13 22:49:31 +00:00
Patrick Uiterwijk
dac6c2b5be
Reorder this to test
2013-10-13 22:48:56 +00:00
Patrick Uiterwijk
03dd6b8584
Reorder this to test
2013-10-13 22:47:49 +00:00
Patrick Uiterwijk
aaaed3a018
Update this to new syntax
2013-10-13 22:46:39 +00:00
Patrick Uiterwijk
be8d98470b
Primary gallery stuff
2013-10-13 22:05:13 +00:00
Patrick Uiterwijk
2cd3301ed5
Merge branch 'master' of /git/ansible
2013-10-13 22:03:28 +00:00
Miroslav Suchý
657502e256
do not validate https certificates
...
workaround for https://bugzilla.redhat.com/show_bug.cgi?id=1003105
2013-10-10 11:11:50 +00:00
Stephen Smoogen
5a28c20233
And now we have some hosts.
2013-10-09 22:30:41 +00:00
Ralph Bean
8e9bef899e
Nicer fedmsg logging.
2013-10-09 13:25:12 +00:00
Patrick Uiterwijk
86fb4d55a6
puiterwijk is also tahrir admin
2013-10-08 12:40:34 +00:00
Toshio くらとみ
08b8f89177
Hotfixes for nuancier
2013-10-05 03:11:00 +00:00
Toshio くらとみ
3be1c20a1e
Two nuancier files from the rpm that are going to be hotfixed
2013-10-05 03:09:22 +00:00
Toshio くらとみ
fea1853b9c
Couple hotfixes to nuancier
2013-10-05 03:04:23 +00:00
Toshio くらとみ
106c831ae1
selinux: httpd_can_connect_db set
2013-10-05 02:33:10 +00:00
Miroslav Suchý
a7890c6874
enable ssh_sysadm_login sebool for all clouds
...
addressing:
type=AVC msg=audit(1380833385.268:173): avc: denied { getattr } for pid=781 comm="sshd" path="/root/.ssh/authorized_keys" dev="vda1" ino=6493 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:file_t:s0 tclass=file
2013-10-04 07:36:31 +00:00
Miroslav Suchý
c0d3729ce2
update playbooks for copr-be-dev
2013-10-03 20:37:34 +00:00
Miroslav Suchý
7a309f3f86
use internal ip address for copr.repo
2013-10-03 12:45:27 +00:00
Stephen Smoogen
d9ae1269d1
Added IUD
2013-10-03 01:20:21 +00:00
Kevin Fenzi
d897a71e5d
Try this
2013-10-03 00:22:39 +00:00
Kevin Fenzi
6c55c0dda0
Fine then, bump it a bit more
2013-10-03 00:18:41 +00:00
Kevin Fenzi
6db6af6afb
Adjust nrpe values for these virthosts.
2013-10-02 15:59:46 +00:00
Kevin Fenzi
9b97078b2a
Fix nagios in vhost_reboot
2013-10-02 19:40:24 +00:00
Stephen Smoogen
80d5497bdd
Add vhost15
2013-10-01 22:52:33 +00:00
Kevin Fenzi
5fe0dc0037
Add a iscsi_client role, add to virthosts
2013-10-01 16:50:55 +00:00
Aurélien Bompard
99c56cb70d
Mailman: adjust path in script
2013-10-01 15:41:13 +00:00
Aurélien Bompard
5ac9c05154
Stupid typo
2013-10-01 14:52:38 +00:00
Aurélien Bompard
df75244847
Fix linebreak
2013-10-01 14:47:19 +00:00
Aurélien Bompard
ca61692776
OK I spotted my syntax error this time
2013-10-01 14:11:12 +00:00
Aurélien Bompard
7ffbb98c70
Fix syntax
2013-10-01 14:02:01 +00:00
Aurélien Bompard
0677e06d50
Mailman: enable the prototype archiver
2013-10-01 13:55:38 +00:00
Aurélien Bompard
a7b83a7f28
Setup HyperKitty and Postorius in the same Django instance
2013-10-01 13:55:38 +00:00
Aurélien Bompard
c50469ade8
The httpd init script should be executable
2013-10-01 13:55:38 +00:00
Patrick Uiterwijk
4dcc5ae689
This code is running as tahrir:tahrir
2013-10-01 08:54:21 +00:00
Kevin Fenzi
9570a444a3
I guess we never got groups working with this.
2013-09-30 22:54:29 +00:00
Kevin Fenzi
06a239ac71
Add shogun-ca instance per ticket 4032
2013-09-30 22:52:08 +00:00
Kevin Fenzi
ff67503a15
Accel the update playbook
2013-09-30 18:15:41 +00:00
Pierre-Yves Chibon
978f481d55
Add dogpile dependency and configuration to nuancier
2013-09-30 13:12:04 +00:00
Ralph Bean
55d12dc69b
Accelerate mode on for the badges playbooks.
2013-09-27 14:38:51 +00:00
Ralph Bean
078dde5680
Correct perm for fedmsg keys.
2013-09-27 13:59:50 +00:00
Ralph Bean
114ed6a719
Cosmetic. Indent this fedmsg task.
2013-09-27 13:59:29 +00:00
Pierre-Yves Chibon
6b148f50bc
Thou shall not ammend and forget the file
2013-09-27 09:53:25 +00:00
Pierre-Yves Chibon
e1a48e15f7
Add missing dependencies on python-openid-cla and python-openid-teams
2013-09-27 09:49:40 +00:00
Pierre-Yves Chibon
6485c98878
Don't forget the configuration now
2013-09-27 09:46:27 +00:00
Pierre-Yves Chibon
1a22da9dc1
Add quick and dirty hotfix for flask_fas_openid
2013-09-27 09:43:47 +00:00
Patrick Uiterwijk
56b43fde5a
Remove this line, as it was not needed
2013-09-27 07:00:44 +00:00
Kevin Fenzi
4c4ad6cefd
Update keypair to the new one
2013-09-26 21:34:09 +00:00
Nick Bebout
535c634d69
Add update_dns playbook
2013-09-26 21:33:03 +00:00
Miroslav Suchý
46409f50bd
fix typo
...
addressing:
ERROR: Syntax Error while loading YAML script, /srv/web/infra/ansible/playbooks/hosts/copr-fe-dev.cloud.fedoraproject.org.yml
Note: The error may actually appear before this position: line 33, column 5
action: yum state=installed pkg=$item
- copr-frontend
^
2013-09-26 21:15:22 +00:00
Ricky Elrod
e2efb2d1d9
more when_integer -> when changes
2013-09-26 20:04:28 +00:00
Ricky Elrod
5452ab5346
add a task to install libselinux-python so ansible doesn't abort.
2013-09-26 19:55:23 +00:00
Ricky Elrod
c17fe661c4
try when instead of when_integer?
2013-09-26 19:28:00 +00:00
Ricky Elrod
c4451ee680
try quotes?
2013-09-26 18:49:57 +00:00
Ricky Elrod
442bef15b3
change this conditional to "when" syntax
2013-09-26 17:56:22 +00:00
Pierre-Yves Chibon
6309daa7f5
Add PREFERRED_URL_SCHEME to nuancier-lite seems to fix login
2013-09-26 17:47:32 +00:00
Ralph Bean
6014e19b6c
Rename incorrectly named files.
2013-09-26 16:11:57 +00:00
Ralph Bean
aa248e3d39
Typofix.
2013-09-26 15:48:08 +00:00
Ralph Bean
589f22d45f
Turn accelerate back on.
2013-09-26 15:44:25 +00:00
Ralph Bean
adfc5eaaaf
copy/pasta fix.
2013-09-26 15:44:13 +00:00
Ralph Bean
b2a1eef7c5
Move fedmsg to its own play so that users and groups are created first.
2013-09-26 15:44:01 +00:00
Ralph Bean
19cc07fcdd
Add hosts files for nuancier.
2013-09-26 15:39:44 +00:00
Ralph Bean
c5de102ff6
Turn off accelerate for now.
2013-09-26 15:30:55 +00:00
Ralph Bean
ca358cf22b
Setup accelerate mode beforehand.
2013-09-26 15:28:45 +00:00
Ralph Bean
1a7046f645
Turn on "accelerate".
2013-09-26 15:23:08 +00:00
Ralph Bean
767cd29c77
Try doing fedmsg last.
2013-09-26 15:22:18 +00:00
Ralph Bean
608b001d39
Typofix.
2013-09-26 14:58:21 +00:00
Ralph Bean
2d9a800f30
Update a number of only_if conditionals.
2013-09-26 14:57:26 +00:00
Ralph Bean
e2f1495aa9
Ensure libselinux-python is installed before we try to manage sshd_config.
2013-09-26 14:57:09 +00:00
Ralph Bean
a9b6ef9f11
Add the prod nuancier group to the nuancier playbook.
2013-09-26 14:46:07 +00:00
Ralph Bean
4b699a5675
Add inventory info for the nuancier prod nodes.
2013-09-26 14:45:14 +00:00
Ralph Bean
4b8c8951db
Declare fedmsg endpoints for nuancier.
2013-09-26 14:30:04 +00:00
Ralph Bean
1c4ed1ee9c
That, except not.
2013-09-26 14:21:14 +00:00
Ralph Bean
1f79455783
Try changing that only_if to a when statement.
2013-09-26 14:17:45 +00:00
Ralph Bean
a25767a969
Declare a fedmsg shell cert for the nuancier nodes.
2013-09-26 14:09:56 +00:00
Miroslav Suchý
fdf1217f48
update copr-fe-dev playbook
...
... to match last copr.rpm and copr-setup.txt
Also move to F19 as current Copr does not run on EL6
2013-09-26 12:54:08 +00:00
Kevin Fenzi
965e506f47
Accellerate all the things!
2013-09-25 21:01:45 +00:00
Kevin Fenzi
9245c6534f
Disable accel again to test speed
2013-09-25 20:58:13 +00:00
Kevin Fenzi
2394bfe6cc
Default env to produciton, override in staging vars
2013-09-25 20:55:47 +00:00
Kevin Fenzi
48e5075d85
Try this
2013-09-25 20:51:42 +00:00
Kevin Fenzi
54d4135670
Lets see if accelerate works. ;)
2013-09-25 20:36:01 +00:00
Kevin Fenzi
86bd1bc69a
Quotes?
2013-09-25 20:35:14 +00:00
Kevin Fenzi
e6025b6e8c
Might be it needs this.
2013-09-25 20:32:47 +00:00
Kevin Fenzi
612f2ac42f
Ok, how about this syntax?
2013-09-25 20:29:02 +00:00
Kevin Fenzi
6b9c8d954a
Try updating syntax here.
2013-09-25 20:25:26 +00:00
Kevin Fenzi
7e60bb96b0
Re-add the skip for not found on host task
2013-09-25 20:04:13 +00:00
Kevin Fenzi
be8a1cbb7a
Adjust template to handle undefined variables.
2013-09-25 20:02:25 +00:00
Kevin Fenzi
45495effe2
Also default custom_rules to empty
2013-09-25 19:58:45 +00:00
Kevin Fenzi
dbb59048db
Default iptables ports to empty for new ansible version that doesn't like undefined vars
2013-09-25 19:57:35 +00:00
Ralph Bean
363160651e
Point the sign_and_import script at the prod repo.
2013-09-25 15:07:05 +00:00
Pierre-Yves Chibon
d5171f3d50
Fix apache conf file for nuancier
2013-09-21 07:40:02 +00:00
Pierre-Yves Chibon
07afa13b9d
Revert "Revert "Fix prefix for nuancier""
...
This reverts commit 2f2ab18e4c .
2013-09-21 07:34:57 +00:00
Pierre-Yves Chibon
2f2ab18e4c
Revert "Fix prefix for nuancier"
...
This reverts commit 57cc4905f7 .
2013-09-20 19:54:31 +00:00
Pierre-Yves Chibon
57cc4905f7
Fix prefix for nuancier
2013-09-20 19:51:17 +00:00
Pierre-Yves Chibon
59eb33e493
Turn on debug for testing
2013-09-20 19:18:14 +00:00
Pierre-Yves Chibon
5b86013c07
Fix DB_URL for nuancier-lite
2013-09-20 19:16:19 +00:00
Pierre-Yves Chibon
524695d103
Add handler to nuancier playbook
2013-09-20 18:09:04 +00:00
Pierre-Yves Chibon
122769c32b
Rename nuancier.cfg
2013-09-20 18:06:18 +00:00
Kevin Fenzi
26c566750d
Try this
2013-09-20 17:42:54 +00:00
Pierre-Yves Chibon
141d91c73f
Back to the very original syntax
2013-09-20 16:30:04 +00:00
Pierre-Yves Chibon
3b9d3d2661
Come back to previous syntax
2013-09-20 16:24:01 +00:00
Pierre-Yves Chibon
44f3fc4bf7
Another test
2013-09-20 16:21:31 +00:00
Pierre-Yves Chibon
21cdce6765
Ignore error but still report them
2013-09-20 16:18:32 +00:00
Pierre-Yves Chibon
0115f9afdc
Fix typo
2013-09-20 16:16:46 +00:00
Pierre-Yves Chibon
bf107cb007
Remove local first_found plugin
2013-09-20 16:13:54 +00:00
Pierre-Yves Chibon
8cb07e13e2
test another syntax
2013-09-20 18:12:12 +02:00
Pierre-Yves Chibon
a2d790628c
Testing using quotes
2013-09-20 18:07:23 +02:00
Pierre-Yves Chibon
6e4809fb1d
Let's not skip
2013-09-20 18:01:09 +02:00
Pierre-Yves Chibon
cdfcf93ce7
Name the files correctly
2013-09-20 15:27:14 +00:00
Pierre-Yves Chibon
1f86fbdd29
Add hosts files for nuancier0{1,2}.stg
2013-09-20 17:19:55 +02:00
Pierre-Yves Chibon
f81b71ea60
Add dependency to python-psycopg2
2013-09-20 15:10:34 +00:00
Pierre-Yves Chibon
25d246b1af
Run the nuancier role at the end, once everything is in place
2013-09-20 15:04:57 +00:00
Pierre-Yves Chibon
e0c98e96dd
With dict representation in yaml
2013-09-20 16:53:03 +02:00
Pierre-Yves Chibon
aa2706c10e
environment should be a dict
2013-09-20 16:51:43 +02:00
Pierre-Yves Chibon
5ed8f2342f
Test another way to call createdb
2013-09-20 16:48:36 +02:00
Pierre-Yves Chibon
73ccae5323
Add nuancier to ssl.py
2013-09-20 16:40:13 +02:00
Pierre-Yves Chibon
370aa99701
Let's try the command with the full path
2013-09-20 16:13:32 +02:00
Pierre-Yves Chibon
21f006b86a
Add the role nuancier to the playbook
2013-09-20 14:10:13 +00:00
Pierre-Yves Chibon
fd28ce82b7
Atm nuancier has only one fedmsg certificate
2013-09-20 15:59:43 +02:00
Pierre-Yves Chibon
ac7ccee552
Comment out fedmsg info in inventory of nuancier
2013-09-20 15:47:38 +02:00
Pierre-Yves Chibon
990dd0ada0
Fix the name of the configuration file
2013-09-20 13:37:15 +00:00
Pierre-Yves Chibon
b876460607
The configuration file is nuancier-lite.cfg and fix the call to createdb.py
2013-09-20 13:40:05 +02:00
Pierre-Yves Chibon
e2fb4d7cac
Tag yum clean all as being related to packages
2013-09-20 13:33:04 +02:00
Pierre-Yves Chibon
c3674065e1
Run yum clean all before installing nuancier-lite
2013-09-20 13:31:45 +02:00
Pierre-Yves Chibon
ffcbe72031
Small formatting changes
2013-09-20 12:35:03 +02:00
Pierre-Yves Chibon
1120037afd
Fix syntax error and install wsgi and apache conf file only when needed
2013-09-20 12:28:40 +02:00
Pierre-Yves Chibon
2115866868
Update the nuancier role and add a new template
2013-09-20 12:01:18 +02:00
Ralph Bean
8c0bb9b136
Add the beginning of a role for nuancier.
2013-09-19 19:29:21 +00:00
Ralph Bean
e186f6feec
Add nuancier02.stg to the staging group.. it was forgotten.
2013-09-19 03:48:57 +00:00
Ralph Bean
a6c4e54c8d
Add inventory and playbook for nuancier staging nodes.
2013-09-19 03:33:43 +00:00
Nick Bebout
9c8b106468
Add wildcard intermediate cert for sks
2013-09-16 17:00:17 +00:00
Nick Bebout
088f55536b
Fix keys.fedoraproject.org colors
2013-09-16 16:49:54 +00:00
Nick Bebout
9689377c27
Fix SKS url
2013-09-16 16:49:29 +00:00
Ralph Bean
72bf42a9f5
Add the design team badge to the cronjob.
2013-09-16 14:36:22 +00:00
Ralph Bean
730e83903f
Treat openid addresses as utf-8 in the mugshot awarder script.
2013-09-16 00:59:04 +00:00
Kevin Fenzi
7777a835b9
Fix filename
2013-09-13 18:02:55 +00:00
Kevin Fenzi
63fa608bce
Move again the installing of koji pkg on db server
2013-09-13 17:25:48 +00:00
Kevin Fenzi
e368591739
Move koji pkg install
2013-09-13 00:26:53 +00:00
Kevin Fenzi
82a00ed5aa
We need the koji package on the db server too to get the schema
2013-09-12 23:10:15 +00:00
Kevin Fenzi
29be86c326
Make this more specific
2013-09-12 23:05:40 +00:00
Kevin Fenzi
d7ffa40a2d
Kinda need the db user created before it can make db's
2013-09-12 23:03:14 +00:00
Kevin Fenzi
3dae75234b
Move postgresql stuff around.
2013-09-12 22:56:34 +00:00
Kevin Fenzi
51746b66d0
fix name and template path here.
2013-09-12 22:44:30 +00:00
Kevin Fenzi
9d56847976
Add postgresql config
2013-09-12 22:40:01 +00:00
Kevin Fenzi
35c1ff1d8c
Add python psycopg2
2013-09-12 22:27:42 +00:00
Kevin Fenzi
86b56a0c24
Need hosts task here.
2013-09-12 22:12:45 +00:00
Kevin Fenzi
10e3a39f47
Update gpg key path for fedora arm repos
2013-09-12 21:58:26 +00:00
Ralph Bean
87cff73a73
Remove a cruft.
2013-09-12 20:54:24 +00:00
Ralph Bean
9270a82044
Add a script to retrieve a persons ID from the badges db on badges-backend01.
2013-09-12 20:34:19 +00:00
Kevin Fenzi
26f73f413c
Move the koji db stuff to it's own role, include in postgres playbook only on kojidb hosts
2013-09-12 17:42:57 +00:00
Kevin Fenzi
63b70b12d4
Fix the rest too
2013-09-12 17:08:32 +00:00
Kevin Fenzi
d3db0b5643
Tweak shell args
2013-09-12 17:06:58 +00:00
Kevin Fenzi
92b4a3ff7c
Add prelim, unfinished yet cut at koji hub role for aarch64 hub.
2013-09-12 17:01:07 +00:00
Nick Bebout
0fba97c3b0
Put my whole fingerprint as server_contact not just short keyid
2013-09-11 20:35:21 +00:00
Nick Bebout
5dafc6e6c6
Remove keys-dev.cloud from membership file for sks
2013-09-11 20:34:47 +00:00
Stephen Smoogen
4dd6934f48
Add bvirthost07/08 to the inventory.
2013-09-11 20:30:08 +00:00
Ralph Bean
8f257305df
Point that var at the testing repo.
2013-09-06 14:01:01 +00:00
Ralph Bean
e2dff8513c
Use a var for the repodir in the sign-and-import playbook.
2013-09-06 14:01:01 +00:00
Aurélien Bompard
de589ffcf9
Fix started services list
2013-09-06 11:23:32 +00:00
Aurélien Bompard
712a661776
Mailman: the conf dir name is versionned
2013-09-06 08:34:09 +00:00
Aurélien Bompard
2343b7c0d2
Mailman: skip granting perms on the DB app users
...
At least until there's a better solution available (eg the Ansible bug
is fixed). For PG<9, there's no way to grant on all tables at once.
2013-09-06 06:53:17 +00:00
Aurélien Bompard
47f420f433
Mailman: don't use postgresql_privs, it's buggy
...
See: https://github.com/ansible/ansible/issues/4043
2013-09-06 06:06:23 +00:00
Ralph Bean
679cd342bb
Use the new tahrir notification callback in yet another place.
2013-09-05 20:31:31 +00:00
Aurélien Bompard
a3f009754b
Syntax error
2013-09-05 17:37:18 +00:00
Aurélien Bompard
319dd9bebb
mailman: missing parameter
2013-09-05 17:30:00 +00:00
Aurélien Bompard
561ae8423d
Separate DB user privileges from creation
...
(race condition)
2013-09-05 17:25:08 +00:00
Aurélien Bompard
c790d0b90d
Use db02.stg as a DB server
2013-09-05 16:46:18 +00:00
Aurélien Bompard
9fa31f6305
Make it obvious it's mailman3 that's restarted
2013-09-05 16:43:25 +00:00
Aurélien Bompard
6ccc54bb9e
Fix handlers
2013-09-05 16:36:18 +00:00
Aurélien Bompard
05524ff6db
Fix syntax error
2013-09-05 16:28:45 +00:00
Aurélien Bompard
16cc8ecc02
Don't use the roles variable, it does not work yet
2013-09-05 16:26:59 +00:00
Aurélien Bompard
440c84cc59
Initial version of the mailman setup
2013-09-05 15:43:24 +00:00
Kevin Fenzi
dfddc08d9d
Arm in f19 is secondary, so the repo paths are all different.
2013-09-05 03:07:25 +00:00
Kevin Fenzi
8659e811dd
Set repos for fedora machines to use infrastructure repo.
2013-09-05 02:11:53 +00:00
Ralph Bean
72daf52395
Yet another typo fix.
2013-09-04 18:38:37 +00:00
Ralph Bean
097c7b2414
Validate that the badge ids actually exist.
2013-09-04 18:32:04 +00:00
Ralph Bean
d690b42006
Another typofix.
2013-09-04 18:22:01 +00:00
Ralph Bean
a2c7e24745
Forgot the .iteritems() here.
2013-09-04 18:17:13 +00:00
Ralph Bean
e6b8eab5fc
Make the badge award cronjob more flexible.
2013-09-04 18:11:39 +00:00
Ralph Bean
76a44ec771
Use tahrir-api notification machinery in the badges cron jobs.
2013-09-04 16:24:17 +00:00
Ralph Bean
b127371ef1
Take badges nodes out of the freeze list as per the freeze break request email.
2013-09-04 15:25:43 +00:00
Nick Bebout
faf21e5dff
Merge branch 'master' of /git/ansible
2013-09-04 00:54:03 +00:00
Nick Bebout
1031862d7e
Add title and link Fedora logo back to main website
2013-09-04 00:53:45 +00:00
Kevin Fenzi
713a9926ce
Note that keys doesn't freeze.
2013-09-04 00:35:01 +00:00
Nick Bebout
8eb6762f4b
Replace eagle.jhcloos.com with keys.jhcloos.com per email to nb
2013-09-04 00:32:08 +00:00
Nick Bebout
25279ce70f
Remove more hardcoded urls
2013-09-04 00:31:13 +00:00
Nick Bebout
981f597365
Remove hardcoded url, just use /pks/lookup
2013-09-04 00:30:43 +00:00
Kevin Fenzi
3c4b440678
Freezebreak: Adjust rsyslogd for buildvm/buildarm instances to pull correctly from journald.
2013-09-03 21:11:25 +00:00
Kevin Fenzi
ce9ef9bf20
Need a correct gw here.
2013-08-30 21:00:37 +00:00
Kevin Fenzi
646c3a9647
Add docs-backend playbook and host
2013-08-30 20:51:01 +00:00
Kevin Fenzi
3f2d88081b
Also backup /srv/web on people03
2013-08-30 20:35:41 +00:00
Kevin Fenzi
adce8a9211
Add yum-cron to taskbot01
2013-08-30 20:12:56 +00:00
Kevin Fenzi
f0c68a4a82
Switch taskbot over to a f19 instance.
2013-08-30 19:59:20 +00:00
Kevin Fenzi
5b55bdd257
Fix path to root key
2013-08-30 19:32:00 +00:00
Kevin Fenzi
8147d339ce
Set limits higher for nrpe on virthost-comm02
2013-08-28 22:07:44 +00:00
Ralph Bean
8191128c44
These cronjobs should append to their logs.
2013-08-28 19:33:35 +00:00
Ralph Bean
2c5dde0e3d
Badges stuff requires sqlalchemy 0.8 or later.
2013-08-28 14:34:51 +00:00
Ralph Bean
74c5c8fa36
Turns out you need to explicitly expire cache.
2013-08-28 14:00:13 +00:00
Dennis Gilmore
da44c683a9
add eth1 ips to buildvm hosts
2013-08-27 22:23:38 +00:00
Kevin Fenzi
51bf4b6268
Add a script that can find a vm instance and kill/undefine it. Use with care!
2013-08-27 20:54:20 +00:00
Kevin Fenzi
33da79db04
Fine then, how about this one?
2013-08-27 20:49:44 +00:00
Kevin Fenzi
9dd63c9b76
Try this, didn't like the previous syntax.
2013-08-27 20:47:17 +00:00
Kevin Fenzi
1ac234e266
Only install this module on rhel, not fedora buildvm's
2013-08-27 20:43:24 +00:00
Kevin Fenzi
8f40999d13
Fix route-eth1
2013-08-27 20:29:30 +00:00
Kevin Fenzi
03f0721efd
Set nameserver too
2013-08-27 19:43:49 +00:00
Kevin Fenzi
e53ee7840d
Revert "Lets give this a try"
...
This reverts commit fe66cb31fc .
Didn't work at all. ;)
2013-08-27 19:08:56 +00:00
Kevin Fenzi
fe66cb31fc
Lets give this a try
2013-08-27 19:05:06 +00:00
Kevin Fenzi
4d4167cc81
If we set eth1 gw it apparently tries to use that for everything.
2013-08-27 18:44:38 +00:00
Kevin Fenzi
90011f9b03
Try this to sort out eth1
2013-08-27 18:25:55 +00:00
Kevin Fenzi
24b2661504
How about passing the right command.
2013-08-27 17:58:05 +00:00
Kevin Fenzi
5278250229
Further tweak
2013-08-27 16:52:38 +00:00
Kevin Fenzi
ddc3c08182
Might be disk needs this?
2013-08-27 16:47:54 +00:00
Kevin Fenzi
14ad3d34e9
Fix up buildvm playbook to build first.
2013-08-27 16:37:42 +00:00
Kevin Fenzi
31b3c1be15
Reorg buildvm/releng playbooks to use base and not duplicate parts of it.
2013-08-27 16:32:55 +00:00
Kevin Fenzi
5875104df3
Default the buildvm's to this one sshd_config
2013-08-27 15:01:25 +00:00
Dennis Gilmore
8a07df00f4
add build versions fo sshd_config
2013-08-27 05:42:31 +00:00
Dennis Gilmore
cdb4e9ed9c
include base role in builders
2013-08-27 05:22:42 +00:00
Dennis Gilmore
16a9759969
switch builders to being fedora 19 based
2013-08-27 04:57:00 +00:00
Kevin Fenzi
9f2514c5b9
Minor output tweak to vhost-info script
2013-08-25 19:29:23 +00:00
Kevin Fenzi
66621b512e
Rename some scripts. ans- is kinda pointless since they are in the ansible repo. ;)
2013-08-25 19:24:24 +00:00
Kevin Fenzi
aecec53380
Move base to a role.
...
Clean up syntax in all the base tasks.
Add CONVENTIONS file for info on where things go.
Tweak readme.
Switch add playbooks to base role instead of task.
2013-08-25 18:44:54 +00:00
Kevin Fenzi
337614085a
sign-vault02 is not around anymore
2013-08-25 17:08:33 +00:00
Dennis Gilmore
bf2187393c
drop compose group and move to releng
2013-08-25 01:46:46 +00:00
Dennis Gilmore
f83dff4476
make sure we have dirs we need and symlink shared bits for compose
2013-08-25 01:43:39 +00:00
Dennis Gilmore
c0b8c3f816
mount /mnt/fedora_koji/ inside compose chroots
2013-08-25 01:40:24 +00:00
Dennis Gilmore
b663b6cbfc
try without trailing /
2013-08-24 22:56:31 +00:00
Dennis Gilmore
5d1d223ce5
try make the symlink a different way
2013-08-24 21:33:40 +00:00
Dennis Gilmore
25c9f19d7f
symlink /mnt/fedora_koji/compose/ to /srv/pungi
2013-08-24 21:26:20 +00:00
Kevin Fenzi
51bdaac0a1
Simplify nagios client template items. (Thanks misc!)
2013-08-24 18:50:59 +00:00
Dennis Gilmore
b0cd472396
make sure we have /srv/pungi and /pub/alt dirs on releng boxes
2013-08-24 18:44:46 +00:00
Dennis Gilmore
7247c51c21
add armhfp compose mock configs and make sure they are installed
2013-08-24 18:40:55 +00:00
Kevin Fenzi
878bc25d22
Add f20 sshd config
2013-08-24 18:21:23 +00:00
Dennis Gilmore
01273d244b
add arm-releng sshd_config
2013-08-24 18:02:42 +00:00
Kevin Fenzi
e79ed31565
squiggly
2013-08-23 23:40:54 +00:00
Kevin Fenzi
3dd836b088
ok, fine, lets be more verbose
2013-08-23 23:25:13 +00:00
Kevin Fenzi
5082e54355
Lets try this syntax. :)
2013-08-23 23:22:30 +00:00
Kevin Fenzi
d2b0a7832a
Fix nrpe templates so they install as .cfg files and not .cfg.j2
2013-08-23 23:16:04 +00:00
Kevin Fenzi
3228299291
Clean up sudoers
2013-08-23 22:55:24 +00:00
Kevin Fenzi
ad1914b567
Add correct variables
2013-08-23 22:33:10 +00:00
Kevin Fenzi
d0eeb056af
Add handlers
2013-08-23 22:29:16 +00:00
Kevin Fenzi
036fde1d4f
Make a 19 version
2013-08-23 22:26:17 +00:00
Kevin Fenzi
5931ac0db5
Also revert this part
2013-08-23 22:23:58 +00:00
Kevin Fenzi
63007a670e
went a step too far.
2013-08-23 22:23:30 +00:00
Kevin Fenzi
f1f1fbd435
Convert this ssh task entirely to new syntax, add ansible_distribution_version
2013-08-23 22:22:14 +00:00
Kevin Fenzi
0b8262c195
Perhaps this is right? lets try
2013-08-23 22:16:53 +00:00
Kevin Fenzi
2a76938de3
We may need to update this syntax.
2013-08-23 22:12:04 +00:00
Kevin Fenzi
8934d2c5a4
This should work hopefully.
2013-08-23 22:02:20 +00:00
Kevin Fenzi
2f53b38e79
Try moving this here.
2013-08-23 21:55:13 +00:00
Kevin Fenzi
1bbbd709bf
Try and make our nagios setup 32/64 bit happy. Add a bunch of things to arm-releng playbook.
2013-08-23 21:50:25 +00:00
Ralph Bean
cf5aefa4fe
Style cleanup.
2013-08-23 19:16:14 +00:00
Ralph Bean
724e8403d8
Start awarding the sponsor badge in the oldschool badges cron.
2013-08-23 19:16:05 +00:00
Ralph Bean
2c2783e127
Add logs and logrotate for badge award cronjobs on badges-backend01.
2013-08-23 15:17:25 +00:00
Ralph Bean
6c284c827e
Some bugfixes to that badge award script.
2013-08-23 14:51:44 +00:00
Ralph Bean
430695a93f
Only initialize all the things until after we checked CLI arguments.
2013-08-23 14:45:47 +00:00
Ralph Bean
46f0f924a9
Tweak that mode.
2013-08-23 14:43:22 +00:00
Ralph Bean
1d0456298e
Add a one-off script for awarding badges.
2013-08-23 14:39:05 +00:00
Ralph Bean
06b7bffd02
Role duplicate roles declaration into one.
2013-08-23 13:50:49 +00:00
Nick Bebout
cbbd2ed615
Turn ProxyVia on
2013-08-23 03:24:57 +00:00
Nick Bebout
d5891ee871
Serve fedora-logo from https so it will stop browser warnings
2013-08-23 02:18:10 +00:00
Nick Bebout
15e2fdec9e
proxy port 80 to sks also
2013-08-23 02:13:32 +00:00
Nick Bebout
7ed979cbd4
Enable SNI for keys
2013-08-23 02:07:24 +00:00
Nick Bebout
605866f5cc
Certificates should be owned by root
2013-08-23 01:47:16 +00:00
Nick Bebout
aa94ea7b49
Fix paths
2013-08-23 00:45:02 +00:00
Nick Bebout
c1ca6c95c4
put wildcard cert on keys01
2013-08-23 00:34:50 +00:00
Nick Bebout
0002cd0cce
Add custom ssl.conf
2013-08-22 23:14:48 +00:00
Nick Bebout
c797ed7888
Merge branch 'master' of /git/ansible
2013-08-22 22:34:03 +00:00
Nick Bebout
b9d6c832cb
Fix path
2013-08-22 22:33:56 +00:00
Ralph Bean
06b38f635a
Improved sign-and-import playbook.
2013-08-22 21:13:05 +00:00
Nick Bebout
9e3e306b79
Fix syntax
2013-08-22 03:54:55 +00:00
Nick Bebout
fb9a416491
Run sks-db and sks-recon on boot
2013-08-22 03:54:04 +00:00
Nick Bebout
4a66c4e699
Merge branch 'master' of /git/ansible
2013-08-22 03:53:11 +00:00
Nick Bebout
91a94d8db5
Install mod_ssl
2013-08-22 03:53:00 +00:00
Nick Bebout
fb018c0941
membership file changes
2013-08-22 03:40:11 +00:00
Nick Bebout
3d730fd457
sksconf changes
2013-08-22 03:39:29 +00:00
Ralph Bean
a5aca28f0f
Finish off that playbook.
2013-08-21 20:05:42 +00:00
Ralph Bean
99266722b6
Puppet on the brain.
2013-08-21 19:31:07 +00:00
Ralph Bean
fa592284b7
Update the host.
2013-08-21 19:29:42 +00:00
Ralph Bean
702311cc3c
Start of a stub of a fedorahosted-git + fedmsg playbook.
2013-08-21 19:27:55 +00:00
Kevin Fenzi
4dbcf3f226
Add yum-cron role, add to mailman-stg group.
2013-08-21 17:09:40 +00:00
Ralph Bean
236acce903
Disable badges cronjobs in staging.
2013-08-21 15:55:14 +00:00
Dennis Gilmore
cf0e452105
use f20 buildroot for branched
2013-08-21 14:35:36 +00:00
Ralph Bean
31868e7896
No need to save these.
2013-08-20 20:09:45 +00:00
Ralph Bean
4c81cc6b65
Ensure the fedmsg user has a homedir for cron to work.
2013-08-20 19:34:07 +00:00
Ralph Bean
e38d3a6088
Cron syntax.
2013-08-20 18:54:41 +00:00
Ralph Bean
4d01b7f4e2
Fix an actual bug.
2013-08-20 18:49:09 +00:00
Ralph Bean
f3c2d8132d
Still more adjusting.
2013-08-20 18:46:15 +00:00
Ralph Bean
4923b7a1fd
Adjust it yet again.
2013-08-20 18:45:40 +00:00
Ralph Bean
e9afaab2c2
Adjust when the cronjob runs.
2013-08-20 18:42:04 +00:00
Ralph Bean
6971c2f402
Log output from badge awarding cronjobs.
2013-08-20 18:37:56 +00:00
Nick Bebout
60df08fc1a
Add /etc/httpd/conf.d/sks.conf to ansible
2013-08-20 00:53:10 +00:00
Nick Bebout
665f1ee4e0
Fix syntax
2013-08-19 23:03:04 +00:00
Nick Bebout
b4f81cdf33
Merge branch 'master' of /git/ansible
2013-08-19 23:02:20 +00:00
Nick Bebout
f3ad1a6570
Keyserver should regenerate stats page hourly
2013-08-19 23:02:06 +00:00
Kevin Fenzi
e448c9d80f
Add openvpn client.
2013-08-19 21:53:09 +00:00
Kevin Fenzi
4fd845e41c
Try this.
2013-08-19 21:25:28 +00:00
Ralph Bean
744e41c179
Add another cronjob for the libravatar badge to badges-backend01.
2013-08-19 21:16:57 +00:00
Kevin Fenzi
3ccd34fad9
Clean up nagios client templates.
2013-08-19 21:14:59 +00:00
Kevin Fenzi
53a138d49f
This is really a template
2013-08-19 21:09:42 +00:00
Kevin Fenzi
6faab6d9bc
Move this to templates too
2013-08-19 21:08:14 +00:00
Kevin Fenzi
b2f0ef86da
Move template to the templates dir
2013-08-19 21:06:22 +00:00
Kevin Fenzi
7ec446f2fb
Revert this attempt
2013-08-19 21:04:46 +00:00
Kevin Fenzi
8215951252
Just hard code these for now until we can figure out why $roles doesn't work.
2013-08-19 21:04:17 +00:00
Kevin Fenzi
8e2ec48cc0
Migrate a bunch of things to roles. Thanks to misc!
2013-08-19 20:12:26 +00:00
Nick Bebout
16ce004157
Disable sks-db and sks-recon for now
2013-08-19 19:42:57 +00:00
Nick Bebout
9112d12d6f
Merge branch 'master' of /git/ansible
2013-08-19 19:30:24 +00:00
Nick Bebout
3272ac4b67
Tweaks to group_vars for keys
2013-08-19 19:29:50 +00:00
Ralph Bean
03cbac1320
Shebang.
2013-08-19 19:24:00 +00:00
Ralph Bean
5dd3b837ba
Change owner and perms of that cron script.
2013-08-19 19:23:13 +00:00
Ralph Bean
2359f4cdbb
Fix paths.
2013-08-19 19:21:07 +00:00
Ralph Bean
332db02c1c
Try out this badge awarder as a cronjob.
2013-08-19 19:20:01 +00:00
Ralph Bean
69fab89a0c
Remove some unneeded whitespace from the copr playbooks.
2013-08-19 17:39:10 +00:00
Kevin Fenzi
3f44fe132e
releng03 is no more
2013-08-19 17:26:14 +00:00
Kevin Fenzi
7fc9bc2ff2
Add value03 to backups
2013-08-19 16:27:01 +00:00
Kevin Fenzi
85e118ae26
Add rdiff-backup reporting emails.
2013-08-19 15:44:55 +00:00
Ralph Bean
da8d00a517
Use httpd aliases for static resources.
2013-08-16 20:03:57 +00:00
Kevin Fenzi
8bb1a9e6f4
Add sks handlers
2013-08-16 18:00:44 +00:00
Ralph Bean
b6918e7d34
First draft of a playbook for signing and importing rpms.
2013-08-16 14:53:06 +00:00
Ralph Bean
78ac81e723
Comment out that expire-cache section for now.
2013-08-16 14:30:31 +00:00
Ralph Bean
abb5fd2041
Use the ansible yum module instead of an action.
2013-08-16 14:24:07 +00:00
Ralph Bean
12a4eca746
New playbook to push out packages, usually from lockbox.
2013-08-16 14:16:12 +00:00
Ricky Elrod
ad4fc390f6
I guess this is why everyone says I should stay in school. :P
2013-08-16 02:46:31 +00:00
Nick Bebout
4147bb7e35
Files should be chowned sks:sks
2013-08-16 02:33:33 +00:00
Nick Bebout
7965caeebb
Merge branch 'master' of /git/ansible
2013-08-16 02:29:12 +00:00
Nick Bebout
a678d8308a
Add /srv/sks and /srv/sks/web directories to ansible
2013-08-16 02:29:00 +00:00
Ricky Elrod
bc0f7492c2
specify the full hostname here
2013-08-16 02:25:11 +00:00
Ricky Elrod
5ee00293f5
first attempt at keys01....might not work.
2013-08-16 02:21:31 +00:00
Nick Bebout
990f5f044f
Run sks-db and sks-recon on boot
2013-08-15 22:39:12 +00:00
Nick Bebout
8c306e4f7a
Add sks web files
2013-08-15 22:36:45 +00:00
Nick Bebout
81d0789fb4
Initial commit of files for ansible-izing keyserver
2013-08-15 22:27:42 +00:00
Ralph Bean
82a6edbbf3
The pngs arent really config, now are they..
2013-08-15 21:31:42 +00:00
Ralph Bean
e38211b237
Pull in badges site-docs changes from upstream git repo.
2013-08-15 21:27:56 +00:00
Ralph Bean
9d0f024681
This glob is not globbing.
2013-08-15 18:24:36 +00:00
Ralph Bean
9b4a6b41fa
Remove hotfix for tahrir-0.3.3.
2013-08-15 18:19:01 +00:00
Ralph Bean
75baff2a37
Configuration for the latest tahrir release.
2013-08-15 18:14:22 +00:00
Kevin Fenzi
c53359f4fa
Add in a pile of other machines to rdiff-backup. It's going to take it many days. ;)
2013-08-15 17:36:14 +00:00
Kevin Fenzi
7f8431a0d1
This hotfix is using a rhel specific path.
2013-08-14 21:23:46 +00:00
Kevin Fenzi
8ac65b6b63
Use the right ks file
2013-08-14 21:06:35 +00:00
Kevin Fenzi
daf9329741
Fix path
2013-08-14 20:57:35 +00:00
Kevin Fenzi
fa788f1922
Add virt-install command for f19 here.
2013-08-14 20:56:01 +00:00
Ralph Bean
9cd201e1ec
Tell tahrir to find the badge pngs where they actually are.
2013-08-14 18:53:46 +00:00
Kevin Fenzi
38c1cb6f81
Fix group name
2013-08-13 02:43:03 +00:00
Kevin Fenzi
ab232cf212
Fix inventory
2013-08-12 21:20:01 +00:00
Kevin Fenzi
749362ae16
Fix group
2013-08-12 21:18:56 +00:00
Kevin Fenzi
3a0857fdd8
Add mailman01.stg
2013-08-12 21:17:21 +00:00
Kevin Fenzi
c89c9de1ac
Add beaker01 to ansible
2013-08-12 15:47:12 +00:00
Ricky Elrod
ec3cadb1af
new hotfix (leaderboard JSON endpoint)
2013-08-12 07:47:53 +00:00
Ricky Elrod
80a53a17fb
nuke old hotfix
2013-08-12 07:44:12 +00:00
Ralph Bean
0a7105213a
Add openvpn_client to badges-backend01.
2013-08-11 22:36:41 +00:00
Ralph Bean
337dd8af3e
Hotfix to fix broken badge search.
2013-08-09 20:40:06 +00:00
Ralph Bean
2f193be848
Update a few old urls in the badges frontend config.
2013-08-07 15:41:12 +00:00
Ralph Bean
897d92d978
These groups don't actually need port 80.
2013-08-07 15:20:16 +00:00
Ralph Bean
97a3b196d0
Try copying python-fedora hotfix over from puppet.
2013-08-07 14:57:04 +00:00
Patrick Uiterwijk
61034c3ccf
Add playbook to clear varnish
2013-08-06 15:41:12 +00:00
Patrick Uiterwijk
681a9273e4
Merge branch 'master' of /git/ansible
2013-08-06 15:40:11 +00:00
Patrick Uiterwijk
ab91d8ea3f
Add playbook to clear memcached
2013-08-06 15:39:57 +00:00
Ralph Bean
c8e12740b6
Remove the old fedmsg module.
2013-08-06 02:20:29 +00:00
Ralph Bean
1ed6213786
Use the correct topic.
2013-08-06 01:56:33 +00:00
Ralph Bean
d88dabe798
Use the shell cert.
2013-08-06 01:46:56 +00:00
Ralph Bean
b306a4f54c
Rename that to avoid import conflict.
2013-08-06 01:45:51 +00:00
Ralph Bean
fcb24a897c
Add forgotten import.
2013-08-06 01:45:22 +00:00
Ralph Bean
8e3bf3f0d6
Typofix.
2013-08-06 01:45:04 +00:00
Ralph Bean
36924c615e
Try adding a callback plugin for fedmsg.
2013-08-06 01:44:17 +00:00
Ralph Bean
defd120da2
Remove trailing whitespace.
2013-08-06 01:24:43 +00:00
Ralph Bean
871807aaf8
I can't believe I forgot this...
2013-08-05 20:13:56 +00:00
Ralph Bean
a04aaaf029
Correctly name those endpoints..
2013-08-05 20:08:57 +00:00
Ralph Bean
435709f550
Ask iptables to open ports for fedmsg on the badges frontend nodes.
2013-08-05 20:02:13 +00:00
Ralph Bean
222e4fcb5b
Correct jinja2 template syntax.
2013-08-05 19:20:58 +00:00
Ralph Bean
a17d0ecfd6
s/frontend/web/g
2013-08-05 19:19:17 +00:00
Ralph Bean
e1e07a4588
Typofix.
2013-08-05 19:16:27 +00:00
Ralph Bean
e47153555e
Deploy those certs to boxes in the right groups.
2013-08-05 19:11:06 +00:00
Ralph Bean
be316406dd
Declare the new fedmsg certs for the badges frontend nodes.
2013-08-05 19:11:05 +00:00
Ralph Bean
09e1edee27
Add badges frontend endpoints that were previously added in puppet.
2013-08-05 19:11:05 +00:00
Patrick Uiterwijk
6419178dc5
Allow sysadmin-gallery to access
2013-08-05 19:08:13 +00:00
Ricky Elrod
6958b5348c
update keypair in temp playbooks
2013-08-02 22:56:46 +00:00
Ralph Bean
176a9fef98
Comment out this httpd alias.
2013-08-02 18:29:47 +00:00
Ralph Bean
a2665f6a7b
Remove the badges path prefix from the httpd conf.
2013-08-02 18:19:18 +00:00
Ralph Bean
6c5ff7c3c1
No more badges path prefix.
2013-08-02 17:49:35 +00:00
Kevin Fenzi
ed0cee0b49
Bump mem and cpus
2013-08-01 21:54:26 +00:00
Ralph Bean
b5e7ac9542
Disallow changing nicknames in our tahrir instance.
2013-08-01 20:47:41 +00:00
Kevin Fenzi
316fc28268
Do the right actual instance
2013-08-01 20:33:50 +00:00
Kevin Fenzi
b54ed736b7
Switch this to the new keypair
2013-08-01 20:32:21 +00:00
Ralph Bean
9ee550e60d
More openid tweaks.
2013-08-01 17:43:16 +00:00
Ralph Bean
1df977ea0c
Hotfix for badges/velruse/openid.
...
https://fedorahosted.org/fedora-infrastructure/ticket/3915
2013-08-01 15:52:26 +00:00
Ralph Bean
fb87fa8df3
Whoops!
2013-08-01 14:36:21 +00:00
Ralph Bean
f9f1cf68fa
Force fedmsg-hub to pick up the latest sqlalchemy.
2013-08-01 14:31:35 +00:00
Ralph Bean
0c3657430c
Add the internal ip of the proxies to /etc/hosts for the badges frontend nodes. Openid. Fingers crossed.
2013-07-31 15:10:35 +00:00
Ralph Bean
25ae7b9441
Or.. is it this?
2013-07-31 14:46:38 +00:00
Ralph Bean
b3d0c6a4d1
Ah HA! Thats why openid was failing.
2013-07-31 14:14:18 +00:00
Ralph Bean
29b9a29557
Revert that. "when" is behaving weirdly.
2013-07-30 20:31:59 +00:00
Ralph Bean
35f4de528a
Got that wrong. Is this right?
2013-07-30 20:17:42 +00:00
Ralph Bean
1c4b0cf05d
Apparently this is more modern syntax.
2013-07-30 19:22:00 +00:00
Ralph Bean
10f5c093e1
Don't include the openvpn_client task for staging.
2013-07-30 19:08:50 +00:00
Ralph Bean
da4ef0387d
Add infra.fp.o back to the hosts files for those badges nodes.
2013-07-30 18:35:29 +00:00
Ralph Bean
c51231910b
Add openvpn_client to the badges web nodes.
2013-07-30 18:28:14 +00:00
Ralph Bean
efbe990221
Add hosts files for the new badges nodes.
2013-07-30 16:44:46 +00:00
Ralph Bean
249dac5b01
Get the right volgroup for virthost01.
2013-07-30 15:02:22 +00:00
Ralph Bean
2435436296
Break the config-distribution play out into two.
...
This is necessary because of how "roles" preceed "loose tasks".
One role here rolls out some fedmsg certs and sets their group
to "sysadmin".. but since roles run before tasks fasClient has
never actually been run so the "sysadmin" group doesn't exist yet.
We need to ensure that those fasclient basic setup tasks get run
first (the first time) before the service-specific stuff gets run.
Another way to do this would be to make the "generic config" stuff
into a role that gets included in every playbook like this one. We
put it first and it will get run before the other roles. We should
consider that after some discussion.
2013-07-30 14:53:17 +00:00
Ralph Bean
0192fa6d32
Use a volgroup that actually exists for the badges nodes.
2013-07-30 14:32:00 +00:00
Ralph Bean
5425ba5f11
Host vars for badges nodes.
2013-07-30 14:25:24 +00:00
Ralph Bean
35ab4759e1
Some enhancements, simplifications to that vhost script.
2013-07-30 02:00:21 +00:00
Ralph Bean
3e43c3f30a
Hopefully correct my cpu math.
2013-07-30 01:41:14 +00:00
Ralph Bean
ae85cbcaed
Make the vhost script report free cpus too.
2013-07-30 01:41:13 +00:00
Ralph Bean
a50eacb027
Use a nice default for the vhost script.
2013-07-30 01:41:13 +00:00
Ricky Elrod
d9e9338ad3
Revert "try quoting things with vars in them so they interpolate?"
...
This reverts commit 357208852e .
2013-07-29 19:58:20 +00:00
Ricky Elrod
357208852e
try quoting things with vars in them so they interpolate?
2013-07-29 19:55:54 +00:00
Ralph Bean
9eca22715c
Give some fedora dummy fas credentials to the badges backend.
2013-07-29 15:01:13 +00:00
Dennis Gilmore
b193c9c035
install mock configs for arm composes
2013-07-29 01:17:09 +00:00
Dennis Gilmore
0357ba87ad
disable package state plugin on the builders
2013-07-29 00:57:59 +00:00
Kevin Fenzi
abd27d1acf
Start rdiff-backup on lockbox01 content
2013-07-28 00:38:54 +00:00
Kevin Fenzi
12f4135e41
ppc11/12 are gone
2013-07-25 21:53:35 +00:00
Dennis Gilmore
fde8999fad
allow udp traffic from builders to storage
2013-07-25 21:39:24 +00:00
Kevin Fenzi
f1c5e4cafd
Fix default route
2013-07-24 22:32:18 +00:00
Kevin Fenzi
fd9294890b
Add taskbot01.qa instance for qa folks.
2013-07-24 22:15:22 +00:00
Kevin Fenzi
5cf6b38f94
Try and actually run it.
2013-07-23 18:00:18 +00:00
Kevin Fenzi
c398ba988e
Kill async for now.
2013-07-23 17:56:37 +00:00
Kevin Fenzi
25916e41bd
Serial needs to be on the playbook, not the task
2013-07-23 17:43:52 +00:00
Kevin Fenzi
7e377baeb5
Fix url
2013-07-23 17:40:46 +00:00
Kevin Fenzi
a16c119073
Add git/ansible and make script 755
2013-07-23 17:37:16 +00:00
Kevin Fenzi
051e78fc3d
Give up on cron module
2013-07-23 17:34:31 +00:00
Kevin Fenzi
3a6e37eb87
And a user too
2013-07-23 17:30:52 +00:00
Kevin Fenzi
a2d892a18b
Need a name
2013-07-23 17:29:18 +00:00
Kevin Fenzi
de351bea39
Very first cut at using ansible to run rdiff backups on backup03
2013-07-23 17:26:34 +00:00
Kevin Fenzi
5ae82572f1
Fix iptables ports on backup03
2013-07-23 15:21:49 +00:00
Kevin Fenzi
5ddb61526c
Drop old vars and add rdiff-backup
2013-07-22 21:41:44 +00:00
Kevin Fenzi
9f3e55494b
Give up and just look at removing logwatch in kickstart
2013-07-22 21:38:25 +00:00
Kevin Fenzi
5ab2ae9c3f
Ok, lets try this.
2013-07-22 19:49:57 +00:00
Kevin Fenzi
96e6c2b19e
Lets try this to override the logwatch removal.
2013-07-22 19:41:54 +00:00
Kevin Fenzi
018c11b660
Add some adjustments for backup03
2013-07-22 19:36:29 +00:00
Kevin Fenzi
7526696150
Less mail in the world. ;(
2013-07-22 16:18:49 +00:00