[10:34:40] hihi, is https://en.wikipedia.beta.wmcloud.org down for everyone or just me :) [10:36:07] (just saw the alerts firing in -releng, not just me) [10:37:22] TheresNoTime: broken for me as well [16:19:53] Quick Q, any ETA on the approval of rejection for the quota request in T437273? Bullseye deprecation deployment-prep is blocked now, until the # of server groups is raised [16:19:53] T437273: Regression: CentralAuth doesn't support Read-Only mode any more - https://phabricator.wikimedia.org/T437273 [16:20:35] Err, I meant T437117 ... [16:20:36] T437117: Quota increase request for project deployment-prep - https://phabricator.wikimedia.org/T437117 [16:27:12] Southparkfan: it was approved, just waiting for the clinic duty to pick it up I guess, they should take tops a week (we discuss them in the weekly team meeting) [17:34:48] dcaro: alright, thank you! Looking forward to the increase :-) [18:33:20] !log dumps shutting down dumps-10 as there is no response on T435767 [18:33:24] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Dumps/SAL [18:33:24] T435767: Migrate dumps away from Debian Bullseye to Bookworm/Trixie - https://phabricator.wikimedia.org/T435767 [18:49:07] !log admin restarting haproxy on proxy-5.project-proxy due to port exhausting. This will likely happen again in a couple hours. [18:49:15] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Admin/SAL [19:03:51] musikanimal: are you involved in the wikisource project? It's getting a zillion connections right now and I'm trying to get some visibility into what's happening. [19:05:12] andrewbogott: not anymore. Which tool? If it's WS Export, I suspect it's a XTools-esque bot attack (this happens to all tools that are linked to from the wiki) [19:05:35] yep, wsexport [19:05:59] by 'xtools-esque' do you mean the attacker is xtools-esque, or that the attack is similar to attacks that xtools has faced? [19:07:15] ohhhh, is that why xtools gets scraped so much (I didn’t know about the “linked from the wiki” bit before, or rather didn’t make that connection) [19:07:24] the latter. I even pinged Samwilson in https://phabricator.wikimedia.org/T430876 as I thought the mitigation strategies we used there could apply to WS-Export, too [19:09:04] there's likely two things that would help immediately: (1) upgrade Anubis and (2) employ use of mod_proxy_cgi so that Apache doesn't get flooded with requests https://phabricator.wikimedia.org/T430888#12080489 [19:09:34] this is a routine, "normal" problem for WS-Export https://stats.uptimerobot.com/BN16RUOP5/782558466 [19:09:40] does xtools use the standard cloud-vps proxy, or does it have a floating IP? [19:09:56] At the moment my main concern is the proxy getting dos'd [19:10:39] I highly doubt it's a real attack, just bots gone wild [19:10:45] XTools uses the standard proxy [19:11:43] ok. That makes me think the new proxy code is more vulnerable to this [19:12:05] I guess when I say 'attack' I'm not assuming malice; the result is the same from malice or incompetence :) [19:12:27] yup, exactly [19:12:46] I think the Anubis upgrade was the main thing that did the trick for XTools [19:13:56] Do you know who is still active in wikisource? [19:15:27] Samwilson is the one to talk to, he's surely asleep at the moment. He usually starts his day sometime after 00:00 UTC [19:18:17] ok, ty [19:18:57] Would it ruin the world if I just closed down that proxy for the moment? [19:19:33] no, it goes down a lot, lol [19:20:31] it is quite important to the Wikisource community so hopefully it gets resolved sooner than later, but folks are used to it being down from time to time [19:25:36] !log wikisource stopping apache2 on wsexport-main01.wikisource.eqiad1.wikimedia.cloud [19:25:38] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Wikisource/SAL [19:31:17] musikanimal: can you spare a few more minutes to properly tag T437349 and also add links and/or responses about your mitigation thoughts? [19:31:17] T437349: wsexport traffic issues - https://phabricator.wikimedia.org/T437349 [19:31:30] sure thing! [19:31:43] thank you! [19:35:48] !log deployment-prep set profile::mediawiki::httpd::enable_forensic_log to false, to avoid disk exhaustion during high-traffic load [19:35:51] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Deployment-prep/SAL [19:36:27] !log deployment-prep truncate Apache2 forensic log on deployment-mediawiki14, disk almost full [19:36:29] Logged the message at https://wikitech.wikimedia.org/wiki/Nova_Resource:Deployment-prep/SAL