-
- Downloads
Configure bifrost to use firewalld trusted zone
Without this setting, bifrost creates a bifrost firewalld zone only allowing network traffic for Ironic services and assigns the provisioning network interface to it, potentially causing loss of connectivity. Using the public zone is suggested as a workaround [1] but is not sufficient: it allows SSH traffic, but blocks other services deployed on the seed, such as Docker registry traffic. [1] https://review.opendev.org/#/c/754406/ Change-Id: I80f9d95f02e11fda5916f9a9dd257b688a9db7e2 Story: 2008153 Task: 40899
Showing
- ansible/group_vars/all/bifrost 4 additions, 0 deletionsansible/group_vars/all/bifrost
- ansible/roles/kolla-bifrost/templates/bifrost.yml.j2 3 additions, 0 deletionsansible/roles/kolla-bifrost/templates/bifrost.yml.j2
- etc/kayobe/bifrost.yml 4 additions, 0 deletionsetc/kayobe/bifrost.yml
- releasenotes/notes/bifrost-firewalld-zone-09a29651a058531a.yaml 16 additions, 0 deletions...enotes/notes/bifrost-firewalld-zone-09a29651a058531a.yaml
Please register or sign in to comment