Repository navigation
Allow editting or removing "CIDR list" from Load Balancer rule #9313
Description
Activity
@GutoVeronezi ah, ok, I wasn't aware it was a relatively new thing reintroduced by yourselves. It's a nice little feature.
@GutoVeronezi my apologies, I've had another go at this and indeed, the CIDRs do get whitelisted in haproxy.cfg - my problem is that I was looking for the CIDRs in the firewall, didn't realise it's a config thing. /facepalm
That said, I've already found a problem, I added a cidrlist when creating the LB on an isolated network and now I realise I cannot change or remove that, it's set in stone so to say, unless I recreate the LB. I hope this will be addressed in the future.
I've tested on 4.19.0.0 btw.@NuxRo , does this mean the original description of the issue is to be changed?
The API
updateLoadBalancerRulealso lacks a parametercidrlistto be able to modify (or indeed: empty) the list.@NuxRo , does this mean the original description of the issue is to be changed?
@DaanHoogland yes, the issue is more "Allow load balancer rule CIDR list to be modified"
Reacted by dahn- moved this from Todo to No status in deprecated: Apache CloudStack - Issues Aug'2024
on Aug 14, 2024 9 remaining items
@DaanHoogland @NuxRo What a strange decision. Deleting and recreating a LB rule also involves having to reattach any VMs that were attached to the LB rule. When using the API programmatically (not for UI use, but for a Kubernetes cloud provider f.e.), it would make a lot more sense to have the ability to update the CIDR list with one call, as opposed to at least 4.
* get list of vms associated with rule * delete the rule (detaches the VMs). In the mean time whatever service is exposed here will be unreachable. * recreate rule with new CIDR list * reattach the VMs acquired in step 1Even from a UI perspective being able to update the list would be an improvement.
Please reconsider this decision.
@hrak , it is closed as not planned, it is not refused, so if you wish to implement it anyway your code won't be refused.
Please note that there are more than 400 issues open so and everybody working on the code has their own priorities. We will be very selective about what we address. Sorry to disappoint you.
- added 2 commits that reference this issue
on Apr 29, 2025 - added 6 commits that reference this issue
on May 27, 2025 - added a commit that references this issue
on Sep 13, 2025
When creating a new load balancer in either Isolated network or VPC Tier there is this option "CIDR list" - supposedly to allow traffic from it automatically. It seems like a nice idea, but it doesn't do anything and it's just confusing people, also hashtag "polish".
Can we remove it from the UI as well as from the createLoadbalancerrule API call ("cidrlist")?
BTW, I'm on 4.19.