Project

General

Profile

Actions

action #124119

closed

QA - coordination #121720: [saga][epic] Migration to QE setup in PRG2+NUE3 while ensuring availability

QA - coordination #116623: [epic] Migration of SUSE Nbg based openQA+QA+QAM systems to new security zones

Conduct the migration of remaining SUSE openQA systems IPMI to new security zones

Added by mkittler over 1 year ago. Updated 11 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
-
Target version:
Start date:
2023-02-08
Due date:
% Done:

0%

Estimated time:
Tags:

Description

Motivation

This is a follow-up of #20270 for the remaining systems (as #20270 only covered machines in SRV1), also see parent #116623

The remaining hosts (as of the creation of this ticket are):

  1. Hosts used for bare-metal testing: sp.openqaw5-xen.qa.suse.de
  2. Prague located: openqaworker14-ipmi.qa.suse.cz, openqaworker15-ipmi.qa.suse.cz, openqaworker16-ipmi.qa.suse.cz, openqaworker17-ipmi.qa.suse.cz, openqaworker18-ipmi.qa.suse.cz
  3. PowerPC machines: qa-power8-4.qa.suse.de, qa-power8-5.qa.suse.de, fsp1-powerqaworker-qam.qa.suse.de, malbec.arch.suse.de
  4. ARM machines: openqaworker-arm-1-ipmi.suse.de, openqaworker-arm-2-ipmi.suse.de, openqaworker-arm-4-ipmi.suse.de, openqaworker-arm-4-ipmi.suse.de, openqaworker-arm-5-ipmi.suse.de

Technically, also the following hosts are remaining -however, they are not used anymore anyways or are broken: openqaworker1, imagetester, power8
So those hosts should supposedly be excluded.

Acceptance criteria

  • AC1: All IPMI interfaces of openQA machines listed in workerconf.sls are in new security zones
  • AC2: All IPMI interfaces of openQA machines listed in workerconf.sls are fully usable in production
  • AC3: All documentation referencing O3+OSD ipmi interfaces are up-to-date
  • AC4: Our automated tools using O3+OSD ipmi interfaces are up-to-date e.g. GitLab pipelines and salt states

Suggestions

Open points

  1. Where is the documentation by SUSE-IT?
  2. Where is the git repo handling ssh keys?
  3. Fix the multi-second login time over ssh (workaround: use ssh -4)

Related issues 1 (0 open1 closed)

Copied from openQA Infrastructure - action #120270: Conduct the migration of SUSE openQA systems IPMI from Nbg SRV1 to new security zones size:MResolvedmkittler

Actions
Actions #1

Updated by mkittler over 1 year ago

  • Copied from action #120270: Conduct the migration of SUSE openQA systems IPMI from Nbg SRV1 to new security zones size:M added
Actions #2

Updated by okurz over 1 year ago

  • Tags set to infra
  • Subject changed from Conduct the migration of remaining SUSE openQA systems IPMI to new security zones size:M to Conduct the migration of remaining SUSE openQA systems IPMI to new security zones
  • Assignee deleted (mkittler)
  • Priority changed from High to Normal
  • Target version changed from Ready to future

Thank you for creating that ticket. It wasn't estimated so I will remove the size:M. I also assume you are not insisting on staying assigned or the priority. Also I think we can keep this outside the backlog for now.

Actions #3

Updated by livdywan about 1 year ago

I assume malbec host up alerts are related to this ticket as per the description?

http://stats.openqa-monitor.qa.suse.de/alerting/grafana/host_up_alert_malbec/view?orgId=1

Actions #4

Updated by okurz about 1 year ago

livdywan wrote in #note-3:

I assume malbec host up alerts are related to this ticket as per the description?

http://stats.openqa-monitor.qa.suse.de/alerting/grafana/host_up_alert_malbec/view?orgId=1

No. But #135515

Actions #5

Updated by okurz 11 months ago

  • Status changed from New to Resolved
  • Assignee set to okurz
  • Target version changed from future to Ready

With NUE1 decommissioned all active systems are in new security zones and I guess machines that are brought (back) into production will also end up in new security zones. No specific work for improving error reporting here was done and I don't think we need to improve that further. We need to rely on SUSE-IT to monitor their firewall accordingly.

Actions

Also available in: Atom PDF