Page MenuHomePhabricator

decommission cp1008, cp1071, cp1072, cp1073, cp1074, cp1099
Closed, ResolvedPublicRequest

Description

This task will track the decommission-hardware of servers cp1008, cp1071, cp1072, cp1073, cp1074, cp1099.

The first 5 steps should be completed by the service owner that is returning the server to DC-ops (for reclaim to spare or decommissioning, dependent on server configuration and age.)

cp1008

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps,

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host - done by decom cookbook run
  • - power down host - done by decom cookbook run
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port - done by decom cookbook run
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate - done by decom cookbook run
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key - done by decom cookbook run

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

cp1071

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host - done by decom cookbook run
  • - power down host - done by decom cookbook run
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port - done by decom cookbook run
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate - done by decom cookbook run
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key - done by decom cookbook run

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

cp1072

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host
  • - power down host
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate (handled by wmf-decommission-host)
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key (handled by wmf-decommission-host)

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

cp1073

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host - done by decom cookbook run
  • - power down host - done by decom cookbook run
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port - done by decom cookbook run
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate - done by decom cookbook run
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key - done by decom cookbook run

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

cp1074

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host - done by decom cookbook run
  • - power down host - done by decom cookbook run
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port - done by decom cookbook run
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate - done by decom cookbook run
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key - done by decom cookbook run

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

cp1099

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system)
  • - unassign service owner from this task, check off completed steps

Steps for DC-Ops:

The following steps cannot be interrupted, as it will leave the system in an unfinished state.

Start non-interrupt steps:

  • - disable puppet on host - done by decom cookbook run
  • - power down host - done by decom cookbook run
  • - update netbox status to Inventory (if decom) or Planned (if spare)
  • - disable switch port - done by decom cookbook run
  • - switch port assignment noted on this task (for later removal)
  • - remove all remaining puppet references (include role::spare)
  • - remove production dns entries
  • - puppet node clean, puppet node deactivate - done by decom cookbook run
  • - remove dbmonitor entries on neodymium/sarin: sudo curl -X DELETE https://debmonitor.discovery.wmnet/hosts/${HOST_FQDN} --cert /etc/debmonitor/ssl/cert.pem --key /etc/debmonitor/ssl/server.key - done by decom cookbook run

End non-interrupt steps.

  • - system disks wiped (by onsite)
  • - IF DECOM: system unracked and decommissioned (by onsite), update racktables with result
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: system added back to spares tracking (by onsite)

Event Timeline

BBlack created this task.Aug 1 2019, 4:00 PM
Restricted Application added a project: Operations. · View Herald TranscriptAug 1 2019, 4:00 PM

Change 527134 had a related patch set uploaded (by BBlack; owner: BBlack):
[operations/puppet@production] eqiad cp decom cleanup

https://gerrit.wikimedia.org/r/527134

Change 527134 merged by BBlack:
[operations/puppet@production] eqiad cp decom cleanup

https://gerrit.wikimedia.org/r/527134

Change 527145 had a related patch set uploaded (by BBlack; owner: BBlack):
[operations/dns@master] pink unicorn death

https://gerrit.wikimedia.org/r/527145

Script wmf-auto-reimage was launched by bblack on cumin1001.eqiad.wmnet for hosts:

['cp1008.wikimedia.org', 'cp1071.eqiad.wmnet', 'cp1072.eqiad.wmnet', 'cp1073.eqiad.wmnet', 'cp1074.eqiad.wmnet', 'cp1099.eqiad.wmnet']

The log can be found in /var/log/wmf-auto-reimage/201908011643_bblack_108239.log.

Change 527145 merged by BBlack:
[operations/dns@master] pink unicorn death

https://gerrit.wikimedia.org/r/527145

Completed auto-reimage of hosts:

['cp1073.eqiad.wmnet', 'cp1074.eqiad.wmnet', 'cp1072.eqiad.wmnet', 'cp1071.eqiad.wmnet', 'cp1099.eqiad.wmnet', 'cp1008.wikimedia.org']

and were ALL successful.

BBlack added a comment.Aug 1 2019, 5:14 PM

These are ready to go for dcops-level work!

Change 527173 had a related patch set uploaded (by Volans; owner: Volans):
[operations/cookbooks@master] sre.hosts.upgrade-varnish: cp1008 decom cleanup

https://gerrit.wikimedia.org/r/527173

Change 527175 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] acme_chief: replace cp1008 with cp1099 as authorized host

https://gerrit.wikimedia.org/r/527175

Change 527177 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] varnish wikimedia-backend.vcl: replace cp1008 with cp1099

https://gerrit.wikimedia.org/r/527177

Change 527180 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] puppetmaster::frontend: remove cp1008 as a canary host

https://gerrit.wikimedia.org/r/527180

Change 527177 abandoned by Dzahn:
varnish wikimedia-backend.vcl: replace cp1008 with cp1099

Reason:
https://gerrit.wikimedia.org/r/c/operations/puppet/ /527209

https://gerrit.wikimedia.org/r/527177

Change 527180 abandoned by Dzahn:
puppetmaster::frontend: remove cp1008 as a canary host

Reason:
https://gerrit.wikimedia.org/r/c/operations/puppet/ /527209

https://gerrit.wikimedia.org/r/527180

Change 527175 abandoned by Dzahn:
acme_chief: replace cp1008 with cp1099 as authorized host

Reason:
https://gerrit.wikimedia.org/r/c/operations/puppet/ /527209

https://gerrit.wikimedia.org/r/527175

Change 527173 merged by jenkins-bot:
[operations/cookbooks@master] sre.hosts.upgrade-varnish: cp1008 decom cleanup

https://gerrit.wikimedia.org/r/527173

Cmjohnson moved this task from Backlog to Decommission on the ops-eqiad board.Aug 8 2019, 3:17 PM

cookbooks.sre.hosts.decommission executed by volans@cumin1001 for hosts: cp1072.eqiad.wmnet

  • cp1072.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB
Volans updated the task description. (Show Details)Nov 8 2019, 3:21 PM

Change 565241 had a related patch set uploaded (by Ema; owner: Ema):
[operations/puppet@production] cache: remove cp1071, cp1099 hieradata

https://gerrit.wikimedia.org/r/565241

Change 565241 merged by Alexandros Kosiaris:
[operations/puppet@production] cache: remove cp1071, cp1099 hieradata

https://gerrit.wikimedia.org/r/565241

faidon added a subscriber: faidon.Jan 23 2020, 12:59 PM

Traffic team, ping? This task has been open since August last year and as I was just saying on IRC, cp1008 is a constant outlier in all of our reports, projections, planning etc. Its purchase date is Jan 27th, 2011, 9 years ago almost to the day :)

RobH reassigned this task from RobH to Volans.Jan 23 2020, 4:10 PM
RobH removed Volans as the assignee of this task.Jan 23 2020, 5:26 PM
RobH added a subscriber: Volans.
faidon assigned this task to RobH.Jan 23 2020, 5:27 PM

(@Volans is not in Traffic), but regardles... judging from @BBlack comments before the flurry of Gerrit commits, it seems like I misunderstood where this lies. This is not blocked on Traffic, but with DC Ops. Reassigning to @RobH and apologies for the added confusion!

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: cp1008.wikimedia.org

  • cp1008.wikimedia.org (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: cp1073.eqiad.wmnet

  • cp1073.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: cp1074.eqiad.wmnet

  • cp1074.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: cp1099.eqiad.wmnet

  • cp1099.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

cookbooks.sre.hosts.decommission executed by robh@cumin1001 for hosts: cp1071.eqiad.wmnet

  • cp1071.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB
RobH reassigned this task from RobH to Jclark-ctr.Jan 23 2020, 6:07 PM
RobH updated the task description. (Show Details)
RobH moved this task from Backlog to pending onsite steps (eqiad) on the decommission-hardware board.
RobH added a subscriber: Jclark-ctr.

@Jclark-ctr:

These hosts are ready for the on-site wipe steps. I've also left the puppet and dns updates, so during our off-site during all hands we can show you how to push these commits to our gerrit server for merge.

RobH removed a subscriber: RobH.Jan 23 2020, 6:14 PM
Jclark-ctr updated the task description. (Show Details)Feb 5 2020, 11:15 PM
Jclark-ctr added a subscriber: RobH.
RobH removed a subscriber: RobH.Mar 3 2020, 6:01 PM

Change 579223 had a related patch set uploaded (by Muehlenhoff; owner: Muehlenhoff):
[operations/puppet@production] Remove some stray Puppet references to cp1008, cp1071-cp1074

https://gerrit.wikimedia.org/r/579223

Change 579223 merged by Muehlenhoff:
[operations/puppet@production] Remove some stray Puppet references to cp1008, cp1071-cp1074

https://gerrit.wikimedia.org/r/579223

MoritzMuehlenhoff added a subscriber: RobH.

Change 579226 had a related patch set uploaded (by Muehlenhoff; owner: Muehlenhoff):
[operations/dns@master] Remove prod DNS entries for cp1008, cp1071-cp1074

https://gerrit.wikimedia.org/r/579226

Change 579226 merged by Muehlenhoff:
[operations/dns@master] Remove prod DNS entries for cp1008, cp1071-cp1074

https://gerrit.wikimedia.org/r/579226

RobH removed a subscriber: RobH.Mar 12 2020, 2:45 PM

Change 580087 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] site/DHCP: remove cp1099

https://gerrit.wikimedia.org/r/580087

Change 580089 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/dns@master] remove production IPs for cp1099

https://gerrit.wikimedia.org/r/580089

Change 580091 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/dns@master] remove mgmt IPs for cp1099

https://gerrit.wikimedia.org/r/580091

Change 580087 merged by Dzahn:
[operations/puppet@production] site/DHCP: remove cp1099

https://gerrit.wikimedia.org/r/580087

Change 580089 merged by Dzahn:
[operations/dns@master] remove production IPs for cp1099

https://gerrit.wikimedia.org/r/580089

Change 580091 abandoned by Dzahn:
remove mgmt IPs for cp1099

Reason:
already done by somebody else

https://gerrit.wikimedia.org/r/580091

RobH updated the task description. (Show Details)Apr 1 2020, 5:00 PM
RobH removed a project: DC-Ops.
RobH added a subscriber: RobH.
RobH updated the task description. (Show Details)Apr 1 2020, 5:34 PM
RobH removed a subscriber: RobH.

all dns and network switch records have been removed, servers have already been sold

Cmjohnson closed this task as Resolved.May 13 2020, 6:44 PM