Re: [tor-bugs] #19909 [Applications/Tor Browser]: Think about switching to Balrog for our server side Tor Browser update components

2020-01-08 Thread Tor Bug Tracker & Wiki
#19909: Think about switching to Balrog for our server side Tor Browser update
components
--+--
 Reporter:  gk|  Owner:  tbb-team
 Type:  task  | Status:  new
 Priority:  Medium|  Milestone:
Component:  Applications/Tor Browser  |Version:
 Severity:  Normal| Resolution:
 Keywords:|  Actual Points:
Parent ID:| Points:
 Reviewer:|Sponsor:
--+--

Comment (by gk):

 Balrog has capbability for throttling updates, which is interesting for
 moving to a regular release channel. Background: https://hearsum.ca/blog
 /streamlining-throttled-rollout-of-firefox-releases.html. Bug:
 https://bugzilla.mozilla.org/show_bug.cgi?id=1246675.

 Additionally, there might be ways to harden our update infrastructure
 against at least some attacks by having multiple sign-off requirements for
 update pushes. Background: https://hearsum.ca/blog/rings-of-power-
 multiple-signoff-in-balrog.html. Bug:
 https://bugzilla.mozilla.org/show_bug.cgi?id=1278974.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19909 [Applications/Tor Browser]: Think about switching to Balrog for our server side Tor Browser update components

2019-11-11 Thread Tor Bug Tracker & Wiki
#19909: Think about switching to Balrog for our server side Tor Browser update
components
--+--
 Reporter:  gk|  Owner:  tbb-team
 Type:  task  | Status:  new
 Priority:  Medium|  Milestone:
Component:  Applications/Tor Browser  |Version:
 Severity:  Normal| Resolution:
 Keywords:|  Actual Points:
Parent ID:| Points:
 Reviewer:|Sponsor:
--+--
Description changed by gk:

Old description:

> While discussing #19890 with Mozilla engineers we came across the topic
> on how we handle our server-sde update part. It turns out that they
> basically did back then what we are doing now. They recommended to look
> at Balrog once we believe our needs do not scale anymore/or the system
> feels like being messed up etc. See: http://wiki.mozilla.org/Balrog for
> details.

New description:

 While discussing #19890 with Mozilla engineers we came across the topic on
 how we handle our server-side update part. It turns out that they
 basically did back then what we are doing now. They recommended to look at
 Balrog once we believe our needs do not scale anymore/or the system feels
 like being messed up etc. See: http://wiki.mozilla.org/Balrog for details.

--

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs