apache / apache/cloudstack

VXLAN persistent networks create bridges on hosts that never ran a VM on them, but don't clean them up

未關閉
#13,966 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
7 天 14 小時
30 天內合併 PR
31

描述

### problem

With a persistent network offering, CloudStack builds the network's bridge on **every** host in the zone. But when the network is deleted it only cleans the bridge up on hosts that actually ran a VM on it. On every other host, the bridge and its VXLAN interface stay behind forever.

**Investigation**
There is a difference between the filters when creating a persistent network, and removing a persistent network.
**Creation:**
`DefaultHostListener.setupPersistentNetwork()` creates the bridges on hostConnect/hostEnabled for all networks from `getAllPersistentNetworksFromZone()` - no isolation-method filter.
**Removal:**
`NetworkOrchestrator.cleanupPersistentnNetworkResources()` is gated by `networkMeetsPersistenceCriteria()`, which requires the broadcast URI scheme to be `Vlan`, so for `vxlan://` networks `CleanupPersistentNetworkResourceCommand` is never sent. (`hostAboutToBeRemoved()` sends the same cleanup with no scheme check either - the VLAN-only gate exists only on the network-delete path.)

Hosts that ran a VM on the network are cleaned up via the normal VM-lifecycle teardown, so the leak only affects uninvolved hosts.

### versions

4.22.1.1, KVM, advanced zone with VXLAN isolation, persistent network offerings.

### The steps to reproduce the bug

1. Advanced zone, KVM, VXLAN isolation, 3+ hosts.
2. Create a VPC with two tiers on a persistent offering.
3. Start VMs so they land on only some hosts. (Restarting `cloudstack-agent` on an uninvolved host also creates the bridges there via hostConnect.)
4. Delete the tiers, then the VPC.
5. `ls -d /sys/class/net/brvx-*` on each host.

Expected behaviour:
The bridge and VXLAN interface are removed from every host in the zone.

Actual behaviour:
The VNI is still present on hosts that never ran a VM on the network; `CleanupPersistentNetworkResourceCommand` never appears in `management-server.log` during the delete.

### What to do about it?

Accept `Vxlan` alongside `Vlan` in `networkMeetsPersistenceCriteria()`, or drop the scheme check to match the setup path.

貢獻指南

開啟貢獻指南

研究方向

先從 NetworkOrchestrator.cleanupPersistentnNetworkResources() 和 networkMeetsPersistenceCriteria() 開始,然後將它們與 DefaultHostListener.setupPersistentNetwork() 和 hostAboutToBeRemoved() 進行比較。在三個或更多主機上重現持久 VXLAN 網路的刪除流程,並檢查 management-server.log 和 /sys/class/net/brvx-*;當 cleanup 已送出,且所有主機上的 bridge 和 VXLAN 介面都消失時,即表示完成。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
infrastructure, networking
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
活躍
描述清晰度
描述清楚
新手友好度
74/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。