Page MenuHomePhabricator

Decommission labcontrol1001 & labcontrol1002
Closed, ResolvedPublic

Description

labcontrol1001:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp (replace with role::spare if system isn't shut down immediately during this process.)

Steps for DC-Ops:
The following steps cannot be interrupted, as it will leave the system in an unfinished state.
Start non-interrupt steps:

  • - disable puppet on host
  • - power down host
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate (handled by wmf-decommission-host)
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key (handled by wmf-decommission-host)

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - change netbox status to offline when unracked

labcontrol1002:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp (replace with role::spare if system isn't shut down immediately during this process.)

Steps for DC-Ops:
The following steps cannot be interrupted, as it will leave the system in an unfinished state.
Start non-interrupt steps:

  • - disable puppet on host
  • - power down host
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate (handled by wmf-decommission-host)
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key (handled by wmf-decommission-host)

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - change netbox status to offline when unracked

Event Timeline

Change 506345 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] Move labcontrol1001/1002 to role::spare and clean up references

https://gerrit.wikimedia.org/r/506345

Andrew renamed this task from Reclaim/Decommission labcontrol1001, 1002 to Decommission labcontrol1001, 1002.Apr 25 2019, 4:27 PM

Change 506345 merged by Andrew Bogott:
[operations/puppet@production] Move labcontrol1001/1002 to role::spare and clean up references

https://gerrit.wikimedia.org/r/506345

Andrew updated the task description. (Show Details)
Andrew added a subscriber: RobH.

@RobH, I'm supposed to assign decom hosts to you at this point, right?

RobH updated the task description. (Show Details)

labcontrol1001:asw2-c-eqiad:ge-5/0/32
labcontrol1002:asw2-c-eqiad:ge-7/0/26

@RobH, I'm supposed to assign decom hosts to you at this point, right?

Yep! Basically once we get to the point of disabling puppet and powering down a host, it also has to immediately have the switch port disabled. So only folks who can change switch config should do those steps.

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: labcontrol1001.wikimedia.org

  • labcontrol1001.wikimedia.org
    • Removed from Puppet master and PuppetDB
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Removed from DebMonitor

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: labcontrol1002.wikimedia.org

  • labcontrol1002.wikimedia.org
    • Removed from Puppet master and PuppetDB
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Removed from DebMonitor
RobH triaged this task as Medium priority.Apr 25 2019, 10:59 PM
RobH added a project: ops-eqiad.
RobH updated the task description. (Show Details)
RobH moved this task from Backlog to Decommission on the ops-eqiad board.
RobH moved this task from Backlog to Ready for Decommission on the decommission-hardware board.

Change 506567 had a related patch set uploaded (by RobH; owner: RobH):
[operations/dns@master] labcontrol100[12] production dns decom

https://gerrit.wikimedia.org/r/506567

Change 506567 merged by RobH:
[operations/dns@master] labcontrol100[12] production dns decom

https://gerrit.wikimedia.org/r/506567

Change 506569 had a related patch set uploaded (by RobH; owner: RobH):
[operations/puppet@production] decom labcontrol100[12]

https://gerrit.wikimedia.org/r/506569

Change 506569 merged by RobH:
[operations/puppet@production] decom labcontrol100[12]

https://gerrit.wikimedia.org/r/506569

RobH removed a project: Patch-For-Review.
RobH updated the task description. (Show Details)
RobH renamed this task from Decommission labcontrol1001, 1002 to Decommission labcontrol1001 & labcontrol1002.Apr 25 2019, 11:49 PM
Cmjohnson added a subscriber: Cmjohnson.

John, please wipe the servers, remove from the rack, update netbox and the tracking sheet. Assign back to me once you finish so I can kill the switch ports.

papaul@asw2-c-eqiad# show | compare 
[edit interfaces]
-   ge-5/0/32 {
-       description labcontrol1001;
-   }
-   ge-7/0/26 {
-       description labcontrol1002;
-   }

Change 544075 had a related patch set uploaded (by Papaul; owner: Papaul):
[operations/dns@master] DNS: Remove mgmt DNS for labcontrol100[1-2]

https://gerrit.wikimedia.org/r/544075

Change 544075 merged by Papaul:
[operations/dns@master] DNS: Remove mgmt DNS for labcontrol100[1-2]

https://gerrit.wikimedia.org/r/544075

Papaul updated the task description. (Show Details)

Complete