Skip to content

Allow editting or removing "CIDR list" from Load Balancer rule #9313

Description

@NuxRo

When creating a new load balancer in either Isolated network or VPC Tier there is this option "CIDR list" - supposedly to allow traffic from it automatically. It seems like a nice idea, but it doesn't do anything and it's just confusing people, also hashtag "polish".

Can we remove it from the UI as well as from the createLoadbalancerrule API call ("cidrlist")?
BTW, I'm on 4.19.

Selection_20240628-003

Activity

  1. GutoVeronezi commented on Jun 28, 2024

    @GutoVeronezi
    Contributor

    Hello @NuxRo

    The parameter was reintroduced in 4.18: in the API via #6460 and the UI via #6869. Therefore, it should work. Some manual tests and investigations are necessary to understand why it is not working.

  2. added this to the 4.19.2.0 milestone on Jul 1, 2024
  3. NuxRo commented on Jul 5, 2024

    @NuxRo
    ContributorAuthor

    @GutoVeronezi ah, ok, I wasn't aware it was a relatively new thing reintroduced by yourselves. It's a nice little feature.

  4. NuxRo commented on Jul 5, 2024

    @NuxRo
    ContributorAuthor

    @GutoVeronezi my apologies, I've had another go at this and indeed, the CIDRs do get whitelisted in haproxy.cfg - my problem is that I was looking for the CIDRs in the firewall, didn't realise it's a config thing. /facepalm

    That said, I've already found a problem, I added a cidrlist when creating the LB on an isolated network and now I realise I cannot change or remove that, it's set in stone so to say, unless I recreate the LB. I hope this will be addressed in the future.
    I've tested on 4.19.0.0 btw.

  5. DaanHoogland commented on Jul 8, 2024

    @DaanHoogland
    Contributor

    @NuxRo , does this mean the original description of the issue is to be changed?

  6. hrak commented on Aug 8, 2024

    @hrak
    Contributor

    The API updateLoadBalancerRule also lacks a parameter cidrlist to be able to modify (or indeed: empty) the list.

  7. hrak commented on Aug 8, 2024

    @hrak
    Contributor

    @NuxRo , does this mean the original description of the issue is to be changed?

    @DaanHoogland yes, the issue is more "Allow load balancer rule CIDR list to be modified"

  8. 9 remaining items

  9. DaanHoogland commented on Feb 7, 2025

    @DaanHoogland
    Contributor

    @DaanHoogland @NuxRo What a strange decision. Deleting and recreating a LB rule also involves having to reattach any VMs that were attached to the LB rule. When using the API programmatically (not for UI use, but for a Kubernetes cloud provider f.e.), it would make a lot more sense to have the ability to update the CIDR list with one call, as opposed to at least 4.

    * get list of vms associated with rule
    
    * delete the rule (detaches the VMs). In the mean time whatever service is exposed here will be unreachable.
    
    * recreate rule with new CIDR list
    
    * reattach the VMs acquired in step 1
    

    Even from a UI perspective being able to update the list would be an improvement.

    Please reconsider this decision.

    @hrak , it is closed as not planned, it is not refused, so if you wish to implement it anyway your code won't be refused.

    Please note that there are more than 400 issues open so and everybody working on the code has their own priorities. We will be very selective about what we address. Sorry to disappoint you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions