Page MenuHomePhabricator

nova-fullstack: add cleanup checking
Open, MediumPublic

Description

Our designate-sink hooks break a lot. The parts that create dns entries are tested by nova-fullstack, but we should also check that cleanup happens properly:

  1. Does the dns entry go away after the VM is deleted?
  2. Does the puppet cert get cleaned up after the VM is deleted?

If we leak and alert on those failures we can at least reduce the swarms of things that we leak whenever designate changes slightly.

Event Timeline

Change 542170 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] nova-fullstack tests: add a test for dns cleanup post-delete

https://gerrit.wikimedia.org/r/542170

Change 542170 merged by Andrew Bogott:
[operations/puppet@production] nova-fullstack tests: add a test for dns cleanup post-delete

https://gerrit.wikimedia.org/r/542170

Change 542201 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] cloud puppetmasters: allow nova controllers to use the certmanager account

https://gerrit.wikimedia.org/r/542201

Change 542202 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] nova-fullstack: add puppet cert monitoring

https://gerrit.wikimedia.org/r/542202

Change 542201 merged by Andrew Bogott:
[operations/puppet@production] cloud puppetmasters: allow nova controllers to use the certmanager account

https://gerrit.wikimedia.org/r/542201

Change 542202 merged by Andrew Bogott:
[operations/puppet@production] nova-fullstack: add puppet cert monitoring

https://gerrit.wikimedia.org/r/542202

Bstorm triaged this task as Medium priority.Feb 11 2020, 4:21 PM