Page MenuHomePhabricator

Investigate decommissioning two eqiad-frack vlans
Closed, ResolvedPublic

Description

the frack infra in eqiad has two vlans not present in codfw:

  • frack-external1-c-eqiad (doesn't seem to have any host in it)
  • frack-DMZ1-c-eqiad (one host)

In an optic of having the less differences between the two sites, are those vlans still needed?

Event Timeline

Sounds like frack-external1-c-eqiad serves no purpose anymore and we should remove it.

DMZ1 has samarium in it, which is a public-reporting webserver. Since we're using host-based firewalls, I think it would be fine to merge this VLAN with the payments-listener server VLAN.

Jgreen changed the task status from Open to Stalled.Jun 21 2018, 7:02 PM
Aklapper changed the task status from Stalled to Open.Aug 16 2020, 2:10 PM

@Jgreen: Boldly resetting task status as the previous comments don't explain who or what (task?) exactly this task is stalled on ("If a report is waiting for further input (e.g. from its reporter or a third party) and can currently not be acted on").

For the records, both frack-external1-c-eqiad and frack-DMZ1-c-eqiad are listed under frack in https://phabricator.wikimedia.org/source/operations-puppet/browse/production/modules/network/data/data.yaml

Jgreen changed the task status from Open to Stalled.Aug 17 2020, 12:40 PM

@Jgreen: Boldly resetting task status as the previous comments don't explain who or what (task?) exactly this task is stalled on ("If a report is waiting for further input (e.g. from its reporter or a third party) and can currently not be acted on").

For the records, both frack-external1-c-eqiad and frack-DMZ1-c-eqiad are listed under frack in https://phabricator.wikimedia.org/source/operations-puppet/browse/production/modules/network/data/data.yaml

Looking at those options I supposed 'waiting on input' is appropriate.

@Jgreen: Thanks for the quick reply! Who exactly is supposed to provide input?

@Jgreen: Thanks for the quick reply! Who exactly is supposed to provide input?

Fundraising Tech, Fundraising Tech Ops, and Network Operations. Basically the point is to refactor the VLANs for the fundraising cluster, which is a nontrivial task and implies a bunch of other tasks. It's just a consistency thing, having things the way they are now is not causing problems. So it's low priority, significant effort. I originally stalled it after noticing that nobody had followed up on it for nearly a year after.

samarium is 7 years old, dunno if a replacement has been planned (see also T245161) but it could be a good opportunity to move it out of that vlan.

samarium is 7 years old, dunno if a replacement has been planned (see also T245161) but it could be a good opportunity to move it out of that vlan.

Samarium was replaced a while back, the host in that vlan now is frdata1001. But we are looking at a role change for that host over the next few months and can look at the possibility moving it to another vlan at that time.

I think it makes sense to merge frack-listener-{site} with frack-DMZ1-{site} as a non-PCI web services vlan, possibly renamed to something more appropriate.

Jgreen changed the task status from Stalled to Open.Mar 12 2021, 7:41 PM
Jgreen moved this task from Backlog to In Progress on the fundraising-tech-ops board.

Mentioned in SAL (#wikimedia-operations) [2021-03-16T20:15:52Z] <XioNoX> remove DMZ zone from pfw3-eqiad - T174203

From Netbox:

Deleted prefix 10.64.40.128/27
Deleted vlan frack-DMZ1-c-eqiad

ayounsi claimed this task.

And fully removed from pfw/fasw-eqiad