Skip to content

Firewall management #274

Description

@dann1

As part of the deployment, it'd be nice to have the firewall on the hosts automatically set up to allow all of the connections required by opennebula. This list does not include the prometheus+grafana+am+exporters observability stack (should be changed upstream to reflect these).

  • Consider the different flows we have, like kvm to kvm live migration or prometheus scrapping the nodes, or udp monitor push, etc..
  • Consider also that as part of the configuration stated in the inventory, the ports might not be necessarily the default ones. So maybe the running processed configuration and the port is bound to, should be the source of truth.

Over time this has become more and more important since we are increasingly distributing exporters.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions