not enough disk on git.fedorahosted.org

2010-04-12 Thread Miroslav Suchý
Please delete something or buy another disk :) We got there email hook, which probobly do not have enough disk space on some mount. [msu...@dri/~/rhn/spacewalk.pub/schema/spacewalk]$ git push --tags Counting objects: 1, done. Writing objects: 100% (1/1), 229 bytes, done. Total 1 (delta 0), reus

www and git of fedoraproject.org do not respond

2010-11-09 Thread Miroslav Suchý
www and git service of fedoraproject.org time-outs. Host responds to ping. -- Miroslav Suchy Red Hat Satellite Engineering ___ infrastructure mailing list infrastructure@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/infrastruct

Re: www and git of fedorahosted.org do not respond

2010-11-09 Thread Miroslav Suchý
On 11/09/2010 09:13 AM, Ricky Zhou wrote: > wget -SO/dev/nullhttp://fedoraproject.org/ Did I say fedoraproject? I'm dumb, sorry. I meant fedorahosted.org. $ wget -SO/dev/null https://fedorahosted.org/ --2010-11-09 09:24:06-- https://fedorahosted.org/ Resolving fedorahosted.org... 66.135.52.17 Co

Fedora Cloud

2013-09-04 Thread Miroslav Suchý
Do we have some documentation about Fedora Cloud? I'm asking because I'm able to start and terminate instances from copr-be. But I would like to learn more about it before I broke something :) -- Miroslav Suchy, RHCE, RHCDS Red Hat, Software Engineer, #brno, #devexp, #fedora-buildsys __

Re: Summary/Minutes from today's Fedora Infrastructure meeting (2013-09-12)

2013-09-13 Thread Miroslav Suchý
On 09/12/2013 09:51 PM, Kevin Fenzi wrote: 19:39:45 I think that's the idea 19:39:51 make a first release of copr 19:39:55 have people start to use it 19:40:01 integrate it into koji later on Yes this is true. I am using current code and polishing it for public roll out. After it will go pu

Re: Summary/Minutes from today's Fedora Infrastructure meeting (2013-09-12)

2013-09-16 Thread Miroslav Suchý
On 09/13/2013 06:40 PM, Kevin Fenzi wrote: I think we can pretty much look at opening it up where it is, then see how things are resource wise before announcing it more widely? *nod* Only thing what worries me is disk space. Currently I have from Fedora Cloud 200 GB. According to my calculation

Re: Migrating to our own bugzilla instance.

2013-09-18 Thread Miroslav Suchý
On 09/17/2013 04:37 PM, "Jóhann B. Guðmundsson" wrote: You do realize that Fedora != RHEL right so it and it's business needs which includes EPEL ( which has absolutely nothing to do with Fedora ) should be run in an entire separated infrastructure from Fedora. /me mumbles something about sha

Re: Migrating to our own bugzilla instance.

2013-09-18 Thread Miroslav Suchý
On 09/17/2013 12:37 PM, "Jóhann B. Guðmundsson" wrote: since my frustration level with RH bugzilla has grown to an all time high due to frequent collision with internal RH administrative policy's that nobody in the community knows exactly which are, Can you please elaborate which Red Hat polic

Re: Summary/Minutes from today's Fedora Infrastructure meeting (2013-09-12)

2013-09-18 Thread Miroslav Suchý
On 09/16/2013 04:58 PM, Kevin Fenzi wrote: When we first setup our cloud, we setup the storage for volumes on just the head node. The other 5 nodes in the mix also have storage. Over time we added another nodes storage to it, but haven't done anything with the other 4. Thats a bit spread out howe

Re: Migrating to our own bugzilla instance.

2013-09-18 Thread Miroslav Suchý
On 09/18/2013 04:20 PM, "Jóhann B. Guðmundsson" wrote: On 09/17/2013 12:37 PM, "Jóhann B. Guðmundsson" wrote: since my frustration level with RH bugzilla has grown to an all time high due to frequent collision with internal RH administrative policy's that nobody in the community knows exactly w

Introduction

2013-09-19 Thread Miroslav Suchý
Hi, I've been on this list for a while, but mostly passive. I want to change that. So let me formally introduce myself. My name is Miroslav Suchý (sometime I use short name Mirek). I'm using Linux from previous millennium. I'm Red Hat employee since 2006. I worked on RHN, Spacew

How we handle attacks?

2013-10-03 Thread Miroslav Suchý
I see in log file of copr-fe-dev a lot of attempts to login as root/postgres/nagios/oracl/test user. Well it is ~4000 attempts. So it depend on your definition of "lot of". But it caught my attention. Do we have some standard procedure how to handle it? Add that IPs to blacklist? Move ssh port t

Re: How we handle attacks?

2013-10-03 Thread Miroslav Suchý
On 10/03/2013 02:55 PM, Jhoanir Torres wrote: Is highly recommended use 'Fail2Ban' in victim servers. And do we already use it? Because git grep in ansible.git returns zero to me. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Software Engineer, #brno, #devexp, #fedora-buildsys __

Re: How we handle attacks?

2013-10-07 Thread Miroslav Suchý
On 10/07/2013 05:23 AM, Anshu Prateek wrote: Most of these logins are automated bot attempts. On my personal servers, one easy way I have found is changing the default port to something else and that cuts down my lastb by almost 99%! Yes, I do that for my personal servers as well (and it works

Arm in Fedora cloud?

2013-10-10 Thread Miroslav Suchý
Hi, Is is possible to get arm VM from Fedora Cloud. If not native, then at least emulated on x86 machine? -- Miroslav Suchy, RHCE, RHCDS Red Hat, Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing list infrastructure@lists.fe

How I create new AMI?

2013-10-10 Thread Miroslav Suchý
Hi, can somebody point me to documentation how to create new AMI in Fedora Cloud, please? I know how to create it in OpenStack dashboard via WebUI, but we do not have dashboard, right? How can I create it in Fedora Cloud? -- Miroslav Suchy, RHCE, RHCDS Red Hat, Software Engineer, #brno, #devexp

Re: How I create new AMI?

2013-10-15 Thread Miroslav Suchý
On 10/15/2013 03:50 PM, Matthew Miller wrote: On Mon, Oct 14, 2013 at 03:07:47PM -0600, Kevin Fenzi wrote: Ideally it would be nice if we could just standardize on the fedora cloud images and provision from there, so we don't need to make our own. Yes please. What do you need to make that happ

Re: How I create new AMI?

2013-10-15 Thread Miroslav Suchý
On 10/14/2013 11:07 PM, Kevin Fenzi wrote: Basically we just make a .qcow2 image and then someone who's got access uploads it into the cloud, then it becomes available (provided it's marked public). And what is the command? Mirek-in-learning-mode -- Miroslav Suchy, RHCE, RHCDS Red Hat, Softwa

Copr documentation

2013-10-22 Thread Miroslav Suchý
Hi, I created http://infrastructure.fedoraproject.org/infra/docs/copr.txt which have some informations, which is stored neither in copr wiki, nor in ansible playbooks. And which may be usefull if somebody have to act on copr machines without knowledge of copr. -- Miroslav Suchy, RHCE, RHCDS R

Re: Some questions around coprs

2013-12-05 Thread Miroslav Suchý
On 12/04/2013 09:20 PM, Kevin Fenzi wrote: 1. Do we even want to persue this? Not my priority. But if somebody will be willing to do it, then you are welcome. 2. If so, do we have any ideas how signing copr packages could work? I did not investigated it yet (again not priority right now) bu

Re: Ansible question

2013-12-09 Thread Miroslav Suchý
On 12/07/2013 10:28 AM, Michael Scherer wrote: Le vendredi 06 décembre 2013 à 18:01 +0100, Miroslav Suchy a écrit : >Working on Copr, I want to replace/add one line in file. I spent more >then hour trying various things, but I'm out of ideas. > >What I'm trying to do is: > >self.conn.module_name

How tickets are resolved

2013-12-19 Thread Miroslav Suchý
Hi, I have suggestion. Can we please put into tickets how they have been resolved? I mean something else then "Fixed". Something like: Fixed - puppet.git commit abc123 or Fixed - I run command "rm foo.bar" This way people (and apprentice group especially) can learn how infra set up works. A

Re: January status update for Fedora Infrastructure Apprentices

2014-01-07 Thread Miroslav Suchý
On 01/06/2014 08:45 PM, Kevin Fenzi wrote: > 0. Whats your fedora account system login? msuchy > 1. Have you logged in and used your fi-apprentice membership to look at > our machines/setup in the last month? Do you plan to? No. I was eating candies and packing and unpacking gifts. > 2. Has it

Re: state of the infra ansible, cron job and roadmap

2014-01-09 Thread Miroslav Suchý
On 01/08/2014 09:10 PM, Kevin Fenzi wrote: > a) run a --check --diff once a day and yell about unreachable or > changed>0 > (I could commit this now) +1 but allow to set exceptions. For example I expect that copr-fe-dev and copr-be-dev differ from ansible config, because I'm breaking it on purpos

Re: Is copr ready for primetime?

2014-02-10 Thread Miroslav Suchý
On 02/08/2014 07:37 PM, Kevin Fenzi wrote: On Sat, 08 Feb 2014 21:29:49 +1100 Graham Williamson wrote: I've created a ticket to add some missing web apps to apps.fp.o. https://fedorahosted.org/fedora-infrastructure/ticket/4224 The question (as discussed in irc just now) is should copr be add

Copr Nagios alerts

2014-02-10 Thread Miroslav Suchý
I will be creating Nagios alerts and testing it. If you will see Copr alerts feel free to ignore them until I say otherwise. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing li

Re: Is copr ready for primetime?

2014-02-11 Thread Miroslav Suchý
On 02/10/2014 05:51 PM, Kevin Fenzi wrote: I don't know how far away that is, or even if it's going to be fully possible tho.;) Far far away :) >But from Copr POV it can be completly fine to have copr-fe in apps >and copr-be in cloud. Yeah, I don't know that there is much advantage, since i

Problems with recent ansible

2014-02-26 Thread Miroslav Suchý
FYI: https://groups.google.com/forum/#!topic/ansible-project/Mj6vmhqMED8 just beware before you do "yum upgrade". -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing list infrastr

Re: Problems with recent ansible

2014-02-27 Thread Miroslav Suchý
On 02/27/2014 12:21 AM, Kevin Fenzi wrote: I'd be interested in short reproducers here... the changes between 1.4.3 and 1.4.5 are really minor: That is really strange. The problem disappear after I downgraded. I was not able to reproduce it on another machine. And today it start happen on copr

Re: Problems with recent ansible

2014-02-28 Thread Miroslav Suchý
It happen again.But now I have more traces and hints. This morning (9:33 UTC) I get Nagios alert that: WARN: datanommer has not seen a copr message in 6 hours, 10 minutes, 39 seconds which means that sometime between 3:30 UTC and 4:30 UTC something happen. I logged to copr-be and to my surprise

Re: Problems with recent ansible

2014-03-02 Thread Miroslav Suchý
On 02/28/2014 06:52 PM, Kevin Fenzi wrote: Just ping me on irc when you are available to watch the copr-be end. Will do. In the meantime I 'solved' it by "chattr +i" on those files. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys

Fedora Cloud cleanup

2014-03-13 Thread Miroslav Suchý
According to my searches this images are not used (I searched both ansible.git and puppet.git). not used at all: f17_qcow_id: ami-0001 f16-64: ami-0002 Can I remove it? Unless you stop me, I will remove it after one week. used by inventory/host_vars/209.132.184.166 (jenkins-f18) and pl

Re: [ansible] Try out this conditional restart stuff.

2014-03-17 Thread Miroslav Suchý
On 03/14/2014 04:30 PM, Ralph Bean wrote: +- name: restart fedmsg-gateway + command: /usr/local/bin/conditional-restart.sh fedmsg-gateway fedmsg-gateway Ralph, I tried to run copr-backend playbook and this notified and therefore executed, but failed, because NOTIFIED: [restart fedmsg-gateway

Re: [ansible] Try out this conditional restart stuff.

2014-03-19 Thread Miroslav Suchý
On 03/17/2014 02:43 PM, Ralph Bean wrote: Did I incorrectly assume that we are including that in every playbook? Obviously :) I fixed that already. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___

Re: Scheduling an IRC meeting on our private cloud setup

2014-03-26 Thread Miroslav Suchý
On 03/25/2014 08:12 PM, Ralph Bean wrote: Meeting started by nirik at 18:00:03 UTC. The full logs are available at http://meetbot.fedoraproject.org/fedora-classroom/2014-03-25/infrastructure-private-cloud-class.2014-03-25-18.00.log.html I promised to ask OpenStack guys two guestions. Here are t

New fedmsg certs

2014-04-24 Thread Miroslav Suchý
Today I was notified that #fedora-fedmsg say: [09:43] copr.build.end (invalid signature!) -- ... I had to re-run playbook because that it seem that fedmsg got new certs and revoked old. I still see at least: [09:56] buildsys.build.state.change (invalid signature!) -- karsten's libccp4-6.3.1-

Openstack ansible manifest

2014-04-25 Thread Miroslav Suchý
Following yesterday meeting: This is may work-in-progress of openstack ansible manifest: https://github.com/xsuchy/openstack-ansible-install I decided to skip all this undercloud etc. and just follow what main wiki suggest: http://docs.openstack.org/trunk/install-guide/install/yum/content/index.h

source FOO in Ansible?

2014-04-28 Thread Miroslav Suchý
Lets have file FOO with: export OS_USERNAME=admin export OS_PASSWORD=ADMIN_PASS can I somehow do in Ansible: source FOO and for all next actions, those variables will be defined? Writing: - shell: source FOO && bar looks kind a ugly to me -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior S

Vacation Thu,Fri *2

2014-04-30 Thread Miroslav Suchý
I will be on vacation on 1st, 2nd and 8th, 9th May. Just FYI. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing list infrastructure@lists.fedoraproject.org https://admin.fedorapr

Plan of work for Copr signing

2014-05-22 Thread Miroslav Suchý
FYI - this is my schedule of work needed to sign packages in Copr: Hardware: = Next visit in PHX is planned on June/July. Next one is January of 2015. Ideal (and most paranoid) setup would require one physical machine for Signing server and one for copr-backend and one wire between them

Re: Plan of work for Copr signing

2014-05-23 Thread Miroslav Suchý
On 05/22/2014 08:47 PM, Paul W. Frields wrote: Has there been any review of the package signing process by security guys? Since this is presumably different from the standard Fedora package signing process, it might make sense to have someone advise, if not done already. Will do. -- Miroslav

Re: Plan of work for Copr signing

2014-05-30 Thread Miroslav Suchý
On 05/23/2014 05:45 PM, Kevin Fenzi wrote: * a key per user key per user When are things intended to be signed? At the end of successfull build? At the end of successful build. If signing fails, will that fail the build? Should it? Likely yes. I will think about it. Can obs-signd hand

Re: July status update for Fedora Infrastructure Apprentices

2014-07-07 Thread Miroslav Suchý
On 07/04/2014 09:00 PM, Kevin Fenzi wrote: 0. Whats your fedora account system login? msuchy 1. Have you logged in and used your fi-apprentice membership to look at our machines/setup in the last month? Do you plan to? No. I'm mostly relying on presence in systadmin-cloud membership. 2. H

Re: Transifex has become proprietary

2014-07-07 Thread Miroslav Suchý
On 07/03/2014 04:20 PM, Dimitris Glezos wrote: It's a good thing that this came up, it'd be nice to have a clear decision from the Fedora part. I explained in detail the log & reasoning behind the decision to stop maintaining the open-source branch in the GitHub issue Rahul provided. Dimitris

Re: Transifex has become proprietary

2014-07-18 Thread Miroslav Suchý
On 07/15/2014 10:41 PM, Dimitris Glezos wrote: The data we have is that very few people used (and use) the open-source version of Transifex. Some of those who did, were using an even older version of Transifex (0.9) which we weren't actively maintaining. We have asked around and carefully revie

New OpenStack instance

2014-07-24 Thread Miroslav Suchý
This is mostly for Kevin and Stephen. Stephen provisioned fed-cloud09.cloud.fedoraproject.org to RHEL7. I installed there new OpenStack instance using [1]. I make git-clone and files are in: /root/openstack-ansible-install I modified var/* to match IP and generated new passwords. It would be n

OpenStack Ansible modules

2014-08-28 Thread Miroslav Suchý
FYI: Adam packaged openstack-ansible-modules for Fedora (and Epel7). https://bugzilla.redhat.com/show_bug.cgi?id=1134377 I expect that it would simplify our new OS playbook. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___

Re: September status update for Fedora Infrastructure Apprentices

2014-09-02 Thread Miroslav Suchý
On 09/03/2014 12:15 AM, Kevin Fenzi wrote: Greetings. You are getting this email because you are in the 'fi-apprentice' group in the fedora account system (or are reading this on the infrastructure list). Feel free to reply just directly to me, or cc the infrastructure list for everyone to see

Re: Gitolite3 on pkgs01.stg

2014-09-05 Thread Miroslav Suchý
On 09/05/2014 12:45 PM, Pierre-Yves Chibon wrote: ? Performance impact of this number of users? Performance drops by 17% http://miroslav.suchy.cz/blog/archives/2014/09/05/how_the_size_of_authorized_keys_affects_speed_of_ssh_authorization/ -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Soft

Re: Gitolite3 on pkgs01.stg

2014-09-05 Thread Miroslav Suchý
On 09/05/2014 02:39 PM, Miroslav Suchý wrote: Performance drops by 17% http://miroslav.suchy.cz/blog/archives/2014/09/05/how_the_size_of_authorized_keys_affects_speed_of_ssh_authorization/ And to emphasis: This is worst case scenario for those users at the end of file. So if we average all

Re: Something is polluting lockbox01 /

2014-10-08 Thread Miroslav Suchý
On 09/17/2014 05:18 PM, Kevin Fenzi wrote: Yes, ansible makes these anytime a playbook has failed hosts. The idea is that you can then pass this retry to it on the next run and it will only run on those hosts that failed.;) There shouldn't be any in / they should be in/root/ I guess ('cos of f

Copr to use primary Fedora download location

2014-10-17 Thread Miroslav Suchý
Hi, right now Copr is using stock mock, with its default configuration. Which means that Copr builders are downloading packages from Fedora mirrors. I find this sub-optimal, because: * sometimes is mirror little bit off-sync and occasionally this result in failed builds. * while mirrors are gen

Re: Copr to use primary Fedora download location

2014-10-17 Thread Miroslav Suchý
Additionally I would like to do the same for Centos. Before I ask CentOS guys... do we have somewhere in our datacenter copy of CentoOS repo? If not, I'm not sure if I would like to rsync everything. Maybe rather just setup squid. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Enginee

change in conditional-restart.sh

2014-12-08 Thread Miroslav Suchý
Hi, today I run groups/copr-backend.yml playbook and fedmsg/base notified "restart httpd". Which failed because httpd is there installed, but not enabled (it is there just as requirement of webalizer). So I'm thinking about change (after freeze): diff --git a/roles/base/files/common-scripts/cond

Ansible question

2015-01-28 Thread Miroslav Suchý
I have this ansible snippet: - name: Create users keystone_user: login_user="admin" login_password="{{ ADMIN_PASS }}" login_tenant_name="admin" user="{{ item.name }}" email="{{ item.email }}" tenant="{{ item.tenant }}" password="{{ item.password }}" state=

Re: Can not use mirrorlist with RHEL $releasever (bz#1175566)

2015-01-28 Thread Miroslav Suchý
On 01/08/2015 11:13 PM, Ian Wienand wrote: > Hi, > > I'd like to try and find the/a person who could help out with [1]. > > EPEL version updates are a fairly constant annoyance that causes > issues with CI systems in upstream openstack when the version updates. > > As described in the bug, I'd r

Re: Request to become apprentice

2015-01-30 Thread Miroslav Suchý
On 01/29/2015 10:50 PM, Mikolaj Izdebski wrote: > What are next steps I need to follow to become apprentice? As nirik stated, apprentice wiki page is good start. I would point out https://infrastructure.fedoraproject.org/infra/docs/sshaccess.txt as good starting point Followed by: https://inf

Re: Ansible question

2015-01-30 Thread Miroslav Suchý
On 01/29/2015 05:30 PM, Toshio Kuratomi wrote: > no_log: True That did the job. Thanks! -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing list infrastructure@lists.fedora

How to open port?

2015-02-02 Thread Miroslav Suchý
How do we open ports in ansible today? I want to open port 5672 for 172.24.0.10/24. Currently it is open only to: [root@fed-cloud09 ~]# iptables-save |grep 5672 -A INPUT -s 209.132.184.9/32 -p tcp -m multiport --dports 5671,5672 -m comment --comment "001 amqp incoming amqp_209.132.184.9" -j ACCE

Re: How to open port?

2015-02-02 Thread Miroslav Suchý
On 02/02/2015 04:10 PM, Kevin Fenzi wrote: > Just copy paste the iptables section from base role and adjust the path > to the iptables templates KISS - I will try this approach. Thanks -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys

Re: route between fed-cloud10 and fed-cloud09

2015-02-04 Thread Miroslav Suchý
On 02/04/2015 02:32 PM, Kevin Fenzi wrote: > On Tue, 03 Feb 2015 17:54:27 +0100 > Miroslav Suchy wrote: > >> [root@fed-cloud10 etc(keystone_admin)]# telnet 209.132.184.9 443 >> Trying 209.132.184.9... >> telnet: connect to address 209.132.184.9: No route to host >> >> I am able to connect using 1

Proper SSL cert for fed-cloud09?

2015-02-04 Thread Miroslav Suchý
When I do: [root@fed-cloud09 ~(keystone_admin)]# cinder type-list ERROR: Unable to establish connection: [Errno 1] _ssl.c:504: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Which just transit to: [root@fed-cloud09 ~(keystone_admin)]# curl -i https://fed-cloud09

Re: Proper SSL cert for fed-cloud09?

2015-02-05 Thread Miroslav Suchý
On 02/05/2015 01:13 AM, Kevin Fenzi wrote: > Could we instead call it 'openstack.cloud.fedoraproject.org' or > 'controller.cloud.fedoraproject.org' or something? Not sure if that > needs us to rename/reinstall the node, or can just be done in the > cert... It can be just cname + name in cert. Rei

Route to Dell EquaLogic

2015-02-05 Thread Miroslav Suchý
[root@fed-cloud09 ~(keystone_admin)]# ssh grpadmin@172.24.0.100 ssh: connect to host 172.24.0.100 port 22: No route to host Nirik can this be result of your (?) change in routes that [root@fed-cloud09 ~(keystone_admin)]# route -n Kernel IP routing table Destination Gateway Genmask

Re: Route to Dell EquaLogic

2015-02-05 Thread Miroslav Suchý
On 02/05/2015 11:40 AM, Miroslav Suchý wrote: > 172.24.0.0 0.0.0.0 255.255.255.0 U 0 00 br-tun Hmm, I rebooted the machine and this ^^^ line disappeared from route and 172.24.0.100 is now reachable. I wish I knew what is going on. -- Miroslav Suchy, RHCE, RH

New OpenStack instance - status

2015-02-20 Thread Miroslav Suchý
Since I'm leaving for one week vacation, I think I may write down current status of our new OpenStack instance and write down TODO list. Just in case someone is desperate enough to do some fixes. I updated docs.git/cloud.txt - mainly which playbooks we use right now and where to write down IP, w

Re: New OpenStack instance - status

2015-03-02 Thread Miroslav Suchý
On 03/02/2015 04:00 AM, Kevin Fenzi wrote: > I guess it it only rebooted after > packstack first runs it could work. That is what I meant. Only needed once, but still nice to have it automated. >> > * routing between compute nodes and controller using public IP does >> > not work. Not fatal right

Re: OpenStack Icehouse + Fedora

2015-03-02 Thread Miroslav Suchý
On 03/02/2015 10:06 AM, Kashyap Chamarthy wrote: > https://blog-rcritten.rhcloud.com/?p=5 -- Configure Keystone to use > SSL in OpenStack This great reading. I switched keystone to SSL and it works. I will try to switch rest of the services. -- Miroslav Suchy, RHCE, RHCDS Red Hat, Senior

Re: New OpenStack instance - status

2015-03-06 Thread Miroslav Suchý
All services are using SSL but novncproxy, which does not worked for me and according some random notes on internet does not work over SSL due some bugs. But novncproxy does not work for me even over plain http. And I do not know why. If somebody else can check it, it would be great. Strange thin

Re: New OpenStack instance - status

2015-03-06 Thread Miroslav Suchý
On 03/06/2015 04:02 PM, Miroslav Suchý wrote: > I tried to automatize adding of SSH keys using this: > > TASK: [shell source /root/keystonerc_admin && F=$(mktemp) && {{ lookup('pipe', > '/srv/web/infra/ansible/scripts/auth-keys-from-fas msuchy'

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/07/2015 07:29 PM, Kevin Fenzi wrote: > * I see that the tenants have the same internal 172.16.0.0 net right > now, can we make sure we seperate them from each other? ie, I don't > want a infrastructure instance being able to talk to a copr builder > if we can avoid it. Are you sure? F

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/07/2015 06:59 PM, Kevin Fenzi wrote: > All thats set and I can see console in the web dash again just fine for > any of the instances I tried, and they are all https using only. Works for me too. Nice. Thanks. >> > I tried to automatize adding of SSH keys using this: > I wonder if we shoul

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/07/2015 06:59 PM, Kevin Fenzi wrote: > * Can we adjust the default tennat quotas in the playbooks? They seem a > bit low to me given the amount of resources we have. I put (and tested) the quota for Copr (it is on bottom of playbook). Can you please write quotas for other tenants (or you

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/09/2015 01:00 PM, Kevin Fenzi wrote: > nova commands worked fine from here, but I didn't really try and do > anything fancy. We could see if the euca stuff will just keep working > for us for now. It works fine. It is just that if you miss some functionality (and I miss a lot) and file RFE

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/07/2015 06:59 PM, Kevin Fenzi wrote: > * We will need to adapt to not giving every instance a floating ip. For > copr, I think this would be fine, as you don't care that they have *nod* I was not sure how VM behave when does not have public IP so I tested it. It is basicaly behind NAT and

Re: New OpenStack instance - status

2015-03-09 Thread Miroslav Suchý
On 03/09/2015 10:29 AM, Miroslav Suchý wrote: > On 03/07/2015 07:29 PM, Kevin Fenzi wrote: >> > * I see that the tenants have the same internal 172.16.0.0 net right >> > now, can we make sure we seperate them from each other? ie, I don't >> > want a infrast

users belonging to tenant in FedoraCloud

2015-03-12 Thread Miroslav Suchý
In new OpenStack instances users belong to this tenants: - { name: kevin, email: 'ke...@fedoraproject.org', tenant: infrastructure, password: "{{kevin_password}}" } - { name: laxathom, email: 'laxat...@fedoraproject.org', tenant: infrastructure, password: "{{laxathom_password}}" }

Re: users belonging to tenant in FedoraCloud

2015-03-13 Thread Miroslav Suchý
On 03/12/2015 04:26 PM, Kevin Fenzi wrote: > I think it might be good to have you, me and patrick at least in all > teanants as we often need to look at and diagnose issues other people > have. Of course we could just login as admin, but perhaps we should > discourage that... Done in commit: * e8

SSL certificate for new FedoraCloud for user's command line tools

2015-03-13 Thread Miroslav Suchý
The new FedoraCloud (FC) is still not in final state, but if you work with it. Or you will work with it in future - here is quick HOWTO regarding certificates. The cerficate can be found at: https://fed-cloud09.cloud.fedoraproject.org/pub/fed-cloud09.pem Your RC file is at: https://fed-cloud09

Routing between tenants networks

2015-03-17 Thread Miroslav Suchý
Quick note for those interested in new OpenStack instance: Routing between two tenants is apparently not possible. Or to be precise I did not discovered how to do that (and even Larsks did not know). However ... we can mark same network as "shared". This means that those networks are visible f

Re: users belonging to tenant in FedoraCloud

2015-03-25 Thread Miroslav Suchý
On 03/25/2015 02:40 AM, Kevin Fenzi wrote: >> > The login here doesn't actually work for me in the new cloud; is it >> > expected to, or were new passwords allocated? > These were new randomly generated passwords. I can send you that one, > but... see below. This is kind of tricky. I have to firs

Re: users belonging to tenant in FedoraCloud

2015-03-25 Thread Miroslav Suchý
On 03/24/2015 11:29 PM, Colin Walters wrote: > - { name: cockpit, email: 'walt...@redhat.com', tenant: scratch, > password: "{{cockpit_password}}" } Colin, to which FAS account this maps? I need to know which SSH key I should upload for this account. Or you can even provide me different SS

Filters in our ansible.git

2015-03-25 Thread Miroslav Suchý
I created ./filter_plugins/openstack.py in our ansible.git to easy writing host_vars in our new cloud. So instead of ids you can write names of networks, images... So far I tested it on separate machine and it works, when I have this directory in ./ and I run ansible playbook in that directory.

Re: crowdsourcing an interview on git

2015-04-01 Thread Miroslav Suchý
On 03/31/2015 10:48 PM, Matthew Miller wrote: > * What is your favorite pro tip for using git? Sometimes git pull takes long time. Sometimes git start garbage collecting in situation, where I was under time pressure. After this line in crontab I have no such problems any more: 40 3 * * * locate

UserKnownHostsFile for copr-*-dev machines

2015-04-02 Thread Miroslav Suchý
Valentin and me are now playing quite a lot with copr-*-dev as part of new OpenStack testing and I always have to ask somebody to wipe the entry from known_hosts on lockbox otherwise rbac will refuse to connect. Can I suggest to put into ssh_config on lockbox: Host copr-be-dev.cloud.fedoraproje

Re: UserKnownHostsFile for copr-*-dev machines

2015-04-03 Thread Miroslav Suchý
On 04/02/2015 06:38 PM, Kevin Fenzi wrote: > The new ansible 1.9 version has a known_hosts module. ;) > > So, stick at the top of your playbook: > > - name: clean out old known_hosts > local_action: known_hosts path=/root/.ssh/known_hosts > name=copr-be-dev.cloud.fedoraproject.org state=abse

Re: Fedora Cloud questions and proposal

2015-04-13 Thread Miroslav Suchý
On 04/10/2015 06:04 PM, Kevin Fenzi wrote: > I think it might be a good idea to have some swift space setup, but I > am not sure what use cases we fully have for it, so I would say it > should be somewhat small. 100GB or something? > This would also be backed by the equalogics? Or would it be > di

Upstream for dist-git [RFC]

2015-04-16 Thread Miroslav Suchý
Hi, Adam Šamalík took dist-git files from fedora-infra ansible.git. He separated what belongs to dist-git itself and what is Fedora specific and with cooperation of Dan Mach and Palo Babinčák he created upstream for dist-git: https://github.com/release-engineering/dist-git This is first attem

Re: Fedora Cloud questions and proposal

2015-04-16 Thread Miroslav Suchý
On 04/13/2015 03:54 PM, Kevin Fenzi wrote: > Yeah. The one place I thought might be nice was if we wanted to reboot > a compute node to update it, but then I got to thinking, why shouldn't > we also just reboot the instances too and update them as well? ;) I just tried - when I reboot Compute Nod

Re: Plan for tomorrow's Fedora Infrastructure meeting (2015-04-23)

2015-04-23 Thread Miroslav Suchý
On 04/22/2015 11:16 PM, Kevin Fenzi wrote: > #info Another re-install cycle of new cloud, hopefully last one - msuchy, > smooge I will not make it to the meeting, so just quit update: I was working on Mock this week to get it in shape before GA. So I put new cloud on back burner for moment, I wi

New Fedora Cloud

2015-04-29 Thread Miroslav Suchý
Long story short: I declare new Fedora Cloud as final. There is still lot of work, but that will be always the case. Please use it (but hold on production things for few days in case there will be some problem). I plan to announce Fedora classroom date for those interrested in setup of that O

Re: Fedora Cloud classroom

2015-04-30 Thread Miroslav Suchý
On 04/30/2015 01:22 AM, Kevin Fenzi wrote: > How about "Fedora Infrastructure Private Servers" and we can just call > it FIPS. ;) Or Fedora Private Cloud - FPC in short :) /me hides too -- Miroslav Suchy, RHCA Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys

Re: New Fedora Cloud

2015-04-30 Thread Miroslav Suchý
On 04/30/2015 02:54 AM, Stephen John Smoogen wrote: > So the playbook fails currently because the interfaces ifcfg-br-ex is setup > and restarted before the software for the > type of bridge is installed. I am not sure if you want to fix that and have > me rebuild one more time? Or just go with >

Re: Fedora Cloud classroom

2015-05-11 Thread Miroslav Suchý
The log of this classroom: http://meetbot.fedoraproject.org/fedora-classroom/2015-05-11/fedora-classroom.2015-05-11-15.02.log.html -- Miroslav Suchy, RHCA Red Hat, Senior Software Engineer, #brno, #devexp, #fedora-buildsys ___ infrastructure mailing lis

Re: Dist Git for Copr

2015-05-15 Thread Miroslav Suchý
Dne 6.5.2015 v 21:08 Kevin Fenzi napsal(a): > How about a short term and a longer term plan? > > Short term: have copr download and store the src.rpm from build urls. > This would at least make things reproducable and at least someone could > download the src.rpm and send a patch. Along with this

Fed-clou02 migration

2015-05-20 Thread Miroslav Suchý
Hi, as you know we have new Fedora Cloud instance. And we still have the *old* Fedora Cloud instance. I hereby declare fed-cloud02 a.k.a old Fedora Cloud as deprecated. There is currently 67 machines in running state. And bunch of VM in shutdown state. I would kindly ask all owners to: * not

Re: DB performance of frequently updated table

2015-07-22 Thread Miroslav Suchý
Dne 2.7.2015 v 10:49 Michael Šimáček napsal(a): > We've been facing some DB performance issues in Koschei production machine > recently. Our central table (package) has > only ~1 rows but sequential scan of the table was taking unreasonably > long (~4s). Other tables that are orders of > magn

Re: Flock discussions

2015-08-19 Thread Miroslav Suchý
Dne 18.8.2015 v 17:20 Kevin Fenzi napsal(a): > - Install two old nodes with openstack Icehouse > - Upgrade the test instance to openstack Kilo(?) > - Upgrade main cluster to Kilo Really? This is not officially supported. I propose to have two nodes as playground. To try Kilo ins

Fwd: [Bug 1268192] New: Rsync fails with "Corrupted MAC on input. Disconnecting: Packet corrupt"

2015-10-02 Thread Miroslav Suchý
Hi, this is an issue in Copr: https://bugzilla.redhat.com/show_bug.cgi?id=1268192 this happen rarely, but this is not first report. So I should address it somehow. Google say: http://serverfault.com/questions/338439/ssh-sessions-terminate-abruptly-with-message-corrupted-mac-on-input-disconne

Re: [Bug 1268192] New: Rsync fails with "Corrupted MAC on input. Disconnecting: Packet corrupt"

2015-10-05 Thread Miroslav Suchý
Dne 3.10.2015 v 19:02 Kevin Fenzi napsal(a): > On Fri, 2 Oct 2015 09:32:08 -0600 > Stephen John Smoogen wrote: >> I would turn it off on Copr machiens only. If other systems see >> problems it can be hard to realize "oh that is happening on all boxes" >> late in the game. If we know we have isolat

  1   2   3   >