)]}'
{"roles/nftables/tasks/main.yaml":[{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"dfa5b736e7b67077dd99f0301d698e5185694cc2","unresolved":true,"context_lines":[{"line_number":12,"context_line":"      /usr/bin/update-alternatives --set ebtables /usr/sbin/ebtables-nft"},{"line_number":13,"context_line":"      /usr/bin/update-alternatives --set arptables /usr/sbin/arptables-nft"},{"line_number":14,"context_line":"    executable: /bin/bash"},{"line_number":15,"context_line":"  become: yes"},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"- name: Restart nftables service, that will replace iptables(4,6), ebtables and arptables"},{"line_number":18,"context_line":"  ansible.builtin.systemd:"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"b3fe3c1a_28f137b9","line":15,"updated":"2021-04-09 07:52:29.000000000","message":"When we will do that, will we keep all iptables rules which were configured so far in legacy iptables? I\u0027m asking because I think infra is configuring some rules on the node, like e.g. https://zuul.opendev.org/t/openstack/build/ab8a5f6412d546b7b2fe4ac66b887acd/log/job-output.txt#651 and don\u0027t want to break something to e.g. open such VM for everything during the job run.","commit_id":"8ed5fd679d76da86ace7d1eeda3c5f50872a1326"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"1e7f030d7f0b3fc429aa34d516115bdd413fe571","unresolved":true,"context_lines":[{"line_number":12,"context_line":"      /usr/bin/update-alternatives --set ebtables /usr/sbin/ebtables-nft"},{"line_number":13,"context_line":"      /usr/bin/update-alternatives --set arptables /usr/sbin/arptables-nft"},{"line_number":14,"context_line":"    executable: /bin/bash"},{"line_number":15,"context_line":"  become: yes"},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"- name: Restart nftables service, that will replace iptables(4,6), ebtables and arptables"},{"line_number":18,"context_line":"  ansible.builtin.systemd:"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"7ad7ef11_08bc8da0","line":15,"in_reply_to":"b3fe3c1a_28f137b9","updated":"2021-04-09 09:55:58.000000000","message":"You are right, we need to ensure that those rules are in the nft FW (using the legacy API). I think I can use what is stored by iptables-persistent, installed just after the iptables FW setup.","commit_id":"8ed5fd679d76da86ace7d1eeda3c5f50872a1326"}]}
