Equatower
$ cat /sys/kernel/mm/transparent_hugepage/enabled always madvise [never]
$ cat /sys/kernel/mm/transparent_hugepage/enabled always madvise [never]
Correct profile name
$ salt equatower state.sls roles/paas-docker/containers/postgresql equatower: ---------- ID: /srv/sentry_db/postgresql Function: file.directory Result: True Comment: Directory /srv/sentry_db/postgresql updated Started: 17:35:40.024081 Duration: 49.16 ms Changes: ---------- /srv/sentry_db/postgresql: New Dir ---------- ID: selinux_context_sentry_db_postgresql_data Function: selinux.fcontext_policy_present Name: /srv/sentry_db/postgresql Result: True Comment: Started: 17:35:40.076026 Duration: 7766.184 ms Changes: ---------- new: ---------- /srv/sentry_db/postgresql: ---------- filetype: all files sel_type: container_file_t old: ---------- ---------- ID: selinux_context_sentry_db_postgresql_data_applied Function: selinux.fcontext_policy_applied Name: /srv/sentry_db/postgresql Result: True Comment: Started: 17:35:47.843316 Duration: 60.945 ms Changes: ---------- /srv/sentry_db/postgresql: ---------- new: ---------- sel_type: container_file_t old: ---------- sel_type: unlabeled_t ---------- ID: sentry_db Function: docker_container.running Result: True Comment: Created container 'sentry_db' Started: 17:35:47.942555 Duration: 8136.003 ms Changes: ---------- container_id: ---------- added: 9514e74ecec76fcfed55a89b2297afe42a73ab732bec794bd9c8221d4d91b4b8 state: ---------- new: running old: None
Add missing image value. sysctl vm.overcommit_memory set at 1 on Docker Engine per Redis requirements
Don't forget Let's encrypt in TLS block
Already done as a part of D1970
New containers roadmap is to wait Fedora CoreOS or a RHEL downstream before to provision and keep CentOS meanwhile.
Use require to set order, remerge zfs blocks (require can solve the state order, previous require block was an onchanges actually)
zfs allow should occur when user is created
tank → zfs_tank
Plan is to move nasquenautes to 3005 as not currently deployed (mediawiki is)