Activity log for bug #1765700

Date Who What changed Old value New value Message
2018-04-20 12:52:01 Harald Jensås bug added bug
2018-04-20 12:52:33 Harald Jensås description In https://review.openstack.org/523944 we switch the ironic inspector filter driver from iptables to dnsmasq. The old iptables driver created a firewall chain, and will in most cases configure a REJECT rule[1] to block any introspection unless the operator start introspection of nodes. https://github.com/openstack/ironic-inspector/blob/master/ironic_inspector/pxe_filter/iptables.py#L186 On the upgraded undercloud we have these left-over rules still there: 357 183K ironic-inspector udp -- br-ctlplane any anywhere anywhere udp dpt:bootps Chain ironic-inspector (1 references) pkts bytes target prot opt in out source destination 357 183K REJECT all -- any any anywhere anywhere reject-with icmp-port-unreachable In https://review.openstack.org/523944 we switch the ironic inspector filter driver from iptables to dnsmasq. The old iptables driver created a firewall chain, and will in most cases configure a REJECT rule[1] to block any introspection unless the operator start introspection of nodes. On the upgraded undercloud we have these left-over rules still there:   357 183K ironic-inspector udp -- br-ctlplane any anywhere anywhere udp dpt:bootps Chain ironic-inspector (1 references) pkts bytes target prot opt in out source destination 357 183K REJECT all -- any any anywhere anywhere reject-with icmp-port-unreachable [1] https://github.com/openstack/ironic-inspector/blob/master/ironic_inspector/pxe_filter/iptables.py#L186
2018-04-20 12:52:40 Harald Jensås tripleo: importance Undecided High
2018-04-20 13:30:52 Bogdan Dobrelya tripleo: status New Triaged
2018-04-20 13:56:54 Harald Jensås tripleo: status Triaged Incomplete
2018-04-20 13:56:56 Harald Jensås tripleo: assignee Harald Jensås (harald-jensas)
2018-04-20 17:55:51 Alex Schultz tripleo: milestone rocky-1 rocky-2
2018-04-20 23:00:24 Harald Jensås tripleo: status Incomplete Triaged
2018-04-22 13:16:43 OpenStack Infra tripleo: status Triaged In Progress
2018-04-24 11:45:35 OpenStack Infra tripleo: status In Progress Fix Released
2018-04-24 11:45:49 OpenStack Infra tags queens-backport-potential upgrade in-stable-queens queens-backport-potential upgrade