Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2164677

Summary: There is no ACCESS target for the port 13005 (heat_cfn_ssl_port) in OSP17.0.
Product: Red Hat OpenStack Reporter: Ryo Hayakawa <rhayakaw>
Component: openstack-tripleo-heat-templatesAssignee: Takashi Kajinami <tkajinam>
Status: CLOSED ERRATA QA Contact: David Rosenfeld <drosenfe>
Severity: medium Docs Contact:
Priority: medium    
Version: 17.0 (Wallaby)CC: jjoyce, jschluet, mburns, slinaber, tkajinam, tvignaud
Target Milestone: betaKeywords: Regression, Triaged
Target Release: 17.1   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: openstack-tripleo-heat-templates-14.3.1-1.20230402010807.563f2cd.el9ost Doc Type: Bug Fix
Doc Text:
Before this update, the iptables rule for the heat-cfn service contained the incorrect TCP port number. Users could not access the heat-cfn service endpoint if SSL was enabled for public endpoints. With this update, the TCP port number is correct in the iptables rule. Users can access the heat-cfn service endpoint, even if SSL is enabled for public endpoints.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-08-16 01:13:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 7 David Rosenfeld 2023-05-05 12:21:40 UTC
Port 13005 is open on controllers:

[tripleo-admin@controller-0 ~]$ sudo iptables -L | grep 13005
ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:13005 ctstate NEW /* 100 heat_api_cfn_haproxy_frontend_ssl ipv4 */

Comment 17 errata-xmlrpc 2023-08-16 01:13:42 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Release of components for Red Hat OpenStack Platform 17.1 (Wallaby)), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2023:4577