Page MenuHomeDevCentral
Feed All Stories

Mar 8 2023

dereckson removed a revision from T1791: Refresh Sentry installation: D2860: Deploy memcached container for Sentry.
Mar 8 2023, 00:54 · Monitoring and reporting
dereckson committed rOPSec1f0fce0832: Deploy memcached container for Sentry (authored by dereckson).
Deploy memcached container for Sentry
Mar 8 2023, 00:54
dereckson closed D2859: Deploy memcached container for Sentry.
Mar 8 2023, 00:54
dereckson accepted D2859: Deploy memcached container for Sentry.
Mar 8 2023, 00:53
dereckson added a comment to D2859: Deploy memcached container for Sentry.

docker inspect <container> allows to check the health check log, and the interval, 30000000000 matches correctly 30s

Mar 8 2023, 00:53
dereckson updated the diff for D2859: Deploy memcached container for Sentry.

Switch to Alpine, so we've busybox nc for the healthcheck

Mar 8 2023, 00:51
dereckson abandoned D2860: Deploy memcached container for Sentry.

Duplicate of D2859

Mar 8 2023, 00:50
dereckson requested review of D2860: Deploy memcached container for Sentry.
Mar 8 2023, 00:49
dereckson added a revision to T1791: Refresh Sentry installation: D2860: Deploy memcached container for Sentry.
Mar 8 2023, 00:49 · Monitoring and reporting
dereckson added a revision to T1791: Refresh Sentry installation: D2859: Deploy memcached container for Sentry.
Mar 8 2023, 00:31 · Monitoring and reporting
dereckson requested review of D2859: Deploy memcached container for Sentry.
Mar 8 2023, 00:31

Mar 7 2023

dereckson committed rOPS1e938695e69e: Use 172.18.3.0/24 as Docker network for Sentry containers (authored by dereckson).
Use 172.18.3.0/24 as Docker network for Sentry containers
Mar 7 2023, 22:54
dereckson closed D2858: Use 172.18.3.0/24 as Docker network for Sentry containers.
Mar 7 2023, 22:54
dereckson accepted D2858: Use 172.18.3.0/24 as Docker network for Sentry containers.
Complector
$ salt docker-002 state.apply roles/paas-docker/docker/networks
docker-002:
----------
[…]
          ID: docker_network_sentry
    Function: docker_network.present
        Name: sentry
      Result: True
     Comment: Network 'sentry' created
     Started: 22:49:11.811458
    Duration: 89.937 ms
     Changes:
              ----------
              created:
                  True
[…]
Mar 7 2023, 22:54
dereckson added a revision to T1791: Refresh Sentry installation: D2858: Use 172.18.3.0/24 as Docker network for Sentry containers.
Mar 7 2023, 22:46 · Monitoring and reporting
dereckson requested review of D2858: Use 172.18.3.0/24 as Docker network for Sentry containers.
Mar 7 2023, 22:46
dereckson closed D2857: Update Exim MTA container configuration.
Mar 7 2023, 22:11
dereckson committed rOPSb104a9d10f59: Update Exim MTA container configuration (authored by dereckson).
Update Exim MTA container configuration
Mar 7 2023, 22:11
dereckson updated the diff for D2857: Update Exim MTA container configuration.

Fix typo

Mar 7 2023, 22:11
dereckson accepted D2857: Update Exim MTA container configuration.
$ ssh -t docker-002 deploy-container exim
local:
----------
          ID: /srv/exim/sentry_smtp
    Function: file.directory
      Result: True
     Comment: The directory /srv/exim/sentry_smtp is in the correct state
     Started: 22:09:41.165494
    Duration: 5.888 ms
     Changes:
----------
          ID: /srv/exim/sentry_smtp/spool
    Function: file.directory
      Result: True
     Comment:
     Started: 22:09:41.171564
    Duration: 1.671 ms
     Changes:
              ----------
              /srv/exim/sentry_smtp/spool:
                  ----------
                  directory:
                      new
----------
          ID: /srv/exim/sentry_smtp/log
    Function: file.directory
      Result: True
     Comment:
     Started: 22:09:41.173356
    Duration: 1.553 ms
     Changes:
              ----------
              /srv/exim/sentry_smtp/log:
                  ----------
                  directory:
                      new
----------
          ID: /srv/exim/sentry_smtp/mailname
    Function: file.managed
      Result: True
     Comment: File /srv/exim/sentry_smtp/mailname is in the correct state
     Started: 22:09:41.175029
    Duration: 29.635 ms
     Changes:
----------
          ID: selinux_context_sentry_smtp_exim_data
    Function: selinux.fcontext_policy_present
        Name: /srv/exim/sentry_smtp
      Result: True
     Comment: SELinux policy for "/srv/exim/sentry_smtp" already present with specified filetype "all files" and sel_type "container_file_t".
     Started: 22:09:41.207344
    Duration: 397.715 ms
     Changes:
----------
          ID: selinux_context_sentry_smtp_exim_data_applied
    Function: selinux.fcontext_policy_applied
        Name: /srv/exim/sentry_smtp
      Result: True
     Comment: SElinux policies are already applied for filespec "/srv/exim/sentry_smtp"
     Started: 22:09:41.605608
    Duration: 13.955 ms
     Changes:
----------
          ID: sentry_smtp
    Function: docker_container.running
      Result: True
     Comment: Replaced container 'sentry_smtp'
     Started: 22:09:41.674233
    Duration: 3848.801 ms
     Changes:
              ----------
              container:
                  ----------
                  Config:
                      ----------
                      Volumes:
                          ----------
                          new:
                              ----------
                              /etc/mailname:
                                  ----------
                              /var/log/exim4:
                                  ----------
                              /var/spool/exim4:
                                  ----------
                          old:
                              ----------
                              /var/log/exim4:
                                  ----------
                              /var/spool/exim4:
                                  ----------
                  HostConfig:
                      ----------
                      Binds:
                          ----------
                          new:
                              - /srv/exim/sentry_smtp/mailname:/etc/mailname:ro
                              - /srv/exim/sentry_smtp/spool:/var/spool/exim4
                              - /srv/exim/sentry_smtp/log:/var/log/exim4
                          old:
                              None
              container_id:
                  ----------
                  added:
                      b060c7cda35cef48e3ab804150832e10f973aa5f71a4261e37e7bdfb331159f4
                  removed:
                      - 3baa77c17efa641675a342682b6ed636b605fd888706fc23376b09fb93e27064
Mar 7 2023, 22:10
dereckson updated the summary of D2857: Update Exim MTA container configuration.
Mar 7 2023, 22:07
dereckson added a revision to T1791: Refresh Sentry installation: D2857: Update Exim MTA container configuration.
Mar 7 2023, 22:06 · Monitoring and reporting
dereckson requested review of D2857: Update Exim MTA container configuration.
Mar 7 2023, 22:06
dereckson closed D2856: Document the repository as legacy.
Mar 7 2023, 20:35
dereckson committed rZRedeb464cd715: Document the repository as legacy (authored by dereckson).
Document the repository as legacy
Mar 7 2023, 20:35
dereckson accepted D2856: Document the repository as legacy.
Mar 7 2023, 20:33
dereckson requested review of D2856: Document the repository as legacy.
Mar 7 2023, 20:33
dereckson added a comment to T1559: Figure how to deploy automatically /var/51-wwwroot credentials.

Documentation says Zemke-Rhyme Phabricator account should be used.

Mar 7 2023, 20:27 · Operations sprints (Consolidate them all), Vault, Servers
dereckson closed T1425: Provision secrets through Salt as Resolved.

All secrets are now stored in Vault and provisioned through Salt, with policies restricting access to secrets by node.

Mar 7 2023, 20:26 · security, Nasqueron Operations Squad, Vault, Salt
dereckson closed T929: Determine a policy for vault master key, a subtask of T928: Deploy Vault to store credentials, as Wontfix.
Mar 7 2023, 20:24 · User-Sandlayth, Vault
dereckson closed T929: Determine a policy for vault master key as Wontfix.

The point is currently moot as we don't have an operations SIG large enough to allow key shares.

Mar 7 2023, 20:24 · Vault
dereckson lowered the priority of T928: Deploy Vault to store credentials from High to Normal.

Current status: ZR has been decom, we now deploy credentials through from Vault.

Mar 7 2023, 20:23 · User-Sandlayth, Vault
dereckson awarded T930: Secrets to migrate from DevCentral to Vault a Evil Spooky Haunted Tree token.
Mar 7 2023, 20:19 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson closed T930: Secrets to migrate from DevCentral to Vault, a subtask of T928: Deploy Vault to store credentials, as Resolved.
Mar 7 2023, 20:19 · User-Sandlayth, Vault
dereckson closed T930: Secrets to migrate from DevCentral to Vault as Resolved.
Mar 7 2023, 20:19 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson added a comment to T930: Secrets to migrate from DevCentral to Vault.

And with the Zemke-Rhyne decom, we're done.

Mar 7 2023, 20:19 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson committed rOPSc682f42c14b6: Decommission Zemke-Rhyne (authored by dereckson).
Decommission Zemke-Rhyne
Mar 7 2023, 20:18
dereckson closed D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:18
dereckson accepted D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:18
dereckson updated the diff for D2854: Decommission Zemke-Rhyne.

Rebased.

Mar 7 2023, 20:17
dereckson closed D2855: Update UID information.
Mar 7 2023, 20:16
dereckson committed rOPS10d8c4d2037b: Update UID information (authored by dereckson).
Update UID information
Mar 7 2023, 20:16
dereckson accepted D2855: Update UID information.
Mar 7 2023, 20:16
dereckson updated the summary of D2855: Update UID information.
Mar 7 2023, 20:16
dereckson requested review of D2855: Update UID information.
Mar 7 2023, 20:16
dereckson accepted D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:15
dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:14 · User-Dereckson, Vault, Nasqueron Operations Squad, security
dereckson requested review of D2854: Decommission Zemke-Rhyne.
Mar 7 2023, 20:14
dereckson closed T116: Create a AuthorizedKeysLine class to refactor GetPublicKeys as Wontfix.

Zemke-Rhyne is now decommissioned, as all secrets have been migrated to Vault.

Mar 7 2023, 20:07 · good-first-issue, Nasqueron Docker deployment squad
dereckson updated zemke-rhyne.
Mar 7 2023, 20:06
dereckson updated zemke-rhyne.
Mar 7 2023, 20:05
dereckson updated zemke-rhyne.
Mar 7 2023, 20:05
dereckson closed D2841: Remove Docker devicemapper configuration.
Mar 7 2023, 19:57
dereckson committed rOPSe96da24d4a2e: Remove Docker devicemapper configuration (authored by dereckson).
Remove Docker devicemapper configuration
Mar 7 2023, 19:57
dereckson added a comment to T1783: Lint if salt:// files exist.

Also, D2853 offers a nice thing to link to: we need to ensure if the source file: value matches the filename.

Mar 7 2023, 19:57 · Salt
dereckson committed rOPS06e3f268ce3c: Update source file header for docker-002 HE tunnel (authored by dereckson).
Update source file header for docker-002 HE tunnel
Mar 7 2023, 19:56
dereckson closed D2853: Update source file header for docker-002 HE tunnel.
Mar 7 2023, 19:56
dereckson accepted D2853: Update source file header for docker-002 HE tunnel.
Mar 7 2023, 19:56
dereckson requested review of D2853: Update source file header for docker-002 HE tunnel.
Mar 7 2023, 19:56
dereckson committed rOPSeaa6e1b6c8d2: Fix space issue (authored by dereckson).
Fix space issue
Mar 7 2023, 19:54
dereckson closed D2852: Fix space issue.
Mar 7 2023, 19:54
dereckson accepted D2852: Fix space issue.
Mar 7 2023, 19:54
dereckson requested review of D2852: Fix space issue.
Mar 7 2023, 19:54
dereckson committed rOPS798759dc846e: Decommission docker-001 (authored by dereckson).
Decommission docker-001
Mar 7 2023, 19:52
dereckson closed D2851: Decommission docker-001.
Mar 7 2023, 19:52
dereckson accepted D2851: Decommission docker-001.
Mar 7 2023, 19:52
dereckson updated the test plan for D2851: Decommission docker-001.
Mar 7 2023, 19:52
dereckson requested review of D2851: Decommission docker-001.
Mar 7 2023, 19:51
dereckson added a revision to T1779: Provision docker-002 Docker Engine: D2851: Decommission docker-001.
Mar 7 2023, 19:51 · Salt, Docker images, Servers, security
dereckson closed D2787: Provision docker-002.
Mar 7 2023, 19:49
dereckson committed rOPS858e30a799d4: Provision docker-002 (authored by dereckson).
Provision docker-002
Mar 7 2023, 19:49
dereckson accepted D2787: Provision docker-002.
Mar 7 2023, 19:48
dereckson updated the diff for D2787: Provision docker-002.

Consolidate network for pillar

Mar 7 2023, 19:48
dereckson updated the diff for D2787: Provision docker-002.

Update network to reuse docker-001 canonical IPv4 and IPv6

Mar 7 2023, 19:46
dereckson updated the summary of D2787: Provision docker-002.
Mar 7 2023, 19:44
dereckson updated the summary of D2787: Provision docker-002.
Mar 7 2023, 19:14
dereckson added a revision to T1779: Provision docker-002 Docker Engine: D2787: Provision docker-002.
Mar 7 2023, 19:10 · Salt, Docker images, Servers, security
dereckson retitled D2787: Provision docker-002 from WIP: Provision docker-002 to Provision docker-002.
Mar 7 2023, 19:10
dereckson updated the diff for D2787: Provision docker-002.

Rebased

Mar 7 2023, 19:08
dereckson closed D2850: Deploy tmux-reattach.
Mar 7 2023, 18:37
dereckson committed rOPSa1bcecf5eae5: Deploy tmux-reattach (authored by dereckson).
Deploy tmux-reattach
Mar 7 2023, 18:37
dereckson updated the summary of D2850: Deploy tmux-reattach.
Mar 7 2023, 18:36
dereckson accepted D2850: Deploy tmux-reattach.
Mar 7 2023, 18:33
dereckson added a comment to D2850: Deploy tmux-reattach.

Alternative way: tmux new -AD -s some-session-name, so yup, seems a correct approach without naming sessions.

Mar 7 2023, 18:33
dereckson requested review of D2850: Deploy tmux-reattach.
Mar 7 2023, 18:11
dereckson updated the task description for T1791: Refresh Sentry installation.
Mar 7 2023, 17:51 · Monitoring and reporting
dereckson renamed T1791: Refresh Sentry installation from Refresh Sentry installation to CalVer modern releases to Refresh Sentry installation.
Mar 7 2023, 17:51 · Monitoring and reporting
dereckson added a parent task for T1790: Trace eggdrop errors: T1791: Refresh Sentry installation.
Mar 7 2023, 17:51 · IRC, Monitoring and reporting, Dæghrefn
dereckson added a subtask for T1791: Refresh Sentry installation: T1790: Trace eggdrop errors.
Mar 7 2023, 17:51 · Monitoring and reporting
dereckson closed D2849: Apply version constraint to pip package, not pip itself.
Mar 7 2023, 17:50
dereckson committed rOPS9d8ff4d04770: Apply version constraint to pip package, not pip itself (authored by dereckson).
Apply version constraint to pip package, not pip itself
Mar 7 2023, 17:50
dereckson closed T1788: Fix sentry wrapper SECRET_KEY templating as Resolved by committing rOPS69a1765ac933: Fix credential helper and sentry wrapper.
Mar 7 2023, 17:50 · Nasqueron Docker deployment squad, Salt
dereckson committed rOPS69a1765ac933: Fix credential helper and sentry wrapper (authored by dereckson).
Fix credential helper and sentry wrapper
Mar 7 2023, 17:49
dereckson closed D2848: Fix credential helper and sentry wrapper.
Mar 7 2023, 17:49
dereckson committed rOPS7d5ca48769a2: Set proxy_redirect for notifications.nasqueron.org nginx vhost (authored by dereckson).
Set proxy_redirect for notifications.nasqueron.org nginx vhost
Mar 7 2023, 17:48
dereckson closed D2847: Set proxy_redirect for notifications.nasqueron.org nginx vhost.
Mar 7 2023, 17:48
dereckson closed D2846: Reformat paas-docker nginx configuration files for vhosts.
Mar 7 2023, 17:48
dereckson committed rOPS081f42df7128: Reformat paas-docker nginx configuration files for vhosts (authored by dereckson).
Reformat paas-docker nginx configuration files for vhosts
Mar 7 2023, 17:48
dereckson triaged T1791: Refresh Sentry installation as Normal priority.
Mar 7 2023, 17:47 · Monitoring and reporting
dereckson triaged T1790: Trace eggdrop errors as Normal priority.
Mar 7 2023, 17:38 · IRC, Monitoring and reporting, Dæghrefn