Page MenuHomePhabricator

update *.tools.wmflabs.org certificate
Closed, ResolvedPublic0 Estimated Story Points

Description

This task will track the implementation of the updated/renewed *.tools.wmflabs.org certificate and key.

The new key is already committed to the private puppet repo as new.star.tools.wmflabs.org.key. The new certificate will be linked into this task via gerrit patchset once the order is received by @RobH. Then this task will be reassigned to the cloud-services-team for implementation.

implementation details

The gerrit patchset https://gerrit.wikimedia.org/r/510250 stages the new certificate, and the new private key is stored in the private puppet repo as new.star.tools.wmflabs.org. Please ensure both the private key and the staged certificate are merged live at the same time, or failures will result.

Related Objects

StatusSubtypeAssignedTask
Resolvedaborrero

Event Timeline

RobH triaged this task as High priority.May 14 2019, 8:31 PM
RobH created this task.

Change 510250 had a related patch set uploaded (by RobH; owner: RobH):
[operations/puppet@production] updating/renewing star.tools.wmflabs.org cert/keypair

https://gerrit.wikimedia.org/r/510250

RobH removed a project: Patch-For-Review.
RobH updated the task description. (Show Details)

@aborrero: Since you were the one to confirm the certificate usage on the procurement task, would you also be the person to implement the renewed certificate/keypair?

If not, can you advise/reassign to who would handle this? Thanks in advance!

The gerrit patchset https://gerrit.wikimedia.org/r/510250 stages the new certificate, and the new private key is stored in the private puppet repo as new.star.tools.wmflabs.org.

RobH mentioned this in Unknown Object (Task).May 14 2019, 9:52 PM

Mentioned in SAL (#wikimedia-cloud) [2019-05-20T10:53:00Z] <arturo> T223332 disable puppet agent in tools-k8s-master and tools-docker-registry nodes

Mentioned in SAL (#wikimedia-operations) [2019-05-20T11:01:47Z] <arturo> icinga downtime toolschecker for 3h for T223332

Change 510250 merged by Arturo Borrero Gonzalez:
[operations/puppet@production] updating/renewing star.tools.wmflabs.org cert/keypair

https://gerrit.wikimedia.org/r/510250

Mentioned in SAL (#wikimedia-cloud) [2019-05-20T11:25:19Z] <arturo> T223332 enable puppet agent in tools-k8s-master and tools-docker-registry nodes and deploy new SSL cert

This has been done. Thanks @RobH