1
0
Fork 0
forked from infra/ansible
Commit graph

45,323 commits

Author SHA1 Message Date
James Antill
0633cda299 updates+uptimes: Minor UI tweaks, less hacky sort.
Signed-off-by: James Antill <james@and.org>
2026-02-10 17:21:18 -05:00
James Antill
a0cab4f3cc mirror_from_forge: Add mirror_from_forge role, based on mirror_from_pagure.
Signed-off-by: James Antill <james@and.org>
2026-02-10 17:19:28 -05:00
8b94d9a7ce anubis-el: try and match without quotes
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 14:13:05 -08:00
3a42bab039 Reenable Centos10 sync for EPEL 10.2 mass branching
Signed-off-by: Diego Herrera <dherrera@redhat.com>
2026-02-10 18:13:35 -03:00
c62e1573f7 storinator01: use same vpn ip as it did in rdu-cc
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 11:11:39 -08:00
599656a420 storinator01: add hosts file for rdu3 iso
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 10:29:28 -08:00
7e6d17307a storinator01: update mac addresses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 10:22:38 -08:00
53a6ce24f3 anubis: switch this to just allowing CloudFront
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 08:26:42 -08:00
e401686427 anubis: switch this to just allowing all repodata
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 07:58:07 -08:00
145e6794fb anubis: allow .zck files universally on el as well
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 07:54:59 -08:00
5615d1b036 anubis: allow .zck files universally
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-10 07:52:53 -08:00
90ed56ae7b
bugzilla2fedmsg: rebase on RHEL9 + Python 3.11
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-02-10 15:29:44 +01:00
d10f2fe3bc
bugzilla2fedmsg: update the staging deployment config for the Kafka port
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-02-10 14:58:12 +01:00
59debdda2c Update playbooks/openshift-apps/fedora-coreos-pipeline.yml 2026-02-10 13:42:04 +00:00
Jiri Podivin
11d11c214e Skipping ansible-lint rules, in cases when it makes sense
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-02-10 10:23:23 +01:00
Jiri Podivin
28d40d6e0b Resolving style issues of the logdetective role
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-02-10 10:23:23 +01:00
Jiri Podivin
34eaee695e Opening 8090 port for communication with packit interface server
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-02-10 10:23:23 +01:00
24ea94601d vmhost-x86-copr01/02/03: stop removing nftables
These hosts are rhel10 now and removing nftables takes out the entire
libvirt stack as it doesn't support iptables anymore.

This results in base removing libvirt and the hypervisor role
re-installing it every playbook run. It also means the network doesn't
work on guests at all.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-09 15:08:28 -08:00
faff0d9e0f vmhost-p09-copr01: not encrypted yet, needs reinstall
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-09 13:34:35 -08:00
09859d9acc Update source branch for Quality apps in staging OpenShift
Signed-off-by: Jaroslav Groman <jgroman@redhat.com>
2026-02-09 20:55:08 +00:00
991273d7f1 copr_hypervisors: enable nbde on all of them
The x86 ones are now in rdu3 and reinstalled with rhel10.
All the power9 ones are in rdu3 and reinstalled.

So, we should just enable nbde on all of them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-09 11:30:46 -08:00
080db33424 turn of new projects UI for production
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-09 12:37:51 +10:00
30c0defe44 copr-backend: more verbose machine termination 2026-02-07 21:08:10 +01:00
a9acbd4c0e bodhi/openshift: restore dropped cd to the right directory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-06 10:17:14 -08:00
dc3fda7f45 bodhi/openshift: fix missing /
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-06 09:59:07 -08:00
9503d8df11 bodhi / openshift: adjust critpath to pull from forge instead of pagure.io
releng moved things from pagure.io/releng to
forge.fedoraproject.org/releng/tooling

Adjust this cron to do likewise.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-06 09:54:04 -08:00
1324b1e72a
Add more CPU to proxy11 to help with httpd alerts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-02-06 14:03:41 +00:00
Patrik Polakovič
46fbcc5567 Branch Fedora 44 from Rawhide
Signed-off-by: Patrik Polakovič <patrik@alphamail.org>
2026-02-05 19:10:58 +00:00
0bb245c653
Zabbix | Rabbit: Fix hardcoded STG entry in zabbix agent drop-in
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-02-05 11:12:42 +00:00
6092f3bdb2 set swappiness to 10 for copr machines 2026-02-04 20:45:38 +01:00
1d6aa6f15a [webhook2fm] fix typo from 8a61479d64
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:18:10 +10:00
8a61479d64 [webhook2fm] update staging rediurect URIs
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 11:06:52 +10:00
a36c5a7a16 [forge] add staging ips to webhook ALLOWED_HOST_LIST settings
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 10:21:35 +10:00
a425f8715f [forge] set default merge style to rebase
fixes: forge/forge#353

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 09:24:20 +10:00
6aab5d6da0 [forge] update ALLOWED_HOST_LIST for webhooks to include internal ips
fixes: forge/forge#368

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-04 09:20:26 +10:00
8e09c0498e copr-be: keep one machine running for Kevin's debugging 2026-02-02 16:55:54 +01:00
502f7c6273
openshift-apps/websites: requesting access for glb
Signed-off-by: Gregory Bartholomew <gregory.lee.bartholomew@gmail.com>
2026-02-01 11:19:51 -06:00
39563d49fe noc-cc01 is no more
Remove it from main and remove it's playbook.
It was already removed from anisible.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-31 16:40:52 -08:00
29a00a8986 bastion: fix conditional for ssh tcpforwarding
I copy pasted this and left a 'not' in there that made this backwards.
Fix the conditional.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-31 08:20:16 -08:00
423f7c0c52 pagure / dist-git: drop hotfix that was pulled into rpm
We pulled this fix into the epel8 rpm we are using, so we shouldn't try
and apply it here also.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-31 08:18:00 -08:00
46ceb38264 vmhost-x86-copr02: update mac addresses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 20:26:15 -08:00
c86adb0115 vmhost-x86-copr01: update mac addesses
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 13:59:30 -08:00
ab01301f5c inventory: update to reflect machines that moved from f42 to f43
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 11:36:47 -08:00
c0f13a07e1 generate-updates-per-host: try explicitly disabling become
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 11:18:19 -08:00
278d9427f8 bastion: allow ssh tcp forwarding on bastion hosts
We need this in order to be able to use them as jumphosts with ssh.
Without it, there's no easy way to get to any internal machines.
Just enable it here and leave the default off.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 11:16:01 -08:00
3d68919779 updates/uptimes: use user root
Some hosts don't seem to be setup right for sudo/become (copr mostly).
Just use root like our normal ansible stuff does.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 11:01:28 -08:00
0b261fc507 inventory: re-enable proxy05
We still aren't able to get to mgmt on this host, but it's up and
operating normally, so we might as well use it for now.

If it goes down we can remove it again.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 10:37:59 -08:00
5091fd4373 ocp-rdu3: retire this host/proxy/cert now that we are moved
There's no need to keep ocp-rdu3 around anymore, we only used
it when we were moving datacenters last year.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 10:35:10 -08:00
1bf508dc18 Revert "[robosignatory] Increase the prefetch value"
This reverts commit 4fdd0c9fca.

This causes robosignatory's priorities to not work.
We want to handle some requests before others, but if we prefetch 25 of
them, there could any mix of requests and we wouldn't process the most
important ones first.
2026-01-30 09:39:58 -08:00
2d28e5de7b hosts: set specific gateway for a few iso hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 09:21:17 -08:00