Compare commits

..

No commits in common. "main" and "main" have entirely different histories.

237 changed files with 3400 additions and 1406 deletions

View file

@ -1,29 +0,0 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGpQExgBEADP5+9qybH7gg2aapWmy7dBLL64j45ALFyYtZCFprsFALW4OdIH
5jQwnt/k3ErygvVA2HTsN85f2vTnBUeRyCcZhgx6wLbfxSMqI1eCvWfTgTQ+Xyd/
TB8eDUW5hVPtW3M/9lCNm3gW8FFsY8eo62gbKQFMEHqv4jzvycJHC+dLSJwqDhRo
8QXcw8Xa3yyD1i4x/CJsxgnkbAuNN3FvJ0ALdc4QkeCslTV0R/APZYojOsdOxxj9
6OM8KsHTofoM90x7uDH5SBYfszA/dV38s7IIRMdhQVff7Vyru1Wg19xWAV1DB/XD
fIarhFV+UuzjdGBdYHCh8dJ7f+l3IvzeYtNDdgf1uho6TPU79OaGF5BQdyq3h3Ep
n7MvP7kDmf3zp/169ED1KafBzKlCxCB1f6C5icaddl4GXHhsSnLVU6GNWVDYzs49
PT1iJquGqQIVrdvZPVRxF9EajtOy2ihZrGuyu0CfEhmlxbxodRhl4QWxHtqI9VQf
qr8hNt3PJjQ9ZXF+39u65aV8VmsZm0ifwLjXf028KHYEn/ZxIADJpf6cs3tST/FC
NUdWydaRy15wHZGAW4DjITJYyOaxS/O88c0AYiPpyIzjcdM5X6yPd/Ks7jNp4jix
xq5+in4kT6Ob6i/vLGPiMOg2lgoDyk9Se4Xnfj0mji8BA+0Kd8822UQZtQARAQAB
tEBGZWRvcmEgSW5mcmFzdHJ1Y3R1cmUgKGluZnJhc3RydWN0dXJlKSA8YWRtaW5A
ZmVkb3JhcHJvamVjdC5vcmc+iQJSBBMBCAA8FiEEZsXzm0iCia3GFtyfH6GpJwHY
P8QFAmpQExgCGw8FCwkIBwIDIgIBBhUKCQgLAgQWAgMBAh4HAheAAAoJEB+hqScB
2D/ET3wP/RvrubZbpK5TGSnLnxbOx74RfjSW7B01cKuLEnZV4VMMlqZONTpvMPBT
t69aifiuVYsD1Pynj+WA0HduZdLnoczrlIYAqeAPwGOPz/ogmsEeTtnlCLzAT8Gr
VIT0MR/jhP/IUVuZQ0t7wY2Ezl7yYRnYiB4y8ZuofF8hmby363bceMsX0T/aDQNy
brbWKF38Ag8FQfzhTnYHnlBVUdo0Sdu94uINoW0jh6Y+ml+zusx4rP+BBqEvSQIG
xYEbWaDxxGyrCIIADz6yz6/0w6HYBh8LgqPOfRKqo/0KTe4ZuzX3Ao8r03ZIiQj4
7N+dA8bC9lPgHsoa6hMXamR6Mh1m/561RIzPSN8bkygg3d+Og4sglGI0FojFmdF7
C/WHZwXpMnLkaDIQgju0JCVO9Blut85u7u0WM5AcoEC7ODsv+kxAIFiTAZVf2zh2
1fV+lDyMVOtbykdn7YjbRvFGj3++2CJq+jP3S0Pnsc34eKsY+bw0pmCV2Wu1VPeA
V8hnpeGqz2vyhG8TqSXZnSgWaVR5T52GCNiohqPBMaOrNFa5xoV+FYPAZbPEJf/A
m85HsYgzmE9DbExX9JxrPpPiCmBe/DDmweP7slq+016OUHafR0shOBXVH5OFLU+w
esbMjQFiccYct/oGbfUZVIyDBxAL3Wq8yGzzI4sskR5HqoYIeNYb
=2YPV
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -1,6 +0,0 @@
[infrastructure-tags]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -1,6 +0,0 @@
[infrastructure-tags-stg]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra-stg/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -11,6 +11,9 @@
- name: Reload apache
action: service name=httpd state=reloaded
- name: Restart collectd
action: service name=collectd state=restarted
- name: Restart crond
action: service name=crond state=restarted

View file

@ -298,8 +298,6 @@ buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
[buildhw_stg]
buildhw-p10-01.stg.rdu3.fedoraproject.org
@ -327,8 +325,6 @@ buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
[buildhw_stg_rdu3]
buildhw-p10-01.stg.rdu3.fedoraproject.org

View file

@ -36,6 +36,8 @@ baseiptables: True
become: false
br0_nm: 255.255.255.0
br1_nm: 255.255.255.0
# assume collectd apache
collectd_apache: true
# communishift project resource overrides
communishift_projects:
# please keep these sorted alphabetically for readability

View file

@ -1,4 +1,5 @@
---
collectd_apache: false
freezes: false
nagios_Check_Services:
nrpe: true

View file

@ -2,6 +2,7 @@
# Define resources for this group of hosts here.
blocked_ip_v6: []
blocked_ips: ['14.102.69.78', '104.219.54.236', '103.38.177.2', '110.172.140.98', '183.80.131.253', '113.190.178.137', '115.76.39.108', '116.109.31.204', '209.64.155.56']
collectd_apache: true
# For the MOTD
custom_rules: [
# Need for rsync from log01 for logs.

View file

@ -1,5 +1,6 @@
---
# Define resources for this group of hosts here.
collectd_apache: true
# For the MOTD
custom_rules: [
# Need for rsync from log01 for logs.

View file

@ -24,8 +24,6 @@ buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
buildhw-x86-16.rdu3.fedoraproject.org
buildhw-x86-17.rdu3.fedoraproject.org
## Build vm hosts
bvmhost-x86-01.rdu3.fedoraproject.org
bvmhost-x86-02.rdu3.fedoraproject.org

View file

@ -1,70 +0,0 @@
---
bmc:
ip_address: 10.16.160.90
ping: true
http: true
https: true
br0_ipv4_ip: 10.16.169.46
br0_ipv4_gw: 10.16.169.254
br0_ipv4_nm: 24
datacenter: rdu3
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
mac0: b4:45:06:fb:8b:3e
mac1: b4:45:06:fb:8b:3f
mac2: 5c:6f:69:81:01:e0
mac3: 5c:6f:69:81:01:e1
network_connections:
# Bridge profile
- name: br0
state: up
type: bridge
mtu: 1500
autoconnect: yes
ip:
address:
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
# Bond profile
- name: bond0
type: bond
interface_name: bond0
mtu: 1500
controller: br0
bond:
mode: 802.3ad
# Port profile for the 1st Ethernet device
- name: bond0-port1
mac: "{{ mac2 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# Port profile for the 2nd Ethernet device
- name: bond0-port2
mac: "{{ mac3 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: ""
date_hw_purchase: ""
hardware: PowerEdge R450
location: RDU3
oob_ip: "{{ bmc.ip_address }}"
serialno_a: G922FZ3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -1,70 +0,0 @@
---
bmc:
ip_address: 10.16.160.79
ping: true
http: true
https: true
br0_ipv4_ip: 10.16.169.48
br0_ipv4_gw: 10.16.169.254
br0_ipv4_nm: 24
datacenter: rdu3
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
mac0: b4:45:06:fb:86:96
mac1: b4:45:06:fb:86:96
mac2: 5c:6f:69:7e:ec:b0
mac3: 5c:6f:69:7e:ec:b1
network_connections:
# Bridge profile
- name: br0
state: up
type: bridge
mtu: 1500
autoconnect: yes
ip:
address:
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
# Bond profile
- name: bond0
type: bond
interface_name: bond0
mtu: 1500
controller: br0
bond:
mode: 802.3ad
# Port profile for the 1st Ethernet device
- name: bond0-port1
mac: "{{ mac2 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# Port profile for the 2nd Ethernet device
- name: bond0-port2
mac: "{{ mac3 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: ""
date_hw_purchase: ""
hardware: PowerEdge R450
location: RDU3
oob_ip: "{{ bmc.ip_address }}"
serialno_a: C922FZ3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -14,8 +14,3 @@ swap_file_path: /swap
swap_file_size_mb: 16000
zabbix_macros:
'CPU.UTIL.CRIT': 100 # frequent CPU spikes, noisy
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_1_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_eu_es_1_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_dev"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_dev"': 300
'COPR.STATS.HOST': copr-be-dev.cloud.fedoraproject.org

View file

@ -14,6 +14,3 @@ swap_file_path: /swap
swap_file_size_mb: 16384
zabbix_macros:
'CPU.UTIL.CRIT': 100 # frequent CPU spikes, noisy
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_1_prod"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_eu_es_1_prod"': 300
'COPR.STARTUP.MAX:"copr_ic_s390x_br_sao_2_prod"': 300

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- datanommer
datacenter: rdu3

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- datanommer
datacenter: rdu3

View file

@ -15,7 +15,7 @@ nft_custom_rules:
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.105 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.106 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.117 tcp dport 5432 counter accept'
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- fas2
- ipsilon

View file

@ -6,7 +6,7 @@
# TODO: lock it down more
nft_custom_rules:
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.0/24 tcp dport 5432 counter accept'
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- fas2
datacenter: rdu3

View file

@ -7,7 +7,7 @@ nft_custom_rules:
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.105 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.10 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- koji
datacenter: rdu3

View file

@ -3,7 +3,7 @@
# Only allow postgresql access from the frontend node.
#
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.167.64 tcp dport 5432 counter accept']
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- koji
datacenter: rdu3

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- postgres
- openqa

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.172.21 --dport 5432 -j ACCEPT']
nft_custom_rules:
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.172.21 tcp dport 5432 counter accept'

View file

@ -3,7 +3,7 @@ ansible_become: yes
ansible_become_user: root
ansible_user: ec2-user
root_auth_users: msuchy
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- coprdb
db_backup_dir: ['/backups']

View file

@ -3,7 +3,7 @@
# We should narrow this down at some point
#
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- anitya
- blockerbugs

View file

@ -3,7 +3,7 @@
# We should narrow this down at some point
#
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- askfedora
- blockerbugs

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- mysql
- fpo-mediawiki

View file

@ -1,5 +1,5 @@
---
# This is a generic list
# This is a generic list, monitored by collectd
databases:
- postgres
datacenter: rdu3

View file

@ -663,7 +663,7 @@ zabbix01.stg.rdu3.fedoraproject.org
# This is a list of hosts that are a little "friendly" with staging.
# They are exempted from the iptables wall between staging and prod.
# For instance, staging needs to send smtp mail data
# For instance, staging needs to send collectd logs to log01 and smtp mail data
# to bastion (both of which are prod boxen).
[staging_friendly]
noc01.rdu3.fedoraproject.org

View file

@ -73,6 +73,16 @@
- /etc/dracut.conf.d/sgdisk.conf
- /etc/dracut.conf.d/xen.conf
# CollectD files:
- /etc/collectd.d/bind.conf
- /etc/collectd.d/fmn.conf
- /etc/collectd.d/memcached.conf
- /etc/collectd.d/network.conf
- /etc/collectd.d/nfs.conf
- /etc/collectd.d/postgres.conf
- /etc/collectd.d/unixsock.conf
- /etc/collectd.d/vfive-upgrade.conf
# Our crond conf files:
- /etc/cron.daily/cleanup-stage-users
- /etc/cron.daily/data-only-backup.sh
@ -255,6 +265,7 @@
- /etc/httpd/conf.d/admin.fedoraproject.org/admin-rewrite.conf
- /etc/httpd/conf.d/admin.fedoraproject.org/apache-status-rewrite.conf
- /etc/httpd/conf.d/admin.fedoraproject.org/awstats.conf
- /etc/httpd/conf.d/admin.fedoraproject.org/collectd.conf
- /etc/httpd/conf.d/admin.fedoraproject.org/community-redirect.conf
- /etc/httpd/conf.d/admin.fedoraproject.org.conf
- /etc/httpd/conf.d/admin.fedoraproject.org/elections-redirectmatch.conf
@ -1596,6 +1607,7 @@
- /etc/systemd/system/anubis.service
- /etc/systemd/system/bodhi-celery.service
- /etc/systemd/system/btrfs-balance.timer.d/schedule.conf
- /etc/systemd/system/collectd.service.d/timeout.conf
- /etc/systemd/system/debuginfod.service.d/override.conf
- /etc/systemd/system/dirsrv@FEDORAPROJECT-ORG.service.d/ipa-env.conf
- /etc/systemd/system/dirsrv@STG-FEDORAPROJECT-ORG.service.d/ipa-env.conf

View file

@ -22,6 +22,7 @@
- zabbix/zabbix_agent
- ipa/client
- sudo
- collectd/base
- { role: nfs/client,
mnt_dir: '/fedora_backups',
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3",

View file

@ -21,6 +21,7 @@
- ipa/client
- hosts
- sudo
- collectd/base
- packager_alias
- opendkim
- fasjson

View file

@ -22,6 +22,7 @@
- ipa/client
- ansible-server
- sudo
- collectd/base
- role: git/hooks
- rsyncd
- apache

View file

@ -36,6 +36,7 @@
roles:
- base
- zabbix/zabbix_agent
- collectd/base
- hosts
- ipa/client
- sudo

View file

@ -24,6 +24,7 @@
- rkhunter
- hosts
- ipa/client
- collectd/base
- sudo
handlers:

View file

@ -67,6 +67,8 @@
# - zabbix/zabbix_agent
- hosts
- postgresql_server
# - collectd/base
# - collectd/postgres # This requires a 'databases' var to be set in host_vars
- sudo
handlers:

View file

@ -22,6 +22,7 @@
- zabbix/zabbix_agent
- hosts
- ipa/client
- collectd/base
- role: nfs/client
mount_stg: true

View file

@ -23,6 +23,8 @@
when: datacenter != 'rdu3' }
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- collectd/bind
- rsyncd
- sudo
- dns

View file

@ -36,6 +36,7 @@
- { role: openvpn/client, when: vpn == True }
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- apache
- download
- role: anubis-el

View file

@ -18,6 +18,7 @@
- rkhunter
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- sudo
- flatpak-cache

View file

@ -17,6 +17,7 @@
- base
- rkhunter
- zabbix/zabbix_agent
- collectd/base
- hosts
- {role: openvpn/client,
when: env != "staging"}

View file

@ -43,6 +43,7 @@
- hosts
- rsyncd
- sudo
- collectd/base
- {role: openvpn/client,
when: env != "staging"}
- mod_wsgi

View file

@ -21,6 +21,7 @@
- hosts
- rsyncd
- sudo
- collectd/base
- {role: openvpn/client,
when: env != "staging"}
- mod_wsgi

View file

@ -30,6 +30,7 @@
- zabbix/zabbix_agent
- hosts
- ipa/client
- collectd/base
- apache
- mod_wsgi
- role: keytab/service

View file

@ -23,6 +23,7 @@
- zabbix/zabbix_agent
- ipa/client
- sudo
- collectd/base
- apache
- rsyncd
- role: nfs/client

View file

@ -21,6 +21,8 @@
- openvpn/client
- ipa/client
- apache
- collectd/base
- collectd/server
- sudo
- web-data-analysis
- role: keytab/service
@ -100,3 +102,6 @@
- bc
- gnuplot
- mod_auth_gssapi
- name: Set domain_can_mmap_files so collectd works
seboolean: name=domain_can_mmap_files state=yes persistent=yes

View file

@ -25,6 +25,7 @@
- {role: openvpn/client,
when: env != "staging"}
- ipa/client
- collectd/base
- sudo
- spamassassin
- mod_wsgi

View file

@ -29,6 +29,7 @@
- zabbix/zabbix_agent
- hosts
- mariadb_server
- collectd/base
- sudo
pre_tasks:

View file

@ -19,6 +19,8 @@
- zabbix/zabbix_agent
- hosts
- ipa/client
- collectd/base
- collectd/memcached
- sudo
- memcached

View file

@ -19,6 +19,7 @@
- rkhunter
- hosts
- ipa/client
- collectd/base
- sudo
- openvpn/client
- zabbix/zabbix_agent

View file

@ -24,6 +24,7 @@
- { role: openvpn/client, when: env != "staging" }
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- { role: rsyncd, when: datacenter == 'rdu3' }
- sudo
- apache

View file

@ -23,6 +23,7 @@
- { role: openvpn/client,
when: env != "staging" }
- ipa/client
- collectd/base
- rsyncd
- sudo
- role: nfs/client

View file

@ -18,6 +18,7 @@
- { role: rkhunter, tags: ['rkhunter'] }
- { role: hosts, tags: ['hosts']}
- ipa/client
- { role: collectd/base, tags: ['collectd_base'] }
- { role: sudo, tags: ['sudo'] }
- apache

View file

@ -19,6 +19,7 @@
- { role: hosts, tags: ['hosts']}
- zabbix/zabbix_agent
- { role: ipa/client, tags: ['ipa_client']}
- { role: collectd/base, tags: ['collectd_base'] }
- { role: sudo, tags: ['sudo'] }
- { role: openqa/worker, tags: ['openqa_worker'] }
- { role: linux-system-roles.nbde_client, tags: ['nbde_client'], when: openqa_nbde|bool }

View file

@ -23,6 +23,7 @@
- { role: hosts, tags: ['hosts']}
- zabbix/zabbix_agent
- ipa/client
- { role: collectd/base, tags: ['collectd_base'] }
- { role: sudo, tags: ['sudo'] }
- apache

View file

@ -22,9 +22,70 @@
- ipa/client
- rsyncd
- sudo
- openshift/control
pre_tasks:
tasks:
- name: Install rdiff-backup for backups
ansible.builtin.package:
name: rdiff-backup
state: present
- name: Install unzip
ansible.builtin.package:
name: unzip
state: present
- name: Install python3-kubernetes
ansible.builtin.package:
name: python3-kubernetes
state: present
- name: Install tar
ansible.builtin.package:
name: tar
state: present
- name: Install tar
ansible.builtin.package:
name: butane
state: present
- name: Create the directories to hold the templates
ansible.builtin.file:
path: "/etc/openshift_apps"
state: directory
owner: root
group: root
mode: "0770"
- name: Install helm if not exists
unarchive:
src: https://get.helm.sh/helm-v3.17.0-linux-amd64.tar.gz
dest: /usr/local/bin
extra_opts: "--strip-components=1"
owner: root
group: root
mode: 0755
remote_src: true
args:
creates: /usr/local/bin/helm
- name: Copy oc rpm
ansible.builtin.copy:
src: /srv/web/infra/bigfiles/openshiftboot/oc-client/oc-client.rpm
dest: /root/oc-client.rpm
- name: Make sure oc-client is installed
dnf:
name: /root/oc-client.rpm
state: installed
- name: Copy the jobs-summary script
ansible.builtin.copy:
src: "{{ files }}/scripts/jobs-summary"
dest: /usr/local/bin/jobs-summary
mode: "0755"
- import_tasks: "{{ tasks_path }}/yumrepos.yml"
handlers:

View file

@ -21,6 +21,7 @@
- openvpn/client
- ipa/client
- sudo
- collectd/base
pre_tasks:
- import_tasks: "{{ tasks_path }}/yumrepos.yml"

View file

@ -21,6 +21,7 @@
- openvpn/client
- ipa/client
- sudo
- collectd/base
- postgresql_server
pre_tasks:

View file

@ -61,6 +61,7 @@
roles:
- base
- collectd/base
- role: openvpn/client
when: env != "staging"
- ipa/client

View file

@ -19,6 +19,7 @@
- rkhunter
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- sudo
- apache

View file

@ -49,6 +49,8 @@
- zabbix/zabbix_agent
- hosts
- postgresql_server
- collectd/base
- collectd/postgres # This requires a 'databases' var to be set in host_vars
- sudo
# TODO: add iscsi task

View file

@ -26,6 +26,7 @@
- ipa/client
- rkhunter
- zabbix/zabbix_agent
- collectd/base
- sudo
- rsyncd
- {role: mirrormanager/mirrorlist_proxy,

View file

@ -22,6 +22,10 @@
- zabbix/zabbix_agent
- hosts
- ipa/client
- collectd/base
# RabbitMQ statistics are cluster-wide, only collect them on one member
- role: collectd/rabbitmq
when: inventory_hostname.startswith('rabbitmq03')
- rsyncd
- sudo
- rabbitmq_cluster

View file

@ -36,6 +36,7 @@
- ipa/client
- rkhunter
- zabbix/zabbix_agent
- collectd/base
- sudo
- role: keytab/service
service: compose

View file

@ -19,6 +19,7 @@
- hosts
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- download
- rsyncd
- sudo

View file

@ -23,6 +23,7 @@
when: env != "staging" }
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- sudo
pre_tasks:

View file

@ -23,6 +23,7 @@
when: env != "staging" }
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- sudo
pre_tasks:

View file

@ -27,6 +27,7 @@
when: env != "staging"
}
- ipa/client
- collectd/base
- mod_wsgi
- geoip
- geoip-city-wsgi/app

View file

@ -20,6 +20,7 @@
- openvpn/client
- zabbix/zabbix_agent
- ipa/client
- collectd/base
- rsyncd
- sudo
- torrent

View file

@ -33,6 +33,7 @@
service: zodbot,
when: env == "production"
}
- collectd/base
- apache
- supybot
- sudo

View file

@ -44,6 +44,7 @@
- hosts
- {role: openvpn/client, when: vpn|bool}
- ipa/client
- {role: collectd/base, when: ansible_distribution_major_version|int != 10}
- sudo
- virthost
- {role: linux-system-roles.nbde_client, tags: ['nbde_client'], when: (nbde|bool) }

View file

@ -29,6 +29,7 @@
- { role: openvpn/client,
when: env != "staging" }
- ipa/client
- collectd/base
- apache
# Set up for fedora-messaging
- role: rabbit/user

View file

@ -18,6 +18,7 @@
- rkhunter
- hosts
- ipa/client
- collectd/base
- sudo
- { role: zabbix/zabbix_server, tags: zabbix_server }
- { role: zabbix/zabbix_agent, tags: zabbix_agent }

View file

@ -19,6 +19,7 @@
- base
- rkhunter
- hosts
- collectd/base
- sudo
- dhcp_server
- tftp_server

View file

@ -552,6 +552,15 @@
localpath: /freemedia
proxyurl: http://localhost:10011
- role: httpd/reverseproxy
website: admin.fedoraproject.org
destname: collectd
localpath: /collectd
remotepath: /collectd
# Talk directly to the app server, not haproxy
proxyurl: http://log01
tags: data-analysis
- role: httpd/reverseproxy
website: data-analysis.fedoraproject.org
destname: data-analysis

View file

@ -27,6 +27,7 @@
- zabbix/zabbix_agent
- hosts
- ipa/client
- collectd/base
- sudo
- role: nfs/client
mnt_dir: '/mnt/fedora_koji'

View file

@ -33,6 +33,7 @@
roles:
- base
- rkhunter
- collectd/base
- sudo
pre_tasks:

View file

@ -0,0 +1,20 @@
---
- name: Make the app be real
hosts: localhost
connection: local
user: root
gather_facts: false
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
module_defaults:
group/awx.awx.controller:
controller_host: awx.fedoraproject.org
controller_username: "{{ awx_admin_username }}"
controller_password: "{{ awx_admin_password }}"
roles:
- role: awx/controller

View file

@ -115,6 +115,12 @@
object_app: bodhi
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: bodhi
start_build_buildname: bodhi-base
tags:
- never
- build
- role: openshift/object
object_app: bodhi
object_template_fullpath: "{{roles_path}}/bodhi2/base/templates/configmap.yml.j2"
@ -152,14 +158,24 @@
- role: openshift/imagestream
imagestream_app: bodhi
imagestream_imagename: bodhi-critpathcron
- role: openshift/app-actions
app_actions_app: bodhi
app_actions_builds:
- bodhi-base
app_actions_deployments:
- bodhi-web
- bodhi-consumer
- bodhi-celery
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-web
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-consumer
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: bodhi
rollout_dname: bodhi-celery
tags:
- never
- rollout
post_tasks:
- name: Scale up pods

View file

@ -83,10 +83,3 @@
object_app: bugzilla2fedmsg
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: bugzilla2fedmsg
app_actions_builds:
- bugzilla2fedmsg-build
app_actions_deployments:
- bugzilla2fedmsg

View file

@ -169,14 +169,15 @@
object_template: container-secrets.yml.j2
object_objectname: container-secrets.yml
- role: openshift/start-build
start_build_app: cloud-image-uploader
start_build_buildname: cloud-image-uploader-build
start_build_objectname: cloud-image-uploader-build
tags:
- never
- build
- role: openshift/object
object_app: cloud-image-uploader
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: cloud-image-uploader
app_actions_builds:
- cloud-image-uploader-build
app_actions_deployments:
- cloud-image-uploader

View file

@ -36,17 +36,25 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: compose-tracker
start_build_buildname: compose-tracker-build
start_build_objectname: compose-tracker-build
tags:
- never
- build
- role: openshift/object
object_app: compose-tracker
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: compose-tracker
app_actions_builds:
- compose-tracker-build
app_actions_deployments:
- compose-tracker
- role: openshift/rollout
rollout_app: compose-tracker
rollout_dname: compose-tracker
tags:
- never
- rollout
###############################################
# actions to delete the project from OpenShift

View file

@ -42,6 +42,11 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: coreos-cincinnati
start_build_buildname: coreos-cincinnati-build
start_build_objectname: coreos-cincinnati-build
- role: openshift/object
object_app: coreos-cincinnati
object_template: config-stub.yml.j2
@ -52,6 +57,11 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/rollout
rollout_app: coreos-cincinnati
rollout_dname: coreos-cincinnati
tags: [never, rollout]
- role: openshift/object
object_app: coreos-cincinnati
object_template: service.yml.j2
@ -90,13 +100,6 @@
route_serviceport: coreos-cincinnati-raw-updates-status
route_servicename: coreos-cincinnati
- role: openshift/app-actions
app_actions_app: coreos-cincinnati
app_actions_builds:
- coreos-cincinnati-build
app_actions_deployments:
- coreos-cincinnati
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -50,12 +50,13 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/app-actions
app_actions_app: coreos-koji-tagger
app_actions_builds:
- coreos-koji-tagger-build
app_actions_deployments:
- coreos-koji-tagger
- role: openshift/start-build
start_build_app: coreos-koji-tagger
start_build_buildname: coreos-koji-tagger-build
start_build_objectname: coreos-koji-tagger-build
tags:
- never
- build
- role: openshift/object
object_app: coreos-koji-tagger

View file

@ -99,9 +99,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: datagrepper
app_actions_builds:
- datagrepper
app_actions_deployments:
- datagrepper
# - role: openshift/start-build
# start_build_app: datagrepper
# start_build_buildname: datagrepper
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: datagrepper
# rollout_dname: datagrepper
# tags:
# - never
# - rollout

View file

@ -87,10 +87,3 @@
object_app: datanommer
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: datanommer
app_actions_builds:
- datanommer
app_actions_deployments:
- datanommer

View file

@ -71,9 +71,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: discourse2fedmsg
app_actions_builds:
- discourse2fedmsg
app_actions_deployments:
- discourse2fedmsg
# - role: openshift/start-build
# start_build_app: discourse2fedmsg
# start_build_buildname: discourse2fedmsg
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: discourse2fedmsg
# rollout_dname: discourse2fedmsg
# tags:
# - never
# - rollout

View file

@ -1,6 +1,6 @@
---
- name: Make the app be real
hosts: os_control_stg # :os_control
hosts: os_control_stg #:os_control
user: root
gather_facts: false

View file

@ -37,10 +37,12 @@
object_objectname: buildconfig.yml
object_template: buildconfig.yml.j2
- role: openshift/app-actions
app_actions_app: docsbuilding
app_actions_builds:
- builder-build
- role: openshift/start-build
start_build_app: docsbuilding
start_build_buildname: builder-build
tags:
- never
- build
- role: openshift/object
object_app: docsbuilding

View file

@ -80,18 +80,6 @@
tags:
- deploy-cronjob
- name: App actions
ansible.builtin.include_role:
name: openshift/app-actions
vars:
app_actions_app: docstranslation
app_actions_builds:
- docstranslation-build
tags:
- never
- build
- rebuild
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -26,6 +26,14 @@
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/start-build
start_build_app: drm-panic-frontend
start_build_buildname: drm-panic-frontend-build
start_build_objectname: drm-panic-frontend-build
tags:
- never
- build
- role: openshift/object
object_app: drm-panic-frontend
object_file: service.yml
@ -43,9 +51,9 @@
object_file: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: drm-panic-frontend
app_actions_builds:
- drm-panic-frontend-build
app_actions_deployments:
- drm-panic-frontend
- role: openshift/rollout
rollout_app: drm-panic-frontend
rollout_dcname: drm-panic-frontend
tags:
- never
- rollout

View file

@ -95,6 +95,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: elections
start_build_buildname: elections-build
start_build_objectname: elections-build
tags:
- never
- build
- role: openshift/object
object_app: elections
object_file: service.yml
@ -113,10 +121,3 @@
object_app: elections
object_file: deployment.yml
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: elections
app_actions_builds:
- elections-build
app_actions_deployments:
- elections

View file

@ -10,8 +10,6 @@
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
- /srv/web/infra/ansible/roles/openshift-apps/elnbuildsync/vars/main.yml
- /srv/web/infra/ansible/roles/openshift-apps/elnbuildsync/vars/{{ env }}.yml
vars:
OCP_BUILD_WAIT: true
tasks:
- name: ELNBuildSync DB user
@ -135,6 +133,16 @@
tags:
- build
- role: openshift/start-build
start_build_app: elnbuildsync
start_build_buildname: elnbuildsync-build
start_build_objectname: elnbuildsync-build
vars:
OCP_BUILD_WAIT: true
tags:
- never
- build
- role: openshift/route
route_app: elnbuildsync
route_name: elnbuildsync
@ -149,13 +157,7 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
vars:
object_always_apply: "{{ 'true' if 'build' in ansible_run_tags else 'false' }}"
object_always_apply: "{{ 'true' if ('build' in ansible_run_tags or 'redeploy' in ansible_run_tags) else 'false' }}"
tags:
- build
- role: openshift/app-actions
app_actions_app: elnbuildsync
app_actions_builds:
- elnbuildsync-build
app_actions_deployments:
- elnbuildsync
- redeploy

View file

@ -110,9 +110,16 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: fasjson
app_actions_builds:
- fasjson
app_actions_deployments:
- fasjson
# - role: openshift/start-build
# start_build_app: fasjson
# start_build_buildname: fasjson
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: noggin
# rollout_dname: noggin
# tags:
# - never
# - rollout

View file

@ -58,6 +58,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: fedocal
start_build_buildname: fedocal-build
start_build_objectname: fedocal-build
tags:
- never
- build
- role: openshift/object
object_app: fedocal
object_file: service.yml
@ -80,10 +88,3 @@
object_file: cron.yml
object_objectname: cron.yml
when: env != 'staging'
- role: openshift/app-actions
app_actions_app: fedocal
app_actions_builds:
- fedocal-build
app_actions_deployments:
- fedocal

View file

@ -45,13 +45,6 @@
object_template: pvc.yml.j2
object_objectname: pvc.yml
- role: openshift/app-actions
app_actions_app: fedora-ostree-pruner
app_actions_builds:
- fedora-ostree-pruner-build
app_actions_deployments:
- fedora-ostree-pruner
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -38,6 +38,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: fedora-packages-static
start_build_buildname: fedora-packages-static-build
start_build_objectname: fedora-packages-static-build
tags:
- never
- build
- role: openshift/object
object_app: fedora-packages-static
object_file: service.yml
@ -55,14 +63,6 @@
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: fedora-packages-static
app_actions_builds:
- fedora-packages-static-build
app_actions_deployments:
- fedora-packages-static
- solr
###############################################
# actions to delete the project from OpenShift
###############################################

View file

@ -45,6 +45,14 @@
object_template: configmap.yml.j2
object_objectname: configmap.yml
- role: openshift/start-build
start_build_app: flatpak-indexer
# This will trigger the main build via a imageChange trigger
start_build_buildname: flatpak-indexer-tardiff-build
tags:
- never
- build
- role: openshift/object
object_app: flatpak-indexer
object_file: service.yml
@ -54,13 +62,3 @@
object_app: flatpak-indexer
object_template: deployment.yml.j2
object_objectname: deployment.yml
- role: openshift/app-actions
app_actions_app: flatpak-indexer
app_actions_builds:
- flatpak-indexer-tardiff-build
app_actions_deployments:
- flatpak-indexer
- flatpak-quay-indexer
- flatpak-indexer-differ
- redis

View file

@ -234,25 +234,3 @@
object_app: fmn
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: fmn
app_actions_builds:
- python-312-collectd
app_actions_deployments:
- frontend
- api
- fmn
- sender-email
- sender-irc
- sender-matrix
- redis
- collectd
# this build and deployment are stg only, hence separated
- role: openshift/app-actions
app_actions_app: fmn
app_actions_builds:
- sendria
app_actions_deployments:
- sendria
when: env == "staging"

View file

@ -86,11 +86,19 @@
tags:
- apply-deploymentconfig
- role: openshift/app-actions
app_actions_app: greenwave
app_actions_deployments:
- greenwave-web
- greenwave-fedmsg-consumers
- role: openshift/rollout
rollout_app: greenwave
rollout_dname: greenwave-web
tags:
- never
- rollout
- role: openshift/rollout
rollout_app: greenwave
rollout_dname: greenwave-fedmsg-consumers
tags:
- never
- rollout
- name: Change the route haproxy default timeout
hosts: os_control[0]:os_control_stg[0]

View file

@ -1,4 +1,3 @@
---
#
# Jira Sync
# https://github.com/Zlopez/jira_sync
@ -84,9 +83,16 @@
object_template: cron.yml.j2
object_objectname: cron.yml
- role: openshift/app-actions
app_actions_app: jira-sync
app_actions_builds:
- app
app_actions_deployments:
- app
- role: openshift/start-build
start_build_app: jira-sync
start_build_buildname: app
tags:
- never
- build
- role: openshift/rollout
rollout_app: jira-sync
rollout_dname: app
tags:
- never
- rollout

Some files were not shown because too many files have changed in this diff Show more