Revert "Do not load br_netfilter"

This reverts commit 15259002be.

Reason for revert: The iptables_firewall produces warnings without it.

Change-Id: Id046a3048436c4c18dd1fd9700ac9971d8c42c57
This commit is contained in:
Mark Goddard 2021-10-25 08:16:09 +00:00 committed by Radosław Piliszek
parent 15259002be
commit c93f59cd8e
2 changed files with 11 additions and 16 deletions

View File

@ -1,4 +1,13 @@
---
- name: Load and persist br_netfilter module
include_role:
name: module-load
vars:
modules:
- { name: br_netfilter }
when:
- inventory_hostname in groups[nova_cell_compute_group]
- name: Setting sysctl values
become: true
vars:
@ -10,6 +19,8 @@
sysctl_set: "{{ should_set }}"
sysctl_file: "{{ kolla_sysctl_conf_path }}"
with_items:
- { name: "net.bridge.bridge-nf-call-iptables", value: 1}
- { name: "net.bridge.bridge-nf-call-ip6tables", value: 1}
- { name: "net.ipv4.conf.all.rp_filter", value: "{{ nova_compute_host_rp_filter_mode }}"}
- { name: "net.ipv4.conf.default.rp_filter", value: "{{ nova_compute_host_rp_filter_mode }}"}
when:

View File

@ -1,16 +0,0 @@
---
fixes:
- |
Fixes ``br_netfilter`` kernel module not to be loaded nor configured
by Kolla Ansible.
It was loaded and configured on Nova compute hosts regardless of the
networking service config and its requirements.
Users of existing setups are advised to re-evaluate whether they
need this module loaded and unload if not necessary (also: remove
from the autoloaded modules, as well as remove the related sysctls
``net.bridge.bridge-nf-call-*``).
Kolla Ansible will simply no longer try to load nor configure this
module at all.
Neutron agents handle loading and configuring this module as
necessary.
`LP#1945789 <https://launchpad.net/bugs/1945789>`__