firewall blocking atomic01.qa access to RHN/registry.access.redhat.com

Colin Walters walters at verbum.org
Fri Apr 24 17:04:15 UTC 2015


On Fri, Apr 24, 2015, at 12:14 PM, Kevin Fenzi wrote:

> So, can you try and get those things via external? ie, instead of using
> an internal ip and trying to cross that great firewall, use external
> IPs and access like any other customer?

Ah I see, the DNS is shared right now.  I think I found this out before
but the knowledge cycled out of my brain.

So...what you're suggesting is basically change /etc/hosts on each
machine to have
209.132.182.63 registry.access.redhat.com
etc?

Oooh wait...there's a far simpler solution - just use a public nameserver
like 8.8.8.8 right?  I see some references to that in the current Ansible
playbooks.  

Indeed that works.  I'll get that into my Ansible code now.

> We could look at doing that if it's needed, sure. 

Medium term it'd certainly be nice if more of infrastructure starts to
rely on Docker.

But short term I can do this myself now on this one machine now
that I can reach the source.

Thanks for the reply!


More information about the infrastructure mailing list