FWIW, I couldn't reproduced it on Juno devstack with:
disable_service n-net enable_service q-svc enable_service q-agt enable_service q-dhcp enable_service q-l3 enable_service q-meta enable_service q-fwaas Q_SERVICE_PLUGIN_CLASSES=neutron.services.firewall.fwaas_plugin.FirewallPlugin Q_USE_SECGROUP=True
The ipset command do fails but it does not prevent new instances to boot nor impact previous instance connectivity.
FWIW, I couldn't reproduced it on Juno devstack with:
disable_service n-net PLUGIN_ CLASSES= neutron. services. firewall. fwaas_plugin. FirewallPlugin
enable_service q-svc
enable_service q-agt
enable_service q-dhcp
enable_service q-l3
enable_service q-meta
enable_service q-fwaas
Q_SERVICE_
Q_USE_SECGROUP=True
The ipset command do fails but it does not prevent new instances to boot nor impact previous instance connectivity.