Commit Graph

69 Commits

Author SHA1 Message Date
Alexis Pentori ebfb7ad799
all: change secret location
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-27 11:27:03 +02:00
Alexis Pentori b02a1025de
ansible/lookup/vault: use ansible variable
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-26 11:52:17 +02:00
Jakub Sokołowski 3b907ade6e
ansible/lookup/bitwarden: sync with template 2024-09-24 08:49:22 +02:00
Ivan Folgueira Bande 5566604913
node-db: increases the shared memory configured in docker
Mitigates the "out of shared memory" issue

Signed-off-by: Ivan Folgueira Bande <ivansete@status.im>
2024-09-23 14:43:31 +02:00
Alexis Pentori 65608788a9
all: fix vault consul acl-tokens
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-23 14:42:40 +02:00
Alexis Pentori 7e00fe0903
vault: update bitwarden plugin
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-20 15:14:21 +02:00
Alexis Pentori 9f2affe758
all: switch agent default acl token secret
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-20 10:28:14 +02:00
Ivan Folgueira Bande 8196f8b016
requirements: bump nim-waku role to remove rest-private parameter
Signed-off-by: Ivan Folgueira Bande <ivansete@status.im>
2024-09-19 16:30:06 +02:00
Alexis Pentori 70b7c6dc72
vault: migrating secrets
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-19 16:24:04 +02:00
markoburcul d3ad781cfc
inventory: Apply updated terraform script
Update terraform script and apply it to get updated version of ansible
inventory file.

Referenced issue: https://github.com/status-im/infra-template/issues/10

Signed-off-by: markoburcul <marko@status.im>
2024-09-13 17:04:16 +02:00
Ivan Folgueira Bande e9ef60b3e5
node: lower max-relay-peers to 200
Given that max p2p connections is 300, with max allowed relay conns
we will have 100 for other protocols such as store, lightpush, etc.

Co-authored-by: Jakub <jakub@status.im>
2024-09-11 19:01:29 +02:00
Siddarth Kumar 9dab86bd56 all: migrate iptables to nftables
- set `bootstrap__firewall_nftables` var to true
- adjust `open_ports_list` to match the structure needed to run firewall role

changes applied to all hosts in  test and sandbox environment of infra-waku

related to : https://github.com/status-im/infra-misc/issues/301
2024-09-06 15:19:55 +05:30
Siddarth Kumar c5de7b8fcb requirements: version bump 2024-09-06 15:19:55 +05:30
Alexis Pentori 6c9ce4dc59
vault: adding lookup and env variables 2024-09-05 11:50:01 +02:00
Alexis Pentori 0251f37dbf
node: adding rln keystore configuration
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-09-03 10:25:50 +02:00
Jakub Sokołowski 6e6849b1bd
all: add Harbor Docker registry credentials
Otherwise hosts create a lot of `/v2/` calls that fail with 401.

Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-09-03 09:31:43 +02:00
Jakub Sokołowski de9094d964
all: do not send trace level logs to logstash
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-07-23 12:08:18 +02:00
Jakub Sokołowski 294ade5f7b
ansible: apply roles.py fixes
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-07-05 11:43:15 +02:00
Ivan Folgueira Bande ba0fc843dd
node: restore back the sepolia rpc url and change the contract addr
We needed to go back to Sepolia network because the Polygon zkEVM didn't
work very well, i.e., it wasn't consistent in the creation of
the nonce values.

We are creating a new contract address because we start using RLN_v2
2024-07-05 11:43:14 +02:00
Ivan Folgueira Bande 2216da1d02
node: update contract and eth client addresses 2024-07-05 11:43:08 +02:00
Jakub Sokołowski d895586e33
ansible/roles.py: fix pull call to handle up-to-date repo
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-06-24 08:49:40 +02:00
Jakub Sokołowski 2f89b7ab94
ansible: add roles.py script to manage roles
https://github.com/status-im/infra-template/pull/5
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-06-13 17:17:31 +02:00
Alexis Pentori cbf30df76c
requirements: bump versions
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-06-06 18:52:13 +02:00
Ivan Folgueira Bande 7992188bf1
node.yml: as per alex recommendation, better set 50GB to avoid limit alarm 2024-06-05 14:26:37 +02:00
Ivan FB fb06c54d38
node.yml change retention policy from time:432000 to size:65GB 2024-06-03 08:47:43 +02:00
Jakub Sokołowski 5d724d2191
requirements: bump nim-waku and certbot roles
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-05-21 14:14:57 +02:00
Gabriel mermelstein c98d9d193c
all: add SSH access for gabriel@status.im 2024-05-09 15:05:32 +02:00
NagyZoltanPeter 37b47fa867
all: add SSH access for zoltan@status.im 2024-05-09 15:05:15 +02:00
Jakub Sokołowski 0cbb8df61f
lookup_plugins/bitwarden: ignore stderr
Otherwise we get weird JSON parsing errors:
```
An unhandled exception occurred while running the lookup plugin 'bitwarden'.
Error was a <class 'json.decoder.JSONDecodeError'>, original message:
Extra data: line 1 column 843 (char 842). Extra data: line 1 column 843 (char 842)
```

Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-05-07 14:48:59 +02:00
Jakub Sokołowski 40c6578cfa
requirements: use full names for all roles
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-05-07 13:03:05 +02:00
Anton Iakimov 5135f173ed
requirements: change naming to repo name 2024-05-03 17:49:32 +02:00
Anton Iakimov f072766321
inventory: update dns_entry to status.im 2024-05-03 16:58:38 +02:00
Ivan Folgueira Bande 8e9524a911
ansible/group_vars/all.yml: correct ivan public key 2024-04-16 16:35:32 +02:00
Anton Iakimov 34abc7a012
terraform: fix domains 2024-03-15 14:41:33 +01:00
Anton Iakimov 85f55e5801
nim-waku: setup ENRTREE for sandbox fleet 2024-03-15 14:41:32 +01:00
Anton Iakimov ec103eb5a9
ansible: setup db hosts first 2024-03-15 14:41:31 +01:00
Jakub Sokołowski 732623de44
ansible/inventory: update to use status.im domain
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-03-14 22:58:01 +01:00
Jakub Sokołowski 21f276a1d3
node: expose config.toml using Nginx server
This can then be linked from the new https://fleets.waku.org/.

https://github.com/status-im/infra-misc/issues/229

Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-03-07 12:45:48 +01:00
Jakub Sokołowski cac71062d5
requirements: bump nim-waku to include toml config file
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-03-06 10:00:54 +01:00
Anton Iakimov 85e8ad0f7e
terraform: add sandbox stage 2024-02-23 12:12:18 +01:00
Alexis Pentori edafd6c4a1
requirements: bump role-nim-waku
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-02-21 12:08:43 +01:00
rymnc 04ecb8e9e1 waku.test: replace ws url with http for rln-relay 2024-02-16 13:09:28 +01:00
Alexis Pentori 7f4bfe9f6b
requirement: bump version for role nim-waku
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-02-01 18:19:56 +01:00
SionoiS f34e1e9f08
node: adding nim_waku_relay_shard_manager config flag
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-02-01 18:07:25 +01:00
Alexis Pentori d2ccace59f
requirements: bump infra-role-postgres-ha version
Signed-off-by: Alexis Pentori <alexis@status.im>
2024-01-23 10:52:41 +01:00
Jakub Sokołowski e97cb8e893
node-db: disable replication explicitly
Fixes format of the healthcheck script.

Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-01-04 19:04:50 +01:00
Jakub Sokołowski 5a0580934b
node: enable databse vacuuming
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-01-04 13:27:01 +01:00
Jakub Sokołowski f0c2632dd2
requirements: bump certbot role
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-01-03 16:55:44 +01:00
Jakub Sokołowski ae4e7831ff
node: lower message retention to 5 days
Signed-off-by: Jakub Sokołowski <jakub@status.im>
2024-01-03 16:55:38 +01:00
Anton Iakimov a727613865
nim-waku: switch to harbor 2023-12-29 17:06:26 +01:00