Page MenuHomePhabricator

decommission phab1003.eqiad.wmnet
Open, MediumPublic

Description

This server has been temporarily assigned in T215335 and used in T221389.

After T190568 and T238956 are done decom it and give it back to dcops into the pool of spares.


This task will track the decommission of server phab1003.eqiad.wmnet.

With the launch of updates to the decom cookbook, the majority of these steps can be handled by the service owners directly. The DC Ops team only gets involved once the system has been fully removed from service and powered down by the decommission cookbook.

phab1003.eqiad.wmnet

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place.
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of server: codfw = @Papaul, eqiad = @Jclark-ctr, all other sites = @RobH.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned. If uncertain, ask @wiki_willy.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: add system to decommission tracking google sheet
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: set netbox state to 'inventory' and hostname to asset tag

Details

Related Gerrit Patches:

Event Timeline

Dzahn renamed this task from decom phab1003 to decommission phab1003.eqiad.wmnet.Nov 22 2019, 10:06 PM
Dzahn changed the task status from Open to Stalled.
Dzahn triaged this task as Medium priority.
Dzahn created this task.
Dzahn updated the task description. (Show Details)
Dzahn added subscribers: Jclark-ctr, wiki_willy, Papaul, RobH.

Change 552592 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] phabricator: remove phab1003 from list of phab servers

https://gerrit.wikimedia.org/r/552592

Change 552599 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/dns@master] remove service IPs and IPv6 for phab1003

https://gerrit.wikimedia.org/r/552599

Change 552601 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/dns@master] remove production IPs for phab1003

https://gerrit.wikimedia.org/r/552601

Change 552603 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] site: turn phab1003 into a spare::system

https://gerrit.wikimedia.org/r/552603

Change 552604 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] mtail: stop using phab1003 for tests, use phab1001

https://gerrit.wikimedia.org/r/552604

Change 552607 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] mariadb: remove grants for users on phab1003

https://gerrit.wikimedia.org/r/552607

Change 552609 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] install_server: remove phab1003

https://gerrit.wikimedia.org/r/552609

RobH removed a subscriber: RobH.Nov 23 2019, 1:08 AM

Change 552604 abandoned by Dzahn:
mtail: stop using phab1003 for tests, use phab1001

Reason:
in favor of https://gerrit.wikimedia.org/r/c/operations/puppet/ /554403

https://gerrit.wikimedia.org/r/552604

Change 552609 merged by Dzahn:
[operations/puppet@production] install_server: remove phab1003

https://gerrit.wikimedia.org/r/552609

Change 552592 merged by Dzahn:
[operations/puppet@production] phabricator: remove phab1003 from list of phab servers

https://gerrit.wikimedia.org/r/552592

Change 552603 merged by Dzahn:
[operations/puppet@production] site: turn phab1003 into a spare::system

https://gerrit.wikimedia.org/r/552603

Dzahn changed the task status from Stalled to Open.Dec 20 2019, 4:18 AM
Dzahn updated the task description. (Show Details)Dec 20 2019, 4:25 AM
Dzahn added a subscriber: RobH.

Change 559648 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] phabricator: delete phab1003.yaml from Hiera data, not used anymore

https://gerrit.wikimedia.org/r/559648

Change 559648 merged by Dzahn:
[operations/puppet@production] phabricator: delete phab1003.yaml from Hiera data, not used anymore

https://gerrit.wikimedia.org/r/559648

Mentioned in SAL (#wikimedia-operations) [2019-12-20T04:55:17Z] <mutante> phab1003 - rm /etc/ssh/sshd_config.phabricator ; kill 26085 (secondary sshd for phab; systemctl start sshd (fixes regular sshd) (T238957)

Dzahn removed subscribers: RobH, Papaul.Dec 20 2019, 4:57 AM

cookbooks.sre.hosts.decommission executed by dzahn@cumin1001 for hosts: phab1003.eqiad.wmnet

  • phab1003.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

Mentioned in SAL (#wikimedia-operations) [2020-01-08T21:30:55Z] <mutante> phab1003 - running decom cookbook - shutdown host, removed from puppetmaster, debmonitor etc (T238957)

Dzahn updated the task description. (Show Details)Jan 8 2020, 9:32 PM
Dzahn added subscribers: Papaul, RobH.

Change 552599 merged by Dzahn:
[operations/dns@master] remove service IPs and IPv6 for phab1003

https://gerrit.wikimedia.org/r/552599

Change 563020 had a related patch set uploaded (by Dzahn; owner: Dzahn):
[operations/puppet@production] site: remove phab1003, decom

https://gerrit.wikimedia.org/r/563020

Change 563020 merged by Dzahn:
[operations/puppet@production] site: remove phab1003, decom

https://gerrit.wikimedia.org/r/563020

Mentioned in SAL (#wikimedia-operations) [2020-01-21T06:28:24Z] <marostegui> Remove the following users from phabricator database: 'phadmin'@'10.64.48.21' 'phuser'@'10.64.48.21' 'phstats'@'10.64.48.21' 'phmanifest'@'10.64.48.21' T238957

Change 552607 merged by Marostegui:
[operations/puppet@production] mariadb: remove grants for users on phab1003

https://gerrit.wikimedia.org/r/552607

Marostegui added a subscriber: Marostegui.EditedJan 21 2020, 6:29 AM

I have removed the users from the database

root@db1128.eqiad.wmnet[mysql]> select user,host from user where host like '10.64.48.21';
Empty set (0.00 sec)

Change 552601 merged by Dzahn:
[operations/dns@master] remove production IPs for phab1003

https://gerrit.wikimedia.org/r/552601

Dzahn added a comment.Jan 21 2020, 6:36 PM

Thanks Manuel !:) Production IPs removed from DNS.

Dzahn reassigned this task from Dzahn to Jclark-ctr.Jan 21 2020, 6:40 PM
Dzahn removed a project: Patch-For-Review.
Dzahn updated the task description. (Show Details)

This server has been temporarily assigned in T215335 and used in T221389. Giving it back to the pool of spares after it has served its purpose.. It has been originally purchased in T195418.

RobH removed a subscriber: RobH.Jan 21 2020, 7:23 PM