Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1709209

Summary: RHOSP13z5 or later prevent to access haproxy stats because of commit 3f8ce6fd96bc4f28a052b4c87a19b4b152734091
Product: Red Hat OpenStack Reporter: Keigo Noha <knoha>
Component: openstack-tripleo-heat-templatesAssignee: Michele Baldessari <michele>
Status: CLOSED ERRATA QA Contact: pkomarov
Severity: high Docs Contact:
Priority: high    
Version: 13.0 (Queens)CC: bperkins, dabarzil, lmiccini, mburns, michele
Target Milestone: z7Keywords: Triaged, ZStream
Target Release: 13.0 (Queens)   
Hardware: x86_64   
OS: Unspecified   
Whiteboard:
Fixed In Version: puppet-tripleo-8.4.1-8.el7ost openstack-tripleo-heat-templates-8.3.1-32.el7ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-07-10 13:05:27 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Keigo Noha 2019-05-13 08:03:43 UTC
Description of problem:
RHOSP13z5 or later prevent to access haproxy stats because of commit 3f8ce6fd96bc4f28a052b4c87a19b4b152734091.

The commit overwrites tripleo.haproxy.firewall_rules.
However, the parameter is also used at puppet/services/haproxy.yaml.

~~~
outputs:
  role_data:
    description: Role data for the HAproxy role.
    value:
      service_name: haproxy
      monitoring_subscription: {get_param: MonitoringSubscriptionHaproxy}
      config_settings:
        map_merge:
          - tripleo.haproxy.firewall_rules:
              '107 haproxy stats':
                dport: 1993
~~~

By the commit, users cannot access to haproxy stats.

Version-Release number of selected component (if applicable):
Current T-H-T.

How reproducible:
Every deployment

Steps to Reproduce:
1.
2.
3.

Actual results:
'iptables -nvL' doesn't contain 107 proxy stats rules for ipv4 and ipv6.

Expected results:
'iptables -nvL' contains 107 proxy stats rules for ipv4 and ipv6.

Additional info:

Comment 11 errata-xmlrpc 2019-07-10 13:05:27 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:1738