Page MenuHomeDevCentral
Feed Advanced Search

Sat, Oct 26

dereckson closed T2046: Deploy Medusa on devserver role as Resolved by committing rOPSa3f1d0f0b601: Install vault-medusa and roll on devserver role.
Sat, Oct 26, 15:27 · upstream, freebsd-port-wanted, Vault, Servers

Oct 12 2024

dereckson moved T2046: Deploy Medusa on devserver role from New port to Port published on the freebsd-port-wanted board.
Oct 12 2024, 09:14 · upstream, freebsd-port-wanted, Vault, Servers
dereckson added a revision to T2046: Deploy Medusa on devserver role: D3508: Publish alkane, roll, phpfpm_exporter, medusa and salt-tower.
Oct 12 2024, 07:49 · upstream, freebsd-port-wanted, Vault, Servers

Oct 8 2024

dereckson added a revision to T2046: Deploy Medusa on devserver role: D3499: Install vault-medusa and roll on devserver role.
Oct 8 2024, 00:11 · upstream, freebsd-port-wanted, Vault, Servers

Oct 7 2024

dereckson added a subtask for T2046: Deploy Medusa on devserver role: T1850: Move packages from Ysul to WindRiver.
Oct 7 2024, 20:27 · upstream, freebsd-port-wanted, Vault, Servers

Oct 5 2024

dereckson moved T2046: Deploy Medusa on devserver role from Backlog to Pending review on the Servers board.
Oct 5 2024, 12:22 · upstream, freebsd-port-wanted, Vault, Servers
dereckson moved T2046: Deploy Medusa on devserver role from Backlog to New port on the freebsd-port-wanted board.
Oct 5 2024, 12:21 · upstream, freebsd-port-wanted, Vault, Servers
dereckson moved T2046: Deploy Medusa on devserver role from Backlog to To check again on the upstream board.
Oct 5 2024, 12:21 · upstream, freebsd-port-wanted, Vault, Servers
dereckson triaged T2046: Deploy Medusa on devserver role as Normal priority.
Oct 5 2024, 12:21 · upstream, freebsd-port-wanted, Vault, Servers

Oct 3 2024

dereckson added a comment to T2040: Supersede Vault by OpenBao.

Yes, it's a fork from Vault 1.14 so we've all the features of token generation. back to the shorter s. tokens).

Oct 3 2024, 17:26 · security, Servers, Vault
DorianWinty added a comment to T2040: Supersede Vault by OpenBao.
  • about the UI it could be usefull managing secrets more easyly
Oct 3 2024, 17:23 · security, Servers, Vault
dereckson moved T2040: Supersede Vault by OpenBao from Backlog to Analysis / under discussion on the Servers board.
Oct 3 2024, 15:21 · security, Servers, Vault
dereckson triaged T2040: Supersede Vault by OpenBao as Normal priority.
Oct 3 2024, 15:21 · security, Servers, Vault

Sep 12 2024

dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D3441: Prune Zemke-Rhyne.
Sep 12 2024, 17:02 · User-Dereckson, Vault, Nasqueron Operations Squad, security

Aug 20 2024

dereckson closed T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration as Resolved by committing rOPSe0cbc48f6a3a: Resolve conflict for Salt Vault configuration.
Aug 20 2024, 19:22 · Vault, Servers, Salt, Eglide

Aug 4 2024

dereckson moved T1983: Enable telemetry on Vault from Backlog to Prometheus on the Monitoring and reporting board.
Aug 4 2024, 17:05 · Vault, Monitoring and reporting
dereckson merged task T1976: Update Salt to 3007 on FreeBSD servers into T1993: Salt migration to 3007, 3008 and extensions.
Aug 4 2024, 09:58 · Salt, Vault
dereckson moved T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration from Working on to Pending review on the Servers board.
Aug 4 2024, 09:53 · Vault, Servers, Salt, Eglide
dereckson added a revision to T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration: D3401: Resolve conflict for Salt Vault configuration.
Aug 4 2024, 09:50 · Vault, Servers, Salt, Eglide
dereckson moved T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration from Backlog to Working on on the Servers board.
Aug 4 2024, 09:29 · Vault, Servers, Salt, Eglide
dereckson claimed T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration.
Aug 4 2024, 09:29 · Vault, Servers, Salt, Eglide

Aug 3 2024

dereckson moved T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration from Backlog to Bug and issues on the Salt board.
Aug 3 2024, 16:26 · Vault, Servers, Salt, Eglide
dereckson moved T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration from Backlog to Server config on the Eglide board.
Aug 3 2024, 16:26 · Vault, Servers, Salt, Eglide
dereckson added projects to T1998: Resolve conflict between core and shellserver roles for Vault in Salt configuration: Servers, Vault.
Aug 3 2024, 16:24 · Vault, Servers, Salt, Eglide

Jul 24 2024

dereckson updated the task description for T1983: Enable telemetry on Vault.
Jul 24 2024, 00:00 · Vault, Monitoring and reporting

Jul 23 2024

dereckson triaged T1983: Enable telemetry on Vault as Low priority.
Jul 23 2024, 23:57 · Vault, Monitoring and reporting

Jul 7 2024

dereckson added a revision to T1975: Allow ops to login to Vault: D3357: Allow to issue Vault token with admin policy.
Jul 7 2024, 14:23 · Salt, Vault
dereckson triaged T1976: Update Salt to 3007 on FreeBSD servers as Normal priority.
Jul 7 2024, 13:29 · Salt, Vault
dereckson added a revision to T1975: Allow ops to login to Vault: D3355: Allow Salt policy to create admin-level tokens.
Jul 7 2024, 13:19 · Salt, Vault
dereckson moved T1975: Allow ops to login to Vault from Backlog to Services to add on the Salt board.
Jul 7 2024, 13:17 · Salt, Vault
dereckson triaged T1975: Allow ops to login to Vault as High priority.
Jul 7 2024, 13:17 · Salt, Vault

Jun 2 2024

dereckson added a comment to P352 Renew Vault certificates automation - renew.py.
  • pprint isn't used anymore
  • need to run black
  • description needs to be updated
  • TTL can be much shorter if we automate this procedure
Jun 2 2024, 22:43 · Servers, Vault
dereckson added a comment to P351 Renew Vault certificates automation - renew.sh.

sudo kill -1 $(cat /var/run/vault.pid)

Error management should be done to check if that pids exist or return an error code.

Jun 2 2024, 22:40 · Servers, Vault
dereckson added a comment to P351 Renew Vault certificates automation - renew.sh.

Needs hvac and pyyaml as packages to be installed on the server, Complector doesn't currently have hvac, only pyyaml.

Jun 2 2024, 22:38 · Servers, Vault
dereckson triaged T1966: Automate certificates renewal for Vault as Normal priority.
Jun 2 2024, 22:37 · Vault
dereckson created P352 Renew Vault certificates automation - renew.py.
Jun 2 2024, 22:35 · Servers, Vault
dereckson created P351 Renew Vault certificates automation - renew.sh.
Jun 2 2024, 22:34 · Servers, Vault

Jan 28 2024

dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D3302: Migrate former Zemke-Rhyne secrets from a.b.c to a/b/c path.
Jan 28 2024, 19:11 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a comment to T930: Secrets to migrate from DevCentral to Vault.

Secrets have been migrated from dot notation to slash notation.

Jan 28 2024, 19:10 · User-Dereckson, Vault, Nasqueron Operations Squad, security

May 29 2023

dereckson closed T1890: Deploy Vault on Eglide as Resolved.
May 29 2023, 17:18 · Odderon, IRC, Vault, security, Eglide
dereckson added a revision to T1890: Deploy Vault on Eglide: D3154: Help to configure Salt for Vault access on shellserver.
May 29 2023, 17:14 · Odderon, IRC, Vault, security, Eglide
dereckson added a revision to T1890: Deploy Vault on Eglide: D3153: Help operations to unseal Eglide Vault.
May 29 2023, 14:43 · Odderon, IRC, Vault, security, Eglide
dereckson added a revision to T1890: Deploy Vault on Eglide: D3152: Configure Vault on shellserver.
May 29 2023, 10:56 · Odderon, IRC, Vault, security, Eglide
dereckson added a comment to T1890: Deploy Vault on Eglide.

Server log

May 29 2023, 10:54 · Odderon, IRC, Vault, security, Eglide
dereckson added a parent task for T1890: Deploy Vault on Eglide: T1739: Add SASL capability to Darkbot.
May 29 2023, 02:29 · Odderon, IRC, Vault, security, Eglide
dereckson added a revision to T1890: Deploy Vault on Eglide: D3151: Install Vault on shellserver.
May 29 2023, 02:28 · Odderon, IRC, Vault, security, Eglide
dereckson added a parent task for T1890: Deploy Vault on Eglide: T1721: Move IRC bots from Freenode to Libera.
May 29 2023, 00:06 · Odderon, IRC, Vault, security, Eglide
dereckson moved T1890: Deploy Vault on Eglide from Backlog to Next to deploy on the Odderon board.
May 29 2023, 00:06 · Odderon, IRC, Vault, security, Eglide
dereckson triaged T1890: Deploy Vault on Eglide as Normal priority.
May 29 2023, 00:01 · Odderon, IRC, Vault, security, Eglide

May 18 2023

dereckson closed T928: Deploy Vault to store credentials as Resolved.

DRP merged, so we're good :)

May 18 2023, 11:45 · User-Sandlayth, Vault
dereckson closed T1702: Deploy Complector aka la source, a subtask of T923: Switch Vault to restricted network, as Resolved.
May 18 2023, 11:44 · Vault, Nasqueron Docker deployment squad
dereckson closed T1702: Deploy Complector aka la source as Resolved.
May 18 2023, 11:44 · Salt, Vault, security, Servers
dereckson closed T1559: Figure how to deploy automatically /var/51-wwwroot credentials as Resolved by committing rOPS4295a983aa53: Clone wwwroot51 repositories wih proper credentials.
May 18 2023, 09:08 · Operations sprints (Consolidate them all), Vault, Servers

May 13 2023

dereckson added a revision to T1559: Figure how to deploy automatically /var/51-wwwroot credentials: D3094: Clone wwwroot51 repositories wih proper credentials.
May 13 2023, 23:57 · Operations sprints (Consolidate them all), Vault, Servers
dereckson moved T1559: Figure how to deploy automatically /var/51-wwwroot credentials from Backlog to Working on on the Operations sprints (Consolidate them all) board.
May 13 2023, 20:14 · Operations sprints (Consolidate them all), Vault, Servers
dereckson moved T1559: Figure how to deploy automatically /var/51-wwwroot credentials from Backlog to Working on on the Servers board.

Okay, let's do an easy thing to solve that for DevCentral repositories:

May 13 2023, 20:13 · Operations sprints (Consolidate them all), Vault, Servers

Apr 16 2023

dereckson added a comment to T1559: Figure how to deploy automatically /var/51-wwwroot credentials.

The role webserver-alkane instead of the role webserver-legacy can be deployed to WindRiver.

Apr 16 2023, 20:14 · Operations sprints (Consolidate them all), Vault, Servers

Mar 15 2023

dereckson triaged T1797: Accept payloads from Vault as Normal priority.
Mar 15 2023, 20:54 · Vault, Notifications center

Mar 7 2023

dereckson added a comment to T1559: Figure how to deploy automatically /var/51-wwwroot credentials.

Documentation says Zemke-Rhyme Phabricator account should be used.

Mar 7 2023, 20:27 · Operations sprints (Consolidate them all), Vault, Servers
dereckson closed T1425: Provision secrets through Salt as Resolved.

All secrets are now stored in Vault and provisioned through Salt, with policies restricting access to secrets by node.

Mar 7 2023, 20:26 · security, Nasqueron Operations Squad, Vault, Salt
dereckson closed T929: Determine a policy for vault master key, a subtask of T928: Deploy Vault to store credentials, as Wontfix.
Mar 7 2023, 20:24 · User-Sandlayth, Vault
dereckson closed T929: Determine a policy for vault master key as Wontfix.

The point is currently moot as we don't have an operations SIG large enough to allow key shares.

Mar 7 2023, 20:24 · Vault
dereckson lowered the priority of T928: Deploy Vault to store credentials from High to Normal.

Current status: ZR has been decom, we now deploy credentials through from Vault.

Mar 7 2023, 20:23 · User-Sandlayth, Vault
dereckson closed T930: Secrets to migrate from DevCentral to Vault, a subtask of T928: Deploy Vault to store credentials, as Resolved.
Mar 7 2023, 20:19 · User-Sandlayth, Vault
dereckson closed T930: Secrets to migrate from DevCentral to Vault as Resolved.
Mar 7 2023, 20:19 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a comment to T930: Secrets to migrate from DevCentral to Vault.

And with the Zemke-Rhyne decom, we're done.

Mar 7 2023, 20:19 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:14 · User-Dereckson, Vault, Nasqueron Operations Squad, security

Mar 3 2023

dereckson closed T1594: Acquisitariat and Etherpad issue as Resolved.

Those issues are resolved now we use Vault to provision passwords.

Mar 3 2023, 20:15 · Operations sprints (Consolidate them all), Vault, security, Nasqueron Docker deployment squad

Feb 24 2023

dereckson closed T1743: Publish Vault certificate information as Resolved by committing rOPSfc39dddc37d9: Publish Vault certificate information.
Feb 24 2023, 20:14 · Servers, Salt, Vault
dereckson added a revision to T1743: Publish Vault certificate information: D2812: Publish Vault certificate information.
Feb 24 2023, 20:13 · Servers, Salt, Vault
dereckson claimed T1743: Publish Vault certificate information.
Feb 24 2023, 20:09 · Servers, Salt, Vault

Feb 16 2023

dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D2800: Switch credentials from Zemke-Rhyme to Vault.
Feb 16 2023, 21:27 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a revision to T1425: Provision secrets through Salt: D2800: Switch credentials from Zemke-Rhyme to Vault.
Feb 16 2023, 21:27 · security, Nasqueron Operations Squad, Vault, Salt

Feb 9 2023

dereckson closed T1733: Store credentials in Vault as Resolved.
Feb 9 2023, 22:25 · security, Vault, Dæghrefn

Nov 13 2022

dereckson created T1743: Publish Vault certificate information.
Nov 13 2022, 11:54 · Servers, Salt, Vault

May 30 2022

dereckson triaged T1736: Audit Vault as Normal priority.
May 30 2022, 21:50 · Vault
dereckson closed T923: Switch Vault to restricted network, a subtask of T928: Deploy Vault to store credentials, as Resolved.
May 30 2022, 21:49 · User-Sandlayth, Vault
dereckson closed T923: Switch Vault to restricted network as Resolved.
May 30 2022, 21:49 · Vault, Nasqueron Docker deployment squad

May 12 2022

dereckson added a revision to T1733: Store credentials in Vault: D2687: Configure ViperServ eggdrops to use Vault.
May 12 2022, 22:54 · security, Vault, Dæghrefn
dereckson added a revision to T1733: Store credentials in Vault: D2686: Fetch credentials from Vault.
May 12 2022, 22:22 · security, Vault, Dæghrefn
dereckson triaged T1733: Store credentials in Vault as Normal priority.
May 12 2022, 22:22 · security, Vault, Dæghrefn

Apr 15 2022

dereckson closed T1619: Connect all baremetal servers to Drake network, a subtask of T1702: Deploy Complector aka la source, as Resolved.
Apr 15 2022, 19:20 · Salt, Vault, security, Servers
dereckson added a comment to T1702: Deploy Complector aka la source.

Vault is live and Salt deployments were successful to cloudhugger dwellers windriver ysul (and Complector itself).

Apr 15 2022, 19:19 · Salt, Vault, security, Servers
dereckson added a revision to T1702: Deploy Complector aka la source: D2672: Prune salt-primary role on Ysul and WindRiver.
Apr 15 2022, 19:16 · Salt, Vault, security, Servers
dereckson added a revision to T1425: Provision secrets through Salt: D2671: Avoid a server to keep access to stale Vault policies.
Apr 15 2022, 19:11 · security, Nasqueron Operations Squad, Vault, Salt
dereckson added a revision to T1425: Provision secrets through Salt: D2669: Avoid to share credentials between dev and prod Docker engines.
Apr 15 2022, 17:53 · security, Nasqueron Operations Squad, Vault, Salt

Apr 3 2022

dereckson updated the task description for T930: Secrets to migrate from DevCentral to Vault.
Apr 3 2022, 19:49 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a revision to T1425: Provision secrets through Salt: D2649: Provide compatibility methods with Zemke-Rhyme for Vault.
Apr 3 2022, 18:59 · security, Nasqueron Operations Squad, Vault, Salt

Mar 29 2022

dereckson lowered the priority of T929: Determine a policy for vault master key from High to Normal.
Mar 29 2022, 22:56 · Vault
dereckson added a revision to T923: Switch Vault to restricted network: D2615: Deploy Vault and Salt master on Complector.
Mar 29 2022, 22:55 · Vault, Nasqueron Docker deployment squad
dereckson added a revision to T928: Deploy Vault to store credentials: D2624: Deploy Vault.
Mar 29 2022, 22:54 · User-Sandlayth, Vault
dereckson added a revision to T923: Switch Vault to restricted network: D2624: Deploy Vault.
Mar 29 2022, 22:54 · Vault, Nasqueron Docker deployment squad
dereckson added a revision to T1702: Deploy Complector aka la source: D2624: Deploy Vault.
Mar 29 2022, 22:54 · Salt, Vault, security, Servers
dereckson added a revision to T923: Switch Vault to restricted network: D2646: Deploy public and Nasqueron certificates.
Mar 29 2022, 22:50 · Vault, Nasqueron Docker deployment squad
dereckson added a revision to T928: Deploy Vault to store credentials: D2646: Deploy public and Nasqueron certificates.
Mar 29 2022, 22:50 · User-Sandlayth, Vault

Mar 26 2022

dereckson added a revision to T1702: Deploy Complector aka la source: D2639: Allow to recreate Vault configuration as DRP plan B.
Mar 26 2022, 15:19 · Salt, Vault, security, Servers
dereckson added a revision to T928: Deploy Vault to store credentials: D2638: Deploy policies for Vault.
Mar 26 2022, 15:09 · User-Sandlayth, Vault
dereckson added a revision to T1425: Provision secrets through Salt: D2638: Deploy policies for Vault.
Mar 26 2022, 15:09 · security, Nasqueron Operations Squad, Vault, Salt

Mar 24 2022

dereckson moved T930: Secrets to migrate from DevCentral to Vault from Backlog to In progress on the User-Dereckson board.
Mar 24 2022, 00:50 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a project to T930: Secrets to migrate from DevCentral to Vault: User-Dereckson.
Mar 24 2022, 00:49 · User-Dereckson, Vault, Nasqueron Operations Squad, security