A few things to clarify:
- VMs are not protected by NAT anymore. Figure out the right firewalling semantics.
- We need to make sure neutron security groups works as expected using IPv6.
A few things to clarify:
| Subject | Repo | Branch | Lines +/- | |
|---|---|---|---|---|
| cloudgw: forward all VRF traffic without restrictions for IPv6 | operations/puppet | production | +4 -9 |
aborrero opened https://gitlab.wikimedia.org/repos/cloud/cloud-vps/tofu-infra/-/merge_requests/96
codfw1dev: default secgroup: refresh IPv6 settings
aborrero merged https://gitlab.wikimedia.org/repos/cloud/cloud-vps/tofu-infra/-/merge_requests/96
codfw1dev: default secgroup: refresh IPv6 settings
aborrero opened https://gitlab.wikimedia.org/repos/cloud/cloud-vps/tofu-infra/-/merge_requests/98
codfw1dev: default secgroup: fix ICMP in IPv6
aborrero merged https://gitlab.wikimedia.org/repos/cloud/cloud-vps/tofu-infra/-/merge_requests/98
codfw1dev: default secgroup: fix ICMP in IPv6
Change #1080267 had a related patch set uploaded (by Arturo Borrero Gonzalez; author: Arturo Borrero Gonzalez):
[operations/puppet@production] cloudgw: forward all VRF traffic without restrictions for IPv6
Change #1080267 merged by Arturo Borrero Gonzalez:
[operations/puppet@production] cloudgw: forward all VRF traffic without restrictions for IPv6
Mentioned in SAL (#wikimedia-cloud) [2024-10-15T11:33:17Z] <arturo> cloudgw maintenance, firewall change for T374714
problem detected: remote_group_name parameter in tofu-infra security group rules is not getting resolved.
For now, the semantics are: