Splitting specific concern from more general T344998, and putting in the general task tree.
Description
Details
Event Timeline
Change 961108 had a related patch set uploaded (by JMeybohm; author: JMeybohm):
[operations/deployment-charts@master] wikifunctions: Switch all clusters to use the service mesh
Change 961108 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Switch all clusters to use the service mesh
Change 961111 had a related patch set uploaded (by JMeybohm; author: JMeybohm):
[operations/deployment-charts@master] Revert "wikifunctions: Switch all clusters to use the service mesh"
Change 961111 merged by jenkins-bot:
[operations/deployment-charts@master] Revert "wikifunctions: Switch all clusters to use the service mesh"
Change 961383 had a related patch set uploaded (by JMeybohm; author: JMeybohm):
[operations/deployment-charts@master] wikifunctions: Allow orchestrator to connecto to mw-api-int pods
Change 961383 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Allow orchestrator to connecto to mw-api-int pods
It took me a while to figure this out, sorry. Due to wikifunctions having more strict firewall rules in general, our automation that puts firewall rules in place for service-mesh listeners did not work as expected. This is now fixed within wikifunctions be specifying a explicit rule as following up on the automation part will take some time.
Rolled out to all clusters, wikifunctions still working and the mesh is used according to metrics. I'll claim this task and will remove the firewall rule allowing direct access to mw-api later.
Change 961394 had a related patch set uploaded (by JMeybohm; author: JMeybohm):
[operations/deployment-charts@master] admin_nd: Don't allow uncached api access from wikifunctions
Change 961394 merged by jenkins-bot:
[operations/deployment-charts@master] admin_nd: Don't allow uncached api access from wikifunctions