summaryrefslogtreecommitdiff
path: root/openstack/etc/neutron/rootwrap.d/l3.filters
diff options
context:
space:
mode:
Diffstat (limited to 'openstack/etc/neutron/rootwrap.d/l3.filters')
-rw-r--r--openstack/etc/neutron/rootwrap.d/l3.filters48
1 files changed, 0 insertions, 48 deletions
diff --git a/openstack/etc/neutron/rootwrap.d/l3.filters b/openstack/etc/neutron/rootwrap.d/l3.filters
deleted file mode 100644
index be69b32c..00000000
--- a/openstack/etc/neutron/rootwrap.d/l3.filters
+++ /dev/null
@@ -1,48 +0,0 @@
-# neutron-rootwrap command filters for nodes on which neutron is
-# expected to control network
-#
-# This file should be owned by (and only-writeable by) the root user
-
-# format seems to be
-# cmd-name: filter-name, raw-command, user, args
-
-[Filters]
-
-# arping
-arping: CommandFilter, arping, root
-
-# l3_agent
-sysctl: CommandFilter, sysctl, root
-route: CommandFilter, route, root
-radvd: CommandFilter, radvd, root
-
-# metadata proxy
-metadata_proxy: CommandFilter, neutron-ns-metadata-proxy, root
-# If installed from source (say, by devstack), the prefix will be
-# /usr/local instead of /usr/bin.
-metadata_proxy_local: CommandFilter, /usr/local/bin/neutron-ns-metadata-proxy, root
-# RHEL invocation of the metadata proxy will report /usr/bin/python
-kill_metadata: KillFilter, root, python, -9
-kill_metadata7: KillFilter, root, python2.7, -9
-kill_radvd_usr: KillFilter, root, /usr/sbin/radvd, -9, -HUP
-kill_radvd: KillFilter, root, /sbin/radvd, -9, -HUP
-
-# ip_lib
-ip: IpFilter, ip, root
-ip_exec: IpNetnsExecFilter, ip, root
-
-# ovs_lib (if OVSInterfaceDriver is used)
-ovs-vsctl: CommandFilter, ovs-vsctl, root
-
-# iptables_manager
-iptables-save: CommandFilter, iptables-save, root
-iptables-restore: CommandFilter, iptables-restore, root
-ip6tables-save: CommandFilter, ip6tables-save, root
-ip6tables-restore: CommandFilter, ip6tables-restore, root
-
-# Keepalived
-keepalived: CommandFilter, keepalived, root
-kill_keepalived: KillFilter, root, /usr/sbin/keepalived, -HUP, -15, -9
-
-# l3 agent to delete floatingip's conntrack state
-conntrack: CommandFilter, conntrack, root