Skip to content

Commit 6ca6d9b

Browse files
committed
advertised network isolation: use LportEgressAfterLB for ACLs
Signed-off-by: Patryk Diak <[email protected]>
1 parent 2847345 commit 6ca6d9b

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

go-controller/pkg/ovn/base_network_controller.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1228,7 +1228,7 @@ func BuildAdvertisedNetworkSubnetsDropACL(advertisedNetworkSubnetsAddressSet add
12281228
strings.Join(dropMatches, " || "),
12291229
nbdb.ACLActionDrop,
12301230
nil,
1231-
libovsdbutil.LportEgress)
1231+
libovsdbutil.LportEgressAfterLB)
12321232
dropACL.Tier = types.PrimaryACLTier
12331233
return dropACL
12341234
}
@@ -1265,7 +1265,7 @@ func (bnc *BaseNetworkController) addAdvertisedNetworkIsolation(nodeName string)
12651265
strings.Join(passMatches, " || "),
12661266
nbdb.ACLActionPass,
12671267
nil,
1268-
libovsdbutil.LportEgress)
1268+
libovsdbutil.LportEgressAfterLB)
12691269
passACL.Tier = types.PrimaryACLTier
12701270

12711271
ops, err = libovsdbops.CreateOrUpdateACLsOps(bnc.nbClient, ops, nil, passACL)

go-controller/pkg/ovn/gateway_test.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ func generateAdvertisedUDNIsolationExpectedNB(testData []libovsdbtest.TestData,
4949
strings.Join(passMatches, " || "),
5050
nbdb.ACLActionPass,
5151
nil,
52-
libovsdbutil.LportEgress)
52+
libovsdbutil.LportEgressAfterLB)
5353
passACL.Tier = types.PrimaryACLTier
5454
passACL.UUID = "advertised-udn-isolation-pass-acl-UUID"
5555
dropACL := BuildAdvertisedNetworkSubnetsDropACL(addrSet)

0 commit comments

Comments
 (0)