Page MenuHomePhabricator

Migrate the KDCs to Bullseye
Open, MediumPublic

Description

The KDCs should be migrated to Bullseye. There's also a new server (krb2002) which can be included in the migration.

Event Timeline

MoritzMuehlenhoff renamed this task from MIgrate the KDCs to Bullseye to Migrate the KDCs to Bullseye.Mar 10 2023, 8:11 AM
MoritzMuehlenhoff triaged this task as Medium priority.

Change 901117 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Make krb2002 a KDC

https://gerrit.wikimedia.org/r/901117

Change 901117 merged by Muehlenhoff:

[operations/puppet@production] Make krb2002 a KDC

https://gerrit.wikimedia.org/r/901117

Change 901170 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Add systemd override to allow KDC to write to it's log file

https://gerrit.wikimedia.org/r/901170

Change 901170 merged by Muehlenhoff:

[operations/puppet@production] Add systemd override to allow KDC to write to it's log file

https://gerrit.wikimedia.org/r/901170

Change 901178 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Fix override to pass full directory

https://gerrit.wikimedia.org/r/901178

Change 901178 merged by Muehlenhoff:

[operations/puppet@production] Fix override to pass full directory

https://gerrit.wikimedia.org/r/901178

Icinga downtime and Alertmanager silence (ID=d3c0fbee-5db6-4389-b75e-415ed51c67bc) set by jmm@cumin2002 for 21 days, 0:00:00 on 1 host(s) and their services with reason: Non-functional, WIP for Bullseye update

krb2002.codfw.wmnet

Change 906560 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Add krb2002 as additional KDC

https://gerrit.wikimedia.org/r/906560

Change 906563 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Create a separate Hiera variable of KDCs specifically for use in client config

https://gerrit.wikimedia.org/r/906563

Change 906563 merged by Muehlenhoff:

[operations/puppet@production] Create a separate Hiera variable of KDCs specifically for use in client config

https://gerrit.wikimedia.org/r/906563

Icinga downtime and Alertmanager silence (ID=22bf6bdd-4c99-40f0-ab28-bb73d3bcbf21) set by jmm@cumin2002 for 6 days, 0:00:00 on 1 host(s) and their services with reason: Non-functional, WIP for Bullseye update

krb2002.codfw.wmnet

Change 906560 merged by Muehlenhoff:

[operations/puppet@production] Add krb2002 as additional KDC

https://gerrit.wikimedia.org/r/906560

Change 915569 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Make krb2002 available to Kerberos client

https://gerrit.wikimedia.org/r/915569

Change 915569 merged by Muehlenhoff:

[operations/puppet@production] Make krb2002 available to Kerberos client

https://gerrit.wikimedia.org/r/915569

Change 917359 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Failover the kadminserver to krb2002

https://gerrit.wikimedia.org/r/917359

Change 917359 merged by Muehlenhoff:

[operations/puppet@production] Failover the kadminserver to krb2002

https://gerrit.wikimedia.org/r/917359

Change 920204 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Temporary drop krb1001 from KDC list used by clients

https://gerrit.wikimedia.org/r/920204

Change 920204 merged by Muehlenhoff:

[operations/puppet@production] Temporary drop krb1001 from KDC list used by clients

https://gerrit.wikimedia.org/r/920204

Icinga downtime and Alertmanager silence (ID=0862bbee-318e-4c78-92cc-9304bf025af3) set by jmm@cumin2002 for 2:00:00 on 1 host(s) and their services with reason: Update to Bullseye

krb1001.eqiad.wmnet

Mentioned in SAL (#wikimedia-operations) [2023-05-17T07:48:58Z] <moritzm> upgrading krb1001 to Bullseye T331695

Change 920637 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Add krb1001 back to KDCs exposed to Kerberos clients and drop krb2001

https://gerrit.wikimedia.org/r/920637

Change 920637 merged by Muehlenhoff:

[operations/puppet@production] Add krb1001 back to KDCs exposed to Kerberos clients and drop krb2001

https://gerrit.wikimedia.org/r/920637

Change 921242 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Switch kadmin server back to krb1001

https://gerrit.wikimedia.org/r/921242

Change 921242 merged by Muehlenhoff:

[operations/puppet@production] Switch kadmin server back to krb1001

https://gerrit.wikimedia.org/r/921242

Change 922068 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove KDC role from krb2001

https://gerrit.wikimedia.org/r/922068