Bug 2217907
| Summary: | (4.11.5) nft rules are not collected if the VMs are running in the node where must-gather is running | ||
|---|---|---|---|
| Product: | Container Native Virtualization (CNV) | Reporter: | Krzysztof Majcher <kmajcher> |
| Component: | Logging | Assignee: | Nahshon Unna-Tsameret <nunnatsa> |
| Status: | CLOSED ERRATA | QA Contact: | SATHEESARAN <sasundar> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.13.0 | CC: | sasundar, sradco |
| Target Milestone: | --- | ||
| Target Release: | 4.11.5 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | v4.11.5-51 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-07-25 15:00:46 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Krzysztof Majcher
2023-06-27 12:47:50 UTC
Please backport the fix. Tested with CNV v4.11.5-64 with the following steps:
1. Created a fedora VM and ran it.
2. Find out the node on which the VM is running. for eg. worker1
# oc get vmi
3. Run must-gather pod in the same node obtained in (2) while the VM is running.
# oc adm must-gather --node-name=<worker1> --image==registry.redhat.io/container-native-virtualization/cnv-must-gather-rhel8@sha256:82055386739d09788c5ad9fa70fed7d6f62fcea91a2a9a1dedec86144bfbaf6b -- /usr/bin/gather --vms_details
4. List the contents of the ruletables.txt from the collected must-gather contents
# cat must-gather.local.3490267327958448045/registry-redhat-io-container-native-virtualization-cnv-must-gather-rhel8-sha256-82055386739d09788c5ad9fa70fed7d6f62fcea91a2a9a1dedec86144bfbaf6b/namespaces/default/vms/fedora-cute-bear/virt-launcher-fedora-cute-bear-gc5pd.ruletables.txt
table ip filter {
chain INPUT {
type filter hook input priority filter; policy accept;
}
....
The contents of ruletables.txt is available and not empty.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Virtualization 4.11.5 Images), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2023:4271 |