| | Status | Subtype | Assigned | Task |
---|
| | Resolved | | LSobanski | T111653 Encrypt all the things |
| | Resolved | | BBlack | T92602 Secure inter-datacenter web request log (Kafka) traffic |
| | Resolved | | Ottomata | T106581 Build 0.8.2.1 Kafka package and upgrade Kafka brokers |
| | Declined | | Ottomata | T98161 Build Kafka 0.8.1.1 package for Jessie and upgrade Brokers to Jessie. |
| | Resolved | | Ottomata | T103106 Create jmxtrans Jessie package |
| | Resolved | | Ottomata | T90640 Audit hyperthreading on analytics nodes. |
| | Resolved | | Eevans | T108953 Cassandra inter-node encryption (TLS) |
| | Resolved | | RobH | T111382 codfw 3x spares for cassandra encryption testing |
| | Resolved | | Ottomata | T97294 Turn off webrequest udp2log instances. |
| | Resolved | | Ottomata | T97771 Backport? and install kafkacat (on stat1002?) |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | | | | Restricted Task |
| | Resolved | | Jgreen | T110592 package udp-filter for Trusty, for use on fundraising banner_logger |
| | Resolved | | Jgreen | T110740 build libcidr package for Trusty |
| | Resolved | | Jgreen | T110739 build libanon package for trusty |
| | Resolved | | Jgreen | T112139 build librdkafka for Trusty |
| | Resolved | | Jgreen | T110591 reformulate kafkatee package to work with Trusty |
| | | | | Restricted Task |
| | Resolved | | awight | T97676 Verify kafkatee use for fundraising logs on erbium |
| | Resolved | | coren | T97860 Add andyrussg to udp2log-users group to allow him to verify kafkatee generated fundraising log files on erbium |
| | Resolved | | awight | T116800 Impression log parsers should get sample rate from filenames |
| | Resolved | | Ottomata | T117727 Turn off sqstat udp2log instance |
| | Resolved | | Ottomata | T83580 Overhaul reqstats |
| | Resolved | | Joe | T118979 Migrate reqstats icinga alerts to new graphite metrics and deprecate or adapt reqstats gdash |
| | Resolved | | jcrespo | T111654 Set up TLS for MariaDB replication |
| | Resolved | | jcrespo | T120122 Perform a rolling restart of all MySQL slaves (masters too for those services with low traffic) |
| | Resolved | | • Cmjohnson | T120689 es1019 and its management interface are unresponsive |
| | Resolved | | jcrespo | T151995 Rolling restart of external storage servers for TLS certificate update |
| | Resolved | | jcrespo | T152029 Rolling restart of parsercache servers for TLS certificate update |
| | Resolved | | jcrespo | T152188 Restart pending mysql hosts with old TLS cert |
| | Resolved | | Marostegui | T152364 db1047 out of disk space, eventlogging_sync spam |
| | Duplicate | | None | T152595 Implement TLS expiration/validation checking for MariaDB certificates |
| | Resolved | | jcrespo | T156005 Reimage db1065 and db1066 |
| | Resolved | | faidon | T82576 Enable STARTTLS (both inbound and outbound) on lists |
| | Resolved | | Dzahn | T105756 Mailman Upgrade (Jessie & Mailman 2.x) and migration to a VM |
| | Resolved | | Dzahn | T108057 Phabricator NDA for John Lewis |
| | | | | Restricted Task |
| | Resolved | | Dzahn | T108073 test importing of mailing list configs and archives on staging VM |
| | Resolved | | Dzahn | T108071 export config and archive data from sodium |
| | Resolved | | Dzahn | T108080 service IP can't be switched over |
| | Resolved | | Dzahn | T108082 give John Lewis shell access on the mailman staging VM |
| | Resolved | | Dzahn | T108070 install jessie on new VM for mailman |
| | Resolved | | RobH | T108065 eqiad: 1 VM request for mailman |
| | Resolved | | Dzahn | T108383 create basic mailman setup on fermium (jessie) for testing import |
| | Resolved | | RobH | T109393 rename wikitech-announce.disabled.T100503 |
| | Resolved | | Dzahn | T109399 go through all directories in /var/lib/mailman and decide if migration is needed |
| | Resolved | | Dzahn | T109467 write migration plan for mailman |
| | Resolved | | Dzahn | T109539 rename lists mwapi-team.disabled.T97148 and flowfunding.disabled.T97328 ? |
| | Resolved | | • JohnLewis | T109624 move mailman server and service IPs to hiera / make it possible to run multiple instances at once |
| | Resolved | | Dzahn | T109838 clean up mailman data directory (moderated messages > 0.5 million) |
| | | | | Restricted Task |
| | Resolved | | Dzahn | T109890 reinstall fermium with public IP |
| | Resolved | | Dzahn | T109923 add public IP for fermium - DNS and DHCP change for reinstall |
| | Duplicate | | Dzahn | T109891 announce mailman downtime |
| | Resolved | | Dzahn | T109921 setup rsyncd on fermium to copy files from sodium |
| | Resolved | | Dzahn | T109922 write script to import mailing lists from other server |
| | Duplicate | | Dzahn | T109924 reinstall fermium with jessie and public IP |
| | Resolved | | Dzahn | T109925 apply regular lists role on fermium and confirm no issues |
| | Resolved | | Dzahn | T110695 mailman: listinfo template encoding |
| | Resolved | | Dzahn | T110129 rsync all configs and archives one more time |
| | Invalid | | Dzahn | T110131 import all lists with the script we wrote for that |
| | Resolved | | Dzahn | T110132 lower lists.wikimedia.org TTL to 5 min |
| | Resolved | | Dzahn | T110133 announce scheduled downtime |
| | Declined | | Dzahn | T110135 right before the switch: lower TTL to 10 seconds |
| | Resolved | | Dzahn | T110136 hold lists.wikimedia.org with exim |
| | Resolved | | Dzahn | T110137 shut down mailman on sodium |
| | Resolved | | Dzahn | T110138 rsync the diff since mail was held on sodium |
| | Resolved | | Dzahn | T110139 switch over mailman service IP |
| | Resolved | | Dzahn | T110140 send follow-up email, announce changes with new mailman version if any that have user impact |
| | Resolved | | • JohnLewis | T110382 mailman cronjobs not running? |
| | Resolved | | Dzahn | T110440 rsync exim spool directory |
| | Resolved | | Dzahn | T110441 test sending individual mails from fermium during migration |
| | Resolved | | Dzahn | T112229 fermium needs to have exim4-daemon-heavy installed, not -light |
| | Resolved | | Dzahn | T113020 run /var/lib/mailman/bin/update and ./check_perms |
| | Resolved | | Dzahn | T113045 start exim on fermium / revert migration hack |
| | Resolved | | faidon | T109239 Ensure mailman VM setup has adequate entropy for STARTTLS |
| | Resolved | | faidon | T101452 Protect incoming emails with SMTP STARTLS |
| | Resolved | | faidon | T113211 Replace primary mail relays (polonium/lead) |
| | Resolved | | Gehel | T124444 Look into encrypting Elasticsearch traffic |
| | Resolved | | Gehel | T128077 Create a PKI that can be used by Puppet and for general purpose certificates |
| | Resolved | | EBernhardson | T130219 Implement connection pooling for elasticsearch connections |
| | Resolved | | Gehel | T130365 Enable metric collection on nginx for elasticsearch |
| | Resolved | | Gehel | T130366 Should we have a specific check for SSL certificate expiration on elasticsearch |
| | Resolved | | Gehel | T131839 Activate SSL + connection pooling for CirrusSearch on PROD |
| | Open | | None | T126989 MediaWiki logging & encryption |
| | Resolved | | fgiunchedi | T127455 Enable HTTPS for Swift traffic |
| | Open | | None | T127498 git/http operations in scap should be secure |
| | Resolved | | fgiunchedi | T136312 Encrypt syslog traffic |
| | Declined | | ArielGlenn | T123560 investigate rsync between dcs with encryption |
| | Resolved | | Jgreen | T142993 encrypt fundraising kafka collector traffic |
| | Resolved | | Ottomata | T166167 Write generic certificate management software for use with Puppet and Self Signing CAs. |
| | Resolved | | Jgreen | T142994 configure TLS for fundraising syslog collection |
| | Resolved | | Jgreen | T145116 replace indium (eqiad fundraising logger) with new hardware running jessie |
| | | | | Unknown Object (Task) |
| | | | | Unknown Object (Task) |
| | | | | Unknown Object (Task) |
| | Resolved | | faidon | T159336 deploy firewall policies for (barium,lutetium,db1025,indium) replacements (civi1001,frdev1001,frdb1002,frlog1001) |
| | Resolved | | Jgreen | T163127 rack and cable frlog1001 |
| | Resolved | | • Cmjohnson | T164748 configure RAID on frlog1001 |
| | Resolved | | aaron | T160616 Enable HTTPS for swift clients |
| | Resolved | | fgiunchedi | T161717 Point swiftrepl to swift HTTPS |