Migration steps:
- depool cloudelastic (but keep monitoring its cluster health)
- stop puppet on cloudelastic, lvs1020 and lvs1018
- apply puppet on cloudelastic (one server at a time, watching cluster health checks) and validate that IPIP is working as expected [we use https://gitlab.wikimedia.org/-/snippets/107 for that]
- apply puppet on lvs1020 and lvs1018
- rolling restart of pybal on the impacted LVS servers (via sre.loadbalancer.restart-pybal cookbook ?)
- validate from the bastion hosts that traffic towards the VIP works as expected
- repool cloudelastic