Project

General

Profile

Actions

action #159063

open

openQA Project - coordination #105624: [saga][epic] Reconsider how openQA handles secrets

openQA Project - coordination #157537: [epic] Secure setup of openQA test machines with secure network+secure authentication

s390x qemu backend host within SUSE networks

Added by okurz about 1 month ago. Updated 1 day ago.

Status:
New
Priority:
Low
Assignee:
-
Category:
Feature requests
Target version:
Start date:
2024-04-16
Due date:
% Done:

0%

Estimated time:
Tags:

Description

Motivation

To prevent test VMs with insecure passwords running in the SUSE networks for #157537 we should setup an s390x qemu backend host within SUSE networks to replace the svirt setup relying on direct SSH to test VMs.

Acceptance criteria

  • AC1: At least on production s390x qemu openQA worker within OSD infrastructure
  • AC2: Both s390zl19+s390zl1a are used in production

Suggestions

  • Wait for #158455 to have native s390x packages
  • See https://confluence.suse.com/display/enginfra/LinuxONE+LPARs about available s390x machines
  • Install on s390x test host or s390zl12+13 in parallel but don't try to break the existing libvirt based setup for now :) Alternative: Use new hosts s390zl19+s390zl1a
  • Trigger test openQA jobs
  • If successful create according tickets for testing squads to transfer their s390x KVM tests to the qemu backend
  • Ensure both s390zl19+s390zl1a are used in production depending on the choice made regarding using s390zl12+13 or s390zl19+1a

Related issues 2 (1 open1 closed)

Related to openQA Project - action #158985: openQA worker native on s390xResolvedokurz

Actions
Copied to openQA Infrastructure - action #160436: Use s390zl19+s390zl1a in productionNew

Actions
Actions #1

Updated by okurz 26 days ago

Actions #2

Updated by okurz 26 days ago

  • Description updated (diff)
  • Status changed from New to Blocked
  • Assignee set to okurz
Actions #3

Updated by mgriessmeier 24 days ago

the ZFCP disks to store images have been added to ZL19 and ZL1A.
They are still missing a filesystem and proper mount rules.

Actions #4

Updated by okurz 1 day ago

Actions #5

Updated by okurz 1 day ago

  • Status changed from Blocked to New
  • Assignee deleted (okurz)
  • Priority changed from Normal to Low
  • Target version changed from Tools - Next to future

With #159069 resolved there is a firewall on the hypervisor hosts preventing access over SSH or VNC from general network. With that this task is less important for us. Hence I have created a new ticket #160436 and will otherwise drop this ticket from our current backlog.

Actions

Also available in: Atom PDF