Page MenuHomePhabricator

Switch thanos-fe to cfssl
Closed, InvalidPublic

Description

Thanos-fe currently uses cergen certs. Since we'll be onboarding the pyrra service to these hosts let's switch to cfssl certificates

Event Timeline

herron triaged this task as Medium priority.Aug 10 2023, 2:16 PM
herron created this task.

Change 946559 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/946559

herron renamed this task from Switch thanos-fe to csffl to Switch thanos-fe to cfssl.Aug 10 2023, 2:19 PM

Change 946559 merged by Herron:

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/946559

Change 948125 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/948125

Change 948125 merged by Herron:

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/948125

Change 950007 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] Revert "thanos-fe: switch to cfssl"

https://gerrit.wikimedia.org/r/950007

Change 950007 merged by Herron:

[operations/puppet@production] Revert "thanos-fe: switch to cfssl"

https://gerrit.wikimedia.org/r/950007

Change 950072 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/950072

Change 950072 merged by Herron:

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/950072

Change 950073 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] Revert "thanos-fe: switch to cfssl"

https://gerrit.wikimedia.org/r/950073

Change 950073 merged by Herron:

[operations/puppet@production] Revert "thanos-fe: switch to cfssl"

https://gerrit.wikimedia.org/r/950073

Change 951851 had a related patch set uploaded (by Herron; author: Herron):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/951851

Change 951851 merged by Herron:

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/951851

Change 952156 had a related patch set uploaded (by Effie Mouzeli; author: Effie Mouzeli):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/952156

Change 952156 merged by Effie Mouzeli:

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/952156

Change 953236 had a related patch set uploaded (by Effie Mouzeli; author: Effie Mouzeli):

[operations/puppet@production] thanos-fe: switch to cfssl

https://gerrit.wikimedia.org/r/953236

observability we are still looking into how things could progress here on the Maps side of things. Please let me know if it is alright to stall this roll out for now.

herron changed the task status from Open to Stalled.Aug 29 2023, 1:48 PM

Yes stalling is fine. The original reason for the switch to cfssl was related to adding a SAN to the thanos-fe certificate. That shouldn't be blocked since we can use still cergen for the time being.

We (o11y) have moved pyrra to the titan hosts, which makes this task moot. Transitioning to invalid

Change 953236 abandoned by Effie Mouzeli:

[operations/puppet@production] thanos-fe: switch to cfssl

Reason:

abandon in favour of T356412

https://gerrit.wikimedia.org/r/953236