Skip to content

network: add default isolated offering with source NAT and egress allowed by default - #14286

Open
weizhouapache wants to merge 1 commit into
apache:mainfrom
weizhouapache:24-add-default-network-offering-egress-allowed
Open

weizhouapache wants to merge 1 commit into
apache:mainfrom
weizhouapache:24-add-default-network-offering-egress-allowed

Conversation

@weizhouapache

Copy link
Copy Markdown
Member

Description

This PR adds a new default network offering,
DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an isolated offering with the SourceNat service whose default egress policy allows traffic, so VMs on it can reach outbound networks without an explicit egress rule.

  • NetworkOffering: declare the offering's unique name constant.
  • NetworkOrchestrator: create the offering (Availability.Optional, egressDefaultPolicy=true) on zones that do not have it yet.
  • ConfigurationServerImpl: create the offering, its service map, and set its state to Enabled with VM autoscaling and egress-default-policy support during first-time setup.
  • NetworkOfferingVO: rename the egressdefaultpolicy field to egressDefaultPolicy and add a setter so the policy can be set before the offering is persisted.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

…owed by default

Adds a new default network offering,
DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed: an
isolated offering with the SourceNat service whose default egress policy
allows traffic, so VMs on it can reach outbound networks without an
explicit egress rule.

- NetworkOffering: declare the offering's unique name constant.
- NetworkOrchestrator: create the offering (Availability.Optional,
  egressDefaultPolicy=true) on zones that do not have it yet.
- ConfigurationServerImpl: create the offering, its service map, and set
  its state to Enabled with VM autoscaling and egress-default-policy
  support during first-time setup.
- NetworkOfferingVO: rename the egressdefaultpolicy field to
  egressDefaultPolicy and add a setter so the policy can be set before
  the offering is persisted.
@weizhouapache

Copy link
Copy Markdown
Member Author

@andrijapanicsb
what's your opinion on adding a new network offering, instead of changing the default network offering ?

cc @DaanHoogland @nvazquez

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The upgrade creation path incorrectly leaves VM autoscaling disabled and lacks regression coverage.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds a default isolated network offering that permits egress traffic while providing Source NAT.

Changes:

  • Declares and creates the new offering during bootstrap and orchestration.
  • Enables egress-by-default and VM autoscaling support.
  • Renames the persisted Java field and adds a setter.
File Description
NetworkOffering.java Defines the offering’s unique name.
NetworkOfferingVO.java Renames and exposes the egress policy field.
NetworkOrchestrator.java Creates the offering when absent.
ConfigurationServerImpl.java Bootstraps the offering and service mappings.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +641 to +644
offering = _configMgr.createNetworkOffering(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed,
"Offering for Isolated networks with Source Nat service enabled and egress traffic allowed by default", TrafficType.Guest, null, false, Availability.Optional, null,
defaultIsolatedSourceNatEnabledNetworkOfferingProviders, true, Network.GuestType.Isolated, false, null, true, null, false, false, null, true, null,
true, false, false, false, false, null, null, null, true, null, null, false);
}

//#4-2 - default isolated offering with Source nat service and egress traffic allowed by default
if (_networkOfferingDao.findByUniqueName(NetworkOffering.DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed) == null) {
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 10.00000% with 18 lines in your changes missing coverage. Please review.
✅ Project coverage is 19.91%. Comparing base (1a48a87) to head (622b023).

Files with missing lines Patch % Lines
...java/com/cloud/server/ConfigurationServerImpl.java 0.00% 11 Missing ⚠️
...in/java/com/cloud/offerings/NetworkOfferingVO.java 33.33% 4 Missing ⚠️
...tack/engine/orchestration/NetworkOrchestrator.java 0.00% 3 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main   #14286      +/-   ##
============================================
- Coverage     19.91%   19.91%   -0.01%     
+ Complexity    20199    20197       -2     
============================================
  Files          6373     6373              
  Lines        577230   577246      +16     
  Branches      70696    70697       +1     
============================================
- Hits         114950   114935      -15     
- Misses       449713   449749      +36     
+ Partials      12567    12562       -5     
Flag Coverage Δ
uitests 3.71% <ø> (ø)
unittests 21.18% <10.00%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19372

@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@DaanHoogland DaanHoogland left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clgtm

public static final String DEFAULT_ROUTED_NSX_OFFERING = "DefaultRoutedNSXNetworkOffering";
public final static String QuickCloudNoServices = "QuickCloudNoServices";
public final static String DefaultIsolatedNetworkOfferingWithSourceNatService = "DefaultIsolatedNetworkOfferingWithSourceNatService";
public final static String DefaultIsolatedNetworkOfferingWithSourceNatServiceDefaultEgressAllowed = "DefaultIsolatedNetworkOfferingWithSourceNatServiceEgressAllowed";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

any reason for the extra "Default" in the name?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as all other built-in offerings start with Default

image

@weizhouapache

Copy link
Copy Markdown
Member Author

checked the testing env

image

and

image

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants