ministryofjustice / analytics-platform

Parent repository for the MOJ Analytics Platform
MIT License
14 stars 1 forks source link

Can't access apps from DOM1 when whitelisted for DOM1 #79

Closed davidread closed 5 years ago

davidread commented 5 years ago

What happened?

on Friday we noticed that DOM1 whitelisted apps no longer work

e.g.:

Same for 2 different users. Same for Chrome and Firefox.

Discussion

It's been suggested that:

(i.e. DOM1 IP address ranges have changed)

The IP address that HS and BF mentioned on Friday are all 194.33.19x.xxx, which is in the same range I've seen for DOM1 since I started collecting empirical data in the summer, and I used for the 2FA Auth0 work. However this doesn't match the IP ranges that concourse allows to access apps: concourse-org-pipeline.yaml, which I think is just wrong. So we can fix that, but I'm surprised this wasn't noticed as a problem earlier.

davidread commented 5 years ago

It's this file with the ip addresses use by apps: chart-env-config/alpha/concourse-org-pipeline.yaml

davidread commented 5 years ago

Consensus is that this is not the long-standing issue I thought, but was indeed working until it broke on Friday.

BF said today:

I can access the pq tool this morning, so looks like the whitelist issue may be fixed.

RL replied:

It looks like ATOS made emergency changes to the network following an outage, and have now restored usual service

So it looks like this was due to networking.