Page MenuHomePhabricator

check if services behind misc-web enforce http->https redirect or not
Closed, ResolvedPublic

Related Objects

StatusAssignedTask
Resolvedema
OpenBBlack
OpenBBlack
ResolvedBBlack
ResolvedArielGlenn
ResolvedChmarkine
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedCCogdill_WMF
DeclinedBBlack
DuplicateBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedDzahn
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack
ResolvedBBlack

Event Timeline

Dzahn created this task.Jun 25 2015, 1:47 AM
Dzahn raised the priority of this task from to Needs Triage.
Dzahn updated the task description. (Show Details)
Dzahn added a project: Traffic.
Dzahn added a subscriber: Dzahn.
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptJun 25 2015, 1:47 AM
Dzahn claimed this task.Jun 25 2015, 1:47 AM
Dzahn added a project: acl*sre-team.
Dzahn set Security to None.
Dzahn added a comment.Jun 25 2015, 4:24 PM

All service names configured in ''./templates/varnish/misc.inc.vcl.erb''. Are they enforcing https?

{| class="wikitable sortable"

-

! service name !! redirects http->https?

-
[http://git.wikimedia.org git.wikimedia.org]NO
-
[http://doc.wikimedia.org doc.wikimedia.org]YES
-
[http://integration.wikimedia.org integration.wikimedia.org]YES
-
[http://download.wikimedia.org download.wikimedia.org]NO (dumps.wikimedia.org)
-
[http://gerrit.wikimedia.org gerrit.wikimedia.org]YES
-
[http://gdash.wikimedia.org gdash.wikimedia.org]YES
-
[http://performance.wikimedia.org performance.wikimedia.org]YES
-
[http://graphite.wikimedia.org graphite.wikimedia.org]NO
-
[http://logstash.wikimedia.org logstash.wikimedia.org]YES
-
[http://releases.wikimedia.org releases.wikimedia.org]NO
-
[http://scholarships.wikimedia.org scholarships.wikimedia.org]YES
-
[http://transparency.wikimedia.org transparency.wikimedia.org]YES
-
[http://grafana.wikimedia.org grafana.wikimedia.org]NO
-
[http://iegreview.wikimedia.org iegreview.wikimedia.org]YES
-
[http://annual.wikimedia.org annual.wikimedia.org]YES
-
[http://policy.wikimedia.org policy.wikimedia.org]YES
-
[http://parsoid-tests.wikimedia.org parsoid-tests.wikimedia.org]NO (?)
-
[http://horizon.wikimedia.org horizon.wikimedia.org]YES
-
[http://phabricator.wikimedia.org phabricator.wikimedia.org]YES
-
[http://phab.wmfusercontent.org phab.wmfusercontent.org]YES
-
[http://bugzilla.wikimedia.org bugzilla.wikimedia.org]YES
-
[http://bugs.wikimedia.org bugs.wikimedia.org]YES
-
[http://static-bugzilla.wikimedia.org static-bugzilla.wikimedia.org]YES
-
[http://dev.wikimedia.org dev.wikimedia.org]YES (actually redirect on cluster, remove)
-
[http://svn.wikimedia.org svn.wikimedia.org]NO (about to be removed)
-
[http://servermon.wikimedia.org servermon.wikimedia.org]YES
-
[http://people.wikimedia.org people.wikimedia.org]YES
-
[http://ishmael.wikimedia.org ishmael.wikimedia.org]YES
-
[http://racktables.wikimedia.org racktables.wikimedia.org]YES
-
[http://rt.wikimedia.org rt.wikimedia.org]YES
-
[http://metrics.wikimedia.org metrics.wikimedia.org]YES
-
[http://datasets.wikimedia.org datasets.wikimedia.org]NO
-
[http://stats.wikimedia.org stats.wikimedia.org]YES
-
[http://stat1001.wikimedia.org stat1001.wikimedia.org]NO (broken, not in DNS)
-
[http://config-master.wikimedia.org config-master.wikimedia.org]NO
-
[http://noc.wikimedia.org noc.wikimedia.org]YES
-
[http://dbtree.wikimedia.org dbtree.wikimedia.org]YES
-
[http://hue.wikimedia.org hue.wikimedia.org]YES
-
[http://yarn.wikimedia.org yarn.wikimedia.org]YES
-
[http://planet.wikimedia.org planet.wikimedia.org]YES
-
[http://en.planet.wikimedia.org *.planet.wikimedia.org]YES
-
[http://etherpad.wikimedia.org etherpad.wikimedia.org]NO
}
Dzahn closed this task as Resolved.Jun 25 2015, 4:25 PM
Dzahn added a comment.Jun 25 2015, 4:27 PM

stat1001 - removed
dev - pending to be removed
download/dumps - afair there were concerns to enforce https here (what where they exactly?)
releases - uses @webserver class unlike most other services, can't just edit config template
git - to be replaced anyways? phab
graphite/grafana - concerns because of internal tools using it? was moved behind misc-web anyways
parsoid-tests - ??

BBlack moved this task from Triage to Done on the Traffic board.Jun 28 2015, 7:38 PM
Restricted Application added a subscriber: Matanya. · View Herald TranscriptJun 28 2015, 7:38 PM