Repository navigation
chore: remove vestigial CrowdStrike Falcon install machinery - #33
Merged
Merged
Conversation
Per NR-520645 (closed P2): NR migrated off CrowdStrike Falcon to SentinelOne and asked to decommission Falcon agents from EC2 instances spun up in account 709144918866 to stop incurring license charges. The deployer's CrowdStrike machinery is already a partial decommission: the OIL-side install role at `open-install-library/test/deploy/crowdstrike/roles/configure/tasks/main.yml` is a no-op stub that prints `"Skipping CrowdStrike Falcon Sensor installation"`. So the deployer has been bundling `shared-crowdstrike-ansible-role` from a private Galaxy collection that nothing invokes — vestigial dead code that today only exists to break the publish workflow when its SSH deploy key (`CROWDSTRIKE_REPO_KEY`) goes stale. This change removes the three deployer-side touchpoints: - `requirements.ansible.private.yml`: the single-entry private Galaxy collection file pointing at `shared-crowdstrike-ansible-role`. - `Dockerfile`: the `RUN mkdir -p ... ssh-keyscan` line and the `RUN --mount=type=secret,id=ssh_private_key ...` block that cloned that private repo at image-build time. - `.github/workflows/publish.yml`: the `secrets:` block that passed `CROWDSTRIKE_REPO_KEY` into the Docker build. After this PR, `publish.yml` no longer needs `CROWDSTRIKE_REPO_KEY` as a secret. The image continues to install all public Ansible collections from `requirements.ansible.yml` exactly as before; nothing that any test invokes is removed. If/when SentinelOne replaces Falcon in the deployer-driven test infrastructure (it currently does not), it would be added at the same layer with a different role + secret. NR-520645 explicitly asks for "decommission", not "replace", and there is no `shared-sentinelone- ansible-role` repo in the org today, so this PR scopes itself to the removal only.
pranav-new-relic
force-pushed
the
feature/remove-crowdstrike
branch
from
June 11, 2026 08:11
5b742a5 to
3986343
Compare
Nandu-pns
approved these changes
Jun 11, 2026
pranav-new-relic
added a commit
to newrelic/open-install-library
that referenced
this pull request
Jun 11, 2026
Companion to newrelic-experimental/deployer#33, which removes the CrowdStrike Ansible Galaxy collection from the deployer image. This PR removes the matching dead code in OIL: - test/deploy/crowdstrike/ — the install role was already a no-op debug stub ("Skipping CrowdStrike Falcon Sensor installation"); it has no consumers other than the manual test definition removed below. - test/manual/definitions/infra-agent/ubuntu20-infra-crowdstrike.json — the manual test that exercised the stub. - nonregression.yml / nonregression-eu.yml / nonregression-jp.yml — removed the CROWDSTRIKE_CLIENT_ID/SECRET/CUSTOMER_ID env block and the matching `-e` docker-run flags. The env vars were inert (no Ruby code or playbook reads them since the install role was stubbed) and the corresponding repo secrets can be removed separately. Per NR-520645 (closed P2): NR migrated off CrowdStrike Falcon to SentinelOne and asked to decommission Falcon agents from EC2 instances spun up in account 709144918866. The deployer/OIL chain has been silently skipping the install for a while; this completes the cleanup.
pranav-new-relic
added a commit
to newrelic/open-install-library
that referenced
this pull request
Jun 22, 2026
## What this PR does
- **JP region test infrastructure** — clones `test/definitions-eu/` → `test/definitions-jp/` and adds matching workflows (`smoke-jp.yml`, `nonregression-jp.yml`, `cleanup-jp.yml`, `*-dp` variants) with the region rewrites (URLs, `*_JP` secret refs, `open-install-library-e2e-jp` identity name, `ap-northeast-1`).
- **Region-aware `validation.yml`** — splits the per-PR test-deploy matrix by path: `definitions/*` → US, `definitions-eu/*` → EU NerdGraph + EU secret, `definitions-jp/*` → JP NerdGraph + JP secret. Adds `create-system-identity-{eu,jp}` and `cleanup-system-identity-{eu,jp}` jobs; matrix builder now uses `--diff-filter=AMR` so deleted files don't enter the matrix.
- **Cross-region coverage parity** — added modern infra-agent OSes (Debian 11–13, Ubuntu 20/22/24, RHEL 9/10, Amazon Linux 2023, SUSE 15.4/5/7), OHI (Redis, RabbitMQ, Elasticsearch), and modern PHP (Ubuntu 22 fpm-wordpress) to both EU and JP. Bumped Debian 10→12 where deprecated, replaced Oracle 8 with RHEL 9, bumped redhat9-infra to `t3.small` for boot reliability, bumped dotnet ASP.NET runtime 5.0→8.0.
- **CrowdStrike removal** — deletes the no-op install stub + its only test consumer + the env-block references in `nonregression*.yml` (companion to deployer #33; [NR-520645](https://new-relic.atlassian.net/browse/NR-520645)). Backing deployer bundle is being removed separately; repo `CROWDSTRIKE_*` secrets can be deleted afterwards.
- **Flake/transient resilience** — retry-wrappers around `docker pull newrelic/deployer:latest`, the Apache `a2enmod` step in the dotnet deploy (start.yml), and `apt install` on Ubuntu 18 EOL mirrors in PHP-WordPress (configure.yml). Same `register`/`until`/`retries`/`delay` pattern used for the mvn retry in github.com/newrelic/demo-javatron/issues/48.
- **End-to-end NRQL verification** — run [`27671298270`](https://github.com/newrelic/open-install-library/actions/runs/27671298270) is fully green (94/96, 0 failures). AGENT entities + `FLEET → AGENT (CONTAINS)` relationships were observed via `NrAuditEvent` in EU NR (account 6729572) and JP NR (account 8163026), each inside the matching test window. Evidence in the [PR comment](#1377 (comment)).
- **Synced with `main`** — pulled agent-control 1.16.1 → 1.17.0 from #1381 (clean auto-merge).
## Prerequisites
1. newrelic-experimental/deployer#32 (merged) + image republish so `newrelic/deployer:latest` includes the `jp:` block under `newRelicUrls`.
2. GitHub repo secrets: `GIT_DEPLOYER_DOCKER_USER_CONFIG_JP` (with `credentials.secrets.{nrHostFleetId, nrWindowsHostFleetId}` populated for the JP fleets) — verified live in run 27671298270.
3. `gitdeployerCanada` keypair imported into AWS region `ap-northeast-1`.
## Companion PRs
- Deployer JP region: newrelic-experimental/deployer#32 (merged)
- Deployer CrowdStrike removal: newrelic-experimental/deployer#33
- newrelic-cli JP workflows: newrelic/newrelic-cli#1851
[NR-520645]: https://new-relic.atlassian.net/browse/NR-520645?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Per NR-520645 (closed, P2), NR migrated off CrowdStrike Falcon to SentinelOne and asked to decommission Falcon agents from EC2 instances spun up in account 709144918866.
The OIL install role is already a no-op stub (prints
"Skipping CrowdStrike Falcon Sensor installation"), so the deployer's bundling ofshared-crowdstrike-ansible-rolewas already vestigial — the only effect today is that it breakspublish.ymlwhenever theCROWDSTRIKE_REPO_KEYdeploy key goes stale, as it currently has.This PR removes the three deployer-side touchpoints:
requirements.ansible.private.yml(deleted), theRUN --mount=type=secret,id=ssh_private_key ...block inDockerfile, and thesecrets:block in.github/workflows/publish.yml. After merge,publish.ymlno longer needsCROWDSTRIKE_REPO_KEY. SentinelOne is not added in this PR — there's noshared-sentinelone-ansible-rolerepo and the ticket scope is decommission-only; if/when it's required on test EC2s, AMI-baking is the natural layer.