- provision new idp-test nodes with Bullseye
- Build new cas debs for Bullseye
- Test everything on the new test cluster after failing over the idp-test CNAME
- Create new idp nodes with Bullseye
- Failover the idp CNAME
- Remove old Buster nodes
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T305518 Upgrade IDPs to CAS 6.6/Bullseye and enable webauthn | |||
Resolved | MoritzMuehlenhoff | T308214 Migrate the IDPs to Bullseye |
Event Timeline
Change 791342 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Add idp-test1002/2002
Change 791342 merged by Muehlenhoff:
[operations/puppet@production] Add idp-test1002/2002
Mentioned in SAL (#wikimedia-operations) [2022-05-13T10:55:37Z] <moritzm> installing idp-test2002 T308214
Mentioned in SAL (#wikimedia-operations) [2022-05-13T11:40:58Z] <moritzm> installing idp-test1002 T308214
Change 793634 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Switch idp-test2002 to idp_test role
Change 793634 merged by Muehlenhoff:
[operations/puppet@production] Switch idp-test2002 to idp_test role
Change 793744 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Only add component/memcached16 on Buster
Change 793751 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Also add component/idp-test for Bullseye
Change 793751 merged by Muehlenhoff:
[operations/puppet@production] Also add component/idp-test for Bullseye
Mentioned in SAL (#wikimedia-operations) [2022-05-20T12:37:32Z] <moritzm> copy prometheus-mcrouter-exporter from buster-wikimedia to bullseye-wikimedia (needed for T308214)
Change 793770 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Enable new Bullseye test IDPs in acmechief config
Change 793783 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] idp: Remove component/idp-test
Change 793770 merged by Muehlenhoff:
[operations/puppet@production] Enable new Bullseye test IDPs in acmechief config
Change 796969 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Also switch idp-test1002 to idp_test role
Change 796969 merged by Muehlenhoff:
[operations/puppet@production] Also switch idp-test1002 to idp_test role
Change 793783 merged by Muehlenhoff:
[operations/puppet@production] idp: Remove component/idp-test
Change 798709 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Allow new idp-test hosts in Ferm rules
Change 798709 merged by Muehlenhoff:
[operations/puppet@production] Allow new idp-test hosts in Ferm rules
The IDPs needs a TLS-enabled build of the bullseye version of memcached, which was only enabled after the bullseye release (in 1.6.12). I'll create a separate component with a memcached build.
Change 793744 merged by Muehlenhoff:
[operations/puppet@production] Only add component/memcached16 on Buster
Change 799286 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Add repository component for TLS-enabled memcached
Change 799286 merged by Muehlenhoff:
[operations/puppet@production] Add repository component for TLS-enabled memcached
Mentioned in SAL (#wikimedia-operations) [2022-05-25T13:15:46Z] <moritzm> imported memcached 1.6.9+dfsg-1+wmf11u1 to bullseye-wikimedia (TLS-enabled build) T308214
Change 799348 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] memcached: Untangle TLS/1.6 options
Change 799354 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] idp::memcached: Only enable memcached_16 on Buster
Change 799348 merged by Muehlenhoff:
[operations/puppet@production] memcached: Untangle TLS/1.6 options
Change 799354 merged by Muehlenhoff:
[operations/puppet@production] idp::memcached: Only enable memcached_16 on Buster
Change 801402 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] idp-test: Point to the new Bullseye hosts
Change 801624 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/dns@master] Point idp-test to idp-test1002
Change 801402 merged by Muehlenhoff:
[operations/puppet@production] idp-test: Point to the new Bullseye hosts
Change 801624 merged by Muehlenhoff:
[operations/dns@master] Point idp-test to idp-test1002
Mentioned in SAL (#wikimedia-operations) [2022-06-01T08:00:08Z] <moritzm> installing idp2002 T308214
Mentioned in SAL (#wikimedia-operations) [2022-06-01T08:49:11Z] <moritzm> installing idp1002 T308214
Change 802098 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] profile::mariadb::ferm_misc: Remove old buster idp-test hosts, add new idp/bullseye ones
Change 802098 merged by Muehlenhoff:
[operations/puppet@production] Remove old buster idp-test hosts, add new idp/bullseye ones from Ferm rules
Change 802444 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Apply idp role to idp1002/idp2002
Change 802444 merged by Muehlenhoff:
[operations/puppet@production] Apply idp role to idp1002/idp2002
Change 802541 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/dns@master] Failover idp.w.o to idp1002 (new Bullseye node)
Change 802542 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Failover active IDP nodes to idp1002/idp2002
Change 802729 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Remove Puppet references to idp-test1001/idp-test2001
Change 802729 merged by Muehlenhoff:
[operations/puppet@production] Remove Puppet references to idp-test1001/idp-test2001
cookbooks.sre.hosts.decommission executed by jmm@cumin2002 for hosts: idp-test2001.wikimedia.org
- idp-test2001.wikimedia.org (PASS)
- Downtimed host on Icinga/Alertmanager
- Found Ganeti VM
- VM shutdown
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.codfw.wmnet to Netbox
- Removed from DebMonitor
- Removed from Puppet master and PuppetDB
- VM removed
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.codfw.wmnet to Netbox
cookbooks.sre.hosts.decommission executed by jmm@cumin2002 for hosts: idp-test1001.wikimedia.org
- idp-test1001.wikimedia.org (PASS)
- Downtimed host on Icinga/Alertmanager
- Found Ganeti VM
- VM shutdown
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.eqiad.wmnet to Netbox
- Removed from DebMonitor
- Removed from Puppet master and PuppetDB
- VM removed
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.eqiad.wmnet to Netbox
Change 802542 merged by Muehlenhoff:
[operations/puppet@production] Failover active IDP nodes to idp1002/idp2002
Change 802541 merged by Muehlenhoff:
[operations/dns@master] Failover idp.w.o to idp1002 (new Bullseye node)
Change 803883 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] profile::mariadb::ferm_misc: Remove old buster IDP nodes
Change 803892 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Switch idp1001/idp2001 to role(insetup)
Change 803883 merged by Muehlenhoff:
[operations/puppet@production] profile::mariadb::ferm_misc: Remove old buster IDP nodes
Change 803892 merged by Muehlenhoff:
[operations/puppet@production] Switch idp1001/idp2001 to role(insetup)
Change 805140 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] acme_chief: Remove old buster IDP hosts
Change 805140 merged by Muehlenhoff:
[operations/puppet@production] acme_chief: Remove old buster IDP hosts
cookbooks.sre.hosts.decommission executed by jmm@cumin2002 for hosts: idp2001.wikimedia.org
- idp2001.wikimedia.org (PASS)
- Downtimed host on Icinga/Alertmanager
- Found Ganeti VM
- VM shutdown
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.codfw.wmnet to Netbox
- Removed from DebMonitor
- Removed from Puppet master and PuppetDB
- VM removed
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.codfw.wmnet to Netbox
cookbooks.sre.hosts.decommission executed by jmm@cumin2002 for hosts: idp1001.wikimedia.org
- idp1001.wikimedia.org (PASS)
- Downtimed host on Icinga/Alertmanager
- Found Ganeti VM
- VM shutdown
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.eqiad.wmnet to Netbox
- Removed from DebMonitor
- Removed from Puppet master and PuppetDB
- VM removed
- Started forced sync of VMs in Ganeti cluster ganeti01.svc.eqiad.wmnet to Netbox