[k8s-R5.0.1]: k8s cluster name should be appended over the contrail firewall policy
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
Juniper Openstack | Status tracked in Trunk | |||||
R5.0 |
Fix Committed
|
High
|
Dinesh Bakiaraj | |||
Trunk |
Fix Committed
|
High
|
Dinesh Bakiaraj |
Bug Description
ocata-master-187
Nested k8s provisioning
Multi cluster setup
The contrail firewall policy created on creating k8s network policy should have cluster name appended over it to avoid conflicts.
Currently, the non default firewall policies created in contrail are having following name:
<namespace_
If we create same namespace and use same policy name across 2 different clusters, the latest setting override the previous one.
The same FW Policy is applied to both the APS groups of 2 different clusters and affect traffic of one of them.
Attached is the snapshot showing FW policy "test-test-
Rules under the policy will be inferred from the recent update from wither of the cluster.
Review in progress for https:/ /review. opencontrail. org/44793
Submitter: Dinesh Bakiaraj (<email address hidden>)