Currently RU orchestration during upgrade/downgrade kills ZKFC on the active NameNode to initiate a failover to standby. We should instead use the failover command.
Where nn1 is the current namenode if it if the active one, and nn2 is the remaining namenode.
This is safer than killing zkfc on the active namenode because this command first tries to gracefully transition a NameNode to the Standby state. If this fails, the fencing methods (as configured by dfs.ha.fencing.methods) will be attempted until one succeeds. After this process the second NameNode will be transitioned to the Active state.
It reduces long waits between ZKFC kill, failure kicking-in after a timeout, and then NN becoming active.