Commit Graph

220 Commits

Author SHA1 Message Date
James E. Blair 3b01cd6afc Add zuul-db01
Change-Id: I9f15b0d1117a7ea88d55332b0a359e42e164e673
2024-04-04 09:45:40 -07:00
Jeremy Stanley 38d39d12d1 Switch the keycloak CNAME to the new server
This puts the newer replacement server into production use.

Change-Id: I29683a2dce2c86cfc8a9f7067f85add07a2eb93a
2024-02-09 17:27:28 +00:00
Jeremy Stanley b5f14a07c8 Add DNS entries for another new Keycloak server
This is a new server in preparation for the keycloak upgrade in
change I01f8045563e9f6db6168b92c5a868b8095c0d97b. The previous one
is also removed by this change, since it did not have the correct
CPU flags to run the latest Keycloak container images.

Change-Id: Ia98d1309dd5a608771732592e2bf3752ecaa1114
2024-02-09 17:26:12 +00:00
Jeremy Stanley 94978d191f Add DNS entries for new Keycloak server
This is a new server in preparation for the keycloak upgrade in
change I01f8045563e9f6db6168b92c5a868b8095c0d97b.

Change-Id: Iad3f5d61e7927e39968d2fccaa5e953b36e0ecf3
2024-02-07 21:04:05 +00:00
Tony Breeds 6f44eb9005 Remove old mirror nodes from DNS
Depends-On: https://review.opendev.org/c/opendev/system-config/+/902715

Change-Id: Iee9da288cd47f549a975e7e59a0e555860e1e5ba
2023-12-05 12:37:08 -06:00
Jeremy Stanley b8bb92123e Add an SPF record for the listserv
Recently, Gmail has started to rate-limit deliveries from our
mailing list server, with this message:

    SMTP error from remote mail server after end of data: This mail
    has been rate limited because it is unauthenticated. Gmail
    requires all senders to authenticate with either SPF or DKIM.

According to https://support.google.com/mail/answer/81126 also:

    Starting February 2024, Gmail will require the following for
    senders who send 5,000 or more messages a day to Gmail accounts:
    Authenticate outgoing email, avoid sending unwanted or
    unsolicited email, and make it easy for recipients to
    unsubscribe.

In order not to place undue additional load on our MTA's deferral
queue, adding a neutral SPF rule is nicer than unsubscribing and
blocking all Gmail users. A simple "a" rule should suffice, since we
don't relay through any smarthost currently. Set the TTL to 5
minutes for now, in case we need to make rapid adjustments to this
policy in the near future.

Change-Id: Ifc4a58e90ee6652cc65ed04ce619ac9b4f1b05a3
2023-12-05 18:10:18 +00:00
Tony Breeds b10312303b Switch CNAME records to new mirrors
Update the CNAME records for mirror.dfw.rax, mirror.gra1.ovh and mirror.bhs1.ovh

Change-Id: I086e78a7c52fe10abc89a351b5a226838e2e616a
2023-11-28 11:40:40 -06:00
Tony Breeds c7f934d607 Add DNS records for mirror02.dfw.rax
Change-Id: Ife0944ebb31a475453f24fcec46f25939ca37c11
2023-11-27 15:38:30 -06:00
Tony Breeds 2de84703fe Add DNS records for mirror02.bhs1.ovh and mirror03.gra1.ovh
Change-Id: Icf7f12403665850337bf772a2375673a06479249
2023-11-21 19:59:14 -06:00
Tony Breeds 58384ae107 Switch CNAME for mirror.ord.rax to new mirror02 node
Change-Id: I1c1d418852f9fb07271812737b441c4fb7f4367a
2023-11-17 12:44:29 -06:00
Tony Breeds 4df0ad1218 Add DNS records for mirror02.ord.rax
New replacement host for the old 01 server is coming online.

Change-Id: I9cf37ecf21fab1033f169af7dd481d5ae47cccdb
2023-11-14 11:29:21 -06:00
James E. Blair def2776864 Replace ze10-ze12
Change-Id: I2edcdca8f32f97f27a9ddca40b690d504aa8754c
2023-06-27 11:20:13 -07:00
James E. Blair 74e4fbd6dc Replace ze07-ze09
Change-Id: I196d880d811b6e89918f857930dac639332e500c
2023-06-27 11:20:01 -07:00
James E. Blair 7583e304cf Replace ze04-ze06
Change-Id: I37fbc868d886b41995177aae52ec96308375b903
2023-06-27 11:19:49 -07:00
James E. Blair 0c27d7b9b0 Replace ze01-ze03
Change-Id: I2fe78c21bcf916f4df0218cf29fd92bc72bc8df3
2023-06-27 11:19:34 -07:00
Clark Boylan 36f95f4c10 Remove insecure-ci-registry01 and update CNAME to 02
This will put the new server into production.

Depends-On: https://review.opendev.org/c/opendev/system-config/+/885421
Change-Id: If3e86f25266e1134926e386a02416b8cc5ea0be4
2023-06-23 13:22:54 -07:00
Clark Boylan bfed0fc31f Add DNS records for insecure-ci-registry02
New replacement host for the old 01 server is coming online.

Change-Id: Ia2898ee26f182391084047d11a97e45fddd39727
2023-06-23 13:21:18 -07:00
James E. Blair 415678179c Update serial on zone file
The previous revert incorrectly reverted the serial instead of
advancing it.

Change-Id: I0d6def41648f74f5ca2b25ec4f77dde1ab2bca91
2023-06-04 08:13:33 -07:00
James E. Blair f8cb14f055 Revert "Replace ze01-ze06"
This reverts commit 20ea24f5d0.

There is a problem with openafs.

Change-Id: I42fa6b78d038705efa7f583c07183cd6e55e9265
2023-06-03 17:51:10 -07:00
James E. Blair 20ea24f5d0 Replace ze01-ze06
Change-Id: I69b731bbb6483cd75feb768f92f2e8e18760aafa
2023-06-02 17:38:11 -07:00
James E. Blair 050e31dc10 Convert spaces to tabs
We prefer consistency, and we're about to make a bunch of changes,
so let's remove any spaces that snuck in.

Courtesy of M-x tabify.

Change-Id: I8e89c586b1ed2e3caa46bab004082cf0c9f77017
2023-06-02 17:35:16 -07:00
Clark Boylan 4a5b77e221 Remove zp01 from DNS
The server should be gone at this point. Remove its DNS records.

Depends-On: https://review.opendev.org/c/opendev/system-config/+/885078
Change-Id: I6842e1e851028895615e6becfdba730673e5373f
2023-06-01 10:10:10 -07:00
Clark Boylan 610cda5543 Add zp02 to DNS
This also updates the zuul-preview wildcard CNAME record to point on
zp02. We should ensure the new server is running services before landing
this change.

Depends-On: https://review.opendev.org/c/opendev/system-config/+/885076
Change-Id: I09da63c469dbb47ab7ea31039537c34bb7135332
2023-06-01 10:08:01 -07:00
James E. Blair 9213f7b075 Replace all zuul mergers
These are the new zm* hosts.

Change-Id: I7a0710a5e25379b698a918434404a40824dc8ea3
2023-05-24 13:17:26 -07:00
Ian Wienand 3fd86c90b3
Remove old DNS servers
These are no longer in use, and are currently shutdown.  Remove their
records.

Change-Id: I0b17ac4e5c397635349d0cef4c6719fd1f42a010
2023-05-02 09:39:11 +10:00
Ian Wienand ab172a760d
Remove old nameservers
These have been replaced with the Jammy refresh servers.  This should
be done after the registry is udpated to point to the new servers.

Change-Id: I862b55d1bbed314d6be9fe77ca9a5444ca6455e9
2023-04-21 13:05:30 +10:00
Ian Wienand afa9ab9e9a
Add Jammy refresh NS records
Add the Jammy refresh nameservers to the NS records.  This should be
done before updating the registry records.

Change-Id: Ie55a519175f28eedc91e7e9236faf9791abb6793
2023-04-21 13:04:54 +10:00
Clark Boylan 80bf281c55 Cleanup etherpad DNS records
This change makes a number of cleanups to the etherpad DNS records:

  * Remove etherpad-dev record as this server no longer exists.
  * Remove old etherpad01 production server as etherpad02 is now in use.
  * Reset TTL to default 3600 for etherpad.o.o CNAME etherpad02.
  * Cleanup tabbing so that related records have similar alignment.

Change-Id: I6a732d2f5c960e6192333c0be1f8842284f2495b
2023-04-19 09:54:29 -07:00
Clark Boylan e0e97bf791 Update etherpad.o.o to point at etherpad02
This updates etherpad.opendev.org CNAME etherpad01 to etherpad02 as the
target which will change the production etherpad server. For this reason
landing this change needs to happen when both etherpad services are
stopped. Then we can migrate the database while this change lands. Once
the db migration is complete we can start the services back on only 02
and wait for DNS to propagate.

Change-Id: Ib1f6379a2d3bf1f74c67db9ffd303eb86ea2ba0a
2023-04-19 09:54:02 -07:00
Ian Wienand 7f21ac42e7
Add DNS servers for Ubuntu Jammy refresh
Note these are not active, and we will switch the NS records after
they have deployed.

Change-Id: I8320e2b91b2652128ec0b16ee46981940a41d8cc
2023-04-17 15:54:35 +10:00
Clark Boylan 24f6623569 Remove old static01 records
This server is no longer needed. Remove its records. Note this should
only be merged once we are happy with the new static02 server. I reset
the static.o.o CNAME ttl to its default value in this change for that
reason.

Change-Id: Id9484c3e8e19bc331f4555377b318d1e872062e7
2023-04-06 11:09:08 -07:00
Clark Boylan 9f17e09656 Update static.o.o CNAME to point at static02
This is a new jammy static afs backed webserver. We temporarily lower
the record TTL to 300 seconds in case this needs to be reverted for some
reason. We will reset the TTL when we clean up static01 records after
deciding the old server isn't necessary anymore.

Change-Id: I79d0c683a14417758061729a010fc1e5b20ad470
2023-04-06 11:06:48 -07:00
Clark Boylan 8fea73262b Add etherpad02 to DNS
This is a new jammy replacement for etherpad01. We will need to take a
short downtime to transplant databases and update the DNS cnme for
etherpad.opendev.org. It is for this reason I've reduced the TTL on the
etherpad.opendev.org CNAME record now.

Change-Id: Ibff9657bc349deba834d64bf452842882c9eb290
2023-04-03 14:41:48 -07:00
Clark Boylan 0db31f955f Add static02
This is a new jammy replacement for static01

Change-Id: Ie3ce4d8b86dbaba83ab93ffb91a4f92cc5447adf
2023-04-03 14:15:15 -07:00
Clark Boylan 91af3efeb2 Remove gitea01-04 server DNS records
These servers have been removed from config management and have been
deleted. We don't need DNS records for them anymore.

Change-Id: If0dcf928e13f427a44391959fe50e7d9ce48c9b0
2023-03-27 08:18:43 -07:00
Clark Boylan 18a22b37f3 Remove gitea05-07 from DNS
These servers have been deleted as they were replaced by gitea10-12.

Change-Id: Ie4de0c56edbc7cd6568f15d9246565310fed34e4
2023-03-10 10:42:48 -08:00
Clark Boylan dfb09efb55 Add gitea13 and gitea14 to DNS
This also removes gitea08 (which has been deleted) because gitea14
recycles its IP address.

Change-Id: I49f17aef4ebefc79f0e990ff14072c0b5b569d52
2023-03-08 11:49:51 -08:00
Clark Boylan 305aec4805 Add gitea10-12 to DNS
These servers will replace older gitea05-07 servers.

Change-Id: Iec3947a650a8eec8501a01f1aa4333dc77d24c0a
2023-03-02 10:17:49 -08:00
Clark Boylan 13f912ce1f Add gitea09 to DNS
This adds the new gitea09 server to DNS. THis change is necessary for
LE cert provisioning. Also I added a AAAA record even though the other
giteas don't have one.

Change-Id: I10563283b58547ac589e317632b1a179ee597916
2023-02-15 16:36:24 -08:00
Ian Wienand 715d174cd9
Add nb04.opendev.org
This is a new ARM64 builder

Change-Id: Ic34acf166bab98196865b3954229f7073220fe7d
2023-01-10 15:22:44 +11:00
Ian Wienand 7cc9c67ead
Add linaro mirror DNS
Change-Id: Ib0e426a5f5c9cc596d8f5c74e5fddd563bca0fc4
2022-12-22 09:53:05 +11:00
Clark Boylan 7773d06a9a Remove iweb mirror records
This cloud provider is going away and we are shutting down the mirror.
Note the depends on is there to avoid system-config attempting to
provision LE certs after the dns records are gone.

The inap records are also removed as these were kept for backward
compatibility with the provider name change and are also no longer
required.

Depends-On: https://review.opendev.org/c/opendev/system-config/+/867267
Change-Id: Ifa6b983342f44697187191b0fa55f5b846ded443
2022-12-16 09:09:23 -08:00
Clark Boylan 0c72857290 Add bridge -> bridge01 CNAME
This will help in the future if/when bridge02 is created and swapped
over to. In particular it helps create a definite point in time when a
new server should be used instead of the old server without humans
needing to think too hard about it.

Change-Id: I471b96e6e0593d02bb50564307f44617d52b0556
2022-12-13 08:45:26 -08:00
Jeremy Stanley 7a98ceeba5 Restore the default TTL to lists
Now that we're comfortable we don't need to make any further urgent
changes, clean up the temporary TTL override.

Change-Id: I490fc7b2937d08de982074a70009fa1b8cae2d8a
2022-12-05 17:48:38 +00:00
Jeremy Stanley 45565a3045 Switch lists to resolve to the new Mailman server
With the import work complete, repoint DNS to the new server so that
deliveries will resume normally.

Change-Id: I8dfc4e805082694e9dc8370f47eb2c18ef1f7886
2022-12-05 17:48:37 +00:00
Jeremy Stanley 121f6ec0d1 Temporarily point lists to review for deferral
This is a cheap hack to get incoming messages for lists.opendev.org
to sit in senders' deferral queues while we're working on moving its
mailing lists to the new server. The firewall rules for
review02.opendev.org are set up to reject connections on 25/tcp,
which causes connecting MTAs to wait and try again after some period
of time. Once we update the records to match the new server instead,
any queued deliveries should arrive normally.

Change-Id: I9e4db643f4bbf66bb19c6f33eff5f3556fbba24e
2022-12-05 17:47:52 +00:00
Jeremy Stanley b49b2aabfb Temporarily lower the address TTLs for lists
Maintenance is coming up in a few hours, during which lists will
have its DNS records changed at least a couple of times, so lower
the TTL on those in advance in order to facilitate faster global
updates.

Change-Id: Ic8986f843a16a00f725842a8201ea38d621f1130
2022-12-05 16:59:11 +00:00
Jeremy Stanley 6d7bf8e38a Add lists01 to DNS
Change-Id: Iaf17b569a97d09eca53a83774e64e6e851a3f2f5
2022-11-23 02:21:12 +00:00
Clark Boylan 06b05336e3 Remove gitea-lb01 and jvb02 from DNS
These servers have been removed. Gitea-lb01 was replaced by gitea-lb02,
and jvb02 is simply unneeded for current scaling needs.

Depends-On: https://review.opendev.org/c/zuul/zuul-jobs/+/863098
Change-Id: I9c7efc728ec4a28362dac4c4e79e4409fe154792
2022-10-31 19:21:54 +00:00
Ian Wienand 396846367e
Bump serial number
... to trigger deployment job that failed due to system-config issues

Change-Id: I483932b7047d0ad43be478aebd2a724caec2d7e2
2022-10-25 13:35:38 +11:00