#5143 DNS and SSL certs for faf.fedoraproject.org
Closed: Fixed 7 years ago Opened 8 years ago by rmarko.

Faf server running at https://retrace.fedoraproject.org/faf/ now needs an separate apache vhost to avoid clashes with actual retrace server and allow migration to retrace02 machine in the future.

Please add the following DNS record:

faf.fedoraproject.org 10.5.124.171

SSL certificates can be installed on the machine - I'll provide apache vhost configuration that can be included to the ansible repository afterwards.

Thank you.


Why does it need direct access from the internet?
We would prefer to have this through the reverse proxies, which would mean we can reuse the current wildcard certificate.

Where is the staging setup so that I can experiment with that and reverse proxying and load balancing?

Sounds good but we don't have staging instances at the moment. Should I create another ticket so we can get two virtual machines for staging (one for retrace server and one for faf)?

Sure, it would be nice to get a real staging setup for retrace and move retrace under our proxy setup.

Hi, staging instances are available at retrace01.stg.phx2.fedoraproject.org and faf01.stg.phx2.fedoraproject.org.

So, those both have been added to our staging setup, but haproxy is marking them both down at the moment.

We need something there to be answering on port 80 and providing a 200 result so it knows they are up.

Once thats in place you should be able to reach them from:

https://retrace.stg.fedoraproject.org/
and
https://faf.stg.fedoraproject.org/

Can you take a look at the httpd setup on those hosts?

Happy to help get you access and such. Just find me on irc (nirik) or drop me an email.

These machines are ready and waiting. :grin:

Perhaps @msuchy could move this forward.

Please let us know if there's anything else we can do from our end...

:eyes:

Metadata Update from @kevin:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

7 years ago

Login to comment on this ticket.

Metadata