mgr/orchestrator: default NFS ingress to haproxy-protocol mode

Change default ingress mode from haproxy-standard to haproxy-protocol
to preserve client IP addresses for proper IP-level export restrictions
in NFS Ganesha.

Fixes: https://tracker.ceph.com/issues/74260

Signed-off-by: Shubha Jain <SHUBHA.JAIN1@ibm.com>
This commit is contained in:
Shubha Jain 2026-01-06 20:49:27 +05:30
parent 5715eac79a
commit 4a64b83c6c
No known key found for this signature in database
GPG Key ID: 7972A9C0B231F1C5

View File

@ -222,7 +222,9 @@ class IngressType(enum.Enum):
def canonicalize(self) -> "IngressType":
if self == self.default:
return IngressType(self.haproxy_standard)
# Default to haproxy-protocol to preserve client IP addresses
# for proper IP-level export restrictions in NFS Ganesha
return IngressType(self.haproxy_protocol)
return IngressType(self)
@ -2623,3 +2625,4 @@ Usage:
completion = self.update_service(service_type.value, service_type.name, image)
raise_if_exception(completion)
return HandleCommandResult(stdout=completion.result_str())