Compare commits

...

106 commits

Author SHA1 Message Date
c686b58853 httpd/koji: set MaxKeepAliveRequests 0 to fix 502 race condition
This acts as the second half of the fix for the 502 Bad Gateway errors
on long-running koji connections.

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-12 20:40:39 +00:00
b0753069a9 proxies-reverseproxy: set keepalive=on ttl=10 for koji
This fixes intermittent 502 Bad Gateway errors during long-running
koji connections (like watch-task or watch-logs).

For more details on proxy keepalive and ttl, see:
https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-12 20:40:39 +00:00
aa2b0180aa Update security.txt for end date and add some more fields
Fix the expire date.
Point users to a wiki page to hopefully cut down on begg bounties
Note that we do NOT have a bug bounty program.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:39:02 +00:00
7413d9c84f proxies / src.fp.o: drop haproxy from src
Right now requests go:

client -> httpd on proxy -> anubis -> httpd on proxy -> varnish -> haproxy -> pkgs01

but haproxy is pretty useless in this case.
There is only one backend (pkgs01) so no load balancing, and doing a
liveness check is also pointless because if its down the request will
fail anyhow.

It might be tha haproxy ovehead is causing varnish to return retries
sometimes ( infra/tickets#13123 )

So, this drops it out for this.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 20:36:49 +00:00
409b8614e7 kojipkgs: all options need - or + if any have it
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 12:29:42 -07:00
094eeb99e8 kojipkgs: disable indexes on ostree/repo/objects directories
These directories have usually around 32k objects in them.
This means when a client asks for a directory index for them
it takes kojipkgs a few minutes to actually generate it, because it has
to stat every single file in order to show timestamps and sizes.
This means it fills up all slots doing this and the proxies start
getting 503's from it on other requests.

I don't _think_ ostree needs this enabled for any reason.
If it did, it would always have been a problem.
I think it's just some clients/crawlers deciding they want the directory index.

So, lets just deny indexes on directories under there.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 12:12:16 -07:00
bd716659c6
Inventory: quote dates because Zabbix API wants that
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 17:01:28 +00:00
4e9c4751bc
Inventory: trim trailing whitespace with sed
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 15:49:27 +00:00
ec5c717b1f
Initial round of Zabbix HW inventory info 2026-03-12 15:49:24 +00:00
a3cbb17ca7
forgejo: Create the secret for the runner config
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-12 14:18:51 +00:00
ee8a20b1f6
Zabbix: enable agent-based reporting on s390 bvmhosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 13:59:23 +00:00
b6401b16d7
forgejo: Create forgejo runner config secret
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-12 13:55:33 +00:00
5ec7103314
Zabbix: role/OS vars won't work in other roles, use a hostvar instead
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 13:04:57 +00:00
9cad3bf76c
Nagios: Drop RabbitMQ checks as Zabbix handles this
This removes (almost) all the Nagios config for Rabbit, including the
templates in the Rabbit role(s).

It leaves the nagios user, because Zabbix is also using it.

It also adds a Matrix-level notification for high queues, above the one
that goes to the UI.

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 12:30:02 +00:00
084da3c5ab
OpenVPN: fix path to Zabbix agent config in cron, part 2
Helps if you add all the files you changed...

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 12:01:33 +00:00
3d7a57e1b0
OpenVPN: fix path to Zabbix agent config in cron
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-12 11:07:00 +00:00
aaa5941e9f base / postfix / bastion: switch some maps back to hash
These two maps are generated by a script, so we should adjust that
script to make lmdb if we want to switch them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 20:36:40 -07:00
4cb953f9e5 download: add mirror to acls ( infra/tickets#13180 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-12 01:02:37 +00:00
d81bf5903b base / postfix: make lmdb regex not also pull , in when entries are seperated by ,s
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 17:54:30 -07:00
1ab995c2f0 bastion/gateway: cache maps have to be btree
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 17:37:41 -07:00
ba480436d7 fix bug: set stg_template as empty list, so ansible doesn't fail
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-11 21:32:50 +00:00
6c98ae9f88 feat: Make the sysadmin-opensift-readonly group deploy in production
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-11 21:32:50 +00:00
1e6cb7b311 fedoraloveskde: Switch sources to new location on Fedora Forge
Signed-off-by: Neal Gompa <ngompa@fedoraproject.org>
2026-03-11 21:14:09 +00:00
aedf43d1f3 Restore arcane breadcrumbs (broken Forge links)
Also some minor changes to satisfy yamllint.

Signed-off-by: Michael Winters <fedora@mwinters.net>
2026-03-11 21:09:36 +00:00
35a1b3223b proxies-reverseproxy: set keepalive=on ttl=10 for koji
This fixes intermittent 502 Bad Gateway errors during long-running
koji connections (like watch-task or watch-logs).

For more details on proxy keepalive and ttl, see:
https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Fixes #12913

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-11 20:36:49 +00:00
6eeed591f7 greenwave updates gating: gate on new server-boot-iso tests
In quality/os-autoinst-distri-fedora#483
we added server-boot-iso tests to openQA that are similar to the
everything-boot-iso tests, but they generate and install a Server
netinst image, not an Everything one. That's been running for a
while, so we can gate on it now. We add a new policy because these
tests run on critical-path-server as well as all the ones we run
the everything-boot-iso tests on.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-03-11 12:38:52 -07:00
88f10244e1 pagure: Set WSGIApplicationGroup %{GLOBAL} for dist-git to prevent httpd core dumps
Fixes #12670.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-11 18:38:57 +00:00
b601ca4c6e storinator01: fix old rdu2-cc host entries
This machine moved from rdu2-cc to rdu3, we missed changing these at the
time.

For copr it should use the external hostname.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-11 10:18:03 -07:00
bcee02c9fd Fixes #13021 - Zabbix: Add OpenVPN Client cert monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-11 16:37:29 +00:00
Jakub Kadlcik
07f0fe3d12 copr: use packages.redhat.com and basic HTTP auth
Fix https://github.com/fedora-copr/copr/issues/4141
Fix https://github.com/fedora-copr/copr/issues/4142
2026-03-11 16:50:41 +01:00
402472283a [postfix] Fix the when condition
Path always needs to be in quotes inside jinja2 template.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 15:25:53 +01:00
e3efee90c1 [postfix] Use the correct variable in lmdb
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:56:43 +01:00
e6f7c234ab [postfix] Move lmdb handler to separate file
After merging I found out that the handler can't handle blocks. The
workaround is to include tasks from separate file.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:48:09 +01:00
48f3055721 [postfix] Migrate to lmdb
This change will migrate postfix from bdb to lmdb.
See infra/tickets#13035 for more
details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 14:46:18 +01:00
f40260df77 [postfix] Don't install postfix-lmdb on RHEL < 8
The RHEL/EPEL 8 doesn't have postfix-lmdb package, so let's skip it for
older releases.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
eeeaaadd9e [postfix] Update pkgs/pagure postfix configs
Missing space in variable for pkgs group ansible config

Revert changes in pagure and pkgs configs to use hash instead of btree
as before

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
01db5bb986 [postfix] Fix ansible-lint issues
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
4908d2b2d7 [postfix] Update lmdb tasks
1. Move lmdb file creation to handler
2. Create separate postfix config for RHEL8 machines (pkgs, pagure)
2026-03-11 13:27:21 +00:00
5e9129cd00 [postfix] Migrate to lmdb
This change will migrate postfix from bdb to lmdb.
See infra/tickets#13035 for more
details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:27:21 +00:00
1b88461e30 [poddlers] Migrated to forge.fedoraproject.org
infra/tickets#13111

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-11 13:21:28 +00:00
fa0f8e073e
We are out of f44 beta freeze
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-11 11:20:47 +00:00
d4000f3282 Add an AI review workflow
This adds AI review for pull requests, using the workflow and
pattern already used by several Quality projects. Pull requests
will be reviewed by
https://gitlab.com/redhat/edge/ci-cd/ai-code-review/ whenever the
'ai-review-please' label is applied to them. Also adds a context
file, generated by claude-4.6-opus-high via Cursor, using the
https://github.com/juanje/context-generator skill, as recommended
by ai-code-review upstream.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
Assisted-by: claude-4.6-opus-high
Assisted-by: Cursor-2.6.11
2026-03-10 08:49:17 -07:00
Jakub Kadlcik
2dd8897adc copr: change Pulp content URL to packages.redhat.com
See https://github.com/fedora-copr/copr/issues/4141
2026-03-10 16:15:50 +01:00
Jakub Kadlcik
ce6c01e905 copr: change STG Pulp content URL to packages.redhat.com
See https://github.com/fedora-copr/copr/issues/4141
2026-03-10 12:22:31 +01:00
a24b5e49dc
forgejo: install runnerhost dependencies at vm creationtime
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-03-10 09:51:15 +00:00
04bbc6004f EPEL minor branching: fix inline documentation for branch-distgit-packages.yml
* Fix typos (disgit -> distgit)
* Run with rbac-playbook
* Use correct relative path when run with rbac-playbook

Resolves epel/releng#85

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-09 22:28:55 +00:00
James Antill
34425d82f2 Change torrent-hashes to Kevin's working version.
Signed-off-by: James Antill <james@and.org>
2026-03-09 18:16:40 -04:00
James Antill
bf1f99860d Add fedora.pt to zones.conf.
Signed-off-by: James Antill <james@and.org>
2026-03-09 15:30:10 -04:00
0262961387 copr-hypervisor: make sure helpers.py expand correctly
Follows-up: 14b89a2a67
2026-03-09 19:08:59 +01:00
538f6e5df0 copr: workers: fix ipv6 allocation
Follows-up: 14b89a2a67
2026-03-09 18:52:47 +01:00
60fd97e7cb copr: one more typo in the new libvirt spawner
Follows-up: 14b89a2a67
2026-03-09 18:47:07 +01:00
4200ac465e copr: fix typo in variable name
Follows-up: 14b89a2a67
2026-03-09 18:06:23 +01:00
14b89a2a67 copr: better divide the ipv6 range we have
Now, all VMs on stage are 0x900+, and 0x100+ are in prod.

Relates: https://github.com/fedora-copr/copr/issues/3984
2026-03-09 17:52:00 +01:00
2e546baf9f copr: debugging: helper script expands more files 2026-03-09 17:36:40 +01:00
Jiri Podivin
14e43e1533 Adding the 8090 port for packit to inventory
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-03-09 15:35:22 +00:00
74e2f728c5
Add the logdetective-packit user in RabbitMQ
Creating a certificate is not sufficient.

Fixes: infra/tickets#12989

Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2026-03-09 10:10:56 +01:00
3dba4c3d44 forge: add group mappings for the flatpak org
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-09 18:15:06 +10:00
d057561208 forge: add group team mapping for games SIG
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-09 16:20:09 +10:00
9f40b67dd1 Perform mapping for Personal Systems teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-09 06:19:07 +00:00
252b8ca273
docsbuilding: update git url 2026-03-07 22:18:22 +01:00
801e40b138 Fedora 44 Beta-1.2 is GO
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-03-06 20:51:37 +05:30
79f1a7c324 gpu01: add vpn and hosts file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 16:51:37 -08:00
0b00ad11d3 gpu: add group_vars and dhcp config
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 15:04:11 -08:00
e254c236dc smtp-auth-iso01: deploy correct postfix config
This config was not moved over when the host moved from rdu2-cc to
rdu3's iso network. It's needed to allow the submission port to work to
submit emails.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 19:56:20 +00:00
893e103461 gpu01: add new gpu01 machine in rdu3-iso
This machine is in the rdu3 isolated network.
For now, just setup a simple kickstart on one disk and a playbook that
does the normal base role things. We can adjust from here.

This machine has 1 nvme and another spinning rust device.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 19:55:21 +00:00
7de3acd96c web-data-analysis: remove hardcoded end date in gnuplot script
The mirrors-data.gp script had a hardcoded X-axis end date of
2024-12-31. Since we are now in 2026, gnuplot fails with "all points
y value undefined!" because the new log data points fall completely
outside this strict plotting window.

By removing the end date and using an open-ended range (e.g. ["2007-05-17":]),
gnuplot will automatically scale the X-axis to the latest available data
point in the CSV, preventing this from breaking again in the future.

Fixes: #12833

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-05 01:05:53 +00:00
Jakub Kadlcik
decd56f48c copr: of course I messed up the brackets 2026-03-04 22:08:09 +00:00
b935cd4d86 distgit: disable mod_mime_magic content encoding for archives
mod_deflate wasn't the issue, as src didn't have gzip enabled. The
backend (pkgs01) uses mod_mime_magic, which sniffs .crate files
and adds false gzip headers. Forcing application/octet-stream
fixes the client double-decompression bug.

Fixes #12812.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-03-04 21:25:59 +00:00
Jakub Kadlcik
c6954081de copr: enable high-perf builders for eseiker/asahi-el-kernel
Fix https://github.com/fedora-copr/copr/issues/4199
2026-03-04 10:37:44 +01:00
95cc5cdeb8 ocp4: fix rolebinding on readonly group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-03 09:51:49 -08:00
cff13b3aa0
fix: make the readonly role a ClusterRole and fix it's rolebinding
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-03 18:34:50 +01:00
775ff5cdfd
Fixes #13149 - Zabbix: Add release-monitoring.org to http page checks
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-03-03 17:05:57 +00:00
72ddc85537 fix: specify correct API for the readonly role
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-03-02 19:25:34 +00:00
59eddc51a8 EPEL minor branching: create symlinks as apache user
epel/releng#89

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-02 19:07:42 +00:00
4051930fa7 EPEL minor branching: update major-only compose symlinks
epel/releng#88

Signed-off-by: Carl George <carlwgeorge@gmail.com>
2026-03-02 19:07:42 +00:00
88eabbfca6 Install ansible zabbix collection for ansible-lint
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-02 17:16:31 +01:00
8146e99e1b [postfix] Fix ansible-lint issues
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-03-02 17:16:30 +01:00
8569744347 forge: add miracle org to group team mappings
related: forge/forge#407

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-03-02 18:27:29 +10:00
b9e60a9cc5 Perform mapping for Fedora Btrfs teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 10:42:18 +05:30
cf24cc841e Perform mapping for CoC committee teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 10:36:33 +05:30
7d4880f9d7 Perform mapping for Security SIG teams and groups
Signed-off-by: Akashdeep Dhar <akashdeep.dhar@gmail.com>
2026-03-02 04:59:31 +00:00
1fa76e4de0
distgit: disable mod_deflate for lookaside cache in staging
Fixes #12812.

This disables mod_deflate for the lookaside cache directory to prevent
incorrect 'Content-Encoding: gzip' headers being sent with archives.
Wrapped in a staging block for initial testing as requested.

Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-02-27 20:22:40 +02:00
b4ddcdd830 removed ipsilon-website entries in proxies-reverseproxy.yml and proxies-websites.yml playbooks
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
8fa05b2955 deleted ipsilon-website playbook
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
5b88ef525f Removed ocp app ipsilon-website
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2026-02-27 18:03:21 +00:00
488e9ae7e5 ocp4: add someone to readonly to test with in staging
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-27 09:54:40 -08:00
96d23293a2 fix: cluster/main.yaml should have been in cluser/handlers/main.yaml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
08928917e6 feat: add handler in openshift/clustr for applying changes
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
4392472669 separate template copying for stg/prod
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
4d8a14db4e move handling back to main.yml and rename role to sysadmin-openshift-readonly
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
b4ff5f819d remove trailing spaces
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
7b4774117d setup handlers, so ansible-lint is happy
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
a7ce1173a6 apply sysadmin-readonly when env is staging
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
f601a5ce0b remove access to configmaps from sysadmin-readonly
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
ae70d6e83a fix wrong role name in role definition
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
d619073a15 Add sysadmin-readonly group to openshift
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-02-27 17:50:24 +00:00
76e6ffd412 Zabbix: Try to improve SSL check to handle timeouts from whatcanido
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-02-27 11:04:59 +00:00
709f7a12c4 Add ignore-errors to skip list
This will ignore CI errors in category ignore-errors in ansible-lint as
this is something we don't need to care about.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-02-27 08:24:13 +00:00
127d7c3269 get yamllint to ignore templates in openshift apps
previously, the yamllint ingores for templates only worked for roles one
level down. Since our openshift apps are nested in the openshift-apps
directory, yamllint was trying to lint jinja templates with a .yml
extension. This updates the yamllint ignores to include templates in
openshift apps roles.

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2026-02-26 08:59:38 +00:00
b3478a46c1 people: disable cgit snapshots downloading for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-25 14:06:36 -08:00
41fef6bf56 people01: try and increase workers and limits
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-02-25 13:43:56 -08:00
a8f1cdfb5e web-data-analysis: export PATH in cron scripts for simple_message_to_bus
Cron jobs run with a stripped-down PATH (usually just /usr/bin:/bin),
causing simple_message_to_bus (which resides in /usr/local/bin) to fail
with "command not found" errors.

This explicitly exports /usr/local/bin to the PATH at the top of the
combineHttpLogs, condense-mirrorlogs, and countme update scripts so
the message bus command executes properly. This also removes the redundant
and late PATH assignments further down in the countme scripts.

Fixes: #12833
Signed-off-by: Victor Koycheff <victorkoycheff@gmail.com>
2026-02-25 19:27:41 +00:00
62eff4cb2d distgit: deploy script to transfer pagure group ownership
Fixes: infra/tickets#12935
Signed-off-by: Victor Koycheff <victorinaforvu@gmail.com>
2026-02-25 19:12:08 +00:00
James Antill
38fe6cbb19 check-etc: Add lots of files/prefixes.
Signed-off-by: James Antill <james@and.org>
2026-02-25 13:47:28 -05:00
James Antill
9fdf8f48c9 updates-uptimes: Accept more values for --ansi yes/no.
Signed-off-by: James Antill <james@and.org>
2026-02-25 11:53:12 -05:00
James Antill
70ff023ee4 ansilog-playbook: Add script to view ansible-playbook logs.
Signed-off-by: James Antill <james@and.org>
2026-02-25 11:51:57 -05:00
212 changed files with 4216 additions and 871 deletions

159
.ai_review/project.md Normal file
View file

@ -0,0 +1,159 @@
## Project Overview
**Purpose:** Ansible automation for the entire Fedora Project infrastructure — managing hundreds of bare-metal hosts, VMs, and OpenShift-deployed applications across production and staging environments.
**Type:** Infrastructure as Code (Ansible)
**Domain:** Linux distribution infrastructure (build systems, package repositories, CI/CD, web services, identity management)
**Key Components:** `roles/` (134 reusable roles), `playbooks/` (groups, hosts, openshift-apps, manual), `inventory/` (host/group vars with constructed plugin)
## Technology Stack
### Versions (current as of 2026-03-05)
- **Ansible** — core automation engine; playbooks target Fedora and RHEL/CentOS hosts
- **yamllint** v1.35.1 — pre-commit hook for YAML validation
- **ansible-lint** — CI linting (skips: `yaml`, `role-name[path]`, `var-naming[no-role-prefix]`, `no-changed-when`, `ignore-errors`)
- **OpenShift 4** (OCP4) — hosts ~60 containerized applications via `openshift-apps/` playbooks
### Target Platforms
- **Fedora** (current cycle: F43 stable, F44 branched, F45 rawhide)
- **RHEL/CentOS** 8+ (EPEL 10, current minor: 10.3)
- **OpenShift 4** cluster (rdu3 datacenter)
### Dev Tools
- **Linting:** yamllint (pre-commit) + ansible-lint (CI)
- **CI:** Forgejo Actions on `quay.io/fedora/fedora:latest` — runs yamllint and ansible-lint on changed files only
- **Control host:** batcave01 (`/srv/web/infra/ansible` public, `/srv/private/ansible` private)
## Resource Organization
### Structure
```
├── main.yml # Master playbook — imports all group/host playbooks
├── playbooks/
│ ├── groups/ # 59 group playbooks (one per service group)
│ ├── hosts/ # 2 host-specific playbooks (FQDN.yml)
│ ├── openshift-apps/ # 60 OCP4 application deployments
│ ├── manual/ # 39 admin-run-only playbooks
│ └── include/ # Shared proxy/virt/cert playbook fragments
├── roles/ # 134 roles
│ ├── base/ # Applied to ALL hosts (packages, SSH, SELinux, nftables)
│ ├── openshift/ # OCP4 primitives (project, object, keytab, route, rollout)
│ └── openshift-apps/ # Per-app roles (templates, files for OCP4 deployments)
├── inventory/
│ ├── inventory/ # Host definitions
│ ├── group_vars/ # 150 group variable files (incl. _stg variants)
│ ├── host_vars/ # Per-host overrides
│ └── zzz-inventory.config # Constructed inventory plugin (dynamic groups by datacenter, distro, vmhost)
├── vars/
│ ├── global.yml # Global vars (paths, SSL config, base packages)
│ ├── all/ # Release cycle vars (Fedora versions, freeze states, EPEL)
│ ├── apps/ # Per-application vars (bodhi, mirrormanager, etc.)
│ ├── Fedora.yml # Distro-specific packages/services
│ └── RedHat.yml / CentOS.yml
├── tasks/ # Reusable task snippets (cloud, postfix, yumrepos, etc.)
├── handlers/ # restart_services.yml
├── library/ # Custom modules (delete_old_oci_images.py, virt_boot, etc.)
├── callback_plugins/ # fedora_messaging_callback.py, logdetail.py
├── files/ # Static files/templates organized by service
└── scripts/ # Admin utility scripts (auth-keys-from-fas, freezelist, etc.)
```
### Module/Role Structure
**Standard role layout:** `tasks/main.yml`, `templates/`, `files/`, `handlers/main.yml`, `meta/main.yml`
**OpenShift app pattern** — the dominant pattern for new services:
1. Playbook in `playbooks/openshift-apps/<app>.yml` targets `os_control[0]:os_control_stg[0]`
2. Uses composable `openshift/*` roles (`project`, `object`, `keytab`, `secret-file`, `imagestream`, `route`, `rollout`)
3. App-specific templates in `roles/openshift-apps/<app>/templates/`
4. Staging vs production controlled by `env` variable and `env_suffix`
**Group playbook pattern** — for traditional VM-based services:
1. Playbook in `playbooks/groups/<group>.yml` with `hosts:` matching inventory group
2. Must include standard `vars_files` triplet (see Review Guidance)
### Critical Resources
- **`vars/all/`** — Fedora release cycle variables. Changed every ~6 months during branching/release. Incorrect values break builds, composes, and Bodhi across the entire infrastructure.
- **`roles/base/tasks/main.yml`** (700+ lines) — Applied to every managed host. Changes here have maximum blast radius.
- **`inventory/group_vars/`** — 150 files controlling per-group behavior. Many have `_stg` counterparts for staging.
- **`main.yml`** — Master playbook importing all groups. Nightly `--check --diff` cron runs all playbooks here.
## Review Guidance
### What Reviewers Must Know
- **All playbooks must be idempotent.** They can be run at any time by the nightly cron. The checked-in state must always be the desired state.
- **Standard vars_files triplet is required** in all group/host playbooks:
```yaml
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "{{ private }}/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
```
Plus `include_vars` for `vars/all/` when release cycle vars are needed.
- **Hardcoded paths are standard** — paths like `/srv/web/infra/ansible/` and `/srv/private/ansible/` are the production layout on batcave01. Don't suggest making them relative or configurable.
- **Use `yml` not `yaml`** for Ansible files (per STYLEGUIDE). The exception is `vars/all/*.yaml` which uses `.yaml` historically.
- **Add `.j2` extension** to all Jinja2 templates.
- **YAML indentation is 2 spaces.** Line length is not enforced.
- **Prefer readable multi-line module args** over single-line `module: name=x arg=y` format.
- **Staging uses `_stg` suffixed group_vars** and `env_suffix` variable (empty string for prod, `.stg` for staging).
- **Tags `packages` and `config`** should be applied to relevant tasks. `build` and `rollout` tags use `never` to prevent accidental execution.
- **OpenShift apps target `os_control[0]:os_control_stg[0]`** — always the first control node. Don't suggest targeting all control nodes.
### Do NOT Flag (Known False Positives)
- `ansible-lint` skip list includes `no-changed-when` and `ignore-errors` — these are intentionally suppressed project-wide
- `yaml` rule category is skipped in ansible-lint — yamllint handles YAML validation separately
- Hardcoded absolute paths in playbooks (e.g., `/srv/web/infra/ansible/...`) — this is the expected deployment layout
- `mock_modules` and `mock_roles` in `.ansible-lint` — used to pass syntax checks without all dependencies
- Octal values forbidden in yamllint — intentional policy to avoid ambiguous YAML parsing
- `when: env == "production"` / `when: env == "staging"` conditional duplication in openshift-apps — standard pattern for different scaling/config per environment
### Common Pitfalls
- **Forgetting to update `vars/all/` during release transitions** — these variables control Fedora version numbers, freeze states, and EPEL branches. Multiple files must be updated together (e.g., branching requires changes to `FedoraBranched.yaml`, `00-FedoraCycleNumber.yaml`, `FedoraBranchedBodhi.yaml`, and `Frozen.yaml`).
- **Not testing with staging first** — staging group_vars (`*_stg`) should be updated before production. Changes that work in staging may still break production due to different scaling or secrets.
- **Breaking idempotency** — a task that makes changes on every run will generate noise in the nightly `--check --diff` report and mask real drift.
- **Wrong file extension for templates** — placing a `.yml` file in `templates/` instead of `.yml.j2` means Jinja2 expressions won't be rendered.
- **ansible-lint file/role misclassification** — the `.ansible-lint` `kinds` section maps `tasks/*.yml` and `vars/*.yml` explicitly. New directories with tasks may need similar mappings.
## Internal & Proprietary
- **`/srv/private/ansible/`** — Private vars (secrets, credentials) stored on batcave01. Referenced as `{{ private }}/vars.yml`. Never committed to this repo.
- **`callback_plugins/fedora_messaging_callback.py`** — Custom Ansible callback that publishes play results to Fedora's AMQP message bus. Don't suggest replacing with standard callback plugins.
- **`callback_plugins/logdetail.py`** — Custom detailed logging callback for the nightly check-diff runs.
- **`library/virt_boot`** / **`library/delete_old_oci_images.py`** — Custom Ansible modules for VM management and OCI image cleanup. Not upstream modules.
- **`scripts/auth-keys-from-fas`** — Fetches SSH authorized keys from Fedora Account System (FAS). Referenced by `auth_keys_from_fas` global variable.
- **Constructed inventory plugin** (`zzz-inventory.config`) — Dynamically creates groups by datacenter (`rdu3`), distro, vmhost, and virtualization role. The `zzz-` prefix ensures it loads last.
---
<!-- MANUAL SECTIONS - DO NOT MODIFY THIS LINE -->
## Architecture & Design Decisions
- **Mostly flat role directory with some nesting**: Most roles live directly under `roles/`, but several use subdirectory namespacing — `openshift/` (OCP4 primitives), `openshift-apps/` (per-app deployments), `awx/`, `openqa/`, `rabbit/`, among others.
- **OpenShift apps via Ansible, not Helm/Kustomize**: OCP4 applications are deployed through Ansible roles that template and apply OpenShift objects. This keeps all infrastructure in one tool and one repo.
- **Staging/production parity through group_vars**: Rather than separate inventories, staging hosts are in the same inventory with `_stg` group_vars files providing overrides. The `env` and `env_suffix` variables control behavior.
- **Release cycle managed through simple YAML vars**: Fedora's complex release lifecycle (rawhide, branched, stable, EOL) is encoded in `vars/all/` as a set of interdependent variables rather than a database or API. This is intentional — the variables are updated manually during each release milestone by the release engineering team.
## Business Logic
- **Fedora release cycle states**: Three main states — unbranched (rawhide only), branched (rawhide + pre-release), and post-release. Controlled by `FedoraBranched`, `FedoraCycleNumber`, `FedoraBranchedBodhi` (preenable/prebeta/postbeta), and freeze flags. These cascade through templates across the entire infrastructure.
- **EPEL minor version lifecycle**: EPEL 10+ has minor versions that move through states: `epel_minor` (built against CentOS), `epel_branched_minor` (branched, built against CentOS snapshot), `epel_z_minor` (built against RHEL). Up to three active minor versions at once.
- **Critical path applications**: forge, pagure, mirrormanager, bodhi, koji, dist-git, and ~20 others require two-reviewer PRs and coordinated downtime scheduling for risky changes.
- **Nightly check-diff**: All playbooks under `playbooks/{groups,hosts}` are run nightly with `--check --diff`. The ideal state is zero changes reported.
## Domain-Specific Context
- **batcave01** — The Ansible control host. All playbooks are run from here via `sudo -i ansible-playbook`.
- **env / env_suffix**`env` is `"production"` or `"staging"`. `env_suffix` is `""` for prod, `".stg"` for staging. Used throughout to construct hostnames, queue names, and paths.
- **FAS (Fedora Account System)** — Identity provider for the Fedora community. SSH keys, group memberships, and permissions come from FAS/IPA.
- **Koji** — Fedora's build system. Build hosts (buildvm, buildhw) are managed here. Koji hub is VM-based (`playbooks/groups/koji-hub.yml` + `roles/koji_hub`), not on OpenShift.
- **Bodhi** — Fedora's update management system. Runs on OpenShift with complex RabbitMQ messaging integration.
- **dist-git / Pagure** — Package source repositories. The lookaside cache and git hosting are managed by separate roles.
- **RabbitMQ / fedora-messaging** — AMQP message bus connecting Fedora services. Certificates managed per-service via `openshift/secret-file` role.
## Special Cases
- **`playbooks/openshift-apps/` uses `gather_facts: false`** — OCP4 playbooks target the control node to run `oc` commands, not the apps themselves. Facts aren't needed and would slow execution.
- **`vars/all/*.yaml` uses `.yaml` extension** despite STYLEGUIDE mandating `.yml` — historical exception, don't "fix" this.
- **`ansible-lint` runs in offline mode** (`offline: true`) — dependencies aren't installed during linting. `mock_modules` and `mock_roles` paper over missing dependencies.
- **Some playbooks are excluded from ansible-lint** (e.g., `copr-db.yml`, `list-vms-per-host.yml`) due to known issues with hardcoded paths or unicode errors.
- **`linux-system-roles.network`** is mocked in ansible-lint — it's an external role not available during CI.

View file

@ -67,3 +67,4 @@ skip_list:
- role-name[path]
- var-naming[no-role-prefix]
- no-changed-when
- ignore-errors

View file

@ -0,0 +1,15 @@
---
name: AI Code Review
on:
pull_request_target:
types: [labeled]
jobs:
ai-review:
runs-on: infra-1
if: forgejo.event.label.name == 'ai-review-please'
uses: quality/workflows/.forgejo/workflows/ai-review.yml@main
with:
pr: ${{ forgejo.event.pull_request.number }}
secrets:
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}

View file

@ -39,7 +39,11 @@ jobs:
steps:
- name: Install testing tools
run: |
dnf install -y ansible-lint nodejs git
dnf install -y ansible-lint nodejs git ansible
- name: Install ansible collections
run: |
ansible-galaxy collection install community.zabbix
- name: Checkout code
uses: https://code.forgejo.org/actions/checkout@v6

View file

@ -26,4 +26,5 @@ rules:
ignore:
- '*/templates/*'
- '*/openshift-apps/*/templates/*'
...

View file

@ -39,7 +39,7 @@ RewriteRule ^/released/i/m/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/released/imapsync https://pagure.io/releases/imapsync [R=301]
RewriteRule ^/fedora-infrastructure/report https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://forge.fedoraproject.org/infra/tickets/$1 [R=301]
RewriteRule ^/fedora-infrastructure/ticket/(.*) https://forge.fedoraproject.org/infra/tickets/issues/$1 [R=301]
RewriteRule ^/fedora-infrastructure https://forge.fedoraproject.org/infra/tickets [R=301]
RewriteRule ^/fesco/report https://pagure.io/fesco/issues [R=301]

1483
files/scripts/ansilog-playbook.py Executable file

File diff suppressed because it is too large Load diff

View file

@ -1848,9 +1848,9 @@ def _cmd_host(args):
def _cmdline_arg_ansi(oval):
val = oval.lower()
if val in ("yes", "on", "1", "always"):
if val in ("true", "y", "yes", "on", "1", "always"):
return True
if val in ("no", "off", "0", "never"):
if val in ("false", "n", "no", "off", "0", "never"):
return False
if val in ("automatic", "?", "tty", "auto"):
return None

View file

@ -3,7 +3,7 @@
# BEGIN: Ansible roles_path variables
#
# Background/reference about external repos pulled in:
# https://forge.fedoraproject.org/infra/tickets/5476
# https://forge.fedoraproject.org/infra/tickets/issues/5476
#
# IPA settings
additional_host_keytabs: []
@ -333,6 +333,7 @@ zabbix_httpapi_use_ssl: true
zabbix_httpapi_validate_certs: false
zabbix_url_path: "" # If Zabbix WebUI runs on non-default (zabbix) path ,e.g. http://<FQDN>/zabbixeu
# Zabbix agent vars
zabbix_agentd: /etc/zabbix_agentd.conf # Needed for zabbix_sender in other roles
zabbix_host: "zabbix01{{ env_suffix }}.{{ datacenter }}.fedoraproject.org"
zabbix_tls_psk_identity: "Fedora"
zabbix_tls_psk: "{{ zabbix_tls_prod_psk }}" # in ansible-private repo

View file

@ -24,6 +24,7 @@ ipa_client_shell_groups:
- sysadmin-datanommer
- sysadmin-debuginfod
- sysadmin-epel
- sysadmin-gpu
- sysadmin-koschei
- sysadmin-libravatar
- sysadmin-messaging

View file

@ -46,6 +46,14 @@ builders:
ppc64le: [15, 5, 15]
p09_hypervisor_04:
ppc64le: [15, 5, 15]
hp_p09_hypervisor_01:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_02:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_03:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_04:
ppc64le: [1, 1, 1]
x86_hypervisor_01:
x86_64: [20, 4, 20]
x86_hypervisor_02:
@ -208,7 +216,7 @@ aws_cloudfront_distribution: E2PUZIRCXCOXTG
nrpe_client_uid: 500
rsnapshot_push:
server_host: storinator01.rdu-cc.fedoraproject.org
server_host: storinator01.fedoraproject.org
backup_dir: /srv/nfs/copr-be
cases:
copr-be-copr-user:
@ -221,7 +229,7 @@ rsnapshot_push:
deployment_type: prod
pulp_content_url: "https://console.redhat.com/api/pulp-content/public-copr/"
pulp_content_url: "https://packages.redhat.com/api/pulp-content/public-copr/"
zabbix_host: 38.145.32.41
zabbix_macros:

View file

@ -45,6 +45,14 @@ builders:
ppc64le: [1, 1, 1]
p09_hypervisor_04:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_01:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_02:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_03:
ppc64le: [1, 1, 1]
hp_p09_hypervisor_04:
ppc64le: [1, 1, 1]
x86_hypervisor_01:
x86_64: [2, 1, 1]
x86_hypervisor_02:
@ -184,6 +192,6 @@ aws_cloudfront_distribution: EX55ITR8LVMOH
nrpe_client_uid: 500
pulp_content_url: "https://console.redhat.com/api/pulp-content/public-copr-stage/"
pulp_content_url: "https://packages.redhat.com/api/pulp-content/public-copr-stage/"
zabbix_host: 38.145.32.42

View file

@ -106,6 +106,7 @@ dl_tier1:
- zaphod.gtlib.gatech.edu # 128.61.111.12
- sv.mirrors.kernel.org
- dfw.mirrors.kernel.org
- mirror.raiolanetworks.com # 91.132.103.246 / 2a12:d282:102:f6::1
ipa_host_group: download
ipa_host_group_desc: Download servers
nagios_Check_Services:

13
inventory/group_vars/gpu Normal file
View file

@ -0,0 +1,13 @@
---
primary_auth_source: ipa
freezes: false
ipa_client_shell_groups:
- sysadmin-gpu
ipa_client_sudo_groups:
- sysadmin-gpu
ipa_host_group: gpu
ipa_host_group_desc: gpu servers
notes: |
gpu machine for testing fedora with gpus

View file

@ -48,3 +48,4 @@ wsgi_procs: 20
wsgi_threads: 5
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'
postfix_group: pkgs

View file

@ -43,3 +43,4 @@ wsgi_procs: 4
wsgi_threads: 4
zabbix_macros:
'VFS.FS.FSTYPE.MATCHES': '^(btrfs|ext2|ext3|ext4|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|zfs|nfs)$'
postfix_group: pkgs

View file

@ -62,3 +62,13 @@ network_connections:
nrpe_procs_crit: 1400
nrpe_procs_warn: 1200
weblate_backup_topdir: /fedora_backups/misc/weblate
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2012-12-31"
hardware: PowerEdge R650
location: RDU3
oob_ip: 10.3.160.099
serialno_a: 717DRT3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -50,3 +50,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.012
serialno_a: 2TFSHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -51,3 +51,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.013
serialno_a: 2TFTHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -50,3 +50,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.014
serialno_a: 2TGRHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.015
serialno_a: 2TGSHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.019
serialno_a: 2THTHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.021
serialno_a: 2TBTHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.022
serialno_a: 2TCRHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.024
serialno_a: 2TFRHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-05-27"
date_hw_purchase: "2016-05-26"
hardware: PowerEdge FC430
location: RDU3
oob_ip: 10.3.160.025
serialno_a: 2TCSHB2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -5,3 +5,13 @@ eth0_ipv4_ip: 10.16.172.23
ipa_server: ipa01.rdu3.fedoraproject.org
resolvconf: "resolv.conf/rdu3"
vmhost: bvmhost-x86-riscv01.rdu3.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-10-12"
date_hw_purchase: "2024-01-31"
hardware: PowerEdge R450
location: RDU3
serialno_a: D922FZ3
type: Build_Vmserver
vendor: Dell

View file

@ -59,3 +59,13 @@ network_connections:
mtu: 1500
nrpe_procs_crit: 4500
nrpe_procs_warn: 4000
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-07-20"
date_hw_purchase: "2024-01-31"
hardware: Mt Snow
location: RDU3
serialno_a: 231001325
type: Build_Vmserver
vendor: Ampere/Gigabyte

View file

@ -57,3 +57,13 @@ nrpe_procs_crit: 4500
nrpe_procs_warn: 4000
zabbix_macros:
NET.IF.IFNAME.NOT_MATCHES: "^vnet.*"
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-07-20"
date_hw_purchase: "2024-01-30"
hardware: Mt Snow
location: RDU3
serialno_a: 231001329
type: Build_Vmserver
vendor: Ampere/Gigabyte

View file

@ -59,3 +59,13 @@ network_connections:
mtu: 1500
nrpe_procs_crit: 4500
nrpe_procs_warn: 4000
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-07-20"
date_hw_purchase: "2024-01-31"
hardware: Mt Snow
location: RDU3
serialno_a: 231001328
type: Build_Vmserver
vendor: Ampere/Gigabyte

View file

@ -59,3 +59,13 @@ network_connections:
mtu: 1500
nrpe_procs_crit: 4500
nrpe_procs_warn: 4000
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-07-20"
date_hw_purchase: "2024-01-31"
hardware: Mt Snow
location: RDU3
serialno_a: 231001327
type: Build_Vmserver
vendor: Ampere/Gigabyte

View file

@ -59,3 +59,13 @@ network_connections:
mtu: 1500
nrpe_procs_crit: 4500
nrpe_procs_warn: 4000
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-07-20"
date_hw_purchase: "2024-01-31"
hardware: Mt Snow
location: RDU3
serialno_a: 231001326
type: Build_Vmserver
vendor: Ampere/Gigabyte

View file

@ -60,3 +60,14 @@ nrpe_procs_crit: 13000
nrpe_procs_warn: 12000
zabbix_macros:
MEMORY.AVAILABLE.MIN: 0
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2027-01-31"
date_hw_purchase: "2021-11-19"
hardware: Power 9 9183-22x
location: RDU3
oob_ip: 10.3.160.62
serialno_a: 780483A
type: Build_vmServer
vendor: IBM

View file

@ -3,4 +3,4 @@ dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: rdu3.fedoraproject.org
nbde: false
zabbix_ping_only: true # no agent access on this host
zabbix_ping_only: false

View file

@ -4,4 +4,4 @@ dns1: 10.16.163.33
dns2: 10.16.163.34
dns_search1: rdu3.fedoraproject.org
nbde: false
zabbix_ping_only: true # no agent access on this host
zabbix_ping_only: false

View file

@ -58,3 +58,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2018-04-12"
hardware: PowerEdge R630
location: RDU3
oob_ip: 10.3.160191
serialno_a: CLTKMN2
type: #Build vm hosts - Other
vendor: Dell

View file

@ -58,3 +58,13 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2022-12-31"
hardware: PowerEdge R650
location: RDU3
oob_ip: 10.3.160.192
serialno_a: 3ZGTRT3
type: Staging_Vmserver
vendor: Dell

View file

@ -58,3 +58,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2018-04-12"
hardware: PowerEdge R630
location: RDU3
oob_ip: 10.3.160.193
serialno_a: CLTDMN2
type: #Build vm hosts - Other
vendor: Dell

View file

@ -0,0 +1,54 @@
---
datacenter: rdu3
dns1: 10.16.163.33
br0_ipv4_ip: 10.16.179.35
br0_ipv4_gw: 10.16.179.254
br0_ipv4_nm: 24
has_ipv4: yes
has_ipv6: no
mac0: c4:cb:e1:ed:b1:6e
mac1: c4:cb:e1:ed:b1:6f
mac2: 30:3e:a7:2a:65:28
mac3: 30:3e:a7:2a:65:29
mac4: 30:3e:a7:2a:65:2a
mac5: 30:3e:a7:2a:65:2b
network_connections:
# Bridge profile
- name: br0
state: up
type: bridge
mtu: 1500
autoconnect: yes
ip:
address:
- "{{ br0_ipv4_ip }}/{{ br0_ipv4_nm }}"
dhcp4: no
dns:
- "{{ dns1 }}"
- "{{ dns2 }}"
dns_search:
- "{{ dns_search1 }}"
- "{{ dns_search2 }}"
gateway4: "{{ br0_ipv4_gw }}"
# Bond profile
- name: bond0
type: bond
interface_name: bond0
mtu: 1500
controller: br0
bond:
mode: 802.3ad
# Port profile for the 1st Ethernet device
- name: bond0-port1
mac: "{{ mac2 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500
# Port profile for the 2nd Ethernet device
- name: bond0-port2
mac: "{{ mac3 }}"
type: ethernet
controller: bond0
state: up
mtu: 1500

View file

@ -63,3 +63,13 @@ nrpe_procs_warn: 1250
postfix_group: vpn
vpn: true
notes: "vhost at ibiblio"
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2022-12-20"
hardware: PowerEdge R750
location: RDU3
serialno_a: 2KC66X3
type: Web_Vmserver
vendor: Dell

View file

@ -66,3 +66,12 @@ vpn: true
zabbix_macros:
VFS.DEV.READ.AWAIT.WARN: 100
VFS.DEV.WRITE.AWAIT.WARN: 100
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2015-06-29"
hardware: PowerEdge R630
location: RDU3
serialno_a: 4T05S52
type: Web_Vmserver
vendor: Dell

View file

@ -48,3 +48,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2029-02-10"
date_hw_purchase: "2024-04-15"
hardware: PowerEdge R650
location: RDU3
oob_ip: 10.3.160.066
serialno_a: F76HC14
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -20,5 +20,5 @@ root_auth_users: msuchy frostyx praiskup nikromen ttomecek jpodivin sgallagh mma
nrpe_client_uid: 500
tcp_ports: [
22, 80, 443,
22, 80, 443, 8090,
]

View file

@ -77,3 +77,14 @@ sudoers: "{{ private }}/files/sudo/qavirt-sudoers"
# $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002;
# so for worker 1 it's 20012, for worker 2 it's 20022, etc etc
tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153', '20163', '20173', '20183', '20193', '20203', '20213', '20223', '20233', '20243', '20253', '20263', '20273', '20283', '20293', '20303', '20313', '20323', '20333', '20343', '20353', '20363', '20373', '20383', '20393', '20403', '20413', '20423', '20433', '20443', '20453', '20463', '20473', '20483', '20493', '20503', '20513', '20523', '20533', '20543', '20553', '20563', '20573', '20583', '20593', '20603']
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2019-12-20"
hardware: PowerEdge R640
location: RDU3
oob_ip: 10.3.160.137
serialno_a: 1483H13
type: QA_Dedicated_HW
vendor: Dell

View file

@ -77,3 +77,14 @@ sudoers: "{{ private }}/files/sudo/qavirt-sudoers"
# $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002;
# so for worker 1 it's 20012, for worker 2 it's 20022, etc etc
tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153', '20163', '20173', '20183', '20193', '20203', '20213', '20223', '20233', '20243', '20253', '20263', '20273', '20283', '20293', '20303', '20313', '20323', '20333', '20343', '20353', '20363', '20373', '20383', '20393', '20403', '20413', '20423', '20433', '20443', '20453', '20463', '20473', '20483', '20493', '20503', '20513', '20523', '20533', '20543', '20553', '20563', '20573', '20583', '20593', '20603']
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2019-09-22"
hardware: PowerEdge R640
location: RDU3
oob_ip: 10.3.160.138
serialno_a: 8693MR2
type: QA_Dedicated_HW
vendor: Dell

View file

@ -77,3 +77,12 @@ sudoers: "{{ private }}/files/sudo/qavirt-sudoers"
# $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002;
# so for worker 1 it's 20012, for worker 2 it's 20022, etc etc
tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153', '20163', '20173', '20183', '20193', '20203', '20213', '20223', '20233', '20243', '20253', '20263', '20273', '20283', '20293', '20303', '20313', '20323', '20333', '20343', '20353', '20363', '20373', '20383', '20393', '20403', '20413', '20423', '20433', '20443', '20453', '20463', '20473', '20483', '20493', '20503', '20513', '20523', '20533', '20543', '20553', '20563', '20573', '20583', '20593', '20603']
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2021-01-13"
hardware: PowerEdge R630
location: RDU3
serialno_a: CLTGMN2
type: QA_Dedicated_HW
vendor: Dell

View file

@ -77,3 +77,14 @@ sudoers: "{{ private }}/files/sudo/qavirt-sudoers"
# $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002;
# so for worker 1 it's 20012, for worker 2 it's 20022, etc etc
tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153', '20163', '20173', '20183', '20193', '20203', '20213', '20223', '20233', '20243', '20253', '20263', '20273', '20283', '20293', '20303', '20313', '20323', '20333', '20343', '20353', '20363', '20373', '20383', '20393', '20403', '20413', '20423', '20433', '20443', '20453', '20463', '20473', '20483', '20493', '20503', '20513', '20523', '20533', '20543', '20553', '20563', '20573', '20583', '20593', '20603']
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2018-09-22"
hardware: PowerEdge R640
location: RDU3
oob_ip: 10.3.160.053
serialno_a: 8692MR2
type: QA_Dedicated_HW
vendor: Dell

View file

@ -77,3 +77,11 @@ sudoers: "{{ private }}/files/sudo/qavirt-sudoers"
# $ENV{QEMUPORT} = ($options{instance}) * 10 + 20002;
# so for worker 1 it's 20012, for worker 2 it's 20022, etc etc
tcp_ports: ['20013', '20023', '20033', '20043', '20053', '20063', '20073', '20083', '20093', '20103', '20113', '20123', '20133', '20143', '20153', '20163', '20173', '20183', '20193', '20203', '20213', '20223', '20233', '20243', '20253', '20263', '20273', '20283', '20293', '20303', '20313', '20323', '20333', '20343', '20353', '20363', '20373', '20383', '20393', '20403', '20413', '20423', '20433', '20443', '20453', '20463', '20473', '20483', '20493', '20503', '20513', '20523', '20533', '20543', '20553', '20563', '20573', '20583', '20593', '20603']
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
hardware: PowerEdge R630
location: RDU3
serialno_a: CLTHMN2
type: QA_Dedicated_HW
vendor: Dell

View file

@ -31,3 +31,11 @@ network_connections:
nrpe_procs_crit: 2500
nrpe_procs_warn: 2000
virthost: true
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_purchase: "2024-05-01"
hardware: PowerEdge R650
location: RDU3
serialno_a: 2RH5X04
vendor: Dell

View file

@ -52,3 +52,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2018-04-18"
hardware: PowerEdge R430
location: RDU3
oob_ip: 10.3.160.132
serialno_a: 1VHTMN2
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -8,7 +8,7 @@ dns2: 10.16.163.34
dns_search1: "rdu3.fedoraproject.org"
dns_search2: "fedoraproject.org"
has_ipv4: yes
mac0: c4:cb:e1:e1:56:1c
mac0: c4:cb:e1:e1:56:1c
mac1: c4:cb:e1:e1:56:1d
mac2: c4:70:bd:c8:cf:cc
mac3: c4:70:bd:c8:cf:cd
@ -52,3 +52,13 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2028-10-12"
date_hw_purchase: "2024-01-31"
hardware: PowerEdge R450
location: RDU3
serialno_a: G922FZ3
type: Prod_Dedicated_HW
vendor: Dell

View file

@ -19,8 +19,9 @@ mac3: "b8:ce:f6:c6:00:c7"
mac4: "b8:ce:f6:c6:00:d0"
mac5: "b8:ce:f6:c6:00:d1"
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_p09_01
libvirt_pool_order_id: 4
libvirt_pools:
- name: vmhost_p09_01
- name: vmhost_p_p09_01
libvirt_arch: ppc64le
network_connections:
# Bridge profile
@ -65,3 +66,13 @@ network_connections:
state: up
mtu: 1500
zabbix_host: zabbix01.vpn.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2027-01-31"
date_hw_purchase: "2021-09-29"
hardware: Power 9 9183-22X
location: RDU3
serialno_a: 780484A
type: #bvmhost-p09-01.stg.rdu3.fedoraproject.org - Other
vendor: IBM

View file

@ -22,8 +22,9 @@ mac7: ac:1f:6b:a5:4e:f5
mac8: ac:1f:6b:a5:4e:f6
mac9: ac:1f:6b:a5:4e:f7
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_p09_02
libvirt_pool_order_id: 0
libvirt_pools:
- name: vmhost_p09_02
- name: vmhost_p_p09_02
libvirt_arch: ppc64le
network_connections:
# Bridge profile

View file

@ -22,8 +22,9 @@ mac7: ac:1f:6b:8a:9a:31
mac8: ac:1f:6b:8a:9a:32
mac9: ac:1f:6b:8a:9a:33
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_p09_03
libvirt_pool_order_id: 1
libvirt_pools:
- name: vmhost_p09_03
- name: vmhost_p_p09_03
libvirt_arch: ppc64le
network_connections:
# Bridge profile

View file

@ -22,8 +22,9 @@ mac7: ac:1f:6b:a4:e3:b1
mac8: ac:1f:6b:a4:e3:b2
mac9: ac:1f:6b:a4:e3:b3
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_p09_04
libvirt_pool_order_id: 2
libvirt_pools:
- name: vmhost_p09_04
- name: vmhost_p_p09_04
libvirt_arch: ppc64le
network_connections:
# Bridge profile

View file

@ -58,3 +58,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2029-02-17"
date_hw_purchase: "2024-04-15"
hardware: PowerEdge R650
location: RDU3
oob_ip: 10.3.160.057
serialno_a: B61SW04
type: Staging_Vmserver
vendor: Dell

View file

@ -58,3 +58,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2023-04-29"
date_hw_purchase: "2016-04-28"
hardware: PowerEdge R630
location: RDU3
oob_ip: 10.3.160.033
serialno_a: 8FVCGB2
type: Staging_Vmserver
vendor: Dell

View file

@ -58,3 +58,14 @@ network_connections:
controller: bond0
state: up
mtu: 1500
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2025-01-01"
date_hw_purchase: "2017-02-20"
hardware: PowerEdge R630
location: RDU3
oob_ip: 10.3.160.036
serialno_a: 8D3NCH2
type: Staging_Vmserver
vendor: Dell

View file

@ -16,12 +16,12 @@ mac2: 84:16:0c:bc:3a:60
mac3: b4:96:91:63:3b:e8
mac4: 84:16:0c:bc:3a:60
mac5: b4:96:91:63:3b:e9
mac6: b4:96:91:63:3b:ea
mac6: b4:96:91:63:3b:ea
mac7: b4:96:91:63:3b:eb
mac8: f4:02:70:d3:15:95
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_x86_01
libvirt_pool_order_id: 7
libvirt_pools:
- name: vmhost_x86_01
libvirt_arch: x86_64
network_connections:
# Bridge profile
@ -69,9 +69,12 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2026-12-31"
date_hw_purchase: "2020-01-10"
hardware: PowerEdge R6525
location: RDU3
oob_ip: 10.16.160.23
serialno_a: BM4LS13
site_rack: W34 U18
type: #autosign01.rdu3.fedoraproject.org
vendor: Dell

View file

@ -19,8 +19,8 @@ mac5: 84:16:0c:bc:24:e0
mac6: b4:96:91:63:3b:9e
mac7: b4:96:91:63:3b:9f
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_x86_02
libvirt_pool_order_id: 8
libvirt_pools:
- name: vmhost_x86_02
libvirt_arch: x86_64
network_connections:
# Bridge profile
@ -68,9 +68,12 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2026-12-31"
date_hw_purchase: "2020-01-10"
hardware: PowerEdge R6525
location: RDU3
oob_ip: 10.16.160.24
serialno_a: BM4MS13
site_rack: W34 U19
type: #autosign01.rdu3.fedoraproject.org
vendor: Dell

View file

@ -19,8 +19,8 @@ mac5: "b4:96:91:63:3b:51"
mac6: "b4:96:91:63:3b:52"
mac7: "b4:96:91:63:3b:53"
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_x86_03
libvirt_pool_order_id: 9
libvirt_pools:
- name: vmhost_x86_03
libvirt_arch: x86_64
network_connections:
# Bridge profile
@ -68,9 +68,12 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2026-12-31"
date_hw_purchase: "2020-01-10"
hardware: PowerEdge R6525
location: RDU3
oob_ip: 10.16.160.25
serialno_a: BM4KS13
site_rack: W34 U20
type: #autosign01.rdu3.fedoraproject.org
vendor: Dell

View file

@ -19,8 +19,8 @@ mac5: "b4:96:91:63:3a:a1"
mac6: "b4:96:91:63:3a:a2"
mac7: "b4:96:91:63:3a:a3"
libvirt_host: "[{{ br0_ipv6_ip }}]"
libvirt_pool: vmhost_x86_04
libvirt_pool_order_id: 3
libvirt_pools:
- name: vmhost_x86_04
libvirt_arch: x86_64
network_connections:
# Bridge profile
@ -68,9 +68,12 @@ zabbix_host: zabbix01.vpn.fedoraproject.org
# This is used to populate the inventory fields, only specific keys are allowed, see
# https://www.zabbix.com/documentation/current/en/manual/api/reference/host/object#host-inventory
zabbix_inventory:
date_hw_expiry: "2026-12-31"
date_hw_purchase: "2020-01-10"
hardware: PowerEdge R6525
location: RDU3
oob_ip: 10.16.160.26
serialno_a: BM3RS13
site_rack: BB34 U18
type: #autosign01.rdu3.fedoraproject.org
vendor: Dell

View file

@ -249,6 +249,9 @@ download_ibiblio
download_iso_rdu3
download_rdu3
[gpu]
gpu01.rdu3.fedoraproject.org
[kernel_qa]
kernel02.rdu3.fedoraproject.org

View file

@ -8,18 +8,37 @@
vars:
# Add files here for things that store data in /etc/
known_prefixes:
- /etc/builder-keytabs
- /etc/containers/systemd/ipatuura.container
- /etc/dnf/modules.d
- /etc/dirsrv/slapd-FEDORAPROJECT-ORG
- /etc/dirsrv/slapd-STG-FEDORAPROJECT-ORG
- /etc/gconf/gconf.xml.defaults
- /etc/ipa-tuura
- /etc/ipatuura-container-config
- /etc/java/java-11-openjdk # rpm:*.aarch64/lib/security/blacklisted.certs
- /etc/letsencrypt/accounts
- /etc/letsencrypt/archive
- /etc/letsencrypt/csr
- /etc/letsencrypt/keys
- /etc/letsencrypt/live # ?
- /etc/letsencrypt/renewal # ?
- /etc/lvm/archive
- /etc/lvm/backup
- /etc/lvm/devices/backup
- /etc/dirsrv/slapd-STG-FEDORAPROJECT-ORG
- /etc/libvirt/storage
- /etc/libvirt/qemu
- /etc/mailman3/__pycache__
- /etc/mock/koji
- /etc/NetworkManager/system-connections
- /etc/nagios # Getting rid of nagios and there are 666 files.
- /etc/nrpe.d # Getting rid of nagios and there are 666 files.
- /etc/openshift_apps # FIXME: ?
- /etc/openvpn/server/ccd # ?
- /etc/openvpn/server/ccd.bad
- /etc/pki/ca-trust/extracted/pem/directory-hash # ? lots of files.
- /etc/pki/pki-tomcat/ca/archives
- /etc/udev/rules.d
- /etc/ipatuura-container-config
- /etc/containers/systemd/ipatuura.container
- /etc/ipa-tuura
# Add files here that you know are safe but aren't from an RPM
known_filenames:
@ -30,21 +49,118 @@
# Email aliases files:
- /etc/aliases.db
- /etc/aliases.lmdb
- /etc/aliases.static
# Ansible files:
- /etc/ansible/facts.d/install_date.fact
# Ansubis files:
- /etc/anubis/policies.yaml
# AWstats files:
- /etc/awstats/awstats.log01.rdu3.fedoraproject.org.conf
# Bodhi files:
- /etc/bodhi/celeryconfig.py
- /etc/bodhi/createrepo_c.ini
- /etc/bodhi/logging.yaml
- /etc/bodhi/pungi_general.conf
- /etc/bodhi/pungi_multilib.conf
# Dracut files:
- /etc/dracut.conf.d/local.conf
- /etc/dracut.conf.d/nbde_client.conf
- /etc/dracut.conf.d/sgdisk.conf
- /etc/dracut.conf.d/xen.conf
# CollectD files:
- /etc/collectd.d/bind.conf
- /etc/collectd.d/fmn.conf
- /etc/collectd.d/memcached.conf
- /etc/collectd.d/network.conf
- /etc/collectd.d/nfs.conf
- /etc/collectd.d/postgres.conf
- /etc/collectd.d/unixsock.conf
- /etc/collectd.d/vfive-upgrade.conf
# Our crond conf files:
- /etc/cron.daily/cleanup-stage-users
- /etc/cron.daily/data-only-backup.sh
- /etc/cron.daily/freshclam
- /etc/cron.daily/grab-daily-logs
- /etc/cron.daily/rotatelogs-cleanup.
- /etc/cron.daily/sync-http-logs-and-merge.sh
# prod, roughly
- /etc/cron.d/ansible-make-git-checkout-seed
- /etc/cron.d/bodhi-automated-pushes
- /etc/cron.d/branched
- /etc/cron.d/bz-review-report.cron
- /etc/cron.d/cgit-clean-lock.cron
- /etc/cron.d/check-broken-planet.cron
- /etc/cron.d/cloud-image-stat.cron
- /etc/cron.d/cloud-updates
- /etc/cron.d/compress-log.cron
- /etc/cron.d/condense-mirrorlogs.cron
- /etc/cron.d/container-updates
- /etc/cron.d/countme-update.cron
- /etc/cron.d/cron-backup-anitya-public
- /etc/cron.d/cron-backup-database-anitya
- /etc/cron.d/cron-backup-database-blockerbugs
- /etc/cron.d/cron-backup-database-bodhi2
- /etc/cron.d/cron-backup-database-datanommer2
- /etc/cron.d/cron-backup-database-elections
- /etc/cron.d/cron-backup-database-fedocal
- /etc/cron.d/cron-backup-database-fpo-mediawiki
- /etc/cron.d/cron-backup-database-hyperkitty
- /etc/cron.d/cron-backup-database-ipsilon
- /etc/cron.d/cron-backup-database-kerneltest
- /etc/cron.d/cron-backup-database-koji
- /etc/cron.d/cron-backup-database-koschei
- /etc/cron.d/cron-backup-database-mailman
- /etc/cron.d/cron-backup-database-mirrormanager2
- /etc/cron.d/cron-backup-database-notifications
- /etc/cron.d/cron-backup-database-openqa
- /etc/cron.d/cron-backup-database-openqa-stg
- /etc/cron.d/cron-backup-database-pagure
- /etc/cron.d/cron-backup-database-postgres
- /etc/cron.d/cron-backup-database-resultsdb
- /etc/cron.d/cron-backup-database-tahrir
- /etc/cron.d/cron-backup-database-testdays
- /etc/cron.d/cron-backup-database-testdays_resultsdb
- /etc/cron.d/cron-backup-database-transtats
- /etc/cron.d/cron-backup-database-waiverdb
- /etc/cron.d/cron-backup-database-webhook2fedmsg
- /etc/cron.d/cron-backup-database-zezere
- /etc/cron.d/cron-docs-translation-update
- /etc/cron.d/cron-weblate-backup
- /etc/cron.d/directory-sizes-update
- /etc/cron.d/download-sync
- /etc/cron.d/eln
- /etc/cron.d/f42-bootc
- /etc/cron.d/f43-compose
- /etc/cron.d/f44-compose
- /etc/cron.d/fasjson-aliases
- /etc/cron.d/grokfsck.cron
- /etc/cron.d/grokmirror.cron
- /etc/cron.d/koji-directory-cleanup
- /etc/cron.d/koji-gc
- /etc/cron.d/koji-prune-signed-copies
- /etc/cron.d/koji-sidetag-cleanup
- /etc/cron.d/linuxsystemroles-logs-clean
- /etc/cron.d/make-people-git
- /etc/cron.d/make-people-page.cron
- /etc/cron.d/package-owner-aliases
- /etc/cron.d/rawhide
- /etc/cron.d/rawhide-compose
- /etc/cron.d/run-rdiff-backups
- /etc/cron.d/sig_policy
- /etc/cron.d/torrent-hash.cron
- /etc/cron.d/torrent-web-generate
- /etc/cron.d/updates-sync
- /etc/cron.d/update-fullfiletimelist
- /etc/cron.d/update-koji-owner
# stg, roughly
- /etc/cron.d/ansible-check-update-hooks
- /etc/cron.d/ansible-clamscan
- /etc/cron.d/budget-sync
@ -76,6 +192,11 @@
- /etc/cron.d/sync-mirrors
- /etc/cron.d/sync-start
- /etc/cron.d/cron-backup-database-fas2
- /etc/cron.d/sa-update
- /etc/cron.weekly/ftbfs.cron
# dconf files:
- /etc/dconf/db/distro
- /etc/dconf/db/local
@ -84,19 +205,34 @@
# dnf plugin files:
- /etc/dnf/libdnf5-plugins/actions.d/mod_wsgi.actions
# docker! files:
- /etc/docker/certs.d/registry.fedoraproject.org/client.cert
- /etc/docker/certs.d/registry.fedoraproject.org/client.key
- /etc/docker/certs.d/registry.stg.fedoraproject.org/client.cert
- /etc/docker/certs.d/registry.stg.fedoraproject.org/client.key
- /etc/fedora-gather-easyfix/template.html
# fedora-messaging files:
- /etc/fedora-messaging/config.toml
- /etc/fedora-messaging/faf/ca.crt # These should be under /etc/pki?
- /etc/fedora-messaging/faf/faf.crt
- /etc/fedora-messaging/faf/faf.key
- /etc/fedora-messaging/git-hooks-messaging.toml
- /etc/fedora-messaging/koji_sync_listener.toml
- /etc/fedora-messaging/ursabot.toml
- /etc/fedora-messaging/zodbot.toml
# ftbfs files:
- /etc/ftbfs.cfg
# gitconfig files:
- /etc/gitconfig
- /etc/gssproxy/10-ipa.conf
# haproxy files:
# HAproxy files:
- /etc/haproxy/503.http
- /etc/haproxy/ipa.pem
- /etc/haproxy/ocp-stg.pem
- /etc/haproxy/ocp-stg-rdu3.pem
@ -899,27 +1035,26 @@
- /etc/httpd/conf.d/zabbix.stg.fedoraproject.org/securityheaders.conf
- /etc/httpd/conf.d/zabbix.stg.fedoraproject.org/zabbix.conf
- /etc/httpd/conf.d/compose.conf
- /etc/httpd/conf.d/fp.conf
- /etc/httpd/conf.d/freemedia-app.conf
- /etc/httpd/conf.d/geoip-city-wsgi.conf
- /etc/httpd/conf.d/ipa-tuura.conf
- /etc/httpd/conf.d/infrastructure.fedoraproject.org.conf
- /etc/httpd/conf.d/kojiweb-stg.conf
- /etc/httpd/conf.d/mailmanweb.conf
- /etc/httpd/conf.d/meetbot.conf
- /etc/httpd/conf.d/nss.conf
- /etc/httpd/conf.d/pager-app.conf
- /etc/httpd/conf.d/referer-override.conf
- /etc/httpd/conf.d/rel-eng.conf
- /etc/httpd/conf.d/repo.conf
- /etc/httpd/conf.d/testproxy.conf
- /etc/httpd/conf.d/wsgi.conf
- /etc/httpd/conf/cacert.pem
- /etc/httpd/conf/pkgs.fedoraproject.org_key_and_cert.pem
- /etc/httpd/conf.d/freemedia-app.conf
- /etc/httpd/conf.d/geoip-city-wsgi.conf
- /etc/httpd/conf.d/pager-app.conf
- /etc/httpd/conf.d/wsgi.conf
- /etc/httpd/conf.d/kojiweb-stg.conf
- /etc/httpd/conf.d/rel-eng.conf
- /etc/httpd/conf.d/repo.conf
- /etc/httpd/conf.d/ipa-tuura.conf
- /etc/httpd/ticketkey_staging.tkey
# IPA files:
@ -928,89 +1063,120 @@
- /etc/ipa/custodia/custodia.conf
- /etc/ipa/custodia/server.keys
# ipsilon files:
- /etc/ipsilon/root/configuration.conf
- /etc/ipsilon/root/idp.conf
- /etc/ipsilon/root/install_changes
- /etc/ipsilon/root/ipsilon.conf
- /etc/ipsilon/root/openidc.key
- /etc/ipsilon/root/openidc.static.cfg
- /etc/ipsilon/root/saml2/idp.crt
- /etc/ipsilon/root/saml2/idp.key
- /etc/ipsilon/root/saml2/metadata.xml
# Kerberos keytab files:
- /etc/dirsrv/ds.keytab
- /etc/httpd.keytab
- /etc/httpd.keytab # Move to below?
- /etc/httpd/conf/http.keytab
- /etc/kojid/kojid.keytab
- /etc/koji-hub/koji-hub.keytab
- /etc/krb5.keytab
- /etc/krb5.releng.keytab
- /etc/pkgs.keytab
- /etc/krb5.HTTP_admin.fedoraproject.org.keytab
- /etc/krb5.HTTP_id.fedoraproject.org.keytab
- /etc/krb5.HTTP_id.fedoraproject.org.keytab.combined
- /etc/krb5.HTTP_koji.fedoraproject.org.keytab
- /etc/krb5.HTTP_nagios.fedoraproject.org.keytab
- /etc/krb5.HTTP_nagios-external.fedoraproject.org.keytab
- /etc/krb5.HTTP_riscv-koji.fedoraproject.org.keytab
- /etc/krb5.bodhi_bodhi.fedoraproject.org.keytab
- /etc/krb5.compose_koji.fedoraproject.org.keytab
- /etc/krb5.compose_riscv-koji.fedoraproject.org.keytab
- /etc/krb5.kojira_koji.fedoraproject.org.keytab
- /etc/krb5.kojira_koji.stg.fedoraproject.org.keytab
- /etc/krb5.kojira_riscv-koji.fedoraproject.org.keytab
- /etc/krb5.koji-gc_koji.fedoraproject.org.keytab
- /etc/krb5.koji-gc_koji.stg.fedoraproject.org.keytab
- /etc/krb5.koji-gc_riscv-koji.fedoraproject.org.keytab
- /etc/krb5.mash_koji.fedoraproject.org.keytab
- /etc/krb5.mash_koji.stg.fedoraproject.org.keytab
- /etc/krb5.monitoring_ipa01.rdu3.fedoraproject.org.keytab
- /etc/krb5.stage-users_ipa01.rdu3.fedoraproject.org.keytab
- /etc/krb5.zodbot_value01.rdu3.fedoraproject.org.keytab
- /etc/krb5.HTTP_id.stg.fedoraproject.org.keytab
- /etc/krb5.HTTP_id.stg.fedoraproject.org.keytab.combined
- /etc/krb5.HTTP_ipatuura01.stg.rdu3.fedoraproject.org.keytab
- /etc/krb5.HTTP_koji.stg.fedoraproject.org.keytab
- /etc/krb5.bodhi_bodhi.stg.fedoraproject.org.keytab
- /etc/krb5.compose_compose-x86-01.stg.rdu3.fedoraproject.org.keytab
- /etc/krb5.compose_koji.stg.fedoraproject.org.keytab
- /etc/krb5.monitoring_ipa01.stg.rdu3.fedoraproject.org.keytab
- /etc/krb5.stage-users_ipa01.stg.rdu3.fedoraproject.org.keytab
- /etc/krb5.ursabot_value01.stg.rdu3.fedoraproject.org.keytab
# Kerberos files:
- /etc/krb5.conf.d/freeipa
- /etc/krb5.conf.d/freeipa-realm
- /etc/krb5.conf.d/freeipa-server
# Kernel/init files:
- /etc/kernel/cmdline
- /etc/modprobe.d/blacklist-nouveau.conf
- /etc/modprobe.d/disable-cdc_ether.conf
- /etc/modprobe.d/i40e.conf
- /etc/modprobe.d/kvm_intel.conf
- /etc/modules-load.d/nf_conntrack.conf
# KOJI files:
- /etc/kojid/plugins/flatpak.conf
- /etc/kojira/extras_cacert.pem
- /etc/kojira/kojira_cert_key.pem
- /etc/koji-hub/gssapi.keytab
- /etc/koji-osbuild/builder.conf
- /etc/koji.conf.d/bodhi.conf
- /etc/koji.conf.d/compose.conf
- /etc/kojid/plugins/flatpak.conf
# FIXME: ?
# FIXME: Seem sus bad name files:
- /etc/pki/tls/certs/extras_cacert.pem
- /etc/pki/tls/certs/extras_upload_cacert.pem
- /etc/pki/tls/certs/localhost.crt
- /etc/pki/tls/certs/upload_cacert.pem
- /etc/pki/tls/private/localhost.key
# logrotate files:
- /etc/logrotate.d/bittorrent
- /etc/logrotate.d/merged-rsyslog
- /etc/logrotate.d/mirrormanager
- /etc/logrotate.d/rsync-fedora
- /etc/logrotate.d/rsyslog
- /etc/logrotate.d/spamassassin
- /etc/logrotate.d/syslog
# LVM files:
- /etc/lvm/devices/system.devices
# Spam files:
- /etc/mail/spamassassin/sa-update-keys/pubring.kbx
- /etc/mail/spamassassin/sa-update-keys/trustdb.gpg
# Mailman files:
- /etc/mailman3/django_fedora_nosignup.py
- /etc/mailman3/gunicorn.conf.py
- /etc/mailman3/initial-data.json
- /etc/mailman3/settings_admin.py
- /etc/mailman3/urls.py
# MDADM files:
- /etc/mdadm.conf
- /etc/modprobe.d/kvm_intel.conf
# Named files:
- /etc/named/zones.conf
# NF Tables files:
- /etc/nftables/fedora-infra-ipv4.nft
- /etc/nftables/fedora-infra-ipv6.nft
# Nagios files:
- /etc/nrpe.d/check_basset.cfg
- /etc/nrpe.d/check_celery_redis_queue.cfg
- /etc/nrpe.d/check_countme.cfg
- /etc/nrpe.d/check_cron.cfg
- /etc/nrpe.d/check_datanommer_history.cfg
- /etc/nrpe.d/check_disk.cfg
- /etc/nrpe.d/check_fedmsg_composer_proc.cfg
- /etc/nrpe.d/check_fedmsg_consumers.cfg
- /etc/nrpe.d/check_fedmsg_gateway_proc.cfg
- /etc/nrpe.d/check_fedmsg_hub_proc.cfg
- /etc/nrpe.d/check_fedmsg_irc_proc.cfg
- /etc/nrpe.d/check_fedmsg_relay_proc.cfg
- /etc/nrpe.d/check_fmn.cfg
- /etc/nrpe.d/check_happroxy_conns.cfg
- /etc/nrpe.d/check_ipa.cfg
- /etc/nrpe.d/check_lock.cfg
- /etc/nrpe.d/check_lock_file_age.cfg
- /etc/nrpe.d/check_memcache.cfg
- /etc/nrpe.d/check_mirrorlist_cache.cfg
- /etc/nrpe.d/check_mirrorlist_docker_proxy.cfg
- /etc/nrpe.d/check_postfix_queue.cfg
- /etc/nrpe.d/check_postfix_redhat.cfg
- /etc/nrpe.d/check_proxies.cfg
- /etc/nrpe.d/check_raid.cfg
- /etc/nrpe.d/check_readonly_fs.cfg
- /etc/nrpe.d/check_redis_proc.cfg
- /etc/nrpe.d/check_rsyslogd_proc.cfg
- /etc/nrpe.d/check_swap.cfg
- /etc/nrpe.d/check_testcloud.cfg
- /etc/nrpe.d/check_websites_buildtime.cfg
- /etc/nrpe.d/check_varnish_proc.cfg
# NVME files:
- /etc/nvme/hostid
- /etc/nvme/hostnqn
@ -1022,24 +1188,32 @@
# OpenVPN files:
- /etc/openvpn/client/ca.crt
- /etc/openvpn/client/client.crt
- /etc/openvpn/client/client.key
- /etc/openvpn/client/openvpn.conf
- /etc/openvpn/fix-routes.sh
- /etc/openvpn/server/ca.crt
# PAM files:
- /etc/pam.d/mock
# Pagure files:
- /etc/pagure/client_secrets.json
- /etc/pagure/pagure_hook.cfg
- /etc/pagure/pagure_plugins.cfg
# PKI files:
- /etc/pki/ca-trust/extracted/pem/directory-hash/STG.FEDORAPROJECT.ORG_IPA_CA.pem
- /etc/pki/fedora-messaging/cacert.pem
- /etc/pki/fedora-messaging/mediawiki.stg-cert.pem
- /etc/pki/fedora-messaging/mediawiki.stg-key.pem
- /etc/pki/fedora-messaging/bodhi-cert.pem
- /etc/pki/fedora-messaging/bodhi-key.pem
- /etc/pki/fedora-messaging/ca.crt
- /etc/pki/fedora-messaging/cacert.pem
- /etc/pki/fedora-messaging/ipa.stg.crt
- /etc/pki/fedora-messaging/ipa.stg.key
- /etc/pki/fedora-messaging/mediawiki.stg-cert.pem
- /etc/pki/fedora-messaging/mediawiki.stg-key.pem
- /etc/pki/fedora-messaging/rabbitmq-ca.crt
- /etc/pki/fedora-messaging/rabbitmq-pungi.crt
- /etc/pki/fedora-messaging/rabbitmq-pungi.key
- /etc/pki/fedora-messaging/ursabot.crt
- /etc/pki/fedora-messaging/ursabot.key
@ -1269,13 +1443,21 @@
- /etc/pki/tls/certs/wildcard-2025.id.fedoraproject.org.intermediate.cert
- /etc/pki/tls/certs/wildcard-2025.id.stg.fedoraproject.org.cert
- /etc/pki/tls/certs/wildcard-2025.id.stg.fedoraproject.org.intermediate.cert
- /etc/pki/tls/certs/wildcard-2025.fedorapeople.org.cert
- /etc/pki/tls/certs/wildcard-2025.fedorapeople.org.intermediate.cert
- /etc/pki/tls/certs/wildcard-2025.stg.fedoraproject.org.cert
- /etc/pki/tls/certs/wildcard-2025.stg.fedoraproject.org.intermediate.cert
- /etc/pki/tls/certs/wildcard-2026.stg.fedoraproject.org.cert
- /etc/pki/tls/certs/wildcard-2026.stg.fedoraproject.org.intermediate.cert
- /etc/pki/tls/private/br.fedoracommunity.org.key
- /etc/pki/tls/private/coreos.stg.fedoraproject.org.key
- /etc/pki/tls/private/epel.io.key
- /etc/pki/tls/private/fedora.im.key
- /etc/pki/tls/private/fedoracommunity.org.key
- /etc/pki/tls/private/fedorahosted.org.key
- /etc/pki/tls/private/fedoramagazine.org.key
- /etc/pki/tls/private/flocktofedora.org.key
- /etc/pki/tls/private/fpaste.org.key
- /etc/pki/tls/private/fedoraloveskde.org.key
- /etc/pki/tls/private/fedoraplanet.org.key
- /etc/pki/tls/private/getfedora.org.key
@ -1296,6 +1478,7 @@
- /etc/pki/tls/private/wildcard-2025.apps.ocp-rdu3.fedoraproject.org.key
- /etc/pki/tls/private/wildcard-2025.apps.ocp-rdu3.stg.fedoraproject.org.key
- /etc/pki/tls/private/wildcard-2025.apps.ocp.stg.fedoraproject.org.key
- /etc/pki/tls/private/wildcard-2025.fedorapeople.org.key
- /etc/pki/tls/private/wildcard-2025.fedoraproject.org.key
- /etc/pki/tls/private/wildcard-2025.id.fedoraproject.org.key
- /etc/pki/tls/private/wildcard-2025.id.stg.fedoraproject.org.key
@ -1308,15 +1491,38 @@
- /etc/pki/rabbitmq/kojicert/koji.ca
- /etc/pki/rabbitmq/kojicert/koji.crt
- /etc/pki/rabbitmq/kojicert/koji.key
- /etc/pki/rabbitmq/mailman/mailman.ca
- /etc/pki/rabbitmq/mailman/mailman.crt
- /etc/pki/rabbitmq/mailman/mailman.key
- /etc/pki/rabbitmq/pagurecert/src.fp.o.ca
- /etc/pki/rabbitmq/pagurecert/src.fp.o.crt
- /etc/pki/rabbitmq/pagurecert/src.fp.o.key
- /etc/pki/releng # ?
- /etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-SIG-Messaging
- /etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-9
# Profile files:
- /etc/profile.d/cudapath.sh
- /etc/profile.d/externalcaches.sh
- /etc/profile.d/history_off.sh
- /etc/profile.d/models.sh
- /etc/profile.d/setprodps1.sh
- /etc/profile.d/setprodiad2ps1.sh # FIXME ?
- /etc/profile.d/setprodrdu3ps1.sh
- /etc/profile.d/setstgps1.sh
# RabbitMQ files:
- /etc/rabbitmq/ca.crt
- /etc/rabbitmq/enabled_plugins
- /etc/rabbitmq/inter_node_tls.config
- /etc/rabbitmq/nodecert.combined.pem
- /etc/rabbitmq/nodecert/node.crt
- /etc/rabbitmq/nodecert/node.key
- /etc/rabbitmq/pubsub_federation/client_cert.pem
- /etc/rabbitmq/pubsub_federation/client_key.pem
- /etc/rabbitmq/rabbitmq-env.conf
# Resolve files:
- /etc/resolv.conf
@ -1326,10 +1532,17 @@
- /etc/rsyslog.d/rsyslog-audit.conf
- /etc/rsyslog.d/rsyslog-disablerate.conf
- /etc/rsyslog.d/rsyslog-imjournal-limits.conf
- /etc/rsyslog.d/rsyslog-limits.conf
- /etc/rsyslog.d/rsyslog-log01.conf
# SSH files:
- /etc/ssh/sshd_config.d/04-ipa.conf
- /etc/ssh/sshd_config.d/50-cloud-init.conf
- /etc/ssh/ssh_config.d/04-ipa.conf
- /etc/ssh/ssh_config.d/99-x11.conf
- /etc/ssh/ssh_host_dsa_key
- /etc/ssh/ssh_host_dsa_key.pub
- /etc/ssh/ssh_host_dsa_key-cert.pub
- /etc/ssh/ssh_host_ecdsa_key
- /etc/ssh/ssh_host_ecdsa_key.pub
- /etc/ssh/ssh_host_ed25519_key
@ -1345,13 +1558,26 @@
- /etc/sssd/conf.d/fedora-nss-ignore.conf
# sudoers files:
- /etc/sudoers.d/01-sysadmin-main
- /etc/sudoers.d/90-cloud-init-users
- /etc/sudoers.d/arm-packager-sudoers
- /etc/sudoers.d/arm-retrace-sudoers
- /etc/sudoers.d/default
- /etc/sudoers.d/norequiretty
- /etc/sudoers.d/pkgs01_rdu3_fedoraproject_org-sudoers
# Sysconfig files:
- /etc/sysconfig/anaconda
- /etc/sysconfig/authconfig
- /etc/sysconfig/bittorrent
- /etc/sysconfig/bootloader
- /etc/sysconfig/firstboot
- /etc/sysconfig/global-update-applied # FIXME: ?
- /etc/sysconfig/freshclam
- /etc/sysconfig/ipv4-br-aggregated.zone
- /etc/sysconfig/ipv6-br.zone
- /etc/sysconfig/ipv4-cu-aggregated.zone
- /etc/sysconfig/ipv4-ir-aggregated.zone
- /etc/sysconfig/ipv4-kp-aggregated.zone
@ -1374,37 +1600,95 @@
- /etc/sysconfig/sshd-permitrootlogin
# Sysctl.d files:
- /etc/sysctl.d/10-tcp-socket-buffers.conf
# SystemD files:
- /etc/systemd/system/anubis.service
- /etc/systemd/system/bodhi-celery.service
- /etc/systemd/system/btrfs-balance.timer.d/schedule.conf
- /etc/systemd/system/collectd.service.d/timeout.conf
- /etc/systemd/system/debuginfod.service.d/override.conf
- /etc/systemd/system/dirsrv@FEDORAPROJECT-ORG.service.d/ipa-env.conf
- /etc/systemd/system/dirsrv@STG-FEDORAPROJECT-ORG.service.d/ipa-env.conf
- /etc/systemd/system/dnf-automatic.timer.d/weekdays.conf
- /etc/systemd/system/dnf5-automatic.timer.d/weekdays.conf
- /etc/systemd/system/dnf-automatic-install.timer.d/weekdays.conf
- /etc/systemd/system/fm-consumer@.service.d/local.conf
- /etc/systemd/system/git@.service
- /etc/systemd/system/haproxy.service.d/postvpn.conf
- /etc/systemd/system/httpd.service
- /etc/systemd/system/httpd.service.d/env.conf
- /etc/systemd/system/httpd.service.d/httpdoverride.conf
- /etc/systemd/system/httpd.service.d/ipa.conf
- /etc/systemd/system/httpd.service.d/override.conf
- /etc/systemd/system/hyperkitty.target
- /etc/systemd/system/hyperkitty-daily.service
- /etc/systemd/system/hyperkitty-daily.timer
- /etc/systemd/system/hyperkitty-hourly.service
- /etc/systemd/system/hyperkitty-hourly.timer
- /etc/systemd/system/hyperkitty-minutely.service
- /etc/systemd/system/hyperkitty-minutely.timer
- /etc/systemd/system/hyperkitty-monthly.service
- /etc/systemd/system/hyperkitty-monthly.timer
- /etc/systemd/system/hyperkitty-quarter_hourly.service
- /etc/systemd/system/hyperkitty-quarter_hourly.timer
- /etc/systemd/system/hyperkitty-weekly.service
- /etc/systemd/system/hyperkitty-weekly.timer
- /etc/systemd/system/hyperkitty-yearly.service
- /etc/systemd/system/hyperkitty-yearly.timer
- /etc/systemd/system/kojid.service
- /etc/systemd/system/machine-.scope.d/80-infra.conf
- /etc/systemd/system/mailman3.service.d/mailman3.conf
- /etc/systemd/system/mailmanweb.service
- /etc/systemd/system/mirrorlist1.service
- /etc/systemd/system/mirrorlist2.service
- /etc/systemd/system/pagure_ev.service
- /etc/systemd/system/pagure_fast_worker.service
- /etc/systemd/system/pagure_logcom.service
- /etc/systemd/system/pagure_medium_worker.service
- /etc/systemd/system/pagure_mirror.service
- /etc/systemd/system/pagure_slow_worker.service
- /etc/systemd/system/pagure_webhook.service
- /etc/systemd/system/pagure_worker.service
- /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d/ipa.conf
- /etc/systemd/system/rabbitmq-server.service.d/override.conf
- /etc/systemd/system/rsyslog.service.d/limits.conf
- /etc/systemd/system/send-rabbitmq-queue.service
- /etc/systemd/system/send-rabbitmq-queue.timer
- /etc/systemd/system/ursabot.service
- /etc/systemd/system/varnish.service
- /etc/systemd/system/varnish.service.d/postvpn.conf
- /etc/systemd/system/varnish.service.d/restart-on-fail.conf
- /etc/systemd/system/webui-qcluster.service
- /etc/systemd/system/webui-warm-up-cache.service
- /etc/systemd/system/zodbot.service
# tmpfiles files:
- /etc/tmpfiles.d/dirsrv-STG-FEDORAPROJECT-ORG.conf
# Varnish files:
- /etc/varnish/secret
# YUM files:
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:dvraaij:ada.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_abrt:faf-el8.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_abrt:faf-el8-devel.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_osbuild:osbuild.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:hobbes1069:testing.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:packit:abrt-retrace-server-434.repo
- /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:psloboda:mariadb10.11-rebase-to-10.11.13.repo
- /etc/yum.repos.d/centos9s-rabbitmq38.repo
- /etc/yum.repos.d/cuda-fedora41.repo
- /etc/yum.repos.d/epel.repo # FIXME ?
- /etc/yum.repos.d/epel8.repo
- /etc/yum.repos.d/epel9.repo
- /etc/yum.repos.d/epel10.repo
- /etc/yum.repos.d/group_abrt-faf-el8-epel-8.repo
- /etc/yum.repos.d/infra-tags.repo
- /etc/yum.repos.d/infra-tags-stg.repo
- /etc/yum.repos.d/redhat.repo
- /etc/yum.repos.d/rhel-infra-tags.repo
- /etc/yum.repos.d/rhel8.repo
- /etc/yum.repos.d/rhel9.repo
- /etc/yum.repos.d/rhel10.repo
@ -1415,14 +1699,28 @@
- /etc/zabbix/zabbix_agentd.d/interface-alias.conf
- /etc/zabbix/zabbix_agentd.d/ipa-backup.conf
- /etc/zabbix/zabbix_agentd.d/postfix.conf
- /etc/zabbix/zabbix_agentd.d/rabbitmq.conf
- /etc/zabbix/zabbix_agentd.d/raid.conf
- /etc/zabbix/zabbix_agentd.conf
# FIXME: Why this and the above?
- /etc/zabbix_agentd.conf
# FIXME: SELinux BS goes here?
- /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.mod
- /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.pp
- /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.te
# Are these known though?
- /etc/firewalld/zones/public.xml
- /etc/modules-load.d/nf_conntrack.conf
- /etc/system_identification
- /etc/varnish/secret
# Misc files:
# FIXME: Are these actually known/good though?
- /etc/crio/crio.conf
- /etc/firewalld/zones/public.xml # everything but s390x has this.
- /etc/grub.d/00_tuned # from 2024 on pkgs01.stg.rdu3
- /etc/iscsi/initiatorname.iscsi
- /etc/motd_fedora
- /etc/stunnel/stunnel.conf
- /etc/sync-http-logs.yaml
- /etc/system_identification # only bvmhost-s390x-01.stg.s390
- /etc/systemd/dont-synthesize-nobody # empty file on memcached02.stg.rdu3
- /etc/xinetd.d/rsync
tasks:

27
playbooks/groups/gpu.yml Normal file
View file

@ -0,0 +1,27 @@
---
- import_playbook: "/srv/web/infra/ansible/playbooks/include/happy_birthday.yml"
vars:
myhosts: "gpu"
- name: make gpu host on raw hw
hosts: gpu
remote_user: root
gather_facts: true
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
pre_tasks:
- import_tasks: "{{ tasks_path }}/yumrepos.yml"
roles:
- base
- hosts
- openvpn/client
- ipa/client
- sudo
handlers:
- import_tasks: "{{ handlers_path }}/restart_services.yml"

View file

@ -30,7 +30,7 @@
## This should be in a different playbook.
- name: Deal with drive items on storinator01
hosts: storinator01.rdu-cc.fedoraproject.org
hosts: storinator01.rdu3.fedoraproject.org
user: root
gather_facts: true
vars_files:
@ -72,7 +72,7 @@
- copr
- name: Deal with NFS
hosts: storinator01.rdu-cc.fedoraproject.org
hosts: storinator01.rdu3.fedoraproject.org
user: root
gather_facts: true
vars_files:

View file

@ -13,7 +13,7 @@
- import_tasks: "{{ handlers_path }}/restart_services.yml"
vars:
- varnish_url: http://localhost:6081
varnish_url: http://localhost:6081
pre_tasks:
@ -661,6 +661,7 @@
website: koji.fedoraproject.org
destname: koji
keephost: true
proxyopts: "keepalive=on ttl=10"
balancer_name: koji
balancer_members:
- "koji01.{{ datacenter }}.fedoraproject.org"
@ -674,6 +675,7 @@
website: koji.fedoraproject.org
destname: koji
keephost: true
proxyopts: "keepalive=on ttl=10"
balancer_name: koji
balancer_members:
- "koji01.stg.{{ datacenter }}.fedoraproject.org"
@ -896,20 +898,6 @@
keephost: true
tags: discourse2fedmsg
# - role: httpd/reverseproxy
# website: ipsilon-project.org
# destname: ipsilon-website
# balancer_name: apps-ocp
# balancer_members: "{{ (env == 'staging')|ternary(ocp_nodes_rdu3_stg, ocp_nodes) }}"
# targettype: openshift
# ocp4: "{{ (env == 'production') | bool }}"
# ocp4_rdu3: "{{ (env == 'staging') | bool }}"
# # When prod has moved to rdu3:
# #ocp4: false
# #ocp4_rdu3: true
# keephost: true
# tags: ipsilon-website
- role: httpd/reverseproxy
website: awx.fedoraproject.org
destname: awx

View file

@ -1210,18 +1210,6 @@
tags:
- fedora.im
# - role: httpd/website
# site_name: ipsilon-project.org
# cert_name: ipsilon-project.org
# server_aliases:
# - ipsilon-project.org
# - www.ipsilon-project.org
# ssl: true
# sslonly: true
# certbot: true
# tags:
# - ipsilon-website
- role: httpd/website
site_name: directory.fedoraproject.org
ssl: true

View file

@ -2,15 +2,15 @@
# creates EPEL branches from a target branch.
#
# Running the following line will do a dry-run of the process on the staging server.
# $ ansible-playbook \
# $ sudo rbac-playbook \
# -l pkgs_stg \
# playbooks/manual/epel-minor-release/branch-disgit-packages.yml
# manual/epel-minor-release/branch-distgit-packages.yml
#
# You can also use it locally to test how it works
# $ ansible-playbook \
# -l localhost \
# -e checkout_path=/tmp/rpms \
# playbooks/manual/epel-minor-release/branch-disgit-packages.yml
# playbooks/manual/epel-minor-release/branch-distgit-packages.yml
#
# Expected extra-vars:
# checkout_path

View file

@ -19,22 +19,51 @@
ansible.builtin.stat:
path: /mnt/koji/compose/updates/epel{{ epel_major }}.{{ epel_branched_minor }}
register: compose_stat
- name: Create compose symlink
become: yes
ansible.builtin.file:
src: "{{ compose_stat.stat.lnk_target }}"
dest: "/mnt/koji/compose/updates/epel{{ epel_major }}.{{ epel_minor }}"
state: link
follow: false
owner: apache
group: apache
- name: Determine current testing compose
ansible.builtin.stat:
path: /mnt/koji/compose/updates/epel{{ epel_major }}.{{ epel_branched_minor }}-testing
register: compose_testing_stat
- name: Create testing compose symlink
become: yes
ansible.builtin.file:
src: "{{ compose_testing_stat.stat.lnk_target }}"
dest: "/mnt/koji/compose/updates/epel{{ epel_major }}.{{ epel_minor }}-testing"
state: link
follow: false
owner: apache
group: apache
- name: Set major-only compose symlink
become: yes
ansible.builtin.file:
src: epel{{ epel_major }}.{{ epel_minor }}
dest: /mnt/koji/compose/updates/epel{{ epel_major }}
state: link
follow: false
owner: apache
group: apache
- name: Set major-only testing compose symlink
become: yes
ansible.builtin.file:
src: epel{{ epel_major }}.{{ epel_minor }}-testing
dest: /mnt/koji/compose/updates/epel{{ epel_major }}-testing
state: link
follow: false
owner: apache
group: apache
- name: Create repos for packages
block:

View file

@ -18,3 +18,5 @@
- gwmngilfen
- nphilipp
- zlopez
cluster_readonly_appowners:
- smoliicek

View file

@ -1,58 +0,0 @@
---
- name: Make the app be real
hosts: os_control_stg[0]:os_control[0]
user: root
gather_facts: false
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
vars:
roles:
- role: openshift/project
project_app: ipsilon-website
project_description: "ipsilon-project.org"
project_appowners:
- abompard
tags:
- apply-appowners
- role: openshift/imagestream
imagestream_app: ipsilon-website
imagestream_imagename: ipsilon-website
- role: openshift/object
object_app: ipsilon-website
object_template: buildconfig.yml.j2
object_objectname: buildconfig.yml
- role: openshift/object
object_app: ipsilon-website
object_file: service.yml
object_objectname: service.yml
- role: openshift/route
route_app: ipsilon-website
route_name: web-internal
route_host: "ipsilon-website.apps.ocp{{ env_suffix }}.fedoraproject.org"
route_serviceport: web
route_servicename: web
route_annotations:
haproxy.router.openshift.io/timeout: 5m
- role: openshift/route
route_app: ipsilon-website
route_name: web
route_host: "ipsilon-project.org"
route_serviceport: web
route_servicename: web
route_annotations:
haproxy.router.openshift.io/timeout: 5m
- role: openshift/object
object_app: ipsilon-website
object_template: deploymentconfig.yml.j2
object_objectname: deploymentconfig.yml

View file

@ -29,7 +29,7 @@
user_sent_topics: ^$
# The openshift/project role breaks if the project already exists:
# https://forge.fedoraproject.org/infra/tickets/6404
# https://forge.fedoraproject.org/infra/tickets/issues/6404
- role: openshift/project
project_app: resultsdb-ci-listener
project_description: resultsdb-ci-listener

View file

@ -44,7 +44,7 @@
user_sent_topics: ^org\.fedoraproject\.{{ env_short }}\.resultsdb\..*
# The openshift/project role breaks if the project already exists:
# https://forge.fedoraproject.org/infra/tickets/6404
# https://forge.fedoraproject.org/infra/tickets/issues/6404
- role: openshift/project
project_app: resultsdb
project_description: resultsdb

View file

@ -46,7 +46,7 @@
user_sent_topics: ^org\.fedoraproject\.{{ env_short }}\.waiverdb\..*
# The openshift/project role breaks if the project already exists:
# https://forge.fedoraproject.org/infra/tickets/6404
# https://forge.fedoraproject.org/infra/tickets/issues/6404
- role: openshift/project
project_app: waiverdb
project_description: waiverdb

View file

@ -1,7 +1,7 @@
---
roles:
# Needed for copr-pulp playbooks
# https://forge.fedoraproject.org/infra/tickets/11396
# https://forge.fedoraproject.org/infra/tickets/issues/11396
- name: geerlingguy.postgresql
version: 3.5.0

View file

@ -104,7 +104,7 @@ children:
url: https://fedoramagazine.org
docs_url: https://codex.wordpress.org/
# We don't have a SOP for the magazine yet.
# https://forge.fedoraproject.org/infra/tickets/5149
# https://forge.fedoraproject.org/infra/tickets/issues/5149
# sops:
# - put the url here
description: >
@ -129,7 +129,7 @@ children:
# TODO - add the docs_url. I asked pete travis for info on this
# docs_url: put the url here
# TODO - add a sop.
# https://forge.fedoraproject.org/infra/tickets/5150
# https://forge.fedoraproject.org/infra/tickets/issues/5150
# sops:
# - add the sop url here.
description: >
@ -152,7 +152,7 @@ children:
bugs_url: https://github.com/abrt/retrace-server/issues
docs_url: https://abrt.readthedocs.org/en/latest/howitworks.html#faf
# TODO - write SOPs for this
# https://forge.fedoraproject.org/infra/tickets/5151
# https://forge.fedoraproject.org/infra/tickets/issues/5151
# sops:
# - url goes here
# - and another one goes here
@ -190,7 +190,7 @@ children:
package_url: >
https://bugzilla.redhat.com/buglist.cgi?component=Package%20Review&query_format=advanced&short_desc_type=allwordssubstr&short_desc={package}
# TODO - write the SOP for this
# https://forge.fedoraproject.org/infra/tickets/5152
# https://forge.fedoraproject.org/infra/tickets/issues/5152
# sops:
# - url goes here
description: >
@ -243,7 +243,7 @@ children:
bugs_url: https://github.com/fedora-infra/asknot-ng/issues
docs_url: https://github.com/fedora-infra/asknot-ng/blob/develop/README.md
# TODO - write SOP for asknot-ng
# https://forge.fedoraproject.org/infra/tickets/5154
# https://forge.fedoraproject.org/infra/tickets/issues/5154
# sops:
# - url goes here
status_mappings: []
@ -425,7 +425,7 @@ children:
bugs_url: https://github.com/fedora-infra/anitya/issues
docs_url: https://fedoraproject.org/wiki/Upstream_release_monitoring
# TODO - write sops for anitya and the-new-hotness
# https://forge.fedoraproject.org/infra/tickets/5157
# https://forge.fedoraproject.org/infra/tickets/issues/5157
# sops:
# - https://infrastructure.fedoraproject.org/infra/docs/anitya.rst
# - https://infrastructure.fedoraproject.org/infra/docs/hotness.rst
@ -479,7 +479,7 @@ children:
bugs_url: https://github.com/fedora-infra/geoip-city-wsgi/issues
docs_url: https://github.com/fedora-infra/geoip-city-wsgi/blob/master/geoip-city.wsgi
# TODO - write a sop for this thing
# https://forge.fedoraproject.org/infra/tickets/5159
# https://forge.fedoraproject.org/infra/tickets/issues/5159
# sops:
# - https://infrastructure.fedoraproject.org/infra/docs/geoip.rst
description: >

View file

@ -410,7 +410,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -421,7 +421,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -387,7 +387,7 @@ relayhost = bastion.fedoraproject.org
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -398,7 +398,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -321,7 +321,7 @@ relayhost = smtp-auth-cc-rdu01.fedoraproject.org
smtp_use_tls = yes
smtp_sasl_auth_enable = yes
smtp_sasl_security_options =
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_password_maps = lmdb:/etc/postfix/sasl_passwd
# REJECTING UNKNOWN RELAY USERS
@ -394,7 +394,7 @@ smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -405,7 +405,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -419,7 +419,7 @@ relay_domains = $mydestination
#
#alias_maps = dbm:/etc/aliases
#alias_maps = hash:/etc/aliases
alias_maps = hash:/etc/aliases, hash:/etc/postfix/package-owner, hash:/etc/postfix/package-maintainers
alias_maps = lmdb:/etc/aliases, hash:/etc/postfix/package-owner, hash:/etc/postfix/package-maintainers
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -430,7 +430,7 @@ alias_maps = hash:/etc/aliases, hash:/etc/postfix/package-owner, hash:/etc/postf
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -736,7 +736,7 @@ smtpd_tls_eecdh_grade = ultra
# smtp TLS Client
smtp_tls_fingerprint_digest=sha1
smtp_tls_note_starttls_offer = yes
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
smtp_tls_policy_maps = lmdb:/etc/postfix/tls_policy
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtp_tls_mandatory_ciphers = high
smtp_tls_mandatory_exclude_ciphers= aNULL, MD5, RC4
@ -749,7 +749,7 @@ smtp_tls_connection_reuse = no
smtp_connection_cache_destinations = mx1.redhat.com,gmail.com,google.com,scrye.com,redhat.com
smtp_tls_session_cache_database = btree:/var/lib/postfix/smtp_scache
smtp_tls_session_cache_timeout = 3600s
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
smtp_tls_policy_maps = lmdb:/etc/postfix/tls_policy
## End smtp_tls
## General TLS
tls_random_source = dev:/dev/urandom
@ -766,7 +766,7 @@ non_smtpd_milters = $smtpd_milters
smtpd_sender_restrictions = regexp:/etc/postfix/sender_access
meta_directory = /etc/postfix
shlib_directory = /usr/lib64/postfix
transport_maps = hash:/etc/postfix/transport
transport_maps = lmdb:/etc/postfix/transport
local_header_rewrite_clients = static:all
message_size_limit = 20971520
@ -779,7 +779,7 @@ smtpd_relay_restrictions = permit_mynetworks, reject_unauth_destination
# here we send emails _from_ redhat.com addresses back out the redhat.com mx
# This avoids us sending them and causing SPF failures.
# It depends on them allowing us to relay email out.
sender_dependent_relayhost_maps = hash:/etc/postfix/bysender
sender_dependent_relayhost_maps = lmdb:/etc/postfix/bysender
# RHEL postfix disables RFC3030 CHUNKING by default for security reasons
# http://www.postfix.org/BDAT_README.html

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -388,7 +388,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -399,7 +399,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -691,9 +691,9 @@ message_size_limit = 20971520
# Mailman, see MTA.rst
owner_request_special = no
transport_maps = hash:/var/lib/mailman3/data/postfix_lmtp
local_recipient_maps = hash:/var/lib/mailman3/data/postfix_lmtp
relay_domains = hash:/var/lib/mailman3/data/postfix_domains
transport_maps = lmdb:/var/lib/mailman3/data/postfix_lmtp
local_recipient_maps = lmdb:/var/lib/mailman3/data/postfix_lmtp
relay_domains = lmdb:/var/lib/mailman3/data/postfix_domains
smtpd_sender_restrictions =
check_sender_access regexp:/etc/postfix/sender_access

View file

@ -388,7 +388,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -399,7 +399,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -691,8 +691,8 @@ message_size_limit = 20971520
# Mailman, see MTA.rst
owner_request_special = no
transport_maps = hash:/var/lib/mailman3/data/postfix_lmtp
local_recipient_maps = hash:/var/lib/mailman3/data/postfix_lmtp
relay_domains = hash:/var/lib/mailman3/data/postfix_domains
transport_maps = lmdb:/var/lib/mailman3/data/postfix_lmtp
local_recipient_maps = lmdb:/var/lib/mailman3/data/postfix_lmtp
relay_domains = lmdb:/var/lib/mailman3/data/postfix_domains
smtpd_recipient_restrictions = permit_mynetworks, reject_unauth_destination

View file

@ -395,7 +395,7 @@ unknown_local_recipient_reject_code = 550
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -406,7 +406,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -691,7 +691,7 @@ inet_protocols = ipv4
# mapping so we know where to go for .redhat.com mail
transport_maps = hash:/etc/postfix/transport
transport_maps = lmdb:/etc/postfix/transport
local_header_rewrite_clients = static:all

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -0,0 +1,718 @@
# Global Postfix configuration file. This file lists only a subset
# of all parameters. For the syntax, and for a complete parameter
# list, see the postconf(5) manual page (command: "man 5 postconf").
#
# For common configuration examples, see BASIC_CONFIGURATION_README
# and STANDARD_CONFIGURATION_README. To find these documents, use
# the command "postconf html_directory readme_directory", or go to
# http://www.postfix.org/BASIC_CONFIGURATION_README.html etc.
#
# For best results, change no more than 2-3 parameters at a time,
# and test if Postfix still works after every change.
# COMPATIBILITY
#
# The compatibility_level determines what default settings Postfix
# will use for main.cf and master.cf settings. These defaults will
# change over time.
#
# To avoid breaking things, Postfix will use backwards-compatible
# default settings and log where it uses those old backwards-compatible
# default settings, until the system administrator has determined
# if any backwards-compatible default settings need to be made
# permanent in main.cf or master.cf.
#
# When this review is complete, update the compatibility_level setting
# below as recommended in the RELEASE_NOTES file.
#
# The level below is what should be used with new (not upgrade) installs.
#
compatibility_level = 2
# SOFT BOUNCE
#
# The soft_bounce parameter provides a limited safety net for
# testing. When soft_bounce is enabled, mail will remain queued that
# would otherwise bounce. This parameter disables locally-generated
# bounces, and prevents the SMTP server from rejecting mail permanently
# (by changing 5xx replies into 4xx replies). However, soft_bounce
# is no cure for address rewriting mistakes or mail routing mistakes.
#
#soft_bounce = no
# LOCAL PATHNAME INFORMATION
#
# The queue_directory specifies the location of the Postfix queue.
# This is also the root directory of Postfix daemons that run chrooted.
# See the files in examples/chroot-setup for setting up Postfix chroot
# environments on different UNIX systems.
#
queue_directory = /var/spool/postfix
# The command_directory parameter specifies the location of all
# postXXX commands.
#
command_directory = /usr/sbin
# The daemon_directory parameter specifies the location of all Postfix
# daemon programs (i.e. programs listed in the master.cf file). This
# directory must be owned by root.
#
daemon_directory = /usr/libexec/postfix
# The data_directory parameter specifies the location of Postfix-writable
# data files (caches, random numbers). This directory must be owned
# by the mail_owner account (see below).
#
data_directory = /var/lib/postfix
# QUEUE AND PROCESS OWNERSHIP
#
# The mail_owner parameter specifies the owner of the Postfix queue
# and of most Postfix daemon processes. Specify the name of a user
# account THAT DOES NOT SHARE ITS USER OR GROUP ID WITH OTHER ACCOUNTS
# AND THAT OWNS NO OTHER FILES OR PROCESSES ON THE SYSTEM. In
# particular, don't specify nobody or daemon. PLEASE USE A DEDICATED
# USER.
#
mail_owner = postfix
# The default_privs parameter specifies the default rights used by
# the local delivery agent for delivery to external file or command.
# These rights are used in the absence of a recipient user context.
# DO NOT SPECIFY A PRIVILEGED USER OR THE POSTFIX OWNER.
#
#default_privs = nobody
# INTERNET HOST AND DOMAIN NAMES
#
# The myhostname parameter specifies the internet hostname of this
# mail system. The default is to use the fully-qualified domain name
# from gethostname(). $myhostname is used as a default value for many
# other configuration parameters.
#
#myhostname = host.domain.tld
#myhostname = virtual.domain.tld
# The mydomain parameter specifies the local internet domain name.
# The default is to use $myhostname minus the first component.
# $mydomain is used as a default value for many other configuration
# parameters.
#
#mydomain = domain.tld
# SENDING MAIL
#
# The myorigin parameter specifies the domain that locally-posted
# mail appears to come from. The default is to append $myhostname,
# which is fine for small sites. If you run a domain with multiple
# machines, you should (1) change this to $mydomain and (2) set up
# a domain-wide alias database that aliases each user to
# user@that.users.mailhost.
#
# For the sake of consistency between sender and recipient addresses,
# myorigin also specifies the default domain name that is appended
# to recipient addresses that have no @domain part.
#
#myorigin = $myhostname
#myorigin = $mydomain
mydomain = fedoraproject.org
myorigin = fedoraproject.org
# RECEIVING MAIL
# The inet_interfaces parameter specifies the network interface
# addresses that this mail system receives mail on. By default,
# the software claims all active interfaces on the machine. The
# parameter also controls delivery of mail to user@[ip.address].
#
# See also the proxy_interfaces parameter, for network addresses that
# are forwarded to us via a proxy or network address translator.
#
# Note: you need to stop/start Postfix when this parameter changes.
#
#inet_interfaces = all
#inet_interfaces = $myhostname
#inet_interfaces = $myhostname, localhost
inet_interfaces = all
# The proxy_interfaces parameter specifies the network interface
# addresses that this mail system receives mail on by way of a
# proxy or network address translation unit. This setting extends
# the address list specified with the inet_interfaces parameter.
#
# You must specify your proxy/NAT addresses when your system is a
# backup MX host for other domains, otherwise mail delivery loops
# will happen when the primary MX host is down.
#
#proxy_interfaces =
#proxy_interfaces = 1.2.3.4
# The mydestination parameter specifies the list of domains that this
# machine considers itself the final destination for.
#
# These domains are routed to the delivery agent specified with the
# local_transport parameter setting. By default, that is the UNIX
# compatible delivery agent that lookups all recipients in /etc/passwd
# and /etc/aliases or their equivalent.
#
# The default is $myhostname + localhost.$mydomain. On a mail domain
# gateway, you should also include $mydomain.
#
# Do not specify the names of virtual domains - those domains are
# specified elsewhere (see VIRTUAL_README).
#
# Do not specify the names of domains that this machine is backup MX
# host for. Specify those names via the relay_domains settings for
# the SMTP server, or use permit_mx_backup if you are lazy (see
# STANDARD_CONFIGURATION_README).
#
# The local machine is always the final destination for mail addressed
# to user@[the.net.work.address] of an interface that the mail system
# receives mail on (see the inet_interfaces parameter).
#
# Specify a list of host or domain names, /file/name or type:table
# patterns, separated by commas and/or whitespace. A /file/name
# pattern is replaced by its contents; a type:table is matched when
# a name matches a lookup key (the right-hand side is ignored).
# Continue long lines by starting the next line with whitespace.
#
# See also below, section "REJECTING MAIL FOR UNKNOWN LOCAL USERS".
#
mydestination = $myhostname, localhost.$mydomain, fedora.redhat.com, localhost
#mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
#mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain,
# mail.$mydomain, www.$mydomain, ftp.$mydomain
# REJECTING MAIL FOR UNKNOWN LOCAL USERS
#
# The local_recipient_maps parameter specifies optional lookup tables
# with all names or addresses of users that are local with respect
# to $mydestination, $inet_interfaces or $proxy_interfaces.
#
# If this parameter is defined, then the SMTP server will reject
# mail for unknown local users. This parameter is defined by default.
#
# To turn off local recipient checking in the SMTP server, specify
# local_recipient_maps = (i.e. empty).
#
# The default setting assumes that you use the default Postfix local
# delivery agent for local delivery. You need to update the
# local_recipient_maps setting if:
#
# - You define $mydestination domain recipients in files other than
# /etc/passwd, /etc/aliases, or the $virtual_alias_maps files.
# For example, you define $mydestination domain recipients in
# the $virtual_mailbox_maps files.
#
# - You redefine the local delivery agent in master.cf.
#
# - You redefine the "local_transport" setting in main.cf.
#
# - You use the "luser_relay", "mailbox_transport", or "fallback_transport"
# feature of the Postfix local delivery agent (see local(8)).
#
# Details are described in the LOCAL_RECIPIENT_README file.
#
# Beware: if the Postfix SMTP server runs chrooted, you probably have
# to access the passwd file via the proxymap service, in order to
# overcome chroot restrictions. The alternative, having a copy of
# the system passwd file in the chroot jail is just not practical.
#
# The right-hand side of the lookup tables is conveniently ignored.
# In the left-hand side, specify a bare username, an @domain.tld
# wild-card, or specify a user@domain.tld address.
#
#local_recipient_maps = unix:passwd.byname $alias_maps
#local_recipient_maps = proxy:unix:passwd.byname $alias_maps
#local_recipient_maps =
# The unknown_local_recipient_reject_code specifies the SMTP server
# response code when a recipient domain matches $mydestination or
# ${proxy,inet}_interfaces, while $local_recipient_maps is non-empty
# and the recipient address or address local-part is not found.
#
# The default setting is 550 (reject mail) but it is safer to start
# with 450 (try again later) until you are certain that your
# local_recipient_maps settings are OK.
#
unknown_local_recipient_reject_code = 550
# TRUST AND RELAY CONTROL
# The mynetworks parameter specifies the list of "trusted" SMTP
# clients that have more privileges than "strangers".
#
# In particular, "trusted" SMTP clients are allowed to relay mail
# through Postfix. See the smtpd_recipient_restrictions parameter
# in postconf(5).
#
# You can specify the list of "trusted" network addresses by hand
# or you can let Postfix do it for you (which is the default).
#
# By default (mynetworks_style = subnet), Postfix "trusts" SMTP
# clients in the same IP subnetworks as the local machine.
# On Linux, this does works correctly only with interfaces specified
# with the "ifconfig" command.
#
# Specify "mynetworks_style = class" when Postfix should "trust" SMTP
# clients in the same IP class A/B/C networks as the local machine.
# Don't do this with a dialup site - it would cause Postfix to "trust"
# your entire provider's network. Instead, specify an explicit
# mynetworks list by hand, as described below.
#
# Specify "mynetworks_style = host" when Postfix should "trust"
# only the local machine.
#
#mynetworks_style = class
#mynetworks_style = subnet
#mynetworks_style = host
# Alternatively, you can specify the mynetworks list by hand, in
# which case Postfix ignores the mynetworks_style setting.
#
# Specify an explicit list of network/netmask patterns, where the
# mask specifies the number of bits in the network part of a host
# address.
#
# You can also specify the absolute pathname of a pattern file instead
# of listing the patterns here. Specify type:table for table-based lookups
# (the value on the table right-hand side is not used).
#
#mynetworks = 168.100.189.0/28, 127.0.0.0/8
#mynetworks = $config_directory/mynetworks
#mynetworks = hash:/etc/postfix/network_table
# The relay_domains parameter restricts what destinations this system will
# relay mail to. See the smtpd_recipient_restrictions description in
# postconf(5) for detailed information.
#
# By default, Postfix relays mail
# - from "trusted" clients (IP address matches $mynetworks) to any destination,
# - from "untrusted" clients to destinations that match $relay_domains or
# subdomains thereof, except addresses with sender-specified routing.
# The default relay_domains value is $mydestination.
#
# In addition to the above, the Postfix SMTP server by default accepts mail
# that Postfix is final destination for:
# - destinations that match $inet_interfaces or $proxy_interfaces,
# - destinations that match $mydestination
# - destinations that match $virtual_alias_domains,
# - destinations that match $virtual_mailbox_domains.
# These destinations do not need to be listed in $relay_domains.
#
# Specify a list of hosts or domains, /file/name patterns or type:name
# lookup tables, separated by commas and/or whitespace. Continue
# long lines by starting the next line with whitespace. A file name
# is replaced by its contents; a type:name table is matched when a
# (parent) domain appears as lookup key.
#
# NOTE: Postfix will not automatically forward mail for domains that
# list this system as their primary or backup MX host. See the
# permit_mx_backup restriction description in postconf(5).
#
relay_domains = $mydestination
# INTERNET OR INTRANET
# The relayhost parameter specifies the default host to send mail to
# when no entry is matched in the optional transport(5) table. When
# no relayhost is given, mail is routed directly to the destination.
#
# On an intranet, specify the organizational domain name. If your
# internal DNS uses no MX records, specify the name of the intranet
# gateway host instead.
#
# In the case of SMTP, specify a domain, host, host:port, [host]:port,
# [address] or [address]:port; the form [host] turns off MX lookups.
#
# If you're connected via UUCP, see also the default_transport parameter.
#
#relayhost = $mydomain
#relayhost = [gateway.my.domain]
#relayhost = [mailserver.isp.tld]
#relayhost = uucphost
#relayhost = [an.ip.add.ress]
relayhost = bastion
# REJECTING UNKNOWN RELAY USERS
#
# The relay_recipient_maps parameter specifies optional lookup tables
# with all addresses in the domains that match $relay_domains.
#
# If this parameter is defined, then the SMTP server will reject
# mail for unknown relay users. This feature is off by default.
#
# The right-hand side of the lookup tables is conveniently ignored.
# In the left-hand side, specify an @domain.tld wild-card, or specify
# a user@domain.tld address.
#
#relay_recipient_maps = hash:/etc/postfix/relay_recipients
# INPUT RATE CONTROL
#
# The in_flow_delay configuration parameter implements mail input
# flow control. This feature is turned on by default, although it
# still needs further development (it's disabled on SCO UNIX due
# to an SCO bug).
#
# A Postfix process will pause for $in_flow_delay seconds before
# accepting a new message, when the message arrival rate exceeds the
# message delivery rate. With the default 100 SMTP server process
# limit, this limits the mail inflow to 100 messages a second more
# than the number of messages delivered per second.
#
# Specify 0 to disable the feature. Valid delays are 0..10.
#
#in_flow_delay = 1s
# ADDRESS REWRITING
#
# The ADDRESS_REWRITING_README document gives information about
# address masquerading or other forms of address rewriting including
# username->Firstname.Lastname mapping.
masquerade_domains = redhat.com
masquerade_exceptions = root apache
# ADDRESS REDIRECTION (VIRTUAL DOMAIN)
#
# The VIRTUAL_README document gives information about the many forms
# of domain hosting that Postfix supports.
# "USER HAS MOVED" BOUNCE MESSAGES
#
# See the discussion in the ADDRESS_REWRITING_README document.
# TRANSPORT MAP
#
# See the discussion in the ADDRESS_REWRITING_README document.
# ALIAS DATABASE
#
# The alias_maps parameter specifies the list of alias databases used
# by the local delivery agent. The default list is system dependent.
#
# On systems with NIS, the default is to search the local alias
# database, then the NIS alias database. See aliases(5) for syntax
# details.
#
# If you change the alias database, run "postalias /etc/aliases" (or
# wherever your system stores the mail alias file), or simply run
# "newaliases" to build the necessary DBM or DB file.
#
# It will take a minute or so before changes become visible. Use
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
# The alias_database parameter specifies the alias database(s) that
# are built with "newaliases" or "sendmail -bi". This is a separate
# configuration parameter, because alias_maps (see above) may specify
# tables that are not necessarily all under control by Postfix.
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
#
# The recipient_delimiter parameter specifies the separator between
# user names and address extensions (user+foo). See canonical(5),
# local(8), relocated(5) and virtual(5) for the effects this has on
# aliases, canonical, virtual, relocated and .forward file lookups.
# Basically, the software tries user+foo and .forward+foo before
# trying user and .forward.
#
recipient_delimiter = +
# DELIVERY TO MAILBOX
#
# The home_mailbox parameter specifies the optional pathname of a
# mailbox file relative to a user's home directory. The default
# mailbox file is /var/spool/mail/user or /var/mail/user. Specify
# "Maildir/" for qmail-style delivery (the / is required).
#
#home_mailbox = Mailbox
#home_mailbox = Maildir/
# The mail_spool_directory parameter specifies the directory where
# UNIX-style mailboxes are kept. The default setting depends on the
# system type.
#
#mail_spool_directory = /var/mail
#mail_spool_directory = /var/spool/mail
# The mailbox_command parameter specifies the optional external
# command to use instead of mailbox delivery. The command is run as
# the recipient with proper HOME, SHELL and LOGNAME environment settings.
# Exception: delivery for root is done as $default_user.
#
# Other environment variables of interest: USER (recipient username),
# EXTENSION (address extension), DOMAIN (domain part of address),
# and LOCAL (the address localpart).
#
# Unlike other Postfix configuration parameters, the mailbox_command
# parameter is not subjected to $parameter substitutions. This is to
# make it easier to specify shell syntax (see example below).
#
# Avoid shell meta characters because they will force Postfix to run
# an expensive shell process. Procmail alone is expensive enough.
#
# IF YOU USE THIS TO DELIVER MAIL SYSTEM-WIDE, YOU MUST SET UP AN
# ALIAS THAT FORWARDS MAIL FOR ROOT TO A REAL USER.
#
#mailbox_command = /usr/bin/procmail
#mailbox_command = /some/where/procmail -a "$EXTENSION"
# The mailbox_transport specifies the optional transport in master.cf
# to use after processing aliases and .forward files. This parameter
# has precedence over the mailbox_command, fallback_transport and
# luser_relay parameters.
#
# Specify a string of the form transport:nexthop, where transport is
# the name of a mail delivery transport defined in master.cf. The
# :nexthop part is optional. For more details see the sample transport
# configuration file.
#
# NOTE: if you use this feature for accounts not in the UNIX password
# file, then you must update the "local_recipient_maps" setting in
# the main.cf file, otherwise the SMTP server will reject mail for
# non-UNIX accounts with "User unknown in local recipient table".
#
# Cyrus IMAP over LMTP. Specify ``lmtpunix cmd="lmtpd"
# listen="/var/imap/socket/lmtp" prefork=0'' in cyrus.conf.
#mailbox_transport = lmtp:unix:/var/lib/imap/socket/lmtp
# If using the cyrus-imapd IMAP server deliver local mail to the IMAP
# server using LMTP (Local Mail Transport Protocol), this is prefered
# over the older cyrus deliver program by setting the
# mailbox_transport as below:
#
# mailbox_transport = lmtp:unix:/var/lib/imap/socket/lmtp
#
# The efficiency of LMTP delivery for cyrus-imapd can be enhanced via
# these settings.
#
# local_destination_recipient_limit = 300
# local_destination_concurrency_limit = 5
#
# Of course you should adjust these settings as appropriate for the
# capacity of the hardware you are using. The recipient limit setting
# can be used to take advantage of the single instance message store
# capability of Cyrus. The concurrency limit can be used to control
# how many simultaneous LMTP sessions will be permitted to the Cyrus
# message store.
#
# Cyrus IMAP via command line. Uncomment the "cyrus...pipe" and
# subsequent line in master.cf.
#mailbox_transport = cyrus
# The fallback_transport specifies the optional transport in master.cf
# to use for recipients that are not found in the UNIX passwd database.
# This parameter has precedence over the luser_relay parameter.
#
# Specify a string of the form transport:nexthop, where transport is
# the name of a mail delivery transport defined in master.cf. The
# :nexthop part is optional. For more details see the sample transport
# configuration file.
#
# NOTE: if you use this feature for accounts not in the UNIX password
# file, then you must update the "local_recipient_maps" setting in
# the main.cf file, otherwise the SMTP server will reject mail for
# non-UNIX accounts with "User unknown in local recipient table".
#
#fallback_transport = lmtp:unix:/var/lib/imap/socket/lmtp
#fallback_transport =
# The luser_relay parameter specifies an optional destination address
# for unknown recipients. By default, mail for unknown@$mydestination,
# unknown@[$inet_interfaces] or unknown@[$proxy_interfaces] is returned
# as undeliverable.
#
# The following expansions are done on luser_relay: $user (recipient
# username), $shell (recipient shell), $home (recipient home directory),
# $recipient (full recipient address), $extension (recipient address
# extension), $domain (recipient domain), $local (entire recipient
# localpart), $recipient_delimiter. Specify ${name?value} or
# ${name:value} to expand value only when $name does (does not) exist.
#
# luser_relay works only for the default Postfix local delivery agent.
#
# NOTE: if you use this feature for accounts not in the UNIX password
# file, then you must specify "local_recipient_maps =" (i.e. empty) in
# the main.cf file, otherwise the SMTP server will reject mail for
# non-UNIX accounts with "User unknown in local recipient table".
#
#luser_relay = $user@other.host
#luser_relay = $local@other.host
#luser_relay = admin+$local
# JUNK MAIL CONTROLS
#
# The controls listed here are only a very small subset. The file
# SMTPD_ACCESS_README provides an overview.
# The header_checks parameter specifies an optional table with patterns
# that each logical message header is matched against, including
# headers that span multiple physical lines.
#
# By default, these patterns also apply to MIME headers and to the
# headers of attached messages. With older Postfix versions, MIME and
# attached message headers were treated as body text.
#
# For details, see "man header_checks".
#
header_checks = regexp:/etc/postfix/header_checks
# FAST ETRN SERVICE
#
# Postfix maintains per-destination logfiles with information about
# deferred mail, so that mail can be flushed quickly with the SMTP
# "ETRN domain.tld" command, or by executing "sendmail -qRdomain.tld".
# See the ETRN_README document for a detailed description.
#
# The fast_flush_domains parameter controls what destinations are
# eligible for this service. By default, they are all domains that
# this server is willing to relay mail to.
#
#fast_flush_domains = $relay_domains
# SHOW SOFTWARE VERSION OR NOT
#
# The smtpd_banner parameter specifies the text that follows the 220
# code in the SMTP server's greeting banner. Some people like to see
# the mail version advertised. By default, Postfix shows no version.
#
# You MUST specify $myhostname at the start of the text. That is an
# RFC requirement. Postfix itself does not care.
#
#smtpd_banner = $myhostname ESMTP $mail_name
#smtpd_banner = $myhostname ESMTP $mail_name ($mail_version)
# PARALLEL DELIVERY TO THE SAME DESTINATION
#
# How many parallel deliveries to the same user or domain? With local
# delivery, it does not make sense to do massively parallel delivery
# to the same user, because mailbox updates must happen sequentially,
# and expensive pipelines in .forward files can cause disasters when
# too many are run at the same time. With SMTP deliveries, 10
# simultaneous connections to the same domain could be sufficient to
# raise eyebrows.
#
# Each message delivery transport has its XXX_destination_concurrency_limit
# parameter. The default is $default_destination_concurrency_limit for
# most delivery transports. For the local delivery agent the default is 2.
#local_destination_concurrency_limit = 2
#default_destination_concurrency_limit = 20
# DEBUGGING CONTROL
#
# The debug_peer_level parameter specifies the increment in verbose
# logging level when an SMTP client or server host name or address
# matches a pattern in the debug_peer_list parameter.
#
debug_peer_level = 2
# The debug_peer_list parameter specifies an optional list of domain
# or network patterns, /file/name patterns or type:name tables. When
# an SMTP client or server host name or address matches a pattern,
# increase the verbose logging level by the amount specified in the
# debug_peer_level parameter.
#
#debug_peer_list = 127.0.0.1
#debug_peer_list = some.domain
# The debugger_command specifies the external command that is executed
# when a Postfix daemon program is run with the -D option.
#
# Use "command .. & sleep 5" so that the debugger can attach before
# the process marches on. If you use an X-based debugger, be sure to
# set up your XAUTHORITY environment variable before starting Postfix.
#
debugger_command =
PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
ddd $daemon_directory/$process_name $process_id & sleep 5
# If you can't use X, use this to capture the call stack when a
# daemon crashes. The result is in a file in the configuration
# directory, and is named after the process name and the process ID.
#
# debugger_command =
# PATH=/bin:/usr/bin:/usr/local/bin; export PATH; (echo cont;
# echo where) | gdb $daemon_directory/$process_name $process_id 2>&1
# >$config_directory/$process_name.$process_id.log & sleep 5
#
# Another possibility is to run gdb under a detached screen session.
# To attach to the screen session, su root and run "screen -r
# <id_string>" where <id_string> uniquely matches one of the detached
# sessions (from "screen -list").
#
# debugger_command =
# PATH=/bin:/usr/bin:/sbin:/usr/sbin; export PATH; screen
# -dmS $process_name gdb $daemon_directory/$process_name
# $process_id & sleep 1
# INSTALL-TIME CONFIGURATION INFORMATION
#
# The following parameters are used when installing a new Postfix version.
#
# sendmail_path: The full pathname of the Postfix sendmail command.
# This is the Sendmail-compatible mail posting interface.
#
sendmail_path = /usr/sbin/sendmail.postfix
# newaliases_path: The full pathname of the Postfix newaliases command.
# This is the Sendmail-compatible command to build alias databases.
#
newaliases_path = /usr/bin/newaliases.postfix
# mailq_path: The full pathname of the Postfix mailq command. This
# is the Sendmail-compatible mail queue listing command.
#
mailq_path = /usr/bin/mailq.postfix
# setgid_group: The group for mail submission and queue management
# commands. This must be a group name with a numerical group ID that
# is not shared with other accounts, not even with the Postfix account.
#
setgid_group = postdrop
# html_directory: The location of the Postfix HTML documentation.
#
html_directory = no
# manpage_directory: The location of the Postfix on-line manual pages.
#
manpage_directory = /usr/share/man
# sample_directory: The location of the Postfix sample configuration files.
# This parameter is obsolete as of Postfix 2.1.
#
sample_directory = /usr/share/doc/postfix/samples
# readme_directory: The location of the Postfix README files.
#
readme_directory = /usr/share/doc/postfix/README_FILES
# add this to new postfix to get it to add proper message-id and other
# headers to outgoing emails via the gateway.
message_size_limit = 20971520
#inet_protocols = ipv4
# This has to be set in newer postfix 3.3.0 or later or it will refuse to
# send any email. ;(
smtpd_recipient_restrictions = permit_mynetworks, reject_unauth_destination
smtpd_relay_restrictions = permit_mynetworks, reject_unauth_destination

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -385,7 +385,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -396,7 +396,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -397,8 +397,8 @@ relayhost = [192.168.0.1]
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -409,7 +409,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -696,7 +696,7 @@ inet_protocols = all
# mapping so we know where to go for .redhat.com mail
transport_maps = hash:/etc/postfix/transport
transport_maps = lmdb:/etc/postfix/transport
message_size_limit = 20971520
@ -716,7 +716,7 @@ smtpd_tls_cert_file = /etc/pki/tls/certs/smtpd.crt
smtpd_tls_key_file = /etc/pki/tls/private/smtpd.key
smtpd_tls_CAfile = /etc/pki/tls/certs/ca.crt
smtpd_tls_session_cache_timeout = 3600s
smtpd_tls_session_cache_database = btree:${queue_directory}/smtpd_scache
smtpd_tls_session_cache_database = lmdb:${queue_directory}/smtpd_scache
smtpd_tls_received_header = yes
smtpd_tls_ask_ccert = yes
smtpd_tls_received_header = yes
@ -728,7 +728,7 @@ tls_eecdh_ultra_curve = secp384r1
#TLS Client
smtp_tls_fingerprint_digest=sha1
smtp_tls_note_starttls_offer = yes
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
smtp_tls_policy_maps = lmdb:/etc/postfix/tls_policy
smtp_tls_security_level = may
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtp_tls_mandatory_ciphers = high

View file

@ -397,8 +397,8 @@ relayhost =
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -409,7 +409,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)
@ -696,7 +696,7 @@ inet_protocols = all
# mapping so we know where to go for .redhat.com mail
transport_maps = hash:/etc/postfix/transport
transport_maps = lmdb:/etc/postfix/transport
message_size_limit = 20971520
@ -728,7 +728,7 @@ tls_eecdh_ultra_curve = secp384r1
smtp_use_tls = yes
smtp_tls_fingerprint_digest=sha1
smtp_tls_note_starttls_offer = yes
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
smtp_tls_policy_maps = lmdb:/etc/postfix/tls_policy
smtp_tls_security_level = may
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtp_tls_mandatory_ciphers = high

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -386,7 +386,7 @@ masquerade_exceptions = root apache
# "postfix reload" to eliminate the delay.
#
#alias_maps = dbm:/etc/aliases
alias_maps = hash:/etc/aliases
alias_maps = lmdb:/etc/aliases
#alias_maps = hash:/etc/aliases, nis:mail.aliases
#alias_maps = netinfo:/aliases
@ -397,7 +397,7 @@ alias_maps = hash:/etc/aliases
#
#alias_database = dbm:/etc/aliases
#alias_database = dbm:/etc/mail/aliases
alias_database = hash:/etc/aliases
alias_database = lmdb:/etc/aliases
#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
# ADDRESS EXTENSIONS (e.g., user+foo)

View file

@ -7,30 +7,50 @@
- "{{ if_uuid.stdout_lines }}"
- name: Restart iptables
service: name=iptables state=restarted
ansible.builtin.service:
name: iptables
state: restarted
- name: Restart nftables
service: name=nftables state=restarted
ansible.builtin.service:
name: nftables
state: restarted
- name: Restart ip6tables
service: name=ip6tables state=restarted
ansible.builtin.service:
name: ip6tables
state: restarted
- name: Restart NetworkManager
service: name=NetworkManager state=restarted
ansible.builtin.service:
name: NetworkManager
state: restarted
- name: Reload NetworkManager-connections
ansible.builtin.command: nmcli c reload
- name: Restart postfix
service: name=postfix state=restarted
ansible.builtin.service:
name: postfix
state: restarted
- name: Restart rsyslog
service: name=rsyslog state=restarted
ansible.builtin.service:
name: rsyslog
state: restarted
- name: Restart watchdog
service: name=watchdog state=restarted
ansible.builtin.service:
name: watchdog
state: restarted
- name: Reload libvirtd
service: name=libvirtd state=reloaded
ansible.builtin.service:
name: libvirtd
state: reloaded
ignore_errors: true
when: ansible_virtualization_role == 'host'
- name: Create lmdb files
ansible.builtin.include_tasks: lmdb.yml
listen: "Create lmdb files"

View file

@ -35,7 +35,7 @@
- crypto-policies
- base/crypto-policies
# see https://forge.fedoraproject.org/infra/tickets/12321
# see https://forge.fedoraproject.org/infra/tickets/issues/12321
# This is needed to get SAML2 auth working with bugzilla.redhat.com
- name: Set crypto-policy on ipsilon servers to FEDORA40
command: "update-crypto-policies --set DEFAULT"

17
roles/base/tasks/lmdb.yml Normal file
View file

@ -0,0 +1,17 @@
---
- name: Read the config file
ansible.builtin.slurp:
src: /etc/postfix/main.cf
register: maincf
- name: Find all the lmdb files
ansible.builtin.set_fact:
lmdb_files: "{{ (maincf.content | b64decode) | regex_findall('lmdb:([^,\\s]+)') }}"
- name: Convert to lmdb
ansible.builtin.command: "{{ (item == '/etc/aliases') | ternary('postalias', 'postmap') }} lmdb:{{ item }}"
args:
creates: "{{ item }}"
loop: "{{ lmdb_files }}"
register: result
failed_when: result.rc != 0

Some files were not shown because too many files have changed in this diff Show more