apache / apache/cloudstack

VMware NSX network implementation can fail before backing DV port group is visible

Đang mở
#13,752 2 bình luận 0 reaction 0 người được giao Được @Dogface2k nhận Xem trên GitHub
component:vmware component:vpc Severity:Major type:bug
Ngôn ngữ chính
Java
Star
3.1k
Fork
1.4k
Merge trung bình
6 ngày 19 giờ
Pull request đã merge (30 ngày)
32

Mô tả

### Problem

On VMware environments using the NSX integration, implementing a guest network can fail during `PlugNicCommand` even though `CreateNsxSegmentCommand` has already succeeded.

The NSX segment is created outside vCenter. Its backing distributed virtual port group can therefore take a short time to become visible through the vCenter API. `HypervisorHostHelper.prepareNetwork` currently performs only one immediate lookup for NSX networks and returns failure when that first lookup is empty.

Sanitized management-server sequence:

```text
CreateNsxSegmentCommand ... NsxAnswer result=true
Prepare network on vmwaredvs
Failed to create guest network
PlugNicAnswer result=false
```

The failure rolls back the NIC attachment and prevents the persistent VPC guest network from being implemented.

### Versions

- Apache CloudStack 4.22.1.0
- VMware vSphere / vCenter 8.0.3
- CloudStack NSX integration

### Steps to reproduce

1. Configure a VMware zone with the CloudStack NSX integration.
2. Create an NSX-backed VPC guest network.
3. Allow the NSX segment command to complete while the backing DV port group is not yet visible through vCenter.
4. Observe the immediate DV port group lookup fail in `HypervisorHostHelper.prepareNetwork`, followed by a failed `PlugNicCommand`.

### Expected behavior

After successful NSX segment creation, CloudStack should use its existing bounded DV port group readiness wait before attempting to attach the NIC. If the port group never becomes visible, the existing timeout should still fail the operation cleanly.

### Proposed fix

Enable the existing `waitForDvPortGroupReady` path for NSX broadcast domains and add a regression test covering an empty first vCenter lookup followed by a successful lookup.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu tại HypervisorHostHelper.prepareNetwork và lần theo đường đi hiện có của waitForDvPortGroupReady được sử dụng trong PlugNicCommand. Thêm bài kiểm thử hồi quy được mô tả trong issue cho trường hợp lần tra cứu vCenter đầu tiên trả về rỗng, sau đó lần tra cứu tiếp theo thành công, và xác minh rằng thời gian chờ có giới hạn vẫn xử lý một port group không bao giờ xuất hiện.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
java
Lĩnh vực
infrastructure, networking
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.