kayobe/ansible/roles
Pierre Riteau 9df0f00bc5 Configure bifrost to use firewalld trusted zone
Without this setting, bifrost creates a bifrost firewalld zone only
allowing network traffic for Ironic services and assigns the
provisioning network interface to it, potentially causing loss of
connectivity.

Using the public zone is suggested as a workaround [1] but is not
sufficient: it allows SSH traffic, but blocks other services deployed on
the seed, such as Docker registry traffic.

[1] https://review.opendev.org/#/c/754406/

Change-Id: I80f9d95f02e11fda5916f9a9dd257b688a9db7e2
Story: 2008153
Task: 40899
2020-10-07 17:38:43 +02:00
..
arista-switch Add support for Arista switches 2019-08-22 16:20:40 +02:00
bootstrap Switch to generic package module 2019-12-09 10:21:20 +00:00
console-allocation Remove support for CentOS 7 and Python 2 2020-05-28 10:25:51 +01:00
dell-switch Remove documentation and use of dell_switch_delegate_to 2018-12-19 13:05:01 +01:00
dell-switch-bmp Update README for dell-switch-bmp role 2017-03-28 16:18:21 +01:00
deploy-containers Add framework to deploy user-defined containers on seed 2020-06-10 19:34:04 +01:00
dev-tools Install bash-completion in dev-tools 2020-08-25 12:59:23 +02:00
disable-cloud-init Don't restart cloud-init when disabling it 2018-03-20 10:43:02 +00:00
disable-glean Small fixes for disable-glean role 2017-05-29 16:55:54 +01:00
disable-selinux Don't disable SELinux if it is not installed 2020-05-28 19:34:20 +01:00
dnf When EPEL install flag is not set 2020-10-01 10:04:58 +00:00
dnf-automatic CentOS 8: Support DNF 2020-03-19 11:23:39 +00:00
docker Use Ansible connection reset support in docker role 2020-04-03 17:25:24 +01:00
docker-devicemapper Switch default docker storage driver to overlay2 2020-10-05 19:59:11 +00:00
docker-registry Docker registry basic auth 2020-09-21 14:19:29 +02:00
drac-boot-mode Fix Ansible warnings for use of until with {{ }} 2018-05-24 17:56:50 +01:00
drac-pxe Fix Ansible warnings for use of until with {{ }} 2018-05-24 17:56:50 +01:00
image-download Fix issue with image download when checksum url is none 2019-10-14 12:24:44 +00:00
inspection-store Add support for stopping overcloud services 2020-03-26 14:34:07 +00:00
ip-allocation Remove support for CentOS 7 and Python 2 2020-05-28 10:25:51 +01:00
ip-routing Support configuring rp_filter mode 2018-07-20 14:56:45 +01:00
ipa-images Remove activate-virtualenv and deactivate-virtualenv roles 2020-02-20 15:28:56 +00:00
ironic-inspector-rules Fix ironic inspector rule creation idempotency 2020-04-28 13:51:35 +00:00
junos-switch Junos switch: update ncclient to 0.6.7+ 2020-02-28 09:49:42 +00:00
kolla Remove support for CentOS 7 and Python 2 2020-05-28 10:25:51 +01:00
kolla-ansible Switch default docker storage driver to overlay2 2020-10-05 19:59:11 +00:00
kolla-ansible-host-vars Performance: Parallelise Kolla Ansible host vars generation 2020-09-22 17:06:04 +01:00
kolla-bifrost Configure bifrost to use firewalld trusted zone 2020-10-07 17:38:43 +02:00
kolla-build CentOS 8: separate kolla build tag from deploy tag 2020-04-27 17:42:55 +01:00
kolla-openstack Add missing barbican.conf support 2020-09-23 19:17:51 +00:00
nclu-switch Add support for configuring Cumulus switches with NCLU 2020-03-03 20:46:32 +00:00
opensm Add support for stopping overcloud services 2020-03-26 14:34:07 +00:00
pip Performance: refactor pip configuration 2020-08-24 10:29:02 +01:00
public-openrc Set endpoint type variables to publicURL in public-openrc.sh 2020-07-23 15:43:31 +02:00
snat/tasks CentOS 8: seed VM & bifrost 2020-04-09 14:04:22 +00:00
ssh-known-host/tasks Fix concurrency issues while adding SSH keys to known_hosts 2020-05-11 15:44:18 +02:00
swift-block-devices Switch to generic package module 2019-12-09 10:21:20 +00:00
swift-rings Stop to use the __future__ module. 2020-06-02 20:19:56 +02:00
sysctl Add support for configuration of sysctl parameters 2017-08-31 17:43:18 +00:00
veth Remove support for CentOS 7 and Python 2 2020-05-28 10:25:51 +01:00
wipe-disks/tasks Merge "Switch to generic package module" 2019-12-11 11:04:31 +00:00