)]}'
{"id":"openstack%2Fkayobe~679739","triplet_id":"openstack%2Fkayobe~master~I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6","project":"openstack/kayobe","branch":"master","attention_set":{},"removed_from_attention_set":{"14200":{"account":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"last_update":"2024-08-20 13:21:49.000000000","reason":"Change was abandoned"},"14826":{"account":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"last_update":"2024-08-20 13:21:49.000000000","reason":"Change was abandoned"}},"hashtags":[],"change_id":"I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6","subject":"Make SNAT iptables rules persistent","status":"ABANDONED","created":"2019-09-03 09:59:41.000000000","updated":"2024-08-20 13:21:49.000000000","total_comment_count":3,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"c507c85150b916df2aab2b013ae400d2a4f5323a","_number":679739,"virtual_id_number":679739,"owner":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"tag":"autogenerated:zuul:check","value":1,"date":"2022-01-27 15:30:53.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"}],"values":{"-1":"Do Not Backport"," 0":"Backport Review Needed","+1":"Should Backport"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-09-03 10:33:52.000000000","updated_by":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"reviewer":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"state":"REVIEWER"},{"updated":"2019-09-03 12:21:00.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-07-22 12:23:46.000000000","updated_by":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"reviewer":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"state":"REVIEWER"},{"updated":"2023-08-27 00:14:51.000000000","updated_by":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"reviewer":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"state":"REVIEWER"}],"messages":[{"id":"3d250ae42fb47b1bb52d882f09172d035d44ab07","author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"date":"2019-09-03 09:59:41.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5ddec3d3666c561aca36526f9043e25a79bafdb8","author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"date":"2019-09-03 10:04:21.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"89e86684285e1ba1f7ad49e94817dc1b466ea0d1","author":{"_account_id":28048,"name":"Will Szumski","email":"will@stackhpc.com","username":"jovial"},"date":"2019-09-03 10:33:52.000000000","message":"Patch Set 2:\n\nAs docker is also managing the firewall, i.e we aren\u0027t using:\n\n  Prevent Docker from manipulating iptables\n  To prevent Docker from manipulating the iptables policies at all, set the iptables key to false in /etc/docker/daemon.json. This is inappropriate for most users, because the iptables policies then need to be managed by hand\n\nCould this cause any issues when you persist some its rules?","accounts_in_message":[],"_revision_number":2},{"id":"22f193cbb776ee165bc910a100668ec50509ee18","author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"date":"2019-09-03 11:53:27.000000000","message":"Patch Set 2: Workflow-1\n\n\u003e As docker is also managing the firewall, i.e we aren\u0027t using:\n \u003e \n \u003e Prevent Docker from manipulating iptables\n \u003e To prevent Docker from manipulating the iptables policies at all,\n \u003e set the iptables key to false in /etc/docker/daemon.json. This is\n \u003e inappropriate for most users, because the iptables policies then\n \u003e need to be managed by hand\n \u003e \n \u003e Could this cause any issues when you persist some its rules?\n\nIt\u0027s a good point. I\u0027ll rethink.","accounts_in_message":[],"_revision_number":2},{"id":"18e6a4938bfa552d880b6c0436e5c843172aea49","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-09-03 12:21:00.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f8075c9d96f04c5d871ea8a71a787455 : SUCCESS in 5m 28s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/e682173650484e3b9b9d8842d932fd3c : SUCCESS in 5m 07s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/a19207008b25426f86be4ff69732344f : SUCCESS in 4m 57s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e8cf8e8694a74139b1e378ab6adbf337 : SUCCESS in 4m 10s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/005bf16023a444209ce30fed4933c9a5 : SUCCESS in 4m 57s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/39c05c8e44f248b5857ad5bc97ce0df0 : SUCCESS in 4m 16s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/da4b297a230240c4a98166c18b96649e : SUCCESS in 4m 23s\n- kayobe-tox-ansible-syntax https://zuul.opendev.org/t/openstack/build/71b8b4aacaa14df3b6b06ae6a9f43339 : SUCCESS in 5m 04s\n- kayobe-tox-ansible https://zuul.opendev.org/t/openstack/build/dd025c8a43bc4717b4c451d9c57f0365 : SUCCESS in 8m 21s\n- kayobe-tox-molecule https://zuul.opendev.org/t/openstack/build/73591d679a15484ab2cf319466bb39ee : SUCCESS in 45m 47s\n- kayobe-overcloud-centos https://zuul.opendev.org/t/openstack/build/05838315321f442c9d32d628d0d3f480 : TIMED_OUT in 2h 02m 16s\n- kayobe-overcloud-upgrade-centos https://zuul.opendev.org/t/openstack/build/f31c9ab905184686a931b056f467b68c : SUCCESS in 2h 00m 57s\n- kayobe-seed-centos https://zuul.opendev.org/t/openstack/build/a21b96faf9b9449ca29d5ce76ec030f2 : SUCCESS in 20m 11s\n- kayobe-seed-upgrade-centos https://zuul.opendev.org/t/openstack/build/856c19ca6f27403095b3b44d625e7151 : SUCCESS in 31m 04s","accounts_in_message":[],"_revision_number":2},{"id":"c8989a55d49d9e569aeaaf8207e47882122d9982","author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"date":"2021-07-22 12:23:46.000000000","message":"Patch Set 2: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"2ba4f13217bee46d3658c3fa391a015c2a79a7e2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"date":"2022-01-27 13:36:20.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"c49682e7b2387fe8ff399541ab5ebe46afa4f59a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"date":"2022-01-27 13:36:58.000000000","message":"Uploaded patch set 4: Commit message was updated.","accounts_in_message":[],"_revision_number":4},{"id":"558702cec3ae9c120b393ad070380264c0488023","author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"date":"2022-01-27 13:37:40.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"04e5f6146587867bdbc940a97d27f46b1271dd06","author":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"date":"2022-01-27 13:37:48.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"f3ffa7487f229563549fdbc1164488ab046f4f2f","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-01-27 15:30:53.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/741dd6b997b84347976b739f4c5058bc : SUCCESS in 6m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5be0b262685646729680de8840c4521d : SUCCESS in 7m 42s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/714e14e65a0d47958e79e7e0b343e95a : SUCCESS in 6m 06s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/b1cb84bf221e4a8eb218fb6a020f9b43 : SUCCESS in 6m 22s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fddf904e30844475a378230264198428 : SUCCESS in 9m 37s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ae63b33c807b4577bba2159d2bff21c4 : SUCCESS in 3m 52s\n- kayobe-tox-ansible-syntax https://zuul.opendev.org/t/openstack/build/d72b50ac35174e138cc7022b476128ab : SUCCESS in 6m 21s\n- kayobe-tox-ansible https://zuul.opendev.org/t/openstack/build/7fc11e9a33a6465aabcf7c8921fdc4f6 : SUCCESS in 12m 50s\n- kayobe-tox-molecule https://zuul.opendev.org/t/openstack/build/50a8a4afb4d640c28e28d770890e6033 : SUCCESS in 32m 25s\n- kayobe-overcloud-centos8s https://zuul.opendev.org/t/openstack/build/d1860db1463e4d5bb39637da99737ee0 : SUCCESS in 1h 13m 14s\n- kayobe-overcloud-ubuntu-focal https://zuul.opendev.org/t/openstack/build/71e9fadf89a8422caba10969d471804f : SUCCESS in 44m 27s\n- kayobe-overcloud-tls-centos8s https://zuul.opendev.org/t/openstack/build/69902cf69dac4a90aec15075eb136160 : SUCCESS in 1h 08m 59s\n- kayobe-overcloud-host-configure-centos8s https://zuul.opendev.org/t/openstack/build/035f41fe232a4cf3a704805b9cb7f440 : SUCCESS in 22m 16s\n- kayobe-overcloud-host-configure-ubuntu-focal https://zuul.opendev.org/t/openstack/build/5383168c80974e7b85e20772c4f0c803 : SUCCESS in 14m 03s\n- kayobe-overcloud-upgrade-centos8s https://zuul.opendev.org/t/openstack/build/17629632c4ce4ee28362a20c00c170db : SUCCESS in 1h 51m 00s\n- kayobe-overcloud-upgrade-ubuntu-focal https://zuul.opendev.org/t/openstack/build/4b46167ee5dc4ee898008db61d031f57 : SUCCESS in 1h 12m 44s\n- kayobe-seed-centos8s https://zuul.opendev.org/t/openstack/build/9047684501534a4db8ad4a3c28200d8f : SUCCESS in 43m 04s\n- kayobe-seed-ubuntu-focal https://zuul.opendev.org/t/openstack/build/67b26cae987449fbad018acdd184938b : SUCCESS in 37m 11s\n- kayobe-seed-upgrade-centos8s https://zuul.opendev.org/t/openstack/build/538609802115462bbf5933db5f997ae1 : SUCCESS in 28m 46s\n- kayobe-seed-upgrade-ubuntu-focal https://zuul.opendev.org/t/openstack/build/5f8c20b17abb4e3484fb567acfdc8e30 : SUCCESS in 22m 42s\n- kayobe-seed-vm-centos8s https://zuul.opendev.org/t/openstack/build/0a044899bff14c48aca850e3b78b1b23 : SUCCESS in 17m 56s\n- kayobe-seed-vm-ubuntu-focal https://zuul.opendev.org/t/openstack/build/251a66f4d39d4a1a9369a3006086e7a2 : SUCCESS in 13m 44s\n- kayobe-infra-vm-centos8s https://zuul.opendev.org/t/openstack/build/f17d0cc4e83542bea24a277050263d7f : SUCCESS in 18m 50s\n- kayobe-infra-vm-ubuntu-focal https://zuul.opendev.org/t/openstack/build/0a780a1d1a8e4d3ebf6660505de0bc1e : SUCCESS in 14m 49s","accounts_in_message":[],"_revision_number":4},{"id":"c507c85150b916df2aab2b013ae400d2a4f5323a","tag":"autogenerated:gerrit:abandon","author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"date":"2024-08-20 13:21:49.000000000","message":"Abandoned\n\nThese rules should instead be migrated to firewalld.","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"9a6942865c25b65e55bc220c6c65cd08bb65ec74","revisions":{"34ad3eff6b1823837adc1c7f5fc62b13c5eeeac0":{"kind":"REWORK","_number":1,"created":"2019-09-03 09:59:41.000000000","uploader":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"ref":"refs/changes/39/679739/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/kayobe","ref":"refs/changes/39/679739/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/kayobe refs/changes/39/679739/1"}}},"commit":{"parents":[{"commit":"1f83d69aca784fc2147c76b25d8d631a1a7b9303","subject":"Merge \"Execute kayobe in verbose mode in CI\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/1f83d69aca784fc2147c76b25d8d631a1a7b9303"}]}],"author":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 09:54:44.000000000","tz":60},"committer":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 09:59:33.000000000","tz":60},"subject":"Make SNAT iptables rules persistent on the seed","message":"Make SNAT iptables rules persistent on the seed\n\nSNAT rules are created on the seed to allow routing via this host\nimmediately after provisioning overcloud hosts. These rules are not\npersistent, so may disappear after a reboot. This can lead to a loss of\nnetwork connectivity after provisioning control plane hosts.\n\nThis change adds a new role, iptables-persist, that persists all active\nIPTables rules. The role is executed in the SNAT playbook.\n\nNote that this role was adapted from Zuul\u0027s persistent-firewall role\n[1].\n\n[1]\nhttps://opendev.org/zuul/zuul-jobs/src/branch/master/roles/persistent-firewall\n\nChange-Id: I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6\nStory: 2006487\nTask: 36433\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/34ad3eff6b1823837adc1c7f5fc62b13c5eeeac0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/34ad3eff6b1823837adc1c7f5fc62b13c5eeeac0"}]},"branch":"refs/heads/master"},"d5ed4852ff73557c62804e65c31afd4ea52ea668":{"kind":"REWORK","_number":2,"created":"2019-09-03 10:04:21.000000000","uploader":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"ref":"refs/changes/39/679739/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/kayobe","ref":"refs/changes/39/679739/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/kayobe refs/changes/39/679739/2"}}},"commit":{"parents":[{"commit":"1f83d69aca784fc2147c76b25d8d631a1a7b9303","subject":"Merge \"Execute kayobe in verbose mode in CI\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/1f83d69aca784fc2147c76b25d8d631a1a7b9303"}]}],"author":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 09:54:44.000000000","tz":60},"committer":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 10:04:14.000000000","tz":60},"subject":"Make SNAT iptables rules persistent on the seed","message":"Make SNAT iptables rules persistent on the seed\n\nSNAT rules are created on the seed to allow routing via this host\nimmediately after provisioning overcloud hosts. These rules are not\npersistent, so may disappear after a reboot. This can lead to a loss of\nnetwork connectivity after provisioning control plane hosts.\n\nThis change adds a new role, iptables-persist, that persists all active\nIPTables rules. The role is executed in the SNAT playbook.\n\nNote that this role was adapted from Zuul\u0027s persistent-firewall role\n[1].\n\n[1]\nhttps://opendev.org/zuul/zuul-jobs/src/branch/master/roles/persistent-firewall\n\nChange-Id: I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6\nStory: 2006487\nTask: 36433\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/d5ed4852ff73557c62804e65c31afd4ea52ea668"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/d5ed4852ff73557c62804e65c31afd4ea52ea668"}]},"branch":"refs/heads/master"},"d51c390a56d039e89e6247095f9c4a4ccc9029d8":{"kind":"REWORK","_number":3,"created":"2022-01-27 13:36:20.000000000","uploader":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"ref":"refs/changes/39/679739/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/kayobe","ref":"refs/changes/39/679739/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/kayobe refs/changes/39/679739/3"}}},"commit":{"parents":[{"commit":"abb2edd8a0de089f219b845ddef8a2c24d0fafb3","subject":"Merge \"Remove chrony cleanup from overcloud host configure\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/abb2edd8a0de089f219b845ddef8a2c24d0fafb3"}]}],"author":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 09:54:44.000000000","tz":60},"committer":{"name":"Pierre Riteau","email":"pierre@stackhpc.com","date":"2022-01-27 13:35:55.000000000","tz":60},"subject":"Make SNAT iptables rules persistent on the seed","message":"Make SNAT iptables rules persistent on the seed\n\nSNAT rules are created on the seed hypervisor or seed host to allow\nrouting via this host immediately after provisioning overcloud hosts.\nThese rules are not persistent, so may disappear after a reboot. This\ncan lead to a loss of network connectivity after provisioning control\nplane hosts.\n\nThis change adds a new role, iptables-persist, that persists all active\niptables rules. The role is executed in the SNAT playbook.\n\nThis role was adapted from Zuul\u0027s persistent-firewall role [1].\n\n[1] https://opendev.org/zuul/zuul-jobs/src/branch/master/roles/persistent-firewall\n\nChange-Id: I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6\nStory: 2006487\nTask: 36433\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/d51c390a56d039e89e6247095f9c4a4ccc9029d8"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/d51c390a56d039e89e6247095f9c4a4ccc9029d8"}]},"branch":"refs/heads/master"},"9a6942865c25b65e55bc220c6c65cd08bb65ec74":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2022-01-27 13:36:58.000000000","uploader":{"_account_id":15197,"name":"Pierre Riteau","email":"pierre@stackhpc.com","username":"priteau","status":"StackHPC"},"ref":"refs/changes/39/679739/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/kayobe","ref":"refs/changes/39/679739/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/kayobe refs/changes/39/679739/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/kayobe refs/changes/39/679739/4"}}},"commit":{"parents":[{"commit":"abb2edd8a0de089f219b845ddef8a2c24d0fafb3","subject":"Merge \"Remove chrony cleanup from overcloud host configure\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/abb2edd8a0de089f219b845ddef8a2c24d0fafb3"}]}],"author":{"name":"Mark Goddard","email":"mark@stackhpc.com","date":"2019-09-03 09:54:44.000000000","tz":60},"committer":{"name":"Pierre Riteau","email":"pierre@stackhpc.com","date":"2022-01-27 13:36:27.000000000","tz":60},"subject":"Make SNAT iptables rules persistent","message":"Make SNAT iptables rules persistent\n\nSNAT rules are created on the seed hypervisor or seed host to allow\nrouting via this host immediately after provisioning overcloud hosts.\nThese rules are not persistent, so may disappear after a reboot. This\ncan lead to a loss of network connectivity after provisioning control\nplane hosts.\n\nThis change adds a new role, iptables-persist, that persists all active\niptables rules. The role is executed in the SNAT playbook.\n\nThis role was adapted from Zuul\u0027s persistent-firewall role [1].\n\n[1] https://opendev.org/zuul/zuul-jobs/src/branch/master/roles/persistent-firewall\n\nChange-Id: I8e485d0ff5b0030d1d91c9d21417ede27c2ee2e6\nStory: 2006487\nTask: 36433\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/9a6942865c25b65e55bc220c6c65cd08bb65ec74"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/kayobe/commit/9a6942865c25b65e55bc220c6c65cd08bb65ec74"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Backport-Candidate","description":"Backport candidate status","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
