Page MenuHomePhabricator

toolforge: introduce docker-registry.svc.toolforge.org FQDN to replace docker-registry.tools.wmflabs.org
Open, LowPublic

Description

We still use docker-registry.tools.wmflabs.org in plenty of places.

However, in T306039: Decision request - Toolforge external infrastructure domain usage we decided to move forward with using svc.toolforge.org for this kind of FQDNs.

This task is to track the work to introduce docker-registry.svc.toolforge.org.

Event Timeline

Change #1038227 had a related patch set uploaded (by Arturo Borrero Gonzalez; author: Arturo Borrero Gonzalez):

[operations/puppet@production] toolforge: docker-registry: enable HTTP endpoint for svc.toolforge.org

https://gerrit.wikimedia.org/r/1038227

Change #1038227 abandoned by Arturo Borrero Gonzalez:

[operations/puppet@production] toolforge: docker-registry: enable HTTP endpoint for svc.toolforge.org

Reason:

no longer interested

https://gerrit.wikimedia.org/r/1038227

aborrero removed a project: User-aborrero.
aborrero unsubscribed.

This change triggered a discussion about the security of the Cloud VPS openstack network, the potential for network sniffing, and nova-proxy, given the fact that it doesn't support HTTPS backend.

Given this is just a cosmetic change, I lost interest, and wont be making it.

fnegri added a subscriber: aborrero.

We discussed this in IRC with @aborrero and @dcaro and this is still the desired solution:

  • docker-registry.tools.wmflabs.org is replaced by docker-registry.svc.toolforge.org
  • docker-registry.toolforge.org remains valid as a public-facing web frontend
fnegri removed a project: Cloud Services Proposals.