DCN nodes cannot access glance-api endpoint when deployed with TLS-everywhere

Bug #1893453 reported by Alan Bishop
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
Fix Released
High
Alan Bishop

Bug Description

Nova and cinder services running at a DCN/Edge site are expected to access a glance-api service running at the same edge site. However, the services are configured to use an endpoint URI that always uses the g-api node's IP address, and this will not work when using TLS everywhere.

When deployed with TLS-everywhere, the glance-api endpoint used by DCN nodes needs to use a FQDN.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-heat-templates (master)

Fix proposed to branch: master
Review: https://review.opendev.org/748736

Changed in tripleo:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-heat-templates (master)

Reviewed: https://review.opendev.org/748736
Committed: https://git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/?id=2035b88f5b9eb1c86391c995f768f9ecc45855a4
Submitter: Zuul
Branch: master

commit 2035b88f5b9eb1c86391c995f768f9ecc45855a4
Author: Alan Bishop <email address hidden>
Date: Thu Aug 27 12:22:02 2020 -0700

    DCN: use FQDN in glance endpoint with internal TLS

    Fix the glance-api endpoint used by cinder and nova services at DCN
    sites. When internal TLS is enabled, the URI must use a FQDN and not
    an IP address.

    Closes-Bug: #1893453
    Change-Id: I386a035f9688c54d617e714888c9c0fa14f34a1e

Changed in tripleo:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-heat-templates (stable/ussuri)

Fix proposed to branch: stable/ussuri
Review: https://review.opendev.org/749422

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-heat-templates (stable/ussuri)

Reviewed: https://review.opendev.org/749422
Committed: https://git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/?id=9471eb030f21d425cb049ada3b91935d4b1bdea7
Submitter: Zuul
Branch: stable/ussuri

commit 9471eb030f21d425cb049ada3b91935d4b1bdea7
Author: Alan Bishop <email address hidden>
Date: Thu Aug 27 12:22:02 2020 -0700

    DCN: use FQDN in glance endpoint with internal TLS

    Fix the glance-api endpoint used by cinder and nova services at DCN
    sites. When internal TLS is enabled, the URI must use a FQDN and not
    an IP address.

    Closes-Bug: #1893453
    Change-Id: I386a035f9688c54d617e714888c9c0fa14f34a1e
    (cherry picked from commit 2035b88f5b9eb1c86391c995f768f9ecc45855a4)

tags: added: in-stable-ussuri
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-heat-templates (stable/train)

Fix proposed to branch: stable/train
Review: https://review.opendev.org/749625

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-heat-templates (stable/train)

Reviewed: https://review.opendev.org/749625
Committed: https://git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/?id=ca3bd9c3dd9ab75f085f66122f63a6dcd607f59b
Submitter: Zuul
Branch: stable/train

commit ca3bd9c3dd9ab75f085f66122f63a6dcd607f59b
Author: Alan Bishop <email address hidden>
Date: Thu Aug 27 12:22:02 2020 -0700

    DCN: use FQDN in glance endpoint with internal TLS

    Fix the glance-api endpoint used by cinder and nova services at DCN
    sites. When internal TLS is enabled, the URI must use a FQDN and not
    an IP address.

    Closes-Bug: #1893453
    Change-Id: I386a035f9688c54d617e714888c9c0fa14f34a1e
    (cherry picked from commit 2035b88f5b9eb1c86391c995f768f9ecc45855a4)
    (cherry picked from commit 9471eb030f21d425cb049ada3b91935d4b1bdea7)

tags: added: in-stable-train
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/tripleo-heat-templates 11.4.0

This issue was fixed in the openstack/tripleo-heat-templates 11.4.0 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.