Skip to content

Conversation

@addyess
Copy link
Member

@addyess addyess commented Feb 14, 2025

This fixes LP#1905008 by using the subnet cidr for member rules allowing the health checks to succeed since they use the amphora VRRP_IP and not the ip of the loadbalancer.

@addyess addyess force-pushed the fix/lp1905008/widen-sg-group-for-amphora-vrrp-ip branch from 371198e to 4b25700 Compare March 3, 2025 20:05
@addyess addyess force-pushed the fix/lp1905008/widen-sg-group-for-amphora-vrrp-ip branch from 4b25700 to ff12b6f Compare May 8, 2025 14:15
@addyess addyess changed the title FIX: Use subnet cidr for member secgroup rules to support amphora VRRP_IP [LP#1905008] Use subnet cidr for member secgroup rules to support amphora VRRP_IP May 8, 2025
Copy link

@rapour rapour left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot @addyess, my assumption is that both LB VIP and amphora VRRP IP reside in the same CIDR and by extending the security group rule Neutron will pass the traffic to kube api, which LGTM. Just left a question out of curiosity

@addyess addyess force-pushed the fix/lp1905008/widen-sg-group-for-amphora-vrrp-ip branch from 30b2e7d to c268e99 Compare October 15, 2025 15:45
@addyess addyess merged commit b8a86a8 into main Oct 16, 2025
8 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants