Page MenuHomePhabricator
Feed Advanced Search

Yesterday

aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

I just came up with what an implementation of option 3 could be: https://gitlab.wikimedia.org/repos/cloud/toolforge/toolforge-deploy/-/blob/a996b2a6ae2d9c3c2b094ae1ae3a39b4afe0433d/components/kyverno-policies/policies/toolforge-base-policy.yaml

Wed, May 8, 4:04 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

Given the new data, I think I'm now more in favor of option 2: mutation.

Wed, May 8, 1:00 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Wed, May 8, 12:31 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

Another data point.

Wed, May 8, 12:29 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

More thoughts on validation vs mutation:

Wed, May 8, 12:23 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge

Tue, May 7

aborrero updated the task description for T362050: toolforge: review pod templates for PSP replacement.
Tue, May 7, 12:37 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero added a comment to T362050: toolforge: review pod templates for PSP replacement.

Before patch https://gitlab.wikimedia.org/repos/cloud/toolforge/toolforge-deploy/-/merge_requests/278 with only PSP, a Pod resource would have:

  • at container level:
securityContext:
  allowPrivilegeEscalation: false
  capabilities:
    drop:
    - ALL
  runAsGroup: 54005
  runAsUser: 54005
  • at pod level:
securityContext:
  fsGroup: 54005
  seccompProfile:
    type: RuntimeDefault
  supplementalGroups:
  - 1
Tue, May 7, 12:24 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero added a comment to T362050: toolforge: review pod templates for PSP replacement.

TODO: webservice

Tue, May 7, 12:06 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero triaged T364376: cloudcephosd: the service unit user@0.service is in failed status as Low priority.
Tue, May 7, 9:47 AM · Cloud-Services, cloud-services-team
aborrero edited projects for T364376: cloudcephosd: the service unit user@0.service is in failed status, added: Cloud-Services; removed Cloud-VPS.
Tue, May 7, 9:46 AM · Cloud-Services, cloud-services-team
aborrero renamed T364376: cloudcephosd: the service unit user@0.service is in failed status from cloudcephosd: user@0.service is in failed status to cloudcephosd: the service unit user@0.service is in failed status.
Tue, May 7, 9:46 AM · Cloud-Services, cloud-services-team
aborrero created T364376: cloudcephosd: the service unit user@0.service is in failed status.

The Cloud-Services project tag is not intended to have any tasks. Please check the list on https://phabricator.wikimedia.org/project/profile/832/ and replace it with a more specific project tag to this task. Thanks!

Tue, May 7, 9:45 AM · Cloud-Services, cloud-services-team
aborrero awarded T364239: Add fox icon / badge to Phabricator a Unicorn! token.
Tue, May 7, 9:12 AM · Phabricator (2024-05-05), Release-Engineering-Team, User-brennen, Upstream, Wikimedia-Hackathon-2024

Mon, May 6

aborrero updated the task description for T364312: toolforge: introduce some logic to backfill maintain-kubeuser resources (like per-tool kyverno policies).
Mon, May 6, 2:18 PM · User-aborrero, cloud-services-team, Toolforge
aborrero triaged T364312: toolforge: introduce some logic to backfill maintain-kubeuser resources (like per-tool kyverno policies) as Medium priority.
Mon, May 6, 2:13 PM · User-aborrero, cloud-services-team, Toolforge
aborrero moved T364312: toolforge: introduce some logic to backfill maintain-kubeuser resources (like per-tool kyverno policies) from Backlog to Ready to be worked on on the Toolforge board.
Mon, May 6, 2:12 PM · User-aborrero, cloud-services-team, Toolforge
aborrero created T364312: toolforge: introduce some logic to backfill maintain-kubeuser resources (like per-tool kyverno policies).
Mon, May 6, 2:11 PM · User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T364297: toolforge: create a PSP migration plan.

Updated T362050: toolforge: review pod templates for PSP replacement to make sure our pod templates are updated accordingly.

Mon, May 6, 2:06 PM · User-aborrero, cloud-services-team, Toolforge
aborrero renamed T362050: toolforge: review pod templates for PSP replacement from review pod templates for stricter security to toolforge: review pod templates for PSP replacement.
Mon, May 6, 12:58 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero changed the status of T364297: toolforge: create a PSP migration plan from Open to In Progress.
Mon, May 6, 12:52 PM · User-aborrero, cloud-services-team, Toolforge
aborrero triaged T364297: toolforge: create a PSP migration plan as Medium priority.
Mon, May 6, 12:50 PM · User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T364297: toolforge: create a PSP migration plan, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Mon, May 6, 12:50 PM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T363983: [toolforge] Investigate authentication.

linking T277778: Toolforge: consider decoupling user & accounts from CloudVPS accounts for reference, in case is relevant

Mon, May 6, 12:43 PM · Toolforge (Toolforge iteration 09)
aborrero added a comment to T364297: toolforge: create a PSP migration plan.

the plan could be this:

Mon, May 6, 12:29 PM · User-aborrero, cloud-services-team, Toolforge
aborrero created T364297: toolforge: create a PSP migration plan.
Mon, May 6, 8:47 AM · User-aborrero, cloud-services-team, Toolforge
aborrero moved T362967: lima-kilo: container image caching from Doing to Next on the User-aborrero board.
Mon, May 6, 8:43 AM · Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team

Fri, May 3

aborrero added a comment to T364105: Streamline the creation of ceph storage cluster user accounts.

the proposed patch LGTM.

Fri, May 3, 2:19 PM · Data-Platform-SRE (2024.05.06 - 2024.05.26), cloud-services-team
aborrero closed T363901: Project WP1.0/mwoffliner requests Trove instance with 75 GB as Resolved.

I updated the quotas, but the administrator documents we have are a bit confusing.
Please, check the quotas and report back if you cannot operate as expected.

Fri, May 3, 12:30 PM · User-aborrero, cloud-services-team, Cloud-VPS (Quota-requests)
aborrero triaged T364113: toolforge: identify and cache in our container registry all kyverno images as Medium priority.
Fri, May 3, 12:23 PM · User-aborrero, cloud-services-team, Toolforge
aborrero created T364113: toolforge: identify and cache in our container registry all kyverno images.
Fri, May 3, 12:20 PM · User-aborrero, cloud-services-team, Toolforge
aborrero claimed T363901: Project WP1.0/mwoffliner requests Trove instance with 75 GB.
Fri, May 3, 11:43 AM · User-aborrero, cloud-services-team, Cloud-VPS (Quota-requests)
aborrero closed T363482: toolforge lima-kilo: refresh maintain-kubeusers test data, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, as Resolved.
Fri, May 3, 11:39 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero closed T363482: toolforge lima-kilo: refresh maintain-kubeusers test data as Resolved.
Fri, May 3, 11:39 AM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero closed T362233: Decision Request - Toolforge policy agent as Resolved.
Fri, May 3, 9:34 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero closed T362233: Decision Request - Toolforge policy agent, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, as Resolved.
Fri, May 3, 9:32 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero updated the task description for T362233: Decision Request - Toolforge policy agent.
Fri, May 3, 9:32 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge

Tue, Apr 30

aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

The decision about commiting to drop the extra component on the upgrade to k8s 1.26 might become way more relevant [..]

Tue, Apr 30, 11:25 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T363800: [builds-builder,lima-kilo] tekton stopped working on default setup.

I think kind in particular has some issues working with appArmor. There is a reference in the doc to just disable it: https://kind.sigs.k8s.io/docs/user/known-issues/#apparmor

Tue, Apr 30, 10:47 AM · Toolforge (Toolforge iteration 09)

Fri, Apr 26

aborrero changed the status of T363482: toolforge lima-kilo: refresh maintain-kubeusers test data from Open to In Progress.
Fri, Apr 26, 9:07 AM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero changed the status of T363482: toolforge lima-kilo: refresh maintain-kubeusers test data, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Fri, Apr 26, 9:05 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero closed T362975: Request increased quota for uploadmap Toolforge tool as Resolved.
Fri, Apr 26, 9:05 AM · User-aborrero, Toolforge (Quota-requests)
aborrero closed T362975: Request increased quota for uploadmap Toolforge tool, a subtask of T337191: Toolforge: consider introducing a command line for creating reverse proxies, as Resolved.
Fri, Apr 26, 9:05 AM · Toolforge, User-aborrero, cloud-services-team

Thu, Apr 25

aborrero added a subtask for T337191: Toolforge: consider introducing a command line for creating reverse proxies: T362975: Request increased quota for uploadmap Toolforge tool.
Thu, Apr 25, 3:18 PM · Toolforge, User-aborrero, cloud-services-team
aborrero added a parent task for T362975: Request increased quota for uploadmap Toolforge tool: T337191: Toolforge: consider introducing a command line for creating reverse proxies.
Thu, Apr 25, 3:18 PM · User-aborrero, Toolforge (Quota-requests)
aborrero claimed T362975: Request increased quota for uploadmap Toolforge tool.
Thu, Apr 25, 3:17 PM · User-aborrero, Toolforge (Quota-requests)
aborrero created T363482: toolforge lima-kilo: refresh maintain-kubeusers test data.
Thu, Apr 25, 3:01 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero closed T362966: lima-kilo: replicate sssd setup from Toolforge, a subtask of T362050: toolforge: review pod templates for PSP replacement, as Resolved.
Thu, Apr 25, 2:58 PM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero closed T362966: lima-kilo: replicate sssd setup from Toolforge as Resolved.
Thu, Apr 25, 2:58 PM · User-aborrero, cloud-services-team, Toolforge
aborrero closed T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled as Resolved.
Thu, Apr 25, 12:31 PM · User-aborrero, cloud-services-team, Toolforge
aborrero closed T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled, a subtask of T362872: Decision Request - Toolforge policy agent enforcement model, as Resolved.
Thu, Apr 25, 12:31 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled.

The problem was we were using a deprecated apiVersion field in the embedded kubeadm configuration.

Thu, Apr 25, 9:50 AM · User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T363296: toolforge: explore options to introduce egress network quotas.

in your opinion, should we decline this task and focus on the other angle you mention?

Thu, Apr 25, 8:55 AM · User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T362233: Decision Request - Toolforge policy agent from Open to In Progress.
Thu, Apr 25, 8:34 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T362233: Decision Request - Toolforge policy agent, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Thu, Apr 25, 8:32 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362233: Decision Request - Toolforge policy agent.

scheduled discussion meeting for 2024-04-30.

Thu, Apr 25, 8:32 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge

Wed, Apr 24

aborrero changed the status of T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled from Open to In Progress.
Wed, Apr 24, 3:32 PM · User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled, a subtask of T362872: Decision Request - Toolforge policy agent enforcement model, from Open to In Progress.
Wed, Apr 24, 3:30 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero created T363347: toolforge lima-kilo: PodSecurityPolicy admission is disabled.
Wed, Apr 24, 3:29 PM · User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

Is there a way for us to see how many objects are currently not meeting the policy? If there's not many, going with option 1 might be doable, otherwise it might requires some time to get everything first valid with the policies, and then moving to option 1 (if we want eventually)

Wed, Apr 24, 3:26 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Wed, Apr 24, 3:12 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero reopened T362872: Decision Request - Toolforge policy agent enforcement model as "Open".

reopening, as I just noticed an important data point: as of today PodSecurityPolicy work on mutation mode. It transparently modifies the resources being defined in the cluster.

Wed, Apr 24, 3:09 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Wed, Apr 24, 3:08 PM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero reopened T362872: Decision Request - Toolforge policy agent enforcement model, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, as Open.
Wed, Apr 24, 3:07 PM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T187929: Cloud IPv6 subnets from Stalled to Open.

reopening -- we might want to take a look at this soon.

Wed, Apr 24, 2:32 PM · User-aborrero, Infrastructure-Foundations, SRE, netops
aborrero moved T187929: Cloud IPv6 subnets from Backlog to Radar on the User-aborrero board.
Wed, Apr 24, 2:31 PM · User-aborrero, Infrastructure-Foundations, SRE, netops
aborrero changed the status of T187929: Cloud IPv6 subnets, a subtask of T245495: CloudVPS: IPv6 early PoC, from Stalled to Open.
Wed, Apr 24, 2:31 PM · cloud-services-team, Infrastructure-Foundations, SRE, netops
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Wed, Apr 24, 11:27 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero closed T362872: Decision Request - Toolforge policy agent enforcement model as Resolved.

I'm fine with option 1 too, so I'm declaring this decision request done.

Wed, Apr 24, 11:25 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero closed T362872: Decision Request - Toolforge policy agent enforcement model, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, as Resolved.
Wed, Apr 24, 11:24 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T356164: [toolforge] several tools get periods of connection refused (104) when connecting to wikis.

Maybe an idea: have a per-tool network quota for concurrent connections. We don't have any semantics in kubernetes/calico for implementing this though.

Can you open a task with more details if you have a clear idea? I'm going to close this one for now, but would be nice to be able to have something more than us looking at the limits.

Wed, Apr 24, 8:12 AM · Toolforge (Toolforge iteration 07), User-aborrero
aborrero triaged T363296: toolforge: explore options to introduce egress network quotas as Medium priority.
Wed, Apr 24, 8:11 AM · User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T329327: Frequent `429 Client Error: Too Many Requests for url: https://stream.wikimedia.org/v2/stream/recentchange` errors in SULWatcher.

Based on this explanation of the rate limiting implementation I am very much wondering if EventStreams is seeing all traffic from Cloud VPS as coming from a single IP, specifically 185.15.56.1 (nat.cloudgw.eqiad1.wikimediacloud.org). If so, EventStreams would be mostly unusable by Toolforge tools and other Cloud VPS projects with potentially hundreds of tools fighting over 16 slots.

Wed, Apr 24, 8:11 AM · Toolforge, Tools, EventStreams, Event-Platform, Data-Engineering, stewardbots
aborrero created T363296: toolforge: explore options to introduce egress network quotas.
Wed, Apr 24, 8:09 AM · User-aborrero, cloud-services-team, Toolforge

Tue, Apr 23

aborrero added a comment to T362966: lima-kilo: replicate sssd setup from Toolforge.

Patch https://gitlab.wikimedia.org/repos/cloud/toolforge/lima-kilo/-/merge_requests/119 seems to work as expected.

Tue, Apr 23, 10:32 AM · User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

In both cases, they don't mention anything about mutation. I assume this means that they cannot backfill (backmutate?) resouces that made it to the system before the policy was updated.

I would assume the policy is applied when a Pod is created, and not when a Deployment/Job/etc is? In that case backfill support doesn't seem that important to me.

Tue, Apr 23, 9:44 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

What do we do with the already defined Pod?

This is something to verify also in Option 1 I think. Does validation apply to existing resources, or only to newly created ones?

Kyverno has a pretty well established behavior for this, see https://kyverno.io/docs/policy-reports/background/ it will report if already existing resources no longer conform with the new policies.

On a similar fashion, OPA Gatekeeper can perform audits of existing resources, see https://open-policy-agent.github.io/gatekeeper/website/docs/audit

Tue, Apr 23, 9:40 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362872: Decision Request - Toolforge policy agent enforcement model.

What do we do with the already defined Pod?

This is something to verify also in Option 1 I think. Does validation apply to existing resources, or only to newly created ones?

Tue, Apr 23, 9:38 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge

Fri, Apr 19

aborrero changed the status of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes from Open to In Progress.
Fri, Apr 19, 10:33 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, a subtask of T316107: [infra,k8s] Upgrade Toolforge Kubernetes to version 1.25, from Open to In Progress.
Fri, Apr 19, 10:32 AM · cloud-services-team, Toolforge
aborrero changed the status of T362967: lima-kilo: container image caching from Open to In Progress.
Fri, Apr 19, 10:18 AM · Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero changed the status of T362967: lima-kilo: container image caching, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Fri, Apr 19, 10:17 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero created T362967: lima-kilo: container image caching.
Fri, Apr 19, 10:16 AM · Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero changed the status of T362966: lima-kilo: replicate sssd setup from Toolforge from Open to In Progress.
Fri, Apr 19, 10:12 AM · User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T362966: lima-kilo: replicate sssd setup from Toolforge, a subtask of T362050: toolforge: review pod templates for PSP replacement, from Open to In Progress.
Fri, Apr 19, 10:11 AM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero created T362966: lima-kilo: replicate sssd setup from Toolforge.
Fri, Apr 19, 10:10 AM · User-aborrero, cloud-services-team, Toolforge
aborrero moved T362233: Decision Request - Toolforge policy agent from Radar to Blocked on the User-aborrero board.
Fri, Apr 19, 10:06 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero added a comment to T362822: Slow loading on Toolforge.

The speeds you reported are perfectly normal.

Fri, Apr 19, 9:36 AM · Toolforge
aborrero created T362956: nova-api can get the listen queue of socket full.
Fri, Apr 19, 8:33 AM · Cloud-VPS, cloud-services-team
aborrero added a comment to T361804: Decision request - Update python team best practices.

cross linking: T327087: Decision request: python source code line length

Fri, Apr 19, 8:13 AM · Cloud Services Proposals

Thu, Apr 18

aborrero added a comment to T362822: Slow loading on Toolforge.

Could you please go to here https://network-tests.toolforge.org/ and download the 1GB file, and report the speed you get?

Thu, Apr 18, 12:45 PM · Toolforge
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Thu, Apr 18, 11:54 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero updated the task description for T362872: Decision Request - Toolforge policy agent enforcement model.
Thu, Apr 18, 11:51 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T362872: Decision Request - Toolforge policy agent enforcement model from Open to In Progress.
Thu, Apr 18, 11:41 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero moved T362872: Decision Request - Toolforge policy agent enforcement model from Backlog to Blocked on the User-aborrero board.
Thu, Apr 18, 11:40 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero changed the status of T362872: Decision Request - Toolforge policy agent enforcement model, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Thu, Apr 18, 11:40 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge
aborrero created T362872: Decision Request - Toolforge policy agent enforcement model.
Thu, Apr 18, 11:36 AM · Cloud Services Proposals, User-aborrero, cloud-services-team, Toolforge
aborrero awarded T362869: [k8s,infra] Upgrade Toolforge to Uwubernetes (1.30) a Love token.
Thu, Apr 18, 11:19 AM · Toolforge

Wed, Apr 17

aborrero changed the status of T362050: toolforge: review pod templates for PSP replacement from Open to In Progress.
Wed, Apr 17, 9:21 AM · Patch-For-Review, Toolforge (Toolforge iteration 09), User-aborrero, cloud-services-team
aborrero changed the status of T362050: toolforge: review pod templates for PSP replacement, a subtask of T279110: [infra] Replace PodSecurityPolicy in Toolforge Kubernetes, from Open to In Progress.
Wed, Apr 17, 9:20 AM · Patch-For-Review, User-aborrero, cloud-services-team, Toolforge

Tue, Apr 16

aborrero added a comment to T362525: builds-api allows impersonating any user by bypassing local TLS termination.

also, the request doesn't use a TLS certificate on the client side. By looking at the nginx deployment, it has ssl_verify_client on, I would expect the request to fail if not using a client cert?

Tue, Apr 16, 1:40 PM · User-aborrero, Toolforge, Security