Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1179615

Summary: foreman-integration: set override-firewall definition on host bare-metal provisioning
Product: Red Hat Enterprise Virtualization Manager Reporter: Oved Ourfali <oourfali>
Component: ovirt-engineAssignee: Yaniv Bronhaim <ybronhei>
Status: CLOSED WONTFIX QA Contact: Petr Kubica <pkubica>
Severity: low Docs Contact:
Priority: low    
Version: 3.5.0CC: lpeer, lsurette, lsvaty, masayag, mgoldboi, oourfali, pstehlik, rbalakri, Rhev-m-bugs, srevivo, ybronhei, ykaul, ylavi
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Provisioning discovered host by ovirt is done by foreman. After provisioning is done Foreman sends API request to deploy the hypervisor. As part of the deploy user can choose if to override firewall rules or not (the option appears in addHost form). Currently we don't check the value and always override the iptables rules. With the fix we will allow to avoid the override by choice.
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-07-04 12:20:52 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Infra RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1179613    
Bug Blocks:    

Description Oved Ourfali 2015-01-07 08:34:19 UTC
Description of problem:
When using bare-metal provisioning, we need to allow the user to set whether he needs to override the firewall definition or not.

This information needs to pass from the engine to foreman (on the provision request), and back to the engine (on the install request).

Comment 1 Eyal Edri 2015-02-25 08:39:44 UTC
3.5.1 is already full with bugs (over 80), and since none of these bugs were added as urgent for 3.5.1 release in the tracker bug, moving to 3.5.2

Comment 2 Yaniv Bronhaim 2015-09-28 07:19:38 UTC
This will require to update rbovirt package [1]. we need to add parameter saying if to override iptables as part of the deploy or not. currently we always override in UpdateVdsCommand (line 119) which is called after the provision is done and start the host-deploy process.
To decide if to override iptables or not we have the checkbox in addHost form saying "Automatically configure host firewall" - if checked we can pass additional foreman parameter that will be checked in the plugin and send by rbovirt the request with the additional field "host.override_iptables:True\False"

Requiring new rbovirt ruby package and ovirt_provision_plugin is still an option for 3.6?

[1] https://github.com/abenari/rbovirt

Comment 3 Oved Ourfali 2015-10-07 10:58:10 UTC
As long as the code is backward compatible (and it should), I don't see an issue with this.
Is it backward compatible?

Comment 4 Yaniv Bronhaim 2015-10-18 12:19:53 UTC
The code will stay compatible and the patch will be posted soon. However, we have an issue with rbovirt releases. Apparently the latest rbovirt requires newer version of Ruby than the one foreman requires - this causes a conflict and foreman limits from above the rbovirt version - this means that our update to rbovirt (which will allow to add host with override_firewall=true parameter) will be quite complicated to require. I'll move forward and see what can be done

Comment 6 Oved Ourfali 2015-11-22 17:05:51 UTC
Changing the target back. 
Yaniv, why did you change it?

Comment 7 Yaniv Kaul 2015-11-22 18:42:33 UTC
Based on Yaniv Dary's scrubbing above.

Comment 8 Oved Ourfali 2015-12-30 08:33:57 UTC
Pushing to 4.0, and reducing priority and severity.

Comment 9 Yaniv Lavi 2016-05-09 10:57:27 UTC
oVirt 4.0 Alpha has been released, moving to oVirt 4.0 Beta target.