openshift-ansible: firewalld failure: Action org.fedoraproject.FirewallD1.config.info is not registered

Firewalld changes are failing frequently in runs. I see this 1/12 times in our runs (since we start 4 nodes I see it a lot).

https://ci.openshift.redhat.com/jenkins/job/test_pull_requests_origin_gce/203/consoleFull#-12808334605849c75fe4b0052e114d805c

TASK [os_firewall : Add firewalld allow rules] *********************************
Friday 27 January 2017  19:20:01 +0000 (0:00:00.042)       0:12:55.481 ******** 
changed: [ci-prtest203-ig-m-blwm] => (item={u'port': u'10250/tcp', u'service': u'Kubernetes kubelet'})
changed: [ci-prtest203-ig-n-pk5d] => (item={u'port': u'10250/tcp', u'service': u'Kubernetes kubelet'})
An exception occurred during task execution. To see the full traceback, use -vvv. The error was: dbus.exceptions.DBusException: org.freedesktop.PolicyKit1.Error.Failed: Action org.fedoraproject.FirewallD1.config.info is not registered
failed: [ci-prtest203-ig-n-wrn3] (item={u'port': u'10250/tcp', u'service': u'Kubernetes kubelet'}) => {"failed": true, "item": {"port": "10250/tcp", "service": "Kubernetes kubelet"}, "module_stderr": "Traceback (most recent call last):\n  File \"/tmp/ansible_DmBAt7/ansible_module_firewalld.py\", line 641, in <module>\n    main()\n  File \"/tmp/ansible_DmBAt7/ansible_module_firewalld.py\", line 489, in main\n    is_enabled = get_port_enabled(zone, [port,protocol])\n  File \"/tmp/ansible_DmBAt7/ansible_module_firewalld.py\", line 155, in get_port_enabled\n    if port_proto in fw.getPorts(zone):\n  File \"<string>\", line 2, in getPorts\n  File \"/usr/lib/python2.7/site-packages/slip/dbus/polkit.py\", line 103, in _enable_proxy\n    return func(*p, **k)\n  File \"<string>\", line 2, in getPorts\n  File \"/usr/lib/python2.7/site-packages/firewall/client.py\", line 53, in handle_exceptions\n    return func(*args, **kwargs)\n  File \"/usr/lib/python2.7/site-packages/firewall/client.py\", line 2754, in getPorts\n    return dbus_to_python(self.fw_zone.getPorts(zone))\n  File \"/usr/lib/python2.7/site-packages/slip/dbus/proxies.py\", line 50, in __call__\n    return dbus.proxies._ProxyMethod.__call__(self, *args, **kwargs)\n  File \"/usr/lib64/python2.7/site-packages/dbus/proxies.py\", line 145, in __call__\n    **keywords)\n  File \"/usr/lib64/python2.7/site-packages/dbus/connection.py\", line 651, in call_blocking\n    message, timeout)\ndbus.exceptions.DBusException: org.freedesktop.PolicyKit1.Error.Failed: Action org.fedoraproject.FirewallD1.config.info is not registered\n", "module_stdout": "", "msg": "MODULE FAILURE"}

About this issue

  • Original URL
  • State: closed
  • Created 7 years ago
  • Comments: 20 (16 by maintainers)

Most upvoted comments

I’m hitting this issue

sudo cat /var/log/firewalld
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -D OUTPUT -m addrtype --dst-type LOCAL ! --dst 127.0.0.0/8 -j DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -D OUTPUT -m addrtype --dst-type LOCAL -j DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -D PREROUTING' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -D OUTPUT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -F DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -X DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -F DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -X DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -F DOCKER-ISOLATION' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -X DOCKER-ISOLATION' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -n -L DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -n -L DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -n -L DOCKER-ISOLATION' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C DOCKER-ISOLATION -j RETURN' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C DOCKER -i docker0 -j RETURN' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -D FORWARD -i docker0 -o docker0 -j DROP' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -i docker0 -o docker0 -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -i docker0 ! -o docker0 -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C PREROUTING -m addrtype --dst-type LOCAL -j DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C OUTPUT -m addrtype --dst-type LOCAL -j DOCKER ! --dst 127.0.0.0/8' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -o docker0 -j DOCKER' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -j DOCKER-ISOLATION' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t nat -C DOCKER -i docker0 -j RETURN' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -D FORWARD -i docker0 -o docker0 -j DROP' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -i docker0 -o docker0 -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -i docker0 ! -o docker0 -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT' failed:
2017-03-15 10:27:15 WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w2 -t filter -C FORWARD -o docker0 -j DOCKER' failed:

is there anything I can do on the host?