1
0
Fork 0
forked from infra/ansible

Compare commits

...

272 commits

Author SHA1 Message Date
Jeremy Cline
ebaf8210f3
draft: add roles for siguldry server and bridge
These roles deploy the Siguldry server and bridge.

There's a few TODOs, and one step that isn't covered at all is the
deployment of the TLS private keys. These need to be encrypted with
systemd-creds, which should be doable via ansible, but the pesign bridge
isn't doing it so I've left it out for now.

Signed-off-by: Jeremy Cline <jeremycline@microsoft.com>
2026-06-02 14:46:46 -04:00
3457eea89b
Add the RabbitMQ user for the lookaside cache
Fixes: infra/tickets#13380

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 11:54:21 +02:00
728b6c57a3
Fix deployment triggers
The annotations must be on the deployment's metadata, not on the pod
template's metadata.

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 10:14:01 +02:00
d98ce9b9f8
Fix the triggers for the deployment in webhook2fedmsg
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 09:53:40 +02:00
ea82ea2c9a
Fix the openshift user id in badges
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-06-02 09:53:40 +02:00
3731a63a13 bodhi-stg: add python-redis to base image
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-06-02 09:08:15 +02:00
James Antill
3fdaf170d5 nftables: Use the config. table names in staging.
Signed-off-by: James Antill <james@and.org>
2026-06-01 18:43:59 -04:00
James Antill
e11b39314d nftables: Fix/merge monitoring changes between prod/staging.
Signed-off-by: James Antill <james@and.org>
2026-06-01 18:38:22 -04:00
James Antill
4a6fc0fdf5 nftables: Fix table name scoping issue.
Signed-off-by: James Antill <james@and.org>
2026-06-01 17:42:12 -04:00
James Antill
5c6868260b Merge branch 'nftables' into upstream
* nftables: (2 commits)
  Cleanup nft merge. Chg osbuildapi and nft_custom_rules to use nft_table_filter.
  ...

Signed-off-by: James Antill <james@and.org>
2026-06-01 17:33:24 -04:00
James Antill
40b3225890 pagure: hotfix for commit hash
Signed-off-by: James Antill <james@and.org>
2026-06-01 21:12:12 +00:00
a9adce6136 robosignatory: enable signing on f45-python 2026-06-01 21:09:43 +00:00
a0156fc54d pkgs: allow apache to read fedora-messaging key
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-01 10:27:44 -07:00
ce1edea8ee distgit: fix the ca cert the git hooks use for fedora-messaging
We were copying in the req instead of the ca, so this messaging hook has
been broken for a long while. This is the hook that notifys on uploads.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-01 09:59:51 -07:00
Jiri Kyjovsky
259ec5b2e8 copr-be: enable rpmeta build time prediction (observability-only)
Deploy rpmeta config to copr-be.conf and hardware pools YAML with
real builder specs. Initially logging-only, does not affect VM allocation.
2026-06-01 17:21:57 +02:00
Lenka Segura
c8a55f0113 forgejo: Increase the capacity of 'ci' and 'atomic-desktops' runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-06-01 09:58:08 +00:00
c6f7e6e601 Update Bodhi Pungi comps git URL from pagure.io to forge.fedoraproject.org/releng/fedora-comps after the fedora-comps migration
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-06-01 14:12:09 +05:30
d830f9ae6e copr: bump up number of reserved instances 2026-06-01 09:54:20 +02:00
615af75669 copr-be: more quota per sandbox 2026-06-01 09:27:15 +02:00
8bbcceafdd proxies: bump max connections fromm 3200 to 4000
It seems like the alerts we have been getting have been when proxies are
near the limit rejecting things via anubis, but unable to keep up.
So, lets try and jump this up a bit and see if it solves those
alerts/slowdowns.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-30 08:36:39 -07:00
71aec6a544 Move s390x staging builders and koji.stg hub to f44.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 12:23:51 -07:00
0248c0d535 virthost: rkhunter is available in epel10/10.2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 11:26:08 -07:00
06c765b10d buildvm-x86: reinstall with fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 11:24:25 -07:00
1be1c69f0f proxy12: fix mac address
This had the hard coded mac address of the previous vm.
We moved to using ansible to just fill in the current mac, so fix that
here too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:52:26 -07:00
141940d1ad basessh: allow tcp forwarding on noc as well as bastion.
We sometimes use forwarding here to access mgmt devices.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:41:46 -07:00
63315f4602 proxy12: reinstall with f44
We need to do this anyhow, but this will test to see if the weird alerts
we have been getting persist on f44 with the latest libvirt machine
setup.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-29 10:10:44 -07:00
9a5bca7aad copr-dist-git: hotfix https://github.com/fedora-copr/copr/issues/4318 2026-05-29 13:49:59 +02:00
6a767b3706 always a missing :
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-28 16:21:54 -07:00
9d572f1839 add coreos-agent, rag-magazine-guidelines, and public-inboc-poc communishift projects
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-28 16:20:15 -07:00
Lenka Segura
177bb00442 forgejo: strip the labels after ':' during registration
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-05-28 20:59:57 +00:00
Patrik Polakovič
a1c7d0828a Fedora 42 is now End Of Life
Signed-off-by: Patrik Polakovič <patrik@alphamail.org>
2026-05-28 20:33:06 +02:00
e73d603bd2
Nagios: remove SSH monitoring, Zabbix does it
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 17:18:50 +01:00
f3a05e1b72
Zabbix: Fix cronjob that generates the SSH target list 2026-05-28 17:18:50 +01:00
f29d91d7af
forgejo: runner config not being passed to the openshift secret
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-28 13:40:44 +01:00
641887c8cf
Zabbix: also test SSH access to the bastions from Batcave
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:36:04 +01:00
de6e36a4e5
Nagios: Remove PostgreSQL checks that we already have in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:28:04 +01:00
e104755e4e
Zabbix: fix DNS perf units, and regexp record trigger
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:20:09 +01:00
9e3cd9d4ff
Zabbix: Move DNS checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 13:12:00 +01:00
Jakub Kadlcik
e537215abc copr-dist-git: move sentry configuration to the correct config 2026-05-28 12:40:26 +02:00
44951845e4
Zabbix: remove incorrect run_once directives from proxy monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:33:34 +01:00
69612dffe5
Zabbix: Add the rest of the previous commit that got missed
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:30:27 +01:00
e3d9be210e
Zabbix: Move internal proxy checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 11:08:35 +01:00
bc2f608f4c
Zabbix: add trigger for one-off httpcheck items
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 09:44:55 +01:00
c0d5169f58
Zabbix: remove some unused checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-28 09:37:45 +01:00
Jan Matufka
d77168ff0c logdetective: service, dependency on nvidia-cdi
- for persistent deployment

Signed-off-by: Jan Matufka <jmatufka@redhat.com>
2026-05-28 08:15:50 +00:00
Jan Matufka
2e2abbedac nvidia-cdi: create a role
Signed-off-by: Jan Matufka <jmatufka@redhat.com>
2026-05-28 08:15:50 +00:00
993e600700 badges: fix image trigger annote order on deploy metadata
Similar to infra/ansible#3338

Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-28 11:38:57 +05:30
b8773db5ba Move the Fedora Badges static assets from Pagure to Forgejo
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-28 02:22:21 +00:00
7b4f3b4182 update location of fedocal to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 12:04:48 +10:00
c796a888d2 update location of fedora-packages-static to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 11:32:32 +10:00
eb0de86f9a update location of elections to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 09:39:52 +10:00
26402546de update location of cloud-image-uploader to new home on forge
related: infra/tickets#13369

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-28 08:59:27 +10:00
bbf9258578 memcached02 (rhel9) retirement
We switched over to the rhel10 versions of these, so these are going
away. Thanks for your service!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-27 13:48:59 -07:00
50559f83d7 memcached: move to new rhel10 instances
This moves all the applications that are using memcached to point to
the 01 (rhel10) versions intead of the 02 (rhel9) ones.

After pushing this, I will roll the changes out in staging and confirm
everything works, then do production. In the event of problems will roll
this back.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-27 12:37:23 -07:00
0baaabd735
Prepare W2FM in staging for Pretix
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 16:56:14 +02:00
2b6ddca8f4
forgejo: update README for runner config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-27 12:26:41 +01:00
1ffd0cd8a5
forgejo: Redesign runnerconfig
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-27 11:47:55 +01:00
068605d67d
Fixup 814582dc: actually use the imagestream.yml file
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 11:52:51 +02:00
f2c2aa037b forge: add group team mapping for atomic
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-27 19:44:39 +10:00
814582dc4d
Rebase webhook2fedmsg to python 3.13
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-27 10:41:13 +02:00
70cfd1412e memcached01: use correct ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:38:05 -07:00
ccb89c99a4 memcached01: add a new prod memcached01
Once this is all setup we can switch to it and retire the rhel9 02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:26:22 -07:00
7268404db7 memcached01.stg: add properly to stg group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:06:58 -07:00
7e226ba150 memcached_stg: increase disk size
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:48:00 -07:00
f8fbb98eda memcached01.stg: add a new rhel10 staging memcached
Once this is up and working, we can switch applications over to using
it, and retire the rhel9 one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:38:28 -07:00
3ac21c8018 tang02: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:00:47 -07:00
31c695a70f tang01: increase disk size a bit
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 13:58:04 -07:00
03dec33fd8 tang01: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 13:53:03 -07:00
1680d35e63
Move more http checks to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 17:10:43 +01:00
0d3e126317
Zabbix: Fix item typo and add another check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:39:21 +01:00
6ed762bb29
Zabbix: use regex instead, more flexible
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:22:13 +01:00
8d40668907
Zabbix: Add some basic non-host HTTP checking to zabbix01
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 14:13:50 +01:00
7e5a64efdc
Zabbix: fix typo in template macro
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 13:50:58 +01:00
6cfda2b8f5
Zabbix: move http-koji checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-26 13:44:59 +01:00
137626c637 forge: fix yet asnother typo in DEFAULT_ACTIONS_URL config
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:54:39 +10:00
f68ab813be forge: fix typo in DEFAULT_ACTIONS_URL
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:26:37 +10:00
90cc0bee98 forge: set DEFAULT_ACTIONS_URL to forge.fp.o
resolves: forge/forge#557

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 17:16:47 +10:00
749c16501f forge: add forgejo.org to migrations whitelist
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 13:02:46 +10:00
f4ca07caf7 forge: add group team mapping for actions org
related: forge/forge#557

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-26 12:36:17 +10:00
004fb438fe
Badges: the frontend needs its own OIDC client
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 10:07:57 +02:00
2e63ef6b72
Badges: adjust the oidc callback URL in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-25 09:31:18 +02:00
7ed0a93f2a forge: add group team mapping for DEI mentor summit team
related: forge/forge#589

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-25 12:52:18 +10:00
40fe2bfc69 fix syntax error
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-23 09:51:54 -07:00
7b21d2756f communishift: add some projects
This will add release-schedule-planner ( 13336 )
and draft-share ( 13358 )

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-23 09:49:35 -07:00
885651a7a7 bodhi-stg: fix valkey unixsocket
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:11:26 +02:00
c46879dc54 bodhi-stg: fix valkey logfile
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:07:47 +02:00
b5eddd80ea bodhi-stg: cannot use --include to override valkey conf
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 11:01:41 +02:00
481443b92f bodhi-stg: use valkey cache
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-23 10:41:49 +02:00
16642a1d02
OK, it works, apply them to prod pagure.io too
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-22 17:03:44 +02:00
05eb12595e
Apply hotfix patches to pagure.io too (staging for now)
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-22 16:44:18 +02:00
4140b2cdfd resultsdb-ci-listener: update for upstream Forge migration
The upstream app migrated from Pagure to Forge. Update references
here.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-21 15:51:34 -07:00
f05fbe3876 dedicatedsolutions01: drop from inventory in favor of 02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 13:30:15 -07:00
d60806aca0 ns05: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 13:10:36 -07:00
98c6cae22b ns01: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 12:45:37 -07:00
0595b45e39 pagure-stg: fix dns search order to fix certgetter01 access
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 11:28:03 -07:00
5887d43751 mirrormanager / mirrorlist_proxy: add explicit Host: to header in checks
In newer curl, not specifying Host: here means it emits a warning:

Warning: The provided HTTP header 'mirrors.fedoraproject.org' does not look
Warning: like a header?

So, specify Host: for the header so it works on both old curl and new.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 10:39:45 -07:00
4908f3bea7
Yet another forgotten thing for badges
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:59:00 +02:00
8cd135b4bd
Fixup 26b81b3
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:57:39 +02:00
fad66f712e
Add a patch to pagure, based on PR 5553
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:17:31 +02:00
26b81b373d
Rebase Badges on python 3.13 (from 3.10)
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-21 17:16:38 +02:00
331eae63d7
Nagios: remember to remove deleted ssl.cfg file from task loop
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 11:21:47 +01:00
5d331ca6e3
Zabbix: port remaining SSL checks over from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 11:07:10 +01:00
1c6dded5bb
Nagios: remove more things we already have in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-21 10:32:22 +01:00
f2759cb8b2 forge: add group team mappings for pungi org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-21 10:10:12 +10:00
2d24211424 ns03: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 15:34:38 -07:00
4262b3610f dns: only set crypto-policy on rhel9 dns servers, 10 does not have that policy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:44:21 -07:00
1963b068d3 Switch epel10.repo and rhel10.repo to use a link to latest
There's no super right answer here, but if we point to a specific minor
release here it means we have to move all machines to it when we change
it, and we have to remember to do so.

If we just use '10' and depend on the link that points to the latest
minor:

lrwxrwxrwx. 1 root root    4 May 19 17:12 /srv/web/repo/rhel/rhel10/10 -> 10.2/

then we don't have to keep changing this all the time, it will just
update when that link changes.

This doesn't leave us an easy way to keep some hosts back to the old
minor, but in practice we pretty much never do this anyhow.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:31:53 -07:00
60e48fd441 ns02: reinstall with rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 14:27:17 -07:00
5e7b40087d proxy11: since we are doing a new install, try f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:35:56 -07:00
a5eb828847 release-monitoring: move back down to 1 web pod, seems to have caused duplicate comments on bugzilla bugs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:34:25 -07:00
cf52816027 proxy11: move to using normal volgroup name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 13:33:41 -07:00
9ffb23bb35 release-monitoring: scale web pods to 3 by default
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 08:55:52 -07:00
44bc3548f0 proxies: add ip that is generating a large number of 404s on mirrorlists
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-20 08:14:31 -07:00
688720342e [mailman3] Fix the patch file
Posix patch doesn't really like the git fake directories.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:18:41 +02:00
13c1dd27d9 [mailman3] Use the correct path to file
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:15:18 +02:00
8f12b3c681 [mailman3] Fix index not being rebuilt
The index build was failing on xapian_haystack issue that happens when
the mail is too long. This patch will skip those e-mails. See
infra/tickets#13355 for more info.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-20 15:07:17 +02:00
Jakub Kadlcik
c33602daf4 copr: high performance builder for karlinator/texlive-2023
Fix https://github.com/fedora-copr/copr/issues/4319
2026-05-20 09:57:24 +02:00
0ea1c9f292 quality: update testdays app builder to python-312 2026-05-19 16:05:42 +00:00
8fbab7e5b3 quality: update testdays app builder to python-311 2026-05-19 16:05:42 +00:00
6e0f4fe7b0 Retire EPEL 10.1
Signed-off-by: Diego Herrera <dherrera@redhat.com>
2026-05-19 14:58:42 +00:00
0723ffa45d
Zabbix update SSH and Varnish templates
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-19 15:31:40 +01:00
9faab10da6 proxy11: the vg here is named differently, but too much hassle to reinstall
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:57:15 -07:00
b0f0cbde39 proxy11: move over to dedicatedsolutions02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:55:19 -07:00
ee21c8afc6 dedicatedsolutions02: add new host
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:20:17 -07:00
2df5c98d16 smtp-mm-iso01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:38:57 -07:00
944efaf34f smtp-mm-osuosl01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:28:38 -07:00
a5d7291edc base / nftables / kojibuilder: allow sign-bridge access for all builders in the secureboot group, not just x86-02/a64-02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 15:24:12 -07:00
0ae3392198 smtp-mm-ib01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 14:53:10 -07:00
d4c013129a kickstarts / rhel10-nohd: drop rdp as it is not implemented in rhel 10.1 kickstarts as far as I can tell
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 12:42:54 -07:00
1aac9b0c7b kickstarts / rhel10-nohd: switch to rdp, vnc is no longer available in 10.1
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 12:07:43 -07:00
917e6f4f5c Zabbix: Migrate SSH connectivity checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-18 14:46:05 +00:00
4cf99e088a
fix(proxies): add www.fedoraproject.org back
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-18 09:14:27 +02:00
4e24b694b4 kickstarts: rhel10: use https for all the urls
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-17 12:18:58 -07:00
51081991be buildhw: install pesign_bridge on all secureboot group members
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 12:30:12 -07:00
442852923d fix: fix the annoying HTTP authentication popup on windows (prod)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:15:51 +00:00
af80a6a3a0 secure-boot: clean up old bkernel role and add 2 more builders
We are no longer using the bkernel role (using the old card thats in
buildhw-x86-01), so this removes that role and mentions of it.

Also, because we are urgently building kernels all the time now,
add one more buildhw-x86 and one more buildhw-a64 to secure-boot channel
so we can build more/faster kernels.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 19:14:17 +00:00
73dc88c487
fix: fix the annoying HTTP authentication popup on windows (stg only)
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-05-15 19:23:41 +02:00
6ccaaca78d proxies: adjust zabbix template name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 09:57:39 -07:00
7688d6da70 proxies / website: on src/koji/riscv-koji have POSTs bypass anubis
See infra/tickets#12913
and https://github.com/TecharoHQ/anubis/issues/1624

We are seeing sporadic EOF errors when koji/src/riscv-koji send a 200
reply back through anubis.

Since we just allow POST in anubis anyhow, bypass it entirely for them
to avoid the EOF issue until we can sort it out more.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 16:39:05 +00:00
623214b0c9 maubot: apply hotfix to maubot to fix __provides__ issue
related: infra/tickets#13347

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-15 20:11:26 +10:00
1bde47906f firmitas: move from t0xic0der/firmitas-test to playground/firmitas-test
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-15 08:23:41 +05:30
68315a2324 s390x-test01: should be in cloud group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-14 13:11:41 -07:00
977a470510 s390x-test01: add s390x maintainer test machine
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-14 13:07:30 -07:00
4998b94fce
Zabbix: Migrate CountMe file-age checks from Nagios
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 16:26:14 +01:00
4be7c97ff1
Nagios: Drop proxy mirrorlist & ostree file-age checks, migrated
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 13:39:54 +01:00
d47a991333
Zabbix: Add proxy file-age checks for ostree & mirrorlist cache
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-14 13:28:16 +01:00
6bdcf23ac7 firmitas: fix the missing variable ansible error
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-14 14:57:11 +05:30
4d2aa5527b firmitas: support ticket creation on forgejo instead of pagure
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-14 14:04:52 +05:30
8b477bcc0a kickstarts / rhel10: install selinux-policy-extra in all cases, needed for epel packages
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 17:21:32 -07:00
cf60e5fab5 kickstarts / rhel10: just point all the rhel10 kickstarts to the latest rhel10, not 10.0
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 16:27:57 -07:00
0d8779bc60 debuginfod: are now both f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 11:11:18 -07:00
c14a9c63af oci-registry01: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:55:15 -07:00
a38aeeab1b oci-registry02: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:34:46 -07:00
ce30489068 oci-candidate-registry01.stg: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 10:01:00 -07:00
acc8549a10 download-ib01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 09:34:23 -07:00
f838451f81 download-iso01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-13 09:11:29 -07:00
ebb316eedd
forgejo: Update runnerhost vm template with subdomain/hostname
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-13 15:47:37 +01:00
6f91abc606 Add releng org in forge staging
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-05-13 16:29:58 +05:30
dd2e76880a dl01: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:38:49 -07:00
4480adb270 dl02: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:24:38 -07:00
6533d2ae71 dl05: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 17:11:46 -07:00
8e461e50f5 dl04: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:55:25 -07:00
bb9984ec61 kickstarts / kvm-rhel-10: use the new 10.1 name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:40:06 -07:00
0986ae491b kickstarts / kvm-rhel-10: we need selinux-policy-epel to set things for epel packages
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:37:25 -07:00
eb0e697fab forge: add group team mappings for the fdwg org
related: forge/forge#559

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-13 09:35:45 +10:00
550aad5c29 forge: add group team mappings for R sig
related: forge/forge#545

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-13 09:34:03 +10:00
c7349dadea kickstarts / kvm-rhel-10: drop packages that do not exist in rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:23:32 -07:00
8c54ea4bad kickstarts: kvm-rhel-10: fix repo paths
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:18:25 -07:00
8f3def5c91 batcave01: also install the new kickstart template
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 16:01:51 -07:00
c55e6f0893 kickstarts: make a rhel10 kvm kickstart and have dl03 use it.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 15:59:45 -07:00
22f47d356a dl03: move to rhel10
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 15:49:05 -07:00
db4f19c2ad oci-registry01.stg: move to f44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-12 14:37:24 -07:00
05b94d7029
Zabbix: Improve Postfix queue trigger/recovery
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 13:54:35 +01:00
55a7c1c9f9
Nagios: remove vpnclients check, migrated to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 11:13:44 +01:00
dfa0766cff
Zabbix: Improve vpnclients connectivity check
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 11:11:46 +01:00
665456d9d9
Add buildhw-x86-14 to inventory groups
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 10:07:03 +01:00
83c42baccb
Add hostvars for buildhw-x86-14
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-12 10:04:48 +01:00
04e230408e copr-fe: no need to grant copr-fe db admin rights 2026-05-12 08:22:30 +00:00
4a68303c36 copr-fe: unix-socket-auth for postgresql 2026-05-12 08:22:30 +00:00
7923f145d9 fix typo in docs-archive group team mapping
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-12 18:01:20 +10:00
d6d3a4db54 add group team mappings for staging atomic-desktops and bootc
related: forge/forge#546

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-12 17:47:34 +10:00
b641125564 proxies / redirectmatch / provisioning-server: I am not sure how this worked before, but it needs a regex
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 17:35:41 -07:00
76e322e65a koji / hub: try increasing the keepalive timeout here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 15:11:29 -07:00
0df0dc0ec9 proxies / koji: lower the keepalive on the proxy side
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 14:30:03 -07:00
274e23e336 proxies: set ttl on the anubis layer to 15 also to match up with other things
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:59:06 -07:00
645cfe0482 proxies: when using a apache balancer, options go on the balancer members
Clanker lead me astray here. We can't pass options on the proxypass here
because we are using a balancer, so we need to pass them on the balancer
members.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:57:42 -07:00
d59d39d281 proxies: more changes for the sporadic 502 issue ( 12913 )
I got claude to dig into the things we tried to fix this issue and look
for things we missed. It found a few things:

1. In commit 35a1b3223b Victor Koycheff added some proxyopts for
   keepalive, etc. However, unfortunately, while the variable was set
   the template wasn't looking at that, so they were never actually
   set in the website. ;( So, we fix that by passing the variable in the
   right template here.

2. kojihub didn't have a keepalive set on the backend. (but this is
   likely cosmetic since the problem is at the proxy layer). We fix
   this by adding one anyhow.

3. The pass thru anubis didn't have keepalive set right, so we do
   that in the template. This may fix other 502 issues with other
   applications also.

Calude used 57,508 tokens looking at all this. ;)

Assisted-By: claude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-11 11:09:55 -07:00
James Antill
28c056c4f7 people: Use ProxyPassReverse to rewrite redirects, and remove the port.
Signed-off-by: James Antill <james@and.org>
2026-05-11 13:43:38 -04:00
James Antill
6ef4d3c158 wiki.stg: Update to F44. 2026-05-11 13:43:33 -04:00
7ce80fab53
zabbix: debugging connections to agents
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 18:00:34 +01:00
a0b48d31b8
zabbix: update internal dns name to match correct value
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:57:29 +01:00
269c4fd64d
zabbix: configure agents to use internal dns for proxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:51:41 +01:00
7dad780f04
zabbix: debugging agent/proxy config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:29:54 +01:00
299e2e4005
zabbix: configure git checkout step to force
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:11:32 +01:00
035be95c3f
zabbix: configure openshift based agents config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 17:10:12 +01:00
850e51c1db
zabbix: debugging encryption config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:44:51 +01:00
769ffc446f
Add OpenVPN connectivity check & triggers to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-11 16:38:08 +01:00
eef6c7bc89
zabbix: enabling ZBX_TLSCONNECT on proxy
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:30:17 +01:00
d1595d1420
zabbix: update the task to checkout correct helm chart
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:24:20 +01:00
c3b29e947c
zabbix: fix typoes in template
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:18:27 +01:00
c098712064
zabbix: fix typo on helm values template.
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:16:24 +01:00
0b9ff51e27
zabbix: playbook to deploy the zabbix proxy in openshift
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 16:04:35 +01:00
9806794f83
zabbix-proxy: tls config for openshift based zabbix-agents
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 15:54:05 +01:00
418cca4d57
communishift: clean up project group vars
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:52:34 +01:00
06d732888f fix bodhi-valkey deployment again
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:40:06 +02:00
1371eae7b6 fix bodhi-valkey deployment
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:38:10 +02:00
c844df0cfb bodhi-stg: use Recreate strategy for bodhi-valkey
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:35:56 +02:00
d02937cc70 bodhi-stg: add bind setting to valkey call
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 14:30:16 +02:00
d99f6f030e
communishift: debugging efs config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:10:35 +01:00
2002267fcb
communishift: helper script for cleaning up removed group_vars projects
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 13:02:50 +01:00
d9aef74a12 bodhi-stg: update to F44 and install valkey-cli
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:55:20 +02:00
fc3816c7fe bodhi: fix duplicated setting in stg
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:48:01 +02:00
22005ff136 bodhi-stg: fix valkey conf
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:42:03 +02:00
9c2eeb276d bodhi-stg: redirect valkey log to stdout
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 13:38:26 +02:00
c6704f92dc
communishift: added cleanup playbook cleanup-administration-delete-projects.yml
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-11 12:27:28 +01:00
6b9752397d bodhi-valkey: change liveness timeout
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 10:13:14 +02:00
6812986bef bodhi-stg: use f44 for bodhi-valkey
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 10:09:30 +02:00
ec82c78f22 bodhi-stg: add secret definition
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-11 09:39:07 +02:00
8c28aba425 mdapi: fix image trigger annote order on deploy metadata
The `image.openshift.io/triggers` annotation was on the pod template metadata
instead of the deployment metadata, so OpenShift's image trigger controller
never detected ImageStream updates for auto-rollout.

Basically, when the MDAPI playbook was re-executed after the repository
`fedora-infra/ansible` was moved from Pagure to Forgejo, we have not had even
a single rollout, even with all the image builds.

Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-05-11 02:37:12 +00:00
ce9d8b3899 bodhi-valkey: use fully qualified image name
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 21:13:08 +02:00
4517eb2ed5 bodhi-stg: fix pvc template filename
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 10:29:20 +02:00
06fc965500 bodhi-stg: define bodhi-valkey-storage pvc
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
AI-assisted-by: Claude (Anthropic)
2026-05-10 10:18:34 +02:00
a58b8699ea bodhi-stg: remove docker entrypoint
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
AI-assisted-by: Claude (Anthropic)
2026-05-10 09:53:29 +02:00
5278566736 bodhi-stg: define bodhi-valkey image stream
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 09:27:57 +02:00
2dc6e6ec68 bodhi-stg: add a valkey pod
Signed-off-by: Mattia Verga <mattia.verga@tiscali.it>
2026-05-10 07:07:51 +00:00
72f01c98a7 amqp: Add queue for ELN->CS sync
This will be used for setting up automatic syncing of ELN builds into
CentOS Stream.

Fixes: infra/tickets#13226

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
2026-05-08 18:40:56 +00:00
ec0c9ed220 pkgs: allow access to archive of git repos fixed for fsck issues
See releng/tickets#11822
for background

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:56:17 -07:00
ef1592400d packager_alias: use lmdb for aliases
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:38:09 -07:00
511f16d9d6 base / postfix: fix handlers for postfix maps to use lmdb
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:22:29 -07:00
8ede1564c8 smtp-mm: add a fedoraproject transport to use the vpn
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-08 10:13:03 -07:00
ac4774b57e ipsilon01.stg: move to fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-07 15:58:13 -07:00
20428c57ee certgetter01: move to fedora 44
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-07 15:47:10 -07:00
5d88d1abb3
Nagios: remove Varnish/HAProxy items, these are already in Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 14:54:15 +01:00
c8abf8630e
Zabbix: move more http-* checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 14:21:51 +01:00
51e4282ff7
Migrate http-* proxy checks from Nagios to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-07 13:53:39 +01:00
1d53d6dd5a copr: do the powerful builds only for selected arches 2026-05-07 10:22:28 +02:00
9af0fa359e copr: more packages to powerful builder 2026-05-07 10:09:16 +02:00
b173990a47 resultsdb: specify correct registry to get image from
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 13:49:13 -07:00
565a59722b resultsdb / resultsdb-ci-listener: convert from deploymentconfig to deployment
This moves these two apps from deploymentconfig to deployment.

Assisted-by: calude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 20:37:07 +00:00
10ad96ad9d copr: more packages to powerful builder 2026-05-06 21:24:54 +02:00
e6491b5cba
communishift: Send email notification when disabling projects
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-06 20:11:29 +01:00
e4321ec9c3
communishift: Disable project playbook
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-05-06 19:58:48 +01:00
09af2093f5 bodhi / backend: quote tokens in sokpeo auth file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-06 11:06:54 -07:00
5b3385240a Update openqa Fedora release versions in host vars
Note I live upgrade these systems, so they've actually been on
F43 for months. This is just making the vars reflect reality (and
fixing it so if we do redeploy them, we deploy the right release).

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-06 10:45:09 -07:00
587aa356d0 fix: fixing metrix values for forge helm
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-05-06 16:52:07 +02:00
cc862368dd feat: add metrics for forge stage
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-05-06 16:09:21 +02:00
27e3392a20 Improve ansible-lint
Why ignore the hardcoded paths, let's just create symlink, so they are
found as they should be.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 13:16:59 +02:00
85f227197c [bodhi] Add missing vars file to playbook
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 11:46:34 +02:00
3d39e9ed5a ][bodhi] Update the bodhi version
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 09:34:23 +00:00
621d586acc [bodhi] Update for quay.io flatpaks
This adds authentication file for flatpak quay.io bots and also adds
quay.io to `container.destination_registry`.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-06 09:34:23 +00:00
ba172de77e roles/bodhi2/pungi: Update config_url with new forge location
See: https://forge.fedoraproject.org/atomic-desktops/config.git
2026-05-05 23:56:55 +02:00
49bec86025 blockerbugs: drop unneeded variables after Pagure->Forge migration
Related: quality/blockerbugs#296
2026-05-05 20:47:25 +00:00
0d4d72dadf blockerbugs: drop a "short-term patch" after 5 years 2026-05-05 20:47:25 +00:00
15a6768ad7
Zabbix: Update IPA template to include healthcheck items/triggers
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-05-05 15:01:16 +01:00
72baeea321
Add a patch for Pagure
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-05-05 11:51:48 +02:00
0506d3a645 [postfix] Obfuscate the IP on smtp-auth server
This will update configuration to clean Received header from e-mail
forwarded by smtp-auth-iso01 server to prevent leaking of internal IPs.
See infra/tickets#12835

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-05 07:52:05 +00:00
Nikita Dubrovskii
66580813a6 coreos-ci: add azukku as appowners 2026-05-05 07:37:33 +00:00
54db5a3f4a forge: add group team mappings for the hummingbird org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 14:39:29 +10:00
40060e7e88 forge: add group team mappings for the matrix org.
resolves: forge/forge#537

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 14:14:41 +10:00
b0f1e9a91d forge: add group team mappings for the magazine organization
related: forge/forge#551

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-05-05 13:40:09 +10:00
1bdd2c4529 ai-review: set include_mr_summary false for shorter reviews
This sets a config option that gets ai-code-review to generate
shorter review text. It skips the MR Summary section and just
posts the Detailed Code Review section.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-05-04 14:02:53 -07:00
a00af9f5cd openshift: adjust rollout in playbooks for deployment instead of deploymentconfig
Since we have moved (almost everything) to deployment, we need to adjust
adjust these rollout commands to use deployment instead.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:39:23 -07:00
cc8e259360 compose-tracker: move stray playbook to the right place
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:20:20 -07:00
d0a17fb7cf compose-tracker: move to deployment from deploymentconfig
This is another pull to move compose-tracker from deploymentconfig to
deployment.

Assisted by: claude

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:12:54 -07:00
81e1871023 waiverdb: add env to db-upgrade container
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-04 13:02:27 -07:00
e3e74bc722 waiverdb: fix deployment reference
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-04 19:57:20 +00:00
e86df4d91b waiverdb: moved deploymentconfig.yml.j2 to deployment.yml.j2
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-05-04 19:57:20 +00:00
Jakub Kadlcik
ea2f954a44 copr: fix the Pulp redirect script for devel repositories
We dont have a ticket but the problem was discovered on the @asahi/kernel
project and reported by @jannau. The use-case is

> We use the devel repositories for fedora asahi remix to have a bodhi like
> experience for copr projects

and technically, they enable the repositores on user machines like this:

26cab83/f/asahi-repos.spec (_149-160)
2026-05-04 19:00:31 +00:00
James Antill
ab631bed2e Merge branch 'upstream' into HEAD
* upstream: (551 commits)

Signed-off-by: James Antill <james@and.org>
2026-05-02 20:02:18 -04:00
James Antill
3821ea36b5 Cleanup nft merge. Chg osbuildapi and nft_custom_rules to use nft_table_filter.
Signed-off-by: James Antill <james@and.org>
2026-05-01 15:29:04 -04:00
James Antill
ba4470365e Merge branch 'main' into nftables
* main: (2174 commits)

Signed-off-by: James Antill <james@and.org>
2026-05-01 12:01:48 -04:00
James Antill
ae9230c37f Cleanup the nftables files, using includes.
Rename the tables to be cle_ prefixed/unique. This allows people to run
cle nftables and firewalld etc.

Signed-off-by: James Antill <james@and.org>
2026-05-01 11:27:07 -04:00
400 changed files with 6310 additions and 2991 deletions

View file

@ -11,5 +11,7 @@ jobs:
uses: quality/workflows/.forgejo/workflows/ai-review.yml@main
with:
pr: ${{ forgejo.event.pull_request.number }}
config: |
include_mr_summary: false
secrets:
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}

View file

@ -54,6 +54,11 @@ jobs:
with:
fetch-depth: 0
- name: Create symlink to overcome absolute paths
run: |
mkdir -p /srv/web/infra/
ln -s /workspace/infra/ansible /srv/web/infra/ansible
- name: Get changed files
id: changed-files
uses: https://code.forgejo.org/tj-actions/changed-files@v47

View file

@ -1,9 +1,10 @@
[epel]
name=Extras Packages for Enterprise Linux $releasever - $basearch
# This is a bit too magic, esp. as we are using the infra. repo. and explicitly
# point to a 10.x variant ... might as well do the same here.
# We aren't using mirrormanager here, but pointing direct to our repos
# So, we want to just point to '10' here and depend on the link that exists
# to point us to the newest minor release.
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10.1/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/10/Everything/$basearch/
enabled=1
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
@ -11,7 +12,7 @@ gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10
[epel-testing]
name=Extras Packages for Enterprise Linux $releasever - $basearch
# baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/$releasever${releasever_minor:+z}/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10.1/Everything/$basearch/
baseurl=https://infrastructure.fedoraproject.org/pub/epel/testing/10/Everything/$basearch/
enabled=0
gpgcheck=1
gpgkey=https://infrastructure.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-10

View file

@ -12,24 +12,25 @@ gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg
enabled=1
gpgcheck=1
# NOTE: When you change the 10.x here also change it in the epel10.repo file.
# These are not using mirrormanager, so point to '10' which will use the link
# to the latest minor release.
[rhel10-BaseOS]
name = rhel10 BaseOS $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/baseos
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/baseos
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-AppStream]
name = rhel10 AppStream $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/appstream
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/appstream
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1
[rhel10-CRB]
name = rhel10 CodeReadyBuilder $basearch
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10.1/repos/$basearch/crb
baseurl=https://infrastructure.fedoraproject.org/repo/rhel/rhel10/10/repos/$basearch/crb
gpgkey = file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta,file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
enabled=1
gpgcheck=1

View file

@ -90,13 +90,13 @@ RewriteRule ^/gfs2-utils/report https://pagure.io/gfs2-utils/issues [R=301]
RewriteRule ^/gfs2-utils/ticket/(.*) https://pagure.io/gfs2-utils/issue/$1 [R=301]
RewriteRule ^/gfs2-utils https://pagure.io/gfs2-utils [R=301]
RewriteRule ^/elections/report https://pagure.io/elections/issues [R=301]
RewriteRule ^/elections/ticket/(.*) https://pagure.io/elections/issue/$1 [R=301]
RewriteRule ^/elections https://pagure.io/elections [R=301]
RewriteRule ^/elections/report https://forge.fedoraproject.org/apps/elections/issues [R=301]
RewriteRule ^/elections/ticket/(.*) https://forge.fedoraproject.org/apps/elections/issues/$1 [R=301]
RewriteRule ^/elections https://forge.fedoraproject.org/apps/elections [R=301]
RewriteRule ^/fedocal/report https://pagure.io/fedocal/issues [R=301]
RewriteRule ^/fedocal/ticket/(.*) https://pagure.io/fedocal/issue/$1 [R=301]
RewriteRule ^/fedocal https://pagure.io/fedocal [R=301]
RewriteRule ^/fedocal/report https://forge.fedoraproject.org/apps/fedocal/issues [R=301]
RewriteRule ^/fedocal/ticket/(.*) https://forge.fedoraproject.org/apps/fedocal/issue/$1 [R=301]
RewriteRule ^/fedocal https://forge.fedoraproject.org/apps/fedocal [R=301]
RewriteRule ^/FedoraReview/report https://pagure.io/FedoraReview/issues [R=301]
RewriteRule ^/FedoraReview/ticket/(.*) https://pagure.io/FedoraReview/issue/$1 [R=301]

View file

@ -80,13 +80,13 @@
action: service name=network state=restarted
- name: Rebuild postfix transport
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/transport
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/transport
- name: Rebuild postfix bysender
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/bysender
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/bysender
- name: Rebuild postfix tls_policy
ansible.builtin.command: /usr/sbin/postmap /etc/postfix/tls_policy
ansible.builtin.command: /usr/sbin/postmap lmdb:/etc/postfix/tls_policy
- name: Restart postfix
service: name=postfix state=restarted

View file

@ -297,6 +297,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
[buildhw_stg]
buildhw-p10-01.stg.rdu3.fedoraproject.org
@ -323,6 +324,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
[buildhw_stg_rdu3]
buildhw-p10-01.stg.rdu3.fedoraproject.org
@ -399,10 +401,9 @@ buildvm-ppc64le-30.rdu3.fedoraproject.org
buildvm-ppc64le-31.rdu3.fedoraproject.org
buildvm-ppc64le-32.rdu3.fedoraproject.org
[bkernel]
buildhw-x86-01.rdu3.fedoraproject.org
[secureboot]
buildhw-x86-01.rdu3.fedoraproject.org
buildhw-a64-01.rdu3.fedoraproject.org
buildhw-x86-02.rdu3.fedoraproject.org
buildhw-a64-02.rdu3.fedoraproject.org
@ -465,7 +466,7 @@ buildvm
buildvm_aarch64
buildvm_ppc64le
buildvm_s390x
bkernel
secureboot
[builders_stg:children]
buildhw_ppc64le_stg

View file

@ -46,6 +46,7 @@ aarch64-test02.fedorainfracloud.org
# This is not in aws, but here is good enough for now
ppc64le-test.fedorainfracloud.org
ppc64le-test02.fedorainfracloud.org
s390x-test01.fedorainfracloud.org
logdetective01.fedorainfracloud.org
logdetective02.fedorainfracloud.org

View file

@ -44,38 +44,12 @@ communishift_projects:
communishift-admins:
name: communishift-admins
do_not_delete: true # Marked do not delete 2024-11-25 - dkirwan
communishift-avant:
name: communishift-avant
cpu_limits: 2
cpu_requests: 2
memory_limits: 3Gi
memory_requests: 1.5Gi
pods: 6
storage_requests: 10Gi
communishift-commops-analytics:
name: communishift-commops-analytics
communishift-commops-datanom:
name: communishift-commops-datanom
communishift-discoursepolls:
name: communishift-discoursepolls
communishift-eventbot:
name: communishift-eventbot
communishift-fedora-coreos-ai-helpers:
name: communishift-fedora-coreos-ai-helpers
do_not_delete: true # Marked do not delete 2025-12-18 - dkirwan infra 12996
communishift-fedora-review-service:
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
name: communishift-fedora-review-service
communishift-forgejo:
name: communishift-forgejo
communishift-fossology:
name: communishift-fossology
communishift-gitlabce:
name: communishift-gitlabce
communishift-jitsi:
name: communishift-jitsi
communishift-lightspeed-build:
name: communishift-lightspeed-build
communishift-log-detective:
name: communishift-log-detective
do_not_delete: true # Marked do not delete 2024-10-21 - dkirwan
@ -83,31 +57,23 @@ communishift_projects:
memory_requests: 4Gi
storage_requests: 10Gi
pods: 6
communishift-mattdm:
name: communishift-mattdm
communishift-metrics:
name: communishift-metrics
communishift-ocm:
name: communishift-ocm
communishift-openscanhub:
name: communishift-openscanhub
cpu_limits: 2
cpu_requests: 2
memory_limits: 4Gi
memory_requests: 2Gi
pods: 16
communishift-planet:
name: communishift-planet
communishift-standupbot:
name: communishift-standupbot
do_not_delete: true # Marked do not delete 2026-05-01 - dkirwan
communishift-weekly-bootc:
do_not_delete: true # Marked do not delete 2024-11-26. Needed until end of bootc initative. - dkirwan
name: communishift-weekly-bootc
communishift-release-schedule-planner:
name: communishift-release-schedule-planner
communishift-draft-share:
name: communishift-draft-share
communishift-happinesspackets:
name: communishift-happinesspackets
communishift-coreos-agent:
name: communishift-coreos-agent
communishift-rag-magazine-guidelines:
name: communishift-rag-magazine-guidelines
storage_requests: 15Gi
communishift-public-inbox-poc:
name: communishift-public-inbox-poc
# true or false if we are or are not a copr build virthost.
# Default to false
copr_build_virthost: false
@ -188,6 +154,12 @@ nftables: True
nft_custom6_rules: []
nft_custom_rules: []
nft_nat_rules: []
# Table names for nft
# Note that the ip/ip6 prefix here means we only look at IPv4/IPv6 packets.
nft_table_filter: "ip cle_infra_filter"
nft_table_nat: "ip cle_infra_nat"
nft_table_raw: "ip cle_infra_raw"
nft_table6_filter: "ip6 cle_infra_filter"
# usually we do not want to enable nested virt, only on some virthosts
nested: false
network_allow_restart: yes

View file

@ -10,7 +10,7 @@ ansible_ifcfg_allowlist:
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: autosign
ipa_client_shell_groups:
- sysadmin-releng

View file

@ -2,5 +2,5 @@
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: autosign

View file

@ -8,8 +8,8 @@
#
custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT']
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
- 'add rule ip filter INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
#
# This host is externally reachable
#

View file

@ -19,8 +19,8 @@ batcave_ipa_client_shell_groups: []
#
custom_rules: ['-A INPUT -s 192.168.100/24 -j REJECT --reject-with icmp-host-prohibited', '-A INPUT -s 10.0.0.0/8 -p udp -m udp --dport 123 -j ACCEPT']
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
- 'add rule ip filter INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.100.0/24 counter reject with icmp type host-prohibited'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.0.0.0/8 udp dport 123 counter accept'
ipa_client_shell_groups: "{{ (bastion_ipa_client_shell_groups + batcave_ipa_client_shell_groups) | sort | unique }}"
#
# allow a bunch of sysadmin groups here so they can access internal stuff

View file

@ -4,8 +4,8 @@ ansible_base: /srv/web/infra
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
#
# This host is externally reachable
#

View file

@ -7,7 +7,7 @@ bodhi_message_routing_keys:
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.5.125.71 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.5.125.71 tcp sport 44334 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.5.125.71 tcp sport 44334 counter accept']
host_group: bodhi2
ipa_client_shell_groups:
- sysadmin-bodhi

View file

@ -9,7 +9,7 @@ bodhi_message_routing_keys:
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
# this is sign-bridge01.rdu3 ip 10.16.169.120
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.16.169.120 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.120 tcp sport 44334 counter accept']
host_group: bodhi2
ipa_client_shell_groups:
- sysadmin-bodhi

View file

@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
# Groups and individual hosts should ovveride them with specific info.
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/ppc64le/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/44/Server/ppc64le/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 150000
main_bridge: br0

View file

@ -13,7 +13,7 @@ koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
koji_instance: "primary"
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/43/Server/s390x/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora-secondary/releases/44/Server/s390x/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora-s390x
virt_install_command: "{{ virt_install_command_s390x_one_nic_unsafe }}"
lvm_size: 100000

View file

@ -18,7 +18,7 @@ koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
# Groups and individual hosts should ovveride them with specific info.
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 150000
max_mem_size: "{{ mem_size }}"

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
lvm_size: 20000
mem_size: 2048
num_cpus: 2

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
lvm_size: 20000
mem_size: 2048
num_cpus: 2

View file

@ -19,12 +19,12 @@ backend_base_url: "https://download.copr.fedorainfracloud.org"
builders:
# max|spawn_concurrently|prealloc
aws:
aarch64: [8, 2, 1]
x86_64: [50, 10, 20]
aarch64: [50, 10, 1]
x86_64: [50, 10, 1]
# put here the number -1 of the actuall reserved instances
aws_reserved:
aarch64: [50, 20, 33]
x86_64: [70, 20, 52]
aarch64: [55, 20, 55]
x86_64: [70, 20, 70]
aws_reserved_powerful:
x86_64: [2, 2, 2]
aws_powerful:

View file

@ -53,6 +53,9 @@ copr_backend_data_2_raid1_volumes:
- nvme-Amazon_Elastic_Block_Store_vol0f226a7163d28d8fd-part1
- nvme-Amazon_Elastic_Block_Store_vol07293869d85a750b8-part1
rpmeta_enabled: true
rpmeta_hostname: rpmeta.fedoraproject.org
notes: |
Provide the backend for copr (3rd party packages)
* Backend: Management of copr cloud infrastructure (OpenStack).

View file

@ -49,6 +49,9 @@ copr_backend_data_2_raid1_volumes:
- nvme-Amazon_Elastic_Block_Store_vol0ce8220e998e2e32a-part1
- nvme-Amazon_Elastic_Block_Store_vol0038e042c49987b82-part1
rpmeta_enabled: true
rpmeta_hostname: rpmeta.stg.fedoraproject.org
notes: |
Provide the testing environment of copr's backend
This host is the testing environment for the cloud infrastructure of copr's backend

View file

@ -47,13 +47,13 @@ nbde_client_bindings:
libvirt_host: "{{ inventory_hostname }}"
nft_custom_rules:
- add rule ip filter INPUT iifname virbr0 udp dport bootps accept
- add rule ip filter INPUT iifname virbr0 udp dport 53 accept
- add rule ip filter INPUT iifname virbr0 tcp dport ssh accept
- add rule ip filter FORWARD iifname "virbr0" oif != "virbr0" counter accept
- add rule ip filter FORWARD iifname "virbr0" ct state new counter accept
- add rule ip filter FORWARD ct state established,related counter accept
- add rule ip filter FORWARD ip protocol icmp counter accept
- add rule {{nft_table_filter}} INPUT iifname virbr0 udp dport bootps accept
- add rule {{nft_table_filter}} INPUT iifname virbr0 udp dport 53 accept
- add rule {{nft_table_filter}} INPUT iifname virbr0 tcp dport ssh accept
- add rule {{nft_table_filter}} FORWARD iifname "virbr0" oif != "virbr0" counter accept
- add rule {{nft_table_filter}} FORWARD iifname "virbr0" ct state new counter accept
- add rule {{nft_table_filter}} FORWARD ct state established,related counter accept
- add rule {{nft_table_filter}} FORWARD ip protocol icmp counter accept
zabbix_macros:
CPU.UTIL.CRIT: 100

View file

@ -9,10 +9,10 @@ custom_rules:
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 172.30.2.105 --dport 5167 -j ACCEPT'
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 52.44.175.77 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.105 tcp dport 5167 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 52.44.175.77 tcp dport 80 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 52.44.175.77 tcp dport 5167 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.105 tcp dport 80 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.105 tcp dport 5167 counter accept'
freezes: false
tcp_ports: [22,
# node_exporter/prometheus

View file

@ -9,10 +9,10 @@ custom_rules:
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 80 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 18.208.10.131 --dport 5167 -j ACCEPT'
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 172.30.2.11 tcp dport 5167 counter accept'
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 80 counter accept'
- 'add rule ip filter INPUT ip saddr 18.208.10.131 tcp dport 5167 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.11 tcp dport 80 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 172.30.2.11 tcp dport 5167 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 18.208.10.131 tcp dport 80 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 18.208.10.131 tcp dport 5167 counter accept'
freezes: false
tcp_ports: [22,
# node_exporter/prometheus

View file

@ -115,7 +115,7 @@ ipa_host_group_desc: Download servers
nagios_Check_Services:
swap: false
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 212.143.41.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 212.143.41.0/24 counter reject'
primary_auth_source: ipa
zabbix_macros:
'APACHE.STATUS.PORT': 443 # Proxies appear to ignore port 80 for apache-status

View file

@ -1,7 +1,7 @@
---
# Define resources for this group of hosts here.
custom_rules: ['-A INPUT -p udp -m udp -s 10.16.0.0/16 --dport 53 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.0.0/16 udp dport 53 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.0.0/16 udp dport 53 counter accept']
host_backup_targets: ['/var/lib/ipa/backup', '/var/log/dirsrv/slapd-FEDORAPROJECT-ORG']
ipa_client_shell_groups:
- sysadmin-accounts

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipatuura
ipa_host_group_desc: IPA-tuura SCIM application
ipa_client_shell_groups:

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipsilon_db_host: "db-fas01.rdu3.fedoraproject.org"

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipa_client_shell_groups:

View file

@ -3,8 +3,8 @@
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_host_group: ipsilon
ipa_host_group_desc: Ipsilon SSO application
ipa_client_shell_groups:

View file

@ -1,6 +1,6 @@
---
custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.122.0/24 --dport 2049 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 192.168.122.0/24 tcp dport 2049 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 192.168.122.0/24 tcp dport 2049 counter accept']
freezes: false
ipa_client_shell_groups:
- sysadmin-kernel

View file

@ -5,8 +5,8 @@ custom_rules: [
'-A INPUT -d 224.0.0.0/8 -j ACCEPT', '-A INPUT -p vrrp -j ACCEPT']
# Needed for keepalived
nft_custom_rules:
- 'add rule ip filter INPUT ip daddr 224.0.0.0/8 counter accept'
- 'add rule ip filter INPUT ip protocol vrrp counter accept'
- 'add rule {{nft_table_filter}} INPUT ip daddr 224.0.0.0/8 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip protocol vrrp counter accept'
docker_registry: "candidate-registry.fedoraproject.org"
ipa_client_shell_groups:
- sysadmin-releng

View file

@ -6,8 +6,8 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 10.16.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
# Need for rsync from log01 for logs.
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
ipa_client_shell_groups:
- sysadmin-noc
- sysadmin-releng

View file

@ -9,7 +9,7 @@ ipa_client_sudo_groups:
- sysadmin-web
ipa_host_group: memcached
ipa_host_group_desc: Distributed Memory Caching service
lvm_size: 20000
lvm_size: 25000
mem_size: 8192
num_cpus: 2
primary_auth_source: ipa

View file

@ -9,7 +9,7 @@ ipa_client_sudo_groups:
- sysadmin-web
ipa_host_group: memcached
ipa_host_group_desc: Distributed Memory Caching service
lvm_size: 20000
lvm_size: 25000
mem_size: 4096
num_cpus: 1
# for systems that do not match the above - specify the same parameter in

View file

@ -2,9 +2,9 @@
# uses interface definition from host vars
custom_rules: ['-A FORWARD -i br0 -j ACCEPT', '-A FORWARD -m state -i {{ openqa_tap_iface }} -o br0 --state RELATED,ESTABLISHED -j ACCEPT', '-A INPUT -i br0 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter FORWARD iifname "br0" counter accept'
- 'add rule ip filter FORWARD iifname "{{ openqa_tap_iface }}" oifname "br0" ct state related,established counter accept'
- 'add rule ip filter INPUT iifname "br0" counter accept'
- 'add rule {{nft_table_filter}} FORWARD iifname "br0" counter accept'
- 'add rule {{nft_table_filter}} FORWARD iifname "{{ openqa_tap_iface }}" oifname "br0" ct state related,established counter accept'
- 'add rule {{nft_table_filter}} INPUT iifname "br0" counter accept'
# for iptables rules...maybe other stuff in future? both staging
# and prod workers are in this group
host_group: openqa-tap-workers

View file

@ -6,10 +6,10 @@ custom_rules: [
'-A INPUT -p tcp --dport 22623 --src 38.145.48.0/27 -j ACCEPT']
nft_custom_rules:
# Needed for keepalived
- 'add rule ip filter INPUT ip daddr 224.0.0.0/8 counter accept'
- 'add rule ip filter INPUT ip protocol vrrp counter accept'
- 'add rule {{nft_table_filter}} INPUT ip daddr 224.0.0.0/8 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip protocol vrrp counter accept'
# machinectl api
- 'add rule ip filter INPUT ip saddr 38.145.48.0/27 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 38.145.48.0/27 tcp dport 22623 counter accept'
datacenter: cloud
host_group: cloud
lvm_size: 20000

View file

@ -8,35 +8,35 @@ custom_rules: [
'-A INPUT -s 47.76.99.127/32 -j REJECT'
]
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 81.69.171.38 counter reject'
- 'add rule ip filter INPUT ip saddr 175.24.248.206 counter reject'
- 'add rule ip filter INPUT ip saddr 47.76.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.80.0.0/13 counter reject'
- 'add rule ip filter INPUT ip saddr 47.74.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 66.249.64.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.0.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.224.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.41.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.163.8.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.156.0.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.133.32.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.128.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.37.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.153.192.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.32.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.156.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.163.0.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 14.153.15.174 counter reject'
- 'add rule ip filter INPUT ip saddr 47.246.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.236.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 146.174.128.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 154.222.253.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 81.69.171.38 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 175.24.248.206 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.76.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.80.0.0/13 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.74.0.0/15 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.64.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.0.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.224.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.41.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.8.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.0.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.133.32.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.128.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.37.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.153.192.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.32.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.0.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 14.153.15.174 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.246.0.0/16 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.236.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 146.174.128.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 154.222.253.0/24 counter reject'
# For the MOTD
db_backup_dir: ['/backups']
dbs_to_backup: ['pagure']
@ -72,6 +72,13 @@ vpn: true
zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_macros:
'VFS.DEV.WRITE.AWAIT.WARN': 60 # frequently saturated writes overnight
# Hotfixes
pagure_patches:
- b50d32b7c92f131ebcc3b633de6c6e91e28297ec
- 5529
- readme-include
- 26bc9746
- 5553
notes: |
Run the pagure instances for fedora

View file

@ -41,6 +41,13 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
zabbix_server: "{{ zabbix_hostname }}"
zabbix_auth_key: "{{ zabbix_apikey }}" # ansible-private repo
zabbix_tls_psk: "{{ zabbix_tls_prod_psk }}" # in ansible-private repo, pagure-stg is weird...
# Hotfixes
pagure_patches:
- b50d32b7c92f131ebcc3b633de6c6e91e28297ec
- 5529
- readme-include
- 26bc9746
- 5553
notes: |
Run the pagure instances for fedora

View file

@ -6,7 +6,7 @@ clamscan_paths:
# For the MOTD
# Neeed for rsync from log01 for logs.
custom_rules: ['-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT']
nft_custom_rules: ['add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept']
git_basepath: /
git_daemon_user: nobody
git_port: 9418

View file

@ -34,90 +34,91 @@ custom_rules: [
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.128 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.163.129 -j ACCEPT']
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 81.69.171.38 counter reject'
- 'add rule ip filter INPUT ip saddr 175.24.248.206 counter reject'
- 'add rule ip filter INPUT ip saddr 47.76.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.80.0.0/13 counter reject'
- 'add rule ip filter INPUT ip saddr 47.74.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 66.249.64.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.0.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.224.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.41.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.163.8.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.156.0.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.133.32.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 43.134.128.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.37.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.153.192.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.159.32.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 43.156.64.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 43.163.0.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 14.153.15.174 counter reject'
- 'add rule ip filter INPUT ip saddr 47.246.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.236.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 152.53.36.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 66.249.69.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 159.138.218.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 188.75.180.46/32 counter reject'
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
- 'add rule ip filter INPUT ip saddr 45.78.192.0/18 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.0.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.32.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.40.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.48.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.64.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.80.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.88.0/22 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.92.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.95.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.96.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.98.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.128.0/19 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.160.0/20 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.176.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.184.0/21 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.185.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 101.47.186.0/23 counter reject'
- 'add rule ip filter INPUT ip saddr 34.159.191.146/32 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 81.69.171.38 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 175.24.248.206 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.76.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.80.0.0/13 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.74.0.0/15 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.64.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.0.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.224.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.41.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.8.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.0.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.128.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.133.32.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.134.128.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.37.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.153.192.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.159.32.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.156.64.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 43.163.0.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 14.153.15.174 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.246.0.0/16 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.236.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 152.53.36.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 66.249.69.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 159.138.218.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 188.75.180.46/32 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 2.57.121.144/32 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 45.78.192.0/18 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.0.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.32.0/21 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.40.0/21 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.48.0/20 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.64.0/20 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.80.0/21 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.88.0/22 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.92.0/23 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.95.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.96.0/23 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.98.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.128.0/19 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.160.0/20 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.176.0/21 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.184.0/21 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.185.0/24 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 101.47.186.0/23 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 34.159.191.146/32 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 208.78.212.5/32 counter reject'
nft_custom_rules:
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 209.132.181.102 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 209.132.181.102 tcp dport 873 counter accept'
# allow varnish from localhost
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.120 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.121 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.122 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.123 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.124 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.125 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.126 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.65 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.127 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.128 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.129 tcp dport 22623 counter accept'
external: true
ipa_client_shell_groups:
- fi-apprentice
@ -131,7 +132,9 @@ ipa_host_group_desc: Proxies between internal hosts and the Internet
lvm_size: 100000
# This is used in the httpd.conf to determine the value for serverlimit and
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
maxrequestworkers: 3200
# However, due to lots of very transitory connections, bumping up to 4000
# to give some head room.
maxrequestworkers: 4000
mem_size: 8192
nagios_Check_Services:
swap: false

View file

@ -11,44 +11,44 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6081 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.16.163.0/24 --dport 6081 -j ACCEPT',
'-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.115 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.116 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.117 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.118 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.119 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.120 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.121 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.122 -j ACCEPT', '-A INPUT -p tcp -m tcp --dport 22623 -s 10.16.166.123 -j ACCEPT']
nft_block_rules:
- 'add rule ip filter INPUT ip saddr 2.57.121.144/32 counter reject'
- 'add rule {{nft_table_filter}} INPUT ip saddr 2.57.121.144/32 counter reject'
nft_custom_rules:
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# allow varnish from localhost
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.50 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.50 tcp dport 873 counter accept'
# allow varnish from localhost
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 127.0.0.1 tcp dport 6082 counter accept'
# also allow varnish from internal for purge requests
- 'add rule ip filter INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.0/24 tcp dport 6081 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.115 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.116 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.117 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.118 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.119 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.120 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.121 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.122 tcp dport 22623 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.123 tcp dport 22623 counter accept'
external: true
ipa_client_shell_groups:
- fi-apprentice
@ -63,7 +63,9 @@ ipa_host_group_desc: Proxies between internal hosts and the Internet
lvm_size: 100000
# This is used in the httpd.conf to determine the value for serverlimit and
# maxrequestworkers. On proxies with 8 cpus it should be 300 * 8 = 3200
maxrequestworkers: 3200
# However, due to lots of very transitory connections, bumping up to 4000
# to give some head room.
maxrequestworkers: 4000
mem_size: 49152
num_cpus: 8
ocp_masters_stg:

View file

@ -9,16 +9,16 @@ custom_rules: [
]
nft_custom_rules:
# Neeed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Inter-node traffic
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
# In RDU3
- 'add rule ip filter INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.78 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.79 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.80 tcp dport 25672 counter accept'
ipa_host_group: rabbitmq
ipa_host_group_desc: RabbitMQ service
ipa_shell_groups:

View file

@ -9,16 +9,16 @@ custom_rules: [
]
nft_custom_rules:
# Neeed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Inter-node traffic
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
# In RDU3
- 'add rule ip filter INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.78 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.79 tcp dport 25672 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.80 tcp dport 25672 counter accept'
ipa_host_group: rabbitmq
ipa_host_group_desc: RabbitMQ service
ipa_shell_groups:

View file

@ -3,8 +3,8 @@ custom_rules:
- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 2049 -j ACCEPT'
- '-A INPUT -p tcp -m tcp -s 10.5.78.11 --dport 5432 -j ACCEPT'
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.5.78.11 tcp dport 2049 counter accept'
- 'add rule ip filter INPUT ip saddr 10.5.78.11 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.5.78.11 tcp dport 2049 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.5.78.11 tcp dport 5432 counter accept'
env: production
freezes: false
ipa_client_shell_groups:

View file

@ -69,3 +69,5 @@ zabbix_tls_psk: "{{ zabbix_tls_stg_psk }}" # in ansible-private repo
zabbix_inventory:
# Env is not a valid key, so use this field for environment
deployment_status: staging
zabbix_macros:
'KOJI.HOST': koji.stg.fedoraproject.org

View file

@ -10,13 +10,13 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 10.16.163.35 --dport 5050 -j ACCEPT']
nft_custom_rules:
# Needed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Needed to let nagios on noc01 and noc02 pipe alerts to zodbot here
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.20 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.20 tcp dport 5050 counter accept'
# batcave01 also needs access to announce commits.
- 'add rule ip filter INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
deployment_type: prod
ipa_client_shell_groups:
- fi-apprentice

View file

@ -10,14 +10,14 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 10.16.163.35 --dport 5050 -j ACCEPT']
nft_custom_rules:
# Neeed for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# Needed to let nagios on noc01 and noc02 (noc01.stg) pipe alerts to zodbot here
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule ip filter INPUT ip saddr 152.19.134.192 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 152.19.134.192 tcp dport 5050 counter accept'
# batcave01 also needs access to announce commits.
- 'add rule ip filter INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.35 tcp dport 5050 counter accept'
deployment_type: stg
ipa_client_shell_groups:
- fi-apprentice

View file

@ -23,6 +23,7 @@ buildhw-x86-09.rdu3.fedoraproject.org
buildhw-x86-10.rdu3.fedoraproject.org
buildhw-x86-12.rdu3.fedoraproject.org
buildhw-x86-13.rdu3.fedoraproject.org
buildhw-x86-14.rdu3.fedoraproject.org
## Build vm hosts
bvmhost-x86-01.rdu3.fedoraproject.org
bvmhost-x86-02.rdu3.fedoraproject.org

View file

@ -1,6 +1,6 @@
---
bmc:
ip_address: 10.16.160.25
ip_address: 10.16.160.87
ping: true
http: true
https: true

View file

@ -0,0 +1,70 @@
---
bmc:
ip_address: 10.16.160.88
ping: true
http: true
https: true
br0_ipv4_ip: 10.16.169.44
br0_ipv4_gw: 10.16.169.254
br0_ipv4_nm: 24
datacenter: rdu3
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
mac0: b4:45:06:fb:84:2e
mac1: b4:45:06:fb:84:2f
mac2: 5c:6f:69:7f:ba:30
mac3: 5c:6f:69:7f:ba:31
network_connections:
# Bridge profile
- name: br0
state: up
type: bridge
mtu: 1500
autoconnect: yes
ip:
address:
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
# Bond profile
- name: bond0
type: bond
interface_name: bond0
mtu: 1500
controller: br0
bond:
mode: 802.3ad
# Port profile for the 1st Ethernet device
- name: bond0-port1
mac: "{{ mac2 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# Port profile for the 2nd Ethernet device
- name: bond0-port2
mac: "{{ mac3 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: ""
date_hw_purchase: ""
hardware: PowerEdge R450
location: RDU3
oob_ip: "{{ bmc.ip_address }}"
serialno_a: F922FZ3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.47
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
mem_size: 4096
vmhost: vmhost-x86-04.rdu3.fedoraproject.org

View file

@ -4,17 +4,17 @@
#
nft_custom_rules:
# Openshift nodes (egress policy will block connection from non-authorized projects)
- 'add rule ip filter INPUT ip saddr 10.16.163.69 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.70 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.71 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.72 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.73 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.69 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.70 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.71 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.72 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.73 tcp dport 5432 counter accept'
# noc01 needs to connect to check the db
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
# Ipsilon VMs
- 'add rule ip filter INPUT ip saddr 10.16.163.105 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.106 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.117 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.105 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.106 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.117 tcp dport 5432 counter accept'
# This is a generic list, monitored by collectd
databases:
- fas2

View file

@ -5,7 +5,7 @@
#
# TODO: lock it down more
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.166.0/24 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.166.0/24 tcp dport 5432 counter accept'
# This is a generic list, monitored by collectd
databases:
- fas2

View file

@ -3,10 +3,10 @@
# Only allow postgresql access from the frontend node.
#
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.169.104 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.169.105 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.169.10 tcp dport 5432 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.104 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.105 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.169.10 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.10 tcp dport 5432 counter accept'
# This is a generic list, monitored by collectd
databases:
- koji

View file

@ -2,7 +2,7 @@
#
# Only allow postgresql access from the frontend node.
#
nft_custom_rules: ['add rule ip filter INPUT ip saddr 10.16.167.64 tcp dport 5432 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT ip saddr 10.16.167.64 tcp dport 5432 counter accept']
# This is a generic list, monitored by collectd
databases:
- koji

View file

@ -2,7 +2,7 @@
# This is a generic list, monitored by collectd
custom_rules: ['-A INPUT -p tcp -m tcp -s 10.16.172.21 --dport 5432 -j ACCEPT']
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 10.16.172.21 tcp dport 5432 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.172.21 tcp dport 5432 counter accept'
databases:
- koji
datacenter: rdu3

View file

@ -2,7 +2,7 @@
#
# We should narrow this down at some point
#
nft_custom_rules: ['add rule ip filter INPUT tcp dport 5432 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
# This is a generic list, monitored by collectd
databases:
- anitya

View file

@ -2,7 +2,7 @@
#
# We should narrow this down at some point
#
nft_custom_rules: ['add rule ip filter INPUT tcp dport 5432 counter accept']
nft_custom_rules: ['add rule {{nft_table_filter}} INPUT tcp dport 5432 counter accept']
# This is a generic list, monitored by collectd
databases:
- askfedora

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.109
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
sar_script_user: root
virt_install_command: "{{ virt_install_command_one_nic }}"

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.166.254
eth0_ipv4_ip: 10.16.166.62
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
vmhost: vmhost-x86-03.stg.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -0,0 +1,46 @@
---
br0_ipv4: 67.219.144.67
br0_ipv4_gw: 67.219.144.65
br0_ipv4_nm: 29
br0_ipv6: "2604:1580:fe00:0:dead:beef:cafe:fe02"
br0_ipv6_gw: "2604:1580:fe00::1"
br0_ipv6_nm: 64
br0_port0_mac: "{{ mac1 }}"
datacenter: dedicatedsolutions
dns1: 8.8.8.8
dns2: 8.8.4.4
dns_search1: "vpn.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
has_ipv6: yes
mac1: 6c:c2:17:2b:73:40
network_connections:
- autoconnect: yes
ip:
address:
- "{{ br0_ipv4 }}/{{ br0_ipv4_nm }}"
- "{{ br0_ipv6 }}/{{ br0_ipv6_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
gateway6: "{{ br0_ipv6_gw }}"
name: br0
state: up
type: bridge
- mac: "{{ br0_port0_mac }}"
master: br0
name: br0-port0
state: up
type: ethernet
nrpe_procs_crit: 1000
nrpe_procs_warn: 900
postfix_group: vpn
virthost: true
vpn: true
zabbix_macros:
'VFS.DEV.WRITE.AWAIT.WARN': 100

View file

@ -29,8 +29,8 @@ network_connections:
type: ethernet
state: up
mtu: 1500
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 20480
mem_size: 16384

View file

@ -29,8 +29,8 @@ network_connections:
type: ethernet
state: up
mtu: 1500
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 20480
mem_size: 16384

View file

@ -29,8 +29,8 @@ network_connections:
type: ethernet
state: up
mtu: 1500
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 20480
mem_size: 16384

View file

@ -29,8 +29,8 @@ network_connections:
type: ethernet
state: up
mtu: 1500
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 20480
mem_size: 16384

View file

@ -29,8 +29,8 @@ network_connections:
type: ethernet
state: up
mtu: 1500
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 20480
mem_size: 16384

View file

@ -11,9 +11,9 @@ eth0_ipv6_ip: "2606:f640:6000:651::10"
eth0_ipv6_gw: "2606:f640:6000:651::1"
eth0_ipv6_nm: 64
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
lvm_size: 150000
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 100000
main_bridge: br0
max_mem_size: 49152
mem_size: 32768

View file

@ -10,8 +10,8 @@ eth0_ipv6_ip: 2620:52:6:1161::35
eth0_ipv6_nm: 64
eth0_nm: 255.255.255.0
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
lvm_size: 50000
max_mem_size: 49152
mem_size: 32768

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.166.254
eth0_ipv4_ip: 10.16.166.30
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
vmhost: vmhost-x86-04.stg.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -6,7 +6,7 @@ koji_instance: primary
koji_server_url: "https://koji.stg.fedoraproject.org/kojihub"
koji_topurl: "https://kojipkgs.stg.fedoraproject.org/"
koji_weburl: "https://koji.stg.fedoraproject.org/koji"
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 1.5t
nrpe_procs_crit: 1000

View file

@ -1,8 +1,8 @@
---
datacenter: rdu3
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.130
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
eth0_ipv4_ip: 10.16.163.59
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
vmhost: vmhost-x86-03.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -1,8 +1,8 @@
---
datacenter: rdu3
eth0_ipv4_gw: 10.16.166.254
eth0_ipv4_ip: 10.16.166.77
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
eth0_ipv4_ip: 10.16.166.41
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
vmhost: vmhost-x86-05.stg.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -6,13 +6,13 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT'
]
nft_custom_rules:
- 'add rule ip filter INPUT ip saddr 192.168.1.20 tcp dport 5666 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.20 tcp dport 5666 counter accept'
# needed to allow rsync from log01
- 'add rule ip filter INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule ip filter INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.163.39 tcp dport 873 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 192.168.1.59 tcp dport 873 counter accept'
# needed to allow 8080 (firmware-proxy from iDRAC mgmt vlans
- 'add rule ip filter INPUT ip saddr 10.16.160.0/24 tcp dport 8080 counter accept'
- 'add rule ip filter INPUT ip saddr 10.16.161.0/24 tcp dport 8080 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.160.0/24 tcp dport 8080 counter accept'
- 'add rule {{nft_table_filter}} INPUT ip saddr 10.16.161.0/24 tcp dport 8080 counter accept'
datacenter: rdu3
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.10

View file

@ -32,7 +32,7 @@ network_connections:
# This host is externally reachable
#
external: true
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
vmhost: vmhost-x86-01.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -24,8 +24,8 @@ eth0_ipv6_ip: "2606:f640:6000:651::11"
eth0_ipv6_gw: "2606:f640:6000:651::1"
eth0_ipv6_nm: 64
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
main_bridge: br0
network_connections:
- autoconnect: yes

View file

@ -32,7 +32,7 @@ network_connections:
# This host is externally reachable
#
external: true
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
vmhost: vmhost-x86-03.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -25,8 +25,8 @@ eth0_ipv6_ip: "2001:4178:2:1269:dead:beef:cafe:fed5"
eth0_ipv6_nm: 64
eth0_nm: 255.255.255.240
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
network_connections:
- autoconnect: yes
ip:

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.167.254
eth0_ipv4_ip: 10.16.167.34
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 120g
max_mem_size: 16384

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.169.254
eth0_ipv4_ip: 10.16.169.119
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 120g
max_mem_size: 16384

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.167.254
eth0_ipv4_ip: 10.16.167.35
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 120g
max_mem_size: 16384

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.169.254
eth0_ipv4_ip: 10.16.169.127
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
lvm_size: 120g
max_mem_size: 16384

View file

@ -5,7 +5,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.174.254
eth0_ipv4_ip: 10.16.174.57
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
############################################################
# install
############################################################

View file

@ -5,7 +5,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.174.254
eth0_ipv4_ip: 10.16.174.52
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
############################################################
# install
############################################################

View file

@ -2,9 +2,10 @@
datacenter: rdu3
dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: "stg.rdu3.fedoraproject.org"
dns_search2: "rdu3.fedoraproject.org"
dns_search3: "fedoraproject.org"
dns_search1: "vpn.fedoraproject.org"
dns_search2: "stg.rdu3.fedoraproject.org"
dns_search3: "rdu3.fedoraproject.org"
dns_search4: "fedoraproject.org"
effective_cache_size: "6GB"
eth0_ipv4_gw: 10.16.179.254
eth0_ipv4_ip: 10.16.179.61
@ -29,6 +30,7 @@ network_connections:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
- "{{ dns_search3 }}"
- "{{ dns_search4 }}"
gateway4: "{{ eth0_ipv4_gw }}"
gateway6: "{{ eth0_ipv6_gw }}"
mac: "{{ ansible_default_ipv4.macaddress }}"

View file

@ -13,7 +13,7 @@ eth0_ipv6_nm: 64
freezes: true
has_ipv4: yes
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
max_mem_size: 32768
mem_size: 32768
@ -43,7 +43,7 @@ postfix_group: vpn
public_hostname: proxy11.fedoraproject.org
# This is consumed by the roles/fedora-web/main role
sponsor: dedicatedsolutions
vmhost: dedicatedsolutions01.fedoraproject.org
vmhost: dedicatedsolutions02.fedoraproject.org
volgroup: /dev/vg_guests
vpn: true
zabbix_macros:

View file

@ -13,9 +13,8 @@ eth0_ipv6_nm: 64
freezes: true
has_ipv4: yes
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/43/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
mac0: "52:54:00:84:5d:9f"
main_bridge: br0
max_mem_size: 20000
mem_size: 16384
@ -35,12 +34,12 @@ network_connections:
- "{{ dns_search2 }}"
gateway4: "{{ eth0_ipv4_gw }}"
gateway6: "{{ eth0_ipv6_gw }}"
mac: "{{ mac0 }}"
mac: "{{ ansible_default_ipv4.macaddress }}"
name: eth0
type: ethernet
nrpe_procs_crit: 1400
nrpe_procs_warn: 1200
num_cpus: 8
num_cpus: 16
postfix_group: vpn
public_hostname: proxy12.fedoraproject.org
# This is consumed by the roles/fedora-web/main role

View file

@ -0,0 +1,4 @@
---
nagios_Can_Connect: false
nagios_Check_Services:
nrpe: false

View file

@ -11,8 +11,8 @@ eth0_ipv6_ip: "2606:f640:6000:651::5"
eth0_ipv6_gw: "2606:f640:6000:651::1"
eth0_ipv6_nm: 64
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
main_bridge: br0
network_connections:
- autoconnect: yes

View file

@ -10,8 +10,8 @@ eth0_ipv4_ip: 10.16.179.63
eth0_ipv6_gw: 2620:52:6:1161::1
eth0_ipv6_ip: 2620:52:6:1161::34
eth0_nm: 255.255.255.0
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
vmhost: vmhost-x86-iso02.rdu3.fedoraproject.org
volgroup: /dev/vg_guests
vpn: true

View file

@ -10,8 +10,8 @@ eth0_ipv6_ip: "2605:bc80:3010:600:dead:beef:cafe:fedb"
eth0_ipv6_gw: "2605:bc80:3010:600::1"
eth0_ipv6_nm: 64
has_ipv6: yes
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
mem_size: 4096
network_connections:
- autoconnect: yes

View file

@ -6,10 +6,10 @@ dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.37
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
# Define resources for this group of hosts here.
lvm_size: 20000
lvm_size: 25000
mem_size: 4096
num_cpus: 2
vmhost: vmhost-x86-01.rdu3.fedoraproject.org

View file

@ -6,10 +6,10 @@ dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
eth0_ipv4_gw: 10.16.163.254
eth0_ipv4_ip: 10.16.163.38
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL9-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel
ks_repo: https://infrastructure.fedoraproject.org/repo/rhel/RHEL10-x86_64/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-rhel-10
# Define resources for this group of hosts here.
lvm_size: 20000
lvm_size: 25000
mem_size: 4096
num_cpus: 2
vmhost: vmhost-x86-05.rdu3.fedoraproject.org

View file

@ -2,7 +2,7 @@
datacenter: rdu3
eth0_ipv4_gw: 10.16.166.254
eth0_ipv4_ip: 10.16.166.24
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/42/Server/x86_64/os/
ks_repo: https://infrastructure.fedoraproject.org/pub/fedora/linux/releases/44/Server/x86_64/os/
ks_url: https://infrastructure.fedoraproject.org/repo/rhel/ks/kvm-fedora
vmhost: vmhost-x86-03.stg.rdu3.fedoraproject.org
volgroup: /dev/vg_guests

View file

@ -109,7 +109,7 @@ bvmhost-x86-02.stg.rdu3.fedoraproject.org
bvmhost-x86-03.stg.rdu3.fedoraproject.org
[colo_virt]
dedicatedsolutions01.fedoraproject.org
dedicatedsolutions02.fedoraproject.org
ibiblio02.fedoraproject.org
ibiblio05.fedoraproject.org
internetx02.fedoraproject.org
@ -343,16 +343,16 @@ noc01.rdu3.fedoraproject.org
noc01.rdu3.fedoraproject.org
[memcached]
memcached02.rdu3.fedoraproject.org
memcached01.rdu3.fedoraproject.org
[memcached_rdu3]
memcached02.rdu3.fedoraproject.org
memcached01.rdu3.fedoraproject.org
[memcached_stg]
memcached02.stg.rdu3.fedoraproject.org
memcached01.stg.rdu3.fedoraproject.org
[memcached_stg_rdu3]
memcached02.stg.rdu3.fedoraproject.org
memcached01.stg.rdu3.fedoraproject.org
[mirrorlist_proxies]
proxy02.fedoraproject.org
@ -642,7 +642,7 @@ ipatuura01.stg.rdu3.fedoraproject.org
ipsilon01.stg.rdu3.fedoraproject.org
koji01.stg.rdu3.fedoraproject.org
mailman01.stg.rdu3.fedoraproject.org
memcached02.stg.rdu3.fedoraproject.org
memcached01.stg.rdu3.fedoraproject.org
os-control01.stg.rdu3.fedoraproject.org
pkgs01.stg.rdu3.fedoraproject.org
proxy01.stg.rdu3.fedoraproject.org
@ -783,6 +783,7 @@ ppc64le-test.fedorainfracloud.org
ppc64le-test02.fedorainfracloud.org
aarch64-test01.fedorainfracloud.org
aarch64-test02.fedorainfracloud.org
s390x-test01.fedorainfracloud.org
[aarch64_test]
aarch64-test01.fedorainfracloud.org
@ -816,7 +817,7 @@ colo_virt
value
staging
builders
bkernel
secureboot
buildvmhost
[groupc]

View file

@ -33,6 +33,7 @@
- import_playbook: /srv/web/infra/ansible/playbooks/groups/koji-hub.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/kojipkgs.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/logserver.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/logdetective.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/mailman.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/maintainer-test.yml
- import_playbook: /srv/web/infra/ansible/playbooks/groups/mariadb-server.yml

Some files were not shown because too many files have changed in this diff Show more