Deploy Siguldry to the staging environment #13199

Open
opened 2026-03-13 14:40:22 +00:00 by jcline · 7 comments

Description of request

I anticipate that the server parts of the new signing service will be ready for a staging deployment starting the week of the 23th. There is some packaging work to do which I believe I'll be able to take care of next week.

The requirements are similar to Sigul in that there's an isolated server host, a bridge host, and then clients including one that runs robosignatory.

The server and bridge should be RHEL 10. I'll work on Ansible roles, but will definitely need some detailed review/hand-holding for them. The client should be Fedora. To properly test the client with rpm signing, it'll need to have a version of rpm that includes https://github.com/rpm-software-management/rpm/pull/4125 so we'll need to consider how best to do that.

### Description of request I anticipate that the server parts of the new signing service will be ready for a staging deployment starting the week of the 23th. There is some packaging work to do which I believe I'll be able to take care of next week. The requirements are similar to Sigul in that there's an isolated server host, a bridge host, and then clients including one that runs robosignatory. The server and bridge should be RHEL 10. I'll work on Ansible roles, but will definitely need some detailed review/hand-holding for them. The client should be Fedora. To properly test the client with rpm signing, it'll need to have a version of rpm that includes https://github.com/rpm-software-management/rpm/pull/4125 so we'll need to consider how best to do that.
kevin self-assigned this 2026-03-13 19:14:07 +00:00
Owner

I'll help get this rolled out in the next sprint...

I'll help get this rolled out in the next sprint...
Owner

Or perhaps the one after. ;)

Or perhaps the one after. ;)
Author

Just to update here, I'm working on getting builds for EPEL 10.

We need https://bugzilla.redhat.com/show_bug.cgi?id=2455556 done, and there's also rust-cryptoki and (for tests/staging environment HSM) kryoptic. I've asked Jakub and Simo about those.

I've also started on some ansible for it, but it's very much not done and there's a lot of copy/pasting that maybe we don't need.

Just to update here, I'm working on getting builds for EPEL 10. We need https://bugzilla.redhat.com/show_bug.cgi?id=2455556 done, and there's also [rust-cryptoki](https://src.fedoraproject.org/rpms/rust-cryptoki) and (for tests/staging environment HSM) [kryoptic](https://src.fedoraproject.org/rpms/kryoptic/). I've asked Jakub and Simo about those. I've also started on some [ansible](https://forge.fedoraproject.org/infra/ansible/compare/main...jcline/ansible:siguldry) for it, but it's very much not done and there's a lot of copy/pasting that maybe we don't need.
Author
There's now a build for EPEL 10: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-04073d0191
Author

Okay, one last update. I subsequently realized there's a lot of EPEL 10 branches and the above is only for 10.3.

I've rebuilt it all for 10.2, but doing it for 10.1 is a bit more of a challenge because there's an old version of bindgen in epel10.1. I know EL 10.2 is "soon" so it possibly won't matter when we get to it, but we start on this before 10.2 is available, we can probably also just use the 10.2 RPMs and I suspect they'll work, unless there's some big glibc breaking changes that happened.

I'm also working on admin documentation - source is here - which might be helpful when looking over the horrible ansible I'm about to write. I'm filling it in as I go so there's lots of gaps, but definitely file issues for any sections of the docs that don't make sense, need expanding, etc.

Okay, one last update. I subsequently realized there's a lot of EPEL 10 branches and the above is only for 10.3. I've [rebuilt it all for 10.2](https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-868d76566b), but doing it for 10.1 is a bit more of a challenge because there's an old version of bindgen in epel10.1. I know EL 10.2 is "soon" so it possibly won't matter when we get to it, but we start on this before 10.2 is available, we can probably also just use the 10.2 RPMs and I suspect they'll work, unless there's some big glibc breaking changes that happened. I'm also working on [admin documentation](https://fedora-infra.github.io/siguldry/) - source is [here](https://github.com/fedora-infra/siguldry/tree/main/docs/src/) - which might be helpful when looking over the horrible ansible I'm about to write. I'm filling it in as I go so there's lots of gaps, but definitely file issues for any sections of the docs that don't make sense, need expanding, etc.
Owner

Just FYI, I will be out on pto all next week... but can help with merging/deploying after I get back.

Just FYI, I will be out on pto all next week... but can help with merging/deploying after I get back.
Author

Yup, no worries. Enjoy your vacation and think nothing of signing.

Yup, no worries. Enjoy your vacation and think nothing of signing.
Sign in to join this conversation.
No milestone
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13199
No description provided.