Page MenuHomePhabricator

Decommission es2001, es2002, es2003, es2004
Closed, ResolvedPublic

Description

es2001,2,3,4 were old hosts which were replaced by es201* hosts. However, due to the lack of space elsewhere, it was requested to keep them for external store backups of non-read only hosts, and later, for backup target of metadata and misc databases.

dbprov and the new bacula shelves were setup, replacing this functionality. So these 4 hosts are ready for decommission.

es2001

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of servee.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.

es2002

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of servee.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.

es2003

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of servee.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.

es2004

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of servee.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.

Event Timeline

jcrespo changed the task status from Open to Stalled.May 6 2019, 9:33 AM

Blocked on bacula setup.

Change 592617 had a related patch set uploaded (by Jcrespo; owner: Jcrespo):
[operations/puppet@production] Decommission es2001, es2002, es2003, es2004

https://gerrit.wikimedia.org/r/592617

jcrespo changed the task status from Stalled to Open.Apr 27 2020, 9:16 AM
jcrespo updated the task description. (Show Details)
jcrespo updated the task description. (Show Details)

Change 592617 merged by Jcrespo:
[operations/puppet@production] Decommission es2001, es2002, es2003, es2004

https://gerrit.wikimedia.org/r/592617

cookbooks.sre.hosts.decommission executed by jynus@cumin2001 for hosts: es2001.codfw.wmnet

  • es2001.codfw.wmnet (PASS)
    • Downtimed host on Icinga
    • Found physical host
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by jynus@cumin2001 for hosts: es2002.codfw.wmnet

  • es2002.codfw.wmnet (PASS)
    • Downtimed host on Icinga
    • Found physical host
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by jynus@cumin2001 for hosts: es2003.codfw.wmnet

  • es2003.codfw.wmnet (PASS)
    • Downtimed host on Icinga
    • Found physical host
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by jynus@cumin2001 for hosts: es2004.codfw.wmnet

  • es2004.codfw.wmnet (PASS)
    • Downtimed host on Icinga
    • Found physical host
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

Change 592623 had a related patch set uploaded (by Jcrespo; owner: Jcrespo):
[operations/dns@master] Remove es2001-4 DNS but leaving asset tags for decommission

https://gerrit.wikimedia.org/r/592623

Change 592623 merged by Jcrespo:
[operations/dns@master] Remove es2001-4 entries for decommission, but not touching asset tags

https://gerrit.wikimedia.org/r/592623

jcrespo removed a project: Patch-For-Review.
jcrespo updated the task description. (Show Details)
jcrespo added a subscriber: RobH.

One year later, this is ready for full decommissioning.

Note: @Papaul These hosts used to contain all Wiki content, so disk should be wiped. Some, at least 2, may have failed already and were never replaces (as requested), FYI.

Obviously, this has little priority right now, leaving you for triaging.

[edit interfaces interface-range disabled]
     member xe-7/0/6 { ... }
+    member ge-1/0/2;
[edit interfaces]
-   ge-1/0/2 {
-       description es2001;
-       enable;
-   }
[edit interfaces interface-range disabled]
     member ge-1/0/2 { ... }
+    member ge-6/0/13;
[edit interfaces]
-   ge-6/0/13 {
-       description es2002;
-       enable;
-   }
[edit interfaces interface-range vlan-private1-b-codfw]
-    member ge-1/0/5;
[edit interfaces interface-range disabled]
     member ge-3/0/23 { ... }
+    member ge-1/0/5;
[edit interfaces]
-   ge-1/0/5 {
-       description es2003;
-       enable;
-   }
[edit interfaces interface-range vlan-private1-b-codfw]
-    member ge-6/0/16;
[edit interfaces interface-range disabled]
     member ge-1/0/5 { ... }
+    member ge-6/0/16;
[edit interfaces]
-   ge-6/0/16 {
-       description es2004;
-       enable;
-   }

Change 593256 had a related patch set uploaded (by Papaul; owner: Papaul):
[operations/dns@master] DNS: Remove mgmt asset tag for es200[1-4]

https://gerrit.wikimedia.org/r/593256

Change 593256 merged by Papaul:
[operations/dns@master] DNS: Remove mgmt asset tag for es200[1-4]

https://gerrit.wikimedia.org/r/593256

Papaul updated the task description. (Show Details)

complete