653cde084b
This patch changes the main sample devstack local.conf to use Octavia. In order for that to work, it does some security group changes to ensure that the communication from the LB to the members will work in both L2 and L3 modes. In L2 mode, which is the default behavior after this patch, but not the default behavior we'll chose going forward, Octavia creates a pod_subnet port per each Load Balancer with the 'default' security group of the 'admin' project. This means that it would not be allowed by the members since they use the 'default' security group from the 'k8s' project. In L3 mode, Octavia does not create a port in the members subnet and relies on the service and the pod subnet to be connected to the same router. Some changes are necessary on the lbaas handler for that and they'll come in a follow-up patch. In case the developers want to try, I added a security group for the service subnet to be allowed into the pod subnet. Partially-Implements: blueprint octavia-support Change-Id: I993ebb0d7b82ad1140d752982013bbadf35dfef7 Signed-off-by: Antoni Segura Puimedon <antonisp@celebdor.com> |
||
---|---|---|
.. | ||
lib | ||
devstackgaterc | ||
gate_hook.sh | ||
kubectl | ||
local.conf.df.sample | ||
local.conf.pod-in-vm.overcloud.sample | ||
local.conf.pod-in-vm.undercloud.sample | ||
local.conf.sample | ||
plugin.sh | ||
settings |