Juju models have the firewall-mode option, and Juju client has the list-firewall-rules and set-firewall-rule commands. However, I can’t find if a specific security group could be added to all the units within a model (or controller).
For example, in “firewall-mode=instance”, new security groups will be created in OpenStack. Besides that, I’d like to include a custom secgroup. I understand the global model secgroup would be enough in almost any circunstance, but a network equipment the OpenStack infrastructure is tagged to needs the “default” secgroup to be added in order to make routing properly work.