#metabrainz

/

      • ruaok
        > -A forward_ssh_nat -d 10.1.1.102 -j log_and_accept
      • 2015-10-05 27814, 2015

      • ruaok
        no, wait, that might already be there.
      • 2015-10-05 27817, 2015

      • ruaok
        hold on, let me check.
      • 2015-10-05 27845, 2015

      • ruaok
        nope doesn't work.
      • 2015-10-05 27819, 2015

      • ruaok
        I think we need to add the rule above to get this ssh forward to work
      • 2015-10-05 27837, 2015

      • zas
        want me to add it to the PR ?
      • 2015-10-05 27806, 2015

      • ruaok
        yes, please.
      • 2015-10-05 27811, 2015

      • ruaok heads out for noms
      • 2015-10-05 27858, 2015

      • flamingspinach has quit
      • 2015-10-05 27816, 2015

      • flamingspinach joined the channel
      • 2015-10-05 27815, 2015

      • ariscop has quit
      • 2015-10-05 27843, 2015

      • UmkaDK has quit
      • 2015-10-05 27802, 2015

      • UmkaDK joined the channel
      • 2015-10-05 27846, 2015

      • ruaok
        zas: I just gave you a pile of MB privs.
      • 2015-10-05 27856, 2015

      • ruaok
        you'll need this one the most, methinks: https://musicbrainz.org/admin/banner/edit
      • 2015-10-05 27832, 2015

      • zas
        Ok, noted
      • 2015-10-05 27811, 2015

      • ruaok
        so, when we play with the firewall, we should put up a message there and on beta.mb.org
      • 2015-10-05 27826, 2015

      • ruaok
        and to tweet that we might loose connectivity for a minute or two
      • 2015-10-05 27845, 2015

      • ruaok
        should I request the DNS change for data.mb.org to now go to: 167.148?
      • 2015-10-05 27847, 2015

      • zas
        i guess so
      • 2015-10-05 27812, 2015

      • zas
        any other hostname to change or add ? scooby had scooby.musicbrainz.org
      • 2015-10-05 27826, 2015

      • zas
        and few others, chatlogs, etc..
      • 2015-10-05 27830, 2015

      • ruaok
        let's do that when we move the domain over.
      • 2015-10-05 27804, 2015

      • D4RK-PH0ENiX has quit
      • 2015-10-05 27844, 2015

      • D4RK-PH0ENiX joined the channel
      • 2015-10-05 27845, 2015

      • D4RK-PH0ENiX has quit
      • 2015-10-05 27852, 2015

      • D4RK-PH0ENiX joined the channel
      • 2015-10-05 27856, 2015

      • CatQuest wonders what "yak shaving means again"
      • 2015-10-05 27801, 2015

      • CatQuest
        erh wrong placement of "
      • 2015-10-05 27826, 2015

      • ruaok
      • 2015-10-05 27826, 2015

      • ruaok
        right zas?
      • 2015-10-05 27804, 2015

      • ruaok
        OMFG.
      • 2015-10-05 27809, 2015

      • zas
        ?
      • 2015-10-05 27857, 2015

      • CatQuest lso thinks we need to finally do a thing for april fools day. al lthe cool sites are doing it :(
      • 2015-10-05 27813, 2015

      • D4RK-PH0ENiX has quit
      • 2015-10-05 27843, 2015

      • ruaok
        zas: does that CNAME change look ok to you?
      • 2015-10-05 27858, 2015

      • zas
        yes, or you can use a A with the matching IP, it prevents useless dns queries (CNAME != alias)
      • 2015-10-05 27841, 2015

      • ruaok
        DWNI really prefers this way. another reason we should move to gandi.
      • 2015-10-05 27850, 2015

      • ruaok
        so, lets make those improvements later.
      • 2015-10-05 27858, 2015

      • zas
        ok np ;)
      • 2015-10-05 27826, 2015

      • ruaok
        have you added the wiki forward to the PR yet?
      • 2015-10-05 27840, 2015

      • zas
        nope
      • 2015-10-05 27846, 2015

      • zas
        i'll do it now
      • 2015-10-05 27857, 2015

      • zas
        done, check the PR
      • 2015-10-05 27809, 2015

      • zas
        i'm looking at the multicast thing
      • 2015-10-05 27838, 2015

      • ruaok
        and that change makes sense to you, yes?
      • 2015-10-05 27856, 2015

      • ruaok
        the NAT forwarding rule was already there, right?
      • 2015-10-05 27813, 2015

      • zas
        i didnt check, let me see
      • 2015-10-05 27826, 2015

      • MajorLurker has quit
      • 2015-10-05 27843, 2015

      • zas
        -A forward_new -i em1 -o em2.1 -p tcp -m tcp --dport 22 -j forward_ssh_nat
      • 2015-10-05 27843, 2015

      • zas
        -A forward_new -i em1 -o em2.3 -p tcp -m tcp --dport 22 -j forward_ssh_nat
      • 2015-10-05 27852, 2015

      • zas
        so it should be pl
      • 2015-10-05 27859, 2015

      • zas
        s/pl/ok/
      • 2015-10-05 27813, 2015

      • ruaok
        k
      • 2015-10-05 27829, 2015

      • D4RK-PH0ENiX joined the channel
      • 2015-10-05 27859, 2015

      • D4RK-PH0ENiX has quit
      • 2015-10-05 27805, 2015

      • D4RK-PH0ENiX joined the channel
      • 2015-10-05 27840, 2015

      • samphippen has quit
      • 2015-10-05 27838, 2015

      • zas
      • 2015-10-05 27814, 2015

      • ruaok
        yes, I had no luck. I probably screwed it up though.
      • 2015-10-05 27836, 2015

      • zas
        btw, multicast packets aren't not specifically handled by current rules it seems to me, so we can start by logging them (i tested, and no packet is logged has dropped)
      • 2015-10-05 27808, 2015

      • zas
        s/has d/when d/
      • 2015-10-05 27855, 2015

      • zas
        hmmm bert and ernie have different corosync configs, mcastaddr and mcastport differ
      • 2015-10-05 27822, 2015

      • ruaok
        yes.
      • 2015-10-05 27838, 2015

      • ruaok
        I've not fixed up bert much yet to reflect what things really ought to look like.
      • 2015-10-05 27849, 2015

      • ruaok
        we want to keep bert out for now.
      • 2015-10-05 27803, 2015

      • ruaok
        get ernie all setup and happy. then get bert happy.
      • 2015-10-05 27826, 2015

      • ruaok
        then fail over. then we can run chef on ernie to make sure 100% that we're caught up.
      • 2015-10-05 27814, 2015

      • ruaok
        wow, we have 10 unicorns now. :)
      • 2015-10-05 27816, 2015

      • ruaok
      • 2015-10-05 27808, 2015

      • Leo_Verto
        Wow
      • 2015-10-05 27819, 2015

      • ruaok
        now lets see if any of the other majors follow suit. :)
      • 2015-10-05 27821, 2015

      • zas
        btw, shouldn't ernie corosync bind to 10.1.1.0 instead of 127.0.0.1 ?
      • 2015-10-05 27816, 2015

      • ruaok
        THAT was the problem.
      • 2015-10-05 27851, 2015

      • ruaok
        the cruz of it all that caused this.
      • 2015-10-05 27819, 2015

      • ruaok
        crux
      • 2015-10-05 27831, 2015

      • zas
        apart that, the rules described at http://serverfault.com/questions/418634/secure-ip… should work (once we adapted them to our setup), i'll prepare a PR for that
      • 2015-10-05 27806, 2015

      • ruaok
        very good.
      • 2015-10-05 27826, 2015

      • ruaok
        huh, they agreed that the contract should be considered retro-active to July 1 when their side signed the contract. Cool. :)
      • 2015-10-05 27833, 2015

      • ruaok
        3 months free money. I dig.
      • 2015-10-05 27801, 2015

      • zas
        :)
      • 2015-10-05 27830, 2015

      • Leo_Verto
        I don't know how many people manage to let huge studios give them free money :P
      • 2015-10-05 27850, 2015

      • ruaok
        <=== :-D
      • 2015-10-05 27826, 2015

      • ruaok
        they will now have contributed more money that they've destroyed for us.
      • 2015-10-05 27832, 2015

      • ruaok
        so, that is a plus.
      • 2015-10-05 27832, 2015

      • Leo_Verto
        and I also don't know how you managed to do all of that stuff plus sysadministration before zas was a thing
      • 2015-10-05 27841, 2015

      • ruaok
        poorly.
      • 2015-10-05 27826, 2015

      • ruaok
        of course the server that I mentioned in the contract is actually down right now, but that's cool, right? :)
      • 2015-10-05 27849, 2015

      • CatQuest
        bert and ernie should really be run together /offtopic
      • 2015-10-05 27851, 2015

      • CatQuest
        :P
      • 2015-10-05 27801, 2015

      • ruaok
        CatQuest: they are.
      • 2015-10-05 27806, 2015

      • ruaok
        they are a pair.
      • 2015-10-05 27846, 2015

      • CatQuest
        indeed :D
      • 2015-10-05 27843, 2015

      • CatQuest
        also, the supporters page.. I guess it's just me, but the logoes all overlap and the text have become pillars
      • 2015-10-05 27801, 2015

      • CatQuest
        only for unicorn thoguh, not the others
      • 2015-10-05 27806, 2015

      • zas
        ruaok: did you ask for data.musicbrainz.org change already ? what is the usual delay (apart the ttl one) ?
      • 2015-10-05 27818, 2015

      • ruaok
        I did.
      • 2015-10-05 27818, 2015

      • CatQuest
        no wait also bronze
      • 2015-10-05 27828, 2015

      • Leo_Verto
        CatQuest, uhh, which firefox version are you using these days?
      • 2015-10-05 27839, 2015

      • ruaok
        usually they are on it reasonably fast, but not today. should I call them to poke them?
      • 2015-10-05 27843, 2015

      • CatQuest
        seems to be dependant on the amounts of peopl in the tier
      • 2015-10-05 27858, 2015

      • CatQuest
        Leo_Verto: let me try in the dev version first ok?
      • 2015-10-05 27817, 2015

      • CatQuest
        not an issue there
      • 2015-10-05 27834, 2015

      • CatQuest
        somehow there is not a newline in the old ff
      • 2015-10-05 27847, 2015

      • CatQuest
        they just get squeezed in on the same line
      • 2015-10-05 27844, 2015

      • zas
        well, i would poke them, ttl is 1 day, ftp is down since too long time imho
      • 2015-10-05 27843, 2015

      • kahu joined the channel
      • 2015-10-05 27846, 2015

      • ruaok
        ftp is up. just not updating. :)
      • 2015-10-05 27829, 2015

      • ruaok stops being snark and calls DWNI
      • 2015-10-05 27813, 2015

      • ruaok
        done, changed while I was holding. he's next going to clear his cache and we should see the change directly off their service
      • 2015-10-05 27826, 2015

      • ruaok
        yep. ok, done
      • 2015-10-05 27856, 2015

      • zas
        we need to apply fw rules now and see if it suffices or no
      • 2015-10-05 27804, 2015

      • ruaok
        is there a new PR?
      • 2015-10-05 27845, 2015

      • zas
        for the multicast ? not ready yet
      • 2015-10-05 27859, 2015

      • ruaok
        ok
      • 2015-10-05 27819, 2015

      • ruaok
        do you want to try the new rules now or wait for the mulitcast?
      • 2015-10-05 27807, 2015

      • zas
        i don't think we need to wait for multicast thing
      • 2015-10-05 27817, 2015

      • ruaok
        ok.
      • 2015-10-05 27829, 2015

      • ruaok
        let me set a banner and tweet about a possible short interruption.
      • 2015-10-05 27835, 2015

      • ruaok
        ready in a few minutes?
      • 2015-10-05 27825, 2015

      • ruaok
        ok, done.
      • 2015-10-05 27827, 2015

      • ruaok
        ready when you are zas
      • 2015-10-05 27822, 2015

      • zas
        did you merge the PR ?
      • 2015-10-05 27833, 2015

      • zas
        ah no ;)
      • 2015-10-05 27836, 2015

      • zas
        i do it
      • 2015-10-05 27838, 2015

      • ruaok
        k
      • 2015-10-05 27840, 2015

      • zas
        to deploy new rules, you just run update.sh ? like for nagios-chef ?
      • 2015-10-05 27855, 2015

      • ruaok
        NO !!!
      • 2015-10-05 27802, 2015

      • zas
        ah ;)
      • 2015-10-05 27804, 2015

      • ruaok
        you can't do that on the live node.
      • 2015-10-05 27817, 2015

      • zas
        so how do you proceed ?
      • 2015-10-05 27818, 2015

      • ruaok
        you need to hand install the updates. :(
      • 2015-10-05 27831, 2015

      • ruaok
        in future you'll fail over, update and then fail over again.
      • 2015-10-05 27848, 2015

      • zas
        ok, so iptables-restore using new rules ?
      • 2015-10-05 27800, 2015

      • alastairp
        new url for chatlogs?
      • 2015-10-05 27808, 2015

      • ruaok
        zas: yes.
      • 2015-10-05 27815, 2015

      • ruaok
      • 2015-10-05 27818, 2015

      • alastairp
        or more specifically, ruaok: what's the url of the second-hand bike page you sent to Gentlecat
      • 2015-10-05 27824, 2015

      • alastairp
        502
      • 2015-10-05 27837, 2015

      • ruaok
        502, really?
      • 2015-10-05 27843, 2015

      • ruaok
        Leo_Verto: ping?
      • 2015-10-05 27804, 2015

      • Leo_Verto
        uh
      • 2015-10-05 27814, 2015

      • ruaok
        Leo_Verto: sorry, nm
      • 2015-10-05 27819, 2015

      • Leo_Verto
        yeah
      • 2015-10-05 27827, 2015

      • ruaok
      • 2015-10-05 27830, 2015

      • Leo_Verto
        :P
      • 2015-10-05 27837, 2015

      • Leo_Verto
        maybe add a redirect?
      • 2015-10-05 27845, 2015

      • ruaok
        I was planning on doing that. :)
      • 2015-10-05 27831, 2015

      • zas
        ruaok: ok, i'm ready, i'll set safety belt to 1 minute
      • 2015-10-05 27836, 2015

      • ruaok
        go!