tcp-mss-clamper works great but has some limitations that could be avoided by using ferm on realservers where it's available. Our current puppezation profile::lvs::realserver::ipip is already firewall aware (only adding certain ferm rules if ferm is present) so switching between tcp-mss-clamper or ferm based MSS clamping should be feasible
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
In Progress | Vgutierrez | T332027 Replace current L4LB with with Katran-based alternative | |||
Resolved | Vgutierrez | T365689 Provide a ferm based alternative to tcp-mss-clamper | |||
Open | CDobbins | T367204 LVSRealserverMSS alert is broken for ferm based hosts |
Event Timeline
Change #1035724 had a related patch set uploaded (by Vgutierrez; author: Vgutierrez):
[operations/puppet@production] lvs::realserver::ipip: Provide ferm MSS clamping support
Mentioned in SAL (#wikimedia-operations) [2024-06-11T13:06:30Z] <vgutierrez> disable puppet on A:ncredir before merging https://gerrit.wikimedia.org/r/c/operations/puppet/+/1035724 - T365689
Change #1035724 merged by Vgutierrez:
[operations/puppet@production] lvs::realserver::ipip: Provide ferm MSS clamping support
Mentioned in SAL (#wikimedia-operations) [2024-06-11T13:15:58Z] <vgutierrez> depool ncredir6001 - T365689
Change #1041645 had a related patch set uploaded (by Vgutierrez; author: Vgutierrez):
[operations/puppet@production] realserver::ipip: Fix ferm MSS clamping rule
Mentioned in SAL (#wikimedia-operations) [2024-06-11T13:36:54Z] <vgutierrez> repool ncredir6001 - T365689
Change #1041645 merged by Vgutierrez:
[operations/puppet@production] realserver::ipip: Fix ferm MSS clamping rule
Mentioned in SAL (#wikimedia-operations) [2024-06-11T13:45:34Z] <vgutierrez> rolling switch from tcp-mss-clamper to ferm based MSS clamping on A:ncredir - T365689
Change #1099792 had a related patch set uploaded (by CDobbins; author: CDobbins):
[operations/puppet@production] lvs: add prometheus::node_ferm_mss to ipip.pp
Change #1099792 merged by CDobbins:
[operations/puppet@production] lvs: Deploy node_ferm_mss exporter on ferm based realservers