Hi Kevin,
Thanks a lot for your response.
I’m interested in participating to package Ansible.
As Fedora apprentice I saw that ticket concerns me:
https://pagure.io/fedora-infrastructure/issue/9693
Could I fix it?
Have a nice day!
++
Kind regards,
Patrick
Le 7 mars 2021 à 22:41, Kevin Fenzi <kevin(a)scrye.com> a écrit :
On Sat, Mar 06, 2021 at 03:47:47PM +0100, Patrick Vavrina wrote:
> Hi Kevin,
Hey.
> How are you?
Not too bad. :)
> In order to improve my skills in infrastructure administration, I would like to know which are the most important tools to master: Ansible, OpenShift, Docker/Podman, Virtualization, OpenStack and so on.
Well, any of those, but I would say you should start with anything that
interests you. If you are interested in something you are much more
likely to learn it and enjoy working with it. So, you might read up on
all the various things and see what catches your interest.
>
> As I’m unemployed at this time, I’m looking for new job opportunities and I wish to stay informed about new system methodologies.
Makes sense.
> Is an essential thing to pass the RHCSA and RHCE certificates for my career, too?
No, but they can be useful sometimes. There's some jobs that might list
those as requirements, and they are good to have on your resume.
That said, they cost a fair bit, so if you dont have a lot of
income/savings it might not be effective to persue them now.
>
> I have been using GNU/Linux and FLOSS for my different jobs since 1998.
Awesome!
> Have a nice weekend!
You too!
> Kind regards,
> Patrick
kevin
Hi Everyone,
If you would like to see this report and toggle to the section you are
most interested in, I would suggest visiting this link
https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view and use the header bar
on your left to skip to where you want to go!
## Initiative FYI Links
Initiatives repo here: https://pagure.io/cpe/initiatives-proposal
2021 Quarterly Planning timetable here:
https://docs.fedoraproject.org/en-US/cpe/time_tables/
Details on initiative requesting/how to work with us on new projects
here: https://docs.fedoraproject.org/en-US/cpe/initiatives/
### Misc
* CentOS Newsletter for March is out!
https://blog.centos.org/2021/03/centos-community-newsletter-march-2021-2103/
* CentOS Dojo scheduled for May 13th & 14th CFP is open, details on
event and CFP link can be found here
https://wiki.centos.org/Events/Dojo/May2021
* New community podcast is out from Red Hat Community
https://twitter.com/redhatopen/status/1367113857936809984
* Lightning Talks & some others from DevConf.cz are now uploaded!
https://www.youtube.com/c/DevConf_INFO/featured
* Check out the most recent blog post on the Fedora Code of Conduct
here https://communityblog.fedoraproject.org/fedora-code-of-conduct-report-2020/
## Project Updates
*The below updates are pulled directly from our CPE team call we have
every week.*
### Fedora
* Still in Beta Freeze
* Working on progressing flatpak-indexer, its currently in staging
* Processed 100+ fedscm requests!
* In staging got pagure on dist-git working with the git user instead
of each packager having their own shell account
* Working with debuginfo-d folks to get them set up with resources to
enable it in Fedora infra
### Noggin/AAA
* Reviewing dates for a planned outage in March - early estimated
dates are 18th & 19th for production migration. Formal email to follow
to all fedora lists once outage period is confirmed early next week.
* Community blog coming middle of next week on the new account system work
* The work tracker for this project can be found here
https://github.com/orgs/fedora-infra/projects/6
* The team use #fedora-aaa for discussions on IRC
* And please report any issues you find in the repo
https://github.com/fedora-infra/noggin
## CentOS Updates
### CentOS
* Legacy CentOS CI Infra Openshift 3.6 has been retired
* CentOS CI OCP clusters updated to 4.6.18
### CentOS Stream
* Testing centpkg against the new buildsystem and CBS
* Developing a style guide for CentOS Stream - first draft will be in
a repo on git.centos.org to view/comment by mid-March
* Building CentOS Stream only packages, eg logos, etc for Stream 9
## Team Info
### Background:
The Community Platform Engineering group, or CPE for short, is the Red
Hat team combining IT and release engineering from Fedora and CentOS.
Our goal is to keep core servers and services running and maintained,
build releases, and other strategic tasks that need more dedicated
time than volunteers can give.
See our wiki page here for more
information:https://docs.fedoraproject.org/en-US/cpe/
--
Aoife Moloney
Product Owner
Community Platform Engineering Team
Red Hat EMEA
Communications House
Cork Road
Waterford
Greetings everyone.
As you may know we are planning on rolling out our new account system in
a few weeks. During this changeover it might be a good time (or might
not!) to change how our ssh auth for git works with
src.fedoraproject.org (well, pkgs.fedoraproject.org really).
How it works now:
* All users in the 'packager' group have accounts on pkgs01.iad2
* All these users have a 'wrapper' on their ssh key that runs the pagure
wrapper that checks who they are, etc.
Cons:
* only packagers have accounts for ssh, so non packagers just get permission
denied and it confuses them.
* operating on the idea of least privledge, having everyone in the
packager group having real accounts seems wrong/bad.
How we could change it:
1) Do nothing. We could add packager again when we move to sssd/ipa and
everything keeps working pretty much the same way it does now.
2) We could move from ssh://username@pkgs to ssh://git@pkgs and not have
real shell accounts for packagers. Everything would get sorted out by
the wrapper on the git account.
Cons:
* Everyone with an existing checkout would have to update their url
* We still have to deal with ssh port open to the world
Pros:
* Everyone could use the ssh://git@pkgs url, no need to just be a
packager
3) We could just retire the ssh part of this and ask everyone to use
https.
Cons:
* Everyone who had a ssh checkout would have to change it to https.
* Some people like ssh over https and would be mad at us.
* https pushing needs a browser to get a token, so it would be a pain
for people with no local gui session.
Pros:
* No need to have the ssh port on pkgs01.iad2 open to the internet
anymore.
* https can be load balanced vis proxies, etc
4) We could add some kind of GSSAPI/Kerberos support to pagure, so
people could use https and a kerberos ticket.
5) Your idea here
So, thoughts?
kevin
Dear all,
You are kindly invited to the meeting:
Fedora Infrastructure on 2021-03-04 from 08:00:00 to 09:00:00 America/Los_Angeles
At fedora-meeting-1(a)irc.freenode.net
The meeting will be about:
Weekly Fedora Infrastructure meeting. See infrastructure list for agenda a day before.
Source: https://apps.fedoraproject.org/calendar/meeting/9675/