From 2cf38c1f17399adfc26b39ee7427e45700ee9cb5 Mon Sep 17 00:00:00 2001 From: Ryan Lerch Date: Mon, 25 Nov 2024 18:24:56 +1000 Subject: [PATCH] [yaml-lint] fix yamllint errors and warnings on plabooks Signed-off-by: Ryan Lerch --- playbooks/check-for-nonvirt-updates.yml | 1 + playbooks/check-for-updates.yml | 1 + playbooks/check-host.yml | 80 +++++++++---------- playbooks/checks_log_failed_services.yml | 1 + playbooks/clear_memcached.yml | 1 + playbooks/clear_varnish.yml | 1 + playbooks/death_to_postfix.yml | 19 ++--- playbooks/destroy_virt_inst.yml | 1 + playbooks/groups/backup-server.yml | 9 ++- playbooks/groups/bastion.yml | 10 +-- playbooks/groups/batcave.yml | 13 +-- playbooks/groups/bodhi-backend.yml | 3 +- playbooks/groups/build-kcs.yml | 3 +- playbooks/groups/buildhw.yml | 11 +-- playbooks/groups/buildvm-osbuild.yml | 3 +- playbooks/groups/buildvm.yml | 17 ++-- playbooks/groups/busgateway.yml | 19 ++--- playbooks/groups/centos-ipa-client.yml | 13 ++- playbooks/groups/certgetter.yml | 9 ++- playbooks/groups/copr-backend.yml | 21 ++--- playbooks/groups/copr-dist-git.yml | 21 ++--- playbooks/groups/copr-frontend.yml | 27 ++++--- playbooks/groups/copr-hypervisor.yml | 9 ++- playbooks/groups/copr-keygen.yml | 23 +++--- playbooks/groups/copr-pulp.yml | 2 +- playbooks/groups/data-reports.yml | 9 ++- playbooks/groups/db.aws.yml | 29 +++---- playbooks/groups/debuginfod.yml | 1 + playbooks/groups/dns.yml | 9 ++- playbooks/groups/download.yml | 28 +++---- playbooks/groups/flatpak-cache.yml | 8 +- playbooks/groups/github2fedmsg.yml | 17 ++-- playbooks/groups/ipa.yml | 11 +-- playbooks/groups/ipsilon.yml | 7 +- playbooks/groups/koji-hub.yml | 17 ++-- playbooks/groups/kojipkgs.yml | 9 ++- playbooks/groups/logserver.yml | 63 ++++++++------- playbooks/groups/maintainer-test.yml | 11 +-- playbooks/groups/mariadb-server.yml | 9 ++- playbooks/groups/memcached.yml | 3 +- playbooks/groups/nfs-servers.yml | 25 +++--- playbooks/groups/noc.yml | 21 ++--- playbooks/groups/oci-registry.yml | 57 ++++++------- playbooks/groups/openqa-onebox-test.yml | 45 ++++++----- playbooks/groups/openqa-workers.yml | 31 +++---- playbooks/groups/openqa.yml | 73 ++++++++--------- playbooks/groups/os-control.yml | 7 +- playbooks/groups/os-proxies.yml | 10 +-- playbooks/groups/pagure.yml | 17 ++-- playbooks/groups/postgresql-server.yml | 3 +- playbooks/groups/proxies.yml | 15 ++-- playbooks/groups/rabbitmq.yml | 3 +- playbooks/groups/releng-compose.yml | 9 ++- playbooks/groups/retrace.yml | 31 +++---- playbooks/groups/secondary.yml | 9 ++- playbooks/groups/sign-bridge.yml | 7 +- playbooks/groups/smtp-auth.yml | 9 ++- playbooks/groups/smtp-mm.yml | 9 ++- playbooks/groups/tang.yml | 9 ++- playbooks/groups/torrent.yml | 9 ++- playbooks/groups/value.yml | 11 +-- playbooks/groups/virthost.yml | 9 ++- playbooks/groups/wiki.yml | 13 +-- playbooks/groups/zabbix.yml | 9 ++- playbooks/host_reboot.yml | 3 +- playbooks/host_update.yml | 3 +- .../cloud-noc01.fedorainfracloud.org.yml | 10 +-- .../noc-cc01.rdu-cc.fedoraproject.org.yml | 9 ++- playbooks/include/happy_birthday.yml | 10 +-- playbooks/include/proxies-certificates.yml | 12 +-- playbooks/include/proxies-fedora-web.yml | 9 ++- playbooks/include/proxies-fedorahosted.yml | 12 +-- playbooks/include/proxies-haproxy.yml | 9 ++- playbooks/include/proxies-miscellaneous.yml | 19 ++--- playbooks/include/proxies-redirects.yml | 15 ++-- playbooks/include/proxies-reverseproxy.yml | 9 ++- playbooks/include/proxies-rewrites.yml | 9 ++- playbooks/include/proxies-websites.yml | 13 +-- playbooks/include/virt-create.yml | 10 +-- playbooks/list-vms-per-host.yml | 2 +- playbooks/manual/autosign.yml | 9 ++- playbooks/manual/copr/_generic_tasks.yml | 1 + .../manual/copr/copr-backend-upgrade.yml | 8 +- .../manual/copr/copr-dist-git-upgrade.yml | 8 +- .../manual/copr/copr-frontend-upgrade.yml | 8 +- playbooks/manual/copr/copr-keygen-upgrade.yml | 8 +- playbooks/manual/copr/copr-pulp-upgrade.yml | 8 +- .../manual/fas-readonly/fas-readonly.yml | 6 +- .../manual/fas-readonly/rollback-readonly.yml | 6 +- playbooks/manual/gdpr/delete.yml | 1 + playbooks/manual/gdpr/sar.yml | 1 + playbooks/manual/gdpr/sar_openshift.yml | 1 + playbooks/manual/get-system-packages.yml | 6 +- playbooks/manual/history_undo.yml | 3 +- .../manual/import-irc-cookies-to-matrix.yml | 11 +-- playbooks/manual/kernel-qa.yml | 9 ++- .../mirrormanager/emergency-expire-repo.yml | 1 + .../mirrormanager/move-devel-to-release.yml | 1 + .../manual/mirrormanager/move-to-archive.yml | 1 + playbooks/manual/nagios/shush-fmn.yml | 9 ++- .../noggin-deployment/create-full-backup.yml | 3 +- .../fix-home-fedora-ownerships.yml | 2 +- .../restore-latest-backup.yml | 1 + .../uninstall_ipa_client.yml | 1 + playbooks/manual/oci-registry-prune.yml | 1 + playbooks/manual/ocp4-place-ignitionfiles.yml | 18 ++--- playbooks/manual/openqa-restart-workers.yml | 8 +- playbooks/manual/qadevel.yml | 17 ++-- playbooks/manual/rabbit/delete-queue.yml | 3 +- playbooks/manual/rebuild/hotspot.yml | 9 ++- playbooks/manual/rebuild/mote.yml | 9 ++- playbooks/manual/rebuild/websites.yml | 13 +-- playbooks/manual/releng/koji-release-tags.yml | 2 +- playbooks/manual/remote_delldrive.yml | 7 +- playbooks/manual/restart-fedmsg-services.yml | 49 ++++++------ playbooks/manual/restart-pagure.yml | 7 +- playbooks/manual/sign-and-import.yml | 13 +-- playbooks/manual/sign-vault.yml | 15 ++-- playbooks/manual/staging-sync/bodhi.yml | 45 +++++------ playbooks/manual/staging-sync/db-sync.yml | 52 ++++++------ playbooks/manual/staging-sync/koji.yml | 31 +++---- playbooks/manual/staging-sync/koschei.yml | 11 +-- playbooks/manual/staging-sync/mailman.yml | 33 ++++---- playbooks/manual/sync-hosts.yml | 20 ++--- playbooks/manual/update-aliases.yml | 9 ++- playbooks/manual/update-firmware.yml | 7 +- playbooks/manual/update-packages.yml | 4 +- playbooks/manual/upgrade/bodhi.yml | 45 ++++++----- playbooks/manual/upgrade/bugzilla2fedmsg.yml | 19 ++--- playbooks/manual/upgrade/datagrepper.yml | 19 ++--- playbooks/manual/upgrade/datanommer.yml | 43 +++++----- playbooks/manual/upgrade/fedmsg.yml | 21 ++--- playbooks/manual/upgrade/koji.yml | 35 ++++---- playbooks/manual/upgrade/koschei-full.yml | 11 +-- playbooks/manual/upgrade/koschei-rolling.yml | 11 +-- playbooks/manual/upgrade/mote.yml | 19 ++--- playbooks/manual/upgrade/packages.yml | 19 ++--- playbooks/manual/upgrade/pagure.yml | 27 ++++--- .../openshift-apps/application-monitoring.yml | 3 +- playbooks/openshift-apps/asknot.yml | 3 +- playbooks/openshift-apps/awx.yml | 2 +- playbooks/openshift-apps/blockerbugs.yml | 5 +- playbooks/openshift-apps/bodhi.yml | 3 +- playbooks/openshift-apps/bugzilla2fedmsg.yml | 3 +- .../openshift-apps/cloud-image-uploader.yml | 3 +- .../openshift-apps/custom-error-pages.yml | 1 + playbooks/openshift-apps/datagrepper.yml | 3 +- playbooks/openshift-apps/datanommer.yml | 3 +- playbooks/openshift-apps/discourse2fedmsg.yml | 3 +- playbooks/openshift-apps/docstranslation.yml | 3 +- playbooks/openshift-apps/easyfix.yml | 4 +- playbooks/openshift-apps/elections.yml | 3 +- playbooks/openshift-apps/fasjson.yml | 3 +- playbooks/openshift-apps/fedocal.yml | 3 +- .../openshift-apps/fedora-packages-static.yml | 3 +- playbooks/openshift-apps/firmitas.yml | 2 +- playbooks/openshift-apps/flask-oidc-dev.yml | 3 +- playbooks/openshift-apps/flatpak-indexer.yml | 3 +- playbooks/openshift-apps/fmn.yml | 6 +- playbooks/openshift-apps/greenwave.yml | 5 +- playbooks/openshift-apps/ipsilon-website.yml | 3 +- playbooks/openshift-apps/kanban.yml | 3 +- playbooks/openshift-apps/kerneltest.yml | 3 +- playbooks/openshift-apps/koschei.yml | 7 +- playbooks/openshift-apps/languages.yml | 3 +- playbooks/openshift-apps/maubot.yml | 3 +- playbooks/openshift-apps/mdapi.yml | 3 +- .../openshift-apps/messaging-bridges.yml | 10 +-- .../openshift-apps/monitor_dashboard.yml | 11 +-- playbooks/openshift-apps/monitor_gating.yml | 5 +- playbooks/openshift-apps/mote.yml | 3 +- playbooks/openshift-apps/noggin-centos.yml | 3 +- playbooks/openshift-apps/noggin.yml | 3 +- playbooks/openshift-apps/openscanhub.yml | 3 +- playbooks/openshift-apps/openvpn.yml | 3 +- playbooks/openshift-apps/oraculum.yml | 9 ++- playbooks/openshift-apps/planet.yml | 2 +- playbooks/openshift-apps/poddlers.yml | 3 +- .../openshift-apps/release-monitoring.yml | 4 +- .../openshift-apps/resultsdb-ci-listener.yml | 3 +- playbooks/openshift-apps/review-stats.yml | 3 +- playbooks/openshift-apps/test-auth.yml | 3 +- playbooks/openshift-apps/testdays.yml | 3 +- playbooks/openshift-apps/the-new-hotness.yml | 3 +- playbooks/openshift-apps/toddlers.yml | 3 +- playbooks/openshift-apps/transtats.yml | 3 +- playbooks/openshift-apps/waiverdb.yml | 3 +- playbooks/openshift-apps/webhook2fedmsg.yml | 4 +- playbooks/openshift-apps/zezere.yml | 3 +- playbooks/rdiff-backup.yml | 3 +- playbooks/restart_when_failed.yml | 1 + playbooks/rkhunter_only.yml | 1 + playbooks/rkhunter_update.yml | 1 + playbooks/set_root_auth_keys.yml | 19 ++--- playbooks/ssh_host_keys.yml | 9 ++- playbooks/universe_update.yml | 31 +++---- playbooks/update-proxy-dns.yml | 7 +- playbooks/update_dns.yml | 1 + playbooks/update_ticketkey.yml | 13 +-- playbooks/vhost_halt_guests.yml | 3 +- playbooks/vhost_poweroff.yml | 11 +-- playbooks/vhost_reboot.yml | 20 ++--- playbooks/vhost_update.yml | 41 +++++----- playbooks/vhost_update_reboot.yml | 1 + 204 files changed, 1210 insertions(+), 1046 deletions(-) diff --git a/playbooks/check-for-nonvirt-updates.yml b/playbooks/check-for-nonvirt-updates.yml index 32d05f953f..eb50720adb 100644 --- a/playbooks/check-for-nonvirt-updates.yml +++ b/playbooks/check-for-nonvirt-updates.yml @@ -8,6 +8,7 @@ # time ansible-playbook check-for-updates.yml | grep msg\": | awk -F: '{print $2}' | sort # +--- - name: check for updates (EL) hosts: virt_host:&distro_RedHat gather_facts: false diff --git a/playbooks/check-for-updates.yml b/playbooks/check-for-updates.yml index ddb1850cdb..54e76aa0bb 100644 --- a/playbooks/check-for-updates.yml +++ b/playbooks/check-for-updates.yml @@ -8,6 +8,7 @@ # time ansible-playbook check-for-updates.yml | grep msg\": | awk -F: '{print $2}' | sort # +--- - name: check for updates hosts: distro_RedHat:distro_CentOS:!ocp*:!worker* gather_facts: false diff --git a/playbooks/check-host.yml b/playbooks/check-host.yml index 4376da1216..d4252d9a11 100644 --- a/playbooks/check-host.yml +++ b/playbooks/check-host.yml @@ -12,11 +12,11 @@ - name: create temp dir for collecting info shell: mktemp -d register: temp_dir - changed_when: False + changed_when: false - name: Get list of active loaded services with systemctl shell: '/bin/systemctl -t service --no-legend | egrep "loaded active" | tr -s " " | cut -d " " -f1' - changed_when: False + changed_when: false when: ansible_distribution_major_version|int >= 29 and ansible_distribution == 'Fedora' register: loaded_active_services_systemctl tags: @@ -25,7 +25,7 @@ - name: Get list of active loaded services with systemctl shell: '/bin/systemctl -t service --no-legend | egrep "loaded active" | tr -s " " | cut -d " " -f1' - changed_when: False + changed_when: false when: ansible_distribution_major_version|int > 6 and ansible_distribution == 'RedHat' register: loaded_active_services_systemctl tags: @@ -34,7 +34,7 @@ - name: Get list of inactive loaded services with systemctl shell: '/bin/systemctl -t service --no-legend | egrep -v "loaded active" | tr -s " " | cut -d " " -f1' - changed_when: False + changed_when: false when: ansible_distribution_major_version|int >= 29 and ansible_distribution == 'Fedora' register: loaded_inactive_services_systemctl tags: @@ -43,7 +43,7 @@ - name: Get list of inactive loaded services with systemctl shell: '/bin/systemctl -t service --no-legend | egrep -v "loaded active" | tr -s " " | cut -d " " -f1' - changed_when: False + changed_when: false when: ansible_distribution_major_version|int > 6 and ansible_distribution == 'RedHat' register: loaded_inactive_services_systemctl tags: @@ -53,7 +53,7 @@ - name: Get list of enabled services with chkconfig at current runlevel shell: "chkconfig | grep \"`runlevel | cut -d ' ' -f 2`:on\" | awk '{print $1}'" - changed_when: False + changed_when: false when: ansible_distribution_major_version|int <= 6 and ansible_distribution == 'RedHat' register: enabled_services_chkconfig tags: @@ -62,7 +62,7 @@ - name: Get list of disabled services with chkconfig at current runlevel shell: "chkconfig | grep \"`runlevel | cut -d ' ' -f 2`:off\" | awk '{print $1}'" - changed_when: False + changed_when: false when: ansible_distribution_major_version|int <= 6 and ansible_distribution == 'RedHat' register: disabled_services_chkconfig tags: @@ -73,7 +73,7 @@ - name: output enabled service list chkconfig shell: echo {{enabled_services_chkconfig.stdout_lines}} >> {{temp_dir.stdout}}/eservices when: enabled_services_chkconfig is defined and enabled_services_chkconfig.rc == 0 - changed_when: False + changed_when: false tags: - check - services @@ -81,7 +81,7 @@ - name: output disabled loaded service list chkconfig shell: echo {{disabled_services_chkconfig.stdout_lines}} >> {{temp_dir.stdout}}/dservices when: disabled_services_chkconfig is defined and disabled_services_chkconfig.rc == 0 - changed_when: False + changed_when: false tags: - check - services @@ -90,7 +90,7 @@ - name: output loaded active service list systemctl shell: echo {{loaded_active_services_systemctl.stdout_lines}} >> {{temp_dir.stdout}}/laservices when: loaded_active_services_systemctl is defined and loaded_active_services_systemctl.rc == 0 - changed_when: False + changed_when: false tags: - check - services @@ -98,7 +98,7 @@ - name: output loaded inactive service list systemctl shell: echo {{loaded_inactive_services_systemctl.stdout_lines}} >> {{temp_dir.stdout}}/liservices when: loaded_inactive_services_systemctl is defined and loaded_inactive_services_systemctl.rc == 0 - changed_when: False + changed_when: false tags: - check - services @@ -108,14 +108,14 @@ script: needs-updates --host {{ inventory_hostname }} register: list_update delegate_to: 127.0.0.1 - changed_when: False + changed_when: false tags: - check - updates - name: Show pending updates shell: echo {{list_update.stdout_lines}} >> {{temp_dir.stdout}}/pending_updates - changed_when: False + changed_when: false tags: - check - updates @@ -123,14 +123,14 @@ - name: Get processes that need restarting shell: needs-restarting register: needs_restarting - changed_when: False + changed_when: false tags: - check - restart - name: Show processes that need restarting shell: echo {{needs_restarting.stdout_lines}} >> {{temp_dir.stdout}}/needing_restart - changed_when: False + changed_when: false tags: - check - restart @@ -138,7 +138,7 @@ - name: Get locally changed files from the rpm package shell: rpm_tmp_var=`mktemp` && ! rpm -Va 2>/dev/null > $rpm_tmp_var && [[ -s $rpm_tmp_var ]] && echo $rpm_tmp_var warn=no register: localchanges - changed_when: False + changed_when: false tags: - check - fileverify @@ -146,7 +146,7 @@ - name: Get locally changed files (excluding config files) command: "egrep -v ' c /' {{ localchanges.stdout }}" register: rpm_va_nc - changed_when: False + changed_when: false when: localchanges is defined and localchanges.stdout != "" tags: - check @@ -155,7 +155,7 @@ - name: Show locally changed files (excluding config files) shell: echo {{rpm_va_nc.stdout_lines}} >> {{temp_dir.stdout}}/local_changed when: rpm_va_nc.stdout != "" - changed_when: False + changed_when: false tags: - check - fileverify @@ -164,14 +164,14 @@ command: "egrep ' c /' {{ localchanges.stdout }}" register: rpm_va_c when: localchanges is defined and localchanges.stdout != "" - changed_when: False + changed_when: false tags: - check - fileverify - name: 'Whitelist - Show locally changed files (config files)' shell: echo {{rpm_va_c.stdout_lines}} >> {{temp_dir.stdout}}/local_config_changed - changed_when: False + changed_when: false when: rpm_va_c.stdout != "" tags: - check @@ -180,21 +180,21 @@ - name: Check if using iptables shell: /sbin/iptables -S register: iptablesn - changed_when: False + changed_when: false tags: - check - iptables - name: Show iptables rules shell: echo "{{iptablesn.stdout_lines}}" >> {{ temp_dir.stdout }}/iptables - changed_when: False + changed_when: false tags: - check - iptables - name: Show current SELinux status shell: echo "SELinux is {{ ansible_selinux.status }} for this System" >> {{temp_dir.stdout}}/selinux - changed_when: False + changed_when: false tags: - check - selinux @@ -202,7 +202,7 @@ - name: Show Boot SELinux mode shell: echo "SELinux boots to {{ ansible_selinux.config_mode }} mode " >> {{temp_dir.stdout}}/selinux when: ansible_selinux.status != "disabled" - changed_when: False + changed_when: false tags: - check - selinux @@ -210,7 +210,7 @@ - name: Show Current SELinux mode shell: echo "SELinux currently is in {{ ansible_selinux.mode }} mode" >> {{temp_dir.stdout}}/selinux when: ansible_selinux.status != "disabled" - changed_when: False + changed_when: false tags: - check - selinux @@ -218,7 +218,7 @@ - name: Match current SELinux status with boot status shell: echo "SElinux Current and Boot modes are in sync" >> {{temp_dir.stdout}}/selinux when: ansible_selinux.status != "disabled" and ansible_selinux.config_mode == ansible_selinux.mode - changed_when: False + changed_when: false tags: - check - selinux @@ -227,7 +227,7 @@ - name: misMatch current SELinux status with boot status shell: echo "SElinux Current and Boot modes are NOT in sync" >> {{temp_dir.stdout}}/selinux when: ansible_selinux.status != "disabled" and ansible_selinux.config_mode != ansible_selinux.mode - changed_when: False + changed_when: false tags: - check - selinux @@ -235,51 +235,51 @@ - name: resolve last persisted dir - if one is present local_action: shell ls -d -1 {{datadir_prfx_path}}/{{inventory_hostname}}-* 2>/dev/null | sort -r | head -1 register: last_dir - changed_when: False - ignore_errors: True + changed_when: false + ignore_errors: true - name: get file list shell: ls -1 {{temp_dir.stdout}}/* register: file_list - changed_when: False + changed_when: false - name: get timestamp shell: "date +%Y-%m-%d-%H-%M-%S" register: timestamp - changed_when: False + changed_when: false - name: create persisting-state directory local_action: file path=/{{datadir_prfx_path}}/{{inventory_hostname}}-{{timestamp.stdout}} state=directory - changed_when: False + changed_when: false - name: fetch file list fetch: src={{item}} dest=/{{datadir_prfx_path}}/{{inventory_hostname}}-{{timestamp.stdout}}/ flat=true with_items: "{{file_list.stdout_lines}}" - changed_when: False + changed_when: false - name: diff the new files with last ones presisted local_action: shell for file in {{datadir_prfx_path}}/{{inventory_hostname}}-{{timestamp.stdout}}/*; do filename=$(basename $file); diff {{datadir_prfx_path}}/{{inventory_hostname}}-{{timestamp.stdout}}/$filename {{last_dir.stdout.strip(':')}}/$filename; done - ignore_errors: True - changed_when: False + ignore_errors: true + changed_when: false register: file_diff when: last_dir is defined and last_dir.stdout != "" - name: display diff debug: var=file_diff.stdout_lines - ignore_errors: True - changed_when: False + ignore_errors: true + changed_when: false when: file_diff is defined -#clean up: can also be put as handlers +# clean up: can also be put as handlers - name: clean remote temp dir file: path={{temp_dir.stdout}} state=absent - changed_when: False + changed_when: false - name: clean rpm temp file file: path={{localchanges.stdout}} state=absent - changed_when: False + changed_when: false # handlers: diff --git a/playbooks/checks_log_failed_services.yml b/playbooks/checks_log_failed_services.yml index 66db83a1e5..26e48026f2 100644 --- a/playbooks/checks_log_failed_services.yml +++ b/playbooks/checks_log_failed_services.yml @@ -1,6 +1,7 @@ # # This playbook lets you safely display systemd logs for failed services +--- - hosts: mirrorlist_proxies gather_facts: false diff --git a/playbooks/clear_memcached.yml b/playbooks/clear_memcached.yml index eaae858dad..0f18b12006 100644 --- a/playbooks/clear_memcached.yml +++ b/playbooks/clear_memcached.yml @@ -1,3 +1,4 @@ +--- - name: clear memcache hosts: memcached:memcached-stg serial: 1 diff --git a/playbooks/clear_varnish.yml b/playbooks/clear_varnish.yml index 3f833c46f2..acd6d74532 100644 --- a/playbooks/clear_varnish.yml +++ b/playbooks/clear_varnish.yml @@ -1,3 +1,4 @@ +--- - name: clear varnish cache hosts: proxies user: root diff --git a/playbooks/death_to_postfix.yml b/playbooks/death_to_postfix.yml index bdf3579303..d27ac650ec 100644 --- a/playbooks/death_to_postfix.yml +++ b/playbooks/death_to_postfix.yml @@ -1,21 +1,22 @@ # requires --extra-vars="target='host1:host2:group'" # thanks threebean on this. +--- - name: kills postfix which has been left around alive after update. hosts: "{{ target }}" user: root tasks: - - name: Try to stop postfix cleanly. - service: name=postfix state=stopped + - name: Try to stop postfix cleanly. + service: name=postfix state=stopped - # This doesn't really remove the pid file.. but we say it does so ansible only runs it if the pid file is there.. - - name: Really kill postfix master process - command: pkill -u root master removes=/var/spool/postfix/pid/master.pid + # This doesn't really remove the pid file.. but we say it does so ansible only runs it if the pid file is there.. + - name: Really kill postfix master process + command: pkill -u root master removes=/var/spool/postfix/pid/master.pid - - name: Clean up old pid lock file. - command: rm /var/spool/postfix/pid/master.pid removes=/var/spool/postfix/pid/master.pid + - name: Clean up old pid lock file. + command: rm /var/spool/postfix/pid/master.pid removes=/var/spool/postfix/pid/master.pid - - name: Try to start postfix cleanly - service: name=postfix state=started + - name: Try to start postfix cleanly + service: name=postfix state=started diff --git a/playbooks/destroy_virt_inst.yml b/playbooks/destroy_virt_inst.yml index 008f67ccbf..162b0c297d 100644 --- a/playbooks/destroy_virt_inst.yml +++ b/playbooks/destroy_virt_inst.yml @@ -9,6 +9,7 @@ # requires --extra-vars="target=hostspec" +--- - name: destroy and undefine vm hosts: "{{ target }}" user: root diff --git a/playbooks/groups/backup-server.yml b/playbooks/groups/backup-server.yml index 90e287fad6..5e28cd2f86 100644 --- a/playbooks/groups/backup-server.yml +++ b/playbooks/groups/backup-server.yml @@ -3,15 +3,16 @@ # NOTE: make sure there is room/space for this instance on the buildvmhost # NOTE: most of these vars_path come from group_vars/backup_server or from hostvars +--- - name: make backup server system hosts: backup user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/bastion.yml b/playbooks/groups/bastion.yml index 0989a8e0d9..29e3f35082 100644 --- a/playbooks/groups/bastion.yml +++ b/playbooks/groups/bastion.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "bastion" @@ -5,12 +6,12 @@ - name: make the boxen be real for real hosts: bastion user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -34,4 +35,3 @@ handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/groups/batcave.yml b/playbooks/groups/batcave.yml index 9f60b949a5..87d2ee8e09 100644 --- a/playbooks/groups/batcave.yml +++ b/playbooks/groups/batcave.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "batcave" @@ -5,12 +6,12 @@ - name: make the box be real hosts: batcave user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -54,8 +55,8 @@ - batcave - role: grobisplitter when: datacenter == 'iad2' - - { role: nfs/client, when: inventory_hostname.startswith('batcave'), mnt_dir: '/srv/web/pub', nfs_src_dir: 'fedora_ftp/fedora.redhat.com/pub' } - - { role: nfs/client, when: inventory_hostname.startswith('batcave01'), mnt_dir: '/mnt/fedora/app', nfs_src_dir: 'fedora_app/app' } + - { role: nfs/client, when: inventory_hostname.startswith('batcave'), mnt_dir: '/srv/web/pub', nfs_src_dir: 'fedora_ftp/fedora.redhat.com/pub' } + - { role: nfs/client, when: inventory_hostname.startswith('batcave01'), mnt_dir: '/mnt/fedora/app', nfs_src_dir: 'fedora_app/app' } - { role: mirror_pagure_ansible, tags: ['mirror_pagure_ansible'] } pre_tasks: diff --git a/playbooks/groups/bodhi-backend.yml b/playbooks/groups/bodhi-backend.yml index 350592ba64..e884f0c8ff 100644 --- a/playbooks/groups/bodhi-backend.yml +++ b/playbooks/groups/bodhi-backend.yml @@ -5,6 +5,7 @@ # They also run some misc releng scripts. # +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "bodhi_backend:bodhi_backend_stg" @@ -14,7 +15,7 @@ - name: make bodhi-backend server system hosts: bodhi_backend:bodhi_backend_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/build-kcs.yml b/playbooks/groups/build-kcs.yml index e285f65df3..224dc7cdd5 100644 --- a/playbooks/groups/build-kcs.yml +++ b/playbooks/groups/build-kcs.yml @@ -3,10 +3,11 @@ # Creation of the system is done by a different process so is not # covered by this playbook. +--- - name: enable an ephemeral builder hosts: build_x86_kcs:build_x86_kcs_stg user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/buildhw.yml b/playbooks/groups/buildhw.yml index ce6717cde6..298c13ee9f 100644 --- a/playbooks/groups/buildhw.yml +++ b/playbooks/groups/buildhw.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/happy_birthday.yml" vars: myhosts: "buildhw:bkernel" @@ -5,12 +6,12 @@ - name: make koji builder(s) on raw hw hosts: buildhw:bkernel remote_user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -33,7 +34,7 @@ roles: - base - - { role: nfs/client, mnt_dir: '/mnt/fedora_koji', nfs_src_dir: "{{ koji_hub_nfs }}", when: koji_hub_nfs is defined } + - { role: nfs/client, mnt_dir: '/mnt/fedora_koji', nfs_src_dir: "{{ koji_hub_nfs }}", when: koji_hub_nfs is defined } - role: nfs/client mnt_dir: '/mnt/koji/ostree' nfs_src_dir: 'fedora_ostree_content/ostree' diff --git a/playbooks/groups/buildvm-osbuild.yml b/playbooks/groups/buildvm-osbuild.yml index 87863ca9c9..221bf098ec 100644 --- a/playbooks/groups/buildvm-osbuild.yml +++ b/playbooks/groups/buildvm-osbuild.yml @@ -1,5 +1,6 @@ # create a new osbuild worker +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "buildvm_osbuild_ppc64le:buildvm_osbuild_ppc64le_staging" @@ -7,7 +8,7 @@ - name: make osbuild-worker hosts: buildvm_osbuild_ppc64le:buildvm_osbuild_ppc64le_staging user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/buildvm.yml b/playbooks/groups/buildvm.yml index eb2b14956b..c3a3f8251a 100644 --- a/playbooks/groups/buildvm.yml +++ b/playbooks/groups/buildvm.yml @@ -3,6 +3,7 @@ # NOTE: make sure there is room/space for this builder on the buildvmhost # NOTE: most of these vars_path come from group_vars/buildvm or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "buildvm:buildvm_stg:buildvm_aarch64:buildvm_ppc64le:buildvm_ppc64le_stg:buildvm_aarch64_stg:buildvm_s390x_kvm" @@ -10,7 +11,7 @@ - name: make koji builder(s) hosts: buildvm:buildvm_stg:buildvm_aarch64:buildvm_ppc64le:buildvm_ppc64le_stg:buildvm_aarch64_stg:buildvm_s390x:buildvm_s390x_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -25,11 +26,11 @@ - base - hosts - { - role: nfs/client, - mnt_dir: "/mnt/fedora_koji", - nfs_src_dir: "{{ koji_hub_nfs }}", - when: "env == 'staging' or createrepo or 'runroot' in group_names and not inventory_hostname.startswith('buildvm-s390x')", - } + role: nfs/client, + mnt_dir: "/mnt/fedora_koji", + nfs_src_dir: "{{ koji_hub_nfs }}", + when: "env == 'staging' or createrepo or 'runroot' in group_names and not inventory_hostname.startswith('buildvm-s390x')", + } - ipa/client - role: sudo when: not inventory_hostname.startswith('bkernel') and env == 'production' @@ -86,7 +87,7 @@ tags: - varnish user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -104,7 +105,7 @@ tags: - sshfs user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/busgateway.yml b/playbooks/groups/busgateway.yml index 807c3a4fb7..e3b365f5df 100644 --- a/playbooks/groups/busgateway.yml +++ b/playbooks/groups/busgateway.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "busgateway:busgateway_stg" @@ -5,12 +6,12 @@ - name: dole out the generic configuration hosts: busgateway:busgateway_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -36,11 +37,11 @@ - name: dole out the service-specific config hosts: busgateway:busgateway_stg user: root - gather_facts: True + gather_facts: true roles: - role: fedmsg/hub - enable_websocket_server: True + enable_websocket_server: true - role: fedmsg/relay - role: fedmsg/gateway - role: collectd/fedmsg-service @@ -52,9 +53,9 @@ - role: collectd/fedmsg-activation vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - "{{ vars_path }}/{{ ansible_distribution }}.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - "{{ vars_path }}/{{ ansible_distribution }}.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/centos-ipa-client.yml b/playbooks/groups/centos-ipa-client.yml index 53d59bca5c..a9eb6ee307 100644 --- a/playbooks/groups/centos-ipa-client.yml +++ b/playbooks/groups/centos-ipa-client.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "centos_ipa_client_stg" @@ -5,21 +6,19 @@ - name: make the boxes be realen hosts: centos_ipa_client_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base - hosts - + pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - - diff --git a/playbooks/groups/certgetter.yml b/playbooks/groups/certgetter.yml index 00db8c92b6..e07c01911c 100644 --- a/playbooks/groups/certgetter.yml +++ b/playbooks/groups/certgetter.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "certgetter" @@ -5,12 +6,12 @@ - name: make the box be real hosts: certgetter user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/copr-backend.yml b/playbooks/groups/copr-backend.yml index 10e0a2157e..ce8a3f35b6 100644 --- a/playbooks/groups/copr-backend.yml +++ b/playbooks/groups/copr-backend.yml @@ -1,11 +1,12 @@ +--- - name: check/create instance hosts: copr_back_dev_aws:copr_back_aws user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -25,10 +26,10 @@ - name: cloud basic setup hosts: copr_back_dev_aws:copr_back_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -45,12 +46,12 @@ - name: provision instance hosts: copr_back_dev_aws:copr_back_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml # Roles are run first, before tasks, regardless of where you place them here. roles: diff --git a/playbooks/groups/copr-dist-git.yml b/playbooks/groups/copr-dist-git.yml index a369e5690e..8c1c3cd8a7 100644 --- a/playbooks/groups/copr-dist-git.yml +++ b/playbooks/groups/copr-dist-git.yml @@ -1,11 +1,12 @@ +--- - name: check/create instance hosts: copr_dist_git_dev_aws:copr_dist_git_aws user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -20,10 +21,10 @@ - name: cloud basic setup hosts: copr_dist_git_dev_aws:copr_dist_git_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -41,12 +42,12 @@ - name: provision instance hosts: copr_dist_git_dev_aws:copr_dist_git_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/copr-frontend.yml b/playbooks/groups/copr-frontend.yml index 3f7f89f709..d54cf3b34d 100644 --- a/playbooks/groups/copr-frontend.yml +++ b/playbooks/groups/copr-frontend.yml @@ -1,11 +1,12 @@ +--- - name: check/create instance hosts: copr_front_dev_aws:copr_front_aws user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -25,10 +26,10 @@ - name: cloud basic setup hosts: copr_front_dev_aws:copr_front_aws - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -41,14 +42,14 @@ - name: provision instance hosts: copr_front_dev_aws:copr_front_aws - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - - base - - nagios_client - - copr/frontend + - base + - nagios_client + - copr/frontend diff --git a/playbooks/groups/copr-hypervisor.yml b/playbooks/groups/copr-hypervisor.yml index 99fee5feba..a57380dcbf 100644 --- a/playbooks/groups/copr-hypervisor.yml +++ b/playbooks/groups/copr-hypervisor.yml @@ -1,12 +1,13 @@ +--- - name: Setup copr hypervisor hosts hosts: copr_hypervisor user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "{{ private }}/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "{{ private }}/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_role: name=copr/reboot diff --git a/playbooks/groups/copr-keygen.yml b/playbooks/groups/copr-keygen.yml index 7a559b8fa6..a5ff0b7a8a 100644 --- a/playbooks/groups/copr-keygen.yml +++ b/playbooks/groups/copr-keygen.yml @@ -1,10 +1,11 @@ +--- - name: check/create instance hosts: copr_keygen_dev_aws:copr_keygen_aws - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -20,7 +21,7 @@ - name: gather facts setup: check_mode: no - ignore_errors: True + ignore_errors: true register: facts - name: install python2 and dnf stuff raw: dnf -y install python-dnf libselinux-python yum @@ -28,10 +29,10 @@ - name: cloud basic setup hosts: copr_keygen_dev_aws:copr_keygen_aws - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -44,12 +45,12 @@ - name: provision instance hosts: copr_keygen_dev_aws:copr_keygen_aws - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/copr-pulp.yml b/playbooks/groups/copr-pulp.yml index 56e729329d..057dd4616d 100644 --- a/playbooks/groups/copr-pulp.yml +++ b/playbooks/groups/copr-pulp.yml @@ -53,7 +53,7 @@ copy: content: "{{ copr_dev_pulp_default_admin_password }}" dest: /tmp/pulp_default_admin_password - mode: 000 + mode: "000" - name: cloud basic setup hosts: copr_pulp_dev_aws:copr_pulp_aws diff --git a/playbooks/groups/data-reports.yml b/playbooks/groups/data-reports.yml index c67815e56d..1dd6c33e8c 100644 --- a/playbooks/groups/data-reports.yml +++ b/playbooks/groups/data-reports.yml @@ -1,6 +1,7 @@ # create a data-reports vm # +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "data_reports" @@ -8,12 +9,12 @@ - name: make the box be real hosts: data_reports user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" diff --git a/playbooks/groups/db.aws.yml b/playbooks/groups/db.aws.yml index 50452c44bb..5f66ac002e 100644 --- a/playbooks/groups/db.aws.yml +++ b/playbooks/groups/db.aws.yml @@ -3,14 +3,15 @@ # Once the instance exists, configure it. +--- - name: check/create instance hosts: db.stg.aws.fedoraproject.org user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -27,10 +28,10 @@ - name: cloud basic setup hosts: db.stg.aws.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -41,12 +42,12 @@ - name: configure server hosts: db.stg.aws.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README @@ -63,12 +64,12 @@ - base - rkhunter # - {role: ipa/client, when: env == "staging"} - #- nagios_client - #- zabbix/zabbix_agent + # - nagios_client + # - zabbix/zabbix_agent - hosts - postgresql_server - #- collectd/base - #- collectd/postgres # This requires a 'databases' var to be set in host_vars + # - collectd/base + # - collectd/postgres # This requires a 'databases' var to be set in host_vars - sudo tasks: diff --git a/playbooks/groups/debuginfod.yml b/playbooks/groups/debuginfod.yml index 668f25ef55..4d23f87635 100644 --- a/playbooks/groups/debuginfod.yml +++ b/playbooks/groups/debuginfod.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "debuginfod:debuginfod_stg" diff --git a/playbooks/groups/dns.yml b/playbooks/groups/dns.yml index f5cc760d50..30ccab5e83 100644 --- a/playbooks/groups/dns.yml +++ b/playbooks/groups/dns.yml @@ -1,5 +1,6 @@ # create a new dns server +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "dns" @@ -7,12 +8,12 @@ - name: make the box be real hosts: dns user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/download.yml b/playbooks/groups/download.yml index 941929322f..4efde5c46b 100644 --- a/playbooks/groups/download.yml +++ b/playbooks/groups/download.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "download_ibiblio:download_cc_rdu:download_iad2" @@ -5,12 +6,12 @@ - name: Download servers hosts: download user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: @@ -21,12 +22,12 @@ - name: post-initial-steps hosts: download user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - "/srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - "/srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml" roles: - base @@ -39,9 +40,9 @@ - apache - download - rsyncd - - { role: nfs/client, when: datacenter == "iad2" or datacenter == "rdu", mnt_dir: '/srv/pub', nfs_src_dir: 'fedora_ftp/fedora.redhat.com/pub' } - - { role: nfs/client, when: datacenter == "iad2" or datacenter == "rdu", mnt_dir: '/srv/pub/archive', nfs_src_dir: 'fedora_ftp_archive' } - - { role: nfs/client, when: datacenter == "iad2", mnt_dir: '/mnt/fedora_koji', nfs_src_dir: 'fedora_koji' } # needed for internal sync + - { role: nfs/client, when: datacenter == "iad2" or datacenter == "rdu", mnt_dir: '/srv/pub', nfs_src_dir: 'fedora_ftp/fedora.redhat.com/pub' } + - { role: nfs/client, when: datacenter == "iad2" or datacenter == "rdu", mnt_dir: '/srv/pub/archive', nfs_src_dir: 'fedora_ftp_archive' } + - { role: nfs/client, when: datacenter == "iad2", mnt_dir: '/mnt/fedora_koji', nfs_src_dir: 'fedora_koji' } # needed for internal sync - sudo pre_tasks: @@ -68,7 +69,7 @@ when: inventory_hostname == 'download-ib01.fedoraproject.org' - name: install bc so last-sync works. package: name=bc state=present - when: inventory_hostname == 'download-ib01.fedoraproject.org' + when: inventory_hostname == 'download-ib01.fedoraproject.org' - name: put in script for syncing on download-cc-rdu01 copy: src="{{ files }}/download/sync-up-downloads.sh.cc-rdu01" dest=/usr/local/bin/sync-up-downloads owner=root group=root mode=755 @@ -86,7 +87,6 @@ - name: make a mnt/koji link file: state=link src=/mnt/fedora_koji/koji dest=/mnt/koji when: datacenter == "iad2" - + handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/groups/flatpak-cache.yml b/playbooks/groups/flatpak-cache.yml index 4a5d3b84b8..468346d734 100644 --- a/playbooks/groups/flatpak-cache.yml +++ b/playbooks/groups/flatpak-cache.yml @@ -6,12 +6,12 @@ - name: make the box be real hosts: flatpak_cache user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/github2fedmsg.yml b/playbooks/groups/github2fedmsg.yml index e27687d49b..08aefeee11 100644 --- a/playbooks/groups/github2fedmsg.yml +++ b/playbooks/groups/github2fedmsg.yml @@ -3,6 +3,7 @@ # NOTE: make sure there is room/space for this server on the vmhost # NOTE: most of these vars_path come from group_vars/github2fedmsg* or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "github2fedmsg:github2fedmsg_stg" @@ -10,12 +11,12 @@ - name: make the box be real hosts: github2fedmsg:github2fedmsg_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -43,12 +44,12 @@ - name: deploy service-specific config hosts: github2fedmsg:github2fedmsg_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/ipa.yml b/playbooks/groups/ipa.yml index 19d32f26d6..fad9624bb1 100644 --- a/playbooks/groups/ipa.yml +++ b/playbooks/groups/ipa.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "ipa:ipa_stg" @@ -5,7 +6,7 @@ - name: make the box be real hosts: ipa:ipa_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -37,7 +38,7 @@ - name: deploy ipa itself hosts: ipa:ipa_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -73,7 +74,7 @@ - krb5 - ipa/server # original: /etc/httpd/conf/ipa.keytab - #- name: Make IPA HTTP use the combined keytab + # - name: Make IPA HTTP use the combined keytab # lineinfile: dest=/etc/httpd/conf.d/ipa.conf # regexp='GssapiCredStore keytab:' # line=' GssapiCredStore keytab:/etc/krb5.HTTP_id{{env_suffix}}.fedoraproject.org.keytab.combined' @@ -81,7 +82,7 @@ # - krb5 # - ipa/server # - config - #- name: Make IPA HTTP use the id.fp.o client keytab + # - name: Make IPA HTTP use the id.fp.o client keytab # lineinfile: dest=/etc/httpd/conf.d/ipa.conf # regexp='GssapiCredStore client_keytab:' # line=' GssapiCredStore client_keytab:/etc/krb5.HTTP_id{{env_suffix}}.fedoraproject.org.keytab' @@ -93,7 +94,7 @@ - name: do base role once more to revert any resolvconf changes hosts: ipa:ipa_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/ipsilon.yml b/playbooks/groups/ipsilon.yml index ababb620e9..6a020a73d2 100644 --- a/playbooks/groups/ipsilon.yml +++ b/playbooks/groups/ipsilon.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "ipsilon:ipsilon_stg" @@ -6,7 +7,7 @@ - name: make the box be real hosts: ipsilon:ipsilon_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -46,7 +47,7 @@ - name: deploy ipsilon itself hosts: ipsilon:ipsilon_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -68,7 +69,7 @@ - name: setup IPA hosts: ipa[0]:ipa_stg[0] user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/koji-hub.yml b/playbooks/groups/koji-hub.yml index 3c0e88bbb7..6b2b3326c4 100644 --- a/playbooks/groups/koji-hub.yml +++ b/playbooks/groups/koji-hub.yml @@ -2,6 +2,7 @@ # NOTE: should be used with --limit most of the time # NOTE: most of these vars_path come from group_vars/koji-hub or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "koji_stg:koji" @@ -11,12 +12,12 @@ - name: make koji_hub server system hosts: koji_stg:koji user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README @@ -133,12 +134,12 @@ tags: - sshfs user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Put public sshfs key in place diff --git a/playbooks/groups/kojipkgs.yml b/playbooks/groups/kojipkgs.yml index e8f3301309..e9b64f04da 100644 --- a/playbooks/groups/kojipkgs.yml +++ b/playbooks/groups/kojipkgs.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "kojipkgs" @@ -5,12 +6,12 @@ - name: make the boxen be real for real hosts: kojipkgs user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" diff --git a/playbooks/groups/logserver.yml b/playbooks/groups/logserver.yml index 9af740b0a7..50be1b7bad 100644 --- a/playbooks/groups/logserver.yml +++ b/playbooks/groups/logserver.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "logging" @@ -5,12 +6,12 @@ - name: make the box be real hosts: logging user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -57,12 +58,12 @@ - name: Cloud Image stats hosts: log01.iad2.fedoraproject.org user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - cloudstats @@ -73,34 +74,34 @@ - name: dole out the service-specific config hosts: log01.iad2.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" roles: - - role: nfs/client - mnt_dir: '/mnt/fedora_stats' - nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" - nfs_src_dir: 'fedora_stats' - - geoip + - role: nfs/client + mnt_dir: '/mnt/fedora_stats' + nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" + nfs_src_dir: 'fedora_stats' + - geoip tasks: - - name: install needed packages - package: name={{ item }} state=present - with_items: - - httpd - - httpd-tools - - mod_ssl - - rsync - - emacs-nox - - git - - bc - - gnuplot - - mod_auth_gssapi + - name: install needed packages + package: name={{ item }} state=present + with_items: + - httpd + - httpd-tools + - mod_ssl + - rsync + - emacs-nox + - git + - bc + - gnuplot + - mod_auth_gssapi - - name: set domain_can_mmap_files so collectd works - seboolean: name=domain_can_mmap_files state=yes persistent=yes + - name: set domain_can_mmap_files so collectd works + seboolean: name=domain_can_mmap_files state=yes persistent=yes diff --git a/playbooks/groups/maintainer-test.yml b/playbooks/groups/maintainer-test.yml index 19a92ff73c..1c71825616 100644 --- a/playbooks/groups/maintainer-test.yml +++ b/playbooks/groups/maintainer-test.yml @@ -1,13 +1,14 @@ +--- - name: Setup maintainer test hosts hosts: maintainer_test - gather_facts: True + gather_facts: true tags: - - maintainer-test + - maintainer-test vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README diff --git a/playbooks/groups/mariadb-server.yml b/playbooks/groups/mariadb-server.yml index c78ef4be76..46821d616d 100644 --- a/playbooks/groups/mariadb-server.yml +++ b/playbooks/groups/mariadb-server.yml @@ -2,6 +2,7 @@ # NOTE: should be used with --limit most of the time # NOTE: most of these vars_path come from group_vars/backup_server or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "db03.stg.iad2.fedoraproject.org:db03.iad2.fedoraproject.org" @@ -11,12 +12,12 @@ - name: configure mariadb server system hosts: db03.stg.iad2.fedoraproject.org:db03.iad2.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/memcached.yml b/playbooks/groups/memcached.yml index e43277addf..9eeaef3ce9 100644 --- a/playbooks/groups/memcached.yml +++ b/playbooks/groups/memcached.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "memcached:memcached_stg" @@ -5,7 +6,7 @@ - name: make the box be real hosts: memcached:memcached_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/nfs-servers.yml b/playbooks/groups/nfs-servers.yml index 7b6f7c5f0a..4875d3579c 100644 --- a/playbooks/groups/nfs-servers.yml +++ b/playbooks/groups/nfs-servers.yml @@ -1,14 +1,15 @@ # This is a basic playbook +--- - name: dole out the basic configuration hosts: nfs_servers user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -33,11 +34,11 @@ - name: Deal with drive items on storinator01 hosts: storinator01.rdu-cc.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -75,11 +76,11 @@ - name: Deal with NFS hosts: storinator01.rdu-cc.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" roles: diff --git a/playbooks/groups/noc.yml b/playbooks/groups/noc.yml index 94ff525e4b..299f7a7236 100644 --- a/playbooks/groups/noc.yml +++ b/playbooks/groups/noc.yml @@ -1,4 +1,5 @@ # This is a basic playbook +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "nagios" @@ -6,12 +7,12 @@ - name: make the box be real hosts: nagios user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -27,7 +28,7 @@ - { role: rsyncd, when: datacenter == 'iad2' } - sudo - apache - #- mod_wsgi + # - mod_wsgi - role: keytab/service owner_user: apache owner_group: apache @@ -39,7 +40,7 @@ owner_group: apache service: HTTP host: "nagios-external{{env_suffix}}.fedoraproject.org" - when: datacenter != 'iad2' + when: datacenter != 'iad2' - { role: letsencrypt, site_name: 'nagios-external.fedoraproject.org', when: inventory_hostname.startswith('noc02') } tasks: @@ -51,12 +52,12 @@ - name: deploy service-specific config (just for production) hosts: nagios user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/oci-registry.yml b/playbooks/groups/oci-registry.yml index baa5dd1c34..0f75beb977 100644 --- a/playbooks/groups/oci-registry.yml +++ b/playbooks/groups/oci-registry.yml @@ -1,17 +1,18 @@ # create an osbs server -- import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" +--- +- import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "oci_registry:oci_registry_stg" - name: make the box be real hosts: oci_registry:oci_registry_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -42,7 +43,7 @@ state: directory owner: root group: root - mode: 0755 + mode: "0755" when: "env == 'staging'" - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -66,39 +67,39 @@ roles: - { role: docker-distribution, - conf_path: "/etc/docker-distribution/registry/config.yml", - tls: { - enabled: False, - }, - log: { - fields: { - service: "registry" - } - }, - storage: { - filesystem: { - rootdirectory: "/srv/registry" - } - }, - http: { - addr: ":5000" + conf_path: "/etc/docker-distribution/registry/config.yml", + tls: { + enabled: false, + }, + log: { + fields: { + service: "registry" } + }, + storage: { + filesystem: { + rootdirectory: "/srv/registry" + } + }, + http: { + addr: ":5000" } + } # Setup compose-x86-01 push docker images to registry - { role: login-registry, - candidate_registry: "candidate-registry.stg.fedoraproject.org", - candidate_registry_osbs_username: "{{candidate_registry_osbs_stg_username}}", - candidate_registry_osbs_password: "{{candidate_registry_osbs_stg_password}}", + candidate_registry: "candidate-registry.stg.fedoraproject.org", + candidate_registry_osbs_username: "{{candidate_registry_osbs_stg_username}}", + candidate_registry_osbs_password: "{{candidate_registry_osbs_stg_password}}", when: env == "staging", delegate_to: "compose-x86-01.{{ datacenter }}.fedoraproject.org" } - { role: login-registry, - candidate_registry: "candidate-registry.fedoraproject.org", - candidate_registry_osbs_username: "{{candidate_registry_osbs_prod_username}}", - candidate_registry_osbs_password: "{{candidate_registry_osbs_prod_password}}", + candidate_registry: "candidate-registry.fedoraproject.org", + candidate_registry_osbs_username: "{{candidate_registry_osbs_prod_username}}", + candidate_registry_osbs_password: "{{candidate_registry_osbs_prod_password}}", when: env == "production", delegate_to: "compose-x86-01.{{ datacenter }}.fedoraproject.org" } diff --git a/playbooks/groups/openqa-onebox-test.yml b/playbooks/groups/openqa-onebox-test.yml index 332b6003c0..fc00db2275 100644 --- a/playbooks/groups/openqa-onebox-test.yml +++ b/playbooks/groups/openqa-onebox-test.yml @@ -1,49 +1,50 @@ +--- - name: setup base openQA host hosts: openqa_onebox_test user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README - import_tasks: "{{ tasks_path }}/yumrepos.yml" roles: - - { role: base, tags: ['base'] } - - { role: rkhunter, tags: ['rkhunter'] } - - { role: nagios_client, tags: ['nagios_client'] } - - { role: hosts, tags: ['hosts']} - - ipa/client - - { role: collectd/base, tags: ['collectd_base'] } - - { role: sudo, tags: ['sudo'] } - - apache + - { role: base, tags: ['base'] } + - { role: rkhunter, tags: ['rkhunter'] } + - { role: nagios_client, tags: ['nagios_client'] } + - { role: hosts, tags: ['hosts']} + - ipa/client + - { role: collectd/base, tags: ['collectd_base'] } + - { role: sudo, tags: ['sudo'] } + - apache tasks: - import_tasks: "{{ tasks_path }}/motd.yml" handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" - name: configure openQA hosts: openqa_onebox_test user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml # we need this box to be its own pgsql server... roles: - - { role: postgresql_server, tags: ['postgresql_server'] } - - { role: openqa/server, tags: ['openqa_server'] } - - { role: openqa/dispatcher, tags: ['openqa_dispatcher'] } - - { role: openqa/worker, tags: ['openqa_worker'] } + - { role: postgresql_server, tags: ['postgresql_server'] } + - { role: openqa/server, tags: ['openqa_server'] } + - { role: openqa/dispatcher, tags: ['openqa_dispatcher'] } + - { role: openqa/worker, tags: ['openqa_worker'] } handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/openqa-workers.yml b/playbooks/groups/openqa-workers.yml index badd71f192..01ba9bec68 100644 --- a/playbooks/groups/openqa-workers.yml +++ b/playbooks/groups/openqa-workers.yml @@ -1,31 +1,32 @@ +--- - name: configure openQA workers hosts: openqa_workers:openqa_lab_workers user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README - import_tasks: "{{ tasks_path }}/yumrepos.yml" roles: - - { role: base, tags: ['base'] } - - { role: rkhunter, tags: ['rkhunter'] } - - { role: nagios_client, tags: ['nagios_client'] } - - { role: hosts, tags: ['hosts']} - - { role: ipa/client, tags: ['ipa_client']} - - { role: collectd/base, tags: ['collectd_base'] } - - { role: sudo, tags: ['sudo'] } - - { role: openqa/worker, tags: ['openqa_worker'] } - - { role: linux-system-roles.nbde_client, tags: ['nbde_client'], when: openqa_nbde|bool } - - apache + - { role: base, tags: ['base'] } + - { role: rkhunter, tags: ['rkhunter'] } + - { role: nagios_client, tags: ['nagios_client'] } + - { role: hosts, tags: ['hosts']} + - { role: ipa/client, tags: ['ipa_client']} + - { role: collectd/base, tags: ['collectd_base'] } + - { role: sudo, tags: ['sudo'] } + - { role: openqa/worker, tags: ['openqa_worker'] } + - { role: linux-system-roles.nbde_client, tags: ['nbde_client'], when: openqa_nbde|bool } + - apache tasks: - import_tasks: "{{ tasks_path }}/motd.yml" handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/openqa.yml b/playbooks/groups/openqa.yml index a6e82306be..f399a16ecc 100644 --- a/playbooks/groups/openqa.yml +++ b/playbooks/groups/openqa.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "openqa:openqa_lab" @@ -5,42 +6,42 @@ - name: setup base openQA host hosts: openqa:openqa_lab user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README - import_tasks: "{{ tasks_path }}/yumrepos.yml" roles: - - { role: base, tags: ['base'] } - - { role: rkhunter, tags: ['rkhunter'] } - - { role: nagios_client, tags: ['nagios_client'] } - - { role: hosts, tags: ['hosts']} - - ipa/client - - { role: collectd/base, tags: ['collectd_base'] } - - { role: sudo, tags: ['sudo'] } - - apache + - { role: base, tags: ['base'] } + - { role: rkhunter, tags: ['rkhunter'] } + - { role: nagios_client, tags: ['nagios_client'] } + - { role: hosts, tags: ['hosts']} + - ipa/client + - { role: collectd/base, tags: ['collectd_base'] } + - { role: sudo, tags: ['sudo'] } + - apache tasks: - import_tasks: "{{ tasks_path }}/motd.yml" handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" - name: configure fedora-messaging queues on openQA servers hosts: openqa:openqa_lab user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: # we must always make sure the prod user exists, as stg uses the @@ -149,9 +150,9 @@ hosts: openqa_lab vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - role: nfs/client @@ -166,15 +167,15 @@ tags: ['nfs_client'] handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" - name: set up openQA server data NFS mounts (prod) hosts: openqa vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - role: nfs/client @@ -189,28 +190,28 @@ tags: ['nfs_client'] handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" - name: configure openQA hosts: openqa:openqa_lab user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml # relvalconsumer isn't particularly related to openQA in any way, we # just put that role on these boxes. There's nowhere more obviously # correct for it, really. Ditto fedora_nightlies and testcase_stats roles: - - { role: openqa/server, tags: ['openqa_server'] } - - { role: openqa/dispatcher, tags: ['openqa_dispatcher'] } - - { role: check-compose, tags: ['check-compose'], when: "checkcompose_amqp_queue is defined" } - - { role: relvalconsumer, tags: ['relvalconsumer'], when: "relvalconsumer_amqp_queue is defined" } - - { role: fedora_nightlies, tags: ['fedora_nightlies'], when: "fedora_nightlies_amqp_queue is defined" } - - { role: testcase_stats, tags: ['testcase_stats'], when: "testcase_stats_output_dir is defined" } + - { role: openqa/server, tags: ['openqa_server'] } + - { role: openqa/dispatcher, tags: ['openqa_dispatcher'] } + - { role: check-compose, tags: ['check-compose'], when: "checkcompose_amqp_queue is defined" } + - { role: relvalconsumer, tags: ['relvalconsumer'], when: "relvalconsumer_amqp_queue is defined" } + - { role: fedora_nightlies, tags: ['fedora_nightlies'], when: "fedora_nightlies_amqp_queue is defined" } + - { role: testcase_stats, tags: ['testcase_stats'], when: "testcase_stats_output_dir is defined" } handlers: - - import_tasks: "{{ handlers_path }}/restart_services.yml" + - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/groups/os-control.yml b/playbooks/groups/os-control.yml index e88629eb1e..2826f0d152 100644 --- a/playbooks/groups/os-control.yml +++ b/playbooks/groups/os-control.yml @@ -1,4 +1,5 @@ # This is a basic playbook +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "os_control:os_control_stg" @@ -6,7 +7,7 @@ - name: make the box be real hosts: os_control:os_control_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -30,7 +31,7 @@ state: directory owner: root group: root - mode: 0770 + mode: "0770" - name: copy oc rpm copy: @@ -46,7 +47,7 @@ copy: src: "{{ files }}/scripts/jobs-summary" dest: /usr/local/bin/jobs-summary - mode: 0755 + mode: "0755" - import_tasks: "{{ tasks_path }}/yumrepos.yml" - import_tasks: "{{ tasks_path }}/motd.yml" diff --git a/playbooks/groups/os-proxies.yml b/playbooks/groups/os-proxies.yml index ad9370efbb..e5e8b5ad4c 100644 --- a/playbooks/groups/os-proxies.yml +++ b/playbooks/groups/os-proxies.yml @@ -1,5 +1,6 @@ # create a new proxy server +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "os_proxies" @@ -7,12 +8,12 @@ - name: make the box be real hosts: os_proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README @@ -40,4 +41,3 @@ handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/groups/pagure.yml b/playbooks/groups/pagure.yml index 0facc93288..54bf5f744e 100644 --- a/playbooks/groups/pagure.yml +++ b/playbooks/groups/pagure.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "pagure:pagure_stg" @@ -5,12 +6,12 @@ - name: make the boxen be real for real hosts: pagure:pagure_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -36,12 +37,12 @@ - name: deploy pagure itself hosts: pagure:pagure_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - "{{ vars_path }}/{{ ansible_distribution }}.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - "{{ vars_path }}/{{ ansible_distribution }}.yml" roles: diff --git a/playbooks/groups/postgresql-server.yml b/playbooks/groups/postgresql-server.yml index 48f439dbe7..b326b3477f 100644 --- a/playbooks/groups/postgresql-server.yml +++ b/playbooks/groups/postgresql-server.yml @@ -2,6 +2,7 @@ # NOTE: should be used with --limit most of the time # NOTE: most of these vars_path come from group_vars/backup_server or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "db-fas01.stg.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org:db-datanommer01.stg.iad2.fedoraproject.org:db-datanommer02.iad2.fedoraproject.org" @@ -11,7 +12,7 @@ - name: configure postgresql server system hosts: db-fas01.stg.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org:db-datanommer01.stg.iad2.fedoraproject.org:db-datanommer02.iad2.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/proxies.yml b/playbooks/groups/proxies.yml index 90e5659ec9..aa600930db 100644 --- a/playbooks/groups/proxies.yml +++ b/playbooks/groups/proxies.yml @@ -1,5 +1,6 @@ # create a new proxy server +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "proxies:proxies_stg:!proxy05.fedoraproject.org:!cloud_aws" @@ -7,7 +8,7 @@ - name: make the box be real hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -33,7 +34,7 @@ - {role: mirrormanager/mirrorlist_proxy, when: env == "staging" or "'mirrorlist_proxy' in group_names"} - apache -#when: env == "staging" +# when: env == "staging" tasks: - import_tasks: "{{ tasks_path }}/motd.yml" @@ -41,8 +42,8 @@ # You might think we would want these tasks_path on the proxy nodes, but they # actually deliver a configuration that our proxy-specific roles below then go # and overwrite... so, let's just leave them out. - #- import_tasks: "{{ tasks_path }}/apache.yml" - #- import_tasks: "{{ tasks_path }}/mod_wsgi.yml" + # - import_tasks: "{{ tasks_path }}/apache.yml" + # - import_tasks: "{{ tasks_path }}/mod_wsgi.yml" - name: Ensure nf_conntrack module is loaded before tuning ip_conntrack_max copy: @@ -51,7 +52,7 @@ dest: /etc/modules-load.d/nf_conntrack.conf owner: root group: root - mode: 0644 + mode: "0644" - name: set ip_conntrack_max to a high value as the proxies deal with lots of connections sysctl: name=net.nf_conntrack_max value=26214400 state=present sysctl_set=yes reload=yes @@ -80,7 +81,7 @@ - name: Set up the proxy basics hosts: proxies_stg:proxies user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -121,7 +122,7 @@ hosts: proxies_stg:proxies strategy: free user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/rabbitmq.yml b/playbooks/groups/rabbitmq.yml index 3bbee034b0..b1579fe281 100644 --- a/playbooks/groups/rabbitmq.yml +++ b/playbooks/groups/rabbitmq.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "rabbitmq:rabbitmq_stg" @@ -5,7 +6,7 @@ - name: make the box be real hosts: rabbitmq:rabbitmq_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/groups/releng-compose.yml b/playbooks/groups/releng-compose.yml index 2caad4a4e7..cde9c0fabe 100644 --- a/playbooks/groups/releng-compose.yml +++ b/playbooks/groups/releng-compose.yml @@ -3,6 +3,7 @@ # NOTE: make sure there is room/space for this instance on the buildvmhost # NOTE: most of these vars_path come from group_vars/releng or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "releng_compose:releng_compose_stg:releng_compose_eln" @@ -203,7 +204,7 @@ dest: /etc/krb5.releng.keytab owner: root group: "releng-team" - mode: 0640 + mode: "0640" tags: - containerrebuild @@ -213,7 +214,7 @@ dest: /etc/pki/releng owner: root group: "releng-team" - mode: 0600 + mode: "0600" tags: - containerrebuild @@ -223,7 +224,7 @@ dest: "/usr/local/bin/relengpush" owner: root group: "releng-team" - mode: 0750 + mode: "0750" tags: - containerrebuild @@ -233,7 +234,7 @@ dest: "/usr/local/bin/relengpush-int" owner: root group: "releng-team" - mode: 0750 + mode: "0750" tags: - containerrebuild diff --git a/playbooks/groups/retrace.yml b/playbooks/groups/retrace.yml index 2e72765849..8ec3c1898a 100644 --- a/playbooks/groups/retrace.yml +++ b/playbooks/groups/retrace.yml @@ -1,7 +1,8 @@ +--- - name: AWS setup hosts: retrace_stg_aws user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -17,7 +18,7 @@ - name: setup RabbitMQ hosts: rabbitmq[0]:rabbitmq_stg[0] user: root - gather_facts: False + gather_facts: false tags: rabbitmq vars_files: @@ -25,7 +26,7 @@ - /srv/private/ansible/vars.yml - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml - roles: + roles: - role: rabbit/queue username: "faf{{ env_suffix }}" queue_name: faf @@ -51,12 +52,12 @@ - name: Setup retrace hosts hosts: retrace,retrace_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "{{ private }}/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "{{ private }}/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -79,12 +80,12 @@ - name: setup FAF server hosts: retrace,retrace_stg - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "{{ private }}/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "{{ private }}/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_role: name=abrt/faf-pre @@ -99,12 +100,12 @@ - name: setup retrace server hosts: retrace,retrace_stg - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "{{ private }}/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "{{ private }}/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_role: name=abrt/retrace-pre diff --git a/playbooks/groups/secondary.yml b/playbooks/groups/secondary.yml index ecad78b21a..980d40b63f 100644 --- a/playbooks/groups/secondary.yml +++ b/playbooks/groups/secondary.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "secondary" @@ -5,12 +6,12 @@ - name: setup secondary arch download server hosts: secondary user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - "/srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml" + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - "/srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml" roles: - base diff --git a/playbooks/groups/sign-bridge.yml b/playbooks/groups/sign-bridge.yml index 459423ea54..4edc2c8ac1 100644 --- a/playbooks/groups/sign-bridge.yml +++ b/playbooks/groups/sign-bridge.yml @@ -6,6 +6,7 @@ # Access is via management interface only. This playbook does initial setup. # Please check with rel-eng before doing anything here. +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "sign_bridge" @@ -16,9 +17,9 @@ gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/smtp-auth.yml b/playbooks/groups/smtp-auth.yml index 177bae1f61..51f92fc94c 100644 --- a/playbooks/groups/smtp-auth.yml +++ b/playbooks/groups/smtp-auth.yml @@ -1,5 +1,6 @@ # create smtp auth servers +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "smtp_auth" @@ -7,12 +8,12 @@ - name: make the box be real hosts: smtp_auth user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/smtp-mm.yml b/playbooks/groups/smtp-mm.yml index be2b11f638..dbc73df793 100644 --- a/playbooks/groups/smtp-mm.yml +++ b/playbooks/groups/smtp-mm.yml @@ -1,5 +1,6 @@ # create smtp servers +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "smtp_mm" @@ -7,12 +8,12 @@ - name: make the box be real hosts: smtp_mm user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/tang.yml b/playbooks/groups/tang.yml index aaef2709a1..2e7f448a05 100644 --- a/playbooks/groups/tang.yml +++ b/playbooks/groups/tang.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "tang" @@ -5,12 +6,12 @@ - name: make the box be real hosts: tang user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" diff --git a/playbooks/groups/torrent.yml b/playbooks/groups/torrent.yml index fe80387fb9..d1fa54a56d 100644 --- a/playbooks/groups/torrent.yml +++ b/playbooks/groups/torrent.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "torrent" @@ -5,12 +6,12 @@ - name: make the box be real hosts: torrent user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/groups/value.yml b/playbooks/groups/value.yml index 44ace4861d..587c92777a 100644 --- a/playbooks/groups/value.yml +++ b/playbooks/groups/value.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "value:value_stg" @@ -5,7 +6,7 @@ - name: make the box be real hosts: value:value_stg user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -39,10 +40,10 @@ - role: collectd/fedmsg-service process: fedmsg-irc - {role: nfs/client, - nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3", - mnt_dir: '/srv/', - nfs_src_dir: 'fedora_value_{{env_short}}', - mount_stg: true } + nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3", + mnt_dir: '/srv/', + nfs_src_dir: 'fedora_value_{{env_short}}', + mount_stg: true } pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" diff --git a/playbooks/groups/virthost.yml b/playbooks/groups/virthost.yml index ac2ea0ef7e..8e9be419ab 100644 --- a/playbooks/groups/virthost.yml +++ b/playbooks/groups/virthost.yml @@ -2,6 +2,7 @@ # NOTE: should be used with --limit most of the time # NOTE: most of these vars_path come from group_vars/backup_server or from hostvars +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/happy_birthday.yml" vars: myhosts: "virthost:bvirthost:buildvmhost:colo_virt" @@ -9,12 +10,12 @@ - name: make virthost server system hosts: virthost:bvirthost:buildvmhost:colo_virt user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README diff --git a/playbooks/groups/wiki.yml b/playbooks/groups/wiki.yml index 528b4843ca..0a4e7425ff 100644 --- a/playbooks/groups/wiki.yml +++ b/playbooks/groups/wiki.yml @@ -3,6 +3,7 @@ # These servers run mediawiki for the main fedora wiki instance. # +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "wiki:wiki_stg" @@ -10,12 +11,12 @@ - name: make the box be real hosts: wiki:wiki_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml pre_tasks: - import_tasks: "{{ tasks_path }}/yumrepos.yml" @@ -36,8 +37,8 @@ username: "mediawiki{{ env_suffix }}" sent_topics: ^org\.fedoraproject\.{{ env_short }}\.(wiki|logger)\..* when: inventory_hostname.startswith('wiki01') - - { role: nfs/client, when: env == "staging", mnt_dir: '/mnt/web/attachments', nfs_src_dir: 'fedora_app_staging/app/attachments', mount_stg: true } - - { role: nfs/client, when: env != "staging", mnt_dir: '/mnt/web/attachments', nfs_src_dir: 'fedora_app/app/attachments' } + - { role: nfs/client, when: env == "staging", mnt_dir: '/mnt/web/attachments', nfs_src_dir: 'fedora_app_staging/app/attachments', mount_stg: true } + - { role: nfs/client, when: env != "staging", mnt_dir: '/mnt/web/attachments', nfs_src_dir: 'fedora_app/app/attachments' } - mediawiki - sudo diff --git a/playbooks/groups/zabbix.yml b/playbooks/groups/zabbix.yml index 7de9ef4686..7b8d160778 100644 --- a/playbooks/groups/zabbix.yml +++ b/playbooks/groups/zabbix.yml @@ -1,3 +1,4 @@ +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "zabbix_stg:zabbix" @@ -5,12 +6,12 @@ - name: make the box be real hosts: zabbix_stg:zabbix user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/host_reboot.yml b/playbooks/host_reboot.yml index f540a6c650..233da105b4 100644 --- a/playbooks/host_reboot.yml +++ b/playbooks/host_reboot.yml @@ -1,8 +1,9 @@ # requires --extra-vars="target=hostspec" +--- - name: reboot hosts hosts: "{{ target }}" - gather_facts: False + gather_facts: false user: root serial: 1 diff --git a/playbooks/host_update.yml b/playbooks/host_update.yml index c7ba870cd9..6deb1efb24 100644 --- a/playbooks/host_update.yml +++ b/playbooks/host_update.yml @@ -3,6 +3,7 @@ # requires --extra-vars="target=somehostname yumcommand=update" +--- - name: update the system hosts: "{{ target }}" gather_facts: false @@ -18,7 +19,7 @@ poll: 30 - name: run rkhunter if installed - hosts: "{{ target }}" + hosts: "{{ target }}" user: root tasks: diff --git a/playbooks/hosts/cloud-noc01.fedorainfracloud.org.yml b/playbooks/hosts/cloud-noc01.fedorainfracloud.org.yml index 0096240b5f..7a4b42ba29 100644 --- a/playbooks/hosts/cloud-noc01.fedorainfracloud.org.yml +++ b/playbooks/hosts/cloud-noc01.fedorainfracloud.org.yml @@ -1,5 +1,6 @@ # This is a basic playbook +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "cloud-noc01.fedorainfracloud.org" @@ -7,12 +8,12 @@ - name: make cloud noc hardware hosts: cloud-noc01.fedorainfracloud.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base @@ -58,4 +59,3 @@ handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/hosts/noc-cc01.rdu-cc.fedoraproject.org.yml b/playbooks/hosts/noc-cc01.rdu-cc.fedoraproject.org.yml index e1893d1f4c..2cc8af886e 100644 --- a/playbooks/hosts/noc-cc01.rdu-cc.fedoraproject.org.yml +++ b/playbooks/hosts/noc-cc01.rdu-cc.fedoraproject.org.yml @@ -1,5 +1,6 @@ # This is a basic playbook +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "noc-cc01.rdu-cc.fedoraproject.org" @@ -7,12 +8,12 @@ - name: make cloud noc hardware hosts: noc-cc01.rdu-cc.fedoraproject.org user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/include/happy_birthday.yml b/playbooks/include/happy_birthday.yml index 6d7a41ce27..9b92aad5f0 100644 --- a/playbooks/include/happy_birthday.yml +++ b/playbooks/include/happy_birthday.yml @@ -1,11 +1,12 @@ +--- - name: handle ssh keys on a hosts birthday (new hw machine) hosts: "{{ myhosts }}" - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_tasks: "{{ tasks_path }}/happy_birthday.yml" @@ -13,4 +14,3 @@ handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/include/proxies-certificates.yml b/playbooks/include/proxies-certificates.yml index 88f25f5c01..36a3677eab 100644 --- a/playbooks/include/proxies-certificates.yml +++ b/playbooks/include/proxies-certificates.yml @@ -1,12 +1,13 @@ +--- - name: Set up those proxy certificates. Good gravy.. hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -22,7 +23,7 @@ - role: httpd/certificate certname: wildcard-2024.fedoraproject.org SSLCertificateChainFile: wildcard-2024.fedoraproject.org.intermediate.cert - + - role: httpd/certificate certname: wildcard-2024.id.fedoraproject.org SSLCertificateChainFile: wildcard-2024.id.fedoraproject.org.intermediate.cert @@ -70,4 +71,3 @@ # - role: httpd/certificate # certname: secondary.koji.fedoraproject.org.letsencrypt # SSLCertificateChainFile: secondary.koji.fedoraproject.org.letsencrypt.intermediate.crt - diff --git a/playbooks/include/proxies-fedora-web.yml b/playbooks/include/proxies-fedora-web.yml index 62eec33f8b..3dd7043df7 100644 --- a/playbooks/include/proxies-fedora-web.yml +++ b/playbooks/include/proxies-fedora-web.yml @@ -1,12 +1,13 @@ +--- - name: Set up all that fedora-web goodness. What a wonder! hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/include/proxies-fedorahosted.yml b/playbooks/include/proxies-fedorahosted.yml index 1e3ed1b494..5062962f4a 100644 --- a/playbooks/include/proxies-fedorahosted.yml +++ b/playbooks/include/proxies-fedorahosted.yml @@ -1,12 +1,13 @@ -- name: Fedorahosted. No more on our servers, but still in our hearts... +--- +- name: Fedorahosted. No more on our servers, but still in our hearts... hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -26,4 +27,3 @@ - name: install special git.fedorahosted-redirects.conf with git.fedorahosted redirects copy: src={{ files }}/httpd/git.fedorahosted-redirects.conf dest=/etc/httpd/conf.d/git.fedorahosted.org/fedorahosted-redirects.conf - diff --git a/playbooks/include/proxies-haproxy.yml b/playbooks/include/proxies-haproxy.yml index 216ac2d022..bef04e47e8 100644 --- a/playbooks/include/proxies-haproxy.yml +++ b/playbooks/include/proxies-haproxy.yml @@ -1,12 +1,13 @@ +--- - name: Set up all the haproxy stuff. hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/include/proxies-miscellaneous.yml b/playbooks/include/proxies-miscellaneous.yml index 22bf4f8f9a..24a3f8793f 100644 --- a/playbooks/include/proxies-miscellaneous.yml +++ b/playbooks/include/proxies-miscellaneous.yml @@ -1,12 +1,13 @@ +--- - name: Set up all the other proxy stuff -- miscellaneous hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -14,11 +15,11 @@ tasks: # We retired this in favor of PDC # https://lists.fedoraproject.org/archives/list/rel-eng@lists.fedoraproject.org/thread/LOWVTF6WTS43LNPWDEISLXUELXAH5YXR/#LOWVTF6WTS43LNPWDEISLXUELXAH5YXR - - file: - dest=/etc/httpd/conf.d/apps.fedoraproject.org/fedora-releng-dash.conf - state=absent - tags: releng-dash - notify: reload proxyhttpd + - file: + dest=/etc/httpd/conf.d/apps.fedoraproject.org/fedora-releng-dash.conf + state=absent + tags: releng-dash + notify: reload proxyhttpd roles: diff --git a/playbooks/include/proxies-redirects.yml b/playbooks/include/proxies-redirects.yml index 5f171f1cd2..a2984c96b3 100644 --- a/playbooks/include/proxies-redirects.yml +++ b/playbooks/include/proxies-redirects.yml @@ -1,12 +1,13 @@ +--- - name: Set up those proxy redirects. Wow! hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -648,13 +649,13 @@ target: https://download.fedoraproject.org/pub/fedora/linux/releases/21/Cloud/Images/x86_64/Fedora-Cloud-Atomic-20141203-21.x86_64.raw.xz # Except, there are no 32bit atomic images atm. - #- role: httpd/redirect + # - role: httpd/redirect # shortname: cloud-atomic-32bit-21-raw # website: cloud.fedoraproject.org # path: /fedora-atomic-21.i386.raw.xz # target: https://download.fedoraproject.org/pub/fedora/linux/releases/21/Cloud/Images/i386/Fedora-Cloud-Atomic-20141203-21.i386.raw.xz - #- role: httpd/redirect + # - role: httpd/redirect # shortname: cloud-atomic-32bit-21 # website: cloud.fedoraproject.org # path: /fedora-atomic-21.i386.qcow2 @@ -901,7 +902,7 @@ regex: ^/composes/production/latest-Fedora-ELN/compose/(.*)$ target: https://dl.fedoraproject.org/pub/eln/1/$1 tags: - - odcs + - odcs - role: httpd/redirect shortname: 01-old-odcs diff --git a/playbooks/include/proxies-reverseproxy.yml b/playbooks/include/proxies-reverseproxy.yml index 3113cdd46e..5c04c49ca2 100644 --- a/playbooks/include/proxies-reverseproxy.yml +++ b/playbooks/include/proxies-reverseproxy.yml @@ -1,12 +1,13 @@ +--- - name: Set up those ProxyPassReverse statements. Somebody get me a cup of coffee.. hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/include/proxies-rewrites.yml b/playbooks/include/proxies-rewrites.yml index c491eae230..66205f3f67 100644 --- a/playbooks/include/proxies-rewrites.yml +++ b/playbooks/include/proxies-rewrites.yml @@ -1,12 +1,13 @@ +--- - name: Set up some domain rewrites. hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/include/proxies-websites.yml b/playbooks/include/proxies-websites.yml index 0443dc6abb..9655cf4b25 100644 --- a/playbooks/include/proxies-websites.yml +++ b/playbooks/include/proxies-websites.yml @@ -1,12 +1,13 @@ +--- - name: Set up those proxy websites. My, my.. hosts: proxies_stg:proxies user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -920,14 +921,14 @@ - role: httpd/website site_name: zabbix.fedoraproject.org sslonly: true - #server_aliases: [zabbix.fedoraproject.org] + # server_aliases: [zabbix.fedoraproject.org] cert_name: "{{wildcard_cert_name}}" tags: zabbix - role: httpd/website site_name: zabbix.stg.fedoraproject.org sslonly: true - #server_aliases: [zabbix.stg.fedoraproject.org] + # server_aliases: [zabbix.stg.fedoraproject.org] cert_name: "{{wildcard_cert_name}}" tags: zabbix when: env == "staging" diff --git a/playbooks/include/virt-create.yml b/playbooks/include/virt-create.yml index 48efb79b13..21095fb7c6 100644 --- a/playbooks/include/virt-create.yml +++ b/playbooks/include/virt-create.yml @@ -1,15 +1,15 @@ +--- - name: make the virtual instance hosts: "{{ myhosts }}" - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_tasks: "{{ tasks_path }}/virt_instance_create.yml" handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" - diff --git a/playbooks/list-vms-per-host.yml b/playbooks/list-vms-per-host.yml index a7e4ef4b7f..1163653295 100644 --- a/playbooks/list-vms-per-host.yml +++ b/playbooks/list-vms-per-host.yml @@ -4,7 +4,7 @@ --- - hosts: virtservers user: root - gather_facts: True + gather_facts: true vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/manual/autosign.yml b/playbooks/manual/autosign.yml index 7b1712518b..43f4f3c330 100644 --- a/playbooks/manual/autosign.yml +++ b/playbooks/manual/autosign.yml @@ -4,6 +4,7 @@ # Access is via management interface only. This playbook does initial setup. # Please check with rel-eng before doing anything here. +--- - import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml" vars: myhosts: "autosign_stg" @@ -11,12 +12,12 @@ - name: make the box be real hosts: autosign:autosign_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/manual/copr/_generic_tasks.yml b/playbooks/manual/copr/_generic_tasks.yml index c266784e1a..96098a7c4e 100644 --- a/playbooks/manual/copr/_generic_tasks.yml +++ b/playbooks/manual/copr/_generic_tasks.yml @@ -1,3 +1,4 @@ +--- - name: detect package versions package_facts: manager=auto diff --git a/playbooks/manual/copr/copr-backend-upgrade.yml b/playbooks/manual/copr/copr-backend-upgrade.yml index 13b8a73479..1911e44635 100644 --- a/playbooks/manual/copr/copr-backend-upgrade.yml +++ b/playbooks/manual/copr/copr-backend-upgrade.yml @@ -2,12 +2,12 @@ - name: upgrade copr backend hosts: copr_back_dev_aws:copr_back_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Generic upgrade tasks for copr servers diff --git a/playbooks/manual/copr/copr-dist-git-upgrade.yml b/playbooks/manual/copr/copr-dist-git-upgrade.yml index 5938d5a106..016a8d6098 100644 --- a/playbooks/manual/copr/copr-dist-git-upgrade.yml +++ b/playbooks/manual/copr/copr-dist-git-upgrade.yml @@ -2,12 +2,12 @@ - name: upgrade copr distgit hosts: copr_dist_git_dev_aws:copr_dist_git_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Generic upgrade tasks for copr servers diff --git a/playbooks/manual/copr/copr-frontend-upgrade.yml b/playbooks/manual/copr/copr-frontend-upgrade.yml index c284635908..ac87edc82f 100644 --- a/playbooks/manual/copr/copr-frontend-upgrade.yml +++ b/playbooks/manual/copr/copr-frontend-upgrade.yml @@ -2,15 +2,15 @@ - name: upgrade copr frontend hosts: copr_front_dev_aws:copr_front_aws user: root - gather_facts: True + gather_facts: true vars: cache_file: /var/lib/copr/.ansible-copr-frontend-version vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Generic upgrade tasks for copr servers diff --git a/playbooks/manual/copr/copr-keygen-upgrade.yml b/playbooks/manual/copr/copr-keygen-upgrade.yml index 6e1f20cfb5..b8009c4de4 100644 --- a/playbooks/manual/copr/copr-keygen-upgrade.yml +++ b/playbooks/manual/copr/copr-keygen-upgrade.yml @@ -2,12 +2,12 @@ - name: upgrade copr keygen hosts: copr_keygen_dev_aws:copr_keygen_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Generic upgrade tasks for copr servers diff --git a/playbooks/manual/copr/copr-pulp-upgrade.yml b/playbooks/manual/copr/copr-pulp-upgrade.yml index 10a0639ac5..99424059bd 100644 --- a/playbooks/manual/copr/copr-pulp-upgrade.yml +++ b/playbooks/manual/copr/copr-pulp-upgrade.yml @@ -2,12 +2,12 @@ - name: upgrade copr pulp hosts: copr_pulp_dev_aws:copr_pulp_aws user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Generic upgrade tasks for copr servers diff --git a/playbooks/manual/fas-readonly/fas-readonly.yml b/playbooks/manual/fas-readonly/fas-readonly.yml index 73b9f02e23..05754c98cc 100644 --- a/playbooks/manual/fas-readonly/fas-readonly.yml +++ b/playbooks/manual/fas-readonly/fas-readonly.yml @@ -3,9 +3,9 @@ hosts: db-fas01.iad2.fedoraproject.org:db-fas01.stg.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: copy the sql script to file template: src=fas-readonly.sql dest=/var/lib/pgsql/fas-readonly.sql diff --git a/playbooks/manual/fas-readonly/rollback-readonly.yml b/playbooks/manual/fas-readonly/rollback-readonly.yml index 78280f094a..c984daa9f6 100644 --- a/playbooks/manual/fas-readonly/rollback-readonly.yml +++ b/playbooks/manual/fas-readonly/rollback-readonly.yml @@ -3,9 +3,9 @@ hosts: db-fas01.iad2.fedoraproject.org:db-fas01.stg.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: copy the sql script to file template: src=rollback.sql dest=/var/lib/pgsql/rollback.sql diff --git a/playbooks/manual/gdpr/delete.yml b/playbooks/manual/gdpr/delete.yml index cefa0a2075..cb407fb2c3 100644 --- a/playbooks/manual/gdpr/delete.yml +++ b/playbooks/manual/gdpr/delete.yml @@ -3,6 +3,7 @@ # Please read http://fedora-infra-docs.readthedocs.io/en/latest/sysadmin-guide/sops/gdpr_delete.html # for information about how to use this playbook and how to integration applications with it. +--- - name: Delete user data hosts: gdpr_delete strategy: free diff --git a/playbooks/manual/gdpr/sar.yml b/playbooks/manual/gdpr/sar.yml index e67712d0d4..b7e9ca1cdd 100644 --- a/playbooks/manual/gdpr/sar.yml +++ b/playbooks/manual/gdpr/sar.yml @@ -2,6 +2,7 @@ # # Please read http://fedora-infra-docs.readthedocs.io/en/latest/sysadmin-guide/sops/gdpr_sar.html # for information about how to use this playbook and how to integration applications with it. +--- - name: Create the archive location hosts: localhost tasks: diff --git a/playbooks/manual/gdpr/sar_openshift.yml b/playbooks/manual/gdpr/sar_openshift.yml index 94b4319c95..2e2dfb9c24 100644 --- a/playbooks/manual/gdpr/sar_openshift.yml +++ b/playbooks/manual/gdpr/sar_openshift.yml @@ -1,5 +1,6 @@ # Retrieve GDPR data from single openshift app. # Get the correct pod +--- - name: Retrieve the id of the running container/pod shell: "oc get -n {{ item.value.openshift_namespace }} -o name -l app={{ item.value.openshift_pod }} pods | cut -f 2 -d '/'" register: pod_id diff --git a/playbooks/manual/get-system-packages.yml b/playbooks/manual/get-system-packages.yml index 28206599ca..b7bfb016d9 100644 --- a/playbooks/manual/get-system-packages.yml +++ b/playbooks/manual/get-system-packages.yml @@ -1,7 +1,8 @@ # -# A playbook to get all the rpms installed on a set of systems. -# +# A playbook to get all the rpms installed on a set of systems. +# +--- - name: Get installed packages hosts: builders:releng-compose:data-analysis01.iad2.fedoraproject.org gather_facts: true @@ -18,4 +19,3 @@ - debug: var=rpm_output.stdout_lines # when: rpm_output is defined and rpm_output.results|length > 0 - diff --git a/playbooks/manual/history_undo.yml b/playbooks/manual/history_undo.yml index 30ec0e404d..0dcdb0ef34 100644 --- a/playbooks/manual/history_undo.yml +++ b/playbooks/manual/history_undo.yml @@ -8,6 +8,7 @@ # all the virthosts. If you run this once, it will undo those transactions. If # you run it again, it will undo that previous *undo*. +--- - name: Find and undo the latest yum transaction involving a $PACKAGE hosts: "{{ target }}" user: root @@ -30,7 +31,7 @@ - debug: var=transaction_info.stdout_lines when: transaction_id.stderr == "" - #- pause: seconds=30 prompt="Undoing that yum transaction. Abort if this is wrong." + # - pause: seconds=30 prompt="Undoing that yum transaction. Abort if this is wrong." # when: transaction_id.stderr == "" - name: Okay.. undo that transaction now diff --git a/playbooks/manual/import-irc-cookies-to-matrix.yml b/playbooks/manual/import-irc-cookies-to-matrix.yml index 844710ab0c..9384e6c6c9 100644 --- a/playbooks/manual/import-irc-cookies-to-matrix.yml +++ b/playbooks/manual/import-irc-cookies-to-matrix.yml @@ -1,13 +1,14 @@ # This playbook imports the cookies given on IRC to the Matrix Zodbot +--- - name: Import the cookies hosts: value02.iad2.fedoraproject.org:value02.stg.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: @@ -18,7 +19,7 @@ dest: /root/.pgpass owner: root group: root - mode: 0400 + mode: "0400" - name: install the required package dnf: @@ -29,7 +30,7 @@ copy: src: "{{ files }}/zodbot/karma-to-cookies-db.py" dest: /usr/local/bin/karma-to-cookies-db - mode: 0755 + mode: "0755" - name: run the import script command: diff --git a/playbooks/manual/kernel-qa.yml b/playbooks/manual/kernel-qa.yml index 644365c38d..a58f1efc3a 100644 --- a/playbooks/manual/kernel-qa.yml +++ b/playbooks/manual/kernel-qa.yml @@ -2,15 +2,16 @@ # NOTE: this assumes the kernel-qa boxes are already up and are accessible # NOTE: most of these vars_path come from group_vars/kernel-qa or from hostvars +--- - name: make kernel-qa hosts: kernel_qa user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/manual/mirrormanager/emergency-expire-repo.yml b/playbooks/manual/mirrormanager/emergency-expire-repo.yml index 7ee7acbb36..edfbfc794c 100644 --- a/playbooks/manual/mirrormanager/emergency-expire-repo.yml +++ b/playbooks/manual/mirrormanager/emergency-expire-repo.yml @@ -6,6 +6,7 @@ # "Fedora", "EPEL" or "RHEL" # version => The version that must be expired and updated. +--- - name: Run the emergency-expire-repo script hosts: os_control[0]:os_control_stg[0] user: root diff --git a/playbooks/manual/mirrormanager/move-devel-to-release.yml b/playbooks/manual/mirrormanager/move-devel-to-release.yml index c15a5061b0..1a50199339 100644 --- a/playbooks/manual/mirrormanager/move-devel-to-release.yml +++ b/playbooks/manual/mirrormanager/move-devel-to-release.yml @@ -4,6 +4,7 @@ # --extra-vars="version='42'" # version => The version that must be expired and updated. +--- - name: Run the move-devel-to-release script hosts: os_control[0]:os_control_stg[0] user: root diff --git a/playbooks/manual/mirrormanager/move-to-archive.yml b/playbooks/manual/mirrormanager/move-to-archive.yml index 46e3725ab5..a8c66c77f2 100644 --- a/playbooks/manual/mirrormanager/move-to-archive.yml +++ b/playbooks/manual/mirrormanager/move-to-archive.yml @@ -6,6 +6,7 @@ # "Fedora", "EPEL" or "RHEL" # version => The version that must be archived. +--- - name: Run the move-to-archive script hosts: os_control[0]:os_control_stg[0] user: root diff --git a/playbooks/manual/nagios/shush-fmn.yml b/playbooks/manual/nagios/shush-fmn.yml index 9e0251b75a..e223a06648 100644 --- a/playbooks/manual/nagios/shush-fmn.yml +++ b/playbooks/manual/nagios/shush-fmn.yml @@ -1,10 +1,11 @@ +--- - name: be quiet please... hosts: notifs_backend:notifs_backend_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: tell nagios to shush. diff --git a/playbooks/manual/noggin-deployment/create-full-backup.yml b/playbooks/manual/noggin-deployment/create-full-backup.yml index 59011c8de8..3e6a87debc 100644 --- a/playbooks/manual/noggin-deployment/create-full-backup.yml +++ b/playbooks/manual/noggin-deployment/create-full-backup.yml @@ -1,6 +1,7 @@ +--- - name: backup IPA data for testing hosts: ipa_stg - #vars_files: + # vars_files: # - /srv/web/infra/ansible/vars/global.yml # - "/srv/private/ansible/vars.yml" # - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml diff --git a/playbooks/manual/noggin-deployment/fix-home-fedora-ownerships.yml b/playbooks/manual/noggin-deployment/fix-home-fedora-ownerships.yml index 85d5a87b4e..b81b31bada 100644 --- a/playbooks/manual/noggin-deployment/fix-home-fedora-ownerships.yml +++ b/playbooks/manual/noggin-deployment/fix-home-fedora-ownerships.yml @@ -19,7 +19,7 @@ copy: src: "{{ files }}/scripts/fix-home-fedora-ownerships.sh" dest: /usr/local/sbin/fix-home-fedora-ownerships.sh - mode: 0755 + mode: "0755" changed_when: false when: home_fedora_res.stat.isdir diff --git a/playbooks/manual/noggin-deployment/restore-latest-backup.yml b/playbooks/manual/noggin-deployment/restore-latest-backup.yml index 8426b53c1d..0935f2428b 100644 --- a/playbooks/manual/noggin-deployment/restore-latest-backup.yml +++ b/playbooks/manual/noggin-deployment/restore-latest-backup.yml @@ -1,3 +1,4 @@ +--- - name: restore latest IPA backup for testing hosts: ipa_stg vars_files: diff --git a/playbooks/manual/noggin-deployment/uninstall_ipa_client.yml b/playbooks/manual/noggin-deployment/uninstall_ipa_client.yml index 24453d4743..6171b84650 100644 --- a/playbooks/manual/noggin-deployment/uninstall_ipa_client.yml +++ b/playbooks/manual/noggin-deployment/uninstall_ipa_client.yml @@ -1,3 +1,4 @@ +--- - name: Uninstall IPA client hosts: bodhi_backend_stg:bugzilla2fedmsg_stg:github2fedmsg_stg:ipsilon_stg:buildvm_stg:buildvm_ppc64le_stg:buildvm_aarch64_stg:buildvm_armv7_stg:buildvm_s390x_stg user: root diff --git a/playbooks/manual/oci-registry-prune.yml b/playbooks/manual/oci-registry-prune.yml index 8a2815180b..6bc56637e4 100644 --- a/playbooks/manual/oci-registry-prune.yml +++ b/playbooks/manual/oci-registry-prune.yml @@ -3,6 +3,7 @@ # Once the images tags are deleted the garbage collection is run on the # registry hosts. +--- - name: Prune 30 days old OCI images from candidate-registry hosts: oci-candidate-registry01.iad2.fedoraproject.org:oci-candidate-registry01.stg.iad2.fedoraproject.org gather_facts: false diff --git a/playbooks/manual/ocp4-place-ignitionfiles.yml b/playbooks/manual/ocp4-place-ignitionfiles.yml index e0254b1f0e..b9f627bd77 100644 --- a/playbooks/manual/ocp4-place-ignitionfiles.yml +++ b/playbooks/manual/ocp4-place-ignitionfiles.yml @@ -26,12 +26,12 @@ file: path: "/var/www/html/rhcos" state: directory - mode: 0755 + mode: "0755" - name: == OCP KVM provisioning == Importing generated Ignition files template: src: "/srv/web/infra/bigfiles/openshiftboot/{{ env }}/{{ item }}" dest: "/var/www/html/rhcos/{{ item }}" - mode: 0755 + mode: "0755" with_items: - bootstrap.ign - controlplane.ign @@ -40,7 +40,7 @@ template: src: "/srv/web/infra/bigfiles/openshiftboot/ocp-treeinfo.j2" dest: "/var/www/html/rhcos/.treeinfo" - mode: 0644 + mode: "0644" - name: == OCP KVM provisioning == Copy kubeadmin config files to bastion copy: src: "/srv/web/infra/bigfiles/openshiftboot/{{ env }}/auth/" @@ -48,10 +48,10 @@ - name: == OCP KVM provisioning == Downloading RHCOS deploy files get_url: dest: /var/www/html/rhcos/ - mode: 0755 + mode: "0755" url: "https://mirror.openshift.com/pub/openshift-v4/dependencies/rhcos/latest/{{ rhcos_version }}/{{ item }}" -# run_once: True - ignore_errors: True +# run_once: true + ignore_errors: true with_items: - "rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" - "rhcos-{{ rhcos_version }}-x86_64-live-rootfs.x86_64.img" @@ -70,10 +70,10 @@ - name: == OCP KVM provisioning == Downloading RHCOS deploy files get_url: dest: /srv/web/infra/bigfiles/tftpboot/rhcos/ - mode: 0755 + mode: "0755" url: "https://mirror.openshift.com/pub/openshift-v4/dependencies/rhcos/latest/{{ rhcos_version }}/{{ item }}" - run_once: True - ignore_errors: True + run_once: true + ignore_errors: true with_items: - "rhcos-{{ rhcos_version }}-x86_64-live-initramfs.x86_64.img" - "rhcos-{{ rhcos_version }}-x86_64-live-kernel-x86_64" diff --git a/playbooks/manual/openqa-restart-workers.yml b/playbooks/manual/openqa-restart-workers.yml index ff9be06775..2a50f5f516 100644 --- a/playbooks/manual/openqa-restart-workers.yml +++ b/playbooks/manual/openqa-restart-workers.yml @@ -1,10 +1,11 @@ +--- - name: restart worker services on openQA worker hosts (production) hosts: openqa_workers:openqa_lab_workers user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -12,4 +13,3 @@ - name: restart all the worker services service: name=openqa-worker@{{ item }} state=restarted with_sequence: "count={{ openqa_workers }}" - diff --git a/playbooks/manual/qadevel.yml b/playbooks/manual/qadevel.yml index 4e424ef624..bc3a57761e 100644 --- a/playbooks/manual/qadevel.yml +++ b/playbooks/manual/qadevel.yml @@ -3,15 +3,16 @@ # This server looks for rawhide builds and requests they be signed. # +--- - name: make qadevel server hosts: qadevel:qadevel_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_tasks: "{{ tasks_path }}/virt_instance_create.yml" @@ -22,12 +23,12 @@ - name: make the box be real hosts: qadevel:qadevel_stg user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/manual/rabbit/delete-queue.yml b/playbooks/manual/rabbit/delete-queue.yml index f32952e350..63271eab9d 100644 --- a/playbooks/manual/rabbit/delete-queue.yml +++ b/playbooks/manual/rabbit/delete-queue.yml @@ -6,6 +6,7 @@ # # Use --extra-vars to define them. +--- - assert: that: - "queue_name is defined" @@ -15,7 +16,7 @@ that: - "vhost is defined" fail_msg: "You must define vhost" - + - name: Create the queue in RabbitMQ hosts: rabbitmq_stg[0]:rabbitmq[0] rabbitmq_queue: diff --git a/playbooks/manual/rebuild/hotspot.yml b/playbooks/manual/rebuild/hotspot.yml index 4ad71a5bc2..1b6b2f3d60 100644 --- a/playbooks/manual/rebuild/hotspot.yml +++ b/playbooks/manual/rebuild/hotspot.yml @@ -1,10 +1,11 @@ +--- - name: Put a hotspot.txt file in place. hosts: proxies:proxies_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - file: dest=/srv/web/fedoraproject.org/static/ state=directory diff --git a/playbooks/manual/rebuild/mote.yml b/playbooks/manual/rebuild/mote.yml index 42044cde8e..2b788f6347 100644 --- a/playbooks/manual/rebuild/mote.yml +++ b/playbooks/manual/rebuild/mote.yml @@ -1,10 +1,11 @@ +--- - name: Nuke the mote cache and restart the services to rebuild it. hosts: value:value_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/rebuild/websites.yml b/playbooks/manual/rebuild/websites.yml index 18beb70155..2a7695786a 100644 --- a/playbooks/manual/rebuild/websites.yml +++ b/playbooks/manual/rebuild/websites.yml @@ -1,12 +1,13 @@ +--- - name: Force a rebuild of website content on the backend builder hosts: sundries01* user: root become: true become_user: apache vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Run syncStatic (this takes a while)... @@ -16,9 +17,9 @@ hosts: proxies:proxies_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: rsync each site in to place diff --git a/playbooks/manual/releng/koji-release-tags.yml b/playbooks/manual/releng/koji-release-tags.yml index c10003d77f..ec8f8ec5c3 100644 --- a/playbooks/manual/releng/koji-release-tags.yml +++ b/playbooks/manual/releng/koji-release-tags.yml @@ -24,7 +24,7 @@ dest: /etc/koji.conf owner: root group: root - mode: 0644 + mode: "0644" tasks: - name: create the main koji tag for {{release}} diff --git a/playbooks/manual/remote_delldrive.yml b/playbooks/manual/remote_delldrive.yml index 066ff7dc26..20697de7dd 100644 --- a/playbooks/manual/remote_delldrive.yml +++ b/playbooks/manual/remote_delldrive.yml @@ -1,11 +1,12 @@ # Call with, for example: -e 'target=ibiblio04.fedoraproject.org mgmt=ibiblio04-mgmt.fedoraproject.org' +--- - name: Do a remote drive check hosts: "{{target}}" user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Copy script over to {{target}} diff --git a/playbooks/manual/restart-fedmsg-services.yml b/playbooks/manual/restart-fedmsg-services.yml index 25935a2ead..c5bc2cee20 100644 --- a/playbooks/manual/restart-fedmsg-services.yml +++ b/playbooks/manual/restart-fedmsg-services.yml @@ -5,15 +5,16 @@ # everywhere will be restarted. As stuff changes over time, this playbook will # need to be periodically updated with new things. +--- - name: restart fedmsg-gateway instances hosts: fedmsg_gateways:fedmsg_gateways_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: bounce the fedmsg-gateway service @@ -22,12 +23,12 @@ - name: restart fedmsg-relay instances hosts: fedmsg_relays:fedmsg_relays_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: bounce the fedmsg-relay service @@ -36,12 +37,12 @@ - name: restart fedmsg-irc instances hosts: fedmsg_ircs:fedmsg_ircs_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: bounce the fedmsg-irc service @@ -50,12 +51,12 @@ - name: tell nagios to be quiet about FMN for the moment hosts: notifs_backend:notifs_backend_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: schedule a 25 minute downtime. give notifs backend time to start up. @@ -68,12 +69,12 @@ - name: restart fedmsg-hub instances hosts: fedmsg_hubs:fedmsg_hubs_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: bounce the fedmsg-hub service @@ -82,12 +83,12 @@ - name: restart moksha-hub instances hosts: moksha_hubs:moksha_hubs_stg user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: bounce the moksha-hub service diff --git a/playbooks/manual/restart-pagure.yml b/playbooks/manual/restart-pagure.yml index b20591245b..3008a90539 100644 --- a/playbooks/manual/restart-pagure.yml +++ b/playbooks/manual/restart-pagure.yml @@ -1,10 +1,11 @@ +--- - name: reload the frontend hosts: pagure:pagure_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/sign-and-import.yml b/playbooks/manual/sign-and-import.yml index 0f2d111030..b288e87b65 100644 --- a/playbooks/manual/sign-and-import.yml +++ b/playbooks/manual/sign-and-import.yml @@ -14,6 +14,7 @@ # TODO -- grab rpms from koji build/task ids beforehand? # TODO -- other arches than x86_64? +--- - name: batch sign and import a directory full of rpms user: root hosts: localhost @@ -24,7 +25,7 @@ # It would be nice to be able to toggle this from the command line. vars: - repodir: /mnt/fedora/app/fi-repo/{% if testing %}testing/{% endif %}{{ rhel }} - - testing: False + - testing: false tasks: - fail: msg="Please use the infra tags from now on" @@ -48,29 +49,29 @@ - name: copy the source rpms to the SRPMS dir of {{ repodir }} copy: src={{ item }} dest={{ repodir }}/SRPMS/ with_fileglob: - - "{{ rpmdir }}/*.src.rpm" + - "{{ rpmdir }}/*.src.rpm" - name: move processed srpms out to {{ rpmdir }}-old command: /bin/mv {{ item }} {{ rpmdir }}-old/ when: not testing with_fileglob: - - "{{ rpmdir }}/*.src.rpm" + - "{{ rpmdir }}/*.src.rpm" - name: copy the binary rpms to the x86_64 dir of {{ repodir }} copy: src={{ item }} dest={{ repodir }}/x86_64/ with_fileglob: - - "{{ rpmdir }}/*.rpm" + - "{{ rpmdir }}/*.rpm" - name: copy the binary rpms to the i386 dir of {{ repodir }} copy: src={{ item }} dest={{ repodir }}/i386/ with_fileglob: - - "{{ rpmdir }}/*.rpm" + - "{{ rpmdir }}/*.rpm" - name: move processed rpms out to {{ rpmdir }}-old command: /bin/mv {{ item }} {{ rpmdir }}-old/ when: not testing with_fileglob: - - "{{ rpmdir }}/*.rpm" + - "{{ rpmdir }}/*.rpm" - name: Run createrepo on each repo command: createrepo --update {{ repodir }}/{{ item }}/ diff --git a/playbooks/manual/sign-vault.yml b/playbooks/manual/sign-vault.yml index e5a232ee5e..a231b61527 100644 --- a/playbooks/manual/sign-vault.yml +++ b/playbooks/manual/sign-vault.yml @@ -6,15 +6,16 @@ # Access is via management interface only. This playbook does initial setup. # Please check with rel-eng before doing anything here. +--- - name: make sign-vault server vm (secondary and stg only) hosts: sign-vault01.stg.iad2.fedoraproject.org user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - import_tasks: "{{ tasks_path }}/virt_instance_create.yml" @@ -28,9 +29,9 @@ gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - base diff --git a/playbooks/manual/staging-sync/bodhi.yml b/playbooks/manual/staging-sync/bodhi.yml index eff5a1a90c..11f93bc79e 100644 --- a/playbooks/manual/staging-sync/bodhi.yml +++ b/playbooks/manual/staging-sync/bodhi.yml @@ -1,13 +1,12 @@ # This playbook syncs the production bodhi instance with staging. - - +--- - name: bring staging services down (httpd) hosts: bodhi2_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - service: name=httpd state=stopped @@ -16,9 +15,9 @@ hosts: os-control01.stg.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - command: oc -n bodhi scale dc/bodhi-web --replicas=0 @@ -29,9 +28,9 @@ hosts: bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - service: @@ -50,9 +49,9 @@ become_method: sudo vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -71,9 +70,9 @@ hosts: os-control01.stg.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - command: oc -n bodhi scale dc/bodhi-web --replicas=1 @@ -84,9 +83,9 @@ hosts: bodhi2_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - service: name=httpd state=started @@ -95,9 +94,9 @@ hosts: bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - service: diff --git a/playbooks/manual/staging-sync/db-sync.yml b/playbooks/manual/staging-sync/db-sync.yml index c34604d17c..affdedc960 100644 --- a/playbooks/manual/staging-sync/db-sync.yml +++ b/playbooks/manual/staging-sync/db-sync.yml @@ -14,6 +14,7 @@ # emptry string (''), for example if the app is running in openshift. # db => The database name on both database server (must be the same) +--- - name: dump the prod db out hosts: "{{ dbhost }}.iad2.fedoraproject.org" user: root @@ -22,9 +23,9 @@ become_method: sudo vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -32,21 +33,21 @@ - name: Dumping the production db. This might take a minute. Go out to the lobby! shell: pg_dump -C {{ db }} |xz -c > /var/tmp/{{ db }}.dump.xz - # Get the dump from `from` in the batcave + # Get the dump from `from` in the batcave - name: Export the dump from the dbhost in prod to batcave fetch: - src: /var/tmp/{{ db }}.dump.xz - dest: /var/tmp/ - flat: yes + src: /var/tmp/{{ db }}.dump.xz + dest: /var/tmp/ + flat: yes - name: bring staging services down hosts: "{{ server or 'batcave01.iad2.fedoraproject.org' }}" user: root any_errors_fatal: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -63,18 +64,18 @@ become_method: sudo vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tasks: - # push dump to stg from batcave + # push dump to stg from batcave - name: push the DB dump from batcave to the dbhost in stg copy: - src: /var/tmp/{{ db }}.dump.xz - dest: /var/tmp/{{ db }}.dump.xz + src: /var/tmp/{{ db }}.dump.xz + dest: /var/tmp/{{ db }}.dump.xz - name: Unpack the archive command: unxz /var/tmp/{{ db }}.dump.xz @@ -95,9 +96,9 @@ user: root any_errors_fatal: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -114,9 +115,9 @@ become_method: sudo vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -129,13 +130,12 @@ user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tasks: - name: remove the DB dump from batcave command: rm -f /var/tmp/{{ db }}.dump.xz - diff --git a/playbooks/manual/staging-sync/koji.yml b/playbooks/manual/staging-sync/koji.yml index df0ba0228e..aeab89b68b 100644 --- a/playbooks/manual/staging-sync/koji.yml +++ b/playbooks/manual/staging-sync/koji.yml @@ -9,13 +9,14 @@ # https://lists.fedoraproject.org/pipermail/buildsys/2015-June/004779.html +--- - name: bring staging services down hosts: koji_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -52,9 +53,9 @@ cg_name: osbuild vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -89,9 +90,9 @@ hosts: koji_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tags: @@ -136,9 +137,9 @@ hosts: builders_stg:releng_compose_stg:bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tags: @@ -155,9 +156,9 @@ hosts: builders_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tags: diff --git a/playbooks/manual/staging-sync/koschei.yml b/playbooks/manual/staging-sync/koschei.yml index 7a1058ed88..9ca05fa0ca 100644 --- a/playbooks/manual/staging-sync/koschei.yml +++ b/playbooks/manual/staging-sync/koschei.yml @@ -6,15 +6,16 @@ # In future, this playbook may be extended to sync content from # production Koschei database dump, but this is not needed for now. +--- - name: sync staging Koschei with production hosts: os_control_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/staging-sync/mailman.yml b/playbooks/manual/staging-sync/mailman.yml index 19a087403a..ec483896d1 100644 --- a/playbooks/manual/staging-sync/mailman.yml +++ b/playbooks/manual/staging-sync/mailman.yml @@ -2,13 +2,14 @@ # the steps we need to keep our setup intact. +--- - name: bring staging services down hosts: mailman-stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -26,14 +27,14 @@ become_method: sudo vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tasks: - #- template: src=templates/mailman-reset-staging.sql dest=/var/lib/pgsql/mailman-reset-staging.sql + # - template: src=templates/mailman-reset-staging.sql dest=/var/lib/pgsql/mailman-reset-staging.sql - copy: src=/srv/web/infra/db-dumps/mailman.dump.xz dest=/var/tmp/mailman.dump.xz @@ -45,10 +46,10 @@ - command: createdb -O mailmanadmin mailman - name: Import the prod db. This will take quite a while. Go get a snack! command: psql -f /var/tmp/mailman.dump mailman - #- name: Fix the database + # - name: Fix the database # shell: psql -f /var/lib/pgsql/mailman-reset-staging.sql mailman - #- template: src=templates/hyperkitty-reset-staging.sql dest=/var/lib/pgsql/hyperkitty-reset-staging.sql + # - template: src=templates/hyperkitty-reset-staging.sql dest=/var/lib/pgsql/hyperkitty-reset-staging.sql - copy: src=/srv/web/infra/db-dumps/hyperkitty.dump.xz dest=/var/tmp/hyperkitty.dump.xz @@ -60,7 +61,7 @@ - command: createdb -O hyperkittyadmin hyperkitty - name: Import the prod db. This will take quite a while. Go get a snack! command: psql -f /var/tmp/hyperkitty.dump hyperkitty - #- name: Fix the database + # - name: Fix the database # shell: psql -f /var/lib/pgsql/hyperkitty-reset-staging.sql hyperkitty # TODO: reindex emails (fulltext)? Not a full-reindex, it may take days. @@ -70,9 +71,9 @@ hosts: batcave user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Nuke the prod db dump that we cached on batcave @@ -83,9 +84,9 @@ hosts: mailman-stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/sync-hosts.yml b/playbooks/manual/sync-hosts.yml index acda283904..1abd555482 100644 --- a/playbooks/manual/sync-hosts.yml +++ b/playbooks/manual/sync-hosts.yml @@ -1,6 +1,6 @@ # Synchronizes files in /tmp/staging between remote hosts -# The following variables need to be supplied with the -# --extra-vars flag for the playbook to work: +# The following variables need to be supplied with the +# --extra-vars flag for the playbook to work: # 'remote_src_host', 'remote_dest_host' # # Example: @@ -10,20 +10,20 @@ --- - hosts: localhost user: root - + tasks: - + - name: copy files from remote_src_host to control node run_once: yes - fetch: - src: /tmp/staging - dest: /tmp/staging + fetch: + src: /tmp/staging + dest: /tmp/staging flat: yes validate_checksum: yes when: "{{ inventory_hostname == 'remote_src_host' }}" - + - name: copy files from control node to remote_dest_host - copy: - src: /tmp/staging + copy: + src: /tmp/staging dest: /tmp/staging when: "{{ inventory_hostname == 'remote_dest_host' }}" diff --git a/playbooks/manual/update-aliases.yml b/playbooks/manual/update-aliases.yml index a6e3a62a8e..f7a69eab19 100644 --- a/playbooks/manual/update-aliases.yml +++ b/playbooks/manual/update-aliases.yml @@ -1,12 +1,13 @@ +--- - name: run fasjson playbook on bastion for alias changes hosts: bastion user: root - gather_facts: True + gather_facts: true vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml roles: - { role: fasjson, when: env != "staging" } diff --git a/playbooks/manual/update-firmware.yml b/playbooks/manual/update-firmware.yml index 56b3b1c2d0..cb4f4b4a50 100644 --- a/playbooks/manual/update-firmware.yml +++ b/playbooks/manual/update-firmware.yml @@ -9,6 +9,7 @@ ##################### WARNING ################################## # +--- - name: Show warning hosts: localhost tasks: @@ -20,9 +21,9 @@ hosts: all user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/update-packages.yml b/playbooks/manual/update-packages.yml index a939a3dc52..ade05ced74 100644 --- a/playbooks/manual/update-packages.yml +++ b/playbooks/manual/update-packages.yml @@ -6,12 +6,13 @@ # To update from testing, adjust as follow: # --extra-vars="target='host1:host2' package='python-t*' testing=True" +--- - name: push packages out hosts: "{{target}}" user: root vars: - testing: False + testing: false tasks: @@ -38,4 +39,3 @@ - name: dnf update {{ package }} from testing repo dnf: name="{{ package }}" state=latest enablerepo=infrastructure-tags-stg when: testing and ansible_distribution_major_version|int > 21 and ansible_distribution == 'Fedora' - diff --git a/playbooks/manual/upgrade/bodhi.yml b/playbooks/manual/upgrade/bodhi.yml index 1d3d0b547a..651ca0eb32 100644 --- a/playbooks/manual/upgrade/bodhi.yml +++ b/playbooks/manual/upgrade/bodhi.yml @@ -1,10 +1,11 @@ +--- - name: check to see if a compose is going on before we do anything... hosts: bodhi_backend:bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - include_vars: dir=/srv/web/infra/ansible/vars/all/ ignore_files=README @@ -23,9 +24,9 @@ hosts: bodhi_backend:bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -51,9 +52,9 @@ hosts: bodhi_backend:bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Find out what the current migration version is @@ -64,9 +65,9 @@ hosts: os_control[0]:os_control_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -88,9 +89,9 @@ hosts: bodhi_backend:bodhi_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -106,8 +107,8 @@ tasks: - name: Stop the backend services service: - name: "{{ item }}" - state: stopped + name: "{{ item }}" + state: stopped with_items: - fm-consumer@config.service - bodhi-celery @@ -119,8 +120,8 @@ - name: Start the backend services service: - name: "{{ item }}" - state: started + name: "{{ item }}" + state: started with_items: - fm-consumer@config.service - bodhi-celery @@ -135,9 +136,9 @@ hosts: os_control[0]:os_control_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/bugzilla2fedmsg.yml b/playbooks/manual/upgrade/bugzilla2fedmsg.yml index 413956cc10..6a05fd382d 100644 --- a/playbooks/manual/upgrade/bugzilla2fedmsg.yml +++ b/playbooks/manual/upgrade/bugzilla2fedmsg.yml @@ -1,12 +1,13 @@ +--- - name: push packages out hosts: bugzilla2fedmsg:bugzilla2fedmsg_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -24,10 +25,10 @@ - name: verify the backend and restart it hosts: bugzilla2fedmsg:bugzilla2fedmsg_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/datagrepper.yml b/playbooks/manual/upgrade/datagrepper.yml index b14184f331..e70fd42e1d 100644 --- a/playbooks/manual/upgrade/datagrepper.yml +++ b/playbooks/manual/upgrade/datagrepper.yml @@ -1,12 +1,13 @@ +--- - name: push packages out hosts: datagrepper:datagrepper_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -24,10 +25,10 @@ - name: verify the config and restart it hosts: datagrepper:datagrepper_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/datanommer.yml b/playbooks/manual/upgrade/datanommer.yml index c128dc61ad..e9613ae8fa 100644 --- a/playbooks/manual/upgrade/datanommer.yml +++ b/playbooks/manual/upgrade/datanommer.yml @@ -1,12 +1,13 @@ +--- - name: Verify the badges backend and stop it hosts: - - badges_backend - - badges_backend_stg + - badges_backend + - badges_backend_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" pre_tasks: @@ -20,14 +21,14 @@ - service: name="fedmsg-hub" state=stopped - name: Stop datagrepper - hosts: + hosts: - os_masters[0] - os_masters_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tasks: @@ -40,9 +41,9 @@ - os_masters_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" tasks: @@ -75,9 +76,9 @@ - os_masters_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Scale up datanommer pods command: oc -n datanommer scale dc/db-datanommer --replicas=1 @@ -88,9 +89,9 @@ - os_masters_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Scale up datagrepper pods command: oc -n datagrepper scale dc/datagrepper --replicas=1 @@ -101,9 +102,9 @@ - badges-backend-stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - service: name="fedmsg-hub" state=started post_tasks: diff --git a/playbooks/manual/upgrade/fedmsg.yml b/playbooks/manual/upgrade/fedmsg.yml index f9153cbc47..fc977781c5 100644 --- a/playbooks/manual/upgrade/fedmsg.yml +++ b/playbooks/manual/upgrade/fedmsg.yml @@ -1,3 +1,4 @@ +--- - name: push packages out hosts: - fedmsg-hubs @@ -19,12 +20,12 @@ - datagrepper-stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false packages: - fedmsg - python2-fedmsg-meta-fedora-infrastructure @@ -46,16 +47,16 @@ with_items: "{{packages}}" # Restart all the backend daemons - #- import_tasks: "{{tasks_path}}../restart-fedmsg-services.yml" + # - import_tasks: "{{tasks_path}}../restart-fedmsg-services.yml" # Also restart the frontend web services - name: bounce apache hosts: datagrepper:datagrepper_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/koji.yml b/playbooks/manual/upgrade/koji.yml index e5dcee7076..3a3ba513cc 100644 --- a/playbooks/manual/upgrade/koji.yml +++ b/playbooks/manual/upgrade/koji.yml @@ -16,20 +16,21 @@ # 5) upgrade database # 6) update hubs # 7) update all builders -# 8) restart +# 8) restart # # TODO: # - stop and restart kojira on koji02 # - kill any koji-gc processes # - nagios outage stuff didn't seem to work as well as we would want last time. +--- - name: preliminary tasks hosts: koji:koji_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: ask admin if an outage ticket was created. @@ -57,10 +58,10 @@ # ... is anything special needed to upgrade pgbdr nodes? hosts: db-koji01.iad2.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - name: Install the koji package, to get the upgrade script. @@ -81,10 +82,10 @@ - name: update and restart the koji hubs before we touch the builders hosts: koji:koji_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - package: name=koji-hub state=latest update_cache=yes - name: restart httpd on the koji-hubs. @@ -97,10 +98,10 @@ - name: update and restart the koji builders, now that we're done with the hubs hosts: builders:builders_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml tasks: - package: name=koji-builder state=latest update_cache=yes - name: restart all the builders. so many. diff --git a/playbooks/manual/upgrade/koschei-full.yml b/playbooks/manual/upgrade/koschei-full.yml index aea5ed1b9c..22a019a29f 100644 --- a/playbooks/manual/upgrade/koschei-full.yml +++ b/playbooks/manual/upgrade/koschei-full.yml @@ -3,15 +3,16 @@ # unlike koschei-rolling.yml, it works even in case when there are # database migrations to apply. +--- - name: Perform full Koschei update hosts: os_control[0]:os_control_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/koschei-rolling.yml b/playbooks/manual/upgrade/koschei-rolling.yml index c033a998b5..ec77c0aea5 100644 --- a/playbooks/manual/upgrade/koschei-rolling.yml +++ b/playbooks/manual/upgrade/koschei-rolling.yml @@ -2,15 +2,16 @@ # latest upstream version without causing user-visible outage, as long # as updated version has identical database schema. +--- - name: Perform Koschei rolling update hosts: os_control[0]:os_control_stg[0] user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - /srv/private/ansible/vars.yml - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml - - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml + - /srv/web/infra/ansible/vars/global.yml + - /srv/private/ansible/vars.yml + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/main.yml + - /srv/web/infra/ansible/roles/openshift-apps/koschei/vars/{{ env }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/mote.yml b/playbooks/manual/upgrade/mote.yml index da324727b3..6a25f2d1a2 100644 --- a/playbooks/manual/upgrade/mote.yml +++ b/playbooks/manual/upgrade/mote.yml @@ -1,12 +1,13 @@ +--- - name: push packages out hosts: value:value_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -24,10 +25,10 @@ - name: verify the config and restart it hosts: value:value_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/packages.yml b/playbooks/manual/upgrade/packages.yml index 74e5aee6ab..379bacc2c4 100644 --- a/playbooks/manual/upgrade/packages.yml +++ b/playbooks/manual/upgrade/packages.yml @@ -1,12 +1,13 @@ +--- - name: push packages out hosts: packages:packages_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -24,10 +25,10 @@ - name: verify the config and restart it hosts: packages:packages_stg user: root - vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + vars_files: + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/manual/upgrade/pagure.yml b/playbooks/manual/upgrade/pagure.yml index a5eab769b4..366a0b2050 100644 --- a/playbooks/manual/upgrade/pagure.yml +++ b/playbooks/manual/upgrade/pagure.yml @@ -5,25 +5,26 @@ # to your ansible command. # Main task to upgrade pagure +--- - name: upgrade pagure hosts: pagure:pagure_stg user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - testing: False + testing: false handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" pre_tasks: - name: tell nagios to shush w.r.t. the frontend nagios: - action=downtime - minutes=15 - service=host - host={{ inventory_hostname_short }}{{ env_suffix }} + action=downtime + minutes=15 + service=host + host={{ inventory_hostname_short }}{{ env_suffix }} delegate_to: noc01.iad2.fedoraproject.org ignore_errors: true @@ -78,7 +79,7 @@ args: chdir: /etc/pagure/ environment: - PAGURE_CONFIG: /etc/pagure/pagure.cfg + PAGURE_CONFIG: /etc/pagure/pagure.cfg post_tasks: @@ -111,13 +112,13 @@ ## ## ToDo: Put in an include to pull in setting status back -## +## - name: tell nagios to unshush w.r.t. the frontend nagios: - action=unsilence - service=host - host={{ inventory_hostname_short }}{{ env_suffix }} + action=unsilence + service=host + host={{ inventory_hostname_short }}{{ env_suffix }} delegate_to: noc01.iad2.fedoraproject.org ignore_errors: true diff --git a/playbooks/openshift-apps/application-monitoring.yml b/playbooks/openshift-apps/application-monitoring.yml index c2430181e5..4606164d12 100644 --- a/playbooks/openshift-apps/application-monitoring.yml +++ b/playbooks/openshift-apps/application-monitoring.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_masters_stg[0] # only in staging for the ARC deployment user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/asknot.yml b/playbooks/openshift-apps/asknot.yml index 065396532a..df32f5fbd9 100644 --- a/playbooks/openshift-apps/asknot.yml +++ b/playbooks/openshift-apps/asknot.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/awx.yml b/playbooks/openshift-apps/awx.yml index 4f3a61cb18..a18531bf9a 100644 --- a/playbooks/openshift-apps/awx.yml +++ b/playbooks/openshift-apps/awx.yml @@ -3,7 +3,7 @@ hosts: localhost connection: local user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/blockerbugs.yml b/playbooks/openshift-apps/blockerbugs.yml index 9a47e74f7b..fc238ea059 100644 --- a/playbooks/openshift-apps/blockerbugs.yml +++ b/playbooks/openshift-apps/blockerbugs.yml @@ -1,3 +1,4 @@ +--- - name: Prepare setting up the database hosts: db01.stg.iad2.fedoraproject.org:db01.iad2.fedoraproject.org gather_facts: no @@ -66,7 +67,7 @@ - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -130,7 +131,7 @@ serviceport: 8080-tcp servicename: qa-landing annotations: - haproxy.router.openshift.io/set-forwarded-headers: append + haproxy.router.openshift.io/set-forwarded-headers: append - role: openshift/start-build app: blockerbugs diff --git a/playbooks/openshift-apps/bodhi.yml b/playbooks/openshift-apps/bodhi.yml index 7a539cae18..9137e08068 100644 --- a/playbooks/openshift-apps/bodhi.yml +++ b/playbooks/openshift-apps/bodhi.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/bugzilla2fedmsg.yml b/playbooks/openshift-apps/bugzilla2fedmsg.yml index c33ac2ba7f..313e3e50a0 100644 --- a/playbooks/openshift-apps/bugzilla2fedmsg.yml +++ b/playbooks/openshift-apps/bugzilla2fedmsg.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/cloud-image-uploader.yml b/playbooks/openshift-apps/cloud-image-uploader.yml index 28c1fd4dba..e9fdd779dd 100644 --- a/playbooks/openshift-apps/cloud-image-uploader.yml +++ b/playbooks/openshift-apps/cloud-image-uploader.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/custom-error-pages.yml b/playbooks/openshift-apps/custom-error-pages.yml index 926f03c9e0..60fb74d8dd 100644 --- a/playbooks/openshift-apps/custom-error-pages.yml +++ b/playbooks/openshift-apps/custom-error-pages.yml @@ -1,3 +1,4 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root diff --git a/playbooks/openshift-apps/datagrepper.yml b/playbooks/openshift-apps/datagrepper.yml index fc9925a702..875af01047 100644 --- a/playbooks/openshift-apps/datagrepper.yml +++ b/playbooks/openshift-apps/datagrepper.yml @@ -1,3 +1,4 @@ +--- - name: Give access to the datanommer DB hosts: datanommer_dbserver:datanommer_dbserver_stg gather_facts: no @@ -25,7 +26,7 @@ - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/datanommer.yml b/playbooks/openshift-apps/datanommer.yml index cabadc4a86..07b43ce375 100644 --- a/playbooks/openshift-apps/datanommer.yml +++ b/playbooks/openshift-apps/datanommer.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/discourse2fedmsg.yml b/playbooks/openshift-apps/discourse2fedmsg.yml index 0f9c09036b..618ca3dc20 100644 --- a/playbooks/openshift-apps/discourse2fedmsg.yml +++ b/playbooks/openshift-apps/discourse2fedmsg.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/docstranslation.yml b/playbooks/openshift-apps/docstranslation.yml index 9532664822..d43facd201 100644 --- a/playbooks/openshift-apps/docstranslation.yml +++ b/playbooks/openshift-apps/docstranslation.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars: app: docstranslation ssh_key_path: "{{ private }}/files/docstranslation/id_rsa_docstrans_{{ env_short }}" diff --git a/playbooks/openshift-apps/easyfix.yml b/playbooks/openshift-apps/easyfix.yml index a43b1c42eb..73c536edfd 100644 --- a/playbooks/openshift-apps/easyfix.yml +++ b/playbooks/openshift-apps/easyfix.yml @@ -1,12 +1,12 @@ # # Fedora Project easyfixes # - +--- - name: Make the app be real # hosts: os_control_stg:os_control hosts: os_control_stg user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/elections.yml b/playbooks/openshift-apps/elections.yml index 4cc4d2e8a9..da28fc5e11 100644 --- a/playbooks/openshift-apps/elections.yml +++ b/playbooks/openshift-apps/elections.yml @@ -1,3 +1,4 @@ +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -23,7 +24,7 @@ - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/fasjson.yml b/playbooks/openshift-apps/fasjson.yml index d05b15a0a0..245ea10d0e 100644 --- a/playbooks/openshift-apps/fasjson.yml +++ b/playbooks/openshift-apps/fasjson.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/fedocal.yml b/playbooks/openshift-apps/fedocal.yml index 4816514ba8..f9f93d6a3e 100644 --- a/playbooks/openshift-apps/fedocal.yml +++ b/playbooks/openshift-apps/fedocal.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0],os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/fedora-packages-static.yml b/playbooks/openshift-apps/fedora-packages-static.yml index 0e15365d1a..4b3f6e6699 100644 --- a/playbooks/openshift-apps/fedora-packages-static.yml +++ b/playbooks/openshift-apps/fedora-packages-static.yml @@ -1,7 +1,8 @@ +--- - name: Make fedora-packages-static hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/firmitas.yml b/playbooks/openshift-apps/firmitas.yml index 822a53f7c4..20244aff76 100644 --- a/playbooks/openshift-apps/firmitas.yml +++ b/playbooks/openshift-apps/firmitas.yml @@ -1,6 +1,6 @@ --- - name: Make the app be real - hosts: os_control_stg #:os_control + hosts: os_control_stg # :os_control user: root gather_facts: false diff --git a/playbooks/openshift-apps/flask-oidc-dev.yml b/playbooks/openshift-apps/flask-oidc-dev.yml index 5146b16b84..bcbf26d855 100644 --- a/playbooks/openshift-apps/flask-oidc-dev.yml +++ b/playbooks/openshift-apps/flask-oidc-dev.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/flatpak-indexer.yml b/playbooks/openshift-apps/flatpak-indexer.yml index db0bfa47c2..67db805475 100644 --- a/playbooks/openshift-apps/flatpak-indexer.yml +++ b/playbooks/openshift-apps/flatpak-indexer.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/fmn.yml b/playbooks/openshift-apps/fmn.yml index da968fdd98..313338ef90 100644 --- a/playbooks/openshift-apps/fmn.yml +++ b/playbooks/openshift-apps/fmn.yml @@ -2,7 +2,7 @@ # Fedora Messaging Notifications (FMN) # - +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -27,7 +27,7 @@ - name: Setup RabbitMQ hosts: rabbitmq[0]:rabbitmq_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -103,7 +103,7 @@ - name: Make the app be real hosts: os_control_stg:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/greenwave.yml b/playbooks/openshift-apps/greenwave.yml index 1362c30aa6..2db305c203 100644 --- a/playbooks/openshift-apps/greenwave.yml +++ b/playbooks/openshift-apps/greenwave.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -90,7 +91,7 @@ - name: Change the route haproxy default timeout hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/ipsilon-website.yml b/playbooks/openshift-apps/ipsilon-website.yml index d9a3e34a34..1ffe353054 100644 --- a/playbooks/openshift-apps/ipsilon-website.yml +++ b/playbooks/openshift-apps/ipsilon-website.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/kanban.yml b/playbooks/openshift-apps/kanban.yml index f6c642b5f4..09aa5ac01a 100644 --- a/playbooks/openshift-apps/kanban.yml +++ b/playbooks/openshift-apps/kanban.yml @@ -1,3 +1,4 @@ +--- - name: Prepare setting up the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -66,7 +67,7 @@ - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/kerneltest.yml b/playbooks/openshift-apps/kerneltest.yml index ba7be43ef1..c8135133f3 100644 --- a/playbooks/openshift-apps/kerneltest.yml +++ b/playbooks/openshift-apps/kerneltest.yml @@ -1,3 +1,4 @@ +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -23,7 +24,7 @@ - name: Make the app be real hosts: os_control_stg:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/koschei.yml b/playbooks/openshift-apps/koschei.yml index 7f0ea7e7d2..0a4be7d2e9 100644 --- a/playbooks/openshift-apps/koschei.yml +++ b/playbooks/openshift-apps/koschei.yml @@ -1,7 +1,8 @@ +--- - name: Provision koschei hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -32,8 +33,8 @@ serviceport: web servicename: frontend annotations: - haproxy.router.openshift.io/set-forwarded-headers: append - haproxy.router.openshift.io/timeout: 180s + haproxy.router.openshift.io/set-forwarded-headers: append + haproxy.router.openshift.io/timeout: 180s tasks: - name: Apply objects diff --git a/playbooks/openshift-apps/languages.yml b/playbooks/openshift-apps/languages.yml index 68cc16f3c9..d8f3237203 100644 --- a/playbooks/openshift-apps/languages.yml +++ b/playbooks/openshift-apps/languages.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/maubot.yml b/playbooks/openshift-apps/maubot.yml index 48d8caf72c..8e66ae854d 100644 --- a/playbooks/openshift-apps/maubot.yml +++ b/playbooks/openshift-apps/maubot.yml @@ -1,3 +1,4 @@ +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -22,7 +23,7 @@ - name: Make the app be real hosts: os_control_stg:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/mdapi.yml b/playbooks/openshift-apps/mdapi.yml index 5a88b28adf..56d8ef6422 100644 --- a/playbooks/openshift-apps/mdapi.yml +++ b/playbooks/openshift-apps/mdapi.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/messaging-bridges.yml b/playbooks/openshift-apps/messaging-bridges.yml index 2477ba6159..3c5909bcd0 100644 --- a/playbooks/openshift-apps/messaging-bridges.yml +++ b/playbooks/openshift-apps/messaging-bridges.yml @@ -1,9 +1,9 @@ # Create the RabbitMQ users - +--- - name: Setup RabbitMQ hosts: rabbitmq[0]:rabbitmq_stg[0]:rabbitmq01.iad2.fedoraproject.org user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -36,8 +36,8 @@ community.rabbitmq.rabbitmq_queue: name: amqp_bridge_verify_missing vhost: /pubsub - durable: True - auto_delete: False + durable: true + auto_delete: false message_ttl: 60000 login_user: admin login_password: "{{ (env == 'production') | ternary(rabbitmq_admin_password_production, rabbitmq_admin_password_staging) }}" @@ -78,7 +78,7 @@ - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/monitor_dashboard.yml b/playbooks/openshift-apps/monitor_dashboard.yml index a6d32d7079..8de8d82801 100644 --- a/playbooks/openshift-apps/monitor_dashboard.yml +++ b/playbooks/openshift-apps/monitor_dashboard.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -33,10 +34,10 @@ # file: dashboard_provision_config.yml # objectname: dashboard_provision_config.yml - #- role: openshift/object - # app: monitor-dashboard - # template: dashboard_config.yml - # objectname: dashboard_config.yml +# - role: openshift/object +# app: monitor-dashboard +# template: dashboard_config.yml +# objectname: dashboard_config.yml # - role: openshift/object diff --git a/playbooks/openshift-apps/monitor_gating.yml b/playbooks/openshift-apps/monitor_gating.yml index e95c80bf5d..e149865056 100644 --- a/playbooks/openshift-apps/monitor_gating.yml +++ b/playbooks/openshift-apps/monitor_gating.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -83,7 +84,7 @@ buildname: monitor-gating-build objectname: monitor-gating-build tags: - - build + - build - role: openshift/object app: monitor-gating diff --git a/playbooks/openshift-apps/mote.yml b/playbooks/openshift-apps/mote.yml index 724d9101e0..9369def79e 100644 --- a/playbooks/openshift-apps/mote.yml +++ b/playbooks/openshift-apps/mote.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars: app: mote vars_files: diff --git a/playbooks/openshift-apps/noggin-centos.yml b/playbooks/openshift-apps/noggin-centos.yml index b943d0b48c..52773803c3 100644 --- a/playbooks/openshift-apps/noggin-centos.yml +++ b/playbooks/openshift-apps/noggin-centos.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/noggin.yml b/playbooks/openshift-apps/noggin.yml index 0efbcb5d10..1c8fa65483 100644 --- a/playbooks/openshift-apps/noggin.yml +++ b/playbooks/openshift-apps/noggin.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/openscanhub.yml b/playbooks/openshift-apps/openscanhub.yml index 24e9397385..db883d0099 100644 --- a/playbooks/openshift-apps/openscanhub.yml +++ b/playbooks/openshift-apps/openscanhub.yml @@ -1,7 +1,8 @@ +--- - name: OpenScanHub hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/openvpn.yml b/playbooks/openshift-apps/openvpn.yml index 12eda937c3..8fd0be4215 100644 --- a/playbooks/openshift-apps/openvpn.yml +++ b/playbooks/openshift-apps/openvpn.yml @@ -1,8 +1,9 @@ +--- - name: Make the app be real # We don't have any VPN set up on stg hosts: os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/oraculum.yml b/playbooks/openshift-apps/oraculum.yml index b73b75f266..dc678774c1 100644 --- a/playbooks/openshift-apps/oraculum.yml +++ b/playbooks/openshift-apps/oraculum.yml @@ -1,3 +1,4 @@ +--- - name: Prepare setting up the database hosts: db01.stg.iad2.fedoraproject.org:db01.iad2.fedoraproject.org gather_facts: no @@ -40,7 +41,7 @@ - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml @@ -90,7 +91,7 @@ serviceport: 8080-tcp servicename: oraculum-api-endpoint annotations: - haproxy.router.openshift.io/set-forwarded-headers: append + haproxy.router.openshift.io/set-forwarded-headers: append - role: openshift/route app: oraculum @@ -100,7 +101,7 @@ serviceport: 8080-tcp servicename: oraculum-api-endpoint annotations: - haproxy.router.openshift.io/set-forwarded-headers: append + haproxy.router.openshift.io/set-forwarded-headers: append - role: openshift/route app: oraculum @@ -119,7 +120,7 @@ serviceport: 8080-tcp servicename: oraculum-frontend annotations: - haproxy.router.openshift.io/set-forwarded-headers: append + haproxy.router.openshift.io/set-forwarded-headers: append - role: openshift/start-build app: oraculum diff --git a/playbooks/openshift-apps/planet.yml b/playbooks/openshift-apps/planet.yml index d66ee5ead0..69bddcc41e 100644 --- a/playbooks/openshift-apps/planet.yml +++ b/playbooks/openshift-apps/planet.yml @@ -2,7 +2,7 @@ - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/poddlers.yml b/playbooks/openshift-apps/poddlers.yml index 9764494f96..1b377c78e4 100644 --- a/playbooks/openshift-apps/poddlers.yml +++ b/playbooks/openshift-apps/poddlers.yml @@ -1,8 +1,9 @@ +--- - name: Make the app be real # hosts: os_control[0]:os_control_stg[0] hosts: os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/release-monitoring.yml b/playbooks/openshift-apps/release-monitoring.yml index 2036f951cf..65d9e1ec2e 100644 --- a/playbooks/openshift-apps/release-monitoring.yml +++ b/playbooks/openshift-apps/release-monitoring.yml @@ -1,9 +1,9 @@ # Deploy the app - +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/resultsdb-ci-listener.yml b/playbooks/openshift-apps/resultsdb-ci-listener.yml index 4a5e1866d8..079ce2c951 100644 --- a/playbooks/openshift-apps/resultsdb-ci-listener.yml +++ b/playbooks/openshift-apps/resultsdb-ci-listener.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/review-stats.yml b/playbooks/openshift-apps/review-stats.yml index a4d7e255ae..1539de3993 100644 --- a/playbooks/openshift-apps/review-stats.yml +++ b/playbooks/openshift-apps/review-stats.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/test-auth.yml b/playbooks/openshift-apps/test-auth.yml index 96ee794318..1424383607 100644 --- a/playbooks/openshift-apps/test-auth.yml +++ b/playbooks/openshift-apps/test-auth.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_masters[0]:os_masters_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/testdays.yml b/playbooks/openshift-apps/testdays.yml index 03d7edc2d3..fc96ce2abb 100644 --- a/playbooks/openshift-apps/testdays.yml +++ b/playbooks/openshift-apps/testdays.yml @@ -1,3 +1,4 @@ +--- - name: Prepare setting up the database hosts: db01.stg.iad2.fedoraproject.org:db01.iad2.fedoraproject.org gather_facts: no @@ -54,7 +55,7 @@ - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/the-new-hotness.yml b/playbooks/openshift-apps/the-new-hotness.yml index 5d0d5746f9..e5bff29fe9 100644 --- a/playbooks/openshift-apps/the-new-hotness.yml +++ b/playbooks/openshift-apps/the-new-hotness.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control_stg[0]:os_control[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/toddlers.yml b/playbooks/openshift-apps/toddlers.yml index fbc967dd8c..374e292652 100644 --- a/playbooks/openshift-apps/toddlers.yml +++ b/playbooks/openshift-apps/toddlers.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/transtats.yml b/playbooks/openshift-apps/transtats.yml index 99580eea27..3141f98e64 100644 --- a/playbooks/openshift-apps/transtats.yml +++ b/playbooks/openshift-apps/transtats.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/waiverdb.yml b/playbooks/openshift-apps/waiverdb.yml index 7ab3fa3f62..5431359d91 100644 --- a/playbooks/openshift-apps/waiverdb.yml +++ b/playbooks/openshift-apps/waiverdb.yml @@ -1,3 +1,4 @@ +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -29,7 +30,7 @@ - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars: waiverdb_oidc_overwrite_redirect_uri: >- https://waiverdb{{ env_suffix }}.fedoraproject.org/oidc_callback diff --git a/playbooks/openshift-apps/webhook2fedmsg.yml b/playbooks/openshift-apps/webhook2fedmsg.yml index 9b9db78804..474810739e 100644 --- a/playbooks/openshift-apps/webhook2fedmsg.yml +++ b/playbooks/openshift-apps/webhook2fedmsg.yml @@ -1,7 +1,7 @@ # # Webhook to Fedora Messaging # - +--- - name: Setup the database hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org gather_facts: no @@ -26,7 +26,7 @@ - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/openshift-apps/zezere.yml b/playbooks/openshift-apps/zezere.yml index b4d0b757d3..142eb824eb 100644 --- a/playbooks/openshift-apps/zezere.yml +++ b/playbooks/openshift-apps/zezere.yml @@ -1,7 +1,8 @@ +--- - name: Make the app be real hosts: os_control[0]:os_control_stg[0] user: root - gather_facts: False + gather_facts: false vars_files: - /srv/web/infra/ansible/vars/global.yml diff --git a/playbooks/rdiff-backup.yml b/playbooks/rdiff-backup.yml index d6c46fea6b..8b03292bcd 100644 --- a/playbooks/rdiff-backup.yml +++ b/playbooks/rdiff-backup.yml @@ -3,10 +3,11 @@ # Since rdiff-backup doesn't have its own built-in-scheduler # this seemed like an obvious cheat +--- - name: rdiff-backup hosts: backup_clients user: root - gather_facts: False + gather_facts: false serial: 10 # host_backup_targets set in host_vars or group_vars # global_backup_targets can be defined in vars, group_vars/all or anywhere diff --git a/playbooks/restart_when_failed.yml b/playbooks/restart_when_failed.yml index d68d2be7f3..9e3fe28086 100644 --- a/playbooks/restart_when_failed.yml +++ b/playbooks/restart_when_failed.yml @@ -1,6 +1,7 @@ # This playbook lets you safely display systemd logs for failed services # and then restart it +--- - hosts: mirrorlist_proxies gather_facts: false diff --git a/playbooks/rkhunter_only.yml b/playbooks/rkhunter_only.yml index 92f5b35af0..6f305ebba5 100644 --- a/playbooks/rkhunter_only.yml +++ b/playbooks/rkhunter_only.yml @@ -1,5 +1,6 @@ # requires --extra-vars="target='host1:host2:group etc'" +--- - name: run rkhunter for times when rkhunter didn't seem to run. hosts: "{{ target }}" user: root diff --git a/playbooks/rkhunter_update.yml b/playbooks/rkhunter_update.yml index 3e59278929..5e5578ea4d 100644 --- a/playbooks/rkhunter_update.yml +++ b/playbooks/rkhunter_update.yml @@ -1,5 +1,6 @@ # requires --extra-vars="target='host1:host2:group etc' yumcommand=update'" +--- - name: update all run rkhunter if installed hosts: "{{ target }}" user: root diff --git a/playbooks/set_root_auth_keys.yml b/playbooks/set_root_auth_keys.yml index ee431de364..128d5bedac 100644 --- a/playbooks/set_root_auth_keys.yml +++ b/playbooks/set_root_auth_keys.yml @@ -1,18 +1,19 @@ # optionally can take --extra-vars="hostbase=hostnamebase root_auth_users='user1 user2 user3'" +--- - name: set auth keys hosts: "{{ target }}" user: root - gather_facts: False + gather_facts: false vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - - root_auth_users: '' + - root_auth_users: '' tasks: - - name: add root keys for sysadmin-main and other allowed users - action: authorized_key user=root key={{ item }} - with_lines: - - "{{ auth_keys_from_fas}} @sysadmin-main {{ root_auth_users }}" + - name: add root keys for sysadmin-main and other allowed users + action: authorized_key user=root key={{ item }} + with_lines: + - "{{ auth_keys_from_fas}} @sysadmin-main {{ root_auth_users }}" diff --git a/playbooks/ssh_host_keys.yml b/playbooks/ssh_host_keys.yml index cb1d9c99c0..2f11a98441 100644 --- a/playbooks/ssh_host_keys.yml +++ b/playbooks/ssh_host_keys.yml @@ -1,16 +1,17 @@ +--- - hosts: all - become: False + become: false vars: keyfile: /tmp/known_hosts tasks: - name: Add short name to file local_action: shell ssh-keyscan -p {{ansible_port|default(22)}} -H {{inventory_hostname}} 2> /dev/null >> {{keyfile}} - ignore_errors: True + ignore_errors: true - name: Add FQDN to file local_action: shell ssh-keyscan -p {{ansible_port|default(22)}} -H {{ansible_fqdn}} 2> /dev/null >> {{keyfile}} - ignore_errors: True + ignore_errors: true - name: Add IPv4 to file local_action: shell ssh-keyscan -p {{ansible_port|default(22)}} -H {{ansible_default_ipv4.address}} 2> /dev/null >> {{keyfile}} - ignore_errors: True + ignore_errors: true diff --git a/playbooks/universe_update.yml b/playbooks/universe_update.yml index 3a8f043a02..e3531b7606 100644 --- a/playbooks/universe_update.yml +++ b/playbooks/universe_update.yml @@ -2,9 +2,10 @@ # This playboook updates every host in inventory # +--- - name: set downtime hosts: all - gather_facts: False + gather_facts: false user: root serial: 1 @@ -19,39 +20,39 @@ - name: update the world hosts: all - gather_facts: True + gather_facts: true user: root tasks: - name: Apply updates package: - state: latest - name: "*" - update_cache: true + state: latest + name: "*" + update_cache: true async: 7200 poll: 30 when: package_excludes is not defined - + - debug: - msg: - - '!!!!!!!!!!!!!!!!!!! host {{ inventory_hostname }} has EXCLUDES OF {{ package_excludes }} !!!!!!!!!!!!!' - - '!!!!!!!!!!!!!!!!!!! DANGER DANGER DANGER ^ CHECK THAT EXCLUDES ARE STILL NEEDED ^ !!!!!!!!!!!!!!!!!!!!' + msg: + - '!!!!!!!!!!!!!!!!!!! host {{ inventory_hostname }} has EXCLUDES OF {{ package_excludes }} !!!!!!!!!!!!!' + - '!!!!!!!!!!!!!!!!!!! DANGER DANGER DANGER ^ CHECK THAT EXCLUDES ARE STILL NEEDED ^ !!!!!!!!!!!!!!!!!!!!' when: package_excludes is defined changed_when: true - + - name: Apply updates with excludes package: - state: latest - name: "*" - update_cache: true - exclude: "{{ package_excludes }}" + state: latest + name: "*" + update_cache: true + exclude: "{{ package_excludes }}" async: 7200 poll: 30 when: package_excludes is defined - name: run rkhunter if installed - hosts: all + hosts: all user: root tasks: diff --git a/playbooks/update-proxy-dns.yml b/playbooks/update-proxy-dns.yml index 7d2d7b5317..d020405d33 100644 --- a/playbooks/update-proxy-dns.yml +++ b/playbooks/update-proxy-dns.yml @@ -3,14 +3,15 @@ # - status -- what to do. must be either 'enable' or 'disable' # - userstring -- the git commit userstring for the dns repo +--- - name: Either take a proxy out of dns or put it back in hosts: "{{ proxies }}" user: root serial: 1 vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml vars: - userstring: "Ansible update-proxy-dns.yml " diff --git a/playbooks/update_dns.yml b/playbooks/update_dns.yml index d5d9253b55..14be26ec49 100644 --- a/playbooks/update_dns.yml +++ b/playbooks/update_dns.yml @@ -1,3 +1,4 @@ +--- - name: push dns changes out hosts: dns user: root diff --git a/playbooks/update_ticketkey.yml b/playbooks/update_ticketkey.yml index 5f24193eae..8fcbd636ba 100644 --- a/playbooks/update_ticketkey.yml +++ b/playbooks/update_ticketkey.yml @@ -1,11 +1,12 @@ +--- - name: make a new ssl ticketkey hosts: batcave01.iad2.fedoraproject.org user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" @@ -22,9 +23,9 @@ user: root vars_files: - - /srv/web/infra/ansible/vars/global.yml - - "/srv/private/ansible/vars.yml" - - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml + - /srv/web/infra/ansible/vars/global.yml + - "/srv/private/ansible/vars.yml" + - /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml handlers: - import_tasks: "{{ handlers_path }}/restart_services.yml" diff --git a/playbooks/vhost_halt_guests.yml b/playbooks/vhost_halt_guests.yml index f2bb4577f0..083e3f94cf 100644 --- a/playbooks/vhost_halt_guests.yml +++ b/playbooks/vhost_halt_guests.yml @@ -1,6 +1,6 @@ # requires --extra-vars="vhost=somevhost fqdn" -#General overview: +# General overview: # talk to the vhost # get back list of instances # add each of their hostnames to an addhoc group @@ -19,6 +19,7 @@ # across multiple plays +--- - name: find instances hosts: "{{ vhost }}" user: root diff --git a/playbooks/vhost_poweroff.yml b/playbooks/vhost_poweroff.yml index 6c2e1712dd..dd0fad90d5 100644 --- a/playbooks/vhost_poweroff.yml +++ b/playbooks/vhost_poweroff.yml @@ -3,7 +3,7 @@ # # requires --extra-vars="target=somevhost fqdn" -#General overview: +# General overview: # talk to the vhost # get back list of instances # add each of their hostnames to an addhoc group @@ -14,9 +14,10 @@ # TODO: Figure out how to compare virt info pre and post boot. +--- - name: find instances hosts: "{{ target }}" - gather_facts: False + gather_facts: false user: root tasks: @@ -35,7 +36,7 @@ - name: halt instances hosts: myvms_new user: root - gather_facts: False + gather_facts: false serial: 1 tasks: @@ -46,7 +47,7 @@ - name: wait for the whole set to die. hosts: myvms_new - gather_facts: False + gather_facts: false user: root tasks: @@ -55,7 +56,7 @@ - name: reboot vhost hosts: "{{ target }}" - gather_facts: False + gather_facts: false user: root tasks: diff --git a/playbooks/vhost_reboot.yml b/playbooks/vhost_reboot.yml index 95f01a5feb..a1cb293bc6 100644 --- a/playbooks/vhost_reboot.yml +++ b/playbooks/vhost_reboot.yml @@ -4,7 +4,7 @@ # requires --extra-vars="target=somevhost fqdn" # Might add nodns=true or nonagios=true to the extra vars -#General overview: +# General overview: # talk to the vhost # get back list of instances # add each of their hostnames to an addhoc group @@ -15,13 +15,14 @@ # TODO: Figure out how to compare virt info pre and post boot. +--- - name: find instances vars_prompt: - - name: target - prompt: What is the target vhost - private: false + - name: target + prompt: What is the target vhost + private: false hosts: "{{ target }}" - gather_facts: False + gather_facts: false user: root tasks: @@ -51,7 +52,7 @@ - name: halt instances hosts: myvms_new user: root - gather_facts: False + gather_facts: false serial: 1 tasks: @@ -69,7 +70,7 @@ - name: wait for the whole set to die. hosts: myvms_new - gather_facts: False + gather_facts: false user: root tasks: @@ -78,7 +79,7 @@ - name: reboot vhost hosts: "target" - gather_facts: False + gather_facts: false user: root tasks: @@ -115,7 +116,7 @@ - name: post reboot tasks hosts: myvms_postreboot user: root - gather_facts: False + gather_facts: false serial: 1 tasks: @@ -143,4 +144,3 @@ # - name: get info on guests (postreboot) # virt: command=info # register: vminfo_post - diff --git a/playbooks/vhost_update.yml b/playbooks/vhost_update.yml index e3297ceaa9..693eeab392 100644 --- a/playbooks/vhost_update.yml +++ b/playbooks/vhost_update.yml @@ -4,13 +4,14 @@ # Might add nodns=true or nonagios=true at extra-vars # +--- - name: find instances vars_prompt: - - name: target - prompt: What is the target vhost - private: false + - name: target + prompt: What is the target vhost + private: false hosts: "{{ target }}" - gather_facts: False + gather_facts: false user: root tasks: @@ -26,11 +27,11 @@ local_action: add_host hostname={{ target }} groupname=target # Call out to another playbook. Disable any proxies that may live here -#- include_playbook: update-proxy-dns.yml status=disable proxies=myvms_new:&proxies +# - include_playbook: update-proxy-dns.yml status=disable proxies=myvms_new:&proxies - name: set downtime hosts: "target:myvms_new" - gather_facts: False + gather_facts: false user: root serial: 1 @@ -45,39 +46,39 @@ - name: update the system hosts: "target:myvms_new" - gather_facts: True + gather_facts: true user: root tasks: - name: Apply updates package: - state: latest - name: "*" - update_cache: true + state: latest + name: "*" + update_cache: true async: 7200 poll: 30 when: package_excludes is not defined - + - debug: - msg: - - '!!!!!!!!!!!!!!!!!!! host {{ inventory_hostname }} has EXCLUDES OF {{ package_excludes }} !!!!!!!!!!!!!' - - '!!!!!!!!!!!!!!!!!!! DANGER DANGER DANGER ^ CHECK THAT EXCLUDES ARE STILL NEEDED ^ !!!!!!!!!!!!!!!!!!!!' + msg: + - '!!!!!!!!!!!!!!!!!!! host {{ inventory_hostname }} has EXCLUDES OF {{ package_excludes }} !!!!!!!!!!!!!' + - '!!!!!!!!!!!!!!!!!!! DANGER DANGER DANGER ^ CHECK THAT EXCLUDES ARE STILL NEEDED ^ !!!!!!!!!!!!!!!!!!!!' when: package_excludes is defined changed_when: true - + - name: Apply updates with excludes package: - state: latest - name: "*" - update_cache: true - exclude: "{{ package_excludes }}" + state: latest + name: "*" + update_cache: true + exclude: "{{ package_excludes }}" async: 7200 poll: 30 when: package_excludes is defined - name: run rkhunter if installed - hosts: "target:myvms_new" + hosts: "target:myvms_new" user: root tasks: diff --git a/playbooks/vhost_update_reboot.yml b/playbooks/vhost_update_reboot.yml index f0083ccbca..991c3297be 100644 --- a/playbooks/vhost_update_reboot.yml +++ b/playbooks/vhost_update_reboot.yml @@ -1,2 +1,3 @@ +--- - import_playbook: /srv/web/infra/ansible/playbooks/vhost_update.yml - import_playbook: /srv/web/infra/ansible/playbooks/vhost_reboot.yml