18:00:31 #startmeeting Infrastructure (2016-06-16) 18:00:31 Meeting started Thu Jun 16 18:00:31 2016 UTC. The chair is nirik. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:00:31 Useful Commands: #action #agreed #halp #info #idea #link #topic. 18:00:31 The meeting name has been set to 'infrastructure_(2016-06-16)' 18:00:31 #meetingname infrastructure 18:00:31 #topic aloha 18:00:31 #chair smooge relrod nirik abadger1999 lmacken dgilmore threebean pingou puiterwijk pbrobinson 18:00:31 The meeting name has been set to 'infrastructure' 18:00:31 Current chairs: abadger1999 dgilmore lmacken nirik pbrobinson pingou puiterwijk relrod smooge threebean 18:00:31 #topic New folks introductions / Apprentice feedback 18:01:00 * threebean waves 18:01:05 Hello 18:01:18 * aikidouke here 18:01:24 * skrzepto is here 18:01:29 * pcreech here 18:01:33 * subho here 18:01:39 * lousab is here 18:01:43 hello 18:02:10 hello 18:02:11 hello :) 18:02:31 hello all. 18:02:41 any new folks like to give a short one line introduction? 18:03:47 ok, if no, will go on to status/info 18:03:57 #topic announcements and information 18:03:57 #info Still in F24 final freeze - everyone 18:03:58 #info spam attacks continue - patrick/smooge/kevin 18:03:58 #info (re)setup proxy07 on a cloud node at bodhost, seems working so far - kevin 18:03:58 #info New 10G switches and new bladecenters arriving in phx2 to be setup in coming weeks - kevin/smooge/patrick 18:04:09 any other status/info folks would like to note? or discuss from above? 18:05:06 spam 18:05:33 yeah, the spam... continues. ;) 18:05:40 * pingou here (late) 18:07:33 * nirik is a bit distracted, still in the go/no-go meeting. 18:07:45 alright will run 18:07:53 ok we are in final freeze 18:07:54 I had one discussion item 18:07:57 which may or may not occur 18:08:18 #topic Some upcoming releng changes that may affect infra: 18:08:18 Review F25 change that may impact Infra: Automated Docker Releases 18:08:18 Review F25 change that may impact Infra: Fedora Docker Registry 18:08:42 .ticket 5356 18:08:43 nirik: #5356 (Review F25 change that may impact Infra: Automated Docker Releases) – Fedora Infrastructure - https://fedorahosted.org/fedora-infrastructure/ticket/5356 18:08:44 .ticket 5357 18:08:46 nirik: #5357 (Review F25 change that may impact Infra: Fedora Docker Registry) – Fedora Infrastructure - https://fedorahosted.org/fedora-infrastructure/ticket/5357 18:09:08 I looked at these and added feedback, but if everyone else could take a look and do so too that would be great. 18:09:47 ok those will require new services and also impcact deliverables so pleas edo 18:10:01 nad my fingers aren't typing well in colocation :) 18:10:31 does anyone have anything to say right now on those two tickets? 18:10:46 I expect we will talk more about them in the upcoming months 18:10:50 yeah. 18:11:22 ok will move onto next topic. 18:11:25 #topic Apprentice office hours 18:11:49 * bwood09 back from hiatus and ready to start working 18:11:51 I first want to say ++ to linuxmodder for helping various apprentices in #fedora-admin 18:11:58 linuxmodder++ 18:11:58 pingou: Karma for linuxmodder changed to 18 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:12:05 linuxmodder++ 18:12:11 linuxmodder++ 18:12:11 vivek_: Karma for linuxmodder changed to 19 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:12:14 I think I gave my cookies alreayd 18:12:32 linuxmodder++ 18:12:32 athos: Karma for linuxmodder changed to 20 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:12:41 I have seen him helping a lot of people while I have been stuck dealing with SPAM issues. 18:12:50 Hi bwood09 18:12:54 welcome back 18:12:57 Thanks ^_^ 18:13:11 are there any questions at the moment? 18:13:34 yes, I didn't even know he was on fi-apprentice since he's been that active in the channel helping ppl out 18:13:46 smooge i have a question on nagios ansible 18:15:05 hi lousab 18:15:08 i've seen on batcave under ansible/roles i think and i didn't understood if there's the yalm file or not or if i have to build for #5337 18:15:10 what is the question 18:15:10 and i have something unrelated to lousab 18:15:29 .ticket 5337 18:15:30 smooge: #5337 (add monitoring for fedoramagazine) – Fedora Infrastructure - https://fedorahosted.org/fedora-infrastructure/ticket/5337 18:15:56 and I was thinking about picking up ticket 4973 if nobody's done anything with it 18:16:00 .ticket 4973 18:16:01 bwood09: #4973 (add nagios check for mailman01's REST interface.) – Fedora Infrastructure - https://fedorahosted.org/fedora-infrastructure/ticket/4973 18:16:12 ha everyone wants to do nagios :). 18:16:20 :) 18:16:24 and I am about to change out how nagios is done 18:16:26 nagios doesn't use anything close to as sane as a yaml file. ;) 18:17:07 so nagios is mostly done through a file format that is one of the many meh formats. Why is it like that? meh 18:17:42 nirik: i normally configure nagios with kickstart if i have to install it and thruk and monarch plugins....i never used ansible..i'm learning it :( 18:17:48 * jflory7 is here 18:17:52 We haven't been consistent on how we implement them across the system so they end up being very fragiole 18:19:28 yeah, the best way I think to see is pick a similar host to the one you are adding and 'git grep' it and look at where it's defined in nagios 18:19:34 Is there anything we can do to streamline that process? What changes are we looking at for nagios? 18:19:40 There's also some old commits likely where machines were added... look in git log 18:20:16 nirik: ok thanks 18:20:33 the plan is for smooge to reimplement it so ansible just adds the needed stuff when we add a host. 18:20:35 aikidouke: i'm new here :) i'm an apprentice 18:20:37 but thats not done yet. ;) 18:20:44 hm, that sounds like a cool idea 18:20:49 maybe this needs to start in releng or something, but how long do we think it might be before we need an app/tracker for snap packages or flatpacks 18:21:04 I need to get my Ansible infra rebuilt and refresh my memory on how to use it 18:21:14 I think the last time I was here we might have been migrating over to it 18:21:31 aikidouke: I think thats a ways out. :) 18:21:47 lousab, so what I think we are looking for right now would be a nagios file just like you would use on your other places htat would monitor a website 18:22:22 :) ack - was typing that out waiting to hit enter, guess im not good at waiting 18:22:39 and sorry lousab: did not mean to step on your toes 18:22:40 aikidouke, releng would be better 18:22:47 thanks 18:23:08 aikidouke: neither snappy nor flatpack is what I would consider ready for widespread use, despite PR people saying so. ;) 18:23:27 aikidouke: no problems :) 18:23:37 bwood09, my plan is to make a set of templates for hosts like we have in the ./roles/nagios/client/templates/check_fedmsg_gateway_proc.cfg.j2 but for services and hosts 18:23:41 :) 18:24:04 smooge: ok right 18:24:12 so lousab and bwood09 what I would like is a file that meets that 18:24:15 smooge, that makes sense 18:24:50 so when looking at say fedoramagazine we want to be able to change that out to be fedoraproject or ask.fedoraproject or ... 18:25:05 I'll need to get back in and look at that file 18:25:19 those files use a {{{ }}} variable substitution 18:25:59 so write the configs with sya fedoramagazine in mind but then look at 'this could be a var' in comments 18:26:37 that way the work is being done once and can be 'redone' when time is ready 18:27:02 for general help on what oges in the files.. I have to work on that this weekend 18:27:11 does that help? 18:27:23 makes sense to me 18:27:56 smooge: ok i'll find you because i'm starting to use ansible now so solving this ticket means undestarnd for me also how ansible works 18:28:04 cool 18:28:17 same here 18:28:25 any other questions? 18:28:46 How much incident management stuff do we do? A lot of my recent professional experience is in that area 18:29:27 we don't have incidents. we have unicorns and butterflies 18:29:44 lol I can see that ;) 18:30:07 lol 18:30:36 and http://media-cache-ak0.pinimg.com/736x/bf/3f/4c/bf3f4c4e4cbc909f957f939bb6bc7cc6.jpg 18:30:41 if a butterfly flaps its wings in the phx2 data center.... 18:30:51 puiterwijk, is our security lead. 18:30:56 aikidouke: we're fine, it's the other end of the world that's not :) 18:31:07 lol 18:31:29 puiterwijk is in another meeting I think so I would aim a question towards his email to find out 18:31:53 truth is we have some but not that many 18:32:01 (luckily) 18:32:26 I work at Navy Federal Credit Union now and omg so many actual incidents it's crazy 18:32:54 somehow, I can imagine that :) 18:32:57 would it help to review our, what are they called, security guidelines? who to report X to, etc 18:33:03 We have some documents of how to manage incidents that I'm updating and writing some more. But I try to make sure we have as few incidents as possible. If you have any specific questions, please let me know 18:33:18 we have CSI for that process currently... 18:33:25 puiterwijk, if there's anything I can do to help out, I'd be happy to 18:33:25 thanks nirik 18:33:35 nirik: right. That CSI is what I'm reading through and updating 18:33:36 https://docs.fedoraproject.org/en-US/Community_Services_Infrastructure/1/html/Security_Policy/index.html 18:33:42 puiterwijk: excellent. 18:33:59 I'm also writing a bunch of documents for myself and others of what to do for specific roles/services. 18:34:11 there are probably a few hosts that need CSI variables updated/added still 18:34:19 that is a good place to start 18:34:20 yes, there's a number of them. ;) 18:34:24 patches welcome. 18:34:35 Yep, absolutely. If anyone sees any open or outdated CSI variables, fixes are welcome 18:34:58 145 groups w/o csi variables 18:35:10 aikidouke: yes but i didn't really understod how to..i mean i've undestood iptables roles but how can we start? 18:35:18 I am trying to understand how to codument those and will probably start shipping patches this weekend 18:35:37 good q lousab 18:35:53 theres a section on them on the apprentice page... and also some previous patches on the list right now. 18:35:59 though I will need to get the feeling on how to set security categories 18:36:04 athos: cool, thanks 18:36:05 so - updating CSI vars takes a bit of research 18:36:21 reading through the security doc nirik linked will help 18:36:29 oh, I did 18:36:39 if you are unsure, make an educated guess, then ask 18:36:48 ack 18:37:26 you can get a feel for the categories, by looking at existing configurations 18:37:39 I am trying to figure out if I can write some scripts to set the relationships 18:37:48 for example - if mirrormanager went down - that would be bad.... 18:38:19 for everyone :) 18:38:39 walk through each of the tasks for one particular service - see what it depends on 18:38:45 it's one of these apps where nagios is slower than our users :) 18:39:06 grep through everything else to see what depends on the service/host you are looking at 18:39:14 :) 18:39:20 thx :) 18:40:00 dont be afraid to make a mistake - I've made them and noone shows up at your house to take away your birthday 18:40:24 I would hope the birthday police don't show up 18:40:24 nirik: could you please tell me exactly what section? of course when you have time...:) 18:40:33 although not aging would be cool 18:40:34 For the most part, the worst you are going to get is a hohoho email from me 18:40:44 :) 18:40:54 https://fedoraproject.org/wiki/Infrastructure_Apprentice#Longer_term_quests 18:40:55 please take away 8 or 9 of my bdays! 18:41:01 bwood09: the problem is: you get older but w/o the cakes 18:41:04 haha...same here 18:41:06 ooooooooh 18:41:11 (even if the cake is a lie) 18:41:15 lol 18:41:28 it wouldn't be a triumph anymore 18:41:31 im getting us off track...sorry 18:41:32 no huge success 18:41:36 lol yeah me too sorry 18:43:16 ok back on topic 18:43:20 any other questions? 18:43:44 I will move to open floor 18:43:48 #topic Open Floor 18:44:15 FYI, the go/no-go meeting just ended a few minutes ago... and we are go for f24 release next tuesday. ;) 18:44:22 yay 18:44:23 \o/ 18:44:25 \ó/ 18:44:30 awesome :) 18:44:44 great :D 18:44:51 so get your f24 ++ cookies while you can 18:44:53 * pingou got to step away 18:45:03 thanks for chairing smooge and nirik :) 18:45:15 ok pingou night 18:45:27 ok I think we are done for today anyway 18:45:31 going once 18:45:33 :) 18:45:35 going twice 18:45:36 I would like to propose replacing the word "spam" with "fish" from now on. My blood triggers anytime I read the word "spam" now, so I want to change it slightly :) 18:45:59 I had a gif somewhere... lol 18:45:59 18:46:00 puiterwijk: and vice-versa? 18:46:05 canned spiced ham? 18:46:06 pingou: sure 18:46:19 puiterwijk: so are dolphin spam or mamals? 18:46:35 #endmeeting