Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Correct policy for OpenStack sec group with no remote_ip_prefix #8026

Merged
merged 1 commit into from
Sep 19, 2023

Commits on Sep 19, 2023

  1. Correct policy for OpenStack sec group with no remote_ip_prefix

    Fixes projectcalico#7968
    
    When an OpenStack security group does not specify a remote_ip_prefix - in other words, it applies to
    traffic from all possible sources - but it does specify ports - in other words, it only applies to
    those ports, the resulting Calico policy is _missing_ the restriction to the intended ports, and so
    is accidentally an allow policy for _all_ ports.
    nelljerram committed Sep 19, 2023
    Configuration menu
    Copy the full SHA
    ff96fc8 View commit details
    Browse the repository at this point in the history