Hardware checklist should contain a list of all open ports required for firewall configuration in case the firewall is put between controller and compute nodes, for example

Bug #1429072 reported by Bogdan Dobrelya
14
This bug affects 3 people
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Triaged
Medium
Fuel Documentation Team

Bug Description

Current https://github.com/stackforge/fuel-docs/blob/master/pages/user-guide/1500-confirm-hardware.rst assumes the firewall configuration checklist only for master node access. We should consider to add a full list of ports required for OpenStack environment as well. This list will be useful for cases then additional HW firewalls must be configured to allow traffic between controllers and compute/other nodes.

The full list of ports could be re-used from here (look for all "firewall {}" entries):
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/openstack/manifests/firewall.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/openstack/manifests/heat.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/openstack/manifests/logging.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/cobbler/manifests/iptables.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/sahara/manifests/init.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/memcached/manifests/init.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/zabbix/manifests/server.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/zabbix/manifests/monitoring/rabbitmq_mon.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/zabbix/manifests/agent.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/osnailyfacter/modular/firewall/firewall.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/nailgun/manifests/host.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/nailgun/manifests/iptables.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/galera/manifests/init.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/mongodb/manifests/firewall.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/ceph/manifests/radosgw.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/ceph/manifests/osd.pp
https://github.com/stackforge/fuel-library/blob/master/deployment/puppet/ceph/manifests/mon.pp

Tags: area-docs docs
Changed in fuel:
milestone: none → 6.1
importance: Undecided → Medium
assignee: nobody → Fuel Documentation Team (fuel-docs)
Changed in fuel:
status: New → Confirmed
tags: added: docs
Changed in fuel:
status: Confirmed → Triaged
Changed in fuel:
milestone: 6.1 → 7.0
Igor Shishkin (teran)
Changed in fuel:
milestone: 7.0 → 8.0
Dmitry Pyzhov (dpyzhov)
tags: added: area-docs
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.