Skip to content

Netris: Improvements and fixes to the Netris plugin - #13591

Open
Pearl1594 wants to merge 16 commits into
4.22from
netris-improvements
Open

Pearl1594 wants to merge 16 commits into
4.22from
netris-improvements

Conversation

@Pearl1594

@Pearl1594 Pearl1594 commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR addresses the following for Netris:

  • Support NAT, PF for Secondary IP
  • Support for L2 networks
  • CKS Support
  • Fix allocate vnets with the correct account ID so that release succeeds on network deletion
  • Add support to include VPN service for NATTED Netris offerings
  • Support Redundant Virtual Routers for Netris VPC networks
  • Enable autoscaling groups for Netris network offerings
  • Prevent re-adding ACLs
  • Add check for vnet name length and cleanup vpc and vnet resources on failure of creation of allocation
  • Add support to the VPC response to display if redundant routers are supported
  • Hide VPN sections and prevent enabling it when service isn't enabled in the vpc offering
  • Fix issue with adding external node to a CKS cluster with Netris offering
  • Update upgrade path to reclaim vnets of deleted netris networks, improve log and hide add upstream route for Netris routed networks
  • Allocate IP from Netris (Provider) range when IP is not specified during associate
  • Prevent VRRP gateway IP conflict on redundant VPC routers with external network providers (Netris/NSX)
  • VPN: Reconfigure static nat and static route on fail over to backup VR - for redundant VPC VRs
  • Fix issue with deletion of vpn connection for DualStack redundant VPCs

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

Pearl1594 and others added 8 commits July 10, 2026 10:13
* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

* Add a check to prevent re-adding existing ACLs

* Add a check to prevent re-adding existing ACLs

* change message compare statement

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
…failure of creation of allocation

* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

* Add a check to prevent re-adding existing ACLs

* Add a check to prevent re-adding existing ACLs

* change message compare statement

* Add check for vnet name length and cleanup vpc and vnet resources on failure of creation of allocation

* add name length validation to update path

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
…upported

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…in the vpc offering

* Hide VPN sections and prevent enabling it when service isn't enabled in the vpc offering

* update

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ring

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ove log and hide add upstream route for Netris routed networks

* Update upgrade path to reclaim vnets of deleted netris networks, improve log and hide add upstream route for Netris routed networks

* Apply suggestions from code review

* hide upstream route banner for netris networks altogether

* fix migration of netris VRs and fix reclaim vnet query

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: Nicolas Vazquez <nicovazquez90@gmail.com>
…ing associate

* Allocate IP from Netris (Provider) range when IP is not specified during associate

* update javadoc and method name

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
@codecov

codecov Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 6.10329% with 600 lines in your changes missing coverage. Please review.
✅ Project coverage is 17.99%. Comparing base (2e63c60) to head (f8669aa).

Files with missing lines Patch % Lines
...apache/cloudstack/service/NetrisApiClientImpl.java 0.00% 237 Missing ⚠️
...che/cloudstack/service/NetrisGuestNetworkGuru.java 14.28% 64 Missing and 8 partials ⚠️
...r/actionworkers/KubernetesClusterActionWorker.java 8.00% 46 Missing ⚠️
...er/actionworkers/KubernetesClusterStartWorker.java 0.00% 35 Missing ⚠️
.../actionworkers/KubernetesClusterDestroyWorker.java 0.00% 27 Missing ⚠️
...ain/java/com/cloud/network/vpc/VpcManagerImpl.java 0.00% 27 Missing ⚠️
...bernetes/cluster/KubernetesClusterManagerImpl.java 0.00% 22 Missing ⚠️
...er/actionworkers/KubernetesClusterScaleWorker.java 0.00% 18 Missing ⚠️
...ck/api/command/admin/vpc/CreateVPCOfferingCmd.java 0.00% 15 Missing ⚠️
...n/java/com/cloud/network/IpAddressManagerImpl.java 0.00% 15 Missing ⚠️
... and 17 more
Additional details and impacted files
@@             Coverage Diff              @@
##               4.22   #13591      +/-   ##
============================================
- Coverage     18.00%   17.99%   -0.02%     
- Complexity    16219    16225       +6     
============================================
  Files          5936     5936              
  Lines        535716   536200     +484     
  Branches      65596    65677      +81     
============================================
+ Hits          96459    96477      +18     
- Misses       428268   428724     +456     
- Partials      10989    10999      +10     
Flag Coverage Δ
uitests 4.02% <ø> (-0.01%) ⬇️
unittests 19.06% <6.10%> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18533

@nvazquez
nvazquez requested a review from kiranchavala July 10, 2026 17:26
@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-16528)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 52917 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t16528-kvm-ol8.zip
Smoke tests completed. 148 look OK, 1 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
ContextSuite context=TestSharedNetworkWithConfigDrive>:setup Error 48.34 test_network.py

@boring-cyborg boring-cyborg Bot added component:virtual-router Python Warning... Python code Ahead! labels Jul 24, 2026
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
4.6% Coverage on New Code (required ≥ 40%)

See analysis details on SonarQube Cloud

@DaanHoogland DaanHoogland moved this from Backlog to conflict/waiting in CloudStack Testing Aug 31, 2026
@Pearl1594

Copy link
Copy Markdown
Contributor Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19255

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

2 similar comments
@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19343

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@nvazquez
nvazquez marked this pull request as ready for review September 29, 2026 14:27
@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17039)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 53722 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t17039-kvm-ol8.zip
Smoke tests completed. 146 look OK, 3 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
ContextSuite context=TestClusterDRS>:setup Error 0.00 test_cluster_drs.py
test_list_system_vms_metrics_history Failure 0.27 test_metrics_api.py
test_02_L2_persistent_network Failure 102.00 test_persistent_network.py
test_03_deploy_and_destroy_VM_and_verify_network_resources_persist Failure 142.86 test_persistent_network.py

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19359

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
4.3% Coverage on New Code (required ≥ 40%)

See analysis details on SonarQube Cloud

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
@nvazquez

nvazquez commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19365

@nvazquez

nvazquez commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

L2 offering creation, mixed-zone IP allocation, legacy static-NAT handling, and failure cleanup contain unresolved correctness issues.

Review effort: Balanced
Findings: 3 High severity · 6 Medium severity

Open (9)
What changed in this PR

Expands Netris networking support across offerings, VPCs, L2 networks, VPN, redundant routers, Kubernetes, IP allocation, and resource cleanup.

Changes:

  • Adds Netris L2, VPN, secondary-IP NAT/PF, autoscaling, and redundant-router support.
  • Improves Netris resource naming, allocation, rollback, and upgrade cleanup.
  • Integrates Netris networking with CKS and updates related UI behavior.
File Description
ui/​src/​views/​offering/​AddVpcOffering.vue Adds Netris VPN and redundant-router options.
ui/​src/​views/​offering/​AddNetworkOffering.vue Adds L2, VPN, and autoscaling controls.
ui/​src/​views/​network/​VpnDetails.vue Gates VPN actions by VPC service support.
ui/​src/​views/​network/​VpcTab.vue Hides unsupported VPN tabs.
ui/​src/​views/​infra/​zone/​AdvancedGuestTrafficForm.vue Adds Netris VNI limits.
ui/​src/​config/​section/​offering.js Displays redundant-router capability.
ui/​src/​config/​section/​network.js Filters VPN views by service.
ui/​src/​components/​view/​DetailsTab.vue Hides upstream routes for Netris.
systemvm/​debian/​opt/​cloud/​bin/​cs/​CsAddress.py Avoids conflicting VRRP gateways.
server/​src/​test/​java/​org/​apache/​cloudstack/​service/​NetrisServiceMockTest.java Updates Netris service mock signatures.
server/​src/​main/​java/​com/​cloud/​network/​vpn/​Site2SiteVpnManagerImpl.java Validates VPC VPN support.
server/​src/​main/​java/​com/​cloud/​network/​vpn/​RemoteAccessVpnManagerImpl.java Validates remote-access VPN support.
server/​src/​main/​java/​com/​cloud/​network/​vpc/​VpcManagerImpl.java Handles redundant VPC router failover.
server/​src/​main/​java/​com/​cloud/​network/​router/​VirtualNetworkApplianceManagerImpl.java Reapplies Netris rules after failover.
server/​src/​main/​java/​com/​cloud/​network/​NetworkModelImpl.java Adjusts IP service handling for Netris.
server/​src/​main/​java/​com/​cloud/​network/​IpAddressManagerImpl.java Selects Netris-reserved IP ranges.
server/​src/​main/​java/​com/​cloud/​network/​guru/​GuestNetworkGuru.java Changes Netris VNET release behavior.
server/​src/​main/​java/​com/​cloud/​api/​query/​dao/​VpcOfferingJoinDaoImpl.java Populates redundant-router response data.
plugins/​network-elements/​netris/​src/​test/​java/​org/​apache/​cloudstack/​service/​NetrisGuestNetworkGuruTest.java Tests network modes and protocols.
plugins/​network-elements/​netris/​src/​test/​java/​org/​apache/​cloudstack/​service/​NetrisElementTest.java Updates vNet deletion test.
plugins/​network-elements/​netris/​src/​test/​java/​org/​apache/​cloudstack/​resource/​NetrisResourceObjectUtilsTest.java Tests unique static-NAT names.
plugins/​network-elements/​netris/​src/​test/​java/​org/​apache/​cloudstack/​agent/​api/​CreateNetrisVnetCommandTest.java Tests new command attributes.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​service/​NetrisServiceImpl.java Propagates L2 and protocol metadata.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​service/​NetrisPublicNetworkGuru.java Normalizes legacy network modes.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​service/​NetrisGuestNetworkGuru.java Implements L2 and VNET lifecycle changes.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​service/​NetrisElement.java Adds gateway capabilities and secondary-IP PF.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​service/​NetrisApiClientImpl.java Implements resource lifecycle and NAT changes.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​resource/​NetrisResourceObjectUtils.java Adds name validation and mode normalization.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​agent/​api/​NetrisCommand.java Adds the L2 command flag.
plugins/​network-elements/​netris/​src/​main/​java/​org/​apache/​cloudstack/​agent/​api/​CreateNetrisVnetCommand.java Carries network mode and protocol.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​KubernetesClusterManagerImpl.java Adds a default Netris CKS offering.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​actionworkers/​KubernetesClusterStartWorker.java Provisions distinct Netris LB/NAT IPs.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​actionworkers/​KubernetesClusterScaleWorker.java Updates Netris scaling rules.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​actionworkers/​KubernetesClusterResourceModifierActionWorker.java Adds Netris-specific CKS rules.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​actionworkers/​KubernetesClusterDestroyWorker.java Cleans up Netris CKS resources.
plugins/​integrations/​kubernetes-service/​src/​main/​java/​com/​cloud/​kubernetes/​cluster/​actionworkers/​KubernetesClusterActionWorker.java Manages separate API and NAT addresses.
engine/​schema/​src/​main/​resources/​META-INF/​db/​schema-42200to42210.sql Reclaims deleted Netris VNET allocations.
engine/​schema/​src/​main/​java/​com/​cloud/​vm/​dao/​NicDaoImpl.java Filters placeholder router NICs.
engine/​schema/​src/​main/​java/​com/​cloud/​vm/​dao/​NicDao.java Updates the NIC DAO contract.
engine/​orchestration/​src/​main/​java/​org/​apache/​cloudstack/​engine/​orchestration/​NetworkOrchestrator.java Adjusts migration and L2 handling.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​VpcOfferingResponse.java Exposes redundant-router support.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​command/​utils/​OfferingUtils.java Centralizes Netris detection.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​command/​admin/​vpc/​CreateVPCOfferingCmd.java Adds Netris VPN and capability handling.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​command/​admin/​network/​CreateNetworkOfferingCmd.java Adds VPN to Netris offerings.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​ApiConstants.java Defines the Netris NAT IP detail key.
api/​src/​main/​java/​com/​cloud/​network/​netris/​NetrisService.java Extends the vNet lifecycle API.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +398 to +405
if (existingNatRule == null && "STATICNAT".equals(cmd.getNatRuleType())) {
String legacyName = getLegacyStaticNatRuleName(natRuleName);
if (legacyName != null) {
logger.debug("Static NAT rule not found with name '{}', falling back to legacy name '{}'", natRuleName, legacyName);
existingNatRule = netrisNatRuleExists(legacyName);
if (existingNatRule != null) {
natRuleName = legacyName;
}
Comment on lines +1712 to +1716
// Backward compatibility: rule with legacy naming convention (no public IP post-fixed) exists - don't create a duplicate
String legacyName = getLegacyStaticNatRuleName(staticNatRuleName);
if (legacyName != null && netrisNatRuleExists(legacyName) != null) {
logger.debug("Legacy static NAT rule '{}' already exists on Netris, skipping creation of '{}'", legacyName, staticNatRuleName);
return true;
Comment on lines +1462 to +1464
// Only steer the range when no explicit IP was requested: an explicit ipaddress is already
// validated against the provider's pool above by checkPublicIpOnExternalProviderZone.
final List<Long> vlanDbIds = ipaddress == null ? getNetrisVlanDbIds(zone) : null;
Comment on lines +3185 to +3188
* Checks for L2 network offering services. Only 3 cases allowed:
* - No services
* - User Data service only, provided by ConfigDrive
* - UserData service only, provided by ConfigDrive
* - Connectivity service only, provided by Netris
Comment on lines +334 to +337
VPCListing existingNetrisVpc = getVpcByNameAndTenant(netrisVpcName);
if (existingNetrisVpc != null) {
logger.info("Netris VPC {} already exists, skipping creation", netrisVpcName);
return true;
Comment on lines +1309 to +1312
if (!isL2) {
rollbackVnetResources(associatedVpc, netrisSubnetName, netrisV6SubnetName,
createdIpv6Allocation ? netrisV6IpamAllocationName : null, networkName);
}
Comment on lines +388 to +389
const networkAclService = this.resource.service.find(svc => svc.name === 'NetworkACL')
return networkAclService && networkAclService.provider && networkAclService.provider.some(p => p.name === 'Netris')
{{ $t('label.isolated') }}
</a-radio-button>
<a-radio-button value="l2" v-if="form.provider !== 'NSX' && form.provider !== 'Netris'">
<a-radio-button value="l2" v-if="form.provider !== 'NSX'">
SourceNat: externalProvider,
StaticNat: externalProvider,
PortForwarding: externalProvider,
Vpn: this.forVpc ? this.VPCVR : this.VR,

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: conflict/waiting

Development

Successfully merging this pull request may close these issues.

6 participants