Project

General

Profile

Actions

tickets #111188

closed

mirrorcache@localhost

Added by pjessen almost 2 years ago. Updated 5 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Mirrors
Target version:
-
Start date:
2022-05-17
Due date:
% Done:

0%

Estimated time:

Description

Every 15mins, anna/elsa receives a connection from mirrorcache-us.infra.opensuse.org[192.168.67.12], which is refused with "Relay access denied" because that network is not known. The mail is from mirrorcache@localhost to mirrorcache@localhost which also sounds pretty silly :-)
After one or two retries, the mail is then delivered from mirrorcache.infra.opensuse.org[192.168.47.23] (i.e. a known network), but it is immediately dropped as non-deliverable "mail for localhost loops back to myself".
I tried to log on to mirrorcache.infra.opensuse.org to have a look at the postfix config, but was unable to.

Actions #1

Updated by pjessen almost 2 years ago

  • Private changed from Yes to No

The issues as I see them -

  • "new" network 192.168.67.0/24 - maybe mails should not be sent from this?
  • sender/recipient the same
  • sender/recipient @localhost
  • no access to mirrorcache.i.o.o
  • general postfix config needs revisiting.
Actions #2

Updated by lrupp almost 2 years ago

  • Assignee set to andriinikitin
Actions #3

Updated by lrupp almost 2 years ago

  • Category set to Mirrors
Actions #4

Updated by andriinikitin almost 2 years ago

  • Assignee changed from andriinikitin to pjessen
  • Private changed from No to Yes

pjessen wrote:

Every 15mins, anna/elsa receives a connection from mirrorcache-us.infra.opensuse.org[192.168.67.12], which is refused with "Relay access denied" because that network is not known. The mail is from mirrorcache@localhost to mirrorcache@localhost which also sounds pretty silly :-)
After one or two retries, the mail is then delivered from mirrorcache.infra.opensuse.org[192.168.47.23] (i.e. a known network), but it is immediately dropped as non-deliverable "mail for localhost loops back to myself".
I tried to log on to mirrorcache.infra.opensuse.org to have a look at the postfix config, but was unable to.

I am not good with access management, but you should be able to ssh to mirrorcache-us from provo-mirror.opensuse.org. Let me know if that doesn't work, maybe we can engage lars with this.

Actions #5

Updated by pjessen almost 2 years ago

  • Private changed from Yes to No

andriinikitin wrote:

pjessen wrote:

Every 15mins, anna/elsa receives a connection from mirrorcache-us.infra.opensuse.org[192.168.67.12], which is refused with "Relay access denied" because that network is not known. The mail is from mirrorcache@localhost to mirrorcache@localhost which also sounds pretty silly :-)
After one or two retries, the mail is then delivered from mirrorcache.infra.opensuse.org[192.168.47.23] (i.e. a known network), but it is immediately dropped as non-deliverable "mail for localhost loops back to myself".
I tried to log on to mirrorcache.infra.opensuse.org to have a look at the postfix config, but was unable to.

I am not good with access management, but you should be able to ssh to mirrorcache-us from provo-mirror.opensuse.org. Let me know if that doesn't work, maybe we can engage lars with this.

I'll try accessing it from provo-mirror, but shouldn't it just work over our VPN?
I thought it was a routing issue with the new network, but I see that route is added.

ssh from provo-mirror also fails, it asks for a password.

There must be something missing on mirrorcache-us, I think ?

I was not aware of that network, 192.168.67.0/24, but I guess it is safe to add it to anna/elsa.

Actions #6

Updated by cboltz almost 2 years ago

pjessen wrote:

andriinikitin wrote:

I'll try accessing it from provo-mirror, but shouldn't it just work over our VPN?

It does, no need to go via provo-mirror. However...

ssh from provo-mirror also fails, it asks for a password.

... that's also what I see. Wild guess - nobody did run the initial salt highstate on mirrorcache-us yet? (Andrii, if I'm correct, please do that - maybe first with test=True to see what would be changed.)

Actions #7

Updated by pjessen 10 months ago

Ping ?
The mail delivery attempts are now coming from mirrorcache-us-db.infra.opensuse.org[192.168.67.23], but otherwise nothing has changed. Trying to log on to mirrorcache-us-db.infra.opensuse.org, and I am still asked for a password.

Actions #8

Updated by crameleon 5 months ago

  • Assignee changed from pjessen to andriinikitin

Any Salt commands against this machine seem utterly slow. Even test.ping takes a while to return. The Postfix states are slower than compiling Postfix from scratch.

Actions #9

Updated by andriinikitin 5 months ago

  • Status changed from New to In Progress
  • Assignee changed from andriinikitin to crameleon

Somehow this ticket got lost and I didn't remember it at all.

I've disabled problem cron job on mirrorcache-us-db and it shouldn't try to send spam every 15 min anymore.
Please feel free to run required/missing salt commands or write them down here and assign the ticket back to me and I will run them.

Actions #10

Updated by crameleon 5 months ago

  • Status changed from In Progress to Resolved

Thank you! I'll follow up with this separately as I notice we currently have some issues with the Salt states for machines in Provo due to mismatching name- and downloadservers.

Actions

Also available in: Atom PDF