Per our network guidelines (https://wikitech.wikimedia.org/wiki/Wikimedia_network_guidelines#Public_IPs) all services (with exceptions!) with a public-facing service should be running behind our CDN, i.e. the service is running on servers with a private DNS name and gets served as https://idm.wikimedi.org via the CDN service.
We should double check that this is none of the exceptions and set up the config changes to serve the IDM via the caching layer. Instructions for this can be found at https://wikitech.wikimedia.org/wiki/LVS#Add_a_new_load_balanced_service (and involve changes to DNS, certs, etcd and conf-tool).