Page MenuHomePhabricator

labweb1001 and 1002 need to access labnet1001.eqiad.wmnet:8774 (and labnet1002.eqiad.wmnet:8774)
Closed, ResolvedPublic

Description

Right now nova-api resides on an internal host (labs-hosts-b) and we have been very cautious about any connectivity between the labs-hosts VLAN and private VLANs. I don't think it's crazy to allow nova-api to respond to queries from private (it's the responses being blocked) but our general agreed on model is to put anything serving cloud and cloud instances in the public VLAN and to use iptables to lock down rather than watering down the restriction between cloud and prod private. In the mid-term nova-api will move to the labcontrol host (or equiv) which is already in the public VLAN as well so let's put labweb in public for now as the most consistent option and revisit later (once nova-api no longer on an internal host)


Currently our wmcs web UI hosts are on public IPs. We're moving all those services to new hosts, labweb1001 and 1002.

The services running on labweb hosts will need to access a variety of openstack endpoints:

All of those are simple ferm changes except for the last one -- labnet hosts are on a different private vlan and I'm not clear on how to get access set up between labweb and labnet.

I've been assuming that those hosts would be on private IPs behind misc-web -- that's how they're set up currently. It wouldn't hurt me any to move labweb hosts to public IPs if that's somehow necessary.

Details

Related Gerrit Patches:

Event Timeline

Andrew triaged this task as Medium priority.Feb 7 2018, 5:00 PM
Andrew created this task.
Restricted Application removed a project: Patch-For-Review. · View Herald TranscriptFeb 7 2018, 5:00 PM
Andrew renamed this task from labweb1001 and 1002 need to access labnet.eqiad.wmnet:8774 to labweb1001 and 1002 need to access labnet1001.eqiad.wmnet:8774 (and labnet1002.eqiad.wmnet:8774).Feb 7 2018, 5:01 PM
Andrew added a subscriber: ayounsi.

Change 408841 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/dns@master] labweb: move labweb1001 and 1002 back to public IPs

https://gerrit.wikimedia.org/r/408841

chasemp updated the task description. (Show Details)Feb 7 2018, 6:41 PM

silenced labweb100[12] in icinga

Mentioned in SAL (#wikimedia-operations) [2018-02-07T19:11:02Z] <chasemp> after conversation with andrew we moved labweb to public for T186729

chasemp closed this task as Resolved.Feb 7 2018, 7:11 PM

Change 408841 merged by Andrew Bogott:
[operations/dns@master] labweb: move labweb1001 and 1002 back to public IPs

https://gerrit.wikimedia.org/r/408841

Change 408854 had a related patch set uploaded (by Andrew Bogott; owner: Andrew Bogott):
[operations/puppet@production] Move labweb1001 and 1002 back to public IPs

https://gerrit.wikimedia.org/r/408854

Change 408854 merged by Andrew Bogott:
[operations/puppet@production] Move labweb1001 and 1002 back to public IPs

https://gerrit.wikimedia.org/r/408854