1
0
Fork 0
forked from infra/ansible
Commit graph

46,619 commits

Author SHA1 Message Date
f14c45f68c
Collectd: missed a deleted role in psql playblook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 14:00:11 +01:00
c5e16e687c [flatpak-indexer] Separate the instances
Try another approach to separate the instances. Create a separate redis
instance for quay.io, that should allow to have completely separate
quay.io resources and registry.fp.o resources.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-08 12:48:20 +00:00
c712b24ee4 Collectd: remove files & packages
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 12:23:07 +00:00
f796c95508
OScontrol: add missing yaml directive to playbook
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 13:11:36 +01:00
92fe69c649 OpenShift: Refactor os-control playbook to a role and add monitoring
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-08 12:06:57 +00:00
360f493bc4 pagure: try adjusting lines on patch
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:33:10 -07:00
71585073ad pagure: add a line to the patch so the numbers match up and it applies
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:14:36 -07:00
d0e61275a6 Allow draft builds on ELN side-tags
Fixes: releng/tickets#13374

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-08 00:05:53 +00:00
6882b20e9b pagure: add a line to the patch so the numbers match up and it applies
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 17:01:28 -07:00
29cce54d62 📧 roles(fasjson): Update logo alias
This commit updates the `logo` alias to make sure trademark permission
requests are correctly routed to the Fedora Design Team Admins as the
most responsible party for the legal stewardship of the Fedora Project
trademark and brand. Therefore, to encourage use of FAS group membership
to better manage access to these hand-coded email aliases, this will now
send all emails to this alias to FAS account users with membership as
sponsors in the `designteam` FAS group.

Once this change is deployed and updated in production, this mail alias
will begin sending mail to @duffy (no change), @ekidney, @jesschitas,
@jflory7, @madelinepeck (no change), and @mleonova.

Signed-off-by: Justin Wheeler <jwheel@redhat.com>
2026-07-07 23:58:12 +00:00
3d93bf17bc releng: run sig_policy script daily instead of weekly
This script should be inexpensive to run, so it'd be nice to run it more
frequently.
2026-07-07 23:54:23 +00:00
99e363981c releng: use new git repo for sig_policy script 2026-07-07 23:54:23 +00:00
66caf2072c add openshift/app-actions to blockerbugs.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:42:56 +00:00
48d0ccef83 add openshift/app-actions to badges.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:42:32 +00:00
200b7a1fd7 add openshift/app-actions to asknot.yml
Signed-off-by: Vít Smolík <me@smoliicek.cz>
2026-07-07 22:40:46 +00:00
3ddb342c58 application-monitoring: retire app
We never deployed this in the new clusters since we moved and the folks
who were working on it have left. If we want to revive it later, we can
always pull it out of git history.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2026-07-07 15:38:59 -07:00
c7a559d359 feat(pagure.io): added notification banner and git hook that informs about pagure migration
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-07 22:34:20 +00:00
0be5e89880 ci: implement differential yamllint scan
Use vcs-diff-lint (with csdiff backend) to report only new warnings and
errors introduced in a PR.  This prevents older, pre-existing linter
violations from blocking new changes.

Same analyzer version is used for both the base and the head commit to
ensure consistent results.

See: infra/ansible#3143
2026-07-07 22:11:11 +00:00
Jiri Kyjovsky
99f1ff2202 base: disable iptables service when nftables is enabled
When `nftables=True` the base role deploys nftables rules and enables the
nftables service, but never disables the iptables service. On freshly
provisioned hosts the iptables service can be left running from cloud-init,
overwriting nftables rules and silently dropping traffic on ports defined
in `tcp_ports`.

Stop and disable the iptables service explicitly when nftables is the
intended firewall backend.
2026-07-07 22:02:24 +00:00
James Antill
ff663e686f elnbuildsync: Use auth_method=client_secret_basic.
Signed-off-by: James Antill <james@and.org>
2026-07-07 17:12:49 -04:00
dabb77faf4 ELNBuildSync: Set authorized groups
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 19:52:17 +00:00
James Antill
108228f6fd elnbuildsync: Add stg. config. to ipsilon.
Signed-off-by: James Antill <james@and.org>
2026-07-07 15:39:11 -04:00
db494be972
ELNBuildSync: enable redeployment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 14:13:02 -04:00
d880671e4f
ELNBuildSync: fix client_id on staging
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 14:09:22 -04:00
cd7f6c2efc
ELNBuildSync: Use the right namespace in the service object
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 13:32:04 -04:00
eee169398c
ELNBuildSync: Actually apply the service object
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 13:25:37 -04:00
James Antill
96b1531c50 Revert "elnbuildsync: limit to staging for now"
This reverts commit 7ef75bd174.
2026-07-07 12:55:32 -04:00
0aa20b9436
ELNBuildSync: Prepare prod deployment
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>

rh-pre-commit.version: 2.4.0
rh-pre-commit.check-secrets: ENABLED
2026-07-07 11:07:32 -04:00
Jiri Podivin
6f377c8d87 Check for undefined deploy script
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 12:37:45 +02:00
dee5b453f1
Zabbix: get the tag name/value pair the right way around
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-07 10:45:17 +01:00
ea32c85fa7
Zabbix: 13450 - filter COPR notifications better
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-07 10:40:59 +01:00
83b0f60d6a [postfix] Change the relayhost for sign machines
Today the bastion relayhost didn't work for sign-bridge. So we changed
it to bastion01.rdu3.fedoraproject.org. This worked, so let's reflect
that change in ansible as well.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2026-07-07 11:01:08 +02:00
Jiri Podivin
51a458f26b User certbot role for Log Detective
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:45:21 +00:00
Jiri Podivin
f4c497e764 Create a separate role for certbot driven certificate renewal
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:45:21 +00:00
Jiri Podivin
cd29c1260e Attempt shut down Log Detective service before restarting it
Signed-off-by: Jiri Podivin <jpodivin@redhat.com>
2026-07-07 08:39:45 +00:00
Lenka Segura
6e63ce738b forge: Add mobility runner to production
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-07 10:26:01 +02:00
Lenka Segura
5686cf77b7 forge: add regular runner for go org
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-07 07:30:40 +00:00
701d7e1867 fix(koji-http-toggle): delete each nft drop rule handle separately
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:45:36 +05:30
f059b1f9d2 fix(koji-http-toggle): resolve proxy IPs via shell so awk pipe works
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:32:36 +05:30
d9e7279830 Add Ansible playbook to toggle Koji HTTP access with nftables
Signed-off-by: Samyak Jain <samyak.jn11@gmail.com>
2026-07-07 12:14:25 +05:30
f2239cb238 feat(forgejo): oauth-proxy delegates /metrics endpoint to be accesible through token
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-06 15:59:51 +02:00
Lenka Segura
53bede04b2 forge: add staging docs and production relend testing-farm runners
Signed-off-by: Lenka Segura <lsegura@redhat.com>
2026-07-06 15:33:27 +02:00
df71a59847
forgejo: fixed bug with UUID in zabbix template
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-06 13:40:36 +01:00
539176cb09
Collectd: disable collectd pod in FMN app, log01 is no longer listening
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-06 11:55:19 +01:00
Jakub Kadlcik
e5bb2ff606 copr: use the latest version of the expect package
Fix https://github.com/fedora-copr/copr/issues/4361
2026-07-06 10:49:20 +02:00
d13496b221
Collectd: stop the collectd service everywhere, prior to removal
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-03 13:09:19 +01:00
42ac8c53d5
forgejo: wip zabbix template to monitor forge metrics endpoint
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2026-07-03 12:03:17 +01:00
9ea0108e6d feat(forgejo): added SA,R,RB,S that zabbix will you to bypass oauth-proxy for accessing metrics endpoint
Signed-off-by: Anton Medvedev <amedvede@redhat.com>
2026-07-03 12:09:43 +02:00
9b65ab416b
Nagios: remove nagios_server role
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-02 13:39:18 +01:00
bf0cafb5b4
Nagios: fix removal task ordeering
Signed-off-by: Greg Sutcliffe <fedora@emeraldreverie.org>
2026-07-02 13:32:09 +01:00