forked from infra/ansible
Compare commits
272 commits
7749af7760
...
ebaf8210f3
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ebaf8210f3 |
||
|
3457eea89b |
|||
|
728b6c57a3 |
|||
|
d98ce9b9f8 |
|||
|
ea82ea2c9a |
|||
| 3731a63a13 | |||
|
|
3fdaf170d5 | ||
|
|
e11b39314d | ||
|
|
4a6fc0fdf5 | ||
|
|
5c6868260b | ||
|
|
40b3225890 | ||
| a9adce6136 | |||
| a0156fc54d | |||
| ce1edea8ee | |||
|
|
259ec5b2e8 | ||
|
|
c8a55f0113 | ||
| c6f7e6e601 | |||
| d830f9ae6e | |||
| 615af75669 | |||
| 8bbcceafdd | |||
| 71aec6a544 | |||
| 0248c0d535 | |||
| 06c765b10d | |||
| 1be1c69f0f | |||
| 141940d1ad | |||
| 63315f4602 | |||
| 9a5bca7aad | |||
| 6a767b3706 | |||
| 9d572f1839 | |||
|
|
177bb00442 | ||
|
|
a1c7d0828a | ||
|
e73d603bd2 |
|||
|
f3a05e1b72 |
|||
|
f29d91d7af |
|||
|
641887c8cf |
|||
|
de6e36a4e5 |
|||
|
e104755e4e |
|||
|
9e3cd9d4ff |
|||
|
|
e537215abc | ||
|
44951845e4 |
|||
|
69612dffe5 |
|||
|
e3d9be210e |
|||
|
bc2f608f4c |
|||
|
c0d5169f58 |
|||
|
|
d77168ff0c | ||
|
|
2e2abbedac | ||
| 993e600700 | |||
| b8773db5ba | |||
| 7b4f3b4182 | |||
| c796a888d2 | |||
| eb0de86f9a | |||
| 26402546de | |||
| bbf9258578 | |||
| 50559f83d7 | |||
|
0baaabd735 |
|||
|
2b6ddca8f4 |
|||
|
1ffd0cd8a5 |
|||
|
068605d67d |
|||
| f2c2aa037b | |||
|
814582dc4d |
|||
| 70cfd1412e | |||
| ccb89c99a4 | |||
| 7268404db7 | |||
| 7e226ba150 | |||
| f8fbb98eda | |||
| 3ac21c8018 | |||
| 31c695a70f | |||
| 03dec33fd8 | |||
|
1680d35e63 |
|||
|
0d3e126317 |
|||
|
6ed762bb29 |
|||
|
8d40668907 |
|||
|
7e5a64efdc |
|||
|
6cfda2b8f5 |
|||
| 137626c637 | |||
| f68ab813be | |||
| 90cc0bee98 | |||
| 749c16501f | |||
| f4ca07caf7 | |||
|
004fb438fe |
|||
|
2e63ef6b72 |
|||
| 7ed0a93f2a | |||
| 40fe2bfc69 | |||
| 7b21d2756f | |||
| 885651a7a7 | |||
| c46879dc54 | |||
| b5eddd80ea | |||
| 481443b92f | |||
|
16642a1d02 |
|||
|
05eb12595e |
|||
| 4140b2cdfd | |||
| f05fbe3876 | |||
| d60806aca0 | |||
| 98c6cae22b | |||
| 0595b45e39 | |||
| 5887d43751 | |||
|
4908f3bea7 |
|||
|
8cd135b4bd |
|||
|
fad66f712e |
|||
|
26b81b373d |
|||
|
331eae63d7 |
|||
|
5d331ca6e3 |
|||
|
1c6dded5bb |
|||
| f2759cb8b2 | |||
| 2d24211424 | |||
| 4262b3610f | |||
| 1963b068d3 | |||
| 60e48fd441 | |||
| 5e7b40087d | |||
| a5eb828847 | |||
| cf52816027 | |||
| 9ffb23bb35 | |||
| 44bc3548f0 | |||
| 688720342e | |||
| 13c1dd27d9 | |||
| 8f12b3c681 | |||
|
|
c33602daf4 | ||
| 0ea1c9f292 | |||
| 8fbab7e5b3 | |||
| 6e0f4fe7b0 | |||
|
0723ffa45d |
|||
| 9faab10da6 | |||
| b0f0cbde39 | |||
| ee21c8afc6 | |||
| 2df5c98d16 | |||
| 944efaf34f | |||
| a5d7291edc | |||
| 0ae3392198 | |||
| d4c013129a | |||
| 1aac9b0c7b | |||
| 917e6f4f5c | |||
|
4cf99e088a |
|||
| 4e24b694b4 | |||
| 51081991be | |||
| 442852923d | |||
| af80a6a3a0 | |||
|
73dc88c487 |
|||
| 6ccaaca78d | |||
| 7688d6da70 | |||
| 623214b0c9 | |||
| 1bde47906f | |||
| 68315a2324 | |||
| 977a470510 | |||
|
4998b94fce |
|||
|
4be7c97ff1 |
|||
|
d47a991333 |
|||
| 6bdcf23ac7 | |||
| 4d2aa5527b | |||
| 8b477bcc0a | |||
| cf60e5fab5 | |||
| 0d8779bc60 | |||
| c14a9c63af | |||
| a38aeeab1b | |||
| ce30489068 | |||
| acc8549a10 | |||
| f838451f81 | |||
|
ebb316eedd |
|||
| 6f91abc606 | |||
| dd2e76880a | |||
| 4480adb270 | |||
| 6533d2ae71 | |||
| 8e461e50f5 | |||
| bb9984ec61 | |||
| 0986ae491b | |||
| eb0e697fab | |||
| 550aad5c29 | |||
| c7349dadea | |||
| 8c54ea4bad | |||
| 8f3def5c91 | |||
| c55e6f0893 | |||
| 22f47d356a | |||
| db4f19c2ad | |||
|
05b94d7029 |
|||
|
55a7c1c9f9 |
|||
|
dfa0766cff |
|||
|
665456d9d9 |
|||
|
83c42baccb |
|||
| 04e230408e | |||
| 4a68303c36 | |||
| 7923f145d9 | |||
| d6d3a4db54 | |||
| b641125564 | |||
| 76e322e65a | |||
| 0df0dc0ec9 | |||
| 274e23e336 | |||
| 645cfe0482 | |||
| d59d39d281 | |||
|
|
28c056c4f7 | ||
|
|
6ef4d3c158 | ||
|
7ce80fab53 |
|||
|
a0b48d31b8 |
|||
|
269c4fd64d |
|||
|
7dad780f04 |
|||
|
299e2e4005 |
|||
|
035be95c3f |
|||
|
850e51c1db |
|||
|
769ffc446f |
|||
|
eef6c7bc89 |
|||
|
d1595d1420 |
|||
|
c3b29e947c |
|||
|
c098712064 |
|||
|
0b9ff51e27 |
|||
|
9806794f83 |
|||
|
418cca4d57 |
|||
| 06d732888f | |||
| 1371eae7b6 | |||
| c844df0cfb | |||
| d02937cc70 | |||
|
d99f6f030e |
|||
|
2002267fcb |
|||
| d9aef74a12 | |||
| fc3816c7fe | |||
| 22005ff136 | |||
| 9c2eeb276d | |||
|
c6704f92dc |
|||
| 6b9752397d | |||
| 6812986bef | |||
| ec82c78f22 | |||
| 8c28aba425 | |||
| ce9d8b3899 | |||
| 4517eb2ed5 | |||
| 06fc965500 | |||
| a58b8699ea | |||
| 5278566736 | |||
| 2dc6e6ec68 | |||
| 72f01c98a7 | |||
| ec0c9ed220 | |||
| ef1592400d | |||
| 511f16d9d6 | |||
| 8ede1564c8 | |||
| ac4774b57e | |||
| 20428c57ee | |||
|
5d88d1abb3 |
|||
|
c8abf8630e |
|||
|
51e4282ff7 |
|||
| 1d53d6dd5a | |||
| 9af0fa359e | |||
| b173990a47 | |||
| 565a59722b | |||
| 10ad96ad9d | |||
|
e6491b5cba |
|||
|
e4321ec9c3 |
|||
| 09af2093f5 | |||
| 5b3385240a | |||
| 587aa356d0 | |||
| cc862368dd | |||
| 27e3392a20 | |||
| 85f227197c | |||
| 3d39e9ed5a | |||
| 621d586acc | |||
| ba172de77e | |||
| 49bec86025 | |||
| 0d4d72dadf | |||
|
15a6768ad7 |
|||
|
72baeea321 |
|||
| 0506d3a645 | |||
|
|
66580813a6 | ||
| 54db5a3f4a | |||
| 40060e7e88 | |||
| b0f1e9a91d | |||
| 1bdd2c4529 | |||
| a00af9f5cd | |||
| cc8e259360 | |||
| d0a17fb7cf | |||
| 81e1871023 | |||
| e3e74bc722 | |||
| e86df4d91b | |||
|
|
ea2f954a44 | ||
|
|
ab631bed2e | ||
|
|
3821ea36b5 | ||
|
|
ba4470365e | ||
|
|
ae9230c37f |
400 changed files with 6310 additions and 2991 deletions
|
|
@ -11,5 +11,7 @@ jobs:
|
|||
uses: quality/workflows/.forgejo/workflows/ai-review.yml@main
|
||||
with:
|
||||
pr: ${{ forgejo.event.pull_request.number }}
|
||||
config: |
|
||||
include_mr_summary: false
|
||||
secrets:
|
||||
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
|
||||
|
|
|
|||
|
|
@ -54,6 +54,11 @@ jobs:
|
|||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Create symlink to overcome absolute paths
|
||||
run: |
|
||||
mkdir -p /srv/web/infra/
|
||||
ln -s /workspace/infra/ansible /srv/web/infra/ansible
|
||||
|
||||
- name: Get changed files
|
||||
id: changed-files
|
||||
uses: https://code.forgejo.org/tj-actions/changed-files@v47
|
||||
|
|
|
|||
|
|
@ -1,9 +1,10 @@
|
|||
[epel]
|
||||
name=Extras Packages for Enterprise Linux $releasever - $basearch
|
||||
# This is a bit too magic, esp. as we are using the infra. repo. and explicitly
|
||||
# point to a 10.x variant ... might as well do the same here.
|
||||
# We aren't using mirrormanager here, but pointing direct to our repos
|
||||
# So, we want to just point to '10' here and depend on the link that exists
|
||||
# to point us to the newest minor release.
|
||||
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
|
||||
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10.1/Everything/$basearch/
|
||||
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10/Everything/$basearch/
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
|
||||
|
|
@ -11,7 +12,7 @@ gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
|
|||
[epel-testing]
|
||||
name=Extras Packages for Enterprise Linux $releasever - $basearch
|
||||
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/$releasever${releasever_minor:+z}/Everything/$basearch/
|
||||
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10.1/Everything/$basearch/
|
||||
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10/Everything/$basearch/
|
||||
enabled=0
|
||||
gpgcheck=1
|
||||
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
|
||||
|
|
|
|||
|
|
@ -12,24 +12,25 @@ gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg
|
|||
enabled=1
|
||||
gpgcheck=1
|
||||
|
||||
# NOTE: When you change the 10.x here also change it in the epel10.repo file.
|
||||
# These are not using mirrormanager, so point to '10' which will use the link
|
||||
# to the latest minor release.
|
||||
[rhel10-BaseOS]
|
||||
name = rhel10 BaseOS $basearch
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/baseos
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/baseos
|
||||
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
|
||||
[rhel10-AppStream]
|
||||
name = rhel10 AppStream $basearch
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/appstream
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/appstream
|
||||
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
|
||||
[rhel10-CRB]
|
||||
name = rhel10 CodeReadyBuilder $basearch
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/crb
|
||||
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/crb
|
||||
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
|
|
|
|||
|
|
@ -90,13 +90,13 @@ RewriteRule ^/gfs2-utils/report https://pagure.io/gfs2-utils/issues [R=301]
|
|||
RewriteRule ^/gfs2-utils/ticket/(.*) https://pagure.io/gfs2-utils/issue/$1 [R=301]
|
||||
RewriteRule ^/gfs2-utils https://pagure.io/gfs2-utils [R=301]
|
||||
|
||||
RewriteRule ^/elections/report https://pagure.io/elections/issues [R=301]
|
||||
RewriteRule ^/elections/ticket/(.*) https://pagure.io/elections/issue/$1 [R=301]
|
||||
RewriteRule ^/elections https://pagure.io/elections [R=301]
|
||||
RewriteRule ^/elections/report https://forge.fedoraproject.org/apps/elections/issues [R=301]
|
||||
RewriteRule ^/elections/ticket/(.*) https://forge.fedoraproject.org/apps/elections/issues/$1 [R=301]
|
||||
RewriteRule ^/elections https://forge.fedoraproject.org/apps/elections [R=301]
|
||||
|
||||
RewriteRule ^/fedocal/report https://pagure.io/fedocal/issues [R=301]
|
||||
RewriteRule ^/fedocal/ticket/(.*) https://pagure.io/fedocal/issue/$1 [R=301]
|
||||
RewriteRule ^/fedocal https://pagure.io/fedocal [R=301]
|
||||
RewriteRule ^/fedocal/report https://forge.fedoraproject.org/apps/fedocal/issues [R=301]
|
||||
RewriteRule ^/fedocal/ticket/(.*) https://forge.fedoraproject.org/apps/fedocal/issue/$1 [R=301]
|
||||
RewriteRule ^/fedocal https://forge.fedoraproject.org/apps/fedocal [R=301]
|
||||
|
||||
RewriteRule ^/FedoraReview/report https://pagure.io/FedoraReview/issues [R=301]
|
||||
RewriteRule ^/FedoraReview/ticket/(.*) https://pagure.io/FedoraReview/issue/$1 [R=301]
|
||||
|
|
|
|||
|
|
@ -80,13 +80,13 @@
|
|||
action: service name=network state=restarted
|
||||
|
||||
- name: Rebuild postfix transport
|
||||
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/transport
|
||||
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/transport
|
||||
|
||||
- name: Rebuild postfix bysender
|
||||
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/bysender
|
||||
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/bysender
|
||||
|
||||
- name: Rebuild postfix tls_policy
|
||||
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/tls_policy
|
||||
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/tls_policy
|
||||
|
||||
- name: Restart postfix
|
||||
service: name=postfix state=restarted
|
||||
|
|
|
|||
|
|
@ -297,6 +297,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
|
|||
buildhw-x86-10.rdu3.fedoraproject.org
|
||||
buildhw-x86-12.rdu3.fedoraproject.org
|
||||
buildhw-x86-13.rdu3.fedoraproject.org
|
||||
buildhw-x86-14.rdu3.fedoraproject.org
|
||||
|
||||
[buildhw_stg]
|
||||
buildhw-p10-01.stg.rdu3.fedoraproject.org
|
||||
|
|
@ -323,6 +324,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
|
|||
buildhw-x86-10.rdu3.fedoraproject.org
|
||||
buildhw-x86-12.rdu3.fedoraproject.org
|
||||
buildhw-x86-13.rdu3.fedoraproject.org
|
||||
buildhw-x86-14.rdu3.fedoraproject.org
|
||||
|
||||
[buildhw_stg_rdu3]
|
||||
buildhw-p10-01.stg.rdu3.fedoraproject.org
|
||||
|
|
@ -399,10 +401,9 @@ buildvm-ppc64le-30.rdu3.fedoraproject.org
|
|||
buildvm-ppc64le-31.rdu3.fedoraproject.org
|
||||
buildvm-ppc64le-32.rdu3.fedoraproject.org
|
||||
|
||||
[bkernel]
|
||||
buildhw-x86-01.rdu3.fedoraproject.org
|
||||
|
||||
[secureboot]
|
||||
buildhw-x86-01.rdu3.fedoraproject.org
|
||||
buildhw-a64-01.rdu3.fedoraproject.org
|
||||
buildhw-x86-02.rdu3.fedoraproject.org
|
||||
buildhw-a64-02.rdu3.fedoraproject.org
|
||||
|
||||
|
|
@ -465,7 +466,7 @@ buildvm
|
|||
buildvm_aarch64
|
||||
buildvm_ppc64le
|
||||
buildvm_s390x
|
||||
bkernel
|
||||
secureboot
|
||||
|
||||
[builders_stg:children]
|
||||
buildhw_ppc64le_stg
|
||||
|
|
|
|||
|
|
@ -46,6 +46,7 @@ aarch64-test02.fedorainfracloud.org
|
|||
# This is not in aws, but here is good enough for now
|
||||
ppc64le-test.fedorainfracloud.org
|
||||
ppc64le-test02.fedorainfracloud.org
|
||||
s390x-test01.fedorainfracloud.org
|
||||
logdetective01.fedorainfracloud.org
|
||||
logdetective02.fedorainfracloud.org
|
||||
|
||||
|
|
|
|||
|
|
@ -44,38 +44,12 @@ communishift_projects:
|
|||
communishift-admins:
|
||||
name: communishift-admins
|
||||
do_not_delete: true # Marked do not delete 2024-11-25 - dkirwan
|
||||
communishift-avant:
|
||||
name: communishift-avant
|
||||
cpu_limits: 2
|
||||
cpu_requests: 2
|
||||
memory_limits: 3Gi
|
||||
memory_requests: 1.5Gi
|
||||
pods: 6
|
||||
storage_requests: 10Gi
|
||||
communishift-commops-analytics:
|
||||
name: communishift-commops-analytics
|
||||
communishift-commops-datanom:
|
||||
name: communishift-commops-datanom
|
||||
communishift-discoursepolls:
|
||||
name: communishift-discoursepolls
|
||||
communishift-eventbot:
|
||||
name: communishift-eventbot
|
||||
communishift-fedora-coreos-ai-helpers:
|
||||
name: communishift-fedora-coreos-ai-helpers
|
||||
do_not_delete: true # Marked do not delete 2025-12-18 - dkirwan infra 12996
|
||||
communishift-fedora-review-service:
|
||||
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
|
||||
name: communishift-fedora-review-service
|
||||
communishift-forgejo:
|
||||
name: communishift-forgejo
|
||||
communishift-fossology:
|
||||
name: communishift-fossology
|
||||
communishift-gitlabce:
|
||||
name: communishift-gitlabce
|
||||
communishift-jitsi:
|
||||
name: communishift-jitsi
|
||||
communishift-lightspeed-build:
|
||||
name: communishift-lightspeed-build
|
||||
communishift-log-detective:
|
||||
name: communishift-log-detective
|
||||
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
|
||||
|
|
@ -83,31 +57,23 @@ communishift_projects:
|
|||
memory_requests: 4Gi
|
||||
storage_requests: 10Gi
|
||||
pods: 6
|
||||
communishift-mattdm:
|
||||
name: communishift-mattdm
|
||||
communishift-metrics:
|
||||
name: communishift-metrics
|
||||
communishift-ocm:
|
||||
name: communishift-ocm
|
||||
communishift-openscanhub:
|
||||
name: communishift-openscanhub
|
||||
cpu_limits: 2
|
||||
cpu_requests: 2
|
||||
memory_limits: 4Gi
|
||||
memory_requests: 2Gi
|
||||
pods: 16
|
||||
communishift-planet:
|
||||
name: communishift-planet
|
||||
communishift-standupbot:
|
||||
name: communishift-standupbot
|
||||
do_not_delete: true # Marked do not delete 2026-05-01 - dkirwan
|
||||
communishift-weekly-bootc:
|
||||
do_not_delete: true # Marked do not delete 2024-11-26. Needed until end of bootc initative. - dkirwan
|
||||
name: communishift-weekly-bootc
|
||||
communishift-release-schedule-planner:
|
||||
name: communishift-release-schedule-planner
|
||||
communishift-draft-share:
|
||||
name: communishift-draft-share
|
||||
communishift-happinesspackets:
|
||||
name: communishift-happinesspackets
|
||||
communishift-coreos-agent:
|
||||
name: communishift-coreos-agent
|
||||
communishift-rag-magazine-guidelines:
|
||||
name: communishift-rag-magazine-guidelines
|
||||
storage_requests: 15Gi
|
||||
communishift-public-inbox-poc:
|
||||
name: communishift-public-inbox-poc
|
||||
# true or false if we are or are not a copr build virthost.
|
||||
# Default to false
|
||||
copr_build_virthost: false
|
||||
|
|
@ -188,6 +154,12 @@ nftables: True
|
|||
nft_custom6_rules: []
|
||||
nft_custom_rules: []
|
||||
nft_nat_rules: []
|
||||
# Table names for nft
|
||||
# Note that the ip/ip6 prefix here means we only look at IPv4/IPv6 packets.
|
||||
nft_table_filter: "ip cle_infra_filter"
|
||||
nft_table_nat: "ip cle_infra_nat"
|
||||
nft_table_raw: "ip cle_infra_raw"
|
||||
nft_table6_filter: "ip6 cle_infra_filter"
|
||||
# usually we do not want to enable nested virt, only on some virthosts
|
||||
nested: false
|
||||
network_allow_restart: yes
|
||||
|
|
|
|||
|
|
@ -10,7 +10,7 @@ ansible_ifcfg_allowlist:
|
|||
# Make connections from signing bridges stateless, they break sigul connections
|
||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
|
||||
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
host_group: autosign
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-releng
|
||||
|
|
|
|||
|
|
@ -2,5 +2,5 @@
|
|||
# Make connections from signing bridges stateless, they break sigul connections
|
||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
|
||||
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
host_group: autosign
|
||||
|
|
|
|||
|
|
@ -8,8 +8,8 @@
|
|||
#
|
||||
custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT']
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
|
||||
- 'add rule ip filter INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
|
||||
#
|
||||
# This host is externally reachable
|
||||
#
|
||||
|
|
|
|||
|
|
@ -19,8 +19,8 @@ batcave_ipa_client_shell_groups: []
|
|||
#
|
||||
custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT']
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
|
||||
- 'add rule ip filter INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
|
||||
ipa_client_shell_groups: "{{ (bastion_ipa_client_shell_groups + batcave_ipa_client_shell_groups) | sort | unique }}"
|
||||
#
|
||||
# allow a bunch of sysadmin groups here so they can access internal stuff
|
||||
|
|
|
|||
|
|
@ -4,8 +4,8 @@ ansible_base: /srv/web/infra
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
#
|
||||
# This host is externally reachable
|
||||
#
|
||||
|
|
|
|||
|
|
@ -7,7 +7,7 @@ bodhi_message_routing_keys:
|
|||
# Make connections from signing bridges stateless, they break sigul connections
|
||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
|
||||
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.5.125.71 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.5.125.71 tcp sport 44334 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.5.125.71 tcp sport 44334 counter accept']
|
||||
host_group: bodhi2
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-bodhi
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ bodhi_message_routing_keys:
|
|||
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
|
||||
# this is sign-bridge01.rdu3 ip 10.16.169.120
|
||||
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
|
||||
host_group: bodhi2
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-bodhi
|
||||
|
|
|
|||
|
|
@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
|
|||
# Groups and individual hosts should ovveride them with specific info.
|
||||
|
||||
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/ppc64le/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/44/Server/ppc64le/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 150000
|
||||
main_bridge: br0
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
|
|||
koji_instance: "primary"
|
||||
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
|
||||
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/s390x/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/44/Server/s390x/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora-s390x
|
||||
virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}"
|
||||
lvm_size: 100000
|
||||
|
|
|
|||
|
|
@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
|
|||
# Groups and individual hosts should ovveride them with specific info.
|
||||
|
||||
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 150000
|
||||
max_mem_size: "{{ mem_size }}"
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
lvm_size: 20000
|
||||
mem_size: 2048
|
||||
num_cpus: 2
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
lvm_size: 20000
|
||||
mem_size: 2048
|
||||
num_cpus: 2
|
||||
|
|
|
|||
|
|
@ -19,12 +19,12 @@ backend_base_url: "https://download.copr.fedorainfracloud.org"
|
|||
builders:
|
||||
# max|spawn_concurrently|prealloc
|
||||
aws:
|
||||
aarch64: [8, 2, 1]
|
||||
x86_64: [50, 10, 20]
|
||||
aarch64: [50, 10, 1]
|
||||
x86_64: [50, 10, 1]
|
||||
# put here the number -1 of the actuall reserved instances
|
||||
aws_reserved:
|
||||
aarch64: [50, 20, 33]
|
||||
x86_64: [70, 20, 52]
|
||||
aarch64: [55, 20, 55]
|
||||
x86_64: [70, 20, 70]
|
||||
aws_reserved_powerful:
|
||||
x86_64: [2, 2, 2]
|
||||
aws_powerful:
|
||||
|
|
|
|||
|
|
@ -53,6 +53,9 @@ copr_backend_data_2_raid1_volumes:
|
|||
- nvme-Amazon_Elastic_Block_Store_vol0f226a7163d28d8fd-part1
|
||||
- nvme-Amazon_Elastic_Block_Store_vol07293869d85a750b8-part1
|
||||
|
||||
rpmeta_enabled: true
|
||||
rpmeta_hostname: rpmeta.fedoraproject.org
|
||||
|
||||
notes: |
|
||||
Provide the backend for copr (3rd party packages)
|
||||
* Backend: Management of copr cloud infrastructure (OpenStack).
|
||||
|
|
|
|||
|
|
@ -49,6 +49,9 @@ copr_backend_data_2_raid1_volumes:
|
|||
- nvme-Amazon_Elastic_Block_Store_vol0ce8220e998e2e32a-part1
|
||||
- nvme-Amazon_Elastic_Block_Store_vol0038e042c49987b82-part1
|
||||
|
||||
rpmeta_enabled: true
|
||||
rpmeta_hostname: rpmeta.stg.fedoraproject.org
|
||||
|
||||
notes: |
|
||||
Provide the testing environment of copr's backend
|
||||
This host is the testing environment for the cloud infrastructure of copr's backend
|
||||
|
|
|
|||
|
|
@ -47,13 +47,13 @@ nbde_client_bindings:
|
|||
libvirt_host: "{{ inventory_hostname }}"
|
||||
|
||||
nft_custom_rules:
|
||||
- add rule ip filter INPUT iifname virbr0 udp dport bootps accept
|
||||
- add rule ip filter INPUT iifname virbr0 udp dport 53 accept
|
||||
- add rule ip filter INPUT iifname virbr0 tcp dport ssh accept
|
||||
- add rule ip filter FORWARD iifname "virbr0" oif != "virbr0" counter accept
|
||||
- add rule ip filter FORWARD iifname "virbr0" ct state new counter accept
|
||||
- add rule ip filter FORWARD ct state established,related counter accept
|
||||
- add rule ip filter FORWARD ip protocol icmp counter accept
|
||||
- add rule {{nft_table_filter}} INPUT iifname virbr0 udp dport bootps accept
|
||||
- add rule {{nft_table_filter}} INPUT iifname virbr0 udp dport 53 accept
|
||||
- add rule {{nft_table_filter}} INPUT iifname virbr0 tcp dport ssh accept
|
||||
- add rule {{nft_table_filter}} FORWARD iifname "virbr0" oif != "virbr0" counter accept
|
||||
- add rule {{nft_table_filter}} FORWARD iifname "virbr0" ct state new counter accept
|
||||
- add rule {{nft_table_filter}} FORWARD ct state established,related counter accept
|
||||
- add rule {{nft_table_filter}} FORWARD ip protocol icmp counter accept
|
||||
|
||||
zabbix_macros:
|
||||
CPU.UTIL.CRIT: 100
|
||||
|
|
|
|||
|
|
@ -9,10 +9,10 @@ custom_rules:
|
|||
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 80 -j ACCEPT'
|
||||
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 5167 -j ACCEPT'
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 80 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 5167 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 80 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 5167 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 52.44.175.77 tcp dport 80 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 52.44.175.77 tcp dport 5167 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.105 tcp dport 80 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.105 tcp dport 5167 counter accept'
|
||||
freezes: false
|
||||
tcp_ports: [22,
|
||||
# node_exporter/prometheus
|
||||
|
|
|
|||
|
|
@ -9,10 +9,10 @@ custom_rules:
|
|||
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 80 -j ACCEPT'
|
||||
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 5167 -j ACCEPT'
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 80 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 5167 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 80 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 5167 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.11 tcp dport 80 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.11 tcp dport 5167 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 18.208.10.131 tcp dport 80 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 18.208.10.131 tcp dport 5167 counter accept'
|
||||
freezes: false
|
||||
tcp_ports: [22,
|
||||
# node_exporter/prometheus
|
||||
|
|
|
|||
|
|
@ -115,7 +115,7 @@ ipa_host_group_desc: Download servers
|
|||
nagios_Check_Services:
|
||||
swap: false
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 212.143.41.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 212.143.41.0/24 counter reject'
|
||||
primary_auth_source: ipa
|
||||
zabbix_macros:
|
||||
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
---
|
||||
# Define resources for this group of hosts here.
|
||||
custom_rules: ['-A INPUT -p udp -m udp -s 10.16.0.0/16 --dport 53 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.0.0/16 udp dport 53 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.0.0/16 udp dport 53 counter accept']
|
||||
host_backup_targets: ['/var/lib/ipa/backup', '/var/log/dirsrv/slapd-FEDORAPROJECT-ORG']
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-accounts
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_host_group: ipatuura
|
||||
ipa_host_group_desc: IPA-tuura SCIM application
|
||||
ipa_client_shell_groups:
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_host_group: ipsilon
|
||||
ipa_host_group_desc: Ipsilon SSO application
|
||||
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_host_group: ipsilon
|
||||
ipa_host_group_desc: Ipsilon SSO application
|
||||
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_host_group: ipsilon
|
||||
ipa_host_group_desc: Ipsilon SSO application
|
||||
ipa_client_shell_groups:
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@
|
|||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_host_group: ipsilon
|
||||
ipa_host_group_desc: Ipsilon SSO application
|
||||
ipa_client_shell_groups:
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
---
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.122.0/24 --dport 2049 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 192.168.122.0/24 tcp dport 2049 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 192.168.122.0/24 tcp dport 2049 counter accept']
|
||||
freezes: false
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-kernel
|
||||
|
|
|
|||
|
|
@ -5,8 +5,8 @@ custom_rules: [
|
|||
'-A INPUT -d 224.0.0.0/8 -j ACCEPT', '-A INPUT -p vrrp -j ACCEPT']
|
||||
# Needed for keepalived
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip daddr 224.0.0.0/8 counter accept'
|
||||
- 'add rule ip filter INPUT ip protocol vrrp counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip daddr 224.0.0.0/8 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip protocol vrrp counter accept'
|
||||
docker_registry: "candidate-registry.fedoraproject.org"
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-releng
|
||||
|
|
|
|||
|
|
@ -6,8 +6,8 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
# Need for rsync from log01 for logs.
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
ipa_client_shell_groups:
|
||||
- sysadmin-noc
|
||||
- sysadmin-releng
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ ipa_client_sudo_groups:
|
|||
- sysadmin-web
|
||||
ipa_host_group: memcached
|
||||
ipa_host_group_desc: Distributed Memory Caching service
|
||||
lvm_size: 20000
|
||||
lvm_size: 25000
|
||||
mem_size: 8192
|
||||
num_cpus: 2
|
||||
primary_auth_source: ipa
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ ipa_client_sudo_groups:
|
|||
- sysadmin-web
|
||||
ipa_host_group: memcached
|
||||
ipa_host_group_desc: Distributed Memory Caching service
|
||||
lvm_size: 20000
|
||||
lvm_size: 25000
|
||||
mem_size: 4096
|
||||
num_cpus: 1
|
||||
# for systems that do not match the above - specify the same parameter in
|
||||
|
|
|
|||
|
|
@ -2,9 +2,9 @@
|
|||
# uses interface definition from host vars
|
||||
custom_rules: ['-A FORWARD -i br0 -j ACCEPT', '-A FORWARD -m state -i {{ openqa_tap_iface }} -o br0 --state RELATED,ESTABLISHED -j ACCEPT', '-A INPUT -i br0 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter FORWARD iifname "br0" counter accept'
|
||||
- 'add rule ip filter FORWARD iifname "{{ openqa_tap_iface }}" oifname "br0" ct state related,established counter accept'
|
||||
- 'add rule ip filter INPUT iifname "br0" counter accept'
|
||||
- 'add rule {{nft_table_filter}} FORWARD iifname "br0" counter accept'
|
||||
- 'add rule {{nft_table_filter}} FORWARD iifname "{{ openqa_tap_iface }}" oifname "br0" ct state related,established counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT iifname "br0" counter accept'
|
||||
# for iptables rules...maybe other stuff in future? both staging
|
||||
# and prod workers are in this group
|
||||
host_group: openqa-tap-workers
|
||||
|
|
|
|||
|
|
@ -6,10 +6,10 @@ custom_rules: [
|
|||
'-A INPUT -p tcp --dport 22623 --src 38.145.48.0/27 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
# Needed for keepalived
|
||||
- 'add rule ip filter INPUT ip daddr 224.0.0.0/8 counter accept'
|
||||
- 'add rule ip filter INPUT ip protocol vrrp counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip daddr 224.0.0.0/8 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip protocol vrrp counter accept'
|
||||
# machinectl api
|
||||
- 'add rule ip filter INPUT ip saddr 38.145.48.0/27 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 38.145.48.0/27 tcp dport 22623 counter accept'
|
||||
datacenter: cloud
|
||||
host_group: cloud
|
||||
lvm_size: 20000
|
||||
|
|
|
|||
|
|
@ -8,35 +8,35 @@ custom_rules: [
|
|||
'-A INPUT -s 47.76.99.127/32 -j REJECT'
|
||||
]
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 81.69.171.38 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 175.24.248.206 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.76.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.80.0.0/13 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.74.0.0/15 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 66.249.64.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.0.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.224.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.41.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.163.8.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.156.0.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.133.32.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.128.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.37.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.153.192.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.32.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.156.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.163.0.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 14.153.15.174 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.246.0.0/16 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.236.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 146.174.128.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 154.222.253.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 81.69.171.38 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 175.24.248.206 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.76.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.80.0.0/13 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.74.0.0/15 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.64.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.0.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.224.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.41.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.8.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.0.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.133.32.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.128.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.37.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.153.192.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.32.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.0.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 14.153.15.174 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.246.0.0/16 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.236.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.235.0.0/16 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.240.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.244.0.0/15 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 146.174.128.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 154.222.253.0/24 counter reject'
|
||||
# For the MOTD
|
||||
db_backup_dir: ['/backups']
|
||||
dbs_to_backup: ['pagure']
|
||||
|
|
@ -72,6 +72,13 @@ vpn: true
|
|||
zabbix_host: zabbix01.vpn.fedoraproject.org
|
||||
zabbix_macros:
|
||||
'VFS.DEV.WRITE.AWAIT.WARN': 60 # frequently saturated writes overnight
|
||||
# Hotfixes
|
||||
pagure_patches:
|
||||
- b50d32b7c92f131ebcc3b633de6c6e91e28297ec
|
||||
- 5529
|
||||
- readme-include
|
||||
- 26bc9746
|
||||
- 5553
|
||||
|
||||
notes: |
|
||||
Run the pagure instances for fedora
|
||||
|
|
|
|||
|
|
@ -41,6 +41,13 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
|
|||
zabbix_server: "{{ zabbix_hostname }}"
|
||||
zabbix_auth_key: "{{ zabbix_apikey }}" # ansible-private repo
|
||||
zabbix_tls_psk: "{{ zabbix_tls_prod_psk }}" # in ansible-private repo, pagure-stg is weird...
|
||||
# Hotfixes
|
||||
pagure_patches:
|
||||
- b50d32b7c92f131ebcc3b633de6c6e91e28297ec
|
||||
- 5529
|
||||
- readme-include
|
||||
- 26bc9746
|
||||
- 5553
|
||||
|
||||
notes: |
|
||||
Run the pagure instances for fedora
|
||||
|
|
|
|||
|
|
@ -6,7 +6,7 @@ clamscan_paths:
|
|||
# For the MOTD
|
||||
# Neeed for rsync from log01 for logs.
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept']
|
||||
git_basepath: /
|
||||
git_daemon_user: nobody
|
||||
git_port: 9418
|
||||
|
|
|
|||
|
|
@ -34,90 +34,91 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.128 -j ACCEPT',
|
||||
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.129 -j ACCEPT']
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 81.69.171.38 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 175.24.248.206 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.76.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.80.0.0/13 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.74.0.0/15 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 66.249.64.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.0.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.224.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.41.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.163.8.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.156.0.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.133.32.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.134.128.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.37.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.153.192.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.159.32.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.156.64.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 43.163.0.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 14.153.15.174 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.246.0.0/16 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.236.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 152.53.36.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 66.249.69.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 159.138.218.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 188.75.180.46/32 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 45.78.192.0/18 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.0.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.32.0/21 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.40.0/21 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.48.0/20 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.64.0/20 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.80.0/21 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.88.0/22 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.92.0/23 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.95.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.96.0/23 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.98.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.128.0/19 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.160.0/20 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.176.0/21 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.184.0/21 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.185.0/24 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 101.47.186.0/23 counter reject'
|
||||
- 'add rule ip filter INPUT ip saddr 34.159.191.146/32 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 81.69.171.38 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 175.24.248.206 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.76.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.80.0.0/13 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.74.0.0/15 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.64.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.0.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.224.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.41.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.8.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.0.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.133.32.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.128.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.37.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.153.192.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.32.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.64.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.0.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 14.153.15.174 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.246.0.0/16 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.236.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.235.0.0/16 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.240.0.0/14 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.244.0.0/15 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 152.53.36.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.69.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 159.138.218.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 188.75.180.46/32 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 2.57.121.144/32 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 45.78.192.0/18 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.0.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.32.0/21 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.40.0/21 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.48.0/20 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.64.0/20 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.80.0/21 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.88.0/22 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.92.0/23 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.95.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.96.0/23 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.98.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.128.0/19 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.160.0/20 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.176.0/21 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.184.0/21 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.185.0/24 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.186.0/23 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 34.159.191.146/32 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 208.78.212.5/32 counter reject'
|
||||
nft_custom_rules:
|
||||
# Need for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 209.132.181.102 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 209.132.181.102 tcp dport 873 counter accept'
|
||||
# allow varnish from localhost
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
# also allow varnish from internal for purge requests
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
|
||||
external: true
|
||||
ipa_client_shell_groups:
|
||||
- fi-apprentice
|
||||
|
|
@ -131,7 +132,9 @@ ipa_host_group_desc: Proxies between internal hosts and the Internet
|
|||
lvm_size: 100000
|
||||
# This is used in the httpd.conf to determine the value for serverlimit and
|
||||
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
|
||||
maxrequestworkers: 3200
|
||||
# However, due to lots of very transitory connections, bumping up to 4000
|
||||
# to give some head room.
|
||||
maxrequestworkers: 4000
|
||||
mem_size: 8192
|
||||
nagios_Check_Services:
|
||||
swap: false
|
||||
|
|
|
|||
|
|
@ -11,44 +11,44 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.0/24 --dport 6081 -j ACCEPT',
|
||||
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.123 -j ACCEPT']
|
||||
nft_block_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 2.57.121.144/32 counter reject'
|
||||
nft_custom_rules:
|
||||
# Need for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# allow varnish from localhost
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
# also allow varnish from internal for purge requests
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
|
||||
# Need for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.50 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.50 tcp dport 873 counter accept'
|
||||
# allow varnish from localhost
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
|
||||
# also allow varnish from internal for purge requests
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
|
||||
external: true
|
||||
ipa_client_shell_groups:
|
||||
- fi-apprentice
|
||||
|
|
@ -63,7 +63,9 @@ ipa_host_group_desc: Proxies between internal hosts and the Internet
|
|||
lvm_size: 100000
|
||||
# This is used in the httpd.conf to determine the value for serverlimit and
|
||||
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
|
||||
maxrequestworkers: 3200
|
||||
# However, due to lots of very transitory connections, bumping up to 4000
|
||||
# to give some head room.
|
||||
maxrequestworkers: 4000
|
||||
mem_size: 49152
|
||||
num_cpus: 8
|
||||
ocp_masters_stg:
|
||||
|
|
|
|||
|
|
@ -9,16 +9,16 @@ custom_rules: [
|
|||
]
|
||||
nft_custom_rules:
|
||||
# Neeed for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# Inter-node traffic
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
|
||||
# In RDU3
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
|
||||
ipa_host_group: rabbitmq
|
||||
ipa_host_group_desc: RabbitMQ service
|
||||
ipa_shell_groups:
|
||||
|
|
|
|||
|
|
@ -9,16 +9,16 @@ custom_rules: [
|
|||
]
|
||||
nft_custom_rules:
|
||||
# Neeed for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# Inter-node traffic
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
|
||||
# In RDU3
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
|
||||
ipa_host_group: rabbitmq
|
||||
ipa_host_group_desc: RabbitMQ service
|
||||
ipa_shell_groups:
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@ custom_rules:
|
|||
- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 2049 -j ACCEPT'
|
||||
- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 5432 -j ACCEPT'
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.5.78.11 tcp dport 2049 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.5.78.11 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.5.78.11 tcp dport 2049 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.5.78.11 tcp dport 5432 counter accept'
|
||||
env: production
|
||||
freezes: false
|
||||
ipa_client_shell_groups:
|
||||
|
|
|
|||
|
|
@ -69,3 +69,5 @@ zabbix_tls_psk: "{{ zabbix_tls_stg_psk }}" # in ansible-private repo
|
|||
zabbix_inventory:
|
||||
# Env is not a valid key, so use this field for environment
|
||||
deployment_status: staging
|
||||
zabbix_macros:
|
||||
'KOJI.HOST': koji.stg.fedoraproject.org
|
||||
|
|
|
|||
|
|
@ -10,13 +10,13 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp -s 10.16.163.35 --dport 5050 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
# Needed for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# Needed to let nagios on noc01 and noc02 pipe alerts to zodbot here
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.20 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.20 tcp dport 5050 counter accept'
|
||||
# batcave01 also needs access to announce commits.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
|
||||
deployment_type: prod
|
||||
ipa_client_shell_groups:
|
||||
- fi-apprentice
|
||||
|
|
|
|||
|
|
@ -10,14 +10,14 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp -s 10.16.163.35 --dport 5050 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
# Neeed for rsync from log01 for logs.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# Needed to let nagios on noc01 and noc02 (noc01.stg) pipe alerts to zodbot here
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 152.19.134.192 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 152.19.134.192 tcp dport 5050 counter accept'
|
||||
# batcave01 also needs access to announce commits.
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
|
||||
deployment_type: stg
|
||||
ipa_client_shell_groups:
|
||||
- fi-apprentice
|
||||
|
|
|
|||
|
|
@ -23,6 +23,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
|
|||
buildhw-x86-10.rdu3.fedoraproject.org
|
||||
buildhw-x86-12.rdu3.fedoraproject.org
|
||||
buildhw-x86-13.rdu3.fedoraproject.org
|
||||
buildhw-x86-14.rdu3.fedoraproject.org
|
||||
## Build vm hosts
|
||||
bvmhost-x86-01.rdu3.fedoraproject.org
|
||||
bvmhost-x86-02.rdu3.fedoraproject.org
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
---
|
||||
bmc:
|
||||
ip_address: 10.16.160.25
|
||||
ip_address: 10.16.160.87
|
||||
ping: true
|
||||
http: true
|
||||
https: true
|
||||
|
|
|
|||
70
inventory/host_vars/buildhw-x86-14.rdu3.fedoraproject.org
Normal file
70
inventory/host_vars/buildhw-x86-14.rdu3.fedoraproject.org
Normal file
|
|
@ -0,0 +1,70 @@
|
|||
---
|
||||
bmc:
|
||||
ip_address: 10.16.160.88
|
||||
ping: true
|
||||
http: true
|
||||
https: true
|
||||
br0_ipv4_ip: 10.16.169.44
|
||||
br0_ipv4_gw: 10.16.169.254
|
||||
br0_ipv4_nm: 24
|
||||
datacenter: rdu3
|
||||
dns1: 10.16.163.33
|
||||
dns2: 10.16.163.34
|
||||
dns_search1: "rdu3.fedoraproject.org"
|
||||
dns_search2: "fedoraproject.org"
|
||||
has_ipv4: yes
|
||||
mac0: b4:45:06:fb:84:2e
|
||||
mac1: b4:45:06:fb:84:2f
|
||||
mac2: 5c:6f:69:7f:ba:30
|
||||
mac3: 5c:6f:69:7f:ba:31
|
||||
network_connections:
|
||||
# Bridge profile
|
||||
- name: br0
|
||||
state: up
|
||||
type: bridge
|
||||
mtu: 1500
|
||||
autoconnect: yes
|
||||
ip:
|
||||
address:
|
||||
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
|
||||
dhcp4: no
|
||||
dns:
|
||||
- "{{ dns1 }}"
|
||||
- "{{ dns2 }}"
|
||||
dns_search:
|
||||
- "{{ dns_search1 }}"
|
||||
- "{{ dns_search2 }}"
|
||||
gateway4: "{{ br0_ipv4_gw }}"
|
||||
# Bond profile
|
||||
- name: bond0
|
||||
type: bond
|
||||
interface_name: bond0
|
||||
mtu: 1500
|
||||
controller: br0
|
||||
bond:
|
||||
mode: 802.3ad
|
||||
# Port profile for the 1st Ethernet device
|
||||
- name: bond0-port1
|
||||
mac: "{{ mac2 }}"
|
||||
type: ethernet
|
||||
controller: bond0
|
||||
state: up
|
||||
mtu: 1500
|
||||
# Port profile for the 2nd Ethernet device
|
||||
- name: bond0-port2
|
||||
mac: "{{ mac3 }}"
|
||||
type: ethernet
|
||||
controller: bond0
|
||||
state: up
|
||||
mtu: 1500
|
||||
# This is used to populate the inventory fields, only specific keys are allowed, see
|
||||
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
|
||||
zabbix_inventory:
|
||||
date_hw_expiry: ""
|
||||
date_hw_purchase: ""
|
||||
hardware: PowerEdge R450
|
||||
location: RDU3
|
||||
oob_ip: "{{ bmc.ip_address }}"
|
||||
serialno_a: F922FZ3
|
||||
type: Prod_Dedicated_HW
|
||||
vendor: Dell
|
||||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.47
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
mem_size: 4096
|
||||
vmhost: vmhost-x86-04.rdu3.fedoraproject.org
|
||||
|
|
|
|||
|
|
@ -4,17 +4,17 @@
|
|||
#
|
||||
nft_custom_rules:
|
||||
# Openshift nodes (egress policy will block connection from non-authorized projects)
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.69 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.70 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.71 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.72 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.73 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.69 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.70 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.71 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.72 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.73 tcp dport 5432 counter accept'
|
||||
# noc01 needs to connect to check the db
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
|
||||
# Ipsilon VMs
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.105 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.106 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.117 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.105 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.106 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.117 tcp dport 5432 counter accept'
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- fas2
|
||||
|
|
|
|||
|
|
@ -5,7 +5,7 @@
|
|||
#
|
||||
# TODO: lock it down more
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.166.0/24 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.0/24 tcp dport 5432 counter accept'
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- fas2
|
||||
|
|
|
|||
|
|
@ -3,10 +3,10 @@
|
|||
# Only allow postgresql access from the frontend node.
|
||||
#
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.169.104 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.169.105 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.169.10 tcp dport 5432 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.104 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.105 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.10 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- koji
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
#
|
||||
# Only allow postgresql access from the frontend node.
|
||||
#
|
||||
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.167.64 tcp dport 5432 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.167.64 tcp dport 5432 counter accept']
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- koji
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
# This is a generic list, monitored by collectd
|
||||
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.172.21 --dport 5432 -j ACCEPT']
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.172.21 tcp dport 5432 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.172.21 tcp dport 5432 counter accept'
|
||||
databases:
|
||||
- koji
|
||||
datacenter: rdu3
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
#
|
||||
# We should narrow this down at some point
|
||||
#
|
||||
nft_custom_rules: ['add rule ip filter INPUT tcp dport 5432 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- anitya
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
#
|
||||
# We should narrow this down at some point
|
||||
#
|
||||
nft_custom_rules: ['add rule ip filter INPUT tcp dport 5432 counter accept']
|
||||
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
|
||||
# This is a generic list, monitored by collectd
|
||||
databases:
|
||||
- askfedora
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.109
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
sar_script_user: root
|
||||
virt_install_command: "{{ virt_install_command_one_nic }}"
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.166.254
|
||||
eth0_ipv4_ip: 10.16.166.62
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
vmhost: vmhost-x86-03.stg.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
|
|||
46
inventory/host_vars/dedicatedsolutions02.fedoraproject.org
Normal file
46
inventory/host_vars/dedicatedsolutions02.fedoraproject.org
Normal file
|
|
@ -0,0 +1,46 @@
|
|||
---
|
||||
br0_ipv4: 67.219.144.67
|
||||
br0_ipv4_gw: 67.219.144.65
|
||||
br0_ipv4_nm: 29
|
||||
br0_ipv6: "2604:1580:fe00:0:dead:beef:cafe:fe02"
|
||||
br0_ipv6_gw: "2604:1580:fe00::1"
|
||||
br0_ipv6_nm: 64
|
||||
br0_port0_mac: "{{ mac1 }}"
|
||||
datacenter: dedicatedsolutions
|
||||
dns1: 8.8.8.8
|
||||
dns2: 8.8.4.4
|
||||
dns_search1: "vpn.fedoraproject.org"
|
||||
dns_search2: "fedoraproject.org"
|
||||
has_ipv4: yes
|
||||
has_ipv6: yes
|
||||
mac1: 6c:c2:17:2b:73:40
|
||||
network_connections:
|
||||
- autoconnect: yes
|
||||
ip:
|
||||
address:
|
||||
- "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}"
|
||||
- "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}"
|
||||
dhcp4: no
|
||||
dns:
|
||||
- "{{ dns1 }}"
|
||||
- "{{ dns2 }}"
|
||||
dns_search:
|
||||
- "{{ dns_search1 }}"
|
||||
- "{{ dns_search2 }}"
|
||||
gateway4: "{{ br0_ipv4_gw }}"
|
||||
gateway6: "{{ br0_ipv6_gw }}"
|
||||
name: br0
|
||||
state: up
|
||||
type: bridge
|
||||
- mac: "{{ br0_port0_mac }}"
|
||||
master: br0
|
||||
name: br0-port0
|
||||
state: up
|
||||
type: ethernet
|
||||
nrpe_procs_crit: 1000
|
||||
nrpe_procs_warn: 900
|
||||
postfix_group: vpn
|
||||
virthost: true
|
||||
vpn: true
|
||||
zabbix_macros:
|
||||
'VFS.DEV.WRITE.AWAIT.WARN': 100
|
||||
|
|
@ -29,8 +29,8 @@ network_connections:
|
|||
type: ethernet
|
||||
state: up
|
||||
mtu: 1500
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 20480
|
||||
mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -29,8 +29,8 @@ network_connections:
|
|||
type: ethernet
|
||||
state: up
|
||||
mtu: 1500
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 20480
|
||||
mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -29,8 +29,8 @@ network_connections:
|
|||
type: ethernet
|
||||
state: up
|
||||
mtu: 1500
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 20480
|
||||
mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -29,8 +29,8 @@ network_connections:
|
|||
type: ethernet
|
||||
state: up
|
||||
mtu: 1500
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 20480
|
||||
mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -29,8 +29,8 @@ network_connections:
|
|||
type: ethernet
|
||||
state: up
|
||||
mtu: 1500
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 20480
|
||||
mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -11,9 +11,9 @@ eth0_ipv6_ip: "2606:f640:6000:651::10"
|
|||
eth0_ipv6_gw: "2606:f640:6000:651::1"
|
||||
eth0_ipv6_nm: 64
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
lvm_size: 150000
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 100000
|
||||
main_bridge: br0
|
||||
max_mem_size: 49152
|
||||
mem_size: 32768
|
||||
|
|
|
|||
|
|
@ -10,8 +10,8 @@ eth0_ipv6_ip: 2620:52:6:1161::35
|
|||
eth0_ipv6_nm: 64
|
||||
eth0_nm: 255.255.255.0
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
lvm_size: 50000
|
||||
max_mem_size: 49152
|
||||
mem_size: 32768
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.166.254
|
||||
eth0_ipv4_ip: 10.16.166.30
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
vmhost: vmhost-x86-04.stg.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
|
|||
|
|
@ -6,7 +6,7 @@ koji_instance: primary
|
|||
koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
|
||||
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
|
||||
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 1.5t
|
||||
nrpe_procs_crit: 1000
|
||||
|
|
|
|||
|
|
@ -1,8 +1,8 @@
|
|||
---
|
||||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.130
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
eth0_ipv4_ip: 10.16.163.59
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
vmhost: vmhost-x86-03.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
@ -1,8 +1,8 @@
|
|||
---
|
||||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.166.254
|
||||
eth0_ipv4_ip: 10.16.166.77
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
eth0_ipv4_ip: 10.16.166.41
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
vmhost: vmhost-x86-05.stg.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
@ -6,13 +6,13 @@ custom_rules: [
|
|||
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'
|
||||
]
|
||||
nft_custom_rules:
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.20 tcp dport 5666 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.20 tcp dport 5666 counter accept'
|
||||
# needed to allow rsync from log01
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
|
||||
# needed to allow 8080 (firmware-proxy from iDRAC mgmt vlans
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.160.0/24 tcp dport 8080 counter accept'
|
||||
- 'add rule ip filter INPUT ip saddr 10.16.161.0/24 tcp dport 8080 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.160.0/24 tcp dport 8080 counter accept'
|
||||
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.161.0/24 tcp dport 8080 counter accept'
|
||||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.10
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ network_connections:
|
|||
# This host is externally reachable
|
||||
#
|
||||
external: true
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
vmhost: vmhost-x86-01.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
|
|||
|
|
@ -24,8 +24,8 @@ eth0_ipv6_ip: "2606:f640:6000:651::11"
|
|||
eth0_ipv6_gw: "2606:f640:6000:651::1"
|
||||
eth0_ipv6_nm: 64
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
main_bridge: br0
|
||||
network_connections:
|
||||
- autoconnect: yes
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ network_connections:
|
|||
# This host is externally reachable
|
||||
#
|
||||
external: true
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
vmhost: vmhost-x86-03.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
|
|||
|
|
@ -25,8 +25,8 @@ eth0_ipv6_ip: "2001:4178:2:1269:dead:beef:cafe:fed5"
|
|||
eth0_ipv6_nm: 64
|
||||
eth0_nm: 255.255.255.240
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
network_connections:
|
||||
- autoconnect: yes
|
||||
ip:
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.167.254
|
||||
eth0_ipv4_ip: 10.16.167.34
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 120g
|
||||
max_mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.169.254
|
||||
eth0_ipv4_ip: 10.16.169.119
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 120g
|
||||
max_mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.167.254
|
||||
eth0_ipv4_ip: 10.16.167.35
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 120g
|
||||
max_mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.169.254
|
||||
eth0_ipv4_ip: 10.16.169.127
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
lvm_size: 120g
|
||||
max_mem_size: 16384
|
||||
|
|
|
|||
|
|
@ -5,7 +5,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.174.254
|
||||
eth0_ipv4_ip: 10.16.174.57
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
############################################################
|
||||
# install
|
||||
############################################################
|
||||
|
|
|
|||
|
|
@ -5,7 +5,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.174.254
|
||||
eth0_ipv4_ip: 10.16.174.52
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
############################################################
|
||||
# install
|
||||
############################################################
|
||||
|
|
|
|||
|
|
@ -2,9 +2,10 @@
|
|||
datacenter: rdu3
|
||||
dns1: 10.16.163.33
|
||||
dns2: 10.16.163.34
|
||||
dns_search1: "stg.rdu3.fedoraproject.org"
|
||||
dns_search2: "rdu3.fedoraproject.org"
|
||||
dns_search3: "fedoraproject.org"
|
||||
dns_search1: "vpn.fedoraproject.org"
|
||||
dns_search2: "stg.rdu3.fedoraproject.org"
|
||||
dns_search3: "rdu3.fedoraproject.org"
|
||||
dns_search4: "fedoraproject.org"
|
||||
effective_cache_size: "6GB"
|
||||
eth0_ipv4_gw: 10.16.179.254
|
||||
eth0_ipv4_ip: 10.16.179.61
|
||||
|
|
@ -29,6 +30,7 @@ network_connections:
|
|||
- "{{ dns_search1 }}"
|
||||
- "{{ dns_search2 }}"
|
||||
- "{{ dns_search3 }}"
|
||||
- "{{ dns_search4 }}"
|
||||
gateway4: "{{ eth0_ipv4_gw }}"
|
||||
gateway6: "{{ eth0_ipv6_gw }}"
|
||||
mac: "{{ ansible_default_ipv4.macaddress }}"
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ eth0_ipv6_nm: 64
|
|||
freezes: true
|
||||
has_ipv4: yes
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
max_mem_size: 32768
|
||||
mem_size: 32768
|
||||
|
|
@ -43,7 +43,7 @@ postfix_group: vpn
|
|||
public_hostname: proxy11.fedoraproject.org
|
||||
# This is consumed by the roles/fedora-web/main role
|
||||
sponsor: dedicatedsolutions
|
||||
vmhost: dedicatedsolutions01.fedoraproject.org
|
||||
vmhost: dedicatedsolutions02.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
vpn: true
|
||||
zabbix_macros:
|
||||
|
|
|
|||
|
|
@ -13,9 +13,8 @@ eth0_ipv6_nm: 64
|
|||
freezes: true
|
||||
has_ipv4: yes
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
mac0: "52:54:00:84:5d:9f"
|
||||
main_bridge: br0
|
||||
max_mem_size: 20000
|
||||
mem_size: 16384
|
||||
|
|
@ -35,12 +34,12 @@ network_connections:
|
|||
- "{{ dns_search2 }}"
|
||||
gateway4: "{{ eth0_ipv4_gw }}"
|
||||
gateway6: "{{ eth0_ipv6_gw }}"
|
||||
mac: "{{ mac0 }}"
|
||||
mac: "{{ ansible_default_ipv4.macaddress }}"
|
||||
name: eth0
|
||||
type: ethernet
|
||||
nrpe_procs_crit: 1400
|
||||
nrpe_procs_warn: 1200
|
||||
num_cpus: 8
|
||||
num_cpus: 16
|
||||
postfix_group: vpn
|
||||
public_hostname: proxy12.fedoraproject.org
|
||||
# This is consumed by the roles/fedora-web/main role
|
||||
|
|
|
|||
4
inventory/host_vars/s390x-test01.fedorainfracloud.org
Normal file
4
inventory/host_vars/s390x-test01.fedorainfracloud.org
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
---
|
||||
nagios_Can_Connect: false
|
||||
nagios_Check_Services:
|
||||
nrpe: false
|
||||
|
|
@ -11,8 +11,8 @@ eth0_ipv6_ip: "2606:f640:6000:651::5"
|
|||
eth0_ipv6_gw: "2606:f640:6000:651::1"
|
||||
eth0_ipv6_nm: 64
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
main_bridge: br0
|
||||
network_connections:
|
||||
- autoconnect: yes
|
||||
|
|
|
|||
|
|
@ -10,8 +10,8 @@ eth0_ipv4_ip: 10.16.179.63
|
|||
eth0_ipv6_gw: 2620:52:6:1161::1
|
||||
eth0_ipv6_ip: 2620:52:6:1161::34
|
||||
eth0_nm: 255.255.255.0
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
vmhost: vmhost-x86-iso02.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
vpn: true
|
||||
|
|
|
|||
|
|
@ -10,8 +10,8 @@ eth0_ipv6_ip: "2605:bc80:3010:600:dead:beef:cafe:fedb"
|
|||
eth0_ipv6_gw: "2605:bc80:3010:600::1"
|
||||
eth0_ipv6_nm: 64
|
||||
has_ipv6: yes
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
mem_size: 4096
|
||||
network_connections:
|
||||
- autoconnect: yes
|
||||
|
|
|
|||
|
|
@ -6,10 +6,10 @@ dns_search1: "rdu3.fedoraproject.org"
|
|||
dns_search2: "fedoraproject.org"
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.37
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
# Define resources for this group of hosts here.
|
||||
lvm_size: 20000
|
||||
lvm_size: 25000
|
||||
mem_size: 4096
|
||||
num_cpus: 2
|
||||
vmhost: vmhost-x86-01.rdu3.fedoraproject.org
|
||||
|
|
|
|||
|
|
@ -6,10 +6,10 @@ dns_search1: "rdu3.fedoraproject.org"
|
|||
dns_search2: "fedoraproject.org"
|
||||
eth0_ipv4_gw: 10.16.163.254
|
||||
eth0_ipv4_ip: 10.16.163.38
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
|
||||
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
|
||||
# Define resources for this group of hosts here.
|
||||
lvm_size: 20000
|
||||
lvm_size: 25000
|
||||
mem_size: 4096
|
||||
num_cpus: 2
|
||||
vmhost: vmhost-x86-05.rdu3.fedoraproject.org
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
datacenter: rdu3
|
||||
eth0_ipv4_gw: 10.16.166.254
|
||||
eth0_ipv4_ip: 10.16.166.24
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
|
||||
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
|
||||
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
|
||||
vmhost: vmhost-x86-03.stg.rdu3.fedoraproject.org
|
||||
volgroup: /dev/vg_guests
|
||||
|
|
|
|||
|
|
@ -109,7 +109,7 @@ bvmhost-x86-02.stg.rdu3.fedoraproject.org
|
|||
bvmhost-x86-03.stg.rdu3.fedoraproject.org
|
||||
|
||||
[colo_virt]
|
||||
dedicatedsolutions01.fedoraproject.org
|
||||
dedicatedsolutions02.fedoraproject.org
|
||||
ibiblio02.fedoraproject.org
|
||||
ibiblio05.fedoraproject.org
|
||||
internetx02.fedoraproject.org
|
||||
|
|
@ -343,16 +343,16 @@ noc01.rdu3.fedoraproject.org
|
|||
noc01.rdu3.fedoraproject.org
|
||||
|
||||
[memcached]
|
||||
memcached02.rdu3.fedoraproject.org
|
||||
memcached01.rdu3.fedoraproject.org
|
||||
|
||||
[memcached_rdu3]
|
||||
memcached02.rdu3.fedoraproject.org
|
||||
memcached01.rdu3.fedoraproject.org
|
||||
|
||||
[memcached_stg]
|
||||
memcached02.stg.rdu3.fedoraproject.org
|
||||
memcached01.stg.rdu3.fedoraproject.org
|
||||
|
||||
[memcached_stg_rdu3]
|
||||
memcached02.stg.rdu3.fedoraproject.org
|
||||
memcached01.stg.rdu3.fedoraproject.org
|
||||
|
||||
[mirrorlist_proxies]
|
||||
proxy02.fedoraproject.org
|
||||
|
|
@ -642,7 +642,7 @@ ipatuura01.stg.rdu3.fedoraproject.org
|
|||
ipsilon01.stg.rdu3.fedoraproject.org
|
||||
koji01.stg.rdu3.fedoraproject.org
|
||||
mailman01.stg.rdu3.fedoraproject.org
|
||||
memcached02.stg.rdu3.fedoraproject.org
|
||||
memcached01.stg.rdu3.fedoraproject.org
|
||||
os-control01.stg.rdu3.fedoraproject.org
|
||||
pkgs01.stg.rdu3.fedoraproject.org
|
||||
proxy01.stg.rdu3.fedoraproject.org
|
||||
|
|
@ -783,6 +783,7 @@ ppc64le-test.fedorainfracloud.org
|
|||
ppc64le-test02.fedorainfracloud.org
|
||||
aarch64-test01.fedorainfracloud.org
|
||||
aarch64-test02.fedorainfracloud.org
|
||||
s390x-test01.fedorainfracloud.org
|
||||
|
||||
[aarch64_test]
|
||||
aarch64-test01.fedorainfracloud.org
|
||||
|
|
@ -816,7 +817,7 @@ colo_virt
|
|||
value
|
||||
staging
|
||||
builders
|
||||
bkernel
|
||||
secureboot
|
||||
buildvmhost
|
||||
|
||||
[groupc]
|
||||
|
|
|
|||
1
main.yml
1
main.yml
|
|
@ -33,6 +33,7 @@
|
|||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/koji-hub.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/kojipkgs.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/logserver.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/logdetective.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/mailman.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/maintainer-test.yml
|
||||
- import_playbook: /srv/web/infra/ansible/playbooks/groups/mariadb-server.yml
|
||||
|
|
|
|||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue