commit e55ff3ec35566a718a325b198fc45b890d129d24
Author: Brian Haley <email address hidden>
Date: Thu Nov 30 16:57:51 2017 -0500
Add iptables metadata marking rule on router init
Move the iptables metadata marking rule earlier in
router init, that way any stray metadata requests
that arrive before the filter metadata redirect rule is
installed will just be dropped. We do this irregardless
of whether we will be running the metadata proxy.
Partial-bug: #1735724
Change-Id: I8982523dbb94a7c5b8a4db88a196fabc4dd2873f
(cherry picked from commit 69419778276a722c3f376046d1e0cc7fc4684e99)
Reviewed: https:/ /review. openstack. org/598979 /git.openstack. org/cgit/ openstack/ neutron/ commit/ ?id=e55ff3ec355 66a718a325b198f c45b890d129d24
Committed: https:/
Submitter: Zuul
Branch: stable/queens
commit e55ff3ec35566a7 18a325b198fc45b 890d129d24
Author: Brian Haley <email address hidden>
Date: Thu Nov 30 16:57:51 2017 -0500
Add iptables metadata marking rule on router init
Move the iptables metadata marking rule earlier in
router init, that way any stray metadata requests
that arrive before the filter metadata redirect rule is
installed will just be dropped. We do this irregardless
of whether we will be running the metadata proxy.
Partial-bug: #1735724
Change-Id: I8982523dbb94a7 c5b8a4db88a196f abc4dd2873f c3f376046d1e0cc 7fc4684e99)
(cherry picked from commit 69419778276a722