network: add default isolated offering with source NAT and egress allowed by default - #14286
weizhouapache wants to merge 1 commit into
Conversation
…owed by default Adds a new default network offering, DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an isolated offering with the SourceNat service whose default egress policy allows traffic, so VMs on it can reach outbound networks without an explicit egress rule. - NetworkOffering: declare the offering's unique name constant. - NetworkOrchestrator: create the offering (Availability.Optional, egressDefaultPolicy=true) on zones that do not have it yet. - ConfigurationServerImpl: create the offering, its service map, and set its state to Enabled with VM autoscaling and egress-default-policy support during first-time setup. - NetworkOfferingVO: rename the egressdefaultpolicy field to egressDefaultPolicy and add a setter so the policy can be set before the offering is persisted.
|
@andrijapanicsb |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The upgrade creation path incorrectly leaves VM autoscaling disabled and lacks regression coverage.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds a default isolated network offering that permits egress traffic while providing Source NAT.
Changes:
- Declares and creates the new offering during bootstrap and orchestration.
- Enables egress-by-default and VM autoscaling support.
- Renames the persisted Java field and adds a setter.
| File | Description |
|---|---|
NetworkOffering.java |
Defines the offering’s unique name. |
NetworkOfferingVO.java |
Renames and exposes the egress policy field. |
NetworkOrchestrator.java |
Creates the offering when absent. |
ConfigurationServerImpl.java |
Bootstraps the offering and service mappings. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| offering = _configMgr.createNetworkOffering(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed, | ||
| "Offering for Isolated networks with Source Nat service enabled and egress traffic allowed by default", TrafficType.Guest, null, false, Availability.Optional, null, | ||
| defaultIsolatedSourceNatEnabledNetworkOfferingProviders, true, Network.GuestType.Isolated, false, null, true, null, false, false, null, true, null, | ||
| true, false, false, false, false, null, null, null, true, null, null, false); |
| } | ||
|
|
||
| //#4-2 - default isolated offering with Source nat service and egress traffic allowed by default | ||
| if (_networkOfferingDao.findByUniqueName(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed) == null) { |
Codecov Report✅ All modified and coverable lines are covered by tests.
Additional details and impacted files@@ Coverage Diff @@
## main #14286 +/- ##
=============================================
- Coverage 19.91% 3.71% -16.21%
=============================================
Files 6373 487 -5886
Lines 577230 41992 -535238
Branches 70696 7942 -62754
=============================================
- Hits 114950 1558 -113392
+ Misses 449713 40208 -409505
+ Partials 12567 226 -12341
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|


Description
This PR adds a new default network offering,
DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an isolated offering with the SourceNat service whose default egress policy allows traffic, so VMs on it can reach outbound networks without an explicit egress rule.
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?