puppet-tripleo package is outdated and doesn't know of enabled_services hiera key
Bug #1836696 reported by
Cédric Jeanneret
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tripleo |
Invalid
|
High
|
Unassigned |
Bug Description
Hello,
When following this doc[1], it appears the firewall isn't properly set: there are only a bunch of rules allowing ping, ESTABLISHED, and final DROP, and it lacks the ones allowing SSH access to the overcloud.
This leads to a timeout, since ansible can't access the host any more.
Cheers,
C.
To post a comment you must log in.
Precisions: download/ Compute/ deployment- hieradata. j2.yaml. rendered has a lot of rules, but in then end only a bunch of them are applied /bugzilla. redhat. com/show_ bug.cgi? id=1724560
- this also happens with the "more standard" deploy command
- it happens on a compute node, while the controller does have all the wanted rules
- the config-
- this deploy involves multi-nic + network isolation
- apparently this is NOT related to https:/
Here are the rules being applied on the compute:
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
621K 1747M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED /* 000 accept related established rules ipv4 */
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW /* 001 accept all icmp ipv4 */
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 state NEW /* 002 accept all to lo interface ipv4 */
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW limit: avg 20/min burst 15 /* 998 log all ipv4 */ LOG flags 0 level 4
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW /* 999 drop all ipv4 */
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 567K packets, 29M bytes)
pkts bytes target prot opt in out source destination
The first one explains why I'm not locked off when connected prior the rule application.
The attached file contains all the hieradata for the compute node.
I'm still digging in the logs in order to find something.