Page MenuHomePhabricator

magru: move sandbox vlan to routed Ganeti
Closed, ResolvedPublic

Description

The only hosts in the sandbox vlan are the RIPE Atlas anchors. Most of them VMs in the "old" Ganeti clusters, one (codfw) still a physical box.

Now that we're migrating Ganeti to routed Ganeti, we need to be able to have routed Anchors and decom the old sandbox vlan, re-using their IP spaces.

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

Change #1180143 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/puppet@production] Add sandbox vlan to routed ganeti

https://gerrit.wikimedia.org/r/1180143

vlan sandbox1-b3-magru deleted as well as its switch IRB.
IP ranges converted to the virtual-machines role: https://netbox.wikimedia.org/ipam/prefixes/?q=sandbox&role_id=41&site_id=11

Change #1180150 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/homer/public@master] Add magru sandbox prefixes to routed ganeti ranges

https://gerrit.wikimedia.org/r/1180150

Change #1180143 merged by Ayounsi:

[operations/puppet@production] Add sandbox vlan to routed ganeti

https://gerrit.wikimedia.org/r/1180143

Change #1180150 merged by jenkins-bot:

[operations/homer/public@master] Add magru sandbox prefixes to routed ganeti ranges

https://gerrit.wikimedia.org/r/1180150

Change #1180579 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/puppet@production] [WIP] Routed ganeti: improve firewalling

https://gerrit.wikimedia.org/r/1180579

Change #1180734 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):

[operations/puppet@production] nftables: Configure a directory with rules affecting the forward chain

https://gerrit.wikimedia.org/r/1180734

Change #1180734 merged by Muehlenhoff:

[operations/puppet@production] nftables: Configure a directory with rules affecting the forward chain

https://gerrit.wikimedia.org/r/1180734

Change #1180579 merged by Ayounsi:

[operations/puppet@production] Routed ganeti: improve firewalling

https://gerrit.wikimedia.org/r/1180579

Change #1181696 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/puppet@production] Routed ganeti: fix nftables typoes

https://gerrit.wikimedia.org/r/1181696

Change #1181696 merged by Ayounsi:

[operations/puppet@production] Routed ganeti: fix nftables typoes

https://gerrit.wikimedia.org/r/1181696

Change #1182109 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/homer/public@master] asw1-b3-magru: remove sandbox firewall

https://gerrit.wikimedia.org/r/1182109

Change #1182109 merged by jenkins-bot:

[operations/homer/public@master] asw1-b3-magru: remove sandbox firewall

https://gerrit.wikimedia.org/r/1182109

magru Anchor is back online. It did require some remote help from the RIPE team, especially to configure v6. v4 worked out of the box, even without the the proper netmask.

ayounsi claimed this task.
ayounsi updated the task description. (Show Details)