Page MenuHomePhabricator

Non zero rated LVS IPs
Closed, DeclinedPublic

Description

To limit the abuse of services (such as Phabricator) on zero rated ranges, one option is to move those services on different IP ranges.

I identified the following v4 /29s:

eqiad - 208.80.155.80/29
codfw - 208.80.152.216/29
esams - 91.198.174.184/29
ulsfo - 198.35.26.128/29

Their adjacent /29 is free and can be reserved in case they need to grow to a /28.

IPv6 doesn't have a shortage of IPs:

codfw - 2620:0:860:ed1a::4:0/110
eqiad - 2620:0:861:ed1a::4:0/110
esams - 2620:0:862:ed1a::4:0/110
ulsfo - 2620:0:863:ed1a::4:0/110

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

Change 370094 had a related patch set uploaded (by Ayounsi; owner: Ayounsi):
[operations/dns@master] Reserve non zero rated IP ranges

https://gerrit.wikimedia.org/r/370094

Change 370201 had a related patch set uploaded (by BBlack; owner: BBlack):
[operations/puppet@production] Add new misc-web-lb IPs

https://gerrit.wikimedia.org/r/370201

Change 370202 had a related patch set uploaded (by BBlack; owner: BBlack):
[operations/puppet@production] Add new git-ssh IPs

https://gerrit.wikimedia.org/r/370202

Change 370210 had a related patch set uploaded (by BBlack; owner: BBlack):
[operations/puppet@production] Add LVS nonzero ranges in network::subnets

https://gerrit.wikimedia.org/r/370210

BBlack changed the task status from Open to Stalled.Aug 14 2017, 6:13 PM

Re-evaluating alternatives here, hold on actual implementation for now.

Change 370201 abandoned by BBlack:
Add new misc-web-lb IPs

https://gerrit.wikimedia.org/r/370201

Change 370202 abandoned by BBlack:
Add new git-ssh IPs

https://gerrit.wikimedia.org/r/370202

Change 370210 abandoned by BBlack:
Add LVS nonzero ranges in network::subnets

https://gerrit.wikimedia.org/r/370210

Change 370094 abandoned by BBlack:
Reserve non zero rated IPs and ranges

https://gerrit.wikimedia.org/r/370094

In light of: https://blog.wikimedia.org/2018/02/16/partnerships-new-approach/ , we're not going to restructure public subnets around this, as that has long-time-horizon implications. We'll deal with these kinds of issues ad-hoc for the remaining lifetime of Zero.