Purge initial firewall for deployed-server's
authorJames Slagle <jslagle@redhat.com>
Mon, 3 Apr 2017 16:50:45 +0000 (12:50 -0400)
committerJames Slagle <jslagle@redhat.com>
Mon, 3 Apr 2017 16:52:45 +0000 (12:52 -0400)
We need to purge the initial firewall for deployed-server's, otherwise
if you have a default REJECT rule, the pacemaker cluster will fail to
initialize. This matches the behavior done when using images, see:
Iddc21316a1a3d42a1a43cbb4b9c178adba8f8db3
I0dee5ff045fbfe7b55d078583e16b107eec534aa

Change-Id: Ia83d17b609e4f737074482a980689cc57c3ad911
Closes-Bug: #1679234

deployed-server/deployed-server-bootstrap-centos.sh
deployed-server/deployed-server-bootstrap-rhel.sh
releasenotes/notes/deployed-server-firewall-purge-9d9fe73faf925056.yaml [new file with mode: 0644]

index c86e771..6f2bb12 100644 (file)
@@ -15,3 +15,6 @@ ln -s -f /usr/share/openstack-puppet/modules/* /etc/puppet/modules
 
 setenforce 0
 sed -i 's/^SELINUX=.*/SELINUX=permissive/' /etc/selinux/config
+
+echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/iptables
+echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/ip6tables
index 10b4999..9e9e9b3 100644 (file)
@@ -12,3 +12,6 @@ yum install -y \
     openstack-selinux
 
 ln -s -f /usr/share/openstack-puppet/modules/* /etc/puppet/modules
+
+echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/iptables
+echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/ip6tables
diff --git a/releasenotes/notes/deployed-server-firewall-purge-9d9fe73faf925056.yaml b/releasenotes/notes/deployed-server-firewall-purge-9d9fe73faf925056.yaml
new file mode 100644 (file)
index 0000000..298a8ec
--- /dev/null
@@ -0,0 +1,6 @@
+---
+fixes:
+  - The initial firewall will now be purged by the deployed-server bootstrap
+    scripts. This is needed to prevent possible issues with bootstrapping the
+    initial Pacemaker cluster. See
+    https://bugs.launchpad.net/tripleo/+bug/1679234