1
0
Fork 0
forked from infra/ansible

Compare commits

...
Sign in to create a new pull request.

1,228 commits

Author SHA1 Message Date
d6cca9eb11 yumrepos: fix rhel10-infra-stg repo also
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-09 15:09:04 -07:00
a326adbb30 epel10-infra: add new signing key
The old key we were using for old releases had some sha1 in it
somewhere, so rhel10 rejects it (great!). So, lets use a newly generated
key that is acceptable to rhel10 and much nicer.

This adds the public key file, the repos that use that file, the rhel10
post kickstart that sets up the repo, robosignatory to sign epel10-infra
stuff with this new key and finally on rhel10 hosts put the new repo in
place.

Note that this only changes the rhel10 setup, all rhel8/9 machines are
still using the old key. We may want to move them over, or just not care
as we retire all of them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-09 14:52:33 -07:00
8533d32360
ELNBuildSync: Upgrade to 1.3.3 in prod
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-09 16:17:20 -04:00
cc1925ec64 add app-actions to elnbuildsync (#3506)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
Reviewed-on: infra/ansible#3506
2026-07-09 19:51:44 +00:00
7b15ebf44a migrate openshift-apps to use openshift/app-actions (#3459)
Reviewed-on: infra/ansible#3459
2026-07-09 19:09:25 +00:00
c089fea71e
ELNBuildSync: use port 25 for email
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-09 14:47:43 -04:00
9808527826
ELNBuildSync: Deploy 1.3.3 in staging
Adds better protection for the loglevel endpoints and adds control
endpoints to pause/unpause operation immediately.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-09 13:39:07 -04:00
b922b9dba1
ELNBuildSync: Enable email sending
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-09 12:21:19 -04:00
Jakub Kadlcik
7e50a3dd8a copr: oops, fix pool names dev -> prod 2026-07-09 16:22:41 +02:00
Jakub Kadlcik
0056660a66 copr-be: don't set permissions for state=absent
FAILED! => {"changed": false, "msg": "'permissions' MUST NOT be set
    when 'state=absent'."}

This is a leftover after e86f495e8d.
2026-07-09 15:56:28 +02:00
4164dbee61
Add buildhw-x86-17 to inventory
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 14:55:35 +01:00
Jakub Kadlcik
11c1eaeda1 copr-be: increase allowed startup time for s390x builders to 300s 2026-07-09 15:34:32 +02:00
40890a5962
Copr: add trigger opdata to Zabbix builds template
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 14:22:00 +01:00
50d9008108
Zabbix: Start using nested hostgroups so RBAC works properly
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 13:43:44 +01:00
c52f7a9416
Copr: Add build-checks template to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 13:22:34 +01:00
d4825ebfb2
zabbix: Update openshift proxy configuration
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-09 13:08:53 +01:00
7324f9f5df
zabbix: openshift proxy prod deploy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-09 12:50:34 +01:00
2cc782bab0
Copr: raise build timeouts on s390 pools to 300s
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 12:14:57 +01:00
c51e04de81 Collectd: cleanup collectd everywhere except FMN
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 11:01:41 +00:00
1529684dc1 Revert "bvmhost-x86-05/06: we need iscsi client here"
This reverts commit 65dc5ada06e29fc7e0da47a3880df3d4fa291abc.
2026-07-08 15:28:57 -07:00
65dc5ada06 bvmhost-x86-05/06: we need iscsi client here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-08 15:20:55 -07:00
f77550f85c kickstarts: rhel10: remove vnc, it is no longer supported and rdp has to be specified on the boot line
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-08 13:35:57 -07:00
92b2fddd2c fedora-ostree-pruner: update to Fedora 44
xref: https://github.com/coreos/fedora-coreos-tracker/issues/2055
2026-07-08 15:52:00 +00:00
072c8a765d coreos-koji-tagger: update to Fedora 44
xref: https://github.com/coreos/fedora-coreos-tracker/issues/2055
2026-07-08 15:52:00 +00:00
eb6222610b coreos-cincinnati: update to Fedora 44
xref: https://github.com/coreos/fedora-coreos-tracker/issues/2055
2026-07-08 15:52:00 +00:00
e924d1be9e
Add buildhw-x86-16 to inventory too
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 16:22:02 +01:00
6303816ffa
IAD2: add newly-built buildhw-x86-16
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 16:13:25 +01:00
f14c45f68c
Collectd: missed a deleted role in psql playblook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 14:00:11 +01:00
c5e16e687c [flatpak-indexer] Separate the instances
Try another approach to separate the instances. Create a separate redis
instance for quay.io, that should allow to have completely separate
quay.io resources and registry.fp.o resources.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-08 12:48:20 +00:00
c712b24ee4 Collectd: remove files & packages
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 12:23:07 +00:00
f796c95508
OScontrol: add missing yaml directive to playbook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 13:11:36 +01:00
92fe69c649 OpenShift: Refactor os-control playbook to a role and add monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 12:06:57 +00:00
360f493bc4 pagure: try adjusting lines on patch
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:33:10 -07:00
71585073ad pagure: add a line to the patch so the numbers match up and it applies
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:14:36 -07:00
d0e61275a6 Allow draft builds on ELN side-tags
Fixes: releng/tickets#13374

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-08 00:05:53 +00:00
6882b20e9b pagure: add a line to the patch so the numbers match up and it applies
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:01:28 -07:00
29cce54d62 📧 roles(fasjson): Update logo alias
This commit updates the `logo` alias to make sure trademark permission
requests are correctly routed to the Fedora Design Team Admins as the
most responsible party for the legal stewardship of the Fedora Project
trademark and brand. Therefore, to encourage use of FAS group membership
to better manage access to these hand-coded email aliases, this will now
send all emails to this alias to FAS account users with membership as
sponsors in the `designteam` FAS group.

Once this change is deployed and updated in production, this mail alias
will begin sending mail to @duffy (no change), @ekidney, @jesschitas,
@jflory7, @madelinepeck (no change), and @mleonova.

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-07-07 23:58:12 +00:00
3d93bf17bc releng: run sig_policy script daily instead of weekly
This script should be inexpensive to run, so it'd be nice to run it more
frequently.
2026-07-07 23:54:23 +00:00
99e363981c releng: use new git repo for sig_policy script 2026-07-07 23:54:23 +00:00
66caf2072c add openshift/app-actions to blockerbugs.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:42:56 +00:00
48d0ccef83 add openshift/app-actions to badges.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:42:32 +00:00
200b7a1fd7 add openshift/app-actions to asknot.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:40:46 +00:00
3ddb342c58 application-monitoring: retire app
We never deployed this in the new clusters since we moved and the folks
who were working on it have left. If we want to revive it later, we can
always pull it out of git history.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 15:38:59 -07:00
c7a559d359 feat(pagure.io): added notification banner and git hook that informs about pagure migration
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-07 22:34:20 +00:00
0be5e89880 ci: implement differential yamllint scan
Use vcs-diff-lint (with csdiff backend) to report only new warnings and
errors introduced in a PR.  This prevents older, pre-existing linter
violations from blocking new changes.

Same analyzer version is used for both the base and the head commit to
ensure consistent results.

See: infra/ansible#3143
2026-07-07 22:11:11 +00:00
Jiri Kyjovsky
99f1ff2202 base: disable iptables service when nftables is enabled
When `nftables=True` the base role deploys nftables rules and enables the
nftables service, but never disables the iptables service. On freshly
provisioned hosts the iptables service can be left running from cloud-init,
overwriting nftables rules and silently dropping traffic on ports defined
in `tcp_ports`.

Stop and disable the iptables service explicitly when nftables is the
intended firewall backend.
2026-07-07 22:02:24 +00:00
James Antill
ff663e686f elnbuildsync: Use auth_method=client_secret_basic.
Signed-off-by: James Antill <james@and.org>
2026-07-07 17:12:49 -04:00
dabb77faf4 ELNBuildSync: Set authorized groups
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 19:52:17 +00:00
James Antill
108228f6fd elnbuildsync: Add stg. config. to ipsilon.
Signed-off-by: James Antill <james@and.org>
2026-07-07 15:39:11 -04:00
db494be972
ELNBuildSync: enable redeployment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 14:13:02 -04:00
d880671e4f
ELNBuildSync: fix client_id on staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 14:09:22 -04:00
cd7f6c2efc
ELNBuildSync: Use the right namespace in the service object
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 13:32:04 -04:00
eee169398c
ELNBuildSync: Actually apply the service object
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 13:25:37 -04:00
James Antill
96b1531c50 Revert "elnbuildsync: limit to staging for now"
This reverts commit 7ef75bd174f7c9f5bbd4451999800bde5167b0e4.
2026-07-07 12:55:32 -04:00
0aa20b9436
ELNBuildSync: Prepare prod deployment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 11:07:32 -04:00
Jiri Podivin
6f377c8d87 Check for undefined deploy script
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 12:37:45 +02:00
dee5b453f1
Zabbix: get the tag name/value pair the right way around
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-07 10:45:17 +01:00
ea32c85fa7
Zabbix: 13450 - filter COPR notifications better
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-07 10:40:59 +01:00
83b0f60d6a [postfix] Change the relayhost for sign machines
Today the bastion relayhost didn't work for sign-bridge. So we changed
it to bastion01.rdu3.fedoraproject.org. This worked, so let's reflect
that change in ansible as well.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-07 11:01:08 +02:00
Jiri Podivin
51a458f26b User certbot role for Log Detective
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:45:21 +00:00
Jiri Podivin
f4c497e764 Create a separate role for certbot driven certificate renewal
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:45:21 +00:00
Jiri Podivin
cd29c1260e Attempt shut down Log Detective service before restarting it
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:39:45 +00:00
Lenka Segura
6e63ce738b forge: Add mobility runner to production
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-07 10:26:01 +02:00
Lenka Segura
5686cf77b7 forge: add regular runner for go org
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-07 07:30:40 +00:00
701d7e1867 fix(koji-http-toggle): delete each nft drop rule handle separately
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:45:36 +05:30
f059b1f9d2 fix(koji-http-toggle): resolve proxy IPs via shell so awk pipe works
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:32:36 +05:30
d9e7279830 Add Ansible playbook to toggle Koji HTTP access with nftables
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:14:25 +05:30
f2239cb238 feat(forgejo): oauth-proxy delegates /metrics endpoint to be accesible through token
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-06 15:59:51 +02:00
Lenka Segura
53bede04b2 forge: add staging docs and production relend testing-farm runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-06 15:33:27 +02:00
df71a59847
forgejo: fixed bug with UUID in zabbix template
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-06 13:40:36 +01:00
539176cb09
Collectd: disable collectd pod in FMN app, log01 is no longer listening
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-06 11:55:19 +01:00
Jakub Kadlcik
e5bb2ff606 copr: use the latest version of the expect package
Fix https://github.com/fedora-copr/copr/issues/4361
2026-07-06 10:49:20 +02:00
d13496b221
Collectd: stop the collectd service everywhere, prior to removal
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-03 13:09:19 +01:00
42ac8c53d5
forgejo: wip zabbix template to monitor forge metrics endpoint
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-03 12:03:17 +01:00
9ea0108e6d feat(forgejo): added SA,R,RB,S that zabbix will you to bypass oauth-proxy for accessing metrics endpoint
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-03 12:09:43 +02:00
9b65ab416b
Nagios: remove nagios_server role
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-02 13:39:18 +01:00
bf0cafb5b4
Nagios: fix removal task ordeering
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-02 13:32:09 +01:00
93f5b63c0c Nagios: remove the Nagios server components
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-02 12:29:06 +00:00
Lenka Segura
2dbf6d5978 forge: Add a handful of runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-02 09:08:55 +02:00
83270e8b3b ipa-free-ids: pass monitoring keytab to the cron jobs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 14:53:49 -07:00
b74bb8e1a3 communishift: add pvc handling and allow 3 for happinesspackets
Per infra/tickets#13437

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 14:40:17 -07:00
b6097f96c2 download: drop centos-stream content
Turns out we were syncing this, but never actually had the categories
set in mirrormanager, so we never got any traffic for it.
These download servers are really close to full, so lets just remove
this for now and see if that gives us some space.

We probibly will need to stop carrying archive or something on these
sooner or later though.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 14:13:10 -07:00
d2c6b0c7dd websites: bypass anubis for POST on forge.fedoraproject.org too
We have been seeing some 502's on forge also, that might be the same
thing we were seeing with src and koji, so lets try and bypass POSTs
here too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 13:03:26 -07:00
56e52aa71c bodhi: adjust config in staging to allow src.stg builds
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 12:27:38 -07:00
b27e90e124
ELNBuildSync: Add hostname entries
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-01 14:34:56 -04:00
20687f05ee
ELNBuildSync: Wait for the build to complete
The playbook can be run with --tags all,build and it will perform the
ImageStream build and then proceed to deployment.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-01 13:57:48 -04:00
92c757a52e
Add OCP_BUILD_WAIT option to openshift/start-build role
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-01 13:56:48 -04:00
609976d3c2
Revert "ELNBuildSync: Wait for build to complete"
This reverts commit baceaabf97ee1de2ee9aaf3dc9da890257c6e095.
2026-07-01 13:54:34 -04:00
baceaabf97
ELNBuildSync: Wait for build to complete
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-01 13:34:47 -04:00
50c4278af6
ELNBuildSync: pull in 1.3.2
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-01 13:22:38 -04:00
James Antill
2f018f36e2 sync-http-logs: Add some missing hosts, and add some comments.
Signed-off-by: James Antill <james@and.org>
2026-07-01 13:17:58 -04:00
0b1267eb9b
Nagios: remove nagios_client role, and remove it from playbooks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 17:31:32 +01:00
449ddd529b
Zabbix: Add koji check_lock script
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 17:31:18 +01:00
c4a96be6cc
Zabbix: set owner of centos-monitoring rabbit scripts/units/timers correctly
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 16:41:06 +01:00
2818ab897e
Nagios: change ownership of centos sender script
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 16:06:48 +01:00
6eac650a10
Nagios: remove nrpe from a bunch of smaller things
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 14:22:40 +01:00
ea960ee1a7
Nagis: remove nrpe config from rabbitmq_cluster
This actually restores some code I deleted in March, because it's needed
for the CentOS sender. It now places that config in /etc/zabbix since
/etc/nrpe.d is going to be removed.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 14:22:40 +01:00
fbf73ff1f9
Nagios: remove nrpe from the firewall config
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 13:35:34 +01:00
bd60dab0fb
Nagios: remove nrpe from fedmsg
The user is already gone in the nagios_client commit, but this alters
the sockets to be group-owned by Zabbix instead of nrpe

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 13:35:34 +01:00
e86f495e8d
Nagios: remove nrpe from COPR
Note we can drop the nrpe.d block entirely because that dir got removed
in the previous commit.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 13:35:34 +01:00
9a83bf66d4
Nagios: remove nrpe from servers
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 13:35:34 +01:00
31776c27e4 Fix syntax error
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-01 14:26:36 +02:00
d96ff34676 Enable infra tags repos on RHEL10
There are now infra tags repositories for RHEL10, let's enable them.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-01 14:19:37 +02:00
cc06635ada
Zabbix: kojipkgs uses a different port for Varnish
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 10:24:30 +01:00
b5a2ece0b9
Zabbix: adjust Varnish tcp port check, and selinux rule
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 10:12:46 +01:00
6837abe432 Add forge-releng-provenpackagers in releng org
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-01 08:20:27 +00:00
541c938f4e greenwave: gate on desktop_notifications_postinstall_updatetest x86_64
Test is disabled on aarch64 on KDE for being flaky, and is also
a bit flaky on aarch64 on GNOME on F43, so we can't gate on
aarch64 for now. Will maybe re-assess when F43 goes EOL.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-30 11:48:51 -07:00
975539e3bb
ELNBuildSync: Don't tell YAML to strip newlines
See "BLOCK SCALARS" in
https://env.dev/cheatsheets/yaml-cheat-sheet

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-30 13:25:03 -04:00
7cbe56ce2f
ELNBuildSync: bump to 1.3.1
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-30 12:34:11 -04:00
e98613ae82
ELNBuildSync: Make mount paths read-only
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-30 12:33:13 -04:00
539427b4c8 robosignatory: setup f45-perl signing and drop f45-python since it is merged
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-30 09:24:09 -07:00
f70420248f
ELNBuildSync: properly quote FM queue name
Also ensure that the fedora-messaging config is updated whenever the tag
is specified.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-30 10:01:11 -04:00
5492b306d8 [flatpak-indexer] Remove quay differ deployment
It seems that we doesn't need this as both differ deployments are
processing tasks from both quay.io and registry.fp.o indexer.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-30 14:59:05 +02:00
796ccbdec9 [flatpak-indexer] Fix deployment
Remove tests from deployment - they are failing, but on upstream all of
them passing.
Fix the quay.io config - use correct quay.io namespace, delta and icons
uris need to point to registry.fp.o as there isn't any space on quay.io
to store them
Use upstream repository for redis build

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-30 13:58:29 +02:00
969a94bd18
Zabbix: add tags missed in previous commit
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-30 12:48:53 +01:00
a0c7bf49ad
Zabbix: migrate still-in-use Nagios plugins to the relevant roles
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-30 12:42:26 +01:00
f594173ae1 [flatpak-indexer] Separate quay.io instance
This is another try to separate the quay.io instance for
flatpak-indexer.
See more info in infra/tickets#11543

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-30 11:20:37 +00:00
24b17321d4
Jira-sync: add timestamp to the consumer logs
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-30 10:31:08 +02:00
f501a4490f dhcp_server: adjust bvmhost-a64-02, it uses the other interface
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-29 16:11:01 -07:00
7f1b0dd13a base: no_log for the keytab fetching
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-29 15:46:53 -07:00
ca2e7ab7cd dhcp_server: adjust provisioning for bvmhost-a64 prod servers to use the correct 25G interfaces
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-29 15:27:44 -07:00
537ab5d20f Revert "nbde: set threshold to 5"
This reverts commit db0b9e4f0cb505813217d8687118eaf874b04da6.

This is not the correct knob to adjust number of attempts.
This is number of things that have to be successfull before unlock.
1 is right here. ;(
2026-06-29 15:25:28 -07:00
887c7c311e
ELNBuildSync: Update file paths to match EBS 1.3.0
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-29 15:59:41 -04:00
0b460d390c Update roles/openshift-apps/forgejo/templates/values.yaml.j2 2026-06-29 19:39:26 +00:00
32a25d7bcc releng / ftbfs cron: supress login message
Right now this script outputs the login message from bugzilla:

Last login: Sun Jun 21 04:22:00 UTC 2026

which causes it to email a cron output. This is useless.
Just supress that and still allow for getting other errors.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-29 11:08:11 -07:00
62f68bf965
jira-sync: actually do changes in Jira
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 20:06:38 +02:00
bd87a50da9
Improve logging in jira-sync
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 19:51:50 +02:00
9a7c1aebeb
Deploy jira-sync to prod
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 19:41:59 +02:00
7b5ae8e938
Jira-sync: fix secrets name in cronjob
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 18:51:17 +02:00
3068b93915
Jira-sync: there is no token for codeberg, and use token_file
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 18:46:42 +02:00
f4dd0f6c2f
Jira-sync: there is no stg token for backends
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-29 18:43:00 +02:00
Lenka Segura
0ec84de2f4 forge: add runner for koji
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-06-29 11:00:15 +02:00
ab3253d1e8
fix command
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:30:42 +02:00
76cc776377
Poetry is not inside the image
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:29:32 +02:00
6aef344777
Adjust path and name
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:24:50 +02:00
a5c7b8018c
And look: more syntax
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:13:10 +02:00
f9ef7d87c7
Syntax, again
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:12:15 +02:00
ee0afdd0aa
Syntax
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-27 00:11:06 +02:00
ff96161c07
Create the project first
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-26 23:54:37 +02:00
ae6524da08
Typo
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-26 23:52:54 +02:00
98276d6b77
Scaffolding for jira-sync in staging Openshift
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-26 23:50:01 +02:00
Cristian Le
16f15b85a1 Add osci-pipeline queue for scratch-build-test 2026-06-26 21:36:54 +00:00
9fb01cb4ef
ELNBuildSync: move to 1.2.1 in STG
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 16:54:34 -04:00
6f5d450cc0
ELNBuildSync: Fix typo in command-line argument
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 16:36:27 -04:00
9443e8e293
ELNBuildSync: Fix incorrect ConfigMap field
ConfigMap and Secret differ nonsensically on the definition of this
keyword.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 15:23:30 -04:00
b8403b4b0f
ELNBuildSync: Force apply of OpenShift objects
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 15:11:54 -04:00
29481de49e
ELNBuildSync: push Kubernetes objects when building
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 14:41:19 -04:00
fa6805a254 ELNBuildSync: Make ebs_oidc_secret an actual Secret
This also means that static-config can be a ConfigMap, rather than a
Secret since it no longer contains any sensitive data.

Also use `stringData` instead of `data` to be explicit about its format.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
5eff1cce5b ELNBuildSync: rename public-config to static-config
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
0e8523bab3 ELNBuildSync: rename ebs-config.yml to ebs-secrets.yml
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
86843d5b2c ELNBuildSync: Add OpenID Connect support
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
318288aedc ELNBuildSync: Add static configuration file
Includes the Koji, Bodhi and Database configuration

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
3e3a01df73 ELNBuildSync: reorganize ansible variables
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-26 17:52:33 +00:00
0ce30a13ba buildvm-s390x-13.s390.fedoraproject.org: remove from compose
We have 3 compose builders, but we don't really need all of them I don't
think. The rawhide composes do boot.iso for everything and server
and server dvd here, so 2 builders I think should be fine.

Lets move this one to be a general builder to try and prevent
backlogs.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-26 09:33:09 -07:00
531895bc5e 📧 roles(fasjson): Update releng-team alias
This commit updates the assignments for the releng-team@fp.o alias to
use a FAS group membership mail for dynamically updating who receives
email sent to this mail alias. The overall goal is to ensure a trusted
and responsible person receives email sent to this alias, and to use a
FAS group to more dynamically handle membership for who should receive
access to emails sent to this alias.

I noticed this while adjusting other aliases in the file nearby, and saw
that @jnsamyak was not yet a member of the email alias. By using the FAS
group member address, all people in the `releng-team` FAS group will
also receive mail sent to releng-team@fp.o from now on.

FYI: @humaton @kevin @jnsamyak

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-06-26 11:46:08 +00:00
1f036616d5 [ipa] Correctly disable NIS on RHEL10
Oops. I just enabled it only for RHEL10 and newer and it should be just
versions lesser than RHEL10.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-26 10:44:03 +02:00
505e300ae4 [ipa] Disable NIS on RHEL10
NIS is no longer supported on RHEL10 IPA. We don't need to disable it anymore.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-26 10:35:33 +02:00
d6f46658ec
Revert "Refs 13419 - disable worker 04/05 in the proxies as httpd-lb isn't doing it's thing"
This reverts commit bdf834a3e91480bb6c1229ba4fdef4209ebe2361. The
workers are back online now, and we can use them again.
2026-06-26 09:08:04 +01:00
d13f189e4f [ipa] Use the correct ks_url
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-26 09:41:14 +02:00
2ab3444d16 openqa/dispatcher: avoid extraneous quote marks in config
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-25 23:13:25 +01:00
db0b9e4f0c nbde: set threshold to 5
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 14:27:07 -07:00
efc43822cd vmhost-x86-copr02: fix mac for bond port
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 11:09:20 -07:00
03295b7d89 vmhost-x86-copr01: fix mac for bond port
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 11:08:25 -07:00
0016f9bbf5 bastion/aliases: add alias for eln-buildsync user
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 10:05:51 -07:00
68a1efb111 buildhw-x86-12: fix mgmt ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 09:40:45 -07:00
479256ae92 [ipa] Move ipa03.stg to RHEL10
First step to move IPA on staging to RHEL 10.
See infra/tickets#13382

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-25 14:40:33 +00:00
a16deeb465
Postfix: use postfix_group variable to get the right main.cf for maintainer_test
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 15:28:25 +01:00
4962777991
Postfix: test host-specific main.cf file for postfix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 15:21:04 +01:00
7db40e0556
Postfix: use vpn route for ending via bastion on maintainer-test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 14:31:13 +01:00
bdf834a3e9
Refs 13419 - disable worker 04/05 in the proxies as httpd-lb isn't doing it's thing
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 10:45:12 +01:00
465c2ca3ec Revert "openQA etc: use a single-cert CA cert file for staging rabbitmq (#13422)"
This reverts commit 49f42faa1b6f3ea4d9a3acb87f9ccda13fef9dea.
I've updated to latest fedora-messaging and want to see if this
is unnecessary now.
2026-06-25 09:50:35 +01:00
0294ed72df 📧 roles(fasjson): Update Fedora Marketing and Ambassadors aliases
This commit updates the assignments for various Fedora Marketing and
Fedora Ambassadors aliases to send mail to specific leadership roles
(i.e., @jspaleta the Fedora Project Leader, @jflory7 the Fedora
Community Architect, @amoloney the Fedora Operations Architect, and some
specific groups such as the Fedora Council private mailing list, Fedora
Mindshare Committee members, and Fedora Marketing Team.

The overall goal is to ensure an accountable person receives email sent
to some of these aliases, and to use FAS group membership to dynamically
add and remove members from the mail alias in the future.

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-06-24 19:04:36 +00:00
383ec9d082 feat(openshift-app-image-report): add enviroment searching
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-06-24 19:01:14 +00:00
412e39286b feat: add a script for checking os versions in openshift-apps
Assisted-by: OpenAI gpt-5.5 in Codex
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-06-24 19:01:14 +00:00
b3fe510408 riscv-kojipkgs: fix template name to actually apply
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-24 11:33:55 -07:00
15d3280750 [bodhi] Always run pre_tasks
When running the playbook with specific tag it will skip pre_tasks and
some of the vars are missing if that happens. Let's add tags: always to
run it everytime.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-24 10:59:36 +02:00
c1724e8ac1 [bodhi] Use the correct namespace in quay.io
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-24 10:40:59 +02:00
05ac1a1e77 [bodhi2] Add script to make flatpak repos public
The repos created through docker push are created as private by default.
This script will run every hour and sets any private repo visibility to
public.

This should be next step to finish
infra/tickets#11543

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-24 09:56:40 +02:00
2519e23c78
Add cluster monitoring to rabbitmq03 in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-24 07:39:05 +02:00
13c67bd1c2 proxies: bump max connections up more
Seems like there are a ton of really small connections and it starts
hitting the limit (although it never logs that it's out, I think because
they free up quickly).

See if this solves the transitory alerts we see.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 15:21:10 -07:00
280e9bbe54 proxy02.stg: add some secondary ips
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 15:20:25 -07:00
6a624f306b basessh: Use ListenAddress on hosts with secondary addresses.
If a host has a secondary ipv4 or ipv6 address, only have sshd listen on
the primary ip. This will allow hosts with secondary ips to use ssh port
on secondary ip's for other things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 14:42:56 -07:00
c9b56e6358 proxy01.stg: use proper ipv6 format
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 14:32:04 -07:00
cda4b5e5a3 proxy01.stg: try an approach using a secondary ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 14:28:39 -07:00
9ce1351301 Revert "proxies / staging: move ssh to port 222"
This reverts commit a83380f64cfd17da3e9608c49e09d8d6dc09b248.
2026-06-23 14:21:20 -07:00
cd7313952e Revert "also create a ssh_config for root with the non standard port"
This reverts commit 03631331d0a817fc783816bf7517df8584afd94d.
2026-06-23 14:21:11 -07:00
03631331d0 also create a ssh_config for root with the non standard port
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 21:02:52 +00:00
a83380f64c proxies / staging: move ssh to port 222
This pr attempts to move sshd to port 222 on proxy01.stg and
proxy02.stg.

We want to do this (first here and then in prod) because we want to nat
in ssh from external and use haproxy to send that into
forge.fedoraproject.org. If we were using port 22 to connect here
it would conflict with forwarding it on to haproxy.

Note that we still need to actually get networking folks to make the nat
mapping and we still need to add haproxy config to send it into forge in
openshift, but this is the first step we need to get working before we
can do those things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 21:02:52 +00:00
242cb123a0 people / jflory7 quota increase ( issue 13430 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 13:57:07 -07:00
6273dafdf2 add fail_msg to assert in roles/openshift/app-actions
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-06-23 19:30:22 +00:00
9d21d55364 fix lint errors
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-06-23 19:30:22 +00:00
642b7afdf3 feat(openshift): add restart for openscanhub + reusable role
Assisted-by: gpt-5.5 in Codex
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-06-23 19:30:22 +00:00
Jiri Kyjovsky
09a329eeb6 copr-anubis: allow all non-get requests
Relates: https://github.com/fedora-copr/copr/issues/4110
2026-06-23 13:43:34 +02:00
e748dc2f85 Forge staging: Add 'fedora' label to all fedora-N runners
There are six global 'fedora' runners in staging forgejo, each with a
different label. This makes it awkward to create workflows as you have to
arbitrarily tie them to a single runner for no very good reason. If we
give them all the 'fedora' label you can just set your workflow to run on
'fedora' and it will run on any available runner.

Also, at least for the quality org, our prod runners have the 'fedora' label,
so if the global staging runners have the same label, we can reuse workflows
between staging and prod.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-23 11:38:29 +00:00
b00e0aaf59
RabbitMQ: private keys need to match the certs, duh
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-23 11:01:06 +02:00
83a81d1ece
Restart RabbitMQ when the cert change
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-23 10:49:55 +02:00
f550f61788
Update the RabbitMQ cluster monitoring on staging
- split off the template into a node template and a cluster template
  (that only needs to be instanciated on one node)
- add certificate expiration monitoring in the cluster template

This is only on staging for now.

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-23 10:35:20 +02:00
c42bde9860
RabbitMQ: use the old server certs in staging for now
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-23 10:34:47 +02:00
60a2cbec78
RabbitMQ: add the staging suffixes to users and queues
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-23 10:28:58 +02:00
Gordon Messmer
6a7d6431e0 gpu01: grant GPU access to all users 2026-06-22 21:15:39 +00:00
Gordon Messmer
a099f7e370 gpu01: grant GPU access to approved user groups 2026-06-22 21:15:39 +00:00
2c85bbbdf1 readd communishift-happinesspackets ( ticket #13238 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-22 13:46:15 -07:00
bca0d4843a
Zabbix: use non-vpn server target for maintainer test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 16:00:23 +01:00
2610b16219
Zabbix: add CS10 package defaults
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:54:50 +01:00
a574775086
Zabbix: use correct and not-typoed server target for maintainer_test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:44:08 +01:00
474152f472
Zabbix: use correct server target for maintainer_test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:35:53 +01:00
34bba84c4a
Zabbix: use correct server target for logdetective hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:27:29 +01:00
cfea78b9cc koji / hub: fix scm_repository name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-21 20:39:18 -07:00
e493015497 koji / hub: allow forge.fedoraproject.org/releng/kiwi-descriptions.git
This repo moved to forge so allow that and drop the no longer used
kickstarts repo as well as pagure.io.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-21 17:47:28 -07:00
47e4cedcff Define openqa_env_prefix for servers
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-21 00:11:49 +01:00
49f42faa1b openQA etc: use a single-cert CA cert file for staging rabbitmq (#13422)
See infra/tickets#13422
for details on this. It seems like rabbitmq staging has been
switch to the 'new' CA cert, and the consumers don't actually
read/trust both certs in the combined CA cert file, only the
first (old) one, so they don't trust the new one. This should
deploy and use a new file with only the new CA cert in it. We
copy it out of the private repo for convenience but it's not
actually private, hence the 0644 perms.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-20 14:39:13 +02:00
7c8d8a1794 Revert "openQA: try using old pki cert/key on staging"
This reverts commit 293930446b728fc0da8caf0b8ad9d721a6275e1b. It
doesn't look like it helped.
2026-06-20 11:19:24 +02:00
293930446b openQA: try using old pki cert/key on staging
I'm having auth issues on openQA staging, I believe it *may* be
to do with the changes Aurelien made in
6fe8b98de21747dc16d59dcf5096da719a541296 . Let's see if using the
old key and cert helps.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-20 11:14:30 +02:00
03b0d89442 rabbitmq: add weblate user to send translation messages
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-19 09:01:42 -07:00
ecac04bf27 Whoops, add the openQA distgit reporter queue to the playbook
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 14:14:13 +02:00
73a749e915
Zabbix: add 100 to postfix queue triggers for smtp-mm
spammers are making the queues longer, lets allow a bit more headroom

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 13:11:56 +01:00
97bd28d71e copr-be: retry libvirt pool-refresh few times
This was causing headaches @ vmhost-copr03-p09 (some unspecified
disk-performance issues).  Let's try the operation several times.
2026-06-19 13:34:48 +02:00
6de0108ef7 openQA dist-git PR test result reporting config (staging)
This *should* configure a new queue and consumer for openQA to
report dist-git PR test results back. It's all a bit speculative
ATM, may need some tweaking. Mostly applied only on staging for
now.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 13:25:02 +02:00
d4ae9f8244 Fix all my message queues to be non-exclusive and durable
AI caught that I've been cargo-culting a dumb message queue
config around from somewhere or other forever. Non-durable,
exclusive, and auto-delete is just about the worst config for a
queue you want to survive transitory issues like the server or
client going down or whatever. This might actually explain the
occasional issues we have with test results not showing up in
resultsdb, even.

This brings the config in line with most other message queues in
infra.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 13:15:18 +02:00
bc5be205b7
Zabbix: add an hour to the web-data triggers to give the crons time to run
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:52:31 +01:00
ef5567d8c0
Zabbix: add an hour to the MariaDB backup trigger to give the daily cron time to run
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:42:15 +01:00
3191e90c16
Zabbix: add zabbix_agent to places where nagios_client is used
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 11:41:51 +01:00
dd8d677a83 Revert "greenwave: disable gating on FreeIPA replica tests on Rawhide"
This reverts commit 0002bf4f26090bbac1260b9b61fe91cae7ba3713. I've
tweaked openQA to always softfail the tests on Rawhide for now, so
we no longer need to special-case the gating.
2026-06-19 10:24:03 +02:00
0002bf4f26 greenwave: disable gating on FreeIPA replica tests on Rawhide
See https://bugzilla.redhat.com/show_bug.cgi?id=2490607
We have found a bug in FreeIPA replica enrolment with the
OpenSSL 4 update. However, the bug is tricky to fix and the update
is massive and maintaining its side tag is very painful. As a
very exceptional case, we're disabling gating on these tests so
the update can be merged without causing all subsequent updates
to fail gating. We will endeavour to fix the bug and re-enable
normal gating service ASAP.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 00:52:33 +02:00
83f050747d Add communishift copr project ( ticket 13409 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-18 15:20:46 -07:00
20575cc5ff
📧 roles(fasjson): Update matrixadmin@ to use FAS group sponsors
This commit updates the `matrixadmin@fp.o` email address alias to now
use the `commops-wg-matrix` sponsor membership for the people who will
automatically receive email to the Matrix admin email. This is one step
to somewhat simplify membership of the email alias to a FAS-backed
mechanism for tracking and updating the sponsors.

Of course, sponsors cannot be updated in Noggin at the moment, so this
requires an IPA FAS admin to update the sponsor list for membership, but
this is an interim step for now.

Additionally, the `cle-managers@fp.o` email alias is added, which
ensures that key members of the CLE Team management will receive comms
to this email address, in the event that a key person from Fedora Infra
is on PTO, unavailable to respond, and to ensure delegation of access in
case of the "lottery factor".

People impacted by this change: @gwmngilfen @jasonbrooks @shaunm @blc
@smilner @ancarrol @jbley @mattdm

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-06-17 22:32:07 +02:00
92ac345388
Zabbix: adjust ping threshold for proxy30 & 38
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-17 11:28:55 +01:00
0655279df0
Zabbix: make ping threshold trigger configurable
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-17 10:26:33 +01:00
9421accd88
Nagios: remove old cronjob
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-16 16:24:16 +01:00
f61ee713df update releng coreos-team ipa group to use forge-* specific nomenclature
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-06-16 14:06:47 +05:30
d0ac65031b
EBS: Specify koji profile
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 17:10:58 -04:00
5736677bf0
EBS: bump to 1.1.2 in staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:58:24 -04:00
fdf8c95b09
ELNBuildSync: use the correct principal name
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:41:03 -04:00
27df4c5f19
ELNBuildSync: Pass krb5 principal name
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:34:29 -04:00
71107c6e45
ELNBuildSync: deploy 1.1.1 in staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:25:13 -04:00
98747b34a7
ELNBuildSync: Further fixes for prod/stg var split
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 16:25:13 -04:00
e0922f3d6c
docstranslation: Use git token instead of ssh key 2026-06-15 22:15:34 +02:00
James Antill
0a8e3dbe21 Revert "elnbuildsync: Add keytab_service variable for openshift/keytab."
This reverts commit 816d3c74a2e900072053872f427b88cee4be36b4.
2026-06-15 15:49:53 -04:00
James Antill
816d3c74a2 elnbuildsync: Add keytab_service variable for openshift/keytab.
Signed-off-by: James Antill <james@and.org>
2026-06-15 15:46:18 -04:00
James Antill
d7b285dfde elnbuildsync: Change serial to string type.
Signed-off-by: James Antill <james@and.org>
2026-06-15 15:22:53 -04:00
3789fc868a
ELNBuildSync: add Deployment serial
Ansible doesn't detect Deployment changes when dependent files are
modified, so we'll just add a serial we can bump up whenever we need to
force Ansible to re-deploy.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 15:16:36 -04:00
391b870f39
ELNBuildSync: Add missing suffix on Secret key
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 15:00:04 -04:00
69969ce815
ELNBuildSync: locate RabbitMQ certificates in the correct place
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 14:30:13 -04:00
9da15d2b03
ELNBuildSync: rework variable locations
Instead of having foo: and foo_stg: variables with ternary() selections
based on environment, take a cue from Koschei and use two variable files
in the role, selected by environment name.

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 14:30:12 -04:00
James Antill
075447568c roles/ipa/botuser: Drop the freeipa. prefix.
Signed-off-by: James Antill <james@and.org>
2026-06-15 13:10:21 -04:00
f5a5681182
elnbuildsync: Retrieve keytab from IPA
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:49:42 -04:00
f5d5a317df
keytab/botuser: Drop recursive variable assignment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:48:07 -04:00
f3766454d0
openshift/keytab: Support botuser keytab Secrets
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:47:23 -04:00
1d1dfa55b7
openshift/keytab check for different stderr
Different versions of OpenShift return different messages when a Secret
already exists in the project. Check for both variants out of an
abundance of caution.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 10:44:43 -04:00
7ef75bd174
elnbuildsync: limit to staging for now
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-15 09:08:05 -04:00
bb005e49aa
New roles: keytab/botuser and ipa/botuser
Allows the idempotent creation of a bot user with a randomized password.
Administrators can retrieve a keytab for this user without modifying the
password.

Playbook usage:

  - role: keytab/botuser
    username: "somebot"
    kt_location: /etc/keytabs/somebot.keytab
    tags:
    - config
    - krb5

Also accepts `first` and `last` arguments for given and family name, if
desired.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-12 14:17:30 -04:00
5343c0947b
Minor fixes to 95b1a7b3
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-12 18:30:09 +02:00
c8d93a8e0f
websites: restart S3 sync if it fails 2026-06-12 17:54:02 +02:00
c56b70e09f
docstranslation: disable scheduling during forge migration 2026-06-12 17:40:08 +02:00
95b1a7b3e4
Rewrite make-rabbitmq-certs-public in Python to access the YAML file
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-12 16:42:06 +02:00
6679a99e3a
Zabbix: Add HTTP check on drm-panic.fpo
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 13:01:35 +01:00
c052919334
Zabbix: Update PGSQL lock thresholds for busy dbs, they seem fine
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 12:18:27 +01:00
dc651012e1 added full path to oauth redirection annotation
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-12 10:16:01 +00:00
71958dc195
Nagios: disable systemd service
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 10:48:33 +01:00
264def3f42
Zabbix: Update Apache template to reduce service-down Matrix alerts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-12 10:47:02 +01:00
9b1c1f4890 feat(forgejo): securing metrics endpoint in prod
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-12 09:07:58 +02:00
3060702ac9 copr-be: the flavor we use in OSUOSL has been moved to P10
https://github.com/fedora-copr/copr/issues/4234
2026-06-11 22:22:19 +02:00
92d93d29f0 ELNBuildSync: Use different config branch on staging
Also fix missing variable reference for the main role deployment
playbook.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
63101653a1 ELNBuildSync: Fix AMQP configuration
Feedback from code review:

* Drop unused routing key
* Remove hardcoded .prod.
* Sync with queue_routing_keys in the playbook
* Properly interpret Jinja variables

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
81329e710d ELNBuildSync: Do not set AMQP queue as exclusive
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
377e504d21 ELNBuildSync: support staging RabbitMQ
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-11 18:13:32 +00:00
6236fc9d67
Zabbix: Migrate Pagure checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 17:12:40 +01:00
5379379e37
Zabbix: write Koji dropin to correct file
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 16:50:27 +01:00
cb5656371d
Zabbix: use escaped double quotes, Zabbix doesn't like single quotes
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 15:45:07 +01:00
06997a5e03
Zabbix: fix typo in hhtpchecks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 15:38:10 +01:00
2336ad427a
Zabbix: re-enable http checks and migrate src.fpo moreutils test
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 15:31:31 +01:00
de5806c609
Fix RabbitMQ cert path
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-11 15:25:50 +02:00
3859aac303
Zabbix: use correct memcached template name
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 14:12:52 +01:00
cd10ee361a
Zabbix: put memcached dropin in the right place
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 14:07:04 +01:00
182bd82802
Zabbix: move Memcached from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 13:34:15 +01:00
6bb31d1d6e
forgejo: debugging oauth-proxy config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 13:00:54 +01:00
Jakub Kadlcik
2e6e48414b copr: upgrade builders to F44
Fix https://github.com/fedora-copr/copr/issues/4306
2026-06-11 13:57:33 +02:00
afb43fd7a2
Zabbix: make NFS lock check specific to koji01
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 12:46:53 +01:00
55a821f5a4
forgejo: fix securityContext config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 12:39:34 +01:00
50785d4c4e
Zabbix: move Koji wellness checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 12:33:15 +01:00
29795cc89c
forgejo: reconfigure valkey deploy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 12:25:01 +01:00
540464a7e0
forgejo: debugging valkey issue
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 12:19:14 +01:00
80cadf76e8
forgejo: fix issue with valkey
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 12:04:23 +01:00
3e32565289 fix(forgejo): added upstream url for oauth-proxy sidecar
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-11 12:33:49 +02:00
c70053039a fix(forrgejo): removing hardcoded localhost ip for sidecar oauth-proxy container
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-11 12:18:36 +02:00
000d326ddf
Zabbix: move Nagios moby check, pt2
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 11:10:17 +01:00
cb69a210a4
forgejo: remove quotes around metrics servicemonitor variable
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 11:05:00 +01:00
51382e7c0e Zabbix: move Nagios moby check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-11 10:03:07 +00:00
80fc523062
forgejo: remove quotes around metrics variable
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-11 11:01:01 +01:00
2521ee8884 feat(forge): recieve right version of oauth-proxy image
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-11 11:45:55 +02:00
Lukas Holecek
51dad08b81 resultsdb: Fix image trigger annotation placement on API deployment
Move the annotation to Deployment metadata where OpenShift's
trigger controller actually watches for it.

Assisted-by: Claude (Anthropic)
2026-06-11 08:08:19 +00:00
33e15c3b95
Zabbix: restrict redhat-postfix cron to boastion hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-10 19:08:42 +01:00
d366c5bf0e
forgejo: Debugging zabbix agent on runnerhostVM
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-10 17:42:43 +01:00
6c3c094583
Zabbix: send COPR notifications to the new copr-monitoring room
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-10 17:29:35 +01:00
25d50d0829 Add coreos-team in releng org
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-06-10 15:56:05 +00:00
dbd28e4164 [release-monitoring] Update to F44 in production
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-10 15:54:29 +02:00
c7d64d230c
forgejo: update values to match latest changes from helm upstream
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-10 13:53:13 +01:00
1669722c4f [the-new-hotness] Update to F44
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-10 13:23:26 +02:00
8bb8c5e129
Zabbix: migrate merged.log age check from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-10 12:11:16 +01:00
fc72ee6a93
Add some tags
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-10 10:28:43 +02:00
da11627a6e
RabbitMQ certs monitoring: also build a JSON file for Zabbix
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-10 07:37:10 +02:00
8e959f2f08 Switch epel10.repo to use epel/10z
The epel/10 symlink tracks the latest EPEL 10 minor version, which
targets CentOS 10.  The epel/10z symlink tracks the EPEL 10 minor
version corresponding to RHEL 10.  Since we're using RHEL 10 in the
infrastructure, we need to use epel/10z to ensure compatibility.

Follow up to 1963b068d3.

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-06-09 22:59:54 +00:00
247089339a greenwave: use hummingbird memcached container
This was not specifying a registry, so it was using docker.io.
docker.io restricts pulls a lot, so when restarting often times
it would just get stuck in imagepullbackoff

Just switch to the nice new hummingbird version.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-09 22:58:09 +00:00
72b346ad2b riscv-koji: missing end brace
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-09 09:41:36 -07:00
eaf5fced69 riscv-koji: allow building from forge overlay
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-09 09:29:48 -07:00
f97891fe72 kojipkgs: disallow indexes on compose/{iot|ostree}/objects too
These directories have 32k entries and when scrapers hit them it causes
kojipkgs to slow to a crawl since it takes minutes to stat all those
files. There is no need to allow indexes here, as ostree doesn't need or
use them, so just disallow it so the scrapers don't nuke kojipkgs.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-09 08:23:58 -07:00
0a63d89212
Zabbix: migrate redhat-specific mailq check from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-09 16:22:04 +01:00
cf272921d9 [release-monitoring] Use correct static paths
F44 has python 3.14. Let's use it.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-09 16:24:31 +02:00
c6aff928a9 [release-monitoring] Bump to F44 on staging
Update buildconfig to Fedora 44 on staging.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-09 15:48:25 +02:00
3202a6b388 Fix 'include_role' usage in rabbitmq setup
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-09 13:22:41 +00:00
0759572fcf Move the ELNBuildSync queue setup
Now that ELNBuildSync is being deployed via Ansible, we should keep its
queue setup with the rest of the playbook.

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-09 13:22:41 +00:00
0cc2b77915 Add ELNBuildSync deployment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-06-09 13:22:41 +00:00
e2b85f3f04
Fix typo in openvpn task definition
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-09 13:40:39 +01:00
d1a797e554
Zabbix: migrate openvpn crl check from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-09 13:37:02 +01:00
78db1e778c
Zabbix: Add IPA free_ids monitoring via cronjob
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-09 11:25:46 +01:00
ea96ad9499 copr-be: enforce SCP over SFTP for config uploads to VMs
This is needed for P09 hypervisors:
RuntimeError: Failed to upload ISO via SCP to /libvirt-images/vmhost_p09_01_prod_11752972_20260609_095937_config on copr@[2620:52:6:1161::10]
2026-06-09 12:01:50 +02:00
947493fdda copr-backend: fix booting VMs on RHEL 10.2
I'm not sure why we originally added acpi=off, but it is breaking dracut
on our F43/44 VMs.
2026-06-09 11:56:59 +02:00
801c68082d
update fas2discourse repo to point at new forge
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-09 10:09:13 +01:00
99fdaaf68d openqa nftables: gah quickfix
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-08 17:21:48 -07:00
b16be7cbdc openqa: try and fix custom nftables rule
Looks like 'nat' was renamed, let's try using the variable.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-08 17:11:49 -07:00
36c203a312 openqa: use updates-testing on prod again
This is to get the latest snapshot packages that we've been
testing on staging, they look good.
2026-06-08 16:46:07 -07:00
cae07e65f6 f42-test: eol and terminated
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-08 11:58:50 -07:00
3a58e87f2f proxy14: move to vmhost-x86-iso03
vmhost-x86-iso03 is empty and moving proxy14 off 04 will free up some
iops for download-iso01.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-08 10:18:15 -07:00
5a33ceb031
Mariadb: Enable backups on db03.stg
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 16:18:34 +01:00
ca291c8669
Zabbix: Migrate MariaDB backup file-age check from Nagios
(also fix tags in the Sigul monitoring from earlier)

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 16:17:13 +01:00
c603e9c69c
Zabbix: migrate sign-bridge sigul check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 14:20:14 +01:00
77cfc6bff2
Add zabbix_agent to sign-bridge
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 14:02:10 +01:00
945ea54ce9
Nagios: also remove the mailman check after migration
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 12:58:15 +01:00
52a5d4db47
Zabbix: migrate Mailman check from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 12:51:38 +01:00
82916a3c2d
Zabbix: add monitoring of SMTP port 25 for mm/gateways
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-08 12:13:31 +01:00
9b7ad64e73 openqa: don't use updates-testing on prod workers
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-05 16:34:29 -07:00
Gordon Messmer
21fc96a4ae gpu01: add sub-ids for CLE and AI/ML SIG members 2026-06-05 21:20:05 +00:00
7fadab3b49 proxy110: move to vmhost-x86-03 so both it and 101 are not on the same virthost
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 13:59:25 -07:00
ccc038e3d4 zabbix: open port 10051 so agents can talk to servers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:56:40 -07:00
12725e170a zabbix: disable these checks in the right place
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:40:46 -07:00
22cde2e827 zabbix: disable this entire trigger for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:36:53 -07:00
ef8cd351b8 zabbix: nope, lets try breaking it up
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:35:25 -07:00
bd32aca8ec zabbix: ok, how about more double quotes
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:32:42 -07:00
d9b0642fe1 zabbix: try just not passing the single quotes
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:27:08 -07:00
18126a9103 Revert "zabbix: try and rework this so it does not pass single quotes to zabbix"
This reverts commit 277d0825f9.
2026-06-05 12:26:06 -07:00
277d0825f9 zabbix: try and rework this so it does not pass single quotes to zabbix
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 12:15:34 -07:00
8eb473412a Reapply "Zabbix: use regex instead, more flexible"
This reverts commit 8a41ace0d6.
2026-06-05 12:03:48 -07:00
6c6719b736 Revert "zabbix: fix quoting from reverts"
This reverts commit e9ff217653.
2026-06-05 12:03:37 -07:00
e9ff217653 zabbix: fix quoting from reverts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 11:53:26 -07:00
8a41ace0d6 Revert "Zabbix: use regex instead, more flexible"
This reverts commit 6ed762bb29.
2026-06-05 11:52:00 -07:00
4f6e3351ad Revert "zabbix: disable certgetter check as it seems to break the playbook"
This reverts commit e9313b5895.
2026-06-05 11:50:47 -07:00
e9313b5895 zabbix: disable certgetter check as it seems to break the playbook
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-05 11:42:04 -07:00
2d031471c5 copr-be: re-enable vmhost-copr-04 after the service
infra/tickets#13275
2026-06-05 15:46:09 +02:00
513de6f058 [release-monitoring] Use quay.io image for build
Docker is failing on rate limit, so let us use quay.io instead.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-05 13:32:47 +02:00
Jakub Kadlcik
7e92010a30 copr-be-dev: update builder images to F44
See https://github.com/fedora-copr/copr/issues/4306
2026-06-05 12:20:39 +02:00
Jakub Kadlcik
dab4b02c10 copr-be: set a non-empty value for IBMCLOUD_CRN
There is a too strict validation in `image-builder upload` requiring this value
to not be empty but we don't actually need or use it.

It should be fixed in `image-builder` but that's not something I want to get
blocked by right now.
2026-06-05 12:12:40 +02:00
bac5b82bfd
Zabbix: copy CPU macro from copr-be to copr-be-dev
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-05 09:38:08 +01:00
17c185f2eb Update all the hosts we upgraded to fedora 44 in the outage today
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-04 20:06:18 -07:00
a9644e208c openQA: specify low minimum free space for server dirs
Recent openQA has a mechanism where it refuses to schedule jobs
if the free space for various dirs (results, asset, archive) is
less than X%, where the default X is 5. We use a very large share
for these things and expand it only on need, so it's usually quite
close to 100% full. Let's try only needing 0.5% to be free.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-04 17:04:02 -07:00
9fa66d2441 proxies_stg: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-04 12:39:55 -07:00
fbab66f62c drm-panic-frontend: Deploy in production 2026-06-04 19:17:43 +00:00
57a760e09c
Zabbix: port remaining Copr items from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-04 16:54:37 +01:00
cf9c46c830
Zabbix: adjust copr-be cpu threshold
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-04 13:23:16 +01:00
1b8573d6bc
Zabbix: migrate Copr ping check on the copr-be from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-04 13:23:16 +01:00
615ebcbf0c [oraculum] Add missing fedora:latest imagestream
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-04 13:20:56 +02:00
146d5d519b [oraculum] Build the redis container locally
The previous deployment of Redis has issue with the latest version and
the docker.io is failing on ratelimit. So let's build the redis
deployment from the flatpak-indexer Dockerfile. For details see infra/tickets#13390

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-04 13:10:54 +02:00
d5b39ff4d3 Add pagure-stg-ro01 hosts file and fix the gpu01 one.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-03 13:36:05 -07:00
52ac6c7ec6 pagure-stg-ro01: add new instance for readonly pagure in stg ( ticket 13351 )
For infra/tickets#13351
This makes a staging rhel10 vm thats just the same size / place
as pagure-stg01.

It still needs external ip's and nat in from those, but this should be
enough to install it and start setting things up.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-03 19:55:22 +00:00
James Antill
f2e951adb6 nftables: Remove zabbix rules. Minor cleanup for jinja comments.
Signed-off-by: James Antill <james@and.org>
2026-06-03 14:37:09 -04:00
8f8a5a0a23 koji / pesign: add systemd-boot to hub policy and pesign
Set the systemd-boot package to build on secure-boot channel and set all
the normal permissions for that that other secure-boot builds have.

Add the systemd-boot cert to pesign config so it can be signed by the
right cert.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-03 17:47:55 +00:00
ecd54431d7 smtp-mm-iso01: fix ipv6 address
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-03 09:18:08 -07:00
f2ebff39e9
Nagios: fix typo in previous commit
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 16:46:01 +01:00
8ef433c8f6
Nagios: Remove rdu-cc-gw
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 16:03:18 +01:00
7d0db42137
Zabbix: improve copr notification logic
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 16:03:18 +01:00
Lenka Segura
f6b3f494ae forgejo: Increase the concurrency of the standard runners to 4
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-06-03 14:49:19 +00:00
7516de601e
Zabbix: Move Copr-fe CDN check from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 15:32:20 +01:00
743f69c8a8
forgejo: debugging oauth-proxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-03 15:11:26 +01:00
0fdaf5ff7d
Zabbix: Use a dedicated Copr group and optional host tag
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 15:10:46 +01:00
013b1f8b48
Zabbix: Add COPR notification target
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-03 14:51:42 +01:00
e8799f5dc5
forgejo: disabling oauth-proxy for further debugging
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-03 14:46:01 +01:00
c9d9ff084f
forgejo: reenable oauth-proxy patch
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-03 14:36:47 +01:00
e5db9f4036
forgejo: oauth-proxy image replaced with quay image
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-03 14:28:14 +01:00
6a1a255d9f drm-panic-frontend: Add deployment 2026-06-02 20:51:28 +00:00
f1bd6131f6 bodhi: fix the hotfix patch
test_models.py is not packaged, so we need to use a modified
patch file with the changes to that file stripped.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-02 12:23:57 -07:00
f89447b834 openshift-apps/bodhi: fix annotations metadata in wrong place
728b6c57a3 inadvertently put the
annotations in the wrong place for bodhi-celery (in spec, not in
metadata).

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-02 11:47:05 -07:00
564b6552f6 bodhi: hotfix for ELN gating
See https://github.com/fedora-infra/bodhi/pull/6110

Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-06-02 18:38:53 +00:00
31b024cdf5 greenwave: quick fix: add missing endif
D'oh.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-02 11:31:12 -07:00
9cd1b6f82d greenwave: handle ELN product_version rename, enable RemoteRule
See https://github.com/fedora-infra/bodhi/pull/6110 . We want to
be able to gate (only) Fedora ELN kernel updates via gating.yaml
(RemoteRule). However, if we just turned on the RemoteRule policy
for "fedora-eln", suddenly hundreds of existing gating.yamls which
specify "fedora-*" would apply to ELN, which we don't want.

To solve this, we will make Bodhi use "eln" not "fedora-eln" as
the product_version for ELN. That requires us to add "eln" to the
null policies. Let's also enable RemoteRule for "eln" at the same
time. This should not cause any existing policies to apply (unless
there are any which just specify '*', I guess) but will allow us
to add a kernel policy that applies to 'eln'.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-02 18:21:34 +00:00
102149236d blockerbugs: add DEBUG env var for staging, remove legacy VM role
Set DEBUG=true for staging OpenShift deployment (both the main
Deployment and the sync CronJob) to enable debug logging.

Remove the entire roles/blockerbugs/ directory which was the old
VM-based deployment (Apache/WSGI). This role has been fully
superseded by roles/openshift-apps/blockerbugs/ and is not
referenced by any playbook.

Assisted-by: Claude Opus 4.6
2026-06-02 15:35:07 +00:00
566eabaac0 quality: blockerbugs app - update health check probes 2026-06-02 15:33:58 +00:00
1066361541
forgejo: disable oauth-container patch for debugging
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-06-02 16:17:10 +01:00
d12a457c97 feat(forge): securing /metrics endpoint for staging
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-06-02 14:50:44 +02:00
3457eea89b
Add the RabbitMQ user for the lookaside cache
Fixes: infra/tickets#13380

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 11:54:21 +02:00
728b6c57a3
Fix deployment triggers
The annotations must be on the deployment's metadata, not on the pod
template's metadata.

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 10:14:01 +02:00
d98ce9b9f8
Fix the triggers for the deployment in webhook2fedmsg
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 09:53:40 +02:00
ea82ea2c9a
Fix the openshift user id in badges
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 09:53:40 +02:00
3731a63a13 bodhi-stg: add python-redis to base image
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-06-02 09:08:15 +02:00
James Antill
3fdaf170d5 nftables: Use the config. table names in staging.
Signed-off-by: James Antill <james@and.org>
2026-06-01 18:43:59 -04:00
James Antill
e11b39314d nftables: Fix/merge monitoring changes between prod/staging.
Signed-off-by: James Antill <james@and.org>
2026-06-01 18:38:22 -04:00
James Antill
4a6fc0fdf5 nftables: Fix table name scoping issue.
Signed-off-by: James Antill <james@and.org>
2026-06-01 17:42:12 -04:00
James Antill
5c6868260b Merge branch 'nftables' into upstream
* nftables: (2 commits)
  Cleanup nft merge. Chg osbuildapi and nft_custom_rules to use nft_table_filter.
  ...

Signed-off-by: James Antill <james@and.org>
2026-06-01 17:33:24 -04:00
James Antill
40b3225890 pagure: hotfix for commit hash
Signed-off-by: James Antill <james@and.org>
2026-06-01 21:12:12 +00:00
a9adce6136 robosignatory: enable signing on f45-python 2026-06-01 21:09:43 +00:00
a0156fc54d pkgs: allow apache to read fedora-messaging key
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-01 10:27:44 -07:00
ce1edea8ee distgit: fix the ca cert the git hooks use for fedora-messaging
We were copying in the req instead of the ca, so this messaging hook has
been broken for a long while. This is the hook that notifys on uploads.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-01 09:59:51 -07:00
Jiri Kyjovsky
259ec5b2e8 copr-be: enable rpmeta build time prediction (observability-only)
Deploy rpmeta config to copr-be.conf and hardware pools YAML with
real builder specs. Initially logging-only, does not affect VM allocation.
2026-06-01 17:21:57 +02:00
Lenka Segura
c8a55f0113 forgejo: Increase the capacity of 'ci' and 'atomic-desktops' runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-06-01 09:58:08 +00:00
c6f7e6e601 Update Bodhi Pungi comps git URL from pagure.io to forge.fedoraproject.org/releng/fedora-comps after the fedora-comps migration
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-06-01 14:12:09 +05:30
d830f9ae6e copr: bump up number of reserved instances 2026-06-01 09:54:20 +02:00
615af75669 copr-be: more quota per sandbox 2026-06-01 09:27:15 +02:00
8bbcceafdd proxies: bump max connections fromm 3200 to 4000
It seems like the alerts we have been getting have been when proxies are
near the limit rejecting things via anubis, but unable to keep up.
So, lets try and jump this up a bit and see if it solves those
alerts/slowdowns.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-30 08:36:39 -07:00
71aec6a544 Move s390x staging builders and koji.stg hub to f44.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 12:23:51 -07:00
0248c0d535 virthost: rkhunter is available in epel10/10.2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 11:26:08 -07:00
06c765b10d buildvm-x86: reinstall with fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 11:24:25 -07:00
1be1c69f0f proxy12: fix mac address
This had the hard coded mac address of the previous vm.
We moved to using ansible to just fill in the current mac, so fix that
here too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:52:26 -07:00
141940d1ad basessh: allow tcp forwarding on noc as well as bastion.
We sometimes use forwarding here to access mgmt devices.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:41:46 -07:00
63315f4602 proxy12: reinstall with f44
We need to do this anyhow, but this will test to see if the weird alerts
we have been getting persist on f44 with the latest libvirt machine
setup.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:10:44 -07:00
9a5bca7aad copr-dist-git: hotfix https://github.com/fedora-copr/copr/issues/4318 2026-05-29 13:49:59 +02:00
6a767b3706 always a missing :
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-28 16:21:54 -07:00
9d572f1839 add coreos-agent, rag-magazine-guidelines, and public-inboc-poc communishift projects
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-28 16:20:15 -07:00
Lenka Segura
177bb00442 forgejo: strip the labels after ':' during registration
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-05-28 20:59:57 +00:00
Patrik Polakovič
a1c7d0828a Fedora 42 is now End Of Life
Signed-off-by: Patrik Polakovič <patrik@alphamail.org>
2026-05-28 20:33:06 +02:00
e73d603bd2
Nagios: remove SSH monitoring, Zabbix does it
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 17:18:50 +01:00
f3a05e1b72
Zabbix: Fix cronjob that generates the SSH target list 2026-05-28 17:18:50 +01:00
f29d91d7af
forgejo: runner config not being passed to the openshift secret
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-28 13:40:44 +01:00
641887c8cf
Zabbix: also test SSH access to the bastions from Batcave
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:36:04 +01:00
de6e36a4e5
Nagios: Remove PostgreSQL checks that we already have in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:28:04 +01:00
e104755e4e
Zabbix: fix DNS perf units, and regexp record trigger
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:20:09 +01:00
9e3cd9d4ff
Zabbix: Move DNS checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:12:00 +01:00
Jakub Kadlcik
e537215abc copr-dist-git: move sentry configuration to the correct config 2026-05-28 12:40:26 +02:00
44951845e4
Zabbix: remove incorrect run_once directives from proxy monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:33:34 +01:00
69612dffe5
Zabbix: Add the rest of the previous commit that got missed
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:30:27 +01:00
e3d9be210e
Zabbix: Move internal proxy checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:08:35 +01:00
bc2f608f4c
Zabbix: add trigger for one-off httpcheck items
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 09:44:55 +01:00
c0d5169f58
Zabbix: remove some unused checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 09:37:45 +01:00
Jan Matufka
d77168ff0c logdetective: service, dependency on nvidia-cdi
- for persistent deployment

Signed-off-by: Jan Matufka <jmatufka@redhat.com>
2026-05-28 08:15:50 +00:00
Jan Matufka
2e2abbedac nvidia-cdi: create a role
Signed-off-by: Jan Matufka <jmatufka@redhat.com>
2026-05-28 08:15:50 +00:00
993e600700 badges: fix image trigger annote order on deploy metadata
Similar to infra/ansible#3338

Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-28 11:38:57 +05:30
b8773db5ba Move the Fedora Badges static assets from Pagure to Forgejo
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-28 02:22:21 +00:00
7b4f3b4182 update location of fedocal to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 12:04:48 +10:00
c796a888d2 update location of fedora-packages-static to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 11:32:32 +10:00
eb0de86f9a update location of elections to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 09:39:52 +10:00
26402546de update location of cloud-image-uploader to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 08:59:27 +10:00
bbf9258578 memcached02 (rhel9) retirement
We switched over to the rhel10 versions of these, so these are going
away. Thanks for your service!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-27 13:48:59 -07:00
50559f83d7 memcached: move to new rhel10 instances
This moves all the applications that are using memcached to point to
the 01 (rhel10) versions intead of the 02 (rhel9) ones.

After pushing this, I will roll the changes out in staging and confirm
everything works, then do production. In the event of problems will roll
this back.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-27 12:37:23 -07:00
0baaabd735
Prepare W2FM in staging for Pretix
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 16:56:14 +02:00
2b6ddca8f4
forgejo: update README for runner config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-27 12:26:41 +01:00
1ffd0cd8a5
forgejo: Redesign runnerconfig
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-27 11:47:55 +01:00
068605d67d
Fixup 814582dc: actually use the imagestream.yml file
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 11:52:51 +02:00
f2c2aa037b forge: add group team mapping for atomic
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-27 19:44:39 +10:00
814582dc4d
Rebase webhook2fedmsg to python 3.13
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 10:41:13 +02:00
70cfd1412e memcached01: use correct ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:38:05 -07:00
ccb89c99a4 memcached01: add a new prod memcached01
Once this is all setup we can switch to it and retire the rhel9 02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:26:22 -07:00
7268404db7 memcached01.stg: add properly to stg group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:06:58 -07:00
7e226ba150 memcached_stg: increase disk size
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:48:00 -07:00
f8fbb98eda memcached01.stg: add a new rhel10 staging memcached
Once this is up and working, we can switch applications over to using
it, and retire the rhel9 one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:38:28 -07:00
3ac21c8018 tang02: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:00:47 -07:00
31c695a70f tang01: increase disk size a bit
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 13:58:04 -07:00
03dec33fd8 tang01: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 13:53:03 -07:00
1680d35e63
Move more http checks to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 17:10:43 +01:00
0d3e126317
Zabbix: Fix item typo and add another check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:39:21 +01:00
6ed762bb29
Zabbix: use regex instead, more flexible
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:22:13 +01:00
8d40668907
Zabbix: Add some basic non-host HTTP checking to zabbix01
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:13:50 +01:00
7e5a64efdc
Zabbix: fix typo in template macro
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 13:50:58 +01:00
6cfda2b8f5
Zabbix: move http-koji checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 13:44:59 +01:00
137626c637 forge: fix yet asnother typo in DEFAULT_ACTIONS_URL config
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:54:39 +10:00
f68ab813be forge: fix typo in DEFAULT_ACTIONS_URL
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:26:37 +10:00
90cc0bee98 forge: set DEFAULT_ACTIONS_URL to forge.fp.o
resolves: forge/forge#557

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:16:47 +10:00
749c16501f forge: add forgejo.org to migrations whitelist
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 13:02:46 +10:00
f4ca07caf7 forge: add group team mapping for actions org
related: forge/forge#557

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 12:36:17 +10:00
004fb438fe
Badges: the frontend needs its own OIDC client
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 10:07:57 +02:00
2e63ef6b72
Badges: adjust the oidc callback URL in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 09:31:18 +02:00
7ed0a93f2a forge: add group team mapping for DEI mentor summit team
related: forge/forge#589

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-25 12:52:18 +10:00
40fe2bfc69 fix syntax error
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-23 09:51:54 -07:00
7b21d2756f communishift: add some projects
This will add release-schedule-planner ( 13336 )
and draft-share ( 13358 )

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-23 09:49:35 -07:00
885651a7a7 bodhi-stg: fix valkey unixsocket
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:11:26 +02:00
c46879dc54 bodhi-stg: fix valkey logfile
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:07:47 +02:00
b5eddd80ea bodhi-stg: cannot use --include to override valkey conf
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:01:41 +02:00
481443b92f bodhi-stg: use valkey cache
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 10:41:49 +02:00
16642a1d02
OK, it works, apply them to prod pagure.io too
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-22 17:03:44 +02:00
05eb12595e
Apply hotfix patches to pagure.io too (staging for now)
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-22 16:44:18 +02:00
4140b2cdfd resultsdb-ci-listener: update for upstream Forge migration
The upstream app migrated from Pagure to Forge. Update references
here.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-21 15:51:34 -07:00
f05fbe3876 dedicatedsolutions01: drop from inventory in favor of 02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 13:30:15 -07:00
d60806aca0 ns05: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 13:10:36 -07:00
98c6cae22b ns01: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 12:45:37 -07:00
0595b45e39 pagure-stg: fix dns search order to fix certgetter01 access
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 11:28:03 -07:00
5887d43751 mirrormanager / mirrorlist_proxy: add explicit Host: to header in checks
In newer curl, not specifying Host: here means it emits a warning:

Warning: The provided HTTP header 'mirrors.fedoraproject.org' does not look
Warning: like a header?

So, specify Host: for the header so it works on both old curl and new.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 10:39:45 -07:00
4908f3bea7
Yet another forgotten thing for badges
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:59:00 +02:00
8cd135b4bd
Fixup 26b81b3
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:57:39 +02:00
fad66f712e
Add a patch to pagure, based on PR 5553
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:17:31 +02:00
26b81b373d
Rebase Badges on python 3.13 (from 3.10)
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:16:38 +02:00
331eae63d7
Nagios: remember to remove deleted ssl.cfg file from task loop
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 11:21:47 +01:00
5d331ca6e3
Zabbix: port remaining SSL checks over from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 11:07:10 +01:00
1c6dded5bb
Nagios: remove more things we already have in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 10:32:22 +01:00
f2759cb8b2 forge: add group team mappings for pungi org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-21 10:10:12 +10:00
2d24211424 ns03: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 15:34:38 -07:00
4262b3610f dns: only set crypto-policy on rhel9 dns servers, 10 does not have that policy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:44:21 -07:00
1963b068d3 Switch epel10.repo and rhel10.repo to use a link to latest
There's no super right answer here, but if we point to a specific minor
release here it means we have to move all machines to it when we change
it, and we have to remember to do so.

If we just use '10' and depend on the link that points to the latest
minor:

lrwxrwxrwx. 1 root root    4 May 19 17:12 /srv/web/repo/rhel/rhel10/10 -> 10.2/

then we don't have to keep changing this all the time, it will just
update when that link changes.

This doesn't leave us an easy way to keep some hosts back to the old
minor, but in practice we pretty much never do this anyhow.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:31:53 -07:00
60e48fd441 ns02: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:27:17 -07:00
5e7b40087d proxy11: since we are doing a new install, try f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:35:56 -07:00
a5eb828847 release-monitoring: move back down to 1 web pod, seems to have caused duplicate comments on bugzilla bugs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:34:25 -07:00
cf52816027 proxy11: move to using normal volgroup name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:33:41 -07:00
9ffb23bb35 release-monitoring: scale web pods to 3 by default
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 08:55:52 -07:00
44bc3548f0 proxies: add ip that is generating a large number of 404s on mirrorlists
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 08:14:31 -07:00
688720342e [mailman3] Fix the patch file
Posix patch doesn't really like the git fake directories.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:18:41 +02:00
13c1dd27d9 [mailman3] Use the correct path to file
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:15:18 +02:00
8f12b3c681 [mailman3] Fix index not being rebuilt
The index build was failing on xapian_haystack issue that happens when
the mail is too long. This patch will skip those e-mails. See
infra/tickets#13355 for more info.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:07:17 +02:00
Jakub Kadlcik
c33602daf4 copr: high performance builder for karlinator/texlive-2023
Fix https://github.com/fedora-copr/copr/issues/4319
2026-05-20 09:57:24 +02:00
0ea1c9f292 quality: update testdays app builder to python-312 2026-05-19 16:05:42 +00:00
8fbab7e5b3 quality: update testdays app builder to python-311 2026-05-19 16:05:42 +00:00
6e0f4fe7b0 Retire EPEL 10.1
Signed-off-by: Diego Herrera <dherrera@redhat.com>
2026-05-19 14:58:42 +00:00
0723ffa45d
Zabbix update SSH and Varnish templates
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-19 15:31:40 +01:00
9faab10da6 proxy11: the vg here is named differently, but too much hassle to reinstall
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:57:15 -07:00
b0f0cbde39 proxy11: move over to dedicatedsolutions02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:55:19 -07:00
ee21c8afc6 dedicatedsolutions02: add new host
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:20:17 -07:00
2df5c98d16 smtp-mm-iso01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:38:57 -07:00
944efaf34f smtp-mm-osuosl01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:28:38 -07:00
a5d7291edc base / nftables / kojibuilder: allow sign-bridge access for all builders in the secureboot group, not just x86-02/a64-02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:24:12 -07:00
0ae3392198 smtp-mm-ib01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 14:53:10 -07:00
d4c013129a kickstarts / rhel10-nohd: drop rdp as it is not implemented in rhel 10.1 kickstarts as far as I can tell
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 12:42:54 -07:00
1aac9b0c7b kickstarts / rhel10-nohd: switch to rdp, vnc is no longer available in 10.1
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 12:07:43 -07:00
917e6f4f5c Zabbix: Migrate SSH connectivity checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-18 14:46:05 +00:00
4cf99e088a
fix(proxies): add www.fedoraproject.org back
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-18 09:14:27 +02:00
4e24b694b4 kickstarts: rhel10: use https for all the urls
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-17 12:18:58 -07:00
51081991be buildhw: install pesign_bridge on all secureboot group members
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 12:30:12 -07:00
442852923d fix: fix the annoying HTTP authentication popup on windows (prod)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:15:51 +00:00
af80a6a3a0 secure-boot: clean up old bkernel role and add 2 more builders
We are no longer using the bkernel role (using the old card thats in
buildhw-x86-01), so this removes that role and mentions of it.

Also, because we are urgently building kernels all the time now,
add one more buildhw-x86 and one more buildhw-a64 to secure-boot channel
so we can build more/faster kernels.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 19:14:17 +00:00
73dc88c487
fix: fix the annoying HTTP authentication popup on windows (stg only)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:23:41 +02:00
6ccaaca78d proxies: adjust zabbix template name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 09:57:39 -07:00
7688d6da70 proxies / website: on src/koji/riscv-koji have POSTs bypass anubis
See infra/tickets#12913
and https://github.com/TecharoHQ/anubis/issues/1624

We are seeing sporadic EOF errors when koji/src/riscv-koji send a 200
reply back through anubis.

Since we just allow POST in anubis anyhow, bypass it entirely for them
to avoid the EOF issue until we can sort it out more.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 16:39:05 +00:00
623214b0c9 maubot: apply hotfix to maubot to fix __provides__ issue
related: infra/tickets#13347

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-15 20:11:26 +10:00
1bde47906f firmitas: move from t0xic0der/firmitas-test to playground/firmitas-test
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-15 08:23:41 +05:30
68315a2324 s390x-test01: should be in cloud group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-14 13:11:41 -07:00
977a470510 s390x-test01: add s390x maintainer test machine
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-14 13:07:30 -07:00
4998b94fce
Zabbix: Migrate CountMe file-age checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 16:26:14 +01:00
4be7c97ff1
Nagios: Drop proxy mirrorlist & ostree file-age checks, migrated
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 13:39:54 +01:00
d47a991333
Zabbix: Add proxy file-age checks for ostree & mirrorlist cache
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 13:28:16 +01:00
6bdcf23ac7 firmitas: fix the missing variable ansible error
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-14 14:57:11 +05:30
4d2aa5527b firmitas: support ticket creation on forgejo instead of pagure
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-14 14:04:52 +05:30
8b477bcc0a kickstarts / rhel10: install selinux-policy-extra in all cases, needed for epel packages
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 17:21:32 -07:00
cf60e5fab5 kickstarts / rhel10: just point all the rhel10 kickstarts to the latest rhel10, not 10.0
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 16:27:57 -07:00
0d8779bc60 debuginfod: are now both f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 11:11:18 -07:00
c14a9c63af oci-registry01: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:55:15 -07:00
a38aeeab1b oci-registry02: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:34:46 -07:00
ce30489068 oci-candidate-registry01.stg: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:01:00 -07:00
acc8549a10 download-ib01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 09:34:23 -07:00
f838451f81 download-iso01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 09:11:29 -07:00
ebb316eedd
forgejo: Update runnerhost vm template with subdomain/hostname
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-13 15:47:37 +01:00
6f91abc606 Add releng org in forge staging
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-05-13 16:29:58 +05:30
dd2e76880a dl01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:38:49 -07:00
4480adb270 dl02: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:24:38 -07:00
6533d2ae71 dl05: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:11:46 -07:00
8e461e50f5 dl04: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:55:25 -07:00
bb9984ec61 kickstarts / kvm-rhel-10: use the new 10.1 name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:40:06 -07:00
0986ae491b kickstarts / kvm-rhel-10: we need selinux-policy-epel to set things for epel packages
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:37:25 -07:00
eb0e697fab forge: add group team mappings for the fdwg org
related: forge/forge#559

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-13 09:35:45 +10:00
550aad5c29 forge: add group team mappings for R sig
related: forge/forge#545

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-13 09:34:03 +10:00
c7349dadea kickstarts / kvm-rhel-10: drop packages that do not exist in rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:23:32 -07:00
8c54ea4bad kickstarts: kvm-rhel-10: fix repo paths
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:18:25 -07:00
8f3def5c91 batcave01: also install the new kickstart template
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:01:51 -07:00
c55e6f0893 kickstarts: make a rhel10 kvm kickstart and have dl03 use it.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 15:59:45 -07:00
22f47d356a dl03: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 15:49:05 -07:00
db4f19c2ad oci-registry01.stg: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 14:37:24 -07:00
05b94d7029
Zabbix: Improve Postfix queue trigger/recovery
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 13:54:35 +01:00
55a7c1c9f9
Nagios: remove vpnclients check, migrated to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 11:13:44 +01:00
dfa0766cff
Zabbix: Improve vpnclients connectivity check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 11:11:46 +01:00
665456d9d9
Add buildhw-x86-14 to inventory groups
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 10:07:03 +01:00
83c42baccb
Add hostvars for buildhw-x86-14
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 10:04:48 +01:00
04e230408e copr-fe: no need to grant copr-fe db admin rights 2026-05-12 08:22:30 +00:00
4a68303c36 copr-fe: unix-socket-auth for postgresql 2026-05-12 08:22:30 +00:00
7923f145d9 fix typo in docs-archive group team mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-12 18:01:20 +10:00
d6d3a4db54 add group team mappings for staging atomic-desktops and bootc
related: forge/forge#546

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-12 17:47:34 +10:00
b641125564 proxies / redirectmatch / provisioning-server: I am not sure how this worked before, but it needs a regex
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 17:35:41 -07:00
76e322e65a koji / hub: try increasing the keepalive timeout here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 15:11:29 -07:00
0df0dc0ec9 proxies / koji: lower the keepalive on the proxy side
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 14:30:03 -07:00
274e23e336 proxies: set ttl on the anubis layer to 15 also to match up with other things
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:59:06 -07:00
645cfe0482 proxies: when using a apache balancer, options go on the balancer members
Clanker lead me astray here. We can't pass options on the proxypass here
because we are using a balancer, so we need to pass them on the balancer
members.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:57:42 -07:00
d59d39d281 proxies: more changes for the sporadic 502 issue ( 12913 )
I got claude to dig into the things we tried to fix this issue and look
for things we missed. It found a few things:

1. In commit 35a1b3223b Victor Koycheff added some proxyopts for
   keepalive, etc. However, unfortunately, while the variable was set
   the template wasn't looking at that, so they were never actually
   set in the website. ;( So, we fix that by passing the variable in the
   right template here.

2. kojihub didn't have a keepalive set on the backend. (but this is
   likely cosmetic since the problem is at the proxy layer). We fix
   this by adding one anyhow.

3. The pass thru anubis didn't have keepalive set right, so we do
   that in the template. This may fix other 502 issues with other
   applications also.

Calude used 57,508 tokens looking at all this. ;)

Assisted-By: claude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:09:55 -07:00
James Antill
28c056c4f7 people: Use ProxyPassReverse to rewrite redirects, and remove the port.
Signed-off-by: James Antill <james@and.org>
2026-05-11 13:43:38 -04:00
James Antill
6ef4d3c158 wiki.stg: Update to F44. 2026-05-11 13:43:33 -04:00
7ce80fab53
zabbix: debugging connections to agents
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 18:00:34 +01:00
a0b48d31b8
zabbix: update internal dns name to match correct value
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:57:29 +01:00
269c4fd64d
zabbix: configure agents to use internal dns for proxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:51:41 +01:00
7dad780f04
zabbix: debugging agent/proxy config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:29:54 +01:00
299e2e4005
zabbix: configure git checkout step to force
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:11:32 +01:00
035be95c3f
zabbix: configure openshift based agents config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:10:12 +01:00
850e51c1db
zabbix: debugging encryption config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:44:51 +01:00
769ffc446f
Add OpenVPN connectivity check & triggers to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-11 16:38:08 +01:00
eef6c7bc89
zabbix: enabling ZBX_TLSCONNECT on proxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:30:17 +01:00
d1595d1420
zabbix: update the task to checkout correct helm chart
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:24:20 +01:00
c3b29e947c
zabbix: fix typoes in template
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:18:27 +01:00
c098712064
zabbix: fix typo on helm values template.
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:16:24 +01:00
0b9ff51e27
zabbix: playbook to deploy the zabbix proxy in openshift
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:04:35 +01:00
9806794f83
zabbix-proxy: tls config for openshift based zabbix-agents
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 15:54:05 +01:00
418cca4d57
communishift: clean up project group vars
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:52:34 +01:00
06d732888f fix bodhi-valkey deployment again
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:40:06 +02:00
1371eae7b6 fix bodhi-valkey deployment
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:38:10 +02:00
c844df0cfb bodhi-stg: use Recreate strategy for bodhi-valkey
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:35:56 +02:00
d02937cc70 bodhi-stg: add bind setting to valkey call
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:30:16 +02:00
d99f6f030e
communishift: debugging efs config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:10:35 +01:00
2002267fcb
communishift: helper script for cleaning up removed group_vars projects
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:02:50 +01:00
d9aef74a12 bodhi-stg: update to F44 and install valkey-cli
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:55:20 +02:00
fc3816c7fe bodhi: fix duplicated setting in stg
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:48:01 +02:00
22005ff136 bodhi-stg: fix valkey conf
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:42:03 +02:00
9c2eeb276d bodhi-stg: redirect valkey log to stdout
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:38:26 +02:00
c6704f92dc
communishift: added cleanup playbook cleanup-administration-delete-projects.yml
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 12:27:28 +01:00
6b9752397d bodhi-valkey: change liveness timeout
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 10:13:14 +02:00
6812986bef bodhi-stg: use f44 for bodhi-valkey
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 10:09:30 +02:00
ec82c78f22 bodhi-stg: add secret definition
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 09:39:07 +02:00
8c28aba425 mdapi: fix image trigger annote order on deploy metadata
The `image.openshift.io/triggers` annotation was on the pod template metadata
instead of the deployment metadata, so OpenShift's image trigger controller
never detected ImageStream updates for auto-rollout.

Basically, when the MDAPI playbook was re-executed after the repository
`fedora-infra/ansible` was moved from Pagure to Forgejo, we have not had even
a single rollout, even with all the image builds.

Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-11 02:37:12 +00:00
ce9d8b3899 bodhi-valkey: use fully qualified image name
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 21:13:08 +02:00
4517eb2ed5 bodhi-stg: fix pvc template filename
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 10:29:20 +02:00
06fc965500 bodhi-stg: define bodhi-valkey-storage pvc
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
AI-assisted-by: Claude (Anthropic)
2026-05-10 10:18:34 +02:00
a58b8699ea bodhi-stg: remove docker entrypoint
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
AI-assisted-by: Claude (Anthropic)
2026-05-10 09:53:29 +02:00
5278566736 bodhi-stg: define bodhi-valkey image stream
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 09:27:57 +02:00
2dc6e6ec68 bodhi-stg: add a valkey pod
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 07:07:51 +00:00
72f01c98a7 amqp: Add queue for ELN->CS sync
This will be used for setting up automatic syncing of ELN builds into
CentOS Stream.

Fixes: infra/tickets#13226

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
2026-05-08 18:40:56 +00:00
ec0c9ed220 pkgs: allow access to archive of git repos fixed for fsck issues
See releng/tickets#11822
for background

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:56:17 -07:00
ef1592400d packager_alias: use lmdb for aliases
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:38:09 -07:00
511f16d9d6 base / postfix: fix handlers for postfix maps to use lmdb
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:22:29 -07:00
8ede1564c8 smtp-mm: add a fedoraproject transport to use the vpn
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:13:03 -07:00
ac4774b57e ipsilon01.stg: move to fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-07 15:58:13 -07:00
20428c57ee certgetter01: move to fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-07 15:47:10 -07:00
5d88d1abb3
Nagios: remove Varnish/HAProxy items, these are already in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 14:54:15 +01:00
c8abf8630e
Zabbix: move more http-* checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 14:21:51 +01:00
51e4282ff7
Migrate http-* proxy checks from Nagios to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 13:53:39 +01:00
1d53d6dd5a copr: do the powerful builds only for selected arches 2026-05-07 10:22:28 +02:00
9af0fa359e copr: more packages to powerful builder 2026-05-07 10:09:16 +02:00
b173990a47 resultsdb: specify correct registry to get image from
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 13:49:13 -07:00
565a59722b resultsdb / resultsdb-ci-listener: convert from deploymentconfig to deployment
This moves these two apps from deploymentconfig to deployment.

Assisted-by: calude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 20:37:07 +00:00
10ad96ad9d copr: more packages to powerful builder 2026-05-06 21:24:54 +02:00
e6491b5cba
communishift: Send email notification when disabling projects
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-06 20:11:29 +01:00
e4321ec9c3
communishift: Disable project playbook
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-06 19:58:48 +01:00
09af2093f5 bodhi / backend: quote tokens in sokpeo auth file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 11:06:54 -07:00
5b3385240a Update openqa Fedora release versions in host vars
Note I live upgrade these systems, so they've actually been on
F43 for months. This is just making the vars reflect reality (and
fixing it so if we do redeploy them, we deploy the right release).

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-06 10:45:09 -07:00
587aa356d0 fix: fixing metrix values for forge helm
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-05-06 16:52:07 +02:00
cc862368dd feat: add metrics for forge stage
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-05-06 16:09:21 +02:00
27e3392a20 Improve ansible-lint
Why ignore the hardcoded paths, let's just create symlink, so they are
found as they should be.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 13:16:59 +02:00
85f227197c [bodhi] Add missing vars file to playbook
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 11:46:34 +02:00
3d39e9ed5a ][bodhi] Update the bodhi version
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 09:34:23 +00:00
621d586acc [bodhi] Update for quay.io flatpaks
This adds authentication file for flatpak quay.io bots and also adds
quay.io to `container.destination_registry`.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 09:34:23 +00:00
ba172de77e roles/bodhi2/pungi: Update config_url with new forge location
See: https://forge.fedoraproject.org/atomic-desktops/config.git
2026-05-05 23:56:55 +02:00
49bec86025 blockerbugs: drop unneeded variables after Pagure->Forge migration
Related: quality/blockerbugs#296
2026-05-05 20:47:25 +00:00
0d4d72dadf blockerbugs: drop a "short-term patch" after 5 years 2026-05-05 20:47:25 +00:00
15a6768ad7
Zabbix: Update IPA template to include healthcheck items/triggers
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-05 15:01:16 +01:00
72baeea321
Add a patch for Pagure
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-05 11:51:48 +02:00
0506d3a645 [postfix] Obfuscate the IP on smtp-auth server
This will update configuration to clean Received header from e-mail
forwarded by smtp-auth-iso01 server to prevent leaking of internal IPs.
See infra/tickets#12835

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-05 07:52:05 +00:00
Nikita Dubrovskii
66580813a6 coreos-ci: add azukku as appowners 2026-05-05 07:37:33 +00:00
54db5a3f4a forge: add group team mappings for the hummingbird org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 14:39:29 +10:00
40060e7e88 forge: add group team mappings for the matrix org.
resolves: forge/forge#537

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 14:14:41 +10:00
b0f1e9a91d forge: add group team mappings for the magazine organization
related: forge/forge#551

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 13:40:09 +10:00
1bdd2c4529 ai-review: set include_mr_summary false for shorter reviews
This sets a config option that gets ai-code-review to generate
shorter review text. It skips the MR Summary section and just
posts the Detailed Code Review section.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-04 14:02:53 -07:00
a00af9f5cd openshift: adjust rollout in playbooks for deployment instead of deploymentconfig
Since we have moved (almost everything) to deployment, we need to adjust
adjust these rollout commands to use deployment instead.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:39:23 -07:00
cc8e259360 compose-tracker: move stray playbook to the right place
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:20:20 -07:00
d0a17fb7cf compose-tracker: move to deployment from deploymentconfig
This is another pull to move compose-tracker from deploymentconfig to
deployment.

Assisted by: claude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:12:54 -07:00
81e1871023 waiverdb: add env to db-upgrade container
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:02:27 -07:00
e3e74bc722 waiverdb: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-04 19:57:20 +00:00
e86df4d91b waiverdb: moved deploymentconfig.yml.j2 to deployment.yml.j2
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-04 19:57:20 +00:00
Jakub Kadlcik
ea2f954a44 copr: fix the Pulp redirect script for devel repositories
We dont have a ticket but the problem was discovered on the @asahi/kernel
project and reported by @jannau. The use-case is

> We use the devel repositories for fedora asahi remix to have a bodhi like
> experience for copr projects

and technically, they enable the repositores on user machines like this:

26cab83/f/asahi-repos.spec (_149-160)
2026-05-04 19:00:31 +00:00
42e605c499 fmn: try adding a emptydir for redis data
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 07:56:57 -07:00
85b073eda1 [ipsilon] Remove ipsilon03 VM
This is an OpenID VM and this is done as part of
infra/tickets#13265

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 14:47:54 +00:00
bbdd8c7b1f Revert "fmn: use the correct place to define the correct image"
This reverts commit 5293ff4fcf.

ok, this wasn't it.
2026-05-04 07:47:44 -07:00
5293ff4fcf fmn: use the correct place to define the correct image
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 07:45:40 -07:00
6e02c3d79d Revert "fmn: use the _right_ redis image"
This reverts commit 6e50e5d9b8.
2026-05-04 07:44:26 -07:00
6e50e5d9b8 fmn: use the _right_ redis image
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 07:42:30 -07:00
086414024f fmn: try and set the redis password for fmn on the redis pod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 07:39:20 -07:00
c03a11f09c [haproxy] Don't remove default_backend for ipsilon
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 16:08:04 +02:00
f6b50eb89c Remove OpenID from Fedora
This change will remove routing and configuration for OpenID in Fedora.
Which was originally announced to sunset on 1st May 2026.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 15:34:39 +02:00
1250c0d961 Fix ansible-lint forgejo action
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 15:20:04 +02:00
Jiri Kyjovsky
c4f2fcfeff copr-ibm: less workers per location 2026-05-04 10:39:17 +02:00
d9f9f04d3d copr: add one reserved powerful builder 2026-05-04 10:03:47 +02:00
21f9d92f8a copr: enable powerful builders for firefox and thunderbird 2026-05-04 09:53:04 +02:00
412125fdcb
Fix image location
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-04 09:28:15 +02:00
18dc8053f7
Move mirrormanager to the Python 3.14 image
The Python 3.11 image is no longer updated on quay.io

Fixes: infra/tickets#13300
2026-05-04 09:24:15 +02:00
James Antill
451ce29956 people: Fix user pages, but break redirects again.
Signed-off-by: James Antill <james@and.org>
2026-05-03 21:25:13 -04:00
James Antill
15eb15bdaf people: Fix main page, copying DocRoot. Also copy the other ServerAliases.
Signed-off-by: James Antill <james@and.org>
2026-05-03 20:46:23 -04:00
James Antill
c635e5ec5c people: Fix redirects after anubis using ServerName, as reqs come in weird.
Signed-off-by: James Antill <james@and.org>
2026-05-03 11:24:44 -04:00
James Antill
6545b1b177 people: Fix redirects after anubis.
Signed-off-by: James Antill <james@and.org>
2026-05-03 11:02:13 -04:00
James Antill
ab631bed2e Merge branch 'upstream' into HEAD
* upstream: (551 commits)

Signed-off-by: James Antill <james@and.org>
2026-05-02 20:02:18 -04:00
c16b2932db testdays: switched to deployment
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 10:28:55 -07:00
4b6c24f76a bodhi: also adjust the service selectors
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 10:08:47 -07:00
830d4d5560 bodhi: try and standardize the app names and also adjust playbook for deployment instead of deploymentconfig for scaling
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 10:06:44 -07:00
ad19395d7b bodhi: qualify imagestream location
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 09:57:32 -07:00
83a1f1393c Revert "bodhi: adjust selectors"
This reverts commit 91a49488ae.
2026-05-02 09:54:36 -07:00
91a49488ae bodhi: adjust selectors
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 09:48:36 -07:00
1fa8aa6700 bodhi: moved deploymentconfig.yml to deployment.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-02 16:45:56 +00:00
36218c17e2 bodhi: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-02 16:45:56 +00:00
b5de39dc82 noggin-centos / noggin: use object_os_app name for image stream namespace for nogin vs nogin-centos
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-02 09:39:58 -07:00
11a7d7adf0 noggin: fix deployment reference in noggin-centos playbook
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-02 16:31:36 +00:00
James Antill
2d9bf1de3c Merge branch 'upstream'
* upstream: (540 commits)
  release-monitoring: fix selector for web
  ...
2026-05-02 11:38:19 -04:00
3c46c0c543 release-monitoring: fix selector for web
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 12:46:03 -07:00
d68317c6a4 release-monitoring: moved deploymentconfig.yml to deployment.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:41:00 +00:00
eb71459da1 release-monitoring: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:41:00 +00:00
b2483df5f6 fmn: specify local image for sendria
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 12:33:45 -07:00
447c746a80 fmn: fix some more labels
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 12:30:34 -07:00
James Antill
3821ea36b5 Cleanup nft merge. Chg osbuildapi and nft_custom_rules to use nft_table_filter.
Signed-off-by: James Antill <james@and.org>
2026-05-01 15:29:04 -04:00
89fc83945d fmn: switch to more generic label instead of service
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 12:23:33 -07:00
23f3a62dda fmn: adjust selectors and labels
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 12:18:07 -07:00
a19387aa22 fmn: moved deploymentconfig.yml to deployment.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:09:57 +00:00
63bfac6cc9 fmn: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:09:57 +00:00
6f7b1a7043 datanommer: moved deploymentconfig.yml to deployment.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:02:35 +00:00
7b4bae5003 datanommer: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 19:02:35 +00:00
140bbcc071 elections: drop unneeded selector on deployment label
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 11:56:51 -07:00
75fea49569 elections: fix deployment reference 2026-05-01 18:55:52 +00:00
a9d3b403bc elections: moved deploymentconfig.yml to deployment.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 18:55:52 +00:00
c6087306fe
communishift: communishift-standupbot marked do not delete.
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-01 18:25:12 +01:00
68cef3f2eb badges: fix namespace for images
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 09:48:17 -07:00
2cc4befb83 badges: fix more labels
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 09:41:20 -07:00
0f2dd689e0 badges: fix selectors and annotations
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 09:37:10 -07:00
ba88e1c63b badges: moved deploymentconfig.yml.j2 to deployment.yml.j2
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 16:32:44 +00:00
fe0f017ef6 badges: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-01 16:32:44 +00:00
James Antill
ba4470365e Merge branch 'main' into nftables
* main: (2174 commits)

Signed-off-by: James Antill <james@and.org>
2026-05-01 12:01:48 -04:00
James Antill
ae9230c37f Cleanup the nftables files, using includes.
Rename the tables to be cle_ prefixed/unique. This allows people to run
cle nftables and firewalld etc.

Signed-off-by: James Antill <james@and.org>
2026-05-01 11:27:07 -04:00
95ad158c84 webhook2fedmsg: drop deploymentconfig from service selector
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-01 08:21:20 -07:00
634a65bb02
Zabbix: Add cron+prometheus monitoring of ipa-healthcheck
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-01 14:18:00 +01:00
9f15813840
communishift: add ability to dry run notification sender
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-01 13:48:50 +01:00
7522b50a64
communishift: Print human readable list of projects once notification
emails sent

Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-01 13:37:37 +01:00
b1fca1e089
communishift: Update email notification with summary
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-01 10:43:28 +01:00
4a51089c2e flatpak-indexer: specify image more closely
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 15:31:43 -07:00
6fec16e4f7 flatpak-indexer: fix selector for new deployment
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 14:51:37 -07:00
da98985e99 flatpak-indexer: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:49:51 +00:00
a66483229f replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:49:51 +00:00
55fe803f4d add flatpak-indexer deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:49:51 +00:00
4c112ac0fe Removed playbooks of deleted ocp apps
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:39:56 +00:00
d985fb7631 Removed deploymentconfig files from ocp apps
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:39:56 +00:00
a41083cf70 webhook2fedmsg: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:33:18 +00:00
df68ebe1fa replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:33:18 +00:00
a2f297a82b add webhook2fedmsg deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 21:33:18 +00:00
6bd6eb6365 people: add directives to log real remote ip in logs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 14:26:08 -07:00
ec9984fcec people: add anubis el container to fedorapeople
Scrapers are hitting git projects really hard, so lets put this behind
anubis as well.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 21:05:13 +00:00
2dd39340ea people robots.txt: disallow all of cgit
There's a flood ATM. Dunno if the flood respects robots.txt, but
if it does this might help?

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-30 12:42:30 -07:00
Jiri Kyjovsky
262735fbd4 copr: remove comment about emulated s390x, but empty 2026-04-30 21:41:02 +02:00
Jiri Kyjovsky
9b08868901 copr: remove comment about emulated s390x 2026-04-30 21:21:27 +02:00
402b7e4b92 poddlers: adjust image path
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 12:20:22 -07:00
321968f756 poddlers: ok, try this for template expansion
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 12:07:37 -07:00
cc5d257675 poddlers: some more template/macro whitespace fixes
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 11:42:46 -07:00
Jiri Kyjovsky
f6d0fec7f2 copr: bring back s390x 2026-04-30 20:31:41 +02:00
c4a4634f49 poddlers: add blank line in volumes for spacing and drop whitespace cleanup in cleaning-packager-groups toddlers
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 11:20:27 -07:00
64045f79bf poddlers: try and not pass {} in the block
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 11:16:02 -07:00
2163e36fcc poddlers: try and set temp-volume to emptydir explicitly
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-30 11:07:26 -07:00
0adc18a9b8 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 17:57:50 +00:00
9f4fc542e4 add poddlers deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-30 17:57:50 +00:00
85b34d77e8
Zabbix: add missing Varnish tag to Zabbix task
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-04-30 12:49:14 +01:00
03e682247a
Zabbix: add Varnish monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-04-30 12:43:05 +01:00
13f80f78db
DHCP: add p10-fco02 builder to the dhcp config
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-04-30 11:37:45 +01:00
b7551004fa
Zabbix: add some more macro overrides
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-04-30 11:37:27 +01:00
bc2bd50a06
Add another Ipsilon patch
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-04-30 10:12:30 +02:00
e56db32aa6 httpd/koji: set MaxKeepAliveRequests 0 to fix 502 race condition
This acts as the second half of the fix for the 502 Bad Gateway errors
on long-running koji connections.

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-04-30 00:54:13 +00:00
9d9edc9658 proxies-reverseproxy: set keepalive=on ttl=10 for koji
This fixes intermittent 502 Bad Gateway errors during long-running
koji connections (like watch-task or watch-logs).

For more details on proxy keepalive and ttl, see:
https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-04-30 00:54:13 +00:00
2b8fecb1f7 openshift: disallow users self-provisioning
We don't want authenticated users being able to self provision projects
in our clusters. We only want that to happen via ansible.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 17:49:41 -07:00
d5c4b09e6e buildvm-a64 staging: move to fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 17:34:14 -07:00
d6e7adc201 dhcpd: bvmhost-a64-01.stg: other interface is the provision one
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 16:06:24 -07:00
8d7f48967d koji: tell policy scratch is a bool for testing
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 15:29:31 -07:00
3066851c81 kickstarts / aarch64 / rhel10 / bvmhost-a64-01.stg
Add a 6 nvme rhel10 kickstart for aarch64 machines.
Set bvmhost-a64-01.stg to use it's 10G interface for provisioning now.
(I fixed it to allow pxe booting).

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 21:53:29 +00:00
ce89bf1cc9 koji hub: move packit scratch builds to ci channel
We don't want to move all packit builds, because it does a lot of
official builds for maintainers. Instead, we want to just move the
scratch builds over to the ci channel.

See: infra/tickets#13069

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 21:48:27 +00:00
384f14c337 🐛 roles(fasjson): Remove spaces after commas in email alias definitions
Some email aliases defined in `aliases.static` used a mix of formatting:
some entries separated recipients with ", " (comma-space) while others
used "," (comma only). The inconsistency may cause recipient resolution
failures if the MTA interprets the leading space as part of the alias
name during expansion.

Normalize all alias recipient lists to use comma-only separation,
matching the format already used by the majority of entries in the file
(e.g., `matrixadmin`, `swag-info`). This brings the following aliases
into alignment:

* codeofconduct
* flock-coc
* flock-staff
* legal
* sponsors

If this resolves delivery issues, the root cause was whitespace-
sensitive alias parsing. If not, it at least eliminates one variable and
standardizes the file format for future troubleshooting.

Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-04-29 21:42:06 +00:00
5cfb5141ab mirrormanager: remove stray deploymentconfig call
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 14:10:28 -07:00
720e354f99 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:42:31 +00:00
a633985c58 add mirrormanager deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:42:31 +00:00
9d6c4314b3 noggin: no need to add deployment selector here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 13:32:29 -07:00
23cd904a0b noggin: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:29:20 +00:00
ac9d0a62ed noggin: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:29:20 +00:00
4384f5150d replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:29:20 +00:00
dce2333bb1 add noggin deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-29 20:29:20 +00:00
aaa3c9403f Add buildhw-x86-05/06/07
These are all old iad2 hardware we want to add as builders.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 17:39:29 +00:00
76f7751d11 downloads: add osuosl mirrors to acls
These osuosl mirrors want to get pre bitflip content, so add them to
acls here.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 10:25:29 -07:00
84f0b9db1e public-db-copy: we no longer have pkgdb2 database/app
This db is no longer used/copied/needed.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 10:13:15 -07:00
06dfffb772 Fedora 44 is released, we are out of freeze
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 10:12:11 -07:00
37638d9289 proxies: drop www.fedoraproject.org for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-29 10:11:45 -07:00
James Antill
3e0e89ba7f riscv-koji: Permanently increase mem_size/max_mem_size.
Signed-off-by: James Antill <james@and.org>
2026-04-29 12:16:42 -04:00
7c02c4570f copr-hypervisor: drop unused argument 2026-04-28 19:03:28 +02:00
8c5923e123 copr-hypervisor: avoid using vol-upload to avoid FD leaks
Per discussion with @pkrempa it seems that it's anyway a good idea to
upload this way, as scp is faster (we avoid many io layers).

Relates: https://redhat.atlassian.net/browse/RHEL-170773
2026-04-28 18:46:47 +02:00
43a7a9e0fe proxies / gnome-software: move f44 to active
This should be pushed tomorrow morning after release at 14utc.

It will tell gnome-software to start offering dist upgrades to users.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-28 14:12:53 +00:00
7ec4975ead
forgejo: Update runnerhost configuration with zabbix agent configuration
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-28 11:26:20 +01:00
b0415adc16 blockerbugs: remove deploymentconfig from playbook
Oops, we should have done this along with deleting it.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-28 06:06:21 +00:00
70013ca384 forge: set AUTO_WATCH_NEW_REPOS to false
resolves: forge/forge#529

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-28 13:31:17 +10:00
3357c380dd blockerbugs: remove deploymentconfig
We want to use deployment, and jskladan claims he's already done
the migration:
infra/tickets#12142 (comment)
let's remove deploymentconfig to avoid confusion.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-27 09:38:07 -07:00
59704e4da7 blockerbugs: add Forgejo vars to deploymentconfig as well
I can't tell for sure, but I suspect if both deploymentconfig
and deployment are present, deploymentconfig is used, so we need
the vars here as well as deployment.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-27 07:48:21 -07:00
Paul Whalen
d9e17ab93c IoT: sign stable with f44 key
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-04-27 14:29:43 +00:00
ad8ed9ef8a forge: add group team mapping for dotnet org
Related: forge/forge#533

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-27 13:42:43 +10:00
6e36c38c7c Fedora 44 is a GO
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-04-24 15:21:12 +05:30
15928472b0 copr-be: temporarily override fedora-eln mock config
https://github.com/rpm-software-management/mock/pull/1747
2026-04-24 08:28:37 +02:00
0374476671 Apply restrictive robots.txt to riscv-koji
This is the same file used on primary koji. It disallows robots
instead of just asking them to slow their roll like the default
robots.txt does.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-23 13:06:03 -07:00
471fb7d3c2 Put riscv Koji behind anubis
it's getting spammed by scrapers ATM. This follows the prod Koji
config as best I can: koji is always behind anubis, kojipkgs is
behind anubis on external proxies, not on internal proxies.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-23 12:55:13 -07:00
36df8e0ac5 vmhost-x86-copr04 is down, let's not try to start VMs on it 2026-04-23 16:57:06 +02:00
583c76363d openQA: drop aarch64 concurrent workers to 45
We're just getting too many flakes on aarch64 tests. Let's see if
this helps.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-04-22 09:11:58 -07:00
cd5d720e6d copr-be: drop Power8 hypervisors from our configuration 2026-04-22 09:19:13 +02:00
Lenka Segura
e5bcb02c66 forgejo: Fix runner registration
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-21 12:59:14 +02:00
fa12d43951 copr-be: fix private key permissions 2026-04-20 16:28:39 +02:00
cea0a27b73 copr-be: pools: normalreserved => reserved 2026-04-20 15:21:34 +02:00
Jakub Kadlcik
6585e9506e copr-fe: oops, this needs to be in quotes 2026-04-20 15:10:52 +02:00
Jakub Kadlcik
f1fdd141c7 copr: configure SENTRY_DSN 2026-04-20 15:00:49 +02:00
a995494928 forge: update provenpackger team mapping typo
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-20 17:03:31 +10:00
40213164a9 forge: add group team mappings for the packager org
related: forge/forge#456

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-20 16:55:40 +10:00
7220447294 forge: add members team mapping for discussion org
resolves: forge/forge#449

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-20 14:36:55 +10:00
bce5f8bbc9 copr-hypervisor: reform things as a single list which the role expects
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 11:06:20 -07:00
53234bcece copr-hypervisor / x86: bind second and third luks devices
These machines have a /dev/md3 and /dev/md4 that are encrypted, but we
were only binding /dev/md2, so boots would wait for a passphrase.

This binds all of them (they have the same passphrase and can use the
same tang server they just need to be bound to do so)

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 11:03:03 -07:00
c8b087230d copr-hypervisor: fix mode on ansible calls
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 10:12:51 -07:00
1c688fe30e copr-hypervisor: fix syntax error
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 09:35:41 -07:00
f0de921632 copr-hypervisor: add serial-console role to x86 hypervisors
This sets up kernel and grub to provide a serial console, which
can be accessed via ipmitool.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 09:32:52 -07:00
b5e2300700 wiki: increase cpus to 16 to handle load
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 09:05:29 -07:00
b4858d172d Revert "proxies / wiki: disable RecentChanges for a bit"
This reverts commit b94e384d21.
2026-04-17 08:49:21 -07:00
b94e384d21 proxies / wiki: disable RecentChanges for a bit
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-17 08:27:22 -07:00
736b083568 copr-be: provide ssh key in config.iso drive for libvirt
This is the way to tell the instance's cloud-init what is the (currently
rotated) correct ssh pub key.
2026-04-17 15:31:41 +02:00
5c07c25ce1 copr-be: typo in root password setting 2026-04-17 14:43:32 +02:00
Jiri Kyjovsky
41b7cfdaf4 copr-hv: add symlinks for buildsys pubkeys 2026-04-17 13:44:04 +02:00
Jiri Kyjovsky
c53dd67f74 Revert "copr-hv: lookup for buildsys keys in backend role"
This reverts commit e9332887b4.
2026-04-17 13:33:21 +02:00
Jiri Kyjovsky
e9332887b4 copr-hv: lookup for buildsys keys in backend role 2026-04-17 13:17:50 +02:00
Jiri Kyjovsky
82e7f803a3 copr-buildsys: new name for copr builder pubkeys 2026-04-17 12:50:48 +02:00
7236e236ff copr: rotate buildsys SSH keys
Split the key for production / staging.  Drop the keys from hypervisors,
as we don't actually need them there (we copy images from backend ->
hypervisors these days, not from hypervisor to hypervisor).

Relates: https://github.com/fedora-copr/copr/pull/4221
2026-04-17 11:23:00 +02:00
James Antill
41da324268 ib01: sync exclude 44_Beta-1.1/1.2 for space.
Signed-off-by: James Antill <james@and.org>
2026-04-16 22:35:49 -04:00
42b2c57e66 copr-be: correctly define the macro override db location 2026-04-16 18:38:14 +02:00
Lenka Segura
cde0bea197 forgejo: let watcher fetch the vars
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-16 16:00:15 +02:00
48343d86c0 copr-be: download a cached variant of the macro database
We don't want to DDoS GitHub by our farm of builders (and get ban).
2026-04-16 15:42:40 +02:00
Jakub Kadlcik
f0279a9c35 copr-be: don't block @fedora-llvm-team anymore
The migration finished
2026-04-16 14:20:55 +02:00
Lenka Segura
d11d12061a forgejo: seed the forgejo vars file for the initial boot
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-16 13:09:10 +02:00
3ac5d6b344 [ipsilon] Remove ipsilon02.stg from inventory
With the decommission of OpenID we no longer need this machine on
staging. Let's get rid of it.

See infra/tickets#13265 for more details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-16 12:15:56 +02:00
5d9fc05269 Decommission OpenID on staging
This commit is a first step to decommission OpenID authentication on
staging. It doesn't do much as most of it needs to stay for production.
See infra/tickets#13265 for more info.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-16 09:48:46 +00:00
Jakub Kadlcik
1e35deb5f6 copr-be: there is a @fedora-llvm-team project currently in migration 2026-04-16 09:21:35 +02:00
7e0b6c5206 feat(poddlers): adding oicd token for plugins use 2026-04-16 00:38:58 +02:00
357edddb55 feat(poddlers): adding git config vars
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-04-15 23:12:55 +02:00
c8351d1fb9
communishift: seperate notifications from shutdown, added new playbook
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-15 18:12:28 +01:00
Lenka Segura
3febfa7233 forgejo: copy secret to the vm
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-14 16:21:04 +02:00
Lenka Segura
baef7ad4e7 forgejo: fix runner automation - wait for user to be creted
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-14 13:36:51 +00:00
44d37df386 Onboard happinesspackets project to communishift
infra/tickets#13238

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-14 15:22:21 +02:00
eead829551 forge: add team mapping for forge-dei-pride to team Pride
Related: forge/forge#514

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-14 16:50:37 +10:00
cb332fa8d3 forge-stg: add group team mappings for the quality org
Related: forge/forge#477

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-14 15:18:16 +10:00
15df3e5cdf proxies / wiki: add a tag to the reverseproxy role for wiki
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-13 14:00:49 -07:00
d281e4ad31 proxies / wiki: add another bot to being blocked
This bot seems to be hitting the wiki really hard.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-13 13:58:56 -07:00
b5f447cdcd proxies: allow websockets through anubis proxying for openqa
This worked in staging, so drop the staging conditional and just apply
it in prod too. It should allow websocket connections via the anubis
proxing.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-13 20:24:05 +00:00
c90ac8d9c6 Removed flask-oidc-dev playbook
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-13 20:23:14 +00:00
e53e8068ee replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-13 20:23:14 +00:00
4dfe5a9cc4 Removed ocp app flask-oidc-dev
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-13 20:23:14 +00:00
237df12258 proxies / staging: adjust conditional to actually apply to openqa.stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-10 12:26:46 -07:00
e9471dd3af openqa-lab: try and fix websockets via anubis
Re-enable anubis for openqa-lab01 and then try and pass it a proxy
statement to pass websockets correctly via the proxy.

disclaimer: claude pointed me in this direction.

Possible fix for infra/tickets#13252

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-10 12:08:54 -07:00
98625936dc
forgejo: Update VM post installation provisioning steps
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-10 18:01:36 +01:00
fdf359f407 Revert "copr-be: limit the number of builds in a single sandbox"
This reverts commit 514bb44914.

After the discussion with Copr team; 10 was too small, and was set just
for too long time period (originally it was a work-around for the lab
rdu-cc lab movement event).
2026-04-10 13:37:20 +02:00
Lenka Segura
b10ff0841d forgejo: enable linger and podman socket
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-04-10 09:21:33 +00:00
4f56817592 maubot: add c++, needed by python-olm. sheesh
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-09 14:29:19 -07:00
c3a03ca5ce maubot: add cmake, needed by python-olm
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-09 14:21:55 -07:00
7a94ae7b97 maubot: change imagestream as well to 43
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-09 14:16:24 -07:00
295c453c36 maubot: try moving to f43 in staging first and fix base image
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-09 14:13:26 -07:00
5c76b93fe1 maubot: try moving to f43 in staging first
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-09 14:10:44 -07:00
986c9821f3
📧 roles(fasjson): Use podcast FAS group sponsors for podcast@ alias
This commit changes how the podcast@fp.o email alias is configured.
Instead of a manually-curated list of FAS usernames in this config file,
instead, it will now use the FAS group sponsors of the `podcast` FAS
group. This allows a cleaner way of managing the permissions and not
requiring changes to config management to update the alias.

A FAS account admin will be needed for now to update the group sponsors,
but this can be done interactively or in a ticketed workflow with Fedora
Infrastructure Team.

In practice, this means the people who will now get emails for the
podcast@fp.o list are the current `podcast` group sponsors:

* @itguyeric
* @x3mboy
* @jflory7
* @jasonbrooks

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-04-09 11:30:46 -04:00
Jakub Kadlcik
2905efef5f copr: enable powerful builders for the @python/python3.X root
Fix https://github.com/fedora-copr/copr/issues/4256
2026-04-09 16:26:29 +02:00
b1ec37d30e forge: add group mapping for quickdocs commit access group
Resolves: forge/forge#501

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-09 11:58:03 +10:00
a0c0340b5b siguldry/pesign-bridge: Move acl handling to systemd unit
We have been moving this around, but decided that just putting it in as
a override for the systemd unit would be the best way to do it.

- Putting it in ansible means you have to run ansible every time you
  restart the service for any reason. If it's in systemd it will
  automagically get that set on start
- If for some reason the socket doesn't appear/the service doesn't start
  right or dies, this will error out.
- adding it in the client is tricky and error prone and not needed
  possibly for other installs, only fedora, so dropping it from there is
  a win.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-08 20:39:23 +00:00
156206c83d feat(compose-tracker): updating fedora image version
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-04-08 20:58:15 +02:00
Jeremy Cline
75f75dff69 fedora-image-uploader: drop the me-south-1 AWS region
This should be reverted whenever it becomes available, but it seems to
have been struck by drones and the replication step fails with:

AWSHTTPSConnection(host='ec2.me-south-1.amazonaws.com', port=443):
Failed to establish a new connection: [Errno 113] No route to host

Signed-off-by: Jeremy Cline <jeremycline@microsoft.com>
2026-04-08 18:15:35 +00:00
2b6b1cf199 blockerbugs: update blockerbugs app env variables
This is related to using Forge for blocker discussions:
quality/blockerbugs#296

Co-authored-by: Kamil Paral <kparal@redhat.com>
2026-04-08 16:49:25 +00:00
James Antill
d3db58fc89 vmhost-x86-01.stg: Use ipa02.stg as ipa_server
Signed-off-by: James Antill <james@and.org>
2026-04-07 16:00:09 -04:00
4fb1f446c5 feat: koji_hub: move rccl to heavybuild
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-04-07 19:17:10 +00:00
0265ecd8b4 openshift / docstranslation: disable cron runs for now.
Per infra/tickets#13171
we want to disable cron runs for now while repos and other things are
sorted out. We can just revert this after things are ready.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-06 19:59:52 +00:00
869ea27150 Add tar to datanommer
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-06 11:06:14 -05:00
a9744b9cd0 Fix location after move in 8fa423e72a
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-03 09:00:42 -05:00
8fa423e72a move file-retention-iso-date to files/scripts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-02 20:39:31 -07:00
2db3130404 Fix Tpyos and errata
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 21:12:54 -05:00
92e35f4f25 Lean on chronic for public-db-copy
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
df3b1f249e Add set -e to cron jobs to help chronic
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
8ac48ade3b Use chronic for datanommer daily export
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
70088899eb Prudent error checking
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
8e218fd14c Use chronic to manage cron email for db backup
Mimics blockerbugs/tasks/main.yml per PR feedback

Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
2a941c4482 Rename retention script per feedback
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
4fd6c27207 Requested changes
Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
7f493a042a Datanommer daily exports
Export daily 24h data in addition to the full pg_dump to allow
downstream replicas to stay in sync without requiring full PG
replication.

We call this "incremental" in some places because perhaps later we will
decide on a different level of granularity, e.g. hourly or weekly.

Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-04-02 23:35:10 +00:00
b69ce1c8d8 siguldry/pesign-bridge: commit the new ca cert to the right filename
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-02 12:02:25 -07:00
ab68f31d85 Revert "siguldry/pesign-bridge: also commit the ca cert"
This was the wrong cert for this.

This reverts commit 9ea5c72641.
2026-04-02 12:01:40 -07:00
9ea5c72641 siguldry/pesign-bridge: also commit the ca cert
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-02 11:56:03 -07:00
f45f1e088d add 20250530 ca cert so we can verify signing grub2 with it
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-02 18:45:17 +00:00
ad84375160 siguldry/pesign-bridge: fix acl call and fix 2nd grub2 cert
The acl call wasn't in the right place, it needed to be in the top
section instead of under [sigul] so it was getting ignored.
Once this is working we can remove the acl calls in ansible related to
this.

Also, at the same time grub2 is being signed by 2 certs currently (which
end up being the same one in the end). We want to switch the old
obsolete one over to the new 2025 one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-02 18:45:17 +00:00
cec3e52d78 copr-be: remove s390x concurrency limits
This restriction is no longer necessary now that s390x builds are
emulated (hopefully temporarily!) on x86_64, where we have 200+
instances available.  These limits were blocking many s390x Packit
builds.
2026-04-02 15:04:15 +02:00
15dafee626 [packages] Fix the service for deployment
The service selector.app needs to match with deployment.selector app. In
this case we have a conflict. This change will fix it.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-02 13:20:06 +02:00
6933510d42 [hotness] Fix the service for deployment
According to what I found the service selector app needs to match the
deployment app, which is pointing to the-new-hotness instead of
the-new-hotness redis. Hopefully this will fix the network issue between
the-new-hotness pod and redis pod.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-02 12:41:03 +02:00
964cf982ec 📧 roles(fasjson): Add my @redhat.com email to all Flock aliases
When I made the change back in January in commit 0ba3182601, little did
I realize that I put myself into a world of hurt because my FAS email
does not route mail to my Red Hat email address. This is not acceptable
for Flock planning since I need the emails in Red Hat email.

*mild internal screaming ensues*

So, this fixes the problem and continues to use FAS group membership for
the mail alias, but now my Red Hat email is specifically folded into the
recipient list for the Flock aliases.

CC: @shaunm @jasonbrooks

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-04-02 10:16:37 +00:00
d508aa48da [websites] Clean the role
The websites moved to new way of doing things and we don't need the old
fedora websites build anymore. This change will clean the role of the
obsolete files.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-02 07:18:00 +00:00
002c57d701 forge: add i18n org team mappings
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-02 15:43:10 +10:00
2b7628fcb3 forge: add koji org team mappings
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-02 13:45:19 +10:00
4c5a880ae2 forge: revert packaging commitee mappings changes added in error
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-02 13:44:33 +10:00
59b3670b00 forge: add group mappings for packaging committee
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-04-02 11:12:51 +10:00
5c334b2d63 proxies / staging: split out openqa and disable anubis in stg only
We want to test and see if this change broke websockets
in openqa.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 18:06:06 -07:00
60ab3ffb2a the-new-hotness: when specifying the registry using the app/image path
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 17:51:12 -07:00
c2b800ab7a the-new-hotness: switch to bitnamilegacy for redis container
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 17:40:42 -07:00
faa9ad6195 the-new-hotness: specify the local registry for images
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 17:37:05 -07:00
57fe4438fe replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:11:54 +00:00
0aa5a2eb56 add the-new-hotness deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:11:54 +00:00
e4b23af09a mdapi: fix selector
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 17:06:43 -07:00
3bddd3eceb mdapi: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:04:28 +00:00
ac42cf820c mdapi: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:04:28 +00:00
2c36f66fc4 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:04:28 +00:00
fee1ffedad add mdapi deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-04-02 00:04:28 +00:00
d6b59232d2 proxies: fix typo
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 12:20:21 -07:00
a9d17bebb7 proxies: tag last change to allow quick deploy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 12:14:55 -07:00
393678ce45 proxies: put openqa behind anubis as it is unusable currently
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-04-01 12:14:07 -07:00
b7a8ccdf87
forgejo: update dependencies for the runnerhost VM
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-01 17:18:43 +01:00
5efffb53b4
forgejo: Create the forgejo runnerhost serviceaccount, rbac etc
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-01 13:47:04 +01:00
27b24d3938
forgejo: move service account into the legacy VM defintion
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-04-01 13:32:15 +01:00
88f165d25c
Zabbix/Copr: copy zabbix staging groupvars to copr_dev_aws
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-04-01 13:17:20 +01:00
5470bdff4d bump up number of reserved instances 2026-04-01 14:15:19 +02:00
Jiri Kyjovsky
d7a41b08da copr-rpmeta: pip does not have creates arg 2026-04-01 13:50:34 +02:00
Jiri Kyjovsky
35af14084d copr-rpmeta: remove prod bday 2026-04-01 13:39:12 +02:00
Jiri Kyjovsky
5b71b2f834 copr-rpmeta: hostnames added + birthday production 2026-04-01 13:13:47 +02:00
Jiri Kyjovsky
6a146a17e2 copr-rpmeta: delete hostname hack and add xgboost to pylibs 2026-03-31 23:27:13 +02:00
Jiri Kyjovsky
ac8f9dbdf4 copr-rpmeta: fix hostname, we don't have them yet 2026-03-31 22:29:12 +02:00
Jiri Kyjovsky
9ade7f2bf3 copr: rpmeta disk was succesfully labeled 2026-03-31 22:02:48 +02:00
Jiri Kyjovsky
13487e6389 copr: rpmeta remove birthday 2026-03-31 21:56:06 +02:00
c1012d9832 Frozen: Fedora 44 final infra freeze starts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 12:48:38 -07:00
bbd6f392ba siguldry-pesign-bridge: put acls back for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 11:59:46 -07:00
c64bbc3353 siguldry-pesign-bridge: change owner to config dir to pesign so it can read it
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 11:48:06 -07:00
James Antill
31e03745cf maintainer-test: Fix syntax.
Signed-off-by: James Antill <james@and.org>
2026-03-31 14:43:00 -04:00
James Antill
8894f695f2 maintainer-test: Remove the AWS users ssh keys override
Signed-off-by: James Antill <james@and.org>
2026-03-31 14:39:40 -04:00
b9fa04724c siguldry-pesign-bridge: fix mode on config dir
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 11:36:21 -07:00
a195fb7e17 siguldry/pesign_bridge: drop ansible acl calls in favor of native
siguldry pesign_bridge now has a way to set acls on startup.
This switches this to using that method.

it's a lot better because it always will be applied on startup instead
of having to wait for an ansible playbook run.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 11:26:31 -07:00
3a537f6ac6 siguldry/pesign_bridge: increase timeout in case of sigul stuck issues
If sigul gets stuck on something, signing just fails here causing
the builds to fail. Instead increase the timeout so it can just keep
retrying until someone fixes things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 11:06:30 -07:00
4c31030110 kerneltest: fix selector for service, should be label, not object type
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 10:45:39 -07:00
0793d8e514 openshift: add phsmoura to read all cluster info
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 10:23:48 -07:00
3d8b2b008e kerneltest: delete old deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 10:02:56 -07:00
f5035b56ce kerneltest: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 17:00:02 +00:00
70904fa116 kerneltest: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 17:00:02 +00:00
bd6627d86a replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 17:00:02 +00:00
36494f1713 add kerneltest deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 17:00:02 +00:00
4ac655aeb8 greenwave: delete old deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-31 09:59:28 -07:00
624a673ef1 greenwave: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 16:51:32 +00:00
198d909842 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 16:51:32 +00:00
d9e81aa65c add greenwave deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-31 16:51:32 +00:00
Jiri Kyjovsky
f6ca11deea copr: add MVP for rpmeta service 2026-03-31 17:40:45 +02:00
48cc7b5989 F44 is in Final Freeze
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-03-31 14:49:59 +00:00
Lenka Segura
940e424745 forgejo: serviceaccount, vm, role, rolebinding and sa_token for runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-03-31 14:16:11 +00:00
edf5178e1d
forgejo: error handling in the runner registration task
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-31 12:55:50 +01:00
2e99c468d2 fedora-packages-static: delete old deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 16:51:46 -07:00
5f347f7a46 fedora-packages-static: fix selector
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 16:21:58 -07:00
33039c2224 fedocal/datagrepper: fix selectors
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 16:12:12 -07:00
dcb905809f fedora-packages-static: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:51:46 +00:00
9ccfbd95b4 fedora-packages-static: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:51:46 +00:00
83dd98cf14 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:51:46 +00:00
9c2387241d add fedora-packages-static deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:51:46 +00:00
2074db4250 fedocal: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:46:05 +00:00
626c3f19a0 fedocal: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:46:05 +00:00
bf3e7a5822 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:46:05 +00:00
30bb043cf8 add fedocal deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:46:05 +00:00
d27aa22ad0 discourse2fedmsg / fasjson: delete old deploymentconfig and fix selector on fasjson
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 15:42:20 -07:00
34ebdba09b fasjson: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:34:14 +00:00
a28588ae10 fasjson: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:34:14 +00:00
6de44ec26f replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:34:14 +00:00
6e324719bc add fasjson deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:34:14 +00:00
064eb5a1f0 discourse2fedmsg: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:25:56 +00:00
ad50034646 discourse2fedmsg: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:25:56 +00:00
99db49a751 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:25:56 +00:00
20e1bb177c add discourse2fedmsg deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:25:56 +00:00
2d46097315 bugzilla2fedmsg / datagrepper: delete old deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 15:25:35 -07:00
ac47ff1e60 datagrepper: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:21:21 +00:00
2469678ac6 datagrepper: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:21:21 +00:00
98a7edda19 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:21:21 +00:00
72552755e9 add datagrepper deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:21:21 +00:00
b9cfea18f3 bugzilla2fedmsg: use correct name of app in image stream
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:12:59 +00:00
c2f6803e24 replaced deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:12:59 +00:00
5415e4de94 add bugzilla2fedmsg deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-30 22:12:59 +00:00
d469c64a92 asknot: drop old deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 15:06:15 -07:00
f39cfe8e88 asknot: drop duplicate selector on route
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-30 15:02:38 -07:00
5c766e21a0 🤖 docs: Add AGENTS.md with project conventions for AI coding agents
Without guardrails, AI tools generate PRs that ignore Fedora Infra's
conventions — wrong file extensions (`.yaml` vs `.yml`), missing
`vars_files` triplets, broken idempotency, relative paths instead of the
required hardcoded `/srv/web/infra/ansible/` layout, and suggestions to
"fix" intentional patterns like the `vars/all/*.yaml` exception or the
`fedora_messaging_callback.py` custom plugin.

AGENTS.md gives AI agents the same context a new human contributor would
get from reading README.md, CONVENTIONS, STYLEGUIDE, and
`.ai_review/project.md` — but in a single file that AI tools
automatically load before generating code. This means AI-assisted PRs
should arrive already following our linting rules, architectural
patterns (OpenShift app vs group playbook), staging/prod conventions
(`_stg` group_vars, `env`/`env_suffix`), and tag discipline.

The file also includes the Fedora AI-Assisted Contribution Policy
requirements, ensuring AI agents prompt contributors to include the
Assisted-by: commit message trailer and respect the project's rules on
accountability, transparency, and human-final review.

The net effect is fewer round-trips in review: maintainers spend less
time explaining the same conventions repeatedly and can focus review on
whether the change is correct, not whether it follows the style guide.

Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-03-30 21:52:51 +00:00
James Antill
3e60b00464 postgresql_server: Remove unused config. file templates (-12 and -15).
Signed-off-by: James Antill <james@and.org>
2026-03-30 11:01:18 -04:00
James Antill
eb2d876d0b postgresql_server: Remove postgresql.conf-15, as -16 overwrites it anyway.
Signed-off-by: James Antill <james@and.org>
2026-03-30 10:57:39 -04:00
6283e1f4a4
Zabbix/Psql: Up threshold for locks on busy DBs
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-30 15:43:21 +01:00
806948259e
Nagios: remove ping & mgmt http(s) checks, Zabbix has all these now
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-30 15:36:08 +01:00
cc948ebee5 feat(compose-tracker): adding amedvede to be able to run playbook
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-03-30 15:15:45 +02:00
2fc3f872ac feat(compose-tracker): migration from pagure to forgejo
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-03-30 12:47:58 +00:00
bd04c8e90a review-stats: switch to new forge
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-03-28 09:04:23 +01:00
0e0bee4e9e Revert "resultsdb: use my test image on staging to debug 400s"
This reverts commit cae77fb2a1.
and fixup commit ec25703442. The
debugging worked and we fixed the bug, so we can go back to
using the official container now.
2026-03-27 12:45:48 -07:00
fdf857f7dd resultsdb: use set-forwarded-headers: replace for now
This should 'fix' result reporting in staging resultsdb (and
future prod), see
infra/tickets#12997 and
infra/tickets#13235 .

This probably isn't ultimately the correct fix but it should make
things work for now. The real issue seems to be that the
RevereProxied custom WSGI app wrapper, which we copied around to
various apps back in the day and which attempts to handle the app
being reverse-proxied, doesn't handle all proxied headers and/or
doesn't handle comma-separated list values. The long-term fix is
likely to be using werkzeug's ProxyFix in a wrapper instead, see
infra/tickets#12997 (comment) .

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-03-27 12:22:05 -07:00
ec25703442 resultsdb: whoops, correct quay.io path to my repo
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-03-27 11:42:11 -07:00
cae77fb2a1 resultsdb: use my test image on staging to debug 400s
We're getting 400s when trying to submit results to staging
and an error handler in resultsdb itself is obfuscating all
details. I sent https://github.com/release-engineering/resultsdb/pull/365
to try and fix this, this deploys a build with that patch to
staging.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-03-27 10:16:19 -07:00
2db94b4913
forgejo: debug runner config being created
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-27 16:13:18 +00:00
29ead44c20
forgejo: fix issue with template src
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-27 16:07:21 +00:00
James Antill
370b17d9f0 mirror_forge_ansible.service: Remove execute bits to make systemd happy.
Signed-off-by: James Antill <james@and.org>
2026-03-27 11:54:32 -04:00
f7dbf5d7a6
forgejo: fix variable name
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-27 15:50:19 +00:00
5b942e0d7b
forgejo: fix error with variable name
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-27 15:26:06 +00:00
abab86991c
forgejo: remove task to checkout runners playbook on oscontrol
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-27 15:04:55 +00:00
Jakub Kadlcik
7222b28631 Copr documentation moved to docs.copr.fedorainfracloud.org
See https://github.com/fedora-copr/copr/pull/4198
2026-03-27 08:58:18 +00:00
30529dd882 copr-be: increase the number of s390x emulated workers 2026-03-27 09:51:54 +01:00
James Antill
d617df21bd update+uptimes: Fix extra brackets.
Signed-off-by: James Antill <james@and.org>
2026-03-26 14:56:34 -04:00
James Antill
4d31cfdd39 updates+uptime: Fix nat sorting of proxy40. vs. proxy101.
Signed-off-by: James Antill <james@and.org>
2026-03-26 14:51:36 -04:00
4bf039b4d0 Revert "greenwave: disable gating on coreos.cosa on Rawhide for now"
This reverts commit d8fad1c724.
2026-03-26 16:23:37 +00:00
b610443a6c bump up number of reserved instances 2026-03-26 14:59:59 +01:00
877ad6b91c
Zabbix: disable http(s) bmc checks in stg, not reachable
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-26 13:42:15 +00:00
8cd324d0e8
Zabbix: fix external_hosts inventory
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-26 13:36:09 +00:00
a0d52dff1a Zabbix: re-use base monitoring role in zabbix_server for non-Ansible hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-26 13:33:02 +00:00
75051c499d [distgit] Fix ansible-lint issues
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-26 13:58:02 +01:00
64b8ca82dd Prevent maintainers from manually tagging builds into fNN-build tags
Fixes: releng/tickets#13261

Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-03-26 05:39:04 +00:00
James Antill
c64432a279 compose*: Update remaining hosts from F42 to F43.
Signed-off-by: James Antill <james@and.org>
2026-03-25 21:07:50 -04:00
5e2de036c0 fasjson/aliases: add scalewaycloud alias ( ticket 13197 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-25 10:18:28 -07:00
585d429097 [ipsilon] Fix the copy/paste error
This should be applied everywhere, not only to openid instances.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 17:02:54 +01:00
67cf76f6f8 [ipsilon] Fix the links pointing to pagure.io
The error pages were pointing to pagure.io/fedora-infrastructure/issues.
This commit adds patch that changes it to
forge.fedoraproject.org/infra/tickets/issues.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 16:53:27 +01:00
c3c82be819 Drop obs-studio-libs from multilib
This is a dep of obs-studio-plugin-vkcapture, but now the relevant
package is a subpackage without the dependency.
2026-03-25 14:38:59 +00:00
a630e8adc9 [forgejo] Allow webhooks for staging proxies
When triggering OpenShift build on staging branch we are reaching to
staging proxies. Till now there were allowed only for staging forgejo
instance, but the repository triggering the webhook could be on
production instance as well. Let's add the staging proxies to webhook
allowlist also for production.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-25 10:24:53 +00:00
4ee26d9257 pkgs: optimize make-git-checkout-seed.sh
The code in if-branch and else-branch is identical. I moved it after the if-else-fi.
2026-03-24 23:14:10 +00:00
45cae9b0d3 pkgs: make sure git checkout points to head
When we modify the timeline of git, e.g. because of legal reason (removing patented things,
leaked tokens), the current checkout may not point to HEAD.
So before doing git-pull we should reset to current HEAD.

Related: #13194
2026-03-24 23:14:10 +00:00
fc72c13c8c communishift: add draft-share project. ticket 13172
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-24 16:06:52 -07:00
James Antill
68c02f4f1a maint-update-reboot: Add script to update, maybe reboot maintainer_test hosts.
Signed-off-by: James Antill <james@and.org>
2026-03-24 17:25:19 -04:00
James Antill
41f6c05954 vhost_update_reboot: Add comments for mainers.
Signed-off-by: James Antill <james@and.org>
2026-03-24 15:27:46 -04:00
276556a4fb refactor: delete fasjson_aliases variable and checks 2026-03-24 17:36:21 +00:00
c5c1fb730f Enable fasjson for email alias creation
Fixes infra/tickets#13219
2026-03-24 17:36:21 +00:00
3b09e415fd smtp-auth-iso01: rename master.cf file to correct hostname
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-24 08:04:49 -07:00
7f9b32c1f5 [bodhi] Fix ansible-lint failures
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-24 15:51:21 +01:00
58a135c6c4 varnish / proxies: do not try and use src backend on non rdu3 hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-23 20:21:08 -07:00
02418450f3 varnish / proxies: do not define pkgs backend on non rdu3 hosts
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-23 20:19:00 -07:00
James Antill
e5996addcd vhost_update: Workaround update transaction fails.
Signed-off-by: James Antill <james@and.org>
2026-03-23 15:53:58 -04:00
James Antill
6dc5b51882 batcave: Add diff-so-fancy from epel.
Signed-off-by: James Antill <james@and.org>
2026-03-23 15:50:43 -04:00
Jiri Podivin
2d82fba337 Increasing quota of pods and memory
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-03-23 18:52:07 +00:00
4fdc9ee95b gpu servers: add some groups to have shell access
This adds 2 groups to the gpu servers for shell access.
Only sysadmin-gpu has sudo access, but these users can login/do non root
things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-23 10:39:26 -07:00
640791dd96
Zabbix: disable monitoring http for Power9 bmc
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 16:35:23 +00:00
6645a421ab
Zabbix: Re-enable https(s) bmc checks now the firewall is sorted
Stg is still blocked but prod seems OK now...

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 14:39:48 +00:00
Jakub Kadlcik
e8fca8f563 copr: temporarily disable IBM cloud and emulate s390x instead
Fix https://github.com/fedora-copr/copr/issues/4219
2026-03-23 13:09:00 +00:00
ac014ece60
Zabbix: Remove leftover variable definition
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 11:56:28 +00:00
795a4e26e9
Zabbix: Move base ping/bmc checks to a template
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 11:52:37 +00:00
3f2332452e
Zabbix/Psql: Use same directory perms as zabbix_agent in psql task
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 10:00:41 +00:00
0a19698e74 [colo-virt] Add correct postfix group
This machines are on VPN, so they should be in the corresponding postfix group.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-23 10:47:54 +01:00
536af76624
Zabbix/Psql: Enable Psql template for all Psql servers
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-23 09:44:39 +00:00
a95ca06d44 Forge: add eln group mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-23 19:12:14 +10:00
a8973664c7 Perform mapping for Fedora Science teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-23 12:24:19 +05:30
64f51abec8 Forge: add discussion group mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-23 15:54:59 +10:00
76625c0ec6 Forge: add podcast group mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-23 13:47:40 +10:00
dad180ac78 Forge: add legal group mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-23 13:41:33 +10:00
2bdbe76d30 Forge: add arm sig group mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-23 12:57:46 +10:00
5cc22d92d7 siguldry-pesign-bridge: add another cert name used by grub2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-20 13:26:54 -07:00
b47eacbfad siguldry-pesign-bridge: add cert name used by grub2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-20 13:05:30 -07:00
f713c3ad74 inventory / secure-boot: enable a64 builder
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-20 12:43:57 -07:00
Gordon Messmer
8ebd10470a gpu01: add subids for kevin 2026-03-20 17:36:40 +00:00
Gordon Messmer
a23ad30a8c gpu01: add subuid/subgid files and management script 2026-03-20 17:36:40 +00:00
Gordon Messmer
1175c0aa41 gpu01: add rootless container tools 2026-03-20 17:36:40 +00:00
910579198f
Zabbix: Disable 80/443 BMC for iso hosts until we can fix networking
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 16:05:54 +00:00
1d38738c5d
Zabbix: Disable https(s) bmc checks until firewalls can be sorted
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 13:17:51 +00:00
4748df11f3
Zabbix: Add defaults for hostgroups
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 12:06:30 +00:00
15ca4c25ed Zabbix: move Zabbix API setup to base role
This relocates the work done via the Zabbix API to create & configure
a host to the base role, such that it is done for *every* host, even the
ones that don't run the agent (such as builders). This covers:

- Creating the host
- Adding the hostgroups
- Creating a set of items/triggers that ping the DNS name
- Creating a set of items/triggers that check the BMC interface (if defined)

The zabbix_agent role then deals with installing the agent and assigning
the agent template, as the rest has already been done in base.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 11:43:51 +00:00
edc040bb3b Zabbix/inventory: add more BMC lists to hardware machines and refer to it from zabbix_inventory
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 11:43:51 +00:00
96f44aa8b5 [the-new-hotness] Bump container to F43
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-20 12:26:33 +01:00
f03559ad08
Zabbix: apply PGSQL template to db-datanommer02 to test with some real load
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-20 10:53:55 +00:00
11ef2e75e3 review-stats: move stg to new forge
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-03-19 18:47:15 +01:00
9f418a521f koji_builder: drop default for pesign facls on secureboot
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-19 10:06:17 -07:00
dc3c7df630 koji_builder / secureboot: use /run instead of /var/run and use pesign user instead of group for the directory so it can write there
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-19 09:18:54 -07:00
2d118fd906
Zabbix: Double thresholds for smtp-mm-*
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-19 16:07:14 +00:00
4308b42b2d
Zabbix: Raise threshold on fmn queue
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-19 16:05:06 +00:00
c16a25f911
Zabbix: add 5mins to the TicketKey check to allow batcave time to copy it over
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-19 16:02:01 +00:00
e39c5797ca forge: add group mappings for the GO sig
Related: forge/forge#454

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-19 12:35:50 +10:00
b844c20f10 asknot: add pedro to app owners to debug issues in stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-18 12:07:29 -07:00
c58470122d secureboot: fix ordering issue
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-18 11:41:18 -07:00
170ab3455d secureboot: setup permissions for new pesign
pesign needs to map the socket into the chroot/container, but also set
acls to allow the users in the container to use it. We setup a
secureboot group to map these builders and only run this setup on them.

For now buildhw-x86-02 is the only builder we want to enable.
Once we know it's working well we can retire the bkernel role and repave
buildhw-x86-01. buildhw-a64-02 will be added once we fix the aarch64
signing.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-18 11:36:05 -07:00
31ab1ca704 siguldry/pesign_bridge: adjust pesign cert name to avoid kernel/grub changes
Change the pesign cert here to match the one that the kernel/grub/fwupd
already use in their spec files, this will allow us to switch over
without any changes to those packages.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-18 11:09:54 -07:00
e2b9207f2a [poddlers] Encode the secert to base64
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-18 17:45:16 +01:00
41519d128c [poddlers] Add generic build trigger
See apps/toddlers#395

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-18 17:12:23 +01:00
c49ea00759 Pagure.io: display the sunset message on web and on git push
This just sets it up to display the messages on prod. They are already
implemented on staging.

Resolves: forge/forge#432

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-18 13:14:22 +10:00
738e58987f
📧 roles(fasjson): Update swag-info email alias
This commit removes Natalie Pazmiño from the email alias for Fedora
Project swag orders and requests. It adds @shaunm, the CentOS Community
Architect, and sponsors email alias for the Design Team (currently, this
is @duffy, @ekidney, @jesschitas, @jflory7, @madelinepeck, and
@mleonova). This will make it easier to coordinate and provide
authoritative answers on Fedora and CentOS brand guidelines and
requirements with swag vendors and printers.

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-03-17 15:43:48 -04:00
James Antill
745e6a2aaf *-test* hosts: Add f44-test host file.
Signed-off-by: James Antill <james@and.org>
2026-03-17 13:57:49 -04:00
2ad9ef5afe
Zabbix: add dependencies and event data to SSL external checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-17 13:29:31 +00:00
025cbe84f1 pagure-staging: fix the patchfile again
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-17 13:22:27 +10:00
67ff813850 pagure-staging: fix the patchfile
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-17 13:04:33 +10:00
566cda9c46 pagure-staging: include the patchfile
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-17 12:38:40 +10:00
a7040abb2b pagure-staging - add sunset warning to git post-recieve
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-17 12:28:32 +10:00
81d53646ca asknot: fix selector to use deployment instead of deploymentconfig
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-16 16:47:49 -07:00
925e6a6df5 proxies / staging: we do not have worker04/worker05 in staging in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-16 16:16:23 -07:00
4cca4112fa asknot: use correct name of app in image stream
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-16 16:09:41 -07:00
ff0288e4c9 asknot: specify the local registry
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-16 16:04:25 -07:00
aa403d6bca replace deployment file in playbook and fixed image path
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-16 22:53:50 +00:00
30c30e172f add asknot deployment
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-03-16 22:53:50 +00:00
James Antill
b17170efc7 koji_sync_listener: Simple workaround for crashes.
Signed-off-by: James Antill <james@and.org>
2026-03-16 16:16:34 -04:00
a7413737d0 dhcpd: add buildhw-p10-fcos01.rdu3.fedoraproject.org
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-16 11:38:58 -07:00
8088e93c33
Zabbix: Deploy PGSQL scripts to /usr instead of /var
Because SELinux won't allow the agent to read /var.
Also fixes a few small things

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-16 15:05:51 +00:00
955f1b776a
Zabbix: fix typo in private var name
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-16 14:05:18 +00:00
54610a8db8
Zabbix: Add upstream PGSQL template and setup code
This uses the upstream template which runs a bunch of SQL to query the
DB via a monitoring user.

Scoped to db01.stg for testing at the moment.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-16 14:03:19 +00:00
36f773ece9 [postfix] Add missing variable to retrace group
The host_group variable was missing in retrace group, so the postfix
role took standard rdu3 main.cf file instead. Let's define the variable.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-16 12:29:56 +01:00
6ac10896be [postfix] Fix postfix config file
Few machines were having issues with sending e-mails (retrace03 and
pkgs01). In both cases it was caused by postfix misconfiguration.

* retrace03 - It's RHEL8 machine, so lmdb is unavailable and it also
didn't used vpn to reach bastion
* pkgs01 - It had just bastion as relay name, which wasn't happy to
resolve through DNS, this is using FQDN instead

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-16 12:12:14 +01:00
0a47333ffc Pagure-staging: remove unimplemented config for git hook message
I mistakenly thought there was a GIT_PUSH_MESSAGE option, but there is
not. so removing this from staging.

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-16 15:08:22 +10:00
50fc6d4d72 pagure-staging: add git push message for pagure.io decommissioning
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-16 13:42:28 +10:00
65aa2a1dcc pagure-staging: add sunset message to top of page
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-16 13:21:24 +10:00
c9d24a39de gpu: add zabbix agent for monitoring
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-13 13:57:34 -07:00
8ef3ba86ac anubis: let Copr servers/clients in
Anubis is breaking the Pagure <-> Copr integration:
https://github.com/fedora-copr/copr/issues/4204
2026-03-13 19:15:54 +00:00
85343d1360 koji / staging_sync: use correct new p10 staging builders in sync script
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-13 10:53:20 -07:00
c68be9b1df [postfix] Check the correct file being created
Let's check for .lmdb file, not the file itself.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-13 15:38:47 +01:00
1c54ac2c54
Zabbix: don't store long data for ticketkey ages
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-13 11:10:32 +00:00
df7fcf39bf
Zabbix: Add ticketkey age monitoring to proxies
This also relocates the `httpchecks` roles to the right place,
as putting it in it's own role was a bit of hack. Having it in
the proxy role is better.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-13 10:35:10 +00:00
bd50f47247
Proxies: use a single path on the proxy as destination for the ticketkey
This also removes the Nagios config - it'll be looking in the wrong
place. A Zabbix replacement check will follow in the next commit.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-13 10:35:10 +00:00
0abe6829ed Use a more complete log format on fedorapeople
Use a log format closer to the "combined" log format on fedorapeople.
This log format includes the referrer and the user agent, it's like
Apache's combined log format plus the virtualhost at the beginning,
like what was used before.

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-03-13 09:23:49 +00:00
a23f551bae storinator01: actually commit the exports file too
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:25:13 -07:00
78fa862d41 storinator01: move exports to new name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:15:14 -07:00
aa2b0180aa Update security.txt for end date and add some more fields
Fix the expire date.
Point users to a wiki page to hopefully cut down on begg bounties
Note that we do NOT have a bug bounty program.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:39:02 +00:00
7413d9c84f proxies / src.fp.o: drop haproxy from src
Right now requests go:

client -> httpd on proxy -> anubis -> httpd on proxy -> varnish -> haproxy -> pkgs01

but haproxy is pretty useless in this case.
There is only one backend (pkgs01) so no load balancing, and doing a
liveness check is also pointless because if its down the request will
fail anyhow.

It might be tha haproxy ovehead is causing varnish to return retries
sometimes ( infra/tickets#13123 )

So, this drops it out for this.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:36:49 +00:00
409b8614e7 kojipkgs: all options need - or + if any have it
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 12:29:42 -07:00
094eeb99e8 kojipkgs: disable indexes on ostree/repo/objects directories
These directories have usually around 32k objects in them.
This means when a client asks for a directory index for them
it takes kojipkgs a few minutes to actually generate it, because it has
to stat every single file in order to show timestamps and sizes.
This means it fills up all slots doing this and the proxies start
getting 503's from it on other requests.

I don't _think_ ostree needs this enabled for any reason.
If it did, it would always have been a problem.
I think it's just some clients/crawlers deciding they want the directory index.

So, lets just deny indexes on directories under there.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 12:12:16 -07:00
bd716659c6
Inventory: quote dates because Zabbix API wants that
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 17:01:28 +00:00
4e9c4751bc
Inventory: trim trailing whitespace with sed
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 15:49:27 +00:00
ec5c717b1f
Initial round of Zabbix HW inventory info 2026-03-12 15:49:24 +00:00
a3cbb17ca7
forgejo: Create the secret for the runner config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-12 14:18:51 +00:00
ee8a20b1f6
Zabbix: enable agent-based reporting on s390 bvmhosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 13:59:23 +00:00
b6401b16d7
forgejo: Create forgejo runner config secret
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-12 13:55:33 +00:00
5ec7103314
Zabbix: role/OS vars won't work in other roles, use a hostvar instead
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 13:04:57 +00:00
9cad3bf76c
Nagios: Drop RabbitMQ checks as Zabbix handles this
This removes (almost) all the Nagios config for Rabbit, including the
templates in the Rabbit role(s).

It leaves the nagios user, because Zabbix is also using it.

It also adds a Matrix-level notification for high queues, above the one
that goes to the UI.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 12:30:02 +00:00
084da3c5ab
OpenVPN: fix path to Zabbix agent config in cron, part 2
Helps if you add all the files you changed...

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 12:01:33 +00:00
3d7a57e1b0
OpenVPN: fix path to Zabbix agent config in cron
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 11:07:00 +00:00
aaa5941e9f base / postfix / bastion: switch some maps back to hash
These two maps are generated by a script, so we should adjust that
script to make lmdb if we want to switch them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 20:36:40 -07:00
4cb953f9e5 download: add mirror to acls ( infra/tickets#13180 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 01:02:37 +00:00
d81bf5903b base / postfix: make lmdb regex not also pull , in when entries are seperated by ,s
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 17:54:30 -07:00
1ab995c2f0 bastion/gateway: cache maps have to be btree
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 17:37:41 -07:00
ba480436d7 fix bug: set stg_template as empty list, so ansible doesn't fail
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-11 21:32:50 +00:00
6c98ae9f88 feat: Make the sysadmin-opensift-readonly group deploy in production
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-11 21:32:50 +00:00
1e6cb7b311 fedoraloveskde: Switch sources to new location on Fedora Forge
Signed-off-by: Neal Gompa <ngompa@fedoraproject.org>
2026-03-11 21:14:09 +00:00
aedf43d1f3 Restore arcane breadcrumbs (broken Forge links)
Also some minor changes to satisfy yamllint.

Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-03-11 21:09:36 +00:00
35a1b3223b proxies-reverseproxy: set keepalive=on ttl=10 for koji
This fixes intermittent 502 Bad Gateway errors during long-running
koji connections (like watch-task or watch-logs).

For more details on proxy keepalive and ttl, see:
https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-11 20:36:49 +00:00
6eeed591f7 greenwave updates gating: gate on new server-boot-iso tests
In quality/os-autoinst-distri-fedora#483
we added server-boot-iso tests to openQA that are similar to the
everything-boot-iso tests, but they generate and install a Server
netinst image, not an Everything one. That's been running for a
while, so we can gate on it now. We add a new policy because these
tests run on critical-path-server as well as all the ones we run
the everything-boot-iso tests on.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-03-11 12:38:52 -07:00
88f10244e1 pagure: Set WSGIApplicationGroup %{GLOBAL} for dist-git to prevent httpd core dumps
Fixes #12670.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-11 18:38:57 +00:00
b601ca4c6e storinator01: fix old rdu2-cc host entries
This machine moved from rdu2-cc to rdu3, we missed changing these at the
time.

For copr it should use the external hostname.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 10:18:03 -07:00
bcee02c9fd Fixes #13021 - Zabbix: Add OpenVPN Client cert monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-11 16:37:29 +00:00
Jakub Kadlcik
07f0fe3d12 copr: use packages.redhat.com and basic HTTP auth
Fix https://github.com/fedora-copr/copr/issues/4141
Fix https://github.com/fedora-copr/copr/issues/4142
2026-03-11 16:50:41 +01:00
402472283a [postfix] Fix the when condition
Path always needs to be in quotes inside jinja2 template.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 15:25:53 +01:00
e3efee90c1 [postfix] Use the correct variable in lmdb
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:56:43 +01:00
e6f7c234ab [postfix] Move lmdb handler to separate file
After merging I found out that the handler can't handle blocks. The
workaround is to include tasks from separate file.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:48:09 +01:00
48f3055721 [postfix] Migrate to lmdb
This change will migrate postfix from bdb to lmdb.
See infra/tickets#13035 for more
details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:46:18 +01:00
f40260df77 [postfix] Don't install postfix-lmdb on RHEL < 8
The RHEL/EPEL 8 doesn't have postfix-lmdb package, so let's skip it for
older releases.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
eeeaaadd9e [postfix] Update pkgs/pagure postfix configs
Missing space in variable for pkgs group ansible config

Revert changes in pagure and pkgs configs to use hash instead of btree
as before

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
01db5bb986 [postfix] Fix ansible-lint issues
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
4908d2b2d7 [postfix] Update lmdb tasks
1. Move lmdb file creation to handler
2. Create separate postfix config for RHEL8 machines (pkgs, pagure)
2026-03-11 13:27:21 +00:00
5e9129cd00 [postfix] Migrate to lmdb
This change will migrate postfix from bdb to lmdb.
See infra/tickets#13035 for more
details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
1b88461e30 [poddlers] Migrated to forge.fedoraproject.org
infra/tickets#13111

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:21:28 +00:00
fa0f8e073e
We are out of f44 beta freeze
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-11 11:20:47 +00:00
d4000f3282 Add an AI review workflow
This adds AI review for pull requests, using the workflow and
pattern already used by several Quality projects. Pull requests
will be reviewed by
https://gitlab.com/redhat/edge/ci-cd/ai-code-review/ whenever the
'ai-review-please' label is applied to them. Also adds a context
file, generated by claude-4.6-opus-high via Cursor, using the
https://github.com/juanje/context-generator skill, as recommended
by ai-code-review upstream.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
Assisted-by: claude-4.6-opus-high
Assisted-by: Cursor-2.6.11
2026-03-10 08:49:17 -07:00
Jakub Kadlcik
2dd8897adc copr: change Pulp content URL to packages.redhat.com
See https://github.com/fedora-copr/copr/issues/4141
2026-03-10 16:15:50 +01:00
Jakub Kadlcik
ce6c01e905 copr: change STG Pulp content URL to packages.redhat.com
See https://github.com/fedora-copr/copr/issues/4141
2026-03-10 12:22:31 +01:00
a24b5e49dc
forgejo: install runnerhost dependencies at vm creationtime
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-10 09:51:15 +00:00
04bbc6004f EPEL minor branching: fix inline documentation for branch-distgit-packages.yml
* Fix typos (disgit -> distgit)
* Run with rbac-playbook
* Use correct relative path when run with rbac-playbook

Resolves epel/releng#85

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-09 22:28:55 +00:00
James Antill
34425d82f2 Change torrent-hashes to Kevin's working version.
Signed-off-by: James Antill <james@and.org>
2026-03-09 18:16:40 -04:00
James Antill
bf1f99860d Add fedora.pt to zones.conf.
Signed-off-by: James Antill <james@and.org>
2026-03-09 15:30:10 -04:00
0262961387 copr-hypervisor: make sure helpers.py expand correctly
Follows-up: 14b89a2a67
2026-03-09 19:08:59 +01:00
538f6e5df0 copr: workers: fix ipv6 allocation
Follows-up: 14b89a2a67
2026-03-09 18:52:47 +01:00
60fd97e7cb copr: one more typo in the new libvirt spawner
Follows-up: 14b89a2a67
2026-03-09 18:47:07 +01:00
4200ac465e copr: fix typo in variable name
Follows-up: 14b89a2a67
2026-03-09 18:06:23 +01:00
14b89a2a67 copr: better divide the ipv6 range we have
Now, all VMs on stage are 0x900+, and 0x100+ are in prod.

Relates: https://github.com/fedora-copr/copr/issues/3984
2026-03-09 17:52:00 +01:00
2e546baf9f copr: debugging: helper script expands more files 2026-03-09 17:36:40 +01:00
Jiri Podivin
14e43e1533 Adding the 8090 port for packit to inventory
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-03-09 15:35:22 +00:00
74e2f728c5
Add the logdetective-packit user in RabbitMQ
Creating a certificate is not sufficient.

Fixes: infra/tickets#12989

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-03-09 10:10:56 +01:00
3dba4c3d44 forge: add group mappings for the flatpak org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-09 18:15:06 +10:00
d057561208 forge: add group team mapping for games SIG
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-09 16:20:09 +10:00
9f40b67dd1 Perform mapping for Personal Systems teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-09 06:19:07 +00:00
252b8ca273
docsbuilding: update git url 2026-03-07 22:18:22 +01:00
801e40b138 Fedora 44 Beta-1.2 is GO
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-03-06 20:51:37 +05:30
79f1a7c324 gpu01: add vpn and hosts file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 16:51:37 -08:00
0b00ad11d3 gpu: add group_vars and dhcp config
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 15:04:11 -08:00
e254c236dc smtp-auth-iso01: deploy correct postfix config
This config was not moved over when the host moved from rdu2-cc to
rdu3's iso network. It's needed to allow the submission port to work to
submit emails.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 19:56:20 +00:00
893e103461 gpu01: add new gpu01 machine in rdu3-iso
This machine is in the rdu3 isolated network.
For now, just setup a simple kickstart on one disk and a playbook that
does the normal base role things. We can adjust from here.

This machine has 1 nvme and another spinning rust device.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 19:55:21 +00:00
7de3acd96c web-data-analysis: remove hardcoded end date in gnuplot script
The mirrors-data.gp script had a hardcoded X-axis end date of
2024-12-31. Since we are now in 2026, gnuplot fails with "all points
y value undefined!" because the new log data points fall completely
outside this strict plotting window.

By removing the end date and using an open-ended range (e.g. ["2007-05-17":]),
gnuplot will automatically scale the X-axis to the latest available data
point in the CSV, preventing this from breaking again in the future.

Fixes: #12833

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-05 01:05:53 +00:00
Jakub Kadlcik
decd56f48c copr: of course I messed up the brackets 2026-03-04 22:08:09 +00:00
b935cd4d86 distgit: disable mod_mime_magic content encoding for archives
mod_deflate wasn't the issue, as src didn't have gzip enabled. The
backend (pkgs01) uses mod_mime_magic, which sniffs .crate files
and adds false gzip headers. Forcing application/octet-stream
fixes the client double-decompression bug.

Fixes #12812.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-04 21:25:59 +00:00
Jakub Kadlcik
c6954081de copr: enable high-perf builders for eseiker/asahi-el-kernel
Fix https://github.com/fedora-copr/copr/issues/4199
2026-03-04 10:37:44 +01:00
95cc5cdeb8 ocp4: fix rolebinding on readonly group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-03 09:51:49 -08:00
cff13b3aa0
fix: make the readonly role a ClusterRole and fix it's rolebinding
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-03 18:34:50 +01:00
775ff5cdfd
Fixes #13149 - Zabbix: Add release-monitoring.org to http page checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-03 17:05:57 +00:00
72ddc85537 fix: specify correct API for the readonly role
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-02 19:25:34 +00:00
59eddc51a8 EPEL minor branching: create symlinks as apache user
epel/releng#89

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-02 19:07:42 +00:00
4051930fa7 EPEL minor branching: update major-only compose symlinks
epel/releng#88

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-02 19:07:42 +00:00
88eabbfca6 Install ansible zabbix collection for ansible-lint
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-02 17:16:31 +01:00
8146e99e1b [postfix] Fix ansible-lint issues
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-02 17:16:30 +01:00
8569744347 forge: add miracle org to group team mappings
related: forge/forge#407

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-02 18:27:29 +10:00
b9e60a9cc5 Perform mapping for Fedora Btrfs teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 10:42:18 +05:30
cf24cc841e Perform mapping for CoC committee teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 10:36:33 +05:30
7d4880f9d7 Perform mapping for Security SIG teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 04:59:31 +00:00
1fa76e4de0
distgit: disable mod_deflate for lookaside cache in staging
Fixes #12812.

This disables mod_deflate for the lookaside cache directory to prevent
incorrect 'Content-Encoding: gzip' headers being sent with archives.
Wrapped in a staging block for initial testing as requested.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-02-27 20:22:40 +02:00
b4ddcdd830 removed ipsilon-website entries in proxies-reverseproxy.yml and proxies-websites.yml playbooks
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
8fa05b2955 deleted ipsilon-website playbook
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
5b88ef525f Removed ocp app ipsilon-website
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
488e9ae7e5 ocp4: add someone to readonly to test with in staging
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-27 09:54:40 -08:00
96d23293a2 fix: cluster/main.yaml should have been in cluser/handlers/main.yaml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
08928917e6 feat: add handler in openshift/clustr for applying changes
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
4392472669 separate template copying for stg/prod
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
4d8a14db4e move handling back to main.yml and rename role to sysadmin-openshift-readonly
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
b4ff5f819d remove trailing spaces
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
7b4774117d setup handlers, so ansible-lint is happy
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
a7ce1173a6 apply sysadmin-readonly when env is staging
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
f601a5ce0b remove access to configmaps from sysadmin-readonly
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
ae70d6e83a fix wrong role name in role definition
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
d619073a15 Add sysadmin-readonly group to openshift
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
76e6ffd412 Zabbix: Try to improve SSL check to handle timeouts from whatcanido
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-02-27 11:04:59 +00:00
709f7a12c4 Add ignore-errors to skip list
This will ignore CI errors in category ignore-errors in ansible-lint as
this is something we don't need to care about.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-27 08:24:13 +00:00
127d7c3269 get yamllint to ignore templates in openshift apps
previously, the yamllint ingores for templates only worked for roles one
level down. Since our openshift apps are nested in the openshift-apps
directory, yamllint was trying to lint jinja templates with a .yml
extension. This updates the yamllint ignores to include templates in
openshift apps roles.

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-26 08:59:38 +00:00
b3478a46c1 people: disable cgit snapshots downloading for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-25 14:06:36 -08:00
41fef6bf56 people01: try and increase workers and limits
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-25 13:43:56 -08:00
a8f1cdfb5e web-data-analysis: export PATH in cron scripts for simple_message_to_bus
Cron jobs run with a stripped-down PATH (usually just /usr/bin:/bin),
causing simple_message_to_bus (which resides in /usr/local/bin) to fail
with "command not found" errors.

This explicitly exports /usr/local/bin to the PATH at the top of the
combineHttpLogs, condense-mirrorlogs, and countme update scripts so
the message bus command executes properly. This also removes the redundant
and late PATH assignments further down in the countme scripts.

Fixes: #12833
Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-02-25 19:27:41 +00:00
62eff4cb2d distgit: deploy script to transfer pagure group ownership
Fixes: infra/tickets#12935
Signed-off-by: Victor Koycheff <victorinaforvu@gmail.com>
2026-02-25 19:12:08 +00:00
James Antill
38fe6cbb19 check-etc: Add lots of files/prefixes.
Signed-off-by: James Antill <james@and.org>
2026-02-25 13:47:28 -05:00
James Antill
9fdf8f48c9 updates-uptimes: Accept more values for --ansi yes/no.
Signed-off-by: James Antill <james@and.org>
2026-02-25 11:53:12 -05:00
James Antill
70ff023ee4 ansilog-playbook: Add script to view ansible-playbook logs.
Signed-off-by: James Antill <james@and.org>
2026-02-25 11:51:57 -05:00
d77eae4e33 base / nftables / builders: allow secure boot signing builders to talk to sign bridge
The builders that sign for secure boot need to talk to the
sigul-bridgd01 server to sign things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-24 15:29:33 -08:00
1847606af0 buildhw: enable sigul pesign bridge on buildhw-a64-02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-24 15:11:45 -08:00
1a18de4e92 buildhw-a64-02.rdu3.fedoraproject.org: disable for testing
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-24 15:03:16 -08:00
9d322cd3cc siguldry/pesign_bridge: fix config, install pesign and ca cert for verify
Fix up the config to the known working version with comments added
for various cert/token names.

Also, make sure we install pesign, we need it for the pesign user.

Also, add the sb ca so we can verify the pesigned files when we sign
them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-24 14:53:06 -08:00
5134a6c604 ipa/service: add one more "already exists" condition 2026-02-24 08:46:22 +01:00
9aa451c062 copr-fe: issue a keytab for correct hostname
We need to issue the keytab for copr.fedorainfracloud.org, as that is
the hostname users interact with.  If we issue it for inventory_hostname
(copr-fe.aws.fedoraproject.org), users would need to configure their
krb5 library with dns_canonicalize_hostname = false.  Since many users
do not have this configured, using the public-facing hostname is
necessary.
2026-02-24 08:16:13 +01:00
46dc8aa2f5 EPEL minor branching: refactor directory creation and createrepo commands
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 13:46:38 -06:00
fd8b32bffc EPEL minor branching: specify global find options first to avoid output on stderr
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 12:27:45 -06:00
2bfad288f8 EPEL minor branching: fix typo in repo path
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 12:20:30 -06:00
c6ce410820 EPEL minor branching: use epel_branched_minor var at the appropriate place
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 10:59:50 -06:00
135582f377 EPEL minor branching: fix concatenation of int variable in string
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 10:44:19 -06:00
9f7bc352ca EPEL minor branching: include EPEL vars file in manual playbooks
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 10:27:17 -06:00
12b9712962 Branch epel10.2 from epel10
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 15:44:31 +00:00
69473d4e45 EPEL minor branching: port manual playbooks to use existing EPEL vars
Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-02-23 15:41:04 +00:00
5f83e0fb6d Simplify FedoraBranchedBodhi handling
The current updates policy has the same rules for Branched after
Beta freeze / updates-testing activation as for stable releases,
so we don't need a specific Branched policy after that point at
all. It only needs to exist for the 'preenable' state. The
'current' state is useless, so get rid of it.

The Koji config handling was actually rather wrong in a few ways.
If we ever got into a situation where FedoraBranched was true
and FedoraBranchedBodhi was 'current', we'd allow block on the
branch, which seems bad. Also, because this block wasn't
conditionalized on FedoraBranched and FedoraBranchedNumber is
0 when FedoraBranched is false, we wound up defining a policy for
tag 'f0', which is also dumb (but probably harmless). Getting
rid of 'current' solves the first, conditionalizing the policy
on FedoraBranched solves the second.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-02-19 23:38:00 +00:00
1af438b1a2 also, it's not a pagure project anymore
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-19 22:39:04 +00:00
b9bc997a80 add forge to the list of critical apps
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-19 22:39:04 +00:00
ee431193b4 Only run yamllint ci on yamlfiles
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-20 07:27:10 +10:00
bed0b6d28f Revert removal of precommit config
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-20 07:21:40 +10:00
db67287890 Perform mapping for Fedora KDE teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-02-20 06:57:54 +10:00
84dedc8a29 Perform mapping for NeuroFedora SIG teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-02-19 20:45:17 +00:00
2d114f4cdc Use correct trigger on CI
pull_request instead of pull-request. Oh boy...
2026-02-19 16:24:29 +00:00
48313c93f8 storinator01: change dns search order to prefer vpn
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-19 08:19:41 -08:00
c808e362c6 Make the CI running on each PR 2026-02-19 16:57:03 +01:00
d62c10ca01 Add git package for CI
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-19 16:50:50 +01:00
7abaa1fcb2 Install missing module for CI 2026-02-19 16:49:32 +01:00
e6779e021a Update CI definition
Split jobs in two and use newer versions of actions

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-19 16:45:43 +01:00
7f8896885d Use fedora:latest image for CI 2026-02-19 16:26:45 +01:00
c8457fac67 Remove sudo from ci action
The first run failed on missing sudo command, let's try it without that.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-19 16:15:42 +01:00
c661866d3c Enable CI using forgejo actions
Clean the old CI setups and define forgejo actions on ansible
repository.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-19 14:47:58 +01:00
06d7dd223e copr-builders: do not enforce digest verification on the host
It is standard practice to use Mock's bootstrap image feature now, so
the vast majority of builds are not affected by the host's RPM
configuration.

However, some workarounds remain—such as for epel-7-ppc64le (where an
architecture-specific UBI7 image is unavailable).  In these cases, we
still need to install the bootstrap chroot using the older method
(`dnf install yum` via the host's DNF/RPM).  This process would fail for
target distributions that were using SIGMD5 digests if verification were
enforced:

| Error: Transaction test error:
|   package libgcc-4.8.5-44.el7.ppc64le does not verify: no digest
|   package tzdata-2024a-1.el7.noarch does not verify: no digest
|   ...

Regardless of this change, we still perform gpgcheck=1 for target
buildroots.  However, these checks are handled by the RPM/DNF stacks
inside the bootstrap environments.  Therefore, this change specifically
affects bootstrap chroot installations (primarily for older targets) on
builder hosts running RPM v6 (Fedora 43+).

See also: infra/ansible#3122
2026-02-19 11:40:20 +01:00
47641126ae Remedy mapping after renaming translations to localization-docs
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-02-19 02:58:24 +00:00
bfee391944 siguldry-bridge: fix some quoting issues
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-18 15:48:06 -08:00
33065287fb buildhw-x86-02: add in pesign bridge
This machine is disabled in koji and not frozen, so using it to deploy
and test this setup. Once I can manually sign something with it, we can
look at enabling it for real (after freeze).

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-18 15:45:16 -08:00
b5cab0e0f1
forgejo: reference correct runner config variable
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-02-18 18:34:53 +00:00
784f4176ca
forgejo: debugging runner registration task
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-02-18 18:31:05 +00:00
22de181157
forgejo: update task with correct variable containing runner configs
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-02-18 18:14:02 +00:00
a689aa55c8
forgejo: remove unnecessary delgate to directives in runner reg task
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-02-18 18:07:36 +00:00
449e5cf508
forgejo: move runner registration here
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-02-18 16:54:47 +00:00
afe88f4027 bodhi-stg: test multiple destination registry
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-02-18 15:47:58 +01:00
7422198c59 Enter Fedora 44 Beta infrafreeze
we are now in the infrastructure freeze leading up to the Fedora 44
Beta release. This is a pre release freeze.

We do this to ensure that our infrastructure is stable and ready to
release Fedora 44 Beta when it's available.

You can always check if an infrastructure freeze is in place by
checking the value of the InfraFrozen variable at:
https://forge.fedoraproject.org/infra/ansible/src/branch/main/vars/all/Frozen.yaml

You can see a list of hosts that do not freeze by checking out the
ansible repo and running the freezelist script:

git clone
https://forge.fedoraproject.org/infra/ansible/src/branch/main/vars/all/Frozen.yaml

ansible/scripts/freezelist -i inventory

Any host listed as "freezes" is frozen until 2026-03-10 (or later if
release slips). Frozen hosts should have no changes made to them without
a sign-off on the change from at least 2 sysadmin-main or rel-eng
members, along with (in most cases) a patch of the exact change to be
made to this list and/or a pull-request to the infra/ansible repo.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-17 12:37:21 -08:00
James Antill
dacafc595d updates+uptimes: Remove dead code.
Signed-off-by: James Antill <james@and.org>
2026-02-17 15:34:02 -05:00
James Antill
a5905f94e0 mirror_forge_ansible: body is wrapped in a body.
Signed-off-by: James Antill <james@and.org>
2026-02-17 14:53:56 -05:00
d8fad1c724 greenwave: disable gating on coreos.cosa on Rawhide for now
See https://github.com/coreos/fedora-coreos-config/pull/4003#issuecomment-3916446960 -
per @dustymabe they can't get the test running on current Rawhide
(f45) ATM due to a container label issue.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-02-17 10:44:21 -08:00
d3e9445c6f readme: change url to ansible repo in readme
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-17 09:33:51 -08:00
James Antill
5e5834a730 updates+uptimes: Minor cleanup.
Signed-off-by: James Antill <james@and.org>
2026-02-17 12:04:25 -05:00
b8c965de2c
HyperKitty: activate pagination in the API
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-02-17 17:12:17 +01:00
1457 changed files with 28626 additions and 40047 deletions

159
.ai_review/project.md Normal file
View file

@ -0,0 +1,159 @@
## Project Overview
**Purpose:** Ansible automation for the entire Fedora Project infrastructure — managing hundreds of bare-metal hosts, VMs, and OpenShift-deployed applications across production and staging environments.
**Type:** Infrastructure as Code (Ansible)
**Domain:** Linux distribution infrastructure (build systems, package repositories, CI/CD, web services, identity management)
**Key Components:** `roles/` (134 reusable roles), `playbooks/` (groups, hosts, openshift-apps, manual), `inventory/` (host/group vars with constructed plugin)
## Technology Stack
### Versions (current as of 2026-03-05)
- **Ansible** — core automation engine; playbooks target Fedora and RHEL/CentOS hosts
- **yamllint** v1.35.1 — pre-commit hook for YAML validation
- **ansible-lint** — CI linting (skips: `yaml`, `role-name[path]`, `var-naming[no-role-prefix]`, `no-changed-when`, `ignore-errors`)
- **OpenShift 4** (OCP4) — hosts ~60 containerized applications via `openshift-apps/` playbooks
### Target Platforms
- **Fedora** (current cycle: F43 stable, F44 branched, F45 rawhide)
- **RHEL/CentOS** 8+ (EPEL 10, current minor: 10.3)
- **OpenShift 4** cluster (rdu3 datacenter)
### Dev Tools
- **Linting:** yamllint (pre-commit) + ansible-lint (CI)
- **CI:** Forgejo Actions on `quay.io/fedora/fedora:latest` — runs yamllint and ansible-lint on changed files only
- **Control host:** batcave01 (`/srv/web/infra/ansible` public, `/srv/private/ansible` private)
## Resource Organization
### Structure
```
├── main.yml # Master playbook — imports all group/host playbooks
├── playbooks/
│ ├── groups/ # 59 group playbooks (one per service group)
│ ├── hosts/ # 2 host-specific playbooks (FQDN.yml)
│ ├── openshift-apps/ # 60 OCP4 application deployments
│ ├── manual/ # 39 admin-run-only playbooks
│ └── include/ # Shared proxy/virt/cert playbook fragments
├── roles/ # 134 roles
│ ├── base/ # Applied to ALL hosts (packages, SSH, SELinux, nftables)
│ ├── openshift/ # OCP4 primitives (project, object, keytab, route, rollout)
│ └── openshift-apps/ # Per-app roles (templates, files for OCP4 deployments)
├── inventory/
│ ├── inventory/ # Host definitions
│ ├── group_vars/ # 150 group variable files (incl. _stg variants)
│ ├── host_vars/ # Per-host overrides
│ └── zzz-inventory.config # Constructed inventory plugin (dynamic groups by datacenter, distro, vmhost)
├── vars/
│ ├── global.yml # Global vars (paths, SSL config, base packages)
│ ├── all/ # Release cycle vars (Fedora versions, freeze states, EPEL)
│ ├── apps/ # Per-application vars (bodhi, mirrormanager, etc.)
│ ├── Fedora.yml # Distro-specific packages/services
│ └── RedHat.yml / CentOS.yml
├── tasks/ # Reusable task snippets (cloud, postfix, yumrepos, etc.)
├── handlers/ # restart_services.yml
├── library/ # Custom modules (delete_old_oci_images.py, virt_boot, etc.)
├── callback_plugins/ # fedora_messaging_callback.py, logdetail.py
├── files/ # Static files/templates organized by service
└── scripts/ # Admin utility scripts (auth-keys-from-fas, freezelist, etc.)
```
### Module/Role Structure
**Standard role layout:** `tasks/main.yml`, `templates/`, `files/`, `handlers/main.yml`, `meta/main.yml`
**OpenShift app pattern** — the dominant pattern for new services:
1. Playbook in `playbooks/openshift-apps/<app>.yml` targets `os_control[0]:os_control_stg[0]`
2. Uses composable `openshift/*` roles (`project`, `object`, `keytab`, `secret-file`, `imagestream`, `route`, `rollout`)
3. App-specific templates in `roles/openshift-apps/<app>/templates/`
4. Staging vs production controlled by `env` variable and `env_suffix`
**Group playbook pattern** — for traditional VM-based services:
1. Playbook in `playbooks/groups/<group>.yml` with `hosts:` matching inventory group
2. Must include standard `vars_files` triplet (see Review Guidance)
### Critical Resources
- **`vars/all/`** — Fedora release cycle variables. Changed every ~6 months during branching/release. Incorrect values break builds, composes, and Bodhi across the entire infrastructure.
- **`roles/base/tasks/main.yml`** (700+ lines) — Applied to every managed host. Changes here have maximum blast radius.
- **`inventory/group_vars/`** — 150 files controlling per-group behavior. Many have `_stg` counterparts for staging.
- **`main.yml`** — Master playbook importing all groups. Nightly `--check --diff` cron runs all playbooks here.
## Review Guidance
### What Reviewers Must Know
- **All playbooks must be idempotent.** They can be run at any time by the nightly cron. The checked-in state must always be the desired state.
- **Standard vars_files triplet is required** in all group/host playbooks:
```yaml
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "{{ private }}/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
```
Plus `include_vars` for `vars/all/` when release cycle vars are needed.
- **Hardcoded paths are standard** — paths like `/srv/web/infra/ansible/` and `/srv/private/ansible/` are the production layout on batcave01. Don't suggest making them relative or configurable.
- **Use `yml` not `yaml`** for Ansible files (per STYLEGUIDE). The exception is `vars/all/*.yaml` which uses `.yaml` historically.
- **Add `.j2` extension** to all Jinja2 templates.
- **YAML indentation is 2 spaces.** Line length is not enforced.
- **Prefer readable multi-line module args** over single-line `module: name=x arg=y` format.
- **Staging uses `_stg` suffixed group_vars** and `env_suffix` variable (empty string for prod, `.stg` for staging).
- **Tags `packages` and `config`** should be applied to relevant tasks. `build` and `rollout` tags use `never` to prevent accidental execution.
- **OpenShift apps target `os_control[0]:os_control_stg[0]`** — always the first control node. Don't suggest targeting all control nodes.
### Do NOT Flag (Known False Positives)
- `ansible-lint` skip list includes `no-changed-when` and `ignore-errors` — these are intentionally suppressed project-wide
- `yaml` rule category is skipped in ansible-lint — yamllint handles YAML validation separately
- Hardcoded absolute paths in playbooks (e.g., `/srv/web/infra/ansible/...`) — this is the expected deployment layout
- `mock_modules` and `mock_roles` in `.ansible-lint` — used to pass syntax checks without all dependencies
- Octal values forbidden in yamllint — intentional policy to avoid ambiguous YAML parsing
- `when: env == "production"` / `when: env == "staging"` conditional duplication in openshift-apps — standard pattern for different scaling/config per environment
### Common Pitfalls
- **Forgetting to update `vars/all/` during release transitions** — these variables control Fedora version numbers, freeze states, and EPEL branches. Multiple files must be updated together (e.g., branching requires changes to `FedoraBranched.yaml`, `00-FedoraCycleNumber.yaml`, `FedoraBranchedBodhi.yaml`, and `Frozen.yaml`).
- **Not testing with staging first** — staging group_vars (`*_stg`) should be updated before production. Changes that work in staging may still break production due to different scaling or secrets.
- **Breaking idempotency** — a task that makes changes on every run will generate noise in the nightly `--check --diff` report and mask real drift.
- **Wrong file extension for templates** — placing a `.yml` file in `templates/` instead of `.yml.j2` means Jinja2 expressions won't be rendered.
- **ansible-lint file/role misclassification** — the `.ansible-lint` `kinds` section maps `tasks/*.yml` and `vars/*.yml` explicitly. New directories with tasks may need similar mappings.
## Internal & Proprietary
- **`/srv/private/ansible/`** — Private vars (secrets, credentials) stored on batcave01. Referenced as `{{ private }}/vars.yml`. Never committed to this repo.
- **`callback_plugins/fedora_messaging_callback.py`** — Custom Ansible callback that publishes play results to Fedora's AMQP message bus. Don't suggest replacing with standard callback plugins.
- **`callback_plugins/logdetail.py`** — Custom detailed logging callback for the nightly check-diff runs.
- **`library/virt_boot`** / **`library/delete_old_oci_images.py`** — Custom Ansible modules for VM management and OCI image cleanup. Not upstream modules.
- **`scripts/auth-keys-from-fas`** — Fetches SSH authorized keys from Fedora Account System (FAS). Referenced by `auth_keys_from_fas` global variable.
- **Constructed inventory plugin** (`zzz-inventory.config`) — Dynamically creates groups by datacenter (`rdu3`), distro, vmhost, and virtualization role. The `zzz-` prefix ensures it loads last.
---
<!-- MANUAL SECTIONS - DO NOT MODIFY THIS LINE -->
## Architecture & Design Decisions
- **Mostly flat role directory with some nesting**: Most roles live directly under `roles/`, but several use subdirectory namespacing — `openshift/` (OCP4 primitives), `openshift-apps/` (per-app deployments), `awx/`, `openqa/`, `rabbit/`, among others.
- **OpenShift apps via Ansible, not Helm/Kustomize**: OCP4 applications are deployed through Ansible roles that template and apply OpenShift objects. This keeps all infrastructure in one tool and one repo.
- **Staging/production parity through group_vars**: Rather than separate inventories, staging hosts are in the same inventory with `_stg` group_vars files providing overrides. The `env` and `env_suffix` variables control behavior.
- **Release cycle managed through simple YAML vars**: Fedora's complex release lifecycle (rawhide, branched, stable, EOL) is encoded in `vars/all/` as a set of interdependent variables rather than a database or API. This is intentional — the variables are updated manually during each release milestone by the release engineering team.
## Business Logic
- **Fedora release cycle states**: Three main states — unbranched (rawhide only), branched (rawhide + pre-release), and post-release. Controlled by `FedoraBranched`, `FedoraCycleNumber`, `FedoraBranchedBodhi` (preenable/prebeta/postbeta), and freeze flags. These cascade through templates across the entire infrastructure.
- **EPEL minor version lifecycle**: EPEL 10+ has minor versions that move through states: `epel_minor` (built against CentOS), `epel_branched_minor` (branched, built against CentOS snapshot), `epel_z_minor` (built against RHEL). Up to three active minor versions at once.
- **Critical path applications**: forge, pagure, mirrormanager, bodhi, koji, dist-git, and ~20 others require two-reviewer PRs and coordinated downtime scheduling for risky changes.
- **Nightly check-diff**: All playbooks under `playbooks/{groups,hosts}` are run nightly with `--check --diff`. The ideal state is zero changes reported.
## Domain-Specific Context
- **batcave01** — The Ansible control host. All playbooks are run from here via `sudo -i ansible-playbook`.
- **env / env_suffix**`env` is `"production"` or `"staging"`. `env_suffix` is `""` for prod, `".stg"` for staging. Used throughout to construct hostnames, queue names, and paths.
- **FAS (Fedora Account System)** — Identity provider for the Fedora community. SSH keys, group memberships, and permissions come from FAS/IPA.
- **Koji** — Fedora's build system. Build hosts (buildvm, buildhw) are managed here. Koji hub is VM-based (`playbooks/groups/koji-hub.yml` + `roles/koji_hub`), not on OpenShift.
- **Bodhi** — Fedora's update management system. Runs on OpenShift with complex RabbitMQ messaging integration.
- **dist-git / Pagure** — Package source repositories. The lookaside cache and git hosting are managed by separate roles.
- **RabbitMQ / fedora-messaging** — AMQP message bus connecting Fedora services. Certificates managed per-service via `openshift/secret-file` role.
## Special Cases
- **`playbooks/openshift-apps/` uses `gather_facts: false`** — OCP4 playbooks target the control node to run `oc` commands, not the apps themselves. Facts aren't needed and would slow execution.
- **`vars/all/*.yaml` uses `.yaml` extension** despite STYLEGUIDE mandating `.yml` — historical exception, don't "fix" this.
- **`ansible-lint` runs in offline mode** (`offline: true`) — dependencies aren't installed during linting. `mock_modules` and `mock_roles` paper over missing dependencies.
- **Some playbooks are excluded from ansible-lint** (e.g., `copr-db.yml`, `list-vms-per-host.yml`) due to known issues with hardcoded paths or unicode errors.
- **`linux-system-roles.network`** is mocked in ansible-lint — it's an external role not available during CI.

View file

@ -67,3 +67,4 @@ skip_list:
- role-name[path]
- var-naming[no-role-prefix]
- no-changed-when
- ignore-errors

View file

@ -0,0 +1,17 @@
---
name: AI Code Review
on:
pull_request_target:
types: [labeled]
jobs:
ai-review:
runs-on: infra-1
if: forgejo.event.label.name == 'ai-review-please'
uses: quality/workflows/.forgejo/workflows/ai-review.yml@main
with:
pr: ${{ forgejo.event.pull_request.number }}
config: |
include_mr_summary: false
secrets:
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}

View file

@ -0,0 +1,71 @@
---
name: Linter
on:
pull_request:
types: [opened, synchronize]
jobs:
yamllint:
runs-on: infra-1
container:
image: quay.io/fedora/fedora:latest
steps:
- name: Install testing tools
run: |
dnf install -y yamllint nodejs git
- name: Checkout code
uses: https://code.forgejo.org/actions/checkout@v6
with:
fetch-depth: 0
- name: Get changed files
id: changed-files
uses: https://code.forgejo.org/tj-actions/changed-files@v47
- name: Run yamllint
if: steps.changed-files.outputs.any_changed == 'true'
run: |
for file in ${{ steps.changed-files.outputs.all_changed_files }}; do
if [[ "$file" == *.yml || "$file" == *.yaml ]]; then
yamllint "$file"
fi
done
ansible-lint:
runs-on: infra-1
container:
image: quay.io/fedora/fedora:latest
steps:
- name: Install testing tools
run: |
dnf install -y python3-pip nodejs git
pip3 install ansible-core ansible-lint
- name: Install ansible collections
run: |
ansible-galaxy collection install \
community.zabbix \
community.general \
ansible.posix
- name: Checkout code
uses: https://code.forgejo.org/actions/checkout@v6
with:
fetch-depth: 0
- name: Create symlink to overcome absolute paths
run: |
mkdir -p /srv/web/infra/
ln -s /workspace/infra/ansible /srv/web/infra/ansible
- name: Get changed files
id: changed-files
uses: https://code.forgejo.org/tj-actions/changed-files@v47
- name: Run ansible-lint
if: steps.changed-files.outputs.any_changed == 'true'
run: |
for file in ${{ steps.changed-files.outputs.all_changed_files }}; do
ansible-lint "$file"
done

View file

@ -0,0 +1,23 @@
---
name: Differential yamllint
"on":
push:
pull_request:
branches: [main]
jobs:
yamllint-job:
runs-on: infra-1
steps:
- name: Repository checkout
uses: actions/checkout@v4
with:
fetch-depth: 100
- name: VCS Diff Lint
uses: https://github.com/fedora-copr/vcs-diff-lint-action@v1
id: VCS_Diff_Lint
with:
linter_tags: |
yamllint

6
.gitignore vendored
View file

@ -1,5 +1,11 @@
*.swp
*.pyc
# Cursor workspace
.cursor
# emacs projectile
.projectile
# ansible-lint directory
.ansible/

View file

@ -1,22 +1,22 @@
---
# See https://pre-commit.com for more information
# See https://pre-commit.com/hooks.html for more hooks
repos:
---
# See https://pre-commit.com for more information
# See https://pre-commit.com/hooks.html for more hooks
repos:
# - repo: https://github.com/pre-commit/pre-commit-hooks
# rev: v3.2.0
# hooks:
# - id: trailing-whitespace
# - id: end-of-file-fixer
# - id: check-yaml
# - id: check-added-large-files
# - repo: https://github.com/pre-commit/pre-commit-hooks
# rev: v3.2.0
# hooks:
# - id: trailing-whitespace
# - id: end-of-file-fixer
# - id: check-yaml
# - id: check-added-large-files
- repo: https://github.com/adrienverge/yamllint
rev: v1.35.1
hooks:
- id: yamllint
- repo: https://github.com/adrienverge/yamllint
rev: v1.35.1
hooks:
- id: yamllint
# - repo: https://github.com/ansible/ansible-lint
# rev: v24.12.1
# hooks:
# - id: ansible-lint
# - repo: https://github.com/ansible/ansible-lint
# rev: v24.12.1
# hooks:
# - id: ansible-lint

View file

@ -23,4 +23,8 @@ rules:
# level: warning
truthy:
allowed-values: ['true', 'false', 'yes', 'no']
ignore:
- '*/templates/*'
- '*/openshift-apps/*/templates/*'
...

View file

@ -1,6 +0,0 @@
---
- project:
check:
jobs:
- fi-ansible-lint-diff
- fi-yamllint-diff

108
AGENTS.md Normal file
View file

@ -0,0 +1,108 @@
# AGENTS.md
This file provides guidance to AI coding agents when working with code in this repository.
## Project Overview
Ansible automation for the entire Fedora Project infrastructure. Manages hundreds of bare-metal hosts, VMs, and OpenShift 4 applications across production and staging environments. The control host is **batcave01** (`/srv/web/infra/ansible` public, `/srv/private/ansible` private).
Repository is hosted at https://forge.fedoraproject.org/infra/ansible
## Linting
Run yamllint on changed files:
```sh
yamllint path/to/file.yml
```
Run ansible-lint on changed files:
```sh
ansible-lint path/to/file.yml
```
CI runs both linters on changed files only (Forgejo Actions on `quay.io/fedora/fedora:latest`). The `community.zabbix` collection is installed before ansible-lint runs.
### Linting configuration
- **yamllint** (`.yamllint.yaml`): 2-space indentation (warning level), line-length disabled, octal values forbidden, truthy values restricted to `true/false/yes/no`, templates directories ignored.
- **ansible-lint** (`.ansible-lint`): Runs in offline mode. Skipped rules: `yaml`, `role-name[path]`, `var-naming[no-role-prefix]`, `no-changed-when`, `ignore-errors`. Uses `mock_modules` and `mock_roles` to pass syntax checks without all dependencies.
## Architecture
### Directory structure
- `playbooks/groups/` — One playbook per service group (multi-host). Filename should be descriptive.
- `playbooks/hosts/` — One playbook per unique host. Filename MUST be `FQDN.yml`.
- `playbooks/openshift-apps/` — ~60 OCP4 application deployments.
- `playbooks/manual/` — Admin-only playbooks, never run by cron.
- `playbooks/include/` — Shared playbook fragments (proxy, virt, cert).
- `roles/` — 134 roles. Flat structure with some namespacing (`openshift/`, `openshift-apps/`, `awx/`, `rabbit/`).
- `roles/base/` — Applied to ALL managed hosts. Changes here have maximum blast radius.
- `inventory/` — Host definitions, `group_vars/` (150 files), `host_vars/`, and `zzz-inventory.config` (constructed inventory plugin, loads last due to `zzz-` prefix).
- `vars/all/` — Fedora release cycle variables. Changed every ~6 months during branching/release. Incorrect values break builds across the entire infrastructure.
- `vars/global.yml` — Global vars (paths, SSL, base packages).
- `tasks/` — Reusable task snippets included in playbooks.
- `library/` — Custom Ansible modules (`delete_old_oci_images.py`, `virt_boot`, etc.).
- `callback_plugins/` — Custom callbacks (`fedora_messaging_callback.py`, `logdetail.py`). Don't suggest replacing these.
- `main.yml` — Master playbook importing all group/host playbooks. Used with `-t tag` to run specific tags across all hosts. Nightly `--check --diff` cron runs all playbooks.
### Two main deployment patterns
**OpenShift app pattern** (dominant for new services):
1. Playbook in `playbooks/openshift-apps/<app>.yml` targets `os_control[0]:os_control_stg[0]`
2. Uses composable `openshift/*` roles: `project`, `object`, `keytab`, `secret-file`, `imagestream`, `route`, `rollout`
3. App templates in `roles/openshift-apps/<app>/templates/`
4. Uses `gather_facts: false` (runs `oc` commands on control node, not on apps)
**Group playbook pattern** (traditional VM services):
1. Playbook in `playbooks/groups/<group>.yml` with `hosts:` matching inventory group
2. Must include standard vars_files (see below)
### Staging vs Production
Same inventory, not separate inventories. Staging hosts use `_stg` suffixed group_vars files. Controlled by:
- `env``"production"` or `"staging"`
- `env_suffix``""` for prod, `".stg"` for staging
## Fedora AI-Assisted Contribution Policy
This repository is part of the Fedora Project and subject to the [Fedora AI-Assisted Contributions Policy](https://docs.fedoraproject.org/en-US/council/policy/ai-contribution-policy/). Key requirements:
- **Accountability**: The human contributor is always the author and is fully accountable for the entirety of AI-assisted contributions. All submissions must meet project standards for quality, license compliance, and utility.
- **Transparency**: Use of AI tools MUST be disclosed when the significant part of the contribution is taken from a tool without changes. For git contributions, use an `Assisted-by:` commit message trailer (e.g., `Assisted-by: ChatGPTv5` or `Assisted-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>`).
- **No AI-only judgments**: AI MUST NOT be used as the sole or final arbiter for substantive or subjective judgments on contributions, nor for evaluating a person's standing in the community. Automated objective validation (CI/CD, testing, linting) is permitted.
When generating commit messages, always include the `Assisted-by:` trailer naming the specific AI model and version used.
## Coding Conventions
### Required vars_files in all group/host playbooks
```yaml
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "{{ private }}/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
```
These hardcoded paths are the production layout on batcave01. Do not make them relative or configurable.
### Style rules
- Use `.yml` not `.yaml` for file extensions. Exception: `vars/all/*.yaml` is historical — don't "fix" this.
- Add `.j2` extension to all Jinja2 templates. A `.yml` file in `templates/` without `.j2` won't render Jinja expressions.
- 2-space YAML indentation. Line length is not enforced.
- Prefer readable multi-line module args over single-line `module: name=x arg=y` format.
- Standard tags: `packages` (installs/removes packages), `config` (installs config files).
- `build` and `rollout` tags use `never` to prevent accidental execution.
- All playbooks must be **idempotent** — they can be run at any time by the nightly cron.
### Common pitfalls
- Forgetting to update multiple files in `vars/all/` together during release transitions (e.g., branching requires `FedoraBranched.yaml`, `00-FedoraCycleNumber.yaml`, `FedoraBranchedBodhi.yaml`, and `Frozen.yaml`).
- Breaking idempotency — generates noise in nightly `--check --diff` and masks real drift.
- OpenShift apps must target `os_control[0]:os_control_stg[0]`, not all control nodes.
### Domain terminology
- **batcave01** — Ansible control host
- **FAS/IPA** — Fedora Account System (identity provider)
- **Koji** — Build system (VM-based, not OpenShift)
- **Bodhi** — Update management (runs on OpenShift)
- **dist-git/src.fedoraproject.org** — Package source repositories
- **fedora-messaging/RabbitMQ** — AMQP message bus connecting services

View file

@ -1,19 +1,19 @@
Fedora Infrastructure
=====================
Welcome! This is the Fedora Infrastructure Ansible Pagure project.
Welcome! This is the Fedora Infrastructure Ansible Forge project.
Pull requests and forks can be made against this repository hosted
at https://pagure.io/fedora-infra/ansible
at <https://forge.fedoraproject.org/infra/ansible>
This repository is also mirrored for production runs to
https://infrastructure.fedoraproject.org/infra/ansible/
<https://infrastructure.fedoraproject.org/infra/ansible/>
but this is the working repository where changes are made.
If you would like to help out with Fedora Infrastructure, see:
* https://docs.fedoraproject.org/en-US/infra/gettingstarted/
* https://docs.fedoraproject.org/en-US/infra/apprentice/
* <https://docs.fedoraproject.org/en-US/infra/gettingstarted/>
* <https://docs.fedoraproject.org/en-US/infra/apprentice/>
Ansible repository/structure
----------------------------
@ -100,19 +100,19 @@ Contributing and Licensing
Contributions to this repository are subject to the Fedora Project
Contributor Agreement. If no license is specified, the MIT license is used, otherwise
the contribution is under the specified acceptable Fedora License.
See https://docs.fedoraproject.org/en-US/legal/fpca/
See <https://docs.fedoraproject.org/en-US/legal/fpca/>
for more information.
Contributing Pull Requests
--------------------------
If found a way to improve this repository or fix an issue found in our
infrastructure tracker (see https://forge.fedoraproject.org/infra/tickets)
infrastructure tracker (see <https://forge.fedoraproject.org/infra/tickets>)
open a pull-request.
You either should have capability to run the playbooks after they have been reviewed,
and merged or find the person responsible and work with them to make sure the changes
will be aplied afterwards.
will be aplied afterwards.
We are currently working on a simple to use list of Point Of Contanct people for the applications
here, untill it is done, you can, look at people that recently edited the ansible files,
@ -120,7 +120,7 @@ or if you belong to sysadmin group, view the /etc/ansible_utils/rbac.yaml locate
where you can see the groups of people that have capabilities to run the relevant playbooks.
For example, to upgrade Release Monitoring, you need to run playbook openshift-apps/release-monitoring.yaml.
People in sysadmin-releasemonitoring have that capability, and you cand find the members in https://accounts.fedoraproject.org/group/sysadmin-releasemonitoring/
People in sysadmin-releasemonitoring have that capability, and you cand find the members in <https://accounts.fedoraproject.org/group/sysadmin-releasemonitoring/>
If the application in question is not on the critical path it should be sufficient,
if person responsible for the application reviews the PR.
@ -131,13 +131,12 @@ at least two different people should review the PR.
If there is any risk at all, that the application of the changes would induce downtime,
work closely with other to ensure that the downtime is properly scheduled:
- there is an issue in https://forge.fedoraproject.org/infra/tickets specifying the downtime
- there is an email sent to the devel-list
- https://status.fedoraproject.org is updated (see https://docs.fedoraproject.org/en-US/infra/sysadmin_guide/status-fedora/)
* there is an issue in <https://forge.fedoraproject.org/infra/tickets> specifying the downtime
* there is an email sent to the devel-list
* <https://status.fedoraproject.org> is updated (see <https://docs.fedoraproject.org/en-US/infra/sysadmin_guide/status-fedora/>)
Applications on critical path: pagure, mirrormanager, toddlers, bodhi, noggin, mdapi, rpmautospec, pagure-dist-git, mirror_from_pagure, fedora-messaging, dist-git, PDC/FPDC, FMN, sigul
Applications on critical path: forge, pagure, mirrormanager, toddlers, bodhi, noggin, mdapi, rpmautospec, pagure-dist-git, mirror_from_pagure, fedora-messaging, dist-git, PDC/FPDC, FMN, sigul
robosignatory, tag2distrepo, ci-resultsdb-listener, stylo, mirrorlist
resultsdb, Nagios, koschei, wiki / mediawiki, wiki / moin, waiverdb,
greenwave, ODCS, Mailman3 / HK, mailman 2, OSBS, pungi, koji, MBS,
resultsdb, Nagios, koschei, wiki / mediawiki, wiki / moin, waiverdb,
greenwave, ODCS, Mailman3 / HK, mailman 2, OSBS, pungi, koji, MBS,
IPA, rabbitmq, geoip,ipsilon

View file

@ -0,0 +1,29 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGpQExgBEADP5+9qybH7gg2aapWmy7dBLL64j45ALFyYtZCFprsFALW4OdIH
5jQwnt/k3ErygvVA2HTsN85f2vTnBUeRyCcZhgx6wLbfxSMqI1eCvWfTgTQ+Xyd/
TB8eDUW5hVPtW3M/9lCNm3gW8FFsY8eo62gbKQFMEHqv4jzvycJHC+dLSJwqDhRo
8QXcw8Xa3yyD1i4x/CJsxgnkbAuNN3FvJ0ALdc4QkeCslTV0R/APZYojOsdOxxj9
6OM8KsHTofoM90x7uDH5SBYfszA/dV38s7IIRMdhQVff7Vyru1Wg19xWAV1DB/XD
fIarhFV+UuzjdGBdYHCh8dJ7f+l3IvzeYtNDdgf1uho6TPU79OaGF5BQdyq3h3Ep
n7MvP7kDmf3zp/169ED1KafBzKlCxCB1f6C5icaddl4GXHhsSnLVU6GNWVDYzs49
PT1iJquGqQIVrdvZPVRxF9EajtOy2ihZrGuyu0CfEhmlxbxodRhl4QWxHtqI9VQf
qr8hNt3PJjQ9ZXF+39u65aV8VmsZm0ifwLjXf028KHYEn/ZxIADJpf6cs3tST/FC
NUdWydaRy15wHZGAW4DjITJYyOaxS/O88c0AYiPpyIzjcdM5X6yPd/Ks7jNp4jix
xq5+in4kT6Ob6i/vLGPiMOg2lgoDyk9Se4Xnfj0mji8BA+0Kd8822UQZtQARAQAB
tEBGZWRvcmEgSW5mcmFzdHJ1Y3R1cmUgKGluZnJhc3RydWN0dXJlKSA8YWRtaW5A
ZmVkb3JhcHJvamVjdC5vcmc+iQJSBBMBCAA8FiEEZsXzm0iCia3GFtyfH6GpJwHY
P8QFAmpQExgCGw8FCwkIBwIDIgIBBhUKCQgLAgQWAgMBAh4HAheAAAoJEB+hqScB
2D/ET3wP/RvrubZbpK5TGSnLnxbOx74RfjSW7B01cKuLEnZV4VMMlqZONTpvMPBT
t69aifiuVYsD1Pynj+WA0HduZdLnoczrlIYAqeAPwGOPz/ogmsEeTtnlCLzAT8Gr
VIT0MR/jhP/IUVuZQ0t7wY2Ezl7yYRnYiB4y8ZuofF8hmby363bceMsX0T/aDQNy
brbWKF38Ag8FQfzhTnYHnlBVUdo0Sdu94uINoW0jh6Y+ml+zusx4rP+BBqEvSQIG
xYEbWaDxxGyrCIIADz6yz6/0w6HYBh8LgqPOfRKqo/0KTe4ZuzX3Ao8r03ZIiQj4
7N+dA8bC9lPgHsoa6hMXamR6Mh1m/561RIzPSN8bkygg3d+Og4sglGI0FojFmdF7
C/WHZwXpMnLkaDIQgju0JCVO9Blut85u7u0WM5AcoEC7ODsv+kxAIFiTAZVf2zh2
1fV+lDyMVOtbykdn7YjbRvFGj3++2CJq+jP3S0Pnsc34eKsY+bw0pmCV2Wu1VPeA
V8hnpeGqz2vyhG8TqSXZnSgWaVR5T52GCNiohqPBMaOrNFa5xoV+FYPAZbPEJf/A
m85HsYgzmE9DbExX9JxrPpPiCmBe/DDmweP7slq+016OUHafR0shOBXVH5OFLU+w
esbMjQFiccYct/oGbfUZVIyDBxAL3Wq8yGzzI4sskR5HqoYIeNYb
=2YPV
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -1,9 +1,10 @@
[epel]
name=Extras Packages for Enterprise Linux $releasever - $basearch
# This is a bit too magic, esp. as we are using the infra. repo. and explicitly
# point to a 10.x variant ... might as well do the same here.
# We aren't using mirrormanager here, but pointing direct to our repos
# So, we want to just point to '10' here and depend on the link that exists
# to point us to the newest minor release.
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10.1/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10z/Everything/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
@ -11,7 +12,7 @@ gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
[epel-testing]
name=Extras Packages for Enterprise Linux $releasever - $basearch
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10.1/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10z/Everything/$basearch/
enabled=0
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10

View file

@ -0,0 +1,6 @@
[infrastructure-tags]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -0,0 +1,6 @@
[infrastructure-tags-stg]
name=Fedora Infrastructure tag $releasever - $basearch
baseurl=https://kojipkgs.fedoraproject.org/repos-dist/epel$releasever-infra-stg/latest/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/repo/infra/RPM-GPG-KEY-INFRA-TAGS-20260709

View file

@ -12,24 +12,25 @@ gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg
enabled=1
gpgcheck=1
# NOTE: When you change the 10.x here also change it in the epel10.repo file.
# These are not using mirrormanager, so point to '10' which will use the link
# to the latest minor release.
[rhel10-BaseOS]
name = rhel10 BaseOS $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/baseos
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/baseos
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-AppStream]
name = rhel10 AppStream $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/appstream
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/appstream
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-CRB]
name = rhel10 CodeReadyBuilder $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/crb
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/crb
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1

View file

@ -1,4 +1,2 @@
# Run quick mirror fedora every 10minutes
*/10 * * * * root flock -n -E0 /tmp/download-sync -c '/root/quick-fedora-mirror/quick-fedora-mirror -c /root/quick-fedora-mirror/quick-fedora-mirror.conf'
## Need to run this to keep centos mirror up to date.
00 1,7,13,19 * * * root /usr/local/bin/lock-wrapper sync-up-downloads "/usr/local/bin/sync-up-centos"

View file

@ -1,5 +1,3 @@
# Run quick mirror fedora every 10minutes
MAILTO=root@fedoraproject.org
*/10 * * * * root flock -n -E0 /tmp/download-sync -c '/root/quick-fedora-mirror/quick-fedora-mirror -c /root/quick-fedora-mirror.conf'
## Need to run this to keep centos mirror up to date.
00 1,7,13,19 * * * root /usr/local/bin/lock-wrapper sync-up-downloads "/usr/local/bin/sync-up-centos"

View file

@ -8,7 +8,7 @@
RSYNC='/usr/bin/rsync'
RS_OPT="-avSHP --numeric-ids"
RS_DEADLY="--delete --delete-excluded --delete-delay --delay-updates"
ALT_EXCLUDES=""
ALT_EXCLUDES="--exclude 44_Beta*" # 2026-04-16 - tmp. running out of space
EPL_EXCLUDES=""
FED_EXCLUDES=""

View file

@ -39,7 +39,7 @@ RewriteRule ^/released/i/m/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/released/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/fedora-infrastructure/report https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://forge.fedoraproject.org/infra/tickets/$1 [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://forge.fedoraproject.org/infra/tickets/issues/$1 [R=301]
RewriteRule ^/fedora-infrastructure https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fesco/report https://pagure.io/fesco/issues [R=301]
@ -90,13 +90,13 @@ RewriteRule ^/gfs2-utils/report https://pagure.io/gfs2-utils/issues [R=301]
RewriteRule ^/gfs2-utils/ticket/(.*) https://pagure.io/gfs2-utils/issue/$1 [R=301]
RewriteRule ^/gfs2-utils https://pagure.io/gfs2-utils [R=301]
RewriteRule ^/elections/report https://pagure.io/elections/issues [R=301]
RewriteRule ^/elections/ticket/(.*) https://pagure.io/elections/issue/$1 [R=301]
RewriteRule ^/elections https://pagure.io/elections [R=301]
RewriteRule ^/elections/report https://forge.fedoraproject.org/apps/elections/issues [R=301]
RewriteRule ^/elections/ticket/(.*) https://forge.fedoraproject.org/apps/elections/issues/$1 [R=301]
RewriteRule ^/elections https://forge.fedoraproject.org/apps/elections [R=301]
RewriteRule ^/fedocal/report https://pagure.io/fedocal/issues [R=301]
RewriteRule ^/fedocal/ticket/(.*) https://pagure.io/fedocal/issue/$1 [R=301]
RewriteRule ^/fedocal https://pagure.io/fedocal [R=301]
RewriteRule ^/fedocal/report https://forge.fedoraproject.org/apps/fedocal/issues [R=301]
RewriteRule ^/fedocal/ticket/(.*) https://forge.fedoraproject.org/apps/fedocal/issue/$1 [R=301]
RewriteRule ^/fedocal https://forge.fedoraproject.org/apps/fedocal [R=301]
RewriteRule ^/FedoraReview/report https://pagure.io/FedoraReview/issues [R=301]
RewriteRule ^/FedoraReview/ticket/(.*) https://pagure.io/FedoraReview/issue/$1 [R=301]

1484
files/scripts/ansilog-playbook.py Executable file

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,94 @@
#!/bin/bash
# vim: ts=4:sw=4:expandtab:tw=100
# This script manages a set of backup files which are prefixed with ISO dates (YYYY-MM-DD).
# - As new files come in, we want to delete the old ones.
# - RETENTION_DAYS decides how old is "old".
# - But if no new files come in (e.g. the backup process is broken), we don't want to
# end up deleting _all_ the files, just because they're old.
# - MIN_KEEP decides how many files to keep.
#
# Usage: ./retain.sh --dry-run <directory>
set -euo pipefail
DRY_RUN=false
DIR=""
# Parse arguments (extremely verbosely to satisfy the LLM reviewing this PR)
while [[ $# -gt 0 ]]; do
case "$1" in
--dry-run)
DRY_RUN=true
shift
;;
-*)
echo "Error: Unknown flag '$1'" >&2
exit 1
;;
*)
if [[ -z "$DIR" ]]; then
DIR="$1"
shift
else
echo "Error: Multiple positional arguments provided. Expected only DIR." >&2
exit 1
fi
;;
esac
done
# Validate required argument
if [[ -z "$DIR" ]]; then
echo "Error: DIR argument is required." >&2
echo "Usage: $0 [--dry-run] DIR" >&2
exit 1
fi
RETENTION_DAYS="${RETENTION_DAYS:-31}"
MIN_KEEP="${MIN_KEEP:-31}"
CUTOFF=$(date -d "${RETENTION_DAYS} days ago" +%Y-%m-%d)
# Collect all dated files (basename matches YYYY-MM-DD-*)
mapfile -t DATED_FILES < <(
find "$DIR" -maxdepth 1 -type f -name "[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-*" \
| sort -r # sort descending by filename (date first)
)
total=${#DATED_FILES[@]}
$DRY_RUN && echo "*** DRY RUN — no files will be deleted ***"
echo ""
if [[ $total -eq 0 ]]; then
echo "No dated files found in '$DIR'."
exit 0
fi
deleted=0
skipped_retention=0
for i in "${!DATED_FILES[@]}"; do
filepath="${DATED_FILES[$i]}"
filename=$(basename "$filepath")
file_date="${filename:0:10}" # extract YYYY-MM-DD
# Always keep the MIN_KEEP most-recent files (indices 0..MIN_KEEP-1)
if [[ $i -lt $MIN_KEEP ]]; then
echo "KEEP (newest ${MIN_KEEP}): $filename"
continue
fi
# Delete if the file's date is before the cutoff
if [[ "$file_date" < "$CUTOFF" ]]; then
echo "DELETE (expired): $filename"
$DRY_RUN || rm -- "$filepath"
deleted="$((deleted + 1))"
else
echo "KEEP (within retention): $filename"
skipped_retention="$((skipped_retention + 1))"
fi
done
echo ""
echo "Deleted: $deleted files (dry-run=$DRY_RUN). Kept by min-count: $(( total < MIN_KEEP ? total : MIN_KEEP )). Kept by date window: $skipped_retention."

View file

@ -0,0 +1,22 @@
---
# Optional annotations for openshift-app-image-report.py.
#
# The scanner reads the OpenShift app files directly. Use this file for cases
# that static scanning cannot infer, such as Jinja variables, external
# Dockerfiles, or manually maintained tags.
# fill in like
# annotations:
# - app: <roles/openshift-apps/THIS>
# match: <string to match in image/source or path>
# os_version: <replacemet version text>
# kind: <optional replacement kind>
# note: <display note>
# EXAMPLE:
# annotations:
# - app: transtats
# match: registry.fedoraproject.org/fedora:34
# os_version: Fedora 34
# note: Inline Dockerfile base image; should be reviewed for EOL.
annotations: []

View file

@ -0,0 +1,522 @@
#! /usr/bin/python3
import argparse
import os
import re
import sys
from dataclasses import dataclass
from pathlib import Path
try:
import yaml
except ImportError:
yaml = None
SCRIPT_DIR = Path(__file__).resolve().parent
NOTES_FILE = SCRIPT_DIR / "openshift-app-image-notes.yml"
def find_repo_root(start):
for path in (start, *start.parents):
if (path / "roles" / "openshift-apps").is_dir():
return path
print("Error: could not find roles/openshift-apps above script path", file=sys.stderr)
sys.exit(2)
REPO_ROOT = find_repo_root(SCRIPT_DIR)
APP_ROOT = REPO_ROOT / "roles" / "openshift-apps"
IMAGE_PREFIXES = (
"docker.io/",
"docker-registry.",
"fedora:",
"image-registry.",
"quay.io/",
"redis:",
"registry.access.redhat.com/",
"registry.fedoraproject.org/",
"solr:",
"valkey/",
"busybox",
)
@dataclass(frozen=True)
class Finding:
app: str
env: str
kind: str
image: str
os_version: str
floating: bool
unresolved: bool
path: str
line: int
note: str = ""
def _strip_value(value):
value = value.strip()
if value.startswith(("'", '"')) and value.endswith(("'", '"')):
value = value[1:-1]
return value.strip()
def _looks_like_image(value):
value = _strip_value(value)
if not value:
return False
if value.startswith(IMAGE_PREFIXES):
return True
if "/" in value and ":" in value:
return True
if ":" in value and not value.startswith(("http://", "https://")):
return True
return False
def _tag_from_image(image):
if "@" in image:
return image.rsplit("@", 1)[1]
# Only inspect the image-name tail so registry ports are not treated as tags.
tail = image.rsplit("/", 1)[-1]
if ":" not in tail:
return ""
return tail.rsplit(":", 1)[1]
def _is_floating(image):
if "{{" in image:
return False
tag = _tag_from_image(image)
return tag in ("", "latest")
def _python_version(text):
match = re.search(r"python[-:]?(\d)(\d{1,2})", text)
if not match:
return ""
major, minor = match.groups()
return f"Python {major}.{minor}"
def _infer_os_version(image):
low = image.lower()
match = re.search(
r"(?:registry\.fedoraproject\.org/|quay\.io/fedora/)?fedora:(\d+|latest)", low
)
if match:
return f"Fedora {match.group(1)}"
match = re.search(r"ubi(\d+)", low)
if match:
parts = [f"UBI {match.group(1)}"]
pyver = _python_version(low)
if pyver:
parts.append(pyver)
nginx = re.search(r"nginx[-:]?(\d)(\d{2})", low)
if nginx:
parts.append(f"nginx {nginx.group(1)}.{nginx.group(2)}")
return " / ".join(parts)
pyver = _python_version(low)
if pyver:
return pyver
if low.startswith("busybox"):
return "busybox"
if low.startswith("redis:"):
return "redis"
if "bitnami" in low and re.search(r"(^|[/:_-])redis($|[/:_.-])", low):
return "redis"
if low.startswith("solr:"):
return "Solr"
if low.startswith("valkey/") or low.startswith("valkey:"):
return "Valkey"
return "?"
def _source_kind(line, value):
stripped = line.strip()
if stripped.startswith("FROM "):
return "dockerfile-from"
if stripped.startswith("image:"):
return "runtime-image"
if stripped.startswith("dockerfilePath:"):
return "dockerfile-path"
if stripped.startswith("uri:"):
return "git-source"
if stripped.startswith("ref:"):
return "git-ref"
if stripped.startswith("name:"):
if value.startswith("image-registry.") or value.startswith("docker-registry."):
return "internal-image"
return "image-or-builder"
return "image-reference"
def _env_from_jinja_condition(line):
if "env" not in line:
return None
if re.search(r"env\s*==\s*['\"]staging['\"]", line):
return "staging"
if re.search(r"env\s*==\s*['\"]production['\"]", line):
return "production"
return "conditional"
def _opposite_env(env):
if env == "staging":
return "production"
if env == "production":
return "staging"
return "conditional"
def _update_env_scope(line, env_stack, current_env):
stripped = line.strip()
if not stripped.startswith("{%"):
return current_env
if re.match(r"{%-?\s*if\b", stripped):
next_env = _env_from_jinja_condition(stripped)
env_stack.append((current_env, next_env))
return next_env or current_env
if re.match(r"{%-?\s*elif\b", stripped):
next_env = _env_from_jinja_condition(stripped)
if env_stack:
previous_env, _old_env = env_stack[-1]
env_stack[-1] = (previous_env, next_env)
return next_env or current_env
if re.match(r"{%-?\s*else\s*-?%}", stripped):
if not env_stack:
return "conditional"
_previous_env, if_env = env_stack[-1]
if if_env is None:
return current_env
return _opposite_env(if_env)
if re.match(r"{%-?\s*endif\s*-?%}", stripped):
if not env_stack:
return "all"
previous_env, _if_env = env_stack.pop()
return previous_env
return current_env
def _line_env(line, current_env):
if "{{" in line and "env" in line and "ternary" in line:
return "conditional"
return current_env
def _iter_scan_files(app_dir):
for path in sorted(app_dir.rglob("*")):
if not path.is_file():
continue
rel_parts = path.relative_to(app_dir).parts
if not rel_parts or rel_parts[0] not in ("files", "templates", "vars"):
continue
name = path.name.lower()
suffix = path.suffix.lower()
if suffix in (".yml", ".yaml", ".j2", ".toml", ".cfg"):
yield path
continue
if "dockerfile" in name or "containerfile" in name:
yield path
def _scan_line(line):
stripped = line.strip()
if not stripped or stripped.startswith("#"):
return None
if stripped.startswith("FROM "):
parts = stripped.split()
if len(parts) > 1:
return parts[1], True
return None
for key in ("image:", "name:", "dockerfilePath:", "uri:", "ref:"):
if not stripped.startswith(key):
continue
value = _strip_value(stripped[len(key) :])
if key == "dockerfilePath:":
return value, False
if key in ("uri:", "ref:"):
if "github.com" in value or "gitlab" in value or "{{" in value:
return value, False
return None
if key == "image:" and "{{" in value:
return value, True
if _looks_like_image(value):
return value, True
return None
return None
def scan_apps(app_filter=None):
findings = []
wanted = set(app_filter or [])
for app_dir in sorted(APP_ROOT.iterdir()):
if not app_dir.is_dir():
continue
app = app_dir.name
if wanted and app not in wanted:
continue
for path in _iter_scan_files(app_dir):
rel_path = path.relative_to(REPO_ROOT).as_posix()
try:
lines = path.read_text(encoding="utf-8").splitlines()
except UnicodeDecodeError:
continue
env_stack = []
current_env = "all"
for lineno, line in enumerate(lines, 1):
current_env = _update_env_scope(line, env_stack, current_env)
scanned = _scan_line(line)
if not scanned:
continue
value, is_image = scanned
unresolved = "{{" in value or "{%" in value
if line.strip().startswith("dockerfilePath:"):
unresolved = True
kind = _source_kind(line, value)
os_version = _infer_os_version(value) if is_image else "?"
findings.append(
Finding(
app=app,
env=_line_env(line, current_env),
kind=kind,
image=value,
os_version=os_version,
floating=_is_floating(value) if is_image else False,
unresolved=unresolved,
path=rel_path,
line=lineno,
)
)
return findings
def load_annotations(notes_file):
if not notes_file.exists():
return []
if yaml is None:
print(
"Error: python3-yaml is required to read openshift-app-image-notes.yml",
file=sys.stderr,
)
sys.exit(2)
with notes_file.open(encoding="utf-8") as stream:
data = yaml.safe_load(stream) or {}
annotations = data.get("annotations", [])
if not isinstance(annotations, list):
print(
"Error: annotations must be a list in openshift-app-image-notes.yml",
file=sys.stderr,
)
sys.exit(2)
return annotations
def apply_annotations(findings, annotations):
by_key = {}
for item in annotations:
if not isinstance(item, dict):
continue
app = item.get("app")
match = item.get("match", "")
note = item.get("note", "")
os_version = item.get("os_version", "")
kind = item.get("kind", "")
if not app or not match:
continue
by_key[(app, match)] = (note, os_version, kind)
used = set()
updated = []
for finding in findings:
note = finding.note
os_version = finding.os_version
kind = finding.kind
for (app, match), values in by_key.items():
if app != finding.app:
continue
if match not in finding.image and match not in finding.path:
continue
used.add((app, match))
ann_note, ann_os, ann_kind = values
note = ann_note or note
os_version = ann_os or os_version
kind = ann_kind or kind
updated.append(
Finding(
app=finding.app,
env=finding.env,
kind=kind,
image=finding.image,
os_version=os_version,
floating=finding.floating,
unresolved=finding.unresolved,
path=finding.path,
line=finding.line,
note=note,
)
)
return updated, sorted(set(by_key) - used)
def filter_findings(findings, args):
filtered = findings
if args.env:
wanted = set(args.env)
env_matches = set(wanted)
if "staging" in wanted or "production" in wanted:
env_matches.add("all")
filtered = [item for item in filtered if item.env in env_matches]
if args.kind:
wanted = set(args.kind)
filtered = [item for item in filtered if item.kind in wanted]
if args.floating_only:
filtered = [item for item in filtered if item.floating]
if args.unresolved_only:
filtered = [item for item in filtered if item.unresolved]
return filtered
def _short_path(finding):
prefix = f"roles/openshift-apps/{finding.app}/"
path = finding.path
if path.startswith(prefix):
path = path[len(prefix) :]
return f"{path}:{finding.line}"
def _clip(value, width):
if len(value) <= width:
return value
if width <= 1:
return value[:width]
return value[: width - 3] + "..."
def print_table(findings):
columns = (
("APP", 22),
("ENV", 11),
("KIND", 16),
("OS/VERSION", 20),
("FLOAT", 5),
("PATH", 58),
("NOTE", 30),
("IMAGE/SOURCE", None),
)
rows = []
for finding in findings:
rows.append(
(
finding.app,
finding.env,
finding.kind,
finding.os_version,
"yes" if finding.floating else "",
_short_path(finding),
finding.note,
("?" if finding.unresolved else "") + finding.image,
)
)
print(
" ".join(
name if width is None else name.ljust(width) for name, width in columns
)
)
print(
" ".join(
"-" * len(name) if width is None else "-" * width for name, width in columns
)
)
for row in rows:
print(
" ".join(
value if width is None else _clip(value, width).ljust(width)
for value, (_name, width) in zip(row, columns)
)
)
print(f"\n{len(rows)} findings")
def parse_args(argv):
parser = argparse.ArgumentParser(
description="Print OpenShift app image and base-image references found in roles/openshift-apps.",
)
parser.add_argument(
"--app",
action="append",
help="Only report one app. May be used more than once.",
)
parser.add_argument(
"--kind",
action="append",
help="Only report one finding kind. May be used more than once.",
)
parser.add_argument(