2470 Commits

Author SHA1 Message Date
Ricky Elrod
5900f6e6c2 First go at letsencrypt automation
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-17 05:07:56 +00:00
Ricky Elrod
b5d3987560 I'm fairly sure these are all old and unused. ¯\_(ツ)_/¯
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-17 03:14:07 +00:00
Kevin Fenzi
5accb15036 perhaps we need a space here 2018-05-17 01:02:35 +00:00
Kevin Fenzi
4bc3ab0eae remove bodhi2 internal check. it is not working and it really just duplicates the openshift aliveness check 2018-05-17 00:08:15 +00:00
Ricky Elrod
2fd0bdac41 bye vh01
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-17 00:03:58 +00:00
Ricky Elrod
63fd649039 Forgot to update this one
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-17 00:03:58 +00:00
Kevin Fenzi
8c044b81e7 set buildvm-armv7-23/24 to fedora 28 for debugging the bug 2018-05-16 23:26:35 +00:00
Ricky Elrod
da0ee26b9d vh01 -> vh14
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-16 22:43:22 +00:00
Kevin Fenzi
8390dd2ff3 some more weeding 2018-05-16 22:21:52 +00:00
Kevin Fenzi
7bb1ba7e8e back to 27 for now on armv7 2018-05-16 19:59:42 +00:00
Kevin Fenzi
17c63535c3 another attempt 2018-05-16 17:29:29 +00:00
Kevin Fenzi
8a029c848a another attempt to weed openshift web traffic 2018-05-16 16:14:54 +00:00
Pierre-Yves Chibon
8b195f8bd6 Add SAR script for pagure
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-16 15:10:02 +02:00
Clement Verna
12ba282425 Disable import_image plugin in prod
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-16 13:55:11 +02:00
Pierre-Yves Chibon
e4055e1d87 Add SAR script for datagrepper/datanommer
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-16 12:15:37 +02:00
Aurélien Bompard
43cdaeda18 SAR: add more data to the HyperKitty/Mailman script 2018-05-16 09:06:55 +00:00
Kevin Fenzi
f05a04b53a try and weed out openshift 2018-05-16 04:46:30 +00:00
Kamil Páral
8561ed8031 resultsdb-dev: turn off fedmsg publishing
Turns out we don't want fedmsgs to be published from dev, we just added
a new config option that was not properly disabled on dev and that
caused the confusion.
2018-05-16 04:56:12 +02:00
Kevin Fenzi
0e46cce112 create the directory as well 2018-05-15 23:35:47 +00:00
Todd Zullinger
0420cb5d0f Mailman: set default list footer
Add links to the list archive and guidelines to the default footer.

https://pagure.io/fedora-infrastructure/issue/6794
2018-05-15 23:24:14 +00:00
Ricky Elrod
49a651e0d7 again
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-15 22:58:56 +00:00
Ricky Elrod
701c6d851a ansible betrayed me
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-15 22:57:56 +00:00
Ricky Elrod
776e17e5d9 use the right users
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-15 22:51:40 +00:00
Ricky Elrod
4c0e883ce0 Add a playbook to sync the old pkl out
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-15 22:47:24 +00:00
Kevin Fenzi
1c5b2c8165 see if we can weed out all the openshift foo.go:line stuff 2018-05-15 21:56:49 +00:00
Kevin Fenzi
759fdf0013 ok, lets try this one more time 2018-05-15 20:56:24 +00:00
Stephen Smoogen
7f2073e917 lets be sane about this 2018-05-15 19:53:38 +00:00
Stephen Smoogen
614cd376bd clean up noc logs by defining a segment for 10.5.127 network 2018-05-15 19:46:55 +00:00
Patrick Uiterwijk
9ea8cd8b2b Attempt delete/add on change
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-15 21:37:27 +02:00
Patrick Uiterwijk
7deedf5d7e Actually fail the secret-file role if another one already existed for now
This role needs to be fixed to actually apply changes, so whomever sees this
gets the fun of fixing this.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-15 21:34:07 +02:00
Patrick Uiterwijk
5ceddcf683 Revert "Revert "switch bodhi web fedmsg key to be more accurate""
This reverts commit f72783414c.
2018-05-15 19:28:20 +00:00
Clement Verna
1887a0a9fd Remove orchestrator.json from osbs inputs
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-15 20:33:45 +02:00
Clement Verna
91ae7b8907 Orchestrator is not needed in prod yet
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-15 19:51:00 +02:00
Kevin Fenzi
e38d96a2f9 fedmsg-irc needs python-twisted-words 2018-05-15 17:13:53 +00:00
Pierre-Yves Chibon
6435ac4b1d Add SAR support/script for fedocal
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-15 15:20:26 +02:00
Aurélien Bompard
2d61c84f2d HyperKitty SAR script: fix env var name 2018-05-15 11:41:45 +00:00
Kamil Páral
9bb4484adc resultsdb-dev: add fedmsg variables
Try to fix fedmsg tracebacks: https://pagure.io/taskotron/issue/263

Also synchronize resultsdb-{dev,stg,prod} files a bit to allow easy
comparison.
2018-05-15 13:17:22 +02:00
Aurélien Bompard
f04a671634 Add the HyperKitty SAR script 2018-05-15 10:32:12 +00:00
Clement Verna
04a42607e9 Be consistent in the secret naming
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-15 08:43:29 +02:00
Kevin Fenzi
c0194de91e we need make and no longer need mash 2018-05-15 05:38:38 +00:00
Kevin Fenzi
8085f13e92 still need python2-koji for block_retired 2018-05-15 05:22:01 +00:00
Kevin Fenzi
8a52115016 actually change the right builder 2018-05-15 04:52:18 +00:00
Kevin Fenzi
96e82f31ba reinstall buildvm-armv7-23 with f27 2018-05-15 02:17:22 +00:00
Ricky Elrod
912be066dd Revert "what if the owner of the files actually existed?"
This reverts commit 75730d40c9.
2018-05-15 01:55:01 +00:00
Ricky Elrod
75730d40c9 what if the owner of the files actually existed?
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-15 01:43:01 +00:00
Kevin Fenzi
411db5e667 1gb is not enough for a rhel7 install to work anymore 2018-05-15 01:36:25 +00:00
Ricky Elrod
9ee3b65f20 need pdc.d directory
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-14 23:48:00 +00:00
Kevin Fenzi
bf945905ff Do not use masher or a seperate modularity group for fedmsg certs 2018-05-14 23:45:22 +00:00
Stephen Smoogen
237e69e6c7 and move it to the right hardware 2018-05-14 23:23:47 +00:00
Stephen Smoogen
ed04ecc72b and we have a vh14 again 2018-05-14 23:23:00 +00:00
Ricky Elrod
9bf5e4f9d2 put old vh12 boxes on vh01.stg
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-14 21:36:51 +00:00
Ricky Elrod
697cd57b83 make virthost01.stg be in [staging]
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-14 21:24:40 +00:00
Kevin Fenzi
fe669daeb1 lets not forget staging composer 2018-05-14 20:49:19 +00:00
Kevin Fenzi
257d8d78f4 move rawhide/branched/compose-x86-01/02 to f28 2018-05-14 20:39:21 +00:00
Stephen Smoogen
1af5acea4f make virthost01.stg real in ansible 2018-05-14 20:16:43 +00:00
Pierre-Yves Chibon
deadff2000 Add the create_branch ACL to pagure's config on dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-14 21:30:36 +02:00
Kevin Fenzi
f1b716597d Add locking to rawhide and branched composes so we only run one at a time. 2018-05-14 19:03:53 +00:00
Clement Verna
82dd1da173 Add registry_secret_name to osbs-client defaults
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-14 19:36:22 +02:00
Randy Barlow
a29a854e2d Reference the SOP for SAR requests instead of inline docs.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-14 17:19:44 +00:00
Stephen Smoogen
7cd5ada92e and now I know how to add persistant storage 2018-05-14 16:54:56 +00:00
Randy Barlow
d545cfe01c bodhi-backend02 runs the SAR script, so it needs the vars.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-14 16:40:07 +00:00
Randy Barlow
4d7e1eb3ab Use umask to create the private SAR tarball.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-14 14:50:23 +00:00
Randy Barlow
a7aec206bd Run Bodhi's SAR script on backend02.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-14 14:36:38 +00:00
Randy Barlow
79db2df447 Add a GDPR SAR script and configure Bodhi to support it.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-14 14:23:03 +00:00
Clement Verna
4902cb0c07 Make the registry_secret_name optional in osbs.conf template
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-14 15:40:30 +02:00
Patrick Uiterwijk
7b9af8332c Use rngd on builders
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-14 13:54:22 +02:00
Clement Verna
f57315e0f1 Declare the registry secret name only in the playbook
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-14 12:07:28 +02:00
Kevin Fenzi
83059c1fbc revert haveged install on builders 2018-05-13 21:55:37 +00:00
Kevin Fenzi
45297394ef add haveged on builders for vm random 2018-05-13 21:30:03 +00:00
Kevin Fenzi
112f14f740 missing ) 2018-05-13 19:50:42 +00:00
Kevin Fenzi
a1a82b2ee7 increase oz time on aarch64 also 2018-05-13 19:44:26 +00:00
Kevin Fenzi
8f00a09b9b Switch this to use dnf instead of command. 2018-05-13 04:08:57 +00:00
Kevin Fenzi
98e4389cd8 Revert "koji_wellness plugin"
This reverts commit 3f5e36799a.
2018-05-13 01:45:48 +00:00
Kevin Fenzi
a9745b7e53 oops, it is already there 2018-05-13 01:36:03 +00:00
Kevin Fenzi
0a0c5025c1 add koji to external phx2 hosts for nagios 2018-05-13 01:08:07 +00:00
Leonardo Rossetti
3f5e36799a koji_wellness plugin
Signed-off-by: Leonardo Rossetti <me@lrossetti.com>
2018-05-13 00:47:40 +00:00
Ralph Bean
ed44e7f0dc Only alert if we haven't seen a greenwave message in 2 days. 2018-05-12 14:20:48 +00:00
Kevin Fenzi
84d27bf694 add bodhi03 back to inventory 2018-05-12 04:19:01 +00:00
Kevin Fenzi
f72783414c Revert "switch bodhi web fedmsg key to be more accurate"
This reverts commit 3e124b70ae.
2018-05-12 04:18:05 +00:00
Kevin Fenzi
3e124b70ae switch bodhi web fedmsg key to be more accurate 2018-05-12 01:55:12 +00:00
Kevin Fenzi
4622fd7805 also add openshift apps to master playbook 2018-05-11 22:57:49 +00:00
Jeremy Cline
e41fd13b9a Drop the distributed lock for FMN's redis caching
By default, locks in redis never expire. This can lead to a deadlock if
a worker dies unexpectedly while trying to create a cache entry, which
leaves the lock in redis for the rest of time. When a worker attempts to
refresh the cache later, it'll wait on the lock permanently. We could
set the "lock_timeout" key in the dogpile.cache configuration, but
realistically we don't need to lock at all. Populating the cache is a
single GET request and we only have a couple workers so if they happen
to try the same entry at the same time, we'll just have 4-5 requests
instead of 1.
2018-05-11 19:36:25 +00:00
Kevin Fenzi
28790ecebe finish cleanup of old bodhi frontend web vms 2018-05-11 19:12:44 +00:00
Kevin Fenzi
223d47519b upgrade os playbook to 3.9.29 2018-05-11 18:32:44 +00:00
Kevin Fenzi
25e0e202b5 Remember to actually register the output 2018-05-11 18:15:41 +00:00
Kevin Fenzi
49454289a6 disable for now pagures recursive chown git.git because it now fails when there are broken synmlinks 2018-05-11 17:43:06 +00:00
mprahl
3b741752a3 Add the MBS URL to the pdc-updater configuration 2018-05-11 16:49:58 +00:00
Kevin Fenzi
1a4710e65f this needs set on 03 also 2018-05-11 16:43:16 +00:00
Ralph Bean
a4bae0fdb9 Disable all greenwave rules. 2018-05-11 15:16:11 +00:00
Mikolaj Izdebski
9d3e45a731 Fix /etc/osbs directory creation 2018-05-11 08:11:09 +00:00
Clement Verna
0ab13ec894 Make sure that /etc/osbs directory exists on the buildvms
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-11 10:05:14 +02:00
Clement Verna
babcbfc0c1 Update the name of the handlers
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-11 07:37:42 +02:00
Patrick Uiterwijk
eeafb0cff3 Only do three concurrent pushes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-10 23:31:20 +02:00
Patrick Uiterwijk
5edea3c3ef Sign and move the rawhide modules from updates-candidate
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-10 23:13:51 +02:00
Kevin Fenzi
732f8b880d start compressing logs on pagure01 2018-05-10 20:22:49 +00:00
Kevin Fenzi
f7e030bdc9 add bodh.update.comment to allowed fedmsgs from bodhi-backend01 2018-05-10 19:49:39 +00:00
Robert Mayr
14cb99687d add prerelease redirect for alt.fp.o 2018-05-10 19:27:16 +00:00
Clement Verna
219b2d78b9 Maybe this should be using a loop
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 21:09:45 +02:00
Clement Verna
d49f0cdf21 Add the missing label command
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 21:01:32 +02:00
Clement Verna
c180d0a679 Fixing the syntax
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 20:58:03 +02:00
Clement Verna
8243ad3b1e Add the labels on the nodes for the scheduler
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 20:48:48 +02:00
Kevin Fenzi
5b62c6b8a1 move bodhi-backend01.stg to vh05 2018-05-10 18:30:23 +00:00
Tim Flink
7c55221fe0 fixing upstreamfirst pagure template for 4.0 2018-05-10 16:56:04 +00:00
Ralph Bean
274dac7069 Try building waiverdb the same way as greenwave. 2018-05-10 16:39:09 +00:00
Ralph Bean
2e09154b58 Make these into templates. 2018-05-10 16:39:09 +00:00
Tim Flink
ff64508291 updating upstreamfirst pagure frontend bits for 4.0 upgrade 2018-05-10 16:34:29 +00:00
Ralph Bean
3bf9334b6f Try out greenwave deployments from a :prod tag. 2018-05-10 16:20:07 +00:00
Ralph Bean
96f19cbee6 Revert "Remove my greenwave-staging experiment to get out of lholecek and giulia's way."
This reverts commit 31c7305313.
2018-05-10 16:16:08 +00:00
Ralph Bean
34f284397a A version update for staging greenwave. 2018-05-10 15:57:24 +00:00
Ralph Bean
274fa478d7 Build greenwave on top of f28. 2018-05-10 15:35:28 +00:00
Ralph Bean
31c7305313 Remove my greenwave-staging experiment to get out of lholecek and giulia's way. 2018-05-10 15:32:01 +00:00
Clement Verna
dd203403db Use docker_image module instead of command
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 16:01:31 +02:00
Ralph Bean
b23be38477 This shouldn't be required. 2018-05-10 13:38:56 +00:00
Ralph Bean
7a4769506d A different filename. 2018-05-10 13:29:07 +00:00
Clement Verna
ae5cbb4fc9 Use systemd module instead of systemctl command
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 15:25:16 +02:00
Clement Verna
2b3df81154 always_run module is deprecated
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 15:21:01 +02:00
Clement Verna
4125fff1eb Use the command module, since we do not need the environment provided by shell
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 15:05:27 +02:00
Clement Verna
62784f9536 Be consistent with docker certs naming
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-05-10 14:37:56 +02:00
Patrick Uiterwijk
7f9d48bbf1 Revert "Let's only start the services for now"
These services must run on system start or parts of Pagure will be down

This reverts commit 75cafd3584.
2018-05-10 13:25:22 +02:00
Patrick Uiterwijk
a70160edf7 For now, allow unsafe-eval for Pagure...
https://pagure.io/pagure/issue/3220

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-10 10:51:00 +02:00
Adam Williamson
8b561f12a6 Correct a stray extra line in previous commit
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-05-09 15:12:07 -07:00
Adam Williamson
38a6abeae5 openqa_worker: install and enable rngd on some worker hosts
Some of the worker hosts have hardware RNGs (but not the x86_64
ones). Install rng-tools and enable rngd.service on these to
hopefully help with the Rawhide RNG issue.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-05-09 15:03:15 -07:00
Randy Barlow
c75e8777c5 Disable test gating in production.
FESCo voted today to disable test gating, at least until our
Friday meeting where we will discuss it further.

[0] https://pagure.io/fesco/issue/1872

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-09 21:07:33 +00:00
Ricky Elrod
079b6cb422 at least make it SOMEWHAT prettier
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 20:19:07 +00:00
Ricky Elrod
72e25721d2 try adding a playbook to run the drive check script on remote boxen
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 20:14:00 +00:00
Nick Bebout
fbd69797b0 Update ham-radio-exams alias for SELF2018 2018-05-09 18:14:24 +00:00
Adrian Reber
edf8b23f12 mm2_crawler: reduce number of threads and increase timeout
This reduce the number of threads used per category by one for each
category. mm-crawler02 sometimes has to OOM kill one of the crawlers and
by using less crawl threads the crawler should not OOM any more. This
needs to be monitored to find the optimal number of threads.

This also increases the timeout for the archive crawling from 4 hours to
5 hours.

Signed-off-by: Adrian Reber <adrian@lisas.de>
2018-05-09 17:23:29 +02:00
Ricky Elrod
93e3b9f7b0 Revert "Shorten commit URLs in irc messages..."
This reverts commit ddc5d6e7ed.
2018-05-09 14:12:28 +00:00
Randy Barlow
967be83623 Upgrade production to bodhi-3.7.0-1.fc27.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-09 14:00:41 +00:00
Randy Barlow
6b90121bb5 bodhi-dequeue-stable is not weekly anymore.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-09 13:58:58 +00:00
Patrick Uiterwijk
08d4e3f7b0 Force TLSv1.2 so we get a TLS handshake
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-09 07:28:51 +02:00
Ricky Elrod
a528da29d8 pre_tasks
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 04:48:18 +00:00
Stephen Smoogen
749a061468 put the proxy01.stg on virthost05 until replace 2018-05-09 04:04:15 +00:00
Patrick Uiterwijk
9b2739908b Update ODCS config with new spec for users and groups
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-09 05:39:23 +02:00
Stephen Smoogen
eb03b3de86 sad trombone 2018-05-09 03:07:05 +00:00
Stephen Smoogen
6694446829 put the host on 17 2018-05-09 02:57:02 +00:00
Ricky Elrod
6647d16def make it https while we are at it
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:56:46 +00:00
Ricky Elrod
d42c2cf202 test
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:55:42 +00:00
Ricky Elrod
ea60710e5c add a tag here
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:54:24 +00:00
Ricky Elrod
ddc5d6e7ed Shorten commit URLs in irc messages...
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:52:55 +00:00
Stephen Smoogen
6b501be0ee oh yeah consistency 2018-05-09 02:50:37 +00:00
Stephen Smoogen
d434948389 lets put datagrepper on 19 2018-05-09 02:49:51 +00:00
Ricky Elrod
e406650ac1 move fedocal02 and elections02 to vh6
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:37:02 +00:00
Stephen Smoogen
6a7d5a8773 and put blockerbugs on 15 too 2018-05-09 02:33:48 +00:00
Stephen Smoogen
44fa10728a because of course we have no consistency in group names 2018-05-09 02:32:50 +00:00
Ricky Elrod
27a78a02ef Merge branch 'master' of /git/ansible 2018-05-09 02:31:35 +00:00
Ricky Elrod
c32629e898 move fas03 to vh06
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-09 02:31:29 +00:00
Stephen Smoogen
3d73c27250 put github2 onto virthost15 2018-05-09 02:31:09 +00:00
Kevin Fenzi
8a0f18b3f4 doesnt seem to help 2018-05-09 02:23:32 +00:00
Stephen Smoogen
8cf93604de make the disks right 2018-05-09 02:23:11 +00:00
Stephen Smoogen
84ece562a2 move badges to other hosts 2018-05-09 02:22:00 +00:00
Kevin Fenzi
cb22afd4fe Look, ask has moved away. I'm sure it will write us back someday... 2018-05-09 02:00:45 +00:00
Kevin Fenzi
8d382c95ac try server here 2018-05-09 01:45:25 +00:00
Kevin Fenzi
ca6ced93bf see if this gets aarch64 vms booting 2018-05-09 01:42:27 +00:00
Kevin Fenzi
2ec9a16a71 fix aarch64 ks repo 2018-05-09 00:36:34 +00:00
Randy Barlow
ec08ff5143 Upgrade staging to bodhi-3.7.0-1.fc27.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-09 00:17:53 +00:00
Randy Barlow
0f3d5ddc87 Upgrade staging to bodhi-3.7.0b3.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-08 21:41:29 +00:00
Kevin Fenzi
12f15295d2 there is no excuse to use http here. Make sure all is https 2018-05-08 20:36:39 +00:00
Kevin Fenzi
d5cee42dd2 add a tag 2018-05-08 20:30:35 +00:00
Kevin Fenzi
e80e8b3abb remove builder-infrastructure repo 2018-05-08 20:30:00 +00:00
Kevin Fenzi
d967e989c8 remove awx for now from haproxy 2018-05-08 20:22:27 +00:00
Kevin Fenzi
a6d41cf1b8 and also fix the secondary stuff 2018-05-08 20:01:28 +00:00
Kevin Fenzi
8095747fa1 ok, I guess we have to template these; 2018-05-08 19:53:52 +00:00
Kevin Fenzi
aa760f16c2 more adjustments 2018-05-08 19:45:38 +00:00
Patrick Uiterwijk
979c8cb327 Double 'and' does not work
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-08 21:39:04 +02:00
Kevin Fenzi
d016b0e2de clean that up and see if this works 2018-05-08 19:35:28 +00:00
Kevin Fenzi
73857351f3 try and handle changed path in f28+ for updates/updates-testing 2018-05-08 19:29:05 +00:00
Kevin Fenzi
bdd9841725 This won't work if we have some hosts on different virthosts. 2018-05-08 18:45:54 +00:00
Kevin Fenzi
c1ac4fb83a aarch64 under primary location for f28+ 2018-05-08 18:34:59 +00:00
Kevin Fenzi
38385645b2 move all the armv7/aarch64 vms to f28 also 2018-05-08 18:00:54 +00:00
Kevin Fenzi
c19bfc7518 Allow bodhi web in openshift to send fedmsgs (but keep bodhi03 around for now to overlap) 2018-05-08 18:00:27 +00:00
Stephen Smoogen
bb3e88188a remove the bodhi from the haproxy 2018-05-08 15:52:19 +00:00
Randy Barlow
68f6a6613a Use the correct variable name for Bodhi's staging wavierdb token.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-08 13:33:57 +00:00
Randy Barlow
b5a0da57e8 Give staging Bodhi an OIDC token for WaiverDB.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-08 13:12:18 +00:00
Mikolaj Izdebski
63a80fa388 Try again to respin ppc64-test on F28
This reverts commit ef08d17409.
2018-05-08 09:23:17 +00:00
Mikolaj Izdebski
2a9c0ed2d0 Install anacron on java-deptools 2018-05-08 08:51:06 +00:00
Peter Robinson
15d48149df compose-iot: update kickstart 2018-05-08 08:36:15 +00:00
Mikolaj Izdebski
ef08d17409 Revert ppc64-test to F27 2018-05-08 04:13:14 +00:00
Mikolaj Izdebski
d70d098d40 Reinstall java-deptools on Fedora 28 2018-05-08 03:30:03 +00:00
Mikolaj Izdebski
674d178a6e Respin PowerPC maintainer-test instances on Fedora 28 2018-05-08 03:24:10 +00:00
Mikolaj Izdebski
ae29faa319 Rebase f28-test VM on F28 GA image 2018-05-08 03:08:59 +00:00
Kevin Fenzi
adf233e961 Revert "ok, how about this?"
This reverts commit 7ec4217fd4.
2018-05-08 02:06:19 +00:00
Kevin Fenzi
7ec4217fd4 ok, how about this? 2018-05-08 02:04:36 +00:00
Kevin Fenzi
a86cd63c69 ok, perhaps a longer poll time would help libvirt 2018-05-08 02:01:03 +00:00
Kevin Fenzi
68268332bb Sometimes virt status is returning a 'no such object' error, so lets ignore those for now. 2018-05-08 01:50:20 +00:00
Kevin Fenzi
9c9ee7c534 I guess lets try not using group nrpe.. 2018-05-08 00:36:41 +00:00
Kevin Fenzi
d3cfabb9af ok then, lets try here. 2018-05-08 00:30:06 +00:00
Kevin Fenzi
edde978768 Try this to avoid undefined variable on buildvm playbooks 2018-05-08 00:26:21 +00:00
Kevin Fenzi
a78b607427 Perhaps we need to do this now to keep libvirt from stepping on itself. 2018-05-08 00:14:45 +00:00
Kevin Fenzi
a8714caab3 first cut at changing all the old |changed to is changed per ansible deprecations 2018-05-07 23:51:48 +00:00
Kevin Fenzi
56123c0d24 move buildvms to f28 also 2018-05-07 23:06:29 +00:00
Kevin Fenzi
5b9d5e2125 switch the ppc64{le} buildvms over to f28 2018-05-07 20:18:05 +00:00
Randy Barlow
da5d97f9f7 Upgrade staging to bodhi 3.7.0b2.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-07 17:51:25 +00:00
Ricky Elrod
550610d96f nuke bodhi01.stg and batcomputer01
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-05-07 17:01:25 +00:00
Peter Robinson
310c085fa9 virt-install: add RNG to VMs 2018-05-07 16:50:45 +00:00
Patrick Uiterwijk
070e889cf4 When running oc commands, make sure to pass namespace (project)
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-07 15:57:26 +02:00
Peter Robinson
abef7d2730 compose-iot: rename in inventory list 2018-05-07 13:05:59 +00:00
Peter Robinson
695034684e compose-iot: rename/re-ip 2018-05-07 13:02:05 +00:00
Dennis Gilmore
7d2072f8f1 cleanup notifications
Set pdc notifications to go to Mohan
remove nagios notifications

Signed-off-by: Dennis Gilmore <ausil@fedoraproject.org>
2018-05-07 12:46:14 +00:00
Ryan Lerch
a89a657fb0 add new 1.2.0 version of Fedora Bootstrap 2018-05-06 19:54:20 +00:00
Patrick Uiterwijk
238a213c66 Sync out f28m-u
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-05 20:45:03 +02:00
Patrick Uiterwijk
7d0ad85b1c Fix iot signature config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-05 15:14:24 +02:00
Ralph Bean
8c490ba88a Modernize waiverdb playbook. 2018-05-05 02:42:52 +00:00
Ralph Bean
60f14d380d Whitespace. 2018-05-05 02:27:16 +00:00
Ralph Bean
9283609e41 Greenwave: Test out RemoteOriginalSpecNvrRule, in staging. 2018-05-05 02:13:01 +00:00
Ralph Bean
5c095a6bda fedmsg needs a username. 2018-05-05 01:52:54 +00:00
Ralph Bean
95a752a8ba dockerStrategy, not sourceStrategy. 2018-05-05 01:37:48 +00:00
Ralph Bean
ca8442787c Declare sourceStrategy. 2018-05-05 01:35:50 +00:00
Ralph Bean
5e0e6d1881 Greenwave fedmsg config in staging. 2018-05-05 01:23:48 +00:00
Randy Barlow
4d6d34cdbf Update staging to Bodhi 3.7.0b1.
Additionally, pin the container to use Fedora 27 since Bodhi 3.7
is in the f27-infra repo.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-05 00:10:55 +00:00
Kevin Fenzi
37464762bb quotes? 2018-05-04 21:47:02 +00:00
Kevin Fenzi
fdeae4e629 adjust command for new os 2018-05-04 21:46:14 +00:00
Robert Mayr
d2d0be6223 add friulian also to alt, spins, arm and labs 2018-05-04 21:12:08 +00:00
Kevin Fenzi
3dee3af273 also ignore resultsdb.result.new in fedora-fedmsg 2018-05-04 20:30:45 +00:00
Patrick Uiterwijk
f8e4f40dc1 Add bodhi-backend03 as "fake"
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 21:18:03 +02:00
Patrick Uiterwijk
f85da25490 Add dl.fp.o/iot/repo
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 17:26:48 +00:00
Patrick Uiterwijk
3ec8875b9f Compose-iot does pungi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 17:17:19 +00:00
Stephen Smoogen
59b547828d lets remove this bodhi stuff. its all in dockah now 2018-05-04 15:07:05 +00:00
mprahl
9603f59db6 Fix the path to the defaults modules during MBS upgrades 2018-05-04 14:46:45 +00:00
mprahl
d35630c9ee Add missing var in the MBS upgrade playbook 2018-05-04 14:41:08 +00:00
mprahl
6585d7a7ed Import default modules after the DB migration when MBS is upgraded 2018-05-04 14:36:51 +00:00
Robert Mayr
784d2f6d98 add friulian language for getfedora.org 2018-05-04 12:40:37 +00:00
Patrick Uiterwijk
aa9414b518 Set up signing for IOT trees
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 13:45:33 +02:00
Patrick Uiterwijk
14bd7fdd7a dl.fp.o has images
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 12:12:17 +02:00
Patrick Uiterwijk
6b226530d4 Allow inline style for pagure
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 12:08:49 +02:00
Patrick Uiterwijk
5171e61866 Do not allow inbound sslv2/sslv3
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 03:04:21 +02:00
Patrick Uiterwijk
005d6913f5 Secure dl.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 02:46:31 +02:00
Patrick Uiterwijk
2d8917470a Set security headers for dl.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-04 02:42:36 +02:00
Robert Mayr
4c4ece38e7 add friulian language to the websites 2018-05-03 21:51:30 +00:00
Randy Barlow
096edb164a Add markers to highlight where to begin and end copy/pasta on oidc script.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-03 21:18:34 +00:00
Randy Barlow
b5cf0d7844 Correctly format the expiration time and issue time.
Additionally:
- Require at least one scope to be provided.
- Print out a more descriptive usage of the SQL.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-03 21:11:01 +00:00
Randy Barlow
4b7005471c Add a script to help generate OIDC tokens.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-05-03 20:48:00 +00:00
Dusty Mabe
fba20b249b new-updates-sync: make log statement more accurate
The Ostree ref has now been synced from the source repo
so the destination repo is now at src_commit.
2018-05-03 16:22:20 -04:00
Mohan Boddu
7e86c49fe3 Fix Pre and Post Beta Bodhi policies
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-05-03 20:06:37 +00:00
Patrick Uiterwijk
a785e4fe06 Add missing import line
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 19:24:01 +00:00
Kevin Fenzi
f210676984 rats nest 2018-05-03 18:13:34 +00:00
Kevin Fenzi
c77390a231 try this a different way 2018-05-03 18:01:25 +00:00
Kevin Fenzi
8ddb528da7 fix dyslexia 2018-05-03 17:33:48 +00:00
Mohan Boddu
edc34b52ee F28 is GA and dont need of any policy changes
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-05-03 17:25:53 +00:00
Kevin Fenzi
e9f8eec98e fix missing quotes 2018-05-03 17:14:30 +00:00
Kevin Fenzi
25a67c0c2d set labels and masters to be sched for OS 3.9 2018-05-03 16:49:18 +00:00
Patrick Uiterwijk
0a67342490 Also allow 'self' for pagure resources
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 17:32:56 +02:00
Nick Bebout
676afa48ae Add bex and asamalik to tahrir.admin 2018-05-03 14:42:09 +00:00
Nick Bebout
32c5586957 Add churchyard to tahrir.admin 2018-05-03 13:47:08 +00:00
Tim Flink
df4c2e8590 adding sysadmin-qa as sudoers for qa db machines 2018-05-03 13:01:57 +00:00
Patrick Uiterwijk
efd3747206 Koji-gc does not work with modules. Let's exclude them for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 14:27:42 +02:00
Patrick Uiterwijk
8edbe4ea29 Remove the vars{} stuff... That does not work
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 12:07:43 +00:00
Patrick Uiterwijk
51769d8533 Change when
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 13:59:10 +02:00
Patrick Uiterwijk
09a12cf4b5 When we try to apply project.yml, the namespace does not yet exist
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 13:58:06 +02:00
Patrick Uiterwijk
0932860a71 We have bootstrap from apps.fp.o :(
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 12:47:20 +02:00
Patrick Uiterwijk
f13980e99d For pagure, allow everything but scripts from https:
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-05-03 12:43:54 +02:00
Pierre-Yves Chibon
14b15f5062 Split tasks by priority on pagure01
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 12:32:44 +02:00
Pierre-Yves Chibon
76dcfec4b0 Update the systemd service file for dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 12:30:36 +02:00
Pierre-Yves Chibon
b22cdd3e17 Always send fedmsg notification on dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 12:08:59 +02:00
Pierre-Yves Chibon
9875b043d3 Drop the fedmsg_hook since it no longer exists
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 12:07:40 +02:00
Pierre-Yves Chibon
840dea9774 Port the .wsgi file to pagure 4.0
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 10:41:27 +02:00
Pierre-Yves Chibon
4c96fae6b1 Port the .wsgi file to pagure 4.0
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-05-03 10:40:13 +02:00
Pierre-Yves Chibon
3b1e225f73 Add missing get_default_branch 2018-05-03 10:40:13 +02:00
Aurélien Bompard
83b96e633d HyperKitty: add GDPR warning on the login page 2018-05-03 07:43:29 +00:00
Kevin Fenzi
c3bf8f3fed add some tags 2018-05-02 21:21:24 +00:00
Kevin Fenzi
3cab6a7939 try upgrading again 2018-05-02 21:11:26 +00:00
Kevin Fenzi
11ceb0ce6a put 3.7 back, the playbook needs to update things 2018-05-02 21:06:57 +00:00
Stephen Smoogen
11b41b21f2 aa:aa:aa:aa:aa:aa does not work for this box 2018-05-02 20:45:33 +00:00
Kevin Fenzi
2f9adefc1f lets try letting the upgrade do rolling reboots 2018-05-02 20:30:40 +00:00
Kevin Fenzi
770acb023b fix typo 2018-05-02 19:53:46 +00:00
Kevin Fenzi
4bc6964bae lets try and upgrade openshift in staging to 3.9 2018-05-02 19:51:41 +00:00
Kevin Fenzi
81d03d71da Also need partner-bz to use external ip in stg. 2018-05-02 19:14:33 +00:00
Paul W. Frields
1346400dde Copy fedmenu staging change to prod 2018-05-02 19:08:50 +00:00
Kevin Fenzi
c8e2ccf562 Add tokenfile=None to prevent trying to use a token 2018-05-02 19:04:52 +00:00
Kevin Fenzi
d55018a9d3 clean up more jenkins leftovers 2018-05-02 17:26:25 +00:00
Stephen Smoogen
ed862a2e02 put in all the mac address for cloud boxes 2018-05-01 22:12:39 +00:00
Stephen Smoogen
8563819678 fix nagios 2018-05-01 18:44:49 +00:00
Paul W. Frields
c12adb989d Update fedmenu in staging with Legal link 2018-05-01 12:38:38 +00:00
Kevin Fenzi
4bbe5105e2 re-add redirects for prerelease 2018-05-01 12:20:58 +00:00
Patrick Uiterwijk
c77dd04246 Make bodhi openshift logs slightly more sane
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-30 19:02:02 +02:00
clime
5a45d3c34e copr-builder: add open-suse mock configs 2018-04-30 11:58:40 +02:00
Patrick Uiterwijk
d1b5526740 Make new-updates-sync resync on re-stage without need for state deletion
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-30 02:19:53 +02:00
Mohan Boddu
086a0f7032 Enable F28 nightlies
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-04-27 18:28:12 +00:00
Randy Barlow
d7cb9de0af Use bodhi-3.7.0-0.0.beta on staging.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-27 17:36:50 +00:00
Clement Verna
39acdd1e61 Fix Dockerfile
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-27 17:05:57 +02:00
Clement Verna
d1502140cd Use the correct path
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-27 16:48:06 +02:00
Clement Verna
53f0ed497c Make sure we have the latest krb5.conf in the buildroots
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-27 16:35:45 +02:00
clime
01b3cc1be1 copr-builder: images updated 2018-04-27 11:34:44 +02:00
clime
6f4c96f5f2 copr-builder: clean dnf cache before installing latest packages 2018-04-27 07:03:12 +02:00
Kevin Fenzi
7606be6195 forgot the trailing Everything dir 2018-04-27 03:42:13 +00:00
Kevin Fenzi
441be3d4ee We also need to sync the f28 stable updates content. 2018-04-27 00:52:57 +00:00
Patrick Uiterwijk
6a1ad7870d Fix small string format error
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-27 01:06:24 +02:00
Dusty Mabe
40c32c97f2 bodhi-pungi: make FAW and FAH use same versioning
We'll get nicer versions, like: 28.20180426.0
2018-04-26 16:17:41 -04:00
Mohan Boddu
ac8cc05119 Bodhi F28 release status update
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-04-26 20:06:05 +00:00
Patrick Uiterwijk
fc5a02530d Make new-updates-sync always print status and email to releng-cron
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-26 21:45:14 +02:00
Stephen Smoogen
f0417181ee and we do have a proxy05 2018-04-26 15:40:14 +00:00
Stephen Smoogen
ca4e65efce remove some jenkins lines 2018-04-26 15:40:14 +00:00
clime
c56b26fb0a copr-frontend: install a newer version of xstatic-jquery-ui-common 2018-04-26 17:21:56 +02:00
Clement Verna
57382e1cb6 This is needed to authenticate with koji stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 15:10:28 +02:00
Clement Verna
a2f15457f3 Missing a colon in the file path
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 15:02:13 +02:00
clime
064d1eee41 copr-builder: add default rpkg conf 2018-04-26 14:50:45 +02:00
Clement Verna
d92ff97453 Add the tag to all play and fix template
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 14:35:36 +02:00
Clement Verna
221e04cdfc Add a tag for orchestrator namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 14:32:10 +02:00
Clement Verna
f481da9f35 add koji kerberos settings to the default vars
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 14:30:13 +02:00
Clement Verna
597cce99e5 Let be consistent in the template
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 14:17:04 +02:00
Clement Verna
381e29dbbe Add the koji kerberos setting to OSBS worker config
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-26 13:48:18 +02:00
clime
cc2c6c0cff copr-rpmbuild: update copr-rpmbuild config 2018-04-26 10:32:33 +02:00
Adrian Reber
e18e308e28 mirror crawler: crawl each category separately
This is the first try to split up the mirror crawling by category. One
of the goals is to better distribute the load on the database. If this
actually works the effects of this change have to be monitored.

Another result could be that mirrors do not get auto-deactivated that
fast. Previously there was a crawl timeout of 4 hours for all categories
together. Now it is 4 hours per category.

Signed-off-by: Adrian Reber <adrian@lisas.de>
2018-04-26 09:47:56 +02:00
Stephen Smoogen
1139a7b6de the butler did it in the basement with a 2x4 2018-04-26 01:30:33 +00:00
Stephen Smoogen
61a8ae20db nope this is that time I go and say durrrr 2018-04-25 23:46:12 +00:00
Stephen Smoogen
3b359d574d for the love of pete.. can you get one thing right tonight? 2018-04-25 23:34:06 +00:00
Stephen Smoogen
bd3f893961 you know what helps? having a certificate 2018-04-25 23:17:24 +00:00
Stephen Smoogen
f7ca003930 tags must be a list you silly bean 2018-04-25 22:54:19 +00:00
Stephen Smoogen
c61209d0f1 we are strong 2018-04-25 22:41:32 +00:00
Stephen Smoogen
0b2cbe69c9 this will make us go. Geordi makes us strong. Smooge needs to lay off benadryl 2018-04-25 22:41:06 +00:00
Adam Williamson
c01bdeee92 check-compose: update template to fix Atomic compose mails
The special configuration for check-compose mails for two-week
Atomic nightly composes was broken due to fedfind changes. We
need to tweak this template a bit as part of fixing it up.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-04-25 14:10:58 -07:00
Sayan Chowdhury
8b776bcf1c fedimg: Add the newer 3 regions
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-25 20:50:25 +00:00
Sayan Chowdhury
8f56ce4b93 fedimg: Remove the earlier three pushed hotfix
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-25 20:50:17 +00:00
Stephen Smoogen
637dcfcd86 and keys02 is keys01 2018-04-25 19:26:32 +00:00
Ricky Elrod
8cbfc07161 try to tag this too
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-25 16:25:39 +00:00
Adam Williamson
342bab110b relvalconsumer: allow fedmsg-hub to write the token cache
Been getting access denied errors lately, and from a look at
the python-openidc-client code, seems that clients may need to
write as well as read the token cache sometimes.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-04-25 09:01:48 -07:00
Dusty Mabe
88a5b49795 new-updates-sync: allow for just syncing ostrees
Previously it was not able to sync just an ostree and
not a repo (i.e. an empty to: [], like we have right now
for f28).
2018-04-25 10:32:21 -04:00
Dusty Mabe
fdb02f3e82 new-updates-sync: convert tab to space 2018-04-25 10:31:52 -04:00
Dusty Mabe
0c94490c57 new-updates-sync: fix some syntax errors 2018-04-25 10:12:50 -04:00
clime
617a02ec26 copr-builder: use new updated images 2018-04-25 13:01:23 +02:00
Pierre-Yves Chibon
cd393dba54 Fix the cron job fixing the git hooks and run it more frequently
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-25 10:39:00 +02:00
Clement Verna
bb8aa762c8 Make sure we have the registry secret on the buildvm config
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-25 07:38:38 +02:00
clime
2feef88231 copr-builder: use the same condition to enable @copr/copr-dev as for infra-stg 2018-04-25 07:20:18 +02:00
clime
21a1d4da5d copr-builder: write the when test condition as a list actually 2018-04-25 06:57:00 +02:00
clime
1faf31fa4a copr-builder: improve prepare_base_image handling 2018-04-25 06:36:20 +02:00
Ricky Elrod
b8e61c03bc add a tag here, though not sure if it works that way
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-25 01:02:44 +00:00
Clement Verna
2343abb711 Use the correct push certificate
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-24 21:43:40 +02:00
Stephen Smoogen
a3129779bd broke inventory 2018-04-24 18:40:31 +00:00
Stephen Smoogen
f2112dd59f try to make hardware as a target 2018-04-24 18:15:27 +00:00
Stephen Smoogen
00b7f0b8dc and to make sure we dont watch netapp stuff in the future 2018-04-24 18:06:24 +00:00
Stephen Smoogen
dfa0191633 and this will just ignore tmpfs overlay no matter the name 2018-04-24 17:17:11 +00:00
Randy Barlow
06721f5266 Also install bodhi-composer on prod.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-24 17:06:01 +00:00
Stephen Smoogen
c3ce541909 so it looks like df uses directory trees and not patterns 2018-04-24 16:40:09 +00:00
Stephen Smoogen
bf9c8d4dba the syntax assumes df- already 2018-04-24 16:21:45 +00:00
Stephen Smoogen
1011d0eeed add filters to stop over collection 2018-04-24 16:05:51 +00:00
Patrick Uiterwijk
4904468ec3 Commit bodhi on openshift stabilization fixes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-24 17:08:08 +02:00
Patrick Uiterwijk
3c57dcaab4 Revert "Revert "Switch production back to Openshift""
This reverts commit d5abfd49d9.
2018-04-24 14:21:42 +00:00
Clement Verna
38accb33e6 We do need a registry secret
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-24 15:58:36 +02:00
Sayan Chowdhury
bdc46138f2 releng: Use template instead of copy for purge-amis
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-24 08:42:49 +00:00
Patrick Uiterwijk
d5abfd49d9 Revert "Switch production back to Openshift"
This reverts commit 1ea687d593.
2018-04-24 00:31:34 +00:00
Dusty Mabe
7d9ac8d314 new-updates-sync: add syncing for F28AH updates ostree
Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-04-23 20:30:55 -04:00
Dusty Mabe
5611b18b64 bodhi-pungi: only do AH artifact creation for f28-u-t for now
We'll start doing it for f28-u when we get the kinks worked out
after the first F28 Atomic Host release.

Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-04-23 20:30:55 -04:00
Dusty Mabe
e6e5ed59b0 robosig: add new refs for f28 atomic host
Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-04-23 20:30:52 -04:00
Patrick Uiterwijk
1ea687d593 Switch production back to Openshift
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-23 23:24:22 +00:00
Patrick Uiterwijk
1cce3a7e0e MAke sure bodhi-backend have bodhi-composer
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-23 23:12:01 +00:00
Patrick Uiterwijk
ae9bea289d Update bodhi config for 3.6.1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-23 22:58:51 +00:00
Randy Barlow
3b187523d1 Use the bodhi-3.6.1 release.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-23 20:48:11 +00:00
Kevin Fenzi
50631e0dd6 Drop some old no longer referenced inventory host_vars 2018-04-23 20:28:48 +00:00
Randy Barlow
93278f9612 Upgrade to Bodhi beta 1.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-23 17:49:58 +00:00
Randy Barlow
a5e1542179 Include the release on the bodhi version.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-23 16:42:07 +00:00
Randy Barlow
c99ece376c Use Bodhi 3.6.1 on staging (and openshift, which isn't prod atm).
This commit also adjusts Bodhi to use dogpile cache's in-memory
backend, and adjusts the backend01 to install bodhi-composer.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-23 16:26:27 +00:00
Nick Bebout
6fe8c48df6 Update SKS membership file 2018-04-23 16:23:58 +00:00
Pierre-Yves Chibon
e671d4a984 Split the tasks into multiple queues on stg.pagure.io
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-23 16:38:04 +02:00
Pierre-Yves Chibon
724308a71a Turn back on the cron jobs on dist-git.stg, they got fixed
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-23 14:33:04 +02:00
Kevin Fenzi
0a06ef19b6 double memory on pdc-web in hopes it stops altering 2018-04-22 00:49:37 +00:00
clime
1666f6257a copr-keygen: set selinux to enforcing, add custom policy 2018-04-22 00:31:50 +02:00
Kevin Fenzi
5f4147e6b6 no spaces in cron hours or it is invalid 2018-04-21 18:28:10 +00:00
Dusty Mabe
61fc61dcd8 bodhi-pugni: ostree installer, subs arch into repo urls
Since we are using a for loop for ostree_installer let's go
ahead and substitute [[arch]] in the urls there.
2018-04-20 13:32:18 -04:00
Dusty Mabe
d082e5e8a9 bodhi-pungi: don't use for loop for arch, use $arch
It turns out we don't need a for loop for this, we just needed to
use $arch instead of $basearch in the URL. Also, the for loop doesn't
work because of koji unique NVR enforcement on image builds.
2018-04-20 13:32:15 -04:00
Ralph Bean
01d70107fc Update to match expected parameter. 2018-04-20 16:18:41 +00:00
Ralph Bean
a0314660d8 Typofix. 2018-04-20 16:17:03 +00:00
Ralph Bean
2b27955e96 Greenwave: No CI requirements for modules, today.
FBR:  https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedoraproject.org/thread/ELBICUXVROZFS3TWY74YSW7BJDDN6WDI/
2018-04-20 16:13:37 +00:00
Sayan Chowdhury
d15f80eab5 fedimg: Add the patch for the PR#103, fix processing Rawhide messages
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-20 15:42:13 +00:00
Sayan Chowdhury
d7b3d03551 fedimg: Add the intial files for PR#103
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-20 15:41:55 +00:00
Sayan Chowdhury
4616a67ec2 Revert "fedimg: Add the intial files for PR#103"
This reverts commit b62aa92015.
2018-04-20 15:41:24 +00:00
Sayan Chowdhury
4875d770c3 Revert "fedimg: Add the patch for the PR#103, fix processing Rawhide messages"
This reverts commit 865c918eb6.
2018-04-20 15:41:08 +00:00
Sayan Chowdhury
865c918eb6 fedimg: Add the patch for the PR#103, fix processing Rawhide messages
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-20 14:18:50 +00:00
Sayan Chowdhury
b62aa92015 fedimg: Add the intial files for PR#103
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-20 14:18:42 +00:00
Clement Verna
2f212ac9a8 Add again cverna to nagios permission
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-20 08:25:38 +02:00
Dusty Mabe
cfaaf3ac9d bodhi-pungi: Add AtomicHost variant
Otherwise we get messages like this when trying to create
Atomic Host artifacts:

```
[WARNING ] [OSTREE_INSTALLER] Patterns in config do not match any variant: ^AtomicHost$
```
2018-04-19 21:45:03 -04:00
Dusty Mabe
aa531848be bodhi-pungi: needed for loop one higher level up 2018-04-19 18:41:20 -04:00
Dusty Mabe
d458e55c8f bodhi-pungi: use AtomicHost variant for AH things
The compose today failed with:

```
[WARNING ] [OSTREE_INSTALLER] Patterns in config do not match any variant: ^Atomic$
```

There is no Atomic variant any longer. Let's use AtomicHost instead,
which will sync it up with what is done inthe pungi-fedora repo.
2018-04-19 18:14:51 -04:00
Dusty Mabe
feb33826b3 bodhi-pungi: fix image-build urls for install_tree_from
Since $basearch won't work in the url we need to manually
substitute arch. Make a for loop and specify a unique url
for each arch.
2018-04-19 18:14:48 -04:00
Kevin Fenzi
9bd9110781 Re-enable fedmsg hooks now that there is a acl allowing access to key 2018-04-19 16:42:36 +00:00
Patrick Uiterwijk
4a12209027 Define bodhi_Version in the playbook for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:39:49 +00:00
Patrick Uiterwijk
312c9f8cf6 Only do secret apply if changed
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 17:37:08 +02:00
Patrick Uiterwijk
633c64b7d2 Only oc apply if the file changed
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 17:35:26 +02:00
Patrick Uiterwijk
bb070496c3 Tie us to specific bodhi package versions
This also means that when we bump this and rerun ansible, openshift will
clear the build cache.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 17:10:02 +02:00
Patrick Uiterwijk
aa3b773f72 DNF is silly.... Why no option to specify this on the CLI? Nobody knows
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 17:04:49 +02:00
Patrick Uiterwijk
a60d438992 Tail logs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 14:48:15 +00:00
Patrick Uiterwijk
113a8b542f Install bodhi-docs for docs in openshift bodhi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 16:30:28 +02:00
Patrick Uiterwijk
96d1f3cc41 Update httpd bodhi conf
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 16:25:05 +02:00
Patrick Uiterwijk
9681d7d8f5 With httpd, no need for this mv
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:54:29 +02:00
Patrick Uiterwijk
1a0920ceee Just don't add whitespace. You don't remove waht you don't add
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 13:48:40 +00:00
Patrick Uiterwijk
671f033999 Again, this is an imagestream, not a route
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 13:48:02 +00:00
Patrick Uiterwijk
cb69ca6321 Try removing whitespace
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 13:47:03 +00:00
Patrick Uiterwijk
322ccb4b1b Fix variable name
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:39:54 +02:00
Patrick Uiterwijk
d32462f4c3 Fix copy-paste errors
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:38:43 +02:00
Patrick Uiterwijk
c2afa0c303 Remove trailing whitespace lines
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:26:36 +02:00
Patrick Uiterwijk
af327709d3 Switch bodhi on openshift from gunicorn to httpd
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-19 15:25:52 +02:00
Clement Verna
2839525202 We do not use the registry-secret
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-19 14:28:56 +02:00
Sayan Chowdhury
ad950dbcc3 fedimg: Checkin the patch for PR#100. Check if the AMI is complete before proceeding
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-19 07:50:48 +00:00
Sayan Chowdhury
6752f195d9 fedimg: Add the initial files for the hotfix, fix copied amis
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-19 07:50:48 +00:00
Randy Barlow
9f74f46187 Cache the Bodhi dockerfile in the OS buildconfig.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-18 22:18:02 +00:00
Clement Verna
63c288907f We do not use registry password/username
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 19:43:33 +02:00
Clement Verna
266c70935f We do not use ssl auth for koji
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 16:57:45 +02:00
Robert Mayr
c184550297 build staging websites with f28 branch 2018-04-18 14:53:48 +00:00
Clement Verna
1f1502cbe0 We don't need to specify that for the orchestrator
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 16:06:00 +02:00
Clement Verna
16e5f3fa19 Make sure we use the correct namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 15:30:06 +02:00
Clement Verna
ba4f7b05f8 Lets keep the default api versions
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 14:54:20 +02:00
Clement Verna
d642789316 Buildvm should have registry_secret_name
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 14:17:25 +02:00
Clement Verna
e57f7888ad Fix registry related configuration
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 14:14:45 +02:00
Miroslav Suchý
f429d744ad retrace: update roles from upstream 2018-04-18 13:24:08 +02:00
Clement Verna
4723c541f5 In staging, use the stg registry
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 13:12:39 +02:00
Clement Verna
119f83a90d Use stg openshift url in stg cluster
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 11:04:26 +02:00
Clement Verna
ec85250ba8 Token name needs to match worker cluster name
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-18 10:39:38 +02:00
Patrick Uiterwijk
9628ddfed5 Add tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-18 02:12:58 +00:00
Patrick Uiterwijk
48c1391b10 Bring bodhi frontend back to VMs for now
This reverts commit 2df768606f.
2018-04-18 02:10:10 +00:00
Kevin Fenzi
81125348a7 adjust tags to reality 2018-04-17 22:19:21 +00:00
Patrick Uiterwijk
be40a2bd4e Enable h2 for httpd/website
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 23:50:24 +02:00
Patrick Uiterwijk
e4ccaef4ca Add h2 tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 23:49:18 +02:00
Patrick Uiterwijk
979cf68f8b Re-enable h2
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 23:48:51 +02:00
Patrick Uiterwijk
47d5891ea1 Use correct repo url
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 21:45:32 +00:00
Patrick Uiterwijk
6833e584a5 Fix redirect
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:45:31 +00:00
Patrick Uiterwijk
c6ce3621b8 Move the ostree redirect to dl.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 22:43:33 +02:00
Clement Verna
fb0f8b35dc We do not use ssl login for koji
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-17 22:08:50 +02:00
Sayan Chowdhury
375f565fcc fedimg: Add the patch for the PR#99
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-17 20:06:44 +00:00
Sayan Chowdhury
ff88d963b5 fedimg: Place a hotfix for the PR#99, original files
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-17 20:06:44 +00:00
Patrick Uiterwijk
c72bca84f4 Use the correct location for F27 FAW
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 21:57:43 +02:00
Patrick Uiterwijk
6e51b543f7 Add reasoning
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 21:53:37 +02:00
Patrick Uiterwijk
e7cf461e0c Deploy 'brokenostreekojipkgs' to avoid https (and thus http/2) for ostree
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 21:51:27 +02:00
Clement Verna
024853883d serverca and ca are in fact not needed
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-17 21:40:42 +02:00
Clement Verna
127087f331 Add missing secrets for koji certs
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-17 21:21:22 +02:00
Kevin Fenzi
d438182e53 drop these for now 2018-04-17 19:14:33 +00:00
Patrick Uiterwijk
ff11859e48 Tabs and spaces...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:39:22 +02:00
Patrick Uiterwijk
d5cec8ec71 Image_build needs a target
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:36:33 +02:00
Mohan Boddu
eccf981b9e Fix runroot settings for bodhi pungi configs
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-04-17 18:23:09 +00:00
Patrick Uiterwijk
69303f6ee6 Remove copy-paste error
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:22:26 +02:00
Patrick Uiterwijk
ce449ad60c Move bodhi to opinionated imagestream role
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:21:47 +02:00
Patrick Uiterwijk
5dbc18df8d Make opinionated openshift/route and make bodhi use it
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 20:12:15 +02:00
Kevin Fenzi
6783d34e8e make the osbs.conf readable to nrpe user for monitoring 2018-04-17 17:59:34 +00:00
Kevin Fenzi
5cc8d5ff7e drop 2 machines that are dead and unlikely to come back soon 2018-04-17 17:25:03 +00:00
Patrick Uiterwijk
9cbf120b54 Make sure packagers can access the fedmsg key
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 18:17:04 +02:00
Pierre-Yves Chibon
dc86b22f90 Turn off the pagure fedmsg hook for now
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 17:39:48 +02:00
Kevin Fenzi
827bd1ca76 perhaps this will fix loopabull playbook? 2018-04-17 15:29:36 +00:00
Patrick Uiterwijk
464590e528 Some tuning of probes and workers
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 16:48:30 +02:00
Patrick Uiterwijk
dae249e679 Fix rel-mon playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 16:08:50 +02:00
Patrick Uiterwijk
4ae951bdda Add objectname to waiverdb
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 16:02:29 +02:00
Patrick Uiterwijk
4dc8b000aa Add objectnames everywhere
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 16:00:58 +02:00
Patrick Uiterwijk
2df768606f Here we go. Bodhi + openshift -> GO
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 15:53:33 +02:00
Pierre-Yves Chibon
e864768c74 Typi typoes...
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 15:49:44 +02:00
Pierre-Yves Chibon
7b6407df81 Technically we only need os.walk() on forks
The other namespace won't have sub-folders

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 15:46:41 +02:00
Pierre-Yves Chibon
cab27352d2 Some more fixes to the script
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 15:26:02 +02:00
Pierre-Yves Chibon
c825ebf5a0 Another attempt at not going down the rabbit hole
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 15:22:17 +02:00
Pierre-Yves Chibon
8a180b87c0 Fix checking only a specific namespace
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 15:14:28 +02:00
Pierre-Yves Chibon
1320c7f424 Remove a debugging statement
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 14:06:21 +02:00
Pierre-Yves Chibon
809489bc7c Disable the fedmsg hook in pagure's ui in dist-git
Since that hook will from now on be enabled for all projects

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 14:04:01 +02:00
Pierre-Yves Chibon
da5d18632b Turn on the pagure fedmsg hook on all projects and forks
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 14:02:00 +02:00
Pierre-Yves Chibon
0b2079ca11 Add new script to check the post-receive hooks on dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 12:52:32 +02:00
Pierre-Yves Chibon
a09604d9b2 Add a custom post-receive-chained hook for forks
This hook doesn't send fedmsg messages on the git.receive topic
and does not notify the alternative arch folks about changes

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-17 12:14:07 +02:00
Patrick Uiterwijk
4d506d964d Add keytab to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:48:57 +00:00
Patrick Uiterwijk
5627f6d68f USe the modern kdc uri
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:14:22 +00:00
Patrick Uiterwijk
251555b692 Deploy krb5.conf for bodhi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:10:57 +00:00
Patrick Uiterwijk
559e7652b4 Symlink krb5 keytab
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:54:53 +00:00
Patrick Uiterwijk
4a43535985 Mount the keytab
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:50:19 +00:00
Randy Barlow
b88f44a32f Use the env_suffix on the bodhi fedmsg endpoint config.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-17 01:47:11 +00:00
Patrick Uiterwijk
bfe9021c09 Play nicely with the magic that bodhi adds on top of fedmsg magic
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 03:44:57 +02:00
Randy Barlow
e34e637b1e Rename fedmsg.d/bodhi.py to zzbodhi.py.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-17 01:08:11 +00:00
Patrick Uiterwijk
8421005db1 Fix dest= missing
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:04:01 +00:00
Patrick Uiterwijk
887f10ae77 Update bodhi to use persistent names
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:02:21 +00:00
Patrick Uiterwijk
ff117118a5 Use consistent, permanent filenames
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:02:21 +00:00
Patrick Uiterwijk
fa8f2d5316 Use inventory_hostname so vars aren't needed
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:53:15 +02:00
Patrick Uiterwijk
82902bc5d8 Remove failed test
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:51:39 +02:00
Patrick Uiterwijk
fa7d48125f Facts are not useful for openshift apps
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:39:14 +02:00
Patrick Uiterwijk
36b7948be8 Rather than run_once, use first os-master entry
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:38:31 +02:00
Patrick Uiterwijk
f3d2bde922 Give staging fedmsg also prod policy since we have prod->stg message flow
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:24:14 +02:00
Randy Barlow
c9d657e9d3 Remove the bodhi.py fedmsg config from the package and use the name.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-17 00:15:22 +00:00
Patrick Uiterwijk
3ddc0f65f0 Make valid fedmsg config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:09:59 +02:00
Patrick Uiterwijk
6f8272e98e Stop leaking via bugyou
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 02:05:15 +02:00
Randy Barlow
4bb555e0ba Don't mount a folder in a read only volume.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 23:52:52 +00:00
Patrick Uiterwijk
e708100dd0 Don't delete the keytab for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:39:25 +00:00
Patrick Uiterwijk
d994779f37 Add key
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:35:02 +00:00
Patrick Uiterwijk
7c95ba3c45 Read the docs, Patrick
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:32:24 +00:00
Patrick Uiterwijk
cb61c9293f Fix include_role
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:31:33 +00:00
Randy Barlow
0521332637 Merge branch 'master' of /git/ansible 2018-04-16 23:29:34 +00:00
Randy Barlow
649b768595 Don't try to bind mount bodhi.py as a directory.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 23:29:18 +00:00
Patrick Uiterwijk
d9a17f5c5d Try to add a keytab for bodhi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:25:04 +02:00
Patrick Uiterwijk
f81f5a943f Add openshift/keytab
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 01:22:18 +02:00
Patrick Uiterwijk
f82264261f Set a user for fedmsg purposes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-17 00:59:13 +02:00
Randy Barlow
e834fffda0 Use bodhi-openshift-web.py for fedmsg instead of bodhi.py.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 22:27:25 +00:00
Randy Barlow
2528d8f450 s/name/dcname/ in bodhi's openshift playbook.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:58:26 +00:00
Randy Barlow
90db775b3b Merge branch 'master' of /git/ansible 2018-04-16 21:55:38 +00:00
Patrick Uiterwijk
c4157bb821 For now, revert the combined registry, until blocking facts are fixed
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:55:30 +02:00
Randy Barlow
6e0b8f8db0 Use buildname instead of name in Bodhi's buildconfig role.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:55:17 +00:00
Patrick Uiterwijk
8de476d74d 'name' is no longer valid
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:49:13 +02:00
Patrick Uiterwijk
3fd13202c8 Our registry is publicly readable to the world
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 23:45:36 +02:00
Randy Barlow
481eb0ce7d Ugh, don't mix up .stg and .phx2 in the bodhi cert names.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:42:25 +00:00
Randy Barlow
2b4264c4bc Revert "s/bodhi-bodhi/bodhi/ on fedmsg cert names."
This reverts commit fdbeca9958.
2018-04-16 21:38:55 +00:00
Randy Barlow
fdbeca9958 s/bodhi-bodhi/bodhi/ on fedmsg cert names.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:34:24 +00:00
Randy Barlow
235a8047cf Use the correct paths to the super secret fedmsg certs.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:32:18 +00:00
Patrick Uiterwijk
3acfa5b4de vars {} makes it a global variable. Let's not do that
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 21:30:17 +00:00
Patrick Uiterwijk
0baf6b2edf Blow out the rats playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 21:26:28 +00:00
Patrick Uiterwijk
2ef2b46a37 Openshift build logs have moved to another namespace. Allow that
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-16 21:26:28 +00:00
Randy Barlow
7d859098a3 Give Bodhi's OpenShift container a more complete fedmsg config.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 21:15:55 +00:00
Randy Barlow
c92f1f0c5d Configure fedmsg in a better way and give it bodhi03's cert.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 20:31:30 +00:00
Kevin Fenzi
d769f6230e move staging to 3.7.44 ansible-openshift to fix bug caused by 3.6 upgrade 2018-04-16 19:57:45 +00:00
Randy Barlow
17a8faa048 Bodhi's build config is called bodhi-web, not bodhi-web-build.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 19:15:21 +00:00
Kevin Fenzi
0d1186a1f8 try just disabling the checks for now 2018-04-16 19:12:41 +00:00
Sayan Chowdhury
0d8493c689 fedimg: Fix the fedimg logging file name 2018-04-16 19:01:59 +00:00
Sayan Chowdhury
7f7b57021f fedimg: Setup the logging for fedimg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-16 18:54:31 +00:00
Randy Barlow
eedee73479 Stop/start openshift bodhi services when syncing database.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 17:59:06 +00:00
Sayan Chowdhury
d596a7c84d fedimg: Update the changes for release 1.2.0
- Remove the cron to kill the EC2 nodes
- Update the trigger_upload
- Remove the hotfixes

Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-16 17:48:07 +00:00
Kevin Fenzi
eb4ec73246 one more 2018-04-16 17:07:50 +00:00
Kevin Fenzi
d0736f1658 another one 2018-04-16 17:03:57 +00:00
Kevin Fenzi
ee4bede73f we no longer seem to get this set on the aarch64 instances 2018-04-16 16:58:35 +00:00
Randy Barlow
79baeb984f Configure Bodhi in OpenShift to use active=True for fedmsgs.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 15:15:44 +00:00
Randy Barlow
14ab93c1cd Document the new Bodhi settings.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-16 15:07:32 +00:00
clime
d9788e6cdf copr-backend: adjust builder limits 2018-04-16 16:40:07 +02:00
Pierre-Yves Chibon
1c8d04443c Still no Atomic CI pipeline for -testing
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-16 14:22:28 +02:00
Pierre-Yves Chibon
a977fe43af Fix variable name in the rollout of greenwave
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-16 14:16:55 +02:00
Pierre-Yves Chibon
a212d0aa30 Turns out there is no f28 of the Atomic CI pipeline...
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-16 14:12:25 +02:00
Miroslav Suchý
e57ed80e1f retrace: move repoassign after faf configuration 2018-04-16 14:05:42 +02:00
Miroslav Suchý
0bc707256f update faf and retrace roles from upstream 2018-04-16 13:38:46 +02:00
Clement Verna
453a4da483 builder sa needs to be able to run custom builds
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-16 12:39:45 +02:00
Clement Verna
480524ffb0 Disable also flatpak_create_oci plugin
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-16 09:43:58 +02:00
Kevin Fenzi
92440ad515 fix another renamed variable 2018-04-15 22:56:52 +00:00
Kevin Fenzi
37e54a718a f28 sshd config needs to be slightly different 2018-04-15 21:28:47 +00:00
Kevin Fenzi
2c8dec04ba fix name typo 2018-04-15 20:53:24 +00:00
Patrick Uiterwijk
eb305726e2 tree_arches limits us too much
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 12:33:52 +02:00
Patrick Uiterwijk
29a5a192b8 Also disable flatpak, it is broken
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 03:34:53 +02:00
Patrick Uiterwijk
f5c19dc893 Disable module compose resolving in OSBS for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 03:00:18 +02:00
Patrick Uiterwijk
e00924ad97 Right, pdc-client is also needed... Let's see how long this will work
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 02:46:20 +02:00
Patrick Uiterwijk
5f5b953a75 For now, we also need modulemd... OSBS will crash and burn with modulemdv2....
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 02:35:36 +02:00
Patrick Uiterwijk
727cf4b931 modularity... the gift that keeps giving.
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-15 02:22:57 +02:00
Patrick Uiterwijk
b9c2887ae5 Use correct branch for module defaults
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:33:04 -04:00
Patrick Uiterwijk
e9184ea524 Add module defaults (Infra #6851)
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:25:01 -04:00
Patrick Uiterwijk
ff22ddcf15 Turns out that 'is_empty' comes from arches... who knew? I didn't
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:23:43 -04:00
Patrick Uiterwijk
7814f1639e Turns out that we need an empty variant for ostree installer
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:21:29 -04:00
Patrick Uiterwijk
e7a8a3c8fa Correct syntax might help
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:13:07 -04:00
Patrick Uiterwijk
41ad323b22 % != $
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-14 18:10:40 -04:00
Ralph Bean
72c6d2ee2c Remove screwy newline markers. 2018-04-13 18:41:23 +00:00
Ralph Bean
3102dbc6ba Make this a template. 2018-04-13 18:34:35 +00:00
Ralph Bean
65f7e6bbc7 Another typofix. 2018-04-13 18:27:58 +00:00
Ralph Bean
e3b9461bb6 Typofix. 2018-04-13 18:27:09 +00:00
Ralph Bean
76cac827fa Needs to be set on the imagestream, not the imagestreamtag. 2018-04-13 18:25:03 +00:00
Ralph Bean
0ce50604ba Try an external imagestream for greenwave stg. 2018-04-13 18:19:12 +00:00
Ralph Bean
4214324b4e Revert that. 2018-04-13 18:14:23 +00:00
Ralph Bean
13a1567a66 Greenwave: try building from git in staging. 2018-04-13 17:32:30 +00:00
Ralph Bean
e969cbc939 Revert "That change didn't take for some reason."
This reverts commit d954bf5ff2.
2018-04-13 17:15:16 +00:00
Patrick Uiterwijk
4237b02bbb RATS server objects
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 16:17:53 +00:00
Patrick Uiterwijk
3e8aaae8cf Do not conflict with ansible names
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 16:07:41 +00:00
Patrick Uiterwijk
c784b339df Start with RATS openshift deployment
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:58:55 +00:00
Patrick Uiterwijk
6f6a5efd5d Add keephost for bodhi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:52:10 +00:00
Patrick Uiterwijk
15f11fd80e Make buildconfig for bodhi do stg infra tags
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:45:24 +00:00
Patrick Uiterwijk
48f871ef3a Keep host for bodhi on os
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:34:55 +00:00
Patrick Uiterwijk
e23baa8a58 Move bodhi in stg to openshift
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:32:19 +00:00
Patrick Uiterwijk
32f1e305bd Make bodhi on openshift listen on correct url
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 15:29:42 +00:00
Patrick Uiterwijk
4a54c073aa Deploy to prod just before heading to a plane
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:58:44 +00:00
Patrick Uiterwijk
906c2587e6 Fix playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:57:55 +00:00
Patrick Uiterwijk
532c3b8ed1 Fix pgbdr names
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:57:25 +00:00
Patrick Uiterwijk
c9f7cf042e Add emptydir for cache
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:57:10 +00:00
Patrick Uiterwijk
d4f665179a Revert "Make bodhi dogpile cache in memory"
This reverts commit d2c70f4203.
2018-04-13 14:51:45 +00:00
Patrick Uiterwijk
d2c70f4203 Make bodhi dogpile cache in memory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:45:48 +00:00
Patrick Uiterwijk
2c6adac806 Allow bodhi into pgbdr
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:37:46 +00:00
Patrick Uiterwijk
2a94bd6f6e Use python package location
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:32:00 +00:00
Patrick Uiterwijk
d3e6a01bbf Gunicorn packaging is... interesting
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:27:05 +00:00
Patrick Uiterwijk
15cfbcb7e2 Remove spurious dash
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:21:50 +00:00
Patrick Uiterwijk
2311f8683a Move configmap for bodhi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:19:38 +00:00
Patrick Uiterwijk
b091251aca Use python string format
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:13:48 +00:00
Patrick Uiterwijk
69faeec852 One more level
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:12:11 +00:00
Patrick Uiterwijk
85885f0cef Let's try relativE
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:11:38 +00:00
Patrick Uiterwijk
173d076269 Embed production.ini in an evil way
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 14:10:06 +00:00
Patrick Uiterwijk
51f9ed1a9c Turns out that that did not work
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:25:40 +00:00
Patrick Uiterwijk
46a1f63df0 Fix rolepath
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:19:30 +00:00
Patrick Uiterwijk
daceb4ea24 Double <> tripple
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:16:34 +00:00
Patrick Uiterwijk
300ec051a3 Try double quotes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:16:09 +00:00
Patrick Uiterwijk
bf33f4c83f Default to no values
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:14:43 +00:00
Patrick Uiterwijk
8746f0777c Add bodhi openshift playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-13 13:02:24 +00:00
Mikolaj Izdebski
b12953aacd Bump fedorapeople quota for jforbes
https://pagure.io/fedora-infrastructure/issue/6856
2018-04-13 12:06:27 +00:00
Clement Verna
c7489cfc5c Fix osbs client arrangement and secret names
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-13 12:43:33 +02:00
clime
4fafa19ead copr-backend: increase builder x86_64 limit in config 2018-04-13 09:24:25 +02:00
clime
8a96f0404a copr-builder: increase spawn timeout 2018-04-13 03:52:17 +02:00
Sayan Chowdhury
dbf65659a3 fedimg: Fix the trigger_upload script to send notifications
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 23:40:53 +00:00
Ralph Bean
d954bf5ff2 That change didn't take for some reason. 2018-04-12 22:53:37 +00:00
Ralph Bean
93bab2a024 Fix fedora atomic config for greenwave.
https://pagure.io/fedora-infrastructure/issue/6806
2018-04-12 22:40:14 +00:00
Ricky Elrod
7cff09ba36 Initial bodhi stuff
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 22:32:30 +00:00
Sayan Chowdhury
b1bd250ca8 fedimg: Add the patch to send the upload messages
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 22:02:34 +00:00
Sayan Chowdhury
c142a1f129 fedimg: Send fedmsg message when upload done
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 22:02:34 +00:00
Pierre-Yves Chibon
3a963a5eeb Drop the quotes in the alembic.ini
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-12 23:57:20 +02:00
Pierre-Yves Chibon
3d057ffcd6 Finish reverting filename -> file as it was
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-12 23:42:14 +02:00
Pierre-Yves Chibon
9aa7b62166 Revert the change to openshift/object to use file as originally
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-12 23:40:49 +02:00
Pierre-Yves Chibon
bb5b4da3c0 Fix typo in anitya's dockerfile
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-12 23:36:08 +02:00
Sayan Chowdhury
04abb2bb4e fedimg: Add the fedimg s3 bucket name to config file
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 21:23:20 +00:00
Ricky Elrod
f367f8fc47 use the right IPs
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 21:16:51 +00:00
Ricky Elrod
2299b42558 anitya stg vm vars
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 21:08:17 +00:00
Dusty Mabe
dd001a2044 bodhi-pungi: change ostree version
We think the one we want is VERSION_FROM_VERSION_DATE_RESPIN
2018-04-12 16:53:44 -04:00
Dusty Mabe
07aaec7566 bodhi-pungi: some fixups for recent addition of Atomic Host
Some fixups and also make them failable.
2018-04-12 16:53:44 -04:00
Dusty Mabe
a99a527673 bodhi-pungi: replace spaces with tabs, fixup spacing 2018-04-12 16:53:43 -04:00
Sayan Chowdhury
e9395b9143 fedimg: Messed up function args
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 20:41:50 +00:00
Sayan Chowdhury
a113d67b62 fedimg: Fix the trigger_upload script a/c to fedimg==1.1.0
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 19:56:29 +00:00
Sayan Chowdhury
ecf57d16a7 fedimg: Add dependency to the manual upgrade script
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-12 19:47:15 +00:00
Patrick Uiterwijk
bc6f16bc6b Add bodhi/pungi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-12 15:33:29 -04:00
Patrick Uiterwijk
2c3b643da2 Let's give this delayed pungi run a try
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-12 15:32:32 -04:00
Patrick Uiterwijk
aa9a5001f2 Fix the awx return url
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-12 16:36:23 +00:00
Patrick Uiterwijk
bd95013e6a Add AWX to SAML2
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-12 16:30:53 +00:00
Clement Verna
4bb10a4ce0 For now let's grab the openshift container image on in prod
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-12 18:17:04 +02:00
Stephen Smoogen
793e740956 and the atomic group looks at the image 2018-04-12 15:55:00 +00:00
Randy Barlow
859c4dbe60 Remove gather_source from Bodhi's pungi configs.
Pungi's gather_source setting doesn't do anything, and using it
causes Pungi to print this to stderr:

WARNING: Config option gather_source was removed and has no effect;
remove it.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-04-12 15:36:00 +00:00
Ricky Elrod
4909fecbe2 Redirect, not Location
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 15:31:29 +00:00
Ricky Elrod
fcccfa4655 jenkins redirect
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 15:26:55 +00:00
Ricky Elrod
674fc14712 Merge branch 'master' of /git/ansible 2018-04-12 14:44:05 +00:00
Ricky Elrod
b6654379b3 make haproxy check with http/1.1
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 14:44:00 +00:00
Clement Verna
5282ff3fe5 We do not need the osbs.conf on the openshift cluster
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-12 16:31:25 +02:00
Patrick Uiterwijk
555665a2f6 Update staging cert name
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-12 10:07:37 -04:00
Ricky Elrod
560159d0f0 try yes instead of true
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 13:04:23 +00:00
Ricky Elrod
32536c8683 limit this to prod
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-12 12:56:38 +00:00
Stephen Smoogen
82d1af54df add in the atomic group 2018-04-12 02:24:46 +00:00
Stephen Smoogen
d9077d97bf ok this sort of works but not the debug yet 2018-04-12 02:22:11 +00:00
Patrick Uiterwijk
3e7af5da81 Use modular kojitag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 22:18:03 -04:00
Patrick Uiterwijk
9e3be74540 Provide module context
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 22:08:10 -04:00
Stephen Smoogen
93d2e8f5bb the sysadmin-atomic group will need to run a job 2018-04-12 01:43:31 +00:00
Ricky Elrod
19ce8c8a05 change name to site_name in our proxy roles....
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 21:53:06 +00:00
Ricky Elrod
c45ec7a8a4 can I tag on these?
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 21:37:13 +00:00
Ricky Elrod
b87efec9a0 make this phx2 only
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 21:24:58 +00:00
Ricky Elrod
5a17d40c3c Merge branch 'awxproxy' 2018-04-11 21:22:21 +00:00
Patrick Uiterwijk
565b18e27e Rename file to filename
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 21:10:07 +00:00
Pierre-Yves Chibon
8cb5e06226 Rename file to filename
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-11 23:09:30 +02:00
Pierre-Yves Chibon
895d3b83ff Add a CORS_URL to waiverdb and combine all staging/prod specific variables in one place
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-11 22:44:00 +02:00
Ricky Elrod
8c17518a10 Merge branch 'master' of /git/ansible 2018-04-11 20:34:17 +00:00
Ricky Elrod
3656ce4c16 Don't run the playbook automatically for now
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 20:34:12 +00:00
Stephen Smoogen
e9f1fe259a sort of works 2018-04-11 20:10:57 +00:00
Patrick Uiterwijk
2c46e8fbc6 Sign f29 modules
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 15:48:57 -04:00
Ricky Elrod
b67f52bca0 Merge branch 'master' of /git/ansible 2018-04-11 19:46:47 +00:00
Ricky Elrod
ebb2ca7938 try devel?
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 19:46:27 +00:00
Ricky Elrod
72003bf457 Break the world (add awx to proxies)
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 19:45:48 +00:00
Patrick Uiterwijk
7dc3db3141 Redirect with
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 15:04:29 -04:00
Patrick Uiterwijk
63b3d2b45b Only use RedirecftMatch
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 12:50:36 -04:00
Patrick Uiterwijk
0fae543a84 Reorder these
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 12:42:01 -04:00
Patrick Uiterwijk
0947c0f3a5 Move the redirect to dl.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 12:30:20 -04:00
Stephen Smoogen
4bac7add69 of course you need facts. 2018-04-11 16:27:25 +00:00
Ricky Elrod
0dced93f85 We need to install and start docker ourselves
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 16:27:17 +00:00
Stephen Smoogen
fa9be4cc0a lets try simplifying this 2018-04-11 16:25:52 +00:00
Stephen Smoogen
f22f70c556 we need a test system 2018-04-11 16:20:21 +00:00
Ricky Elrod
b9b784e6ec add awx role
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 16:15:38 +00:00
Ricky Elrod
5defa0e203 tag everything here
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 16:15:28 +00:00
Ricky Elrod
2762721ecf Merge branch 'master' of /git/ansible 2018-04-11 16:10:54 +00:00
Ricky Elrod
6afb864cad awx, not aws...
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 16:10:48 +00:00
Ricky Elrod
4130e9a467 awx first attempt
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 16:10:20 +00:00
Patrick Uiterwijk
0ba63db834 Make the atomic rewrite happen at the proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 11:49:51 -04:00
Stephen Smoogen
41a6166fd5 clean up the chum 2018-04-11 15:46:44 +00:00
Stephen Smoogen
8789f4de03 we have a new one 2018-04-11 15:44:31 +00:00
Ricky Elrod
5482f8af95 Merge branch 'master' of /git/ansible 2018-04-11 15:23:44 +00:00
Ricky Elrod
256357ee1d no vpn here
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 15:23:38 +00:00
Patrick Uiterwijk
f5c246d5d0 Do not forward with X-CloudFront header
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 11:13:22 -04:00
Ricky Elrod
93975a8b0b Merge branch 'master' of /git/ansible 2018-04-11 15:02:43 +00:00
Ricky Elrod
7ae53ae7ca batcomputer01, bare vm for now
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 15:02:13 +00:00
Stephen Smoogen
78ec2c3f6b proxy05 has a line in a config which needs for it to be defined for nagios to restart 2018-04-11 14:51:34 +00:00
Patrick Uiterwijk
8f7df9629c Close quotes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 10:36:04 -04:00
Patrick Uiterwijk
6264d4e468 Redirect atomic/repo/objects via cloudfront
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-11 10:18:26 -04:00
Ricky Elrod
150f622bcb fix paste info and deactivation scripts
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-11 13:51:50 +00:00
Kevin Fenzi
dd1ccb9cc3 missed a few 2018-04-10 21:42:50 +00:00
Kevin Fenzi
e51b6285a6 Shelve summershum 2018-04-10 21:39:56 +00:00
Stephen Smoogen
73f534bd37 dennis-s email was down and I saw a way to clean up stuff 2018-04-10 21:32:04 +00:00
Kevin Fenzi
0e494da145 shelve darkserver 2018-04-10 20:36:40 +00:00
Clement Verna
65d21f48b7 Add the token_file variable to osbs.conf template
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-10 09:30:51 +02:00
Clement Verna
750862e4e3 The docker service needs to be started
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-10 09:30:09 +02:00
Kevin Fenzi
9b8b671cac adjust libraries2fedmsg to try and fix fedmsgs 2018-04-10 01:44:10 +00:00
Ricky Elrod
4e45d450bc Up to f27
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-10 00:28:47 +00:00
Patrick Uiterwijk
61866f76ee Disable waive button in bodhi until we fix the code to match API
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-09 20:28:37 +00:00
Ricky Elrod
636fc10d9f Merge branch 'master' of /git/ansible 2018-04-09 19:57:31 +00:00
Ricky Elrod
775a872556 remove old db04/5 references
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-09 19:57:17 +00:00
Clement Verna
fdc68d327d We need docker on the composer for OSBS
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-09 20:50:27 +02:00
Clement Verna
c8ede853ff Use the service account koji token in buildvm to authenticate
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-09 20:42:26 +02:00
Mikolaj Izdebski
f3a7bc9341 Add f28-infra tags to tag2distrepo config 2018-04-09 16:34:08 +00:00
Patrick Uiterwijk
e30f89375b Deploy Bodhi2 waiverdb token
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-09 16:24:19 +00:00
Mikolaj Izdebski
2b6ac2ad14 Fix a typo in iptables-restore command 2018-04-09 15:16:59 +00:00
Mikolaj Izdebski
b753de9428 Don't install custom Fedora repos on f28-test 2018-04-09 14:36:44 +00:00
Jan Kaluža
0a0efd9e04 Merge branch 'master' of /git/ansible 2018-04-09 13:55:14 +00:00
Jan Kaluža
82a4b78fce Use commit:f29 for platform-f29 virtual module. 2018-04-09 13:55:07 +00:00
Mikolaj Izdebski
3a591c2ad3 Increase timeout for spinning UP VM using nova_compute 2018-04-09 09:21:49 +00:00
Mikolaj Izdebski
cf874ad5b7 Install f28 maintainer-test in cloud 2018-04-09 08:09:25 +00:00
Kevin Fenzi
dce218db12 moved pkgs02 over to bvirthost04 and ssds and off iscsi 2018-04-07 19:59:04 +00:00
Kevin Fenzi
1c861d231d add another stray fedmsg 2018-04-07 17:41:20 +00:00
Clement Verna
e0d35a1b9c Fix the variable name
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-07 14:16:28 +02:00
Clement Verna
ccdf42ccc6 Fixing the syntax for osbs readwrite users
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-07 14:11:42 +02:00
Clement Verna
887d7df729 Osbs readwrite users is not needed in the worker namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-07 14:03:01 +02:00
Kevin Fenzi
72bbaa220c add another fedmsg it is ok for bodhi03/04 to emit 2018-04-07 01:11:37 +00:00
Ricky Elrod
41b2948b3c comment out control01.cloud for now
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-06 21:00:29 +00:00
Ricky Elrod
c60591bebe add nagios check for modernpaste
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-06 20:38:25 +00:00
Ricky Elrod
e66ca49d5c Merge branch 'master' of /git/ansible 2018-04-06 20:04:05 +00:00
Ricky Elrod
0e4f235443 make this f27
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-06 20:04:05 +00:00
Clement Verna
53946acfd6 Add the vars and KUBECONFIG Path
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-06 17:27:46 +02:00
Clement Verna
51444b5dc8 Let's try without the user in stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-06 17:13:48 +02:00
Jeremy Cline
58633c9921 Drop if statement in deploymentconfig
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-06 15:12:54 +00:00
Jeremy Cline
346d810a6e Run release-monitoring db migrations in a pre-deployment step
This also adds the necessary alembic configuration.

Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-06 15:08:39 +00:00
Clement Verna
46a249f5ad Ensures /etc/dnsmasq.d/ dir exists
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-06 17:03:50 +02:00
Kevin Fenzi
aabe4115b5 try and simplify 2018-04-06 05:38:25 +00:00
Kevin Fenzi
6699d4ed8e fix space 2018-04-06 05:34:04 +00:00
Kevin Fenzi
180cc21c6a fix typo 2018-04-06 05:31:38 +00:00
Kevin Fenzi
52c43d2148 adjust shm size check for postgres servers 2018-04-06 05:26:20 +00:00
Kevin Fenzi
0bb668f2df some more fedmsg can_send 2018-04-06 04:09:44 +00:00
Kevin Fenzi
32ff935a55 fix typos in pdc-backend csi data. ticket 6775 2018-04-06 02:14:14 +00:00
Sayan Chowdhury
586b46910d fedimg: patch to process the F28+ messages
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-06 00:06:43 +00:00
Sayan Chowdhury
628906a945 fedimg: Port fix for F28 compose messages to 1.0.1
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-06 00:06:01 +00:00
Sayan Chowdhury
8693bb0902 fedimg: Remove the fedimg hotfix
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-05 22:50:38 +00:00
Ricky Elrod
7e8b30ea74 Merge branch 'master' of /git/ansible 2018-04-05 22:33:00 +00:00
Ricky Elrod
93ab6cdfc9 add issuer
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-05 22:32:59 +00:00
Sayan Chowdhury
1049a16bf0 fedimg: Set testing False for fedimg group
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-05 22:29:39 +00:00
Ricky Elrod
aa927689ea Merge branch 'master' of /git/ansible 2018-04-05 22:12:05 +00:00
Ricky Elrod
1eddae4170 conditionalize this for now
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-05 22:12:00 +00:00
Sayan Chowdhury
e70ba90841 fedimg: Remove the configuration related to staging
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-05 22:06:57 +00:00
Ricky Elrod
57a98d07db Toggle another selinux bool so sn2mp works
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-05 22:02:59 +00:00
Ricky Elrod
b23ca76b4f Merge branch 'master' of /git/ansible 2018-04-05 21:19:57 +00:00
Ricky Elrod
2a709b0387 f27 this box
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-05 21:19:51 +00:00
Kevin Fenzi
109a1fd243 drop stray }}s 2018-04-05 20:52:19 +00:00
Kevin Fenzi
8748872272 clean up some leftover }s 2018-04-05 20:50:24 +00:00
Kevin Fenzi
c7f95e7c9e try and deal with name scoping some more 2018-04-05 20:48:29 +00:00
Kevin Fenzi
066c97690e tell ansible these are vars 2018-04-05 19:58:10 +00:00
Kevin Fenzi
75d7bbc738 bad global replace 2018-04-05 18:45:27 +00:00
Kevin Fenzi
0dbe0cf95d also change vars here 2018-04-05 18:29:36 +00:00
Jeremy Cline
81edf503cd Install python-social-auth for release-monitoring
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-05 18:23:14 +00:00
Jeremy Cline
c12a30acce Add the release-monitoring stage db to the config
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-05 18:19:49 +00:00
Kevin Fenzi
caf130a422 lets see if the problem here is the name keyword 2018-04-05 18:08:24 +00:00
Pierre-Yves Chibon
c7133fefad Let's disable the cron on staging dist-git until they are fixed
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-04-05 19:02:04 +02:00
Clement Verna
c9c32b806d Make osbs-master01.stg an f27 box
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-05 17:29:14 +02:00
Clement Verna
9a20193464 Give sudo before collectd
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-05 17:20:35 +02:00
Jan Kaluža
941e16bd75 Merge branch 'master' of /git/ansible 2018-04-05 14:52:42 +00:00
Jan Kaluža
6a49c82511 MBS: Use 'db' RESOLVER also for prod. 2018-04-05 14:52:36 +00:00
Clement Verna
a675df7cc5 Use composer.stg for staging hosts
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-05 16:39:42 +02:00
Jan Kaluža
804bf00dd3 MBS: Add default-modules.production. 2018-04-05 13:22:09 +00:00
Ralph Bean
4734a63051 Add libmodulemd to the list of things to update. 2018-04-05 12:29:13 +00:00
František Zatloukal
f4a05f3fae Taskotron-prod: Update vars to latest libtaskotron 2018-04-05 14:13:18 +02:00
Patrick Uiterwijk
f6d0d1762f dest != path
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-05 13:56:21 +02:00
Patrick Uiterwijk
35178bbbe0 Add explicitly empty datanommer.py
This is needed because otherwise every package update we get a datanommer.py
with a broken database_url.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-05 13:54:59 +02:00
Ralph Bean
14c64f25f7 Looks like this really needs a modname argument. 2018-04-05 11:54:50 +00:00
Ralph Bean
54136b60c9 Restore old taskotron messaging settings. 2018-04-05 11:47:47 +00:00
František Zatloukal
60590b4f57 Taskotron-stg: Make changes to support latest libtaskotron 2018-04-05 13:21:35 +02:00
Kevin Fenzi
d8d79f7933 more adjusting to ansible not wanting | in when 2018-04-04 22:52:22 +00:00
Kevin Fenzi
ca009a7d62 fix up includes in vhost_reboot playbook 2018-04-04 20:07:08 +00:00
Ricky Elrod
92b381d957 add python2-flask-oidc here, until I include it as a Requires in the rpm
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 20:01:59 +00:00
Ricky Elrod
68c4d47f8a Drop 1wk expiry in stage, make httpd config a template and drop /login redirect in stg
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 19:54:05 +00:00
Ricky Elrod
d234533b90 Merge branch 'master' of /git/ansible 2018-04-04 19:38:32 +00:00
Ricky Elrod
92401e1c0f modernpaste config for oidc
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 19:38:25 +00:00
Ricky Elrod
5f12f40dfb ipsilon oidc scope for modernpaste
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 19:37:08 +00:00
Kevin Fenzi
9fe41eca70 fix deprecated |success to is success 2018-04-04 19:24:21 +00:00
Kevin Fenzi
0353f1f6a2 fix up vhost_update to not swamp noc01 and cause unreachables 2018-04-04 19:20:34 +00:00
Patrick Uiterwijk
7d5983e35f This is now the default, and specifying both is not working well
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 19:49:17 +02:00
Clement Verna
84052aaf53 Update osbs-client configuration on builders
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-04 19:22:12 +02:00
Kevin Fenzi
d3f892291c Lets try and cut down on invalid fedmsg senders. 2018-04-04 16:39:08 +00:00
Clement Verna
43acb9144f Add OSBS service account and worker cluster
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-04 10:55:35 +02:00
Clement Verna
7023422105 Remove osbs-on-openshift on stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-04 09:55:48 +02:00
Patrick Uiterwijk
a6fc58fa93 Do not use baseiptables with newcloud
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 07:12:56 +00:00
Ricky Elrod
a9d58375f6 make yumrepos a pre_task
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 06:07:30 +00:00
Ricky Elrod
ffd05099f3 these boxes need to become non-f25. This starts that process
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 05:41:56 +00:00
Ricky Elrod
7d3a6fb9e5 Merge branch 'master' of /git/ansible 2018-04-04 03:55:19 +00:00
Ricky Elrod
3fcc8b4b4c Add missing project role to os/modernpaste
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-04 03:55:13 +00:00
Patrick Uiterwijk
8fa2c2e77e Use public DNS from cloud
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 00:53:16 +00:00
Patrick Uiterwijk
94c8e45c9c Only configure eth1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 00:49:23 +00:00
Patrick Uiterwijk
e6bff2c6d9 Add core of newcloud.yml
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 00:44:33 +00:00
Patrick Uiterwijk
b8f7ea06e1 Add newcloud to inventory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-04 00:42:22 +00:00
Patrick Uiterwijk
5284391da8 Stay consistent with .0 vs .1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 23:10:11 +00:00
Patrick Uiterwijk
f140194cfe Add missing comma
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 22:40:20 +00:00
Patrick Uiterwijk
779a73cd48 Allow dhcp and tftp from eth1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 22:39:13 +00:00
Patrick Uiterwijk
507782ab17 Use correct kickstart
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 22:37:18 +00:00
Patrick Uiterwijk
e1f5a8ac15 Update DHCP config for cloud-noc
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 22:32:04 +00:00
Patrick Uiterwijk
ba22bd753b Update dhcpd config for cloud-noc01
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 21:37:48 +00:00
Patrick Uiterwijk
4e4f8f1067 Update cloud-noc01 PXE config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 20:26:28 +00:00
Patrick Uiterwijk
792d8f140a Fix IP for cloud-noc01
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-04-03 20:23:16 +00:00
Kevin Fenzi
9e5540045d gnome backups to 50GB / 2018-04-03 19:37:46 +00:00
Clement Verna
e59e0368fa We do not need osbs-on-openshift since we use osbs-namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-03 19:27:55 +02:00
Clement Verna
cda8708927 osbs-client is not needed on the openshift master and nodes
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-03 19:25:46 +02:00
Kevin Fenzi
15cda5a74d Remove prerelease redirects in prod 2018-04-03 12:36:06 +00:00
Clement Verna
0c3884744d Add osbs worker cluster definition
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-04-03 13:28:24 +02:00
Justin W. Flory
26efab6ef6 Organize Fedora Council aliases; update Flock aliases
This commit changes the following:

* Organizes and comments Fedora Council aliases together
    * Changes board alias to council-private@lists.fp.o
    * Links to new doc pages for FPL and FCAIC in comments
    * Drop diversity alias (this was never used in Diversity Team)
* Use fcaic alias for Flock emails instead of hard-coding bex
2018-04-02 17:47:49 +00:00
Jeremy Cline
f5d5e8e39e Whitelist org.release-monitoring topics
Notifications from anitya have been broken because
org.release-monitoring wasn't in the topic subscription list.

Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-04-02 17:44:24 +00:00
Justin W. Flory
3fffa116ac Add oldschool badge mapping for 'mindshare' to 'meeting-of-the-minds' 2018-04-02 17:42:03 +00:00
Sayan Chowdhury
efd630c25b autolcoud: Add the fedmsg loop back to the backend stg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-04-02 10:32:35 +00:00
Ricky Elrod
04ea47a7a1 Don't include candidate-registry in the gluster group
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-01 23:31:26 +00:00
Ricky Elrod
69a1db0dcd gluster ports
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-01 22:57:28 +00:00
Ricky Elrod
f5321e5d86 use the right group for gluster config
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-01 22:47:04 +00:00
Ricky Elrod
9da5b2626d make yumrepos be a pre_task
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-01 22:19:02 +00:00
Ricky Elrod
4a8fcdfcb1 Revert "Revert "Remove myself from scholarship alias, it is all spam at this point anyway""
This reverts commit 94d9e20bc0.
2018-04-01 21:55:40 +00:00
Ricky Elrod
94d9e20bc0 Revert "Remove myself from scholarship alias, it is all spam at this point anyway"
This reverts commit 4f1428c249.

Waiting for a second +1 to my FBR.
2018-04-01 21:50:00 +00:00
Ricky Elrod
97ff16dbc5 Rebuild docker registry stg boxes as f27 (#6744)
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-04-01 21:48:00 +00:00
Ricky Elrod
033bee07b2 Merge branch 'master' of /git/ansible 2018-04-01 00:00:06 +00:00
Kevin Fenzi
fb3d45d749 missed a few more 2018-03-31 16:00:02 +00:00
Kevin Fenzi
041fac03bf really drop prerelease redirect in stg 2018-03-31 15:35:16 +00:00
Ricky Elrod
da4e8d4725 Merge branch 'master' of /git/ansible 2018-03-31 00:00:04 +00:00
Robert Mayr
35f70da7f6 do not redirect staging webpages anymore 2018-03-30 21:08:56 +00:00
Clement Verna
93abefa309 Add oidc scopes for pagure.io
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-30 10:56:40 +02:00
Adam Williamson
c3a7acd301 Update relvalconsumer package installs
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-29 22:51:40 -07:00
Ricky Elrod
525d0f434d Merge branch 'master' of /git/ansible 2018-03-29 20:41:00 +00:00
Nick Bebout
77bd7da1c3 Add BZ email exception for jbwillia 2018-03-29 20:32:49 +00:00
Nick Bebout
230a9e78c9 Add a bugzilla email exception for jbwillia 2018-03-29 17:39:34 +00:00
Clement Verna
48f71cb3eb Let's remove the double quotes
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-29 15:53:32 +02:00
Clement Verna
be2b4af30c Account should service account and not users
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-29 15:27:35 +02:00
Clement Verna
14d4e036e0 Change the name of the conf variable
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-29 14:38:02 +02:00
Clement Verna
2b181e86c0 Give custom build permission to default and builder account
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-29 14:31:57 +02:00
Ricky Elrod
4f1428c249 Remove myself from scholarship alias, it is all spam at this point anyway
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-03-28 21:41:06 +00:00
Stephen Smoogen
83dd6b4bb7 fix a ,, in the csv file 2018-03-28 21:11:32 +00:00
Robert Mayr
2d8db9d68e build stg websites with f28-beta branch 2018-03-28 17:09:38 +00:00
Mikolaj Izdebski
ded045181f Add buildvm-stg hosts to container channel 2018-03-28 09:39:38 +00:00
Kevin Fenzi
d8ba3fb037 drop the dequeue job in stg 2018-03-27 20:18:12 +00:00
Jeremy Cline
1816d3de06 Try to fix the OpenShift YAML
OpenShift refuses to roll out librariesio2fedmsg. Maybe it doesn't like
this yaml snippet. Who knows?

Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-03-27 17:59:10 +00:00
Jeremy Cline
b1ecd16de4 Drop the route and service for librariesio2fedmsg
Since we use the busrelay, there are no incoming connections to the
service, just outgoing ones.

Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-03-27 17:37:30 +00:00
Jeremy Cline
da7ee64218 Drop the relay container build
sse2fedmsg is configured to use the relay at
tcp://busgateway01.stg.phx2.fedoraproject.org:9941

Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-03-27 17:28:07 +00:00
Kevin Fenzi
6f750a05ee fix incorrect filename 2018-03-27 17:12:31 +00:00
Dennis Gilmore
875cf18839 changes to releng-team email alias
Remove myself from releng-team as I am no longer involved
Add Rob Marshall to the releng-team alias

Signed-off-by: Dennis Gilmore <ausil@fedoraproject.org>
2018-03-27 15:15:22 +00:00
Sayan Chowdhury
0b38aaa1ed autocloud, hotfix: Add the patch for the hotfix (F28 messages)
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-27 12:55:04 +00:00
Sayan Chowdhury
cbb62f1c37 autocloud, hotfix: Add the hotfix to process F28 Atomic, Cloud messages
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-27 12:55:04 +00:00
Sayan Chowdhury
1a4116b66b autocloud, hotfix: Remove the autocloud hotfix for the PR#56
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-27 12:55:04 +00:00
clime
f915d6bed6 dist-git: add temporary cache_dir_override option 2018-03-27 12:41:10 +02:00
Kevin Fenzi
8405ead31d add sysadmin-osbs to staging koji/builders to help debugging 2018-03-26 20:32:42 +00:00
Randy Barlow
410258bb75 Dequeue bodhi batched updates daily.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-03-26 02:37:49 +00:00
Stephen Smoogen
ed4e1e7eaa and this will add jim to the people to see logs 2018-03-24 15:47:53 +00:00
Adam Williamson
f6b38111ff openQA: try only 3 workers per aarch64 host
4 seems a bit too many (esp. since we assign 4GB per job and
the hosts only have 16GiB RAM). Let's try 3. I hope there's no
case where we actually *need* to run 4 tap jobs simultaneously.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-23 15:56:28 -07:00
Stephen Smoogen
22c93a9bbd ok try to make moving average and graphs look good 2018-03-23 21:52:30 +00:00
Stephen Smoogen
f93e67ffe1 oh yeah order matters in pattern matching. realy it does 2018-03-23 20:58:48 +00:00
Ricky Elrod
539a6fad34 use pagure01 here instead
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-03-23 19:35:08 +00:00
Ricky Elrod
4dcc2ba7b8 Merge branch 'master' of /git/ansible 2018-03-23 19:07:05 +00:00
Ricky Elrod
28e1107e28 some new and improved ssl checks
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-03-23 19:06:54 +00:00
Stephen Smoogen
1e274cbcf6 oh yeah order matters in pattern matching 2018-03-23 18:22:24 +00:00
clime
7788abfbd0 copr-be: lower vm limits for ppc64le not to overload cloud 2018-03-23 18:01:03 +01:00
Kevin Fenzi
d4fcdaa7a2 drop jenkins f27 ppc host to large from xlarge 2018-03-23 15:44:54 +00:00
Adam Williamson
a8ee935cbe Fix 'when' condition for previous commits
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-22 16:14:10 -07:00
Adam Williamson
e6fbc29d42 Try and fix previous commit (I hate sql)
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-22 16:11:12 -07:00
Adam Williamson
e069489ecc Tweak openQA asset size settings again
The UI makes this easier to investigate now, and it looks like
we could give x86_64 a bit more space, but other arches less.
So let's tweak things to do that. This should also reduce
overall usage on staging a bit, as it's up against its limits.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-22 16:06:42 -07:00
Kevin Fenzi
37dd6c16a4 fix logic 2018-03-22 22:54:55 +00:00
Kevin Fenzi
6dcc71fe94 fix typo 2018-03-22 22:23:03 +00:00
Kevin Fenzi
5dcd66d570 Per https://pagure.io/releng/issue/7326 move the power builders oz config to use just 1 cpu for now.
There is a bug in nested virt with more than 1 cpu that is causing all the images to fail to build.
2018-03-22 21:37:39 +00:00
Stephen Smoogen
4fd408b021 this will allow for csv to be correct. 2018-03-22 19:58:24 +00:00
Sayan Chowdhury
f37206dbc4 fedimg: Add the hotfix patch to parse Cloud and Atomic Image variant
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-22 17:33:53 +00:00
Sayan Chowdhury
6335ef4dc2 fedimg: Put hotfix for add Atomic & Cloud variant
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-22 17:33:53 +00:00
Stephen Smoogen
4e166d60b5 remember what the program did and rewrite statement 2018-03-21 22:03:52 +00:00
Stephen Smoogen
23be9d8791 remember what the program did and rewrite statement 2018-03-21 21:51:10 +00:00
Stephen Smoogen
8d48479d62 and we may have new stuff to spew for modules 2018-03-21 21:06:24 +00:00
Kevin Fenzi
470ce2ba50 missed a place 2018-03-21 18:14:36 +00:00
Kevin Fenzi
2622dea3c4 drop db-koji02.stg from inventory 2018-03-21 17:44:36 +00:00
Kevin Fenzi
2cf42b973e Drop old twisted buildbot cloud instances. 2018-03-21 17:42:10 +00:00
Kamil Páral
c8e8eb3fc2 taskotron-dev: update taskotron.yaml
Specify minion COPR repos in a new syntax.
2018-03-21 15:25:04 +01:00
Clement Verna
931ab6c7ad namespace is osbs-fedora not osbs-client
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:53:05 +01:00
Clement Verna
fdd944b973 Add secret and namesapce to koji builder osbs configuration
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:46:23 +01:00
Clement Verna
e872730d88 Add namespace to osbs master configuration
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:45:23 +01:00
Clement Verna
982ca6c913 Add x86-64 osbs platform
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:44:39 +01:00
Clement Verna
6f009a72fc Replace incorrect char in the variable name second try
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:18:55 +01:00
Clement Verna
66ffe1141f Replace incorrect char in the variable name
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 10:06:11 +01:00
Clement Verna
ce79fc6f8f Correct the secret file path
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 09:59:39 +01:00
Clement Verna
05566181a9 Add the vars files to see the private repo
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 09:54:09 +01:00
Clement Verna
52d6bfb335 Fixing identation
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 09:49:33 +01:00
Clement Verna
8ba9d66ac1 fixing the hosts for the orchestrator secret
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 08:22:12 +01:00
Clement Verna
360656636d Add the worker orchestrator token secret to the orchestrator namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-21 08:20:54 +01:00
Kevin Fenzi
71945b4c1d follow the redirect on pkgs monitoring as we want to know if the entire path to src.fedoraproject.org is working anyhow 2018-03-21 01:08:00 +00:00
Kevin Fenzi
877215fa7d Make the redirect for pkgs handle more than just / Ticket https://pagure.io/fedora-infrastructure/issue/6785 2018-03-20 18:59:54 +00:00
Clement Verna
0ffc553d9f Add Orchestrator/Worker config to osbs.conf template
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-20 12:18:07 +01:00
Stephen Smoogen
524c1e2479 the playbooks home moved down one dir 2018-03-19 21:19:55 +00:00
Stephen Smoogen
fdb5e7423a fix the download problem for kernel.org 2018-03-19 17:36:43 +00:00
Jan Kaluža
91fe6a354d Update also python2-solv during manual/upgrade/mbs.yml 2018-03-19 07:25:54 +00:00
Jan Kaluža
ebaa897f1a Use basename when referencing MBS default module 2018-03-19 07:17:04 +00:00
Jan Kaluža
e02cbc0fff Use files/default-modules.{{ env }} to store default modules and copy them using fileglob. 2018-03-19 07:14:33 +00:00
Jan Kaluža
e9cff502ae Revert "Do not copy default-modules to MBS backend, but import it from files directly."
This reverts commit 23f6b3b6b9.
2018-03-19 07:08:25 +00:00
Jan Kaluža
23f6b3b6b9 Do not copy default-modules to MBS backend, but import it from files directly. 2018-03-19 07:04:27 +00:00
Jan Kaluža
c212c43cba Fix typo in MBS common role. 2018-03-19 06:54:31 +00:00
Jan Kaluža
e0285b7f50 Import default modules as part of MBS common role. 2018-03-19 06:49:14 +00:00
Kevin Fenzi
b10e5a2ca4 Fix this cron job to run as pagure instead of nobody so it can actually fix hooks. 2018-03-17 01:15:51 +00:00
Kevin Fenzi
4d82d4f9aa make s390x image building vm have a longer/different timeout for oz than the rest do for now 2018-03-16 21:19:35 +00:00
Stephen Smoogen
9c512cd276 add memory to pdc-web01 2018-03-16 21:19:11 +00:00
Stephen Smoogen
5cd49565a1 add in download for kernel.org systems 2018-03-16 20:48:35 +00:00
Sayan Chowdhury
326ab635c8 fedimg: Configure euca2ools for fedimg stg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-16 18:13:15 +00:00
Sayan Chowdhury
08e1d3c5b3 fedimg: Add the missing quotes to the config file
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-16 13:20:53 +00:00
Ralph Bean
fa5afee24b Config for puiterwijk's dead.package hotfix. 2018-03-16 13:20:08 +00:00
Patrick Uiterwijk
c47c621a07 Bump quota for kalev to 5gb
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-16 12:52:05 +01:00
Kevin Fenzi
e113592d40 add handlers 2018-03-15 20:19:29 +00:00
Nick Bebout
b6529072df Enable IPv6 for port 11371 2018-03-15 20:14:25 +00:00
Kevin Fenzi
24ac1f73a8 Add telegram-irc machine. Ticket https://pagure.io/fedora-infrastructure/issue/6781 2018-03-15 20:11:40 +00:00
Nick Bebout
4832f6a85c Update SKS membership file 2018-03-15 20:06:33 +00:00
Sayan Chowdhury
ddd5c92e79 fedimg: Use bools in fedimg toml config file itself
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-15 04:46:00 +00:00
Ricky Elrod
9fcbd30b55 add dell qa boxes to [dells]
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-03-14 22:54:01 +00:00
Adam Williamson
a0e93efde2 openQA: tweak ansible_ifcfg_whitelist handling for workers
As we have more and more tap workers, it's no longer practical
to do this for the whole group, as each one seems to have a
*different* set of interfaces a) present and b) 'active'. So
let's just take it out of the group vars and do it per-host
instead. Each tap worker only actually has *one* real hardware
interface that should be handled by network / NetworkManager,
so we just list that one per-host (it's eth0 for all of them
except the ppc64 host, which is eth2 for some damn reason).

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-14 12:01:20 -07:00
Kevin Fenzi
4039e6bc32 try unsetting content-encoding completely for this silly app 2018-03-14 16:28:23 +00:00
Kevin Fenzi
45f8b8b226 do not set content-encoding on xml.gz files 2018-03-14 16:19:10 +00:00
Clement Verna
d4dfa0e47e Setup the authoritative_registry to registry.fp.o
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-14 17:07:14 +01:00
Patrick Uiterwijk
29497a56ba Use modernpaste-sudoers
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-14 16:42:08 +01:00
Patrick Uiterwijk
7e4cb74c09 Allow paste-deleter onto modernpaste hosts
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-14 16:40:48 +01:00
Kamil Páral
09d4cbd774 taskotron-dev: adjust artifacts_base_url
Because /all/ is no longer hardcoded in latest libtaskotron.
2018-03-14 15:08:26 +01:00
Sayan Chowdhury
f71f59f4e3 fedimg: Fix the trigger_upload script to create AMIs manually
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-03-14 12:26:29 +00:00
Clement Verna
2954f0c71c Add missing osbs_namespace var
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-14 08:51:52 +01:00
Clement Verna
06544db130 Add the orchestrator namespace to osbs-cluster stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-14 08:41:16 +01:00
Kevin Fenzi
78f123bd87 swap order here 2018-03-13 18:30:30 +00:00
Kevin Fenzi
d51b51a295 remove user who no longer has a people account from quota increase 2018-03-13 18:14:54 +00:00
Kevin Fenzi
a052bdcaef attempt to fix fedorapeople repos sending repodata as text/plain 2018-03-13 18:04:31 +00:00
Ralph Bean
53c3ca1269 Set session key for PDC. 2018-03-13 15:25:55 +00:00
Ricky Elrod
440f270f4b Apply FBR (Fix the broken fedimg hub config key)
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-03-13 04:32:41 +00:00
Kevin Fenzi
92f0ccf3e1 do not set sysctl on buildvm-armv7-03 for debug info gathering 2018-03-13 00:10:15 +00:00
Kevin Fenzi
d6bfb71113 Tweak the prerelease redirects for server/workstation/atomic.
If using the default lang, there will not be a /NN/ code in the url resulting in the redirect failing to work.
So, we drop the / on the end and it works for both /en/workstation/prerelease and /workstation/prerelease.
We need to fix this so users aren't directed to a Fedora 28 prerelease page even before Beta.
2018-03-13 00:09:13 +00:00
Nick Bebout
37281b2e13 Update IP for keyserver 2018-03-12 20:29:15 +00:00
Nick Bebout
2911cbc2cd Add keys01 2018-03-12 19:43:20 +00:00
Kevin Fenzi
4551663ddc move the target to be a bit more sane for some of these redirects 2018-03-12 18:50:31 +00:00
Kevin Fenzi
f7a70fd34a try this in staging to fix prerelease links 2018-03-12 18:26:15 +00:00
Sayan Chowdhury
8ba20a7887 fedimg: Change the fedimg-conf.toml file 2018-03-12 14:56:19 +00:00
Clement Verna
23dd9655a6 set the name of the registry cert
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 15:36:43 +01:00
Clement Verna
4462031955 Add the vars files
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 14:44:51 +01:00
Clement Verna
088fc91d08 Use the private repo as cert source for osbs secret
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 14:36:47 +01:00
Patrick Uiterwijk
60011aff73 Update f28 atomic workstation filename
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-12 14:18:49 +01:00
Clement Verna
1ef6c369fc Forgot to remove the comma here
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 11:57:47 +01:00
Clement Verna
9976018c36 More syntax fix
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 11:56:41 +01:00
Clement Verna
75cab810e6 fixing osbs playbook syntax errors
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 11:45:07 +01:00
Clement Verna
e05fc4c3b5 Use the correct syntax to specify stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 11:35:11 +01:00
Clement Verna
af01660d27 Add osbs worker namespace to main playbook but only stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 11:17:27 +01:00
Adrian Reber
9e13fede63 MM crawler: skip lost+found during rsync crawl
The rsync based crawler has two excludes hardcoded:

 cmd = "rsync --temp-dir=/tmp -r --exclude=.snapshot --exclude='*.~tmp~'"

To avoid failures during rsync crawling this adds 'lost+found' to the
exclude list via the configuration file.

Signed-off-by: Adrian Reber <adrian@lisas.de>
2018-03-12 10:19:51 +01:00
Clement Verna
47242c6716 Add a manual playbook to create a worker namespace (testing)
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 10:01:36 +01:00
Clement Verna
7d7db0bcb9 Add OSBS variable to osbs-master-stg
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-12 10:00:51 +01:00
Patrick Uiterwijk
43ac82d4bf Fix naming in updates-sync, add f28 primary arches and set 28 testing repomd
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-10 00:09:55 +01:00
Patrick Uiterwijk
692ddc2f78 Some objects got promoted in kubernetes 1.8 to core
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-09 23:29:57 +01:00
Patrick Uiterwijk
78ff12f828 Update openshift role to use namespace-local roles
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-09 22:53:23 +01:00
Dusty Mabe
aaa694f7e4 bodhi pungi ostree: point to different repos for f28
The f28 repos we need to tap into are not in the same locations
as for post release (f26/f27) runs.

Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-03-09 16:46:00 -05:00
Kevin Fenzi
5bbb1c5f5e fix invocation of git-check-perms. This is needed to setup hooks on new packages as they are added 2018-03-09 19:01:56 +00:00
Aurélien Bompard
1ad3c43c45 Mailman: strip DKIM signatures 2018-03-09 12:07:06 +00:00
Dusty Mabe
8e7dfe7e20 change FAW redirects to point to new unified repo 2018-03-08 11:58:32 -05:00
Peter Robinson
2790ef5dab releng: run fedmsg/base before releng because needs fedmsg group 2018-03-08 13:36:25 +00:00
Michael Simacek
9e428483b2 Add upgrade playbook for java-deptools 2018-03-08 13:54:42 +01:00
Peter Robinson
125443fbcc compose-iot: add nfs mount, fas groups 2018-03-08 11:20:42 +00:00
Peter Robinson
14ab0377e5 compose-iot: add nfs interface 2018-03-08 10:33:11 +00:00
Patrick Uiterwijk
6ffa97bce8 Update Bodhi configuration for modularity changes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-08 10:53:25 +01:00
Clement Verna
3c69f743ba Increase the warning and critical threshold for packages fedmsg backlog
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-08 08:32:00 +01:00
Mikolaj Izdebski
83499c9f59 Adjust postgres memory settings on db-koji.stg 2018-03-08 04:12:40 +00:00
Mikolaj Izdebski
a3c6fb1061 Fix another typo 2018-03-08 03:36:54 +00:00
Mikolaj Izdebski
823e3efb37 Fix a typo 2018-03-08 03:34:46 +00:00
Mikolaj Izdebski
beb0966299 Allow staging mbs to use koji content generator 2018-03-08 03:21:16 +00:00
Mikolaj Izdebski
e4eec6ddea In staging koji grant admin perm to mbs.stg 2018-03-08 03:06:09 +00:00
Qixiang Wan
58022df256 freshmaker: remove testmodule from whitelist
Token for talking with MBS has not been ready yet, remove this to
prevent error messages on stage.
2018-03-08 09:26:13 +08:00
Patrick Uiterwijk
3e00a64432 Disable ostree on bodhi staging
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-08 02:20:13 +01:00
Patrick Uiterwijk
d1b8077874 Fix bodhi email in stg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-08 02:19:32 +01:00
Randy Barlow
2b02820f7f Add fedora-28-modular to Greenwave's policy.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-03-07 16:10:12 +00:00
Patrick Uiterwijk
4420d04ad4 Update key for f28m
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-07 13:14:12 +01:00
Jan Kaluža
261ab77b50 Use 'db' resolver in MBS staging. 2018-03-07 11:44:44 +00:00
Peter Robinson
83696db4d9 fix compose-iot-01 c/p errror 2018-03-07 09:22:57 +00:00
Peter Robinson
c2ecdcf281 add compose-iot-01 2018-03-07 09:05:10 +00:00
Jan Kaluža
f5760b6f5e Do exit with 1 in case service is not present while running conditional-restart.sh. 2018-03-07 08:57:58 +00:00
Adam Williamson
4017e9ebdc openqa: update ppc64 images.json for Atomic variant renames
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-06 16:09:02 -08:00
Patrick Uiterwijk
007e001582 Sync f28(m) updates-testing
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-07 00:59:01 +01:00
Kevin Fenzi
1dc149a5ca add 2fa client to pre here so we can get it working 2018-03-06 23:42:07 +00:00
Adam Williamson
41bdf9d47b inventory: fix openqa aarch worker group memberships again
We really should not deploy these straight to production, they
need to go to staging first. It's easy to move them if we're
happy with everything. Also, both boxes need to be in the main
workers group.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-06 15:34:29 -08:00
Adam Williamson
f7c87b0f75 openqa/worker: make some file existence checks safer
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-03-06 15:24:37 -08:00
Ralph Bean
df75f880d1 greenwave: remove debugging patch. 2018-03-06 17:57:50 +00:00
Ralph Bean
a8982b04f3 greenwave: more debugging. 2018-03-06 17:47:16 +00:00
Ralph Bean
15db2a3a45 Specific hash to get around layer caching. 2018-03-06 17:37:56 +00:00
Ralph Bean
b7f1e5496c greenwave: needed to apply patch. 2018-03-06 17:17:45 +00:00
Ralph Bean
d8a1d8a7a2 Debugging for greenwave messaging. 2018-03-06 17:15:43 +00:00
Nick Bebout
ba582d7af2 Merge branch 'master' of /git/ansible 2018-03-06 16:54:56 +00:00
Nick Bebout
62ffac5b61 Add bexelbie to username blacklist 2018-03-06 16:54:41 +00:00
Nick Bebout
1c8f04d698 add bexelbie alias for bex 2018-03-06 16:52:48 +00:00
Nick Bebout
ece11efa66 change fama alias 2018-03-06 16:51:13 +00:00
Patrick Uiterwijk
4540ba5db3 re-add dropped }
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-06 17:50:49 +01:00
Peter Robinson
7db24487c4 openqa: aarch64: add sysadmin-secondary users 2018-03-06 16:38:18 +00:00
Ralph Bean
699e15c6d5 greenwave: some additional logging for http requests. 2018-03-06 16:25:12 +00:00
Randy Barlow
d0267d5f79 Remove Fedora 25 from Greenwave's update policy.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-03-06 15:26:00 +00:00
Randy Barlow
aeee011ea0 Add Fedora 28 to Greenwave's update policy.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-03-06 15:25:31 +00:00
Dusty Mabe
07c0d29dee For F26 and F27 Atomic Host we keep their prod repos in place
We aren't moving their prod repos to the new unified prod repo.

Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-03-06 09:26:17 -05:00
Dusty Mabe
482a7878dd robosig: move to unified atomic ostree repo structure 2018-03-06 15:21:01 +01:00
Patrick Uiterwijk
50069a2d53 Add f28 signing key to pungi config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-06 15:08:43 +01:00
Dusty Mabe
c728992501 move to unified atomic ostree repo structure
We move to /compose/atomic/repo for the compose time repo and to
/atomic/repo for the production/user repo. See [1].

[1] https://lists.fedoraproject.org/archives/list/rel-eng@lists.fedoraproject.org/thread/KLN5L33BIR3ZEHC5RIG4NXGO7LT6HBXJ/
2018-03-06 08:48:55 -05:00
Peter Robinson
9b802fc4c2 openqa: aarch64: add sudo entry 2018-03-06 12:31:25 +00:00
Peter Robinson
f3a36eb162 openQA: run yumrepos as a pre task 2018-03-06 12:06:59 +00:00
Peter Robinson
255e1c1cab add openqa-hdds-workers group to openQA workers playbook 2018-03-06 11:51:15 +00:00
Peter Robinson
a4e44783a4 enable openqa-aarch64-01 openQA worker 2018-03-06 11:46:49 +00:00
Peter Robinson
26f2074487 update openqa-aarch64 dhcp entries 2018-03-06 11:42:01 +00:00
Paul Whalen
970640e4f4 Add aarch64 server boot, dvd to images. 2018-03-06 09:47:32 +00:00
Paul Whalen
d05660192c Add aarch64 to workers template. 2018-03-06 09:47:01 +00:00
Paul Whalen
888c66f52e Add edk2-aarch64 to aarch64 workers. 2018-03-06 09:46:30 +00:00
Paul Whalen
e8b4c4d2b4 Add aarch64 openqa host_vars details 2018-03-06 09:45:57 +00:00
Mikolaj Izdebski
fa661d85c5 Install GNU screen on java-deptools 2018-03-06 05:26:28 +00:00
Mikolaj Izdebski
04689c6bda java-deptools cron: don't overwrite logs 2018-03-06 05:20:45 +00:00
Mikolaj Izdebski
1ca045f3af Fix a typo 2018-03-06 05:15:13 +00:00
Mikolaj Izdebski
2a26bce586 Become postgres user when creating java-deptools db and importing schema 2018-03-06 05:13:24 +00:00
Mikolaj Izdebski
d356094d2b Fix java-deptools postgres role creation 2018-03-06 05:10:47 +00:00
Mikolaj Izdebski
610739f9a2 Remove basessh role from java-deptools
cloud_setup_basic.yml already includes this role, no need to apply it
again.
2018-03-06 05:04:20 +00:00
Mikolaj Izdebski
b89f326057 Become postgres user when creating java-deptools db role 2018-03-06 05:00:47 +00:00
Mikolaj Izdebski
459172721b Remove extra root_auth_users from jenkins hosts 2018-03-06 04:57:48 +00:00
Mikolaj Izdebski
feb94e7a0c Make certbot role install httpd
This role tries to put file in /etc/httpd/conf.d, httpd should be
installed first.
2018-03-06 04:54:35 +00:00
Mikolaj Izdebski
b3a6656363 Include restart_services.yml handlers from java-deptools playbook 2018-03-06 04:37:08 +00:00
Mikolaj Izdebski
19b597c3c9 Remove java-deptools openstack volume 2018-03-06 04:30:31 +00:00
Mikolaj Izdebski
6407f2e55f Switch java-deptools to https 2018-03-06 04:21:53 +00:00
Patrick Uiterwijk
b58dfc3086 Sync up the robosig config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-06 00:58:37 +00:00
Kevin Fenzi
442e431e1b fix typo on pagure service. It is loadjson 2018-03-06 00:41:37 +00:00
Mohan Boddu
ea8e3fa29c F28 Bodhi enablement changes
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-03-05 23:59:26 +00:00
Kevin Fenzi
061e528ff7 add some missed playbooks to master 2018-03-05 22:30:55 +00:00
Kevin Fenzi
a9f5e8e78a update base rootpw role to not change some more releng machines that have had koji_builder added to them 2018-03-05 22:14:26 +00:00
Kevin Fenzi
8c899e6bc2 missed some inventory 2018-03-05 19:31:40 +00:00
Kevin Fenzi
a3d3003eb6 remove graphite config entirely 2018-03-05 18:59:18 +00:00
Stephen Smoogen
c24fd7522b and we have a zone file for epel.io and fedp.org 2018-03-05 18:57:13 +00:00
Kevin Fenzi
85acea3408 clean up master playbook 2018-03-05 18:38:35 +00:00
Kevin Fenzi
2cce3883a3 drop collectd graphite plugin 2018-03-05 17:59:38 +00:00
Kevin Fenzi
2a10011a91 Drop some obsolete cloud instances 2018-03-05 17:50:58 +00:00
Michael Simacek
b8956caa8f Change java-deptools machine to f27 2018-03-05 17:53:24 +01:00
Michael Simacek
3708951dca Update list of active releases in java-deptools 2018-03-05 17:51:45 +01:00
Michael Simacek
83d5b1470b Add role for java-deptools 2018-03-05 17:34:03 +01:00
Mikolaj Izdebski
614e5fea56 Mark virthost-comm03.qa as freezing 2018-03-05 16:32:33 +00:00
Tim Flink
91e384d3e9 removing db-qa-stg01.qa from ansible 2018-03-05 16:25:51 +00:00
Tim Flink
977c8371a5 adding host_backup_targets to qa db hosts 2018-03-05 16:19:05 +00:00
Mikolaj Izdebski
cabf04098c Install libsolv Python bindings on jenkins f26 slave 2018-03-05 14:05:42 +00:00
Nick Bebout
2a5b3bdda9 Add mleonova to tahrir.ini as admin 2018-03-05 11:09:50 +00:00
Mikolaj Izdebski
1c459c1ee6 koschei/backend: silence cron job for refreshing groups 2018-03-05 10:33:50 +00:00
Mikolaj Izdebski
9f310d40b7 Move db-koji01.stg from pgbdr-stg group to dbserver-stg 2018-03-05 10:22:06 +00:00
Kevin Fenzi
305e7a30a0 fix missing curly 2018-03-05 02:05:55 +00:00
Kevin Fenzi
dad12eb4ca fix this lookup so it works on primary again 2018-03-05 01:54:17 +00:00
Kevin Fenzi
e6efe566ec Move ppc64le jenkins to f27 2018-03-05 00:34:21 +00:00
Kevin Fenzi
178509d30c adjust and fix typo in rkhunter config 2018-03-04 18:02:42 +00:00
Patrick Uiterwijk
561b3afebb Deploy updated auth.py for koji
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-03 12:25:32 +00:00
Patrick Uiterwijk
9eca0c928d Commit patched auth.py
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-03 12:25:32 +00:00
Patrick Uiterwijk
e3cb272c41 Commit original auth.py
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-03-03 12:25:32 +00:00
Mikolaj Izdebski
c7c272ca89 Fix kojira staging principal 2018-03-03 09:00:25 +00:00
Mikolaj Izdebski
8036100108 fix quotation 2018-03-03 05:43:18 +00:00
Mikolaj Izdebski
833c2340d0 koji stg sync: remount nfs, restart kojid 2018-03-03 05:40:49 +00:00
Mikolaj Izdebski
fcc48ee1a9 create /mnt/fedora_koji/koji directory too 2018-03-03 05:25:12 +00:00
Mikolaj Izdebski
07afb0e009 nuke old staging koji date during sync with production 2018-03-03 05:21:48 +00:00
Mikolaj Izdebski
41321e5ad2 Staging Koji hub should not mount NFS on itself 2018-03-03 03:44:02 +00:00
Mikolaj Izdebski
117070e183 Point staging koji hub back to db-koji01.stg 2018-03-03 03:22:00 +00:00
Mikolaj Izdebski
fa7975df4b Switch koji staging sync back to db-koji01.stg 2018-03-03 01:53:06 +00:00
Mikolaj Izdebski
928cc3f0de Fix postgresql_server initdb
Empty /var/lib/pgsql/ directory is created during postgresql-server
package installation.  We need another file to detect whether DB has
already been initialized.
2018-03-03 01:46:46 +00:00
Mikolaj Izdebski
5d5187d4ce Don't forget to create virt instance for db-koji01.stg 2018-03-03 01:17:48 +00:00
Mikolaj Izdebski
ed381bb762 db-koji01.stg is non-BDR postgres now 2018-03-03 01:16:36 +00:00
Mikolaj Izdebski
81b04cf18a Reinstall db-koji01.stg on Fedora 27 2018-03-03 01:10:55 +00:00
Kevin Fenzi
0b5895d664 add 2 more machines to allow rkhunter shm file 2018-03-02 18:32:47 +00:00
Kevin Fenzi
a7150be776 try upping this to 8 for bodhi compose threads 2018-03-02 15:09:06 +00:00
Kamil Páral
fc188690cd taskotron: remove git checkouts of unsupported tasks
Those tasks are no longer executed.
2018-03-02 13:20:13 +01:00
František Zatloukal
810b335983 Taskotron: Switch back to master branch on stg/prod 2018-03-02 12:56:30 +01:00
clime
a5bbf1583f copr-backend: custom SELinux rules for copr-backend extended/fixed 2018-03-02 09:55:00 +01:00
Mikolaj Izdebski
8c4faccea3 Enable runroot on buildvm-s390x-01.stg 2018-03-01 23:49:22 +00:00
Kevin Fenzi
f14ef92fd3 add sysctl for armv7 builders to avoid compose lockups 2018-03-01 21:04:16 +00:00
Mohan Boddu
3199806955 aarch64 is now a primary arch starting from F28
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-03-01 20:49:03 +00:00
Mikolaj Izdebski
39cdd1af91 Move koji hub sshfs setup to koji-hub.yml 2018-03-01 19:45:30 +00:00
Ralph Bean
a73e34b120 greenwave-0.6.1 2018-03-01 19:42:06 +00:00
Kamil Páral
6bca96f430 taskotron-prod: switch to running STI tasks 2018-03-01 19:53:02 +01:00
Kamil Páral
5921b21d6e taskotron: switch default minion to F27 2018-03-01 19:13:53 +01:00
Mikolaj Izdebski
577f928431 Add koschei-web02 to haproxy 2018-03-01 17:38:36 +00:00
Kamil Páral
1fb0dcceec taskotron-stg: switch to running STI tasks 2018-03-01 18:09:44 +01:00
Kamil Páral
336ff4d0f5 taskotron-trigger: fix abicheck blacklist
See https://pagure.io/taskotron/taskotron-trigger/issue/47
2018-03-01 17:44:25 +01:00
Ralph Bean
0b2120ba84 Remove old greenwave staging conditional. 2018-03-01 16:43:02 +00:00
Mikolaj Izdebski
1d0f7473c1 Add koschei-web02.phx2 to inventory 2018-03-01 15:44:16 +00:00
Clement Verna
d489ab855f Add osbs-secret role to create secret for namedspaced cluster
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-01 14:29:55 +01:00
Clement Verna
bf757c97ad atomic-reactor is not needed on the osbs hosts.
atomic-reactor is only needed in the buildroot,
therefore we do not need to install it on the
osbs master and nodes.

Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-03-01 14:28:02 +01:00
Kamil Páral
95c1989180 taskotron: get rid for /task_output/ subdir in results URL (on dev) 2018-03-01 13:19:32 +01:00
Kamil Páral
a78c239de5 taskotron buildmaster: follow taskotron.log (on dev) 2018-03-01 09:43:23 +01:00
Mikolaj Izdebski
6ecfec3243 Configure sshfs on buildvm-s390x-stg 2018-03-01 00:44:14 +00:00
Mikolaj Izdebski
8054c79719 Rename buildvm-s390x-15 to buildvm-s390x-01.stg 2018-02-28 23:54:12 +00:00
Mikolaj Izdebski
bc32f6f367 After stg koji sync NFS on composer.stg needs to be remounted too 2018-02-28 23:52:59 +00:00
Mikolaj Izdebski
4e0d282290 Use custom kickstart for installing koji01.stg 2018-02-28 19:11:48 +00:00
Mikolaj Izdebski
58609c0644 Switch staging koji to db-koji02 2018-02-28 18:38:15 +00:00
Mikolaj Izdebski
698ede0787 Add atop to global_pkgs_inst
This small tool is especially useful in identifying performance
bolltenecks.
2018-02-28 18:29:14 +00:00
Mikolaj Izdebski
b9a6da7eeb Try some pipe buffering for faster db-koji stg sync 2018-02-28 18:27:23 +00:00
Mikolaj Izdebski
32a9204273 koji01.stg is not supposed to run kojid 2018-02-28 17:41:29 +00:00
Kevin Fenzi
be38d5fcd9 increase greenwave datanommer fedmsg check from 4 hours to 6 hours as it has been alerting some nights with low build activity 2018-02-28 17:38:20 +00:00
Mikolaj Izdebski
7150a81a04 Add empty buildvm-s390x-stg inventory group 2018-02-28 17:37:12 +00:00
Mikolaj Izdebski
9a12f6bf79 Run koji-reset-staging.sql in a single db transaction
If the script fails for some reason, we want DB to be in consistent
state so that the script can be fixed and re-ran more easily.
2018-02-28 17:31:33 +00:00
Mikolaj Izdebski
a97de30d27 Koji stg sync: run vacuum in a separate task 2018-02-28 17:30:20 +00:00
Mikolaj Izdebski
38786f14cf De-duplicate builder setup code in koji-reset-staging.sql 2018-02-28 17:16:52 +00:00
Mikolaj Izdebski
d0b9678cbb Staging koji hub is not supposed to be builder 2018-02-28 16:53:34 +00:00
Mikolaj Izdebski
0e632b2f51 Add more koji stg sync steps to be ansiblized later 2018-02-28 16:27:27 +00:00
Mikolaj Izdebski
1aa06f2fa9 Make sure koji role is set up before syncing db 2018-02-28 01:06:12 +00:00
Mikolaj Izdebski
a2899a7817 Use postgresql_db module to recreate koji stg db 2018-02-28 00:48:22 +00:00
Mikolaj Izdebski
d1b11e0dbc Run koji staging sync on db-koji02.stg for now 2018-02-28 00:28:30 +00:00
Mikolaj Izdebski
1b78a55604 Koji sync: try downloading DB dump in parallel to restoring it 2018-02-28 00:24:57 +00:00
Paul W. Frields
57e3d7ceef Add aws-s3 FAS role mapping 2018-02-27 22:52:25 +00:00
Matej Marusak
a06f01d1a2 ABRT: Rebase to upstream roles
Signed-off-by: Matej Marusak <mmarusak@redhat.com>
2018-02-27 16:01:26 +01:00
Matej Marusak
7d158fa8a4 ABRT: Add Fedora 28
Signed-off-by: Matej Marusak <mmarusak@redhat.com>
2018-02-27 16:00:57 +01:00
Mikolaj Izdebski
25d990f519 Unfreeze staging virthosts 2018-02-27 13:47:15 +00:00
Mikolaj Izdebski
586bc378a8 Terminate insim.fedorainfracloud.org 2018-02-27 11:12:14 +00:00
Kevin Fenzi
11e384a8c3 lets try and install oz/imagefactory on s390x builders too 2018-02-27 00:57:34 +00:00
clime
84994494c3 copr-backend: fix copr-be-dev setup 2018-02-27 00:23:06 +01:00
Dusty Mabe
3745b0d4f5 bodhi: remove atomic-config.py.j2
We used to use this when we used fedmsg-atomic-composer but since the
move to pungi I don't think this is used any longer.
2018-02-26 15:54:03 -05:00
clime
a9c57de46e copr-backend: ignore 209.132.184.53 when counting rpm downloads
* that ip belongs to copr-builder-gateway.fedorainfracloud.org
* also ignore other ips on the same /24 subnet
2018-02-26 20:01:32 +01:00
clime
4f901eb9cf update dist-git.conf for next dist-git release
* this change is not exactly necessary due to default values, but
  I think it's better to be explicit
2018-02-26 14:46:54 +01:00
Kevin Fenzi
fd4d59e47f move db-datanommer02 to virthost06 2018-02-25 16:47:30 +00:00
Adam Williamson
f9fc0ca090 Tweak openqa inventory groups a bit
Only one of the planned aarch64 boxes should be in tap-workers
and hdds-workers, not both.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-02-23 23:29:53 -08:00
Kevin Fenzi
8a19a0ef8d try this one 2018-02-24 01:44:25 +00:00
Adam Williamson
fdecceb571 openqa: Fix a check in createhdds worker
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-02-23 17:21:55 -08:00
Adam Williamson
672bf06b04 openqa: do createhdds on x86_64 workers for now
1539330 is turning out to be pretty intransigent and the images
are getting very old, plus we need f28 branched base images. So
let's do image builds on the x86_64 workers for now. Also re-
enable image builds on workers - I never should've turned that
off in the first place, as they shouldn't be susceptible to the
bug.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-02-23 17:14:28 -08:00
Kevin Fenzi
b651061e5c new staging ca cert 2018-02-24 01:13:56 +00:00
Kevin Fenzi
53726e10ce nodes need the os-stg hosts too 2018-02-24 00:07:56 +00:00
Kevin Fenzi
96396febd0 openshift 3.7 wants 16gb memory for machines 2018-02-23 23:28:29 +00:00
Kevin Fenzi
204d620b51 enable this fastpath repo for openvswitch in stg too 2018-02-23 23:17:17 +00:00
Kevin Fenzi
41d57bd5ce add a os-stg-hosts with pointer to the external ip for registery 2018-02-23 23:16:13 +00:00
Kevin Fenzi
304641b149 make os-control01.stg also larger 2018-02-23 23:05:15 +00:00
Kevin Fenzi
577076925e try this 2018-02-23 22:49:36 +00:00
Kevin Fenzi
4e6a50ee7e update openshift repo file for 3.7 2018-02-23 22:26:39 +00:00
Kevin Fenzi
45748f17d0 Update OpenShift in stg to 3.7 hopefully and reinstall vm's to get larger disks. 2018-02-23 22:02:23 +00:00
clime
201237b9d0 copr-frontend: dep is python3-alembic 2018-02-23 22:55:04 +01:00
clime
811c436340 copr-frontend: it's alembic-3 now 2018-02-23 22:53:41 +01:00
clime
f278a47117 copr-frontend: fix alembic invocation
* see https://bugzilla.redhat.com/show_bug.cgi?id=1536058
2018-02-23 21:29:50 +01:00
clime
c50aa8746f copr-backend: tweak lighttpd logrotate script 2018-02-23 18:03:40 +01:00
Patrick Uiterwijk
89fc603a89 Allow GET/HEAD requesting by everything
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-23 18:02:32 +01:00
clime
b2ab563302 copr-backend: activate copr_prune_results but on weekly basis 2018-02-23 17:57:12 +01:00
clime
176c3bb2fc copr-frontend: allow execmem
* see https://bugzilla.redhat.com/show_bug.cgi?id=1535689
2018-02-23 17:52:26 +01:00
Stephen Smoogen
c996069fe7 make this longer so we dont have as many 503s 2018-02-23 16:51:08 +00:00
František Zatloukal
49611b2e6e Taskotron: Adapt buildmaster-configure playbook to "Try to launch buildmaster.service multiple times before giving up" 2018-02-23 15:34:36 +01:00
Mikolaj Izdebski
4beb7fe6c6 Don't use deprecated state=running service parameter 2018-02-23 14:14:28 +00:00
Mikolaj Izdebski
37e17c124a Fix typo in Koschei upgrade playbook 2018-02-23 14:08:08 +00:00
Mikolaj Izdebski
9f97d061ba Rework Koschei upgrade playbook 2018-02-23 13:59:31 +00:00
Pierre-Yves Chibon
f69eaee359 Pretty please simple_koji_ci, log more info
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-23 12:34:08 +01:00
Aurélien Bompard
50da569cb0 Hubs: allow execmem 2018-02-23 10:12:30 +00:00
Aurélien Bompard
974e4058ac Hubs: move the stg variables to the group vars 2018-02-23 08:25:16 +00:00
Aurélien Bompard
bd10b60d7a Hubs: minor update 2018-02-23 08:25:16 +00:00
clime
0b0f4dd06c copr-backend: install OpenStack clients as python2-* 2018-02-23 09:07:04 +01:00
clime
4ecca0ed53 copr-builder: ensure the latest mock-core-configs 2018-02-23 08:53:40 +01:00
clime
e8ea8a80c8 copr: we no longer use mbs 2018-02-23 08:53:33 +01:00
Stephen Smoogen
f39c2b99ee make sure proxy06 can be built on a real disk 2018-02-22 23:11:50 +00:00
Stephen Smoogen
817898b748 move this to another box 2018-02-22 23:08:53 +00:00
Todd Zullinger
4a3ef1013c git/hooks: only use first line as project description
Hi all,

This is something I've seen for ages and thought should be fixed (either by
this patch and/or another which supports multi-line description files
properly).

I have an alternate version of this patch which side-steps the issue by adding
the X-Project header last, so if it's multiple lines it won't screw up other
headers.  I think this is the proper fix though.

If multi-line description files are really something which are desired, then a
commit on top of this change could add support for reading the remaining lines
from the description file and add them to the message body.

 roles/git/hooks/files/git.py | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
2018-02-22 21:58:11 +00:00
Dusty Mabe
25d9274b52 remove cron job for atomic-cd repo
This is not used and we agreed to remove it. See [1] [2].

[1] https://pagure.io/releng/issue/7269
[2] https://pagure.io/atomic-wg/issue/349

Signed-off-by: Dusty Mabe <dusty@dustymabe.com>
2018-02-22 16:16:40 -05:00
Nick Bebout
8ec4cb7c16 I just noticed that kevin's email address was spelled wrong in tahrir.ini, fixing 2018-02-22 21:16:18 +00:00
Ralph Bean
b714b23b92 When upgrading, choose python2-productmd over python-productmd. 2018-02-22 21:15:43 +00:00
Nick Bebout
c737933ae6 Add dustymabe to bugzilla exceptions 2018-02-22 21:13:46 +00:00
Patrick Uiterwijk
840e608559 Add tags
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-22 22:03:33 +01:00
Patrick Uiterwijk
8de70bd9a0 Sorry, KCM, but please fix your bugs and we'll look again 2018-02-22 22:02:53 +01:00
Patrick Uiterwijk
6920be10fa Remove f27m from new-updates-sync
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-22 15:47:51 +01:00
Peter Robinson
11365cf98b buildhw-aarch64 11/12 will become openqa-aarch64 1/2 2018-02-22 14:45:42 +00:00
Pierre-Yves Chibon
20ba04e6fb Fix typo in simple-koji-ci's fedmsg config
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-22 15:31:02 +01:00
Pierre-Yves Chibon
f6b7c0307b Adjust the simple_koji_ci fedmsg config
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-22 11:17:50 +01:00
Mikolaj Izdebski
120fc846c5 Check if service unit is present before trying to restart it 2018-02-22 09:35:29 +00:00
Patrick Uiterwijk
50a5082089 Update variable name for database host
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-22 10:26:33 +01:00
Jan Kaluža
d26cb9aab2 Enable i686 arch for staging MBS, so we can test multilib on staging. 2018-02-22 08:54:52 +00:00
Kevin Fenzi
f92afac098 try and disable disk space checks for openshift nodes 2018-02-22 04:18:13 +00:00
Kevin Fenzi
feba553390 os-nodes hosts file does not exist, we want them to use the defaul os one, perhaps 2018-02-21 20:14:22 +00:00
Kevin Fenzi
fc591915ac add gnaponie to greenwave and waiverdb app owners per ticket 6716 2018-02-21 19:19:52 +00:00
Aurélien Bompard
e604f022e4 Hubs: use Apache + mod_wsgi 2018-02-21 16:23:34 +00:00
Aurélien Bompard
87dc6e0e9e Hubs: improve gunicorn config 2018-02-21 14:55:34 +00:00
Aurélien Bompard
475709bd70 Hubs: fixes related to the staging env 2018-02-21 14:55:34 +00:00
Aurélien Bompard
7e291eb576 Hubs: fix fedmsg services declaration 2018-02-21 14:55:34 +00:00
Pierre-Yves Chibon
56efae7e16 Do not relying on the existance of 3 spaces to make decisions
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-21 15:21:21 +01:00
Andrea Veri
ec5aff5eb9 GNOME Backups: excludes sockets and fifos 2018-02-21 12:56:52 +00:00
František Zatloukal
ac70030718 Taskotron: Try to launch buildmaster.service multiple times before giving up 2018-02-21 13:18:48 +01:00
Kamil Páral
84e7f60262 taskotron buildmaster: don't set executable bit on service file 2018-02-21 13:02:04 +01:00
Kamil Páral
d661bac3a7 taskotron: improve messaging for imagefactory-kill-zombie 2018-02-21 12:39:47 +01:00
František Zatloukal
a5d81b53bd Taskotron: Fix invalid variable names 2018-02-21 12:25:52 +01:00
František Zatloukal
5bb54e4325 taskotron: install timer to kill zombie VMs from ImageFactory
Fixes: https://pagure.io/taskotron/issue/233
2018-02-21 12:15:15 +01:00
Miroslav Suchý
98dd57011d retrace: delete invalid and processed reports 2018-02-21 12:12:33 +01:00
František Zatloukal
b56833ffbc Taskotron: ImageFactory Client - Rawhide=29 2018-02-21 12:06:05 +01:00
František Zatloukal
5d88b24c44 Taskotron: Add F28 to Imagefactory 2018-02-21 11:57:40 +01:00
František Zatloukal
2905880ace Taskotron: Update yumrepoinfo on prod,stg,dev 2018-02-21 10:47:57 +01:00
František Zatloukal
bf4e45adfb Taskotron: Update yumrepoinfo on stg 2018-02-21 10:30:14 +01:00
František Zatloukal
8dab9581c4 Taskotron: Update yumrepoinfo on stg 2018-02-21 10:19:23 +01:00
František Zatloukal
47efdae07f Taskotron: Update yumrepoinfo on dev 2018-02-21 10:08:34 +01:00
Aurélien Bompard
ad8dda1f5e Hubs: disable the fedmsg hubs service for now 2018-02-21 08:16:32 +00:00
Aurélien Bompard
f6b6e21363 Hubs: declare Fedmsg certs 2018-02-21 08:11:22 +00:00
Aurélien Bompard
5a908ed559 Hubs: adapt to SSL proxy 2018-02-21 08:11:21 +00:00
Kevin Fenzi
936e6df897 install python3 versions of these since pungi is all python3 now 2018-02-21 00:55:49 +00:00
Randy Barlow
fa0cfc333b Remove all of Bodhi's mash configs since we use Pungi now.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-20 21:38:56 +00:00
Patrick Uiterwijk
a90921040f There are *WAY* too many places this needs to be updated
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-20 20:57:54 +01:00
Kevin Fenzi
f4ae00064b add f29 to koji garbage collection 2018-02-20 19:56:44 +00:00
Patrick Uiterwijk
015b6fb649 Bring the tooling in sync post-branch as the docs say
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-20 20:52:53 +01:00
Mohan Boddu
9943bf9af8 Bodhi changes for f28 branching
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-02-20 18:35:00 +00:00
Mohan Boddu
9886b18831 Enabling branched/f28 compose
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-02-20 17:45:20 +00:00
Patrick Uiterwijk
5a46e3bbe9 Set keephost for hubs
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-20 17:40:47 +01:00
Pierre-Yves Chibon
445e2eadfc Invert logic of namespace vs pdc type
We are iterating through the gitolite config that is namespace
aware (ie: rpms, modules) and are checking if the repo is in the
list to update, list coming from pdc and thus style aware not
namespaces (ie: rpm, module).
So invert the logic.

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-20 17:23:21 +01:00
Pierre-Yves Chibon
d640cbbba0 Fix if the entry exists in pdc and not on disk and typo in an error message 2018-02-20 17:22:58 +01:00
Pierre-Yves Chibon
5b81d69c5d More proxy tweaking for hubs
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-20 15:40:54 +01:00
Aurélien Bompard
211f01e121 Hubs: use more variables 2018-02-20 14:28:44 +00:00
Aurélien Bompard
7b3cb4cbfb Hubs: mistake in the DB hostname 2018-02-20 14:26:02 +00:00
Aurélien Bompard
99fbf6fcd9 Hubs: we use a SSL proxy in staging 2018-02-20 14:10:11 +00:00
Aurélien Bompard
88dfabb402 Hubs: syntax error... 2018-02-20 13:49:37 +00:00
Aurélien Bompard
ab89150191 Hubs: OIDC authentication 2018-02-20 13:47:56 +00:00
Mikolaj Izdebski
51b0d7f025 Install tox on jenkins f26 slave 2018-02-20 12:58:50 +00:00
Pierre-Yves Chibon
c558e739d8 dist-git doesn't trigger the POST_COMPILE (that was missing anyway
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-20 12:54:15 +01:00
Pierre-Yves Chibon
4464bf6eda Fixes some typos in the script updating the gitolite config for mass-branching
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-20 12:48:35 +01:00
Andrea Veri
3e26e68ff4 GNOME backups: clutter.g.o has been decommissioned 2018-02-20 11:40:34 +00:00
Pierre-Yves Chibon
f17603d02a Add to dist-git the scripts we use for mass-branching
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-20 12:04:15 +01:00
Mohan Boddu
68598ed941 Setup for branching f28 from rawhide
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2018-02-20 09:00:29 +00:00
Giulia Naponiello
8fdb53319d Added RESULTSDB_API_URL settings parameter 2018-02-17 05:43:38 +01:00
Giulia Naponiello
d5a3be5032 deploymentconfig is now a template 2018-02-17 05:32:01 +01:00
Giulia Naponiello
e836860eb1 use new upgrade database strategies 2018-02-17 05:20:55 +01:00
Kevin Fenzi
d57a7c3a00 need a restart httpd handler here for copr/mbs 2018-02-20 04:32:03 +00:00
Kevin Fenzi
f8a8bac129 this is poll 2018-02-20 00:28:12 +00:00
Kevin Fenzi
e621c76c8f Fix up the fedmsg handler. Ticket https://pagure.io/fedora-infrastructure/issue/6550
Just change the conditional script to use systemctl try-restart and hopefully it will do what we want.
2018-02-20 00:24:11 +00:00
Kevin Fenzi
3896b82982 try disallowing blobs for robots on pagure.io 2018-02-19 20:41:03 +00:00
Sayan Chowdhury
1ae76f5983 fedimg: Fix the vars for the fedimg configuration
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-19 16:31:16 +00:00
Randy Barlow
22a85b8b8a We no longer use mash or /var/log/bodhi.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-19 16:07:40 +00:00
Sayan Chowdhury
0373ea8867 fedimg: Update the fedimg tasks a/c to the 1.0.1 release
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-19 14:47:24 +00:00
Mikolaj Izdebski
87a209c8d3 Also install python-gobject-base on jeninks 2018-02-19 14:27:55 +00:00
Mikolaj Izdebski
cea8a3fc52 jenkins: install libmodulemd on f26 2018-02-19 14:21:28 +00:00
Clement Verna
fb240ea470 Update osbs-namespace to latest upstream.
This is an update of the ansible-role-osbs-namespace role
to the latest upstream available + PR16 not yet merged.

https://github.com/projectatomic/ansible-role-osbs-namespace
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-19 14:55:32 +01:00
Patrick Uiterwijk
65ef0a7240 Provide epoch if requested
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-19 13:12:39 +01:00
Patrick Uiterwijk
3a870bf672 Add to ansible: sign f28 also with f29 pre-branching
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-19 11:58:50 +00:00
clime
72e42a56b3 update dist-git.conf 2018-02-19 12:34:10 +01:00
Pierre-Yves Chibon
45564e852f List the commit_flag in the list of ACLs supported
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-02-19 11:36:17 +01:00
Aurélien Bompard
68d73e1307 Hubs: add the hubs role to the playbook 2018-02-19 10:36:07 +00:00
Pierre-Yves Chibon
3bd998fffe Allow pagure admin to create API token with the commit_flag ACL 2018-02-19 11:16:05 +01:00
Pierre-Yves Chibon
143a5ee77d Add haproxy config for hubs01 2018-02-19 11:16:05 +01:00
Aurélien Bompard
5e96738be1 Hubs: fix yum repos in playbook 2018-02-19 10:02:29 +00:00
clime
ffa7e30e2e Revert "copr-backend: install python3-novaclient in 3.3. version from Koji"
That version of python3-novaclient depends on python3.5 which is not available
on f27.

This reverts commit d19485a9e8.
2018-02-18 14:10:27 +01:00
clime
d19485a9e8 copr-backend: install python3-novaclient in 3.3. version from Koji 2018-02-18 14:06:35 +01:00
Patrick Uiterwijk
4f603b63ff By default, people are a guest
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-17 13:57:17 +00:00
Kevin Fenzi
2e2be41ceb Move pagure01 to osuosl03 and double cpus and memory. 2018-02-17 04:48:43 +00:00
Kevin Fenzi
3dd177029e adjust epylog weeding 2018-02-17 04:00:20 +00:00
Stephen Smoogen
318e7d03fd all for the want of a } 2018-02-17 00:57:24 +00:00
Kevin Fenzi
de89c4f9c4 add some draining to mirrorlist containers 2018-02-17 00:08:05 +00:00
Kevin Fenzi
252126c28d add bugurl default to koji builders 2018-02-16 23:08:05 +00:00
Kevin Fenzi
7407e99a93 drop retrace01.stg in favor of using retrace02 as staging 2018-02-16 22:42:52 +00:00
Kevin Fenzi
b8fab4e7c2 try and run both docker mirrorlist containers most of the time, see if it helps with heavily loaded mirrorlists 2018-02-16 22:21:25 +00:00
Kevin Fenzi
1ab575069f add osbs sudoers for osbs nodes. This is a superset with the old releng one + sysadmin-osbs only for these nodes 2018-02-16 21:56:08 +00:00
Giulia Naponiello
16d1924eda Merge branch 'master' of /git/ansible 2018-02-16 18:55:58 +00:00
Sayan Chowdhury
b0e1198a7c fedimg: Use the package name python2-fedimg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-16 18:55:37 +00:00
Giulia Naponiello
23a7e7dc30 Merge branch 'master' of /git/ansible 2018-02-16 18:55:11 +00:00
Giulia Naponiello
d2be676be3 greenwave 0.6.0 for staging for now 2018-02-16 18:50:58 +00:00
Kevin Fenzi
29dbecbd01 disable and enable require the backend name 2018-02-16 18:27:39 +00:00
Kamil Páral
ef740c2147 fix typo in taskotron DBs and testdays configs 2018-02-16 16:55:10 +01:00
Pierre-Yves Chibon
2340924394 Create the basic structure for hubs 2018-02-16 15:05:08 +01:00
Patrick Uiterwijk
cb56517d44 s/djang/django/
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:51:32 +00:00
Patrick Uiterwijk
69cffcc8c9 true is special and must be escaped
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:37:05 +00:00
Patrick Uiterwijk
8ca6a2453f Update pip due to bug in building cryptography
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:32:40 +00:00
Patrick Uiterwijk
52a5988a71 Add blank oidc secret for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:28:40 +00:00
Patrick Uiterwijk
75b913c96c Different name
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:27:19 +00:00
Patrick Uiterwijk
9247b47176 Define the from image in buildconfig
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:26:07 +00:00
Patrick Uiterwijk
ec3a9f5ff4 Add db host and user
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-16 13:22:15 +01:00
Patrick Uiterwijk
fb1b32c6ed Add initial transtats playbook et al
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:16:49 +00:00
Patrick Uiterwijk
55bb54f122 Allow unauthenticated nagios read access
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-16 12:16:49 +00:00
Sayan Chowdhury
5c94580223 fedimg: Don't pull from main repo in stg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-16 12:07:26 +00:00
Sayan Chowdhury
f8e520e736 fedimg: Fix the typo in the installation task
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-16 11:47:28 +00:00
Clement Verna
dc2af9f8b0 Add cverna to nagios access
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-16 11:50:13 +01:00
Sayan Chowdhury
493e28c61e fedimg: Add testing vars to fedimg-stg
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-16 09:45:20 +00:00
Sayan Chowdhury
1b286043bf fedimg: Compress the multiple tasks into one
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
2018-02-16 08:46:38 +00:00
Kevin Fenzi
e43c8b50d1 stop bodhi-check-policies cron job from sending out No handlers could be found for logger bodhi.server emails all the time 2018-02-15 20:16:42 +00:00
Kevin Fenzi
bfb9d492b0 do not need to compose this anymore 2018-02-15 18:27:31 +00:00
Mikolaj Izdebski
04aebd9fc0 Staging apps in OpenShift are not frozen 2018-02-15 13:10:25 +00:00
Clement Verna
d434a4c8d2 Make we reindex the database and fix the file recurse param
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-15 10:54:59 +01:00
Clement Verna
1fb1628608 Drop async command from playbook
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-15 10:47:20 +01:00
Clement Verna
a3aa09430c Use stg mdapi and tagger during stg indexing
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-15 08:42:03 +01:00
Kevin Fenzi
b52aeaa952 direct retrace.stg to retrace02 per request in staging 2018-02-14 19:43:00 +00:00
Clement Verna
b8100fc5ff Fix packages stg bugzilla.
This commit add the correct bugzilla address for
packages.stg.
It also cleanup the template by making use of
the env_suffix variable.

Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-14 19:43:45 +01:00
Clement Verna
70343cf977 Fix syntax error in playbooks/manual/rebuild/fedora-packages.yml
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-14 14:55:34 +01:00
Clement Verna
9a8a06d28b Update the command use to rebuild xapian db
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-14 13:40:39 +01:00
Clement Verna
a4b3eee7e6 Cleanup the packages03 role
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-14 10:05:22 +01:00
Clement Verna
8c6165ecbb Replace yum by dnf since packages now runs on Fedora
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-14 10:04:32 +01:00
Clement Verna
5885e444be Set the correct selinux context to allow httpd to clone git repos
Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-13 20:32:22 +01:00
Kevin Fenzi
7cf8d4f451 add sysadmin-osbs to the various osbs groups 2018-02-13 18:20:35 +00:00
Mikolaj Izdebski
23e624fe20 Koschei-web is now running on Fedora, not EPEL 2018-02-13 16:44:17 +00:00
Patrick Uiterwijk
d15072a4e6 Make pagure01 skip the proxy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-13 15:47:25 +00:00
Mikolaj Izdebski
734e9939a4 Install Copr-dev credentials for Koschei 2018-02-13 11:12:31 +00:00
Clement Verna
d80ead8087 Allow httpd to write the git repo used by the source tab
The Source tab is using git repository that are cloned under
/var/cache/fedoracommunity/git.fp.o.
This commit allow httpd to access this folder.

Signed-off-by: Clement Verna <cverna@tutanota.com>
2018-02-13 10:45:55 +00:00
Kevin Fenzi
de71bacf72 add in missing ,s 2018-02-13 03:42:37 +00:00
Lee Keitel
40879a4fa8 Fixed rabbitmq Nagios service checks for FMN 2018-02-13 02:45:45 +00:00
Dusty Mabe
86d5272115 fix typo
In 00f727dbaf I had a syntax error.
2018-02-12 13:46:00 -05:00
Kevin Fenzi
30594ba5d1 these lists need to be defined apparently 2018-02-12 18:31:21 +00:00
Randy Barlow
ff890ad085 Add new waiverdb settings to Bodhi's config.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-12 16:31:31 +00:00
Patrick Uiterwijk
d56a613b5d Remove stray characters
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-12 15:26:13 +01:00
Patrick Uiterwijk
f73b9f8934 Open firewall port to pagure proxy
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-12 15:21:34 +01:00
Mikolaj Izdebski
5c4f49ade3 Staging hosts should use staging fedmsg CA (#6621) 2018-02-12 13:53:13 +00:00
Mikolaj Izdebski
e35814f140 Add mizdebsk to all cloud tenants 2018-02-12 11:49:41 +00:00
Mikolaj Izdebski
40df3ce04a Open web ports on commops.fedorainfracloud.org, #6687 2018-02-12 11:06:21 +00:00
Qixiang Wan
a4096ccd0d freshmaker: add MBS urls in app config 2018-02-11 16:55:41 +08:00
Qixiang Wan
e5a9e25aa2 freshmaker: whitelist testmodule on stage 2018-02-11 16:40:05 +08:00
Qixiang Wan
f20559c617 freshmaker: remove the temporary task
Seems nothing wrong with app config, revert the slurp task, and
remove 'org.fedoraproject.prod' from message topic prefix on stage that
was added for troubleshooting too.
2018-02-11 15:07:26 +08:00
Qixiang Wan
a1175e60a7 freshmaker: show app config on stage for temp troubleshooting
Seems the parsers on stage are not enabled successfully, show app config
file content for troubleshooting, remove this later.

And a minor var change to restart fedmsg-hub.
2018-02-11 14:13:22 +08:00
Qixiang Wan
f8017a26cf freshmaker: restart fedmsg-hub daemon
'restart fedmsg-hub' handler from restart_services doesn't work, use our
own handler before that fix that one (it's used by many roles, I don't
want to break anything before confirm the issue). And update app config
(add prod fedmsg topic for stage to listen on) to notify the handler.
2018-02-11 10:05:50 +08:00
Patrick Uiterwijk
311a60d262 Revert "Enable h2 on pagure.io"
This reverts commit 173c68df67.
2018-02-10 21:42:16 +00:00
Patrick Uiterwijk
173c68df67 Enable h2 on pagure.io
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-10 21:27:14 +00:00
Patrick Uiterwijk
6e7e0bacc5 Pagure-proxy doees forwarding...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-10 21:21:02 +00:00
Patrick Uiterwijk
18f1320eb3 Support secondary IP
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-10 21:12:27 +00:00
Patrick Uiterwijk
5eecd68868 Enable ip_forward for proxy
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-10 22:05:34 +01:00
Patrick Uiterwijk
fd46e74adc Finish pagure-proxy nat rules
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-10 20:33:58 +00:00
Mikolaj Izdebski
1f694e6b5b Don't sync Koji buildroot listings in staging
buildroot_listing is by far the biggest table in koji db (>100 GB for
table data, plus indexes) and it's rarely used - skipping it saves us
some considerable amount of time.  If the table turns out to be
needed, the playbook can always be updated not to exclude it.
2018-02-10 03:29:50 +00:00
Mikolaj Izdebski
4891cfb03e Clean imageinfo listings during Koji staging sync 2018-02-10 03:14:01 +00:00
Mikolaj Izdebski
861c36103d Remove ralph and puiterwijk from list of stg-only Koji admins
Lets not try to grant admin perm to users that already have it, or
we'd get duplicate constraint violation errors.
2018-02-10 03:06:21 +00:00
Mikolaj Izdebski
cda638a3fe Koji staging sync: remove hosts from DB prior to adding them
Some staging hosts already exist in production Koji (they were added
by mistake?), either as hosts or pure users, but can be removed.
2018-02-10 03:06:20 +00:00
Mikolaj Izdebski
7eaec29885 Update koji-reset-staging.sql to recent Koji schema 2018-02-10 03:06:20 +00:00
Dusty Mabe
00f727dbaf atomic host life support for f26
Sync out the stable ref too, which is just aliased to
the updates ref at this point.
2018-02-09 17:29:23 -05:00
Randy Barlow
39fb321ecd Add the staging alt_master_repomd settings.
Also, rearrange the settings to correspond to their blocks for
primary and alt arches.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-09 18:39:19 +00:00
Randy Barlow
d65b46a209 Redefine master_repomd settings that don't have defaults.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-09 17:39:36 +00:00
Ralph Bean
db817ee0f3 Typofix. 2018-02-09 16:34:09 +00:00
Ralph Bean
86c78df3f9 Try to fix freshmaker server_name handling. 2018-02-09 16:29:50 +00:00
Ralph Bean
ab1f81b0ce Just set inventory_hostname to freshmaker_servername for now. 2018-02-09 16:29:45 +00:00
Patrick Uiterwijk
24dbc5cf4d Open port 80/443 on pkgs01.stg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-09 15:13:53 +00:00
Randy Barlow
d5bab6cc8a Correct the CORS setting for staging Bodhi.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-02-09 13:23:10 +00:00
Michael Simacek
6995f01232 Increase koschei pagure cache expiration time 2018-02-09 12:58:55 +01:00
Michael Simacek
45fde4032d Disable distributed memcached lock on koschei.
It seems to deadlock for some reason and is not really needed.
2018-02-09 12:52:12 +01:00
Michael Simacek
e66501a312 Revert "Disable koschei pagure plugin until I figure out why it segfaults"
It was selinux vs dogpile.cache.

This reverts commit ef6f884a0a.
2018-02-09 12:44:39 +01:00
Michael Simacek
05ad37b3f8 Set httpd_execmem sebool on koschei-web 2018-02-09 12:42:38 +01:00
Michael Simacek
ef6f884a0a Disable koschei pagure plugin until I figure out why it segfaults 2018-02-09 10:59:20 +01:00
Qixiang Wan
22930dead9 freshmaker: enable debug log level on stage 2018-02-09 17:49:07 +08:00
Qixiang Wan
f97e5bc371 freshmaker: enable git parser and module build handlers on stage 2018-02-09 15:52:49 +08:00
Qixiang Wan
a2a2d89718 freshmaker: add vars for mbs auth token 2018-02-09 14:54:12 +08:00
Patrick Uiterwijk
31fe8d6bcb Open ports 80 and 443 to everyone
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 23:01:22 +00:00
Patrick Uiterwijk
4aa1c5bcc3 Block all but internal from pkgs.fp.o and set up robots.txt files
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 22:44:06 +00:00
Kevin Fenzi
cd65be2774 fix conditional 2018-02-08 21:47:19 +00:00
Kevin Fenzi
595a2c40ad changes to get a working bodhi config. Cannot list mounts that the frontend doesnt have and also need to specify the dogpile cache file as it is different than default 2018-02-08 21:33:56 +00:00
Kevin Fenzi
56e9dd9dee fix conditionals 2018-02-08 20:36:36 +00:00
Kevin Fenzi
f75c4dfc55 Merge bodhi production.ini and staging.ini with the shipped version from the upstream rpm. 2018-02-08 20:25:32 +00:00
Adam Williamson
78a7f59ae0 Bump openQA asset size limits for staging
This is due to an upstream change in how the asset reduction
logic works: it now includes 'fixed' assets in the total size
calculation, so we should include the size of those assets
(which is currently ~110GB) in our limits. This is only on stg
for now as only stg has been updated to the new upstream code.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-02-08 10:41:29 -08:00
František Zatloukal
4936b644e9 Taskotron: correct location of imagefactoryd.service 2018-02-08 17:01:00 +01:00
Patrick Uiterwijk
da7f7f89eb Commit to our changes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:39:49 +00:00
Patrick Uiterwijk
ce78bf8497 Nat table has different entries
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:38:58 +00:00
Patrick Uiterwijk
0bfb2a2d1f nat_rules go into the nat table
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:37:20 +00:00
Patrick Uiterwijk
645654e584 Add empty nat rules
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:35:49 +00:00
Patrick Uiterwijk
a4f04d53f9 -t nat not needed
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:32:55 +00:00
Patrick Uiterwijk
40fbf2d575 Do not remove all whitespace
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:31:24 +00:00
Patrick Uiterwijk
d5ce7a014e Add nat-rules
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:30:13 +00:00
František Zatloukal
ace5dbaa17 Taskotron: Properly fix imagefactory service
Workaround for https://github.com/redhat-imaging/imagefactory/issues/417
2018-02-08 16:23:50 +01:00
Patrick Uiterwijk
da39a96667 Temporarily override cpu model for virtinstall
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:22:04 +00:00
Patrick Uiterwijk
7a058ec0ba Fix up pagure-proxy01 gateway
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 15:00:55 +00:00
Patrick Uiterwijk
1af277590e Virt-install the correct box
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 14:54:37 +00:00
Patrick Uiterwijk
a5a51cadc5 Add playbook for pagure-proxy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 14:53:09 +00:00
Patrick Uiterwijk
557f79da69 Add basis for pagure-proxy01
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-08 14:51:43 +00:00
František Zatloukal
c1ab76cef4 Taskotron: patch imagefactoryd service file so it can be enabled on boot 2018-02-08 13:57:19 +01:00
Mikolaj Izdebski
833d9e9bab Increase memory and disk size on Koschei web prod 2018-02-08 12:41:41 +00:00
Michael Simacek
9397a3579f Disable koschei logging mail handler 2018-02-08 13:22:52 +01:00
Mikolaj Izdebski
da2e9766d7 Make Koschei backend auth to Koji using GSSAPI 2018-02-08 12:01:09 +00:00
Mikolaj Izdebski
0eec23dcd8 Switch Koschei web auth to OpenIDC 2018-02-08 11:58:00 +00:00
Mikolaj Izdebski
d5db6392b4 Reinstall Koschei on Fedora 27 2018-02-08 11:57:38 +00:00
Mikolaj Izdebski
cc6ca2352a Switch SELinux on Koschei back to enforcing
Hopefully SELinux bug workaround shouldn't be needed any longer.
2018-02-08 11:56:42 +00:00
Patrick Uiterwijk
e4baec55e4 Blacklist username 'pagure'
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-08 00:34:02 +01:00
Stephen Smoogen
b2d8343b3f and the rhn files need to be added someday 2018-02-07 19:41:36 +00:00
Patrick Uiterwijk
b9b720043b Mark the username 'git' as blacklisted
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-07 20:12:22 +01:00
Patrick Uiterwijk
de9af8deda Add src.fp.o OIDC push OIDC scope
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-07 19:48:49 +01:00
Andrea Veri
3c27e5a250 GNOME Backups: live.g.o has been decomm and replaced by wiki.g.o 2018-02-07 14:31:49 +00:00
Miroslav Suchý
a554ac30fe retrace: update faf role 2018-02-07 14:31:53 +01:00
Miroslav Suchý
2a890f180b add retrace02.qa.fedoraproject.org host vars 2018-02-07 14:00:43 +01:00
Miroslav Suchý
138c94c891 do not sync f25 on retrace 2018-02-07 13:43:38 +01:00
Till Maas
8f7acb0dde Increase HSTS max age to one year
The HSTS preload list requires this now: https://hstspreload.org/
2018-02-07 12:42:36 +01:00
Qixiang Wan
7edc8430dc freshmaker: fix openidc userinfo uri in template 2018-02-07 12:52:25 +08:00
Qixiang Wan
808daa5377 freshmaker: create kerberos keytab on backend nodes 2018-02-07 12:14:28 +08:00
Kevin Fenzi
c8e5316fb7 adjust more 2018-02-07 01:32:17 +00:00
Kevin Fenzi
8a0c1f266f and setup check on mailman01 nrpe side 2018-02-07 01:24:52 +00:00
Kevin Fenzi
326c39d1b0 perhaps this? 2018-02-07 01:06:04 +00:00
Kevin Fenzi
dec23cd1bc try this 2018-02-07 00:31:15 +00:00
Kevin Fenzi
407efad1f7 and put it in the right place 2018-02-06 23:55:01 +00:00
Kevin Fenzi
68a56482fa need to add new file to the loop to actually install 2018-02-06 23:47:26 +00:00
Patrick Uiterwijk
4a6402394a Make releng-team able to use releng keytab
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-06 23:17:17 +00:00
Kevin Fenzi
3cea53b5b5 perhaps this needs quoted 2018-02-06 23:16:37 +00:00
Kevin Fenzi
1cb897a769 Clean up nagios client for old stuff that no longer matters.
Add a mailman api check. It gets a 401 now, but at least that tells us it's working.
2018-02-06 23:12:14 +00:00
Stephen Smoogen
4d411ec36d you must have a ; at the end of every line stupid 2018-02-06 19:30:26 +00:00
Stephen Smoogen
619dd465e4 and we try to make this work for the 10.5.129 2018-02-06 18:41:57 +00:00
Stephen Smoogen
ef09bafb79 oh did you remember the mac address? 2018-02-06 18:16:29 +00:00
Stephen Smoogen
81c5978890 try to make awstats file a bit more resilient 2018-02-06 16:42:36 +00:00
Tim Flink
7adc884a8e running backups for prod resultsdb db would be a good thing 2018-02-06 13:37:05 +00:00
Andrea Veri
c5f1b83e49 GNOME Backups: puppet 2.0 has been decommissioned, new master FQDN is puppetmaster01.gnome.org 2018-02-06 10:17:22 +00:00
Patrick Uiterwijk
a9fe75e330 Instead of mailing, log to syslog
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-02-06 01:32:29 +01:00
Kevin Fenzi
d70b3eb3b4 move to f27 mirrorlist container, will roll out slowly 2018-02-05 19:25:20 +00:00
Patrick Uiterwijk
321ad82c19 Unblock pkgs and do redirect instead
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-05 13:17:54 +00:00
Andrea Veri
f220d38189 GNOME Backups: s/bugzilla-new/bugzilla/ 2018-02-05 11:06:30 +00:00
František Zatloukal
5de10318d3 Taskotron: Enable task python-versions on dev
Ansiblized version of python-versions is ready!
2018-02-05 10:35:47 +01:00
Stephen Smoogen
b93bd375fb ok let us try to cut down http access ot the server from whatever backdoor is letting it in 2018-02-02 23:21:46 +00:00
Ralph Bean
a907fb6d56 Use wsgi_procs and wsgi_threads for freshmaker apache config. 2018-02-02 17:18:57 +00:00
Ralph Bean
b2655e43b0 Freshmaker config should be owned by the fedmsg user. 2018-02-02 17:17:02 +00:00
Ralph Bean
193971bcf0 Enable freshmaker OIDC scopes in prod ipsilon. 2018-02-02 17:10:21 +00:00
Ralph Bean
ef89fb2cbb Use the correct scope name. 2018-02-02 17:08:21 +00:00
Ralph Bean
3b21215d4d Add OIDC scope for freshmaker (staging). 2018-02-02 17:04:05 +00:00
Ralph Bean
0da5d836e2 Fix redirect and servername issue in freshmaker role. 2018-02-02 15:29:50 +00:00
Ralph Bean
ead99e7441 Freshmaker should rely on tls termination at the proxy layer. 2018-02-02 15:29:50 +00:00
Aurélien Bompard
0a00c5a82c Hubs: fix syntax in the fedmsg conf file 2018-02-02 15:10:15 +00:00
Ralph Bean
42f2d39f92 Tag these roles, for convenience. 2018-02-02 15:01:57 +00:00
Ralph Bean
1d00065c41 Add httpd/website entry for freshmaker. 2018-02-02 14:59:27 +00:00
Ralph Bean
005cb81bd4 Add reverseproxy entry for freshmaker. 2018-02-02 14:59:27 +00:00
Ralph Bean
1b0742d155 Add freshmaker to haproxy. 2018-02-02 14:59:27 +00:00
Jan Kaluža
5caf19ea91 Default freshmaker_stg_oidc_client_id and freshmaker_stg_oidc_client_secret in defaults yaml to test role on staging 2018-02-02 13:02:02 +00:00
Jan Kaluža
ed5965b505 Default freshmaker_stg_oidc_client_id and freshmaker_stg_oidc_client_secret in defaults yaml to test role on staging 2018-02-02 12:54:35 +00:00
Patrick Uiterwijk
d1276cf303 Add registry tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-02 10:20:49 +00:00
Mikolaj Izdebski
87b919f769 Auto track rust-sig packages on Koschei 2018-02-02 10:08:26 +00:00
Patrick Uiterwijk
ad58850372 Add CentOS registry info
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-02 10:08:14 +00:00
Patrick Uiterwijk
ed66fe9f6d Update passwd for staging for new staging cert
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-02 09:50:56 +00:00
Kevin Fenzi
60bd571609 Add sysadmin-packages to packages 2018-02-01 23:07:58 +00:00
Kevin Fenzi
ea59d00bd7 Drop some old playbooks and hosts that no longer exist 2018-02-01 22:45:57 +00:00
Kevin Fenzi
7797abb629 This will not work here in a role mixed into tasks 2018-02-01 22:39:35 +00:00
Patrick Uiterwijk
e70400ae18 Deploy fedoradocsredirect to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-02-01 14:53:16 +00:00
František Zatloukal
4fd1ac5690 Taskotron: Disable task python-versions on dev
Ansiblized changes were reverted on develop for now.
2018-02-01 14:49:17 +01:00
František Zatloukal
ad4747d69e Taskotron: Ansiblized Tasks merged to develop 2018-02-01 13:35:59 +01:00
Andrea Veri
303b9bed28 GNOME backups: stop backing extensions.g.o up, rename ghispano to gnome-hispano 2018-02-01 12:18:41 +00:00
Aurélien Bompard
854892a33b Hubs: fix playbook after service rename 2018-02-01 09:39:50 +00:00
Aurélien Bompard
ee65d47e58 Hubs: update playbook to use RPM 2018-02-01 09:33:50 +00:00
Kevin Fenzi
9d1075e993 really it was a missing quote 2018-02-01 00:52:10 +00:00
Kevin Fenzi
859c75ba8d everyone loves parens 2018-02-01 00:49:27 +00:00
Kevin Fenzi
d3b961e767 simplify and comment on root pw setting 2018-02-01 00:31:55 +00:00
Ricky Elrod
6875a450b0 Make www.fp.o be an alias of fp.o instead of fp.c
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2018-01-31 23:52:11 +00:00
Stephen Smoogen
c68cb601bf add the httpd logs from download-ib 2018-01-31 21:30:54 +00:00
Patrick Uiterwijk
777b1ad676 Getting logs for the bodhi expire overrides might be useful
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-31 19:21:41 +00:00
Kamil Páral
d5c712d465 taskotron-client: add taskotron-ansiblize copr into minion_repos 2018-01-31 15:46:53 +01:00
Adam Williamson
38ed0ef84c Allow openQA staging to publish 'ci' fedmsgs
This is part of a Big Secret Red Hat Conspiracy. Look away now!
OK, we're working on a standardized messaging format for testing
related messages, and this is part of testing out how that looks
with a Fedora testing system. Won't go to prod till it's a bit
more locked in.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-01-31 00:17:59 +01:00
Andrea Veri
0a1fe3862f GNOME backups: s/choose/palette, combobox has been decommissioned 2018-01-30 19:31:48 +00:00
Andrea Veri
9fa7b8db9f chooser and combobox are being decommissioned 2018-01-30 14:45:19 +00:00
Kevin Fenzi
1cb7267a6a disable this for now 2018-01-29 17:27:02 +00:00
Kevin Fenzi
e7a8feb2d7 try this 2018-01-29 17:09:33 +00:00
Kevin Fenzi
750f0c7333 switch this to use package 2018-01-29 17:02:02 +00:00
Miroslav Suchý
b27f0508df retrace: do not block on long task 2018-01-29 14:57:11 +01:00
Miroslav Suchý
479a0aedca retrace: remove f25 2018-01-29 14:26:33 +01:00
Qixiang Wan
ffa7656480 freshmaker: add freshmaker playbook and roles 2018-01-29 20:38:02 +08:00
Adam Williamson
69ed1bb554 openqa: disable createhdds cron jobs (#1539330)
Yeah, daily crashes are bad.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2018-01-28 01:08:44 +01:00
Mikolaj Izdebski
571ca7275a Second try on fixing cron-refresh-groups on koschei-backend 2018-01-27 15:01:13 +00:00
Mikolaj Izdebski
53d318abc2 Fix cron-refresh-groups on koschei-backend 2018-01-27 14:15:03 +00:00
Ralph Bean
4d8ad20419 This script seems to be working now. 2018-01-27 08:53:37 +00:00
Ralph Bean
7b3eeba89b Ramp this down to see if we can keep out of swap. 2018-01-27 08:51:38 +00:00
Kamil Páral
ce5c96c094 taskotron-client: sync taskotron.yaml.j2 with latest upstream content 2018-01-26 16:48:10 +01:00
Kevin Fenzi
9cfe2d113b add python26 and python35 on jenkins f26 worker 2018-01-26 13:14:30 +00:00
Kevin Fenzi
0126a1272b add birthdays to virthosts 2018-01-25 14:57:48 +00:00
Kevin Fenzi
8cd7d733fb switch this location 2018-01-25 13:29:34 +00:00
Patrick Uiterwijk
e342afe8d3 Deploy the registry multi-tenant in staging
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-24 22:29:37 +01:00
Aurélien Bompard
2bb12e25e6 Hubs: fix playbook strikes back 2018-01-24 21:16:53 +00:00
Patrick Uiterwijk
445d4f0919 Move
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-24 22:05:15 +01:00
Aurélien Bompard
f1ef844715 Hubs: fix playbook 5: legacy 2018-01-24 21:04:45 +00:00
Patrick Uiterwijk
1a0590e5fd Add multitenancy to staging registry
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-24 21:53:27 +01:00
Aurélien Bompard
bb11108fe8 Hubs: fix playbook 4, the mission 2018-01-24 20:50:38 +00:00
Aurélien Bompard
cf69510ab9 Hubs: fix playbook 3, the revenge 2018-01-24 20:42:56 +00:00
Aurélien Bompard
b05b9bcb80 Hubs: fix playbook again 2018-01-24 20:38:18 +00:00
Aurélien Bompard
e27614fde6 Hubs: fix playbook 2018-01-24 20:31:48 +00:00
Aurélien Bompard
70be01e16c Hubs: fix even moooore python3 deps 2018-01-24 16:43:01 +00:00
Kamil Páral
e8bab5cba6 taskotron-buildmaster: use lazylogfiles 2018-01-24 17:41:57 +01:00
Aurélien Bompard
134c02a499 Hubs: actually use the local fedmsg-relay (python2) 2018-01-24 16:25:20 +00:00
Aurélien Bompard
7e5db19f66 Hubs: fix even more python3 deps 2018-01-24 16:15:37 +00:00
Aurélien Bompard
4a2901f8d9 Hubs: fix more python3 deps 2018-01-24 16:13:47 +00:00
Kevin Fenzi
c032c55921 Drop dynamic range and just update carts mac addrs 2018-01-24 16:11:27 +00:00
Aurélien Bompard
555b49499e Hubs: require twisted 2018-01-24 16:10:56 +00:00
Aurélien Bompard
fdef430f4e Hubs: don't rely on become being set globally 2018-01-24 16:03:37 +00:00
Kevin Fenzi
c4ac385638 add some dynamic ips for moonshot in the 129 net 2018-01-24 15:56:27 +00:00
Aurélien Bompard
400fd88e13 Hubs: fix playbook 2018-01-24 15:27:48 +00:00
Kamil Páral
45d373507c taskotron-buildmaster: improve path for heartbeat.log
It's now placed in artifacts dir root instead of per-playbook artifacts
dir.
2018-01-24 15:22:37 +01:00
Aurélien Bompard
c89d481d51 Hubs: update the playbook 2018-01-24 13:28:08 +00:00
Kamil Páral
8f2dd30ae2 taskotron-buildmaster: send TERM signal before KILL
Also follow heartbeat.log.
2018-01-24 13:36:39 +01:00
Miroslav Suchý
858fcf681b copr-be-dev-data volume is back again, so we can mount it 2018-01-24 10:06:34 +01:00
Ralph Bean
e7accbe066 Move this to the right place in the file. 2018-01-24 08:53:02 +00:00
Ralph Bean
09f15fbc78 Greenwave should require nothing for EPEL. 2018-01-24 08:40:17 +00:00
Patrick Uiterwijk
baa418b692 Only add pkg on staging for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-24 06:20:08 +00:00
Patrick Uiterwijk
87b84c41ca Deploy fedoradocsredirect in staging mediawiki
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-24 06:03:36 +00:00
Ralph Bean
465f155d14 Remove the abicheck from greenwave's policy. We have some test run issues to sort out first. 2018-01-23 17:16:34 +00:00
Ralph Bean
2ee431319b Add epel releases to the greenwave policy. 2018-01-23 17:08:17 +00:00
Sayan Chowdhury
50e65f4d47 Update the edit-badge script to edit the badge tags 2018-01-23 13:18:28 +00:00
Filip Valder
cf6dc8a348 mbs: change REBUILD_STRATEGY from the default 'changed-and-after' to 'only-changed' 2018-01-22 14:23:34 +00:00
clime
ead8042cfd copr-frontend: requiring certain versions of a package should be in copr-frontend.spec 2018-01-20 19:13:01 +01:00
clime
8c816c031e copr-frontend: reeanble alembic upgrade head 2018-01-20 18:55:18 +01:00
Patrick Uiterwijk
ab455cd57d Remove proxy07 from inventory for now so it doesn't get tkey
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-19 23:40:09 +00:00
Kevin Fenzi
0b138f9111 add mdapi and greenwave monitoring. tickets 6639 and 6643 2018-01-19 21:32:19 +00:00
Kevin Fenzi
d96ccc806d add libkcapi to increase a kernel limit on arm builders. Ticket 6636 2018-01-19 21:06:53 +00:00
Dan Callaghan
b53181dce9 greenwave: use 8 gunicorn workers instead of the default 1
Trying to avoid Openshift killing the Greenwave pods because of the
liveness check timing out, if it gets stuck behind other slow HTTP
requests.

https://pagure.io/greenwave/issue/116
2018-01-20 01:59:54 +10:00
Todd Zullinger
476ca97e74 git (post-receive-alternativearch): use unicode for git output
The commit message and diff is stored in `full_change` as a string, via
`read_output()`.  This is passed to `TEXT` which is a unicode string.

When a commit message or diff contains non-ascii characters we get:

    UnicodeDecodeError: 'ascii' codec can't decode byte ...

Encode git output returned from `read_output()` as a unicode string and
define `full_change` as unicode for completeness.

Fixes #6040.
2018-01-19 16:40:08 +01:00
Jan Kaluža
f388a20a82 Merge branch 'master' of /git/ansible 2018-01-19 13:48:36 +00:00
Jan Kaluža
357d6b69d1 Set proper translate_paths for ODCS according to env. 2018-01-19 13:48:31 +00:00
Kamil Páral
35bb27240e taskotron-trigger: make rules more readable
But expanding the structured fields.
2018-01-19 14:32:10 +01:00
Jan Kaluža
0433a955da Allow sgallagh to generate ODCS composes to test modules. 2018-01-19 13:30:30 +00:00
Jan Kaluža
f5c4fe4874 Merge branch 'master' of /git/ansible 2018-01-19 13:05:53 +00:00
Jan Kaluža
55e65fbbaf Set runroot to False when config.bootable is False 2018-01-19 13:05:49 +00:00
Patrick Uiterwijk
b3df9abc8a Remove eth1 from odcs-backend01 for now. NFS will go over main if
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-19 13:02:51 +00:00
Jan Kaluža
c2cd3ae32b Enable runroot only when config.bootable is set 2018-01-19 12:33:53 +00:00
Jan Kaluža
a5e44f3c22 Merge branch 'master' of /git/ansible 2018-01-19 10:20:21 +00:00
Jan Kaluža
64ccbfe3de Fix typo in raw_config_wrapper.conf 2018-01-19 10:20:18 +00:00
Kamil Páral
a4b9280479 taskotron-trigger: merge trigger rules 2018-01-19 10:21:37 +01:00
Jan Kaluža
db9301cf93 Allow only x86_64 architectures on ODCS staging 2018-01-19 06:51:55 +00:00
Jeremy Cline
12a1603323 Add a fedmsg consumer for release-monitoring.org
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-18 17:55:40 +00:00
Randy Barlow
3a78f3deeb Enable Bodhi's test gating based on Greenwave decisions.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-01-18 16:09:34 +00:00
Randy Barlow
e561d139e6 Run bodhi-check-policies on backend02 for production.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-01-18 16:08:57 +00:00
Randy Barlow
c9aa542567 Run bodhi-check-policies on production.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-01-18 16:01:56 +00:00
Patrick Uiterwijk
52c1c426c6 Bodhi 3.2.0 is GO
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-18 15:55:34 +00:00
Kamil Páral
d5cc71560b buildmaster-configure: fix gzipping artifacts
Used to fail for symlinks.
See https://pagure.io/taskotron/issue/247
2018-01-18 16:30:55 +01:00
Giulia Naponiello
498863ccc3 Fixing incorrect variable name 2018-01-18 15:14:56 +00:00
Kamil Páral
aca5d8fac6 taskotron-dev: enable task-mtf-containers
It has been ansiblized.
2018-01-18 15:13:59 +01:00
Jan Kaluža
0e252bcc54 Use symlink link_type for ODCS in staging 2018-01-18 11:55:26 +00:00
Jan Kaluža
4239068ed6 Prefix ODCS KRB_* options with KOJI_ to match new odcs version. 2018-01-18 07:58:38 +00:00
Jan Kaluža
6ecba72fc7 Fix typo in raw_config_wrapper template 2018-01-18 07:14:04 +00:00
Jan Kaluža
b9ee857349 Merge branch 'master' of /git/ansible 2018-01-18 07:03:05 +00:00
Jan Kaluža
d0ef82673f Add ODCS raw_config_wrapper and runroot_koji configs as ansible templates 2018-01-18 07:03:01 +00:00
Randy Barlow
318424e9e1 Configure Bodhi to use PDC for critpath pacakge determination.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-01-17 23:00:55 +00:00
Jeremy Cline
caff14cc9f Just publish through the public relay
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-17 20:53:31 +00:00
Jeremy Cline
25e2152f11 More configs to make fedmsg happy
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-17 20:30:27 +00:00
Jeremy Cline
7d003a81bc Add an empty endpoints dict because fedmsg
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-17 20:21:27 +00:00
Ralph Bean
a24287b5e3 bodhi@service is your True Name!
https://en.wikipedia.org/wiki/True_name#Folklore_and_Literature
2018-01-17 20:15:31 +00:00
Jeremy Cline
0af39d9314 Import socket in the fedmsg config
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-17 20:11:10 +00:00
Jeremy Cline
e912cac4b3 Set up librariesio2fedsmg publishing cert
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2018-01-17 20:02:07 +00:00
Ralph Bean
eb4c688d5e Set waiverdb SUPERUSERS in staging. 2018-01-17 19:22:33 +00:00
Ralph Bean
dc6bf5e0b4 Caching may be fine as long as forcePull works. 2018-01-17 19:04:09 +00:00
Ralph Bean
31893c1aba The source here is not an ImageStreamTag. 2018-01-17 19:01:02 +00:00
Ralph Bean
3281bb1110 Some more buildconfig options for waiverdb. 2018-01-17 18:53:33 +00:00
Patrick Uiterwijk
6b71348385 Add staging to runroot
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:51:19 +00:00
Patrick Uiterwijk
f7c777f20c Turns out we do actually want altarch on staging to do runroot
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:48:05 +00:00
Patrick Uiterwijk
bce67dcb91 Revert "Enable runroot on all stg buildvms"
This reverts commit 2703eb8a64.
2018-01-17 18:48:05 +00:00
Ralph Bean
cd0cd7fe5e puiterwijk gave us a workaround in 8dcf3d2faa 2018-01-17 18:45:08 +00:00
Patrick Uiterwijk
2703eb8a64 Enable runroot on all stg buildvms
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:44:24 +00:00
Ralph Bean
15a923f822 Initiate waiverdb build (from candidate-registry base image). 2018-01-17 18:44:20 +00:00
Ralph Bean
742a4043df Don't cache the waiverdb parent image. 2018-01-17 18:43:13 +00:00
Patrick Uiterwijk
3df76d9e22 Silly me
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:41:53 +00:00
Patrick Uiterwijk
dde1f23589 Mount nfs on all staging buildvms
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:41:00 +00:00
Patrick Uiterwijk
09284197a3 Prod koji must be mounted with nfsv3
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 18:39:26 +00:00
Patrick Uiterwijk
8dcf3d2faa If the secret already exists, don't crash
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-17 16:52:21 +00:00
Kamil Páral
17f8c88111 taskotron-dev: enable task-check_modulemd
It's been ansiblized.
2018-01-17 16:49:43 +01:00
Randy Barlow
0507611d4d Configure bodhi.stg to use PDC.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2018-01-17 14:22:06 +00:00
Jan Kaluža
e8ef32271c Set odcs_migrate_db to False in backend by default 2018-01-17 10:41:41 +00:00
Jan Kaluža
3070ad4a14 Install intltool in ODCS pungi runroot 2018-01-17 10:32:35 +00:00
Jan Kaluža
07d1963a18 Migrate the ODCS db on backend node. 2018-01-17 09:53:45 +00:00
Jan Kaluža
e2feacb1db Revert "Run odcs_migrate_db on every ODCS upgrade"
This reverts commit 1025ee6108.
2018-01-17 09:51:33 +00:00
Jan Kaluža
585dcc7b1e Revert "Revert "Add also jkaluza's pungi-fedora fork to be built on ODCS stg for testing.""
This reverts commit 4d0d6bb7e2.
2018-01-17 09:51:15 +00:00
Jan Kaluža
4d0d6bb7e2 Revert "Add also jkaluza's pungi-fedora fork to be built on ODCS stg for testing."
This reverts commit 580609cc79.
2018-01-17 09:40:54 +00:00
Jan Kaluža
1025ee6108 Run odcs_migrate_db on every ODCS upgrade 2018-01-17 09:30:17 +00:00
Jan Kaluža
580609cc79 Add also jkaluza's pungi-fedora fork to be built on ODCS stg for testing. 2018-01-17 07:22:09 +00:00
Jan Kaluža
69833d376e Add ODCS mboddu_pungi_fedora raw_config also to odcs frontend on staging. 2018-01-17 07:06:12 +00:00
Jan Kaluža
1a680ca7de Merge branch 'master' of /git/ansible 2018-01-17 06:58:21 +00:00
Jan Kaluža
594edb2037 Use inner runroot again in ODCS. Grant raw_config source_type to mohanboddu and kellin. 2018-01-17 06:58:17 +00:00
Patrick Uiterwijk
69ef6a8846 Revert "Also deploy certs for managing registry to prod"
This reverts commit 199de030b6.
2018-01-16 22:10:58 +00:00
Patrick Uiterwijk
5c7650801d Revert "Disable wiki Badges plugin for now due to performance reasons"
This reverts commit 50ec59b9b8.
2018-01-16 22:10:58 +00:00
Kevin Fenzi
ac01a47ba7 adjust twoweek composes 2018-01-16 21:54:16 +00:00
Kevin Fenzi
6811e48da3 Add buildvm-ppc64{le} 15-19 2018-01-16 20:26:49 +00:00
Kevin Fenzi
8f8772f1e0 Fix some more nfs ips 2018-01-16 20:10:27 +00:00
Kevin Fenzi
679f3f6fbe helps if you use a unique ip address instead of another ones 2018-01-16 19:59:39 +00:00
Kevin Fenzi
1868c0d751 ok, how about vnc? 2018-01-16 19:54:25 +00:00
Kevin Fenzi
f3331e8fd4 see if this gets us more info 2018-01-16 19:50:57 +00:00
Patrick Uiterwijk
50ec59b9b8 Disable wiki Badges plugin for now due to performance reasons
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-16 19:48:03 +00:00
Stephen Smoogen
96482b42dc another year, move the graphs up 2018-01-16 18:19:30 +00:00
Aurélien Bompard
2333f77787 Hubs: use the dummy FAS user 2018-01-16 16:27:56 +00:00
Kamil Páral
88db2b665a taskotron-dev: enable task-rpmdeplint
It's been ansiblized.
2018-01-16 14:59:36 +01:00
Jan Kaluža
91bc4a1876 Try running lorax in parent ODCS runroot for a test. 2018-01-16 13:01:27 +00:00
Jan Kaluža
db6bf44bfc Merge branch 'master' of /git/ansible 2018-01-16 10:23:48 +00:00
Jan Kaluža
e43b30b65c Set buildinstall_use_guestmount to False for ODCS stg 2018-01-16 10:23:42 +00:00
clime
d1e2eb6fcb copr-be: disable copr-prune-repo until prunerepo is tested properly on f27 2018-01-16 11:10:25 +01:00
Patrick Uiterwijk
5a474cba2e Let bodhi staging send messages
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-16 10:47:17 +01:00
clime
3461014f3c copr: update copr_backend_ips 2018-01-16 10:42:52 +01:00
clime
e638d191b6 copr-be: upgrade to f27 2018-01-16 10:10:12 +01:00
clime
a57f1b6ac5 copr-backend-stg: update ips 2018-01-16 02:31:01 +01:00
Kevin Fenzi
176c8e09e4 add a 14 of each kind 2018-01-16 01:17:08 +00:00
Kevin Fenzi
198ca55a6d move some more ppc64s around 2018-01-16 01:14:18 +00:00
Kevin Fenzi
293f255fc2 move around more ppc buildvms 2018-01-16 00:20:19 +00:00
Kevin Fenzi
7033f1e1b7 Revert "move 05 to the next virthost"
This reverts commit b095ece240.
2018-01-15 23:19:54 +00:00
Kevin Fenzi
b095ece240 move 05 to the next virthost 2018-01-15 22:56:12 +00:00
Kevin Fenzi
91561ec365 move to f27 and shave a bit of disk off to allow all to fit 2018-01-15 22:27:59 +00:00
Patrick Uiterwijk
084801fc55 Rather than hard sleep 45, use curl retry
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-15 22:24:03 +00:00
Kevin Fenzi
4567fd57b6 buildvm-ppc64le 01-05 to ppc8-01 too 2018-01-15 22:05:37 +00:00
Kevin Fenzi
e0cb07319c put buildvm-ppc64 01-05 on ppc8-01 2018-01-15 22:02:51 +00:00
clime
1591610513 copr-backend-stg: install python-novaclient-3.3.1-3.fc25 2018-01-15 22:17:09 +01:00
Jan Kaluža
344de0a896 Install kernel package in ODCS pungi master runroot 2018-01-15 19:20:12 +00:00
Jan Kaluža
eb6a021114 Merge branch 'master' of /git/ansible 2018-01-15 19:12:42 +00:00
Jan Kaluža
bebc6bd1c8 Remove symlink link_type 2018-01-15 19:12:37 +00:00
Tim Flink
44eed62fad using db-qa02.qa for public resultsdb dumps 2018-01-15 14:31:45 +00:00
Kevin Fenzi
8748b547a2 give buildvm-01.stg some more oomph 2018-01-14 20:51:06 +00:00
Kevin Fenzi
302cee73a9 8 cpus for proxy06 since the vh is so slow 2018-01-14 05:32:44 +00:00
Kevin Fenzi
e07dc6a07e db01 is now on virthost06 2018-01-14 05:31:04 +00:00
Kevin Fenzi
2938c39067 Drop mirrorlists from templates too 2018-01-14 05:02:15 +00:00
Patrick Uiterwijk
98a7ec292b Allow proxy07
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-13 20:28:28 +00:00
Kevin Fenzi
5da6f7f479 Fix up fedora repo files. 2018-01-13 20:20:36 +00:00
Kevin Fenzi
190a344f8e no longer try to sync to mirrorlist servers as they are gone 2018-01-13 17:02:16 +00:00
Patrick Uiterwijk
c18ea6b658 Allow mmfrontend-checkin to connect to VPN
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-13 13:59:53 +00:00
Aurélien Bompard
9ac07ad1b4 Hubs: fix some permissions 2018-01-13 11:20:07 +00:00
Aurélien Bompard
69175c9756 Hubs: add dep on MongoDB 2018-01-13 11:03:51 +00:00
Aurélien Bompard
d548b86bef Hubs: fix letsencrypt setup 2018-01-13 10:57:33 +00:00
Patrick Uiterwijk
8c05e1685b Extend proxytimeout for admin.fp.o for mirror checkins
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-13 10:45:17 +00:00
Patrick Uiterwijk
749cdd2b3f Cleanup uunused template
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-13 10:45:17 +00:00
Aurélien Bompard
33a47eb4a9 Fix Hubs SSL config for letsencrypt 2018-01-13 10:42:11 +00:00
Aurélien Bompard
b1d52167f4 Hubs: create letsencrypt certs 2018-01-13 10:33:09 +00:00
Aurélien Bompard
6086e4c18e Fix hubs-dev deployment 2018-01-13 10:33:08 +00:00
Stephen Smoogen
67c97cd08f we forgot to undefine one define 2018-01-12 21:57:14 +00:00
Patrick Uiterwijk
a89e7984fa Add quotes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 21:48:40 +00:00
Patrick Uiterwijk
2b879d49e6 tags
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 21:48:01 +00:00
Patrick Uiterwijk
f46144bd78 Add mirrorlist container selinux policy
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 21:47:07 +00:00
Patrick Uiterwijk
d3ea8120ee Add some more selinux policy to fi-nrpe
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 21:47:07 +00:00
Ralph Bean
1ddf40d19c Put freshmaker backendon virthost21. 2018-01-12 21:20:03 +00:00
Ralph Bean
07e961bb75 Freshmaker hosts. 2018-01-12 21:05:08 +00:00
Patrick Uiterwijk
2f48eb9293 Remove deleted box
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 20:59:22 +00:00
Patrick Uiterwijk
ca798ca07d Add check_mirrorlist_cache.cfg
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 20:44:44 +00:00
Patrick Uiterwijk
b58aec5fdb Perform mirrorlist cache check against proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-12 20:37:25 +00:00
Kevin Fenzi
1b1c9c4968 add back in containers 2018-01-12 20:05:41 +00:00
Kevin Fenzi
0d355478cc move this to f27 with all the other compose machines 2018-01-12 19:54:09 +00:00
Stephen Smoogen
3aafbd1307 remove mirrorlists from inventory 2018-01-12 19:53:59 +00:00
Stephen Smoogen
ece29a885c remove the mirrorlist2 items from haproxy 2018-01-12 19:38:51 +00:00
Kevin Fenzi
4bb54d7837 this will be f27 too 2018-01-12 18:57:38 +00:00
Stephen Smoogen
1fe837bbd4 add in a rule for the control 2018-01-12 18:15:49 +00:00
Ralph Bean
05d37919ce Back to yum, for pdc. 2018-01-12 16:43:35 +00:00
Ralph Bean
1c9c2b649b Set pdc-web01 to el7. 2018-01-12 15:49:01 +00:00
Kamil Páral
310fe97b1c taskotron-dev: enable python-versions task
It has been ansiblized.
2018-01-12 14:19:40 +01:00
Jan Kaluža
2a34aa7736 Merge branch 'master' of /git/ansible 2018-01-12 07:47:08 +00:00
Jan Kaluža
f5d64be174 Use link_type set to 'symlink' for ODCS testing 2018-01-12 07:47:00 +00:00
Kevin Fenzi
50be6a9b9c add some more weeding 2018-01-12 04:17:50 +00:00
Kevin Fenzi
adb8ed0ab8 Revert "try disabling memcached for a sec"
This reverts commit 149300192f.
2018-01-12 00:13:26 +00:00
Kevin Fenzi
149300192f try disabling memcached for a sec 2018-01-12 00:02:07 +00:00
Kevin Fenzi
b88a822e90 proxy07 is down, remove it from wiki squid servers. Also lower cache time from 5 days to 6 hours 2018-01-11 23:21:04 +00:00
clime
5e7cfaa163 copr-keygen-stg: fix bug in iptables rules 2018-01-12 00:09:31 +01:00
Patrick Uiterwijk
c2493bc677 Allow access to repos
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-11 23:05:01 +00:00
Patrick Uiterwijk
f94a5f94cd Also allow dns out
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-11 23:02:44 +00:00
Patrick Uiterwijk
cc859650e0 Move mm-frontend-checkin01 to vh06
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-11 22:36:11 +00:00
Patrick Uiterwijk
eb2fab3c6a Add iptables for mm-frontend-checkin01
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-11 22:36:11 +00:00
Kevin Fenzi
0be887c09a try and untangle the stg koji mount on bodhi-backend01 2018-01-11 22:12:07 +00:00
clime
66e1c84bd8 copr-builder: collect dnf logs for debugging 2018-01-11 22:46:54 +01:00
Patrick Uiterwijk
5bbafa3c1a Make vhost-info indicate insecure vhosts
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-11 21:45:25 +00:00
Tim Flink
313a61a0f2 more phab scrubbing, increasing disk size 2018-01-11 19:53:21 +00:00
Tim Flink
4f274c703f upgrading qa-prod to f27 2018-01-11 19:41:33 +00:00
Tim Flink
5c5c3c4e09 no longer using phabricator, removing role and references to it 2018-01-11 19:38:50 +00:00
Ralph Bean
6d4386647a Set pdc-web02 to el7. 2018-01-11 17:41:52 +00:00
Ralph Bean
2163bf9cdd Add nagios downtime to the destroyer of virt insts. 2018-01-11 17:41:04 +00:00
Ralph Bean
75030e7f19 bodhi:owner-sync-pagure - stop trying to contact arm and ppc kojis. 2018-01-11 17:01:30 +00:00
Kevin Fenzi
1bdcff0844 add some more weeding 2018-01-11 16:57:04 +00:00
Ralph Bean
8ad55ee238 Reverse, reverse!
Revert "Stike that. Reverse it."

This reverts commit 88994f2466.
2018-01-11 16:10:34 +00:00
Kamil Páral
b37d14503c taskotron-dev: enable task-abicheck (ansiblized) 2018-01-11 16:27:59 +01:00
Pierre-Yves Chibon
ced538034b Make the Atomic CI results be considered to push to testing
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-01-11 09:37:17 +01:00
Kevin Fenzi
aa042ad6ac Add handlers 2018-01-11 04:41:59 +00:00
Kevin Fenzi
a6bd79e364 Add handlers 2018-01-11 04:28:55 +00:00
Kevin Fenzi
88994f2466 Stike that. Reverse it.
Revert "try moving pdc-web01.stg back to el7"

This reverts commit 1497a92d2c.
2018-01-10 20:16:08 +00:00
Kevin Fenzi
e6971b3d19 switch this to use package instead of dnf 2018-01-10 19:20:56 +00:00
Tim Flink
d611fbf1a7 upgrading resultsdb01.qa to F27 2018-01-10 19:12:19 +00:00
Kevin Fenzi
1497a92d2c try moving pdc-web01.stg back to el7 2018-01-10 18:54:30 +00:00
Kevin Fenzi
3c1796f0fe drop f25 from this sync script 2018-01-10 17:13:24 +00:00
Jan Kaluža
fc9283b51d Revert 'Mount /etc/kojid/secrets/ in ODCS pungi parent runroot.' 2018-01-10 16:23:12 +00:00
Jan Kaluža
daf1bdd274 Merge branch 'master' of /git/ansible 2018-01-10 16:04:57 +00:00
Jan Kaluža
46f2376732 Mount /etc/kojid/secrets/ in ODCS pungi parent runroot. 2018-01-10 16:04:53 +00:00
Patrick Uiterwijk
e82dafaafd Mount kojid secrets by default in runroot
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-10 15:47:32 +00:00
Kamil Páral
7f76bc4cea taskotron-master: enable httpd_use_nfs even on dev
It's using NFS now as well.
2018-01-10 15:59:39 +01:00
Patrick Uiterwijk
16d7c30208 CPU host is no longer needed with new qemu-kvm
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-10 14:44:29 +00:00
Tim Flink
404980c319 fixing old selinux context setting 2018-01-10 01:35:06 +00:00
Tim Flink
4046affc69 removing old buildslave service stuff for taskotron prod 2018-01-10 01:15:28 +00:00
Tim Flink
7b111b6ab3 updating buildmaster pubkey for taskotron-prod-client-hosts 2018-01-09 23:57:43 +00:00
Tim Flink
99948b9d69 updating taskotron prod bits for redeployment 2018-01-09 22:48:10 +00:00
Patrick Uiterwijk
199de030b6 Also deploy certs for managing registry to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-09 12:13:57 +00:00
clime
f2ee5f642e copr-stg: update backend ips 2018-01-09 12:23:25 +01:00
clime
ae39b8778c copr-backend: try switching staging to f27 2018-01-09 11:49:50 +01:00
Jan Kaluža
dbfe9545eb Set runroot_tag and runroot_channel for ODCS. 2018-01-09 10:06:14 +00:00
Jan Kaluža
3418ad602a Merge branch 'master' of /git/ansible 2018-01-09 09:38:13 +00:00
Jan Kaluža
4c1816b12e Enable runroot in pungi.conf for ODCS. 2018-01-09 09:38:07 +00:00
clime
e015ecc604 copr-backend: switch to f26 on staging 2018-01-09 10:33:04 +01:00
Patrick Uiterwijk
a43aa24023 Add tag to fix
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-09 00:31:14 +01:00
Patrick Uiterwijk
f64ad48e6c Allow osbs to communicate with infra.fp.o
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-09 00:30:01 +01:00
Kevin Fenzi
22e593c0c5 move to pre_tasks for yum repos 2018-01-08 21:30:21 +00:00
Kevin Fenzi
c625021c45 only exclude modules in staging, they exist in prod 2018-01-08 20:41:15 +00:00
Kevin Fenzi
b750d1e773 Move pdc-web01.stg to f27. 2018-01-08 20:37:43 +00:00
Kevin Fenzi
6fee8fb738 adjust epylog weed rules. 2018-01-08 18:32:36 +00:00
clime
fbe7b42dba copr-backend: fixup for new builder images with mock-1.4.8 2018-01-08 16:58:24 +01:00
Kamil Páral
dc771f332f the sebool should have been in resultsdb-frontend
instead of taskotron-frontend
2018-01-08 16:57:15 +01:00
Kamil Páral
353a4867e5 taskotron-frontend: enable sebool httpd_can_network_connect
See https://pagure.io/taskotron/issue/246
2018-01-08 16:46:46 +01:00
clime
63f0120b0e copr-backend: only mount external disk on production, not on staging 2018-01-08 14:11:48 +01:00
clime
3b4fb50161 copr-builder: exclude infra mock => allow installing mock 1.4.8 from Fedora 2018-01-08 13:10:47 +01:00
Jan Kaluža
17171a9d0c Merge branch 'master' of /git/ansible 2018-01-08 07:52:47 +00:00
Jan Kaluža
92e3bd97f3 Update also pungi package when updating odcs. 2018-01-08 07:52:41 +00:00
Kevin Fenzi
c54b3f2082 put requireany inside 2.4 apache block 2018-01-08 00:55:47 +00:00
Kevin Fenzi
af8d89d205 bump to 4 2018-01-07 19:28:02 +00:00
Patrick Uiterwijk
f54e8493e7 Until signal processing gets fixed for mirrorlist, hack around it
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-06 00:51:57 +00:00
Kevin Fenzi
353cb995fa add timeout here 2018-01-05 21:54:55 +00:00
Patrick Uiterwijk
02087054e8 Use cpu=host for now. This limits live migration thus needs to be reconsidered later.
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 19:42:56 +00:00
Patrick Uiterwijk
e6df0ae97a Move to the openstack 10 repo
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-05 20:23:15 +01:00
Kevin Fenzi
cb228ec04e move autocloud-web to fedora 27 as well in prod 2018-01-05 18:52:36 +00:00
Tim Flink
6de46913f2 updating stg buildmaster host key 2018-01-05 17:06:53 +00:00
Tim Flink
5a9c6b883b updating buildslave home path for taskotron stg 2018-01-05 16:57:22 +00:00
Kamil Páral
2cff88a919 taskotron: one more buildslave service to disable PIDFile in 2018-01-05 16:00:21 +01:00
Kamil Páral
52f45933ee taskotron: fix wrong variable name 2018-01-05 15:54:29 +01:00
Kamil Páral
c8bd3d356e taskotron: use valid variable names 2018-01-05 15:48:13 +01:00
Patrick Uiterwijk
5f4ea314a0 Also disable h2 here
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 14:45:33 +00:00
Kamil Páral
925fc4277d taskotron: use tasks instead of handlers for buildmaster-configure
Because the meta keyword doesn't seem to work.
2018-01-05 15:42:19 +01:00
Patrick Uiterwijk
076286e4c4 Disable h2 for now due to ostree bugs. Re-enable 2018-01-19
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 14:39:40 +00:00
Kamil Páral
acb6babb45 taskotron: add restart buildmaster handler and fix buildslave services 2018-01-05 15:33:48 +01:00
Kamil Páral
54168ace6b taskotron: need to flush handlers immediately 2018-01-05 14:57:30 +01:00
Patrick Uiterwijk
2ea0e76545 Attempt ppc8-04
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 13:21:27 +00:00
clime
37f69d3950 copr-builder: use builder images with the latest kernel 2018-01-05 14:16:17 +01:00
Kamil Páral
08ff0eb0ed taskotron: reload systemd after creating buildmaster/slave service files 2018-01-05 14:14:16 +01:00
Patrick Uiterwijk
0dd454ae66 Move buildvm-ppc64-01.stg out of ppc8-02 to get it moving
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 13:11:16 +00:00
Pierre-Yves Chibon
2767cfd05b Looks like the pagure fedmsg hook is using the shell fedmsg cert
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-01-05 14:09:08 +01:00
Kamil Páral
b3f1ab6516 taskotron: disable PIDFile in buildmaster/buildslave.service
The services now don't start correctly when PIDFile is present.
See https://pagure.io/taskotron/issue/236
2018-01-05 14:02:37 +01:00
Patrick Uiterwijk
24d7d693c3 Only reboot running vms
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 12:25:32 +00:00
Jan Kaluža
c35de02e5e Disallow 'repo' source_type and enable 'module' source type 2018-01-05 11:51:19 +00:00
Jan Kaluža
25e41c0adc Prefix ODCS koji profiles with 'odcs_' 2018-01-05 11:37:17 +00:00
Patrick Uiterwijk
99e5c3a775 Fix indentation
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 09:55:52 +00:00
Patrick Uiterwijk
4763d25f0a Move the inner keytab stuff to the actual playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 09:55:15 +00:00
Patrick Uiterwijk
f56cb3e60a Rename the keytab and its service
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 09:51:17 +00:00
Patrick Uiterwijk
c05ef11ebd Allow the shared directory to be mounted
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-05 10:47:35 +01:00
Patrick Uiterwijk
cea3c93ff9 Attempt setup for shared secret keytab for odcs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-05 09:47:11 +00:00
Pierre-Yves Chibon
9eab06dcca Let's allow pagure's fedmsg hook on dist-git.stg as well
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-01-05 10:23:49 +01:00
Andrea Veri
e74db598e1 GNOME Backups: enable gitlab.gnome.org 2018-01-05 09:11:58 +00:00
Pierre-Yves Chibon
22b5207726 Enable the fedmsg hook from pagure on dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-01-05 10:06:14 +01:00
Patrick Uiterwijk
adc597d0ad Add some tags
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-04 22:56:23 +00:00
Patrick Uiterwijk
dcc55eed7c Move the rebuild stuff to production
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-04 23:53:38 +01:00
Kevin Fenzi
b4e4e417b4 move autocloud-web.stg to f27 2018-01-04 20:06:08 +00:00
Kevin Fenzi
64c2ef3ac6 move autocloud-backend01/02.stg to f27 2018-01-04 19:16:37 +00:00
clime
f825a4549e copr-frontend: prolong graceful restart period for wsgi daemons 2018-01-04 15:48:49 +01:00
Kevin Fenzi
ca02c9df17 no more digests services 2018-01-04 05:12:18 +00:00
Patrick Uiterwijk
fa1ae4a4b4 This should use become
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-04 04:05:21 +01:00
clime
7dc96d992a copr-frontend: set maximum-requests=8000 for each wsgi daemon process 2018-01-03 23:16:46 +01:00
Kevin Fenzi
fe80bed235 reorder these nfs clients 2018-01-03 21:55:50 +00:00
Kevin Fenzi
076bd1fd25 need repos first 2018-01-03 21:41:17 +00:00
Kevin Fenzi
13a1d15229 move bodhi in stg to f27 2018-01-03 21:01:39 +00:00
Patrick Uiterwijk
5a5dc9d9b0 Close down apache-status from the public
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-03 21:55:36 +01:00
Kevin Fenzi
22cd1bc504 add trailing / to planet.fedoraproject.org redirect. Should fix ticket 6607 2018-01-03 20:51:59 +00:00
Kevin Fenzi
fdee623cf8 mdapi to f27 2018-01-03 20:13:16 +00:00
Kevin Fenzi
a052e655b3 this is not really f27, but to help track things move it up 2018-01-03 19:45:22 +00:00
Patrick Uiterwijk
efd711ad97 This should have gone to production a while ago... Lets do so now
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-03 20:29:48 +01:00
Patrick Uiterwijk
2fe1b7a5c5 Fix typo (thanks Todd)
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-03 17:03:37 +01:00
Patrick Uiterwijk
073e963e3f Switch to using docker run --rm and stop
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-03 16:53:07 +01:00
clime
6122dd4901 copr-dist-git: create directory for custom SELinux policies 2018-01-03 14:18:43 +01:00
clime
c0631fed5d copr-dist-git: give map permission on git_user_content_t to cgit 2018-01-03 14:07:40 +01:00
Kevin Fenzi
54ca4ea95c remember to push change to f27 before pointlessly reinstalling as f25 2018-01-03 01:46:57 +00:00
Kevin Fenzi
66c93ef08a change order of nfs mounts 2018-01-03 01:26:08 +00:00
Kevin Fenzi
246da292b3 move yum repos to pre_tasks so we have them to install fas-clients 2018-01-03 01:20:31 +00:00
Kevin Fenzi
5dd45d0971 move kojipkgs01 to f27 2018-01-03 01:01:01 +00:00
Kevin Fenzi
de268e731b move mdapi stg over to f27 2018-01-02 23:32:49 +00:00
Patrick Uiterwijk
d2cb9a71e6 Prevent confusion by adding handlers
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-03 00:21:22 +01:00
Kevin Fenzi
09ec0145f7 Add host inv files and clean up some old ones. 2018-01-02 22:54:10 +00:00
Kevin Fenzi
da625a6f0b add in more aarch64 buildhw to primary 2018-01-02 22:42:25 +00:00
Paul W. Frields
e1a9c38a25 Add aws-fedoramirror FAS role mapping 2018-01-02 21:57:43 +00:00
Kevin Fenzi
1f8bbceaa7 drop buildppc64/buildppc64le/aarch64 secondary builders 2018-01-02 21:35:54 +00:00
Kevin Fenzi
6837a16455 eeeeeee. thanks tmz 2018-01-02 20:01:20 +00:00
Kevin Fenzi
a072eba8df make checkout-seed handle rpms namespace. someday should handle others 2018-01-02 19:52:09 +00:00
Kevin Fenzi
c3e500e5dc add f27 twisted buildbot instances 2018-01-02 18:21:09 +00:00
Patrick Uiterwijk
e6b71e250c Add f28-ruby
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-02 19:11:06 +01:00
Jeremy Cline
40879071bf Use Anitya's stage secret 2018-01-02 15:28:34 +00:00
Patrick Uiterwijk
45de9a7a66 Turns out that for coloamer, we use gdns
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-02 14:15:49 +01:00
Patrick Uiterwijk
194455471f proxy08 also needs 1*8gb
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-01-02 13:55:31 +01:00
Pierre-Yves Chibon
4b6c5733ed Specify the APP_URL in the hook's config file
Fixes https://pagure.io/fedora-infrastructure/issue/6596

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2018-01-02 09:43:38 +01:00
Patrick Uiterwijk
2948514084 Use the variable, not the string
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-02 02:14:00 +00:00
Patrick Uiterwijk
543acabdb1 Try to ensure that haproxy and varnish get started after VPN comes up on proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-02 02:11:43 +00:00
Patrick Uiterwijk
fe05fdcb83 Tummy01 does not even have 1*8gb
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-01 23:40:03 +00:00
Patrick Uiterwijk
9eaf9bd848 tummy01 also does not have 4*8gb mem
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2018-01-01 23:34:54 +00:00
Kevin Fenzi
c7d9226c9a aarch64-c17 is still slow for no reason, drop it for now 2017-12-31 23:03:11 +00:00
Kevin Fenzi
be241c71f1 adjust postgresql settings here 2017-12-31 21:02:37 +00:00
Kevin Fenzi
2b21f8992a try doing 3 pungi composes at once on bodhi-backend01 2017-12-31 18:49:03 +00:00
Kevin Fenzi
80faef200d move rawhide/branched composers to f27 2017-12-29 23:16:03 +00:00
Kevin Fenzi
28d64293c4 these do not need to be different 2017-12-28 21:56:36 +00:00
Kevin Fenzi
4ee2e234a7 switch aarch64 and armv7 buildvms to f27 2017-12-28 21:53:50 +00:00
Kevin Fenzi
2a4fc39c0b move buildvms to 27 2017-12-27 19:48:26 +00:00
Kevin Fenzi
1c7b0be223 we do not want output from nmcli here 2017-12-26 22:23:37 +00:00
Kevin Fenzi
89d7f0665d adjust fedora-commops fedmsgs 2017-12-26 21:22:34 +00:00
Kevin Fenzi
ba1e76b9b2 not 110, only 11 2017-12-26 21:08:40 +00:00
Kevin Fenzi
5d5c7e3ab9 add some tags 2017-12-26 21:06:48 +00:00
Kevin Fenzi
9d34078176 commit workaround for proxy11 in ansible 2017-12-26 21:04:33 +00:00
Patrick Uiterwijk
cc16ee5187 Fix the capitlization
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-24 20:36:27 +01:00
Kevin Fenzi
6104ad97ce move buildvm-armv7-02 and 03 to f27 2017-12-23 21:24:34 +00:00
Kevin Fenzi
5429c27278 switch buildvm-armv7-01 to f27 2017-12-23 20:20:29 +00:00
Kevin Fenzi
c6bc13809a do not care that a tmp dir does not exist in basessh 2017-12-23 20:09:26 +00:00
Kevin Fenzi
50fed999bd move fedmsg after releng so we have masher user 2017-12-23 20:01:33 +00:00
Kevin Fenzi
aca45f1b97 move composer.stg to f27 2017-12-23 19:20:20 +00:00
Kevin Fenzi
4c758db375 remove from here too 2017-12-23 18:23:16 +00:00
Kevin Fenzi
917eea8f7b drop f25 maintainer test instance, update ppc64* ones to f27 2017-12-23 18:18:48 +00:00
Patrick Uiterwijk
ba4bccf109 Allow httpd_execmem and nfs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 18:48:37 +00:00
Patrick Uiterwijk
cb8c7a63fc Not enough mem for standard 4*mem_size
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 18:40:25 +00:00
Patrick Uiterwijk
076db9c93c Reinstall packages04 as Fedora
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 18:38:50 +00:00
Patrick Uiterwijk
6d556e7c86 Add the fedmsg/base role
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 18:07:06 +00:00
Kevin Fenzi
747faacf4e Fix excluding agent sockets. 2017-12-22 17:14:58 +00:00
Patrick Uiterwijk
d40c83881f Give packages RW access to the fedora_app_packages volume
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 13:25:54 +00:00
Patrick Uiterwijk
5b2d454b40 Packages is no longer rhel6
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 13:08:06 +00:00
Patrick Uiterwijk
10241d4c2d Rebuild packages03 as f27
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 13:05:52 +00:00
Patrick Uiterwijk
a0ea57487e Revert splitting creates out. That was invalid
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 13:00:30 +00:00
Patrick Uiterwijk
884600f959 Mount fedora_app_packages on packages prod boxes and get rid of gluster
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 12:58:11 +00:00
Patrick Uiterwijk
5f0b3fb7e1 Only do koji-mount related things if mounting /mnt/koji
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 12:55:41 +00:00
Adam Williamson
24c78b5f6d Disable eth1 on qa07 2017-12-21 17:20:35 -08:00
Patrick Uiterwijk
54399eb157 If I say disabled, do not enable
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 02:19:30 +01:00
Patrick Uiterwijk
4d7f15164c Allow interfaces to be marked as explicitly disabled
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 02:15:04 +01:00
Adam Williamson
3f284aed9e openqa/worker: run the ppc64 script hourly
The /dev/kvm permissions just seem to keep getting reset somehow
and I'm sick of it. Let's see if this helps.
2017-12-21 16:55:35 -08:00
Patrick Uiterwijk
c70c29df19 Split --debug into --verbose and --dry-run
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-22 01:35:36 +01:00
Patrick Uiterwijk
4762042663 Ignore unknown project namespaces for the bugzilla sync
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-21 21:24:26 +00:00
Kevin Fenzi
94e5f3f345 fix this for check mode 2017-12-21 21:10:07 +00:00
clime
a74ef55e4b copr-builder: enable nosync for ppc64le and ensure it is always latest nosync 2017-12-21 15:48:16 +01:00
Clement Verna
6396276ec9 Add the destination for the icons during indexing
Signed-off-by: Clement Verna <cverna@tutanota.com>
2017-12-21 12:00:26 +01:00
Clement Verna
e22d3eb039 Cleanup packages httpd configuration file.
This commit remove the duplicated Directory configuration
and use apache 2.4 configuration syntax.

Signed-off-by: Clement Verna <cverna@tutanota.com>
2017-12-21 10:54:38 +01:00
Kevin Fenzi
5c4851f8f2 Fix handler name 2017-12-20 23:04:13 +00:00
Patrick Uiterwijk
ad4a96b03f Allow access to icons
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-20 23:00:59 +00:00
Stephen Smoogen
3ae360d866 ok let us try removing the rotatelogs altogether 2017-12-20 22:22:00 +00:00
Stephen Smoogen
02938f63ad we need to update this in 2 places and run it on logs and people 2017-12-20 21:37:46 +00:00
clime
53e86336fd copr-backend: upgrade to copr-backend-1.110 2017-12-20 20:33:19 +01:00
Stephen Smoogen
c8f6a9cb4b add in test for magazine and communityblog 2017-12-20 18:34:37 +00:00
Patrick Uiterwijk
a0c0e235c4 Add script_name for packages
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-20 17:40:53 +00:00
Pierre-Yves Chibon
fa0a6a8439 Add the tests namespace to dist-git
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-20 10:44:58 +01:00
Patrick Uiterwijk
988148e972 Update the filename of the termlist database
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-20 03:15:59 +00:00
Patrick Uiterwijk
6db05ccb51 Allow buildhw-aarch64* into the rhel repos
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-19 21:52:13 +00:00
Patrick Uiterwijk
d510cef413 Fix path to xapian db
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-19 18:19:39 +00:00
Tim Flink
898ce65380 updating stg buildmaster w/ new setup 2017-12-19 15:26:18 +00:00
Michael Simacek
db5fa411a0 Use mod_auth_openidc for koschei 2017-12-19 17:05:57 +02:00
Pierre-Yves Chibon
eb2848250b And again try indented
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-19 14:46:35 +01:00
Pierre-Yves Chibon
487d2d6625 Move back to include_tasks
Commit afef097a3d changed from include_tasks to import_tasks but running
this playbook we run into error:
1/ just running it we got:
  ERROR! 'import_tasks' is not a valid attribute for a Play
so we indented the line to put it in the task list, but that
lead to another error:
2/ exception: this task 'user' has extra params
So let's move back to include_tasks and see if that helps

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-19 14:42:58 +01:00
Pierre-Yves Chibon
eea3829754 Some more indentation
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-19 14:37:45 +01:00
clime
2ac87474cd copr-builder: install default.cfg for mock-1.3.4 that does not have it 2017-12-19 10:07:04 +01:00
Patrick Uiterwijk
f2f282bc1c Mash is no longer in use
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-19 00:07:10 +00:00
Patrick Uiterwijk
ade5cfb3c9 Delete the arm and ppc koji websites from proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-18 22:05:33 +00:00
Patrick Uiterwijk
a9bc117c3b Arm-koji01 is gone. Gone I tell you
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-18 21:42:06 +00:00
Patrick Uiterwijk
4e386a4eab Terminate arm and ppc secondary koji instances
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-18 21:19:38 +00:00
clime
a2883ab54d copr-builder: disable nosync on ppc64le
- hotfix for building in epel-7-ppc64le chroot
2017-12-18 21:04:19 +01:00
Tim Flink
a6dede2002 moving slavedir creation plays around to work with newer setup 2017-12-18 20:00:33 +00:00
Tim Flink
ee32e49728 upgrading taskotron-stg to f27 2017-12-18 19:52:20 +00:00
Jeremy Cline
8205d799af Incorrect selector for release-monitoring service 2017-12-18 18:33:49 +00:00
Jeremy Cline
253327d95b Remove the fedmsg service from release-monitoring 2017-12-18 18:12:19 +00:00
Jeremy Cline
32d4aec131 Maybe this makes the deploymentconfig valid? 2017-12-18 16:44:50 +00:00
Jeremy Cline
0b3c018fde Maybe this fixes the router for release-monitoring 2017-12-18 16:39:21 +00:00
Jeremy Cline
3d2f69a2b0 Adjust release-monitoring build 2017-12-18 16:19:37 +00:00
clime
ce25d68e5a copr: update IP of copr-keygen 2017-12-18 17:01:00 +01:00
Pierre-Yves Chibon
e7eb8bbddc Fix the bz url in stg vs prod 2017-12-18 15:44:22 +01:00
Pierre-Yves Chibon
325f083e56 Install python-celery on the el7 builder in jenkins for pagure
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-18 15:44:22 +01:00
clime
e8f6c7f76d copr-frontend: temporary hotfix - do not upgrade db to head 2017-12-18 14:41:16 +01:00
clime
1f23f09ac4 copr: upgrade keygen, copr-dist-git, and frontend to f27 2017-12-18 14:13:54 +01:00
clime
74cff261b6 copr-backend: install the latest copr-backend package from f26
...we can no longer build for f25
2017-12-18 13:34:25 +01:00
clime
d03a23530d copr-backend: update logrotate config for lighttpd 2017-12-18 13:02:40 +01:00
clime
18bf734ad0 fed-cloud09: add source of the provided Fedora-Cloud-Base-27-1.6.ppc64le image 2017-12-18 12:42:17 +01:00
clime
eb3d5983f8 copr-builder: fix ansible module name from copy to command 2017-12-18 10:30:45 +01:00
clime
b5e71ff3a6 copr-builder: do not disable @copr/copr (disabled in base image) and install nosync.i686 on intel 2017-12-18 10:21:37 +01:00
clime
73a3ec9f2e copr-backend: bump to f27 builder images 2017-12-18 10:12:11 +01:00
Kevin Fenzi
a891cf8b96 fix become 2017-12-16 23:39:31 +00:00
Kevin Fenzi
ab7f61840f only run this in prod 2017-12-16 23:35:32 +00:00
Kevin Fenzi
da87f26600 thats a - not a _ 2017-12-16 23:29:47 +00:00
Kevin Fenzi
ccd5225ba6 move quote 2017-12-16 23:19:16 +00:00
Kevin Fenzi
c1a72a16d8 lets see if this helps with new proxy deploys 2017-12-16 23:17:57 +00:00
Kevin Fenzi
9239431b43 drop duplicate when: 2017-12-16 21:51:19 +00:00
Ralph Bean
d75b0eba55 Don't create new bugzilla components for modules, yet. 2017-12-15 21:34:20 +00:00
Dennis Gilmore
3199c15328 remove no longer needed hotfix koji-gc
Signed-off-by: Dennis Gilmore <ausil@fedoraproject.org>
2017-12-15 21:24:55 +00:00
Mohan Boddu
1a20e6dd03 Adding F28 key to koji-gc
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-12-15 21:20:19 +00:00
Patrick Uiterwijk
bd77fcedf9 Set max_mem on proxy06
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-15 18:12:28 +00:00
Patrick Uiterwijk
b3ae5a8957 This is a 'create' on 'pods/attach', not 'attach' on 'pods'
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-15 17:15:23 +00:00
Jeremy Cline
e35676adbd Install fedmsg with dnf 2017-12-15 16:32:17 +00:00
Jeremy Cline
7bf4602009 Bump librariesio2fedmsg to f27 and install sse2fedmsg from git
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-15 16:13:16 +00:00
Patrick Uiterwijk
cf1d4d544b Add rudimentary vhost poweroff playbook
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-15 15:39:23 +00:00
Patrick Uiterwijk
984d230e7a Allow appowners to attach to pods (Fixes #6548)
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-15 15:39:00 +00:00
Ralph Bean
96a946515f Only if successful. 2017-12-15 15:12:29 +00:00
Ralph Bean
83ce739c02 Indentation matters. 2017-12-15 15:08:18 +00:00
Ralph Bean
3a63cd771e create directory for the active_branches cache 2017-12-15 15:03:33 +00:00
Ralph Bean
e0534e11b0 Integrate staging pagure-sync-bugzilla changes into prod. 2017-12-15 14:58:18 +00:00
Ralph Bean
7c83acbcd0 Back to one copy of pagure-sync-bugzilla.py.j2. 2017-12-15 14:58:18 +00:00
clime
96771bd58f copr-backend: enable copr_prune_repo.py again that was disabled
...temporarily for debugging purposes of copr_log_hitcounter.py
2017-12-15 12:55:42 +01:00
clime
82098b02b6 copr-builder: enable and infra-stg repo @copr/copr-dev on staging builders
...also remove commented out swapon /dev/vda lines as the /dev/vdb is
already used as swap in the f27 images
2017-12-15 12:51:18 +01:00
Ralph Bean
d194394dc4 Generate the active-branches cache in for prod pdc also. 2017-12-14 21:52:17 +00:00
Ralph Bean
da55d8e499 Send no email in staging. 2017-12-14 21:50:46 +00:00
Ralph Bean
b3be475477 Add a staging version of pagure-sync-bugzilla.py to try in staging. 2017-12-14 21:49:29 +00:00
Mohan Boddu
560ae55b4e Disable F25 Docker nightlies
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-12-14 20:07:42 +00:00
clime
0280a3ffdb copr-builder: attempt to use ansible facts in when condition 2017-12-14 15:23:26 +01:00
clime
e54fc2a119 copr-builder: do not do variable interpolation inside string 2017-12-14 14:19:22 +01:00
clime
df5ec4a008 copr-builder: install infra-tags-stg on staging builders 2017-12-14 14:06:52 +01:00
clime
09c011ec4f copr-builder: more monkey-patching due to outdated mock in infra repos
...that works with haskell packages as opposed to the latest mock
2017-12-14 13:44:03 +01:00
Matt Jia
79c0b564c4 greenwave role: remove upgradepath from mandatory checks 2017-12-14 16:40:52 +10:00
clime
3709ebe728 copr-builder: we need to put f27 configs back because of 2:mock-1.3.4 in infra repos 2017-12-13 21:49:04 +01:00
clime
dfa95ac4bd copr-keygen-stg: update iptables rules after copr-backend-dev reprovisioning 2017-12-13 21:33:26 +01:00
clime
2578ab78f5 copr-backend-stg: update backend ips after reprovisioning 2017-12-13 20:47:04 +01:00
clime
842d555ba3 copr-mbs: fix installation of python-copr package 2017-12-13 19:21:58 +01:00
clime
837b1c1106 copr-backend: make sure mock-core-configs is not present before installing/upgrading mock
...hack for 2:mock-1.3.4-2 currently being the latest version in infra repos
2017-12-13 18:42:56 +01:00
Kamil Páral
de157dcc35 taskotron: we don't run tasks from distgit (yet)
Do not clone and search it needlessly.
2017-12-13 15:31:20 +01:00
František Zatloukal
6a1dea6865 Taskotron: Disable task-upgradepath 2017-12-13 14:42:04 +01:00
Patrick Uiterwijk
7b5ab455f1 Remove some mash stuff
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-12 20:46:30 +00:00
Patrick Uiterwijk
c9f5123223 Remove bodhi2/base file context setting
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-12 20:42:53 +00:00
Ralph Bean
8a0a0d30dc Include active/inactive flag. 2017-12-12 20:17:26 +00:00
Ralph Bean
907af54d73 Generate, then move. 2017-12-12 19:55:40 +00:00
Ralph Bean
c35d565302 Only in staging for now. 2017-12-12 19:48:04 +00:00
Ralph Bean
88e9b62d57 Export PDC branches in a JSON file. 2017-12-12 19:47:16 +00:00
Ralph Bean
e9d85a10b7 Adjust format of PDC branch cache script. 2017-12-12 19:36:17 +00:00
Patrick Uiterwijk
b1c34e40a6 Move compose-ppc64-01 to ppc8-04
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-12 17:26:20 +00:00
Kevin Fenzi
ebd6cb15a1 weed out stupid usb from kvm that is spewing to logs 2017-12-12 17:20:39 +00:00
Mohan Boddu
894654efca F25 is now EOL
Also removing 24 mash files as it is also a EOL release

Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-12-12 16:20:56 +00:00
Patrick Uiterwijk
c9817d2b47 Add selinux to allow map for pamdatabase from unix_chkpwd
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-12 15:42:02 +00:00
Patrick Uiterwijk
9f4175b53b Upgrade Bodhi to f26
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-12 14:05:03 +00:00
Kamil Páral
86cfa2a707 taskotron: Fedora 25 is EOL 2017-12-12 13:03:07 +01:00
clime
8cfb476ded copr-backend: do not install i686 nosync on builders
...until we have nosync properly test on x86_64
2017-12-12 12:56:32 +01:00
Robert Mayr
5c6ac5b62a redirect server prerelease page 2017-12-12 11:52:27 +00:00
clime
0b19d059bb copr-backend: do not install createrepo_c on builders 2017-12-12 12:47:18 +01:00
clime
e8b4bd55b9 copr-backend: remove no longer present mock configs from copy list 2017-12-12 12:11:29 +01:00
clime
e0d9932207 copr-backend: simplify install of infra-tags repo on builders across archs 2017-12-12 12:09:32 +01:00
clime
bd14f29c43 copr-backend: enable nosync for all builders
See https://github.com/rpm-software-management/mock/issues/53
2017-12-12 12:04:30 +01:00
clime
8db3a16f5e copr-backend: remove always True condition for copr-builders 2017-12-12 12:02:39 +01:00
clime
4a8ce4600c copr-backend: remove extra mock configs (no longer needed) 2017-12-12 11:10:46 +01:00
Randy Barlow
9510c5caca Use the new migration location for Bodhi production and stg.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-12-11 22:56:06 +00:00
Ralph Bean
5cc1b3d26b Smaller icons. 2017-12-11 21:01:59 +00:00
Ralph Bean
ba38017689 Logos for some factory services. 2017-12-11 20:48:30 +00:00
Kevin Fenzi
fef564be75 more weed cleanup 2017-12-11 18:47:40 +00:00
Jan Kaluža
0e23800526 Merge branch 'master' of /git/ansible 2017-12-11 12:53:25 +00:00
Jan Kaluža
0688d5e8f8 Set ODCS pungi runroot variables also for frontend 2017-12-11 12:53:03 +00:00
Miroslav Suchý
75c4206259 copr: upgrade just dist-git to f27 2017-12-11 13:31:56 +01:00
Miroslav Suchý
4e4f6a6edc Revert "copr: lets try upgrade dist-git and be to F27"
This reverts commit 88a2759200.
2017-12-11 13:31:56 +01:00
Jan Kaluža
81610a9337 Corrent wrong variables names in ODCS defaults/main.yml 2017-12-11 12:04:23 +00:00
Jan Kaluža
bda0ef046c Fix wrong name of odcs_pungi_parent_tag variable in ODCS role. 2017-12-11 11:51:47 +00:00
Jan Kaluža
a4a66398d5 Add missing pungi_ prefix to ODCS Pungi related variables. 2017-12-11 11:43:40 +00:00
Jan Kaluža
5cf9d013df Fix typos in odcs config 2017-12-11 10:47:34 +00:00
Jan Kaluža
f856c0f9cd Fix typos in odcs config 2017-12-11 10:44:09 +00:00
Jan Kaluža
524b07800a Move ODCS kerberos configuration from koji conf to odcs conf. 2017-12-11 10:43:38 +00:00
Jan Kaluža
a496d0ab42 Revert "Fix kerberos variables in ODCS koji config."
This reverts commit 82b8291ee5.
2017-12-11 10:19:50 +00:00
Jan Kaluža
82b8291ee5 Fix kerberos variables in ODCS koji config. 2017-12-11 09:33:27 +00:00
Jan Kaluža
0531fbbd0d Set ODCs buildinstall_method only when bootable compose is requested. Enable Pungi runroot on stg backend. 2017-12-11 09:10:02 +00:00
Jan Kaluža
254d35c042 Move ODCS pungi.conf from 'templates' to 'files', so it can be copied without replacing the jinja2 vars. 2017-12-11 09:03:03 +00:00
Jan Kaluža
64856d2aea Add ODCS pungi.conf to base ODCS role. 2017-12-11 08:48:28 +00:00
Jan Kaluža
0eaf711e24 Add missing quotation mark 2017-12-11 08:37:19 +00:00
Jan Kaluža
42090b813a Define odcs_runroot_target_dir and do not enable raw_config source type for jscotka. 2017-12-11 08:33:57 +00:00
Jan Kaluža
edf2a634a9 Fix typo in odcs-backend-stg 2017-12-11 08:26:50 +00:00
Jan Kaluža
8cfb6ed977 Use double-quotes in odcs-backend-stg 2017-12-11 08:23:09 +00:00
Jan Kaluža
f904fc0363 Update ODCS role to new ODCS version and enable runroot backend on staging so I can test it. 2017-12-11 08:19:39 +00:00
Kevin Fenzi
039a627ac2 These are moved to buildhw's 2017-12-10 21:01:54 +00:00
Kevin Fenzi
b55984ca31 none of the armv7 instances are in createrepo channel 2017-12-10 19:39:20 +00:00
Kevin Fenzi
d630a230f0 correct and add some weed rules 2017-12-09 22:20:39 +00:00
Kevin Fenzi
1050e57cab helps if you commit all the vars 2017-12-09 00:52:46 +00:00
Kevin Fenzi
12e7d36f02 add 10 2017-12-09 00:44:16 +00:00
Kevin Fenzi
c1d15680a3 Revert "copr: make this work with ansible@F27"
This reverts commit 6f77265724.

Revert this until the instances are actually f27. :)
2017-12-09 00:35:41 +00:00
Kevin Fenzi
12f3e68c35 add 08/09 2017-12-09 00:06:07 +00:00
Kevin Fenzi
24912f4f58 add 06 2017-12-08 23:28:07 +00:00
Patrick Uiterwijk
ff3daf593f Koji builder is missing a dep on python2-koji
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-08 21:57:54 +00:00
Stephen Smoogen
66e9a93876 and we have a bunch of foo 2017-12-08 21:46:03 +00:00
Kevin Fenzi
ac481b9a2c make sure we have libselinux-python here 2017-12-08 21:44:18 +00:00
Kevin Fenzi
077e8aa289 buildhw-aarch64-07 2017-12-08 21:20:01 +00:00
Kevin Fenzi
c112b38634 add birthday to buildhw 2017-12-08 18:13:58 +00:00
Kevin Fenzi
36bcee9a10 Add 04/05 buildhw-aarch64 2017-12-08 18:11:00 +00:00
Randy Barlow
70e9eda7fa Fix the Bodhi stg --> prod sync script.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-12-08 15:58:22 +00:00
Michael Simacek
82cc107e9a Disable koschei-refresh-distgit-group on stg
The packages from the group don't exists on staging koji
2017-12-08 16:44:19 +02:00
Mikolaj Izdebski
6f97b5dad7 SELinux prevents login on Koschei Fedora 27 machines 2017-12-08 11:31:02 +00:00
Kevin Fenzi
7e8e8d6288 adjust master playbook 2017-12-08 05:35:45 +00:00
Kevin Fenzi
fff5f49714 drop old stuff from nagios 2017-12-08 03:16:16 +00:00
Patrick Uiterwijk
550e128daf Kill DHCP on storage VLAN
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-12-08 04:02:45 +01:00
Patrick Uiterwijk
42aaf6dd92 Only define 421 document on Fedora
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-12-08 04:02:01 +01:00
Kevin Fenzi
347628834a Switch stg ppc builders too. 2017-12-07 22:00:19 +00:00
Jeremy Cline
c74efc8f87 Fix anitya certnames for fedmsg 2017-12-07 21:57:45 +00:00
Kevin Fenzi
e2a65a242c move the x86 stg builders to f27 2017-12-07 21:54:23 +00:00
Kevin Fenzi
236302efb4 disable dnf makecache timer on all fedora boxes 2017-12-07 20:51:19 +00:00
Patrick Uiterwijk
75f1af5005 Add aliases to Pagure for verification of domain
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-12-07 21:07:22 +01:00
Nick Bebout
cc9cb380f2 Test fixing protectors group 2017-12-07 19:55:14 +00:00
Kevin Fenzi
445be50ac8 aarch64-03a lives 2017-12-07 18:58:28 +00:00
Mohan Boddu
9da779f388 Disabling F27 modular nightly composes
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-12-07 18:29:40 +00:00
Miroslav Suchý
6f77265724 copr: make this work with ansible@F27 2017-12-07 10:42:57 +01:00
Kevin Fenzi
afc3c1eb12 add birthday for arm-packager 2017-12-07 01:57:17 +00:00
Ryan Lerch
b12d085416 add the Fedora Bootstrap 1.1.1 release 2017-12-07 02:47:49 +01:00
Kevin Fenzi
9f266e920e _ here 2017-12-07 01:32:10 +00:00
Kevin Fenzi
e1f93a204e Need to also check for the variable 2017-12-07 01:31:17 +00:00
Kevin Fenzi
bef13aee3b Take another stab at handling new hardware installs. 2017-12-07 01:30:02 +00:00
Kevin Fenzi
af0894f472 see if this fixes this up so it can go on 2017-12-07 00:23:55 +00:00
Patrick Uiterwijk
92219f1462 Add iptables rule for nrpe to osbs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-07 00:16:21 +00:00
Patrick Uiterwijk
d3c59728fb Add tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-07 00:04:01 +00:00
Patrick Uiterwijk
6d0daa1871 Stop trying to maintain the docker.service, and just inject
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-06 23:58:05 +00:00
Patrick Uiterwijk
3ca43aff75 Seems sni is not enabled by default
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-06 23:20:50 +00:00
Ralph Bean
e4e83fb43b Tag this task. 2017-12-06 20:38:28 +00:00
Ralph Bean
a654c55201 Add pkgdb to robots.txt. 2017-12-06 20:37:44 +00:00
Patrick Uiterwijk
9b3c452be1 Yank qa01/02/03/04/08
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-06 19:26:53 +00:00
Kevin Fenzi
0ff391c44c add this to cloud group too 2017-12-06 18:04:51 +00:00
Stephen Smoogen
e2a69931d8 remove andkilled 2017-12-06 17:16:36 +00:00
Kamil Páral
c543f5446d taskotron dev trigger: also run task-rpmgrill 2017-12-06 13:48:25 +01:00
Kamil Páral
ac73b62fd4 taskotron trigger: limit executed tasks on dev
Run only ansiblized tasks.
2017-12-06 13:15:03 +01:00
Kevin Fenzi
c79bcad1dd might have fixed c17 2017-12-06 01:06:42 +00:00
Jeremy Cline
23da6e942b Create a temporary SQLite database for anitya staging
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 20:54:54 +00:00
Jeremy Cline
44d9cc9db3 Add health checks for release-monitoring.org
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 18:37:33 +00:00
Jeremy Cline
abbadc88e3 Fix route port name for release-monitoring-web
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 18:28:57 +00:00
Jeremy Cline
10f3e6e10c Add route, service, config to release-monitoring playbook
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 18:17:21 +00:00
Jeremy Cline
fce04f8ece Add basic configuration file
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 18:14:40 +00:00
Jeremy Cline
ed2289c5b1 Add route and service for stage release-monitoring
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 18:14:33 +00:00
Jeremy Cline
d35d4979d3 Fix release-monitoring web entry point
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 16:21:06 +00:00
Jeremy Cline
72a0698353 Configure anitya to use its fedmsg-relay
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-05 15:35:29 +00:00
Pierre-Yves Chibon
f239c0f263 Add custom krb5.conf file for simple-koji-ci
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-05 16:01:02 +01:00
Mohan Boddu
669481887e Enable F27 docker nightly
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-12-05 14:48:38 +00:00
clime
1283d4f603 copr-stg: update keygen IP after reboot 2017-12-05 11:35:13 +01:00
clime
7cbe59401e copr-keygen-stg: update iptables rules for new copr-be-dev instance 2017-12-05 10:10:25 +01:00
clime
81de9ba61a copr-stg: update keygen IP 2017-12-05 09:59:25 +01:00
clime
24ececd9c3 copr-keygen-dev: set machine to f27 2017-12-05 09:30:21 +01:00
Kevin Fenzi
8e87ad1b26 fix typo 2017-12-05 02:48:50 +00:00
Kevin Fenzi
5fc4bddf78 move armv7/aarch64 builders in stg to f27 2017-12-05 02:41:37 +00:00
Kevin Fenzi
36af79bb1d use include here for now 2017-12-05 02:31:23 +00:00
Patrick Uiterwijk
04e59b42dc Re-enable download-rdu01
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-05 02:07:36 +00:00
Patrick Uiterwijk
2aeb91e62f Use a per-host keydir
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-05 01:44:30 +00:00
Kevin Fenzi
d73314a5a3 fix bridges on buildvm-aarch64, which is now sane 2017-12-05 00:15:02 +00:00
Kevin Fenzi
11db6fd4e3 disable rhev repo for aarch64 virthosts 2017-12-04 23:47:17 +00:00
Dennis Gilmore
24cd3ac23d allow bikeshed fedmsgs
Signed-off-by: Dennis Gilmore <ausil@fedoraproject.org>
2017-12-04 22:25:45 +00:00
Patrick Uiterwijk
d83d883690 Let's not be too fast, and test stuff first
This reverts commit 3e1f25539e.
2017-12-04 21:20:39 +00:00
Patrick Uiterwijk
3e1f25539e Rebuild armv7 buildvms are f27
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-04 21:15:32 +00:00
Kevin Fenzi
4d6fdfca11 adjust this a bit 2017-12-04 20:40:35 +00:00
Kevin Fenzi
c217c21252 bodhi-backend01 seems to be working with v4, keep it for a bit 2017-12-04 20:28:36 +00:00
Kevin Fenzi
1c179c0102 set this to override pkgs.example.com 2017-12-04 20:26:47 +00:00
clime
5fad2d01a8 copr-backend: disable copr_prune_results to test if hitcounting works 2017-12-04 21:07:32 +01:00
Patrick Uiterwijk
0a06c5bb6d Also send the spam to me
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-04 19:55:30 +00:00
Pierre-Yves Chibon
56e1e1beb0 Fix variable for prod vs dev
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 17:13:39 +01:00
clime
19bf359da4 copr-backend: log out/err of logrotate prerotate script 2017-12-04 16:14:35 +01:00
Pierre-Yves Chibon
965e228594 Drop base for simple-koji-ci for now
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 15:50:29 +01:00
Patrick Uiterwijk
42da45351c Fix koji service accounts with gssapi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-04 14:41:01 +00:00
Pierre-Yves Chibon
50bc2411a2 Move the roles to the second section
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 15:38:20 +01:00
Miroslav Suchý
88a2759200 copr: lets try upgrade dist-git and be to F27 2017-12-04 15:36:06 +01:00
Pierre-Yves Chibon
3ec0052d0b Add some more of the basic roles for simple-koji-ci
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 15:32:19 +01:00
Jakub Kadlcik
02a558ce53 Not restrict to trusted repositories only 2017-12-04 15:28:13 +01:00
Jakub Kadlcik
124505f9cd Use https for connecting to PDC 2017-12-04 15:28:12 +01:00
Jakub Kadlčík
c9dc528e2d Restart httpd and fedmsg-hub after installing MBS 2017-12-04 15:28:12 +01:00
Pierre-Yves Chibon
2bc283d4b2 Prod isn't staging 2017-12-04 15:13:45 +01:00
Pierre-Yves Chibon
290ac87b99 Try fixing including multiple hosts
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 14:44:24 +01:00
Pierre-Yves Chibon
ac48044383 Include simple-koji-ci-prod.fedorainfracloud.org in the list of persistant cloud host
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 14:43:42 +01:00
Pierre-Yves Chibon
5e9bc67136 Move the simple-koji-ci playbook to the groups folder
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 14:39:37 +01:00
Pierre-Yves Chibon
e457fc3dce Include the prod instance in the playbook
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 14:38:58 +01:00
Pierre-Yves Chibon
3340927fac Add the host file for simple-koji-ci-prod
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-04 14:38:12 +01:00
Michael Simacek
f7e3dcc2b2 Configure GSSAPI auth for koschei stg 2017-12-04 10:55:31 +02:00
Kevin Fenzi
b649df98f3 no swap anymore on openshift instances 2017-12-03 02:18:50 +00:00
Patrick Uiterwijk
364cdcc60e The list of members doesn't change significantly over the runtime of this script
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 22:13:17 +00:00
Patrick Uiterwijk
9527cce666 Allow builders to proxy101 and proxy110
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 10:51:53 +00:00
Kevin Fenzi
3ceb59e3b7 Revert "try 4 again here"
This reverts commit 60012331ca.
2017-12-02 01:48:47 +00:00
Kevin Fenzi
60012331ca try 4 again here 2017-12-02 01:42:42 +00:00
Mikolaj Izdebski
1e691f0088 Don't install mod_wsgi on Koschei during upgrade 2017-12-02 01:10:47 +00:00
Mikolaj Izdebski
ebf5e505ce Adjust upgrade/koschei.yml after move to Fedora 27 2017-12-02 01:03:03 +00:00
Mikolaj Izdebski
05a89c01b8 Try include instead of include_playbook in upgrade/koschei-testing.yml 2017-12-02 00:56:12 +00:00
Patrick Uiterwijk
35c7dc8c34 RDU2 does not need to match 172.16.0.0/12 and does not contain PHX2
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 00:11:19 +00:00
Patrick Uiterwijk
d166747ad3 RDU2 is in NA
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 00:10:16 +00:00
Patrick Uiterwijk
5537ac3ef4 RDU2 is 172.31.0.0/16
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 00:08:04 +00:00
Patrick Uiterwijk
2d1516c17b RDU2 != PHX2. LEt's not mix up DNS
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-02 00:06:31 +00:00
Mikolaj Izdebski
26fb326bc3 Fix a typo in file name 2017-12-02 00:06:25 +00:00
Mikolaj Izdebski
24e916c2cf Add script to refresh koschei groups based on dist-git groups 2017-12-02 00:02:47 +00:00
Stephen Smoogen
551ea4ec3f and for want of a ; I nearly broke all of fedora.. again 2017-12-01 23:30:34 +00:00
Stephen Smoogen
d8c50af1d3 and aha moment. 4 hours of debugging and 8 characters I missed last night 2017-12-01 23:15:51 +00:00
Stephen Smoogen
c53c0b2fc8 ok lets try and be smarterish 2017-12-01 22:37:06 +00:00
Jeremy Cline
d29dfdae88 Adjust app build to release-monitoring-web 2017-12-01 22:36:50 +00:00
Jeremy Cline
3c8d008c9d Fix incorrect label in anitya
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-01 22:32:09 +00:00
Stephen Smoogen
585b6ff82f why why why 2017-12-01 22:27:30 +00:00
Stephen Smoogen
264af96b04 ok lets see if this works for dns 2017-12-01 21:40:46 +00:00
Jeremy Cline
5621cb53dd Change deploymentconfig label
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-01 21:36:52 +00:00
Mikolaj Izdebski
a9be5ca8cf koschei-web-stg uses python3-mod_wsgi, not mod_wsgi 2017-12-01 21:26:29 +00:00
Jeremy Cline
7d03a1cae9 Missing name in playbook 2017-12-01 21:21:01 +00:00
Jeremy Cline
57e0ec0918 Initial release-monitoring openshift app
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-12-01 21:19:30 +00:00
Stephen Smoogen
d6ab106d41 this works on both networks and useful 2017-12-01 20:46:15 +00:00
Stephen Smoogen
14dcf4fca0 limit access for disaester recovery 2017-12-01 20:37:44 +00:00
Patrick Uiterwijk
299dae3384 Redirect registry /latest to /f27 for now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-01 19:48:03 +00:00
Jeremy Cline
108f68c590 Revert "Apply fedmsg/base and fedmsg/relay role to anitya"
This reverts commit 3d914ff046.
2017-12-01 18:26:28 +00:00
Jeremy Cline
3d914ff046 Apply fedmsg/base and fedmsg/relay role to anitya 2017-12-01 17:51:36 +00:00
Patrick Uiterwijk
894a0cc805 FedoraHosted is not anymore
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-12-01 12:54:34 +00:00
clime
c565bffbd8 copr-backend: fix builder ppc64le provisioning failure 2017-12-01 11:50:34 +01:00
Pierre-Yves Chibon
148696bd80 Adjust the endpoint config for fedmsg on simple-koji-ci stg vs prod
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-12-01 11:47:47 +01:00
Kevin Fenzi
25c384d744 also only do these mounts in phx2 2017-12-01 03:36:26 +00:00
Kevin Fenzi
3d6fe7241a only do some things on batcave01 for now 2017-12-01 03:22:10 +00:00
Stephen Smoogen
0498b53e9b rdu doesnt need a route so dont ask for one 2017-12-01 03:06:19 +00:00
Stephen Smoogen
050682457b welp that was silly 2017-12-01 02:58:00 +00:00
Stephen Smoogen
fa59462ab3 bastion02 only vpns when things go bad 2017-12-01 02:49:05 +00:00
Stephen Smoogen
eebb019329 we dont have a route like that in rdu anymore. 2017-12-01 02:33:34 +00:00
Stephen Smoogen
c4ed34bea1 try to make rdu2 have proper dns view 2017-12-01 02:14:46 +00:00
Stephen Smoogen
5980773461 oh the comma needs to be in the endif or it blows up 2017-12-01 02:00:07 +00:00
Stephen Smoogen
cecac4ee45 and we needed to add it here 2017-12-01 01:52:14 +00:00
Stephen Smoogen
36cfe3a769 try some logic in nagios jinja template to allow for hosts not to be defined 2017-12-01 01:44:30 +00:00
Stephen Smoogen
d4042134d4 lets try not defining some 2017-12-01 01:29:27 +00:00
Stephen Smoogen
d113cd744d and we have ip for batcve 2017-12-01 01:02:54 +00:00
Ricky Elrod
b868ab88ae oh, rdu, not rdu2 here
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-30 23:39:12 +00:00
Ricky Elrod
b660d36d5a Or not
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-30 23:26:35 +00:00
Ricky Elrod
9715b3df7b No vpn for now for ns13
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-30 23:22:20 +00:00
Ricky Elrod
534011c2bb Merge branch 'master' of /git/ansible 2017-11-30 22:49:28 +00:00
Ricky Elrod
4f5769bdf9 try ansible_ssh_common_args
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-30 22:49:19 +00:00
Kevin Fenzi
91ebf8fdd3 no swap checking on os cluster, new openshift disallows swap 2017-11-30 22:46:30 +00:00
Ricky Elrod
1ad440cde0 ns13
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-30 22:12:01 +00:00
Kevin Fenzi
6fa6018428 increase / size since mem size is bigger and thus swap 2017-11-30 21:12:42 +00:00
Stephen Smoogen
15aa64b807 and a batcave inside the other batcave doesnt work. put it in the right place 2017-11-30 20:32:12 +00:00
Stephen Smoogen
07200eb127 and we have a backup batcave for when the pingou finds the first batcave 2017-11-30 20:30:56 +00:00
Stephen Smoogen
4c936e6a45 and voila.. a viola. [Or maybe a fix to make noc02 work] 2017-11-30 20:02:53 +00:00
Adam Miller
8817396cb6 fix releng push key permissions on stage composer
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-30 20:00:17 +00:00
Patrick Uiterwijk
5ee3b0bbdc Do the lazy porting to mw 1.29.0 hooks
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-30 19:59:08 +00:00
Stephen Smoogen
21c78da886 try to make batcave13 possible 2017-11-30 19:57:08 +00:00
Kevin Fenzi
8b5b985e20 move repos to pre 2017-11-30 19:56:05 +00:00
Adam Williamson
25d1c79a4b Tweak openQA asset size settings again
Staging is running out of space...let's kick it back down to
300, and also create a separate setting for update group asset
size. We test lots of updates, and for each update we only need
to upload one disk image, so we really don't need 300GB of
asset space for update job groups, that just means we'll keep
like 300 update disk images lying around. If PPC starts getting
incompletions again I'll have to, uh, do something? Yeahhh.
Something.
2017-11-30 11:48:22 -08:00
Kevin Fenzi
054f2a5681 fedora needs more memory than rhel7 2017-11-30 19:17:55 +00:00
Kevin Fenzi
29c1d4bf30 also need the repo file 2017-11-30 19:17:05 +00:00
Kevin Fenzi
2c9dfe445c install ppc64le rhv repo on ppc64le cloud compute too 2017-11-30 19:14:26 +00:00
Kevin Fenzi
223c782564 move koschei-web01.stg also to f27 2017-11-30 18:50:40 +00:00
Kevin Fenzi
3fc0edff5e move koschei-backend01.stg to f27 2017-11-30 18:30:36 +00:00
Adam Miller
9cc1d2de91 Add relengpush and relengpush-int scripts for automated rebuilds
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-30 17:25:27 +00:00
Patrick Uiterwijk
39ac0a38ee Search for a project tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-30 15:40:36 +00:00
Adam Miller
ff5eef2422 set releng-team group perms for container rebuild credentials in stage
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-30 15:09:30 +00:00
Patrick Uiterwijk
4b037b2314 Be more selective in #ipsilon messages
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-30 12:57:45 +00:00
Mikolaj Izdebski
6c884c55c6 Reinstall koschei-backend-stg as Fedora 27 2017-11-30 11:17:56 +00:00
Jan Kaluža
6bb4ec0acf Merge branch 'master' of /git/ansible 2017-11-30 07:43:13 +00:00
Jan Kaluža
80d97a84b5 Allow jscotka to access ODCS, so he is able to develop ODCS integration for modules testing. 2017-11-30 07:43:08 +00:00
Patrick Uiterwijk
1d7755a63f Move packages extra resources to apache
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-30 00:09:00 +00:00
Adam Miller
10d7262ef0 change manage-container-images role to set releng-team group perms on certs
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-29 22:16:52 +00:00
Kevin Fenzi
7d265c9bf9 switch openqa machines to alert on disk only when 90% or higher instead of 85% 2017-11-29 21:52:49 +00:00
Adam Miller
20178f7b42 change push-docker role to set releng-team group perms on certs
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-29 21:49:46 +00:00
Adam Miller
f0571cdb2e add keytab and ssh key for releng rebuilds on composer machines in stage
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-29 17:44:45 +00:00
Patrick Uiterwijk
7bc194f17a Work around link missing on f25 ostree
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-29 16:10:19 +00:00
Patrick Uiterwijk
e43b8f84b6 Sync FAW trees
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-29 15:46:05 +00:00
Patrick Uiterwijk
90878bb51d Make 5666 opening part of iptables
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-29 12:07:21 +00:00
Patrick Uiterwijk
2880217bcb We need to just fix re-entering a role rather than commenting it out
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-29 12:03:17 +00:00
Patrick Uiterwijk
100c857bf2 Let networkManager handle DNS for openshift
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-29 11:46:18 +00:00
Ricky Elrod
a5d017c71f new os-master cert
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 07:14:00 +00:00
Ricky Elrod
7d27cdd2f9 nuke the old ones
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 05:55:52 +00:00
Ricky Elrod
39dded872d enable these repos in prod
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 05:45:24 +00:00
Ricky Elrod
381ae542bb Fix some os* ips
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 04:39:29 +00:00
Ricky Elrod
314339d79c see if this works - openshift 3.6 on prod
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-29 02:37:09 +00:00
Stephen Smoogen
f81cb66458 put the openvpn client on bastion13 2017-11-29 02:10:26 +00:00
Stephen Smoogen
956d274a7b and we need to fix this to be a different host 2017-11-29 01:22:10 +00:00
Patrick Uiterwijk
3790314254 COPR has had a lot of time to transfer to TLS. Now require it
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 23:55:32 +00:00
Kevin Fenzi
a8c0d9b32d add sysadmin-releng to db-koji02.stg 2017-11-28 23:43:07 +00:00
Kevin Fenzi
c924b3d04e update inventory too 2017-11-28 23:31:49 +00:00
Kevin Fenzi
dd0744fc2c change db-koji02.stg to be a normal postgresql server running f27 2017-11-28 23:28:15 +00:00
Patrick Uiterwijk
76da2fe5ed This is on SSL, and let's also use fs.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 22:24:39 +00:00
Stephen Smoogen
47ba642bc8 and make the name right 2017-11-28 20:42:53 +00:00
Stephen Smoogen
09746514b8 put in bastion13 and start building 2017-11-28 20:41:28 +00:00
Kevin Fenzi
4cc1a5deb5 add policy to allow mbs to untag module builds in the secure-boot channel 2017-11-28 18:47:35 +00:00
Patrick Uiterwijk
99e5baf76e Send HTTP/421 on kojipkgs on non-phx2
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 15:39:37 +00:00
Pierre-Yves Chibon
8f6855eea6 Fedora-Badges renamed to fedora-badges
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-11-28 11:55:37 +01:00
Jan Kaluža
ec87815def Generate keytab for ODCS and use it in Koji profile. 2017-11-28 08:20:17 +00:00
Patrick Uiterwijk
7e908361d4 Also set cert secret correct for scratch
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 00:36:39 +00:00
Patrick Uiterwijk
8a08126441 Add tags to osbs-client role
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 00:33:30 +00:00
Patrick Uiterwijk
4c463059db Do not set koji_certs_secret = False. That leads to unstarted builds
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-28 00:32:54 +00:00
Kevin Fenzi
1819b09d89 commops is f27 after upgrading 2017-11-27 22:25:16 +00:00
Dennis Gilmore
c09b4d3d5f send emaisl to Mohan and not Dennis on failures
Mohan is dealing with the day to day things in fedora relng so he is
better suited to recieve the emails

Signed-off-by: Dennis Gilmore <ausil@fedoraproject.org>
2017-11-27 22:24:35 +00:00
Kevin Fenzi
6467a7f5bf we need to protect the infra-stg tags as well from gc 2017-11-27 22:22:28 +00:00
Kevin Fenzi
b1118af2df This is going to be a Fedora machine now. 2017-11-27 21:33:57 +00:00
Patrick Uiterwijk
e1121167e8 We have trees for ppc64le, not ppc64
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-27 20:55:48 +00:00
Stephen Smoogen
3c631c8075 add some items for fedorapeople.org 2017-11-27 20:20:26 +00:00
Patrick Uiterwijk
cd32d50d8c Get rid of special casing
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-27 19:44:52 +00:00
Patrick Uiterwijk
065a99364e Fix two silly oversights
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-27 19:30:46 +00:00
Patrick Uiterwijk
2ce6013160 Add multiple arches and multiple trees for ostree per release
Based on a patch by Dusty Mabe <dusty@dustymabe.com>

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-27 19:25:34 +00:00
Kevin Fenzi
e4eedd47fc move packages in stg over to f27 2017-11-27 19:13:19 +00:00
Patrick Uiterwijk
71f2d85920 mattdm likes Fedora Project Wiki
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-27 19:09:07 +00:00
Sayan Chowdhury
fe1d1adbf8 Don't delete the amis on failure 2017-11-27 18:36:20 +00:00
Kevin Fenzi
38fa2e710c apply additioanl extracmdline for atomic. ticket 6494 2017-11-27 18:32:52 +00:00
Kevin Fenzi
32fc8a626a fix totpcgi role to put templates in the right place 2017-11-27 17:25:01 +00:00
Kevin Fenzi
b9b2b34af1 only set 421 error doc on proxies not everything using apache role 2017-11-27 16:21:17 +00:00
Kamil Páral
493b871b49 taskotron: use production-override repo and enable mtf-containers
In production.
2017-11-27 14:36:03 +01:00
Patrick Uiterwijk
bc3bbcb5c0 Also return 421 from non-phx2 proxies for src.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-26 21:13:33 +00:00
Patrick Uiterwijk
40de21728b Set the error message centrally
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-26 21:12:32 +00:00
Patrick Uiterwijk
34a655ee37 Send a 421 Misdirected error to koji from non-phx2 proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-26 21:05:59 +00:00
Jakub Kadlcik
a4d4c044c8 Fix KeyError issue with relay_inbound and relay_outbound settings 2017-11-26 00:46:39 +00:00
Kevin Fenzi
a901cb2093 drop this since we just remove it later because we are using python3 2017-11-25 23:36:59 +00:00
Kevin Fenzi
fc484f796c drop some old openvpn stuff 2017-11-25 21:44:59 +00:00
Patrick Uiterwijk
44b5d262f7 We keep getting more constants. Instead just stop reporting these
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-25 18:43:49 +00:00
Patrick Uiterwijk
55081a1dff Add silly definitions to avoid using undefined things
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-25 18:39:20 +00:00
Patrick Uiterwijk
afc9870755 Make fpaste.org use certgetter
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-25 00:07:42 +00:00
Patrick Uiterwijk
ac055b3927 Deploy ticketkey as part of proxy role
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-25 00:02:26 +00:00
Patrick Uiterwijk
1225d45cfe Nuke these letsencrypt entries as well
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 23:36:41 +00:00
Patrick Uiterwijk
fbd3ed0d53 Proxies do not need to get certbot
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 23:31:34 +00:00
Patrick Uiterwijk
361fccdcc2 On vh21, we have vg_guests
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 23:12:29 +00:00
Patrick Uiterwijk
502b8ca509 Use standard wildcard cert for id.fp.o
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 22:56:58 +00:00
Patrick Uiterwijk
0f678956da Fix prod reverse proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 22:53:44 +00:00
Patrick Uiterwijk
e1bb4e64a4 Do not includeSubDomains for id.fp.o STS
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 22:49:05 +00:00
Patrick Uiterwijk
cabbfe3015 Deploy split servers to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 22:46:24 +00:00
Patrick Uiterwijk
bc95beb269 Split id.fp.o and username.id.fp.o for TLS/h2 reasons. Start with staging
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 22:20:25 +00:00
Patrick Uiterwijk
cc1795cec7 Also add koji stuff on other internal proxies
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-24 21:45:48 +00:00
Kevin Fenzi
37c7bf8b21 try increasing this to make src.fp.o more responsive 2017-11-24 19:51:35 +00:00
Kevin Fenzi
07cdaf24f4 weed out some debug and warn messages from openshift apps and fedmsg 2017-11-24 04:43:50 +00:00
Patrick Uiterwijk
a20b20b32a Try this
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 23:56:01 +00:00
Patrick Uiterwijk
e578d9be02 Fix this consistently
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 23:55:19 +00:00
Patrick Uiterwijk
a8aef4be9b Make sure that nrpe can monitor fedmsg-gateway on slave gateways
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 23:50:14 +00:00
Patrick Uiterwijk
012f59c57f PDC is too slow for bodhi, for a workaround let's use pkgdb
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 20:53:22 +00:00
Patrick Uiterwijk
5e40f1b33b Revert "Remove the mirrorlist container on removal"
This doesn't work with older docker

This reverts commit a408629158.
2017-11-23 20:49:38 +00:00
Kevin Fenzi
163569f068 if we do not have lvm installed at all we should ignore the failure here 2017-11-23 20:39:06 +00:00
Patrick Uiterwijk
a408629158 Remove the mirrorlist container on removal
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 20:29:52 +00:00
Kevin Fenzi
b38e329ced work around cancel button issue in WikiEditor, hopefully fixed next release 2017-11-23 19:00:52 +00:00
Patrick Uiterwijk
907ae0d6a9 Add tag
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 17:39:58 +00:00
Kevin Fenzi
36ac145a7e drop all twistd messages for now until notifs stops looping on a bad email 2017-11-23 17:37:29 +00:00
Kamil Páral
d053983613 taskotron-trigger: fix template/copy error 2017-11-23 16:46:07 +01:00
Kamil Páral
d6e02c0d27 taskotron-trigger: allow to use .env suffix for trigger_rules.yml.j2 2017-11-23 16:44:05 +01:00
Kamil Páral
1d13d60295 taskotron: enable task-mtf-containers on stg 2017-11-23 16:37:41 +01:00
Kamil Páral
2ea37aef64 taskotron-client: add taskotron-production-override repo to minion_repos
For stg only, to test it.
2017-11-23 16:22:49 +01:00
Patrick Uiterwijk
31e183670f Add proxy101/110 to the correct groups
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 14:24:00 +00:00
Patrick Uiterwijk
c3e5a23426 Add ccd files
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 14:19:11 +00:00
Kamil Páral
b402380168 taskotron: clone mtf-containers task everywhere 2017-11-23 14:58:13 +01:00
Patrick Uiterwijk
d42f2a8b3d Add proxy101/110 vars
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 13:53:05 +00:00
Kevin Fenzi
8e916e6388 enable WikiEditor. ticket 6521 2017-11-23 05:56:05 +00:00
Kevin Fenzi
547e12ddf8 we need this for openidc to work right 2017-11-23 05:37:11 +00:00
Kevin Fenzi
18433b198f more memory for unbound 2017-11-23 04:16:15 +00:00
Patrick Uiterwijk
dac95658c9 This is a full path
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 01:51:13 +00:00
Patrick Uiterwijk
cf97e949ad If mirrorlist2 is empty, populate
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 01:50:05 +00:00
Patrick Uiterwijk
6ca79cbfa3 Require CLA+1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 01:31:34 +00:00
Patrick Uiterwijk
a52525b9e8 Stg and prod have the same role now
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 01:10:21 +00:00
Patrick Uiterwijk
0527d7d23e Request CLA and groups scopes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 01:07:11 +00:00
Patrick Uiterwijk
70155259a7 This plugin is no longer there
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 00:52:13 +00:00
Patrick Uiterwijk
3a55c768bf Fix fedmsg-emit accessing private fields
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-23 00:50:45 +00:00
Patrick Uiterwijk
8f81f24ad7 Wiki is now Fedora
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 23:51:12 +00:00
Patrick Uiterwijk
35063dd962 Set max_mem for wiki
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 23:49:51 +00:00
Patrick Uiterwijk
6d453719cb Update localsettings with OIDC info for prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 23:33:49 +00:00
Patrick Uiterwijk
a85c1261ed Allow CORS from fedoraproject.org
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 23:22:35 +00:00
Patrick Uiterwijk
53d0c7517b Make this work in prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 23:19:09 +00:00
Patrick Uiterwijk
f9a0e1afd7 More prod-izing changes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 21:41:30 +00:00
Patrick Uiterwijk
5c2196a999 Update config for new wiki in prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 21:40:37 +00:00
Patrick Uiterwijk
5f2a79a6c3 Install correct mediawiki packages
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 21:39:05 +00:00
Patrick Uiterwijk
9426e17287 Wiki is becoming Fedora
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 21:21:19 +00:00
Patrick Uiterwijk
928927a64a Reinstall wiki02 as fedora 27
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 21:03:05 +00:00
Patrick Uiterwijk
0a98934168 Make the haproxy admin file root owned, the group isn't available due to selinux
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 19:37:27 +00:00
mprahl
50da23f384 Add git+https as an acceptable SMCM URL prefix in MBS 2017-11-22 19:30:43 +00:00
Tim Flink
998fd306e5 disabling host_key_checking on taskotron client-hosts 2017-11-22 19:26:14 +00:00
Tim Flink
5ad2adcb08 convert taskotron-dev to use new ansiblized libtaskotron with buildmaster 2017-11-22 19:01:36 +00:00
Tim Flink
f4704de141 changing default task repo branch for taskotron-dev 2017-11-22 18:42:51 +00:00
Patrick Uiterwijk
ed3aea328b Only put h2.conf on Fedora boxes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 18:15:34 +00:00
Kevin Fenzi
12be49917c this needs to be rw mount in stg for koji 2017-11-22 17:51:56 +00:00
Patrick Uiterwijk
48b51ab359 Do not overallocate for proxy09
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 17:11:15 +00:00
Patrick Uiterwijk
de010afa89 Enable h2 in production
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 15:03:06 +00:00
Pierre-Yves Chibon
ad84229ae3 Adjust simple-koji-ci's config for stg and prod 2017-11-22 14:04:16 +01:00
Patrick Uiterwijk
99c912800d Do previous compose detection per release type
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-22 13:00:58 +00:00
Pierre-Yves Chibon
efe23a468b Invert the order of the role so fedmsg is there when generating the keytab file 2017-11-22 10:16:07 +01:00
Pierre-Yves Chibon
59875c96d8 Include the handlers in simple-koji-ci's playbook
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-11-22 10:12:34 +01:00
Pierre-Yves Chibon
819fd61e9c Move simple-koji-ci to F27 2017-11-22 10:08:06 +01:00
Kevin Fenzi
f84aa0765e this fails in non prod 2017-11-22 02:44:25 +00:00
Kevin Fenzi
70fa66d8f9 fix typo 2017-11-22 02:13:07 +00:00
Kevin Fenzi
8214877003 Move this to a template for dev and prod handling 2017-11-22 02:01:40 +00:00
Kevin Fenzi
276135ccca replace several buggy lineinfiles with a local copy 2017-11-22 01:52:27 +00:00
Kevin Fenzi
e7cfb0d1d1 see if this fixes this lineinfile problem 2017-11-22 01:33:31 +00:00
Kevin Fenzi
cb60dca825 instead of file module and touch, which changes every time, we use copy and empty contents and force no if the file already exists 2017-11-22 01:04:21 +00:00
Kevin Fenzi
d8e2898cc7 clean up copr-dist-git hostname 2017-11-22 00:51:30 +00:00
Kevin Fenzi
9848b4eb85 this is just gathering information it should not ever show changed 2017-11-22 00:40:54 +00:00
Patrick Uiterwijk
65a6ad06f2 This service does not exist on newly installed boxes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 23:07:56 +00:00
Tim Flink
f2b42f6c9e forgot a path in the buildslave service file 2017-11-21 23:07:15 +00:00
Tim Flink
55de44408e correcting buildslave service file to reflect new home dir locations 2017-11-21 22:57:02 +00:00
Patrick Uiterwijk
3dff602f01 Deploy yumrepos first
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 22:56:21 +00:00
Patrick Uiterwijk
a564c51a18 Reconfigure proxies to Fedora
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 22:39:40 +00:00
Josef Skladanka
047caaf50c taskotron - fix selinux context the same way we do in buildslave-configure 2017-11-21 23:36:23 +01:00
František Zatloukal
ab1ba9605e Add new ssh key for taskotron-dev01 2017-11-21 23:25:31 +01:00
Patrick Uiterwijk
3f46535e75 This is 0755
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 22:13:03 +00:00
Kevin Fenzi
e5f559daca and case was right before 2017-11-21 22:03:28 +00:00
Kevin Fenzi
4d1cad7a6e make parser happy 2017-11-21 22:03:10 +00:00
Kevin Fenzi
6ae9aa8df6 not not 2017-11-21 22:02:24 +00:00
Kevin Fenzi
470e8c0e3c try this 2017-11-21 22:01:27 +00:00
Patrick Uiterwijk
732824986c Deploy reg-server to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:56:50 +00:00
Patrick Uiterwijk
408460130e Deploy registry-index to prod and fix up directory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:54:52 +00:00
Patrick Uiterwijk
a7f712fa31 Give proxies more disk
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:48:29 +00:00
Josef Skladanka
c76842617c taskotron - selinux context workaround 2017-11-21 22:46:15 +01:00
Kevin Fenzi
0633c0b63b also need a check mode no here 2017-11-21 21:38:59 +00:00
Patrick Uiterwijk
5f7cda28f8 Disable local account creation
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:33:40 +00:00
Kevin Fenzi
818a29acb3 try and fix this another way 2017-11-21 21:26:50 +00:00
Kevin Fenzi
47c9adb579 this may need quotes for check mode 2017-11-21 21:21:31 +00:00
Patrick Uiterwijk
2789ed774a Set the ordering right -h2c over http1.1
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:18:51 +00:00
Patrick Uiterwijk
0f94698922 Enable h2 for proxies and also h2c for Fedora app servers
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-21 21:16:27 +00:00
Tim Flink
1fca20da63 moving yumrepos to pre_tasks for other taskotron playbooks 2017-11-21 21:12:42 +00:00
Kevin Fenzi
f0e21b57f1 convert this synchronize into a copy to make it idempotent 2017-11-21 20:52:43 +00:00
Tim Flink
6b0c3c8b8b changing taskotron hw pxe entry to use f27 2017-11-21 20:47:18 +00:00
Ralph Bean
483a7423e1 Reinstitute greenwave abicheck policy, borrowing taskotron's blacklist. 2017-11-21 20:35:57 +00:00
František Zatloukal
c68d023707 Change f25 to f27 for dev taskotron/resultsdb 2017-11-21 21:27:17 +01:00
Kevin Fenzi
02b821e0ef These hosts should all be using the ext kickstart 2017-11-21 20:21:23 +00:00
Kevin Fenzi
6584ee57aa move keys02 to osuosl02 2017-11-21 19:54:07 +00:00
Pierre-Yves Chibon
675e8d93db Make the keytab belong to the fedmsg user 2017-11-21 19:40:04 +01:00
Pierre-Yves Chibon
5efb867282 Mark the host as staging, fix the config file 2017-11-21 18:00:02 +01:00
Pierre-Yves Chibon
6721d7a153 Specify krb_principal 2017-11-21 17:51:36 +01:00
Pierre-Yves Chibon
1f19a9d0b3 Add fedmsg to the mock group 2017-11-21 17:42:44 +01:00
Pierre-Yves Chibon
253e4ec8a0 Couple of more packages are required 2017-11-21 17:32:06 +01:00
Pierre-Yves Chibon
0725398edf Fix config file and ensure git is installed 2017-11-21 17:29:43 +01:00
Pierre-Yves Chibon
983d5b4518 Try adding a log handler for simple-koji-ci 2017-11-21 17:16:27 +01:00
Pierre-Yves Chibon
bfd02c7fd0 Create /usr/share/fedmsg manually... 2017-11-21 17:11:37 +01:00
Pierre-Yves Chibon
f8d26977a3 Let fedmsg read the fedmsg config file 2017-11-21 17:04:57 +01:00
Pierre-Yves Chibon
6208b4a213 Rename the file to drop the from it 2017-11-21 16:49:52 +01:00
Pierre-Yves Chibon
b4a06cdb72 Some more package to install 2017-11-21 16:46:34 +01:00
Pierre-Yves Chibon
1a8056d93c Ensure fedmsg-hub is up and running 2017-11-21 16:40:15 +01:00
Pierre-Yves Chibon
3125b5c763 Override the default fedmsg endpoints 2017-11-21 16:38:26 +01:00
Pierre-Yves Chibon
06532ef4b7 Typi typo 2017-11-21 16:34:50 +01:00
Pierre-Yves Chibon
ad94e48fe7 Specify the keytab file to use 2017-11-21 16:29:51 +01:00
Pierre-Yves Chibon
0c77331e46 Fix location for simple-koji-ci config file 2017-11-21 16:29:39 +01:00
Pierre-Yves Chibon
4d29d49b2d Start working on the simple-koji-ci playbook 2017-11-21 16:11:01 +01:00
Pierre-Yves Chibon
1afabeef71 Still no need for 80 or 443 in simple-koji-ci but mark it as staging host
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-11-21 15:22:54 +01:00
Kamil Páral
ea277aa89f taskotron: add disabled mtf-containers task to trigger_rules 2017-11-21 15:15:14 +01:00
Pierre-Yves Chibon
35c87a5c30 simple-koji-ci doesn't need 80/443
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-11-21 15:14:40 +01:00
Miroslav Suchý
d9cd6a9bd0 copr: this is likely not needed 2017-11-21 14:42:37 +01:00
Kevin Fenzi
5aa67ede4e backup anitya database backups 2017-11-21 06:21:40 +00:00
Kevin Fenzi
392b41cbf7 upstreamfirst does not need fedmsg-relay started 2017-11-21 01:16:36 +00:00
Kevin Fenzi
ea715e6723 adjust master playbook to have some of the new recent apps 2017-11-21 01:08:46 +00:00
Kevin Fenzi
ceb53f786f fedmsg-relay is not even installed here, so its really not likely to be needed 2017-11-21 00:54:01 +00:00
Kevin Fenzi
112b77e690 Drop mirrormanager2 xmlrpc hotfix for json submit. Long since upstream. 2017-11-21 00:46:10 +00:00
Kevin Fenzi
dd9424a0b8 drop some file: state=touch calls in favor of copy with content and force=no 2017-11-21 00:30:55 +00:00
Kevin Fenzi
9ef0827546 this is a cloud instance, do not try and mess with networking 2017-11-21 00:20:39 +00:00
Kevin Fenzi
8a8980044d we need merge behavior here for osbs 2017-11-20 23:38:03 +00:00
Kevin Fenzi
14439f87f7 since we later rsync these dirs, set them to the mode we sync over so they do not change every ansible run 2017-11-20 22:33:02 +00:00
Tim Flink
7b28efc60c moving home directories for biuldslave users 2017-11-20 19:25:48 +00:00
Kevin Fenzi
df30abd43c the default rsyslog logrotate in f27 is rsyslog, not syslog 2017-11-20 16:49:34 +00:00
Ralph Bean
622c76d189 Looks good. 2017-11-20 12:52:28 +00:00
Ralph Bean
7151663037 Fix ordering in PDC.
https://github.com/product-definition-center/product-definition-center/issues/439
2017-11-20 12:48:21 +00:00
Pierre-Yves Chibon
63f13cf8cd Specify the username in the GIT URL 2017-11-20 11:05:15 +01:00
Kevin Fenzi
fbe46c39de switch back to the native qemu-kvm on aarch64 virthosts again 2017-11-18 23:49:54 +00:00
Kevin Fenzi
e2f4f0f09b increase some timeouts on restart mirrorlist containers 2017-11-18 23:33:56 +00:00
Kevin Fenzi
84ab5c11c0 only link vendor in staging mediawiki 2017-11-18 23:10:56 +00:00
Patrick Uiterwijk
22e80e947c Remove extra slash
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 13:06:32 +00:00
Patrick Uiterwijk
ffdbb5b990 This is not a regex anymore
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 13:05:39 +00:00
Patrick Uiterwijk
c0de69b340 Redirect with path retained
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 13:04:22 +00:00
Patrick Uiterwijk
cfa9756284 Try to fix redirect
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 12:59:03 +00:00
Patrick Uiterwijk
6fc4ba64fd Also redirect /ostree
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 12:53:17 +00:00
Patrick Uiterwijk
e919efcf98 Redirect /ostree/27/ to kojipkgs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-18 12:49:39 +00:00
Kevin Fenzi
c84e60782f looks like new rhel 7.4 alt swaps these bridges 2017-11-17 21:43:40 +00:00
Adam Miller
084ae43c99 need python2-dockerfile-parse for container rebuild testing also
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-17 20:04:27 +00:00
Adam Miller
37f1f500ad add ansible to stage composer for container rebuild automation testing
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-17 18:38:44 +00:00
Jeremy Cline
f71d96a74a Bump the redis cache expiration to 24 hours for fmn
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-11-17 18:08:36 +00:00
Robert Mayr
deb74aae7c redirect CoC pages to the authoritative docs.fpo destination 2017-11-17 16:49:09 +00:00
Ralph Bean
5752ba7fcb Fix https doc urls for PDC.
https://pagure.io/fedora-infrastructure/issue/6122
2017-11-17 15:32:36 +00:00
Ralph Bean
3c596b38cf Give PDC some extra, unused fedmsg endpoints.
https://pagure.io/fedora-infrastructure/issue/6482
2017-11-17 15:22:33 +00:00
Patrick Uiterwijk
73554e042e Make secondary arch atomic host trees failable
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-17 15:20:49 +00:00
Ralph Bean
448186269c Copy, not file. 2017-11-17 14:00:34 +00:00
Ralph Bean
572f6c7ce3 Fix value of state. 2017-11-17 13:59:52 +00:00
Ralph Bean
ff06a0e256 Fix value of state. 2017-11-17 13:59:08 +00:00
Ralph Bean
76f6aabcd4 Tag with cron. 2017-11-17 13:54:20 +00:00
Ralph Bean
5676d70ef4 Add exportbranches command for PDC. 2017-11-17 13:52:29 +00:00
Matt Jia
f8a3c46e93 greenwave: new build to pick up 2017-11-17 16:48:30 +10:00
Kevin Fenzi
76e85ef2d8 and switch aarch64 back to rhev kvm 2017-11-17 00:51:24 +00:00
Patrick Uiterwijk
9d60d3017a Make atomic workstation failable
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-17 00:09:13 +00:00
Kevin Fenzi
0a494a4fc1 fix the clean ami scripts to actually work. Need to quote the ansible variables and also install python2-fedfind needed by the script 2017-11-16 22:27:46 +00:00
Kevin Fenzi
81855bb0b4 also allow bodhi-backend01 to emit this pungi message to make bodhi-backend02 happy about it and not error 2017-11-16 22:02:08 +00:00
Patrick Uiterwijk
8359fdc170 Add F27 AW to robosignatory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 21:52:54 +00:00
Patrick Uiterwijk
d4fa2f152e Update path to atomic workstation config file
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 21:51:07 +00:00
Adam Williamson
aa6a0c7071 wikitcms: ensure openidc-client is available for token auth
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2017-11-16 13:36:17 -08:00
Adam Williamson
d3356663d8 wikitcms token: create directory, install for fedmsg and root
Previous commit didn't work as the directory doesn't exist.
Also, I think we need the file in two places, one for root
(for if an admin runs something wikitcms-ish manually while
logged in as root) and one for fedmsg (for the usual case
when the wiki is updated by fedmsg consumers). So do that.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2017-11-16 13:24:05 -08:00
Adam Williamson
c5450c9cfe openqa, relvalconsumer: write wikitcms token file for new auth
Unattended wiki interaction with the new openidc auth method
requires a special token file which @puiterwijk created and
put in the private store for us. Have the appropriate roles
install it.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2017-11-16 12:59:30 -08:00
Jeremy Cline
37f84244a3 Make sure fedmsg roles are applied on fmn upgrade 2017-11-16 20:35:19 +00:00
Jeremy Cline
86e40cf9e3 Don't overwrite default fedmsg log file 2017-11-16 20:27:49 +00:00
Jeremy Cline
3e7da2ef63 Adjust FMN logging so moksha doesn't log DEBUG
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-11-16 19:55:20 +00:00
Patrick Uiterwijk
714d351fc9 Add src.fp.o to trusted roots and deploy wiki scope to prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 19:33:04 +00:00
Patrick Uiterwijk
0c0f26fe59 Fix terminating things
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 19:17:46 +00:00
Patrick Uiterwijk
b2a87216bc Fix up Atomic Host and add Atomic Workstation to bodhi pungi
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 15:43:34 +00:00
Randy Barlow
169278f5fa Bodhi now uses pdc to determine critpath packages.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-11-16 15:40:28 +00:00
Randy Barlow
98b1b337e2 The Bodhi MASHING lock files have moved.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-11-16 15:38:30 +00:00
Miroslav Suchý
a0023baece copr: use file module rather then shell: rm 2017-11-16 16:37:02 +01:00
Miroslav Suchý
af03addd58 copr: disable DNF makecache timer/service 2017-11-16 16:34:43 +01:00
Miroslav Suchý
2942112ff3 lets try to upgrade copr-fe-dev to F27 2017-11-16 16:18:13 +01:00
Miroslav Suchý
0e0b05a475 add F27 image to Fedora Cloud 2017-11-16 16:17:00 +01:00
Ralph Bean
8fa8632e37 Enable greenwave and waiverdb pseudohosts (for fedmsg routing_policy from openshift). 2017-11-16 14:12:32 +00:00
Kamil Páral
f333cecbbe taskotron-client: F27 in yumrepoinfo for production 2017-11-16 14:02:28 +01:00
Patrick Uiterwijk
d1d9455370 Let Pagure manage the git-daemon-export-ok files
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-16 09:42:27 +00:00
Kevin Fenzi
b6aa8ac07e fix cert name 2017-11-16 04:23:07 +00:00
Kevin Fenzi
fe769cf62e use fedoracommunity.org cert 2017-11-16 02:00:19 +00:00
Kevin Fenzi
a306a334b2 we need to setup planet.fedoraproject.org site too on proxies 2017-11-16 01:01:28 +00:00
Kevin Fenzi
5770c4ddf8 drop trailing / on Manual 2017-11-16 00:52:53 +00:00
Kevin Fenzi
21bc9a865c redirect planet.fedoraproject.org to fedoraplanet.org 2017-11-16 00:41:09 +00:00
Kevin Fenzi
6ac39c507e switch aarch64 rhel7.4 virthosts to use new alt packages for kvm 2017-11-15 20:11:10 +00:00
Jeremy Cline
065d9ff801 Update FMN queues in nagios
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-11-15 19:18:47 +00:00
Kevin Fenzi
8a31937429 move notifs-backend01 prod to f27 2017-11-15 18:59:19 +00:00
Jeremy Cline
6fe55bf3cb fmn-web is still EL7, use yum 2017-11-15 18:15:18 +00:00
Jeremy Cline
f56b1ecd83 Update FMN roles for 2.0.0 2017-11-15 18:12:11 +00:00
Kevin Fenzi
f939d582dd switch notifs-backend01.stg to f27 2017-11-15 17:20:47 +00:00
Kevin Fenzi
bcc62fa2cb correct wiki01.stg kickstart/repo urls for f27 release 2017-11-15 17:20:15 +00:00
Kevin Fenzi
6b248fa847 now apply in prod fix to emit fedmsg on block/unblock. ticket 3960 2017-11-15 17:10:19 +00:00
Kevin Fenzi
9a6a3a49be switch rhel7 aarch64 repos to new rhel 7.4 alt ones 2017-11-15 17:07:34 +00:00
Ryan Lerch
1c20d0cf51 Update the fedora-bootstrap-fonts to v0.3
this adds the montseraat font, and the 600 weight
of open-sans
2017-11-15 17:04:57 +00:00
Kamil Páral
3174264417 taskotron: add mtf-containers repo to dev 2017-11-15 12:11:52 +01:00
Kamil Páral
5fe0404d03 taskotron-client: sort rules in namespaces/yaml 2017-11-15 12:10:23 +01:00
Kamil Páral
4380801eab taskotron group vars: synchronize configs between envs
Make the lines appear in roughly the same order between {dev,stg,prod}
files to make diffing easier. Sort grokmirror repos by name.
2017-11-15 12:05:36 +01:00
Kamil Páral
61d5f66985 taskotron-client: F27 is stable in yumrepoinfo
test in dev
2017-11-15 11:46:58 +01:00
Patrick Uiterwijk
8355e9fa9f Define dequeue stable file age check
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-15 03:08:41 +00:00
Jeremy Cline
6ad04bda36 Mount the config read-only for sse2fedmsg 2017-11-15 00:20:40 +00:00
Jeremy Cline
c44b5fbc99 Adjust volume name for the config map 2017-11-15 00:17:28 +00:00
Jeremy Cline
92d8214328 Fix typo in librariesio2fedmsg deployment config
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-11-14 23:58:04 +00:00
Jeremy Cline
dc08d45293 Remove the secret.yml object, there are no secrets in librariesio2fedmsg 2017-11-14 23:53:54 +00:00
Kevin Fenzi
508f1bc3c2 fix syntax 2017-11-14 23:25:30 +00:00
Kevin Fenzi
c9bf62fffb switch elastic-dev to f26 2017-11-14 23:23:23 +00:00
Miroslav Suchý
6756c4147e add jkadlcik to copr* tenant of fedorainfracloud
I am using clime_password here, because it is only about initial password.
2017-11-14 15:28:19 +01:00
Kevin Fenzi
73a3cb1313 split out redirect on server so we can still have prerelease for modular server 2017-11-14 13:26:09 +00:00
Kevin Fenzi
d6838f49c7 handle redirects for release morning 2017-11-14 12:48:10 +00:00
Stephen Smoogen
a1eeeb79bf start the process of bat/bast 2017-11-14 01:31:42 +00:00
Dusty Mabe
92be4a09a3 robosig: sign F27AH updates-testing refs
The diff looks ugly but all I did was copy the updates
entries and s/updates/testing/ and then I deleted the one
existing testing entry that was below f27-workstation.
2017-11-13 23:43:24 +00:00
Dusty Mabe
12f077e92e robosig: sign F27AH updates refs
Also move directory to point to updates repo.
2017-11-13 23:43:18 +00:00
Jeremy Cline
5ee07c719d Initial openshift app for librariesio2fedmsg
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-11-13 21:27:14 +00:00
Ralph Bean
d5d94eb93e Try using memcached for greenwave in "prod". 2017-11-13 15:08:32 +00:00
Patrick Uiterwijk
bc0bd0df5b Define mediawiki scope
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-13 00:37:39 +00:00
Patrick Uiterwijk
99f92097af Add plugin loading
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-13 00:26:52 +00:00
Patrick Uiterwijk
3097411673 Add OpenID Connect configuration
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-13 00:24:24 +00:00
Patrick Uiterwijk
6050d3e5e3 Add mediawiki OIDC(API) packages for staging
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-13 00:13:41 +00:00
Patrick Uiterwijk
0a0b58be97 Create live fedimg indicator file on sundries
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-12 20:49:05 +00:00
Patrick Uiterwijk
1c2b327e74 Add the preferred_username mapping for mediawiki
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-12 20:34:34 +00:00
Adam Williamson
4a6d33d863 openqa, relvalconsumer: need fedfind/wikitcms from u-t for now 2017-11-10 18:34:10 -08:00
Patrick Uiterwijk
3a16dff47a Fix typo
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-11 02:23:15 +00:00
Patrick Uiterwijk
78c661da95 Fix one occurence of [[ vs {{
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-11 01:05:44 +00:00
Dusty Mabe
f5e62b5dbf add syncing for f27-updates 2017-11-11 00:53:07 +00:00
Patrick Uiterwijk
e72703fa06 Only sync drpms if a repo has them
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-11 00:51:23 +00:00
Patrick Uiterwijk
998473eb7b Compose F27 alt-arch ostrees
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-11 00:39:55 +00:00
Kevin Fenzi
bfd94ffe69 also link vendor 2017-11-10 23:42:05 +00:00
Patrick Uiterwijk
bb7379e007 Revert "Add --depth=1 to ostree sync"
This reverts commit 8ea9a3766c.
2017-11-10 23:36:53 +00:00
Patrick Uiterwijk
8ea9a3766c Add --depth=1 to ostree sync
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-10 22:56:14 +00:00
Mohan Boddu
15dab543af Disabling F27 branched compose
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-11-10 22:22:35 +00:00
Kevin Fenzi
b7b867bbd6 exclude wiki01.stg from yumrepos as they are not correct for prerelease, remove after release 2017-11-10 20:50:28 +00:00
Kevin Fenzi
def9f2bdae drop openid plugin in stg wiki, move stg wiki to f27 2017-11-10 20:24:59 +00:00
Ricky Elrod
f67bb34783 add initial playbooks for librariesio2fedmsg and release-monitoring, both on openshift stg
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-10 19:20:39 +00:00
Dusty Mabe
d5ffeddb05 add syncing for f27-u-t ostree ref 2017-11-10 17:05:51 +00:00
Adam Miller
b5613c90d1 make osbs stage and prod buildroot Dockerfile the same
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-10 17:02:55 +00:00
Adam Miller
150a115b39 fix switched stg/prod conditional for osbs custom build
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-10 16:44:29 +00:00
Mohan Boddu
7484cdcbbb Performing 0-day actions for F27 final release
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2017-11-10 16:41:59 +00:00
Adam Miller
8151b82280 Revert osbs orchtestrator namespacing for osbs-client on buildvms
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-10 16:06:17 +00:00
Robert Mayr
02d678fe0c build stg websites with f27 branch 2017-11-10 14:39:07 +00:00
Robert Mayr
9cb8dae206 redirect staging prerelease pages excepts server - still needs config files to be removed 2017-11-09 21:02:51 +00:00
Stephen Smoogen
8f12b29a5a just no checking for moment 2017-11-09 18:19:04 +00:00
Ricky Elrod
2d07754cff Update search string for wiki front page
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-09 17:51:15 +00:00
clime
0f61b68d52 copr-backend: remove hack to install fixed versions of builder packages 2017-11-09 15:06:30 +01:00
Ralph Bean
61210be170 Retrieve only the correct branches for a given package. 2017-11-08 20:52:09 +00:00
Adam Miller
4d9ec7ded9 re-enable stage osbs custom build policy
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-08 19:45:36 +00:00
clime
ecac38619f copr-backend: update copr-rpmbuild's main.ini config template 2017-11-08 19:30:39 +01:00
Adam Miller
0dca69a6f5 disable openshift_enable_docker_excluder in openshift-ansible for osbs
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-08 16:55:19 +00:00
Patrick Uiterwijk
e114a89fdf Move yumrepos to pre-tasks for osbs-cluster
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-08 14:59:18 +00:00
Kamil Páral
d89c1e5860 tasktron: sort output in fetch_activity.py 2017-11-08 13:27:28 +01:00
clime
ebc29977ef copr-mbs: set allow_custom_scmurls to True 2017-11-08 13:00:42 +01:00
Adam Miller
21e1fab182 set memory limits on osbs-control hosts
Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-07 23:36:46 +00:00
Adam Miller
d71a039927 Remove osbs-orchestrator-cluster.yml; align stg/prod OSBS
For the time being, this needs to be removed. This work has been
put on hold until a new Fedora Engineering Team member is onboarded
in order to take this work over and in the mean time there's no
sense in leaving stage OSBS broken for users.

This commit also brings stage OSBS back into alignment with the
production OSBS which is the "old" OSBS Architecture as defined in
the upstream documentation:

    https://osbs.readthedocs.io/en/latest/multiarch.html

Signed-off-by: Adam Miller <admiller@redhat.com>
2017-11-07 21:19:23 +00:00
Randy Barlow
177bb8c15e Configure alembic.ini for the new migrations location.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-11-07 21:14:31 +00:00
Randy Barlow
134b51c31a Only configure the mash_dir on the staging backend.
Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-11-07 20:13:26 +00:00
Randy Barlow
7e9324b189 Do not semanage /usr/share/bodhi/.fedora on stg.
It does not exist.

Signed-off-by: Randy Barlow <randy@electronsweatshop.com>
2017-11-07 19:51:41 +00:00
Kevin Fenzi
e0037fcbf0 ok try this one 2017-11-07 18:48:49 +00:00
Kevin Fenzi
9368950a21 perhaps this needs to import in order to find the handler correctly 2017-11-07 18:43:17 +00:00
Kevin Fenzi
8927aba6a3 try and adjust cloud deployment to handle strict ssh keys 2017-11-07 18:39:25 +00:00
Kevin Fenzi
7703a73663 This is supposed to be a rhel7 instance. 2017-11-07 18:39:02 +00:00
Kevin Fenzi
9fb91cddcc Look, our very own copy of nova_compute module. We cannot move to os_server because that requires python-shade, which is not packaged for RHEL7. When/if we move batcave01 to fedora we can drop this. 2017-11-07 18:32:12 +00:00
Kevin Fenzi
57e6a6b8f2 add elastic-dev and simple-koji-ci-dev cloud instances 2017-11-07 18:25:37 +00:00
Kevin Fenzi
d8b735741d Add redirects for generic-logos and beakerlib from old fedorahosted.org to new locations.
Fixes https://pagure.io/fedora-infrastructure/issue/6474 and https://pagure.io/fedora-infrastructure/issue/6489
2017-11-07 17:03:14 +00:00
Kamil Páral
1957d79cdc taskotron-trigger: disable atomic and cloud tests
Due to missing nested virt:
https://pagure.io/taskotron/issue/239
2017-11-07 10:28:37 +01:00
Ralph Bean
cad734d27c Try building right from candidate-registry.fp.o. 2017-11-07 02:05:54 +00:00
Ralph Bean
5370a4f3a6 Declare the secondary image stream. 2017-11-07 01:59:43 +00:00
Ralph Bean
942f370c35 Declare the buildconfig. 2017-11-07 01:57:52 +00:00
Ralph Bean
c6cea79a7c Layer a deployment image ontop of the waiverdb candidate-registry image. 2017-11-07 01:56:19 +00:00
Ralph Bean
46a505414b Re-enable fedmsg for waiverdb. 2017-11-07 01:42:19 +00:00
Ralph Bean
789e59ad3b Tell waiverdb to poll for new images at candidate-registry.fedoraproject.org. 2017-11-07 01:39:08 +00:00
Ralph Bean
380bc1d7ca Disable fedmsg for waiverdb again, for now. 2017-11-06 22:10:21 +00:00
Ralph Bean
bc8eef2cf0 Need an endpoints value for fedmsg to be happy. 2017-11-06 22:06:32 +00:00
Ralph Bean
fabea55717 Fedmsg config for waiverdb. 2017-11-06 21:59:38 +00:00
Ralph Bean
95207ee370 Disable waiverdb fedmsg messages for now. 2017-11-06 21:39:28 +00:00
Kevin Fenzi
8484ed6962 add patch to add fedmsg block events to koji in staging only for now. Many thanks to vrutkovs. https://pagure.io/fedora-infrastructure/issue/3960 2017-11-06 21:28:01 +00:00
Ralph Bean
cb6772b847 Correct waiverdb client_secrets.json. 2017-11-06 21:22:15 +00:00
Ralph Bean
8dcaae4b8f Specify OIDC_REQUIRED_SCOPE for waiverdb. 2017-11-06 21:01:16 +00:00
Ralph Bean
ce8b4467c7 Remove old waiverdb role. See roles/openshift-apps/waiverdb/ 2017-11-06 20:59:44 +00:00
Ralph Bean
cd36f2d5a0 Remove unnecessary with_items. 2017-11-06 19:45:26 +00:00
Ralph Bean
f6a85adb22 have fedmsg own /usr/share/fedmsg, so it can write its CRL there. 2017-11-06 15:07:37 +00:00
Miroslav Suchý
72e5f19e54 retrace: typo in path 2017-11-06 15:04:23 +01:00
Patrick Uiterwijk
ce99ffc7d9 Sync out delta rpms
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-11-05 08:17:27 +01:00
Patrick Uiterwijk
647c08a47e Re-enable delta rpms for updates
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-11-04 18:24:00 +01:00
Patrick Uiterwijk
f184b79ac6 Fix debuginfo repodata syncing
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-04 17:23:48 +00:00
Kevin Fenzi
e45f763b19 need repos to install fas_clients 2017-11-03 23:01:51 +00:00
Kevin Fenzi
53ff936cb3 make sure bodhi hosts in stg are f26 2017-11-03 22:44:12 +00:00
Patrick Uiterwijk
af6a1915e2 Use new keytabs for secondary kojis
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-03 21:43:53 +00:00
Patrick Uiterwijk
1108230512 Add koji keytab for secondary kojis
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-03 21:22:58 +00:00
mprahl
381bd1b389 Allow overriding rebuild_strategy in MBS in prod 2017-11-03 15:10:55 +00:00
Kevin Fenzi
7ccec4476e and on f25 too 2017-11-03 01:32:06 +00:00
Kevin Fenzi
e7ecd1959d python-argparse went away in f26 2017-11-03 01:22:08 +00:00
Kevin Fenzi
af3ae55bd8 adjust to anoying python to python2 renaming 2017-11-03 01:07:38 +00:00
Kevin Fenzi
5ccc1da6d6 add f26_only jenkins var and install python2/3-koji for pyrpkg 2017-11-03 00:34:22 +00:00
Pierre-Yves Chibon
8e3b71da59 Support msi binaries release in pagure.io
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2017-11-02 19:40:04 +01:00
Kevin Fenzi
149de51ee6 fix typo in resultsdb database publishing script 2017-11-02 16:43:05 +00:00
Michael Simacek
127ecb9134 Make koschei-refresh-group work with current dnf 2017-11-02 16:35:20 +02:00
Julius Milan
9955f3a0d6 faf: add cron job for old db backups removal
Signed-off-by: Miroslav Suchý <msuchy@redhat.com>
2017-11-02 14:52:09 +01:00
Miroslav Suchý
268bc7317d install cron for deleting old archives 2017-11-02 14:41:08 +01:00
mprahl
0a7ebf6c23 Allow overriding the rebuild strategy on MBS stage 2017-11-02 12:24:32 +00:00
Miroslav Suchý
a95d8b2bc7 raise Copr quota for builders in fedora cloud 2017-11-02 08:48:55 +01:00
Ricky Elrod
778dae3492 nb told me to add myself here
Signed-off-by: Ricky Elrod <relrod@redhat.com>
2017-11-02 01:07:10 +00:00
Kevin Fenzi
a022c2ff09 drop -q from purge-amis cron so it works 2017-11-01 18:44:38 +00:00
Stephen Smoogen
9d09e0a79f need more raaaaaammzzzz 2017-11-01 15:41:31 +00:00
Paul W. Frields
bc4d329c58 Add nightly Wordpress update to Magazine
Signed-off-by: Paul W. Frields <stickster@gmail.com>
2017-11-01 12:56:40 +00:00
Kamil Páral
587d280614 taskotron-trigger: run abicheck on all packages
Not just critpath. Apply this also to production.
See: https://pagure.io/taskotron/issue/238
2017-11-01 11:33:17 +01:00
Kamil Páral
858391375b taskotron-trigger: push latest changes to prod
Fixes upgradepath+rpmdeplint scheduling.
2017-11-01 10:35:09 +01:00
Patrick Uiterwijk
b188cef81b Turns out that the subjects: thing is just informational
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-11-01 00:16:39 +00:00
Jeremy Cline
d064359e01 Disable fmn android on stg
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-10-31 21:28:55 +00:00
Jeremy Cline
7b08ff9c88 Remove the apparently unused custom dogpile lock
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-10-31 20:36:47 +00:00
Jeremy Cline
0d1517e203 Make the fmn upgrade playbook work with f26 and fmn-2.0
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-10-31 20:30:57 +00:00
Jeremy Cline
a746737520 Start celerybeat on the staging notif backend
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
2017-10-31 20:21:19 +00:00
Patrick Uiterwijk
bb9d9dc0c8 @bowlofeggs says we'll need these, so let's add gigantic size suffixes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 18:15:12 +00:00
Patrick Uiterwijk
15f41a1943 Define modular dest
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 18:09:23 +00:00
Patrick Uiterwijk
bb7ff3a1d9 Turns out that *iB = 1024.. Thanks @bowlofeggs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 18:05:47 +00:00
Patrick Uiterwijk
268372641d Let us not forget about x86_64
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 18:02:19 +00:00
Kevin Fenzi
99ab131353 need repos to install fas-clients from 2017-10-31 18:01:26 +00:00
Patrick Uiterwijk
50cbc6e1f9 Sync out f27m u-t
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 17:55:57 +00:00
Kevin Fenzi
52780b6b49 move buildvm-armv7-01.stg and buildvm-aarch64-01.stg to f26 2017-10-31 17:51:51 +00:00
Kevin Fenzi
c69c85b9ca switch notifs-backend01.stg to f26 2017-10-31 17:44:57 +00:00
Adam Miller
4055216044 Remove duplicate osbs buildroot handling
We are handling this in the osbs cluster playbook, it's redundant
here.

Signed-off-by: Adam Miller <admiller@redhat.com>
2017-10-31 17:02:46 +00:00
Adam Miller
3bcb923f19 Revert "fix osbs-custom-build role to allow edits for metadata storing in atomic-reactor"
Turns out this wasn't necessary.

This reverts commit f2ba8005c4.
2017-10-31 16:57:23 +00:00
Patrick Uiterwijk
f749d87064 Remove extra /os
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 16:44:16 +00:00
Patrick Uiterwijk
b84350f0e2 Add modular arches
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-31 17:21:05 +01:00
Patrick Uiterwijk
4ac729219c Enable signing of f27-u-t ostrees
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-31 17:20:18 +01:00
Patrick Uiterwijk
f780cdb76f Humanize bytes
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 16:05:53 +00:00
Patrick Uiterwijk
97e133f85b s/download02/download01/g
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 16:02:04 +00:00
Patrick Uiterwijk
aef714c57d Not all errors are correct
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 15:57:32 +00:00
Patrick Uiterwijk
226ab9c341 Use version rather than version_int
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 15:55:09 +00:00
Patrick Uiterwijk
691539faae We need pdc-client for modules
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 15:55:09 +00:00
Josef Skladanka
4ab8b53333 Taskotron Trigger: Ignore fNN-modular- for depcheck/upgradepath 2017-10-31 15:50:57 +01:00
Patrick Uiterwijk
220d5cdeb3 Make the releng-bodhi-backend01 key owned by sysadmin-releng
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 14:47:13 +00:00
Patrick Uiterwijk
16386da998 Staging /mnt/koji must be mounted with nfsv4
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 13:59:46 +00:00
Jan Kaluža
8c2e2d7e20 Ensure the odcs-backend is started after an upgrade 2017-10-31 13:41:34 +00:00
Jan Kaluža
9b716b5b4b Set back to False 2017-10-31 13:23:43 +00:00
Patrick Uiterwijk
eee234510d Use download01.phx2
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 12:37:48 +00:00
Patrick Uiterwijk
738ca55835 Define options for fedora_modular
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 12:36:09 +00:00
Patrick Uiterwijk
9cb785a853 Use the package: module
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 09:29:20 +00:00
Patrick Uiterwijk
60b34a0d32 Use DNF for odcs
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 09:25:27 +00:00
Patrick Uiterwijk
f8d55e697b Infra-tags-stg is always enabled on staging machines
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-31 09:22:40 +00:00
Jan Kaluža
a04b8ff097 Add missing double-quotes 2017-10-31 07:31:22 +00:00
Jan Kaluža
a358ae39f2 Set testing to True when running on staging 2017-10-31 07:25:02 +00:00
Ralph Bean
75e3338501 Try setting header_scheme: true for PDC https links. 2017-10-30 21:02:10 +00:00
Ralph Bean
c3b20a632a Attempt setting SECURE_PROXY_SSL_HEADER on stg PDC. 2017-10-30 20:55:41 +00:00
Ralph Bean
654c94f105 Only one play needs odcs_migrate_db, not all. 2017-10-30 15:05:06 +00:00
Matt Jia
3cc04ae62d greenwave: add missing blacklist key for each policy 2017-10-30 16:12:49 +10:00
Matt Jia
ca280ac4f3 greenwave: fix configmap.yml to make 'oc apply' happy 2017-10-30 16:04:36 +10:00
Matt Jia
c48f91a353 greenwave: new release 0.4 to pick up 2017-10-30 15:44:15 +10:00
Patrick Uiterwijk
d269acd9e9 Fix the name of the 'release' field in new-updates-sync
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-29 10:46:16 +01:00
Patrick Uiterwijk
7f8b1a2005 Remove duplicate fedmsg cert definition
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-29 09:22:49 +00:00
Nick Bebout
629a22835c Update to new badges repo 2017-10-28 23:58:26 +00:00
Patrick Uiterwijk
58fcfbaca2 Remove the namespace from dist-git.conf so namespaced lookaside becomes possible
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-28 01:40:32 +02:00
Patrick Uiterwijk
13cc604141 Ansible keeps adding more fields to _result. Let's just use inclusion rather than exclusion
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-27 23:09:37 +00:00
Patrick Uiterwijk
cd56887767 Only log errors
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 23:59:37 +02:00
Patrick Uiterwijk
d09c212737 RHEL7.4 needs more memory
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-27 21:15:37 +00:00
Patrick Uiterwijk
67e27110d9 Define loopabull01 prod
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-27 20:34:27 +00:00
Patrick Uiterwijk
7f239aa0eb Only allow unsigned rpms in staging
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 21:51:55 +02:00
Patrick Uiterwijk
32ba94008b Rename 'modules' to 'filelists' to not confuse people
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 21:22:11 +02:00
Patrick Uiterwijk
2c61d942b3 Only sync ostrees if refs are updated
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 21:18:18 +02:00
Patrick Uiterwijk
6870c18197 Open this as read, not write
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 21:14:48 +02:00
Patrick Uiterwijk
a411fb57b3 Update ostree summary
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 20:51:32 +02:00
Patrick Uiterwijk
cafa97566d Update cron for new updates sync
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 20:12:38 +02:00
Patrick Uiterwijk
233517cb43 Sync f26-updates ostree out
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 19:39:16 +02:00
Patrick Uiterwijk
3fb8ace963 Update robosignatory paths
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-27 16:10:23 +00:00
Patrick Uiterwijk
7eec48adc6 s/include/import/
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-27 16:08:11 +00:00
Patrick Uiterwijk
b722dc15d5 Also sync ostree's out
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 18:03:48 +02:00
Patrick Uiterwijk
f06165241b Do not call update-fullfiletimelist if there's no modules updated
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 17:46:41 +02:00
Patrick Uiterwijk
e4022c656e Also call updating fullfilelist if needed
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-27 17:39:28 +02:00
Patrick Uiterwijk
f235cec0b6 Add updates/
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 23:57:11 +02:00
Patrick Uiterwijk
7c590d0256 Turns out that koji will not allow us to mount that other thing RW
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-26 21:56:11 +00:00
Patrick Uiterwijk
d5212c311e Update ostree config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-26 21:37:12 +00:00
Ralph Bean
b403eb2d36 Make super sure that fedmsg-hub isn't running on the mbs-frontend. 2017-10-26 14:13:47 +00:00
Patrick Uiterwijk
a427b2974d Deploy new updates sync script
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 13:28:45 +02:00
Patrick Uiterwijk
390cec9bf5 Remove older update push scripts
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 13:26:33 +02:00
Patrick Uiterwijk
03f7710d61 Add el6 for updates sync
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 12:08:07 +02:00
Pierre-Yves Chibon
a199694786 Make pagure use pygments2 explicitely
Got the +1 from Peter and Patrick on IRC, thanks for that!
2017-10-26 11:06:52 +02:00
clime
5598d8dae6 copr-backend: hotfix unavailable infra f26 repos 2017-10-26 08:18:13 +02:00
Patrick Uiterwijk
5d2510f700 Check in initial new-updates-sync
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 04:12:43 +02:00
Patrick Uiterwijk
50ada17ad4 EL6 also has ppc64 and i386
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-26 02:45:51 +02:00
Patrick Uiterwijk
9b9cdd4e2b Fix ostree config
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-25 21:22:05 +02:00
mprahl
4b15a2367b Add https://src.fedoraproject.org/git/modules/ as a valid URL for MBS 2017-10-25 15:21:59 +00:00
Patrick Uiterwijk
2bf80ff028 Set primary arches
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-25 13:07:38 +00:00
Patrick Uiterwijk
9b2bcb5f97 Use base arches
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-25 12:47:20 +00:00
Ralph Bean
052a90bd3a Comment out the abicheck policy, since it should only apply to critpath packages. 2017-10-25 01:07:44 +00:00
Ralph Bean
2a9c33eee3 Unhappy whitespace. 2017-10-25 00:47:33 +00:00
Ralph Bean
44a2cdd777 (greenwave) Borrow abicheck blacklist from taskotron vars. 2017-10-25 00:42:56 +00:00
Ralph Bean
1f77e50178 Try to format this correctly. 2017-10-25 00:34:44 +00:00
Ralph Bean
d5b7f9c993 Move the dist.abicheck blacklist to a group_var. 2017-10-25 00:32:36 +00:00
Patrick Uiterwijk
40b9794e35 Add koji runroot
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-25 00:24:08 +00:00
Adam Williamson
11ccb2c285 Adjust greenwave rawhide sync policy to Basic tests only
This adjusts the `openqa_important_stuff_for_rawhide` Greenwave
policy to include only openQA tests that enforce Basic release
criteria, removing all the tests that enforce Beta or Final
criteria. This matches the intentions expressed in the 'no more
Alphas' Change - we intend to gate Rawhide composes on meeting
the Basic criteria, not Beta or Final.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2017-10-24 17:21:29 -07:00
Patrick Uiterwijk
67786cf8ef Re-enable bodhi-backend for master
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2017-10-25 02:09:12 +02:00
Patrick Uiterwijk
78ee3fa54c Fix atomic path
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-24 23:54:21 +00:00
Patrick Uiterwijk
ba00c00df4 Pungi runs as 'apache'
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-24 22:58:45 +00:00
Patrick Uiterwijk
ffcf265423 Be verbose
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-24 22:21:47 +00:00
Patrick Uiterwijk
dc6e6fd0bb Also compose non-x86_64 repos
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-24 22:21:09 +00:00
Patrick Uiterwijk
494d1498c6 Fix pungi.rpm.conf
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2017-10-24 22:07:03 +00:00
2335 changed files with 53358 additions and 144041 deletions

View File

@@ -131,7 +131,6 @@ This lists all security groups in that tenant:
the output will look like this:
euca-describe-groups | grep GROU
GROUP d4e664a10e2c4210839150be09c46e5e default default
GROUP d4e664a10e2c4210839150be09c46e5e jenkins jenkins instance group
GROUP d4e664a10e2c4210839150be09c46e5e logstash logstash security group
GROUP d4e664a10e2c4210839150be09c46e5e smtpserver list server group. needs web and smtp
GROUP d4e664a10e2c4210839150be09c46e5e webserver webserver security group

1
TODO
View File

@@ -14,4 +14,3 @@
- merge in tasks/playbooks/inventory/etc from:
- builders

View File

@@ -1,7 +1,11 @@
[updates-testing]
name=Fedora $releasever - $basearch - Test Updates
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/$basearch/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/Everything/$basearch/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/$basearch/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -10,7 +14,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-testing-debuginfo]
name=Fedora $releasever - $basearch - Test Updates Debug
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/$basearch/debug/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/Everything/$basearch/debug/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/$basearch/debug/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-debug-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -19,7 +27,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-testing-source]
name=Fedora $releasever - Test Updates Source
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/SRPMS/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/Everything/SRPMS/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/SRPMS/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-source-f$releasever&arch=$basearch
enabled=0
gpgcheck=1

View File

@@ -1,7 +1,11 @@
[updates-testing]
name=Fedora $releasever - $basearch - Test Updates
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/$basearch/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/Everything/$basearch/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/$basearch/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -10,7 +14,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-testing-debuginfo]
name=Fedora $releasever - $basearch - Test Updates Debug
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/$basearch/debug/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/Everything/$basearch/debug/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/$basearch/debug/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-debug-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -19,7 +27,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-testing-source]
name=Fedora $releasever - Test Updates Source
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/SRPMS/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/Everything/SRPMS/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/SRPMS/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-source-f$releasever&arch=$basearch
enabled=0
gpgcheck=1

View File

@@ -1,7 +1,11 @@
[updates]
name=Fedora $releasever - $basearch - Updates
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/$basearch/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/Everything/$basearch/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/$basearch/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-f$releasever&arch=$basearch
enabled=1
gpgcheck=1
@@ -10,7 +14,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-debuginfo]
name=Fedora $releasever - $basearch - Updates - Debug
failovermethod=priority
{% if ansible_distribution_major_version|int >27 %}
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/Everything/$basearch/debug/
{% else %}
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/$basearch/debug/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-debug-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -19,7 +27,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-source]
name=Fedora $releasever - Updates Source
failovermethod=priority
{% if ansible_distribution_major_version|int >27 %}
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/Everything/SRPMS/
{% else %}
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/updates/$releasever/SRPMS/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-source-f$releasever&arch=$basearch
enabled=0
gpgcheck=1

View File

@@ -1,7 +1,11 @@
[updates]
name=Fedora $releasever - $basearch - Updates
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/$basearch/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/Everything/$basearch/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/$basearch/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-f$releasever&arch=$basearch
enabled=1
gpgcheck=1
@@ -10,7 +14,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-debuginfo]
name=Fedora $releasever - $basearch - Updates - Debug
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/$basearch/debug/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/Everything/$basearch/debug/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/$basearch/debug/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-debug-f$releasever&arch=$basearch
enabled=0
gpgcheck=1
@@ -19,7 +27,11 @@ gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[updates-source]
name=Fedora $releasever - Updates Source
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/SRPMS/
{% if ansible_distribution_major_version|int >27 %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/SRPMS/
{% else %}
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/updates/$releasever/Everything/SRPMS/
{% endif %}
#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-source-f$releasever&arch=$basearch
enabled=0
gpgcheck=1

View File

@@ -1,11 +1,11 @@
[fedora]
name=Fedora $releasever - $basearch
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora/linux/releases/$releasever/Everything/$basearch/os/
baseurl=https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/$releasever/Everything/$basearch/os/
#metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch
enabled=1
metadata_expire=7d
gpgcheck=0
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[fedora-debuginfo]

View File

@@ -1,11 +1,11 @@
[fedora]
name=Fedora $releasever - $basearch
failovermethod=priority
baseurl=http://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/$releasever/Everything/$basearch/os/
baseurl=https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/$releasever/Everything/$basearch/os/
#metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch
enabled=1
metadata_expire=7d
gpgcheck=0
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
[fedora-debuginfo]

View File

@@ -1,4 +1,13 @@
[rhel7-aarch64-server]
name = rhel7 $basearch server
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-server-rpms
[rhel-7-alt-for-arm-64-optional-rpms]
name = rhel7 $basearch server optional
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-alt-for-arm-64-optional-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel-7-alt-for-arm-64-rpms]
name = rhel7 $basearch server
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-alt-for-arm-64-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1

View File

@@ -68,44 +68,44 @@ defaults
frontend neutron
bind 0.0.0.0:9696 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend neutron
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend cinder
bind 0.0.0.0:8776 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend cinder
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend swift
bind 0.0.0.0:8080 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend swift
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend nova
bind 0.0.0.0:8774 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend nova
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend ceilometer
bind 0.0.0.0:8777 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend ceilometer
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend ec2
bind 0.0.0.0:8773 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend ec2
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
frontend glance
bind 0.0.0.0:9292 ssl no-sslv3 no-tlsv10 crt /etc/haproxy/fedorainfracloud.org.combined
default_backend glance
# HSTS (15768000 seconds = 6 months)
rspadd Strict-Transport-Security:\ max-age=15768000
# HSTS (31536000 seconds = 365 days)
rspadd Strict-Transport-Security:\ max-age=31536000
backend neutron
server neutron 127.0.0.1:8696 check

View File

@@ -48,7 +48,6 @@ class AutoCloudConsumer(fedmsg.consumers.FedmsgConsumer):
log.info('Received %r %r' % (msg['topic'], msg['body']['msg_id']))
STATUS_F = ('FINISHED_INCOMPLETE', 'FINISHED',)
VARIANTS_F = ('CloudImages',)
images = []
compose_db_update = False
@@ -56,6 +55,16 @@ class AutoCloudConsumer(fedmsg.consumers.FedmsgConsumer):
status = msg_body['msg']['status']
compose_images_json = None
# Till F27, both cloud-base and atomic images were available
# under variant CloudImages. With F28 and onward releases,
# cloud-base image compose moved to cloud variant and atomic images
# moved under atomic variant.
prev_rel = ['26', '27']
if msg_body['msg']['release_version'] in prev_rel:
VARIANTS_F = ('CloudImages',)
else:
VARIANTS_F = ('AtomicHost', 'Cloud')
if status in STATUS_F:
location = msg_body['msg']['location']
json_metadata = '{}/metadata/images.json'.format(location)

View File

@@ -2,4 +2,13 @@ ExtendedStatus on
<Location /apache-status>
SetHandler server-status
<IfModule mod_authz_core.c>
# Apache 2.4
<RequireAny>
Require ip 127.0.0.1
Require ip ::1
Require host localhost
Require valid-user
</RequireAny>
</IfModule>
</Location>

View File

@@ -237,6 +237,15 @@ RewriteRule ^/pki/p/k/pki/(.*) https://releases.pagure.org/dogtagpki/$1 [L,R]
RewriteRule ^/pki/p/k/pki https://releases.pagure.org/dogtagpki/ [L,R]
RewriteRule ^/pki https://pagure.io/dogtagpki [R=301]
RewriteRule ^/generic-logos/ https://pagure.io/generic-logos/ [R=301]
RewriteRule ^/generic-logos https://pagure.io/generic-logos/ [R=301]
RewriteRule ^/released/generic-logos/(.*) https://releases.pagure.org/generic-logos/$1 [R=301]
RewriteRule ^/released/generic-logos https://releases.pagure.org/generic-logos/ [R=301]
RewriteRule ^/beakerlib/wiki/Manual https://github.com/beakerlib/beakerlib/wiki/man [R=301]
RewriteRule ^/beakerlib/wiki/(.*) https://github.com/beakerlib/beakerlib/wiki/$1 [R=301]
RewriteRule ^/beakerlib/(.*) https://github.com/beakerlib/beakerlib/ [R=301]
# Ipsilon wiki is now moving content
ReWriteCond %{REQUEST_URI} !^/ipsilon/.*

1
files/httpd/h2.conf.j2 Normal file
View File

@@ -0,0 +1 @@
Protocols h2 {% if not inventory_hostname.startswith('proxy') %} h2c {% endif %} http/1.1

View File

@@ -1,3 +1,7 @@
Header set AppTime "%D"
PassEnv HOSTNAME
Header set AppServer "{{ inventory_hostname }}"
{% if inventory_hostname in groups['proxies'] and ansible_distribution == 'Fedora' %}
ErrorDocument 421 "You have hit an incorrect proxy for a Fedora Project website due to a bug in Firefox. Please refresh"
{% endif %}

View File

@@ -1,22 +1,31 @@
[rhel7-openshift-3.4]
name = rhel7 openshift 3.4 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.4-rpms/
{% if env == "staging" %}
[rhel7-openshift-3.9]
name = rhel7 openshift 3.9 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.9-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
[rhel7-openshift-3.5]
name = rhel7 openshift 3.5 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.5-rpms/
# 3.8 is needed to upgrade from 3.7 to 3.9
[rhel7-openshift-3.8]
name = rhel7 openshift 3.8 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.8-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
{% if env == 'staging' %}
[rhel7-openshift-3.7]
name = rhel7 openshift 3.7 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.7-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=0
{% else %}
[rhel7-openshift-3.6]
name = rhel7 openshift 3.6 $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-openshift-3.6-rpms/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
{% endif %}
# OpenShift 3.6 needs this for new openvswitch
[rhel7-fast-datapath]
name = rhel7 fast datapath $basearch
baseurl=http://infrastructure.fedoraproject.org/repo/rhel/rhel7/$basearch/rhel-7-fast-datapath/
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
{% endif %}

View File

@@ -1,7 +1,9 @@
FROM registry.fedoraproject.org/fedora
ADD ./infra-tags.repo /etc/yum.repos.d/infra-tags.repo
RUN dnf -y install --refresh dnf-plugins-core && dnf -y install docker git python-setuptools e2fsprogs koji python-backports-lzma osbs-client python-osbs-client gssproxy fedpkg python-docker-squash atomic-reactor python-atomic-reactor* go-md2man
RUN sed -i 's|.*default_ccache_name.*| default_ccache_name = DIR:/tmp/ccache_%{uid}|g' /etc/krb5.conf
RUN dnf -y install --refresh python2-productmd python3-productmd libmodulemd python2-gobject python3-gobject python2-modulemd python3-modulemd python2-pdc-client python3-pdc-client
ADD ./krb5.conf /etc
RUN printf '[libdefaults]\n default_ccache_name = DIR:/tmp/ccache_%%{uid}' >/etc/krb5.conf.d/ccache.conf
ADD ./krb5.osbs_{{osbs_url}}.keytab /etc/
ADD ./ca.crt /etc/pki/ca-trust/source/anchors/osbs.ca.crt
RUN update-ca-trust

View File

@@ -1,8 +1,10 @@
FROM registry.fedoraproject.org/fedora
ADD ./infra-tags.repo /etc/yum.repos.d/infra-tags.repo
RUN dnf -y install --refresh dnf-plugins-core && dnf -y install docker git python3-docker-py python3-setuptools e2fsprogs koji osbs-client gssproxy fedpkg python3-docker-squash atomic-reactor python3-atomic-reactor* go-md2man
RUN sed -i 's|.*default_ccache_name.*| default_ccache_name = DIR:/tmp/ccache_%{uid}|g' /etc/krb5.conf
RUN dnf -y install --refresh dnf-plugins-core && dnf -y install docker git python-setuptools e2fsprogs koji python-backports-lzma osbs-client python-osbs-client gssproxy fedpkg python-docker-squash atomic-reactor python-atomic-reactor* go-md2man
ADD ./krb5.conf /etc
RUN printf '[libdefaults]\n default_ccache_name = DIR:/tmp/ccache_%%{uid}' >/etc/krb5.conf.d/ccache.conf
ADD ./krb5.osbs_{{osbs_url}}.keytab /etc/
ADD ./ca.crt /etc/pki/ca-trust/source/anchors/osbs.ca.crt
RUN update-ca-trust
CMD ["python3", "/usr/bin/atomic-reactor", "--verbose", "inside-build"]
CMD ["python2", "/usr/bin/atomic-reactor", "--verbose", "inside-build"]

View File

@@ -0,0 +1,2 @@
[Service]
ExecStartPost=/usr/local/bin/fix-docker-iptables

View File

@@ -1,32 +0,0 @@
[Unit]
Description=Docker Application Container Engine
Documentation=http://docs.docker.com
After=network.target
Wants=docker-storage-setup.service
[Service]
Type=notify
NotifyAccess=all
EnvironmentFile=-/etc/sysconfig/docker
EnvironmentFile=-/etc/sysconfig/docker-storage
EnvironmentFile=-/etc/sysconfig/docker-network
Environment=GOTRACEBACK=crash
ExecStart=/usr/bin/docker daemon \
--exec-opt native.cgroupdriver=systemd \
$OPTIONS \
$DOCKER_STORAGE_OPTIONS \
$DOCKER_NETWORK_OPTIONS \
$INSECURE_REGISTRY
ExecStartPost=/usr/local/bin/fix-docker-iptables
LimitNOFILE=1048576
LimitNPROC=1048576
LimitCORE=infinity
MountFlags=slave
StandardOutput=null
StandardError=null
TimeoutStartSec=0
Restart=on-abnormal
[Install]
WantedBy=multi-user.target

View File

@@ -49,6 +49,9 @@ iptables -A FILTER_FORWARD -p udp -m udp -d 10.5.126.22 --dport 53 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.51 --dport 443 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.52 --dport 443 -j ACCEPT
# infrastructure.fp.o (infra repos)
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.23 --dport 443 -j ACCEPT
# Kerberos
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.51 --dport 1088 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.52 --dport 1088 -j ACCEPT

View File

@@ -53,6 +53,9 @@ iptables -A FILTER_FORWARD -p udp -m udp -d 10.5.126.22 --dport 53 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.51 --dport 443 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.52 --dport 443 -j ACCEPT
# infrastructure.fp.o (infra repos)
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.23 --dport 443 -j ACCEPT
# dl.phx2
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.93 --dport 80 -j ACCEPT
iptables -A FILTER_FORWARD -p tcp -m tcp -d 10.5.126.93 --dport 443 -j ACCEPT

4
files/releng/relengpush Executable file
View File

@@ -0,0 +1,4 @@
#!/bin/bash
# This file exists to facilitate fully automated mass rebuilds without relying
# on user intervention or an individual users's account permissions
sudo /usr/local/bin/relengpush-int $@

4
files/releng/relengpush-int Executable file
View File

@@ -0,0 +1,4 @@
#!/bin/bash
# This file exists to facilitate fully automated mass rebuilds without relying
# on user intervention or an individual users's account permissions
ssh -i /etc/pki/releng $@

View File

@@ -0,0 +1,7 @@
#!/bin/bash
ping6 -q -c 1 -w 2 2600:: >& /dev/null
if [ $? -ne 0 ];
then
nmcli c up eth0 >& /dev/null
fi

View File

@@ -0,0 +1 @@
* * * * * root /usr/local/bin/restart-broken-ipv6

View File

@@ -9,7 +9,7 @@ def invert_fedmsg_policy(groups, vars, env):
"""
if env == 'staging':
hosts = groups['staging'] + groups['fedmsg-qa-network-stg'] + groups['openshift-pseudohosts-stg']
hosts = groups['all'] + groups['staging'] + groups['fedmsg-qa-network-stg'] + groups['openshift-pseudohosts-stg']
else:
hosts = [h for h in groups['all'] if h not in groups['staging'] + groups['openshift-pseudohosts-stg']]

View File

@@ -15,20 +15,20 @@
action: service name=crond state=restarted
- name: restart fedmsg-gateway
command: /usr/local/bin/conditional-restart.sh fedmsg-gateway fedmsg-gateway
command: /usr/local/bin/conditional-restart.sh fedmsg-gateway
- name: restart fedmsg-hub
command: /usr/local/bin/conditional-restart.sh fedmsg-hub fedmsg-hub
command: /usr/local/bin/conditional-restart.sh fedmsg-hub
# Note that, we're cool with arbitrary restarts on bodhi-backend02, just
# not bodhi-backend01 or bodhi-backend03. 01 and 03 is where the releng/mash
# not bodhi-backend01 or bodhi-backend03. 01 and 03 is where the releng/mash
# stuff happens and we # don't want to interrupt that.
when: inventory_hostname not in ['bodhi-backend01.phx2.fedoraproject.org', 'bodhi-backend03.phx2.fedoraproject.org']
- name: restart fedmsg-irc
command: /usr/local/bin/conditional-restart.sh fedmsg-irc fedmsg-irc
command: /usr/local/bin/conditional-restart.sh fedmsg-irc
- name: restart fedmsg-relay
command: /usr/local/bin/conditional-restart.sh fedmsg-relay fedmsg-relay
command: /usr/local/bin/conditional-restart.sh fedmsg-relay
- name: restart koji-sync-listener
action: service name=koji-sync-listener state=restarted
@@ -42,9 +42,6 @@
- name: restart ip6tables
action: service name=ip6tables state=restarted
- name: restart jenkins
action: service name=jenkins state=restarted
- name: restart libvirtd
action: service name=libvirtd state=restarted
@@ -177,6 +174,5 @@
- name: restart idmapd
service: name=nfs-idmapd state=restarted
- name: restart darkserver
service: name=darkserver state=restarted
- name: restart buildmaster
service: name=buildmaster state=restarted

View File

@@ -13,6 +13,7 @@ people02.fedoraproject.org
pkgs02.phx2.fedoraproject.org
log01.phx2.fedoraproject.org
db-qa01.qa.fedoraproject.org
db-qa02.qa.fedoraproject.org
db-koji01.phx2.fedoraproject.org
#copr-be.cloud.fedoraproject.org
copr-fe.cloud.fedoraproject.org

View File

@@ -51,6 +51,9 @@ buildvm-aarch64-01.stg.arm.fedoraproject.org
[buildvm-armv7-stg]
buildvm-armv7-01.stg.arm.fedoraproject.org
[buildvm-s390x-stg]
buildvm-s390x-01.stg.s390.fedoraproject.org
[buildvm-aarch64]
buildvm-aarch64-01.arm.fedoraproject.org
buildvm-aarch64-02.arm.fedoraproject.org
@@ -68,7 +71,6 @@ buildvm-aarch64-13.arm.fedoraproject.org
buildvm-aarch64-14.arm.fedoraproject.org
buildvm-aarch64-15.arm.fedoraproject.org
buildvm-aarch64-16.arm.fedoraproject.org
# these vm's are too slow to use, cause still under investigation
#buildvm-aarch64-17.arm.fedoraproject.org
buildvm-aarch64-18.arm.fedoraproject.org
buildvm-aarch64-19.arm.fedoraproject.org
@@ -95,7 +97,6 @@ buildvm-armv7-13.arm.fedoraproject.org
buildvm-armv7-14.arm.fedoraproject.org
buildvm-armv7-15.arm.fedoraproject.org
buildvm-armv7-16.arm.fedoraproject.org
# these vm's are too slow to use, cause still under investigation
#buildvm-armv7-17.arm.fedoraproject.org
buildvm-armv7-18.arm.fedoraproject.org
buildvm-armv7-19.arm.fedoraproject.org
@@ -123,7 +124,6 @@ buildvm-s390x-11.s390.fedoraproject.org
buildvm-s390x-12.s390.fedoraproject.org
buildvm-s390x-13.s390.fedoraproject.org
buildvm-s390x-14.s390.fedoraproject.org
buildvm-s390x-15.s390.fedoraproject.org
[buildvmhost]
buildvmhost-01.phx2.fedoraproject.org
@@ -151,7 +151,8 @@ aarch64-c13n1.arm.fedoraproject.org
aarch64-c14n1.arm.fedoraproject.org
aarch64-c15n1.arm.fedoraproject.org
aarch64-c16n1.arm.fedoraproject.org
aarch64-c17n1.arm.fedoraproject.org
# HP cannot seem to get this cart working.
#aarch64-c17n1.arm.fedoraproject.org
aarch64-c18n1.arm.fedoraproject.org
aarch64-c19n1.arm.fedoraproject.org
aarch64-c20n1.arm.fedoraproject.org
@@ -177,6 +178,14 @@ buildhw-10.phx2.fedoraproject.org
buildhw-aarch64-01.arm.fedoraproject.org
buildhw-aarch64-02.arm.fedoraproject.org
buildhw-aarch64-03.arm.fedoraproject.org
buildhw-aarch64-04.arm.fedoraproject.org
buildhw-aarch64-05.arm.fedoraproject.org
buildhw-aarch64-06.arm.fedoraproject.org
buildhw-aarch64-07.arm.fedoraproject.org
buildhw-aarch64-08.arm.fedoraproject.org
# Machine unresponsive, likely dead
#buildhw-aarch64-09.arm.fedoraproject.org
buildhw-aarch64-10.arm.fedoraproject.org
#
# These are primary koji builders.
@@ -195,6 +204,12 @@ buildvm-ppc64-10.ppc.fedoraproject.org
buildvm-ppc64-11.ppc.fedoraproject.org
buildvm-ppc64-12.ppc.fedoraproject.org
buildvm-ppc64-13.ppc.fedoraproject.org
buildvm-ppc64-14.ppc.fedoraproject.org
buildvm-ppc64-15.ppc.fedoraproject.org
buildvm-ppc64-16.ppc.fedoraproject.org
buildvm-ppc64-17.ppc.fedoraproject.org
buildvm-ppc64-18.ppc.fedoraproject.org
buildvm-ppc64-19.ppc.fedoraproject.org
#
# These are primary koji builders.
@@ -213,33 +228,12 @@ buildvm-ppc64le-10.ppc.fedoraproject.org
buildvm-ppc64le-11.ppc.fedoraproject.org
buildvm-ppc64le-12.ppc.fedoraproject.org
buildvm-ppc64le-13.ppc.fedoraproject.org
#
# These are secondary arch builders.
#
[buildppc]
buildppc-01.ppc.fedoraproject.org
buildppc-02.ppc.fedoraproject.org
buildppc-03.ppc.fedoraproject.org
buildppc-04.ppc.fedoraproject.org
#
# These are secondary arch builders.
#
[buildppcle]
buildppcle-01.ppc.fedoraproject.org
buildppcle-02.ppc.fedoraproject.org
buildppcle-03.ppc.fedoraproject.org
buildppcle-04.ppc.fedoraproject.org
[buildaarch64]
aarch64-02a.arm.fedoraproject.org
# Marked DEAD in pdu
#aarch64-03a.arm.fedoraproject.org
aarch64-04a.arm.fedoraproject.org
aarch64-05a.arm.fedoraproject.org
aarch64-06a.arm.fedoraproject.org
aarch64-07a.arm.fedoraproject.org
buildvm-ppc64le-14.ppc.fedoraproject.org
buildvm-ppc64le-15.ppc.fedoraproject.org
buildvm-ppc64le-16.ppc.fedoraproject.org
buildvm-ppc64le-17.ppc.fedoraproject.org
buildvm-ppc64le-18.ppc.fedoraproject.org
buildvm-ppc64le-19.ppc.fedoraproject.org
[bkernel]
bkernel01.phx2.fedoraproject.org
@@ -285,17 +279,21 @@ buildvm-01.stg.phx2.fedoraproject.org
buildvm-02.stg.phx2.fedoraproject.org
buildvm-01.phx2.fedoraproject.org
buildhw-01.phx2.fedoraproject.org
buildvm-aarch64-01.stg.arm.fedoraproject.org
buildvm-aarch64-01.arm.fedoraproject.org
buildvm-aarch64-02.arm.fedoraproject.org
buildvm-armv7-01.stg.arm.fedoraproject.org
buildvm-armv7-01.arm.fedoraproject.org
buildvm-armv7-02.arm.fedoraproject.org
buildvm-armv7-03.arm.fedoraproject.org
aarch64-02a.arm.fedoraproject.org
buildvm-ppc64-01.stg.ppc.fedoraproject.org
buildvm-ppc64-01.ppc.fedoraproject.org
buildvm-ppc64-02.ppc.fedoraproject.org
buildvm-ppc64le-01.stg.ppc.fedoraproject.org
buildvm-ppc64le-01.ppc.fedoraproject.org
buildvm-ppc64le-02.ppc.fedoraproject.org
buildvm-s390x-01.s390.fedoraproject.org
buildvm-s390x-01.stg.s390.fedoraproject.org
[builders:children]
buildhw
@@ -304,9 +302,6 @@ buildvm-aarch64
buildvm-armv7
buildvm-ppc64
buildvm-ppc64le
buildppc
buildppcle
buildaarch64
buildvm-s390
buildvm-s390x
bkernel
@@ -317,3 +312,4 @@ buildvm-ppc64-stg
buildvm-ppc64le-stg
buildvm-aarch64-stg
buildvm-armv7-stg
buildvm-s390x-stg

View File

@@ -16,14 +16,14 @@ copr-fe.cloud.fedoraproject.org
copr-fe-dev.cloud.fedoraproject.org
copr-keygen.cloud.fedoraproject.org
copr-keygen-dev.cloud.fedoraproject.org
darkserver-dev.fedorainfracloud.org
developer.fedorainfracloud.org
eclipse.fedorainfracloud.org
elastic-dev.fedorainfracloud.org
el6-test.fedorainfracloud.org
el7-test.fedorainfracloud.org
f25-test.fedorainfracloud.org
f26-test.fedorainfracloud.org
f27-test.fedorainfracloud.org
f28-test.fedorainfracloud.org
faitout.fedorainfracloud.org
fas2-dev.fedorainfracloud.org
fas3-dev.fedorainfracloud.org
@@ -48,21 +48,13 @@ fed-cloud-ppc02.cloud.fedoraproject.org
fedimg-dev.fedorainfracloud.org
fedora-bootstrap.fedorainfracloud.org
glittergallery-dev.fedorainfracloud.org
grafana.cloud.fedoraproject.org
graphite.fedorainfracloud.org
hubs-dev.fedorainfracloud.org
iddev.fedorainfracloud.org
insim.fedorainfracloud.org
java-deptools.fedorainfracloud.org
jenkins.fedorainfracloud.org
jenkins-slave-el6.fedorainfracloud.org
jenkins-slave-el7.fedorainfracloud.org
jenkins-slave-f26.fedorainfracloud.org
jenkins-slave-f25.fedorainfracloud.org
jenkins-slave-f25-ppc64le.fedorainfracloud.org
simple-koji-ci-dev.fedorainfracloud.org
simple-koji-ci-prod.fedorainfracloud.org
lists-dev.fedorainfracloud.org
magazine2.fedorainfracloud.org
modernpaste.fedorainfracloud.org
modularity.fedorainfracloud.org
modularity2.fedorainfracloud.org
ppc64le-test.fedorainfracloud.org
@@ -73,13 +65,12 @@ respins.fedorainfracloud.org
shumgrepper-dev.fedorainfracloud.org
taiga.fedorainfracloud.org
taigastg.fedorainfracloud.org
telegram-irc.fedorainfracloud.org
testdays.fedorainfracloud.org
twisted-fedora24-1.fedorainfracloud.org
twisted-fedora24-2.fedorainfracloud.org
twisted-fedora25-1.fedorainfracloud.org
twisted-fedora25-2.fedorainfracloud.org
twisted-fedora26-1.fedorainfracloud.org
twisted-fedora26-2.fedorainfracloud.org
twisted-fedora27-1.fedorainfracloud.org
twisted-fedora27-2.fedorainfracloud.org
twisted-rhel7-1.fedorainfracloud.org
twisted-rhel7-2.fedorainfracloud.org
upstreamfirst.fedorainfracloud.org

View File

@@ -42,6 +42,7 @@ use_default_epel: true
udp_ports: []
tcp_ports: []
custom_rules: []
nat_rules: []
custom6_rules: []
# defaults for virt installs
@@ -60,6 +61,8 @@ br0_nm: 255.255.255.0
br1_nm: 255.255.255.0
# Default to managing the network, we want to not do this on select hosts (like cloud nodes)
ansible_ifcfg_blacklist: false
# List of interfaces to explicitly disable
ansible_ifcfg_disabled: []
#
# The default virt-install works for rhel7 or fedora with 1 nic
#
@@ -76,7 +79,7 @@ virt_install_command_one_nic: virt-install -n {{ inventory_hostname }}
hostname={{ inventory_hostname }} nameserver={{ dns }}
ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none'
--network bridge={{ main_bridge }},model=virtio
--autostart --noautoconsole --watchdog default
--autostart --noautoconsole --watchdog default --rng /dev/random --cpu host
virt_install_command_two_nic: virt-install -n {{ inventory_hostname }}
--memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio
@@ -87,7 +90,7 @@ virt_install_command_two_nic: virt-install -n {{ inventory_hostname }}
ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none
ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname }}-nfs:eth1:none'
--network bridge={{ main_bridge }},model=virtio --network=bridge={{ nfs_bridge }},model=virtio
--autostart --noautoconsole --watchdog default
--autostart --noautoconsole --watchdog default --rng /dev/random
virt_install_command_aarch64_one_nic: virt-install -n {{ inventory_hostname }}
--memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio
@@ -97,7 +100,7 @@ virt_install_command_aarch64_one_nic: virt-install -n {{ inventory_hostname }}
hostname={{ inventory_hostname }} nameserver={{ dns }}
ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none'
--network bridge={{ main_bridge }},model=virtio
--autostart --noautoconsole
--autostart --noautoconsole --rng /dev/random
virt_install_command_aarch64_two_nic: virt-install -n {{ inventory_hostname }}
--memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio
@@ -108,7 +111,7 @@ virt_install_command_aarch64_two_nic: virt-install -n {{ inventory_hostname }}
ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none
ip={{ eth1_ip }}:::{{ nm }}:{{ inventory_hostname }}-nfs:eth1:none'
--network bridge={{ main_bridge }},model=virtio --network=bridge={{ nfs_bridge }},model=virtio
--autostart --noautoconsole
--autostart --noautoconsole --rng /dev/random
virt_install_command_armv7_one_nic: virt-install -n {{ inventory_hostname }} --arch armv7l
--memory={{ mem_size }},maxmemory={{ max_mem_size }} --memballoon virtio
@@ -118,7 +121,7 @@ virt_install_command_armv7_one_nic: virt-install -n {{ inventory_hostname }} --a
hostname={{ inventory_hostname }} nameserver={{ dns }}
ip={{ eth0_ip }}::{{ gw }}:{{ nm }}:{{ inventory_hostname }}:eth0:none'
--network bridge={{ main_bridge }},model=virtio
--autostart --noautoconsole
--autostart --noautoconsole --rng /dev/random
virt_install_command_rhel6: virt-install -n {{ inventory_hostname }}
--memory={{ mem_size }},maxmemory={{ max_mem_size }}
@@ -262,6 +265,7 @@ nagios_Check_Services:
dhcpd: false
httpd: false
swap: true
ping: true
# Set variable if we want to use our global iptables defaults
# Some things need to set their own.
@@ -272,3 +276,6 @@ baseiptables: True
nm_controlled_resolv: False
dns1: "10.5.126.21"
dns2: "10.5.126.22"
# This is a list of services that need to wait for VPN to be up before getting started.
postvpnservices: []

View File

@@ -1,54 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 2048
num_cpus: 2
tcp_ports: [ 80, 443,
# This port is required by gluster
6996,
# These 12 ports are used by fedmsg. One for each wsgi thread.
3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007, 3008, 3009, 30010, 3011, 3012]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice,sysadmin-veteran
freezes: false
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:
- service: shell
owner: root
group: sysadmin
can_send:
- logger.log
- service: askbot
owner: root
group: apache
can_send:
- askbot.post.delete
- askbot.post.edit
- askbot.post.flag_offensive.add
- askbot.post.flag_offensive.delete
- askbot.tag.update
virt_install_command: "{{ virt_install_command_rhel6 }}"
# For the MOTD
csi_security_category: Low
csi_primary_contact: Fedora admins - admin@fedoraproject.org
csi_purpose: Run the django webapp for ask.fedoraproject.org
csi_relationship: |
This depends on:
- The database server on db01.
- memcached (specifically memcached02), but only in production. In staging,
a local-memory backend is used instead.
Gotchas:
- The packages for celery are installed, but we do not actually run or
depend on the celery daemon.
- There are *lots* of hotfixes in effect on this machine.

View File

@@ -1,54 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 2048
num_cpus: 2
tcp_ports: [ 80, 443,
# This port is required by gluster
6996,
# These 8 ports are used by fedmsg. One for each wsgi thread.
3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice,sysadmin-veteran
freezes: false
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:
- service: shell
owner: root
group: sysadmin
can_send:
- logger.log
- service: askbot
owner: root
group: apache
can_send:
- askbot.post.delete
- askbot.post.edit
- askbot.post.flag_offensive.add
- askbot.post.flag_offensive.delete
- askbot.tag.update
virt_install_command: "{{ virt_install_command_rhel6 }}"
# For the MOTD
csi_security_category: Low
csi_primary_contact: Fedora admins - admin@fedoraproject.org
csi_purpose: Run the django webapp for ask.fedoraproject.org
csi_relationship: |
This depends on:
- The database server on db01.
- memcached (specifically memcached02), but only in production. In staging,
a local-memory backend is used instead.
Gotchas:
- The packages for celery are installed, but we do not actually run or
depend on the celery daemon.
- There are *lots* of hotfixes in effect on this machine.

View File

@@ -14,6 +14,8 @@ tcp_ports: [
fas_client_groups: sysadmin-noc,sysadmin-fedimg,sysadmin-releng,sysadmin-veteran
fedmsg_debug_loopback: True
# These people get told when something goes wrong.
fedmsg_error_recipients:
- sysadmin-fedimg-members@fedoraproject.org

View File

@@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 1024
mem_size: 4096
num_cpus: 2
# for systems that do not match the above - specify the same parameter in

View File

@@ -23,7 +23,7 @@ custom_rules: [
# TODO - remove modularity-wg membership here once it is not longer needed:
# https://fedorahosted.org/fedora-infrastructure/ticket/5363
fas_client_groups: sysadmin-ask,sysadmin-web,sysadmin-main,sysadmin-cvs,sysadmin-build,sysadmin-noc,sysadmin-releng,sysadmin-dba,sysadmin-hosted,sysadmin-tools,sysadmin-spin,sysadmin-cloud,fi-apprentice,sysadmin-darkserver,sysadmin-badges,sysadmin-troubleshoot,sysadmin-qa,sysadmin-centos,sysadmin-ppc,sysadmin-koschei,sysadmin-secondary,sysadmin-fedimg,sysadmin-veteran,sysadmin-mbs,modularity-wg,pungi-devel
fas_client_groups: sysadmin-ask,sysadmin-atomic,sysadmin-web,sysadmin-main,sysadmin-cvs,sysadmin-build,sysadmin-noc,sysadmin-releng,sysadmin-dba,sysadmin-hosted,sysadmin-tools,sysadmin-spin,sysadmin-cloud,fi-apprentice,sysadmin-badges,sysadmin-troubleshoot,sysadmin-qa,sysadmin-centos,sysadmin-ppc,sysadmin-koschei,sysadmin-secondary,sysadmin-fedimg,sysadmin-veteran,sysadmin-mbs,modularity-wg,pungi-devel
#
# This is a postfix gateway. This will pick up gateway postfix config in base

View File

@@ -8,7 +8,7 @@ tcp_ports: [ 80, 443 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-ask,sysadmin-build,sysadmin-cvs,sysadmin-main,sysadmin-web,sysadmin-noc,sysadmin-hosted,sysadmin-releng,sysadmin-qa,sysadmin-tools,sysadmin-cloud,sysadmin-bot,sysadmin-centos,sysadmin-koschei,sysadmin-datanommer,sysadmin-fedimg,fi-apprentice,sysadmin-regcfp,sysadmin-badges,sysadmin-mbs,sysadmin-veteran
fas_client_groups: sysadmin-ask,sysadmin-atomic,sysadmin-build,sysadmin-cvs,sysadmin-main,sysadmin-web,sysadmin-noc,sysadmin-hosted,sysadmin-releng,sysadmin-qa,sysadmin-tools,sysadmin-cloud,sysadmin-bot,sysadmin-centos,sysadmin-koschei,sysadmin-datanommer,sysadmin-fedimg,fi-apprentice,sysadmin-regcfp,sysadmin-badges,sysadmin-mbs,sysadmin-veteran
ansible_base: /srv/web/infra
freezes: false

View File

@@ -68,6 +68,9 @@ fedmsg_certs:
- bodhi.update.eject
- bodhi.update.complete.testing
- bodhi.update.complete.stable
- bodhi.update.request.testing
- bodhi.update.request.stable
- bodhi.update.request.batched
- bodhi.buildroot_override.untag
- service: ftpsync
owner: root

View File

@@ -60,6 +60,7 @@ fedmsg_certs:
- bodhi.update.request.revoke
- bodhi.update.request.stable
- bodhi.update.request.testing
- bodhi.update.request.batched
- bodhi.update.request.unpush
# Things that only the mash does - not the web UI

View File

@@ -5,8 +5,8 @@ lvm_size: 262144
mem_size: 15360
max_mem_size: "{{ mem_size }}"
num_cpus: 6
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/26/Server/x86_64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/28/Server/x86_64/os/
nm: 255.255.255.0
gw: 10.5.125.254
eth1_gw: 10.5.127.254

View File

@@ -6,16 +6,13 @@ mem_size: 24576
max_mem_size: "{{ mem_size }}"
num_cpus: 4
max_cpu: "{{ num_cpus }}"
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-aarch64
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/26/Everything/aarch64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-aarch64
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/28/Server/aarch64/os/
nm: 255.255.255.0
gw: 10.5.129.254
dns: 10.5.126.21
# This is reverted so that eth1 gets br0 and eth0 gets br1
# This seems some kind of bug where in the guest kernel the devices are swapped around
# when compared to the host.
main_bridge: br1
nfs_bridge: br0
main_bridge: br0
nfs_bridge: br1
virt_install_command: "{{ virt_install_command_aarch64_two_nic }}"
# for systems that do not match the above - specify the same parameter in

View File

@@ -5,8 +5,8 @@ lvm_size: 150000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-25
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/25/Server/x86_64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-aarch64
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/28/Server/aarch64/os/
nm: 255.255.255.0
gw: 10.5.126.254
dns: 10.5.126.21
@@ -46,4 +46,4 @@ docker_registry: "candidate-registry.stg.fedoraproject.org"
koji_root: "koji.stg.fedoraproject.org/koji"
koji_hub: "koji.stg.fedoraproject.org/kojihub"
createrepo: False
createrepo: True

View File

@@ -6,8 +6,8 @@ mem_size: 24576
max_mem_size: "{{ mem_size }}"
num_cpus: 4
max_cpu: "{{ num_cpus }}"
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-armv7
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/26/Everything/armhfp/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-27-armv7
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/27/Everything/armhfp/os/
nm: 255.255.255.0
gw: 10.5.129.254
dns: 10.5.126.21

View File

@@ -5,8 +5,8 @@ lvm_size: 150000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-25
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/25/Server/x86_64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-armv7
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/28/Server/armhfp/os/
nm: 255.255.255.0
gw: 10.5.126.254
dns: 10.5.126.21
@@ -46,4 +46,4 @@ docker_registry: "candidate-registry.stg.fedoraproject.org"
koji_root: "koji.stg.fedoraproject.org/koji"
koji_hub: "koji.stg.fedoraproject.org/kojihub"
createrepo: False
createrepo: True

View File

@@ -1,12 +1,12 @@
---
# common items for the buildvm-* koji builders
volgroup: /dev/vg_guests
lvm_size: 150000
lvm_size: 145000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-ppc64
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/26/Server/ppc64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-ppc64
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/28/Server/ppc64/os/
nm: 255.255.255.0
gw: 10.5.129.254
dns: 10.5.126.21

View File

@@ -5,8 +5,8 @@ lvm_size: 150000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-ppc64
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/26/Server/ppc64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-ppc64
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/28/Server/ppc64/os/
nm: 255.255.255.0
gw: 10.5.126.254
dns: 10.5.126.21
@@ -46,4 +46,4 @@ docker_registry: "candidate-registry.stg.fedoraproject.org"
koji_root: "koji.stg.fedoraproject.org/koji"
koji_hub: "koji.stg.fedoraproject.org/kojihub"
createrepo: False
createrepo: True

View File

@@ -1,12 +1,12 @@
---
# common items for the buildvm-* koji builders
volgroup: /dev/vg_guests
lvm_size: 150000
lvm_size: 145000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-ppc64le
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/26/Server/ppc64le/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-ppc64le
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/28/Server/ppc64le/os/
nm: 255.255.255.0
gw: 10.5.129.254
dns: 10.5.126.21

View File

@@ -5,8 +5,8 @@ lvm_size: 150000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26-ppc64le
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/26/Server/ppc64le/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28-ppc64le
ks_repo: http://10.5.126.23/pub/fedora-secondary/releases/28/Server/ppc64le/os/
nm: 255.255.255.0
gw: 10.5.126.254
dns: 10.5.126.21
@@ -46,4 +46,4 @@ docker_registry: "candidate-registry.stg.fedoraproject.org"
koji_root: "koji.stg.fedoraproject.org/koji"
koji_hub: "koji.stg.fedoraproject.org/kojihub"
createrepo: False
createrepo: True

View File

@@ -0,0 +1,20 @@
---
ansible_ifcfg_blacklist: True
createrepo: False
host_group: kojibuilder
fas_client_groups: sysadmin-releng
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
koji_hub_nfs: "fedora_koji"
koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
csi_security_category: High
csi_primary_contact: Fedora Admins - admin@fedoraproject.org
csi_purpose: Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders.
csi_relationship: |
* VMs built on top of a s390x LPAR
* Relies on koji-hub, Packages, PkgDB, apache, fedmsg, fas, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new

View File

@@ -5,8 +5,8 @@ lvm_size: 150000
mem_size: 10240
max_mem_size: "{{ mem_size }}"
num_cpus: 4
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-26
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/26/Server/x86_64/os/
ks_url: http://10.5.126.23/repo/rhel/ks/buildvm-fedora-28
ks_repo: http://10.5.126.23/pub/fedora/linux/releases/28/Server/x86_64/os/
nm: 255.255.255.0
gw: 10.5.126.254
dns: 10.5.126.21
@@ -14,8 +14,8 @@ dns: 10.5.126.21
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
fas_client_groups: sysadmin-releng
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/buildvm-stg-sudoers"
datacenter: staging
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=4"

View File

@@ -4,8 +4,8 @@ _forward_src: "forward"
# don't forget to update ip in ./copr-keygen, due to custom firewall rules
copr_backend_ips: ["172.25.32.155", "209.132.184.48"]
keygen_host: "172.25.32.157"
copr_backend_ips: ["172.25.32.218", "209.132.184.48"]
keygen_host: "172.25.32.209"
resolvconf: "resolv.conf/cloud"

View File

@@ -12,5 +12,3 @@ csi_purpose: Provide a publicly accessible frontend for 3rd party packages (copr
csi_relationship: |
- This host provides the frontend part of copr only.
- It's the point of contact between end users and the copr build system (backend, package singer)
copr_mbs_cli_login: Y29wcg==##vtvvikhcjncwkfkdcssv

View File

@@ -2,9 +2,9 @@
tcp_ports: [22]
# http + signd dest ports
custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.32.155 --dport 80 -j ACCEPT',
custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.32.218 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 209.132.184.48 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.32.155 --dport 5167 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.32.218 --dport 5167 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 209.132.184.48 --dport 5167 -j ACCEPT']
datacenter: cloud

View File

@@ -3,10 +3,10 @@ copr_hostbase: copr-keygen-dev
tcp_ports: []
# http + signd dest ports
custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.32.175 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 209.132.184.53 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.32.175 --dport 5167 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 209.132.184.53 --dport 5167 -j ACCEPT']
custom_rules: [ '-A INPUT -p tcp -m tcp -s 172.25.32.217 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.155.215 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.32.217 --dport 5167 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 172.25.155.215 --dport 5167 -j ACCEPT']
datacenter: cloud

View File

@@ -5,8 +5,8 @@ _forward_src: "forward_dev"
# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules
copr_backend_ips: ["172.25.32.175", "172.25.150.48"]
keygen_host: "172.25.32.154"
copr_backend_ips: ["172.25.32.217", "172.25.155.215"]
keygen_host: "172.25.32.205"
resolvconf: "resolv.conf/cloud"

View File

@@ -1,11 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 6144
num_cpus: 8
tcp_ports: [ 80, 443 ]
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View File

@@ -1,11 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 3144
num_cpus: 2
tcp_ports: []
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View File

@@ -1,11 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 3144
num_cpus: 2
tcp_ports: [ 80, 443 ]
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View File

@@ -8,7 +8,12 @@ sudoers: "{{ private }}/files/sudo/00releng-sudoers"
tcp_ports: [
5000,
# This is for the gluster server
6996]
# These ports all required for gluster
111, 24007, 24008, 24009, 24010, 24011,
49152, 49153, 49154, 49155,
]
# gluster
udp_ports: [111]
registry_gluster_username_stg: registry-stg

View File

@@ -66,3 +66,6 @@ dl_tier1:
- ultra.linux.cz # 195.113.15.27
- wpi.edu # 130.215.36.26
- zaphod.gtlib.gatech.edu # 128.61.111.12
- 147.75.69.165 # sjc.edge.kernel.org
- 147.75.197.195 # ewr.edge.kernel.org
- 147.75.101.1 # ams.edge.kernel.org

View File

@@ -8,3 +8,9 @@ sudoers: "{{ private }}/files/sudo/arm-retrace-sudoers"
nagios_Check_Services:
nrpe: false
swap: false
# kernel SHMMAX value
kernel_shmmax: 687194767
shared_buffers: "1GB"
effective_cache_size: "3GB"

View File

@@ -3,6 +3,8 @@ lvm_size: 20000
mem_size: 6144
num_cpus: 2
testing: False
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file

View File

@@ -3,6 +3,9 @@ lvm_size: 20000
mem_size: 6144
num_cpus: 2
# Use infrastructure-tags-stg repo
testing: True
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
@@ -13,7 +16,7 @@ tcp_ports: [
]
# TODO, restrict this down to just sysadmin-releng
fas_client_groups: sysadmin-datanommer,sysadmin-releng,sysadmin-fedimg,fi-apprentice,sysadmin-noc,sysadmin-veteran
fas_client_groups: sysadmin-datanommer,sysadmin-releng,sysadmin-fedimg,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-atomic
fedmsg_debug_loopback: True

View File

@@ -0,0 +1,28 @@
---
# For app config
freshmaker_messaging_topic_prefix:
- org.fedoraproject.stg
freshmaker_parsers:
- freshmaker.parsers.git:GitReceiveParser
freshmaker_handlers:
- freshmaker.handlers.git:GitModuleMetadataChangeHandler
- freshmaker.handlers.git:GitRPMSpecChangeHandler
freshmaker_admins:
users:
- jkaluza
- cqi
- qwan
- sochotni
groups: []
freshmaker_dry_run: True
freshmaker_log_level: debug
#
#freshmaker_handler_build_whitelist:
# global:
# module:
# - name:
# - testmodule

View File

@@ -0,0 +1,33 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 4096
num_cpus: 2
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
tcp_ports: [ 80 ]
fas_client_groups: sysadmin-noc,sysadmin-web,sysadmin-hubs,sysadmin-veteran
# These are consumed by a task in roles/fedmsg/base/tasks/main.yml
fedmsg_certs:
- service: shell
owner: hubs
group: hubs
can_send:
- logger.log
- hubs.user.created
- hubs.user.role.added
- hubs.user.role.changed
- hubs.user.role.removed
- hubs.hub.created
- hubs.hub.updated
- hubs.widget.updated
# Used by the hubs role
hubs_url_hostname: hubs.stg.fedoraproject.org
hubs_db_host: db01.stg.phx2.fedoraproject.org
hubs_oidc_url: id.stg.fedoraproject.org
hubs_oidc_secret: "{{ hubs_stg_oidc_secret }}"

View File

@@ -1,49 +0,0 @@
---
datacenter: cloud
freezes: false
ansible_ifcfg_blacklist: true
slaves:
- name: EL6
host: jenkins-slave-el6.fedorainfracloud.org
description: CentOS 6.8
labels: el EL el6 EL6 centos CentOS centos6 CentOS6
capacity: 4
- name: EL7
host: jenkins-slave-el7.fedorainfracloud.org
description: Red Hat Enterprise Linux Server 7.3
labels: el EL el7 EL7 rhel RHEL rhel7 RHEL7
capacity: 4
- name: F26
host: jenkins-slave-f26.fedorainfracloud.org
description: Fedora 26
labels: fedora Fedora fedora26 Fedora26
capacity: 4
- name: F25
host: jenkins-slave-f25.fedorainfracloud.org
description: Fedora 25
labels: fedora Fedora fedora25 Fedora25
capacity: 4
- name: F25-ppc64le
host: jenkins-slave-f25-ppc64le.fedorainfracloud.org
description: Fedora 25 ppc64le
labels: fedora Fedora fedora25 Fedora25 Fedora25ppc64le ppc64le
capacity: 4
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:
- service: shell
owner: root
group: root
can_send:
- logger.log
- service: jenkins
owner: root
group: jenkins
can_send:
- jenkins.build.aborted
- jenkins.build.failed
- jenkins.build.notbuilt
- jenkins.build.passed
- jenkins.build.start
- jenkins.build.unstable

View File

@@ -1,287 +0,0 @@
---
datacenter: cloud
freezes: false
ansible_ifcfg_blacklist: true
# Packages installed on all Jenkins slaves (Fedora, CentOS)
slave_packages_common:
- java-1.8.0-openjdk-devel
- vim
- subversion
- bzr
- git
- rpmlint
- rpmdevtools
- mercurial
- mock
- gcc
- gcc-c++
- libjpeg-turbo-devel
- python-bugzilla
- python-pip
- python-virtualenv
- python-coverage
- pylint
- python-argparse
- python-nose
- python-BeautifulSoup
- python-fedora
- python-pep8
- python-psycopg2
- postgresql-devel # Required to install python-psycopg2 w/in a venv
- docbook-style-xsl # Required by gimp-help-2
- make # Required by gimp-help-2
- automake # Required by gimp-help-2
- libcurl-devel # Required by blockerbugs
- python-formencode # Required by javapackages-tools
- asciidoc # Required by javapackages-tools
- xmlto # Required by javapackages-tools
- pycairo-devel # Required by dogtail
- packagedb-cli # Required by FedoraReview
- xorg-x11-server-Xvfb # Required by fedora-rube
- libffi-devel # Required by bodhi/cffi/cryptography
- openssl-devel # Required by bodhi/cffi/cryptography
- redis # Required by copr
- createrepo_c # Required by bodhi2
- python-straight-plugin
- pyflakes # Requested by user rholy (ticket #4175)
- koji # Required by koschei (ticket #4852) and pyrpkg (ticket #4838)
- rpm-python # Required by koschei (ticket #4852)
- libgit2-devel # Required by pagure
- osbs-client # Required by pyrpkg (ticket #4838)
- intltool # Required by fedora-comps (ticket #5307)
- fedpkg # Required by fedora-kickstarts (ticket #5406)
- sqlite-devel # Required by fedora-hubs (ticket #5425)
- python-virtualenvwrapper # Required by fedora-hubs (ticket #5425)
- swig # Required by fm-orchestrator (ticket #5517)
- python-tox # Required by resultsdb_conventions (ticket #5785)
- gcc-c++ # Required by libabigail (ticket 5797)
- libtool # Required by libabigail (ticket 5797)
- elfutils-devel # Required by libabigail (ticket 5797)
- libxml2-devel # Required by libabigail (ticket 5797)
- doxygen # Required by libabigail (ticket 5797)
- python-sphinx # Required by libabigail (ticket 5797)
- texinfo # Required by libabigail (ticket 5797)
- dos2unix # Required by libabigail (ticket 5797)
- dpkg # Required by libabigail (ticket 5797)
- python2-devel # Required by libabigail (ticket 5797)
- rpm-python # Required by libabigail (ticket 5797)
- python2-mock # Required by libabigail (ticket 5797)
- koji # Required by libabigail (ticket 5797)
- pyxdg # Required by libabigail (ticket 5797)
- python-unittest2 # Required by libabigail (ticket 5797)
- wget # Required by libabigail (ticket 5797)
- mailcap # Required by libabigail (ticket 5797)
# Packages installed only on Fedora Jenkins slaves
slave_packages_fedora:
- python3
- python-nose-cover3
- python3-nose-cover3
- glibc
- glibc-devel
- libstdc++
- zlib-devel
- ncurses-devel
- libX11-devel
- libXrender
- libXrandr
- nspr-devel ## Requested by 389-ds-base
- nss-devel
- svrcore-devel
- openldap-devel
- libdb-devel
- cyrus-sasl-devel
- icu
- libicu-devel
- gcc-c++
- net-snmp-devel
- lm_sensors-devel
- bzip2-devel
- zlib-devel
- openssl-devel
- tcp_wrappers
- pam-devel
- systemd-units
- policycoreutils-python
- openldap-clients
- perl-Mozilla-LDAP
- nss-tools
- cyrus-sasl-gssapi
- cyrus-sasl-md5
- libdb-utils
- perl-Socket
- perl-NetAddr-IP
- pcre-devel ## End of request list for 389-ds-base
- maven # Required by xmvn https://fedorahosted.org/fedora-infrastructure/ticket/4054
- gtk3-devel # Required by dogtail
- glib2-devel # Required by Cockpit
- libgudev1-devel
- json-glib-devel
- gobject-introspection-devel
- libudisks2-devel
- NetworkManager-glib-devel
- systemd-devel
- accountsservice-devel
- pam-devel
- autoconf
- libtool
- intltool
- jsl
- python-scss
- gtk-doc
- krb5-devel
- sshpass
- perl-Locale-PO
- perl-JSON
- glib-networking
- realmd
- udisks2
- mdadm
- lvm2
- sshpass # End requires for Cockpit
- tito # Requested by msrb for javapackages-tools and xmvn (ticket#4113)
- pyflakes # Requested by user rholy (ticket #4175)
- firefox # Required for rube
- python-devel # Required for mpi4py
- python3-devel # Required for mpi4py
- pwgen # Required for mpi4py
- openmpi-devel # Required for mpi4py
- mpich2-devel # Required for mpi4py
- pylint # Required by Ipsilon
- python-pep8
- nodejs-less
- python-openid
- python-openid-teams
- python-openid-cla
- python-cherrypy
- m2crypto
- lasso-python
- python-sqlalchemy
- python-ldap
- python-pam
- python-fedora
- freeipa-python
- httpd
- mod_auth_mellon
- postgresql-server
- openssl
- mod_wsgi
- python-psycopg2
- sssd
- libsss_simpleifp
- openldap-servers
- mod_auth_gssapi
- krb5-server
- socket_wrapper
- nss_wrapper
- krb5-workstation
- python-sssdconfig
- mod_ssl
- python-jwcrypto
- python-lesscpy # End requires for Ipsilon
- libxml2-python # Required by gimp-docs
- createrepo # Required by dnf
- dia # Required by javapackages-tools ticket #4279
- python-hawkey # Required by koschei (ticket #4852)
- python-librepo # Required by koschei (ticket #4852)
- python3-pygit2 # Required by pagure
- nosync # for use in mock
- liberasurecode-devel # Required by pyeclib (ticket #5015) - No EPEL7 build
- python2-mock
- python-lxml
- mongodb-server
- ruby # For modularity (ticket 5379)
- ruby-devel
- ruby-irb
- ruby-libs
- rubygem-bigdecimal
- rubygem-bundler
- rubygem-io-console
- rubygem-json
- rubygem-net-http-persistent
- rubygem-psych
- rubygem-rdoc
- rubygem-rmagick
- rubygem-thor # Required by Fedora Budget (ticket 5679)
- rubygems
- rubypick
- python2-unittest2
- python2-createrepo_c # Required by bodhi2
- python2-pygit2 # Required by pagure
- iptables
- ledger # Required by Fedora Budget (ticket 5679)
- rubygem-asciidoctor # Required by Fedora Budget (ticket 5679)
- rubygem-builder # Required by Fedora Budget (ticket 5679)
- rubygem-coderay # Required by Fedora Budget (ticket 5679)
- rubygem-eventmachine # Required by Fedora Budget (ticket 5679)
- rubygem-ffi # Required by Fedora Budget (ticket 5679)
- rubygem-formatador # Required by Fedora Budget (ticket 5679)
- rubygem-git # Required by Fedora Budget (ticket 5679)
- rubygem-haml # Required by Fedora Budget (ticket 5679)
- rubygem-listen # Required by Fedora Budget (ticket 5679)
- rubygem-method_source # Required by Fedora Budget (ticket 5679)
- rubygem-multi_json # Required by Fedora Budget (ticket 5679)
- rubygem-nenv # Required by Fedora Budget (ticket 5679)
- rubygem-pry # Required by Fedora Budget (ticket 5679)
- rubygem-rake # Required by Fedora Budget (ticket 5679)
- rubygem-rb-inotify # Required by Fedora Budget (ticket 5679)
- rubygem-shellany # Required by Fedora Budget (ticket 5679)
- rubygem-slop # Required by Fedora Budget (ticket 5679)
- rubygem-tilt # Required by Fedora Budget (ticket 5679)
- doxygen # Required by gssproxy (ticket 5703)
- findutils # Required by gssproxy (ticket 5703)
- gettext-devel # Required by gssproxy (ticket 5703)
- keyutils-libs-devel # Required by gssproxy (ticket 5703)
- libini_config-devel # Required by gssproxy (ticket 5703)
- libselinux-devel # Required by gssproxy (ticket 5703)
- libverto-devel # Required by gssproxy (ticket 5703)
- libxml2 # Required by gssproxy (ticket 5703)
- libxslt # Required by gssproxy (ticket 5703)
- m4 # Required by gssproxy (ticket 5703)
- pkgconfig # Required by gssproxy (ticket 5703)
- popt-devel # Required by gssproxy (ticket 5703)
- krb5-server-ldap # Required by gssproxy (ticket 5703)
- valgrind # Required by gssproxy (ticket 5703) Required by libabigail (Ticket 5797)
- perl-Fedora-VSP # needed by 389
- perl-generators # needed by 389
- libevent-devel # needed by 389
- libcmocka-devel # needed by 389
- gperftools-devel # needed by 389
# Packages installed only on CentOS Jenkins slaves
slave_packages_centos:
# "setup" is just a placeholder value
- setup
# Packages only installed on el7 slave
el7_only:
- python-webob1.4 # Required by bodhi2
- python-pillow # Required by bodhi2
- python-hawkey # Required by koschei (ticket #4852)
- python-librepo # Required by koschei (ticket #4852)
- nosync # for use in mock
- python-unittest2
- python-createrepo_c # Required by bodhi2
- python-pygit2 # Required by pagure
- python-pygments-markdown-lexer # Required by fedora-hubs (ticket #5425)
# Packages only available/needed in f24+
f24_only:
- python2-systemd
- python2-requests-kerberos
- python2-jinja2
- devscripts-minimal # Required by FedoraReview
- python26
- python33
- python34
- python36
f25_only:
- python3-tox
- python26
- python33
- python34
- python36
- swig # required for coco

View File

@@ -12,7 +12,7 @@ tcp_ports: [ 80, 443, 111, 2049,
udp_ports: [ 111, 2049 ]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:

View File

@@ -12,6 +12,9 @@ koschei_pgsql_hostname: db01.phx2.fedoraproject.org
koschei_koji_hub: koji.fedoraproject.org
koschei_kojipkgs: kojipkgs.fedoraproject.org
koschei_koji_web: koji.fedoraproject.org
koschei_copr_url: http://copr-fe.cloud.fedoraproject.org
koschei_copr_login: NOT-USED-YET
koschei_copr_token: NOT-USED-YET
host_group: koschei-backend

View File

@@ -12,6 +12,9 @@ koschei_pgsql_hostname: pgbdr.stg.phx2.fedoraproject.org
koschei_koji_hub: koji.stg.fedoraproject.org
koschei_kojipkgs: koji.stg.fedoraproject.org
koschei_koji_web: koji.stg.fedoraproject.org
koschei_copr_url: http://copr-fe-dev.cloud.fedoraproject.org
koschei_copr_login: "{{ koschei_copr_login_stg }}"
koschei_copr_token: "{{ koschei_copr_token_stg }}"
tcp_ports: [
@@ -55,6 +58,7 @@ csi_relationship: |
- fedmsg hub
- bastion (for mail relay)
- memcached01
- Copr development instance
koschei_backend_services:
- koschei-polling

View File

@@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
lvm_size: 6000
mem_size: 1024
lvm_size: 8000
mem_size: 2048
num_cpus: 1
# for systems that do not match the above - specify the same parameter in
@@ -12,9 +12,11 @@ koschei_pgsql_hostname: db01.phx2.fedoraproject.org
koschei_koji_hub: koji02.phx2.fedoraproject.org
koschei_kojipkgs: kojipkgs.fedoraproject.org
koschei_koji_web: koji.fedoraproject.org
koschei_openid_provider: id.fedoraproject.org
koschei_oidc_provider: id.fedoraproject.org
koschei_bugzilla: bugzilla.redhat.com
koschei_oidc_client_secret: "{{ koschei_oidc_client_secret_prod }}"
koschei_oidc_crypto_secret: "{{ koschei_oidc_crypto_secret_prod }}"
tcp_ports: [ 80, 443 ]

View File

@@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
lvm_size: 6000
mem_size: 1024
lvm_size: 8000
mem_size: 2048
num_cpus: 1
# for systems that do not match the above - specify the same parameter in
@@ -11,9 +11,12 @@ koschei_topurl: https://apps.stg.fedoraproject.org/koschei
koschei_pgsql_hostname: pgbdr.stg.phx2.fedoraproject.org
koschei_kojipkgs: koji.stg.fedoraproject.org
koschei_koji_web: koji.stg.fedoraproject.org
koschei_openid_provider: id.stg.fedoraproject.org
koschei_oidc_provider: id.stg.fedoraproject.org
koschei_bugzilla: partner-bugzilla.redhat.com
koschei_oidc_client_secret: "{{ koschei_oidc_client_secret_stg }}"
koschei_oidc_crypto_secret: "{{ koschei_oidc_crypto_secret_stg }}"
tcp_ports: [ 80, 443 ]
custom_rules: [

View File

@@ -0,0 +1,11 @@
---
# XXX - this is not really a group of real hosts.
# Instead, it represents an application in openshift.
# See playbooks/openshift-apps/waiverdb.yml
fedmsg_env: stg
fedmsg_certs:
- service: librariesio2fedmsg
can_send:
- librariesio2fedmsg.sse2fedmsg.librariesio

View File

@@ -0,0 +1,13 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 2048
num_cpus: 1
fas_client_groups: sysadmin-loopabull
sudoers: "{{ private }}/files/sudo/mm2-sudoers"
# For the MOTD
csi_security_category: High
csi_primary_contact: admin@fedoraproject.org / sysadmin-main-members
csi_purpose: Release Engineering automation hosts

View File

@@ -3,3 +3,6 @@ freezes: false
mem_size: 4096
num_cpus: 2
tcp_ports: [22, 80, 443]
fas_client_groups: paste-deleter
sudoers: "{{ private }}/files/sudo/modernpaste-sudoers"

View File

@@ -34,8 +34,6 @@ csi_purpose: Monitoring system
# and they don't do ansible
#
phx2_management_hosts:
- autocloud-backend-libvirt.mgmt.fedoraproject.org
- autocloud-backend-vbox.mgmt.fedoraproject.org
- backup01.mgmt.fedoraproject.org
- beaker-client01.mgmt.fedoraproject.org
- beaker-client02.mgmt.fedoraproject.org
@@ -61,10 +59,19 @@ phx2_management_hosts:
- dell-fx02-07.mgmt.fedoraproject.org
- dell-fx02-08.mgmt.fedoraproject.org
- dell-fx02.mgmt.fedoraproject.org
- dell-fxqa01-01.mgmt.fedoraproject.org
- dell-fxqa01-02.mgmt.fedoraproject.org
- dell-fxqa01-03.mgmt.fedoraproject.org
- dell-fxqa01.mgmt.fedoraproject.org
- cloud-fx01.mgmt.fedoraproject.org
- control01.mgmt.fedoraproject.org
- control02.mgmt.fedoraproject.org
- cn-x86-64-01-03.mgmt.fedoraproject.org
- cn-x86-64-01-04.mgmt.fedoraproject.org
- cn-x86-64-01-05.mgmt.fedoraproject.org
- cn-x86-64-01-06.mgmt.fedoraproject.org
- cn-x86-64-01-07.mgmt.fedoraproject.org
- cn-x86-64-01-08.mgmt.fedoraproject.org
- cn-x86-64-02-01.mgmt.fedoraproject.org
- cn-x86-64-02-02.mgmt.fedoraproject.org
- cn-x86-64-02-03.mgmt.fedoraproject.org
- cloud-fx02.mgmt.fedoraproject.org
- download01.mgmt.fedoraproject.org
- download02.mgmt.fedoraproject.org
- download03.mgmt.fedoraproject.org
@@ -86,11 +93,6 @@ phx2_management_hosts:
- fed-cloud14.mgmt.fedoraproject.org
- fed-cloud15.mgmt.fedoraproject.org
- kvm01.mgmt.fedoraproject.org
- oldbox01.mgmt.fedoraproject.org
- oldbox02.mgmt.fedoraproject.org
- oldbox03.mgmt.fedoraproject.org
- oldbox04.mgmt.fedoraproject.org
- oldbox05.mgmt.fedoraproject.org
- qa09.mgmt.fedoraproject.org
- qa10.mgmt.fedoraproject.org
- qa11.mgmt.fedoraproject.org
@@ -103,7 +105,7 @@ phx2_management_hosts:
- virthost-comm03.mgmt.fedoraproject.org
- virthost-comm04.mgmt.fedoraproject.org
- virthost-s390.mgmt.fedoraproject.org
- virthost01.mgmt.fedoraproject.org
- virthost01-stg.mgmt.fedoraproject.org
- virthost02.mgmt.fedoraproject.org
- virthost03.mgmt.fedoraproject.org
- virthost04.mgmt.fedoraproject.org
@@ -133,32 +135,11 @@ phx2_management_limited:
- moonshot01-sw2.mgmt.fedoraproject.org
- opengear01.mgmt.fedoraproject.org
- opengear02.mgmt.fedoraproject.org
- qa01.mgmt.fedoraproject.org
- qa02.mgmt.fedoraproject.org
- qa03.mgmt.fedoraproject.org
- qa04.mgmt.fedoraproject.org
- qa05.mgmt.fedoraproject.org
- qa07.mgmt.fedoraproject.org
- qa08.mgmt.fedoraproject.org
- rack16-pdu-a.mgmt.fedoraproject.org
- rack16-pdu-b.mgmt.fedoraproject.org
- rack17-pdu-a.mgmt.fedoraproject.org
- rack17-pdu-b.mgmt.fedoraproject.org
- rack47-pdu-a.mgmt.fedoraproject.org
- rack47-pdu-b.mgmt.fedoraproject.org
- rack47-serial.mgmt.fedoraproject.org
- rack48-pdu-a.mgmt.fedoraproject.org
- rack48-serial.mgmt.fedoraproject.org
- rack51-pdu-a.mgmt.fedoraproject.org
- rack51-pdu-b.mgmt.fedoraproject.org
- rack51-serial.mgmt.fedoraproject.org
- rack52-serial.mgmt.fedoraproject.org
- rack58-pdu-a.mgmt.fedoraproject.org
- rack58-pdu-b.mgmt.fedoraproject.org
- sign-vault03.mgmt.fedoraproject.org
- sign-vault04.mgmt.fedoraproject.org
- virthost-comm02.mgmt.fedoraproject.org
- virthost12.mgmt.fedoraproject.org
- virthost14.mgmt.fedoraproject.org
phx2_management_slowping:

View File

@@ -0,0 +1,9 @@
---
datacenter: cloud
nm: 255.255.254.0
gw: 209.132.184.254
fas_client_groups: sysadmin-main
dns: 8.8.8.8
freezes: false
ansible_ifcfg_whitelist: ['eth1']
baseiptables: false

View File

@@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 1024
mem_size: 4096
num_cpus: 2
# Definining these vars has a number of effects

View File

@@ -39,6 +39,16 @@ fedmsg_certs:
can_send:
- odcs.compose.state-changed
odcs_allowed_source_types: ["tag", "raw_config", "module"]
odcs_pungi_runroot_enabled: True
odcs_pungi_parent_runroot_packages: ["pungi", "fedora-packager", "python2-modulemd", "python2-pdc-client", "intltool"]
odcs_pungi_parent_runroot_tag: f26-build
odcs_pungi_runroot_target_dir_url: http://kojipkgs.stg.fedoraproject.org/compose/odcs
odcs_raw_config_urls:
mboddu_pungi_fedora: https://pagure.io/fork/mohanboddu/pungi-fedora/raw/%s/f/fedora.conf
jkaluza_pungi_fedora: https://pagure.io/fork/jkaluza/pungi-fedora/raw/%s/f/fedora.conf
odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes
# For the MOTD

View File

@@ -37,6 +37,11 @@ fedmsg_certs:
- odcs.compose.state-changed
odcs_target_dir_url: https://odcs.fedoraproject.org/composes
# Give access to jscotka to be able to develop module testing integration
# for taskotron.
# Give access to sgallagh to be able to generate testing composes for new
# modules.
odcs_allowed_clients_users: {"jscotka": {}, "sgallagh": {}}
# For the MOTD
csi_security_category: Low

View File

@@ -36,8 +36,25 @@ fedmsg_certs:
can_send:
- odcs.compose.state-changed
odcs_allowed_source_types: ["tag", "raw_config", "module"]
odcs_pungi_runroot_enabled: True
odcs_pungi_parent_runroot_packages: ["pungi", "fedora-packager", "python2-modulemd", "python2-pdc-client", "intltool"]
odcs_pungi_parent_runroot_tag: f26-build
odcs_pungi_runroot_target_dir_url: http://kojipkgs.stg.fedoraproject.org/compose/odcs
odcs_raw_config_urls:
mboddu_pungi_fedora: https://pagure.io/fork/mohanboddu/pungi-fedora/raw/%s/f/fedora.conf
jkaluza_pungi_fedora: https://pagure.io/fork/jkaluza/pungi-fedora/raw/%s/f/fedora.conf
odcs_target_dir_url: https://odcs.stg.fedoraproject.org/composes
# Give access to jscotka to be able to develop module testing integration
# for taskotron.
odcs_allowed_clients_users:
- jscotka: ["tag", "module"]
- mohanboddu: ["tag", "module", "raw_config"]
- kellin: ["tag", "module", "raw_config"]
# For the MOTD
csi_security_category: Low
csi_primary_contact: Factory 2 factory2-members@fedoraproject.org

View File

@@ -16,20 +16,22 @@ openqa_dbhost: db-qa01.qa.fedoraproject.org
openqa_dbuser: openqa
openqa_dbpassword: "{{ prod_openqa_dbpassword }}"
openqa_assetsize: 300
openqa_assetsize_updates: 50
openqa_key: "{{ prod_openqa_apikey }}"
openqa_secret: "{{ prod_openqa_apisecret }}"
wikitcms_user: coconut
wikitcms_password: "{{ prod_wikitcms_password }}"
wikitcms_token: "{{ private }}/files/openidc/production/wikitcms.json"
# The checkcompose settings below cause system(s) in this group to
# send out check-compose reports. This could cause duplicate reports
# if additional systems were added to this group.
checkcompose_emailfrom: rawhide@fedoraproject.org
checkcompose_emailto: "test@lists.fedoraproject.org devel@lists.fedoraproject.org"
checkcompose_postrelease_emailto: "mmcgrath@fedoraproject.org atomic@lists.fedoraproject.org"
checkcompose_postrelease_emailerror: "true"
checkcompose_atomic_emailto: "dusty@dustymabe.com walters@verbum.org atomic@lists.fedoraproject.org"
checkcompose_atomic_emailerror: "true"
checkcompose_smtp: bastion.phx2.fedoraproject.org
checkcompose_url: "https://{{ external_hostname }}"

View File

@@ -26,12 +26,16 @@ openqa_dbname: openqa-stg
openqa_dbhost: db-qa01.qa.fedoraproject.org
openqa_dbuser: openqastg
openqa_dbpassword: "{{ stg_openqa_dbpassword }}"
openqa_assetsize: 400
openqa_assetsize: 450
openqa_assetsize_ppc: 150
openqa_assetsize_aarch64: 150
openqa_assetsize_updates: 75
openqa_key: "{{ stg_openqa_apikey }}"
openqa_secret: "{{ stg_openqa_apisecret }}"
wikitcms_password: "{{ stg_wikitcms_password }}"
wikitcms_token: "{{ private }}/files/openidc/staging/wikitcms.json"
checkcompose_url: "https://{{ external_hostname }}"
@@ -69,6 +73,14 @@ fedmsg_certs:
- openqa.jobs.restart
- openqa.job.update.result
- openqa.job.done
- service: ci
owner: root
group: geekotest
can_send:
- ci.productmd-compose.test.queued
- ci.productmd-compose.test.running
- ci.productmd-compose.test.complete
- ci.productmd-compose.test.error
# we need this to log with fedmsg-logger
fedmsg_active: True

View File

@@ -12,9 +12,3 @@ custom_rules: [
'-A FORWARD -m state -i eth2 -o br0 --state RELATED,ESTABLISHED -j ACCEPT',
'-A INPUT -i br0 -j ACCEPT'
]
# we do stuff with ifcfg that base doesn't understand. terrible, terrible
# stuff. seriously - it doesn't handle the openvswitch config well. so
# let's tell it to just configure eth0 (and eth2, for ppc64) for us and
# leave everything else alone.
ansible_ifcfg_whitelist: ['eth0', 'eth2']

View File

@@ -0,0 +1,2 @@
---
freezes: false

View File

@@ -2,3 +2,4 @@
host_group: os
baseiptables: False
no_http2: True
nm_controlled_resolv: True

View File

@@ -2,3 +2,7 @@
os_url: os.fedoraproject.org
os_app_url: app.os.fedoraproject.org
swap: false
nagios_Check_Services:
swap: false
nrpe: false

View File

@@ -2,3 +2,7 @@
os_url: os.fedoraproject.org
os_app_url: app.os.fedoraproject.org
swap: false
nagios_Check_Services:
swap: false
nrpe: false

View File

@@ -2,3 +2,4 @@
host_group: os
baseiptables: False
no_http2: True
nm_controlled_resolv: True

View File

@@ -6,8 +6,8 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8443]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org"
docker_registry: "candidate-registry.fedoraproject.org"

View File

@@ -1,6 +1,6 @@
---
# Define resources for this group of hosts here.
fas_client_groups: sysadmin-releng,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
osbs_url: "osbs.fedoraproject.org"

View File

@@ -1,6 +1,6 @@
---
# Define resources for this group of hosts here.
fas_client_groups: sysadmin-releng,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
osbs_url: "osbs.stg.fedoraproject.org"

View File

@@ -6,8 +6,8 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8443]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org"
source_registry: "registry.fedoraproject.org"
@@ -23,6 +23,8 @@ osbs_client_conf_path: /etc/osbs.conf
openshift_node_labels: {'region':'infra'}
openshift_schedulable: False
composer: compose-x86-01.phx2.fedoraproject.org
nagios_Check_Services:
nrpe: true
sshd: true

View File

@@ -9,6 +9,50 @@ tcp_ports: [ 80, 443, 8443]
openshift_node_labels: {'region':'infra'}
openshift_schedulable: False
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org"
source_registry: "registry.stg.fedoraproject.org"
docker_registry: "candidate-registry.stg.fedoraproject.org"
osbs_url: "osbs.stg.fedoraproject.org"
osbs_koji_username: "kojibuilder_stg"
koji_url: "koji.stg.fedoraproject.org"
osbs_client_conf_path: /etc/osbs.conf
osbs_namespace: "osbs-fedora"
osbs_worker_namespace: worker
osbs_worker_service_accounts:
- orchestrator
- builder
osbs_conf_sources_command: fedpkg sources
osbs_conf_vendor: Fedora Project
osbs_orchestrator_cpu_limitrange: "95m"
osbs_worker_default_nodeselector: "worker=true"
osbs_orchestrator_default_nodeselector: "orchestrator=true"
osbs_conf_service_accounts:
- koji
- builder
osbs_conf_readwrite_users:
- "system:serviceaccount:{{ osbs_namespace }}:default"
- "system:serviceaccount:{{ osbs_namespace }}:builder"
osbs_conf_worker_clusters:
x86_64:
- name: x86_64-stg
max_concurrent_builds: 2
openshift_url: "https://osbs.stg.fedoraproject.org/"
verify_ssl: 'false'
composer: composer.stg.phx2.fedoraproject.org
nagios_Check_Services:
nrpe: true
sshd: true

View File

@@ -6,8 +6,8 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8443, 10250]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.fedoraproject.org"
docker_registry: "candidate-registry.fedoraproject.org"

View File

@@ -1,145 +1,34 @@
---
# Define resources for this group of hosts here.
lvm_size: 60000
mem_size: 8192
num_cpus: 2
baseiptables: False
tcp_ports: [ 80, 443, 8443]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran,sysadmin-osbs
sudoers: "{{ private }}/files/sudo/osbs-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org"
stable_registry: "registry.stg.fedoraproject.org"
candidate_registry: "candidate-registry.stg.fedoraproject.org"
source_registry: "registry.stg.fedoraproject.org"
docker_registry: "candidate-registry.stg.fedoraproject.org"
osbs_url: "osbs.stg.fedoraproject.org"
osbsworker_x86_64_url: "osbsworker-x86-64.stg.fedoraproject.org"
osbs_koji_username: "kojibuilder_stg"
koji_url: "koji.stg.fedoraproject.org"
osbs_builder_user: builder
koji_builder_user: dockerbuilder
osbs_client_conf_path: /etc/osbs.conf
# openshift-ansible variables
# Need to use this special branch on my fork for stage until these are merged
# upstream and backported to the release-3.6 branch
#
# https://github.com/openshift/openshift-ansible/pull/5101
# https://github.com/openshift/openshift-ansible/pull/5129
oa_version: 3.6-add-dnf-support
oa_ssh_user: root
oa_install_examples: false
oa_containerized_deploy: false
oa_auth_profile: osbs
oa_debug_level: 2
oa_htpasswd_file: /etc/origin/htpasswd
origin_release: v3.6.0
osbs_koji_username: "kojibuilder_stg"
openshift_home: /var/lib/origin
generated_config_path: /tmp
osbs_admin: true
osbs_orchestrator_service_accounts:
- worker
- orchestrator
- metrics
os_cpu_limitrange: '200m'
# FIXME
osbs_orchestrator: false
osbs_worker_namespace: "worker"
osbs_orchestrator_namespace: "osbs"
osbs_worker_service_accounts:
- worker
- orchestrator
worker_clusters:
x86_64:
- name: osbsworker-x86-64
max_concurrent_builds: 12
openshift_url: "https://{{ osbsworker_x86_64_url }}"
verify_ssl: 'false'
artifacts_allowed_domains:
- "{{stable_registry}}"
- "{{candidate_registry}}"
koji_hub: "https://{{koji_url}}/kojihub"
koji_root: "https://{{koji_url}}/koji"
osbs_pulp_registry_name: brew-prod
osbs_registry_uri: "https://{{candidate_registry}}/v2"
osbs_source_registry_uri: http://brew-pulp-docker01.web.prod.ext.phx2.redhat.com:8888
koji_secret_name: kojisecret
distribution_scope: public
authoritative_registry: "{{ stable_registry }}"
registry_api_versions:
- v2
registry_secret_name: v2-registry-dockercfg
build_json_dir: /usr/share/osbs
sources_command: fedpkg sources
vendor: Fedora Project
osbs_manage_firewalld: false
kubeconfig_path: /etc/origin/master/admin.kubeconfig
osbs_env:
HOME: "{{ lookup('env', 'HOME') }}"
KUBECONFIG: "{{ osbs_kubeconfig_path }}"
osbs_orchestrator_readonly_users:
- "system:serviceaccount:{{ osbs_orchestrator_namespace }}:metrics"
osbs_orchestrator_readonly_groups:
- "system:authenticated"
osbs_orchestrator_readwrite_groups: []
osbs_orchestrator_readwrite_users:
- "{{ ansible_hostname }}"
- "system:serviceaccount:{{ osbs_orchestrator_namespace }}:default"
- "system:serviceaccount:{{ osbs_orchestrator_namespace }}:builder"
osbs_worker_readonly_users:
- "system:serviceaccount:{{ osbs_worker_namespace }}:metrics"
osbs_worker_readonly_groups:
- "system:authenticated"
osbs_worker_readwrite_groups: []
osbs_worker_readwrite_users:
- "{{ ansible_hostname }}"
- "system:serviceaccount:{{ osbs_worker_namespace }}:default"
- "system:serviceaccount:{{ osbs_worker_namespace }}:builder"
os_admin_users:
- kevin
- puiterwijk
- maxamillion
- dgilmore
- kojibuilder_stg
os_admin_groups: []
osbs_nodes: "{{ groups['osbs-orchestrator-' + env + '-nodes'] }}"
#nodeselectors
osbs_orchestrator_default_nodeselector: "orchestrator=true"
osbs_orchestrator_nodeselector_labels: "'orchestrator': 'true'"
osbs_worker_default_nodeselector: "worker=true"
osbs_worker_nodeselector_labels: "'worker': 'true'"
# fedora container images required by buildroot
fedora_required_images:
- "fedora:latest"
baseiptables: False
# docker images required by OpenShift Origin
openshift_required_images:
- "openshift/origin-pod"
# fedora container images required by buildroot
fedora_required_images:
- "fedora:latest"
nm_controlled_resolv: True

View File

@@ -1,32 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 60000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 80, 443, 8443]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org"
source_registry: "registry.stg.fedoraproject.org"
docker_registry: "candidate-registry.stg.fedoraproject.org"
osbs_url: "osbs.stg.fedoraproject.org"
osbs_koji_username: "kojibuilder_stg"
koji_url: "koji.stg.fedoraproject.org"
osbs_client_conf_path: /etc/osbs.conf
openshift_node_labels: {'region':'infra'}
openshift_schedulable: False
nagios_Check_Services:
nrpe: true
sshd: true
named: false
dhcpd: false
httpd: false
swap: false

View File

@@ -1,31 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 60000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 80, 443, 8443, 10250]
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
docker_cert_dir: "/etc/docker/certs.d/candidate-registry.stg.fedoraproject.org"
source_registry: "registry.stg.fedoraproject.org"
docker_registry: "candidate-registry.stg.fedoraproject.org"
osbs_url: "osbs.stg.fedoraproject.org"
osbs_koji_username: "kojibuilder_stg"
koji_url: "koji.stg.fedoraproject.org"
osbs_client_conf_path: /etc/osbs.conf
openshift_node_labels: {'region': 'primary', 'zone': 'default'}
nagios_Check_Services:
nrpe: true
sshd: true
named: false
dhcpd: false
httpd: false
swap: false

View File

@@ -1,10 +0,0 @@
---
# Define resources for this group of hosts here.
lvm_size: 60000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 80, 443, 8443]
openshift_node_labels: {'region':'infra'}
openshift_schedulable: False

Some files were not shown because too many files have changed in this diff Show More