)]}'
{"deployment/tripleo-firewall/tripleo-firewall-baremetal-puppet.yaml":[{"author":{"_account_id":24245,"name":"Harald Jensås","email":"hjensas@redhat.com","username":"harald.jensas"},"change_message_id":"1b278b0c4b3860887ab7c2a2587075e41279b08b","unresolved":false,"context_lines":[{"line_number":77,"context_line":"                  # so that nftables and iptables do not race each other"},{"line_number":78,"context_line":"              register: nftablesconf"},{"line_number":79,"context_line":"            - name: Flush Nftables rules when nftables.conf changed"},{"line_number":80,"context_line":"              command: /usr/sbin/nft flush ruleset"},{"line_number":81,"context_line":"              when: nftablesconf is changed"},{"line_number":82,"context_line":"          - if:"},{"line_number":83,"context_line":"            - no_ctlplane"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"df33271e_d6a6d453","line":80,"range":{"start_line":80,"start_character":23,"end_line":80,"end_character":50},"updated":"2020-03-26 11:18:11.000000000","message":"This is dropping all the firewall rules?\ni.e we end up with no firewall for several minutes until the deploy_steps_task run on update.","commit_id":"5884e91cfb541dd8c1c2bbf39b5a122ad72d6253"},{"author":{"_account_id":20172,"name":"Michele Baldessari","email":"michele@acksyn.org","username":"michele"},"change_message_id":"a86dcd5105ef62de79d344d2143b5fa82f4ba6a1","unresolved":false,"context_lines":[{"line_number":77,"context_line":"                  # so that nftables and iptables do not race each other"},{"line_number":78,"context_line":"              register: nftablesconf"},{"line_number":79,"context_line":"            - name: Flush Nftables rules when nftables.conf changed"},{"line_number":80,"context_line":"              command: /usr/sbin/nft flush ruleset"},{"line_number":81,"context_line":"              when: nftablesconf is changed"},{"line_number":82,"context_line":"          - if:"},{"line_number":83,"context_line":"            - no_ctlplane"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"df33271e_56492489","line":80,"range":{"start_line":80,"start_character":23,"end_line":80,"end_character":50},"in_reply_to":"df33271e_d6a6d453","updated":"2020-03-26 11:21:06.000000000","message":"correct, but only if the above file changes? which should be a onetimer. I mean to mitigate it we could prolly restart the iptables service right after as well? That would prolly be more robust I guess","commit_id":"5884e91cfb541dd8c1c2bbf39b5a122ad72d6253"}]}
