From 70e706619fb291ef4d34ad4a02582b29208298ee Mon Sep 17 00:00:00 2001 From: Luis Tomas Bolivar Date: Mon, 24 Dec 2018 11:28:51 +0100 Subject: [PATCH] Avoid namespace isolation on LoadBalancer type svcs This patch ensures namespace isolation is not applied when svcs are of LoadBalancer type, regardless of the sg_mode (update or create) Closes-Bug: 1809649 Change-Id: I9af39073fd6546ec44b849be1c5d216ed9fe1f31 --- kuryr_kubernetes/controller/drivers/lbaasv2.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/kuryr_kubernetes/controller/drivers/lbaasv2.py b/kuryr_kubernetes/controller/drivers/lbaasv2.py index 570c5f402..3b592c42b 100644 --- a/kuryr_kubernetes/controller/drivers/lbaasv2.py +++ b/kuryr_kubernetes/controller/drivers/lbaasv2.py @@ -288,8 +288,7 @@ class LBaaSv2Driver(base.LBaaSDriver): if loadbalancer.provider == const.NEUTRON_LBAAS_HAPROXY_PROVIDER: self._ensure_lb_security_group_rule(loadbalancer, listener) - elif namespace_isolation and (service_type == 'ClusterIP' or - create_sg): + elif namespace_isolation and service_type == 'ClusterIP': self._extend_lb_security_group_rules(loadbalancer, listener) elif create_sg: self._create_lb_security_group_rule(loadbalancer, listener)