Page MenuHomePhabricator

Move wikifeeds to use TLS only
Open, MediumPublic

Description

  • Add TLS support to the deployment chart
  • Enable TLS on k8s in production
  • Add Additional LVS endpoint configuration
  • Switch services to use the TLS LVS
  • Remove non-TLS LVS endpoint configuration
  • Remove the non-TLS k8s service

Event Timeline

JMeybohm created this task.Jun 19 2020, 3:42 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptJun 19 2020, 3:42 PM
JMeybohm triaged this task as Medium priority.Jul 21 2020, 7:54 AM
jijiki moved this task from Incoming 🐫 to Unsorted on the serviceops board.Aug 17 2020, 11:45 PM

Change 626132 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/deployment-charts@master] wikifeeds: use the service proxy in staging

https://gerrit.wikimedia.org/r/626132

Change 626132 merged by jenkins-bot:
[operations/deployment-charts@master] wikifeeds: use the service proxy in staging

https://gerrit.wikimedia.org/r/626132

Change 627517 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/deployment-charts@master] wikifeeds: use the service proxy everywhere

https://gerrit.wikimedia.org/r/627517

Change 627517 merged by jenkins-bot:
[operations/deployment-charts@master] wikifeeds: use the service proxy everywhere

https://gerrit.wikimedia.org/r/627517

Change 628756 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/deployment-charts@master] wikifeeds: use the service proxy for reaching the MediaWiki api

https://gerrit.wikimedia.org/r/628756

Change 629154 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] services: add TLS encrypted endpoint for wikifeeds (1/2)

https://gerrit.wikimedia.org/r/629154

Change 629155 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] services: add TLS encrypted endpoint for wikifeeds (2/2)

https://gerrit.wikimedia.org/r/629155

Change 629154 merged by Giuseppe Lavagetto:
[operations/puppet@production] services: add TLS encrypted endpoint for wikifeeds (1/2)

https://gerrit.wikimedia.org/r/629154

Change 629155 merged by Giuseppe Lavagetto:
[operations/puppet@production] services: add TLS encrypted endpoint for wikifeeds (2/2)

https://gerrit.wikimedia.org/r/629155

Joe updated the task description. (Show Details)Mon, Sep 28, 10:19 AM

Change 628756 abandoned by Giuseppe Lavagetto:
[operations/deployment-charts@master] wikifeeds: use the service proxy for reaching the MediaWiki api

Reason:

https://gerrit.wikimedia.org/r/628756

Change 631405 had a related patch set uploaded (by JMeybohm; owner: JMeybohm):
[operations/puppet@production] lvs: Remove wikifeeds non-TLS endpoint 1/2

https://gerrit.wikimedia.org/r/631405

Change 631406 had a related patch set uploaded (by JMeybohm; owner: JMeybohm):
[operations/puppet@production] lvs: Remove wikifeeds non-TLS endpoint 2/2

https://gerrit.wikimedia.org/r/631406

Change 631405 merged by JMeybohm:
[operations/puppet@production] lvs: Remove wikifeeds non-TLS endpoint 1/2

https://gerrit.wikimedia.org/r/631405

Change 631406 merged by JMeybohm:
[operations/puppet@production] lvs: Remove wikifeeds non-TLS endpoint 2/2

https://gerrit.wikimedia.org/r/631406

Mentioned in SAL (#wikimedia-operations) [2020-10-01T14:48:36Z] <jayme> restarting pybal on lvs2010.codfw.wmnet - T244843 T255878

Mentioned in SAL (#wikimedia-operations) [2020-10-01T14:50:02Z] <jayme> restarting pybal on lvs1015.eqiad.wmnet,lvs2009.codfw.wmnet - T244843 T255878

Mentioned in SAL (#wikimedia-operations) [2020-10-01T14:53:48Z] <jayme> running ipvsadm -D -t 10.2.1.10:8081; ipvsadm -D -t 10.2.1.47:8889 on lvs2010.codfw.wmnet,lvs2009.codfw.wmnet - T244843 T255878

Mentioned in SAL (#wikimedia-operations) [2020-10-01T14:55:43Z] <jayme> running ipvsadm -D -t 10.2.2.10:8081; ipvsadm -D -t 10.2.2.47:8889 on lvs1015.eqiad.wmnet - T244843 T255878

JMeybohm updated the task description. (Show Details)Fri, Oct 2, 8:36 AM