Reorganize Content of Guides
- Sys Config Guide
- Node Management Guide
Topic already in Sys Config Guide with different names (deleted).
Added links to topics
Moved links to other topics according to review.
Signed-off-by: Adil <mohamed.adilassakkali@windriver.com>
Change-Id: Ifb015461a60bedd7b5ddd8cee651ac41fc038c3f
(cherry picked from commit e6d6e84cad)
This commit is contained in:
@@ -299,6 +299,7 @@ Common device management tasks
|
|||||||
hardware_acceleration_devices/removing-a-device-label
|
hardware_acceleration_devices/removing-a-device-label
|
||||||
hardware_acceleration_devices/initiating-a-device-image-update-for-a-host
|
hardware_acceleration_devices/initiating-a-device-image-update-for-a-host
|
||||||
hardware_acceleration_devices/displaying-the-status-of-device-images
|
hardware_acceleration_devices/displaying-the-status-of-device-images
|
||||||
|
cli-commands-for-managing-pci-devices
|
||||||
|
|
||||||
***********************************************
|
***********************************************
|
||||||
vRAN Accelerator ACC100 Adapter \(Mount Bryce\)
|
vRAN Accelerator ACC100 Adapter \(Mount Bryce\)
|
||||||
@@ -366,12 +367,3 @@ Provision BMC using the CLI
|
|||||||
provisioning_bmc/provisioning-bmc-when-adding-a-host
|
provisioning_bmc/provisioning-bmc-when-adding-a-host
|
||||||
provisioning_bmc/provisioning-bmc-after-adding-a-host
|
provisioning_bmc/provisioning-bmc-after-adding-a-host
|
||||||
provisioning_bmc/deprovisioning-board-management-control-from-the-cli
|
provisioning_bmc/deprovisioning-board-management-control-from-the-cli
|
||||||
|
|
||||||
-------------------------------------
|
|
||||||
CLI commands for managing PCI devices
|
|
||||||
-------------------------------------
|
|
||||||
|
|
||||||
.. toctree::
|
|
||||||
:maxdepth: 1
|
|
||||||
|
|
||||||
cli-commands-for-managing-pci-devices
|
|
||||||
|
|||||||
@@ -49,4 +49,4 @@ locked. This requires a swact during the procedure.
|
|||||||
|
|
||||||
#. Modify the |MTU| of the |OAM| interface on the new standby controller.
|
#. Modify the |MTU| of the |OAM| interface on the new standby controller.
|
||||||
|
|
||||||
#. Unlock the standby controller.
|
#. Unlock the standby controller.
|
||||||
|
|||||||
@@ -59,4 +59,4 @@ requires a swact.
|
|||||||
|
|
||||||
.. code-block:: none
|
.. code-block:: none
|
||||||
|
|
||||||
~(keystone_admin)]$ system host-unlock controller-0
|
~(keystone_admin)]$ system host-unlock controller-0
|
||||||
|
|||||||
@@ -123,4 +123,10 @@ the system configuration is updated.
|
|||||||
.. rubric:: |postreq|
|
.. rubric:: |postreq|
|
||||||
|
|
||||||
If alarms are not cleared after a few minutes, lock and unlock the worker
|
If alarms are not cleared after a few minutes, lock and unlock the worker
|
||||||
nodes to apply any other incomplete configuration changes.
|
nodes to apply any other incomplete configuration changes.
|
||||||
|
|
||||||
|
For more information about the default firewall rules, see
|
||||||
|
:ref:`Default Firewall Rules <security-default-firewall-rules>`.
|
||||||
|
|
||||||
|
For more information about modifying the firewall options, see
|
||||||
|
:ref:`Modify Firewall Options <security-firewall-options>`.
|
||||||
|
|||||||
@@ -71,4 +71,10 @@ resources are available to migrate any running instances.
|
|||||||
|
|
||||||
.. note::
|
.. note::
|
||||||
On AIO Simplex systems you do not need to lock and unlock the host. The
|
On AIO Simplex systems you do not need to lock and unlock the host. The
|
||||||
changes are applied automatically.
|
changes are applied automatically.
|
||||||
|
|
||||||
|
For more information about the default firewall rules, see
|
||||||
|
:ref:`Default Firewall Rules <security-default-firewall-rules>`.
|
||||||
|
|
||||||
|
For more information about modifying the firewall options, see
|
||||||
|
:ref:`Modify Firewall Options <security-firewall-options>`.
|
||||||
|
|||||||
@@ -54,7 +54,6 @@ OAM IP Configuration
|
|||||||
|
|
||||||
changing-the-oam-ip-configuration-using-horizon
|
changing-the-oam-ip-configuration-using-horizon
|
||||||
changing-the-oam-ip-configuration-using-the-cli
|
changing-the-oam-ip-configuration-using-the-cli
|
||||||
modifying-oam-firewall-rules
|
|
||||||
changing-the-mtu-of-an-oam-interface-using-horizon
|
changing-the-mtu-of-an-oam-interface-using-horizon
|
||||||
changing-the-mtu-of-an-oam-interface-using-the-cli
|
changing-the-mtu-of-an-oam-interface-using-the-cli
|
||||||
|
|
||||||
|
|||||||
@@ -1,92 +0,0 @@
|
|||||||
|
|
||||||
.. yqd1552574422118
|
|
||||||
.. _modifying-oam-firewall-rules:
|
|
||||||
|
|
||||||
==========================
|
|
||||||
Modify OAM Firewall Rules
|
|
||||||
==========================
|
|
||||||
|
|
||||||
|prod| supports custom |OAM| firewall rules using Kubernetes Global Network
|
|
||||||
Policies.
|
|
||||||
|
|
||||||
These policies are defined using yaml syntax. For example:
|
|
||||||
|
|
||||||
.. code-block:: yaml
|
|
||||||
|
|
||||||
~(keystone_admin)]$ kubectl get globalnetworkpolicies.crd.projectcalico.org -o yaml
|
|
||||||
apiVersion: v1
|
|
||||||
items:
|
|
||||||
- apiVersion: crd.projectcalico.org/v1
|
|
||||||
kind: GlobalNetworkPolicy
|
|
||||||
metadata:
|
|
||||||
creationTimestamp: "2019-06-28T17:06:33Z"
|
|
||||||
generation: 1
|
|
||||||
name: controller-oam-if-gnp
|
|
||||||
resourceVersion: "1916"
|
|
||||||
selfLink: /apis/crd.projectcalico.org/v1/globalnetworkpolicies/controller-oam-if-gnp
|
|
||||||
uid: 146ec9a4-99c7-11e9-b187-0800275484ef
|
|
||||||
spec:
|
|
||||||
applyOnForward: false
|
|
||||||
egress:
|
|
||||||
- action: Allow
|
|
||||||
ipVersion: 4
|
|
||||||
protocol: TCP
|
|
||||||
- action: Allow
|
|
||||||
ipVersion: 4
|
|
||||||
protocol: UDP
|
|
||||||
- action: Allow
|
|
||||||
protocol: ICMP
|
|
||||||
ingress:
|
|
||||||
- action: Allow
|
|
||||||
destination:
|
|
||||||
ports:
|
|
||||||
- 22
|
|
||||||
- 18002
|
|
||||||
- 4545
|
|
||||||
- 15491
|
|
||||||
- 6385
|
|
||||||
- 7777
|
|
||||||
- 6443
|
|
||||||
- 7480
|
|
||||||
- 9311
|
|
||||||
- 5000
|
|
||||||
- 8080
|
|
||||||
ipVersion: 4
|
|
||||||
protocol: TCP
|
|
||||||
- action: Allow
|
|
||||||
destination:
|
|
||||||
ports:
|
|
||||||
- 2222
|
|
||||||
- 2223
|
|
||||||
- 123
|
|
||||||
- 161
|
|
||||||
- 162
|
|
||||||
- 319
|
|
||||||
- 320
|
|
||||||
ipVersion: 4
|
|
||||||
protocol: UDP
|
|
||||||
- action: Allow
|
|
||||||
protocol: ICMP
|
|
||||||
order: 100
|
|
||||||
selector: has(iftype) && iftype == 'oam'
|
|
||||||
types:
|
|
||||||
- Ingress
|
|
||||||
- Egress
|
|
||||||
kind: List
|
|
||||||
metadata:
|
|
||||||
resourceVersion: ""
|
|
||||||
selfLink: ""
|
|
||||||
|
|
||||||
For a full description of |GNP| syntax,
|
|
||||||
see `https://docs.projectcalico.org/v3.6/reference/calicoctl/resources/globalnetworkpolicy
|
|
||||||
<https://docs.projectcalico.org/v3.6/reference/calicoctl/resources/globalnetworkpolicy>`__.
|
|
||||||
|
|
||||||
Use the following command to edit the globalnetworkpolicy and modify the
|
|
||||||
|OAM| Firewall according to the above |GNP| syntax:
|
|
||||||
|
|
||||||
.. code-block:: none
|
|
||||||
|
|
||||||
kubectl edit globalnetworkpolicy
|
|
||||||
|
|
||||||
.. xbooklink For more information about the |prod| firewall,
|
|
||||||
see |sec-doc|: `Firewall Options <network-planning-firewall-options>`.
|
|
||||||
Reference in New Issue
Block a user