SELinux context overrides fail for neutron install on metal
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack-Ansible |
Fix Released
|
Medium
|
Guilherme Steinmuller Pimentel |
Bug Description
Non-container hosts on which neutron services are installed fail during neutron installation with an error like the following:
fatal: [host01]: FAILED! => {"changed": false, "failed": true, "msg": "ValueError: File spec /openstack/
Somewhere earlier in the installation, an SELinux equivalency context rule was set matching /openstack/log with /var/log; that causes this error to arise when the neutron-specific rule conflicts with the equivalency rule.
Manually removing the equivalency rule on the affected hosts after the failure arises allows a successful re-run of the neutron plays.
Changed in openstack-ansible: | |
status: | New → Confirmed |
importance: | Undecided → Medium |
assignee: | nobody → Guilherme Steinmuller Pimentel (guilhermesp) |
Reviewed: https:/ /review. openstack. org/603472 /git.openstack. org/cgit/ openstack/ openstack- ansible- os_neutron/ commit/ ?id=baf17001b8d 7afca87907aef47 eca4fde4747ca1
Committed: https:/
Submitter: Zuul
Branch: stable/queens
commit baf17001b8d7afc a87907aef47eca4 fde4747ca1
Author: Mohammed Naser <email address hidden>
Date: Sun Aug 26 01:21:48 2018 -0400
Drop SELinux support for CentOS 7
We do not have a maintainer at the moment for SELinux and hopefully
we will adopt the upstream openstack-selinux package, but for now
in order to let deploys in environments where SELinux is set to
permissive work, we'll have to remove these bits.
This change can be reverted whenever we have a maintainer that's
available to do the work required.
Closes-Bug: 1792050 458a9396422d047 e1327bb4d45 2b7e6a530e6f6da 804d38e056)
Change-Id: I4c7b6a9c0d8ec1
(cherry picked from commit 084559b8cf7c7fe