bcgov / bcgov/cloud-pathfinder

Pattern for clean AMI image based upgrading of firewall manager, upgrade LZ0

Open
#1,893 1 comment 0 reactions 0 assignees View on GitHub
CSP: AWS ECF Forge Technical Debt Technology
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the issue**
CheckPoint has announced a new version of the Firewall manager. We want to upgrade but we don't like the "reuse the existing VM and click upgrade in the UI" approach. We prefer to IaC the upgrade and roll out a fresh AMI VM. The issue is we need to figure this out.

**Additional context**
- Ensure that the configuration is not lost
- The AMIs are configured by the SEA, although we may want to consider terraform

**Definition of done**
- Talk to Ryan Jaeger and see if there was any consideration for AMI upgrades. We will likely need to provide feedback upstream.
- Back up the firewall and firewall manager configurations, for reapplication on the new instances (include policies in the backup)
- Update the SEA config, re-run the state machine
- Create a pattern for re-running some automation to get a fresh updated VM AMI firewall manager appliance
- Consider this pattern for the firewalls too, and think forward to how this could affect policies updates that we have consumed from secops (we don't want to lose them)
- Use AWS ECF Dev for developing this pattern
- Upgrade the Check Point Firewall Manager in LZ0
- Document the pattern in private cloudops-internal in markdown and review with Carles
- Look at linked ticket, create extra well formed tickets if needed
- Timebox to a 3

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the SEA configuration and existing state-machine automation in AWS ECF Dev, then consult the linked ticket and discuss AMI upgrades with Ryan Jaeger. Done means configurations and policies are backed up, a fresh Check Point Firewall Manager AMI pattern is defined and tested, LZ0 is upgraded, and the pattern is documented in cloudops-internal markdown for review.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, markdown, terraform
Domain
cloud, documentation, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.