Just a quick note that I've moved the TLS termination and related rate
limiting and access control logic on the Cloud VPS web proxies from
the Nginx instance to a HAProxy layer in front of it.
I have disabled Puppet on the non-active instance
(proxy-6.project-proxy.eqiad1.wikimedia.cloud) just before rolling
out the changes. In case of a major issue with the new setup and I am
not around, just stopping keepalived on the active instance (proxy-5)
will be enough to move traffic to the other instance with the old
Nginx-only setup. I plan to move proxy-6 to the new setup in a day or
two if there are no issues found.
This work is a part of <https://phabricator.wikimedia.org/T429930>.
--
Taavi Väänänen (he/they)
Site Reliability Engineer, Tools Infrastructure
Wikimedia Foundation
Next Wednesday we will up upgrading the Toolforge Kubernetes install to
version 1.33.
This upgrade should not result in any feature changes or downtime but
there may be brief network resets and pods may be restarted and/or
rescheduled.
This upgrade is tracked here: https://phabricator.wikimedia.org/T433132
-Andrew