bcgov / bcgov/cloud-pathfinder
Pattern for clean AMI image based upgrading of firewall manager, upgrade LZ0
- Dominant language
- Jinja
- Stars
- 2
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
**Describe the issue**
CheckPoint has announced a new version of the Firewall manager. We want to upgrade but we don't like the "reuse the existing VM and click upgrade in the UI" approach. We prefer to IaC the upgrade and roll out a fresh AMI VM. The issue is we need to figure this out.
**Additional context**
- Ensure that the configuration is not lost
- The AMIs are configured by the SEA, although we may want to consider terraform
**Definition of done**
- Talk to Ryan Jaeger and see if there was any consideration for AMI upgrades. We will likely need to provide feedback upstream.
- Back up the firewall and firewall manager configurations, for reapplication on the new instances (include policies in the backup)
- Update the SEA config, re-run the state machine
- Create a pattern for re-running some automation to get a fresh updated VM AMI firewall manager appliance
- Consider this pattern for the firewalls too, and think forward to how this could affect policies updates that we have consumed from secops (we don't want to lose them)
- Use AWS ECF Dev for developing this pattern
- Upgrade the Check Point Firewall Manager in LZ0
- Document the pattern in private cloudops-internal in markdown and review with Carles
- Look at linked ticket, create extra well formed tickets if needed
- Timebox to a 3
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the SEA configuration and existing state-machine automation in AWS ECF Dev, then consult the linked ticket and discuss AMI upgrades with Ryan Jaeger. Done means configurations and policies are backed up, a fresh Check Point Firewall Manager AMI pattern is defined and tested, LZ0 is upgraded, and the pattern is documented in cloudops-internal markdown for review.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, markdown, terraform
- Domain
- cloud, documentation, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100