services:networking
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:networking [2026/05/07 15:02] – [Table] djgalloway | services:networking [2026/09/05 00:52] (current) – [Table] djgalloway | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| ^ Name ^ Purpose | ^ Name ^ Purpose | ||
| - | | Sepia Front Copy | + | | RDU Front Copy |
| - | | Sepia IPMI Copy | Created to make lab migration easy | 172.21.32.0/ | + | | RDU IPMI Copy | Created to make lab migration easy | 172.21.32.0/ |
| | New Front | Server uplinks | | New Front | Server uplinks | ||
| | New IPMI | New server BMC | 10.20.208.0/ | | New IPMI | New server BMC | 10.20.208.0/ | ||
| Line 21: | Line 21: | ||
| | vlan107 | | vlan107 | ||
| - | In January 2020, 4 new small subnets were created for the [[hardware: | + | The first IP of each is the gateway and the first 5 IPs should not be used (.0 through .4) |
| ==== Officinalis ==== | ==== Officinalis ==== | ||
| + | In January 2020, 4 new small subnets were created for the [[hardware: | ||
| [[services: | [[services: | ||
| - | | ^ vlan104.sepia.ceph.com | + | ===== Firewall Rules ===== |
| - | ^ Available IP Range | + | |
| - | ^ Gateway | + | IBM OneIT manages the Juniper SRX in front of the lab. |
| - | ^ VLAN ID | 104 | + | |
| + | ^ Application Name ^ Inbound/ | ||
| + | | OpenVPN | ||
| + | | nginx / file share (e.g., https:// | ||
| + | | GitWeb | ||
| + | | githelper (https:// | ||
| + | | Etherpad (pad.ceph.com) | Inbound | ||
| + | | Pulpito (https:// | ||
| + | | qa-proxy.ceph.com | ||
| + | | sentry.ceph.com | ||
| + | | teuthology-api.ceph.com | ||
| + | | Dokuwiki (wiki.sepia.ceph.com) | Inbound | ||
| + | | Postorius & Hyperkitty | ||
| + | | Postfix (Ceph project mailing lists) | ||
| + | | telemetry.ceph.com (apache2) | ||
| + | | telemetry-public.ceph.com (nginx serving grafana) | ||
| + | | chacra.ceph.com (nginx) | ||
| + | | quay.ceph.io | ||
| + | | INBOUND OKAY TO BLOCK: 20,21, | ||
| + | | Outbound web traffic | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | rsync unsigned packages from chacra.ceph.com | Outbound | ||
| + | | rsync signed packages to download.ceph.com | ||
| + | | OUTBOUND OKAY TO BLOCK: 20,21, | ||
| + | | All non-blocklisted ports | ||
| + | | All, unrestricted | ||
| + | |||
| + | Firewall rules can be updated by following https:// | ||
| + | |||
| + | IES keeps [[https:// | ||
| ===== Hardware ===== | ===== Hardware ===== | ||
services/networking.1778166128.txt.gz · Last modified: by djgalloway
