Page MenuHomePhabricator

ferm policy on deployment-bastion prevents scap rsync from mw hosts
Closed, ResolvedPublic

Description

The deployment-bastion.eqiad.wmflabs has ferm enabled. A changed occurred at 17:20 UTC which is added a network to a global ferm rule, that made puppet reload the service and discard whatever rule we might have add.

End result: the mediawiki instances can not ssh to deployment-bastion anymore. We might had a ferm::rule for it which disappeared somehow, or maybe that was hacked up manually and it is now gone.

That breaks beta-scap-eqiad job:

https://integration.wikimedia.org/ci/job/beta-scap-eqiad/21680/console

rsync: failed to connect to deployment-bastion.eqiad.wmflabs (10.68.16.58): Connection timed out (110)


Version: unspecified
Severity: normal
See Also:
https://bugzilla.wikimedia.org/show_bug.cgi?id=70863

Details

Reference
bz70858