1
0
Fork 0
forked from infra/ansible
Commit graph

2,226 commits

Author SHA1 Message Date
fbb7921ae9 Revert adding pagure-stg-ro01 to staging group 2026-08-05 08:07:30 +10:00
1b31df922b pagure-ro: fix staging SSL by adding host to staging group
pagure-stg-ro01 was missing from the [staging] inventory group, so it
got production wildcard cert vars instead of staging ones. Also pass
SSLCertificateChainFile through to httpd/website to avoid falling back
to the hardcoded 2025 production default.
2026-08-05 07:47:47 +10:00
6af8546180 batcave02: remove from inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-26 11:51:31 -07:00
James Antill
2a46108a91 siguldry: Add sign-bridge01.stg and initial signul-bridge playbook.
Signed-off-by: James Antill <james@and.org>
2026-07-22 12:09:27 -04:00
fadbb39054 batcave01: add git and attachments to backups again
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-16 16:43:10 -07:00
c51e04de81 Collectd: cleanup collectd everywhere except FMN
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-09 11:01:41 +00:00
9ce1351301 Revert "proxies / staging: move ssh to port 222"
This reverts commit a83380f64c.
2026-06-23 14:21:20 -07:00
a83380f64c proxies / staging: move ssh to port 222
This pr attempts to move sshd to port 222 on proxy01.stg and
proxy02.stg.

We want to do this (first here and then in prod) because we want to nat
in ssh from external and use haproxy to send that into
forge.fedoraproject.org. If we were using port 22 to connect here
it would conflict with forwarding it on to haproxy.

Note that we still need to actually get networking folks to make the nat
mapping and we still need to add haproxy config to send it into forge in
openshift, but this is the first step we need to get working before we
can do those things.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-23 21:02:52 +00:00
cae07e65f6 f42-test: eol and terminated
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-08 11:58:50 -07:00
52ac6c7ec6 pagure-stg-ro01: add new instance for readonly pagure in stg ( ticket 13351 )
For infra/tickets#13351
This makes a staging rhel10 vm thats just the same size / place
as pagure-stg01.

It still needs external ip's and nat in from those, but this should be
enough to install it and start setting things up.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-06-03 19:55:22 +00:00
bbf9258578 memcached02 (rhel9) retirement
We switched over to the rhel10 versions of these, so these are going
away. Thanks for your service!

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-27 13:48:59 -07:00
ccb89c99a4 memcached01: add a new prod memcached01
Once this is all setup we can switch to it and retire the rhel9 02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:26:22 -07:00
7268404db7 memcached01.stg: add properly to stg group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 17:06:58 -07:00
f8fbb98eda memcached01.stg: add a new rhel10 staging memcached
Once this is up and working, we can switch applications over to using
it, and retire the rhel9 one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-26 16:38:28 -07:00
f05fbe3876 dedicatedsolutions01: drop from inventory in favor of 02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-21 13:30:15 -07:00
ee21c8afc6 dedicatedsolutions02: add new host
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-18 16:20:17 -07:00
af80a6a3a0 secure-boot: clean up old bkernel role and add 2 more builders
We are no longer using the bkernel role (using the old card thats in
buildhw-x86-01), so this removes that role and mentions of it.

Also, because we are urgently building kernels all the time now,
add one more buildhw-x86 and one more buildhw-a64 to secure-boot channel
so we can build more/faster kernels.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-15 19:14:17 +00:00
977a470510 s390x-test01: add s390x maintainer test machine
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-05-14 13:07:30 -07:00
85b073eda1 [ipsilon] Remove ipsilon03 VM
This is an OpenID VM and this is done as part of
infra/tickets#13265

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-05-04 14:47:54 +00:00
3ac5d6b344 [ipsilon] Remove ipsilon02.stg from inventory
With the decommission of OpenID we no longer need this machine on
staging. Let's get rid of it.

See infra/tickets#13265 for more details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-04-16 12:15:56 +02:00
Jiri Kyjovsky
35af14084d copr-rpmeta: remove prod bday 2026-04-01 13:39:12 +02:00
Jiri Kyjovsky
5b71b2f834 copr-rpmeta: hostnames added + birthday production 2026-04-01 13:13:47 +02:00
Jiri Kyjovsky
13487e6389 copr: rpmeta remove birthday 2026-03-31 21:56:06 +02:00
Jiri Kyjovsky
f6ca11deea copr: add MVP for rpmeta service 2026-03-31 17:40:45 +02:00
James Antill
745e6a2aaf *-test* hosts: Add f44-test host file.
Signed-off-by: James Antill <james@and.org>
2026-03-17 13:57:49 -04:00
893e103461 gpu01: add new gpu01 machine in rdu3-iso
This machine is in the rdu3 isolated network.
For now, just setup a simple kickstart on one disk and a playbook that
does the normal base role things. We can adjust from here.

This machine has 1 nvme and another spinning rust device.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-03-05 19:55:21 +00:00
0b261fc507 inventory: re-enable proxy05
We still aren't able to get to mgmt on this host, but it's up and
operating normally, so we might as well use it for now.

If it goes down we can remove it again.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-01-30 10:37:59 -08:00
5809288d1e Remove proxy05 from mirrorlist proxies
The proxy05 is unavailable for last few days, let's remove it from
mirrorlist_proxies till the situation is resolved.

This will fix mirrorlist-statistics cronjob. See
https://pagure.io/fedora-infrastructure/issue/12993 for more info.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-01-19 13:37:35 +01:00
James Antill
efa0061ca5 Remove f41-test from inventory.
Signed-off-by: James Antill <james@and.org>
2025-12-25 08:35:47 -05:00
e1524d1fd0 smtp-mm-iso01: use correct hostname in inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 14:20:16 -08:00
e8bd81d11d vmhost-x86-iso03: add to inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 13:58:12 -08:00
16ce599474 vmhost-x86-iso02: add to inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-12 12:58:15 -08:00
2ea32b924f proxies: update hostnames for proxy03/14
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 17:53:29 -08:00
117c334dae rename smtp-mm-cc-rdu01 to smtp-mm-iso01
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 17:13:39 -08:00
3b3399c6d8 proxy03 and proxy14 adjustments for rdu3 move
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 16:30:02 -08:00
9fdcd69f80 download-cc-rdu01 becomes download-iso01.rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 15:02:59 -08:00
af10d77d68 smtp-auth-iso01: use rdu3 domain in name
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:51:06 -08:00
8b85f0e197 vmhost-x86-iso04: add to inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:36:25 -08:00
7d4c52b418 smtp-auth-iso01: provision in rdu3
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-11 14:24:14 -08:00
4b16351ce0 rdu2-cc to rdu3 dc move reorg
move all the rdu2-cc machines to rdu3, reconfigure things.

We will want to fill in a bit more info and check each of these before
using them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-10 14:02:52 -08:00
c7ee62b09b retrace03: move to rdu3 and reconfigure
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-10 12:12:50 -08:00
70c964ed9b pagure02: fare thee well.
We have moved to pagure01, retire pagure02

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-03 16:20:22 -08:00
91ca2a6bf3 pagure-stg01: say fare thee well
We have moved over to pagure-stg02 now in rdu3, so retire this vm.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-02 14:28:06 -08:00
ea1b90077f retire vmhost-x86-cc05.rdu-cc.fedoraproject.org and vmhost-x86-cc06.rdu-cc.fedoraproject.org
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2025-12-01 09:44:25 -08:00
Jiri Kyjovsky
6f94dc8907 copr: migration to f43, drop birthday, enable services 2025-11-26 10:57:16 +01:00
Jiri Kyjovsky
f8cf895147 copr: migration to f43 part 2 2025-11-26 09:47:15 +01:00
Jiri Kyjovsky
b29b05efb5 copr-be-temp: initiate temp backend instance 2025-11-26 08:49:20 +01:00
Jiri Kyjovsky
8daa7e4eb1 copr: revert inventory changes, and birthday 2025-11-23 22:34:22 +01:00
Jiri Kyjovsky
04b6d4fea5 copr-be-dev-temp: revert inventory changes 2025-11-23 22:10:34 +01:00
Jiri Kyjovsky
49a79212a4 copr: practise second round of migration 2025-11-23 18:25:03 +01:00