remove cot gpg support
Categories
(Release Engineering :: Release Automation: Other, enhancement)
Tracking
(Not tracked)
People
(Reporter: mozilla, Assigned: mozilla)
References
(Blocks 1 open bug)
Details
Attachments
(5 files)
- [X] audit for cot verification falling back to gpg
- [X] update mobile workerTypes to use the ed25519-enabled AMIs
- [X] update in-tree chainOfTrust.json.asc download to download chain-of-trust.json
- [X] remove gpg support from scriptworker
- [X] remove scriptworker gpg support from puppet
- [X] remove scriptworker cot gpg keypair from hiera
- [X] remove rebuild_gpg_homedirs nagios monitoring
- [X] archive cot-gpg-keys repo
- [X] remove cot-gpg-keys expiration hook
- [ ] remove gpg support from docker-worker
- [X] remove gpg support from generic-worker
Assignee | ||
Comment 1•6 years ago
|
||
Assignee | ||
Updated•6 years ago
|
Assignee | ||
Comment 2•6 years ago
|
||
Comment 4•6 years ago
|
||
bugherder |
Assignee | ||
Comment 5•6 years ago
|
||
Johan, this task for focus-android is still using an old AMI. Do we need to support that task? If so, could we bump the AMI for that workerType, or switch it to use a valid workerType?
Thank you for pointing this out. I forgot about that worker type, because of the prefix. We eventually want to get rid of it, but not now. I updated the AMIs. Please let me know if this doesn't work tomorrow.
Assignee | ||
Comment 7•6 years ago
|
||
Thanks!
Assignee | ||
Comment 8•6 years ago
|
||
Assignee | ||
Comment 9•6 years ago
|
||
Assignee | ||
Comment 10•6 years ago
|
||
Assignee | ||
Comment 11•6 years ago
|
||
Assignee | ||
Comment 12•6 years ago
|
||
I noticed m-r was still downloading chainOfTrust.json.asc; uplifting.
https://hg.mozilla.org/releases/mozilla-release/rev/7174884ffa0f
Assignee | ||
Comment 13•6 years ago
|
||
Assignee | ||
Comment 14•6 years ago
|
||
Chain of Trust gpg verification is essentially removed. We still have the two generic- and docker-worker PRs to stop generating gpg signatures; those can be reviewed and land at any point.
Comment hidden (Intermittent Failures Robot) |
Comment hidden (Intermittent Failures Robot) |
Assignee | ||
Comment 17•5 years ago
|
||
generic-worker and docker-worker have both merged the remove-gpg PRs.
Assignee | ||
Updated•5 years ago
|
Description
•