Updating the security group rules does not reflected in the applicable running instances
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
New
|
Undecided
|
Unassigned |
Bug Description
Hi,
Open Stack Version : Kilo
Problem :
========
A instance has been created with the security group- Sample_Group and it's running as per the rules in the security group. While modify/updating the rules in the group doesn't reflected in the running instances.
Query :
======
Is it possible to update/modify the security rule for running instance without adding any new group to that instance?
Step/Terminal Output :
=======
[root@centos7-
+------
| IP Protocol | From Port | To Port | IP Range | Source Group |
+------
| tcp | 22 | 22 | 203.0.113.0/24 | |
| icmp | -1 | -1 | 203.0.113.0/24 | |
+------
[root@centos7-
+------
| Property | Value |
+------
| OS-DCF:diskConfig | MANUAL |
| OS-EXT-
| OS-EXT-
| OS-EXT-
| OS-EXT-
| OS-EXT-
| OS-EXT-
| OS-EXT-STS:vm_state | building |
| OS-SRV-
| OS-SRV-
| accessIPv4 | |
| accessIPv6 | |
| adminPass | fmHZXR638udt |
| config_drive | |
| created | 2015-09-
| flavor | m1.tiny (1) |
| hostId | |
| id | 92623f86-
| image | cirros-0.3.4-x86_64 (44fc5cb7-
| key_name | demo-key |
| metadata | {} |
| name | demo-instance3 |
| os-extended-
| progress | 0 |
| security_groups | Sample_Group |
| status | BUILD |
| tenant_id | e91aeb7cdcf1410
| updated | 2015-09-
| user_id | 6ea371c469ee41b
+------
[root@centos7-
+------
| ID | Name | Status | Task State | Power State | Networks |
+------
| 080c3068-
| 92623f86-
+------
[root@centos7-
PING 203.0.113.27 (203.0.113.27) 56(84) bytes of data.
64 bytes from 203.0.113.27: icmp_seq=1 ttl=64 time=4.56 ms
64 bytes from 203.0.113.27: icmp_seq=2 ttl=64 time=0.757 ms
64 bytes from 203.0.113.27: icmp_seq=3 ttl=64 time=0.728 ms
[root@centos7-
+------
| IP Protocol | From Port | To Port | IP Range | Source Group |
+------
| icmp | -1 | -1 | 203.0.113.0/24 | |
+------
[root@centos7-
+------
| IP Protocol | From Port | To Port | IP Range | Source Group |
+------
| tcp | 22 | 22 | 203.0.113.0/24 | |
+------
[root@centos7-
PING 203.0.113.27 (203.0.113.27) 56(84) bytes of data.
64 bytes from 203.0.113.27: icmp_seq=1 ttl=64 time=2.35 ms
64 bytes from 203.0.113.27: icmp_seq=2 ttl=64 time=0.995 ms
64 bytes from 203.0.113.27: icmp_seq=3 ttl=64 time=0.683 ms
64 bytes from 203.0.113.27: icmp_seq=4 ttl=64 time=0.588 ms
64 bytes from 203.0.113.27: icmp_seq=5 ttl=64 time=0.614 ms
Regards
Jeya Murugan B
tags: | added: network security-groups |