Bug 1026367 - openshift-iptables-port-proxy service script should enable net.ipv4.conf.all.route_localnet
openshift-iptables-port-proxy service script should enable net.ipv4.conf.all....
Product: OpenShift Origin
Classification: Red Hat
Component: Containers (Show other bugs)
Unspecified Unspecified
medium Severity medium
: ---
: ---
Assigned To: Brenton Leanhardt
libra bugs
Depends On:
  Show dependency treegraph
Reported: 2013-11-04 09:11 EST by Brenton Leanhardt
Modified: 2017-01-25 01:38 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2017-01-25 01:38:55 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Brenton Leanhardt 2013-11-04 09:11:34 EST
Description of problem:

The openshift-iptables-port-proxy service script will not function properly if net.ipv4.conf.all.route_localnet is disabled.  Typically this is a step performed as part of an OpenShift deployment.  However, as a safety check it should be temporarily enabled in this service script.

I say temporary because admins in different environments may have their own procedure for persisting sysctl changes.  This change will warn the admin to persist the setting and mention that it is being temporarily enabled.
Comment 1 Brenton Leanhardt 2013-11-04 09:15:12 EST
Comment 2 openshift-github-bot 2013-11-04 19:55:20 EST
Commits pushed to master at https://github.com/openshift/origin-server

Bug 1026367 - openshift-iptables-port-proxy service script should enable net.ipv4.conf.all.route_localnet

Bug 1026367 - starting openshift-iptables-port-proxy after the network is up

Bug 1026367 - Improving oo-admin-ctl-iptables-port-proxy "UI"

Previously the restart, reload, stop and status commands were noop.  This can
be confusing for admins.


stop: flushes the rhc-app-comm chain
restart: calls stop then start
reload: calls start
status: removed

The motivation for this is the following:

1 Admin sees something weird with the rhc-app-comm chain not working as expected
2 Admin runs `for s in 'iptables network openshift-iptables-port-proxy'; do server $s restart'
3 Admin notices rhc-app-comm is still empty and is really confused

In this case the event that trigged #1 is that net.ipv4.conf.all.route_localnet
wasn't set in /etc/sysctl.conf.

Bug 1026367 - Moving the sysctl logic to oo-admin-ctl-iptables-port-proxy
Comment 3 Michal Fojtik 2013-11-20 06:38:26 EST

Note You need to log in before you can comment on or make changes to this bug.