Update Ingress Allow Lists for gitlab.com
Summary
The allow lists for our HAProxy nodes may be out of date. There are concerns that blocking our own IPs during levels of high API activity could protect us, but it could also disable valid API use for users.
Related Incident(s)
Originating issue(s): https://gitlab.com/gitlab-com/gl-infra/production/-/issues/6587
Desired Outcome/Acceptance Criteria
Consolidate and refine the allow lists we have in place for HAProxy rate limiting. Also look at the Cloudflare rules to see if we need to update that as well.
Associated Services
Corrective Action Issue Checklist
-
Link the incident(s) this corrective action arose out of -
Give context for what problem this corrective action is trying to prevent from re-occurring -
Assign a severity label (this is the highest sev of related incidents, defaults to 'severity::4') -
Assign a priority (this will default to 'priority::4')