Bug 1179615
| Summary: | foreman-integration: set override-firewall definition on host bare-metal provisioning | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Virtualization Manager | Reporter: | Oved Ourfali <oourfali> |
| Component: | ovirt-engine | Assignee: | Yaniv Bronhaim <ybronhei> |
| Status: | CLOSED WONTFIX | QA Contact: | Petr Kubica <pkubica> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | 3.5.0 | CC: | lpeer, lsurette, lsvaty, masayag, mgoldboi, oourfali, pstehlik, rbalakri, Rhev-m-bugs, srevivo, ybronhei, ykaul, ylavi |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: |
Provisioning discovered host by ovirt is done by foreman. After provisioning is done Foreman sends API request to deploy the hypervisor. As part of the deploy user can choose if to override firewall rules or not (the option appears in addHost form). Currently we don't check the value and always override the iptables rules. With the fix we will allow to avoid the override by choice.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-07-04 12:20:52 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | Infra | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1179613 | ||
| Bug Blocks: | |||
|
Description
Oved Ourfali
2015-01-07 08:34:19 UTC
3.5.1 is already full with bugs (over 80), and since none of these bugs were added as urgent for 3.5.1 release in the tracker bug, moving to 3.5.2 This will require to update rbovirt package [1]. we need to add parameter saying if to override iptables as part of the deploy or not. currently we always override in UpdateVdsCommand (line 119) which is called after the provision is done and start the host-deploy process. To decide if to override iptables or not we have the checkbox in addHost form saying "Automatically configure host firewall" - if checked we can pass additional foreman parameter that will be checked in the plugin and send by rbovirt the request with the additional field "host.override_iptables:True\False" Requiring new rbovirt ruby package and ovirt_provision_plugin is still an option for 3.6? [1] https://github.com/abenari/rbovirt As long as the code is backward compatible (and it should), I don't see an issue with this. Is it backward compatible? The code will stay compatible and the patch will be posted soon. However, we have an issue with rbovirt releases. Apparently the latest rbovirt requires newer version of Ruby than the one foreman requires - this causes a conflict and foreman limits from above the rbovirt version - this means that our update to rbovirt (which will allow to add host with override_firewall=true parameter) will be quite complicated to require. I'll move forward and see what can be done Changing the target back. Yaniv, why did you change it? Based on Yaniv Dary's scrubbing above. Pushing to 4.0, and reducing priority and severity. oVirt 4.0 Alpha has been released, moving to oVirt 4.0 Beta target. |