swift-storage should only allow connections from swift-proxy

Bug #1727463 reported by David Ames
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Swift Storage Charm
Fix Released
High
David Ames

Bug Description

Implement ACLs to limit connectivity to swift-storage from the swift-proxy only.

The charm-helper modules ufw as seen in the memcached charm is the right solution.

David Ames (thedac)
Changed in charm-swift-storage:
status: New → Triaged
importance: Undecided → High
assignee: nobody → David Ames (thedac)
milestone: none → 17.11
David Ames (thedac)
Changed in charm-swift-storage:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to charm-swift-storage (master)

Reviewed: https://review.openstack.org/517115
Committed: https://git.openstack.org/cgit/openstack/charm-swift-storage/commit/?id=5368af630294f796acbc776448dad68f3e16edff
Submitter: Zuul
Branch: master

commit 5368af630294f796acbc776448dad68f3e16edff
Author: David Ames <email address hidden>
Date: Wed Nov 1 14:58:57 2017 -0700

    Swift storage ACLs

    Ensure that only the swift-proxy units and swift-storage peers have
    access to direct communication with swift storage daemons.

    Charm-helpers sync to include ufw module and the ingress_address and
    iter_units_for_relation_name functions.

    Please review and merge first:
    https://github.com/juju/charm-helpers/pull/35

    Closes-Bug: #1727463

    Change-Id: Id5677edbc40b0b891cbe66867d39d076a94c5436

Changed in charm-swift-storage:
status: In Progress → Fix Committed
James Page (james-page)
Changed in charm-swift-storage:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.