the frack infra in eqiad has two vlans not present in codfw:
- frack-external1-c-eqiad (doesn't seem to have any host in it)
- frack-DMZ1-c-eqiad (one host)
In an optic of having the less differences between the two sites, are those vlans still needed?
the frack infra in eqiad has two vlans not present in codfw:
In an optic of having the less differences between the two sites, are those vlans still needed?
Sounds like frack-external1-c-eqiad serves no purpose anymore and we should remove it.
DMZ1 has samarium in it, which is a public-reporting webserver. Since we're using host-based firewalls, I think it would be fine to merge this VLAN with the payments-listener server VLAN.
@Jgreen: Boldly resetting task status as the previous comments don't explain who or what (task?) exactly this task is stalled on ("If a report is waiting for further input (e.g. from its reporter or a third party) and can currently not be acted on").
For the records, both frack-external1-c-eqiad and frack-DMZ1-c-eqiad are listed under frack in https://phabricator.wikimedia.org/source/operations-puppet/browse/production/modules/network/data/data.yaml
Fundraising Tech, Fundraising Tech Ops, and Network Operations. Basically the point is to refactor the VLANs for the fundraising cluster, which is a nontrivial task and implies a bunch of other tasks. It's just a consistency thing, having things the way they are now is not causing problems. So it's low priority, significant effort. I originally stalled it after noticing that nobody had followed up on it for nearly a year after.
samarium is 7 years old, dunno if a replacement has been planned (see also T245161) but it could be a good opportunity to move it out of that vlan.
Samarium was replaced a while back, the host in that vlan now is frdata1001. But we are looking at a role change for that host over the next few months and can look at the possibility moving it to another vlan at that time.
I think it makes sense to merge frack-listener-{site} with frack-DMZ1-{site} as a non-PCI web services vlan, possibly renamed to something more appropriate.
Mentioned in SAL (#wikimedia-operations) [2021-03-16T20:15:52Z] <XioNoX> remove DMZ zone from pfw3-eqiad - T174203