From a4cff34be036ea9054ed5e586cc23fc1834f4380 Mon Sep 17 00:00:00 2001 From: Michal Konecny Date: Nov 05 2025 15:11:43 +0000 Subject: Document OpenId changes in ipsilon Document how the OpenId instance is separated in ipsilon and add dates when it will go away. Signed-off-by: Michal Konecny --- diff --git a/modules/sysadmin_guide/pages/ipsilon.adoc b/modules/sysadmin_guide/pages/ipsilon.adoc index 7c6a11a..88f8e70 100644 --- a/modules/sysadmin_guide/pages/ipsilon.adoc +++ b/modules/sysadmin_guide/pages/ipsilon.adoc @@ -27,7 +27,9 @@ Backup upstream contact:: Servers:: * ipsilon01.rdu3.fedoraproject.org * ipsilon02.rdu3.fedoraproject.org -* ipsilion01.stg.rdu3.fedoraproject.org +* ipsilon03.rdu3.fedoraproject.org +* ipsilon01.stg.rdu3.fedoraproject.org +* ipsilon02.stg.rdu3.fedoraproject.rog Purpose:: Ipsilon is our central authentication service that is used to authenticate users agains FAS. It is seperate from FAS. @@ -39,6 +41,14 @@ users agains FAS. It is seperate from FAS. The only service that is not using this currently is the wiki. It is a web service that is presented via httpd and is load balanced by our standard haproxy setup. +*Till November 2025* OpenId instance is separated +(`ipsilon02.stg.rdu3.fedoraproject.org`, `ipsilon03.rdu3.fedoraproject.org`) +because we want to remove OpenId authentication completely in future +(May 2026). This will allow us to replace the existing ipsilon instance +and still keep OpenId capabalities for some time. This separation is done +by adding new backend in haproxy setup `ipsilon-backend-openid`, which +redirects on specific OpenId related requests. + == Known issues No known issues at this time. There is not currently a logout option for