Actually move to nftables for any host with nftables: true (nothing atm). #2482
No reviewers
Labels
No labels
freeze-break-request
post-freeze
No milestone
No project
No assignees
4 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Infrastructure/ansible#2482
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "nft-swap"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
I think this should be everything to get things installed, when a host has the nftables variable set to true.
I'm pretty sure I've missed at least something minor, but we could start testing a staging machine and see what happens.
Build failed. More information on how to proceed and troubleshoot errors available at https://fedoraproject.org/wiki/Zuul-based-ci
https://fedora.softwarefactory-project.io/zuul/buildset/f4532e84b0e04ef3ac5e1b3070d8807e
LGTM +1
Shoud this be nftables for the tag?
Oh, I updated roles/koji_builder/templates/osbuildapi-update.sh can you fold in the changes to the nft one?
Also, I am quite possibly missing it, but do we have anywhere that copies the templates to the host for nftables service to use?
I used the iptables tag because I figured that might be used as a generic thing to say "this is firewall stuff" ... I can easily create a nftables tag if you know it won't cause extra changes.
The
e7b50aaee4
change is just to not remove old entries anymore? The change I did was to comment out the flush line.1 new commit added
Don't flush old osbuildapi entries in nftables land either.
Build failed. More information on how to proceed and troubleshoot errors available at https://fedoraproject.org/wiki/Zuul-based-ci
https://fedora.softwarefactory-project.io/zuul/buildset/4ef6279d11444ad481a756fb81478980
nftables tag might be better... it's not a huge deal tho.
Yeah, just stops removing entries and swapping new one in, just keeps adding to the one existing one.
1 new commit added
Actually install the nftable template file.
Build failed. More information on how to proceed and troubleshoot errors available at https://fedoraproject.org/wiki/Zuul-based-ci
https://fedora.softwarefactory-project.io/zuul/buildset/2e4c3baf887e484187978ad21acafab6
2 new commits added
Move staging builders to nftables.
Add new osbuildapi-update-nft.cron entries, and get it installed when nftables.
rebased onto
c9b9086535
rebased onto
c9b9086535
ok, lets give it a go!
Pull-Request has been merged by kevin
Build failed. More information on how to proceed and troubleshoot errors available at https://fedoraproject.org/wiki/Zuul-based-ci
https://fedora.softwarefactory-project.io/zuul/buildset/f33e315a7b134e90afe8049bd6489101