Skip to content

[Europa][S6] DNS·Network Extension·VR·VPC 변경 통합 - #1037

Merged
dhslove merged 35 commits into
ablecloud-team:ablestack-europafrom
dhslove:codex/epic-987-s6-network
Sep 11, 2026
Merged

dhslove merged 35 commits into
ablecloud-team:ablestack-europafrom
dhslove:codex/epic-987-s6-network

Conversation

@dhslove

@dhslove dhslove commented Sep 11, 2026 •

Copy link
Copy Markdown

Apache CloudStack 4.23의 DNS·Network Extension·VR/VPC 변경을 Europa에 통합합니다. 직접 원본32개와 S2 후속2개(#13608의 offering 분류, #13848의 README), 공유 merge10개를 완료하며, 남은 S7 원본8개와 S2 잔여4개는 추적표에 Pending으로 유지합니다.

PowerDNS 최초 기능과 테넌트 충돌·URL 검증 후속을 함께 반영했습니다. Network Extension provider/스크립트 계약, VPC 방화벽·규칙 soft delete, DHCP/IPv6/VXLAN/MAC-IP hook, NIC 설명·네트워크 오퍼링·CKS KVM scaling을 포함합니다. Europa Storage Service·FTCTL/DR·KVDO·KMS, VPN 설정 제외 목록과 기존 편집값, 네트워크 속도 기본10000 Mbps를 보존합니다. DHCP lease 교체 시 소유자·권한과 임시 파일 정리도 보완합니다.

기존 Complete DB 단계를 유지하고 새 europa-4.23-s6-v1 단계 및 DNS view 생성 순서를 추가했습니다. 실제 MySQL 신규/014895d8f3/S5C 업그레이드3경로가473 table/view를 생성하며 반복 실행 전후 전체 데이터가 같습니다. DDL24개 커밋 경계의 중단·재시도와 기존 행 보존을 확인했습니다.

UI354개/31 suite·전체 lint, Network Extension 실제 프로세스/JSON/오류/임시 파일 테스트3개, DHCP/주소 처리 집중 Python10개가 통과했습니다. 조립된 Management API와 HTTP 모의 PowerDNS로 provider·zone·record 수명주기, 계정 ACL·동일/하위 존 충돌·URL 거부·비밀값 생략을 검증했습니다. 로컬 전체 Java 14,688개는 실패0/오류0/skip15로 통과했고, 영향 경로 1,291개/56 suite는 실패0/오류0/skip2입니다. 전체 회귀 실행 중 뒤늦게 추가한 script 테스트3개는 별도 검증했으며 최종 Actions에도 포함됩니다. 공식 산출물은 아래 최종 SHA의 Actions 결과를 참조합니다.

기존 한계는 분리했습니다. 전체 TestCs는 기준25개/변경후28개에서 같은 TestCsRoute 실패2개가 남으며, exdhcp의 기존 Python2 스크립트는 Python3 문법 PASS에서 제외합니다. 전체 Lint는 기존13개 실패 범주이며 S6 변경 경로 추가 진단은 없습니다. 네트워크가 없는 신규 fixture에서 주기적 LB/cluster balancing의 networks.get(0) 오류도 관찰됐으며 해당 메서드는 S5C와 바이트 단위로 동일합니다. 이 API fixture 결과를 실물 LB 트래픽 성공으로 확장하지 않습니다.

검증 보고 · 원본44개 판정 · 공유 merge12개 검토.

실물 시나리오13개는 #1025에 NOT_RUN으로 기록했습니다. 모든 코드 병합 후 S8 #999에서 수행하며 이 코드 PR의 Draft/병합 보류 조건이 아닙니다.

Closes #997

최종 Actions 검증

최종 PR HEAD 58bd4ce7a362b026c6c697e54a38a5ad9d519063. 공식 backend 14,691 tests / failures0 / errors0 / skipped17.

전체 Lint는 기존13개 실패 범주, 변경 경로 추가 진단0개. Simulator/Coverage/Sonar skipped는 PASS에 포함하지 않습니다. Actions 산출물은 이 S6 코드의 검증용이며 최종 S8 RC가 아닙니다.

DaanHoogland and others added 30 commits September 11, 2026 05:12
…pache#12645)

* Fix VPC network offerings listing in isolated network creation form

* Apply suggestions from code review

Co-authored-by: GaOrtiga <49285692+GaOrtiga@users.noreply.github.com>

* Address Bernardo's review

---------

Co-authored-by: GaOrtiga <49285692+GaOrtiga@users.noreply.github.com>
(cherry picked from commit c165806)
…e#12864)

* Addition of description field for NIC's secondary IP addresses

* Address copilot's review

* Add newline at the end of file

Co-authored-by: dahn <daan.hoogland@gmail.com>

* Address Wei's label changes

* Remove colon from label

* Apply suggestions from code review

Co-authored-by: Bernardo De Marco Gonçalves <bernardomg2004@gmail.com>

* Fix missing newline at end of SQL file

---------

Co-authored-by: dahn <daan.hoogland@gmail.com>
Co-authored-by: Bernardo De Marco Gonçalves <bernardomg2004@gmail.com>
(cherry picked from commit 02bb5de)
…as-is template (apache#13423)

* Allow selecting network for VNF nics if template nics > 0 and is a non-deploy as is template

* delpoy as is param not required

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
(cherry picked from commit e689c02)
… VXLAN modes (apache#13107)

* kvm: Add a configuration setting to switch between multicast and evpn VXLAN modes

Using the 'network.vxlan.mode' setting you can switch between the multicast (default) and evpn VXLAN modes on a KVM Agent.

When nothing is configured CloudStack will default to multicast by using the modifyvxlan.sh script in the background.
If this setting is set to 'evpn' the KVM Agent will execute the 'modifyvxlan-evpn.sh' script which will configure the VXLAN
devices for EVPN (usually with FRRouting with BGP) mode.

This removes the need to manually replace a shell script on the hypervisor to switch modes.

Existing environments are not touched by this and it is safe to add this setting a an environment already using EVPN for the
VXLAN deployment.

* Add network.vxlan.mode to agent.properties

Make sure there is an example in the agent.properties file so people
can easily discover this configuration setting exists

(cherry picked from commit a97c510)
…che#13380)

* update column type

* Apply suggestion from @DaanHoogland

Co-authored-by: dahn <daan@onecht.net>

---------

Co-authored-by: Daan Hoogland <daan@onecht.net>
Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
Co-authored-by: Harikrishna <harikrishna.patnala@gmail.com>
(cherry picked from commit e63b7da)
…NIC DB round-trips (apache#13474)

Co-authored-by: Aaron Chung <aaron_chung@apple.com>
(cherry picked from commit 4625a43)
…ork has a tag (apache#13503)

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
(cherry picked from commit 006831d)
)

* Enhance DHCP functionality by adding lease time support across various components. Updated DhcpEntryCommand to include lease time, modified VmDhcpConfig to handle lease time, and adjusted related scripts and configurations to accommodate this new parameter. This allows for configurable DHCP lease durations, improving flexibility in network management.

* Move dhcp lease timeout to ConfigKey, set it to 'zone' scope, and add some tests.

* Refactor DHCP lease timeout tests to pass code standards/remove white space.

* add DhcpLeaseTimeout in getConfigKeys() method

* Apply suggestion from @weizhouapache

---------

Co-authored-by: Wei Zhou <weizhou@apache.org>
(cherry picked from commit de3656c)
This PR introduces and wires a new extension model for external network orchestration in CloudStack, centered on a new extension type: NetworkOrchestrator.

It extends the extension lifecycle from cluster-only registration to physical-network registration, adds API support for updating registered extension metadata, and enables automatic offering creation (network and VPC) based on provider-declared supported services and capabilities.

It also adds smoke coverage (KVM-only) using a Linux network namespace based implementation.

Doc PR: apache/cloudstack-documentation#649

What's new

1) New extension type: NetworkOrchestrator
Adds support for creating extensions of type NetworkOrchestrator.
Intended to back CloudStack network/VPC operations via an external orchestrator/provider.

2) Register extension with PhysicalNetwork (in addition to Cluster)
Extensions can now be registered against a PhysicalNetwork resource.
This enables network service provider behavior at physical-network scope, not only cluster scope.

3) Physical network registration details support
Registered extension details for PhysicalNetwork are handled similarly to cluster registration details.
Supports storing/updating external access metadata (credentials/endpoints/config details).

4) New API: update registered extension
Adds API support to update extension registration metadata after registration.
Useful for rotating credentials, updating endpoints, and changing external connection properties without re-registering.

5) Offering automation from external provider capabilities
Network/VPC offerings can be created with the external network provider using:
provider supportedservices
per-service service capabilities
This allows CloudStack offerings to align with what the external provider actually supports.

6) Network support via generated offerings
Using offerings backed by the external provider, networks can be created and operated with supported services/capabilities.

Supported operations include (based on provider capabilities):

Source NAT
Static NAT
Port Forwarding
Firewall
Load Balancing
DHCP
DNS
UserData

7) VPC support via generated offerings
Using VPC offerings backed by the external provider, VPCs and tiers can be created and operated with supported services/capabilities.

Supported operations include (based on provider capabilities):

VPC tier creation/implementation
Source NAT in VPC context
Static NAT / Port Forwarding / LB on VPC tiers
Network ACL association and ACL rule apply paths
Related lifecycle/restart/reapply operations

8) Linux network namespace based external implementation
Adds/uses a network extension implementation based on Linux network namespaces.
Reference implementation:
https://github.com/apache/cloudstack-extensions/tree/network-namespace/Network-Namespace

9) Smoke test coverage (KVM-only)
Adds smoke tests using the namespace-based extension implementation.
Scope includes provider lifecycle, offering creation, network/VPC flows, and key network services.
Applicable hypervisor for this smoke suite: KVM.

(cherry picked from commit 8996286)
This commit does not change any functionality, it merely changes documentation
inside the script.

(cherry picked from commit c46fb70)
apache#13495)

* KVM: add configurable MAC/IP script hook for static ARP/NDP and routes

Introduces a new agent.properties option `vm.network.macip.static`
(false by default) that makes BridgeVifDriver invoke on modifymacip.sh
on every NIC plug (VM start) and unplug (VM stop).

This is very useful in EVPN+VXLAN environments as it can reduce BUM
traffic. By setting static ARP/NDP entries bridges can be configured
using 'neigh_suppress on' as the ARP/NDP entries are already set
statically by CloudStack.

Setting 'neigh_suppress on' requires a manual change in the modifyvxlan.sh
script as this is not the default behavior.

* vxlan: In EVPN mode, disable ARP/NDP learning

FRR populates the FDB via BGP EVPN, so kernel data-plane learning is
redundant and counterproductive.

Static ARP (IPv4) and NDP (IPv6) entries are added on startup of the
Instance and remove on shutdown.

FRR populates the FDB/neighbor table via control plane, and neigh_suppress
tells the kernel bridge to use that information instead of flooding.

This will vastly reduce BUM traffic with static ARP/NDP entries.

(cherry picked from commit 4816e05)
Co-authored-by: Gustavo Rück <gustavo.silveira@scclouds.com.br>
(cherry picked from commit b26b70c)
Co-authored-by: Gustavo Rück <gustavo.silveira@scclouds.com.br>
(cherry picked from commit 78d9cb5)
…apache#13615)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
(cherry picked from commit 7900b27)
…expunge VM (apache#13194)

* Ensure VM IP is removed from VR DHCP records in dnsmasq.leases after expunge VM

This also reverts the PR apache#10183 changes (for apache#10182), in turn resulting in apache#11877.

* review changes

(cherry picked from commit 5432a04)
* validate DNS server URLs in provider framework

* fixes

* Apply suggestion from @DaanHoogland

* address (some) review comments

* restrict pvt/site-local urls to root admin only

* trim url before passing to validation method

* fix minor comment

* restrict Add/Update/Delete Dns server api for root admin

* fix minor comment

* fix unit test

* address review comments

* fix build error

* server: optimize DnsProviderManagerImplTest

---------

Co-authored-by: Daan Hoogland <dahn@apache.org>
Co-authored-by: Manoj Kumar <manojkr.itbhu@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
(cherry picked from commit 158fe4f)
dhslove and others added 4 commits September 11, 2026 05:23
* markdaown table format fixes

* remove superfluent chars

---------

Co-authored-by: Daan Hoogland <dahn@apache.org>
(cherry picked from commit e201213)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.