Skip to content

Commit 8d334f0

Browse files
committed
OpenStack: enable 30000:32767 nodePort IPv6 traffic
To make nodePort type Service work fine we need to enable the well known 30000:32767 traffic range.
1 parent d7bdcdf commit 8d334f0

File tree

1 file changed

+36
-0
lines changed

1 file changed

+36
-0
lines changed

upi/openstack/security-groups.yaml

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -372,4 +372,40 @@
372372
port_range_max: 1936
373373
when: os_master_schedulable is defined and os_master_schedulable
374374

375+
- name: 'Create master-sg IPv6 rule "master ingress services (TCP)"'
376+
openstack.cloud.security_group_rule:
377+
security_group: "{{ os_sg_master }}"
378+
ethertype: IPv6
379+
protocol: tcp
380+
remote_ip_prefix: "{{ os_subnet6_range }}"
381+
port_range_min: 30000
382+
port_range_max: 32767
383+
384+
- name: 'Create master-sg IPv6 rule "master ingress services (UDP)"'
385+
openstack.cloud.security_group_rule:
386+
security_group: "{{ os_sg_master }}"
387+
ethertype: IPv6
388+
protocol: udp
389+
remote_ip_prefix: "{{ os_subnet6_range }}"
390+
port_range_min: 30000
391+
port_range_max: 32767
392+
393+
- name: 'Create worker-sg IPv6 rule "worker ingress services (TCP)"'
394+
openstack.cloud.security_group_rule:
395+
security_group: "{{ os_sg_worker }}"
396+
ethertype: IPv6
397+
protocol: tcp
398+
remote_ip_prefix: "{{ os_subnet6_range }}"
399+
port_range_min: 30000
400+
port_range_max: 32767
401+
402+
- name: 'Create worker-sg rule IPv6 "worker ingress services (UDP)"'
403+
openstack.cloud.security_group_rule:
404+
security_group: "{{ os_sg_worker }}"
405+
ethertype: IPv6
406+
protocol: udp
407+
remote_ip_prefix: "{{ os_subnet6_range }}"
408+
port_range_min: 30000
409+
port_range_max: 32767
410+
375411
when: os_subnet6 is defined

0 commit comments

Comments
 (0)