Page MenuHomePhabricator

Decommission puppetmaster1002
Closed, ResolvedPublic

Description

We're down to 659 servers using Puppet 5 and we can start reducing the number of Puppet 5 servers. One of the codfw nodes is being repurposed as a Puppet 7 server (where we previously only have/had two), but we alreay have three Puppet 7 servers in eqiad, so the old Puppet 5 servers can simply be decommissioned over time.

puppetmaster1002 is the first which can be decommisioned in eqiad; it is long out of warranty (bought in 2016)

Steps for service owner:

  • - all system services confirmed offline from production use
  • - set all icinga checks to maint mode/disabled while reclaim/decommmission takes place. (likely done by script)
  • - remove system from all lvs/pybal active configuration
  • - any service group puppet/hiera/dsh config removed
  • - remove site.pp, replace with role(spare::system) recommended to ensure services offline but not 100% required as long as the decom script is IMMEDIATELY run below.
  • - login to cumin host and run the decom cookbook: cookbook sre.hosts.decommission <host fqdn> -t <phab task>. This does: bootloader wipe, host power down, netbox update to decommissioning status, puppet node clean, puppet node deactivate, debmonitor removal, and run homer.
  • - remove all remaining puppet references and all host entries in the puppet repo
  • - reassign task from service owner to DC ops team member and site project (ops-sitename) depending on site of server

End service owner steps / Begin DC-Ops team steps:

  • - system disks removed (by onsite)
  • - determine system age, under 5 years are reclaimed to spare, over 5 years are decommissioned.
  • - IF DECOM: system unracked and decommissioned (by onsite), update netbox with result and set state to offline
  • - IF DECOM: mgmt dns entries removed.

Related Objects

StatusSubtypeAssignedTask
OpenNone
ResolvedVRiley-WMF

Event Timeline

MoritzMuehlenhoff triaged this task as Medium priority.
MoritzMuehlenhoff created this task.

Change 999533 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove puppetmaster1002

https://gerrit.wikimedia.org/r/999533

Change 999533 abandoned by Muehlenhoff:

[operations/puppet@production] Remove puppetmaster1002

Reason:

Already removed for T358187

https://gerrit.wikimedia.org/r/999533

Change 1013020 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove puppetmaster::backend role from puppetmaster1002

https://gerrit.wikimedia.org/r/1013020

Change 1013020 merged by Muehlenhoff:

[operations/puppet@production] Remove puppetmaster::backend role from puppetmaster1002

https://gerrit.wikimedia.org/r/1013020

cookbooks.sre.hosts.decommission executed by jmm@cumin2002 for hosts: puppetmaster1002.eqiad.wmnet

  • puppetmaster1002.eqiad.wmnet (PASS)
    • Downtimed host on Icinga/Alertmanager
    • Found physical host
    • Downtimed management interface on Alertmanager
    • Wiped all swraid, partition-table and filesystem signatures
    • Powered off
    • [Netbox] Set status to Decommissioning, deleted all non-mgmt IPs, updated switch interfaces (disabled, removed vlans, etc)
    • Configured the linked switch interface(s)
    • Removed from DebMonitor
    • Removed from Puppet master and PuppetDB

puppetmaster1002 has been decommissioned.

MoritzMuehlenhoff reassigned this task from MoritzMuehlenhoff to Jclark-ctr.
MoritzMuehlenhoff edited projects, added ops-eqiad; removed Puppet (Puppet 7.0).
MoritzMuehlenhoff updated the task description. (Show Details)

Change #1016716 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove puppetmaster1002 from puppetdb ACLs

https://gerrit.wikimedia.org/r/1016716

Change #1016717 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] Remove puppetmaster1002 from site.pp

https://gerrit.wikimedia.org/r/1016717

Change #1016717 merged by Muehlenhoff:

[operations/puppet@production] Remove puppetmaster1002 from site.pp

https://gerrit.wikimedia.org/r/1016717

Change #1016716 merged by Muehlenhoff:

[operations/puppet@production] Remove puppetmaster1002 from puppetdb ACLs

https://gerrit.wikimedia.org/r/1016716

VRiley-WMF updated Other Assignee, added: Jclark-ctr.
VRiley-WMF added a subscriber: Jclark-ctr.

This has been unracked and decommission script has been run.