OVS agent firewall is not configurable

Bug #1618507 reported by Brent Eagles
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
Fix Released
Medium
Brent Eagles

Bug Description

New firewall support was added to the neutron OVS agent that does not rely on interposing a linux bridge between VIFs and the integration, reducing the number of "hops" we introduce into the network path. While the puppet modules support configuring the agent's firewall driver, we are missing the option in the TripleO heat templates.

Changed in tripleo:
assignee: nobody → Brent Eagles (beagles)
status: New → In Progress
Brent Eagles (beagles)
Changed in tripleo:
status: In Progress → Confirmed
status: Confirmed → In Progress
importance: Undecided → Medium
milestone: none → newton-rc1
Revision history for this message
Steven Hardy (shardy) wrote :

Any patch planned for RC1?

If not I'll probably defer this to ocata-1 as it sounds like folks can work around it via ExtraConfig overrides?

Revision history for this message
Brent Eagles (beagles) wrote :

Sorry, forgot to add link for patch!

https://review.openstack.org/#/c/357556/

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-heat-templates (master)

Reviewed: https://review.openstack.org/357556
Committed: https://git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/?id=866ed11712d8e2e7d664abf1b0b572e2c240357c
Submitter: Jenkins
Branch: master

commit 866ed11712d8e2e7d664abf1b0b572e2c240357c
Author: Brent Eagles <email address hidden>
Date: Thu Aug 18 19:03:30 2016 -0230

    Add support for configuring the OVS firewall driver

    This patch introduces a parameter to allow customizing the Neutron
    OpenvSwitch agent's firewall driver configuration.

    Closes-Bug: 1618507
    Change-Id: I595c392f7a1afe2164bf562224d9eda9b3dfa982

Changed in tripleo:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.