Octavia services are running on composable role and Haproxy on different one. Octavia ports are open by iptables on Haproxy node, but not open on where Octavia API runs. Does this need a different bug or can we fix it here?
This might not be a supported configuration as we don't specifically configure firewall rules based on HAproxy's location as we assume HAProxy is always on the same host as the api services. It's likely that there might need to be a custom set of rules created for this architecture. Slightly related would be Bug 1445766
Fix is in place.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:0448