Conversation
* Netris - Support NAT, PF for Secondary IP * Allow PF rules to be correctly created on secondary IP of a VM on netris * unique static nat names on netris by adding public IP - handle backward compatibility --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Support for L2 networks * Add support for L2 networks in Netris * remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering * create vpc network and use it for l2 networks * dont fail if deletion on netris doesnt succeed * remove connectivity capability * update vpc name when l2 name is updated --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - CKS support Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs * Set globalRouting = true, when network offering is NATTED, dual-stack * update global routing based on routing mode and ip protocol type --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion * Fix allocate vnets with the correct account ID so that release succeeds on network deletion * add fix for vpc tiers as well * move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris * cleanup vnets when reservation id is null --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Add support to include VPN service for NATTED Netris offerings * Add support to include VPN service for NATTED Netris offerings * missing changes of global routing * Remove extra space --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Support Redundant Virtual Routers for Netris VPC networks * Add support for redundant routers for Netris VPC networks * address comment * default null network mode to natted for netris * preventing vpc and ipam creation if already exists --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable autoscaling groups for Netris network offerings * Enable autoscaling groups for Netris network offerings * Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode * Revert removed comment --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * merge conflict * systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris * show networks for vnf nic mappings --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> Co-authored-by: Wei Zhou <weizhou@apache.org>
* Netris - Support NAT, PF for Secondary IP * Allow PF rules to be correctly created on secondary IP of a VM on netris * unique static nat names on netris by adding public IP - handle backward compatibility --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Support for L2 networks * Add support for L2 networks in Netris * remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering * create vpc network and use it for l2 networks * dont fail if deletion on netris doesnt succeed * remove connectivity capability * update vpc name when l2 name is updated --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - CKS support Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs * Set globalRouting = true, when network offering is NATTED, dual-stack * update global routing based on routing mode and ip protocol type --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion * Fix allocate vnets with the correct account ID so that release succeeds on network deletion * add fix for vpc tiers as well * move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris * cleanup vnets when reservation id is null --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Add support to include VPN service for NATTED Netris offerings * Add support to include VPN service for NATTED Netris offerings * missing changes of global routing * Remove extra space --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Support Redundant Virtual Routers for Netris VPC networks * Add support for redundant routers for Netris VPC networks * address comment * default null network mode to natted for netris * preventing vpc and ipam creation if already exists --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable autoscaling groups for Netris network offerings * Enable autoscaling groups for Netris network offerings * Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode * Revert removed comment --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * merge conflict * systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris * show networks for vnf nic mappings * Add a check to prevent re-adding existing ACLs * Add a check to prevent re-adding existing ACLs * change message compare statement --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> Co-authored-by: Wei Zhou <weizhou@apache.org>
…failure of creation of allocation * Netris - Support NAT, PF for Secondary IP * Allow PF rules to be correctly created on secondary IP of a VM on netris * unique static nat names on netris by adding public IP - handle backward compatibility --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Support for L2 networks * Add support for L2 networks in Netris * remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering * create vpc network and use it for l2 networks * dont fail if deletion on netris doesnt succeed * remove connectivity capability * update vpc name when l2 name is updated --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - CKS support Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs * Set globalRouting = true, when network offering is NATTED, dual-stack * update global routing based on routing mode and ip protocol type --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion * Fix allocate vnets with the correct account ID so that release succeeds on network deletion * add fix for vpc tiers as well * move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris * cleanup vnets when reservation id is null --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Add support to include VPN service for NATTED Netris offerings * Add support to include VPN service for NATTED Netris offerings * missing changes of global routing * Remove extra space --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * Netris - Support Redundant Virtual Routers for Netris VPC networks * Add support for redundant routers for Netris VPC networks * address comment * default null network mode to natted for netris * preventing vpc and ipam creation if already exists --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> * Netris - Enable autoscaling groups for Netris network offerings * Enable autoscaling groups for Netris network offerings * Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode * Revert removed comment --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> * merge conflict * systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris * show networks for vnf nic mappings * Add a check to prevent re-adding existing ACLs * Add a check to prevent re-adding existing ACLs * change message compare statement * Add check for vnet name length and cleanup vpc and vnet resources on failure of creation of allocation * add name length validation to update path --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: nvazquez <nicovazquez90@gmail.com> Co-authored-by: Wei Zhou <weizhou@apache.org>
…upported Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…in the vpc offering * Hide VPN sections and prevent enabling it when service isn't enabled in the vpc offering * update --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ring Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ove log and hide add upstream route for Netris routed networks * Update upgrade path to reclaim vnets of deleted netris networks, improve log and hide add upstream route for Netris routed networks * Apply suggestions from code review * hide upstream route banner for netris networks altogether * fix migration of netris VRs and fix reclaim vnet query --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com> Co-authored-by: Nicolas Vazquez <nicovazquez90@gmail.com>
…ing associate * Allocate IP from Netris (Provider) range when IP is not specified during associate * update javadoc and method name --------- Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## 4.22 #13591 +/- ##
============================================
- Coverage 18.00% 17.99% -0.02%
- Complexity 16219 16225 +6
============================================
Files 5936 5936
Lines 535716 536200 +484
Branches 65596 65677 +81
============================================
+ Hits 96459 96477 +18
- Misses 428268 428724 +456
- Partials 10989 10999 +10
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@blueorangutan package |
|
@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18533 |
|
@blueorangutan test |
|
@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests |
|
[SF] Trillian test result (tid-16528)
|
|
81b5274 to
71f6299
Compare
|
@blueorangutan package |
|
@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19255 |
|
@blueorangutan package |
|
@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19343 |
|
@blueorangutan test |
|
@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests |
|
[SF] Trillian test result (tid-17039)
|
|
@blueorangutan package |
|
@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19359 |
|
Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
|
@blueorangutan package |
|
@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19365 |
|
@blueorangutan test |
|
@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
L2 offering creation, mixed-zone IP allocation, legacy static-NAT handling, and failure cleanup contain unresolved correctness issues.
Review effort: Balanced
Findings: 3
Open (9)
Verify legacy NAT IP before deletion fallback · New Match legacy static NAT rules by public IP · New Apply Netris IP steering only to Netris networks · New Allow exactly the Netris Connectivity service · New Ensure IPAM allocation exists for existing VPCs · New Rollback newly created L2 VPCs on failure · New Detect Netris across all network service providers · New Add an L2-specific Netris offering service path · New Restrict VPN service mapping to Netris · New
What changed in this PR
Expands Netris networking support across offerings, VPCs, L2 networks, VPN, redundant routers, Kubernetes, IP allocation, and resource cleanup.
Changes:
- Adds Netris L2, VPN, secondary-IP NAT/PF, autoscaling, and redundant-router support.
- Improves Netris resource naming, allocation, rollback, and upgrade cleanup.
- Integrates Netris networking with CKS and updates related UI behavior.
| File | Description |
|---|---|
ui/src/views/offering/AddVpcOffering.vue |
Adds Netris VPN and redundant-router options. |
ui/src/views/offering/AddNetworkOffering.vue |
Adds L2, VPN, and autoscaling controls. |
ui/src/views/network/VpnDetails.vue |
Gates VPN actions by VPC service support. |
ui/src/views/network/VpcTab.vue |
Hides unsupported VPN tabs. |
ui/src/views/infra/zone/AdvancedGuestTrafficForm.vue |
Adds Netris VNI limits. |
ui/src/config/section/offering.js |
Displays redundant-router capability. |
ui/src/config/section/network.js |
Filters VPN views by service. |
ui/src/components/view/DetailsTab.vue |
Hides upstream routes for Netris. |
systemvm/debian/opt/cloud/bin/cs/CsAddress.py |
Avoids conflicting VRRP gateways. |
server/src/test/java/org/apache/cloudstack/service/NetrisServiceMockTest.java |
Updates Netris service mock signatures. |
server/src/main/java/com/cloud/network/vpn/Site2SiteVpnManagerImpl.java |
Validates VPC VPN support. |
server/src/main/java/com/cloud/network/vpn/RemoteAccessVpnManagerImpl.java |
Validates remote-access VPN support. |
server/src/main/java/com/cloud/network/vpc/VpcManagerImpl.java |
Handles redundant VPC router failover. |
server/src/main/java/com/cloud/network/router/VirtualNetworkApplianceManagerImpl.java |
Reapplies Netris rules after failover. |
server/src/main/java/com/cloud/network/NetworkModelImpl.java |
Adjusts IP service handling for Netris. |
server/src/main/java/com/cloud/network/IpAddressManagerImpl.java |
Selects Netris-reserved IP ranges. |
server/src/main/java/com/cloud/network/guru/GuestNetworkGuru.java |
Changes Netris VNET release behavior. |
server/src/main/java/com/cloud/api/query/dao/VpcOfferingJoinDaoImpl.java |
Populates redundant-router response data. |
plugins/network-elements/netris/src/test/java/org/apache/cloudstack/service/NetrisGuestNetworkGuruTest.java |
Tests network modes and protocols. |
plugins/network-elements/netris/src/test/java/org/apache/cloudstack/service/NetrisElementTest.java |
Updates vNet deletion test. |
plugins/network-elements/netris/src/test/java/org/apache/cloudstack/resource/NetrisResourceObjectUtilsTest.java |
Tests unique static-NAT names. |
plugins/network-elements/netris/src/test/java/org/apache/cloudstack/agent/api/CreateNetrisVnetCommandTest.java |
Tests new command attributes. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/service/NetrisServiceImpl.java |
Propagates L2 and protocol metadata. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/service/NetrisPublicNetworkGuru.java |
Normalizes legacy network modes. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/service/NetrisGuestNetworkGuru.java |
Implements L2 and VNET lifecycle changes. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/service/NetrisElement.java |
Adds gateway capabilities and secondary-IP PF. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/service/NetrisApiClientImpl.java |
Implements resource lifecycle and NAT changes. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/resource/NetrisResourceObjectUtils.java |
Adds name validation and mode normalization. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/agent/api/NetrisCommand.java |
Adds the L2 command flag. |
plugins/network-elements/netris/src/main/java/org/apache/cloudstack/agent/api/CreateNetrisVnetCommand.java |
Carries network mode and protocol. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/KubernetesClusterManagerImpl.java |
Adds a default Netris CKS offering. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/actionworkers/KubernetesClusterStartWorker.java |
Provisions distinct Netris LB/NAT IPs. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/actionworkers/KubernetesClusterScaleWorker.java |
Updates Netris scaling rules. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/actionworkers/KubernetesClusterResourceModifierActionWorker.java |
Adds Netris-specific CKS rules. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/actionworkers/KubernetesClusterDestroyWorker.java |
Cleans up Netris CKS resources. |
plugins/integrations/kubernetes-service/src/main/java/com/cloud/kubernetes/cluster/actionworkers/KubernetesClusterActionWorker.java |
Manages separate API and NAT addresses. |
engine/schema/src/main/resources/META-INF/db/schema-42200to42210.sql |
Reclaims deleted Netris VNET allocations. |
engine/schema/src/main/java/com/cloud/vm/dao/NicDaoImpl.java |
Filters placeholder router NICs. |
engine/schema/src/main/java/com/cloud/vm/dao/NicDao.java |
Updates the NIC DAO contract. |
engine/orchestration/src/main/java/org/apache/cloudstack/engine/orchestration/NetworkOrchestrator.java |
Adjusts migration and L2 handling. |
api/src/main/java/org/apache/cloudstack/api/response/VpcOfferingResponse.java |
Exposes redundant-router support. |
api/src/main/java/org/apache/cloudstack/api/command/utils/OfferingUtils.java |
Centralizes Netris detection. |
api/src/main/java/org/apache/cloudstack/api/command/admin/vpc/CreateVPCOfferingCmd.java |
Adds Netris VPN and capability handling. |
api/src/main/java/org/apache/cloudstack/api/command/admin/network/CreateNetworkOfferingCmd.java |
Adds VPN to Netris offerings. |
api/src/main/java/org/apache/cloudstack/api/ApiConstants.java |
Defines the Netris NAT IP detail key. |
api/src/main/java/com/cloud/network/netris/NetrisService.java |
Extends the vNet lifecycle API. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if (existingNatRule == null && "STATICNAT".equals(cmd.getNatRuleType())) { | ||
| String legacyName = getLegacyStaticNatRuleName(natRuleName); | ||
| if (legacyName != null) { | ||
| logger.debug("Static NAT rule not found with name '{}', falling back to legacy name '{}'", natRuleName, legacyName); | ||
| existingNatRule = netrisNatRuleExists(legacyName); | ||
| if (existingNatRule != null) { | ||
| natRuleName = legacyName; | ||
| } |
| // Backward compatibility: rule with legacy naming convention (no public IP post-fixed) exists - don't create a duplicate | ||
| String legacyName = getLegacyStaticNatRuleName(staticNatRuleName); | ||
| if (legacyName != null && netrisNatRuleExists(legacyName) != null) { | ||
| logger.debug("Legacy static NAT rule '{}' already exists on Netris, skipping creation of '{}'", legacyName, staticNatRuleName); | ||
| return true; |
| // Only steer the range when no explicit IP was requested: an explicit ipaddress is already | ||
| // validated against the provider's pool above by checkPublicIpOnExternalProviderZone. | ||
| final List<Long> vlanDbIds = ipaddress == null ? getNetrisVlanDbIds(zone) : null; |
| * Checks for L2 network offering services. Only 3 cases allowed: | ||
| * - No services | ||
| * - User Data service only, provided by ConfigDrive | ||
| * - UserData service only, provided by ConfigDrive | ||
| * - Connectivity service only, provided by Netris |
| VPCListing existingNetrisVpc = getVpcByNameAndTenant(netrisVpcName); | ||
| if (existingNetrisVpc != null) { | ||
| logger.info("Netris VPC {} already exists, skipping creation", netrisVpcName); | ||
| return true; |
| if (!isL2) { | ||
| rollbackVnetResources(associatedVpc, netrisSubnetName, netrisV6SubnetName, | ||
| createdIpv6Allocation ? netrisV6IpamAllocationName : null, networkName); | ||
| } |
| const networkAclService = this.resource.service.find(svc => svc.name === 'NetworkACL') | ||
| return networkAclService && networkAclService.provider && networkAclService.provider.some(p => p.name === 'Netris') |
| {{ $t('label.isolated') }} | ||
| </a-radio-button> | ||
| <a-radio-button value="l2" v-if="form.provider !== 'NSX' && form.provider !== 'Netris'"> | ||
| <a-radio-button value="l2" v-if="form.provider !== 'NSX'"> |
| SourceNat: externalProvider, | ||
| StaticNat: externalProvider, | ||
| PortForwarding: externalProvider, | ||
| Vpn: this.forVpc ? this.VPCVR : this.VR, |




Description
This PR addresses the following for Netris:
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?