Remove ansible.nodejs.org
Les mainteneurs répondent en général sous 2 jours
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Accessibilité débutants
- 35/100
- Type d'issue
- Refactorisation
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- ansible, docker, docker-compose
- Domaine
- cloud, devops, infrastructure, security
Piste de recherche
Start by reviewing ansible/inventory.yml, the ~/.ssh/config conventions, and the secrets repository for references to ansible.nodejs.org, infra-ibm-ubuntu2004-x64-1, and awx_password. Confirm that no credentials, scheduled jobs, webhooks, or workflows depend on the AWX host, then coordinate decommissioning the host and removing its DNS and Cloudflare configuration. Done means the host and related references are safely removed and exclusive credentials are rotated.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Summary
ansible.nodejs.org (IBM host infra-ibm-ubuntu2004-x64-1, 169.60.150.91) is an unmanaged, unwatched AWX (open-source Ansible Tower) instance that has been effectively dead for years and should be decommissioned rather than repaired.
What's running there
- AWX 17.1.0 (
ansible/awx:17.1.0), deployed via docker-compose, containers created ~5 years ago. awx_web,awx_task,awx_rediscontainers, plusawx_postgres.- No nginx/reverse proxy — the AWX web container binds host ports 80/443 directly.
Key detail: it's been idle for years, then crashed
The last time this AWX instance did anything at all was around 2023-09-29 (a project sync attempt), and the last time there's evidence of actually running a job against current code was back when the checkout was at the Feb 2022 commit. Either way, it's been sitting completely idle for roughly 2.5+ years before postgres even died in Dec 2025 — the disk-full crash-loop just finished off something that was already effectively unused.
Supporting evidence:
awx_postgreshas been crash-looping since 2025-12-29 (no space left on device, 605+ restart attempts logged), because the host's root disk is 100% full (99G/99G).- The AWX-synced checkout of
nodejs/buildunder/var/lib/awx/projectsis pinned at commit472b2953("Update README.md", #2874, merged 2022-02-21). - The project's
.git/FETCH_HEAD(updated on each pre-job sync) has an mtime of 2023-09-29 11:56 UTC, and picked up no newer commits — the last sync attempt, whatever triggered it, did nothing useful. - The host's origin TLS cert (served directly by the AWX container, not through Cloudflare) is self-signed and expired 2024-04-09. The only reason
https://ansible.nodejs.orgstill shows a valid cert to browsers is that Cloudflare is terminating TLS at the edge with the shared*.nodejs.orgwildcard cert and not validating the origin connection.
Why this should be removed, not fixed
- It's a privileged automation platform (AWX manages Ansible credentials/inventory) that nobody has been watching for 2.5+ years.
- Disk exhaustion took down its database in Dec 2025 and nobody noticed for ~9 months — reinforcing that it has no active owner.
- The AWX release (17.1.0) is multiple years out of date.
- No current build/infra workflow appears to depend on it (last real activity predates most current infra automation, which now runs through this
ansible/repo directly).
Suggested next steps
- Confirm nothing currently depends on this AWX instance (credentials stored only here, scheduled jobs, webhooks pointing at it, etc.)
- Decommission the host (
infra-ibm-ubuntu2004-x64-1/ansible.nodejs.org, IBM, 169.60.150.91) - Remove its DNS record and Cloudflare configuration
- Remove/rotate any credentials that were only ever exposed to this box (e.g.
awx_passwordin the secrets repo) - Remove references to it from
ansible/inventory.ymland~/.ssh/configconventions once decommissioned
🤖 Generated with Claude Code
- Langage dominant
- Jinja
- Étoiles
- 541
- Forks
- 185
- Merge moyen
- 2 j 19 h
- PR mergées (30 j)
- 6
Préparer son environnement
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de nodejs/build
-
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
nodejs/build#4482 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
-
platform:ppc
Difficulté 1/5 Moins d'une heure Accessibilité débutants 65/100
nodejs/build#4479 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
nodejs/build#4324 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
-
incident
Difficulté 4/5 3-5 jours Accessibilité débutants 42/100
nodejs/build#4483 · 3 commentaires ·
Les mainteneurs répondent en général sous 2 jours
-
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
nodejs/build#4477 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
Toutes les issues de nodejs/build
Issues similaires
-
enhancement
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
pydantic/pydantic-ai#8935 ·
Les mainteneurs répondent en général sous 1 jour
-
Language: Terraform :globe_with_meridians: Needs: Triage :mag: Type: Bug :bug:
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
Azure/terraform-azurerm-avm-res-web-site#408 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
[Bug]: avm-ptn-alz-connectivity-hub-and-spoke-vnet not setting location within security_policyOuverteNeeds: Triage :mag: Product: Terraform (AVM) Topic: Networking (HS) :globe_with_meridians:
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Azure/Azure-Landing-Zones#4291 · 1 commentaire ·
Les mainteneurs répondent en général sous 4 jours
-
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
cloudtools/troposphere#2367 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
googleapis/google-cloud-dart#366 ·
Les mainteneurs répondent en général sous 1 jour