Copr (https://copr.fedoraproject.org/) should sign packages using dedicated host.
Overall setup roughly described here: http://copr-keygen.readthedocs.org/en/latest/README.html
Requierments for host: - OS: Fedora-20 - CPU: one core is enough - Memory: 1Gb also enough - Disk: 10Gb for everything
Playbooks is available in ansible git: playbooks/groups/copr-keygen.yml
Backup: we need to backup gpg keyring. It is archive and encrypted by cron script. Playbook require armored public gpg key at location "{{ private }}/copr/keygen/backup_key.asc" (or change location in roles/copr/keygen/tasks/setup_backup.yml )
backup result is placed to "/backup/copr_keygen_keyring.tar.gz.gpg"
ok. I have commited the dns and ansible changes that add a copr-keysign.cloud.fedoraproject.org in.
Can you run your playbook and spin it up and make sure all is setup as you need?
Then we can get backups sorted out.
Is this all up and running now? shall we look at backups?
Yes, everything looks fine and configuration is reproducible by groups/copr-keygen.yml playbook. We can proceed with backups, though I'll be unavailable 19->28.
groups/copr-keygen.yml
Yeah, lets wait and touch base on it in january...
Hopefully we can get it set quickly then.
ok. The pub key should be in place (I adjusted the path a bit).
I have added the host to backups.
So, go ahead and enable the part on copr-keygen and backup03 should start picking things up from /backup/