Develop and maintain a manifest of what Cloud Services are actually consuming as far as internal network endpoints for future virtualization, tracking and consideration.
A jump start on this with a specific goal is T207536: Move various support services for Cloud VPS currently in prod into their own instances
Current resources include this list (which needs an update on labstores): https://wikitech.wikimedia.org/wiki/Portal:Cloud_VPS/Admin/Neutron_ideal_model#supporting_services
An example config from our network management system is https://github.com/wikimedia/operations-homer-public/blob/master/templates/cr/firewall.conf#L1437