In #wikimedia-sre it was pointed out that the current situation regarding the lists.wikimedia.org IPs is a legacy thing that we would like not continue forward. With the mailman3 migration, now is a good time as any to plan something better.
Currently mailman has:
- host IP - lists100X.wikimedia.org
- service IP - lists.wikimedia.org
In the past when mailman switched servers, the service IP was just moved to the new host (ex: https://gerrit.wikimedia.org/r/c/operations/dns/+/233642/3/templates/wikimedia.org). I think this helps with IP-based allowlists for antispam stuff but I'm really not sure.
One option is to put mailman behind LVS. I'm pretty sure we can (and should!) make mailman3 HA since all state should be stored in the database. I think then the main question is whether exim would be OK with that setup.