Skip to content

[202205][caclmgrd][chassis]: Fix missing acl rules to allow internal docker traffic from fabric namespaces#11956

Merged
SuvarnaMeenakshi merged 3 commits intosonic-net:202205from
SuvarnaMeenakshi:cacl05
Nov 1, 2022
Merged

[202205][caclmgrd][chassis]: Fix missing acl rules to allow internal docker traffic from fabric namespaces#11956
SuvarnaMeenakshi merged 3 commits intosonic-net:202205from
SuvarnaMeenakshi:cacl05

Conversation

@SuvarnaMeenakshi
Copy link
Copy Markdown
Contributor

Signed-off-by: Suvarna Meenakshi [email protected]

Why I did it

Changes from master branch PR sonic-net/sonic-host-services#13
est_cacl_application fails on VoQ chassis Supervisor with the error:
Failed: Missing expected iptables rules: set(['-A INPUT -s 240.127.1.1/32 -d 240.127.1.1/32 -j ACCEPT', '-A INPUT -s 240.127.1.3/32 -d 240.127.1.1/32 -j ACCEPT', '-A INPUT -s 240.127.1.2/32 -d 240.127.1.1/32 -j ACCEPT'])
This failure is seen because acl rules to allow traffic from fabric namespaces is missing.
This PR is to include fabric namespace docker mgmt ips so that acl rules to allow traffic from namespace is added for fabric namespace as well.

How I did it

Get list of fabric namespaces, use this list to get docker mgmt ip of fabric asic namespace as well.

How to verify it

Verified on voq chassis.
unit-test passes

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

internal docker traffic from fabric namespaces

Signed-off-by: Suvarna Meenakshi <[email protected]>
Signed-off-by: Suvarna Meenakshi <[email protected]>
Copy link
Copy Markdown
Contributor

@judyjoseph judyjoseph left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@SuvarnaMeenakshi SuvarnaMeenakshi merged commit 84fc3ec into sonic-net:202205 Nov 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants