Migrate ELNBuildSync to Fedora Infrastructure OpenShift #13139
Labels
No labels
announcement
anubis
authentication
aws
backlog
blocked
bodhi
ci
cloud
communishift
copr
database
day-to-day
dc-move
deprecated
dev
discourse
dns
downloads
easyfix
epel
firmitas
forgejo_migration
Gain
High
Gain
Low
Gain
Medium
gitlab
greenwave
hardware
help wanted
high-trouble
koji
koschei
lists
low-trouble
medium-trouble
mirrorlists
monitoring
Needs investigation
odcs
OpenShift
ops
outage
packager_workflow_blocker
pagure
permissions
Priority
Needs Review
Priority
Next Meeting
Priority
🔥 URGENT 🔥
Priority
Waiting on Assignee
Priority
Waiting on External
Priority
Waiting on Reporter
rabbitmq
release-monitoring
releng
request-for-resources
s390x
security
SMTP
sprint-0
sprint-1
src.fp.o
staging
unfreeze
waiverdb
websites-general
wiki
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
infra/tickets#13139
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description of request
The Fedora ELN team is currently maintaining the ELNBuildSync (aka EBS) service inside Red Hat using an OpenShift cluster meant for internal CentOS Stream usage. We are currently in the process of adding proper OIDC support to it, at which point we would like to move it to public hosting where it will be available to the general public.
What we're looking for is:
The people responsible for maintenance and upkeep will be Stephen Gallagher (@sgallagh) and Yaakov Selkowitz (@yselkowitz) initially. Access to the restricted portions of the application (such as the build submission endpoint) will be restricted to members of the
elngroup in FAS.ELNBuildSync has landed support for authentication via OpenID Connect.
Can we get an estimate on when (and how) we might be able to get access to Fedora's OpenShift, please?
Please see: https://docs.fedoraproject.org/en-US/infra/developer_guide/openshift/#_openshift
Our applications are all deployed via ansible.
You can look in our ansible repo under roles/openshift-apps/ and playbooks/openshift-apps to see how this is setup. Basically your config is under roles and the playbook deploys them. If you want to make a initial pr that just deploys to staging we can try things out there. Please let us know if / when you have questions...
@kevin I can try, but I still need at least the OIDC and psql connection information, I think?
Yeah. We can get you those when you are ready.
We have a oidc request template here and for database we have a general db01/db01.stg instance we can add a db for you on.
infra/ansible#3374 is now out for review.
Going to close this one, as it's working in both stg/prod. ... they'll be more updates, and maybe more tickets, but still nice to close tickets before the end of time ;)
Agreed, the migration is complete. Further work will be separate. Thanks again for all the help!