Page MenuHomePhabricator

Remove hardcoded NFT rules related to PAWS workers
Closed, ResolvedPublic

Description

In T381373: Restrict outbound connectivity from PAWS hosts @cmooney added temporary NFT rules to filter suspicious traffic originating from PAWS workers. The traffic is now blocked directly at the source with Kubernetes Network Policies in the PAWS k8s cluster.

We need to remove these hardcoded rules, otherwise they might end up affecting other unrelated hosts that will reuse those IPs in the future.

Event Timeline

fnegri triaged this task as Medium priority.Jan 8 2025, 6:54 PM

Change #1105036 had a related patch set uploaded (by FNegri; author: FNegri):

[operations/puppet@production] Revert "Block PAWS workers nodes from all UDP traffic other than DNS & NTP"

https://gerrit.wikimedia.org/r/1105036

Change #1105036 merged by FNegri:

[operations/puppet@production] Revert "Block PAWS workers nodes from all UDP traffic other than DNS & NTP"

https://gerrit.wikimedia.org/r/1105036