Page MenuHomePhabricator

Add Link engineering: Puppetize DB credentials
Closed, ResolvedPublic

Description

Per: T267214#6662762

I have tested the connection from kubernetes1017 which is on 10.64.0, and it works fine, it can reach m2-master.eqiad.wmnet thru port 3306 just fine.
Going to close this as fixed as the DB side is done (T267214#6658395)
As mentioned at T267214#6658395 you might need help from @jijiki or @JMeybohm to puppetize and commit the password to the private repo once ready. If by any reason a firewall hole is required, check this as an example: https://gerrit.wikimedia.org/r/c/operations/puppet/+/643239/1/modules/profile/manifests/mariadb/ferm_misc.pp

Event Timeline

Change 646658 had a related patch set uploaded (by Kosta Harlan; owner: Kosta Harlan):
[operations/deployment-charts@master] linkrecommendation: Add private config for DB write user

https://gerrit.wikimedia.org/r/646658

Change 646658 merged by jenkins-bot:
[operations/deployment-charts@master] linkrecommendation: Add private config for DB admin user

https://gerrit.wikimedia.org/r/646658

JMeybohm claimed this task.

Secrets have been planted with "[puppet-private] (d2082d1e) (jayme) Add linkrecommendation db credentials".
Generated YAML looks fine (deploy1001:/srv/deployment-charts/helmfile.d/services/linkrecommendation$ helmfile -e staging template)