Live security group additions and removals
オープン
component:security-group
type:improvement
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
Problem:
Currently CloudStack requires an instance to be stopped before adding or removing a security group, causing unnecessary downtime. The underlying iptables rules are enforced at the hypervisor level and should not require instance downtime to modify.
Expected behavior:
Security groups can be added or removed from a running instance without a stop/start cycle.
CloudStack version: 4.21.0.0
Zone type: Security Group zone
コントリビューションガイド
調査の方向性
まず、実行中のインスタンスに対する CloudStack の security-group 追加/削除操作を追跡し、ハイパーバイザーレベルの iptables ルールがどのように適用されるかを調査します。Security Group zone における実行中のインスタンスと停止中のインスタンスの動作を比較します。stop/start サイクルなしで追加と削除が機能し、期待される security-group の適用が維持されれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- infrastructure, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100