16:00:02 #startmeeting Infrastructure (2021-02-04) 16:00:02 Meeting started Thu Feb 4 16:00:02 2021 UTC. 16:00:02 This meeting is logged and archived in a public location. 16:00:02 The chair is siddharthvipul. Information about MeetBot at http://wiki.debian.org/MeetBot. 16:00:02 Useful Commands: #action #agreed #halp #info #idea #link #topic. 16:00:02 The meeting name has been set to 'infrastructure_(2021-02-04)' 16:00:02 #meetingname infrastructure 16:00:02 The meeting name has been set to 'infrastructure' 16:00:02 #chair nirik pingou smooge cverna mizdebsk mkonecny abompard siddharthvipul mobrien 16:00:02 #info Agenda is at: https://board.net/p/fedora-infra 16:00:02 #info About our team: https://docs.fedoraproject.org/en-US/cpe/ 16:00:02 Current chairs: abompard cverna mizdebsk mkonecny mobrien nirik pingou siddharthvipul smooge 16:00:02 #topic aloha 16:00:13 Good morning everyone :) 16:00:18 who is here today? 16:00:23 .hello siddharthvipul1 16:00:24 siddharthvipul: siddharthvipul1 'Vipul Siddharth' 16:00:24 morning 16:00:24 hi 16:00:41 Good morning 16:00:50 nirik, dtometzki, ComputerKid \o How are you all 16:01:05 Good! 16:01:11 .hello zlopez 16:01:12 Zlopez[m]: zlopez 'Michal Konečný' 16:01:15 hello 16:01:18 .hi 16:01:19 darknao: darknao 'Francois Andrieu' 16:01:24 welcome Zlopez[m] and darknao :D 16:01:39 fine thanks 16:01:47 I can't complain... but sometimes I still do... lifes been good to me so far. :) (wonder if anyone will get the reference) 16:03:11 I also hear you have a mansion? :P 16:03:17 * siddharthvipul just googled.. sorry haha 16:03:36 * siddharthvipul plays it now! 16:04:02 okay.. so let's give chance to new folks here introduce (if any) :D 16:04:04 #topic New folks introductions 16:04:04 #info This is a place where people who are interested in Fedora Infrastructure can introduce themselves 16:04:05 #info Getting Started Guide: https://fedoraproject.org/wiki/Infrastructure/GettingStarted 16:04:17 so, who has attended these meeting less that 2-3 times :) 16:05:08 Hi 16:05:10 I have 16:05:17 oh welcome ComputerKid :) 16:05:20 This is my second meeting 16:05:28 do you want to do a brief introduction? or we have already done that? 16:05:34 ComputerKid++ for joining us :D 16:05:34 siddharthvipul: Karma for computerkid changed to 3 (for the current release cycle): https://badges.fedoraproject.org/tags/cookie/any 16:05:39 I think I get the gist 16:05:44 Aw, thanks! 16:06:01 Fedora community is great 16:06:08 ComputerKid, do let us know if you need any help in gettting started.. or just want to know what we do :) 16:06:26 ComputerKid, I will agree with you on that :) 16:06:32 Y'all keep all the fedora apps running right? 16:07:01 we try to.. yes! we look after all of Fedora Infrastructure (most of?) 16:07:44 right.. so seems we don't have anyone else. Let's move to next item on agenda 16:07:57 #topic Next chair 16:07:57 #info magic eight ball says: 16:07:57 #info chair 2021-02-11 - zlopez 16:07:57 #info chair 2021-02-18 - smooge 16:07:59 Lol. That's really cool! I run a decent homelab IMO, so I have a small appreciation of how much that would be 16:08:16 ComputerKid, opos,sorry about that 16:08:19 Sorry 16:08:34 that's great! we should talk about it. let's get back to it on open floor :D 16:08:42 ComputerKid, not at all.. very welcomed :) 16:08:58 Don't let it too open, so we don't fall 16:09:09 so we have chairs for next 2 meetings.. we are looking for a volunteer for Feb 25, 2021 16:09:20 Zlopez[m], ah, what's life without some risk 16:09:51 I would really like to see someone new running the meetings.. It's very easy and you can ping us if you are ever stuck 16:10:22 i can try it 16:10:30 dtometzki, oh awesome! sold :D 16:10:42 i am "new" :-) 16:10:42 #info chair 2021-02-25 - dtometzki 16:10:43 I would be happy to help 16:10:57 I am new to being in fedora community 16:11:07 ComputerKid, let's do it the one after that? we can decide that in the next meeting? 16:11:23 dtometzki, ComputerKid please feel free to contact me on how to run these 16:11:35 basically we have everything in agenda and we follow that 16:11:39 yes we will do it 16:11:44 ComputerKid++ dtometzki++ 16:11:44 siddharthvipul: Karma for dtometzki changed to 1 (for the current release cycle): https://badges.fedoraproject.org/tags/cookie/any 16:11:55 right, let's move to the next topic then :) 16:12:06 #topic announcements and information 16:12:07 #info CPE Infra&Releng EU-hours team has a Monday through Friday 30 minute meeting going through tickets at 1030 Europe/paris in #centos-meeting 16:12:07 #info CPE Infra&Releng NA-hours team has a Monday through Friday 30 minute meeting going through tickets at 1800 UTC in #fedora-admin 16:12:07 #info Datacenter move is over, but some items still need to be done: see https://fedoraproject.org/wiki/Infrastructure/2020-post-datacenter-move-known-issues 16:12:34 nirik, for the last info, are there still some stuff that needs attention after DC move? 16:12:53 let me check the link 16:13:03 oh I see 16:13:16 well, ongoing. I guess we can drop it from the meeting. 16:13:33 nirik, got it 16:13:48 anyone has anything to add in announcements? 16:14:18 #info master to rawhide/main changes have mostly finished on src.fedoraproject.org 16:14:37 #info tomorrow is a Red Hat day of learning, so many employees will be out learning things. :) 16:14:53 #info Fedora stand in FOSDEM. Please check https://stands.fosdem.org/stands/the_fedora_project/ 16:15:13 awesome 16:15:32 I will wait for 30 seconds before moving to next topic 16:16:17 #topic Oncall 16:16:17 #info https://fedoraproject.org/wiki/Infrastructure/Oncall 16:16:17 #info smooge is oncall for 2021-01-28 to 2021-02-04 16:16:17 #info nirik is oncall for 2021-02-04 to 2021-02-11 16:16:17 #info dtometzki is oncall for 2021-02-11 to 2021-02-18 16:16:26 that was more than 30 seconds! 16:16:28 yes 16:16:48 pingou, India is UTC+5:30.. time is different here 16:16:50 everyone's a critic. ;) 16:17:16 :P 16:17:41 we are looking for an oncall volunteer from 2021-02-18 to 2021-02-25 16:18:03 do we have any? if no one, I can take it 16:18:14 but if you would like to.. please say it now :D 16:18:24 What do you mean by volunteer 16:18:45 siddharthvipul++ good answer ;-) 16:19:06 WhErE aRe My cOoKiES 16:19:12 Lol 16:19:18 you ate them already! 16:19:18 :-) 16:19:37 ComputerKid, anyone can volunteer to be oncall for a week. It means if someone notices a problem, they will use oncall feature to interact with you 16:19:48 instead of directly pinging anyone else 16:20:06 ComputerKid, I would recommend you going through https://fedoraproject.org/wiki/Infrastructure/Oncall 16:20:38 it's a nice experience.. if the week is good, you get to learn a few things about Fedora applications.. and if the week is really really good.. you don't realize you were oncall for the whole week 16:21:25 I think the next week will be good 16:21:37 haha.. I hope not :P 16:21:49 right! let me assign it to myself 16:22:09 Cool. I would be up for it sometime, I don't know how available I could be. As a kid I have to sleep a little more than most people 16:22:19 #info siddharthvipul is on call for 2021-02-18 to 2021-02-25 16:23:02 ComputerKid, oh that's totally understandable.. we are just glad you are here and are interested in things O:) 16:23:12 nirik, would you like to take on call duty? 16:23:36 for the week I mean.. ## .oncalltakeus 16:23:46 sure. 16:23:50 .oncalltakeus 16:23:50 nirik: Kneel before zod! 16:24:00 great 16:24:05 #info Summary of last week: (from current oncall) 16:24:08 smooge, hey 16:24:11 you around? 16:24:21 oh sorry 16:24:28 too many windows. 16:24:59 I had a couple of oncalls. One was for a bad permissions on NFS and another was on oci running out of disk space. 16:25:04 otherwise it was quiet 16:26:08 nice 16:26:17 cool 16:26:21 #topic Monitoring discussion [nirik] 16:26:22 #info https://nagios.fedoraproject.org/nagios 16:26:31 ComputerKid: there is no expectation to be online 24/7 when oncall, the message returned by zodbot says that if the oncall person does not respond a ticket is way to go 16:27:04 so, I think we are pretty much the same as last week, but let me see. 16:27:14 I did want to note one thing: 16:27:38 There's some services we have to keep restarting all the time. We should look at making nagios do so for us. 16:27:59 Those are: pdc-web01 httpd, pdc-web02 httpd and resultsdb01 httpd 16:28:50 we still have 2 down aarch64 boxes... one with a bad drive, one needs power recycling. We haven't made much progress on those... smooge: perhaps you could bug people about pdus again? 16:29:28 badges-backend has a big backlog. perhaps we could ask misc to look into it? 16:30:03 the bodhi-sync-listener queue is big... we need to fix that from the main/rawhide branch changes: 16:30:06 RABBITMQ_QUEUE CRITICAL - messages CRITICAL (167), messages_ready OK (167) messages_unacknowledged OK (0) consumers OK (0) 16:30:28 otherwise it's all the old small things. ;) 16:30:35 and we can move along. 16:30:49 thank you nirik (as always) 16:31:08 oh wow.. we are already here 16:31:09 #topic Learning topic 16:31:23 #info IPA [nirik] 16:31:28 nirik, we are doing this, right? 16:31:28 ah yes... 16:31:42 :excited: :D 16:31:47 Same 16:31:48 sure, I can give a overview of our setup... but probibly not a ton of detail. :) 16:31:51 nirik the people with pdu access will not be able to fix it until they get to the dc 16:32:37 so... we have been using ipa for about 4 years now with our current account system: fas. 16:33:22 ipa provides a full suite of identity and auth management... it can do kerberos auth, dns, certificiate management, and all sorts of things. :) 16:33:48 right now however we are only using it for kerberos authentication. 16:34:40 The current system works by syncing data from our fas system on user login (to fas) to the ipa cluster, then later when a user uses kinit to get a kerberos ticket they talk to the ipa server, it has their password and they get a ticket, etc. :) 16:35:16 Very soon however, our new replacement account system (noggin) is going to move into production. It's already there in staging. 16:35:49 With the new setup, noggin is just a frontend to ipa. It uses ipa to store everything, it doesn't keep info itself. 16:35:49 and for sso is it used too ? 16:36:33 dtometzki: there's another part to our setup: ipsilon. ipsilon handles things like OIDC, SAML2, openid and such. 16:36:50 ipsilon is going to stay the same with the new setup (at least for now) 16:36:54 ahh 16:37:53 is ipsilon related in some way to keycloak ? 16:38:09 Under the current setup, ssh access to hosts is via a fasClient script. It gathers info from fas on users/groups and sets up those on the local host. 16:38:33 Under the current setup, sudo is using pam_url and totpcgi 16:39:06 ipsilon and keycloak handle the same usecases (mostly). ;) Just one is in python the other in java. And keycloak doesn't do openid 16:39:32 Under the new setup, ssh and sudo will be via sssd and ipa. So much more standard. 16:39:54 You can see the noggin interface in stg: 16:40:04 https://admin.stg.fedoraproject.org/accounts/ 16:40:37 (all the prod accounts have been synced, but there's some issues with group membership). Probibly you will want to use 'forgot password' to reset your password at first 16:41:06 Down the road we may move to keycloak from ipsilon, but no timetable for that yet... 16:42:08 lets see... what else. 16:42:54 Right now in prod we have 2 ipa servers in the cluster. 16:43:13 Likely we will add a few more before we roll out the new setup (as they are gonna be under some more load) 16:43:40 ipa is pretty cool in that you can pretty easily add more masters and they handle all the syncing and keeping them up to date. 16:44:23 when we moved datacenters, we setup these 2 masters in the new dc and they synced with the old ones, then after moving we just turned off the old ones. :) 16:44:47 fine i can login 16:45:11 cool. 16:45:27 So, any questions or things you would like me to expand on? 16:46:12 we are still sorting out 2fa stuff... it's mostly working tho. 16:47:10 sadly there's some more work to get kinit working with 2fa setups, but hopefully we can reduce that. 16:48:27 ok, as always feel free to ask questions anytime in #fedora-admin or the like. ;) 16:48:37 awesome 16:48:45 nirik, thanks a lot for taking these 16:48:51 very interesting and definitely learning a lot 16:49:10 tomorrow for learning day, I am going to visit all the notes once more and might disturb you all next week :) 16:49:28 if there are not questions, should we move to open floor? 16:50:24 I plan to play with my PinePhone and try to run Fedora on it :-) 16:50:39 Zlopez[m], oh, very cool! 16:50:51 Zlopez[m]: see #fedora-phone. ;) 16:51:14 nirik: I wasn't aware there is a channel on freenode 16:51:20 nirik++ 16:51:38 you know what.. I am really excited for element now (helps with discovering channels) 16:51:45 #topic Open Floor 16:51:58 element == Fedora home matrix server 16:52:10 It's too new and shiny for me.. but I will get used to it soon :P 16:52:25 offers a ton of nice handy things in pros 16:52:35 siddharthvipul: Yes, I'm using it too 16:53:14 i need any permission to do my oncall job next week ? 16:53:15 Zlopez[m], I am not.. just using it for FOSDEM but might move later next week or month 16:53:59 dtometzki, we can sort it out in next week call. but you will take the duty with .oncalltakeeu or .oncalltakeus (depends on timezone) 16:54:13 you have to be verified with zodbot 16:54:20 now now, let me remember how to do that 16:54:28 .whoami 16:54:28 siddharthvipul: siddharthvipul1 16:55:03 Thanks for the talk on ipa 16:55:05 Was cool 16:55:54 Is the meeting over? 16:56:01 can anyone help me fetch the link or command to verify fas id with zodbot? 16:56:06 ComputerKid, we have a few more minutes :) 16:56:37 user identify 16:56:42 Zlopez[m], thank you 16:56:45 dtometzki, ^ 16:56:58 Just sent this to zodbot in private talk 16:57:04 password being your freenode password (this is to sent to zodbot in private) 16:58:06 okay folks.. if nothing else I will close the meeting in 60 seconds 16:58:18 or 40-100 seconds in Indian time zone :P 16:58:31 thanks for chairing siddharthvipul 16:58:40 Zlopez[m], my pleasure :) 16:58:41 siddhartvipul++ 16:58:58 It looks like I gave all my cookies already :-D 16:58:59 thanks siddharthvipul, and nirik 16:59:06 Zlopez[m], I am sad 16:59:17 .thanks siddharthvipul 16:59:17 Zlopez [m] thinks siddharthvipul is awesome and is happy they are helping! (Please also type siddharthvipul++ since that is what gives them a cookie) 16:59:17 siddharthvipul++ 16:59:28 haha 16:59:32 #endmeeting