Create and configure a new user for ELNBuildSync #13132
Labels
No labels
after freeze
automation
backlog
blocked
change-ack
change-nak
change-noreleng
changes
Closed As
Can't Fix
Closed As
Duplicate
Closed As
Fixed
Closed As
Fixed with Explanation
Closed As
Get back later
Closed As
Grooming
Closed As
Insufficient data
Closed As
Invalid
Closed As
It's all good
Closed As
taiga
Closed As
upstream
day-to-day
dev
docs
easyfix
epel
f26
f27
f28
f29
f30
f31
f32
f33
f34
f35
f36
f37
f38
f39
f40
f41
f42
f43
f44
f45
fedora
groomed
high-gain
high-trouble
in-progress
in-review
investigation
legal
low-gain
low-trouble
mass rebuild
medium-gain
medium-trouble
meeting
mini-initiative
new_artifact
ops
pdc_retirement
rawhide
RCA
review
script
sidetarget
sprint-0
sprint-1
sprint-2
sprint-3
sprint-4
sprint-5
unfrozen
waiting on external
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
release-process
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
5 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
releng/tickets#13132
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Describe the issue
Until now, ELNBuildSync has been using the
distrobuildsync-eln/jenkins-continuous-infra.apps.ci.centos.orgname in Koji to create and tag builds. However, in order to implement the requested change to create a single side-tag update per batch (or a small number of such in the case of a mass rebuild), our automation would have to also interact with Bodhi, and the keytab we have will not log in to Bodhi.In discussion tonight in #eln, @kevin stated that because this name is not a real user in FAS, it does not have the capability to log into Bodhi, and that services that need to do so need to be real users, e.g. like
packit. Therefore, we apparently need to do the same for ELNBuildSync in order to implement this change.a. roles/bodhi2/base/templates/production.ini.j2: include the new user in
stats_blacklistb. roles/openshift-apps/badges/templates/fm-fedbadges.toml: include the new user in
skip_usersMore information on this change:
https://github.com/fedora-eln/eln/issues/200
#12869
https://gitlab.com/redhat/centos-stream/ci-cd/distrosync/distrobuildsync/-/merge_requests/98
https://gitlab.com/redhat/centos-stream/ci-cd/distrosync/distrobuildsync/-/merge_requests/100
When do you need this? (YYYY/MM/DD)
ASAP (although we haven't created such a user yet)
When is this no longer needed or useful? (YYYY/MM/DD)
N/A
If we cannot complete this, what is the impact? [Dependencies/Blocker]
ELN cannot implement batching of updates.
/cc @sgallagh
Checklist
Also, if this means we will be changing the user in Koji, we need to make sure that this new user has the same privileges as the existing
distrobuildsync-eln/jenkins-continuous-infra.apps.ci.centos.org. Among other things, this means the new user needs to have privilege to rebuild the secure boot packages.Do we need to create the user, or will releng generate one. It's unclear if "service account" users differ in FAS, so I don't want to jump the gun and create one manually.
As a step 1 to it, I created
eln-buildsyncuser, and gave it a signed-fpca for Fedora.@jnsamyak The
eln-buildsyncuser will need to be a provenpackager and also be granted privileges to build secure boot packages. Put another way, it needs the same privileges afforded to thedistrobuildsync-eln/jenkins-continuous-infra.apps.ci.centos.orgcurrently on Koji, plus the ability to submit updates to Bodhi.The previous user on koji only had
secure-bootpermission:I'm not sure what group giving ability to submit updates on Bodhi, perhaps
bodhi-admin?yeah
bodhiadminshould be the one, there issysadmin-bodhitoo but I'll check.@jnsamyak can you please later document the steps you did, because I will need
releng-botuser in the future and this knowledge will be really valuableSo Ansible changes are merged, perms are given, sgallagh created the keytab also.
CC: @yselkowitz @sgallagh
The changes have been deployed on our end, and everything looks good so far. Presumably there will be a kernel build in the next few days which will allow us to verify the secure-boot permissions.
Finally got a kernel build, and it was correctly sent to secure-boot channel. So looks like the user is working fine.
One question, does this account still have login credentials (aside from the keytab), and if so are we responsible for keeping those or releng?
A couple of things here:
@kevin wrote in #13132 (comment):
I'll look into writing this up as part of the work I'm doing with the Ansible deployment.
Can you point it at
sgallagh+elnbuildsync@redhat.comfor now? That will at least get it to me (and be easily filterable).Done. (should be active in a bit, get your filters ready. ;)
Also, I think we can drop this from provenpackager and instead add it to the bodhi_update_bots group (which is where we have packit now).
@kevin wrote in #13132 (comment):
As long as we are sure that won't impact our ability to build in Koji, that's fine with me.
It shouldn't.
I have removed it from provenpackager and bodhiadmin and added it to bodhi_update_bots
I think that makes it more clear it's a bot, and I don't think it needs bodhiadmin (which also sends all the bodhi admin emails to it).
Please let me know if any of that breaks something.
I think you may have just added it to Bodhi STG admins, because I am suddenly flooded with emails.
I... only adjusted the production one.
Are the emails from prod or stg?
It may be that bodhi still thinks it's in the group right now?
They're coming from stg, it looks like.
ok, I adjusted stg to the same groups now.
I don't get why you would get staging emails tho. It wasn't in any groups in stg before I added it.
I guess if you can forward one of those to me to look at?
Forwarded one
Ping?
Sorry, this dropped off my radar. You are still getting them?
Can you send a more recent one?