Page MenuHomePhabricator

notebook1001 shown as DOWN in icinga, due to firewall rules
Closed, ResolvedPublic

Description

icinga reports notebook1001 as a DOWN host. but it is actually up.

There are iptables rules on it that don't appear to be puppetized and probably prevent icinga from connecting to it.

From puppet just base::firewall is included but there are things like

Chain DOCKER-ISOLATION (1 references)

That should probably be done with ferm rules (and base::firewall would leave the standard holes for icinga open)

Event Timeline

Briefly talked to Yuvi and Madhu. These rules come from the docker package.

still marked as DOWN in Icinga for a couple months now. notebook1002 does not have this issue

Dzahn claimed this task.
Dzahn added a project: Analytics.

no response since 2016 and meanwhile there is no more notebook1001. closing.