Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1797670

Summary: ovn_nb_connection for Octavia is hard-coded to use tcp: schema
Product: Red Hat OpenStack Reporter: Andrew Austin <aaustin>
Component: puppet-tripleoAssignee: ffernand <ffernand>
Status: CLOSED ERRATA QA Contact: nlevinki <nlevinki>
Severity: high Docs Contact:
Priority: high    
Version: 16.0 (Train)CC: amuller, aschultz, cgoncalves, ekuris, ffernand, jjoyce, jlibosva, jschluet, mgarciac, njohnston, rlondhe, shrjoshi, slinaber, sputhenp, tvignaud
Target Milestone: z2Keywords: AutomationBlocker, Regression, Triaged
Target Release: 16.0 (Train on RHEL 8.1)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-tripleo-heat-templates-11.3.2-0.20200405044623.ec9970c.el8ost puppet-tripleo-11.4.1-0.20200402130302.b4678ba.el8ost puppet-octavia-15.4.1-0.20200414135415.8bae62d.el8ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1803067 1823848 (view as bug list) Environment:
Last Closed: 2020-05-14 12:15:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1614299, 1803067, 1823848    

Description Andrew Austin 2020-02-03 15:48:26 UTC
Description of problem:
When deploying Octavia with TLS Everywhere and the OVN mechanism, the ovn_nb_connection option in Octavia still uses tcp:<VIP>:<Port> This appears to be hard-coded in puppet-tripleo. It should be ssl:<VIP>:<Port> when TLS Everywhere is enabled.

Comment 7 Jakub Libosvar 2020-03-17 14:14:06 UTC
*** Bug 1812744 has been marked as a duplicate of this bug. ***

Comment 9 ffernand 2020-03-20 10:06:55 UTC
*** Bug 1803067 has been marked as a duplicate of this bug. ***

Comment 13 ffernand 2020-04-14 14:57:34 UTC
Fix is in:
openstack-tripleo-heat-templates-11.3.2-0.20200414055425.89b7d51.el8ost
puppet-tripleo-11.4.1-0.20200409181944.5d41a09.el8ost
puppet-octavia-15.4.1-0.20200414135415.8bae62d.el8ost

Comment 19 Eran Kuris 2020-04-20 06:14:02 UTC
Fix verified :
[root@controller-1 ~]# export SBDB=$(sudo ovs-vsctl get open . external_ids:ovn-remote | sed -e 's/\"//g')
[root@controller-1 ~]# export NBDB=$(sudo ovs-vsctl get open . external_ids:ovn-remote | sed -e 's/\"//g' | sed -e 's/6642/6641/g')
[root@controller-1 ~]# echo $NBDB
ssl:172.17.1.42:6641
[root@controller-1 ~]# echo $SBDB
ssl:172.17.1.42:6642


(undercloud) [stack@undercloud-0 ~]$ rpm -qa | grep openstack-tripleo-heat-templates-11.
openstack-tripleo-heat-templates-11.3.2-0.20200405044623.ec9970c.el8ost.noarch
(undercloud) [stack@undercloud-0 ~]$ cat core_puddle_version 
RHOS_TRUNK-16.0-RHEL-8-20200417.n.1(undercloud) [stack@undercloud-0 ~]$

Comment 24 Carlos Goncalves 2020-05-06 14:29:22 UTC
*** Bug 1825171 has been marked as a duplicate of this bug. ***

Comment 26 errata-xmlrpc 2020-05-14 12:15:31 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:2114