Uploaded image for project: 'TrueNAS'
  1. TrueNAS
  2. NAS-109047

use iptables to sever and/or allow connections on SCALE failover

    XMLWordPrintable

    Details

      Description

      The freeBSD failover code used the "pf" firewall in the capacity of:

      --on failover backup event, reject existing connections
      --on failover master event, allow existing connectinos

      When I implemented the SCALE active/passive failover code, k8s was also being developed and I tried to use nftables. I learned that nftables has an incompatibility with k8s so I skipped adding any firewalls at the time.

      k8s is now mostly implemented using iptables so I need to implement the necessary rules for SCALE HA systems.

        Attachments

          Attachments

            JEditor

              Issue Links

                Activity

                  People

                  Assignee:
                  caleb Caleb St. John
                  Reporter:
                  caleb Caleb St. John
                  Votes:
                  0 Vote for this issue
                  Watchers:
                  2 Start watching this issue

                    Dates

                    Created:
                    Updated:
                    Resolved: