Introduction
- We need to migrate SSA's 'interface servers' for the new archive to RHEL7
- This project won't consider the legacy archive, which will be deprecated soon'
- This project won't consider the workspaces effort and the new web stack, which are already on RHEL7
- As we do this migration, we will be 're-branding' these servers with new DNS aliases and apache virtual hosts.
Action Items
- SSA to document what makes an interface server unique, what things CIS will have to do beyond just re-installing the OS and getting ganglia and nagios working
- SSA will cleanup anything it can before the upgrades, nuking stale websites and so on.
- Strawman is to upgrade first development, then test, then production, with a week between each upgrade. for dev, for test and for production. SSA will take the strawman schedule to the stakeholders and get try to get buy-in on
Customizations
- The data partition on each machine needs to be intact after the upgrade.
- The SSA16 key should be added to root's authorized keys.
- Each machine needs to be able to submit jobs to its cluster, using the almapipe account for CV and the vlapipe account for NM.
- Each machine needs to see its site's lustre, /cv and /naasc for CV, /aoc for NM.
- Each machine needs apache http (2.4), apache tomcat (7 series) running on Java 8.
- For NM machines: the /var/lib/pgsql directory needs to be backed up and restored after the upgrade.
- /etc/sudoers.d needs to be backed up and restored after the upgrade.
the following local accounts need to be in place:
solr:x:9039:9039::/opt/services/solr:/bin/bash rabbitmq:x:9040:9040::/opt/services/rabbitmq:/bin/bash webapps:x:9036:9028:NRAO Web Apps:/opt/services/webapps-account:/bin/bash influxdb:x:9043:9043:influxdb:/dev/null:/bin/false telegraf:x:9044:9044:telegraf:/dev/null:/bin/false
Existing Servers | |||||
---|---|---|---|---|---|
Site | Profile | Hostname | VM | Current DNS Aliases | New DNS Aliases |
CV | production | hopper | dl-naasc.nrao.edu | ||
CV | test | borg | dl-naasc-test.nrao.edu | ||
CV | development | aatweb-dev | dl-alma.cv.nrao.edu | ||
NM | production | mcilroy | data.nrao.edu | ||
NM | test | hamilton | data-test.nrao.edu | ||
NM | development | wirth |
6 Comments
Patrick Murphy
Tracy Halstead will work on aatweb-dev starting September 14.
Based on Info from Matthew, William Colburn will work on wirth that same week.
Patrick Murphy
Also, wirth runs dl-alma.aoc.nrao.edu as well as dl-nrao and webtest.aoc.
Stephan Witz
Some of that is crap that can go away.
Patrick Murphy
We'll also want to preserve the /etc/shadow/ entries for those 5 accounts.
Stephan Witz
Probably /etc/group as well. Go ahead and edit the page to Make It So.
Stephan Witz
I don't think there are any kernel level customizations (/etc/sysctl) to worry about here, but the CIS folks should check and confirm.