Last modified: 2014-09-12 15:32:27 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T72181, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 70181 - Setup a mediawiki03 (or what not) on Beta Cluster that we can direct the security scanning work to
Setup a mediawiki03 (or what not) on Beta Cluster that we can direct the secu...
Status: ASSIGNED
Product: Wikimedia Labs
Classification: Unclassified
deployment-prep (beta) (Other open bugs)
unspecified
All All
: High normal
: ---
Assigned To: Dan Duvall
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-29 16:56 UTC by Greg Grossmeier
Modified: 2014-09-12 15:32 UTC (History)
13 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Greg Grossmeier 2014-08-29 16:56:15 UTC
Sherif is doing great work scanning the Beta Cluster for security vulnerabilities, but we had to stop the scanning as it was negatively effecting other browser tests/user tests going on.

It'd be good if we could setup a separate mediawiki instance that only serves his scanning traffic, and thus leave the other two mediawikis to handle the browser tests and user tests that normally go on during the day.
Comment 1 Greg Grossmeier 2014-08-29 16:57:38 UTC
We'd like to get this going as soon as possible as the work is proving to be fruitful. Setting to High accordingly.
Comment 2 Giuseppe Lavagetto 2014-08-29 18:13:55 UTC
Redirecting traffic based on a cookie in varnish can be subtle, although I expect beta to be much simpler than production, it's still something that will probably need some non-trivial effort.
Comment 3 Dan Duvall 2014-08-29 18:18:54 UTC
Giving this a go.
Comment 4 Gerrit Notification Bot 2014-09-02 23:09:57 UTC
Change 158016 had a related patch set uploaded by Dduvall:
Labs: Varnish backend/director for isolated security audits

https://gerrit.wikimedia.org/r/158016
Comment 5 Dan Duvall 2014-09-02 23:43:12 UTC
The new deployment-mediawiki03 instance is fully provisioned, and I've cherry picked the varnish patch on deployment-salt. I've verified that the instance receives traffic [only] if a "security_audit=1" cookie is set, but I'd appreciate a second set of eyes on it.
Comment 6 Sherif Mansour 2014-09-02 23:49:30 UTC
Thanks Dan, will take a look tomorrow and test it, what is the url and domain I should hit?
Comment 7 Dan Duvall 2014-09-03 00:04:30 UTC
The host should be the same (en.wikipedia.beta.wmflabs.org). You just need to make sure the requests contain a "security_audit=1" cookie.

To be on the safe side, you might want to ping the #wikimedia-qa IRC channel when you're ready to start, just so we can keep an eye on things.
Comment 8 Sherif Mansour 2014-09-03 00:08:19 UTC
Will do
Comment 9 Greg Grossmeier 2014-09-10 17:58:36 UTC
13:57 <     bd808> mediawiki03 isn't in the scap pool yet I just noticed.
13:58 <     bd808> so it has stale code
Comment 10 Gerrit Notification Bot 2014-09-10 18:56:41 UTC
Change 159520 had a related patch set uploaded by BryanDavis:
beta: add deployment-mediawiki03 to scap targets

https://gerrit.wikimedia.org/r/159520
Comment 11 Dan Duvall 2014-09-11 21:50:55 UTC
I've cherry-picked the patch to deployment-salt.eqiad.wmflabs and the last scap deployment seems to have synced to deployment-mediawiki03.

dduvall@deployment-mediawiki03:~$ ls -ld /srv/mediawiki/
drwxr-xr-x 12 mwdeploy mwdeploy 4096 Sep 11 21:35 /srv/mediawiki/
Comment 12 Gerrit Notification Bot 2014-09-11 22:06:42 UTC
Change 159520 merged by Dzahn:
beta: add deployment-mediawiki03 to scap targets

https://gerrit.wikimedia.org/r/159520
Comment 13 Greg Grossmeier 2014-09-12 00:16:36 UTC
Are we all good here, then?
Comment 14 Dan Duvall 2014-09-12 15:32:27 UTC
Still waiting for https://gerrit.wikimedia.org/r/#/c/158016/ to be merged.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links