1
0
Fork 0
forked from infra/ansible
Commit graph

411 commits

Author SHA1 Message Date
James Antill
e98ab237e1 oidc: Change prod. ipsilon to use template file.
Signed-off-by: James Antill <james@and.org>
2026-07-14 14:12:29 -04:00
60a3b4052d forgefiler: add staging ipsilon config
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-07-14 09:10:44 +10:00
James Antill
898f57e064 oidc: Move openidc.production.static from a private file to a public template.
Signed-off-by: James Antill <james@and.org>
2026-07-13 17:15:18 -04:00
James Antill
ff663e686f elnbuildsync: Use auth_method=client_secret_basic.
Signed-off-by: James Antill <james@and.org>
2026-07-07 17:12:49 -04:00
James Antill
108228f6fd elnbuildsync: Add stg. config. to ipsilon.
Signed-off-by: James Antill <james@and.org>
2026-07-07 15:39:11 -04:00
004fb438fe
Badges: the frontend needs its own OIDC client
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 10:07:57 +02:00
2e63ef6b72
Badges: adjust the oidc callback URL in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 09:31:18 +02:00
442852923d fix: fix the annoying HTTP authentication popup on windows (prod)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:15:51 +00:00
73dc88c487
fix: fix the annoying HTTP authentication popup on windows (stg only)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:23:41 +02:00
f6b50eb89c Remove OpenID from Fedora
This change will remove routing and configuration for OpenID in Fedora.
Which was originally announced to sunset on 1st May 2026.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 15:34:39 +02:00
bc2bd50a06
Add another Ipsilon patch
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-04-30 10:12:30 +02:00
5d9fc05269 Decommission OpenID on staging
This commit is a first step to decommission OpenID authentication on
staging. It doesn't do much as most of it needs to stay for production.
See infra/tickets#13265 for more info.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-16 09:48:46 +00:00
585d429097 [ipsilon] Fix the copy/paste error
This should be applied everywhere, not only to openid instances.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 17:02:54 +01:00
67cf76f6f8 [ipsilon] Fix the links pointing to pagure.io
The error pages were pointing to pagure.io/fedora-infrastructure/issues.
This commit adds patch that changes it to
forge.fedoraproject.org/infra/tickets/issues.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 16:53:27 +01:00
aedf43d1f3 Restore arcane breadcrumbs (broken Forge links)
Also some minor changes to satisfy yamllint.

Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-03-11 21:09:36 +00:00
1d6aa6f15a [webhook2fm] fix typo from 8a61479d64
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:18:10 +10:00
8a61479d64 [webhook2fm] update staging rediurect URIs
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:06:52 +10:00
5091fd4373 ocp-rdu3: retire this host/proxy/cert now that we are moved
There's no need to keep ocp-rdu3 around anymore, we only used
it when we were moving datacenters last year.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 10:35:10 -08:00
72fad29431
Ipsilon: fix the GNOME Damned Lies redirect URL
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-01-30 13:03:59 +01:00
a754144f19 Update infra pagure.io links to forge.fp.o (WIP)
This should update all the references we have to
https://pagure.io/fedora-infrastructure to the
new https://forge.fedoraproject.org/infra/tickets/ area.

Do not merge this before the migration on tuesday.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-20 14:39:40 -08:00
867111750e [ipsilon] Add OIDC entry for GNOME Damned Lies
Add staging OIDC entry to ipsilon for GNOME Damned Lies. See more info
in https://pagure.io/fedora-infrastructure/issue/13017.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-01-20 15:16:48 +01:00
021c63e9df Update some Forgejo-migrated repo URLs
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-01-09 18:51:10 -08:00
6a12544029
forgejo: modifying ipsilon config for the staging dist-git instance
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-19 13:34:53 +00:00
53e01287bb
forgejo: update ipsilon with the correct temporary hostname for callback
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-19 13:26:46 +00:00
27186ed2cf
forgejo: distgit staging config for ipsilon
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-10 14:16:14 +00:00
aa81d9a1c9 [ipsilon] Fix jinja2 template
Missing endif caused it to fail during playbook run. This should fix it.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-11-21 11:44:00 +01:00
a08cbb190f [ipsilon] Separate openID instance on production
This will apply the changes done for staging on production and
introduces ipsilon03 machine, which will be OpenID only.
2025-11-18 14:27:58 +01:00
ba209ee7df Fixes for OpenID only ipsilon instance in staging
After some troubleshooting I was finally able to fix the OpenID
authentication on staging. These are the changes I ended up deploying to fix
the remaining issues.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-11-03 09:33:32 +00:00
446e63e6c6 [ipsilon] Check if the variable is defined first
Check if the openid variabled defined first, otherwise the playbook will fail.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-03 13:53:06 +02:00
6cbcc82f53 [ipsilon] Add OpenID banner
This will add OpenID banner to ipsilon instance that is set as OpenID only.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-03 13:24:55 +02:00
f1213c4af8 [ipsilon] Fix nesting in jinja template
I hope this is the last one.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:50:16 +02:00
99bebc403e [ipsilon] Fix jinja2 nesting
This time it should be correct.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:30:56 +02:00
ebaab04a7b [ipsilon] Add missing endif
Nesting with jinja2 is somewhat not visible at first glance.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:11:03 +02:00
3ff5d4fc8b [ipsilon] Enable openid again on production
I forgot to specify that the changes are only for staging now, so it
disabled OpenID on production when the playbook was played. Let's fix that.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 12:54:50 +02:00
b8a41de30e [ipsilon] Fix ansible-lint errors
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 10:09:22 +02:00
ca04c6d41a [ipsilon] Use different repo URL
The current repo URL was evaluated as
https://pagure.io/fedora-infra/ipsilon-fedora.git/ which returns 404 on
pagure.io. Let's use just the
https://pagure.io/fedora-infra/ipsilon-fedora, which works even with the
added / at the end.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 07:40:48 +00:00
825069860a [ipsilon] Add OpenID header
The ipsilon instance with disabled OpenID authentication still needs to
sent the header for OpenID in response so the authentication could
continue with different instance.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 07:25:34 +00:00
a9ef982c03 [ipsilon] Check if variable is defined first
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-09-25 14:35:57 +02:00
4592e463f4 Setup ipsilon02 as OpenID only instance
This will split the ipsilon config to OpenID and everything else.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-09-25 14:17:08 +02:00
9ea5295dca [forgejo] update oauth config to match brand better
resolves: https://codeberg.org/fedora/forgejo-deployment/issues/144

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-08-21 18:48:30 +10:00
da2c3cc7bb
forgejo: update the ipsilon config for forgejo staging
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-08-20 15:53:15 +00:00
34f4f8d119
Webhook2fedmsg: Allow the UI's OIDC callback URL
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-08-18 14:45:56 +02:00
651b58cee2 badges: add client config for UI revamp testing
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2025-08-12 07:31:16 +00:00
ea4f07c9d7
Revert "Zabbix: Add ipsilon oidc entry for zabbix-stg"
Zabbix uses SAML, not OIDC, which I misunderstood

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-07-17 12:20:23 +01:00
978916004d
Zabbix: Add ipsilon oidc entry for zabbix-stg
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-07-16 10:23:31 +01:00
c319941db9 Add client config for W2FM UI test environment
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2025-07-10 05:16:44 +00:00
56fb57934b
Ipsilon: adjust rewrite rule because apache now adds the / prefix
Fixes: https://pagure.io/fedora-infrastructure/issue/12624

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-07-07 16:36:42 +02:00
82b4bb3b4e
Change the fedocal OIDC callback URL
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-07-07 12:14:00 +02:00
fb5f6de876
add ocp-rdu3.stg oauth config 2025-06-26 13:10:55 +02:00
302e329a54 [ipsilon] Remove secret from w2fm entry for staging
w2fm doesn't need a secret as it's client application and doesn't use SSO.
2025-06-03 16:33:36 +02:00