Page MenuHomePhabricator

Migrate cloudlb hosts to nftables
Closed, ResolvedPublic

Description

Looks like the Ferm puppetization doesn't quite allow mixing source range + destination range + destination port filtering, but nftables does.

Event Timeline

Change 973781 had a related patch set uploaded (by Majavah; author: Majavah):

[operations/puppet@production] cloudlb: haproxy: migrate to firewall::service

https://gerrit.wikimedia.org/r/973781

Change 973782 had a related patch set uploaded (by Majavah; author: Majavah):

[operations/puppet@production] P:bird::anycast: migrate to nftables

https://gerrit.wikimedia.org/r/973782

Change 973785 had a related patch set uploaded (by Majavah; author: Majavah):

[operations/puppet@production] hieradata: migrate codfw cloudlb to nftables

https://gerrit.wikimedia.org/r/973785

Change 973806 had a related patch set uploaded (by Majavah; author: Majavah):

[operations/puppet@production] hieradata: migrate all cloudlb hosts to nftables

https://gerrit.wikimedia.org/r/973806

Change 973781 merged by Majavah:

[operations/puppet@production] cloudlb: haproxy: migrate to firewall::service

https://gerrit.wikimedia.org/r/973781

Change 973782 merged by Majavah:

[operations/puppet@production] P:bird::anycast: migrate to nftables

https://gerrit.wikimedia.org/r/973782

Change 973785 merged by Majavah:

[operations/puppet@production] hieradata: migrate codfw cloudlb to nftables

https://gerrit.wikimedia.org/r/973785

Change 973806 merged by Majavah:

[operations/puppet@production] hieradata: migrate all cloudlb hosts to nftables

https://gerrit.wikimedia.org/r/973806