I'm gonna be a bit lazy and copy-paste some irc context:
seems we also need to update ferm rules, can't access relforge from an-airflow1001 or stat1007.
typical operations ... would be for airflow to run something in the hadoop cluster, and that thing would talk to relfroge
We use https://wikitech.wikimedia.org/wiki/Homer to manage our networking configuration. There is a repo for the software itself, a public repo, a private repo (like the puppet private one), a public mock of the private repo, and data in netbox that gets automatically pulled in to generate the junos configuration.
Thus using the above context:
What to do
- Patch public homer repo: https://gerrit.wikimedia.org/r/c/operations/homer/public/+/663054
AC
- relforge100[3,4] can be reached from an-airflow1001 or stat1007 and hadoop workers (figure out if there's other hosts we should check reachability from as well)