Page MenuHomePhabricator

decommission icinga1001.wikimedia.org
Closed, ResolvedPublicRequest

Description

This task will track the decommission-hardware of server icinga1001.wikimedia.org

With the launch of updates to the decom cookbook, the majority of these steps can be handled by the service owners directly. The DC Ops team only gets involved once the system has been fully removed from service and powered down by the decommission cookbook.

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place. (likely done by script)
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal, and run homer.
  • - remove all remaining puppet references and all host entries in the puppet repo
  • - reassign task from service owner to DC ops team member depending on site of server.

End service owner steps / Begin DC-Ops team steps:

  • - system disks removed (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: mgmt dns entries removed.
  • - IF RECLAIM: set netbox state to 'inventory' and hostname to asset tag

Event Timeline

colewhite renamed this task from decommission icinga1001.wikimedia.org to reclaim icinga1001.wikimedia.org.Apr 7 2021, 10:00 PM
colewhite created this task.

Change 682992 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] remove all references to icinga1001

https://gerrit.wikimedia.org/r/682992

Change 683420 had a related patch set uploaded (by Herron; author: Herron):

[operations/homer/public@master] remove icinga[12]001 addresses from firewall rules

https://gerrit.wikimedia.org/r/683420

Change 682992 merged by Herron:

[operations/puppet@production] remove all references to icinga1001

https://gerrit.wikimedia.org/r/682992

cookbooks.sre.hosts.decommission executed by herron@cumin1001 for hosts: icinga1001.wikimedia.org

  • icinga1001.wikimedia.org (FAIL)
    • Failed downtime host on Icinga (likely already removed)
    • Found physical host
    • Skipped downtime management interface on Icinga (likely already removed)
    • Wiped bootloaders
    • Powered off
    • Set Netbox status to Decommissioning and deleted all non-mgmt interfaces and related IPs
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

ERROR: some step on some host failed, check the bolded items above

Change 683420 merged by Herron:

[operations/homer/public@master] remove icinga[12]001 addresses from firewall rules

https://gerrit.wikimedia.org/r/683420

wiki_willy added a subscriber: wiki_willy.

Hi @colewhite - just a heads up to add "ops-eqiad" as a project task, when this is ready for dc-ops to unrack. Much appreciated! Thanks, Willy

Cmjohnson renamed this task from reclaim icinga1001.wikimedia.org to decommission icinga1001.wikimedia.org.Sep 14 2021, 4:13 PM

removed from rack and updated netbox