[00:20:14] The cache nodes in deployment-prep are failing to connect to the new acme-chief server, complaining about "unable to get local issuer certificate for CN=deployment-acme-chief07.deployment-prep.eqiad1.wikimedia.cloud". Is there something I should be doing on the puppetserver that I missed? [00:33:09] omfg I just had to restart acme-chief [00:33:19] acme-chief's nginx [08:11:46] yes all good re: dumps-nfs bliviero inflatador ! I have repooled dumps-nfs for clouddumps1002 so all clouddumps hosts are now active/active for all services [09:03:33] !log tools restart harbor in tools-harbor-2 with "docker compose restart" [09:03:36] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools/SAL [13:10:50] Trying to use the build service, but the last hours, all I get is "BuildClientError: The build service seems to be down – please retry in a few minutes." [13:11:23] On tools.mix-n-match if that makes a difference [13:11:57] I was finishing gathering data to fill in a bug on the exact same topic, 503 are piling up it seems [13:18:28] team is looking into it. there's already a phab ticket fwiw: https://phabricator.wikimedia.org/T436243 [13:20:19] a crap I didn't check again before filing it sorry I created a duplicate (and I don't think I can merge tickets or delete mine I apologize) [13:24:28] schiste: edit related tasks... > close as duplicate from the sidebar [13:25:44] Done! Thanks :) [13:35:03] build service seems to work again, thanks! [13:36:54] !log jeanfred@tools-bastion-15 tools.integraality Deploy ae8f642 (Unify local dev DB config in a single dev.env file) for T436062 [13:36:57] !log jeanfred@tools-bastion-15 tools.integraality Deploy d3bb817 (Add reset-db mise task to drop the database) for T436062 [13:36:57] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:36:59] !log jeanfred@tools-bastion-15 tools.integraality Deploy aed346c (Add connect-db mise task for an interactive local DB shell) for T436062 [13:37:00] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:37:01] !log jeanfred@tools-bastion-15 tools.integraality Deploy 46bbd63 (Use DictCursor for database connections) for T436062 [13:37:03] !log jeanfred@tools-bastion-15 tools.integraality Deploy 09ca78b (Switch database name to be public-readable) for T436062 [13:37:03] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:37:05] !log jeanfred@tools-bastion-15 tools.integraality Deploy 4c1328e (Provision tool database on ToolsDB using Ansible) for T436062 [13:37:05] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:37:07] !log jeanfred@tools-bastion-15 tools.integraality Deploy 6623a9b (Pin database charset to utf8mb4 in dev environment) for T436062 [13:37:08] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:37:11] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [13:37:13] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.integraality/SAL [19:33:46] !log lucaswerkmeister@tools-bastion-15 tools.ranker deployed 1bf418f5d8 (l10n updates: hu) [19:33:49] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.ranker/SAL [19:35:07] !log lucaswerkmeister@tools-bastion-15 tools.lexeme-forms deployed 04ffe29b8d (l10n updates: da, ha, he, ru) [actually deployed 7f46fc10fc, temporary T431146 branch rebased on top of that] [19:35:10] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.lexeme-forms/SAL [19:38:02] !log lucaswerkmeister@tools-bastion-15 tools.wd-image-positions deployed 42c2642f71 (l10n updates: pl) [19:38:03] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools.wd-image-positions/SAL [22:47:26] Hi, I'm prototyping a gadget on zh-wikisource using statically served webfonts files in https://tools-static.wmflabs.org/webfont-zh-static/ [22:47:27] Now, before I go too far, I want to quickly confirm that there are no concerns of using this serving infra in this way? [23:10:40] @PhV6OSm4va3IiJ: from the Toolforge side that is fine. It is a question for your users and your community on zhwikisource if side loading fonts from Toolforge is considered a security risk or not. There are groups within the WMF would would like to ban loading content from Toolforge or Cloud VPS via user scripts and gadgets based on their security analysis, but to date that has not happened. [23:24:10] I agree that the general third-party dependency concern is reasonable, but I think the risk profile is substantially different for this particular use case. [23:24:11] The dependency here is limited to static WOFF2 font files served from Toolforge. The files are publicly enumerable, the source and build process are publicly auditable, and the resource itself has no executable content or per-user behavior. The gadget does not load any JavaScript or dynamically generated content from Toolforge. [23:24:12] In particular, the Toolforge application itself has no way to inspect or react to individual users requesting these static files. I would therefore consider this closer to hosting a static asset than to depending on a third-party application or JavaScript CDN. [23:24:40] I agree that the remaining concern is the integrity of the hosting infrastructure and future modification of these files, which can be mitigated by using versioned/immutable asset paths and making the source/build process public. [23:34:02] My other issue is: is it possible to add a `Cache-Control` header in the tools-static.wmflabs.org/webfont-zh-static/ serving path? [23:41:36] no, there is no functionality for header additions in tools-static