Skip to content

feat: open api ports from config reconciliation - #145

Open
ale8k wants to merge 1 commit into
juju:mainfrom
ale8k:open-api-ports-from-config
Open

feat: open api ports from config reconciliation#145
ale8k wants to merge 1 commit into
juju:mainfrom
ale8k:open-api-ports-from-config

Conversation

@ale8k

@ale8k ale8k commented Sep 10, 2026

Copy link
Copy Markdown

The controller application (jujud-controller) is the workload managed by this charm, so its externally reachable ports are a property of the charm rather than of Juju's controller config (as expressed by @SimonRichardson in this PR).

This adds charm config for the controller's ports and opens them via the charm, which lets operators restrict access with juju expose --to-cidrs which is something that isn't possible while the ports are opened by Juju's internal hardcoded firewall rules.

This is the charm side of the wider work to move controller port management out of Juju's hardcoded rules and onto the controller charm. There will be follow up work on the juju side will feed these config values at bootstrap, expose the controller app by default, have jujud read its ports from the charm, and remove the old hardcoded rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant