- Add TLS support to the deployment chart
- Enable TLS on k8s in production
- Add Additional LVS endpoint configuration
- Switch services to use the TLS LVS
- Remove non-TLS LVS endpoint configuration
- Remove the non-TLS k8s service
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | JMeybohm | T235411 Add TLS termination to services running on kubernetes | |||
Resolved | JMeybohm | T255868 Move citoid to use TLS only |
Event Timeline
Change 625592 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] profile::services_proxy::envoy: add zotero as a backend
Change 625592 merged by Giuseppe Lavagetto:
[operations/puppet@production] profile::services_proxy::envoy: add zotero as a backend
Change 625595 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/deployment-charts@master] citoid: make the zotero port configurable
Change 625596 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/deployment-charts@master] citoid: use the service proxy
Change 625600 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] citoid: add LVS endpoint
Change 625601 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] citoid: promote https lvs to production status
Change 625602 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] service_proxy: switch citoid to TLS
Change 625603 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] citoid: remove unencrypted LVS endpoint
Change 625595 merged by jenkins-bot:
[operations/deployment-charts@master] citoid: make the zotero port configurable
Change 625596 merged by jenkins-bot:
[operations/deployment-charts@master] citoid: use the service proxy
Change 625600 merged by Giuseppe Lavagetto:
[operations/puppet@production] citoid: add TLS LVS endpoint
Change 625601 merged by Giuseppe Lavagetto:
[operations/puppet@production] citoid: promote https lvs to production status
Change 625602 merged by Giuseppe Lavagetto:
[operations/puppet@production] service_proxy: switch citoid to TLS
Change 629077 had a related patch set uploaded (by JMeybohm; owner: JMeybohm):
[operations/puppet@production] citoid: remove unencrypted LVS endpoint 1/2
Change 629077 merged by Giuseppe Lavagetto:
[operations/puppet@production] citoid: remove unencrypted LVS endpoint 1/2
Change 625603 merged by JMeybohm:
[operations/puppet@production] citoid: remove unencrypted LVS endpoint 2/2
Mentioned in SAL (#wikimedia-operations) [2020-09-22T14:05:57Z] <jayme> running puppet on lvs servers - T255868 T255877
Mentioned in SAL (#wikimedia-operations) [2020-09-22T14:09:15Z] <jayme> restarting pybal on lvs1016.eqiad.wmnet,lvs2010.codfw.wmnet - T255868 T255877
Mentioned in SAL (#wikimedia-operations) [2020-09-22T14:11:21Z] <jayme> restarting pybal on lvs1015.eqiad.wmnet,lvs2009.codfw.wmnet - T255868 T255877
Mentioned in SAL (#wikimedia-operations) [2020-09-22T14:12:01Z] <jayme> running ipvsadm -D -t 10.2.2.19:1970; ipvsadm -D -t 10.2.2.21:24766 on lvs1016.eqiad.wmnet,lvs1015.eqiad.wmnet - T255868 T255877
Mentioned in SAL (#wikimedia-operations) [2020-09-22T14:12:40Z] <jayme> running ipvsadm -D -t 10.2.1.19:1970; ipvsadm -D -t 10.2.1.21:24766 on lvs2010.codfw.wmnet,lvs2009.codfw.wmnet - T255868 T255877
Change 629646 had a related patch set uploaded (by JMeybohm; owner: JMeybohm):
[operations/puppet@production] monitor_services: switch citoid monitor to https
Change 629646 merged by JMeybohm:
[operations/puppet@production] monitor_services: switch citoid monitor to https
Change 631147 had a related patch set uploaded (by JMeybohm; owner: JMeybohm):
[operations/puppet@production] services_proxy: Add nodejs keepalive timeout (4.5s) to citoid and zotero
Change 631147 merged by JMeybohm:
[operations/puppet@production] services_proxy: Add nodejs keepalive timeout (4.5s) to citoid and zotero
Change 715449 had a related patch set uploaded (by JMeybohm; author: JMeybohm):
[operations/deployment-charts@master] citoid: Remove HTTP service from kubernetes
Change 715449 merged by jenkins-bot:
[operations/deployment-charts@master] citoid: Remove HTTP service from kubernetes