Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions ansible/roles/bootstrap/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,18 @@
become: yes
ignore_errors: yes

- name: Remove default REJECT rules from iptables
block:
- name: Remove INPUT REJECT rule
command: iptables -D INPUT -j REJECT --reject-with icmp-host-prohibited
become: yes
ignore_errors: yes

- name: Remove FORWARD REJECT rule
command: iptables -D FORWARD -j REJECT --reject-with icmp-host-prohibited
become: yes
ignore_errors: yes

- name: clean up the dt_path
file:
path: "{{ dt_path }}"
Expand Down Expand Up @@ -31,6 +43,19 @@
shell: |
oc patch network.operator cluster -p '{"spec":{"defaultNetwork": {"ovnKubernetesConfig":{"gatewayConfig":{"ipForwarding": "Global"}}}}}' --type=merge

- name: Configure NAT masquerade on public interface
block:
- name: get default route
shell: |
ip r | grep default | cut -d ' ' -f5
register: default_route
become: yes

- name: masquerade on public interface
shell: |
iptables -t nat -A POSTROUTING -o {{ default_route.stdout }} -j MASQUERADE
Comment on lines +48 to +56

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

git ls-files ansible/roles/bootstrap/tasks/main.yml
wc -l ansible/roles/bootstrap/tasks/main.yml
cat -n ansible/roles/bootstrap/tasks/main.yml | sed -n '1,120p'

Repository: redhat-performance/JetBrew

Length of output: 3374


Select one default interface before building the NAT rule. (ansible/roles/bootstrap/tasks/main.yml:48-56) ip r | grep default | cut -d ' ' -f5 can return multiple or empty values depending on route output, which makes the iptables command invalid; parse the dev field from a single default route and fail when none is found.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ansible/roles/bootstrap/tasks/main.yml` around lines 48 - 56, Update the “get
default route” task to extract the interface following the dev field from
exactly one default route, and fail explicitly when no default interface is
found. Ensure the “masquerade on public interface” task uses that validated
single interface value when constructing the iptables command.

become: yes

- name: Setup observability operator
block:
- name: Copy observability operator subscription template
Expand Down
4 changes: 0 additions & 4 deletions ansible/roles/values-prep/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,10 +47,6 @@
become: yes
ignore_errors: yes

- name: set masquerade for the jump host
shell: |
iptables -t nat -A POSTROUTING -s 172.16.0.0/16 -o {{ iface_0 }} -j MASQUERADE

- name: get the common disk accros nodes
include_tasks: find-node-disks.yml

Expand Down
Loading