Page MenuHomePhabricator

discovery-systemTag
ArchivedPublic

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

NOT USED ANYMORE - see T282948.

Was: All tickets related to the configuration/discovery system should hold this label

Recent Activity

Mar 2 2022

Aklapper moved T282948: Document what #discovery-system is from Incoming to Projects to archive on the Project-Admins board.
Mar 2 2022, 10:38 AM · Project-Admins, Kubernetes, SRE, discovery-system
Aklapper added a project to T282948: Document what #discovery-system is: Project-Admins.
Mar 2 2022, 10:38 AM · Project-Admins, Kubernetes, SRE, discovery-system
Aklapper added a comment to T282948: Document what #discovery-system is.

Project archived - https://www.mediawiki.org/wiki/Phabricator/Project_management#Archiving_a_project

Mar 2 2022, 10:38 AM · Project-Admins, Kubernetes, SRE, discovery-system
Aklapper set the color for discovery-system to Red.
Mar 2 2022, 10:37 AM
Aklapper archived discovery-system.
Mar 2 2022, 10:37 AM
RhinosF1 added a comment to T282948: Document what #discovery-system is.

Should it be archived then?

Mar 2 2022, 7:45 AM · Project-Admins, Kubernetes, SRE, discovery-system
Joe closed T282948: Document what #discovery-system is as Resolved.

@Aklapper all done. I think we can retire the tag.

Mar 2 2022, 7:19 AM · Project-Admins, Kubernetes, SRE, discovery-system
Joe closed T98165: Figure out an etcd deploy strategy that includes multi DC failure scenarios. as Resolved.

This task was left open by mistake; we've had a multi-dc setup for years now.

Mar 2 2022, 7:19 AM · Traffic-Icebox, Platform Team Legacy (Watching / External), Services (watching), SRE, services-tooling, discovery-system
Joe closed T107285: Create a conftool "agent" that overcomes confd deficiencies as Declined.

7 years later no one is working on this and I doubt it will ever be. Declining the task as a consequence.

Mar 2 2022, 7:18 AM · SRE, discovery-system
Joe closed T124413: confctl should provide tags information after writing data as Resolved.

This has been solved years ago.

Mar 2 2022, 7:16 AM · SRE, discovery-system
Joe closed T146355: Replace etcd internal auth mechanism with a frontend proxy as Resolved.

This has been implemented years ago.

Mar 2 2022, 7:16 AM · discovery-system, SRE
Joe closed T182597: Use EtcdConfig in production to allow automation of a datacenter switch as Resolved.
Mar 2 2022, 7:16 AM · MW-1.31-release-notes (WMF-deploy-2018-02-27 (1.31.0-wmf.23)), discovery-system, MediaWiki-Configuration, SRE
Joe closed T156232: confctl SubjectAltNameWarning after python-urllib3 upgrade as Resolved.
Mar 2 2022, 7:15 AM · discovery-system, SRE

Feb 5 2022

Aklapper assigned T282948: Document what #discovery-system is to Joe.

@Joe: Thanks in advance!

Feb 5 2022, 7:43 AM · Project-Admins, Kubernetes, SRE, discovery-system

Jan 24 2022

Joe added a comment to T282948: Document what #discovery-system is.

@Aklapper yes it used to be used for the system we built that is the base for both the DNS discovery system and dynamic configuration for things like pybal or mediawiki.

Jan 24 2022, 2:46 PM · Project-Admins, Kubernetes, SRE, discovery-system

Jan 20 2022

Aklapper added a comment to T282948: Document what #discovery-system is.

@Joe: Do you know, by any chance? (Or have some link handy?)

Jan 20 2022, 1:15 PM · Project-Admins, Kubernetes, SRE, discovery-system

May 25 2021

Marostegui triaged T282948: Document what #discovery-system is as Medium priority.
May 25 2021, 5:02 AM · Project-Admins, Kubernetes, SRE, discovery-system

May 18 2021

Dzahn added a project to T282948: Document what #discovery-system is: Kubernetes.
May 18 2021, 9:49 PM · Project-Admins, Kubernetes, SRE, discovery-system
Dzahn added a comment to T282948: Document what #discovery-system is.

Pretty sure it's T95662 and service discovery as in https://platform9.com/blog/kubernetes-service-discovery-principles-in-practice/ but @Joe will be able to confirm.

May 18 2021, 9:49 PM · Project-Admins, Kubernetes, SRE, discovery-system

May 15 2021

Aklapper updated the task description for T282948: Document what #discovery-system is.
May 15 2021, 4:17 PM · Project-Admins, Kubernetes, SRE, discovery-system
Aklapper created T282948: Document what #discovery-system is.
May 15 2021, 4:17 PM · Project-Admins, Kubernetes, SRE, discovery-system

Sep 22 2020

BBlack moved T98165: Figure out an etcd deploy strategy that includes multi DC failure scenarios. from etcd to Radar/Not for Service on the Traffic board.
Sep 22 2020, 4:22 PM · Traffic-Icebox, Platform Team Legacy (Watching / External), Services (watching), SRE, services-tooling, discovery-system

Jun 4 2020

Joe closed T97972: Figure out a security model for etcd, a subtask of T97978: Create a tool to sync static configuration from a repository to the consistent k/v store, as Resolved.
Jun 4 2020, 5:55 AM · SRE, services-tooling, discovery-system, Traffic
Joe closed T97972: Figure out a security model for etcd as Resolved.
Jun 4 2020, 5:55 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 602047 merged by Giuseppe Lavagetto:
[operations/puppet@production] profile::conftool::client: only use root on cumin*, puppetmasters

Jun 4 2020, 5:39 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Jun 3 2020

Joe added a comment to T97972: Figure out a security model for etcd.

My tests went fine:

  • mwdebug* servers got the datacenter-appropriate pool-$dc-testserver user
  • the deployment servers got the conftool user instead
Jun 3 2020, 10:57 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 602047 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] profile::conftool::client: only use root on cumin*, puppetmasters

Jun 3 2020, 10:56 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 598415 merged by Giuseppe Lavagetto:
[operations/puppet@production] profile::conftool::client: allow overriding the user root can access

Jun 3 2020, 9:35 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

May 28 2020

gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 597806 merged by Giuseppe Lavagetto:
[operations/puppet@production] profile::etcd::tlsproxy: add additional users for pools

May 28 2020, 8:48 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 597805 merged by Giuseppe Lavagetto:
[operations/puppet@production] profile::etcd::tlsproxy: refresh code for modern puppet

May 28 2020, 6:55 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
Joe added a comment to T97972: Figure out a security model for etcd.

The deploy strategy is simply adding the new users to etcd, move most hosts to use conftool as the root user immediately, and then progressively move them to the new users system on the long run.

May 28 2020, 6:51 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

May 25 2020

gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 598415 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] profile::conftool::client: allow overriding the user root can access

May 25 2020, 8:17 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

May 22 2020

Volans added a comment to T97972: Figure out a security model for etcd.

+1 as the above schema of auth reflects mostly my old comment/proposal. What's the deploy strategy?

May 22 2020, 11:20 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

May 21 2020

gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 597806 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] profile::etcd::tlsproxy: add additional users for pools

May 21 2020, 3:27 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a project to T97972: Figure out a security model for etcd: Patch-For-Review.
May 21 2020, 3:27 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 597805 had a related patch set uploaded (by Giuseppe Lavagetto; owner: Giuseppe Lavagetto):
[operations/puppet@production] profile::etcd::tlsproxy: refresh code for modern puppet

May 21 2020, 3:27 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
CDanis added a comment to T97972: Figure out a security model for etcd.

These permissions LGTM.

May 21 2020, 12:54 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
akosiaris added a comment to T97972: Figure out a security model for etcd.

RBAC without roles isn't really Role Based Access Control, but I digress.

May 21 2020, 12:50 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic
Joe added a comment to T97972: Figure out a security model for etcd.

I think I will try to implement the following RBAC schema:

May 21 2020, 5:48 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Mar 1 2020

Aklapper removed a project from T97972: Figure out a security model for etcd: Patch-For-Review.
Mar 1 2020, 6:24 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Feb 26 2020

akosiaris added a comment to T97972: Figure out a security model for etcd.

Per @Volans recommendation, adding a use case here:

Feb 26 2020, 7:53 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Jan 15 2020

gerritbot added a comment to T97972: Figure out a security model for etcd.

Change 564994 abandoned by Giuseppe Lavagetto:
This is a test, please disregard.

Jan 15 2020, 1:09 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Oct 22 2019

chasemp removed a watcher for discovery-system: chasemp.
Oct 22 2019, 2:18 PM

Oct 16 2019

chasemp removed a member for discovery-system: chasemp.
Oct 16 2019, 12:29 PM

Aug 21 2019

Marostegui updated the task description for T182597: Use EtcdConfig in production to allow automation of a datacenter switch.
Aug 21 2019, 10:57 AM · MW-1.31-release-notes (WMF-deploy-2018-02-27 (1.31.0-wmf.23)), discovery-system, MediaWiki-Configuration, SRE
Joe closed T185084: Allow use of EtcdConfig to configure slave databases as Resolved.

Indeed! we're doing more than this!

Aug 21 2019, 10:55 AM · DBA, discovery-system, MediaWiki-Configuration, SRE
Joe closed T185084: Allow use of EtcdConfig to configure slave databases, a subtask of T182597: Use EtcdConfig in production to allow automation of a datacenter switch, as Resolved.
Aug 21 2019, 10:55 AM · MW-1.31-release-notes (WMF-deploy-2018-02-27 (1.31.0-wmf.23)), discovery-system, MediaWiki-Configuration, SRE
Marostegui added a comment to T185084: Allow use of EtcdConfig to configure slave databases.

@Joe can this be considered done already with dbctl?

Aug 21 2019, 10:54 AM · DBA, discovery-system, MediaWiki-Configuration, SRE

Aug 2 2019

CDanis added a project to T97972: Figure out a security model for etcd: conftool.
Aug 2 2019, 4:27 PM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic

Aug 1 2019

Joe added a comment to T97972: Figure out a security model for etcd.
In T97972#5352851, @Joe wrote:

IIRC we already have an account specialized for accessing only mwconfig, we could expand on the concept.

Not in etcd, we only have a root user (see v2/auth/users) and root and guest roles (see v2/auth/roles). The guest role having access to eventlogging objects, but I don't see them, so maybe relic from the past of setup in anticipation of something that never happened.

Aug 1 2019, 11:20 AM · Patch-For-Review, conftool, SRE, services-tooling, discovery-system, Traffic