Do not load br_netfilter
Nor set related sysctls. More details in the reno. Change-Id: I898548ecc6df3caa094c3222159b7ba1e16dc211 Closes-Bug: #1945789
This commit is contained in:
parent
3e04e0043f
commit
15259002be
@ -1,13 +1,4 @@
|
||||
---
|
||||
- name: Load and persist br_netfilter module
|
||||
include_role:
|
||||
name: module-load
|
||||
vars:
|
||||
modules:
|
||||
- { name: br_netfilter }
|
||||
when:
|
||||
- inventory_hostname in groups[nova_cell_compute_group]
|
||||
|
||||
- name: Setting sysctl values
|
||||
become: true
|
||||
vars:
|
||||
@ -19,8 +10,6 @@
|
||||
sysctl_set: "{{ should_set }}"
|
||||
sysctl_file: "{{ kolla_sysctl_conf_path }}"
|
||||
with_items:
|
||||
- { name: "net.bridge.bridge-nf-call-iptables", value: 1}
|
||||
- { name: "net.bridge.bridge-nf-call-ip6tables", value: 1}
|
||||
- { name: "net.ipv4.conf.all.rp_filter", value: "{{ nova_compute_host_rp_filter_mode }}"}
|
||||
- { name: "net.ipv4.conf.default.rp_filter", value: "{{ nova_compute_host_rp_filter_mode }}"}
|
||||
when:
|
||||
|
16
releasenotes/notes/bug-1945789-cfb50a9bd8693c41.yaml
Normal file
16
releasenotes/notes/bug-1945789-cfb50a9bd8693c41.yaml
Normal file
@ -0,0 +1,16 @@
|
||||
---
|
||||
fixes:
|
||||
- |
|
||||
Fixes ``br_netfilter`` kernel module not to be loaded nor configured
|
||||
by Kolla Ansible.
|
||||
It was loaded and configured on Nova compute hosts regardless of the
|
||||
networking service config and its requirements.
|
||||
Users of existing setups are advised to re-evaluate whether they
|
||||
need this module loaded and unload if not necessary (also: remove
|
||||
from the autoloaded modules, as well as remove the related sysctls
|
||||
``net.bridge.bridge-nf-call-*``).
|
||||
Kolla Ansible will simply no longer try to load nor configure this
|
||||
module at all.
|
||||
Neutron agents handle loading and configuring this module as
|
||||
necessary.
|
||||
`LP#1945789 <https://launchpad.net/bugs/1945789>`__
|
Loading…
Reference in New Issue
Block a user