Thanos-fe currently uses cergen certs. Since we'll be onboarding the pyrra service to these hosts let's switch to cfssl certificates
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Invalid | None | T343987 Switch thanos-fe to cfssl | |||
Resolved | Jgiannelos | T344324 Maps Unavailability due to thanos-swift cfssl rollout (14 Aug 2023) | |||
Resolved | elukey | T356412 Consolidate TLS cert puppetry for ms and thanos swift frontends |
Event Timeline
Change 946559 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] thanos-fe: switch to cfssl
Change 946559 merged by Herron:
[operations/puppet@production] thanos-fe: switch to cfssl
Change 948125 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] thanos-fe: switch to cfssl
Change 948125 merged by Herron:
[operations/puppet@production] thanos-fe: switch to cfssl
Change 950007 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] Revert "thanos-fe: switch to cfssl"
Change 950007 merged by Herron:
[operations/puppet@production] Revert "thanos-fe: switch to cfssl"
Change 950072 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] thanos-fe: switch to cfssl
Change 950072 merged by Herron:
[operations/puppet@production] thanos-fe: switch to cfssl
Change 950073 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] Revert "thanos-fe: switch to cfssl"
Change 950073 merged by Herron:
[operations/puppet@production] Revert "thanos-fe: switch to cfssl"
Change 951851 had a related patch set uploaded (by Herron; author: Herron):
[operations/puppet@production] thanos-fe: switch to cfssl
Change 951851 merged by Herron:
[operations/puppet@production] thanos-fe: switch to cfssl
Change 952156 had a related patch set uploaded (by Effie Mouzeli; author: Effie Mouzeli):
[operations/puppet@production] thanos-fe: switch to cfssl
Change 952156 merged by Effie Mouzeli:
[operations/puppet@production] thanos-fe: switch to cfssl
Change 953236 had a related patch set uploaded (by Effie Mouzeli; author: Effie Mouzeli):
[operations/puppet@production] thanos-fe: switch to cfssl
observability we are still looking into how things could progress here on the Maps side of things. Please let me know if it is alright to stall this roll out for now.
Yes stalling is fine. The original reason for the switch to cfssl was related to adding a SAN to the thanos-fe certificate. That shouldn't be blocked since we can use still cergen for the time being.
We (o11y) have moved pyrra to the titan hosts, which makes this task moot. Transitioning to invalid
Change 953236 abandoned by Effie Mouzeli:
[operations/puppet@production] thanos-fe: switch to cfssl
Reason:
abandon in favour of T356412