[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #29863 [Obfuscation/Snowflake]: Add disk space monitoring for snowflake infrastructure



#29863: Add disk space monitoring for snowflake infrastructure
-----------------------------------+-----------------------------
 Reporter:  cohosh                 |          Owner:  (none)
     Type:  task                   |         Status:  merge_ready
 Priority:  Medium                 |      Milestone:
Component:  Obfuscation/Snowflake  |        Version:
 Severity:  Normal                 |     Resolution:
 Keywords:  snowflake              |  Actual Points:
Parent ID:  #30152                 |         Points:
 Reviewer:                         |        Sponsor:  Sponsor19
-----------------------------------+-----------------------------

Comment (by anarcat):

 I confirm that `/etc/default/prometheus-node-exporter` is the right place
 and sufficient for configuration. I can also confirm there are firewall
 rules on nodes we configure at TPO, but I believe you'll have to set that
 up yourself on snowflake, as it's not managed by us.

 As I previously mentioned, I believe we'll need to setup a new machine for
 this. It would be great if someone from the anti-censorship team could get
 budget approval to get VM from Hetzner like we did for the other
 prometheus server. I tried to document the requirements for such a machine
 in #29388 and we ended up picking a `CX21` instance (5€/mth, 2vCPU, 4GB
 RAM, 40GB disk, 20TB traffic) in #29389.

 Once budget is approved, I can take it from there and setup the machine,
 install prometheus/grafana and give you the keys (more or less). :)
 Specifically, I think it would be fair to give anti-censorship folks admin
 access to the Grafana instance so you can build your own graphs, create
 user accounts and so on. It would also be necessary to decide how that
 authentication be done  on the Grafana instance (semi-public with the
 easy-to-guess password or real accounts just for that instance or LDAP).

 How does that sound?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29863#comment:25>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs