Looks like the Ferm puppetization doesn't quite allow mixing source range + destination range + destination port filtering, but nftables does.
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | aborrero | T296411 cloud: decide on general idea for having cloud-dedicated hardware provide service in the cloud realm & the internet | |||
Resolved | aborrero | T297596 have cloud hardware servers in the cloud realm using a dedicated LB layer | |||
Open | None | T297026 Automate maintain-views workflow | |||
Open | fnegri | T300427 Automate maintain-views replica depooling | |||
Resolved | • taavi | T355115 Remove cloud-support1-c-eqiad VLAN | |||
Resolved | • taavi | T346947 Move wiki replicas behind cloudlb | |||
Resolved | • taavi | T351087 Migrate cloudlb hosts to nftables |
Event Timeline
Change 973781 had a related patch set uploaded (by Majavah; author: Majavah):
[operations/puppet@production] cloudlb: haproxy: migrate to firewall::service
Change 973782 had a related patch set uploaded (by Majavah; author: Majavah):
[operations/puppet@production] P:bird::anycast: migrate to nftables
Change 973785 had a related patch set uploaded (by Majavah; author: Majavah):
[operations/puppet@production] hieradata: migrate codfw cloudlb to nftables
Change 973806 had a related patch set uploaded (by Majavah; author: Majavah):
[operations/puppet@production] hieradata: migrate all cloudlb hosts to nftables
Change 973781 merged by Majavah:
[operations/puppet@production] cloudlb: haproxy: migrate to firewall::service
Change 973782 merged by Majavah:
[operations/puppet@production] P:bird::anycast: migrate to nftables
Change 973785 merged by Majavah:
[operations/puppet@production] hieradata: migrate codfw cloudlb to nftables
Change 973806 merged by Majavah:
[operations/puppet@production] hieradata: migrate all cloudlb hosts to nftables