Skip to content

Netris: Improvements and fixes to the Netris plugin - #13591

Open
Pearl1594 wants to merge 21 commits into
4.22from
netris-improvements
Open

Pearl1594 wants to merge 21 commits into
4.22from
netris-improvements

Conversation

@Pearl1594

@Pearl1594 Pearl1594 commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR addresses the following for Netris:

  • Support NAT, PF for Secondary IP
  • Support for L2 networks
  • CKS Support
  • Fix allocate vnets with the correct account ID so that release succeeds on network deletion
  • Add support to include VPN service for NATTED Netris offerings
  • Support Redundant Virtual Routers for Netris VPC networks
  • Enable autoscaling groups for Netris network offerings
  • Prevent re-adding ACLs
  • Add check for vnet name length and cleanup vpc and vnet resources on failure of creation of allocation
  • Add support to the VPC response to display if redundant routers are supported
  • Hide VPN sections and prevent enabling it when service isn't enabled in the vpc offering
  • Fix issue with adding external node to a CKS cluster with Netris offering
  • Update upgrade path to reclaim vnets of deleted netris networks, improve log and hide add upstream route for Netris routed networks
  • Allocate IP from Netris (Provider) range when IP is not specified during associate
  • Prevent VRRP gateway IP conflict on redundant VPC routers with external network providers (Netris/NSX)
  • VPN: Reconfigure static nat and static route on fail over to backup VR - for redundant VPC VRs
  • Fix issue with deletion of vpn connection for DualStack redundant VPCs

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

Pearl1594 and others added 8 commits July 10, 2026 10:13
* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

* Add a check to prevent re-adding existing ACLs

* Add a check to prevent re-adding existing ACLs

* change message compare statement

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
…failure of creation of allocation

* Netris - Support NAT, PF for Secondary IP

* Allow PF rules to be correctly created on secondary IP of a VM on netris

* unique static nat names on netris by adding public IP - handle backward compatibility

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Support for L2 networks

* Add support for L2 networks in Netris

* remove the need to add connectivity to identify netris provider, remove changes to ui and create net offering

* create vpc network and use it for l2 networks

* dont fail if deletion on netris doesnt succeed

* remove connectivity capability

* update vpc name when l2 name is updated

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - CKS support

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable Global Routing Flag for NATTED Dual-Stack VPCs

* Set globalRouting = true, when network offering is NATTED, dual-stack

* update global routing based on routing mode and ip protocol type

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* Fix allocate vnets with the correct account ID so that release succeeds on network deletion

* add fix for vpc tiers as well

* move entire vnet cleanup logic to trash from shutdown, so that it works for all network types for netris

* cleanup vnets when reservation id is null

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Add support to include VPN service for NATTED Netris offerings

* Add support to include VPN service for NATTED Netris offerings

* missing changes of global routing

* Remove extra space

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* Netris - Support Redundant Virtual Routers for Netris VPC networks

* Add support for redundant routers for Netris VPC networks

* address comment

* default null network mode to natted for netris

* preventing vpc and ipam creation if already exists

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>

* Netris - Enable autoscaling groups for Netris network offerings

* Enable autoscaling groups for Netris network offerings

* Fix UI loading for services when network mode changes for external providers and show vm autoscaling always set to true / non-editable for netris when LB is selected i.e, natted mode

* Revert removed comment

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>

* merge conflict

* systemvm: fix VPC VPN issue when network id is bigger than 1000 on Netris

* show networks for vnf nic mappings

* Add a check to prevent re-adding existing ACLs

* Add a check to prevent re-adding existing ACLs

* change message compare statement

* Add check for vnet name length and cleanup vpc and vnet resources on failure of creation of allocation

* add name length validation to update path

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>
Co-authored-by: Wei Zhou <weizhou@apache.org>
…upported

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…in the vpc offering

* Hide VPN sections and prevent enabling it when service isn't enabled in the vpc offering

* update

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ring

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
…ove log and hide add upstream route for Netris routed networks

* Update upgrade path to reclaim vnets of deleted netris networks, improve log and hide add upstream route for Netris routed networks

* Apply suggestions from code review

* hide upstream route banner for netris networks altogether

* fix migration of netris VRs and fix reclaim vnet query

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
Co-authored-by: Nicolas Vazquez <nicovazquez90@gmail.com>
…ing associate

* Allocate IP from Netris (Provider) range when IP is not specified during associate

* update javadoc and method name

---------

Co-authored-by: Pearl Dsilva <pearl1954@gmail.com>
@codecov

codecov Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 5.92705% with 619 lines in your changes missing coverage. Please review.
✅ Project coverage is 18.00%. Comparing base (0931cf8) to head (e008445).

Files with missing lines Patch % Lines
...apache/cloudstack/service/NetrisApiClientImpl.java 0.00% 256 Missing ⚠️
...che/cloudstack/service/NetrisGuestNetworkGuru.java 14.28% 64 Missing and 8 partials ⚠️
...r/actionworkers/KubernetesClusterActionWorker.java 8.00% 46 Missing ⚠️
...er/actionworkers/KubernetesClusterStartWorker.java 0.00% 35 Missing ⚠️
.../actionworkers/KubernetesClusterDestroyWorker.java 0.00% 27 Missing ⚠️
...ain/java/com/cloud/network/vpc/VpcManagerImpl.java 0.00% 27 Missing ⚠️
...bernetes/cluster/KubernetesClusterManagerImpl.java 0.00% 22 Missing ⚠️
...er/actionworkers/KubernetesClusterScaleWorker.java 0.00% 18 Missing ⚠️
...ck/api/command/admin/vpc/CreateVPCOfferingCmd.java 0.00% 15 Missing ⚠️
...n/java/com/cloud/network/IpAddressManagerImpl.java 0.00% 15 Missing ⚠️
... and 17 more
Additional details and impacted files
@@             Coverage Diff              @@
##               4.22   #13591      +/-   ##
============================================
- Coverage     18.02%   18.00%   -0.02%     
- Complexity    16248    16255       +7     
============================================
  Files          5936     5936              
  Lines        535866   536369     +503     
  Branches      65614    65699      +85     
============================================
+ Hits          96574    96600      +26     
- Misses       428291   428761     +470     
- Partials      11001    11008       +7     
Flag Coverage Δ
uitests 4.04% <ø> (-0.01%) ⬇️
unittests 19.08% <5.92%> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18533

@nvazquez
nvazquez requested a review from kiranchavala July 10, 2026 17:26
@nvazquez

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-16528)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 52917 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t16528-kvm-ol8.zip
Smoke tests completed. 148 look OK, 1 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
ContextSuite context=TestSharedNetworkWithConfigDrive>:setup Error 48.34 test_network.py

@boring-cyborg boring-cyborg Bot added component:virtual-router Python Warning... Python code Ahead! labels Jul 24, 2026
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
4.6% Coverage on New Code (required ≥ 40%)

See analysis details on SonarQube Cloud

@DaanHoogland DaanHoogland moved this from Backlog to conflict/waiting in CloudStack Testing Aug 31, 2026
@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19383

@nvazquez

nvazquez commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@nvazquez nvazquez left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM

Also verified creating new zone from fresh installation against a Netris Controller version 4.13.0-007

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17070)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 58596 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t17070-kvm-ol8.zip
Smoke tests completed. 147 look OK, 2 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
ContextSuite context=TestIpv4Routing>:setup Error 0.00 test_ipv4_routing.py
test_hostha_enable_ha_when_host_in_maintenance Error 307.19 test_hostha_kvm.py

@nvazquez

nvazquez commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan package

1 similar comment
@nvazquez

nvazquez commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19478

@nvazquez

nvazquez commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17105)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 52506 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t17105-kvm-ol8.zip
Smoke tests completed. 148 look OK, 1 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
test_09_arping_in_cpvm Failure 5.21 test_diagnostics.py

@kiranchavala kiranchavala left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Pearl1594

Found a issue where a vm deployed on a rvr network if not acquiring a dhcp ip address and user-data is not getting applied

@nvazquez

nvazquez commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19498

@nvazquez

nvazquez commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@nvazquez a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@Pearl1594

Copy link
Copy Markdown
Contributor Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
4.2% Coverage on New Code (required ≥ 40%)

See analysis details on SonarQube Cloud

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19504

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17120)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 52961 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13591-t17120-kvm-ol8.zip
Smoke tests completed. 149 look OK, 0 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Development

Successfully merging this pull request may close these issues.

7 participants