Bug 1633782 - The EC2 Metadata IP 169.254.169.254 is problematic with routed spine/leaf
Summary: The EC2 Metadata IP 169.254.169.254 is problematic with routed spine/leaf
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates
Version: 15.0 (Stein)
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: ---
Assignee: Emilien Macchi
QA Contact: Sasha Smolyak
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-09-27 18:28 UTC by Dan Sneddon
Modified: 2019-11-11 17:53 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-11-11 17:36:56 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Dan Sneddon 2018-09-27 18:28:59 UTC
Description of problem:
OSP-Director requires that overcloud nodes obtain their password to enroll in the CA via the EC2 metadata IP (169.254.169.254). Unfortunately, this IP is not routable, so this doesn't work well for routed spine/leaf.

Version-Release number of selected component (if applicable):
Stein and all previous versions

How reproducible:
100%

Steps to Reproduce:
1. Deploy nodes using routed spine/leaf with TLS everywhere.
2.
3.

Actual results:
Nodes that are not on the same control plane subnet as the undercloud cannot reach the metadata server unless there exist routes on the routers that point 169.254.169.254 to the undercloud IP. 

Expected results:
We should not rely on link-local addresses for routed installations.

Additional info:
The issue is that the 169.254.169.254 destination address is not known to the routers unless a special route is added for this address. This is not always permissible depending on network policy at specific sites. This is also an extra step that can be forgotten on some segments.

Comment 3 Bob Fournier 2018-11-30 16:30:41 UTC
We ultimately want to remove the Metadata IP settings from the undercloud.

Comment 5 Bob Fournier 2019-11-11 17:36:56 UTC
Closing this as fixed per comment 2.

Comment 6 Dan Sneddon 2019-11-11 17:53:38 UTC
Fixed under https://bugzilla.redhat.com/show_bug.cgi?id=1635370


Note You need to log in before you can comment on or make changes to this bug.