Bug 1156342

Summary: memcached port 11211 is not opened by default on controllers in HA environments.
Product: Red Hat OpenStack Reporter: Lee Yarwood <lyarwood>
Component: openstack-foreman-installerAssignee: Jason Guiditta <jguiditt>
Status: CLOSED ERRATA QA Contact: Alexander Chuzhoy <sasha>
Severity: urgent Docs Contact:
Priority: urgent    
Version: Foreman (RHEL 6)CC: ddomingo, mburns, morazi, racedoro, rhos-maint, sclewis, yeylon
Target Milestone: z2   
Target Release: Installer   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: openstack-foreman-installer-2.0.32-1.el6ost Doc Type: Bug Fix
Doc Text:
With this update, the memcached port (11211) is now open by default on controllers in HA environments. This helps avoid any authentication errors or other similar issues that can severely affect access speed to the dashboard.
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-11-04 17:04:04 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Lee Yarwood 2014-10-24 09:09:19 UTC
Description of problem:
memcached port 11211 is not opened by default on controllers in HA environments.

This in turn leads to vnc proxy token authentication errors, slow horizon access times etc.

Version-Release number of selected component (if applicable):
# egrep '(osp-installer|puppet)' installed-rpms
openstack-puppet-modules-2014.1-21.8.el6ost.noarch          Mon Oct 13 16:26:35 2014
puppet-3.6.2-1.1.el6.noarch                                 Mon Oct 13 16:26:42 2014
puppet-server-3.6.2-1.1.el6.noarch                          Mon Oct 13 15:40:08 2014
rhel-osp-installer-0.3.6-1.el6ost.noarch                    Mon Oct 13 16:27:09 2014

How reproducible:
Always.

Steps to Reproduce:
1. Deploy multiple HA controllers.

Actual results:
Port 11211 is not opened by default.

Expected results:
Port 11211 is opened by default.

Additional info:

Comment 3 Jason Guiditta 2014-10-27 16:01:16 UTC
firewall rule added, undergoing testing now:

https://github.com/redhat-openstack/astapor/pull/397

Comment 6 Alexander Chuzhoy 2014-10-28 15:55:59 UTC
Verified:
openstack-puppet-modules-2014.1-24.2.el6ost.noarch
rhel-osp-installer-0.4.5-2.el6ost.noarch
ruby193-rubygem-foreman_openstack_simplify-0.0.6-8.el6ost.noarch
openstack-foreman-installer-2.0.32-1.el6ost.noarch
ruby193-rubygem-staypuft-0.4.10-1.el6ost.noarch

On all controllers get the following:
iptables -L -n|grep 11211
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 11211 /* 010 memcached incoming */

Comment 8 Mike Burns 2014-10-30 00:26:34 UTC
ack on doc text

Comment 10 errata-xmlrpc 2014-11-04 17:04:04 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2014-1800.html