commit 65f3714164f3c3be4d6b4eb6a29c753b4f0fee96
Author: Emilien Macchi <email address hidden>
Date: Sun Mar 11 08:30:19 2018 +0100
firewall: don't reload IPtables after cleanup
This patch stops the IPtables reload when doing Neutron rules cleanup.
Full context:
puppetlabs-firewall only manages the current state of iptables
rules and writes out the rules to a file to ensure they are
persisted. We are specifically running the following commands after the
iptables rules to ensure the persisted file does not contain any
ephemeral neutron rules. Neutron assumes the iptables rules are not
persisted so it may cause an issue if the rule is loaded on boot
(or via iptables restart). If an operator needs to reload iptables
for any reason, they may need to manually reload the appropriate
neutron agent to restore these iptables rules.
Reviewed: https:/ /review. openstack. org/551747 /git.openstack. org/cgit/ openstack/ puppet- tripleo/ commit/ ?id=65f3714164f 3c3be4d6b4eb6a2 9c753b4f0fee96
Committed: https:/
Submitter: Zuul
Branch: master
commit 65f3714164f3c3b e4d6b4eb6a29c75 3b4f0fee96
Author: Emilien Macchi <email address hidden>
Date: Sun Mar 11 08:30:19 2018 +0100
firewall: don't reload IPtables after cleanup
This patch stops the IPtables reload when doing Neutron rules cleanup.
Full context: firewall only manages the current state of iptables
puppetlabs-
rules and writes out the rules to a file to ensure they are
persisted. We are specifically running the following commands after the
iptables rules to ensure the persisted file does not contain any
ephemeral neutron rules. Neutron assumes the iptables rules are not
persisted so it may cause an issue if the rule is loaded on boot
(or via iptables restart). If an operator needs to reload iptables
for any reason, they may need to manually reload the appropriate
neutron agent to restore these iptables rules.
rhbz#1541528 aadb70d2210a378 417087f1ecf
Related-Bug: #1747960
Change-Id: I1ab3a52306b91b