1
0
Fork 0
forked from infra/ansible
Commit graph

46,581 commits

Author SHA1 Message Date
73a749e915
Zabbix: add 100 to postfix queue triggers for smtp-mm
spammers are making the queues longer, lets allow a bit more headroom

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 13:11:56 +01:00
97bd28d71e copr-be: retry libvirt pool-refresh few times
This was causing headaches @ vmhost-copr03-p09 (some unspecified
disk-performance issues).  Let's try the operation several times.
2026-06-19 13:34:48 +02:00
6de0108ef7 openQA dist-git PR test result reporting config (staging)
This *should* configure a new queue and consumer for openQA to
report dist-git PR test results back. It's all a bit speculative
ATM, may need some tweaking. Mostly applied only on staging for
now.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 13:25:02 +02:00
d4ae9f8244 Fix all my message queues to be non-exclusive and durable
AI caught that I've been cargo-culting a dumb message queue
config around from somewhere or other forever. Non-durable,
exclusive, and auto-delete is just about the worst config for a
queue you want to survive transitory issues like the server or
client going down or whatever. This might actually explain the
occasional issues we have with test results not showing up in
resultsdb, even.

This brings the config in line with most other message queues in
infra.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 13:15:18 +02:00
bc5be205b7
Zabbix: add an hour to the web-data triggers to give the crons time to run
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:52:31 +01:00
ef5567d8c0
Zabbix: add an hour to the MariaDB backup trigger to give the daily cron time to run
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:42:15 +01:00
3191e90c16
Zabbix: add zabbix_agent to places where nagios_client is used
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:41:51 +01:00
dd8d677a83 Revert "greenwave: disable gating on FreeIPA replica tests on Rawhide"
This reverts commit 0002bf4f26. I've
tweaked openQA to always softfail the tests on Rawhide for now, so
we no longer need to special-case the gating.
2026-06-19 10:24:03 +02:00
0002bf4f26 greenwave: disable gating on FreeIPA replica tests on Rawhide
See https://bugzilla.redhat.com/show_bug.cgi?id=2490607
We have found a bug in FreeIPA replica enrolment with the
OpenSSL 4 update. However, the bug is tricky to fix and the update
is massive and maintaining its side tag is very painful. As a
very exceptional case, we're disabling gating on these tests so
the update can be merged without causing all subsequent updates
to fail gating. We will endeavour to fix the bug and re-enable
normal gating service ASAP.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 00:52:33 +02:00
83f050747d Add communishift copr project ( ticket 13409 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-18 15:20:46 -07:00
20575cc5ff
📧 roles(fasjson): Update matrixadmin@ to use FAS group sponsors
This commit updates the `matrixadmin@fp.o` email address alias to now
use the `commops-wg-matrix` sponsor membership for the people who will
automatically receive email to the Matrix admin email. This is one step
to somewhat simplify membership of the email alias to a FAS-backed
mechanism for tracking and updating the sponsors.

Of course, sponsors cannot be updated in Noggin at the moment, so this
requires an IPA FAS admin to update the sponsor list for membership, but
this is an interim step for now.

Additionally, the `cle-managers@fp.o` email alias is added, which
ensures that key members of the CLE Team management will receive comms
to this email address, in the event that a key person from Fedora Infra
is on PTO, unavailable to respond, and to ensure delegation of access in
case of the "lottery factor".

People impacted by this change: @gwmngilfen @jasonbrooks @shaunm @blc
@smilner @ancarrol @jbley @mattdm

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-06-17 22:32:07 +02:00
92ac345388
Zabbix: adjust ping threshold for proxy30 & 38
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-17 11:28:55 +01:00
0655279df0
Zabbix: make ping threshold trigger configurable
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-17 10:26:33 +01:00
9421accd88
Nagios: remove old cronjob
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-16 16:24:16 +01:00
f61ee713df update releng coreos-team ipa group to use forge-* specific nomenclature
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-06-16 14:06:47 +05:30
d0ac65031b
EBS: Specify koji profile
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 17:10:58 -04:00
5736677bf0
EBS: bump to 1.1.2 in staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:58:24 -04:00
fdf8c95b09
ELNBuildSync: use the correct principal name
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:41:03 -04:00
27df4c5f19
ELNBuildSync: Pass krb5 principal name
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:34:29 -04:00
71107c6e45
ELNBuildSync: deploy 1.1.1 in staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:25:13 -04:00
98747b34a7
ELNBuildSync: Further fixes for prod/stg var split
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:25:13 -04:00
e0922f3d6c
docstranslation: Use git token instead of ssh key 2026-06-15 22:15:34 +02:00
James Antill
0a8e3dbe21 Revert "elnbuildsync: Add keytab_service variable for openshift/keytab."
This reverts commit 816d3c74a2.
2026-06-15 15:49:53 -04:00
James Antill
816d3c74a2 elnbuildsync: Add keytab_service variable for openshift/keytab.
Signed-off-by: James Antill <james@and.org>
2026-06-15 15:46:18 -04:00
James Antill
d7b285dfde elnbuildsync: Change serial to string type.
Signed-off-by: James Antill <james@and.org>
2026-06-15 15:22:53 -04:00
3789fc868a
ELNBuildSync: add Deployment serial
Ansible doesn't detect Deployment changes when dependent files are
modified, so we'll just add a serial we can bump up whenever we need to
force Ansible to re-deploy.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 15:16:36 -04:00
391b870f39
ELNBuildSync: Add missing suffix on Secret key
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 15:00:04 -04:00
69969ce815
ELNBuildSync: locate RabbitMQ certificates in the correct place
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 14:30:13 -04:00
9da15d2b03
ELNBuildSync: rework variable locations
Instead of having foo: and foo_stg: variables with ternary() selections
based on environment, take a cue from Koschei and use two variable files
in the role, selected by environment name.

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 14:30:12 -04:00
James Antill
075447568c roles/ipa/botuser: Drop the freeipa. prefix.
Signed-off-by: James Antill <james@and.org>
2026-06-15 13:10:21 -04:00
f5a5681182
elnbuildsync: Retrieve keytab from IPA
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:49:42 -04:00
f5d5a317df
keytab/botuser: Drop recursive variable assignment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:48:07 -04:00
f3766454d0
openshift/keytab: Support botuser keytab Secrets
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:47:23 -04:00
1d1dfa55b7
openshift/keytab check for different stderr
Different versions of OpenShift return different messages when a Secret
already exists in the project. Check for both variants out of an
abundance of caution.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:44:43 -04:00
7ef75bd174
elnbuildsync: limit to staging for now
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 09:08:05 -04:00
bb005e49aa
New roles: keytab/botuser and ipa/botuser
Allows the idempotent creation of a bot user with a randomized password.
Administrators can retrieve a keytab for this user without modifying the
password.

Playbook usage:

  - role: keytab/botuser
    username: "somebot"
    kt_location: /etc/keytabs/somebot.keytab
    tags:
    - config
    - krb5

Also accepts `first` and `last` arguments for given and family name, if
desired.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-12 14:17:30 -04:00
5343c0947b
Minor fixes to 95b1a7b3
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-12 18:30:09 +02:00
c8d93a8e0f
websites: restart S3 sync if it fails 2026-06-12 17:54:02 +02:00
c56b70e09f
docstranslation: disable scheduling during forge migration 2026-06-12 17:40:08 +02:00
95b1a7b3e4
Rewrite make-rabbitmq-certs-public in Python to access the YAML file
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-12 16:42:06 +02:00
6679a99e3a
Zabbix: Add HTTP check on drm-panic.fpo
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 13:01:35 +01:00
c052919334
Zabbix: Update PGSQL lock thresholds for busy dbs, they seem fine
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 12:18:27 +01:00
dc651012e1 added full path to oauth redirection annotation
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-12 10:16:01 +00:00
71958dc195
Nagios: disable systemd service
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 10:48:33 +01:00
264def3f42
Zabbix: Update Apache template to reduce service-down Matrix alerts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 10:47:02 +01:00
9b1c1f4890 feat(forgejo): securing metrics endpoint in prod
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-12 09:07:58 +02:00
3060702ac9 copr-be: the flavor we use in OSUOSL has been moved to P10
https://github.com/fedora-copr/copr/issues/4234
2026-06-11 22:22:19 +02:00
92d93d29f0 ELNBuildSync: Use different config branch on staging
Also fix missing variable reference for the main role deployment
playbook.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
63101653a1 ELNBuildSync: Fix AMQP configuration
Feedback from code review:

* Drop unused routing key
* Remove hardcoded .prod.
* Sync with queue_routing_keys in the playbook
* Properly interpret Jinja variables

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
81329e710d ELNBuildSync: Do not set AMQP queue as exclusive
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00