1
0
Fork 0
forked from infra/ansible
Commit graph

10,447 commits

Author SHA1 Message Date
8d7c1a3d5a
Add buildhw-x86-15 to inventory
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-13 10:25:59 +01:00
b9a1fa57f3 openqa: enable dist-git testing in prod
This should enable dist-git PR testing in prod, and make *only*
prod report status back to dist-git (staging no longer should).

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-07-10 18:21:28 -07:00
14af240a82 swap buildhw-a64-02 and bvmhost-a64-03
bvmhost-a64-03 has a bad memory slot, so needs to be sent back to get
fixed/replaced. In the mean time lets replace it with buildhw-a64-02,
which has the same specs.

When the fixed one comes back we can make it a new buildhw-a64-02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-10 10:21:33 -07:00
4376cb6af3 buildhw-a64-03: move into secureboot group and drop 02 out
We are moving 02 out to become the new bvmhost-a64-03 while that one is
shipped back for repairs. 03 will take over on secureboot.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-10 09:40:20 -07:00
dd027f50c6 Revert "[ipa] Switch ipa_server to ipa03.stg"
This reverts commit 0a1c8efada.
2026-07-10 13:41:13 +02:00
0a1c8efada [ipa] Switch ipa_server to ipa03.stg
This is temporary to reinstall ipa01.stg

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-10 13:26:32 +02:00
bb4724a116 [ipa] Move ipa01.stg to RHEL 10
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-10 13:12:41 +02:00
8b4b0b4587 [ipa] Use correct ks file
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-10 10:56:58 +02:00
bc04ce9e65 [ipa] Move ipa02.stg to RHEL10
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-10 10:48:07 +02:00
Jakub Kadlcik
7e50a3dd8a copr: oops, fix pool names dev -> prod 2026-07-09 16:22:41 +02:00
4164dbee61
Add buildhw-x86-17 to inventory
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 14:55:35 +01:00
Jakub Kadlcik
11c1eaeda1 copr-be: increase allowed startup time for s390x builders to 300s 2026-07-09 15:34:32 +02:00
c52f7a9416
Copr: Add build-checks template to Zabbix
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 13:22:34 +01:00
2cc782bab0
Copr: raise build timeouts on s390 pools to 300s
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 12:14:57 +01:00
c51e04de81 Collectd: cleanup collectd everywhere except FMN
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 11:01:41 +00:00
e924d1be9e
Add buildhw-x86-16 to inventory too
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 16:22:02 +01:00
6303816ffa
IAD2: add newly-built buildhw-x86-16
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 16:13:25 +01:00
Jiri Podivin
51a458f26b User certbot role for Log Detective
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:45:21 +00:00
b74bb8e1a3 communishift: add pvc handling and allow 3 for happinesspackets
Per infra/tickets#13437

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-01 14:40:17 -07:00
cc06635ada
Zabbix: kojipkgs uses a different port for Varnish
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-01 10:24:30 +01:00
537ab5d20f Revert "nbde: set threshold to 5"
This reverts commit db0b9e4f0c.

This is not the correct knob to adjust number of attempts.
This is number of things that have to be successfull before unlock.
1 is right here. ;(
2026-06-29 15:25:28 -07:00
0ce30a13ba buildvm-s390x-13.s390.fedoraproject.org: remove from compose
We have 3 compose builders, but we don't really need all of them I don't
think. The rawhide composes do boot.iso for everything and server
and server dvd here, so 2 builders I think should be fine.

Lets move this one to be a general builder to try and prevent
backlogs.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-26 09:33:09 -07:00
d6f46658ec
Revert "Refs 13419 - disable worker 04/05 in the proxies as httpd-lb isn't doing it's thing"
This reverts commit bdf834a3e9. The
workers are back online now, and we can use them again.
2026-06-26 09:08:04 +01:00
d13f189e4f [ipa] Use the correct ks_url
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-26 09:41:14 +02:00
db0b9e4f0c nbde: set threshold to 5
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 14:27:07 -07:00
efc43822cd vmhost-x86-copr02: fix mac for bond port
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 11:09:20 -07:00
03295b7d89 vmhost-x86-copr01: fix mac for bond port
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 11:08:25 -07:00
68a1efb111 buildhw-x86-12: fix mgmt ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-25 09:40:45 -07:00
479256ae92 [ipa] Move ipa03.stg to RHEL10
First step to move IPA on staging to RHEL 10.
See infra/tickets#13382

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-06-25 14:40:33 +00:00
a16deeb465
Postfix: use postfix_group variable to get the right main.cf for maintainer_test
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 15:28:25 +01:00
bdf834a3e9
Refs 13419 - disable worker 04/05 in the proxies as httpd-lb isn't doing it's thing
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-25 10:45:12 +01:00
465c2ca3ec Revert "openQA etc: use a single-cert CA cert file for staging rabbitmq (#13422)"
This reverts commit 49f42faa1b.
I've updated to latest fedora-messaging and want to see if this
is unnecessary now.
2026-06-25 09:50:35 +01:00
13c67bd1c2 proxies: bump max connections up more
Seems like there are a ton of really small connections and it starts
hitting the limit (although it never logs that it's out, I think because
they free up quickly).

See if this solves the transitory alerts we see.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 15:21:10 -07:00
280e9bbe54 proxy02.stg: add some secondary ips
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 15:20:25 -07:00
c9b56e6358 proxy01.stg: use proper ipv6 format
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 14:32:04 -07:00
cda4b5e5a3 proxy01.stg: try an approach using a secondary ip
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 14:28:39 -07:00
9ce1351301 Revert "proxies / staging: move ssh to port 222"
This reverts commit a83380f64c.
2026-06-23 14:21:20 -07:00
a83380f64c proxies / staging: move ssh to port 222
This pr attempts to move sshd to port 222 on proxy01.stg and
proxy02.stg.

We want to do this (first here and then in prod) because we want to nat
in ssh from external and use haproxy to send that into
forge.fedoraproject.org. If we were using port 22 to connect here
it would conflict with forwarding it on to haproxy.

Note that we still need to actually get networking folks to make the nat
mapping and we still need to add haproxy config to send it into forge in
openshift, but this is the first step we need to get working before we
can do those things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 21:02:52 +00:00
2c85bbbdf1 readd communishift-happinesspackets ( ticket #13238 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-22 13:46:15 -07:00
bca0d4843a
Zabbix: use non-vpn server target for maintainer test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 16:00:23 +01:00
a574775086
Zabbix: use correct and not-typoed server target for maintainer_test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:44:08 +01:00
474152f472
Zabbix: use correct server target for maintainer_test hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:35:53 +01:00
34bba84c4a
Zabbix: use correct server target for logdetective hosts
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-22 15:27:29 +01:00
47e4cedcff Define openqa_env_prefix for servers
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-21 00:11:49 +01:00
49f42faa1b openQA etc: use a single-cert CA cert file for staging rabbitmq (#13422)
See infra/tickets#13422
for details on this. It seems like rabbitmq staging has been
switch to the 'new' CA cert, and the consumers don't actually
read/trust both certs in the combined CA cert file, only the
first (old) one, so they don't trust the new one. This should
deploy and use a new file with only the new CA cert in it. We
copy it out of the private repo for convenience but it's not
actually private, hence the 0644 perms.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-20 14:39:13 +02:00
7c8d8a1794 Revert "openQA: try using old pki cert/key on staging"
This reverts commit 293930446b. It
doesn't look like it helped.
2026-06-20 11:19:24 +02:00
293930446b openQA: try using old pki cert/key on staging
I'm having auth issues on openQA staging, I believe it *may* be
to do with the changes Aurelien made in
6fe8b98de21747dc16d59dcf5096da719a541296 . Let's see if using the
old key and cert helps.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-20 11:14:30 +02:00
73a749e915
Zabbix: add 100 to postfix queue triggers for smtp-mm
spammers are making the queues longer, lets allow a bit more headroom

Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-06-19 13:11:56 +01:00
6de0108ef7 openQA dist-git PR test result reporting config (staging)
This *should* configure a new queue and consumer for openQA to
report dist-git PR test results back. It's all a bit speculative
ATM, may need some tweaking. Mostly applied only on staging for
now.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-06-19 13:25:02 +02:00
83f050747d Add communishift copr project ( ticket 13409 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-18 15:20:46 -07:00