services:networking
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:networking [2026/05/07 15:01] – djgalloway | services:networking [2026/09/05 00:52] (current) – [Table] djgalloway | ||
|---|---|---|---|
| Line 3: | Line 3: | ||
| ===== Networks ===== | ===== Networks ===== | ||
| - | ^ Name ^ Purpose | + | ^ Name |
| - | | Sepia Front Copy | Mirrors existing upstream Ceph lab | + | | RDU Front Copy |
| - | | Sepia IPMI Copy | + | | RDU IPMI Copy | Created to make lab migration easy |
| - | | New Front | + | | New Front | Server uplinks |
| - | | New IPMI | New server BMC | + | | New IPMI |
| - | | VPN Clients | + | | VPN Clients |
| - | | LRC | + | | LRC | Ceph Cluster Backend Storage Traffic |
| - | | Openshift Cluster | + | | Openshift Cluster |
| - | | Openshift Provision | Openshift Provisioning/ | + | | Openshift Provision |
| - | | Openshift Clients | + | | Openshift Clients |
| - | | ODF Public | + | | ODF Public |
| - | | ODF Storage | + | | ODF Storage |
| - | | Public | + | | Public |
| - | | vlan104 | + | | vlan104 |
| - | | vlan105 | + | | vlan105 |
| - | | vlan106 | + | | vlan106 |
| - | | vlan107 | + | | vlan107 |
| - | In January 2020, 4 new small subnets were created for the [[hardware: | + | The first IP of each is the gateway and the first 5 IPs should not be used (.0 through .4) |
| ==== Officinalis ==== | ==== Officinalis ==== | ||
| + | In January 2020, 4 new small subnets were created for the [[hardware: | ||
| [[services: | [[services: | ||
| - | | ^ vlan104.sepia.ceph.com | + | ===== Firewall Rules ===== |
| - | ^ Available IP Range | + | |
| - | ^ Gateway | + | IBM OneIT manages the Juniper SRX in front of the lab. |
| - | ^ VLAN ID | 104 | + | |
| + | ^ Application Name ^ Inbound/ | ||
| + | | OpenVPN | ||
| + | | nginx / file share (e.g., https:// | ||
| + | | GitWeb | ||
| + | | githelper (https:// | ||
| + | | Etherpad (pad.ceph.com) | Inbound | ||
| + | | Pulpito (https:// | ||
| + | | qa-proxy.ceph.com | ||
| + | | sentry.ceph.com | ||
| + | | teuthology-api.ceph.com | ||
| + | | Dokuwiki (wiki.sepia.ceph.com) | Inbound | ||
| + | | Postorius & Hyperkitty | ||
| + | | Postfix (Ceph project mailing lists) | ||
| + | | telemetry.ceph.com (apache2) | ||
| + | | telemetry-public.ceph.com (nginx serving grafana) | ||
| + | | chacra.ceph.com (nginx) | ||
| + | | quay.ceph.io | ||
| + | | INBOUND OKAY TO BLOCK: 20,21, | ||
| + | | Outbound web traffic | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | rsync unsigned packages from chacra.ceph.com | Outbound | ||
| + | | rsync signed packages to download.ceph.com | ||
| + | | OUTBOUND OKAY TO BLOCK: 20,21, | ||
| + | | All non-blocklisted ports | ||
| + | | All, unrestricted | ||
| + | |||
| + | Firewall rules can be updated by following https:// | ||
| + | |||
| + | IES keeps [[https:// | ||
| ===== Hardware ===== | ===== Hardware ===== | ||
services/networking.1778166075.txt.gz · Last modified: by djgalloway
