Project

General

Profile

tickets #67600

IPv6 network migration

Added by lrupp 4 months ago. Updated about 2 months ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
Core services and infra
Start date:
2020-06-02
Due date:
2020-06-30
% Done:

90%

Estimated time:

Description

As SUSE is becoming independent, some networks need to be re-arranged. One of them is the IPv6 network.

The old IPv6 network range (2620:113:80c0:8000::/50) in Nuremberg will go away end of the month. openSUSE still has some machines using this old IPv6 address since 2012. These machines need to be switched to the new IPv6 range (2001:67c:2178::/50), which is already in place and can be used directly.


Checklist

  • admin.lists4 (2620:113:80c0:8::14)
  • download (2620:113:80c0:8::13)
  • downloadcontent (2620:113:80c0:8::27)
  • foreman (2620:113:80c0:8::22)
  • gate2 (2620:113:8044:72:130:57:72:5) => disable for now
  • hydra (2620:113:80c0:8::19)
  • lists4 (2620:113:80c0:8::14)
  • lists5 (2620:113:80c0:8::26)
  • login (2620:113:80c0:8::12)
  • login2 (2620:113:80c0:8::161)
  • login2-nue (2620:113:80c0:8::161)
  • ns4 (2620:113:8044:72:130:57:72:32) => disable for now
  • pontifex (2620:113:80c0:8::13)
  • provo-downloadcontent (2620:113:8044:72:130:57:72:9) => disable for now
  • provo-mirror (2620:113:8044:72:130:57:72:10) => disable for now
  • proxy-nue (2620:113:80c0:8::16)
  • proxy-prv (2620:113:8044:72:130:57:72:1) => disable for now
  • proxy-prv1 (2620:113:8044:72:130:57:72:2) => disable for now
  • proxy-prv2 (2620:113:8044:72:130:57:72:3) => disable for now
  • scanner (2620:113:80c0:8::20)
  • scar (2620:113:80c0:8::28)
  • stage (2620:113:80c0:8::10)
  • static (2620:113:80c0:8::18)
  • status2 (2620:113:8044:72:130:57:72:11) => disable for now
  • login3 (2620:113:8044:72:130:57:72:20) => disable for now

History

#1 Updated by lrupp 4 months ago

  • Checklist changed from [ ] admin.lists4 (2620:113:80c0:8::14), [ ] download (2620:113:80c0:8::13), [ ] downloadcontent (2620:113:80c0:8::27), [ ] foreman (2620:113:80c0:8::22), [ ] gate2 (2620:113:8044:72:130:57:72:5) => disable for now, [ ] hydra (2620:113:80c0:8::19), [ ] lists4 (2620:113:80c0:8::14), [ ] lists5 (2620:113:80c0:8::26), [ ] login (2620:113:80c0:8::12), [ ] login2 (2620:113:80c0:8::161), [ ] login2-nue (2620:113:80c0:8::161), [ ] login3 (2620:113:8044:72:130:57:72:20), [ ] ns4 (2620:113:8044:72:130:57:72:32) => disable for now, [ ] pontifex (2620:113:80c0:8::13), [ ] provo-downloadcontent (2620:113:8044:72:130:57:72:9) => disable for now, [ ] provo-mirror (2620:113:8044:72:130:57:72:10) => disable for now, [ ] proxy-nue (2620:113:80c0:8::16), [ ] proxy-prv (2620:113:8044:72:130:57:72:1) => disable for now, [ ] proxy-prv1 (2620:113:8044:72:130:57:72:2) => disable for now, [ ] proxy-prv2 (2620:113:8044:72:130:57:72:3) => disable for now, [ ] scanner (2620:113:80c0:8::20), [ ] scar (2620:113:80c0:8::28), [ ] stage (2620:113:80c0:8::10), [ ] static (2620:113:80c0:8::18), [ ] status2 (2620:113:8044:72:130:57:72:11) => disable for now to [ ] admin.lists4 (2620:113:80c0:8::14), [ ] download (2620:113:80c0:8::13), [ ] downloadcontent (2620:113:80c0:8::27), [ ] foreman (2620:113:80c0:8::22), [ ] gate2 (2620:113:8044:72:130:57:72:5) => disable for now, [ ] hydra (2620:113:80c0:8::19), [ ] lists4 (2620:113:80c0:8::14), [ ] lists5 (2620:113:80c0:8::26), [ ] login (2620:113:80c0:8::12), [ ] login2 (2620:113:80c0:8::161), [ ] login2-nue (2620:113:80c0:8::161), [ ] ns4 (2620:113:8044:72:130:57:72:32) => disable for now, [ ] pontifex (2620:113:80c0:8::13), [ ] provo-downloadcontent (2620:113:8044:72:130:57:72:9) => disable for now, [ ] provo-mirror (2620:113:8044:72:130:57:72:10) => disable for now, [ ] proxy-nue (2620:113:80c0:8::16), [ ] proxy-prv (2620:113:8044:72:130:57:72:1) => disable for now, [ ] proxy-prv1 (2620:113:8044:72:130:57:72:2) => disable for now, [ ] proxy-prv2 (2620:113:8044:72:130:57:72:3) => disable for now, [ ] scanner (2620:113:80c0:8::20), [ ] scar (2620:113:80c0:8::28), [ ] stage (2620:113:80c0:8::10), [ ] static (2620:113:80c0:8::18), [ ] status2 (2620:113:8044:72:130:57:72:11) => disable for now, [ ] login3 (2620:113:8044:72:130:57:72:20) => disable for now

#2 Updated by lrupp 4 months ago

  • Due date set to 2020-06-30
  • Category changed from Servers hosted in NBG to Core services and infra
  • Status changed from New to In Progress
  • Assignee set to lrupp
  • Priority changed from Normal to High
  • Private changed from Yes to No

#3 Updated by lrupp 4 months ago

  • Checklist set to [x] proxy-prv1 (2620:113:8044:72:130:57:72:2) => disable for now

#4 Updated by lrupp 4 months ago

  • Checklist set to [x] proxy-prv2 (2620:113:8044:72:130:57:72:3) => disable for now

#5 Updated by lrupp 4 months ago

  • Checklist set to [x] proxy-prv (2620:113:8044:72:130:57:72:1) => disable for now

#6 Updated by lrupp 4 months ago

  • Checklist set to [x] login3 (2620:113:8044:72:130:57:72:20) => disable for now

#7 Updated by lrupp 4 months ago

  • Checklist set to [x] provo-mirror (2620:113:8044:72:130:57:72:10) => disable for now

#8 Updated by lrupp 4 months ago

  • Checklist set to [x] provo-downloadcontent (2620:113:8044:72:130:57:72:9) => disable for now

#9 Updated by lrupp 4 months ago

  • Checklist set to [x] gate2 (2620:113:8044:72:130:57:72:5) => disable for now

#10 Updated by lrupp 4 months ago

  • Checklist set to [x] ns4 (2620:113:8044:72:130:57:72:32) => disable for now

#11 Updated by lrupp 4 months ago

  • Checklist set to [x] status2 (2620:113:8044:72:130:57:72:11) => disable for now

#12 Updated by lrupp 4 months ago

  • Checklist set to [x] proxy-nue (2620:113:80c0:8::16)

#13 Updated by lrupp 4 months ago

  • Checklist set to [x] static (2620:113:80c0:8::18)

#14 Updated by ryanbach 4 months ago

http://download.opensuse.org/ is currently givng a 403 access forbidden.

#15 Updated by ryanbach 4 months ago

It looks like it is unrelated to this: https://status.opensuse.org/incidents/230 and is due to filesystem errors.

#16 Updated by lrupp 3 months ago

  • Checklist set to [x] scanner (2620:113:80c0:8::20)

#17 Updated by lrupp 3 months ago

  • Checklist set to [x] scar (2620:113:80c0:8::28)

#18 Updated by lrupp 3 months ago

  • Checklist set to [x] login2 (2620:113:80c0:8::161)

#19 Updated by lrupp 3 months ago

  • Checklist set to [x] login2-nue (2620:113:80c0:8::161)

#20 Updated by lrupp 3 months ago

  • Checklist set to [x] foreman (2620:113:80c0:8::22)

#21 Updated by lrupp 3 months ago

  • Checklist set to [x] lists4 (2620:113:80c0:8::14)

#22 Updated by lrupp 3 months ago

  • Checklist set to [x] lists5 (2620:113:80c0:8::26)

#23 Updated by lrupp 3 months ago

  • Checklist set to [x] admin.lists4 (2620:113:80c0:8::14)

#24 Updated by lrupp 3 months ago

  • Checklist set to [x] hydra (2620:113:80c0:8::19)

#25 Updated by lrupp 3 months ago

  • Checklist set to [x] login (2620:113:80c0:8::12)

#26 Updated by lrupp 3 months ago

  • Checklist set to [x] pontifex (2620:113:80c0:8::13)

#27 Updated by lrupp 3 months ago

  • Checklist set to [x] downloadcontent (2620:113:80c0:8::27)

#28 Updated by lrupp 3 months ago

  • Checklist set to [x] download (2620:113:80c0:8::13)

#29 Updated by lrupp 3 months ago

  • Checklist set to [x] stage (2620:113:80c0:8::10)

#30 Updated by lrupp 3 months ago

  • % Done changed from 0 to 90

As announced on the mirrors@opensuse.org list, all IPv6 entries are now available.

DNS had been changed and is pointing to the new IPv6 addresses as well.

Reverse IPv6 entries exist as well.

=> Waiting for the DNS to get distributed through all DNS servers.

#31 Updated by cboltz 3 months ago

Please don't forget to update the keepalived in salt git - currently it still has:

role/login.sls-      virtual_ipaddress:
role/login.sls-        # external IPs
role/login.sls-        # login2.opensuse.org
role/login.sls:        - 2620:113:80c0:8::161/64 dev external
--
role/proxy.sls-      virtual_ipaddress:
role/proxy.sls-        # proxy-nue.opensuse.org
role/proxy.sls:        - 2620:113:80c0:8::16/64 dev external
role/proxy.sls-        # static.opensuse.org
role/proxy.sls:        - 2620:113:80c0:8::18/64 dev external

#32 Updated by lrupp 3 months ago

  • Assignee changed from lrupp to cboltz

cboltz wrote:

Please don't forget to update the keepalived in salt git - currently it still has:

role/login.sls-      virtual_ipaddress:
role/login.sls-        # external IPs
role/login.sls-        # login2.opensuse.org
role/login.sls:        - 2620:113:80c0:8::161/64 dev external
--
role/proxy.sls-      virtual_ipaddress:
role/proxy.sls-        # proxy-nue.opensuse.org
role/proxy.sls:        - 2620:113:80c0:8::16/64 dev external
role/proxy.sls-        # static.opensuse.org
role/proxy.sls:        - 2620:113:80c0:8::18/64 dev external

I've currently no access to gitlab (forgot my 2nd factor @home). => leaving this up to you, Christian.

#33 Updated by cboltz about 2 months ago

  • Status changed from In Progress to Resolved

I've currently no access to gitlab (forgot my 2nd factor @home). => leaving this up to you, Christian.

I hope you have your 2FA device ready to review https://gitlab.infra.opensuse.org/infra/salt/-/merge_requests/430 ;-)

Also available in: Atom PDF