Allow temporarily disabling replica eg for maintenance:
Set dns.disabled attribute to current timestamp
Make sure GoreDNS does not return those A, AAAA records anymore; including when querying the dns.san value
Update iptables rules so admin-prohibited is returned for new incoming VPN connections. Test that returned message makes client TCP/IP stack fall back to other nodes.
Kick clients connected to this replica's OpenVPN, IPSec endpoints. Possibly spread it over some time (10min?)
Allow temporarily disabling replica eg for maintenance:
* Set `dns.disabled` attribute to current timestamp
* Make sure GoreDNS does not return those A, AAAA records anymore; including when querying the `dns.san` value
* Update `iptables` rules so [admin-prohibited](https://wiki.nftables.org/wiki-nftables/index.php/Rejecting_traffic) is returned for *new* incoming VPN connections. Test that returned message makes client TCP/IP stack fall back to other nodes.
* [Kick clients](https://git.k-space.ee/pinecrypt/server/issues/2) connected to this replica's OpenVPN, IPSec endpoints. Possibly spread it over some time (10min?)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Allow temporarily disabling replica eg for maintenance:
dns.disabledattribute to current timestampdns.sanvalueiptablesrules so admin-prohibited is returned for new incoming VPN connections. Test that returned message makes client TCP/IP stack fall back to other nodes.