Add a script to zero /etc/sysconfig/iptables at build time
When including this element we empty the stock /etc/sysconfig/iptables
file as shipped by the iptables rpm package. The reason for this is that
puppet firewall has a hard time to cope with exiting rules when
/etc/sysconfig/iptables is populated and the iptables service is not
active. The referenced bug has a full explanation for the problem.
Reviewed: https:/ /review. openstack. org/422472 /git.openstack. org/cgit/ openstack/ tripleo- image-elements/ commit/ ?id=48c2a3f7ce9 58a8593795e29bb e244ba48f2708e
Committed: https:/
Submitter: Jenkins
Branch: master
commit 48c2a3f7ce958a8 593795e29bbe244 ba48f2708e
Author: Michele Baldessari <email address hidden>
Date: Thu Jan 19 09:53:19 2017 +0100
Add a script to zero /etc/sysconfig/ iptables at build time
When including this element we empty the stock /etc/sysconfig/ iptables sysconfig/ iptables is populated and the iptables service is not
file as shipped by the iptables rpm package. The reason for this is that
puppet firewall has a hard time to cope with exiting rules when
/etc/
active. The referenced bug has a full explanation for the problem.
Partial-Bug: #1657108
Change-Id: Iddc21316a1a3d4 2a1a43cbb4b9c17 8adba8f8db3