Skip to content

Wpb 23988 fix internet access wiab stag#881

Merged
mohitrajain merged 16 commits intofix-wiab-stag-feedbackfrom
wpb-23988-fix-internet-access-wiab-stag
Apr 2, 2026
Merged

Wpb 23988 fix internet access wiab stag#881
mohitrajain merged 16 commits intofix-wiab-stag-feedbackfrom
wpb-23988-fix-internet-access-wiab-stag

Conversation

@mohitrajain
Copy link
Copy Markdown
Contributor

@mohitrajain mohitrajain commented Mar 17, 2026

Change type

  • Fix
  • Feature
  • Documentation
  • Security / Upgrade

Basic information

  • THIS CHANGE REQUIRES A DEPLOYMENT PACKAGE RELEASE
  • THIS CHANGE REQUIRES A WIRE-DOCS RELEASE

Testing

  • I ran/applied the changes myself, in a test environment.
  • The CI job attached to this repo will test it for me.

Offline Build CI (label-based)

Add one or more labels to trigger offline builds:

  • build-default - Full production build (ansible, terraform, all packages)
  • build-demo - Demo/WIAB build
  • build-wiab-staging - WIAB-staging build
  • build-min - Minimal build (fastest, essential charts only)
  • build-all - Run all three builds

Note: No builds run by default. Add a label to trigger CI.

Tracking

  • I added a new entry in an appropriate subdirectory of changelog.d
  • I mentioned this PR in Jira, OR I mentioned the Jira ticket in this PR.
  • I mentioned this PR in one of the issues attached to one of our repositories.

Knowledge Transfer

  • An Asciinema session is attached to the Jira ticket.

Motivation

Objective

Reason

Use case

@mohitrajain mohitrajain requested review from a team and julialongtin as code owners March 17, 2026 15:48
@mohitrajain mohitrajain changed the base branch from master to wpb-23988-enable-5.25 March 17, 2026 15:48

If you observe HTTP-01 challenge timeouts or self-check failures in a NAT/bridge environment, hairpin SNAT and relaxed reverse-path filtering handling may be required. One possible approach is:

> **Note:** All `nft` and `sysctl` commands should run on the adminhost.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this should not be a note, it should be an instruction: run these commands to...

Base automatically changed from wpb-23988-enable-5.25 to fix-wiab-stag-feedback March 24, 2026 13:26
@mohitrajain mohitrajain force-pushed the wpb-23988-fix-internet-access-wiab-stag branch from 5fe8c25 to d6ff314 Compare March 24, 2026 15:41
@mohitrajain mohitrajain requested a review from Copilot March 26, 2026 12:51

This comment was marked as off-topic.

>
> ```bash
> # Host WAN interface name
> INF_WAN=enp41s0
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

.. This interface name will change.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes, this is suggestive in nature that a user has to mention the interface name

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I do not see anything suggesting it, however. do so.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

let me make an explicit note for this

@mohitrajain mohitrajain force-pushed the fix-wiab-stag-feedback branch from 48a7792 to c51ad4c Compare March 27, 2026 17:06
@mohitrajain mohitrajain force-pushed the wpb-23988-fix-internet-access-wiab-stag branch from 926eaa8 to b56f8b2 Compare March 27, 2026 17:12
>
> ```bash
> # Host WAN interface name
> INF_WAN=enp41s0
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I do not see anything suggesting it, however. do so.

* fix: wpb-23988 update the wiab-staging.md to improve documentation around running commands

* fix: wpb-23988 stop deploying smallstep by default in wiab-staging and wiab-dev

* fix: wpb-23988 changelog

* fix wpb-23988: replace demo-smtp with smtp

* fix wpb-23988: push action on master branch only

* fix wpb-23988: update documentation based on wire-docs pr101
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 2, 2026

@mohitrajain mohitrajain merged commit 7e43c4c into fix-wiab-stag-feedback Apr 2, 2026
15 checks passed
@mohitrajain mohitrajain deleted the wpb-23988-fix-internet-access-wiab-stag branch April 2, 2026 14:18
mohitrajain added a commit that referenced this pull request Apr 2, 2026
* Fixed: debug_logs.sh to log only the pods for default and cert-manager-ns namespace and limit log lines

* fix: rebase master

* Rebase master

* Fixed: documentation for wiab-staging.md based on a user feedback

* Fixed: sftd helm chart values for joinCall component which fails to find hashbased images

* fix: update bash scripts for issues highlighted by linting and update the wiab-staging artifact hash

* patched documentation further

* updated artifact hash post fixing issues shown by linter

* fix: helm-operations.sh for sonarcloud exceptions and update wiab-staging based on review

* fix: update sync_pg_secrets function to also update .background-worker

* Wpb 23988 enable 5.25 (#879)

* fix: wpb-23988 sync offline-secrets and prod-secrets.example.yaml and add comments

* fix: wpb-23988 enable postgresql secret for background-worker inwiab-dev

* fix: wpb-23988 sync wire-server helm chart values for wiab-dev from prod values

* fix: wpb-23988 sync wire-server helm chart secrets for wiab-dev from prod values for 5.25

* fix: wpb-23988 add a changelog file

* fix: wpb-23988 fix the changelog verification workflow to consider the non-master branches as well

* fix: wpb-23988 remove the changelog trigger for every push operation

* fix: wpb-23988 comment out empty mls secrets for wiab-dev

* fix: wpb-23988 update wiab-stag artifact hash

* fix: wpb-22988 fix minio service name

* Update values/wire-server/demo-values.example.yaml

Co-authored-by: Sukanta <amisukanta02@gmail.com>

---------

Co-authored-by: Sukanta <amisukanta02@gmail.com>

* Update offline/wiab-staging.md

Co-authored-by: Julia Longtin <julia.longtin@wire.com>

* Wpb 23988 fix internet access wiab stag (#881)

* fix: wpb-23988 sync wire-server helm chart values for wiab-dev from prod values

* fix: wpb-23988 fix the changelog verification workflow to consider the non-master branches as well

* fix: wpb-23988 remove the changelog trigger for every push operation

* add: wpb-23988 variable private_deployment with default true to disable SNAT on adminhost

* fix: wpb-23988 cert_master_email env var

* fix: wpb-23988 running wiab-staging-nftables.yaml playbook is explicit

* fix: wpb-23988 wiab-staging.md documentation to add details about default SNAT access being denied and how to enable it

* fix: wpb-23988 add changelog

* fix: wpb-23988 update the wiab-staging.md to improve documentation around running commands

* fix: wpb-23988 update the artifact hash

* Apply suggestions from code review

Co-authored-by: Julia Longtin <julia.longtin@gmail.com>

* fix: wpb-24291 update the documentation for wiab-staging

* fix wpb-24291: fix the minio endpoint for s3 endpoint

* fix wpb-23988: fix the logic in wiab_server_nftables.conf.j2 and update the inventory comment

* fix wpb-23988: upgrade documentation and small fixes for inventory

* Wpb 23988 disable smallstep (#882)

* fix: wpb-23988 update the wiab-staging.md to improve documentation around running commands

* fix: wpb-23988 stop deploying smallstep by default in wiab-staging and wiab-dev

* fix: wpb-23988 changelog

* fix wpb-23988: replace demo-smtp with smtp

* fix wpb-23988: push action on master branch only

* fix wpb-23988: update documentation based on wire-docs pr101

---------

Co-authored-by: Julia Longtin <julia.longtin@gmail.com>

---------

Co-authored-by: Sukanta <amisukanta02@gmail.com>
Co-authored-by: Julia Longtin <julia.longtin@wire.com>
Co-authored-by: Julia Longtin <julia.longtin@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants