project-config/nodepool/elements/nodepool-base/install.d
Dirk Mueller b0b73ea971 Stop using connection tracking for ssh connections
There is an issue with newer kernels (it seems to happen with 4.15.x)
that when conntrack is reloaded while a connection has packets in
flight, this connection going forward is neither considered INVALID
nor RELATED nor ESTABLISHED by the stateful tracking. While this is
certainly a bug somewhere in the kernel, we can be easily avoiding
this by just not using stateful filtering for ssh connections, as
we accept any connection from anywhere anyway.

Change-Id: I1b20644ce888930cd28d6eaf2c23787315e8199c
2018-03-01 20:09:50 +01:00
..
05-record-details diskimage-builder element cleanups for dib-lint 2015-10-08 11:33:03 +11:00
06-record-builddate Add a dib-builddate file 2016-03-01 15:16:15 +11:00
20-iptables Stop using connection tracking for ssh connections 2018-03-01 20:09:50 +01:00
50-disable-metadata-cloudinit diskimage-builder element cleanups for dib-lint 2015-10-08 11:33:03 +11:00
91-venv-os-testr diskimage-builder element cleanups for dib-lint 2015-10-08 11:33:03 +11:00
96-clean-cron Stop installing and running puppet in node builds 2017-04-27 23:23:32 +02:00
99-disable-rfc3041 Disabled IPv6 privacy extensions 2016-08-16 23:18:23 -05:00