Last modified: 2014-08-28 01:20:55 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T62144, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 60144 - Audit security groups
Audit security groups
Status: REOPENED
Product: Wikimedia Labs
Classification: Unclassified
tools (Other open bugs)
unspecified
All All
: Unprioritized normal
: ---
Assigned To: Marc A. Pelletier
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-01-16 19:41 UTC by Tim Landscheidt
Modified: 2014-08-28 01:20 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Tim Landscheidt 2014-01-16 19:41:04 UTC
Currently, intra-project traffic (i. e., from tools-login to tools-redis or from tools-webproxy to tools-webgrid-01) is not subject to the firewall rules of security groups.  Due to that, security groups are not up to date, for example, the redis security group doesn't explicitely allow traffic on port 6379.

The move to eqiad could change the default behaviour.

Therefore, prior to the move, we need to make sure that:

a) all hosts have proper security groups assigned, and
b) security groups really allow traffic they're supposed to allow.
Comment 1 Marc A. Pelletier 2014-08-27 22:49:31 UTC
Anything intended "prior to the move" is not all that relevant today.  :-)
Comment 2 Tim Landscheidt 2014-08-28 01:09:37 UTC
Eh, yes, irrespective of the DC location, we should still make sure that:

a) all hosts have proper security groups assigned, and
b) security groups really allow traffic they're supposed to allow.
Comment 3 Daniel Zahn 2014-08-28 01:20:55 UTC
agree, just because we didn't already do it doesn't mean it's invalid :)

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links