1
0
Fork 0
forked from infra/ansible

Merge branch 'main' into nftables

* main: (2174 commits)

Signed-off-by: James Antill <james@and.org>
This commit is contained in:
James Antill 2026-05-01 11:57:58 -04:00
commit ba4470365e
1913 changed files with 44064 additions and 34610 deletions

View file

@ -66,3 +66,4 @@ skip_list:
- yaml
- role-name[path]
- var-naming[no-role-prefix]
- no-changed-when

View file

@ -107,7 +107,7 @@ Contributing Pull Requests
--------------------------
If found a way to improve this repository or fix an issue found in our
infrastructure tracker (see https://pagure.io/fedora-infrastructure/issues)
infrastructure tracker (see https://forge.fedoraproject.org/infra/tickets)
open a pull-request.
You either should have capability to run the playbooks after they have been reviewed,
@ -131,13 +131,13 @@ at least two different people should review the PR.
If there is any risk at all, that the application of the changes would induce downtime,
work closely with other to ensure that the downtime is properly scheduled:
- there is an issue in https://pagure.io/fedora-infrastructure/issues specifying the downtime
- there is an issue in https://forge.fedoraproject.org/infra/tickets specifying the downtime
- there is an email sent to the devel-list
- https://status.fedoraproject.org is updated (see https://docs.fedoraproject.org/en-US/infra/sysadmin_guide/status-fedora/)
Applications on critical path: pagure, mirrormanager, toddlers, bodhi, noggin, mdapi, rpmautospec,
pagure-dist-git, mirror_from_pagure, fedora-messaging, dist-git, PDC/FPDC, FMN, sigul
Applications on critical path: pagure, mirrormanager, toddlers, bodhi, noggin, mdapi, rpmautospec, pagure-dist-git, mirror_from_pagure, fedora-messaging, dist-git, PDC/FPDC, FMN, sigul
robosignatory, tag2distrepo, ci-resultsdb-listener, stylo, mirrorlist
resultsdb, Nagios, koschei, wiki / mediawiki, wiki / moin, waiverdb,
greenwave, ODCS, Mailman3 / HK, mailman 2, OSBS, pungi, koji, MBS,
IPA, rabbitmq, geoip,ipsilon

View file

@ -0,0 +1,32 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.22 (GNU/Linux)
mQENBF3jBZQBCAC3mGl8pmWoOuUzh8rJAbaqiOXEZ8wa904VN2bTDgxydtwL16cy
ad54OaW+jyD0+api5b5pKmmu+7qLT3vfndITQaF8lE1w+1qSFFJpbxOSsqU7rVx5
+KpqfmfBJ9/jTIQsCcIdcx8Ajachgjifj1bM48quYE5pQp4YTu+I/HhwjacO9CEt
yIcX48wph2CbvY/xPX8E+8kdrc4/gd3F9c5Nmvj5Xa22QsXpCzrJSO5Vm8NIGycU
O4NhE4ctQLa5MqydvyAyORA4IYrzsK1Ioa8MJeeKvUQ46NWR+N2AsTQPbnULAiJM
ef3giEt56YpPx3JMe7G4XfAgsnYQphhFdV5VABEBAAG0Y0NlbnRPUyBNZXNzYWdp
bmcgU0lHIChodHRwczovL3dpa2kuY2VudG9zLm9yZy9TcGVjaWFsSW50ZXJlc3RH
cm91cC9NZXNzYWdpbmcpIDxzZWN1cml0eUBjZW50b3Mub3JnPokBOQQTAQoAIwIb
AwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheABQJiTWLmAAoJEIMBTrvhbg0SQFYH
/0RFI9yxWGchuygAlsiX8bBgp0oM/vWmX+b5gZuZBM0vCPFYgICCSG5yVcRZofqx
QBCOQ5tCVPlGR6DGxRjKlJJ5AIFLDh57no76wbR+RQAzMzXxrRNSlbu8ccwJX10e
njSOLvPvKXq16HuLq2PJ2p7ZkmsCpab9fiD080RFXvgr9cQ7etE5jp55zo5zRmF6
CGSpjZKcgVwRc5zPq3W1OwT7LQNZhClotlWT3RjujkmFkhYjEK4Q2HO9dRc/lHXz
B24suCv7wGtyUcGr1ghqNGQV5kr2uBpqTK8pvOFs+jJRczGmnUcY8YVKUo/fJZEV
eGTZc4X0Gfhq2nGTWE4xcDy5AQ0EXeMFlAEIANFN5aHtItH/5c0hxBNv8S4yDnEm
NwHKzWQBPJv69zjcokjYyAImRs6EqbEKL2hWA+9AbrLOC+s1Fya3U0EJIZmVKsuj
8GFaFBB7l26t596re8aWMWf+sbHGgBPHxi+Z/3LAkBGViI5r1WZO1h3b/v9j3QOA
A8WIVAcqGzwbBQDCV4zVZuePoNouYhMLvjai3Y3Ydd8vnZyGT02Zk4zYgBOw7cnh
0yveyYxJ+11x53UJXFmGI/vbslqmnWawp0eqT5T/TH45KNXHglvGqPct+6FdQ9N/
sIFjjYDXxuFNr3jCleXdP3SSi+Fvx7OrIVGmXNa0b02DWjci0wouXR0kGn0AEQEA
AYkBHwQYAQoACQIbDAUCYk1i2gAKCRCDAU674W4NEgtpB/9YAciHdlQm9Bfk/lwA
otibXlqqzQAtjQ7UAbHsPYL1s8ty1RxrW3Moi2y6fVFcFaDpzo8MEXO22TV7Pff+
hnhvea/XhXcIpTCEKfuK2gapvVIQ6cHFqpbthrzTj7SAOdp9mxkxdqXYVsiMAoWl
PweZDxc+S73ryC6OexoI6s/HJBQcmcnhArdQUAxQQed//oEFfz+Gznj3VBsFumMV
Hldqd3MYc1mcPC5ok4oBoBY2QYg74NYSxIZU5DVsv/rJYrw0cz7+539f9TgOCYqs
GbyAJgLIJBBZnS0rPyqCEbMyV1H2ah2FgPGFKxo1uVtRWA2/oulu96uHJFeN9rSg
Ud3Q
=SGO3
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -0,0 +1,29 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGV4X6kBEAC3eQxgiWuo08uc3mHo4ELux++uqTnYz/tJzEf9Ou3h36WnhumA
Nvs+Ts5h8PBx879Y9/aIX1Z20p1kf6tBCinZnEJu59n+TAAsph0+XQlV1l5YkleK
Z2ff/Fg65k8QcLXWaIGykA/FaKznRiSurGuD6tRGhJw7DawEwBJr8QZSkRUpnH1L
URW97Q/iKrRPiE5VEayE0y8eAL28jIIiFvR+4oJMzvCsRRB/2wYZ2MlJOW91hcYf
mbUoXKOBD5UzsJylu7kj25K/ge8rEJ7KicOOwcdYddxsU3DxGSSfwF8AMagENcm2
XROeXknjm84A8sNlUkFZBJwfuc7eRTiZGJrnQQVYLrkKj8Mxpq9Ts7hU51TqAWNI
uvGDlJdYNE3D2RMqjMEsZ8ej08Thrib6xslu4NzTBkt+6QNnXL4E3hEgYtoyio60
GswSz2ulogKg7X4JrNdJYE8/qNowyF3hoVgj5TG1/wQRq+5HlMMOLjgGu9wzLUix
fnVfEUnzaofbrUf4/GabCaeY8xRe4tFQrvzigQ4g+kgwKKnfAeqBmPov0yljkw9z
BYJWR5zvaw0ffg9Ing00KUSaXBXA5jSlgk1603Y+LefY1SlXsTyqohiRvGH6FI77
HNMo72DwoJfFcYjncZUzKgXWJECR4nhVsdj6pKoOjcQ4aSuyVxtsR86ASQARAQAB
tChGZWRvcmEgKGVwZWwxMCkgPGVwZWxAZmVkb3JhcHJvamVjdC5vcmc+iQJOBBMB
CAA4FiEEfY0Vy/xOYmiFkfsmM9mFF+N+0VgFAmV4X6kCGw8FCwkIBwIGFQoJCAsC
BBYCAwECHgECF4AACgkQM9mFF+N+0Vhv/A/+PlhPLSctGRCUEahE+cN4764Acc3p
l40ZYzXRhqR0/Tc1/cSDjlA3qVTc8SPohi5OJXwCyr9EiMqKoyoDN097euqbYpyp
yN/Pj0lBjsXwcpdDtZ21WGeQU0Khb04N68bMtJbDaxeBciTvDDQravZuPPh0m4Rg
Z6myEoa6Aa6EK0hI1Qwi1qIWeRiuEkVT671IaKVETBW5XiUpNBXDAB/L+6DzUF9u
scBzfsUDiPO6NrpYDtV3jwq22y6gWluIct/Ka8brwPbqK2sBfFzrHboRhfqlTGjs
7F9qUGwIQZn/A8iozXZYQ0+JG1bhQyvjA8eN1GOcRpT+O7H7JXN49o6IG2As4+iK
F04+qjqAu2sVfpD8mzM2VubFNllcKKiyCzRYHhSbObRCPzsudDL9GPiXeGGaCuWg
sDkiA1MESvf2tLETAGBs/TziO4GwmXUtlKbRiq1FYm90mVq9mBxPZ/Idn+yZusNB
0O5SXIbI8lYZw5n4XTK4b+byHRBYsOTHiTsGvjTF2Y7oSwW2CVUmL6RZ23mI4qoY
1p5kzRS+GjT1acnTei/FTsOlIKCsjfeHx7uxCkX6xpAD8P3UtLQqfsgH0CL4vSZt
TGO6L1InQlp4ZG3OYIomTKbD3/R0wod3U3dTqdulQMXL895u6OLTY3spY2m2MO2k
p9Dfd2pKuxK9Mys=
=mhQZ
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -0,0 +1,23 @@
# See: https://git.centos.org/rpms/centos-release-messaging/blob/c9s-sig-messaging/f/SOURCES
[centos-rabbitmq38]
# Yes, the repo is called 38. Yes, it only contains 3.9.x packages as of 2025-06
name=CentOS-9 - RabbitMQ 38 (3.9.x) - $basearch
#baseurl=<mirror>/CentOS-Stream/SIGs/9-stream/messaging/x86_64/rabbitmq-38/
metalink=https://mirrors.centos.org/metalink?release=$releasever&arch=$basearch&repo=centos-messaging-sig-rabbitmq-38-9-stream&protocol=https,http
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-SIG-Messaging
[centos-rabbitmq-38-test]
name=CentOS-8 - RabbitMQ 38 Testing
baseurl=https://buildlogs.centos.org/centos/$releasever-stream/messaging/$basearch/rabbitmq-38/
gpgcheck=0
enabled=0
[centos-rabbitmq-38-source]
name=CentOS-8 - RabbitMQ 38 - Source
baseurl=http://mirror.stream.centos.org/SIGs/$releasever-stream/messaging/source/rabbitmq-38/
gpgcheck=1
enabled=0
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-SIG-Messaging

View file

@ -1,13 +1,17 @@
[epel]
name=Extras Packages for Enterprise Linux $releasever - $basearch
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10/Everything/$basearch/
# This is a bit too magic, esp. as we are using the infra. repo. and explicitly
# point to a 10.x variant ... might as well do the same here.
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10.1/Everything/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
[epel-testing]
name=Extras Packages for Enterprise Linux $releasever - $basearch
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10/Everything/$basearch/
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10.1/Everything/$basearch/
enabled=0
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10

View file

@ -0,0 +1,24 @@
[epel]
name=Extra Packages for Enterprise Linux $releasever - $basearch
#baseurl=https://download.example/pub/epel/$releasever/Everything/$basearch/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel-$releasever&arch=$basearch&infra=$infra&content=$contentdir
enabled=1
gpgcheck=1
countme=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever
[epel-debuginfo]
name=Extra Packages for Enterprise Linux $releasever - $basearch - Debug
#baseurl=https://download.example/pub/epel/$releasever/Everything/$basearch/debug/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel-debug-$releasever&arch=$basearch&infra=$infra&content=$contentdir
enabled=0
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever
gpgcheck=1
[epel-source]
name=Extra Packages for Enterprise Linux $releasever - $basearch - Source
#baseurl=https://download.example/pub/epel/$releasever/Everything/source/tree/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel-source-$releasever&arch=$basearch&infra=$infra&content=$contentdir
enabled=0
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever
gpgcheck=1

View file

@ -12,23 +12,24 @@ gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg
enabled=1
gpgcheck=1
# NOTE: When you change the 10.x here also change it in the epel10.repo file.
[rhel10-BaseOS]
name = rhel10 BaseOS $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.0/repos/$basearch/baseos
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/baseos
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-AppStream]
name = rhel10 AppStream $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.0/repos/$basearch/appstream
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/appstream
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-CRB]
name = rhel10 CodeReadyBuilder $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.0/repos/$basearch/crb
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/crb
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1

View file

@ -1,4 +1,5 @@
[Service]
Restart=always
TasksMax=40
CPUAccounting=yes
IOAccounting=yes

View file

@ -11,17 +11,6 @@ RS_DEADLY="--delete --delete-excluded --delete-delay --delay-updates"
EPL_EXCLUDES=""
FED_EXCLUDES=""
# CentOS
${RSYNC} ${RS_OPT} ${RS_DEADLY} download-cc-rdu01.fedoraproject.org::centos/ /srv/centos/ | tail -n2 | logger -p local0.notice -t rsync_centos
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS"
fi
# CentOS-altarch
${RSYNC} ${RS_OPT} ${RS_DEADLY} download-cc-rdu01.fedoraproject.org::centos-altarch/ /srv/centos-altarch/ | tail -n2 | logger -p local0.notice -t rsync_centos_alt
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS-altarch"
fi
${RSYNC} ${RS_OPT} ${RS_DEADLY} rsync.stream.centos.org::CentOS-Stream-All/ /srv/centos-stream/ | tail -n2 | logger -p local0.notice -t rsync_centos_stream
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS-stream"

View file

@ -11,17 +11,6 @@ RS_DEADLY="--delete --delete-excluded --delete-delay --delay-updates"
EPL_EXCLUDES=""
FED_EXCLUDES=""
# CentOS
${RSYNC} ${RS_OPT} ${RS_DEADLY} master-1.centos.org::CentOS-community-cage/centos/ /srv/centos/ | tail -n2 | logger -p local0.notice -t rsync_centos
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS"
fi
# CentOS-altarch
${RSYNC} ${RS_OPT} ${RS_DEADLY} master-1.centos.org::CentOS-community-cage/altarch/ /srv/centos-altarch/ | tail -n2 | logger -p local0.notice -t rsync_centos_alt
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS-altarch"
fi
${RSYNC} ${RS_OPT} ${RS_DEADLY} rsync.stream.centos.org::CentOS-Stream-All/ /srv/centos-stream/ | tail -n2 | logger -p local0.notice -t rsync_centos_stream
if [[ $? -ne 0 ]]; then
echo "Unable to finish sync to CentOS-stream"

View file

@ -38,9 +38,9 @@ RewriteRule ^/released/i/m/imapsync/(.*) https://pagure.io/releases/imapsync/$1
RewriteRule ^/released/i/m/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/released/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/fedora-infrastructure/report https://pagure.io/fedora-infrastructure/issues [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://pagure.io/fedora-infrastructure/issue/$1 [R=301]
RewriteRule ^/fedora-infrastructure https://pagure.io/fedora-infrastructure [R=301]
RewriteRule ^/fedora-infrastructure/report https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://forge.fedoraproject.org/infra/tickets/$1 [R=301]
RewriteRule ^/fedora-infrastructure https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fesco/report https://pagure.io/fesco/issues [R=301]
RewriteRule ^/fesco/ticket/(.*) https://pagure.io/fesco/issue/$1 [R=301]

View file

@ -1,7 +1,4 @@
/var/log/httpd/*log
{% if ansible_hostname.startswith("kojipkgs") %}
/var/log/httpd/*.log.????-??-??
{% endif %}
{
daily
rotate 7

57
files/scripts/reboot-decider.sh Executable file
View file

@ -0,0 +1,57 @@
#! /bin/sh -e
# Simple script to maybe reboot the machine.
# We want to reboot if:
#
# * There's a new kernel installed.
#
# ...also if we are running from cron, we probably only want to reboot if
# there's nobody logged into the machine (Eg. the *-test.* machines, or
# maybe someone debugging a staging machine).
CUR_KERNEL="$(uname -r)"
_DEF_KERN_PATH="$(grubby --default-kernel)"
NXT_KERNEL=$(basename "$_DEF_KERN_PATH" | sed 's/^vmlinuz-//')
# How many users are logged into the machine.
USER_COUNT=$(who | wc -l)
function err {
echo "$@" >&2
}
function maybe_reboot {
if [ "x$CUR_KERNEL" != "x$NXT_KERNEL" ]; then
reboot
fi
}
case "$1" in
info)
echo "-------- Kernel Status Check --------"
echo "Running: $CUR_KERNEL"
if [ "x$CUR_KERNEL" != "x$NXT_KERNEL" ]; then
echo " Next: $NXT_KERNEL"
fi
echo "-------------------------------------"
echo "Users: $USER_COUNT"
;;
maybe-reboot)
maybe_reboot
;;
maybe-cron-reboot|cron-maybe-reboot)
if [ "$USER_COUNT" -eq 0 ]; then
maybe_reboot
fi
;;
*)
err "Usage: $0 info | maybe-reboot | cron-maybe-reboot"
exit 1
esac

View file

@ -0,0 +1,276 @@
#! /usr/bin/python3
# When logging to files with Apache/httpd rotatelogs and using the date
# specifiers nothing will ever cleanup the old logfiles.
# This is a simple script which will do that.
# Eg. To keep the last 16 days of the following rotatelogs...
# | rotatelogs 'foo.log-%Y-%m-%d_%H:%M' 86400A
# rotatelogs-cleanup.py keep 16 foo.log-'%Y-%m-%d_%H:%M'
# rotatelogs-cleanup.py compress foo.log-'%Y-%m-%d_%H:%M'
# ...this sorts the files that match the wildcard, and removes the oldest
# until there are 16 left. We don't actually parse the time, but converts
# it to globs and will ignore files like:
# foo.log-X-blah-test
# foo.log-2004-01-02_12:34.old
#
# We do treat zero length files differently, removing them before older
# files with data (ignoring the latest file, if it's zero length).
#
conf_rm = True # For testing, we can turn this off and nothing gets deleted
# Do we want to rm zero length files when we are compressing.
conf_rm_zero_len_compress = False
conf_compress_cmd_gz = ["gzip", "-9"]
conf_compress_cmd_xz = ["xz", "-9"]
conf_compress_cmd_def = conf_compress_cmd_xz
import argparse
import glob
import os
import subprocess
import sys
def ftime2glob(fmt):
ftime_rep = (
("%A", "*"),
("%a", "???"),
("%B", "*"),
("%b", "???"),
("%c", "*"),
("%d", "??"),
("%H", "??"),
("%I", "??"),
("%j", "??"),
("%M", "??"),
("%m", "??"),
("%p", "*"),
("%S", "??"),
("%U", "??"),
("%W", "??"),
("%w", "?"),
("%X", "*"),
("%x", "*"),
("%Y", "????"),
("%y", "??"),
("%Z", "*"),
("%%", "%"),
)
for key in ftime_rep:
fmt = fmt.replace(*key)
return fmt
def _unlink(fname):
# Don't blow up everything if we can't rm a file...
try:
os.unlink(fname)
except OSError as e:
print("Error: rm(%s): %s" % (fname, e), file=sys.stderr)
def read_count(fo):
CHUNK_SIZE = 8192
tot = 0
while True:
chunk = fo.read(CHUNK_SIZE)
# If the chunk is empty, we've reached the end of the file
if not chunk:
break
tot += len(chunk)
return tot
def uncompressed_file_size(fname, stop_any=False):
if False:
pass
elif fname.endswith(".gz"):
p = subprocess.Popen(["zcat", fname], stdout=subprocess.PIPE)
elif fname.endswith(".xz"):
p = subprocess.Popen(["xzcat", fname], stdout=subprocess.PIPE)
else:
return os.path.getsize(fname)
if not stop_any:
return read_count(p.stdout)
# We want to know if there's any data there
d = p.stdout.read(1)
p.terminate()
return len(d)
def uncompressed_file_not_empty(fname):
return uncompressed_file_size(fname, stop_any=True) > 0
def _rm_zero_len(files):
if not files:
return []
nfiles = []
for fname in files[:-1]: # Don't delete the latest, even if empty
try:
sz = uncompressed_file_not_empty(fname)
except:
nfiles.append(fname)
continue
if sz == 0:
_ui_unlink(fname)
continue
nfiles.append(fname)
nfiles.append(files[-1]) # Add latest back
return nfiles
def _ui_unlink(fname):
print("rm", fname)
if conf_rm:
_unlink(fname)
def _ui_int(num):
return "{:_}".format(int(num))
def _glob(ftime_path, rm_zero_len=False):
ftime_path = ftime2glob(ftime_path)
files = glob.glob(ftime_path)
if ftime_path[-1] != "*": # Make sure we include the compressed files.
files += glob.glob(ftime_path + ".gz")
files += glob.glob(ftime_path + ".xz")
files = sorted(files)
files = list(files)
if rm_zero_len:
files = _rm_zero_len(files)
return files
# --- commands ----
def _cmd_compress(args):
files = _glob(args.ftime_path, conf_rm_zero_len_compress)
if False:
pass
elif args.cmd == "gzip":
cmd = conf_compress_cmd_gz
elif args.cmd == "xz":
cmd = conf_compress_cmd_xz
else: # compress/etc
cmd = conf_compress_cmd_def
files = files[:-1] # Everything but the latest
for fname in files:
if fname.endswith(".gz"):
continue
if fname.endswith(".xz"):
continue
print(cmd[0], fname)
subprocess.call(cmd + [fname])
def _cmd_ls(args):
files = _glob(args.ftime_path)
nfiles = []
for fname in files:
sz = ''
if args.cmd != "ls-f":
sz = _ui_int(uncompressed_file_size(fname))
nfiles.append((sz, fname))
msz = 0
for sz, _ in nfiles:
msz = max(msz, len(sz))
for sz, fname in nfiles:
if args.cmd != "ls-f":
print("%*s %s" % (msz, sz, fname))
else:
print(fname)
def _cmd_keep(args):
files = _glob(args.ftime_path, True)
files = files[: -args.num]
for fname in files:
_ui_unlink(fname)
def _cmd_rm(args):
files = _glob(args.ftime_path)
for fname in files:
_ui_unlink(fname)
def _cmd_show(args):
print(ftime2glob(args.ftime_path))
# --- main ----
def _parse_positive_integer(oval):
try:
val = int(oval)
except:
val = -1
if val <= 0:
raise argparse.ArgumentTypeError(f"{oval} is not a positive integer")
return val
def _main():
parser = argparse.ArgumentParser()
# parser.add_argument("-v", dest="verbose", action="store_true")
subparsers = parser.add_subparsers(required=True, dest="cmd")
cmd = subparsers.add_parser("help")
cmd.set_defaults(func=lambda x: parser.print_help())
hlp_ftime = "ftime expanded path (see rotatelogs)"
hlp_num = "number of files to keep"
hlp = "compress old files"
als = ["gzip", "xz"]
cmd = subparsers.add_parser("compress", aliases=als, help=hlp)
cmd.add_argument("ftime_path", help=hlp_ftime)
cmd.set_defaults(func=_cmd_compress)
cmd = subparsers.add_parser("keep", help="remove old files")
hlp = "number of files to keep"
cmd.add_argument("num", type=_parse_positive_integer, help=hlp)
cmd.add_argument("ftime_path", help=hlp_ftime)
cmd.set_defaults(func=_cmd_keep)
hlp = "list all files"
cmd = subparsers.add_parser("list", aliases=["ls", "ls-f"], help=hlp)
cmd.add_argument("ftime_path", help=hlp_ftime)
cmd.set_defaults(func=_cmd_ls)
hlp = "remove all files"
cmd = subparsers.add_parser("remove", aliases=["rm"], help=hlp)
cmd.add_argument("ftime_path", help=hlp_ftime)
cmd.set_defaults(func=_cmd_rm)
hlp = "show what the glob will look like"
cmd = subparsers.add_parser("show-glob", aliases=["show"], help=hlp)
cmd.add_argument("ftime_path", help=hlp_ftime)
cmd.set_defaults(func=_cmd_show)
args = parser.parse_args()
args.func(args)
if __name__ == "__main__":
_main()

File diff suppressed because it is too large Load diff

View file

@ -135,9 +135,6 @@
- name: Reload NetworkManager-connections
ansible.builtin.command: nmcli c reload
- name: Restart basset-worker
service: name=basset-worker state=restarted
- name: Apply interface-changes
ansible.builtin.command: nmcli con up {{ item.split()[1] }}
async: 1
@ -188,3 +185,17 @@
- name: Restart debuginfod
service: name=debuginfod state=restarted
# This is allowed to fail when the zabbix agent is not found
# as it may be triggered from hosts without the zabbix_agent role
- name: Restart zabbix agent
ansible.builtin.systemd:
name: zabbix-agent
state: restarted
register: zabbix_restart
failed_when:
- zabbix_restart.failed
- "'Could not find' not in zabbix_restart.msg"
- name: Restart rsyslog
service: name=rsyslog state=restarted

View file

@ -4,17 +4,18 @@
[backup_clients]
copr-fe.aws.fedoraproject.org
copr-keygen.aws.fedoraproject.org
db01.iad2.fedoraproject.org
db03.iad2.fedoraproject.org
db-datanommer02.iad2.fedoraproject.org
db-fas01.iad2.fedoraproject.org
batcave01.iad2.fedoraproject.org
pagure02.fedoraproject.org
db01.rdu3.fedoraproject.org
db03.rdu3.fedoraproject.org
db-datanommer02.rdu3.fedoraproject.org
db-fas01.rdu3.fedoraproject.org
batcave01.rdu3.fedoraproject.org
pagure01.fedoraproject.org
people01.fedoraproject.org
pkgs01.iad2.fedoraproject.org
log01.iad2.fedoraproject.org
db-openqa01.iad2.fedoraproject.org
db-koji01.iad2.fedoraproject.org
value02.iad2.fedoraproject.org
tang01.iad2.fedoraproject.org
ipa01.iad2.fedoraproject.org
pkgs01.rdu3.fedoraproject.org
log01.rdu3.fedoraproject.org
db-openqa01.rdu3.fedoraproject.org
db-koji01.rdu3.fedoraproject.org
value01.rdu3.fedoraproject.org
tang01.rdu3.fedoraproject.org
ipa01.rdu3.fedoraproject.org
os-control01.rdu3.fedoraproject.org

View file

@ -1,99 +1,215 @@
[buildvm]
buildvm-x86-01.iad2.fedoraproject.org
buildvm-x86-02.iad2.fedoraproject.org
buildvm-x86-03.iad2.fedoraproject.org
buildvm-x86-04.iad2.fedoraproject.org
buildvm-x86-05.iad2.fedoraproject.org
buildvm-x86-06.iad2.fedoraproject.org
buildvm-x86-07.iad2.fedoraproject.org
buildvm-x86-08.iad2.fedoraproject.org
buildvm-x86-09.iad2.fedoraproject.org
buildvm-x86-10.iad2.fedoraproject.org
buildvm-x86-11.iad2.fedoraproject.org
buildvm-x86-12.iad2.fedoraproject.org
buildvm-x86-13.iad2.fedoraproject.org
buildvm-x86-14.iad2.fedoraproject.org
buildvm-x86-15.iad2.fedoraproject.org
buildvm-x86-16.iad2.fedoraproject.org
buildvm-x86-17.iad2.fedoraproject.org
buildvm-x86-18.iad2.fedoraproject.org
buildvm-x86-19.iad2.fedoraproject.org
buildvm-x86-20.iad2.fedoraproject.org
buildvm-x86-21.iad2.fedoraproject.org
buildvm-x86-22.iad2.fedoraproject.org
buildvm-x86-23.iad2.fedoraproject.org
buildvm-x86-24.iad2.fedoraproject.org
buildvm-x86-25.iad2.fedoraproject.org
buildvm-x86-26.iad2.fedoraproject.org
buildvm-x86-27.iad2.fedoraproject.org
buildvm-x86-28.iad2.fedoraproject.org
buildvm-x86-29.iad2.fedoraproject.org
buildvm-x86-30.iad2.fedoraproject.org
buildvm-x86-31.iad2.fedoraproject.org
buildvm-x86-32.iad2.fedoraproject.org
buildvm-x86-01.rdu3.fedoraproject.org
buildvm-x86-02.rdu3.fedoraproject.org
buildvm-x86-03.rdu3.fedoraproject.org
buildvm-x86-04.rdu3.fedoraproject.org
buildvm-x86-05.rdu3.fedoraproject.org
buildvm-x86-06.rdu3.fedoraproject.org
buildvm-x86-07.rdu3.fedoraproject.org
buildvm-x86-08.rdu3.fedoraproject.org
buildvm-x86-09.rdu3.fedoraproject.org
buildvm-x86-10.rdu3.fedoraproject.org
buildvm-x86-11.rdu3.fedoraproject.org
buildvm-x86-12.rdu3.fedoraproject.org
buildvm-x86-13.rdu3.fedoraproject.org
buildvm-x86-14.rdu3.fedoraproject.org
buildvm-x86-15.rdu3.fedoraproject.org
buildvm-x86-16.rdu3.fedoraproject.org
buildvm-x86-17.rdu3.fedoraproject.org
buildvm-x86-18.rdu3.fedoraproject.org
buildvm-x86-19.rdu3.fedoraproject.org
buildvm-x86-20.rdu3.fedoraproject.org
buildvm-x86-21.rdu3.fedoraproject.org
buildvm-x86-22.rdu3.fedoraproject.org
buildvm-x86-23.rdu3.fedoraproject.org
buildvm-x86-24.rdu3.fedoraproject.org
buildvm-x86-25.rdu3.fedoraproject.org
buildvm-x86-26.rdu3.fedoraproject.org
buildvm-x86-27.rdu3.fedoraproject.org
buildvm-x86-28.rdu3.fedoraproject.org
buildvm-x86-29.rdu3.fedoraproject.org
buildvm-x86-30.rdu3.fedoraproject.org
buildvm-x86-31.rdu3.fedoraproject.org
buildvm-x86-32.rdu3.fedoraproject.org
[buildvm_rdu3]
buildvm-x86-01.rdu3.fedoraproject.org
buildvm-x86-02.rdu3.fedoraproject.org
buildvm-x86-03.rdu3.fedoraproject.org
buildvm-x86-04.rdu3.fedoraproject.org
buildvm-x86-05.rdu3.fedoraproject.org
buildvm-x86-06.rdu3.fedoraproject.org
buildvm-x86-07.rdu3.fedoraproject.org
buildvm-x86-08.rdu3.fedoraproject.org
buildvm-x86-09.rdu3.fedoraproject.org
buildvm-x86-10.rdu3.fedoraproject.org
buildvm-x86-11.rdu3.fedoraproject.org
buildvm-x86-12.rdu3.fedoraproject.org
buildvm-x86-13.rdu3.fedoraproject.org
buildvm-x86-14.rdu3.fedoraproject.org
buildvm-x86-15.rdu3.fedoraproject.org
buildvm-x86-16.rdu3.fedoraproject.org
buildvm-x86-17.rdu3.fedoraproject.org
buildvm-x86-18.rdu3.fedoraproject.org
buildvm-x86-19.rdu3.fedoraproject.org
buildvm-x86-20.rdu3.fedoraproject.org
buildvm-x86-21.rdu3.fedoraproject.org
buildvm-x86-22.rdu3.fedoraproject.org
buildvm-x86-23.rdu3.fedoraproject.org
buildvm-x86-24.rdu3.fedoraproject.org
buildvm-x86-25.rdu3.fedoraproject.org
buildvm-x86-26.rdu3.fedoraproject.org
buildvm-x86-27.rdu3.fedoraproject.org
buildvm-x86-28.rdu3.fedoraproject.org
buildvm-x86-29.rdu3.fedoraproject.org
buildvm-x86-30.rdu3.fedoraproject.org
buildvm-x86-31.rdu3.fedoraproject.org
buildvm-x86-32.rdu3.fedoraproject.org
[buildvm_stg]
buildvm-x86-01.stg.iad2.fedoraproject.org
buildvm-x86-02.stg.iad2.fedoraproject.org
buildvm-x86-03.stg.iad2.fedoraproject.org
buildvm-x86-04.stg.iad2.fedoraproject.org
buildvm-x86-05.stg.iad2.fedoraproject.org
buildvm-x86-01.stg.rdu3.fedoraproject.org
buildvm-x86-02.stg.rdu3.fedoraproject.org
buildvm-x86-03.stg.rdu3.fedoraproject.org
buildvm-x86-04.stg.rdu3.fedoraproject.org
buildvm-x86-05.stg.rdu3.fedoraproject.org
[buildvm_stg_rdu3]
buildvm-x86-01.stg.rdu3.fedoraproject.org
buildvm-x86-02.stg.rdu3.fedoraproject.org
buildvm-x86-03.stg.rdu3.fedoraproject.org
buildvm-x86-04.stg.rdu3.fedoraproject.org
buildvm-x86-05.stg.rdu3.fedoraproject.org
[buildvm_aarch64_stg]
buildvm-a64-01.stg.iad2.fedoraproject.org
buildvm-a64-02.stg.iad2.fedoraproject.org
buildvm-a64-01.stg.rdu3.fedoraproject.org
buildvm-a64-02.stg.rdu3.fedoraproject.org
[buildvm_aarch64_stg_rdu3]
buildvm-a64-01.stg.rdu3.fedoraproject.org
buildvm-a64-02.stg.rdu3.fedoraproject.org
[buildvm_s390x_stg]
buildvm-s390x-01.stg.s390.fedoraproject.org
[buildvm_ppc64le_stg]
buildvm-ppc64le-01.stg.iad2.fedoraproject.org
buildvm-ppc64le-02.stg.iad2.fedoraproject.org
buildvm-ppc64le-03.stg.iad2.fedoraproject.org
buildvm-ppc64le-04.stg.iad2.fedoraproject.org
buildvm-ppc64le-05.stg.iad2.fedoraproject.org
#buildvm-ppc64le-01.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-02.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-03.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-04.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-05.stg.rdu3.fedoraproject.org
[buildhw_ppc64le_stg]
buildhw-p10-01.stg.rdu3.fedoraproject.org
buildhw-p10-02.stg.rdu3.fedoraproject.org
[buildvm_ppc64le_stg_rdu3]
#buildvm-ppc64le-01.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-02.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-03.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-04.stg.rdu3.fedoraproject.org
#buildvm-ppc64le-05.stg.rdu3.fedoraproject.org
[buildhw_ppc64le_stg_rdu3]
buildhw-p10-01.stg.rdu3.fedoraproject.org
buildhw-p10-02.stg.rdu3.fedoraproject.org
[buildvm_aarch64]
buildvm-a64-01.iad2.fedoraproject.org
buildvm-a64-02.iad2.fedoraproject.org
buildvm-a64-03.iad2.fedoraproject.org
buildvm-a64-04.iad2.fedoraproject.org
buildvm-a64-05.iad2.fedoraproject.org
buildvm-a64-06.iad2.fedoraproject.org
buildvm-a64-07.iad2.fedoraproject.org
buildvm-a64-08.iad2.fedoraproject.org
buildvm-a64-09.iad2.fedoraproject.org
buildvm-a64-10.iad2.fedoraproject.org
buildvm-a64-11.iad2.fedoraproject.org
buildvm-a64-12.iad2.fedoraproject.org
buildvm-a64-13.iad2.fedoraproject.org
buildvm-a64-14.iad2.fedoraproject.org
buildvm-a64-15.iad2.fedoraproject.org
buildvm-a64-16.iad2.fedoraproject.org
buildvm-a64-17.iad2.fedoraproject.org
buildvm-a64-18.iad2.fedoraproject.org
buildvm-a64-19.iad2.fedoraproject.org
buildvm-a64-20.iad2.fedoraproject.org
buildvm-a64-21.iad2.fedoraproject.org
buildvm-a64-22.iad2.fedoraproject.org
buildvm-a64-23.iad2.fedoraproject.org
buildvm-a64-24.iad2.fedoraproject.org
buildvm-a64-25.iad2.fedoraproject.org
buildvm-a64-26.iad2.fedoraproject.org
buildvm-a64-27.iad2.fedoraproject.org
buildvm-a64-28.iad2.fedoraproject.org
buildvm-a64-29.iad2.fedoraproject.org
buildvm-a64-30.iad2.fedoraproject.org
buildvm-a64-31.iad2.fedoraproject.org
buildvm-a64-32.iad2.fedoraproject.org
buildvm-a64-33.iad2.fedoraproject.org
buildvm-a64-34.iad2.fedoraproject.org
buildvm-a64-35.iad2.fedoraproject.org
buildvm-a64-36.iad2.fedoraproject.org
buildvm-a64-37.iad2.fedoraproject.org
buildvm-a64-38.iad2.fedoraproject.org
buildvm-a64-39.iad2.fedoraproject.org
buildvm-a64-40.iad2.fedoraproject.org
buildvm-a64-01.rdu3.fedoraproject.org
buildvm-a64-02.rdu3.fedoraproject.org
buildvm-a64-03.rdu3.fedoraproject.org
buildvm-a64-04.rdu3.fedoraproject.org
buildvm-a64-05.rdu3.fedoraproject.org
buildvm-a64-06.rdu3.fedoraproject.org
buildvm-a64-07.rdu3.fedoraproject.org
buildvm-a64-08.rdu3.fedoraproject.org
buildvm-a64-09.rdu3.fedoraproject.org
buildvm-a64-10.rdu3.fedoraproject.org
buildvm-a64-11.rdu3.fedoraproject.org
buildvm-a64-12.rdu3.fedoraproject.org
buildvm-a64-13.rdu3.fedoraproject.org
buildvm-a64-14.rdu3.fedoraproject.org
buildvm-a64-15.rdu3.fedoraproject.org
buildvm-a64-16.rdu3.fedoraproject.org
buildvm-a64-17.rdu3.fedoraproject.org
buildvm-a64-18.rdu3.fedoraproject.org
buildvm-a64-19.rdu3.fedoraproject.org
buildvm-a64-20.rdu3.fedoraproject.org
buildvm-a64-21.rdu3.fedoraproject.org
buildvm-a64-22.rdu3.fedoraproject.org
buildvm-a64-23.rdu3.fedoraproject.org
buildvm-a64-24.rdu3.fedoraproject.org
buildvm-a64-25.rdu3.fedoraproject.org
buildvm-a64-26.rdu3.fedoraproject.org
buildvm-a64-27.rdu3.fedoraproject.org
buildvm-a64-28.rdu3.fedoraproject.org
buildvm-a64-29.rdu3.fedoraproject.org
buildvm-a64-30.rdu3.fedoraproject.org
buildvm-a64-31.rdu3.fedoraproject.org
buildvm-a64-32.rdu3.fedoraproject.org
buildvm-a64-33.rdu3.fedoraproject.org
buildvm-a64-34.rdu3.fedoraproject.org
buildvm-a64-35.rdu3.fedoraproject.org
buildvm-a64-36.rdu3.fedoraproject.org
buildvm-a64-37.rdu3.fedoraproject.org
buildvm-a64-38.rdu3.fedoraproject.org
buildvm-a64-39.rdu3.fedoraproject.org
buildvm-a64-40.rdu3.fedoraproject.org
buildvm-a64-41.rdu3.fedoraproject.org
buildvm-a64-42.rdu3.fedoraproject.org
buildvm-a64-43.rdu3.fedoraproject.org
buildvm-a64-44.rdu3.fedoraproject.org
buildvm-a64-45.rdu3.fedoraproject.org
buildvm-a64-46.rdu3.fedoraproject.org
buildvm-a64-47.rdu3.fedoraproject.org
[buildvm_aarch64_rdu3]
buildvm-a64-01.rdu3.fedoraproject.org
buildvm-a64-02.rdu3.fedoraproject.org
buildvm-a64-03.rdu3.fedoraproject.org
buildvm-a64-04.rdu3.fedoraproject.org
buildvm-a64-05.rdu3.fedoraproject.org
buildvm-a64-06.rdu3.fedoraproject.org
buildvm-a64-07.rdu3.fedoraproject.org
buildvm-a64-08.rdu3.fedoraproject.org
buildvm-a64-09.rdu3.fedoraproject.org
buildvm-a64-10.rdu3.fedoraproject.org
buildvm-a64-11.rdu3.fedoraproject.org
buildvm-a64-12.rdu3.fedoraproject.org
buildvm-a64-13.rdu3.fedoraproject.org
buildvm-a64-14.rdu3.fedoraproject.org
buildvm-a64-15.rdu3.fedoraproject.org
buildvm-a64-16.rdu3.fedoraproject.org
buildvm-a64-17.rdu3.fedoraproject.org
buildvm-a64-18.rdu3.fedoraproject.org
buildvm-a64-19.rdu3.fedoraproject.org
buildvm-a64-20.rdu3.fedoraproject.org
buildvm-a64-21.rdu3.fedoraproject.org
buildvm-a64-22.rdu3.fedoraproject.org
buildvm-a64-23.rdu3.fedoraproject.org
buildvm-a64-24.rdu3.fedoraproject.org
buildvm-a64-25.rdu3.fedoraproject.org
buildvm-a64-26.rdu3.fedoraproject.org
buildvm-a64-27.rdu3.fedoraproject.org
buildvm-a64-28.rdu3.fedoraproject.org
buildvm-a64-29.rdu3.fedoraproject.org
buildvm-a64-30.rdu3.fedoraproject.org
buildvm-a64-31.rdu3.fedoraproject.org
buildvm-a64-32.rdu3.fedoraproject.org
buildvm-a64-33.rdu3.fedoraproject.org
buildvm-a64-34.rdu3.fedoraproject.org
buildvm-a64-35.rdu3.fedoraproject.org
buildvm-a64-36.rdu3.fedoraproject.org
buildvm-a64-37.rdu3.fedoraproject.org
buildvm-a64-38.rdu3.fedoraproject.org
buildvm-a64-39.rdu3.fedoraproject.org
buildvm-a64-40.rdu3.fedoraproject.org
buildvm-a64-41.rdu3.fedoraproject.org
buildvm-a64-42.rdu3.fedoraproject.org
buildvm-a64-43.rdu3.fedoraproject.org
buildvm-a64-44.rdu3.fedoraproject.org
buildvm-a64-45.rdu3.fedoraproject.org
buildvm-a64-46.rdu3.fedoraproject.org
buildvm-a64-47.rdu3.fedoraproject.org
[buildvm_s390x]
buildvm-s390x-01.s390.fedoraproject.org
@ -125,139 +241,213 @@ bvmhost-s390x-01.s390.fedoraproject.org
bvmhost-s390x-01.stg.s390.fedoraproject.org
bvmhost-s390x-01.s390.fedoraproject.org
# mt snow machines
bvmhost-a64-01.iad2.fedoraproject.org
bvmhost-a64-02.iad2.fedoraproject.org
bvmhost-a64-03.iad2.fedoraproject.org
bvmhost-a64-04.iad2.fedoraproject.org
# These are lenovo emags in IAD2
bvmhost-a64-01.stg.iad2.fedoraproject.org
bvmhost-a64-01.rdu3.fedoraproject.org
bvmhost-a64-02.rdu3.fedoraproject.org
bvmhost-a64-03.rdu3.fedoraproject.org
bvmhost-a64-04.rdu3.fedoraproject.org
bvmhost-a64-05.rdu3.fedoraproject.org
# These are lenovo emags in RDU3
bvmhost-a64-01.stg.rdu3.fedoraproject.org
# ppc
bvmhost-p09-01.iad2.fedoraproject.org
bvmhost-p09-02.iad2.fedoraproject.org
bvmhost-p09-03.iad2.fedoraproject.org
bvmhost-p09-04.iad2.fedoraproject.org
bvmhost-p09-05.iad2.fedoraproject.org
bvmhost-p09-01.stg.iad2.fedoraproject.org
#bvmhost-p09-01.rdu3.fedoraproject.org
#bvmhost-p09-02.rdu3.fedoraproject.org
#bvmhost-p09-03.rdu3.fedoraproject.org
#bvmhost-p09-04.rdu3.fedoraproject.org
bvmhost-p09-05.rdu3.fedoraproject.org
#bvmhost-p09-01.stg.rdu3.fedoraproject.org
bvmhost-p10-01.rdu3.fedoraproject.org
[buildvmhost_rdu3]
# mt snow machines
bvmhost-a64-01.rdu3.fedoraproject.org
bvmhost-a64-02.rdu3.fedoraproject.org
bvmhost-a64-03.rdu3.fedoraproject.org
bvmhost-a64-05.rdu3.fedoraproject.org
# These are lenovo emags in RDU3
bvmhost-a64-01.stg.rdu3.fedoraproject.org
# ppc
#bvmhost-p09-01.rdu3.fedoraproject.org
#bvmhost-p09-02.rdu3.fedoraproject.org
#bvmhost-p09-03.rdu3.fedoraproject.org
#bvmhost-p09-04.rdu3.fedoraproject.org
bvmhost-p09-05.rdu3.fedoraproject.org
#bvmhost-p09-01.stg.rdu3.fedoraproject.org
[buildvmhost_stg_rdu3]
bvmhost-a64-01.stg.rdu3.fedoraproject.org
#bvmhost-p09-01.stg.rdu3.fedoraproject.org
[buildhw]
# mt snow
buildhw-a64-03.iad2.fedoraproject.org
buildhw-a64-04.iad2.fedoraproject.org
buildhw-a64-05.iad2.fedoraproject.org
buildhw-a64-06.iad2.fedoraproject.org
# emags
buildhw-x86-01.iad2.fedoraproject.org
buildhw-x86-02.iad2.fedoraproject.org
buildhw-x86-03.iad2.fedoraproject.org
buildhw-x86-04.iad2.fedoraproject.org
buildhw-x86-05.iad2.fedoraproject.org
buildhw-x86-06.iad2.fedoraproject.org
buildhw-x86-07.iad2.fedoraproject.org
buildhw-x86-08.iad2.fedoraproject.org
buildhw-x86-09.iad2.fedoraproject.org
buildhw-x86-10.iad2.fedoraproject.org
buildhw-x86-11.iad2.fedoraproject.org
buildhw-x86-12.iad2.fedoraproject.org
buildhw-x86-13.iad2.fedoraproject.org
buildhw-x86-14.iad2.fedoraproject.org
buildhw-x86-15.iad2.fedoraproject.org
buildhw-x86-16.iad2.fedoraproject.org
buildhw-a64-01.rdu3.fedoraproject.org
buildhw-a64-02.rdu3.fedoraproject.org
buildhw-a64-03.rdu3.fedoraproject.org
buildhw-a64-04.rdu3.fedoraproject.org
buildhw-a64-05.rdu3.fedoraproject.org
buildhw-a64-06.rdu3.fedoraproject.org
buildhw-a64-07.rdu3.fedoraproject.org
buildhw-x86-01.rdu3.fedoraproject.org
buildhw-x86-02.rdu3.fedoraproject.org
buildhw-x86-03.rdu3.fedoraproject.org
buildhw-x86-04.rdu3.fedoraproject.org
buildhw-x86-08.rdu3.fedoraproject.org
buildhw-x86-09.rdu3.fedoraproject.org
buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
[buildhw_stg]
buildhw-p10-01.stg.rdu3.fedoraproject.org
buildhw-p10-02.stg.rdu3.fedoraproject.org
[buildhw_rdu3]
buildhw-a64-01.rdu3.fedoraproject.org
buildhw-a64-02.rdu3.fedoraproject.org
buildhw-a64-03.rdu3.fedoraproject.org
buildhw-a64-04.rdu3.fedoraproject.org
buildhw-a64-05.rdu3.fedoraproject.org
buildhw-a64-06.rdu3.fedoraproject.org
buildhw-a64-07.rdu3.fedoraproject.org
buildhw-x86-01.rdu3.fedoraproject.org
buildhw-x86-02.rdu3.fedoraproject.org
buildhw-x86-03.rdu3.fedoraproject.org
buildhw-x86-04.rdu3.fedoraproject.org
# old iad2 hw
buildhw-x86-08.rdu3.fedoraproject.org
buildhw-x86-09.rdu3.fedoraproject.org
buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
[buildhw_stg_rdu3]
buildhw-p10-01.stg.rdu3.fedoraproject.org
buildhw-p10-02.stg.rdu3.fedoraproject.org
#
# These are primary koji builders.
#
[buildvm_ppc64le]
buildvm-ppc64le-01.iad2.fedoraproject.org
buildvm-ppc64le-02.iad2.fedoraproject.org
buildvm-ppc64le-03.iad2.fedoraproject.org
buildvm-ppc64le-04.iad2.fedoraproject.org
buildvm-ppc64le-05.iad2.fedoraproject.org
buildvm-ppc64le-06.iad2.fedoraproject.org
buildvm-ppc64le-07.iad2.fedoraproject.org
buildvm-ppc64le-08.iad2.fedoraproject.org
buildvm-ppc64le-09.iad2.fedoraproject.org
buildvm-ppc64le-10.iad2.fedoraproject.org
buildvm-ppc64le-11.iad2.fedoraproject.org
buildvm-ppc64le-12.iad2.fedoraproject.org
buildvm-ppc64le-13.iad2.fedoraproject.org
buildvm-ppc64le-14.iad2.fedoraproject.org
buildvm-ppc64le-15.iad2.fedoraproject.org
buildvm-ppc64le-16.iad2.fedoraproject.org
buildvm-ppc64le-17.iad2.fedoraproject.org
buildvm-ppc64le-18.iad2.fedoraproject.org
buildvm-ppc64le-19.iad2.fedoraproject.org
buildvm-ppc64le-20.iad2.fedoraproject.org
buildvm-ppc64le-21.iad2.fedoraproject.org
buildvm-ppc64le-22.iad2.fedoraproject.org
buildvm-ppc64le-23.iad2.fedoraproject.org
buildvm-ppc64le-24.iad2.fedoraproject.org
buildvm-ppc64le-25.iad2.fedoraproject.org
buildvm-ppc64le-26.iad2.fedoraproject.org
buildvm-ppc64le-27.iad2.fedoraproject.org
buildvm-ppc64le-28.iad2.fedoraproject.org
buildvm-ppc64le-29.iad2.fedoraproject.org
buildvm-ppc64le-30.iad2.fedoraproject.org
buildvm-ppc64le-31.iad2.fedoraproject.org
buildvm-ppc64le-32.iad2.fedoraproject.org
buildvm-ppc64le-33.iad2.fedoraproject.org
buildvm-ppc64le-01.rdu3.fedoraproject.org
buildvm-ppc64le-02.rdu3.fedoraproject.org
buildvm-ppc64le-03.rdu3.fedoraproject.org
buildvm-ppc64le-04.rdu3.fedoraproject.org
buildvm-ppc64le-05.rdu3.fedoraproject.org
buildvm-ppc64le-06.rdu3.fedoraproject.org
buildvm-ppc64le-07.rdu3.fedoraproject.org
buildvm-ppc64le-08.rdu3.fedoraproject.org
buildvm-ppc64le-09.rdu3.fedoraproject.org
buildvm-ppc64le-10.rdu3.fedoraproject.org
buildvm-ppc64le-11.rdu3.fedoraproject.org
buildvm-ppc64le-12.rdu3.fedoraproject.org
buildvm-ppc64le-13.rdu3.fedoraproject.org
buildvm-ppc64le-14.rdu3.fedoraproject.org
buildvm-ppc64le-15.rdu3.fedoraproject.org
buildvm-ppc64le-16.rdu3.fedoraproject.org
buildvm-ppc64le-17.rdu3.fedoraproject.org
buildvm-ppc64le-18.rdu3.fedoraproject.org
buildvm-ppc64le-19.rdu3.fedoraproject.org
buildvm-ppc64le-20.rdu3.fedoraproject.org
buildvm-ppc64le-21.rdu3.fedoraproject.org
buildvm-ppc64le-22.rdu3.fedoraproject.org
buildvm-ppc64le-23.rdu3.fedoraproject.org
buildvm-ppc64le-24.rdu3.fedoraproject.org
buildvm-ppc64le-25.rdu3.fedoraproject.org
buildvm-ppc64le-26.rdu3.fedoraproject.org
buildvm-ppc64le-27.rdu3.fedoraproject.org
buildvm-ppc64le-28.rdu3.fedoraproject.org
buildvm-ppc64le-29.rdu3.fedoraproject.org
buildvm-ppc64le-30.rdu3.fedoraproject.org
buildvm-ppc64le-31.rdu3.fedoraproject.org
buildvm-ppc64le-32.rdu3.fedoraproject.org
[buildvm_ppc64le_rdu3]
buildvm-ppc64le-01.rdu3.fedoraproject.org
buildvm-ppc64le-02.rdu3.fedoraproject.org
buildvm-ppc64le-03.rdu3.fedoraproject.org
buildvm-ppc64le-04.rdu3.fedoraproject.org
buildvm-ppc64le-05.rdu3.fedoraproject.org
buildvm-ppc64le-06.rdu3.fedoraproject.org
buildvm-ppc64le-07.rdu3.fedoraproject.org
buildvm-ppc64le-08.rdu3.fedoraproject.org
buildvm-ppc64le-09.rdu3.fedoraproject.org
buildvm-ppc64le-10.rdu3.fedoraproject.org
buildvm-ppc64le-11.rdu3.fedoraproject.org
buildvm-ppc64le-12.rdu3.fedoraproject.org
buildvm-ppc64le-13.rdu3.fedoraproject.org
buildvm-ppc64le-14.rdu3.fedoraproject.org
buildvm-ppc64le-15.rdu3.fedoraproject.org
buildvm-ppc64le-16.rdu3.fedoraproject.org
buildvm-ppc64le-17.rdu3.fedoraproject.org
buildvm-ppc64le-18.rdu3.fedoraproject.org
buildvm-ppc64le-19.rdu3.fedoraproject.org
buildvm-ppc64le-20.rdu3.fedoraproject.org
buildvm-ppc64le-21.rdu3.fedoraproject.org
buildvm-ppc64le-22.rdu3.fedoraproject.org
buildvm-ppc64le-23.rdu3.fedoraproject.org
buildvm-ppc64le-24.rdu3.fedoraproject.org
buildvm-ppc64le-25.rdu3.fedoraproject.org
buildvm-ppc64le-26.rdu3.fedoraproject.org
buildvm-ppc64le-27.rdu3.fedoraproject.org
buildvm-ppc64le-28.rdu3.fedoraproject.org
buildvm-ppc64le-29.rdu3.fedoraproject.org
buildvm-ppc64le-30.rdu3.fedoraproject.org
buildvm-ppc64le-31.rdu3.fedoraproject.org
buildvm-ppc64le-32.rdu3.fedoraproject.org
[bkernel]
bkernel01.iad2.fedoraproject.org
bkernel02.iad2.fedoraproject.org
buildhw-x86-01.rdu3.fedoraproject.org
# These hosts get the runroot plugin installed.
# They should be added to their own 'compose' channel in the koji db
# .. and they should not appear in the default channel for builds.
[runroot]
buildvm-x86-01.iad2.fedoraproject.org
buildvm-x86-02.iad2.fedoraproject.org
buildvm-x86-03.iad2.fedoraproject.org
buildvm-a64-01.iad2.fedoraproject.org
buildvm-a64-02.iad2.fedoraproject.org
buildvm-a64-03.iad2.fedoraproject.org
buildvm-ppc64le-01.iad2.fedoraproject.org
buildvm-ppc64le-09.iad2.fedoraproject.org
buildvm-ppc64le-18.iad2.fedoraproject.org
buildvm-ppc64le-27.iad2.fedoraproject.org
buildvm-ppc64le-33.iad2.fedoraproject.org
buildvm-x86-01.rdu3.fedoraproject.org
buildvm-x86-02.rdu3.fedoraproject.org
buildvm-x86-03.rdu3.fedoraproject.org
buildvm-a64-01.rdu3.fedoraproject.org
buildvm-a64-02.rdu3.fedoraproject.org
buildvm-a64-03.rdu3.fedoraproject.org
buildvm-ppc64le-01.rdu3.fedoraproject.org
buildvm-ppc64le-02.rdu3.fedoraproject.org
buildvm-ppc64le-03.rdu3.fedoraproject.org
buildvm-s390x-11.s390.fedoraproject.org
buildvm-s390x-12.s390.fedoraproject.org
buildvm-s390x-13.s390.fedoraproject.org
buildvm-a64-01.stg.iad2.fedoraproject.org
buildvm-ppc64le-01.stg.iad2.fedoraproject.org
buildvm-a64-01.stg.rdu3.fedoraproject.org
buildvm-s390x-01.stg.s390.fedoraproject.org
buildvm-x86-01.stg.iad2.fedoraproject.org
buildvm-x86-01.stg.rdu3.fedoraproject.org
# These are builders in the osbuild channel.
# This means they are used for osbuild jobs and need
# a special ipset to allow them to talk to the osbuild
# API endpoint.
[osbuild]
buildhw-x86-01.iad2.fedoraproject.org
buildhw-x86-02.iad2.fedoraproject.org
buildhw-x86-03.iad2.fedoraproject.org
buildhw-x86-04.iad2.fedoraproject.org
buildhw-x86-05.iad2.fedoraproject.org
buildhw-x86-06.iad2.fedoraproject.org
buildhw-x86-07.iad2.fedoraproject.org
buildhw-x86-08.iad2.fedoraproject.org
buildhw-x86-09.iad2.fedoraproject.org
buildhw-x86-10.iad2.fedoraproject.org
buildhw-x86-11.iad2.fedoraproject.org
buildhw-x86-12.iad2.fedoraproject.org
buildhw-x86-13.iad2.fedoraproject.org
buildhw-x86-14.iad2.fedoraproject.org
buildhw-x86-15.iad2.fedoraproject.org
buildhw-x86-16.iad2.fedoraproject.org
buildvm-x86-01.stg.iad2.fedoraproject.org
buildvm-x86-02.stg.iad2.fedoraproject.org
buildvm-x86-03.stg.iad2.fedoraproject.org
buildvm-x86-04.stg.iad2.fedoraproject.org
buildvm-x86-05.stg.iad2.fedoraproject.org
buildvm-x86-10.rdu3.fedoraproject.org
buildvm-x86-11.rdu3.fedoraproject.org
buildvm-x86-12.rdu3.fedoraproject.org
buildvm-x86-13.rdu3.fedoraproject.org
buildvm-x86-14.rdu3.fedoraproject.org
buildvm-x86-15.rdu3.fedoraproject.org
[buildvm_x86_riscv]
buildvm-x86-riscv01.iad2.fedoraproject.org
buildvm-x86-riscv02.iad2.fedoraproject.org
buildvm-x86-riscv01.rdu3.fedoraproject.org
buildvm-x86-riscv02.rdu3.fedoraproject.org
[buildvm_x86_riscv_rdu3]
buildvm-x86-riscv01.rdu3.fedoraproject.org
buildvm-x86-riscv02.rdu3.fedoraproject.org
[builders_rdu3:children]
buildvm_rdu3
buildvm_aarch64_rdu3
buildhw_rdu3
buildvm_ppc64le_rdu3
buildvm_x86_riscv_rdu3
[builders_rdu3_stg:children]
buildvm_stg_rdu3
buildhw_stg_rdu3
buildvm_aarch64_stg_rdu3
buildvm_ppc64le_stg_rdu3
[builders:children]
buildhw
@ -268,13 +458,8 @@ buildvm_s390x
bkernel
[builders_stg:children]
buildhw_ppc64le_stg
buildvm_stg
buildvm_ppc64le_stg
buildvm_aarch64_stg
buildvm_s390x_stg
[buildvm_osbuild_ppc64le]
buildvm-ppc64le-osbuild01.iad2.fedoraproject.org
[buildvm_osbuild_ppc64le_staging]
buildvm-ppc64le-osbuild02.iad2.fedoraproject.org

View file

@ -33,16 +33,13 @@ copr-keygen.aws.fedoraproject.org
copr-keygen-dev.aws.fedoraproject.org
#copr-be-dev.cloud.fedoraproject.org
copr-dist-git-dev.fedorainfracloud.org
#copr-pulp.aws.fedoraproject.org
copr-pulp-dev.aws.fedoraproject.org
f40-test.fedorainfracloud.org
f41-test.fedorainfracloud.org
f42-test.fedorainfracloud.org
f43-test.fedorainfracloud.org
rawhide-test.fedorainfracloud.org
el9-test.fedorainfracloud.org
el10-test.fedorainfracloud.org
aarch64-test01.fedorainfracloud.org
aarch64-test02.fedorainfracloud.org
datanommer01.fedorainfracloud.org
# This is not in aws, but here is good enough for now
ppc64le-test.fedorainfracloud.org
ppc64le-test02.fedorainfracloud.org

View file

@ -3,10 +3,15 @@
# BEGIN: Ansible roles_path variables
#
# Background/reference about external repos pulled in:
# https://pagure.io/fedora-infrastructure/issue/5476
# https://forge.fedoraproject.org/infra/tickets/5476
#
# IPA settings
additional_host_keytabs: []
#
# Conditional for if anubis is enabled for a proxy application or not.
# Defaults to false and only set to true on the particular site.
#
anubis: false
ansible_base: /srv/web/infra
# Default to managing the network, we want to not do this on select
# hosts (like cloud nodes)
@ -35,49 +40,68 @@ br1_nm: 255.255.255.0
collectd_apache: true
# communishift project resource overrides
communishift_projects:
# please keep these sorted alphabetically for readability
communishift-admins:
do_not_delete: true # Marked do not delete 2024-11-25
name: communishift-admins
do_not_delete: true # Marked do not delete 2024-11-25 - dkirwan
communishift-avant:
name: communishift-avant
cpu_limits: 2
cpu_requests: 2
memory_limits: 3Gi
memory_requests: 1.5Gi
pods: 6
storage_requests: 10Gi
communishift-commops-analytics:
name: communishift-commops-analytics
communishift-commops-datanom:
name: communishift-commops-datanom
communishift-discoursepolls:
name: communishift-discoursepolls
communishift-eventbot:
name: communishift-eventbot
communishift-fedora-coreos-ai-helpers:
name: communishift-fedora-coreos-ai-helpers
do_not_delete: true # Marked do not delete 2025-12-18 - dkirwan infra 12996
communishift-fedora-review-service:
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
name: communishift-fedora-review-service
do_not_delete: true # Marked do not delete 2024-10-21
communishift-forgejo:
name: communishift-forgejo
communishift-fossology:
name: communishift-fossology
communishift-gitlabce:
name: communishift-gitlabce
communishift-jitsi:
name: communishift-jitsi
communishift-lightspeed-build:
name: communishift-lightspeed-build
communishift-log-detective:
name: communishift-log-detective
do_not_delete: true # Marked do not delete 2024-10-21
memory_requests: 4Gi
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
memory_limits: 6Gi
memory_requests: 4Gi
storage_requests: 10Gi
communishift-mattdm:
name: communishift-mattdm
communishift-metrics:
name: communishift-metrics
communishift-ocm:
name: communishift-ocm
communishift-openscanhub:
name: communishift-openscanhub
cpu_requests: 2
memory_requests: 2Gi
cpu_limits: 2
cpu_requests: 2
memory_limits: 4Gi
memory_requests: 2Gi
pods: 16
communishift-planet:
name: communishift-planet
communishift-forgejo:
name: communishift-forgejo
communishift-gitlabce:
name: communishift-gitlabce
communishift-ocm:
name: communishift-ocm
communishift-standupbot:
name: communishift-standupbot
communishift-weekly-bootc:
do_not_delete: true # Marked do not delete 2024-11-26. Needed until end of bootc initative. - dkirwan
name: communishift-weekly-bootc
do_not_delete: true # Marked do not delete 2024-11-26. Needed until end of bootc initative.
communishift-fossology:
name: communishift-fossology
communishift-commops-analytics:
name: communishift-commops-analytics
communishift-commops-datanom:
name: communishift-commops-datanom
# true or false if we are or are not a copr build virthost.
# Default to false
copr_build_virthost: false
@ -87,8 +111,8 @@ createrepo: True
# Groups and individual hosts should override them with specific info.
custom6_rules: []
custom_rules: []
# most of our systems are in IAD2
datacenter: iad2
# most of our systems are in RDU3
datacenter: rdu3
# Datanommer
datanommer_db_hostname: db-datanommer02
@ -96,18 +120,18 @@ datanommer_db_hostname: db-datanommer02
dbs_to_backup: []
# dnf-automatic-install.service mode default: security-only
dnf_automatic_type: security
dns: "10.3.163.33"
dns1: "10.3.163.33"
dns2: "10.3.163.34"
dns_search1: "iad2.fedoraproject.org"
dns: "10.16.163.33"
dns1: "10.16.163.33"
dns2: "10.16.163.34"
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
# env is staging or production, we default it to production here.
env: production
env_prefix: ""
env_short: prod
env_suffix: ""
# Default netmask. All of our iad2 nets are /24's. Almost all of our
# non-iad2 sites are less than a /24.
# Default netmask. All of our rdu3 nets are /24's. Almost all of our
# non-rdu3 sites are less than a /24.
eth0_ipv4_nm: 24
eth1_ip: 10.0.0.10
eth1_nm: 255.255.255.0
@ -118,11 +142,14 @@ freezes: true
install_noc: none
ipa_admin_password: "{{ ipa_prod_admin_password }}"
ipa_realm: FEDORAPROJECT.ORG
ipa_server: ipa01.iad2.fedoraproject.org
ipa_basedn: dc=fedoraproject,dc=org
ipa_server: ipa01.rdu3.fedoraproject.org
ipa_server_nodes:
- ipa01.iad2.fedoraproject.org
- ipa02.iad2.fedoraproject.org
- ipa03.iad2.fedoraproject.org
- ipa01.rdu3.fedoraproject.org
- ipa02.rdu3.fedoraproject.org
- ipa03.rdu3.fedoraproject.org
keycloak_db_hostname: "db-fas01.rdu3.fedoraproject.org"
keycloak_version: "26.3.5"
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
# defaults for virt installs
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
@ -161,17 +188,6 @@ nft_table_filter: "ip cle_infra_filter"
nft_table_nat: "ip cle_infra_nat"
nft_table_raw: "ip cle_infra_raw"
nft_table6_filter: "ip6 cle_infra_filter"
# default network block device encryption settings for linux-system-roles/nbde_client
nbde: true
nbde_device: /dev/md2
nbde_client_bindings:
- device: "{{ nbde_device }}"
encryption_password: "{{ nbde_password }}"
password_temporary: no
threshold: 1
servers:
- http://tang01.iad2.fedoraproject.org
- http://tang02.iad2.fedoraproject.org
# usually we do not want to enable nested virt, only on some virthosts
nested: false
network_allow_restart: yes
@ -212,35 +228,29 @@ ocp4_rdu3: false
# All the ocp production workers.
# This is used by the openvpn openshift app to make sure there's a vpn pod on each node.
ocp_nodes:
- worker01.ocp.iad2.fedoraproject.org
- worker02.ocp.iad2.fedoraproject.org
- worker03.ocp.iad2.fedoraproject.org
- worker04.ocp.iad2.fedoraproject.org
- worker05.ocp.iad2.fedoraproject.org
- worker06.ocp.iad2.fedoraproject.org
- worker01.ocp.rdu3.fedoraproject.org
- worker02.ocp.rdu3.fedoraproject.org
- worker03.ocp.rdu3.fedoraproject.org
- worker04.ocp.rdu3.fedoraproject.org
- worker05.ocp.rdu3.fedoraproject.org
ocp_nodes_rdu3:
- worker01.ocp.rdu3.fedoraproject.org
- worker02.ocp.rdu3.fedoraproject.org
- worker03.ocp.rdu3.fedoraproject.org
- worker04.ocp.rdu3.fedoraproject.org
- worker05.ocp.rdu3.fedoraproject.org
ocp_wildcard_cert_file: wildcard-2024.apps.ocp.fedoraproject.org.cert
ocp_wildcard_cert_file: wildcard-2025.apps.ocp.fedoraproject.org.cert
# This is the openshift wildcard cert for ocp
ocp_wildcard_cert_name: wildcard-2024.apps.ocp.fedoraproject.org
ocp_wildcard_int_file: wildcard-2024.apps.ocp.fedoraproject.org.intermediate.cert
ocp_wildcard_key_file: wildcard-2024.apps.ocp.fedoraproject.org.key
# rdu3 ocp cert while we are not yet moved
ocp_rdu3_wildcard_cert_file: wildcard-2025.apps.ocp-rdu3.fedoraproject.org.cert
ocp_rdu3_wildcard_cert_name: wildcard-2025.apps.ocp-rdu3.fedoraproject.org
ocp_rdu3_wildcard_int_file: wildcard-2025.apps.ocp-rdu3.fedoraproject.org.intermediate.cert
ocp_rdu3_wildcard_key_file: wildcard-2025.apps.ocp-rdu3.fedoraproject.org.key
ocp_wildcard_cert_name: wildcard-2025.apps.ocp.fedoraproject.org
ocp_wildcard_int_file: wildcard-2025.apps.ocp.fedoraproject.org.intermediate.cert
ocp_wildcard_key_file: wildcard-2025.apps.ocp.fedoraproject.org.key
# Path to the openshift-ansible checkout as external git repo brought into
# Fedora Infra
openshift_ansible: /srv/web/infra/openshift-ansible/
postfix_group: "none"
# This is a list of services that need to wait for VPN to be up before getting started.
postvpnservices: []
preferred_dc: iad2
preferred_dc: rdu3
primary_auth_source: ipa
#
# Set a redirectmatch variable we can use to disable some redirectmatches
@ -290,10 +300,10 @@ virt_install_command_two_nic_unsafe: virt-install -n {{ inventory_hostname }} --
vpn: False
# This is the wildcard certname for our proxies. It has a different name for
# the staging group and is used in the proxies.yml playbook.
wildcard_cert_name: wildcard-2024.fedoraproject.org
wildcard_crt_file: wildcard-2024.fedoraproject.org.cert
wildcard_int_file: wildcard-2024.fedoraproject.org.intermediate.cert
wildcard_key_file: wildcard-2024.fedoraproject.org.key
wildcard_cert_name: wildcard-2025.fedoraproject.org
wildcard_crt_file: wildcard-2025.fedoraproject.org.cert
wildcard_int_file: wildcard-2025.fedoraproject.org.intermediate.cert
wildcard_key_file: wildcard-2025.fedoraproject.org.key
#
# say if we want the apache role dependency for mod_wsgi or not
# In some cases we want mod_wsgi and no apache (for python3 httpaio stuff)
@ -303,6 +313,13 @@ wsgi_wants_apache: true
x_forward: false
#
# Copied from group_vars/nagios for Zabbix to consume on a per-host basis
exclude_rdu3_hostgroups:
- centos_ipa_client_stg
- zabbix_stg
- zabbix
- logdetective
# Template defaults are defined in the template macros. If we need a specific
# host to have different values for a macro, define it here. Use the macro name
# as it is in Zabbix so we can search for it easily. If you remove a key,
@ -311,7 +328,32 @@ x_forward: false
# This is overriden at the host_var level, this is empty just so the var exists
zabbix_macros: {}
# Zabbix connection vars. Production values here, staging values in "staging"
# These are used to delegate API actions from the ansible host to the Zabbix API
zabbix_server: zabbix.fedoraproject.org
zabbix_auth_key: "{{ zabbix_apikey }}" # in ansible-private repo
zabbix_network_os: community.zabbix.zabbix
zabbix_connection: httpapi
zabbix_httpapi_port: 443
zabbix_httpapi_use_ssl: true
zabbix_httpapi_validate_certs: false
zabbix_url_path: "" # If Zabbix WebUI runs on non-default (zabbix) path ,e.g. http://<FQDN>/zabbixeu
# Zabbix agent vars
zabbix_host: "zabbix01{{ env_suffix }}.{{ datacenter }}.fedoraproject.org"
zabbix_tls_psk_identity: "Fedora"
zabbix_tls_psk: "{{ zabbix_tls_prod_psk }}" # in ansible-private repo
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
# Env is not a valid key, so use this field for environment
deployment_status: production
notes: |
Unspecified.
* What hosts/services does this rely on?
* What hosts/services rely on this?
# network block device encryption default to false,
# only set on hardware hosts that are encrypted installs where
# there is a local tang server or tpm
nbde: false

View file

@ -9,8 +9,8 @@ ansible_ifcfg_allowlist:
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.3.169.120 tcp sport 44334 counter accept']
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: autosign
ipa_client_shell_groups:
- sysadmin-releng

View file

@ -1,6 +1,6 @@
---
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.3.169.120 tcp sport 44334 counter accept']
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: autosign

View file

@ -63,11 +63,16 @@ primary_auth_source: ipa
#
tcp_ports: [22, 1194]
udp_ports: [1194]
zabbix_macros:
# We don't care *too much* about mail here
POSTFIX.QUEUE.WARN: 10000
POSTFIX.QUEUE.AVG: 15000
POSTFIX.QUEUE.CRIT: 20000
notes: |
SSH proxy to access infrastructure not exposed to the web
* Provides ssh access to all iad2/vpn connected servers.
* Provides ssh access to all rdu3/vpn connected servers.
* Bastion is the hub for all infrastructure's VPN connections.
* All incoming SMTP from iad2 and VPN, as well as outgoing SMTP, pass or are filtered here.
* All incoming SMTP from rdu3 and VPN, as well as outgoing SMTP, pass or are filtered here.
* Bastion does not accept any mail outside phx2/vpn.

View file

@ -50,7 +50,7 @@ udp_ports: [1194]
notes: |
SSH proxy to access STAGING infrastructure not exposed to the web
* Provides ssh access to all iad2/vpn connected servers.
* Provides ssh access to all rdu3/vpn connected servers.
* Bastion is the hub for all infrastructure's VPN connections.
* All incoming SMTP from iad2 and VPN, as well as outgoing SMTP, pass or are filtered here.
* All incoming SMTP from rdu3 and VPN, as well as outgoing SMTP, pass or are filtered here.
* Bastion does not accept any mail outside phx2/vpn.

View file

@ -2,9 +2,9 @@
ansible_base: /srv/web/infra
# For the MOTD
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
#
# This host is externally reachable
@ -23,6 +23,7 @@ ipa_client_shell_groups:
- sysadmin-cvs
- sysadmin-datanommer
- sysadmin-debuginfod
- sysadmin-epel
- sysadmin-koschei
- sysadmin-libravatar
- sysadmin-messaging
@ -39,17 +40,20 @@ ipa_client_shell_groups:
- sysadmin-web
ipa_host_group: batcave
ipa_host_group_desc: The Bat Cave
lvm_size: 750000
mem_size: 24576
lvm_size: 850000
mem_size: 32768
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3"
nrpe_procs_crit: 1000
nrpe_procs_warn: 900
num_cpus: 10
num_cpus: 16
primary_auth_source: ipa
tcp_ports: [80, 443, 8442, 8443]
vpn: true
nagios_Check_Services:
swap: false
zabbix_macros:
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status
'APACHE.STATUS.SCHEME': https # but https://localhost seems to work instead
notes: |
Central management host for ansible
@ -61,7 +65,7 @@ notes: |
It houses a number of infrastructure git repos.
This host relies on:
* The virthost it's hosted on (virthost22)
* The virthost it's hosted on (vmhost-x86-01.rdu3.fedoraproject.org)
Things that rely on this host:
* Things that access rhel/fedora/infra rpm repos, including builders and infra hosts.

View file

@ -7,9 +7,9 @@ bodhi_message_routing_keys:
# For the MOTD
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
# this is sign-bridge01.iad2 ip 10.3.169.120
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.3.169.120 tcp sport 44334 counter accept']
# this is sign-bridge01.rdu3 ip 10.16.169.120
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: bodhi2
ipa_client_shell_groups:
- sysadmin-bodhi

View file

@ -0,0 +1,22 @@
---
# These variables are pushed into /etc/system_identification by the base role.
# Groups and individual hosts should ovveride them with specific info.
docker_registry: "candidate-registry.stg.fedoraproject.org"
freezes: false
host_group: kojibuilder
koji_hub: "koji.stg.fedoraproject.org/kojihub"
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
koji_root: "koji.stg.fedoraproject.org/koji"
koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
source_registry: "registry.stg.fedoraproject.org"
notes: |
Koji service employs a set of machines to build packages for the Fedora project.
* Relies on koji-hub, Packages, PkgDB, apache, fedora messaging, fas, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new

View file

@ -1,8 +1,8 @@
---
# common items for the buildvm-* koji builders
dns: 10.3.163.33
dns: 10.16.163.33
docker_registry: "candidate-registry.fedoraproject.org"
eth0_ipv4_gw: 10.3.169.254
eth0_ipv4_gw: 10.16.169.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
@ -13,7 +13,7 @@ koji_root: "koji.fedoraproject.org/koji"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/41/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 262144
max_mem_size: "{{ mem_size }}"

View file

@ -1,8 +1,9 @@
---
# common items for the buildvm-aarch64* koji builders
dns: 10.3.163.33
datacenter: rdu3
dns: 10.16.163.33
docker_registry: "candidate-registry.fedoraproject.org"
eth0_ipv4_gw: 10.3.170.254
eth0_ipv4_gw: 10.16.170.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
@ -13,7 +14,7 @@ koji_root: "koji.fedoraproject.org/koji"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/41/Server/aarch64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/aarch64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 300000
max_cpu: "{{ num_cpus }}"

View file

@ -0,0 +1,34 @@
---
# common items for the buildvm-aarch64* koji builders
datacenter: rdu3
dns: 10.16.163.33
docker_registry: "candidate-registry.fedoraproject.org"
eth0_ipv4_gw: 10.16.170.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
ipa_server: ipa01.rdu3.fedoraproject.org
koji_hub: "koji.fedoraproject.org/kojihub"
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
koji_root: "koji.fedoraproject.org/koji"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/aarch64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 300000
max_cpu: "{{ num_cpus }}"
max_mem_size: "{{ mem_size }}"
mem_size: 49152
num_cpus: 12
source_registry: "registry.fedoraproject.org"
virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}"
volgroup: /dev/vg_guests
notes: |
Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders.
* VMs built on top of buildvmhost
* Relies on koji-hub, Packages, PkgDB, apache, fedora messaging, fas, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new

View file

@ -1,10 +1,10 @@
---
# common items for the buildvm-* koji builders
createrepo: True
datacenter: iad2
dns: 10.3.163.33
datacenter: rdu3
dns: 10.16.163.33
docker_registry: "candidate-registry.stg.fedoraproject.org"
eth0_ipv4_gw: 10.3.167.254
eth0_ipv4_gw: 10.16.167.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
# Groups and individual hosts should ovveride them with specific info.
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/41/Server/aarch64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/aarch64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 140000
max_cpu: "{{ num_cpus }}"

View file

@ -1,46 +0,0 @@
# common variables for osbuild workers
datacenter: iad2
dns: 10.3.163.33
dns_search1: iad2.fedoraproject.org
dns_search2: fedoraproject.org
eth0_ipv4_gw: 10.3.171.254
external: false
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/39/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 102400 # 100 GB
main_bridge: br0
max_mem_size: "{{ mem_size }}"
mem_size: 8192 # 8 GB
num_cpus: 2
virt_install_command: "{{ virt_install_command_ppc64le_one_nic_unsafe }}"
volgroup: /dev/vg_guests
# setup access to workers
ipa_server: ipa01.iad2.fedoraproject.org
ipa_host_group: osbuild
ipa_host_group_desc: osbuild Build vms
primary_auth_source: ipa
ipa_client_shell_groups:
- sysadmin-osbuild
- sysadmin-releng
ipa_client_sudo_groups:
- sysadmin-osbuild
- sysadmin-releng
# osbuild worker variables
osbuild_worker_server_hostname: "api.openshift.com"
osbuild_worker_server_api_base_path: "/api/image-builder-worker/v1"
osbuild_worker_authentication_oauth_url: "https://sso.redhat.com/auth/realms/redhat-external/protocol/openid-connect/token"
osbuild_worker_authentication_client_id: "ab28d581-164e-42ec-99d9-dff8e2020a51"
# the secret is turned into file in the playbook
osbuild_worker_authentication_client_secret: "{{ osbuild_worker_client_secret }}"
osbuild_worker_koji_instances:
- koji_host: "koji.fedoraproject.org"
krb_principal: "osbuild-automation-bot@FEDORAPROJECT.ORG"
krb_keytab_file: "{{ private }}/files/osbuild/worker_koji.keytab"
notes: |
This group of VMs builds OS images via Koji using image builder for ppc64le architecture.
* Relies on koji-hub and image-builder-api (external).
* Produces automated builds of OS images for the architecture listed. Wokers can be scaled by adding new
virtual instances

View file

@ -1,46 +0,0 @@
# common variables for osbuild workers (staging)
datacenter: iad2
dns: 10.3.163.33
dns_search1: iad2.fedoraproject.org
dns_search2: fedoraproject.org
eth0_ipv4_gw: 10.3.171.254
external: false
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/39/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 102400 # 100 GB
main_bridge: br0
max_mem_size: "{{ mem_size }}"
mem_size: 4096 # 4 GB
num_cpus: 2
virt_install_command: "{{ virt_install_command_ppc64le_one_nic_unsafe }}"
volgroup: /dev/vg_guests
# setup access to workers
ipa_server: ipa01.iad2.fedoraproject.org
ipa_host_group: osbuild
ipa_host_group_desc: osbuild Build vms
primary_auth_source: ipa
ipa_client_shell_groups:
- sysadmin-osbuild
- sysadmin-releng
ipa_client_sudo_groups:
- sysadmin-osbuild
- sysadmin-releng
# osbuild worker variables
osbuild_worker_server_hostname: "api.stage.openshift.com"
osbuild_worker_server_api_base_path: "/api/image-builder-worker/v1"
osbuild_worker_authentication_oauth_url: "https://sso.redhat.com/auth/realms/redhat-external/protocol/openid-connect/token"
osbuild_worker_authentication_client_id: "07120c6c-fd31-4735-bb2f-891439b0bf41"
# the secret is turned into file in the playbook
osbuild_worker_authentication_client_secret: "{{ osbuild_worker_stg_client_secret }}"
osbuild_worker_koji_instances:
- koji_host: "koji.stg.fedoraproject.org"
krb_principal: "osbuild-automation-bot@STG.FEDORAPROJECT.ORG"
krb_keytab_file: "{{ private }}/files/osbuild/worker_stg_koji.keytab"
notes: |
This group of VMs builds OS images via Koji (staging) using image builder for ppc64le architecture.
* Relies on koji-hub and image-builder-api (external).
* Produces automated builds of OS images for the architecture listed. Wokers can be scaled by adding new
virtual instances

View file

@ -1,28 +1,28 @@
# common items for the buildvm-* koji builders
# These variables are pushed into /etc/system_identification by the base role.
# Groups and individual hosts should ovveride them with specific info.
datacenter: iad2
dns: 10.3.163.33
eth0_ipv4_gw: 10.3.171.254
datacenter: rdu3
dns: 10.16.163.33
eth0_ipv4_gw: 10.16.171.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
ipa_server: ipa01.iad2.fedoraproject.org
ipa_server: ipa01.rdu3.fedoraproject.org
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/41/Server/ppc64le/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 262144
#
# The ppc virthosts have different bridge names for the main and nfs bridges.
#
main_bridge: br0
max_mem_size: 20480
mem_size: 20480
num_cpus: 8
max_mem_size: 38912
mem_size: 38912
num_cpus: 10
virt_install_command: "{{ virt_install_command_ppc64le_one_nic_unsafe }}"
volgroup: /dev/vg_virt_buildvm_ppc64le_iscsi

View file

@ -0,0 +1,36 @@
---
# common items for the buildvm-aarch64* koji builders
datacenter: rdu3
dns: 10.16.163.33
dns1: 10.16.163.33
dns2: 10.16.163.34
docker_registry: "candidate-registry.fedoraproject.org"
eth0_ipv4_gw: 10.16.171.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
koji_hub: "koji.fedoraproject.org/kojihub"
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
koji_root: "koji.fedoraproject.org/koji"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 300000
main_bridge: br0
max_cpu: "{{ num_cpus }}"
max_mem_size: "{{ mem_size }}"
mem_size: 38912
num_cpus: 10
source_registry: "registry.fedoraproject.org"
virt_install_command: "{{ virt_install_command_aarch64_one_nic_unsafe }}"
volgroup: /dev/vg_fedora_ppc64le_builders
notes: |
Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders.
* VMs built on top of buildvmhost
* Relies on koji-hub, Packages, PkgDB, apache, fedora messaging, fas, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new

View file

@ -2,9 +2,9 @@
# common items for the buildvm-* koji builders
createrepo: True
datacenter: staging
dns: 10.3.163.33
dns: 10.16.163.33
docker_registry: "candidate-registry.stg.fedoraproject.org"
eth0_ipv4_gw: 10.3.167.254
eth0_ipv4_gw: 10.16.167.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
# Groups and individual hosts should ovveride them with specific info.
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/41/Server/ppc64le/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 150000
main_bridge: br0

View file

@ -0,0 +1,32 @@
---
# common items for the buildvm-* koji builders
dns: 10.16.163.33
docker_registry: "candidate-registry.fedoraproject.org"
eth0_ipv4_gw: 10.16.169.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
koji_hub: "koji.fedoraproject.org/kojihub"
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
koji_root: "koji.fedoraproject.org/koji"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 300000
max_mem_size: "{{ mem_size }}"
mem_size: 30720
num_cpus: 8
source_registry: "registry.fedoraproject.org"
virt_install_command: "{{ virt_install_command_one_nic_unsafe }}"
volgroup: /dev/vg_guests
notes: |
Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders.
* VMs built on top of buildvmhost
* Relies on koji-hub, Packages, PkgDB, apache, fedora messaging, fas, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Produces automated builds of packages for the architecture listed. Builders can be scaled by adding new

View file

@ -1,8 +1,8 @@
---
createrepo: False
dns1: 10.3.163.33
dns2: 10.3.163.34
dns_search1: "iad2.fedoraproject.org"
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
eth0_ipv4_gw: 10.1.102.254
external: false
@ -13,8 +13,8 @@ koji_instance: "primary"
koji_server_url: "https://koji.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.fedoraproject.org/"
koji_weburl: "https://koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/41/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora-s390x
lvm_size: 128000
main_bridge: br0
mem_size: 25600

View file

@ -1,10 +1,10 @@
---
dns1: 10.3.163.33
dns2: 10.3.163.34
dns_search1: "iad2.fedoraproject.org"
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
eth0_ipv4_gw: 10.16.0.254
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/41/Server/s390x/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 102400
main_bridge: vmbr

View file

@ -1,14 +1,30 @@
---
createrepo: False
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
eth0_ipv4_gw: 10.1.102.254
external: false
has_ipv4: yes
host_group: kojibuilder
koji_hub_nfs: "fedora_koji"
koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
koji_instance: "primary"
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/41/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora-s390x
virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}"
lvm_size: 100000
main_bridge: br0
max_cpu: 4
max_mem_size: 10240
mem_size: 10240
num_cpus: 2
varnish_group: s390kojipkgs
vmhost: bvmhost-s390x-01.s390.fedoraproject.org
volgroup: /dev/fedora_rdu-z16-l51
notes: |
Koji service employs a set of machines to build packages for the Fedora project. This playbook builds vm builders.

View file

@ -1,13 +1,13 @@
---
# common items for the buildvm-* koji builders
datacenter: iad2
dns1: 10.3.163.33
datacenter: rdu3
dns1: 10.16.163.33
docker_registry: "candidate-registry.stg.fedoraproject.org"
eth0_ipv4_gw: 10.3.167.254
eth0_ipv4_gw: 10.16.167.254
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
host_group: kojibuilder
ipa_server: ipa01.stg.iad2.fedoraproject.org
ipa_server: ipa01.stg.rdu3.fedoraproject.org
koji_hub: "koji.stg.fedoraproject.org/kojihub"
koji_hub_nfs: "fedora_koji"
koji_instance: "primary"
@ -18,14 +18,14 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
# Groups and individual hosts should ovveride them with specific info.
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/41/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 150000
max_mem_size: "{{ mem_size }}"
mem_size: 10240
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=4"
num_cpus: 4
resolvconf: "resolv.conf/iad2"
resolvconf: "resolv.conf/rdu3"
source_registry: "registry.fedoraproject.org"
virt_install_command: "{{ virt_install_command_one_nic_unsafe }}"
volgroup: /dev/vg_guests

View file

@ -1,7 +1,7 @@
---
# common items for the buildvm-* koji builders
dns: 10.3.163.33
eth0_ipv4_gw: 10.3.172.254
dns: 10.16.163.33
eth0_ipv4_gw: 10.16.172.254
external: false
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
@ -13,7 +13,7 @@ koji_root: "riscv-koji.fedoraproject.org/koji"
koji_server_url: "https://riscv-koji.fedoraproject.org/kojihub"
koji_topurl: "https://riscv-kojipkgs.fedoraproject.org/"
koji_weburl: "https://riscv-koji.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/41/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 262144
max_mem_size: "{{ mem_size }}"

View file

@ -7,6 +7,12 @@ nrpe_procs_warn: 1700
virthost: true
nagios_Check_Services:
swap: false
zabbix_macros:
MEMORY.UTIL.MAX: 100
NET.IF.IFNAME.NOT_MATCHES: "^vnet.*"
SWAP.PFREE.MIN.WARN: 0
VFS.DEV.READ.AWAIT.WARN: 40
VFS.DEV.WRITE.AWAIT.WARN: 120
notes: |
Koji service employs a set of virtual machines to build packages for the Fedora project. This playbook is for the provisioning of a physical host for buildvm's.

View file

@ -2,6 +2,12 @@
nagios_Check_Services:
swap: false
nested: true
nrpe_procs_crit: 1500
nrpe_procs_warn: 1400
nrpe_procs_crit: 3500
nrpe_procs_warn: 3000
virthost: true
zabbix_macros:
MEMORY.UTIL.MAX: 100
NET.IF.IFNAME.NOT_MATCHES: "^vnet.*"
SWAP.PFREE.MIN.WARN: 0
VFS.DEV.READ.AWAIT.WARN: 40
VFS.DEV.WRITE.AWAIT.WARN: 80

View file

@ -1,9 +1,9 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
lvm_size: 20000
mem_size: 2048

View file

@ -1,9 +1,9 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
lvm_size: 20000
mem_size: 2048

View file

@ -6,7 +6,7 @@ checkcompose_prod: true
# if additional systems were added to this group.
checkcompose_emailfrom: rawhide@fedoraproject.org
checkcompose_emailto: "test-reports@lists.fedoraproject.org"
checkcompose_smtp: bastion.iad2.fedoraproject.org
checkcompose_smtp: bastion.rdu3.fedoraproject.org
checkcompose_subvariant_emails:
BaseOS:
error: ["yselkowitz@redhat.com", "aavraham@redhat.com"]

View file

@ -5,3 +5,9 @@ dns_search1: vpn.fedoraproject.org
dns_search2: fedoraproject.org
virthost: true
vpn: true
# Zabbix in RDU3 via vpn
zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_server: "{{ zabbix_hostname }}"
zabbix_auth_key: "{{ zabbix_apikey }}" # ansible-private repo
zabbix_macros:
NET.IF.IFNAME.NOT_MATCHES: "^vnet.*"

View file

@ -14,3 +14,9 @@ additional_known_hosts_cleanup:
- copr-be-temp.aws.fedoraproject.org
aws_ipv6_con: "cloud-init ens5"
freezes: false
cgit_uri: packages
# We don't actually have an IPA host group allocated yet, but Anubis role needs
# us to have something set in ipa_host_group.
ipa_host_group: copr-infrastructure

View file

@ -19,18 +19,33 @@ backend_base_url: "https://download.copr.fedorainfracloud.org"
builders:
# max|spawn_concurrently|prealloc
aws:
aarch64: [8, 2, 2]
x86_64: [20, 4, 1]
aarch64: [8, 2, 1]
x86_64: [50, 10, 20]
# put here the number -1 of the actuall reserved instances
aws_reserved:
aarch64: [50, 20, 33]
x86_64: [58, 20, 52]
aws_reserved_powerful:
x86_64: [1, 1, 1]
aws_powerful:
aarch64: [10, 2, 0]
x86_64: [10, 2, 1]
aws_spot:
aarch64: [30, 4, 3]
x86_64: [70, 8, 8]
aarch64: [30, 4, 1]
x86_64: [70, 8, 16]
ppc64le_hypervisor_01:
ppc64le: [15, 4, 15]
ppc64le: [0, 4, 15]
# There's the ppc64le-test machine, so keep 2 builders less.
ppc64le_hypervisor_02:
ppc64le: [13, 4, 13]
ppc64le: [0, 4, 13]
p09_hypervisor_01:
ppc64le: [31, 5, 31]
ppc64le: [15, 5, 15]
p09_hypervisor_02:
ppc64le: [15, 5, 15]
p09_hypervisor_03:
ppc64le: [15, 5, 15]
p09_hypervisor_04:
ppc64le: [15, 5, 15]
x86_hypervisor_01:
x86_64: [20, 4, 20]
x86_hypervisor_02:
@ -148,35 +163,36 @@ copr_aws_region: us-east-1
# don't forget to update ip in ./copr-keygen, due to custom firewall rules
# eth0, eth1
copr_backend_ips: ["52.44.175.77", "172.30.2.145"]
copr_backend_ips: ["52.44.175.77", "172.30.2.105"]
copr_builder_fedora_version: 42
copr_builder_images:
aws:
# WARNING: when changing, always remove images N-2 and older
# n-1: aarch64: ami-0c3217e2af416bf2d
# n-1: x86_64: ami-0c430e4bc139d93ec
aarch64: ami-0b12d7f04cd8eb605
x86_64: ami-0b230bd6612b2f249
# WARNING: never forget to tag FedoraGroup=copr!
# n-1: aarch64: ami-016278526bb5e2a63
# n-1: x86_64: ami-01f4000c6312cc58e
aarch64: ami-0b8871c5be60af626
x86_64: ami-0a3a77adba2c726a2
hypervisor:
# n-1: ppc64le: copr-builder-ppc64le-20241119_171239
# n-1: x86_64: copr-builder-x86_64-20241119_172236
ppc64le: copr-builder-ppc64le-20250604_082355
x86_64: copr-builder-x86_64-20250522_185837
# n-1: ppc64le: copr-builder-ppc64le-2025-09-13
# n-1: x86_64: copr-builder-x86_64-2025-09-13
ppc64le: copr-builder-ppc64le-2026-01-20
x86_64: copr-builder-x86_64-2026-01-20
ibm_cloud:
br_sao: # São Paulo
# n-1: s390x: r042-5e105a96-4a84-4c07-950b-9fd12d58c8a2
s390x: r042-9060a649-d463-470b-ad1b-cb5243352117
# n-1: s390x: r042-e3538e98-9297-422f-b30d-b566ad8b0ac7
s390x: r042-8ea365c9-fcdd-4611-848c-75ccb3e56a5d
eu_es: # Madrid
# n-1: s390x: r050-053cfdb8-52eb-486d-b8b3-bc9cba2fbe56
s390x: r050-eacdf1fc-ed2b-4994-a80d-12cdead6e6f1
# n-1: s390x: r050-39129a43-d427-41a1-8aa0-26ae65305fbf
s390x: r050-3afb8f3d-5552-43e7-8eee-de6511ca41dc
us_east: # Washington
# n-1: s390x: r014-9ba4feec-ce45-4401-acea-f123114685b5
s390x: r014-c153ec34-99d1-4dc1-bc75-5724606e9ee9
# n-1: s390x: r014-1c40f060-69c7-42a1-83ed-005626de5e81
s390x: r014-43e2144b-2795-402a-92b2-066d1f989b5c
osuosl:
# n-1: ppc64le: copr-builder-ppc64le-20241119_171239
ppc64le: copr-builder-ppc64le-20250604_082355
# n-1: ppc64le: copr-builder-ppc64le-2025-09-13
ppc64le: copr-builder-ppc64le-2026-01-14
copr_messaging: true
datacenter: aws
@ -206,3 +222,7 @@ rsnapshot_push:
deployment_type: prod
pulp_content_url: "https://console.redhat.com/api/pulp-content/public-copr/"
zabbix_host: 38.145.32.41
zabbix_macros:
'LOAD_AVG_PER_CPU.MAX.WARN': 6 # frequently busy hosts

View file

@ -22,17 +22,29 @@ backend_base_url: "https://download.copr-dev.fedorainfracloud.org"
builders:
# max|spawn_concurrently|prealloc
aws:
aarch64: [2, 0, 0]
aarch64: [2, 1, 1]
x86_64: [4, 0, 0]
aws_reserved:
aarch64: [0, 0, 0]
x86_64: [0, 0, 0]
aws_powerful:
aarch64: [10, 1, 0]
x86_64: [10, 1, 0]
aws_spot:
aarch64: [5, 1, 1]
x86_64: [5, 1, 1]
aarch64: [3, 3, 1]
x86_64: [0, 0, 1]
ppc64le_hypervisor_01:
ppc64le: [2, 1, 1]
ppc64le: [0, 1, 1]
ppc64le_hypervisor_02:
ppc64le: [2, 1, 1]
ppc64le: [0, 1, 1]
p09_hypervisor_01:
ppc64le: [2, 1, 1]
ppc64le: [1, 1, 1]
p09_hypervisor_02:
ppc64le: [1, 1, 1]
p09_hypervisor_03:
ppc64le: [1, 1, 1]
p09_hypervisor_04:
ppc64le: [1, 1, 1]
x86_hypervisor_01:
x86_64: [2, 1, 1]
x86_hypervisor_02:
@ -137,26 +149,27 @@ copr_aws_region: us-east-1
# don't forget to update ip in ./copr-keygen-stg, due to custom firewall rules
# eth0, eth1
copr_backend_ips: ["18.208.10.131", "172.30.2.173"]
copr_backend_ips: ["18.208.10.131", "172.30.2.11"]
copr_builder_fedora_version: 41
copr_builder_fedora_version: 42
copr_builder_images:
aws:
aarch64: ami-0b12d7f04cd8eb605
x86_64: ami-0b230bd6612b2f249
# WARNING: never forget to tag FedoraGroup=copr!
aarch64: ami-0b8871c5be60af626
x86_64: ami-0a3a77adba2c726a2
hypervisor:
ppc64le: copr-builder-ppc64le-20250604_082355
x86_64: copr-builder-x86_64-20250522_185837
ppc64le: copr-builder-ppc64le-2026-01-20
x86_64: copr-builder-x86_64-2026-01-20
ibm_cloud:
br_sao: # São Paulo
s390x: r042-9060a649-d463-470b-ad1b-cb5243352117
s390x: r042-8ea365c9-fcdd-4611-848c-75ccb3e56a5d
eu_es: # Madrid
s390x: r050-eacdf1fc-ed2b-4994-a80d-12cdead6e6f1
s390x: r050-3afb8f3d-5552-43e7-8eee-de6511ca41dc
us_east: # Washington
s390x: r014-c153ec34-99d1-4dc1-bc75-5724606e9ee9
s390x: r014-43e2144b-2795-402a-92b2-066d1f989b5c
osuosl:
ppc64le: copr-builder-ppc64le-20250604_082355
ppc64le: copr-builder-ppc64le-2026-01-14
copr_messaging: true
datacenter: aws
@ -172,3 +185,5 @@ aws_cloudfront_distribution: EX55ITR8LVMOH
nrpe_client_uid: 500
pulp_content_url: "https://console.redhat.com/api/pulp-content/public-copr-stage/"
zabbix_host: 38.145.32.42

View file

@ -1,6 +1,9 @@
---
copr_machine_type: distgit
# Enable verbose Anubis logging for debugging
anubis_debug: true
devel: true
freezes: false
# consumed by roles/copr/certbot

View file

@ -1,6 +1,9 @@
---
copr_machine_type: frontend
# Enable verbose Anubis logging for debugging
anubis_debug: true
allowlist_emails:
- msuchy@redhat.com
- praiskup@redhat.com

View file

@ -1,4 +1,8 @@
---
freezes: false
host_group: copr_hypervisor
vpn: true
ipa_client_shell_groups:
- sysadmin-noc
@ -10,6 +14,35 @@ ipa_client_sudo_groups:
ipa_host_group: copr-vmhost
ipa_host_group_desc: Copr hypervisors
postfix_group: vpn
primary_auth_source: ipa
nftables: false
nbde: true
nbde_device: /dev/md2
nbde_client_bindings:
- device: "{{ nbde_device }}"
encryption_password: "{{ nbde_password }}"
password_temporary: no
threshold: 1
servers:
- http://tang01.rdu3.fedoraproject.org
- http://tang02.rdu3.fedoraproject.org
libvirt_host: "{{ inventory_hostname }}"
nft_custom_rules:
- add rule ip filter INPUT iifname virbr0 udp dport bootps accept
- add rule ip filter INPUT iifname virbr0 udp dport 53 accept
- add rule ip filter INPUT iifname virbr0 tcp dport ssh accept
- add rule ip filter FORWARD iifname "virbr0" oif != "virbr0" counter accept
- add rule ip filter FORWARD iifname "virbr0" ct state new counter accept
- add rule ip filter FORWARD ct state established,related counter accept
- add rule ip filter FORWARD ip protocol icmp counter accept
zabbix_macros:
CPU.UTIL.CRIT: 100
MEMORY.UTIL.MAX: 100
NET.IF.IFNAME.NOT_MATCHES: "^(vnet.*|virbr.*)"
SWAP.PFREE.MIN.WARN: 0
VFS.DEV.READ.AWAIT.WARN: 40
VFS.DEV.WRITE.AWAIT.WARN: 80

View file

@ -6,13 +6,13 @@ copr_hostbase: copr-keygen
custom_rules:
- '-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 52.44.175.77 --dport 5167 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.145 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.145 --dport 5167 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 5167 -j ACCEPT'
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.145 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.145 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 5167 counter accept'
freezes: false
tcp_ports: [22,
# node_exporter/prometheus

View file

@ -4,13 +4,13 @@ copr_machine_type: keygen
copr_hostbase: copr-keygen-dev
# http + signd dest ports
custom_rules:
- '-A INPUT -p tcp -m tcp -s 172.30.2.173 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.173 --dport 5167 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.11 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.11 --dport 5167 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 5167 -j ACCEPT'
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 172.30.2.173 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.173 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 5167 counter accept'
freezes: false

View file

@ -1,14 +0,0 @@
---
# These variables are pushed into /etc/system_identification by the base role.
# Groups and individual hosts should ovveride them with specific info.
nrpe_procs_crit: 1000
nrpe_procs_warn: 900
virthost: true
notes: |
Koji service employs a set of virtual machines to build packages for the Fedora project. This playbook is for the provisioning of a physical host for buildvm's.
* Relies on ansible, virthost, and is monitored by nagios
* Several services rely on the builders, including koschei, Bodhi, Tagger, SCM, Darkserver.
* Builder vm's are hosted on hosts created with this playbook.

View file

@ -36,6 +36,8 @@ dl_tier1:
- 192.206.9.160 # University of Southern Indiana
- 208.96.144.68 # University of Southern Indiana
- 208.89.84.55 # Mirror.dst.ca
- 162.255.90.27 # fedora-mirror-atl.gigsouth.com
- 162.255.95.178 # fedora-mirror-mia.gigsouth.com
- 213.175.37.8/29 # ??
- 66.187.233.206 # Red Hat BOS
- 71.19.151.18 # prgmr.com / nb.zone
@ -54,6 +56,8 @@ dl_tier1:
- 2604:1380:3000:1500::1 # kernel.org apac
- 2620:52:3:1:dead:beef:cafe:fed1 # download-cc-rdu01's ipv6 address
- 2602:fc25:101:702::68 # University of Southern Indiana
- 2605:7b80:63:5::27 # fedora-mirror-atl.gigsouth.com
- 2605:7b80:200f:3::178 # fedora-mirror-mia.gigsouth.com
- archive.linux.duke.edu # 152.3.102.53
- 152.3.68.159 # new archive.linux.duke.edu
- auslistsdr01.us.dell.com # 143.166.224.62
@ -100,8 +104,15 @@ dl_tier1:
- ultra.linux.cz # 195.113.15.27
- wpi.edu # 130.215.36.26
- zaphod.gtlib.gatech.edu # 128.61.111.12
- sv.mirrors.kernel.org
- dfw.mirrors.kernel.org
ipa_host_group: download
ipa_host_group_desc: Download servers
nagios_Check_Services:
swap: false
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 212.143.41.0/24 counter reject'
primary_auth_source: ipa
zabbix_macros:
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status
'APACHE.STATUS.SCHEME': https # but https://localhost seems to work instead

View file

@ -1,15 +0,0 @@
---
blocked_ips: []
datacenter: iad2
dns: 10.3.163.33
#
# This host is externally reachable
#
external: true
host_group: download-iad2
# nfs mount options, overrides the all/default
nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=4"
nrpe_procs_crit: 1000
nrpe_procs_warn: 900
rsyncd_conf: "rsyncd.conf.download-{{ datacenter }}"
tcp_ports: [80, 443, 873]

View file

@ -1,18 +0,0 @@
---
network_connections:
- autoconnect: yes
ip:
address:
- "{{ eth0_ipv4_ip }}/{{ eth0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ eth0_ipv4_gw }}"
mac: "{{ ansible_default_ipv4.macaddress }}"
name: eth0
type: ethernet
mtu: 9000

View file

@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
custom_rules: ['-A INPUT -p udp -m udp -s 10.3.0.0/16 --dport 53 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.3.0.0/16 udp dport 53 counter accept']
custom_rules: ['-A INPUT -p udp -m udp -s 10.16.0.0/16 --dport 53 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.0.0/16 udp dport 53 counter accept']
host_backup_targets: ['/var/lib/ipa/backup', '/var/log/dirsrv/slapd-FEDORAPROJECT-ORG']
ipa_client_shell_groups:
- sysadmin-accounts
@ -20,3 +20,4 @@ num_cpus: 8
primary_auth_source: ipa
tcp_ports: [80, 88, 389, 443, 464, 636]
udp_ports: [88, 464]
vpn: true

View file

@ -0,0 +1,20 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipatuura
ipa_host_group_desc: IPA-tuura SCIM application
ipa_client_shell_groups:
- sysadmin-noc
ipa_client_sudo_groups:
- sysadmin-noc
ipatuura_db_host: "db-fas01.stg.rdu3.fedoraproject.org"
lvm_size: 20000
mem_size: 4096
num_cpus: 2
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
proxy_tcp_ports: [80, 443]

View file

@ -1,12 +1,13 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"
lvm_size: 50000
mem_size: 32768
num_cpus: 2

View file

@ -0,0 +1,16 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"
lvm_size: 50000
mem_size: 32768
num_cpus: 2
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
tcp_ports: [80, 443]

View file

@ -1,9 +1,9 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
@ -11,6 +11,7 @@ ipa_client_shell_groups:
- sysadmin-noc
ipa_client_sudo_groups:
- sysadmin-noc
ipsilon_db_host: "db-fas01.stg.rdu3.fedoraproject.org"
lvm_size: 20000
mem_size: 4096
num_cpus: 2

View file

@ -0,0 +1,20 @@
---
# Define resources for this group of hosts here.
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipa_client_shell_groups:
- sysadmin-noc
ipa_client_sudo_groups:
- sysadmin-noc
ipsilon_db_host: "db-fas01.stg.rdu3.fedoraproject.org"
lvm_size: 20000
mem_size: 4096
num_cpus: 2
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
proxy_tcp_ports: [80, 443]

View file

@ -8,4 +8,14 @@ ipa_client_sudo_groups:
- sysadmin-kernel
ipa_host_group: kernel_qa
ipa_host_group_desc: kernel test machines
resolvconf: "{{ files }}/resolv.conf/iad2"
resolvconf: "{{ files }}/resolv.conf/rdu3"
nbde: true
nbde_device: /dev/md2
nbde_client_bindings:
- device: "{{ nbde_device }}"
encryption_password: "{{ nbde_password }}"
password_temporary: no
threshold: 1
servers:
- http://tang01.rdu3.fedoraproject.org
- http://tang02.rdu3.fedoraproject.org

View file

@ -3,10 +3,10 @@
# For the MOTD
custom_rules: [
# Need for rsync from log01 for logs.
'-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
# Need for rsync from log01 for logs.
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_client_shell_groups:
- sysadmin-noc

View file

@ -9,15 +9,12 @@ ipa_host_group: mailman
ipa_host_group_desc: Mailing list services
lvm_size: 950000
# Used by the mailman role
mailman3_db_server: db01.iad2.fedoraproject.org
mailman3_db_server: db01.rdu3.fedoraproject.org
mailman3_domains:
- lists.fedoraproject.org
- lists.fedorahosted.org
- lists.pagure.io
mailman3_login:
facebook:
display_name: Facebook
provider: facebook
github:
display_name: GitHub
provider: github
@ -27,12 +24,6 @@ mailman3_login:
google:
display_name: Google
provider: google
stackexchange:
display_name: StackExchange
provider: stackexchange
twitter:
display_name: Twitter
provider: twitter
fedora:
display_name: Fedora
provider: fedora

View file

@ -9,15 +9,12 @@ ipa_host_group: mailman
ipa_host_group_desc: Mailing list services
lvm_size: 350000
# Used by the mailman role
mailman3_db_server: db01.stg.iad2.fedoraproject.org
mailman3_db_server: db01.stg.rdu3.fedoraproject.org
mailman3_domains:
- lists.stg.fedoraproject.org
- lists.stg.fedorahosted.org
- lists.stg.pagure.io
mailman3_login:
facebook:
display_name: Facebook
provider: facebook
github:
display_name: GitHub
provider: github
@ -27,12 +24,6 @@ mailman3_login:
google:
display_name: Google
provider: google
stackexchange:
display_name: StackExchange
provider: stackexchange
twitter:
display_name: Twitter
provider: twitter
fedora:
display_name: Fedora
provider: fedora

View file

@ -1,5 +1,6 @@
---
datacenter: aws
dnf_automatic_type: default
freezes: false
ipa_client_shell_groups:
- packager

View file

@ -10,23 +10,23 @@ dns_external:
# to add that group to this list. Other items on this list are ones
# where it is an enormous group not needed.
# Exclude these ansible host groups in hostgroups/all.cfg
exclude_iad2_hostgroups:
exclude_rdu3_hostgroups:
- centos_ipa_client_stg
- zabbix_stg
- zabbix
- logdetective
#iad2_management_slowping:
#rdu3_management_slowping:
# - ppc8-01-fsp.mgmt.fedoraproject.org
# - ppc8-02-fsp.mgmt.fedoraproject.org
# - ppc8-03-fsp.mgmt.fedoraproject.org
iad2_external:
rdu3_external:
- bastion01.fedoraproject.org
- bastion02.fedoraproject.org
- dl-iad01.fedoraproject.org
- dl-iad02.fedoraproject.org
- dl-iad03.fedoraproject.org
- dl-iad04.fedoraproject.org
- dl-iad05.fedoraproject.org
- dl01.fedoraproject.org
- dl02.fedoraproject.org
- dl03.fedoraproject.org
- dl04.fedoraproject.org
- dl05.fedoraproject.org
- infrastructure.fedoraproject.org
- koji.fedoraproject.org
- kojipkgs.fedoraproject.org
@ -34,104 +34,83 @@ iad2_external:
- ns-iad02.fedoraproject.org
- pkgs.fedoraproject.org
- proxy01.fedoraproject.org
- proxy03.fedoraproject.org
- proxy10.fedoraproject.org
- proxy14.fedoraproject.org
- secondary01.fedoraproject.org
- smtp-mm-iso01.fedoraproject.org
- storinator01.fedoraproject.org
#
# This is a list of hosts which are in the IAD2 160 mgmt network
# This is a list of hosts which are in the RDU3 160 mgmt network
# we do not have them in ansible because it tries to connect
# and they don't do ansible
#
iad2_management_hosts:
- autosign02.mgmt.iad2.fedoraproject.org
- backup01.mgmt.iad2.fedoraproject.org
- bkernel01.mgmt.iad2.fedoraproject.org
- bkernel02.mgmt.iad2.fedoraproject.org
- bvmhost-a64-01.mgmt.iad2.fedoraproject.org.
- bvmhost-a64-02.mgmt.iad2.fedoraproject.org.
- bvmhost-a64-03.mgmt.iad2.fedoraproject.org.
- bvmhost-a64-04.mgmt.iad2.fedoraproject.org.
- bvmhost-p09-01.mgmt.iad2.fedoraproject.org.
- bvmhost-p09-02.mgmt.iad2.fedoraproject.org.
- bvmhost-p09-03.mgmt.iad2.fedoraproject.org.
- bvmhost-p09-04.mgmt.iad2.fedoraproject.org.
- bvmhost-x86-01.mgmt.iad2.fedoraproject.org
- bvmhost-x86-02.mgmt.iad2.fedoraproject.org
- bvmhost-x86-03.mgmt.iad2.fedoraproject.org
- bvmhost-x86-04.mgmt.iad2.fedoraproject.org
- bvmhost-x86-05.mgmt.iad2.fedoraproject.org
- bvmhost-x86-06.mgmt.iad2.fedoraproject.org
- bvmhost-x86-07.mgmt.iad2.fedoraproject.org
- dell-fx01-fc01.mgmt.iad2.fedoraproject.org
- dell-fx01-fc02.mgmt.iad2.fedoraproject.org
- dell-fx01-fc03.mgmt.iad2.fedoraproject.org
- dell-fx01-fc04.mgmt.iad2.fedoraproject.org
- dell-fx01-fc05.mgmt.iad2.fedoraproject.org
- dell-fx01-fc06.mgmt.iad2.fedoraproject.org
- dell-fx01-fc07.mgmt.iad2.fedoraproject.org
- dell-fx01-fc08.mgmt.iad2.fedoraproject.org
- dell-fx01.mgmt.iad2.fedoraproject.org
- dell-fx02-fc01.mgmt.iad2.fedoraproject.org
- dell-fx02-fc02.mgmt.iad2.fedoraproject.org
- dell-fx02-fc03.mgmt.iad2.fedoraproject.org
- dell-fx02-fc04.mgmt.iad2.fedoraproject.org
- dell-fx02-fc05.mgmt.iad2.fedoraproject.org
- dell-fx02-fc06.mgmt.iad2.fedoraproject.org
- dell-fx02-fc07.mgmt.iad2.fedoraproject.org
- dell-fx02-fc08.mgmt.iad2.fedoraproject.org
- dell-fx02.mgmt.iad2.fedoraproject.org
- openqa-a64-worker01.mgmt.iad2.fedoraproject.org
- openqa-a64-worker02.mgmt.iad2.fedoraproject.org
- openqa-a64-worker03.mgmt.iad2.fedoraproject.org
- openqa-p09-worker01.mgmt.iad2.fedoraproject.org
- openqa-p09-worker02.mgmt.iad2.fedoraproject.org
- openqa-x86-worker01.mgmt.iad2.fedoraproject.org
- openqa-x86-worker02.mgmt.iad2.fedoraproject.org
- openqa-x86-worker03.mgmt.iad2.fedoraproject.org
- openqa-x86-worker04.mgmt.iad2.fedoraproject.org
- openqa-x86-worker05.mgmt.iad2.fedoraproject.org
- openqa-x86-worker06.mgmt.iad2.fedoraproject.org
- qvmhost-x86-01.mgmt.iad2.fedoraproject.org
- qvmhost-x86-02.mgmt.iad2.fedoraproject.org
- sign-vault01.mgmt.iad2.fedoraproject.org
- sign-vault02.mgmt.iad2.fedoraproject.org
- vmhost-x86-01.mgmt.iad2.fedoraproject.org
- vmhost-x86-02.mgmt.iad2.fedoraproject.org
- vmhost-x86-03.mgmt.iad2.fedoraproject.org
- vmhost-x86-04.mgmt.iad2.fedoraproject.org
- vmhost-x86-05.mgmt.iad2.fedoraproject.org
- vmhost-x86-06.mgmt.iad2.fedoraproject.org
- vmhost-x86-08.mgmt.iad2.fedoraproject.org
- bvmhost-a64-01-stg.mgmt.iad2.fedoraproject.org
- bvmhost-x86-01-stg.mgmt.iad2.fedoraproject.org
- bvmhost-x86-02-stg.mgmt.iad2.fedoraproject.org
- bvmhost-x86-03-stg.mgmt.iad2.fedoraproject.org
- bvmhost-x86-05-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-01-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-02-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-05-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-06-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-07-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-08-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-09-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-11-stg.mgmt.iad2.fedoraproject.org
- vmhost-x86-12-stg.mgmt.iad2.fedoraproject.org
- worker01.mgmt.iad2.fedoraproject.org
- worker02.mgmt.iad2.fedoraproject.org
- worker03.mgmt.iad2.fedoraproject.org
- worker04.mgmt.iad2.fedoraproject.org
- worker05.mgmt.iad2.fedoraproject.org
- worker06.mgmt.iad2.fedoraproject.org
- worker01-stg.mgmt.iad2.fedoraproject.org
- worker02-stg.mgmt.iad2.fedoraproject.org
- worker03-stg.mgmt.iad2.fedoraproject.org
- worker04-stg.mgmt.iad2.fedoraproject.org
- worker05-stg.mgmt.iad2.fedoraproject.org
rdu3_management_hosts:
- autosign01.mgmt.rdu3.fedoraproject.org
- backup01.mgmt.rdu3.fedoraproject.org
- buildhw-a64-01.mgmt.rdu3.fedoraproject.org
- buildhw-a64-02.mgmt.rdu3.fedoraproject.org
- buildhw-x86-01.mgmt.rdu3.fedoraproject.org
- buildhw-x86-02.mgmt.rdu3.fedoraproject.org
- buildhw-x86-03.mgmt.rdu3.fedoraproject.org
- buildhw-x86-04.mgmt.rdu3.fedoraproject.org
- buildhw-x86-08.mgmt.rdu3.fedoraproject.org
- buildhw-x86-09.mgmt.rdu3.fedoraproject.org
- buildhw-x86-10.mgmt.rdu3.fedoraproject.org
- buildhw-x86-12.mgmt.rdu3.fedoraproject.org
- buildhw-x86-13.mgmt.rdu3.fedoraproject.org
- bvmhost-a64-01.mgmt.rdu3.fedoraproject.org
- bvmhost-a64-02.mgmt.rdu3.fedoraproject.org
- bvmhost-a64-03.mgmt.rdu3.fedoraproject.org
- bvmhost-a64-04.mgmt.rdu3.fedoraproject.org
- bvmhost-p10-01.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-01.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-02.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-03.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-04.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-06.mgmt.rdu3.fedoraproject.org
- openqa-a64-worker01.mgmt.rdu3.fedoraproject.org
- openqa-a64-worker02.mgmt.rdu3.fedoraproject.org
- openqa-x86-worker01.mgmt.rdu3.fedoraproject.org
- openqa-x86-worker02.mgmt.rdu3.fedoraproject.org
- openqa-x86-worker03.mgmt.rdu3.fedoraproject.org
- openqa-x86-worker04.mgmt.rdu3.fedoraproject.org
- openqa-x86-worker05.mgmt.rdu3.fedoraproject.org
- qvmhost-x86-01.mgmt.rdu3.fedoraproject.org
- sign-vault01.mgmt.rdu3.fedoraproject.org
- sign-vault02.mgmt.rdu3.fedoraproject.org
- vmhost-x86-01.mgmt.rdu3.fedoraproject.org
- vmhost-x86-02.mgmt.rdu3.fedoraproject.org
- vmhost-x86-03.mgmt.rdu3.fedoraproject.org
- vmhost-x86-04.mgmt.rdu3.fedoraproject.org
- vmhost-x86-05.mgmt.rdu3.fedoraproject.org
- bvmhost-a64-01-stg.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-01-stg.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-02-stg.mgmt.rdu3.fedoraproject.org
- bvmhost-x86-03-stg.mgmt.rdu3.fedoraproject.org
- vmhost-x86-01-stg.mgmt.rdu3.fedoraproject.org
- vmhost-x86-02-stg.mgmt.rdu3.fedoraproject.org
- vmhost-x86-03-stg.mgmt.rdu3.fedoraproject.org
- vmhost-x86-04-stg.mgmt.rdu3.fedoraproject.org
- vmhost-x86-05-stg.mgmt.rdu3.fedoraproject.org
- worker01.mgmt.rdu3.fedoraproject.org
- worker02.mgmt.rdu3.fedoraproject.org
- worker03.mgmt.rdu3.fedoraproject.org
- worker04.mgmt.rdu3.fedoraproject.org
- worker05.mgmt.rdu3.fedoraproject.org
- worker01-stg.mgmt.rdu3.fedoraproject.org
- worker02-stg.mgmt.rdu3.fedoraproject.org
- worker03-stg.mgmt.rdu3.fedoraproject.org
#
# These are management interfaces we only want
# to test ping against. No http/https
#
iad2_management_limited:
- opengear01.mgmt.iad2.fedoraproject.org
rdu3_management_limited:
- opengear01.mgmt.rdu3.fedoraproject.org
# These hosts only respond on https, not http
rdu3_management_no_http:
- bvmhost-p10-01.mgmt.rdu3.fedoraproject.org
ipa_client_shell_groups:
- sysadmin-noc
- sysadmin-veteran

View file

@ -1,11 +0,0 @@
---
ipa_client_shell_groups:
- sysadmin-datanommer
- sysadmin-noc
- sysadmin-veteran
ipa_client_sudo_groups:
- sysadmin-datanommer
- sysadmin-noc
ipa_host_group: notifs
ipa_host_group_desc: Fedora Notifications
primary_auth_source: ipa

View file

@ -1,11 +0,0 @@
---
# Define resources for this group of hosts here.
deployment_type: prod
# For performance measurement.. for now. This can be removed whenever.
lvm_size: 65536
max_mem_size: "{{ mem_size }}"
mem_size: 24576
num_cpus: 8
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
tcp_ports: [3000, 3001, 3002, 3003, 3004, 3005]

View file

@ -1,17 +0,0 @@
---
# Define resources for this group of hosts here.
deployment_type: stg
ipa_client_shell_groups:
- fi-apprentice
- sysadmin-noc
- sysadmin-veteran
- sysadmin-web
ipa_client_sudo_groups:
- sysadmin-web
lvm_size: 20000
max_mem_size: "{{ mem_size }}"
mem_size: 16384
num_cpus: 4
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
tcp_ports: [3000, 3001, 3002, 3003, 3004]

View file

@ -1,11 +0,0 @@
---
ipa_client_shell_groups:
- sysadmin-datanommer
- sysadmin-noc
- sysadmin-veteran
ipa_client_sudo_groups:
- sysadmin-datanommer
- sysadmin-noc
- sysadmin-veteran
ipa_host_group: notifs
ipa_host_group_desc: Fedora Notifications

View file

@ -1,12 +0,0 @@
---
# Define resources for this group of hosts here.
deployment_type: prod
lvm_size: 20000
mem_size: 1024
num_cpus: 2
tcp_ports: [80]
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
wsgi_fedmsg_service: fmn
wsgi_procs: 2
wsgi_threads: 2

View file

@ -1,12 +0,0 @@
---
# Define resources for this group of hosts here.
deployment_type: stg
lvm_size: 20000
mem_size: 1024
num_cpus: 2
tcp_ports: [80]
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
wsgi_fedmsg_service: fmn
wsgi_procs: 2
wsgi_threads: 2

View file

@ -8,3 +8,5 @@ ipa_host_group_desc: OCI Registry service
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3"
primary_auth_source: ipa
tcp_ports: [5000]
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'

View file

@ -7,3 +7,5 @@ ipa_host_group: oci-registry
ipa_host_group_desc: OCI Registry service
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3"
tcp_ports: [5000]
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'

View file

@ -4,5 +4,5 @@ nagios_Check_Services:
nrpe: false
swap: false
ocp4: true
rhcos_version: 4.8.2
rhcos_version: 4.18.17
vpn: false

View file

@ -11,7 +11,6 @@ openqa_amqp_this_username: "{{ openqa_amqp_prod_username }}"
openqa_amqp_scheduler_queue: "{{ openqa_amqp_prod_username }}_scheduler"
# auth stuff
openqa_auth_method: OAuth2
openqa_oauth2_secret: "{{ openqa_prod_oidc_secret }}"
openqa_compose_arches: x86_64,aarch64

View file

@ -25,13 +25,11 @@ openqa_amqp_this_username: "{{ openqa_amqp_stg_username }}"
openqa_amqp_scheduler_queue: "{{ openqa_amqp_prod_username }}_scheduler_stg"
# auth stuff
openqa_auth_method: OAuth2
openqa_oauth2_secret: "{{ openqa_stg_oidc_secret }}"
openqa_assetsize_updates_aarch64: 50
openqa_assetsize_ppc: 300
openqa_assetsize_updates_ppc: 100
openqa_compose_arches: x86_64,aarch64,ppc64le
openqa_assetsize_ppc: 1
openqa_assetsize_updates_ppc: 1
openqa_compose_arches: x86_64,aarch64
openqa_dbname: openqa-stg
openqa_dbpassword: "{{ stg_openqa_dbpassword }}"
openqa_dbuser: openqastg
@ -47,7 +45,7 @@ openqa_resultsdb_url: https://resultsdb.stg.fedoraproject.org/api/v2.0/
openqa_resultsdb_user: "{{ stg_resultsdb_httpd_user }}"
openqa_resultsdb_password: "{{ stg_resultsdb_httpd_password }}"
openqa_secret: "{{ stg_openqa_apisecret }}"
openqa_update_arches: ['aarch64', 'x86_64', 'ppc64le']
openqa_update_arches: ['aarch64', 'x86_64']
openqa_webapi_plugins: FedoraMessaging
openqa_wikitcms_hostname: stg.fedoraproject.org
wikitcms_token: "{{ private }}/files/openidc/staging/wikitcms.json"

View file

@ -1,12 +1,14 @@
deployment_type: stg
freezes: false
gw: 10.3.174.254
gw: 10.16.174.254
ipa_client_shell_groups:
- sysadmin-qa
ipa_client_sudo_groups:
- sysadmin-qa
ipa_host_group: openqa-lab-workers
ipa_host_group_desc: OpenQA Lab worker hosts
nagios_Check_Services:
swap: false
nftables: true
openqa_env: staging
openqa_env_prefix: stg-
@ -15,7 +17,7 @@ openqa_env_prefix: stg-
# break some other plays, but we do need the env suffix for the
# fedora-messaging bits, so let's make our own
openqa_env_suffix: .stg
openqa_hostname: openqa-lab01.iad2.fedoraproject.org
openqa_hostname: openqa-lab01.rdu3.fedoraproject.org
openqa_key: "{{ stg_openqa_apikey }}"
# we are all NFS workers for now at least
openqa_nfs_worker: true
@ -27,3 +29,6 @@ openqa_workers: 4
primary_auth_source: ipa
# all worker hosts should be encrypted as of 2024-10 redeployment
openqa_nbde: true
zabbix_macros:
NET.IF.IFNAME.NOT_MATCHES: "^tap.*"
SWAP.PFREE.MIN.WARN: 0

View file

@ -17,7 +17,7 @@ deployment_type: stg
# the webui from outside the box, but we gotta set it to something
external_hostname: openqa.oneboxtest.fedoraproject.org
freezes: false
gw: 10.3.174.254
gw: 10.16.174.254
# we need this bigger on stg to handle Rawhide updates, if we enable
# Rawhide update testing in prod we can just move this to servers_common

View file

@ -73,16 +73,18 @@ openqa_amqp_resultsdb_reporter_routing_keys:
openqa_amqp_wiki_reporter_queue: "{{ openqa_amqp_this_username }}_wiki_reporter"
openqa_amqp_wiki_reporter_routing_keys: ["org.fedoraproject.{{ deployment_type }}.openqa.job.done"]
openqa_assetsize: 500
openqa_assetsize_aarch64: 350
openqa_assetsize_updates: 250
openqa_assetsize: 850
openqa_assetsize_aarch64: 1
openqa_assetsize_updates: 500
openqa_assetsize_updates_aarch64: 1
# stg and prod use the same database server
openqa_dbhost: db-openqa01.iad2.fedoraproject.org
openqa_dbhost: db-openqa01.rdu3.fedoraproject.org
openqa_email: adamwill@fedoraproject.org
openqa_fullname: Adam Williamson
openqa_hostname: localhost
openqa_nickname: adamwill
openqa_userid: http://adamwill.id.fedoraproject.org/
openqa_auth_method: OAuth2
primary_auth_source: ipa
# http and NFS
tcp_ports: [80, 2049]

View file

@ -7,6 +7,8 @@ ipa_client_sudo_groups:
- sysadmin-qa
ipa_host_group: openqa-workers
ipa_host_group_desc: OpenQA worker hosts
nagios_Check_Services:
swap: false
nftables: true
openqa_env: production
openqa_env_prefix:
@ -15,12 +17,18 @@ openqa_env_prefix:
# break some other plays, but we do need the env suffix for the
# fedora-messaging bits, so let's make our own
openqa_env_suffix:
openqa_hostname: openqa01.iad2.fedoraproject.org
openqa_hostname: openqa01.rdu3.fedoraproject.org
openqa_key: "{{ prod_openqa_apikey }}"
# we are all NFS workers for now at least
openqa_nfs_worker: true
# using u-t for prod temporarily to get QMP USB disconnect feature
# drop when https://bodhi.fedoraproject.org/updates/FEDORA-2025-8a79a3d9af is stable
openqa_repo: updates-testing
openqa_secret: "{{ prod_openqa_apisecret }}"
openqa_workers: 4
primary_auth_source: ipa
# all worker hosts should be encrypted as of 2024-10 redeployment
openqa_nbde: true
zabbix_macros:
NET.IF.IFNAME.NOT_MATCHES: "^tap.*"
SWAP.PFREE.MIN.WARN: 0

View file

@ -1 +1,7 @@
---
ipa_client_shell_groups:
- sysadmin-openshift
ipa_client_sudo_groups:
- sysadmin-openshift
ipa_host_group: os-control
ipa_host_group_desc: openshift control hosts

View file

@ -1 +1,7 @@
---
ipa_client_shell_groups:
- sysadmin-openshift
ipa_client_sudo_groups:
- sysadmin-openshift
ipa_host_group: os-control
ipa_host_group_desc: openshift control hosts

View file

@ -35,6 +35,8 @@ nft_block_rules:
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 146.174.128.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 154.222.253.0/24 counter reject'
# For the MOTD
db_backup_dir: ['/backups']
dbs_to_backup: ['pagure']
@ -49,7 +51,7 @@ ipa_client_sudo_groups:
- sysadmin-web
ipa_host_group: pagure
ipa_host_group_desc: Pagure GIT Forge
lvm_size: 750000
lvm_size: 2t
max_mem_size: 131072
mem_size: 65536
num_cpus: 48
@ -66,6 +68,10 @@ tcp_ports: [22, 25, 80, 443, 8442, 8443, 8444, 8445,
# Used for the eventsource
8088]
vpn: true
# Pagure has needs vpn for monitoring
zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_macros:
'VFS.DEV.WRITE.AWAIT.WARN': 60 # frequently saturated writes overnight
notes: |
Run the pagure instances for fedora

View file

@ -2,6 +2,9 @@
# Define resources for this group of hosts here.
# For the MOTD
env: pagure-staging
env_prefix: stg.
env_suffix: .stg
env_short: stg
freezes: false
git_basepath: /srv/git/repositories
git_daemon_user: git
@ -33,6 +36,11 @@ tcp_ports: [22, 25, 80, 443, 9418,
# Used for the eventsource server
8088]
vpn: true
# Pagure-stg has special needs for monitoring
zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_server: "{{ zabbix_hostname }}"
zabbix_auth_key: "{{ zabbix_apikey }}" # ansible-private repo
zabbix_tls_psk: "{{ zabbix_tls_prod_psk }}" # in ansible-private repo, pagure-stg is weird...
notes: |
Run the pagure instances for fedora

View file

@ -34,14 +34,17 @@ ipa_client_sudo_groups:
- sysadmin-cvs
- sysadmin-main
ipa_host_group: pkgs
lvm_size: 500000
ipa_host_group_desc: pkgs host group
lvm_size: 700000
max_mem_size: 32768
mem_size: 32768
num_cpus: 8
pagure_static_uid: 600
pagure_static_uid: 1000
primary_auth_source: ipa
sshd_keyhelper: true
tcp_ports: [80, 443]
# There vars are used to configure mod_wsgi
wsgi_procs: 10
wsgi_threads: 6
wsgi_procs: 20
wsgi_threads: 5
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'

View file

@ -41,3 +41,5 @@ tcp_ports: [80, 443, 8444, 8443, 8445]
# There vars are used to configure mod_wsgi
wsgi_procs: 4
wsgi_threads: 4
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'

View file

@ -6,22 +6,22 @@ collectd_apache: true
# For the MOTD
custom_rules: [
# Need for rsync from log01 for logs.
'-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.181.102 --dport 873 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 209.132.181.102 --dport 873 -j ACCEPT',
# allow varnish from localhost
'-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT',
# also allow varnish from internal for purge requests
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.0/24 --dport 6081 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.120 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.121 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.122 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.123 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.124 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.125 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.126 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.65 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.127 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.128 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.163.129 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.0/24 --dport 6081 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.120 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.121 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.122 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.123 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.124 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.125 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.126 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.65 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.127 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.128 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.129 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.120 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.121 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.122 -j ACCEPT',
@ -61,9 +61,33 @@ nft_block_rules:
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 152.53.36.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 66.249.69.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 159.138.218.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 188.75.180.46/32 counter reject'
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
- 'add rule ip filter INPUT ip saddr 45.78.192.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.0.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.32.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.40.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.48.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.64.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.80.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.88.0/22 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.92.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.95.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.96.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.98.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.128.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.160.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.176.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.184.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.185.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.186.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 34.159.191.146/32 counter reject'
nft_custom_rules:
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 209.132.181.102 tcp dport 873 counter accept'
# allow varnish from localhost
@ -71,18 +95,18 @@ nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.123 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.124 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.125 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.126 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.65 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.127 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.128 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.129 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
@ -106,18 +130,17 @@ ipa_host_group: proxies
ipa_host_group_desc: Proxies between internal hosts and the Internet
lvm_size: 100000
# This is used in the httpd.conf to determine the value for serverlimit and
# maxrequestworkers. On 8gb proxies, 900 seems fine. But on 4gb proxies, this
# should be lowered in the host vars for that proxy.
maxrequestworkers: 2500
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
maxrequestworkers: 3200
mem_size: 8192
nagios_Check_Services:
swap: false
num_cpus: 6
ocp_masters:
#- bootstrap.ocp.iad2.fedoraproject.org
- ocp01.ocp.iad2.fedoraproject.org
- ocp02.ocp.iad2.fedoraproject.org
- ocp03.ocp.iad2.fedoraproject.org
#- bootstrap.ocp.rdu3.fedoraproject.org
- ocp01.ocp.rdu3.fedoraproject.org
- ocp02.ocp.rdu3.fedoraproject.org
- ocp03.ocp.rdu3.fedoraproject.org
# we override this here to point to the vpn endpoints of the ocp_nodes instead of
# The real internal hostnames. This is because proxies access them via vpn.
ocp_nodes:
@ -126,7 +149,6 @@ ocp_nodes:
- worker03.vpn.fedoraproject.org
- worker04.vpn.fedoraproject.org
- worker05.vpn.fedoraproject.org
- worker06.vpn.fedoraproject.org
# On most proxies we want to use the vpn to access the rdu3 compute nodes.
# We override this for the rdu3 proxies themseleves, they go direct.
ocp_nodes_rdu3:
@ -154,11 +176,11 @@ tcp_ports: [
8443,
]
varnish_group: proxies
zabbix_templates:
- group: "proxies" # Ansible group
template: "external_hosts_http.json" # Template name in roles/zabbix/zabbix_templates/files/templatename.json
custom_template: true # Is the template official template bundled with Zabbix or one of our custom templates
hostgroup: "fedora external hosts" # Zabbix hostgroup
# Proxies are (mostly) external, use vpn for monitoring
zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_macros:
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status
'APACHE.STATUS.SCHEME': https # but https://localhost seems to work instead
notes: |
* Provides frontend (reverse) proxy for most web applications

View file

@ -4,31 +4,51 @@ collectd_apache: true
# For the MOTD
custom_rules: [
# Need for rsync from log01 for logs.
'-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
# allow varnish from localhost
'-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 127.0.0.1 --dport 6082 -j ACCEPT',
# also allow varnish from internal for purge requests
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.0/24 --dport 6081 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.3.166.123 -j ACCEPT']
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.0/24 --dport 6081 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.123 -j ACCEPT']
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
nft_custom_rules:
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# allow varnish from localhost
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.115 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.116 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.117 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.118 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.119 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.123 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.50 tcp dport 873 counter accept'
# allow varnish from localhost
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
external: true
ipa_client_shell_groups:
- fi-apprentice
@ -42,24 +62,27 @@ ipa_host_group: proxies
ipa_host_group_desc: Proxies between internal hosts and the Internet
lvm_size: 100000
# This is used in the httpd.conf to determine the value for serverlimit and
# maxrequestworkers. On 8gb proxies, 900 seems fine. But on 4gb proxies, this
# should be lowered in the host vars for that proxy.
maxrequestworkers: 900
mem_size: 8192
num_cpus: 2
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
maxrequestworkers: 3200
mem_size: 49152
num_cpus: 8
ocp_masters_stg:
# - bootstrap.ocp.stg.iad2.fedoraproject.org
- ocp01.ocp.stg.iad2.fedoraproject.org
- ocp02.ocp.stg.iad2.fedoraproject.org
- ocp03.ocp.stg.iad2.fedoraproject.org
# - bootstrap.ocp.stg.rdu3.fedoraproject.org
- ocp01.ocp.stg.rdu3.fedoraproject.org
- ocp02.ocp.stg.rdu3.fedoraproject.org
- ocp03.ocp.stg.rdu3.fedoraproject.org
ocp_nodes_stg:
- worker01.ocp.stg.iad2.fedoraproject.org
- worker02.ocp.stg.iad2.fedoraproject.org
- worker03.ocp.stg.iad2.fedoraproject.org
- worker04.ocp.stg.iad2.fedoraproject.org
- worker05.ocp.stg.iad2.fedoraproject.org
- worker01.ocp.stg.rdu3.fedoraproject.org
- worker02.ocp.stg.rdu3.fedoraproject.org
- worker03.ocp.stg.rdu3.fedoraproject.org
- worker04.ocp.stg.rdu3.fedoraproject.org
- worker05.ocp.stg.rdu3.fedoraproject.org
ocp_masters_rdu3_stg:
- bootstrap.ocp.stg.rdu3.fedoraproject.org
ocp_nodes_rdu3_stg:
- worker01.ocp.stg.rdu3.fedoraproject.org
- worker02.ocp.stg.rdu3.fedoraproject.org
- worker03.ocp.stg.rdu3.fedoraproject.org
tcp_ports: [
# For apache, generally.
80, 443,
@ -75,7 +98,9 @@ tcp_ports: [
8443,
]
varnish_group: proxies
zabbix_templates: "{{ [] }}" # For the moment we have no proxies external to IAD2, if this changes, put in the changes in the production group.
zabbix_macros:
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status
'APACHE.STATUS.SCHEME': https # but https://localhost seems to work instead
notes: |
* Provides frontend (reverse) proxy for most web applications

View file

@ -1,17 +1,24 @@
---
custom_rules: [
# Neeed for rsync from log01 for logs.
'-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
# Inter-node traffic
'-A INPUT -p tcp -m tcp -s 10.3.163.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.163.80 --dport 25672 -j ACCEPT']
'-A INPUT -p tcp -m tcp -s 10.16.163.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.80 --dport 25672 -j ACCEPT',
# Same but in RDU3
'-A INPUT -p tcp -m tcp -s 10.16.163.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.80 --dport 25672 -j ACCEPT',
]
nft_custom_rules:
# Neeed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Inter-node traffic
- 'add rule ip filter INPUT ip saddr 10.3.163.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.163.80 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
# In RDU3
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
ipa_host_group: rabbitmq
ipa_host_group_desc: RabbitMQ service
ipa_shell_groups:
@ -36,3 +43,11 @@ zabbix_templates:
template: "RabbitMQ node by Zabbix agent" # Template name in roles/zabbix/zabbix_templates/files/templatename.json
custom_template: false # Is the template official template bundled with Zabbix or one of our custom templates
hostgroup: "fedora rabbitmq" # Zabbix hostgroup
## CentOS monitoring
# Zabbix server instance
centos_zabbix_server: mon.centos.org
# Name of the RabbitMQ host in Zabbix
centos_zabbix_host: rabbitmq.fedora
centos_zabbix_queues:
- centos-stream-robosignatory

View file

@ -1,26 +1,30 @@
---
custom_rules: [
# Neeed for rsync from log01 for logs.
'-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
# Inter-node traffic
'-A INPUT -p tcp -m tcp -s 10.3.166.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.166.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.3.166.80 --dport 25672 -j ACCEPT']
'-A INPUT -p tcp -m tcp -s 10.16.166.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.166.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.166.80 --dport 25672 -j ACCEPT',
# Same but in RDU3
'-A INPUT -p tcp -m tcp -s 10.16.166.78 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.166.79 --dport 25672 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.166.80 --dport 25672 -j ACCEPT',
]
nft_custom_rules:
# Neeed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Inter-node traffic
- 'add rule ip filter INPUT ip saddr 10.3.166.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.3.166.80 tcp dport 25672 counter accept'
datacenter: iad2
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
# In RDU3
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
ipa_host_group: rabbitmq
ipa_host_group_desc: RabbitMQ service
ipa_shell_groups:
- sysadmin-messaging
ipa_client_sudo_groups:
- sysadmin-messaging
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL8-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-8-iad2
# Define resources for this group of hosts here.
lvm_size: 20000
mem_size: 8192

Some files were not shown because too many files have changed in this diff Show more