Page MenuHomePhabricator

Site: 4 VM request for kubernetes
Closed, ResolvedPublic

Description

Labs Project Tested: deployment-prep
Site/Location:EQIAD and CODFW
Number of systems: 4, 2 per DC
Service: kubernetes
Networking Requirements: internal IP
Processor Requirements: 2
Memory: 4G
Disks: 10G
Other Requirements:

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald TranscriptApr 12 2019, 1:34 PM
akosiaris triaged this task as Normal priority.Apr 12 2019, 1:39 PM
jijiki added a subscriber: jijiki.

Change 504311 had a related patch set uploaded (by Alexandros Kosiaris; owner: Alexandros Kosiaris):
[operations/dns@master] Introduce kubernetes{1,2}00{5,6}.{eqiad,codfw}.wmnet

https://gerrit.wikimedia.org/r/504311

Change 504311 merged by Alexandros Kosiaris:
[operations/dns@master] Introduce kubernetes{1,2}00{5,6}.{eqiad,codfw}.wmnet

https://gerrit.wikimedia.org/r/504311

Change 504342 had a related patch set uploaded (by Alexandros Kosiaris; owner: Alexandros Kosiaris):
[operations/puppet@production] Add kubernetes[12]00[56]

https://gerrit.wikimedia.org/r/504342

Change 504851 had a related patch set uploaded (by Alexandros Kosiaris; owner: Alexandros Kosiaris):
[operations/puppet@production] Give roles to the new kubernetes[12]00[56] VMs

https://gerrit.wikimedia.org/r/504851

Change 504342 merged by Alexandros Kosiaris:
[operations/puppet@production] Add kubernetes[12]00[56]

https://gerrit.wikimedia.org/r/504342

Change 504872 had a related patch set uploaded (by Alexandros Kosiaris; owner: Alexandros Kosiaris):
[operations/puppet@production] Fixup for kubernetes-node-virtual.cfg

https://gerrit.wikimedia.org/r/504872

Change 504872 merged by Alexandros Kosiaris:
[operations/puppet@production] Fixup for kubernetes-node-virtual.cfg

https://gerrit.wikimedia.org/r/504872

Change 504877 had a related patch set uploaded (by Alexandros Kosiaris; owner: Alexandros Kosiaris):
[operations/puppet@production] More fixes to kubernetes-node-virtual.cfg

https://gerrit.wikimedia.org/r/504877

Change 504877 merged by Alexandros Kosiaris:
[operations/puppet@production] More fixes to kubernetes-node-virtual.cfg

https://gerrit.wikimedia.org/r/504877

Change 504851 merged by Alexandros Kosiaris:
[operations/puppet@production] Give roles to the new kubernetes[12]00[56] VMs

https://gerrit.wikimedia.org/r/504851

akosiaris assigned this task to ayounsi.Apr 19 2019, 3:00 PM
akosiaris added a subscriber: ayounsi.

This is almost done. That only thing missing seems to be the peering with the juniper routers.

@ayounsi, could you please have a look? What we need is essentially

EQIAD:

set protocols bgp group Kubernetes4 neighbor 10.64.0.145
set protocols bgp group Kubernetes6 neighbor 2620:0:861:101:10:64:0:145
set protocols bgp group Kubernetes4 neighbor 10.64.32.18
set protocols bgp group Kubernetes6 neighbor 2620:0:861:103:10:64:32:18

If you like to keep the current comment stanzas the hosts are kubernetes1005, kubernetes1006 respectively

CODFW:

set protocols bgp group Kubernetes4 neighbor 10.64.32.18
set protocols bgp group Kubernetes6 neighbor 2620:0:861:103:10:64:32:18
set protocols bgp group Kubernetes4 neighbor 10.192.16.102
set protocols bgp group Kubernetes6 neighbor 2620:0:860:102:10:192:16:102

If you like to keep the current comment stanzas the hosts are kubernetes2005, kubernetes2006 respectively

I would do it myself but I am unsure of the way we use currently to update our routers. It used to be jnt, but I haven't used it in a pretty long time. Sorry!

One typo:
codfw has 10.64.32.18 and 2620:0:861:103:10:64:32:18

Other than that it looks all good. Some questions:
Can it be done anytime?
Is your side already listening?
Are the import policy still good or do they need to be update? (eg. import 10.64.64.0/21 and 2620:0:861:cabe::/64` in eqiad.
jnt doesn't manage BGP so it still needs to be done manually.

One typo:
codfw has 10.64.32.18 and 2620:0:861:103:10:64:32:18

Indeed it's 10.192.0.117 and 2620:0:860:101:10:192:0:117

Other than that it looks all good. Some questions:
Can it be done anytime?

Yes.

Is your side already listening?

Yes

Are the import policy still good or do they need to be update? (eg. import 10.64.64.0/21 and 2620:0:861:cabe::/64` in eqiad.

They are still good. There aren't going to be any changes there anytime soon fwiw.

jnt doesn't manage BGP so it still needs to be done manually.

Ah, ok, good to know.

Mentioned in SAL (#wikimedia-operations) [2019-04-22T18:15:10Z] <XioNoX> Add k8s BGP neighbors on cr1/2-codfw - T220822

Mentioned in SAL (#wikimedia-operations) [2019-04-22T18:22:24Z] <XioNoX> Add k8s BGP neighbors on cr1/2-eqiad - T220822

ayounsi closed this task as Resolved.Apr 22 2019, 6:27 PM

Sessions added and established.