Skip to content

Commit 622b023

Browse files
committed
network: add default isolated offering with source NAT and egress allowed by default
Adds a new default network offering, DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an isolated offering with the SourceNat service whose default egress policy allows traffic, so VMs on it can reach outbound networks without an explicit egress rule. - NetworkOffering: declare the offering's unique name constant. - NetworkOrchestrator: create the offering (Availability.Optional, egressDefaultPolicy=true) on zones that do not have it yet. - ConfigurationServerImpl: create the offering, its service map, and set its state to Enabled with VM autoscaling and egress-default-policy support during first-time setup. - NetworkOfferingVO: rename the egressdefaultpolicy field to egressDefaultPolicy and add a setter so the policy can be set before the offering is persisted.
1 parent 1a48a87 commit 622b023

4 files changed

Lines changed: 36 additions & 6 deletions

File tree

‎api/src/main/java/com/cloud/offering/NetworkOffering.java‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,7 @@ enum RoutingMode {
7070
public static final String DEFAULT_ROUTED_NSX_OFFERING = "DefaultRoutedNSXNetworkOffering";
7171
public final static String QuickCloudNoServices = "QuickCloudNoServices";
7272
public final static String DefaultIsolatedNetworkOfferingWithSourceNatService = "DefaultIsolatedNetworkOfferingWithSourceNatService";
73+
public final static String DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed = "DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed";
7374
public final static String OvsIsolatedNetworkOfferingWithSourceNatService = "OvsIsolatedNetworkOfferingWithSourceNatService";
7475
public final static String DefaultSharedNetworkOffering = "DefaultSharedNetworkOffering";
7576
public final static String DefaultIsolatedNetworkOffering = "DefaultIsolatedNetworkOffering";

‎engine/orchestration/src/main/java/org/apache/cloudstack/engine/orchestration/NetworkOrchestrator.java‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -636,6 +636,14 @@ public void doInTransactionWithoutResult(final TransactionStatus status) {
636636
true, false, false, false, false, null, null, null, true, null, null, false);
637637
}
638638

639+
//#4-2 - default isolated offering with Source nat service and egress traffic allowed by default
640+
if (_networkOfferingDao.findByUniqueName(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed) == null) {
641+
offering = _configMgr.createNetworkOffering(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed,
642+
"Offering for Isolated networks with Source Nat service enabled and egress traffic allowed by default", TrafficType.Guest, null, false, Availability.Optional, null,
643+
defaultIsolatedSourceNatEnabledNetworkOfferingProviders, true, Network.GuestType.Isolated, false, null, true, null, false, false, null, true, null,
644+
true, false, false, false, false, null, null, null, true, null, null, false);
645+
}
646+
639647
//#5 - default vpc offering with LB service
640648
if (_networkOfferingDao.findByUniqueName(NetworkOffering.DefaultIsolatedNetworkOfferingForVpcNetworks) == null) {
641649
offering = _configMgr.createNetworkOffering(NetworkOffering.DefaultIsolatedNetworkOfferingForVpcNetworks,

‎engine/schema/src/main/java/com/cloud/offerings/NetworkOfferingVO.java‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -138,7 +138,7 @@ public class NetworkOfferingVO implements NetworkOffering {
138138
NetworkMode networkMode;
139139

140140
@Column(name = "egress_default_policy")
141-
boolean egressdefaultpolicy;
141+
boolean egressDefaultPolicy;
142142

143143
@Column(name = "concurrent_connections")
144144
Integer concurrentConnections;
@@ -343,12 +343,16 @@ public void setRedundantRouter(boolean redundantRouter) {
343343

344344
@Override
345345
public boolean isEgressDefaultPolicy() {
346-
return egressdefaultpolicy;
346+
return egressDefaultPolicy;
347+
}
348+
349+
public void setEgressDefaultPolicy(boolean egressDefaultPolicy) {
350+
this.egressDefaultPolicy = egressDefaultPolicy;
347351
}
348352

349353
public NetworkOfferingVO(String name, String displayText, TrafficType trafficType, boolean systemOnly, boolean specifyVlan, Integer rateMbps,
350-
Integer multicastRateMbps, boolean isDefault, Availability availability, String tags, Network.GuestType guestType, boolean conserveMode,
351-
boolean specifyIpRanges, boolean isPersistent, boolean internalLb, boolean publicLb, boolean isForVpc) {
354+
Integer multicastRateMbps, boolean isDefault, Availability availability, String tags, Network.GuestType guestType, boolean conserveMode,
355+
boolean specifyIpRanges, boolean isPersistent, boolean internalLb, boolean publicLb, boolean isForVpc) {
352356
this.name = name;
353357
this.displayText = displayText;
354358
this.rateMbps = rateMbps;
@@ -404,7 +408,7 @@ public NetworkOfferingVO(String name, String displayText, TrafficType trafficTyp
404408
this.elasticLb = elasticLb;
405409
this.inline = inline;
406410
this.eipAssociatePublicIp = associatePublicIP;
407-
this.egressdefaultpolicy = egressdefaultpolicy;
411+
this.egressDefaultPolicy = egressdefaultpolicy;
408412
this.supportsStrechedL2 = supportsStrechedL2;
409413
this.supportsPublicAccess = supportsPublicAccess;
410414
}

‎server/src/main/java/com/cloud/server/ConfigurationServerImpl.java‎

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1070,12 +1070,29 @@ public void doInTransactionWithoutResult(TransactionStatus status) {
10701070
defaultIsolatedSourceNatEnabledNetworkOffering.setSupportsVmAutoScaling(true);
10711071
defaultIsolatedSourceNatEnabledNetworkOffering = _networkOfferingDao.persistDefaultNetworkOffering(defaultIsolatedSourceNatEnabledNetworkOffering);
10721072

1073+
// Offering #3-2
1074+
NetworkOfferingVO defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed =
1075+
new NetworkOfferingVO(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed,
1076+
"Offering for Isolated networks with Source Nat service enabled and egress traffic allowed by default", TrafficType.Guest, false, false, null, null, true, Availability.Optional, null,
1077+
Network.GuestType.Isolated, true, false, false, false, true, false);
1078+
1079+
defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed.setState(NetworkOffering.State.Enabled);
1080+
defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed.setSupportsVmAutoScaling(true);
1081+
defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed.setEgressDefaultPolicy(true);
1082+
defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed = _networkOfferingDao.persistDefaultNetworkOffering(defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed);
1083+
10731084
for (Service service : defaultIsolatedSourceNatEnabledNetworkOfferingProviders.keySet()) {
10741085
NetworkOfferingServiceMapVO offService =
10751086
new NetworkOfferingServiceMapVO(defaultIsolatedSourceNatEnabledNetworkOffering.getId(), service,
10761087
defaultIsolatedSourceNatEnabledNetworkOfferingProviders.get(service));
10771088
_ntwkOfferingServiceMapDao.persist(offService);
1078-
logger.trace("Added service for the network offering: " + offService);
1089+
logger.trace("Added service {} for the network offering: {}", offService, defaultIsolatedSourceNatEnabledNetworkOffering.getUniqueName());
1090+
1091+
offService =
1092+
new NetworkOfferingServiceMapVO(defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed.getId(), service,
1093+
defaultIsolatedSourceNatEnabledNetworkOfferingProviders.get(service));
1094+
_ntwkOfferingServiceMapDao.persist(offService);
1095+
logger.trace("Added service {} for the network offering: {}", offService, defaultIsolatedSourceNatEnabledNetworkOfferingWithDefaultEgressAllowed.getUniqueName());
10791096
}
10801097

10811098
// Offering #4

0 commit comments

Comments
 (0)