canonical-ci-engineering team mailing list archive
-
canonical-ci-engineering team
-
Mailing list archive
-
Message #00048
Re: Migration of s-jenkins to new hardware
On Sat, Oct 5, 2013 at 6:21 PM, Stéphane Graber <
stephane.graber@xxxxxxxxxxxxx> wrote:
> On Sat, Oct 05, 2013 at 07:01:10PM +0200, Michał Sawicz wrote:
> > On 05.10.2013 13:37, Larry Works wrote:
> > >The migration of the s-jenkins instance to new hardware is complete. The
> > >URL that is accessible from outside the lab ishttp://10.97.0.26:8080.
> > >The old URL,http://10.97.2.10:8080 has been configured to redirect
> > >users to the new URL. There is an issue accessing the new server from
> > >external sources like snakefruit and nusakan which affects some CI jobs.
> > >An RT (65040) has been filed with IS ti fix this.
> > >
> > >
> > >The URL sent during the notification message,http://10.97.2.26:8080, is
> > >valid inside the lab for all systems on the 10.97.2.0/24 network but is
> > >currently not directly accesible outside the lab. The new server is
> > >multi-homed though so thehttp://10.97.0.26:8080 URL will give external
> > >access to the same server.
> >
> > I filed a bug¹ about using IPs for all services behind the VPN, as
> > it resulted in hardcoding the IP (bug²) and tenmporarily (thanks
> > fginther) broken jobs. Not to mention that having to let everyone
> > know that the IP changed, update /etc/hosts or bookmarks... Can we
> > please just have static domain names for these services? And a DNS
> > server behind the VPN, so that no one has to ask for the IP again?
> >
> > ¹ https://bugs.launchpad.net/ps-qa-tools/+bug/1235622
> > ² https://bugs.launchpad.net/ps-qa-tools/+bug/1235621
>
> I apparently can't access those bugs so can't really see what you
> reported, note that for the case of snakefruit and nusakan, a DNS record
> wouldn't have helped since it's the IS maintained firewalls that are the
> main problem (those machines have very restricted network access so any
> change in IP address needs to be coordinated with IS so that the
> firewalls can be updated).
>
For firewall rules, yes; in the case of Saviq's bug, there are also jobs
that call back on the jenkins master node, one case I can think of right
now is the meta build system which has it's internal archive.
References