Page MenuHomePhabricator

Use base::firewall on tools proxies
Closed, ResolvedPublic

Description

This should allow access to:

port 80 / 443 to everyone in the universe
port 8282 from just labs (for proxylistener)
redis replication port from just other webproxies
port 22 from bastions

This allows us to open up the redis replication just to other webproxies instead of opening it up to the world.

Event Timeline

yuvipanda raised the priority of this task from to Needs Triage.
yuvipanda updated the task description. (Show Details)
yuvipanda added subscribers: Aklapper, yuvipanda.

Change 204685 had a related patch set uploaded (by Yuvipanda):
dynamicproxy: Add ferm rules for http / https

https://gerrit.wikimedia.org/r/204685

yuvipanda set Security to None.

Change 204688 had a related patch set uploaded (by Yuvipanda):
tools: Explicitly open port for proxylistener

https://gerrit.wikimedia.org/r/204688

Change 204685 merged by Yuvipanda:
dynamicproxy: Add ferm rules for http / https

https://gerrit.wikimedia.org/r/204685

Change 204688 merged by Yuvipanda:
tools: Explicitly open port for proxylistener

https://gerrit.wikimedia.org/r/204688

Change 204693 had a related patch set uploaded (by Yuvipanda):
tools: Enable firewall on webproxies

https://gerrit.wikimedia.org/r/204693

Change 204693 merged by Yuvipanda:
tools: Enable firewall on webproxies

https://gerrit.wikimedia.org/r/204693

Change 204697 had a related patch set uploaded (by Yuvipanda):
dynamicproxy: Include firewall for base proxy

https://gerrit.wikimedia.org/r/204697

Change 204698 had a related patch set uploaded (by Yuvipanda):
dynamicproxy: Do not bind redis only on localhost

https://gerrit.wikimedia.org/r/204698

Change 204697 merged by Yuvipanda:
dynamicproxy: Include firewall for base proxy

https://gerrit.wikimedia.org/r/204697

Change 204698 merged by Yuvipanda:
dynamicproxy: Do not bind redis only on localhost

https://gerrit.wikimedia.org/r/204698

Change 204701 had a related patch set uploaded (by Yuvipanda):
tools: Allow redis access between proxies

https://gerrit.wikimedia.org/r/204701

Change 204701 merged by Yuvipanda:
tools: Allow redis access between proxies

https://gerrit.wikimedia.org/r/204701

yuvipanda claimed this task.

Boom all done :D