The firewall was going into the colocation facility that night.

I sent a three-part plan before starting. Install the firewall and connect the external router. Build the internal network for two new Linux Virtual Server machines. Rebuild the load-balanced services without moving any production hosts yet.

The existing switches could keep the two sides of the network separate for now. It was not the finished design, but it was enough to create a WAN side and a LAN side until better switching and VLAN support arrived.

The new load balancers would sit behind the firewall on their own internal network. Once that path worked, each production service could move separately. Create the mapping on the firewall, remove the service from the old load balancer, change the backend addresses, test it, then move to the next one.

There would be downtime, but it should be brief and limited to one service at a time.

This was side work after the Beatport day. The plan was not a formal migration document. It was an email that began, “Here is a brief plan for what I am going to do tonight.”

The email gives the order and the expected interruption. It also makes clear what will not happen tonight: no production hosts move during the first stage.

If the firewall and internal network are ready, the virtual load balancers can be built behind them. The production services can then be scheduled separately. Each one gets its own mapping, backend change, test, and short outage rather than sharing one large cutover.

That is tonight's plan. Firewall first. Internal network second. Replacement load-balancing services third. Production stays where it is until those pieces are ready and the individual cutovers have been scheduled.

Archive