Page MenuHomePhabricator

MoritzMuehlenhoff (Moritz Mühlenhoff)
User

Today

  • No visible events.

Tomorrow

  • No visible events.

Saturday

  • No visible events.

User Details

User Since
Apr 1 2015, 4:33 PM (585 w, 10 h)
Availability
Available
LDAP User
Moritz Mühlenhoff
MediaWiki User
MMuhlenhoff (WMF) [ Global Accounts ]

Recent Activity

Yesterday

MoritzMuehlenhoff added a comment to T429129: Terminal configuration for cookbooks.

@MoritzMuehlenhoff what do you think of the patch? Or do you want to find a way to retain the colors?

The patch sounds great, let's take that route. There's no need for colour output for the command to disable Puppet merges.

sounds good, merged

Wed, Jun 17, 5:14 PM · Infrastructure-Foundations, SRE-tools, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Wed, Jun 17, 3:51 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T429129: Terminal configuration for cookbooks.

@MoritzMuehlenhoff what do you think of the patch? Or do you want to find a way to retain the colors?

Wed, Jun 17, 3:44 PM · Infrastructure-Foundations, SRE-tools, SRE
MoritzMuehlenhoff added a comment to T427897: Upgrade Cumin hosts to Trixie.

@MoritzMuehlenhoff The test worked succesfully, thus, I've migrated the backups from cumin2002 to cumin2003. The backups are setup, but disabled on the old host. It would be nice to keep the host available for at least a week to observe a full cycle of backups happening with no errors, should a last minute error happened, monitoring would alert us. After that, I won't need cumin2002 for anything.

Wed, Jun 17, 12:20 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Wed, Jun 17, 11:44 AM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Wed, Jun 17, 11:00 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T429446: Check current usage of project maps on CloudVPS.

Its not used by CTT team so we don't need it. Can somebody check with the owners though ?

Wed, Jun 17, 9:38 AM · Maps, Cloud-VPS (Project-requests)
MoritzMuehlenhoff added a comment to T429446: Check current usage of project maps on CloudVPS.

Can be removed

Wed, Jun 17, 8:21 AM · Maps, Cloud-VPS (Project-requests)
MoritzMuehlenhoff added a comment to T427897: Upgrade Cumin hosts to Trixie.

@jcrespo Cumin is now working on cumin2003, you can test backups.

Wed, Jun 17, 6:31 AM · Infrastructure-Foundations, SRE

Tue, Jun 16

MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Tue, Jun 16, 1:41 PM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff updated the task description for T428020: codfw: rack A5 maintenance.
Tue, Jun 16, 10:56 AM · Infrastructure-Foundations, netops, ServiceOps new
MoritzMuehlenhoff added a comment to T429175: Scaling urldownloaders by adding redundancy and load balancing.

Let's wait until Liberica is available and then go with 3.

Tue, Jun 16, 6:43 AM · Infrastructure-Foundations, Traffic, SRE

Mon, Jun 15

MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Mon, Jun 15, 1:05 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Mon, Jun 15, 1:04 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T416707: Sunsetting mirrors.wikimedia.org.

Likewise osbpo and the Ubuntu mirror are moved by now, the last remaining part is the Debian mirror.

Mon, Jun 15, 11:49 AM · Patch-For-Review, User-notice, Release-Engineering-Team (Radar), Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T416707: Sunsetting mirrors.wikimedia.org.

I opened a ticket at https://anonticket.torproject.org/ and mirrors.wikimedia.org has been removed from the download mirror rotation for Tails.

Mon, Jun 15, 11:49 AM · Patch-For-Review, User-notice, Release-Engineering-Team (Radar), Infrastructure-Foundations, SRE
MoritzMuehlenhoff created T429129: Terminal configuration for cookbooks.
Mon, Jun 15, 8:08 AM · Infrastructure-Foundations, SRE-tools, SRE
MoritzMuehlenhoff updated the task description for T428495: Migrate conf* hosts away from bullseye.
Mon, Jun 15, 6:54 AM · ServiceOps new, ServiceOps-Upgrades-Hardware

Fri, Jun 12

MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Fri, Jun 12, 3:53 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T428495: Migrate conf* hosts away from bullseye.

Thank you very much, @MoritzMuehlenhoff. Other than compatibility tests I'll run in the interim, we're unlikely to use the new packages for at least two weeks, so take your time.

Fri, Jun 12, 1:35 PM · ServiceOps new, ServiceOps-Upgrades-Hardware
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Fri, Jun 12, 12:24 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T427897: Upgrade Cumin hosts to Trixie.

@elukey Cumin is still not in a working state, see below:

Fri, Jun 12, 10:54 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Fri, Jun 12, 9:48 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Fri, Jun 12, 7:21 AM · Infrastructure-Foundations, SRE

Thu, Jun 11

MoritzMuehlenhoff updated the task description for T428229: eqsin: re-image rack 604 servers on new vlan.
Thu, Jun 11, 2:38 PM · Infrastructure-Foundations, Traffic
MoritzMuehlenhoff added a comment to T428020: codfw: rack A5 maintenance.

@ayounsi For puppetserver2002 will need to be merged before the maintenance starts: https://gerrit.wikimedia.org/r/c/operations/dns/+/1300766 I'll take care of that.

Thu, Jun 11, 12:08 PM · Infrastructure-Foundations, netops, ServiceOps new
MoritzMuehlenhoff updated the task description for T428229: eqsin: re-image rack 604 servers on new vlan.
Thu, Jun 11, 11:12 AM · Infrastructure-Foundations, Traffic
MoritzMuehlenhoff triaged T428878: Raise DRBD replication speed for Ganeti clusters as Medium priority.
Thu, Jun 11, 11:11 AM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff created T428878: Raise DRBD replication speed for Ganeti clusters.
Thu, Jun 11, 11:11 AM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T428495: Migrate conf* hosts away from bullseye.

@MoritzMuehlenhoff - How challenging would be to rebuild the forward-port of zookeeper (3.4.13) from bullseye that you prepared in T418915#11851872 for bookworm as well? That would be the last moving part of this intermediate in-place step to bookworm before stepping to trixie.

Thu, Jun 11, 7:23 AM · ServiceOps new, ServiceOps-Upgrades-Hardware
MoritzMuehlenhoff added a comment to T411642: GitLab Private Repository Request for: production access meta data.

@brennen Sorry, I missed your reply until now! Yes, that is still needed, repos/sre sounds good to me.

Thu, Jun 11, 6:50 AM · GitLab (Project and group requests), Essential-Work, User-brennen, Release-Engineering-Team

Wed, Jun 10

MoritzMuehlenhoff created T428769: Check home/HDFS leftovers of harrayo-wmf.
Wed, Jun 10, 3:28 PM · Data-Platform-SRE
MoritzMuehlenhoff created T428768: Check home/HDFS leftovers of atieno.
Wed, Jun 10, 3:20 PM · Data-Platform-SRE
MoritzMuehlenhoff added a comment to T427900: Build wmfdb-admin for Trixie.

@FCeratto-WMF Can you please import them to the "main" component of apt.wikimedia.org?

Wed, Jun 10, 12:04 PM · Data-Persistence, DBA, SRE
MoritzMuehlenhoff closed T428456: Upgrade Routinator to 0.15.2 as Resolved.

Routinator has been upgraded to 0.15.2 in eqiad and codfw.

Wed, Jun 10, 9:48 AM · Infrastructure-Foundations
MoritzMuehlenhoff changed the status of T428494: Requesting GitLab account activation for dmiranda from Declined to Resolved.

Access to cn=wmf was granted via Wikimedia IDM.

Wed, Jun 10, 7:02 AM · GitLab (Account Approval), Release-Engineering-Team

Tue, Jun 9

MoritzMuehlenhoff updated subscribers of T421484: decommission parsoidtest1001.eqiad.wmnet.

@Muehlenhoff following up on our discussion, and unless there are no objections, we could repurpose this machine for the ganeti cluster on eqiad. It was purchased on 2024-06-26.

Tue, Jun 9, 2:21 PM · Infrastructure-Foundations, decommission-hardware
MoritzMuehlenhoff added a comment to T421484: decommission parsoidtest1001.eqiad.wmnet.

@Muehlenhoff following up on our discussion, and unless there are no objections, we could repurpose this machine for the ganeti cluster on eqiad. It was purchased on 2024-06-26.

Tue, Jun 9, 2:16 PM · Infrastructure-Foundations, decommission-hardware
MoritzMuehlenhoff added a comment to T427357: codfw: rack A4 maintenance.

All Ganeti nodes are back in service

Tue, Jun 9, 2:07 PM · Infrastructure-Foundations, netops, Observability-Logging, Machine-Learning-Team, Traffic, ServiceOps new, Discovery-Search
MoritzMuehlenhoff created T428579: Check home/HDFS leftovers of ksiebert.
Tue, Jun 9, 11:31 AM · Data-Platform-SRE
MoritzMuehlenhoff created T428569: Check home/HDFS leftovers of dmaza.
Tue, Jun 9, 10:28 AM · Data-Platform-SRE
MoritzMuehlenhoff renamed T428567: Check home/HDFS leftovers of hmonroy from heck home/HDFS leftovers of hmonroy to Check home/HDFS leftovers of hmonroy.
Tue, Jun 9, 10:27 AM · Data-Platform-SRE
MoritzMuehlenhoff created T428567: Check home/HDFS leftovers of hmonroy.
Tue, Jun 9, 10:13 AM · Data-Platform-SRE

Tue, Jun 2

MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, Jun 2, 2:56 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Tue, Jun 2, 12:45 PM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, Jun 2, 11:39 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, Jun 2, 11:20 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated subscribers of T421705: Move mariadb hosts to nftables.

After migrating pc2022 to nftables we noticed a bump of connections tracked. The root cause is that on ferm connection tracking was disabled for 3306 being the source and dest port:

  • /etc/ferm/conf.d/10_mariadb_internal.conf configures NO_TRACK for the entire 3306 port (via /etc/ferm/functions.conf)
  • on nftables in /etc/nftables/notrack/10_mariadb_internal.nft we only set notrack for the destination port

This is no issue for pc2022, we have plenty of headroom on it. But we should resolve this before we move further mariadb nodes.

I've been debugging this and haven't made much progress but I have a couple of different ideas:

  • Maybe we can add a separate rule on source port of 3306 in mariadb::firewall but I can't find a way to actually set the source port (and not the destination port).
  • It could be that we are only allowing dport only in nftables and should allow sport too. Since the puppet code to set the notrack just takes the accept and replaces it with notrack (https://gerrit.wikimedia.org/r/c/operations/puppet/+/1259874/1/modules/nftables/manifests/client.pp#158)
  • A bit weirder: I could suggest to leave it as is. This is the source port being 3306 and mariadb itself shouldn't be connecting to stuff and I'd argue it was not the intention of the notrack to ignore those. The only case I can think of is when a replica connects to a master to get replication data and the overhead of those should be small on all dbs.

Just random late night thoughts.

Tue, Jun 2, 10:32 AM · DBA
MoritzMuehlenhoff created T427900: Build wmfdb-admin for Trixie.
Tue, Jun 2, 9:43 AM · Data-Persistence, DBA, SRE
MoritzMuehlenhoff created T427899: Build httpbb for Trixie.
Tue, Jun 2, 9:42 AM · Patch-For-Review, ServiceOps new, SRE
MoritzMuehlenhoff updated the task description for T427357: codfw: rack A4 maintenance.
Tue, Jun 2, 9:36 AM · Infrastructure-Foundations, netops, Observability-Logging, Machine-Learning-Team, Traffic, ServiceOps new, Discovery-Search
MoritzMuehlenhoff updated the task description for T427357: codfw: rack A4 maintenance.
Tue, Jun 2, 9:33 AM · Infrastructure-Foundations, netops, Observability-Logging, Machine-Learning-Team, Traffic, ServiceOps new, Discovery-Search
MoritzMuehlenhoff created T427897: Upgrade Cumin hosts to Trixie.
Tue, Jun 2, 9:29 AM · Infrastructure-Foundations, SRE

Mon, Jun 1

MoritzMuehlenhoff updated the task description for T427357: codfw: rack A4 maintenance.
Mon, Jun 1, 4:15 PM · Infrastructure-Foundations, netops, Observability-Logging, Machine-Learning-Team, Traffic, ServiceOps new, Discovery-Search
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Mon, Jun 1, 2:57 PM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff triaged T427282: Move URL downloaders to trixie as Medium priority.
Mon, Jun 1, 2:23 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Mon, Jun 1, 10:36 AM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff created T427774: Flink image fails to build in weekly rebuild.
Mon, Jun 1, 8:46 AM · Data-Platform-SRE (2026-04-24 - 2026-05-15)
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Mon, Jun 1, 7:00 AM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE

Fri, May 29

MoritzMuehlenhoff created T427646: netconsole being used for cache hosts?.
Fri, May 29, 2:21 PM · Traffic, SRE
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Fri, May 29, 8:39 AM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Fri, May 29, 6:38 AM · Infrastructure-Foundations, SRE

Thu, May 28

MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Thu, May 28, 3:13 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T149804: Review of firewall services without srange.
Thu, May 28, 2:49 PM · Patch-For-Review, Infrastructure-Foundations, User-MoritzMuehlenhoff, SRE
MoritzMuehlenhoff updated the task description for T420240: Integrate Trixie 13.4 point update.
Thu, May 28, 2:21 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Thu, May 28, 11:51 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Thu, May 28, 10:51 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Thu, May 28, 10:50 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T416707: Sunsetting mirrors.wikimedia.org.

I opened a ticket at https://anonticket.torproject.org/ and mirrors.wikimedia.org has been removed from the download mirror rotation for Tails.

Thu, May 28, 7:12 AM · Patch-For-Review, User-notice, Release-Engineering-Team (Radar), Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T427312: Build PHP 8.3 packages for bookworm.

Why didn't I run into this issue for php, php-defaults, or dh-php?

Thu, May 28, 7:05 AM · ServiceOps new, ServiceOps-Upgrades-Hardware, ServiceOps-Mediawiki

Wed, May 27

MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Wed, May 27, 1:40 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Wed, May 27, 12:52 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Wed, May 27, 11:33 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff closed T424680: Add ganeti105[5678] and decom ganeti102[3456] as Resolved.

All done

Wed, May 27, 9:36 AM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427353: Repurpose ganeti102[3456] for Zuul migration.
Wed, May 27, 8:29 AM · DC-Ops, ops-eqiad, collaboration-services, SRE
MoritzMuehlenhoff created T427353: Repurpose ganeti102[3456] for Zuul migration.
Wed, May 27, 8:28 AM · DC-Ops, ops-eqiad, collaboration-services, SRE
MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Wed, May 27, 8:07 AM · Ganeti, Infrastructure-Foundations, SRE

Tue, May 26

MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Tue, May 26, 2:52 PM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff created T427282: Move URL downloaders to trixie.
Tue, May 26, 1:47 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff added a comment to T416664: Refresh OS and hardware in the PKI infrastructure.

I had a look at the debmonitor PKI setup and I agree that the CSR file on pki-root seems unused. since we have all of /etc/cfssl in Bacula we can also always restore it, so it seems safe to me to go ahead and just decom pki-root1001

Tue, May 26, 1:26 PM · Infrastructure-Foundations
MoritzMuehlenhoff added a comment to T421705: Move mariadb hosts to nftables.

After migrating pc2022 to nftables we noticed a bump of connections tracked. The root cause is that on ferm connection tracking was disabled for 3306 being the source and dest port:

Tue, May 26, 1:05 PM · DBA
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, May 26, 12:52 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Tue, May 26, 12:51 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, May 26, 11:33 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Tue, May 26, 11:33 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, May 26, 11:31 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, May 26, 9:10 AM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T426759: Integrate Bookworm 12.14 point update.
Tue, May 26, 8:51 AM · Infrastructure-Foundations, SRE

Fri, May 22

MoritzMuehlenhoff updated the task description for T427072: Integrate Trixie 13.5 point update.
Fri, May 22, 3:15 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff triaged T427072: Integrate Trixie 13.5 point update as Medium priority.
Fri, May 22, 2:41 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T420240: Integrate Trixie 13.4 point update.
Fri, May 22, 2:40 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff created T427072: Integrate Trixie 13.5 point update.
Fri, May 22, 2:39 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Fri, May 22, 12:11 PM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Fri, May 22, 10:44 AM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff created T427039: Rollout ptrace hardening to roles which allow it.
Fri, May 22, 10:00 AM · Infrastructure Security, SRE
MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Fri, May 22, 7:59 AM · Ganeti, Infrastructure-Foundations, SRE

Thu, May 21

MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Thu, May 21, 9:37 AM · Ganeti, Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T424680: Add ganeti105[5678] and decom ganeti102[3456].
Thu, May 21, 6:23 AM · Ganeti, Infrastructure-Foundations, SRE

Wed, May 20

MoritzMuehlenhoff closed T373795: Integrate Bullseye 11.11 point update as Resolved.

All done

Wed, May 20, 2:45 PM · Infrastructure-Foundations, SRE
MoritzMuehlenhoff updated the task description for T373795: Integrate Bullseye 11.11 point update.
Wed, May 20, 2:45 PM · Infrastructure-Foundations, SRE