Closed Bug 784521 Opened 12 years ago Closed 12 years ago

Allow 10.130.0.0/16 talking to aus3-staging.mozilla.org:22

Categories

(Infrastructure & Operations Graveyard :: NetOps: DC ACL Request, task, P1)

x86_64
Linux

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: rail, Assigned: cransom)

References

Details

We need to upload update snippets from ec2 slaves (10.130.0.0/16) to aus3-staging.mozilla.org using scp.

$ host aus3-staging.mozilla.org 
aus3-staging.mozilla.org is an alias for dp-ausstage01.phx.mozilla.com.
dp-ausstage01.phx.mozilla.com has address 10.8.74.30

Could you add add 10.130.0.0/16 to netflows, pleasw?
Blocks: 783518
I'll note this netflow block is unfortunately causing Android Native nightlies on m-c to fail to update. And report as broken to the tree.

(was busted for the weekend and yesterday for other reasons, and wasn't until now that we realized we needed seperate netflows setup for this)
Priority: -- → P1
impacting production builds, hence raising to blocker.
Severity: major → blocker
(In reply to John O'Duinn [:joduinn] from comment #2)
> impacting production builds, hence raising to blocker.

Just to bring the point home, this is resulting in inadequate test coverage on Android nightly builds and the next uplift is only 6 days away.
(In reply to Bill Gianopoulos [:WG9s] from comment #3)
> (In reply to John O'Duinn [:joduinn] from comment #2)
> > impacting production builds, hence raising to blocker.
> 
> Just to bring the point home, this is resulting in inadequate test coverage
> on Android nightly builds and the next uplift is only 6 days away.

I should point out that I was not referring to the automated tests here (although they don't run on these builds either).  What I was referring to is a large drop in the number of Nightly testers who are running recent builds because they do not show and update as available when you click check for updates.
This is an ACL request for netops, moving this to the ACL queue where it belongs and ccing joes in case this needs a security review.
Assignee: server-ops-releng → network-operations
Component: Server Operations: RelEng → Server Operations: ACL Request
QA Contact: arich → ravi
Taking this bug while escalating within netops
Assignee: network-operations → ashish
Assignee: ashish → cransom
I'm unfamiliar with the AWS setup but I've added 10.130 access to dp-ausstage01. Please verify and re-open if non-functional.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
It seems you need it for operational reasons, so we are not blocking on it for now. We might have some concerns in the future - mainly, we're opening up a flow from a whole subnet, instead of some specific hosts.
I can ssh from AWS based builders to aus3-staging.mozilla.org now. Thanks a lot!
Status: RESOLVED → VERIFIED
Product: mozilla.org → Infrastructure & Operations
Product: Infrastructure & Operations → Infrastructure & Operations Graveyard
You need to log in before you can comment on or make changes to this bug.