Page MenuHomePhabricator

serve our production ssh known_hosts file over public HTTPS
Closed, ResolvedPublic

Description

There's not really good reason why this data only has to live on the bastions and require SSH access to access.

Furthermore it'd be a way of trusting the bastion hosts on initial machine setup, removing a trust dependency there.

config-master.wikimedia.org (served by the puppetmasters) seems like a fine place for it to live, and is already served publicly.

Event Timeline

Change 609796 had a related patch set uploaded (by Jbond; owner: John Bond):
[operations/puppet@production] SSHFP: add a text file with the SSHFB of all hosts

https://gerrit.wikimedia.org/r/609796

jcrespo triaged this task as Medium priority.Jul 8 2020, 10:43 AM
jcrespo subscribed.

Feel free to alter the priority, only setting it so to remove it from untriaged tickets list.

Change 609796 merged by Jbond:
[operations/puppet@production] SSHFP: add a text file with the SSHFB of all hosts

https://gerrit.wikimedia.org/r/609796

Volans claimed this task.
Volans subscribed.

This is already available on https://config-master.wikimedia.org/ , resolving.