Cloudflare: Migrate GitLab.com (Phase 2)

  1. Once traffic is ensured to flow though Cloudflare, we initiate decommission of Route53.
    • We would disable the transfer lock and generate an auth code.
    • immediately after, we move the domain over to the Cloudflare registry
    • Next we enable DNSSEC within Cloudflare.
  2. Now we have reached the target infrastructure described in the diagrams in the readiness review.
  3. Lock down, to re gain a defined path for rate limiting.
    • While not having one of these in place we are reachable via our origin IPs and rate-limiting will be disabled there.
    • Cut off the old GCP LBs after we monitored, that traffic shifted to Cloudflare completely.
    • IP whitelist Cloudflare and reject everything else.
      • This might not be an option, due to the GCP LB facing the internet
    • Enable Authenticated Origin Pulls.

~"workflow::Blocked" because of phase 1

Edited by Hendrik Meyer (xLabber)