Juju openstack provider: set extra security group for all instances

Hi,

Juju models have the firewall-mode option, and Juju client has the list-firewall-rules and set-firewall-rule commands. However, I can’t find if a specific security group could be added to all the units within a model (or controller).

For example, in “firewall-mode=instance”, new security groups will be created in OpenStack. Besides that, I’d like to include a custom secgroup. I understand the global model secgroup would be enough in almost any circunstance, but a network equipment the OpenStack infrastructure is tagged to needs the “default” secgroup to be added in order to make routing properly work.

Thank you,
-Alvaro.

My bad. The configuring-models doc doesn’t show the same config parameters as juju model-config.

A special parameter use-default-secgroup can be enabled to force the use of the default secgroup together with the custom Juju secgroups.

Nevertheless, this question is still valid if we would want a different secgroup to be added by default on a Juju model.

Thank you,
-Alvaro.