Historically profile::openldap::management was co-hosted on the mwmaint servers. These will vanish when the wikikube migration is completed, so this task is about moving them to separate ldap-maint1001/ldap-maint2002 hosts.
Description
Details
Event Timeline
Change #1043645 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Add ldap-maint[12]001 to site.pp
Change #1043646 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Add partman globbing for ldap-maint
Change #1043645 merged by Muehlenhoff:
[operations/puppet@production] Add ldap-maint[12]001 to site.pp
Change #1043646 merged by Muehlenhoff:
[operations/puppet@production] Add partman globbing for ldap-maint
Change #1043656 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] profile::openldap::management: Add support for bookworm
Change #1043656 merged by Muehlenhoff:
[operations/puppet@production] profile::openldap::management: Add support for bookworm
Change #1043680 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] New openldap::management role
Change #1043680 merged by Muehlenhoff:
[operations/puppet@production] New openldap::management role
Change #1043709 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Apply openldap::maintenance role to ldap-maint* hosts
Change #1043709 merged by Muehlenhoff:
[operations/puppet@production] Apply openldap::maintenance role to ldap-maint* hosts
Change #1043770 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Add ldap-admins settings to new ldap-maint role
Change #1043770 merged by Muehlenhoff:
[operations/puppet@production] Add ldap-admins settings to new ldap-maint role
Change #1043783 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Enable account check on new ldap-main host in eqiad
Change #1043783 merged by Muehlenhoff:
[operations/puppet@production] Enable account check on new ldap-main host in eqiad
Mentioned in SAL (#wikimedia-operations) [2024-06-14T13:49:15Z] <jmm@cumin2002> START - Cookbook sre.puppet.sync-netbox-hiera generate netbox hiera data: "new ldap-maint hosts - jmm@cumin2002 - T367490"
Mentioned in SAL (#wikimedia-operations) [2024-06-14T14:04:54Z] <jmm@cumin2002> END (PASS) - Cookbook sre.puppet.sync-netbox-hiera (exit_code=0) generate netbox hiera data: "new ldap-maint hosts - jmm@cumin2002 - T367490"
Change #1046318 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] mwmaint: Stop including profile::openldap::management
Change #1046318 merged by Muehlenhoff:
[operations/puppet@production] mwmaint: Stop including profile::openldap::management
Change #1046592 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Disable openldap::management timers on mwmaint hosts
Change #1046594 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] profile::openldap::management: Remove support for buster
Change #1046596 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] Drop ldap-admins access group from mwmaint hosts
Change #1046594 merged by Muehlenhoff:
[operations/puppet@production] profile::openldap::management: Remove support for buster
Change #1046592 merged by Muehlenhoff:
[operations/puppet@production] Disable openldap::management timers on mwmaint hosts
The LDAP management parts have been split off to the new ldap-maint1001/ldap-maint2001 hosts.
Change #1046596 merged by Muehlenhoff:
[operations/puppet@production] Drop ldap-admins access group from mwmaint hosts
Change #1049536 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/puppet@production] offboard-user: New -H for ldapmodify
Change #1049536 merged by Muehlenhoff:
[operations/puppet@production] offboard-user: New -H for ldapmodify