Skip to content

chore: remove vestigial CrowdStrike Falcon install machinery - #33

Merged
pranav-new-relic merged 1 commit into
mainfrom
feature/remove-crowdstrike
Jun 11, 2026
Merged

pranav-new-relic merged 1 commit into
mainfrom
feature/remove-crowdstrike

Conversation

@pranav-new-relic

@pranav-new-relic pranav-new-relic commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

Per NR-520645 (closed, P2), NR migrated off CrowdStrike Falcon to SentinelOne and asked to decommission Falcon agents from EC2 instances spun up in account 709144918866.

The OIL install role is already a no-op stub (prints "Skipping CrowdStrike Falcon Sensor installation"), so the deployer's bundling of shared-crowdstrike-ansible-role was already vestigial — the only effect today is that it breaks publish.yml whenever the CROWDSTRIKE_REPO_KEY deploy key goes stale, as it currently has.

This PR removes the three deployer-side touchpoints: requirements.ansible.private.yml (deleted), the RUN --mount=type=secret,id=ssh_private_key ... block in Dockerfile, and the secrets: block in .github/workflows/publish.yml. After merge, publish.yml no longer needs CROWDSTRIKE_REPO_KEY. SentinelOne is not added in this PR — there's no shared-sentinelone-ansible-role repo and the ticket scope is decommission-only; if/when it's required on test EC2s, AMI-baking is the natural layer.

Per NR-520645 (closed P2): NR migrated off CrowdStrike Falcon to
SentinelOne and asked to decommission Falcon agents from EC2 instances
spun up in account 709144918866 to stop incurring license charges.

The deployer's CrowdStrike machinery is already a partial decommission:
the OIL-side install role at
`open-install-library/test/deploy/crowdstrike/roles/configure/tasks/main.yml`
is a no-op stub that prints `"Skipping CrowdStrike Falcon Sensor
installation"`. So the deployer has been bundling
`shared-crowdstrike-ansible-role` from a private Galaxy collection that
nothing invokes — vestigial dead code that today only exists to break
the publish workflow when its SSH deploy key (`CROWDSTRIKE_REPO_KEY`)
goes stale.

This change removes the three deployer-side touchpoints:

- `requirements.ansible.private.yml`: the single-entry private Galaxy
  collection file pointing at `shared-crowdstrike-ansible-role`.
- `Dockerfile`: the `RUN mkdir -p ... ssh-keyscan` line and the
  `RUN --mount=type=secret,id=ssh_private_key ...` block that cloned
  that private repo at image-build time.
- `.github/workflows/publish.yml`: the `secrets:` block that passed
  `CROWDSTRIKE_REPO_KEY` into the Docker build.

After this PR, `publish.yml` no longer needs `CROWDSTRIKE_REPO_KEY` as
a secret. The image continues to install all public Ansible
collections from `requirements.ansible.yml` exactly as before; nothing
that any test invokes is removed.

If/when SentinelOne replaces Falcon in the deployer-driven test
infrastructure (it currently does not), it would be added at the same
layer with a different role + secret. NR-520645 explicitly asks for
"decommission", not "replace", and there is no `shared-sentinelone-
ansible-role` repo in the org today, so this PR scopes itself to the
removal only.
@pranav-new-relic
pranav-new-relic force-pushed the feature/remove-crowdstrike branch from 5b742a5 to 3986343 Compare June 11, 2026 08:11
pranav-new-relic added a commit to newrelic/open-install-library that referenced this pull request Jun 11, 2026
Companion to newrelic-experimental/deployer#33,
which removes the CrowdStrike Ansible Galaxy collection from the
deployer image. This PR removes the matching dead code in OIL:

- test/deploy/crowdstrike/ — the install role was already a no-op
  debug stub ("Skipping CrowdStrike Falcon Sensor installation"); it
  has no consumers other than the manual test definition removed
  below.
- test/manual/definitions/infra-agent/ubuntu20-infra-crowdstrike.json
  — the manual test that exercised the stub.
- nonregression.yml / nonregression-eu.yml / nonregression-jp.yml —
  removed the CROWDSTRIKE_CLIENT_ID/SECRET/CUSTOMER_ID env block and
  the matching `-e` docker-run flags. The env vars were inert (no
  Ruby code or playbook reads them since the install role was stubbed)
  and the corresponding repo secrets can be removed separately.

Per NR-520645 (closed P2): NR migrated off CrowdStrike Falcon to
SentinelOne and asked to decommission Falcon agents from EC2 instances
spun up in account 709144918866. The deployer/OIL chain has been
silently skipping the install for a while; this completes the cleanup.
@pranav-new-relic
pranav-new-relic merged commit 08c7e44 into main Jun 11, 2026
12 of 15 checks passed
pranav-new-relic added a commit to newrelic/open-install-library that referenced this pull request Jun 22, 2026
## What this PR does

- **JP region test infrastructure** — clones `test/definitions-eu/` → `test/definitions-jp/` and adds matching workflows (`smoke-jp.yml`, `nonregression-jp.yml`, `cleanup-jp.yml`, `*-dp` variants) with the region rewrites (URLs, `*_JP` secret refs, `open-install-library-e2e-jp` identity name, `ap-northeast-1`).

- **Region-aware `validation.yml`** — splits the per-PR test-deploy matrix by path: `definitions/*` → US, `definitions-eu/*` → EU NerdGraph + EU secret, `definitions-jp/*` → JP NerdGraph + JP secret. Adds `create-system-identity-{eu,jp}` and `cleanup-system-identity-{eu,jp}` jobs; matrix builder now uses `--diff-filter=AMR` so deleted files don't enter the matrix.

- **Cross-region coverage parity** — added modern infra-agent OSes (Debian 11–13, Ubuntu 20/22/24, RHEL 9/10, Amazon Linux 2023, SUSE 15.4/5/7), OHI (Redis, RabbitMQ, Elasticsearch), and modern PHP (Ubuntu 22 fpm-wordpress) to both EU and JP. Bumped Debian 10→12 where deprecated, replaced Oracle 8 with RHEL 9, bumped redhat9-infra to `t3.small` for boot reliability, bumped dotnet ASP.NET runtime 5.0→8.0.

- **CrowdStrike removal** — deletes the no-op install stub + its only test consumer + the env-block references in `nonregression*.yml` (companion to deployer #33; [NR-520645](https://new-relic.atlassian.net/browse/NR-520645)). Backing deployer bundle is being removed separately; repo `CROWDSTRIKE_*` secrets can be deleted afterwards.

- **Flake/transient resilience** — retry-wrappers around `docker pull newrelic/deployer:latest`, the Apache `a2enmod` step in the dotnet deploy (start.yml), and `apt install` on Ubuntu 18 EOL mirrors in PHP-WordPress (configure.yml). Same `register`/`until`/`retries`/`delay` pattern used for the mvn retry in github.com/newrelic/demo-javatron/issues/48.

- **End-to-end NRQL verification** — run [`27671298270`](https://github.com/newrelic/open-install-library/actions/runs/27671298270) is fully green (94/96, 0 failures). AGENT entities + `FLEET → AGENT (CONTAINS)` relationships were observed via `NrAuditEvent` in EU NR (account 6729572) and JP NR (account 8163026), each inside the matching test window. Evidence in the [PR comment](#1377 (comment)).

- **Synced with `main`** — pulled agent-control 1.16.1 → 1.17.0 from #1381 (clean auto-merge).

## Prerequisites

1. newrelic-experimental/deployer#32 (merged) + image republish so `newrelic/deployer:latest` includes the `jp:` block under `newRelicUrls`.
2. GitHub repo secrets: `GIT_DEPLOYER_DOCKER_USER_CONFIG_JP` (with `credentials.secrets.{nrHostFleetId, nrWindowsHostFleetId}` populated for the JP fleets) — verified live in run 27671298270.
3. `gitdeployerCanada` keypair imported into AWS region `ap-northeast-1`.

## Companion PRs

- Deployer JP region: newrelic-experimental/deployer#32 (merged)
- Deployer CrowdStrike removal: newrelic-experimental/deployer#33
- newrelic-cli JP workflows: newrelic/newrelic-cli#1851


[NR-520645]: https://new-relic.atlassian.net/browse/NR-520645?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants