Re: Default Model SG Rules

2017-02-02 Thread James Beedy
Thanks for creating/sharing those bugs, it looks like the milestone got changed to "None" though ... I've created a new one here: https://bugs.launchpad.net/juju/+bug/1661275 Possibly you could link those in, and put some heat on it for me? On Sun, Jan 29, 2017 at 2:11 PM, Michael Nelson < mich

Re: Default Model SG Rules

2017-01-31 Thread Ian Booth
As part of the cross model relations work, the provider interface is being reworked such that Open/Close Port() API calls can now take as parameters ingress rules, ie a collection of port ranges and allowed source CIDRs. With the above work, it will be possible to use that new provider capability

Re: Default Model SG Rules

2017-01-29 Thread Michael Nelson
On Sat, Jan 28, 2017 at 4:34 AM James Beedy wrote: > A default SG rule generated for every model allows 22 from 0.0.0.0/0, I'm > guessing this is because we are trying to facilitate the use case for juju > deployed on a public cloud, and instances being ssh accessed from the > internet and not fr

Re: Default Model SG Rules

2017-01-27 Thread James Beedy
On Fri, Jan 27, 2017 at 9:45 AM, Samuel Cozannet < samuel.cozan...@canonical.com> wrote: > I am having similar questions / requests from other users, so +1 from me > (actually +3). Plus I like the sshallownes of ssh-allow. > > Another request I have heard is get the ability to associate an IAM rol

Re: Default Model SG Rules

2017-01-27 Thread Samuel Cozannet
I am having similar questions / requests from other users, so +1 from me (actually +3). Plus I like the sshallownes of ssh-allow. Another request I have heard is get the ability to associate an IAM role attached to the instances. Currently Juju doesn't attach any role to the instances, which means