nova: add missing vnc console port in firewall
authorEmilien Macchi <emilien@redhat.com>
Wed, 2 Nov 2016 17:37:07 +0000 (13:37 -0400)
committerEmilien Macchi <emilien@redhat.com>
Thu, 3 Nov 2016 18:22:21 +0000 (18:22 +0000)
- Remove vncproxy firewall rules from nova-api service
- Add vncproxy firewall rules to nova-vncproxy service
- Add console port range firewall rules to nova-libvirt service

Change-Id: I421ae21c130cac6f25e7c0869b941ba77441172c

puppet/services/nova-api.yaml
puppet/services/nova-libvirt.yaml
puppet/services/nova-vnc-proxy.yaml

index bf47943..3cc238c 100644 (file)
@@ -88,8 +88,6 @@ outputs:
           tripleo.nova_api.firewall_rules:
             '113 nova_api':
               dport:
-                - 6080
-                - 13080
                 - 8773
                 - 3773
                 - 8774
index 241e605..70774ba 100644 (file)
@@ -56,6 +56,7 @@ outputs:
                   - 16509
                   - 16514
                   - '49152-49215'
+                  - '5900-5999'
 
       step_config: |
         include tripleo::profile::base::nova::libvirt
index 85d59ae..e6b0703 100644 (file)
@@ -57,5 +57,10 @@ outputs:
             # internal_api_uri -> [IP]
             # internal_api_subnet - > IP/CIDR
             nova::vncproxy::host: {get_param: [ServiceNetMap, NovaApiNetwork]}
+            tripleo.nova_vnc_proxy.firewall_rules:
+              '137 nova_vnc_proxy':
+                dport:
+                  - 6080
+                  - 13080
       step_config: |
         include tripleo::profile::base::nova::vncproxy