Page MenuHomePhabricator

decommission dbproxy1008.eqiad.wmnet
Closed, ResolvedPublicRequest

Description

This task will track the decommission-hardware of server dbproxy1008.eqiad.wmnet.

With the launch of updates to the decom cookbook, the majority of these steps can be handled by the service owners directly. The DC Ops team only gets involved once the system has been fully removed from service and powered down by the decommission cookbook.

dbproxy1008

Steps for service owner:

  • - Remove grants T231280 https://gerrit.wikimedia.org/r/607407
  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place. https://gerrit.wikimedia.org/r/606066
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal.
  • - remove all remaining puppet references (include role::spare) and all host entries in the puppet repo
  • - remove ALL dns entries except the asset tag mgmt entries.
  • - reassign task from service owner to DC ops team member depending on site of servee.

End service owner steps / Begin DC-Ops team steps:

  • - disable switch port / set to asset tag if host isn't being unracked / remove from switch if being unracked.
  • - system disks wiped (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: switch port configration removed from switch once system is unracked.
  • - IF DECOM: mgmt dns entries removed.

Event Timeline

Marostegui moved this task from Triage to Pending comment on the DBA board.

dbproxy1008 is no longer the active m3-master per https://gerrit.wikimedia.org/r/#/c/operations/dns/+/605531/
Let's give it a few days before starting its decommissioning process.

Change 606066 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/puppet@production] dbproxy1008: Disable notifications

https://gerrit.wikimedia.org/r/606066

Change 606066 merged by Marostegui:
[operations/puppet@production] dbproxy1008: Disable notifications

https://gerrit.wikimedia.org/r/606066

Mentioned in SAL (#wikimedia-operations) [2020-06-22T05:43:55Z] <marostegui> Stop haproxy on dbproxy1008 - T255406

Mentioned in SAL (#wikimedia-operations) [2020-06-24T05:14:56Z] <marostegui> Remove grants from dbproxy1008 - T231280 T255406

dbproxy1008 grants removed from m3 (and also checked all the other mX sections):

root@cumin2001:/home/marostegui# ./section m3 | while read host port; do echo $host; mysql.py -h$host:$port -e "show grants for 'haproxy'@'10.64.32.157';"; done
db2134.codfw.wmnet
ERROR 1141 (42000) at line 1: There is no such grant defined for user 'haproxy' on host '10.64.32.157'
db2078.codfw.wmnet
ERROR 1141 (42000) at line 1: There is no such grant defined for user 'haproxy' on host '10.64.32.157'
db1128.eqiad.wmnet
ERROR 1141 (42000) at line 1: There is no such grant defined for user 'haproxy' on host '10.64.32.157'
db1117.eqiad.wmnet
ERROR 1141 (42000) at line 1: There is no such grant defined for user 'haproxy' on host '10.64.32.157'

Change 607407 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/puppet@production] production-m3.sql: Remove grants for dbproxy1008

https://gerrit.wikimedia.org/r/607407

Change 607407 merged by Marostegui:
[operations/puppet@production] production-m3.sql: Remove grants for dbproxy1008

https://gerrit.wikimedia.org/r/607407

Change 607408 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/software@master] report_users: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607408

Change 607409 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/puppet@production] mariadb: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607409

Change 607408 merged by Marostegui:
[operations/software@master] report_users: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607408

cookbooks.sre.hosts.decommission executed by marostegui@cumin2001 for hosts: dbproxy1008.eqiad.wmnet

  • dbproxy1008.eqiad.wmnet (PASS)
    • Downtimed host on Icinga
    • Found physical host
    • Downtimed management interface on Icinga
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

Change 607409 merged by Marostegui:
[operations/puppet@production] mariadb: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607409

Change 607410 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/dns@master] templates: Remove dbproxy1008 production entries

https://gerrit.wikimedia.org/r/607410

Change 607411 had a related patch set uploaded (by Marostegui; owner: Marostegui):
[operations/puppet@production] check-microcode.py: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607411

Change 607410 merged by Marostegui:
[operations/dns@master] templates: Remove dbproxy1008 production entries

https://gerrit.wikimedia.org/r/607410

Marostegui removed projects: Patch-For-Review, DBA.
Marostegui added a project: DC-Ops.
Marostegui edited subscribers, added: wiki_willy; removed: Marostegui.

This is ready for DC-Ops.

Change 607411 merged by Muehlenhoff:
[operations/puppet@production] check-microcode.py: Remove dbproxy1008

https://gerrit.wikimedia.org/r/607411

Marostegui updated the task description. (Show Details)
Marostegui subscribed.

Change 619338 had a related patch set uploaded (by Cmjohnson; owner: Cmjohnson):
[operations/dns@master] Removing mgmt dns entries for dbproxy1008

https://gerrit.wikimedia.org/r/619338

Change 619338 merged by Cmjohnson:
[operations/dns@master] Removing mgmt dns entries for dbproxy1008

https://gerrit.wikimedia.org/r/619338

Change 619343 had a related patch set uploaded (by Cmjohnson; owner: Cmjohnson):
[operations/dns@master] Missed the asset tag for dbproxy1008 mgmt removal

https://gerrit.wikimedia.org/r/619343

Change 619343 merged by Cmjohnson:
[operations/dns@master] Missed the asset tag for dbproxy1008 mgmt removal

https://gerrit.wikimedia.org/r/619343

Cmjohnson updated the task description. (Show Details)