Compare commits

..

No commits in common. "main" and "main" have entirely different histories.

95 changed files with 1320 additions and 711 deletions

View file

@ -1,29 +0,0 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGpQExgBEADP5+9qybH7gg2aapWmy7dBLL64j45ALFyYtZCFprsFALW4OdIH
5jQwnt/k3ErygvVA2HTsN85f2vTnBUeRyCcZhgx6wLbfxSMqI1eCvWfTgTQ+Xyd/
TB8eDUW5hVPtW3M/9lCNm3gW8FFsY8eo62gbKQFMEHqv4jzvycJHC+dLSJwqDhRo
8QXcw8Xa3yyD1i4x/CJsxgnkbAuNN3FvJ0ALdc4QkeCslTV0R/APZYojOsdOxxj9
6OM8KsHTofoM90x7uDH5SBYfszA/dV38s7IIRMdhQVff7Vyru1Wg19xWAV1DB/XD
fIarhFV+UuzjdGBdYHCh8dJ7f+l3IvzeYtNDdgf1uho6TPU79OaGF5BQdyq3h3Ep
n7MvP7kDmf3zp/169ED1KafBzKlCxCB1f6C5icaddl4GXHhsSnLVU6GNWVDYzs49
PT1iJquGqQIVrdvZPVRxF9EajtOy2ihZrGuyu0CfEhmlxbxodRhl4QWxHtqI9VQf
qr8hNt3PJjQ9ZXF+39u65aV8VmsZm0ifwLjXf028KHYEn/ZxIADJpf6cs3tST/FC
NUdWydaRy15wHZGAW4DjITJYyOaxS/O88c0AYiPpyIzjcdM5X6yPd/Ks7jNp4jix
xq5+in4kT6Ob6i/vLGPiMOg2lgoDyk9Se4Xnfj0mji8BA+0Kd8822UQZtQARAQAB
tEBGZWRvcmEgSW5mcmFzdHJ1Y3R1cmUgKGluZnJhc3RydWN0dXJlKSA8YWRtaW5A
ZmVkb3JhcHJvamVjdC5vcmc+iQJSBBMBCAA8FiEEZsXzm0iCia3GFtyfH6GpJwHY
P8QFAmpQExgCGw8FCwkIBwIDIgIBBhUKCQgLAgQWAgMBAh4HAheAAAoJEB+hqScB
2D/ET3wP/RvrubZbpK5TGSnLnxbOx74RfjSW7B01cKuLEnZV4VMMlqZONTpvMPBT
t69aifiuVYsD1Pynj+WA0HduZdLnoczrlIYAqeAPwGOPz/ogmsEeTtnlCLzAT8Gr
VIT0MR/jhP/IUVuZQ0t7wY2Ezl7yYRnYiB4y8ZuofF8hmby363bceMsX0T/aDQNy
brbWKF38Ag8FQfzhTnYHnlBVUdo0Sdu94uINoW0jh6Y+ml+zusx4rP+BBqEvSQIG
xYEbWaDxxGyrCIIADz6yz6/0w6HYBh8LgqPOfRKqo/0KTe4ZuzX3Ao8r03ZIiQj4
7N+dA8bC9lPgHsoa6hMXamR6Mh1m/561RIzPSN8bkygg3d+Og4sglGI0FojFmdF7
C/WHZwXpMnLkaDIQgju0JCVO9Blut85u7u0WM5AcoEC7ODsv+kxAIFiTAZVf2zh2
1fV+lDyMVOtbykdn7YjbRvFGj3++2CJq+jP3S0Pnsc34eKsY+bw0pmCV2Wu1VPeA
V8hnpeGqz2vyhG8TqSXZnSgWaVR5T52GCNiohqPBMaOrNFa5xoV+FYPAZbPEJf/A
m85HsYgzmE9DbExX9JxrPpPiCmBe/DDmweP7slq+016OUHafR0shOBXVH5OFLU+w
esbMjQFiccYct/oGbfUZVIyDBxAL3Wq8yGzzI4sskR5HqoYIeNYb
=2YPV
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -1,6 +0,0 @@
[infrastructure-tags]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -1,6 +0,0 @@
[infrastructure-tags-stg]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra-stg/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -299,7 +299,6 @@ buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
[buildhw_stg]
buildhw-p10-01.stg.rdu3.fedoraproject.org
@ -328,7 +327,6 @@ buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
[buildhw_stg_rdu3]
buildhw-p10-01.stg.rdu3.fedoraproject.org

View file

@ -25,7 +25,6 @@ buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
## Build vm hosts
bvmhost-x86-01.rdu3.fedoraproject.org
bvmhost-x86-02.rdu3.fedoraproject.org

View file

@ -1,70 +0,0 @@
---
bmc:
ip_address: 10.16.160.79
ping: true
http: true
https: true
br0_ipv4_ip: 10.16.169.48
br0_ipv4_gw: 10.16.169.254
br0_ipv4_nm: 24
datacenter: rdu3
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
mac0: b4:45:06:fb:86:96
mac1: b4:45:06:fb:86:96
mac2: 5c:6f:69:7e:ec:b0
mac3: 5c:6f:69:7e:ec:b1
network_connections:
# Bridge profile
- name: br0
state: up
type: bridge
mtu: 1500
autoconnect: yes
ip:
address:
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
# Bond profile
- name: bond0
type: bond
interface_name: bond0
mtu: 1500
controller: br0
bond:
mode: 802.3ad
# Port profile for the 1st Ethernet device
- name: bond0-port1
mac: "{{ mac2 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# Port profile for the 2nd Ethernet device
- name: bond0-port2
mac: "{{ mac3 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: ""
date_hw_purchase: ""
hardware: PowerEdge R450
location: RDU3
oob_ip: "{{ bmc.ip_address }}"
serialno_a: C922FZ3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -17,5 +17,3 @@ zabbix_macros:
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_1_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_eu_es_1_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_dev"': 300
'COPR.STATS.HOST': copr-be-dev.cloud.fedoraproject.org

View file

@ -14,6 +14,3 @@ swap_file_path: /swap
swap_file_size_mb: 16384
zabbix_macros:
'CPU.UTIL.CRIT': 100 # frequent CPU spikes, noisy
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_1_prod"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_eu_es_1_prod"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_prod"': 300

View file

@ -0,0 +1,20 @@
---
- name: Make the app be real
hosts: localhost
connection: local
user: root
gather_facts: false
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
module_defaults:
group/awx.awx.controller:
controller_host: awx.fedoraproject.org
controller_username: "{{ awx_admin_username }}"
controller_password: "{{ awx_admin_password }}"
roles:
- role: awx/controller

View file

@ -115,6 +115,12 @@
object_app: bodhi
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: bodhi
start_build_buildname: bodhi-base
tags:
- never
- build
- role: openshift/object
object_app: bodhi
object_template_fullpath: "{{roles_path}}/bodhi2/base/templates/configmap.yml.j2"
@ -152,14 +158,24 @@
- role: openshift/imagestream
imagestream_app: bodhi
imagestream_imagename: bodhi-critpathcron
- role: openshift/app-actions
app_actions_app: bodhi
app_actions_builds:
- bodhi-base
app_actions_deployments:
- bodhi-web
- bodhi-consumer
- bodhi-celery
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-web
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-consumer
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-celery
tags:
- never
- rollout
post_tasks:
- name: Scale up pods

View file

@ -83,10 +83,3 @@
object_app: bugzilla2fedmsg
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: bugzilla2fedmsg
app_actions_builds:
- bugzilla2fedmsg-build
app_actions_deployments:
- bugzilla2fedmsg

View file

@ -169,14 +169,15 @@
object_template: container-secrets.yml.j2
object_objectname: container-secrets.yml
- role: openshift/start-build
start_build_app: cloud-image-uploader
start_build_buildname: cloud-image-uploader-build
start_build_objectname: cloud-image-uploader-build
tags:
- never
- build
- role: openshift/object
object_app: cloud-image-uploader
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: cloud-image-uploader
app_actions_builds:
- cloud-image-uploader-build
app_actions_deployments:
- cloud-image-uploader

View file

@ -36,17 +36,25 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: compose-tracker
start_build_buildname: compose-tracker-build
start_build_objectname: compose-tracker-build
tags:
- never
- build
- role: openshift/object
object_app: compose-tracker
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: compose-tracker
app_actions_builds:
- compose-tracker-build
app_actions_deployments:
- compose-tracker
- role: openshift/rollout
rollout_app: compose-tracker
rollout_dname: compose-tracker
tags:
- never
- rollout
###############################################
# actions to delete the project from OpenShift

View file

@ -42,6 +42,11 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: coreos-cincinnati
start_build_buildname: coreos-cincinnati-build
start_build_objectname: coreos-cincinnati-build
- role: openshift/object
object_app: coreos-cincinnati
object_template: config-stub.yml.j2
@ -52,6 +57,11 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/rollout
rollout_app: coreos-cincinnati
rollout_dname: coreos-cincinnati
tags: [never, rollout]
- role: openshift/object
object_app: coreos-cincinnati
object_template: service.yml.j2
@ -90,13 +100,6 @@
route_serviceport: coreos-cincinnati-raw-updates-status
route_servicename: coreos-cincinnati
- role: openshift/app-actions
app_actions_app: coreos-cincinnati
app_actions_builds:
- coreos-cincinnati-build
app_actions_deployments:
- coreos-cincinnati
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -50,12 +50,13 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/app-actions
app_actions_app: coreos-koji-tagger
app_actions_builds:
- coreos-koji-tagger-build
app_actions_deployments:
- coreos-koji-tagger
- role: openshift/start-build
start_build_app: coreos-koji-tagger
start_build_buildname: coreos-koji-tagger-build
start_build_objectname: coreos-koji-tagger-build
tags:
- never
- build
- role: openshift/object
object_app: coreos-koji-tagger

View file

@ -99,9 +99,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: datagrepper
app_actions_builds:
- datagrepper
app_actions_deployments:
- datagrepper
# - role: openshift/start-build
# start_build_app: datagrepper
# start_build_buildname: datagrepper
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: datagrepper
# rollout_dname: datagrepper
# tags:
# - never
# - rollout

View file

@ -87,10 +87,3 @@
object_app: datanommer
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: datanommer
app_actions_builds:
- datanommer
app_actions_deployments:
- datanommer

View file

@ -71,9 +71,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: discourse2fedmsg
app_actions_builds:
- discourse2fedmsg
app_actions_deployments:
- discourse2fedmsg
# - role: openshift/start-build
# start_build_app: discourse2fedmsg
# start_build_buildname: discourse2fedmsg
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: discourse2fedmsg
# rollout_dname: discourse2fedmsg
# tags:
# - never
# - rollout

View file

@ -1,6 +1,6 @@
---
- name: Make the app be real
hosts: os_control_stg # :os_control
hosts: os_control_stg #:os_control
user: root
gather_facts: false

View file

@ -37,10 +37,12 @@
object_objectname: buildconfig.yml
object_template: buildconfig.yml.j2
- role: openshift/app-actions
app_actions_app: docsbuilding
app_actions_builds:
- builder-build
- role: openshift/start-build
start_build_app: docsbuilding
start_build_buildname: builder-build
tags:
- never
- build
- role: openshift/object
object_app: docsbuilding

View file

@ -80,18 +80,6 @@
tags:
- deploy-cronjob
- name: App actions
ansible.builtin.include_role:
name: openshift/app-actions
vars:
app_actions_app: docstranslation
app_actions_builds:
- docstranslation-build
tags:
- never
- build
- rebuild
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -26,6 +26,14 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: drm-panic-frontend
start_build_buildname: drm-panic-frontend-build
start_build_objectname: drm-panic-frontend-build
tags:
- never
- build
- role: openshift/object
object_app: drm-panic-frontend
object_file: service.yml
@ -43,9 +51,9 @@
object_file: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: drm-panic-frontend
app_actions_builds:
- drm-panic-frontend-build
app_actions_deployments:
- drm-panic-frontend
- role: openshift/rollout
rollout_app: drm-panic-frontend
rollout_dcname: drm-panic-frontend
tags:
- never
- rollout

View file

@ -95,6 +95,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: elections
start_build_buildname: elections-build
start_build_objectname: elections-build
tags:
- never
- build
- role: openshift/object
object_app: elections
object_file: service.yml
@ -113,10 +121,3 @@
object_app: elections
object_file: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: elections
app_actions_builds:
- elections-build
app_actions_deployments:
- elections

View file

@ -10,8 +10,6 @@
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
- /srv/web/infra/ansible/roles/openshift-apps/elnbuildsync/vars/main.yml
- /srv/web/infra/ansible/roles/openshift-apps/elnbuildsync/vars/{{ env }}.yml
vars:
OCP_BUILD_WAIT: true
tasks:
- name: ELNBuildSync DB user
@ -135,6 +133,16 @@
tags:
- build
- role: openshift/start-build
start_build_app: elnbuildsync
start_build_buildname: elnbuildsync-build
start_build_objectname: elnbuildsync-build
vars:
OCP_BUILD_WAIT: true
tags:
- never
- build
- role: openshift/route
route_app: elnbuildsync
route_name: elnbuildsync
@ -149,13 +157,7 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
vars:
object_always_apply: "{{ 'true' if 'build' in ansible_run_tags else 'false' }}"
object_always_apply: "{{ 'true' if ('build' in ansible_run_tags or 'redeploy' in ansible_run_tags) else 'false' }}"
tags:
- build
- role: openshift/app-actions
app_actions_app: elnbuildsync
app_actions_builds:
- elnbuildsync-build
app_actions_deployments:
- elnbuildsync
- redeploy

View file

@ -110,9 +110,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: fasjson
app_actions_builds:
- fasjson
app_actions_deployments:
- fasjson
# - role: openshift/start-build
# start_build_app: fasjson
# start_build_buildname: fasjson
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: noggin
# rollout_dname: noggin
# tags:
# - never
# - rollout

View file

@ -58,6 +58,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: fedocal
start_build_buildname: fedocal-build
start_build_objectname: fedocal-build
tags:
- never
- build
- role: openshift/object
object_app: fedocal
object_file: service.yml
@ -80,10 +88,3 @@
object_file: cron.yml
object_objectname: cron.yml
when: env != 'staging'
- role: openshift/app-actions
app_actions_app: fedocal
app_actions_builds:
- fedocal-build
app_actions_deployments:
- fedocal

View file

@ -45,13 +45,6 @@
object_template: pvc.yml.j2
object_objectname: pvc.yml
- role: openshift/app-actions
app_actions_app: fedora-ostree-pruner
app_actions_builds:
- fedora-ostree-pruner-build
app_actions_deployments:
- fedora-ostree-pruner
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -38,6 +38,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: fedora-packages-static
start_build_buildname: fedora-packages-static-build
start_build_objectname: fedora-packages-static-build
tags:
- never
- build
- role: openshift/object
object_app: fedora-packages-static
object_file: service.yml
@ -55,14 +63,6 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: fedora-packages-static
app_actions_builds:
- fedora-packages-static-build
app_actions_deployments:
- fedora-packages-static
- solr
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -45,6 +45,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: flatpak-indexer
# This will trigger the main build via a imageChange trigger
start_build_buildname: flatpak-indexer-tardiff-build
tags:
- never
- build
- role: openshift/object
object_app: flatpak-indexer
object_file: service.yml
@ -54,13 +62,3 @@
object_app: flatpak-indexer
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: flatpak-indexer
app_actions_builds:
- flatpak-indexer-tardiff-build
app_actions_deployments:
- flatpak-indexer
- flatpak-quay-indexer
- flatpak-indexer-differ
- redis

View file

@ -234,25 +234,3 @@
object_app: fmn
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: fmn
app_actions_builds:
- python-312-collectd
app_actions_deployments:
- frontend
- api
- fmn
- sender-email
- sender-irc
- sender-matrix
- redis
- collectd
# this build and deployment are stg only, hence separated
- role: openshift/app-actions
app_actions_app: fmn
app_actions_builds:
- sendria
app_actions_deployments:
- sendria
when: env == "staging"

View file

@ -86,11 +86,19 @@
tags:
- apply-deploymentconfig
- role: openshift/app-actions
app_actions_app: greenwave
app_actions_deployments:
- greenwave-web
- greenwave-fedmsg-consumers
- role: openshift/rollout
rollout_app: greenwave
rollout_dname: greenwave-web
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: greenwave
rollout_dname: greenwave-fedmsg-consumers
tags:
- never
- rollout
- name: Change the route haproxy default timeout
hosts: os_control[0]:os_control_stg[0]

View file

@ -1,4 +1,3 @@
---
#
# Jira Sync
# https://github.com/Zlopez/jira_sync
@ -84,9 +83,16 @@
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: jira-sync
app_actions_builds:
- app
app_actions_deployments:
- app
- role: openshift/start-build
start_build_app: jira-sync
start_build_buildname: app
tags:
- never
- build
- role: openshift/rollout
rollout_app: jira-sync
rollout_dname: app
tags:
- never
- rollout

View file

@ -125,9 +125,10 @@
route_serviceport: 8080-tcp
route_servicename: kanban-web
- role: openshift/app-actions
app_actions_app: kanban
app_actions_builds:
- kanban-build
app_actions_deployments:
- kanban-web
- role: openshift/start-build
start_build_app: kanban
start_build_buildname: kanban-build
start_build_objectname: kanban-build
tags:
- never
- build

View file

@ -111,10 +111,3 @@
object_app: kerneltest
object_file: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: kerneltest
app_actions_builds:
- kerneltest-build
app_actions_deployments:
- kerneltest

View file

@ -100,9 +100,3 @@
object_app: keycloak
object_template: ipatuura-deployment.yml.j2
object_objectname: ipatuura-deployment.yml
# since keycloak is managed by the operator, there isn't a way to restart it using openshift/app-actions (rollout), hence only restarting ipa-tuura
- role: openshift/app-actions
app_actions_app: keycloak
app_actions_deployments:
- ipa-tuura

View file

@ -86,26 +86,3 @@
with_items: "{{ koschei_cron_jobs }}"
loop_control:
label: "{{ item.name }}"
- name: App actions
ansible.builtin.include_role:
name: openshift/app-actions
vars:
app_actions_app: "{{ app }}"
app_actions_deployments:
- admin
- frontend
- polling
- scheduler
- build-resolver
- repo-resolver
- watcher
- name: App actions (staging only)
ansible.builtin.include_role:
name: openshift/app-actions
vars:
app_actions_app: "{{ app }}"
app_actions_deployments:
- copr-resolver
- copr-scheduler
when: env == "staging"

View file

@ -27,12 +27,12 @@
object_objectname: buildconfig.yml
object_template: buildconfig.yml.j2
- role: openshift/app-actions
app_actions_app: languages
app_actions_builds:
- build-latest
app_actions_deployments:
- web
- role: openshift/start-build
start_build_app: languages
start_build_buildname: build-latest
tags:
- never
- build
- role: openshift/object
object_app: languages

View file

@ -92,6 +92,14 @@
secret_file_key: maubot.ca
secret_file_privatefile: "rabbitmq/{{env}}/ca-combined.crt"
- role: openshift/start-build
start_build_app: maubot
start_build_buildname: maubot-build
start_build_objectname: maubot-build
tags:
- never
- build
- role: openshift/object
object_app: maubot
object_file: service.yml
@ -109,12 +117,6 @@
object_template: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: maubot
app_actions_builds:
- maubot-build
app_actions_deployments:
- maubot
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -61,6 +61,14 @@
tags:
- cron-job
- role: openshift/start-build
start_build_app: mdapi
start_build_buildname: mdapi-build
start_build_objectname: mdapi-build
tags:
- never
- build
- role: openshift/object
object_app: mdapi
object_file: service.yml
@ -78,9 +86,9 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: mdapi
app_actions_builds:
- mdapi-build
app_actions_deployments:
- mdapi
- role: openshift/rollout
rollout_app: mdapi
rollout_dname: mdapi
tags:
- never
- rollout

View file

@ -164,9 +164,16 @@
object_template: cron-primary-mirror.yml.j2
object_objectname: cron-primary-mirror.yml
- role: openshift/app-actions
app_actions_app: mirrormanager
app_actions_builds:
- mirrormanager2
app_actions_deployments:
- frontend
- role: openshift/start-build
start_build_app: mirrormanager
start_build_buildname: mirrormanager2
tags:
- never
- build
- role: openshift/rollout
rollout_app: mirrormanager
rollout_dname: frontend
tags:
- never
- rollout

View file

@ -92,15 +92,14 @@
route_annotations:
haproxy.router.openshift.io/set-forwarded-headers: append
- role: openshift/app-actions
app_actions_app: mote
app_actions_builds:
- mote
app_actions_deployments:
- fedmsg
- mote
- mote-worker
- redis
- role: openshift/start-build
start_build_app: mote
start_build_buildname: mote
start_build_objectname: mote
tags:
- never
- build
#
###############################################
# actions to delete the project from OpenShift

View file

@ -106,9 +106,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: noggin-centos
app_actions_builds:
- noggin
app_actions_deployments:
- noggin
- role: openshift/start-build
start_build_app: noggin-centos
start_build_buildname: noggin
tags:
- never
- build
- role: openshift/rollout
rollout_app: noggin-centos
rollout_dname: noggin
tags:
- never
- rollout

View file

@ -102,9 +102,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: noggin
app_actions_builds:
- noggin
app_actions_deployments:
- noggin
- role: openshift/start-build
start_build_app: noggin
start_build_buildname: noggin
tags:
- never
- build
- role: openshift/rollout
rollout_app: noggin
rollout_dname: noggin
tags:
- never
- rollout

View file

@ -67,12 +67,12 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: openvpn
app_actions_builds:
- openvpn
app_actions_deployments:
- openvpn-client
- role: openshift/start-build
start_build_app: openvpn
start_build_buildname: openvpn
tags:
- never
- build
###############################################
# actions to delete the project from OpenShift

View file

@ -129,16 +129,10 @@
route_annotations:
haproxy.router.openshift.io/set-forwarded-headers: append
- role: openshift/app-actions
app_actions_app: oraculum
app_actions_builds:
- packager-dashboard-build
- packager-dashboard-frontend-build
- packager-dashboard-redis-build
app_actions_deployments:
- oraculum-api-endpoint
- oraculum-worker
- oraculum-beat
- oraculum-flower
- oraculum-redis
- oraculum-frontend
- role: openshift/start-build
start_build_app: oraculum
start_build_buildname: packager-dashboard-build
start_build_objectname: packager-dashboard-build
tags:
- never
- build

View file

@ -103,10 +103,3 @@
- role: rabbit/user
user_name: "planet{{ env_suffix }}"
user_sent_topics: ^org\.fedoraproject\.{{ env_short }}\.planet\..*
- role: openshift/app-actions
app_actions_app: planet
app_actions_builds:
- planet
app_actions_deployments:
- planet

View file

@ -113,32 +113,30 @@
object_objectname: imagestream.yml
tasks:
# doing it like this so it's dynamic and loads from vars/apps/poddlers.yml
- name: App actions (build)
- name: Include openshift/start-build role
tags:
- never
- build
- rebuild
block:
- name: Include openshift/app-actions role
# Use a block here to apply the tags to the tasks within the included role
# https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_tags.html#tag-inheritance-for-includes-blocks-and-the-apply-keyword
- name: Include openshift/start-build role
ansible.builtin.include_role:
name: openshift/app-actions
name: openshift/start-build
vars:
app_actions_app: poddlers
app_actions_builds:
- toddlers
- name: App actions (deployments)
start_build_app: poddlers
start_build_buildname: toddlers
- name: Include openshift/rollout role
tags:
- never
- restart
- rollout
- never
- rollout
block:
- name: Include openshift/app-actions role
# Use a block here too, same reason as above
- name: Include openshift/rollout role
ansible.builtin.include_role:
name: openshift/app-actions
name: openshift/rollout
vars:
app_actions_app: poddlers
app_actions_deployments:
- "{{ item.name }}"
rollout_app: poddlers
rollout_dname: "{{ item.name }}"
loop: "{{ poddlers_toddlers }}"
when: "item.replicas | default(1) > 0"

View file

@ -43,6 +43,12 @@
object_app: release-monitoring
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: release-monitoring
start_build_buildname: release-monitoring-web-build
tags:
- never
- build
- role: openshift/object
object_app: release-monitoring
object_template: configmap.yml.j2
@ -59,9 +65,9 @@
object_app: release-monitoring
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: release-monitoring
app_actions_builds:
- release-monitoring-web-build
app_actions_deployments:
- release-monitoring-web
- role: openshift/rollout
rollout_app: release-monitoring
rollout_dname: release-monitoring-web
tags:
- never
- rollout

View file

@ -83,10 +83,3 @@
object_app: resultsdb-ci-listener
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: resultsdb-ci-listener
app_actions_builds:
- resultsdb-ci-listener
app_actions_deployments:
- resultsdb-ci-listener

View file

@ -139,8 +139,19 @@
route_servicename: resultsdb-frontend
route_path: /
- role: openshift/app-actions
app_actions_app: resultsdb
app_actions_deployments:
- resultsdb-api
- resultsdb-frontend
# rollouts
- role: openshift/rollout
rollout_app: resultsdb
rollout_dname: "resultsdb-api"
failed_when: false
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: resultsdb
rollout_dname: "resultsdb-frontend"
failed_when: false
tags:
- never
- rollout

View file

@ -33,14 +33,15 @@
object_app: review-stats
object_template: pvc.yml.j2
object_objectname: pvc.yml
- role: openshift/start-build
start_build_app: review-stats
start_build_buildname: builder-build
tags:
- never
- build
- role: openshift/object
object_app: review-stats
object_template: cron.yml.j2
object_objectname: cron.yml
tags:
- deploy-cronjob
- role: openshift/app-actions
app_actions_app: review-stats
app_actions_builds:
- builder-build

View file

@ -0,0 +1,68 @@
---
- name: Make the app be real
hosts: os_masters[0]:os_masters_stg[0]
user: root
gather_facts: false
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
vars:
roles:
- role: openshift/project
project_app: test-auth
project_description: "Authentication testing"
project_appowners:
- abompard
tags:
- apply-appowners
- role: openshift/imagestream
imagestream_app: test-auth
imagestream_imagename: test-auth
- role: openshift/object
object_app: test-auth
object_template: buildconfig.yml
object_objectname: buildconfig.yml
- role: openshift/object
object_app: test-auth
object_template: configmap.yml
object_objectname: configmap.yml
- role: openshift/object
object_app: test-auth
object_file: service.yml
object_objectname: service.yml
# - role: openshift/route
# route_app: test-auth
# route_name: test-auth
# route_host: "admin{{ env_suffix }}.fedoraproject.org"
# route_path: "/test-auth"
# route_serviceport: web
# route_servicename: test-auth
# route_annotations:
# haproxy.router.openshift.io/timeout: 5m
- role: openshift/route
route_app: test-auth
route_name: test-auth
route_host: "test-auth.apps.ocp{{ env_suffix }}.fedoraproject.org"
route_serviceport: web
route_servicename: test-auth
route_annotations:
haproxy.router.openshift.io/timeout: 5m
- role: openshift/object
object_app: test-auth
object_template: secret-webhook.yml
object_objectname: secret-webhook.yml
- role: openshift/object
object_app: test-auth
object_template: deploymentconfig.yml
object_objectname: deploymentconfig.yml

View file

@ -105,11 +105,10 @@
route_serviceport: 8080-tcp
route_servicename: testdays
- role: openshift/app-actions
app_actions_app: testdays
app_actions_builds:
- testdays-build
- resultsdb-build
app_actions_deployments:
- testdays
- resultsdb
- role: openshift/start-build
start_build_app: testdays
start_build_buildname: testdays-build
start_build_objectname: testdays-build
tags:
- never
- build

View file

@ -83,14 +83,22 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: the-new-hotness
start_build_buildname: the-new-hotness-build
start_build_objectname: the-new-hotness-build
tags:
- never
- build
- role: openshift/object
object_app: the-new-hotness
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: the-new-hotness
app_actions_builds:
- the-new-hotness-build
app_actions_deployments:
- the-new-hotness
- role: openshift/rollout
rollout_app: the-new-hotness
rollout_dname: the-new-hotness
tags:
- never
- rollout

View file

@ -113,7 +113,9 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: waiverdb
app_actions_deployments:
- waiverdb-web
- role: openshift/rollout
rollout_app: waiverdb
rollout_dname: waiverdb-web
tags:
- never
- rollout

View file

@ -114,9 +114,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: webhook2fedmsg
app_actions_builds:
- webhook2fedmsg
app_actions_deployments:
- webhook2fedmsg
# - role: openshift/start-build
# start_build_app: webhook2fedmsg
# start_build_buildname: webhook2fedmsg
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: webhook2fedmsg
# rollout_dname: webhook2fedmsg
# tags:
# - never
# - rollout

View file

@ -31,13 +31,10 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
# NOTE: this was the original start-build, without any tags
# the current implementation with app-actions requires the build tag
# - role: openshift/start-build
# start_build_app: websites
# start_build_buildname: websites-build
# start_build_objectname: websites-build
- role: openshift/start-build
start_build_app: websites
start_build_buildname: websites-build
start_build_objectname: websites-build
- role: openshift/object
object_app: websites
@ -48,10 +45,3 @@
object_app: websites
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: websites
app_actions_builds:
- websites-build
app_actions_deployments:
- fedoraproject-push

View file

@ -0,0 +1,3 @@
---
collections:
- awx.awx

View file

@ -0,0 +1,6 @@
---
- name: Create Fedora Ansible Execution Environment
execution_environment:
name: Fedora ansible EE
image: registry.gitlab.com/darknao/fedora-ansible-ee:latest
pull: always

View file

@ -0,0 +1,11 @@
---
- name: Define batcave01 as execution node
instance:
hostname: batcave01.vpn.fedoraproject.org
node_type: execution
- name: Create batcave instance group
instance_group:
name: batcave
instances:
- batcave01.vpn.fedoraproject.org

View file

@ -0,0 +1,6 @@
---
- include_tasks: saml2.yml
- include_tasks: execution_environment.yml
- include_tasks: org.yml
- include_tasks: execution_nodes.yml
- include_tasks: projects.yml

View file

@ -0,0 +1,5 @@
---
- name: Create Fedora organization
organization:
name: Fedora
description: Fedora Project Org

View file

@ -0,0 +1,31 @@
---
- name: Create Fedora Infra project
project:
name: Fedora Infra
description: ""
scm_type: git
scm_url: https://pagure.io/fedora-infra/ansible.git
scm_clean: true
organization: Fedora
scm_update_on_launch: true
default_environment: Fedora ansible EE
- name: Create Fedora Infra Inventory
inventory:
name: Fedora Infra
description: ""
organization: Fedora
- name: Set up Fedora Infra Inventory source
inventory_source:
source_project: Fedora Infra
inventory: Fedora Infra
name: Fedora Infra Git
source: scm
source_path: inventory
update_on_launch: true
- name: Trigger inventory update
inventory_source_update:
name: Fedora Infra Git
inventory: Fedora Infra

View file

@ -0,0 +1,50 @@
---
- name: Configure SAML2 authentication
settings:
settings:
SAML_AUTO_CREATE_OBJECTS: true
SOCIAL_AUTH_SAML_SP_ENTITY_ID: https://awx.fedoraproject.org/
SOCIAL_AUTH_SAML_SP_PUBLIC_CERT:
"{{ lookup('file', '{{ private }}/files/awx/{{ env }}/awx-saml.crt') }}"
SOCIAL_AUTH_SAML_SP_PRIVATE_KEY:
"{{ lookup('file', '{{ private }}/files/awx/{{ env }}/awx-saml.key') }}"
SOCIAL_AUTH_SAML_ORG_INFO:
en-US:
url: https://awx.fedoraproject.org/
name: AWX
displayname: Ansible AWX
SOCIAL_AUTH_SAML_TECHNICAL_CONTACT:
emailAddress: infrastructure@lists.fedoraproject.org
givenName: Fedora Infrastructure
SOCIAL_AUTH_SAML_SUPPORT_CONTACT:
emailAddress: infrastructure@lists.fedoraproject.org
givenName: Fedora Infrastructure
SOCIAL_AUTH_SAML_ENABLED_IDPS:
fedora:
x509cert:
"{{ lookup(
'file',
'{{ private }}/files/saml2/{{ env }}/keys/idp.crt'
)
| regex_replace('\n', '')
}}"
attr_email: "email"
attr_first_name: "givenname"
attr_last_name: "surname"
attr_user_permanent_id: "name_id"
attr_username: "name_id"
entity_id: "https://id.fedoraproject.org/saml2/metadata"
url: "https://id.fedoraproject.org/saml2/SSO/Redirect"
SOCIAL_AUTH_SAML_SECURITY_CONFIG:
authnRequestsSigned: true
SOCIAL_AUTH_SAML_USER_FLAGS_BY_ATTR:
is_superuser_attr: groups
is_superuser_value:
- sysadmin-main
SOCIAL_AUTH_SAML_ORGANIZATION_MAP: {}
SOCIAL_AUTH_SAML_TEAM_ATTR:
saml_attr: groups
remove: true
team_org_map:
- organization: Fedora
team: fedora-websites

View file

@ -0,0 +1,57 @@
---
- name: Create the awx user
user:
name: awx
ansible.builtin.shell: /bin/bash
- name: Enable Copr repo for Ansible Receptor (Fedora)
community.general.copr:
name: ansible-awx/receptor
when: ansible_distribution == 'Fedora'
- name: Enable Copr repo for Ansible Receptor (RHEL)
community.general.copr:
name: ansible-awx/receptor
chroot: epel-9-x86_64
when:
- ansible_distribution == 'RedHat'
- ansible_distribution_major_version|int == 9
- name: Deploy podman
include_role:
name: awx/podman
vars:
podman_user: awx
podman_group: awx
- name: Deploy Ansible Receptor
include_role:
name: awx/receptor
vars:
receptor_user: awx
receptor_group: awx
receptor_verify: true
receptor_tls: true
receptor_mintls13: false
receptor_work_commands:
ansible-runner:
command: ansible-runner
params: worker
allowruntimeparams: true
verifysignature: true
custom_worksign_public_keyfile:
"{{ private }}/files/awx/{{ inventory_hostname }}/work-public-key.pem"
custom_tls_certfile: "{{ private }}/files/awx/{{ inventory_hostname }}/tls/receptor.crt"
custom_tls_keyfile: "{{ private }}/files/awx/{{ inventory_hostname }}/tls/receptor.key"
custom_ca_certfile: "{{ private }}/files/awx/{{ inventory_hostname }}/tls/ca/receptor-ca.crt"
receptor_protocol: 'tcp'
receptor_listener: true
receptor_port: 27199
receptor_dependencies:
- python3-pip
ansible_host: "{{ inventory_hostname }}"
- name: Install ansible-runner
pip:
name: ansible-runner
executable: pip3

View file

@ -0,0 +1,32 @@
# Ansible Role: Podman
Installs and configures Podman on RHEL/CentOS/Fedora servers.
## Role Variables
Available variables are listed below, along with default values.
---
podman_user: 'podman'
podman_group: 'podman'
The user and group under which podman will be configured.
---
default_runtime: 'crun'
The default container runtime to use for Podman.
---
default_cgroup_manager: 'cgroupfs'
The default cgroup manager to use for Podman.
---
# License
Apache 2

View file

@ -0,0 +1,8 @@
---
podman_user: 'podman'
podman_group: 'podman'
default_runtime: 'crun'
default_cgroup_manager: 'cgroupfs'
_hostname: "{{ routable_hostname | default(ansible_host) }}"

View file

@ -0,0 +1,48 @@
---
# Variable configuration.
- include_tasks: variables.yml
# Setup/install tasks.
- include_tasks: setup-RedHat.yml
when: ansible_os_family == 'RedHat'
- name: Create directory for podman runtime config
ansible.builtin.file:
path: "~{{ podman_user }}/.config/containers"
state: directory
mode: "0700"
owner: "{{ podman_user }}"
group: "{{ podman_group }}"
- name: Configure podman default runtime
ansible.builtin.copy:
content: |
[engine]
runtime = "{{ default_runtime }}"
cgroup_manager = "{{ default_cgroup_manager }}"
dest: "~{{ podman_user }}/.config/containers/containers.conf"
owner: "{{ podman_user }}"
group: "{{ podman_group }}"
mode: "0600"
- name: Create empty mounts config file to avoid permissions error message
ansible.builtin.copy:
content: ""
dest: "~{{ podman_user }}/.config/containers/mounts.conf"
force: false
owner: "{{ podman_user }}"
group: "{{ podman_group }}"
mode: "0600"
- name: Ensure registries.conf.d exists
ansible.builtin.file:
path: /etc/containers/registries.conf.d/
state: directory
mode: "0755"
- name: Force fully qualified image names to be provided to podman pull
ansible.builtin.copy:
content: |
unqualified-search-registries = []
dest: /etc/containers/registries.conf.d/force-fully-qualified-images.conf
mode: "0644"

View file

@ -0,0 +1,5 @@
---
- name: Install podman packages
ansible.builtin.dnf:
name: "{{ podman_packages }}"
state: present

View file

@ -0,0 +1,10 @@
---
- name: Include OS-specific variables (RedHat)
ansible.builtin.include_vars: "{{ ansible_os_family }}.yml"
when:
- ansible_os_family == 'RedHat'
- name: Define podman_packages
ansible.builtin.set_fact:
podman_packages: "{{ __podman_packages | list }}"
when: podman_packages is not defined

View file

@ -0,0 +1,4 @@
---
__podman_packages:
- podman
- crun

View file

@ -0,0 +1,219 @@
# Ansible Role: Setup
Installs and configures a Receptor node on RHEL/CentOS/Fedora servers.
## Role Variables
Available variables are listed below, along with default values.
---
receptor_packages:
- receptor
Set the names of the packages needed to install Receptor.
---
receptor_dependencies: []
Specify other packages needed, probably on a per-node-type basis using
groupvars or hostvars.
---
receptor_user: 'receptor'
receptor_group: 'receptor'
The user and group under which Receptor will run.
---
receptor_socket_dir: '/var/run/receptor'
The directory that Receptor will place its control socket into.
---
receptor_control_filename: 'receptor.sock'
The name of the control socket file.
---
receptor_config_path: '/etc/receptor'
Path to the Receptor config file.
---
routable_hostname: # defaults to not set
Hostvar for the routable address to this node. If this is unset
`ansible_host` will be used instead. Must be unique.
---
receptor_peers: # defaults to not set
Hostvar for the Ansible hosts that this node is peering outwards to.
This is expected to be a list of dicts.
In the dicts, the `'host'` key is required, `'port'` and `'protocol'`
are optional and will default to the overall defaults for
`receptor_port` and `receptor_protocol`.
---
receptor_tls: false
Enables the TLS protocol to be used for communication between nodes.
If enabled, appropriate certificates will have to be provided or
generated.
---
receptor_mintls13: false
If set to true, this forces the minimum TLS version used to be 1.3.
Otherwise, the minimum version will be 1.2. This variable has no
effect unless `receptor_tls` is enabled.
---
receptor_tls_dir: '/etc/receptor/tls'
receptor_tls_ca_dir: '{{ receptor_tls_dir }}/ca'
Directories on the server where the TLS keys and CA keys would be located.
---
receptor_tls_certfile: "{{ receptor_tls_dir }}/{{ receptor_host_identifier }}.crt"
receptor_tls_keyfile: "{{ receptor_tls_dir }}/{{ receptor_host_identifier }}.key"
Path on the server to the public and private TLS key files.
---
receptor_ca_certfile: "{{ receptor_tls_ca_dir }}/mesh-CA.crt"
receptor_ca_keyfile: "{{ receptor_tls_ca_dir }}/mesh-CA.key"
Path on the server where the public and private Certificate Authority
key files would be located.
---
custom_ca_certfile: # defaults to not set
custom_ca_keyfile: # defaults to not set
Path on the local filesystem to user-provided Certificate Authority
files.
---
custom_tls_certfile: # defaults to not set
custom_tls_keyfile: # defaults to not set
Hostvar that is the path on the local filesystem to user-provided
per-node certificate files. If used, both must be provided in
combination with a `custom_ca_certfile` that was used to sign them.
---
receptor_sign: false
Hostvar designating that this host will sign any work that it sends
over the Receptor mesh.
---
receptor_verify: false
Hostvar designating that this host will verify any work that it
receives using a public key.
---
receptor_worksign_key_dir: "/etc/receptor"
receptor_worksign_private_keyfile: "{{ receptor_worksign_key_dir }}/work_private_key.pem"
receptor_worksign_public_keyfile: "{{ receptor_worksign_key_dir }}/work_public_key.pem"
Path on the server to the public and private OpenSSL work signing key files.
---
custom_worksign_private_keyfile: # defaults to not set
custom_worksign_public_keyfile: # defaults to not set
Path on the local filesystem to user-provided OpenSSL work signing key
files.
---
receptor_fd_limit_soft: 4096
receptor_fd_limit_hard: 8192
The file descriptor limits in PAM for Receptor.
---
receptor_app_service: # defaults to not set
Optional variable to tie Receptor together with some other service in systemd.
---
receptor_log_level: 'info'
The level at which Receptor should write logs. Allowable options are 'error', 'warning', 'info', and 'debug'.
---
receptor_listener: true
Hostvar to enable Receptor to listen for incoming remote connections.
---
receptor_local_only: false
Hostvar to make this instance of Receptor listen for local-only
connections. If set to true, this will take precedence over the value
of `receptor_listener`.
---
receptor_protocol: 'tcp'
receptor_port: 27199
Override with hostvars for the protocol this instance of Receptor will
use (allowable options are 'tcp', 'udp', and 'ws' for websockets), and
the port number it will listen for those connections on.
---
receptor_work_commands: # defaults to not set
The definition of the Receptor work commands. This variable is
expected to be a dictionary, with keys the unique worktype name, and
values a dict of the rest of the key-value pairs of the work
definition. See
<https://receptor.readthedocs.io/en/latest/workceptor.html> for more
information.
---
receptor_kubernetes_commands: # defaults to not set
The definition of the Receptor work-kubernetes commands. This
variable is expected to be a dictionary, with keys the unique worktype
name, and values a dict of the rest of the key-value pairs of the work
definition. See <https://receptor.readthedocs.io/en/latest/k8s.html>
for more information.
---
# License
Apache 2

View file

@ -0,0 +1,38 @@
---
receptor_user: receptor
receptor_group: receptor
receptor_config_path: '/etc/receptor'
receptor_socket_dir: '/var/run/receptor'
receptor_control_filename: 'receptor.sock'
receptor_tls: false
receptor_mintls13: false
receptor_tls_dir: '/etc/receptor/tls'
receptor_tls_ca_dir: '{{ receptor_tls_dir }}/ca'
receptor_tls_certfile: "{{ receptor_tls_dir }}/{{ receptor_host_identifier }}.crt"
receptor_tls_keyfile: "{{ receptor_tls_dir }}/{{ receptor_host_identifier }}.key"
receptor_ca_certfile: "{{ receptor_tls_ca_dir }}/mesh-CA.crt"
receptor_ca_keyfile: "{{ receptor_tls_ca_dir }}/mesh-CA.key"
receptor_worksign_key_dir: "/etc/receptor"
receptor_worksign_private_keyfile: "{{ receptor_worksign_key_dir }}/work_private_key.pem"
receptor_worksign_public_keyfile: "{{ receptor_worksign_key_dir }}/work_public_key.pem"
receptor_fd_limit_soft: 4096
receptor_fd_limit_hard: 8192
receptor_listener: true
receptor_local_only: false
receptor_protocol: 'tcp'
receptor_port: 27199
receptor_sign: false
receptor_verify: false
receptor_log_level: 'info'
_hostname: "{{ routable_hostname | default(ansible_host) }}"
receptor_host_identifier:
"{{ (_hostname == 'localhost') | ternary('localhost.localdomain', _hostname) }}"

View file

@ -0,0 +1,41 @@
---
- name: Ensure soft/hard file descriptors limits
ansible.builtin.template:
src: templates/pam_limits.conf.j2
dest: /etc/security/limits.d/receptor.conf
mode: '0600'
owner: root
group: root
- name: Ensure systemd override directory exists
ansible.builtin.file:
dest: /etc/systemd/system/receptor.service.d
state: directory
owner: root
group: root
mode: '0755'
- name: Override receptor's systemd service runuser
ansible.builtin.template:
src: templates/systemd_receptor_override.conf.j2
dest: /etc/systemd/system/receptor.service.d/override.conf
mode: '0644'
owner: root
group: root
# notify: Restart Receptor
- name: Configure the receptor socket directory
ansible.builtin.file:
path: "{{ receptor_socket_dir }}"
state: directory
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
mode: '0750'
- name: Create tmpfiles.d entry for receptor socket directory
ansible.builtin.template:
src: templates/receptor_tmpd.conf.j2
dest: /etc/tmpfiles.d/receptor.conf
mode: '0640'
owner: root
group: root

View file

@ -0,0 +1,32 @@
---
# Variable configuration.
- include_tasks: variables.yml
# Setup/install tasks.
- include_tasks: setup-RedHat.yml
when: ansible_os_family == 'RedHat'
- include_tasks: configure.yml
- include_tasks: tls.yml
when: receptor_tls
- include_tasks: worksign.yml
when: receptor_sign or receptor_verify
- name: Deploy receptor config
ansible.builtin.template:
src: templates/receptor.conf.j2
dest: "{{ receptor_config_path }}/receptor.conf"
mode: '0644'
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
# notify:
# - "Receptor Reload"
- name: Start Receptor service
ansible.builtin.systemd:
name: receptor
state: started
daemon_reload: true
enabled: true

View file

@ -0,0 +1,10 @@
---
- name: Install receptor packages
ansible.builtin.dnf:
name: "{{ receptor_packages }}"
state: present
- name: Install dependencies specific to the node type
ansible.builtin.dnf:
name: "{{ receptor_dependencies | default([]) }}"
state: present

View file

@ -0,0 +1,27 @@
---
- name: Create Receptor cert directories
ansible.builtin.file:
dest: "{{ item }}"
state: directory
mode: '0750'
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
recurse: true
with_items:
- "{{ receptor_tls_dir }}"
- "{{ receptor_tls_ca_dir }}"
- name: Process provided TLS files
include_tasks: tls_local.yml
when: custom_tls_certfile is defined or custom_tls_keyfile is defined
- name: Set TLS file permissions
ansible.builtin.file:
dest: "{{ item }}"
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
mode: '0640'
with_items:
- "{{ receptor_tls_certfile }}"
- "{{ receptor_tls_keyfile }}"
- "{{ receptor_ca_certfile }}"

View file

@ -0,0 +1,61 @@
---
- name: Ensure both TLS files are provided
ansible.builtin.assert:
quiet: true
that:
- custom_tls_certfile | default('') | length
- custom_tls_keyfile | default('') | length
fail_msg: >
"You must provide both 'custom_tls_certfile' and 'custom_tls_keyfile'."
- name: Ensure CA certfile is provided
ansible.builtin.assert:
quiet: true
that:
- custom_ca_certfile | default('') | length
fail_msg: >
"You must provide the public CA file when providing custom TLS certificates."
- name: Check TLS private key modulus
delegate_to: localhost
become: false
ansible.builtin.command: openssl rsa -modulus -noout -in "{{ custom_tls_keyfile }}"
register: _tls_keyfile_modulus
changed_when: false
- name: Check TLS x509 key modulus
delegate_to: localhost
become: false
ansible.builtin.command: openssl x509 -modulus -noout -in "{{ custom_tls_certfile }}"
register: _tls_certfile_modulus
changed_when: false
- name: Ensure TLS pair matches
ansible.builtin.assert:
quiet: true
that:
- _tls_keyfile_modulus.stdout == _tls_certfile_modulus.stdout
fail_msg: >
"TLS !modulus! for {{ custom_tls_keyfile }} and {{ custom_tls_certfile }} doesn't match."
success_msg: "TLS !modulus! for {{ custom_tls_keyfile }} and {{ custom_tls_certfile }} matches."
- name: Ensure x509 certificate was signed by the expected Certificate Authority
delegate_to: localhost
become: false
ansible.builtin.command:
openssl verify -CAfile "{{ custom_ca_certfile }}" "{{ custom_tls_certfile }}"
changed_when: false
- name: Upload TLS files
become: true
become_user: "{{ receptor_user }}"
ansible.builtin.copy:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
mode: '0640'
with_items:
- {src: '{{ custom_tls_certfile }}', dest: '{{ receptor_tls_certfile }}'}
- {src: '{{ custom_tls_keyfile }}', dest: '{{ receptor_tls_keyfile }}'}
- {src: '{{ custom_ca_certfile }}', dest: '{{ receptor_ca_certfile }}'}

View file

@ -0,0 +1,10 @@
---
- name: Include OS-specific variables (RedHat)
ansible.builtin.include_vars: "{{ ansible_os_family }}.yml"
when:
- ansible_os_family == 'RedHat'
- name: Define receptor_packages
ansible.builtin.set_fact:
receptor_packages: "{{ __receptor_packages | list }}"
when: receptor_packages is not defined

View file

@ -0,0 +1,3 @@
---
- include_tasks: worksign_local.yml
when: custom_worksign_private_keyfile is defined or custom_worksign_public_keyfile is defined

View file

@ -0,0 +1,18 @@
---
- name: Distribute private work signing key
ansible.builtin.copy:
src: "{{ custom_worksign_private_keyfile }}"
dest: "{{ receptor_worksign_private_keyfile }}"
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
mode: '0640'
when: receptor_sign
- name: Distribute public work signing key
ansible.builtin.copy:
src: "{{ custom_worksign_public_keyfile }}"
dest: "{{ receptor_worksign_public_keyfile }}"
owner: "{{ receptor_user }}"
group: "{{ receptor_group }}"
mode: '0640'
when: receptor_verify

View file

@ -0,0 +1,3 @@
# Receptor limits
{{ receptor_user }} soft nofile {{ receptor_fd_limit_soft }}
{{ receptor_user }} hard nofile {{ receptor_fd_limit_hard }}

View file

@ -0,0 +1,83 @@
---
- node:
id: {{ receptor_host_identifier }}
{% if receptor_sign %}
- work-signing:
privatekey: {{ receptor_worksign_private_keyfile }}
tokenexpiration: 1m
{% endif %}
{% if receptor_verify %}
- work-verification:
publickey: {{ receptor_worksign_public_keyfile }}
{% endif %}
- log-level: {{ receptor_log_level }}
- control-service:
service: control
filename: {{ receptor_socket_dir }}/{{ receptor_control_filename }}
permissions: 0660
{% if receptor_tls -%}
tls: tls_server
{%- endif %}
{% if receptor_tls -%}
- tls-server:
name: tls_server
cert: {{ receptor_tls_certfile }}
key: {{ receptor_tls_keyfile }}
clientcas: {{ receptor_ca_certfile }}
requireclientcert: true
mintls13: {{ receptor_mintls13 | bool }}
- tls-client:
name: tls_client
cert: {{ receptor_tls_certfile }}
key: {{ receptor_tls_keyfile }}
rootcas: {{ receptor_ca_certfile }}
insecureskipverify: false
mintls13: {{ receptor_mintls13 | bool }}
{%- endif %}
{% if receptor_local_only %}
- local-only
{% elif receptor_listener %}
- {{ receptor_protocol }}-listener:
port: {{ receptor_port }}
{% if receptor_tls -%}
tls: tls_server
{%- endif %}
{% endif %}
{% if receptor_peers | default([]) %}
{% for peer in receptor_peers %}
- {{ peer['protocol'] }}-peer:
address: {{ peer['address'] | default(peer['host']) }}:{{ peer['port'] }}
redial: true
{% if receptor_tls -%}
tls: tls_client
{%- endif %}
{% endfor %}
{% endif %}
{% if receptor_work_commands is defined -%}
{% for command, config in receptor_work_commands.items() %}
- work-command:
worktype: {{ command }}
{% for key, value in config.items() %}
{{ key }}: {{ value }}
{% endfor %}
{% endfor %}
{%- endif %}
{%- if receptor_kubernetes_commands is defined %}
{% for command, config in receptor_kubernetes_commands.items() %}
- work-kubernetes:
worktype: {{ command }}
{% for key, value in config.items() %}
{{ key }}: {{ value }}
{% endfor %}
{% endfor %}
{% endif -%}

View file

@ -0,0 +1 @@
D {{ receptor_socket_dir }} 0750 {{ receptor_user }} {{ receptor_group }} -

View file

@ -0,0 +1,7 @@
[Service]
User={{ receptor_user }}
Group={{ receptor_group }}
{% if receptor_app_service is defined %}
[Unit]
PartOf={{ receptor_app_service }}
{% endif %}

View file

@ -0,0 +1,3 @@
---
__receptor_packages:
- receptor

View file

@ -1,179 +0,0 @@
zabbix_export:
version: '7.0'
template_groups:
- uuid: a333cbd6a3ad44baaa4eee4b0c0b1bec
name: Fedora
templates:
- uuid: 3ed7e6fe050847ea93a764a967ff5b6e
template: 'COPR Build metrics'
name: 'COPR Build metrics'
groups:
- name: Fedora
items:
- uuid: ad7184dda6f0453e9d63b587fc074cfb
name: 'Raw build metrics'
type: HTTP_AGENT
key: copr.builds.metrics
delay: 5m
history: 1h
value_type: TEXT
trends: '0'
url: 'https://{$COPR.STATS.HOST}/resalloc/api/stats'
tags:
- tag: source
value: raw
discovery_rules:
- uuid: 06250193c36d483994587fcc888f2e13
name: 'Discover pools'
type: DEPENDENT
key: copr.builds.pools
delay: '0'
description: 'Parse JSON from COPR build system for pool names'
item_prototypes:
- uuid: edfa8fa7ee694a4782fcdfe411545d0a
name: '{#POOL} - Average startup time'
type: DEPENDENT
key: 'copr.builds.avg_time[{#POOL}]'
delay: '0'
value_type: FLOAT
units: s
preprocessing:
- type: JSONPATH
parameters:
- '$.["{#POOL}"].startup_time_avg'
master_item:
key: copr.builds.metrics
tags:
- tag: copr-pool
value: '{#POOL}'
trigger_prototypes:
- uuid: 5ef177b6793041e79442412d0fd19479
expression: 'last(/COPR Build metrics/copr.builds.avg_time[{#POOL}]) > {$COPR.STARTUP.MAX:"{#POOL}"}'
name: 'Pool {#POOL}: startup time over {$COPR.STARTUP.MAX:"{#POOL}"}'
opdata: '{ITEM.LASTVALUE1}'
priority: WARNING
tags:
- tag: scope
value: builds
- uuid: 813ae4441c4b4a0d8ff9a0231661bc42
name: '{#POOL} - Last attempt'
type: DEPENDENT
key: 'copr.builds.last_attempt[{#POOL}]'
delay: '0'
history: 7d
trends: '0'
units: unixtime
preprocessing:
- type: JSONPATH
parameters:
- '$.["{#POOL}"].last_attempt_to_start'
master_item:
key: copr.builds.metrics
tags:
- tag: copr-pool
value: '{#POOL}'
- uuid: c2d15e23ebf44c8a81be03c9dc87ce2b
name: '{#POOL} - Last success'
type: DEPENDENT
key: 'copr.builds.last_success[{#POOL}]'
delay: '0'
history: 7d
trends: '0'
units: unixtime
preprocessing:
- type: JSONPATH
parameters:
- '$.["{#POOL}"].last_successful_start'
- type: STR_REPLACE
parameters:
- 'null'
- '0'
master_item:
key: copr.builds.metrics
tags:
- tag: copr-pool
value: '{#POOL}'
trigger_prototypes:
- uuid: 79ef1fe9b2c34229bfbe567da1ac525b
expression: 'last(/COPR Build metrics/copr.builds.last_success[{#POOL}])=0'
name: 'Pool {#POOL}: is not parseable'
priority: WARNING
tags:
- tag: scope
value: pools
- uuid: c5bc30b2923649e18e97220627a0ada5
name: '{#POOL} - Success rate'
type: DEPENDENT
key: 'copr.builds.success_rate[{#POOL}]'
delay: '0'
value_type: FLOAT
units: '%'
preprocessing:
- type: JSONPATH
parameters:
- '$.["{#POOL}"].startup_success_rate'
- type: MULTIPLIER
parameters:
- '100'
master_item:
key: copr.builds.metrics
tags:
- tag: copr-pool
value: '{#POOL}'
trigger_prototypes:
- uuid: e28b894fcebc4b7b9ce13a83edd90a85
expression: 'last(/COPR Build metrics/copr.builds.success_rate[{#POOL}])<60'
name: 'Pool {#POOL}: success rate below 60%'
opdata: '{{ITEM.LASTVALUE1}.fmtnum(2)}%'
priority: WARNING
tags:
- tag: scope
value: builds
trigger_prototypes:
- uuid: 29fe2b0ea017407ea687196b47f21483
expression: |
(
last(/COPR Build metrics/copr.builds.last_attempt[{#POOL}]) - last(/COPR Build metrics/copr.builds.last_success[{#POOL}])
) > 3600
and
(
last(/COPR Build metrics/copr.builds.last_attempt[{#POOL}],#1:now-6m) - last(/COPR Build metrics/copr.builds.last_success[{#POOL}],#1:now-6m)
) > 3600
name: 'Pool {#POOL}: last successful build is more than 1h older than last attempted build'
opdata: '{{ITEM.LASTVALUE1} - {ITEM.LASTVALUE2}} s'
priority: WARNING
tags:
- tag: scope
value: builds
master_item:
key: copr.builds.metrics
preprocessing:
- type: JAVASCRIPT
parameters:
- |
var metrics = JSON.parse(value);
var result = [];
Object.keys(metrics).forEach(function(pool) {
var metric = metrics[pool];
result.push({
"{#POOL}": pool,
"{#LAST_ATTEMPT}": metric.last_attempt_to_start,
"{#LAST_SUCCESS}": metric.last_successful_start,
"{#SUCCESS_RATE}": metric.startup_success_rate,
"{#STARTUP_AVG}": metric.startup_time_avg
});
});
return JSON.stringify(result);
tags:
- tag: not-infra
value: 'true'
- tag: team
value: copr
macros:
- macro: '{$COPR.STARTUP.MAX}'
value: '200'
description: 'seconds for startup time on a COPR pool'
- macro: '{$COPR.STATS.HOST}'
value: copr-be.cloud.fedoraproject.org

View file

@ -3,7 +3,7 @@
dnf: name=nrpe state=absent
- name: Set acl for nrpe on /etc/copr
acl: name=/etc/copr entity=nrpe etype=user state=absent
acl: name=/etc/copr entity=nrpe etype=user permissions=rx state=absent
- name: Set acl for nrpe on /etc/copr/copr-be.conf
acl: name=/etc/copr/copr-be.conf entity=nrpe etype=user state=absent
acl: name=/etc/copr/copr-be.conf entity=nrpe etype=user permissions=r state=absent

View file

@ -23,6 +23,12 @@
tags:
- zabbix_api
block:
- name: Import COPR BE template file
community.zabbix.zabbix_template:
template_yaml: "{{ lookup('file', 'zabbix/template-copr-be.yml') }}"
state: present
run_once: true
- name: Ensure COPR Zabbix hostgroup is present
community.zabbix.zabbix_group:
host_groups:
@ -30,23 +36,9 @@
state: present
run_once: true
- name: Import COPR BE template file
community.zabbix.zabbix_template:
template_yaml: "{{ lookup('file', 'zabbix/template-copr-be.yml') }}"
state: present
run_once: true
- name: Import COPR build checks template file
community.zabbix.zabbix_template:
template_yaml: "{{ lookup('file', 'zabbix/template-copr-builds.yml') }}"
state: present
run_once: true
- name: Add self to COPR BE template in Zabbix
community.zabbix.zabbix_host:
host_name: "{{ inventory_hostname }}"
host_groups: "All servers/Copr Hosts" # nest for permissions
link_templates:
- Copr BE checks
- COPR Build metrics
host_groups: Copr Hosts
link_templates: Copr BE checks
force: false

View file

@ -19,7 +19,7 @@ restorecon -Rv /etc/ssh
pushd /etc/yum.repos.d
curl -O $infraurl/rhel/rhel10.repo
curl -O $infraurl/rhel/epel10.repo
curl -o /etc/yum.repos.d/rhel-infra-tags.repo $infraurl/infra/ansible/files/common/rhel-infra-tags-20260709.repo
curl -O $infraurl/infra/ansible/files/common/rhel-infra-tags.repo
popd
#

View file

@ -28,11 +28,4 @@ configuration:
admin_groups:
- sysadmin-main
- sysadmin-eln
email:
smtp_host: bastion.fedoraproject.org
smtp_port: 25
smtp_username: eln-buildsync
from: eln-buildsync@fedoraproject.org
recipients:
- sgallagh@redhat.com
- yselkowitz@redhat.com
email: false

View file

@ -1,7 +1,7 @@
---
ebs_upstream_repo: https://github.com/fedora-eln/elnbuildsync.git
ebs_upstream_ref: 1.3.3
ebs_upstream_ref: 1.3.2
ebs_config_url: https://github.com/fedora-eln/elnbuildsync-config.git
ebs_config_branch: production

View file

@ -1,7 +1,7 @@
---
ebs_upstream_repo: https://github.com/fedora-eln/elnbuildsync.git
ebs_upstream_ref: 1.3.3
ebs_upstream_ref: 1.3.2
ebs_config_url: https://github.com/fedora-eln/elnbuildsync-config.git
ebs_config_branch: staging

View file

@ -109,8 +109,8 @@ handlers = ["console"]
[[consumer_config.koji_instances.primary.tags]]
from = "epel10-infra-candidate"
to = "epel10-infra-stg"
key = "{{ (env == 'production')|ternary('fedora-infra-20260709', 'testkey') }}"
keyid = "{{ (env == 'production')|ternary('01d83fc4', 'd300e724') }}"
key = "{{ (env == 'production')|ternary('fedora-infra', 'testkey') }}"
keyid = "{{ (env == 'production')|ternary('47dd8ef9', 'd300e724') }}"
[[consumer_config.koji_instances.primary.tags]]
from = "f43-infra-candidate"

View file

@ -100,33 +100,17 @@
- packages
- yumrepos
- name: Add infrastructure tags repo - RHEL (8,9)
- name: Add infrastructure tags repo - RHEL
ansible.builtin.copy: src="{{ files }}/common/rhel-infra-tags.repo" dest="/etc/yum.repos.d/infra-tags.repo"
when: ansible_distribution == 'RedHat' and ansible_distribution_major_version|int != 10
when: ansible_distribution == 'RedHat' or ansible_distribution == 'CentOS'
tags:
- config
- packages
- yumrepos
- name: Add infrastructure tags repo - RHEL (10+)
ansible.builtin.copy: src="{{ files }}/common/rhel-infra-tags-20260709.repo" dest="/etc/yum.repos.d/infra-tags.repo"
when: ansible_distribution == 'RedHat' and ansible_distribution_major_version|int >= 10
tags:
- config
- packages
- yumrepos
- name: Add infrastructure STAGING tags repo - RHEL (8,9)
- name: Add infrastructure STAGING tags repo - RHEL
ansible.builtin.copy: src="{{ files }}/common/rhel-infra-tags-stg.repo" dest="/etc/yum.repos.d/infra-tags-stg.repo"
when: (ansible_distribution == 'RedHat' and ansible_distribution_major_version|int != 10) and env in ['staging', 'pagure-staging']
tags:
- config
- packages
- yumrepos
- name: Add infrastructure STAGING tags repo - RHEL (10+)
ansible.builtin.copy: src="{{ files }}/common/rhel-infra-tags-stg-20260709.repo" dest="/etc/yum.repos.d/infra-tags-stg.repo"
when: (ansible_distribution == 'RedHat' and ansible_distribution_major_version|int >= 10) and env in ['staging', 'pagure-staging']
when: (ansible_distribution == 'RedHat' or ansible_distribution == 'CentOS') and env in ['staging', 'pagure-staging']
tags:
- config
- packages