Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
The getting started guide appears to have lost mention of disabling ufw #1142
Comments
ghost
commented
Jun 7, 2016
|
I've been bitten twice on this. First when I tried to bootstrap localhost on lxd. And then again after I had reenabled ufw when deploying a local charm. +1 |
ghost
commented
Jun 7, 2016
|
One of the reasons this is hard to debug is NOTHING get's printed to debug-log until the juju agent has initialized. |
|
If you can be explicit with how iptables/ufw interferes then we can fit something in. There was such a warning at one time ("turn off your firewall") but it was removed due to its bluntness and because nobody could explain it. The non-existent FAQ page is linked from getting-started-general. Please open a bug to get that fixed quickly. |
ghost
commented
Jun 7, 2016
|
Sure. lxdbr0 is open on 10.176.236.1 and if ufw is on the JuJu agent is blocked. The suggestion to turn it off is a non-advisable solution to enabling it (at best it's a quick litmus test to confirm the bug). Currently I use a rule to 'ALLOW' traffic 'Anywhere' across the address CIDR range 10.176.236.0/24. |
evilnick
added
2.0
high priority
labels
Jun 7, 2016
|
according to the LXD guys, the bridge setup script adds rules to iptables and there should be no conflict, except in the possible case where ufw is initialised while LXD is already running. I will put a note back in to cover this case. I think if there is something more systemic it should probably be addressed elsewhere |
ghost
commented
Jun 8, 2016
|
I see the iptable rules for lxdbr0. Do we know that the JuJu agent is operating within those rules? |
|
I have added a note #1186 . If there is some problem with the rules created, that would be a LXD bug. If there is some problem with Juju, that would be a Juju bug. |
chuckbutler commentedJun 7, 2016
•
Edited 1 time
-
chuckbutler
Jun 7, 2016
Its common for juju newbies to attempt bootstrapping a lxd controller without first disabling ufw. UFW will indeed cause some headaches.
It would be good to call this out in the docs so that new users who experience problems bootstrapping are given the opportunity to catch the pitfall themselves.
It does have a callout to a FAQ but that appears to 404
https://jujucharms.com/docs/devel/getting-started-faq/