including global ssh access in tripleo::firewall::pre makes it
difficult for the operator to control ssh access to overcloud hosts.
This removes the hardcoded rule and the accompanying change in t-h-t
configures the default firewall rules via hiera config_settings.
Reviewed: https:/ /review. opendev. org/656244 /git.openstack. org/cgit/ openstack/ puppet- tripleo/ commit/ ?id=47034b224cd 532c9b1d76f0aac e0bdddbce9ea87
Committed: https:/
Submitter: Zuul
Branch: stable/rocky
commit 47034b224cd532c 9b1d76f0aace0bd ddbce9ea87
Author: Lars Kellogg-Stedman <email address hidden>
Date: Thu Jul 12 15:22:10 2018 -0400
remove ssh from tripleo: :firewall: :pre
including global ssh access in tripleo: :firewall: :pre makes it
difficult for the operator to control ssh access to overcloud hosts.
This removes the hardcoded rule and the accompanying change in t-h-t
configures the default firewall rules via hiera config_settings.
Depends-On: I89cff59947dda3 f51482486c41a3d 67c4aa36a3e 7c5d54b4f1fd536 8b000744135 6283292a6964a08 9f012f2ae9)
Change-Id: I14b540e6564c5b
Related-Bug: #1826829
(cherry picked from commit 9bdb8199cc394bd