Closed
Bug 1148099
Opened 11 years ago
Closed 11 years ago
Enable inbound access to NRPE (tcp/5666) on vcssync{1,2}
Categories
(Release Engineering :: General, defect)
Release Engineering
General
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: hwine, Unassigned)
References
Details
Attachments
(1 file)
|
645 bytes,
patch
|
dustin
:
review+
|
Details | Diff | Splinter Review |
details are in bug 1135266 comment 5
Per arr in irc, current AWS security group doesn't allow. Likely a new one needs to be created and applied to these hosts.
Comment 1•11 years ago
|
||
afaik, rail, catlee, and dustin are the ones with perms to update the cloud-tools repo.
Currently this uses the default sg which is ssh from anywhere. Hal, what hosts actually need to connect to port 22 on these two boxes?
(In reply to Amy Rich [:arich] [:arr] from comment #1)
> Currently this uses the default sg which is ssh from anywhere. Hal, what
> hosts actually need to connect to port 22 on these two boxes?
We don't have any admin or jump hosts for this role yet. All admins need access (dev-services + pmoore + me). Some sort of restricted access will be added when boxes moved to dev-services AWS account, but that isn't planned out at this time.
Neither of these hosts produce repositories that are used in official builds at this time.
Comment 3•11 years ago
|
||
If you don't need any special inbound ports, I suggest you just create a new SG with the standard inbound allowances.
This doesn't have anything to do with roles or accounts, it's just a restriction on inbound and outbound IP/port access.
Updated•11 years ago
|
Attachment #8584485 -
Flags: review+
Comment 4•11 years ago
|
||
Can someone with access to merge this please check it in and merge it?
Comment 5•11 years ago
|
||
Pushed (there's no merging in this repo) and deployed.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Comment 6•11 years ago
|
||
Hal: you'll need to switch your instances to use the new security group.
Not done - per comment 0 needs to be applied to hosts, which requires console access, which I don't have.
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Comment 8•11 years ago
|
||
I can do it
Comment 9•11 years ago
|
||
changed
Status: REOPENED → RESOLVED
Closed: 11 years ago → 11 years ago
Resolution: --- → FIXED
Updated•11 years ago
|
QA Contact: pmoore → mshal
You need to log in
before you can comment on or make changes to this bug.
Description
•