skorchir commented on issue #13687:
URL: https://github.com/apache/cloudstack/issues/13687#issuecomment-5922500179

   Same symptom on 4.22.1.1 (VPC, VpcVirtualRouter, non-persistent tier 
offering). Traced it to the state poller's router selection rather than to the 
tunnel.
   
   **Symptom**
   
   A site-to-site VPN connection on a VPC with no running VM never changes 
state. After `createVpnConnection` it reads `Connecting` (or `Disconnected` 
when passive) indefinitely, even while the peer has completed IKE and reports 
its tunnel up; `resetVpnConnection` only rewrites the same word. Deploying one 
VM in a tier moves it to `Connected` within a minute. Destroying every VM and 
waiting out network GC freezes it at its last value, so a tunnel that later 
drops still reads `Connected`. `listRouters` shows the VPC router's guest NIC 
appearing and disappearing with the tier; the router itself stays Running.
   
   **Cause (branch 4.22, head 2e63c601; the cited files are byte-identical on 
tag 4.22.1.1 and on main)**
   
   - The only writer of `Connected`/`Disconnected` from live router state is 
`CheckRouterTask` → `updateSite2SiteVpnConnectionState` 
(`VirtualNetworkApplianceManagerImpl.java:1077-1080`, body `:784-870`), fed by 
`_routerDao.listIsolatedByHostId(null)`.
   - That query is an INNER JOIN on `router_network_ref` with `guest_type = 
Isolated` (`DomainRouterDaoImpl.java:110-118`, `:253-265`). A router with no 
such row is never polled.
   - A VPC router has no such row at deploy. It gets one when a tier is 
implemented (`VpcVirtualRouterElement.java:227-234` → 
`VpcVirtualNetworkApplianceManagerImpl.java:151-166`) and loses it when the 
tier is shut down (`removeVpcRouterFromGuestNetwork`).
   - A tier is implemented by the first VM start and shut down by 
`NetworkGarbageCollector` once no running VM holds a NIC in it 
(`NetworkOrchestrator.java:3602-3662`, 
`NetworkDaoImpl.findNetworksToGarbageCollect:540-547`).
   
   So until a VM runs, and again after the last one is gone, the task never 
looks at the router, and the connection keeps whatever `startVpnConnection` 
last wrote (`Site2SiteVpnManagerImpl.java:417-421`).
   
   **Fix**
   
   `updateSite2SiteVpnConnectionState` only does work for VPC routers: 
`getConnectionsForRouter` returns an empty list when `vpcId` is null 
(`Site2SiteVpnManagerImpl.java:887-896`). Selecting routers by isolated-tier 
membership is the wrong join for this step. `CheckRouterTask` already iterates 
`_vpcDao.listAll()` for its redundant-state half (`:1083-1088`); passing 
`_routerDao.listByVpcId(vpcId)` (`DomainRouterDaoImpl.java:415-420`) for each 
VPC that owns site-to-site connections into the VPN check, keeping its existing 
Running / redundant-PRIMARY / INTERNAL_LB_VM filters, polls the router for as 
long as it exists. A DAO method listing routers with `vpc_id IS NOT NULL` would 
do the same.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to