Skip to content

network: add default isolated offering with source NAT and egress allowed by default - #14286

Open
weizhouapache wants to merge 1 commit into
apache:mainfrom
weizhouapache:24-add-default-network-offering-egress-allowed
Open

weizhouapache wants to merge 1 commit into
apache:mainfrom
weizhouapache:24-add-default-network-offering-egress-allowed

Conversation

@weizhouapache

Copy link
Copy Markdown
Member

Description

This PR adds a new default network offering,
DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an isolated offering with the SourceNat service whose default egress policy allows traffic, so VMs on it can reach outbound networks without an explicit egress rule.

  • NetworkOffering: declare the offering's unique name constant.
  • NetworkOrchestrator: create the offering (Availability.Optional, egressDefaultPolicy=true) on zones that do not have it yet.
  • ConfigurationServerImpl: create the offering, its service map, and set its state to Enabled with VM autoscaling and egress-default-policy support during first-time setup.
  • NetworkOfferingVO: rename the egressdefaultpolicy field to egressDefaultPolicy and add a setter so the policy can be set before the offering is persisted.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

…owed by default

Adds a new default network offering,
DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an
isolated offering with the SourceNat service whose default egress policy
allows traffic, so VMs on it can reach outbound networks without an
explicit egress rule.

- NetworkOffering: declare the offering's unique name constant.
- NetworkOrchestrator: create the offering (Availability.Optional,
  egressDefaultPolicy=true) on zones that do not have it yet.
- ConfigurationServerImpl: create the offering, its service map, and set
  its state to Enabled with VM autoscaling and egress-default-policy
  support during first-time setup.
- NetworkOfferingVO: rename the egressdefaultpolicy field to
  egressDefaultPolicy and add a setter so the policy can be set before
  the offering is persisted.
@weizhouapache

Copy link
Copy Markdown
Member Author

@andrijapanicsb
what's your opinion on adding a new network offering, instead of changing the default network offering ?

cc @DaanHoogland @nvazquez

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The upgrade creation path incorrectly leaves VM autoscaling disabled and lacks regression coverage.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds a default isolated network offering that permits egress traffic while providing Source NAT.

Changes:

  • Declares and creates the new offering during bootstrap and orchestration.
  • Enables egress-by-default and VM autoscaling support.
  • Renames the persisted Java field and adds a setter.
File Description
NetworkOffering.java Defines the offering’s unique name.
NetworkOfferingVO.java Renames and exposes the egress policy field.
NetworkOrchestrator.java Creates the offering when absent.
ConfigurationServerImpl.java Bootstraps the offering and service mappings.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +641 to +644
offering = _configMgr.createNetworkOffering(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed,
"Offering for Isolated networks with Source Nat service enabled and egress traffic allowed by default", TrafficType.Guest, null, false, Availability.Optional, null,
defaultIsolatedSourceNatEnabledNetworkOfferingProviders, true, Network.GuestType.Isolated, false, null, true, null, false, false, null, true, null,
true, false, false, false, false, null, null, null, true, null, null, false);
}

//#4-2 - default isolated offering with Source nat service and egress traffic allowed by default
if (_networkOfferingDao.findByUniqueName(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed) == null) {
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 3.71%. Comparing base (1a48a87) to head (622b023).

❗ There is a different number of reports uploaded between BASE (1a48a87) and HEAD (622b023). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (1a48a87) HEAD (622b023)
unittests 1 0
Additional details and impacted files
@@              Coverage Diff              @@
##               main   #14286       +/-   ##
=============================================
- Coverage     19.91%    3.71%   -16.21%     
=============================================
  Files          6373      487     -5886     
  Lines        577230    41992   -535238     
  Branches      70696     7942    -62754     
=============================================
- Hits         114950     1558   -113392     
+ Misses       449713    40208   -409505     
+ Partials      12567      226    -12341     
Flag Coverage Δ
uitests 3.71% <ø> (ø)
unittests ?

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants