Page MenuHomePhabricator

POPs LVS : remove public vlan trunking
Open, LowPublic

Description

Similar to T367731

Now that IPIP has been rolled out to all the POPs we should be able to simplify the POPs network topology by removing now unnecessary configuration/links.

Slight drawback here is that in ulsfo/eqsin LVS traffic towards public hosts (if any) will hair-pin through the routers and back to the switches.
As a reminder, the CP servers are on the private vlan, so they won't be impacted. This also doesn't happen in drmrs/esams/magru as routing between vlans happens on the switches.

As no physical changes need to be done, it can be rolled back easily if any issues.
Steps along the lines of:

  1. Depool the site
  2. Remove the vlan and and IP config on the LVS
  3. Remove the vlan trunking on the switch
  4. Check monitoring (make sure health checks are still working)
  5. Repool the site

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

Slight drawback here is that in ulsfo/eqsin LVS traffic towards public hosts (if any) will hair-pin through the routers and back to the switches.

I think that's probably not a major issue in this limited case so +1 from me.

ayounsi moved this task from This quarter to Next quarter on the netops board.

@ssingh started working on this with https://gerrit.wikimedia.org/r/1206424 in T410047: No free IPs on public1-ulsfo vlan (Nov 2025) boldly assigning the task to him :)

For step 3, we will need the help of netops folks. Should we perhaps set up a dedicated time for this?

To confirm all that remains to be done is have someone on-site remove this cable:

https://netbox.wikimedia.org/dcim/interfaces/27216/trace/

(assuming it actually reflects reality, but Netbox should reflect reality so.....)