James Antill
e98ab237e1
oidc: Change prod. ipsilon to use template file.
...
Signed-off-by: James Antill <james@and.org>
2026-07-14 14:12:29 -04:00
60a3b4052d
forgefiler: add staging ipsilon config
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-07-14 09:10:44 +10:00
James Antill
898f57e064
oidc: Move openidc.production.static from a private file to a public template.
...
Signed-off-by: James Antill <james@and.org>
2026-07-13 17:15:18 -04:00
James Antill
ff663e686f
elnbuildsync: Use auth_method=client_secret_basic.
...
Signed-off-by: James Antill <james@and.org>
2026-07-07 17:12:49 -04:00
James Antill
108228f6fd
elnbuildsync: Add stg. config. to ipsilon.
...
Signed-off-by: James Antill <james@and.org>
2026-07-07 15:39:11 -04:00
004fb438fe
Badges: the frontend needs its own OIDC client
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 10:07:57 +02:00
2e63ef6b72
Badges: adjust the oidc callback URL in staging
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 09:31:18 +02:00
442852923d
fix: fix the annoying HTTP authentication popup on windows (prod)
...
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:15:51 +00:00
73dc88c487
fix: fix the annoying HTTP authentication popup on windows (stg only)
...
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:23:41 +02:00
f6b50eb89c
Remove OpenID from Fedora
...
This change will remove routing and configuration for OpenID in Fedora.
Which was originally announced to sunset on 1st May 2026.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 15:34:39 +02:00
bc2bd50a06
Add another Ipsilon patch
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-04-30 10:12:30 +02:00
5d9fc05269
Decommission OpenID on staging
...
This commit is a first step to decommission OpenID authentication on
staging. It doesn't do much as most of it needs to stay for production.
See infra/tickets#13265 for more info.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-16 09:48:46 +00:00
585d429097
[ipsilon] Fix the copy/paste error
...
This should be applied everywhere, not only to openid instances.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 17:02:54 +01:00
67cf76f6f8
[ipsilon] Fix the links pointing to pagure.io
...
The error pages were pointing to pagure.io/fedora-infrastructure/issues.
This commit adds patch that changes it to
forge.fedoraproject.org/infra/tickets/issues.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 16:53:27 +01:00
aedf43d1f3
Restore arcane breadcrumbs (broken Forge links)
...
Also some minor changes to satisfy yamllint.
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-03-11 21:09:36 +00:00
1d6aa6f15a
[webhook2fm] fix typo from 8a61479d64
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:18:10 +10:00
8a61479d64
[webhook2fm] update staging rediurect URIs
...
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:06:52 +10:00
5091fd4373
ocp-rdu3: retire this host/proxy/cert now that we are moved
...
There's no need to keep ocp-rdu3 around anymore, we only used
it when we were moving datacenters last year.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 10:35:10 -08:00
72fad29431
Ipsilon: fix the GNOME Damned Lies redirect URL
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-01-30 13:03:59 +01:00
a754144f19
Update infra pagure.io links to forge.fp.o (WIP)
...
This should update all the references we have to
https://pagure.io/fedora-infrastructure to the
new https://forge.fedoraproject.org/infra/tickets/ area.
Do not merge this before the migration on tuesday.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-20 14:39:40 -08:00
867111750e
[ipsilon] Add OIDC entry for GNOME Damned Lies
...
Add staging OIDC entry to ipsilon for GNOME Damned Lies. See more info
in https://pagure.io/fedora-infrastructure/issue/13017 .
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-01-20 15:16:48 +01:00
021c63e9df
Update some Forgejo-migrated repo URLs
...
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-01-09 18:51:10 -08:00
6a12544029
forgejo: modifying ipsilon config for the staging dist-git instance
...
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-19 13:34:53 +00:00
53e01287bb
forgejo: update ipsilon with the correct temporary hostname for callback
...
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-19 13:26:46 +00:00
27186ed2cf
forgejo: distgit staging config for ipsilon
...
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-12-10 14:16:14 +00:00
aa81d9a1c9
[ipsilon] Fix jinja2 template
...
Missing endif caused it to fail during playbook run. This should fix it.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-11-21 11:44:00 +01:00
a08cbb190f
[ipsilon] Separate openID instance on production
...
This will apply the changes done for staging on production and
introduces ipsilon03 machine, which will be OpenID only.
2025-11-18 14:27:58 +01:00
ba209ee7df
Fixes for OpenID only ipsilon instance in staging
...
After some troubleshooting I was finally able to fix the OpenID
authentication on staging. These are the changes I ended up deploying to fix
the remaining issues.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-11-03 09:33:32 +00:00
446e63e6c6
[ipsilon] Check if the variable is defined first
...
Check if the openid variabled defined first, otherwise the playbook will fail.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-03 13:53:06 +02:00
6cbcc82f53
[ipsilon] Add OpenID banner
...
This will add OpenID banner to ipsilon instance that is set as OpenID only.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-03 13:24:55 +02:00
f1213c4af8
[ipsilon] Fix nesting in jinja template
...
I hope this is the last one.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:50:16 +02:00
99bebc403e
[ipsilon] Fix jinja2 nesting
...
This time it should be correct.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:30:56 +02:00
ebaab04a7b
[ipsilon] Add missing endif
...
Nesting with jinja2 is somewhat not visible at first glance.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 13:11:03 +02:00
3ff5d4fc8b
[ipsilon] Enable openid again on production
...
I forgot to specify that the changes are only for staging now, so it
disabled OpenID on production when the playbook was played. Let's fix that.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 12:54:50 +02:00
b8a41de30e
[ipsilon] Fix ansible-lint errors
...
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 10:09:22 +02:00
ca04c6d41a
[ipsilon] Use different repo URL
...
The current repo URL was evaluated as
https://pagure.io/fedora-infra/ipsilon-fedora.git/ which returns 404 on
pagure.io. Let's use just the
https://pagure.io/fedora-infra/ipsilon-fedora , which works even with the
added / at the end.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 07:40:48 +00:00
825069860a
[ipsilon] Add OpenID header
...
The ipsilon instance with disabled OpenID authentication still needs to
sent the header for OpenID in response so the authentication could
continue with different instance.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-10-02 07:25:34 +00:00
a9ef982c03
[ipsilon] Check if variable is defined first
...
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-09-25 14:35:57 +02:00
4592e463f4
Setup ipsilon02 as OpenID only instance
...
This will split the ipsilon config to OpenID and everything else.
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2025-09-25 14:17:08 +02:00
9ea5295dca
[forgejo] update oauth config to match brand better
...
resolves: https://codeberg.org/fedora/forgejo-deployment/issues/144
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-08-21 18:48:30 +10:00
da2c3cc7bb
forgejo: update the ipsilon config for forgejo staging
...
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2025-08-20 15:53:15 +00:00
34f4f8d119
Webhook2fedmsg: Allow the UI's OIDC callback URL
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-08-18 14:45:56 +02:00
651b58cee2
badges: add client config for UI revamp testing
...
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2025-08-12 07:31:16 +00:00
ea4f07c9d7
Revert "Zabbix: Add ipsilon oidc entry for zabbix-stg"
...
Zabbix uses SAML, not OIDC, which I misunderstood
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-07-17 12:20:23 +01:00
978916004d
Zabbix: Add ipsilon oidc entry for zabbix-stg
...
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2025-07-16 10:23:31 +01:00
c319941db9
Add client config for W2FM UI test environment
...
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2025-07-10 05:16:44 +00:00
56fb57934b
Ipsilon: adjust rewrite rule because apache now adds the / prefix
...
Fixes: https://pagure.io/fedora-infrastructure/issue/12624
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-07-07 16:36:42 +02:00
82b4bb3b4e
Change the fedocal OIDC callback URL
...
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2025-07-07 12:14:00 +02:00
fb5f6de876
add ocp-rdu3.stg oauth config
2025-06-26 13:10:55 +02:00
302e329a54
[ipsilon] Remove secret from w2fm entry for staging
...
w2fm doesn't need a secret as it's client application and doesn't use SSO.
2025-06-03 16:33:36 +02:00