Skip to content
Snippets Groups Projects
Commit 6fb47e21 authored by Michal Nasiadka's avatar Michal Nasiadka Committed by Pierre Riteau
Browse files

Add internal VIP address to no_proxy

Change-Id: I7a9aa9abf611cdaa47cc91f40a6753f23a7f187e
Closes-Bug: #2087556
parent 2d7ce453
No related branches found
No related tags found
No related merge requests found
......@@ -19,3 +19,4 @@ no_proxy:
- "127.0.0.1"
- "localhost"
- "{{ ('http://' ~ docker_registry) | urlsplit('hostname') if docker_registry else '' }}"
- "{{ kolla_internal_vip_address }}"
......@@ -12,8 +12,9 @@
# List of domains, hostnames, IP addresses and networks for which no proxy is
# used. Defaults to ["127.0.0.1", "localhost", "{{ ('http://' ~
# docker_registry) | urlsplit('hostname') }}"] if docker_registry is set, or
# ["127.0.0.1", "localhost"] otherwise. This is configured only if either
# docker_registry) | urlsplit('hostname') }}","{{ kolla_internal_vip_address
# }}"] if docker_registry is set, or ["127.0.0.1", "localhost","{{
# kolla_internal_vip_address }}"] otherwise. This is configured only if either
# http_proxy or https_proxy is set.
#no_proxy:
......
---
features:
- |
Adds the internal VIP to the NOPROXY/noproxy environment variables.
security:
- |
When running API requests from a host configured with kayobe, traffic
destined for the internal VIP is sent via the default proxy. This can be a
security issue if not using TLS as the proxy will be able to intercept the
traffic. If using an untrusted proxy, with TLS disabled on the internal
VIP, it is recommended that you run ``kayobe overcloud host configure -t
proxy``, ``kayobe seed hypervisor host configure -t proxy``, ``kayobe seed
host configure -t proxy``, and ``kayobe infra vm host configure -t proxy``,
to add the internal VIP to the no proxy configuration. This is considered a
minor issue as traffic between containers will not use the proxy by
default.
`LP#2087556 <https://launchpad.net/bugs/2087556>`__
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment