Project

General

Profile

Actions

action #168177

open

coordination #167054: [epic] Run more workloads in CC-compliant PRG2 to be less affected by CC related network changes

Migrate critical VM based services needing access to CC-services to CC areas

Added by okurz 5 months ago. Updated 4 days ago.

Status:
Blocked
Priority:
Normal
Assignee:
Category:
Feature requests
Start date:
2024-09-19
Due date:
% Done:

0%

Estimated time:
Tags:

Description

Motivation

non-compliant NUE2 based production VMs might become problematic due to #165282 so we should evaluate which VMs we can migrate and where and execute accordingly.

Acceptance criteria

  • AC1: Critical VM based services needing access to CC-services are running from CC areas where reasonable
  • AC2: Users can access the services using location independant CNAME records where applicable as in before

Suggestions

  • DONE Wait for #168174
  • DONE Try out with non-critical changes, e.g. tumblesle
  • Decide which VMs and/or services should be migrated considering the alternative #168133. At time of writing we have 10 VMs on osiris+qamaster
  • Prepare DHCP+DNS changes in https://gitlab.suse.de/OPS-Service/salt/
  • See suggestions from #168174-3 about how to migrate
  • Migrate VMs from qamaster to a (temporary) service hypervisor running on a free OSD openQA worker, e.g. w38+w39
  • Move VMs to openplatform

Related issues 2 (1 open1 closed)

Blocked by openQA Infrastructure (public) - action #173674: qamaster-independent backup size:SBlockeddheidler2024-12-03

Actions
Copied from openQA Infrastructure (public) - action #167057: Run more standard, qemu OSD openQA jobs in CC-compliant PRG2 and none in NUE2 size:SResolvedokurz2024-09-19

Actions
Actions #1

Updated by okurz 5 months ago

  • Copied from action #167057: Run more standard, qemu OSD openQA jobs in CC-compliant PRG2 and none in NUE2 size:S added
Actions #2

Updated by okurz 5 months ago

  • Subject changed from Evacuate critical VM based services needing access to CC-services to CC areas to Migrate critical VM based services needing access to CC-services to CC areas
Actions #3

Updated by okurz 5 months ago

  • Description updated (diff)
  • Assignee set to okurz
Actions #5

Updated by okurz 5 months ago

  • Target version changed from Ready to Tools - Next
Actions #6

Updated by okurz 4 months ago

  • Subject changed from Migrate critical VM based services needing access to CC-services to CC areas to Migrate critical VM based services needing access to CC-services to CC areas size:M
  • Description updated (diff)
  • Status changed from New to Workable
Actions #7

Updated by okurz 4 months ago

  • Status changed from Workable to Blocked
Actions #8

Updated by okurz 4 months ago

  • Target version changed from Tools - Next to Ready
Actions #9

Updated by okurz 4 months ago

  • Assignee changed from okurz to mkittler

assigning to mkittler to track blocker tickets for now

Actions #10

Updated by okurz 4 months ago

Just from today https://suse.slack.com/archives/C04S88VCHS7/p1729859212598989

This time it’s about Common Criteria on OpenPlatform

:tldr: : You can now run CC-related workloads on OpenPlatform, if you fulfill the prerequisites :catjam:

Please read https://itpe.io.suse.de/open-platform/docs/news/this-sprint-in-openplatform-27 (VPN needed), or https://docs.google.com/document/d/14i2OXdJuFphLpw9CslH3xFDfiZgskSPMsIiWNDMEzPc/edit?usp=sharing (VPN not needed)

Actions #11

Updated by okurz 4 months ago

As today the network access rules have been put in place to prevent access to sensitive data we can see the problems that are linked to that.

Today actually regarding monitoring it seems it's weird that there was a short data outage but by now at least data from OSD itself shows up just fine on https://monitor.qa.suse.de/d/nRDab3Jiz/openqa-jobs-test?orgId=1&from=now-7d&to=now so it's really traffic from OSD (CC) to non-CC monitor is coming through ok it seems. With that it's less critical to move ressources like monitor.qa.suse.de

Actions #15

Updated by okurz 3 months ago

  • Description updated (diff)
Actions #16

Updated by okurz 3 months ago

  • Subject changed from Migrate critical VM based services needing access to CC-services to CC areas size:M to Migrate critical VM based services needing access to CC-services to CC areas

Based on discussion with szarate we should refine and re-estimate the ticket. Better split into multiple S-sized-tasks, e.g. split into "support migration of other people's VMs" and "our own critical service workloads" excluding any "personal toy VMs" :)

Actions #18

Updated by livdywan about 2 months ago

okurz wrote in #note-17:

https://sd.suse.com/servicedesk/customer/portal/1/SD-171367 still open

Asked in the ticket. Not sure who this is waiting on now.

Actions #19

Updated by livdywan 19 days ago · Edited

livdywan wrote in #note-18:

okurz wrote in #note-17:

https://sd.suse.com/servicedesk/customer/portal/1/SD-171367 still open

Asked in the ticket. Not sure who this is waiting on now.

I distilled specific open questions from the ticket that were not answered as far as I can see, and would suggest to discuss it on the Unblock as well.

Actions #20

Updated by okurz 10 days ago

  • Assignee changed from mkittler to okurz
  • Target version changed from Ready to future
Actions #21

Updated by livdywan 5 days ago

@okurz I'm afraid this ticket has to be on the backlog since it is blocking #168177 🙃 (See #167054#note-7)

Actions #22

Updated by livdywan 5 days ago

  • Status changed from Blocked to Feedback
  • Target version changed from future to Ready

Perhaps it helps to discuss it on a call? (not necessarily the whole team) Or if you feel differently about it we need to find another solution for the epic

Actions #23

Updated by okurz 4 days ago

Actions #24

Updated by okurz 4 days ago

  • Status changed from Feedback to Blocked
Actions

Also available in: Atom PDF