Skip to content

FAQ: add standby allowlist IPs, drop rows that have no static IP - #456

Merged
lcbill merged 1 commit into
masterfrom
bt-standby-allowlist-ips
Sep 28, 2026
Merged

lcbill merged 1 commit into
masterfrom
bt-standby-allowlist-ips

Conversation

@lcbill

@lcbill lcbill commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Why

Every published allow-list endpoint (.lc, .edr, .wss, .ingest in each of the six regions) now has a second static IP reserved for it (refractionPOINT/tracking#4710). Customers allow both addresses; later infrastructure changes on our side then never require another allow-list update.

The standby addresses are not serving yet — they're reserved and dark until after the customer adoption window (activation planned 2026-10-28). The page says so.

Changes to docs/8-reference/faq/sensor-installation.md

  • New Standby IP column on every regional table, filled for .lc, .edr, .wss, .ingest (24 pairs). Australia's Replay/Webhooks rows keep their single IP (— in the new column).
  • Intro paragraph telling customers to allow both addresses and why.
  • Removed rows that were never correct:
    • Replay/Webhooks in Canada, US, India, UK, Europe listed 142.250.115.121 — a Google front-end address, not a LimaCharlie IP (those hostnames are Cloud Run domain mappings with no static IP).
    • Live feed (.live) in all regions — no client uses it (verified from load-balancer logs).

Source of truth for the addresses: SREScripts/issues/2026-09-23T06-55-standby-allowlist-ips/standby-ips.md (also mirrored on the Notion "Public IPs" page).

Test plan

  • Every remaining IP in the tables matches gcloud compute addresses list in its project (A) / the reserved -b address (B)
  • No 142.250.115.121 or .live rows remain
  • Docs preview renders the 4-column tables
  • Merge timed with the customer notice

Every published endpoint (.lc, .edr, .wss, .ingest in each region) now has
a second, standby IP reserved for it. Customers should allow both so future
infrastructure changes on our side never require another allow-list update.
The standby addresses are not serving yet; they enter service after
2026-10-28.

Also removes rows that were never correct: the Replay/Webhook entries for
the non-Australia regions listed a Google front-end address rather than a
LimaCharlie IP (those hostnames have no static IP), and the Live feed rows
described an endpoint no client uses.

Refs refractionPOINT/tracking#4710
@lcbill
lcbill requested a review from maximelb September 28, 2026 16:58
@lcbill
lcbill merged commit a9abfd1 into master Sep 28, 2026
7 checks passed
@lcbill
lcbill deleted the bt-standby-allowlist-ips branch September 28, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants