Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Rachel
Rachel
@rachel@transitory.social  ·  activity timestamp 2 days ago

aaaaaaand we're back, that was fun!

  • Copy link
  • Flag this post
  • Block
Rachel
Rachel
@rachel@transitory.social replied  ·  activity timestamp 2 days ago
ablobcatbounce Incident report: ablobcatbounce * Previously in the week it was noticed that Cilium had an update to 1.19.0 * Upon further inspection, this looked to be a pre-release, so it was left alone, cilium is a load-bearing component and should only be touched with care * At some point in the last week I forgot about that and hit merge in forgejo, not an issue, since argocd won't auto-sync any load-bearing components (cilium, forgejo, argo, cert-manger, and a handful of others) * Over the last few days I have repeatedly restarted various components while troubleshooting some OIDC issues. Including ArgoCD and Forgejo * This caused a few sync errors or argo state refresh errors as pods were unceremoniously exploded * At some point during this time Cilium ended up out of sync/errored * By this point I had forgotten about the cilium major`*` update * I hit sync to clear that out and see what is wrong. Everything is green, and nothing breaks. * BGP sessions continue * I go about my afternoon * BGP sessions expire, causing immediate issues. since my old config was depricated * I start the investigation with DNS, since the TV stopped playback and sites stopped loading on my laptop * Yup, DNS is down. * But not from my dev console, that means ad-guard DNS is down. * Ad-guard DNS is throwing errors connecting to quad9 via DoT, I am not sure the cause of this, maybe the UI has a clue * ad-guard DNS ui isn't opening, oh. No cluster-based site is opening actually. * Confirmed, all LB services are down, must be BGP related * Looking in the Mikrotik router I see two BGP sessions, so I restart the BGP service on the router, they drop and don't re-appear, must have been stale on that side. * Restart cilium to see logs * BGP config error? Wait, did cilium update??? > ⚠️ You may need to take action during upgrade to Cilium v1.19 if you use Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. * Oh right, I've been seeing depreciation warnings about the BGP config for ages now * After converting the docs format I am rewarded with the TV abruptly starting the playlist, time to commit this to git and move on, phew ablobcatjumping #Homelab #Networking #Kubernetes #BGP
  • Copy link
  • Flag this comment
  • Block
Michael
Michael
@mmeier@social.mei-home.net replied  ·  activity timestamp 2 days ago

@rachel I'm not sure whether I might have done you one better during my Cilium update tonight: I dutifully read the upgrade notes, and somehow got my brain in a tizzy about the formulation of the BGPv1 deprecation - and thought that it was saying the new BGP manifests, listed in the bullet point, were the once which were deprecated. Took me a solid thirty minutes of googling to realize my mistake. 🤦

  • Copy link
  • Flag this comment
  • Block
Rachel
Rachel
@rachel@transitory.social replied  ·  activity timestamp 2 days ago

@mmeier@social.mei-home.net heh I can picture doing that, looking for the docs that replace the v1.....

  • Copy link
  • Flag this comment
  • Block
Mauricio Teixeira🐧:kubernetes:
Mauricio Teixeira🐧:kubernetes:
@badnetmask@hachyderm.io replied  ·  activity timestamp 2 days ago

@rachel @mmeier
I not only read all the release notes for everything, but I also separate cluster from apps.

Basically the things that make the cluster "tick" (like Cilium) sit in a repo, separate from the apps, which require manual intervention. I'm that paranoid. 😄

  • Copy link
  • Flag this comment
  • Block
Rachel
Rachel
@rachel@transitory.social replied  ·  activity timestamp 2 days ago

@badnetmask@hachyderm.io @mmeier@social.mei-home.net I wonder if I can have renovate add certain tags based on the app ? might be worth looking into

  • Copy link
  • Flag this comment
  • Block
Mauricio Teixeira🐧:kubernetes:
Mauricio Teixeira🐧:kubernetes:
@badnetmask@hachyderm.io replied  ·  activity timestamp 2 days ago

@rachel @mmeier
My Renovate does watch the repo, and does let me know about the updates, but nothing is applied without me cloning the repo to my laptop, and running a series of commands to do the actual updates.

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Code of Conduct