6 ms·
That isn't really how production networks work in my uneducated opinion. If they are connected to the production network then they are the production network, a
by sillybov3456 4y ago
That isn't really how production networks work in my uneducated opinion. If they are connected to the production network then they are the production network, and the level of isolation required to make that not the case would be so extreme as to make things potentially more unreliable.
Others can correct me if I'm wrong about this. All I know is that the production network where I work is not air gapped in the way that would be required to truthfully consider testing networks a non production environment, so non prod changes typically wind up in front of the change review board anyway.
Ask your own sites network engineers and see if they have similar constraints because I would be interested to hear more perspectives on that.
One other thing I will say is that the abstractions of "config plane" and "data plane" and "control plane" don't really exist on real physical systems. That is mostly an abstraction created for applications people, those systems are not going to be totally blocked from interacting with eachother, they kind of have to. So if any of your "planes" are shared with production it is a production environment.
- rkeene2 4y agoThat would mean that all networks which peer with the Internet would necessarily be considered Production. This isn't that reasonable outside certain niches (i.e., national government networks). Instead, what's commonly done is to provide a Controlled Interface (to borrow a term from those national government networks) that gates which things are at which level of trust. This is where security boundaries are enforced -- and if they are sound security boundaries things on either side can't reasonably damage the other side.
- sillybov3456 4y agoThat's super interesting, and you're definitely right about the internet thing. I suppose our network guys must have some way to see if a change will propagate beyond a particular interface?
- sangnoir 4y ago> One other thing I will say is that the abstractions of "config plane" and "data plane" and "control plane" don't really exist on real physical systems If you use any sort of virtualization: the control plane (infra) vs data plane (apps) will naturally evolve from the architecture. The config plane and control plane can get squashed into the same thing though, but it can also be disparate for at both infra- and application level.
- dekhn 4y agoData plane and control plane are definitely a thing in real physical systems- look at a classical router, where the packet processor works independently of, and is occasionally programmed by, or assisted by, a message passing from the data plane to the control plane. That control plane is typical elsewhere on the main board, talking to the data plane through a well-specific protocol. Google's network is complicated, making many assumptions about "what is prod" etc hard to reason about.