skorchir commented on issue #13687: URL: https://github.com/apache/cloudstack/issues/13687#issuecomment-5922500179
Same symptom on 4.22.1.1 (VPC, VpcVirtualRouter, non-persistent tier offering). Traced it to the state poller's router selection rather than to the tunnel. **Symptom** A site-to-site VPN connection on a VPC with no running VM never changes state. After `createVpnConnection` it reads `Connecting` (or `Disconnected` when passive) indefinitely, even while the peer has completed IKE and reports its tunnel up; `resetVpnConnection` only rewrites the same word. Deploying one VM in a tier moves it to `Connected` within a minute. Destroying every VM and waiting out network GC freezes it at its last value, so a tunnel that later drops still reads `Connected`. `listRouters` shows the VPC router's guest NIC appearing and disappearing with the tier; the router itself stays Running. **Cause (branch 4.22, head 2e63c601; the cited files are byte-identical on tag 4.22.1.1 and on main)** - The only writer of `Connected`/`Disconnected` from live router state is `CheckRouterTask` → `updateSite2SiteVpnConnectionState` (`VirtualNetworkApplianceManagerImpl.java:1077-1080`, body `:784-870`), fed by `_routerDao.listIsolatedByHostId(null)`. - That query is an INNER JOIN on `router_network_ref` with `guest_type = Isolated` (`DomainRouterDaoImpl.java:110-118`, `:253-265`). A router with no such row is never polled. - A VPC router has no such row at deploy. It gets one when a tier is implemented (`VpcVirtualRouterElement.java:227-234` → `VpcVirtualNetworkApplianceManagerImpl.java:151-166`) and loses it when the tier is shut down (`removeVpcRouterFromGuestNetwork`). - A tier is implemented by the first VM start and shut down by `NetworkGarbageCollector` once no running VM holds a NIC in it (`NetworkOrchestrator.java:3602-3662`, `NetworkDaoImpl.findNetworksToGarbageCollect:540-547`). So until a VM runs, and again after the last one is gone, the task never looks at the router, and the connection keeps whatever `startVpnConnection` last wrote (`Site2SiteVpnManagerImpl.java:417-421`). **Fix** `updateSite2SiteVpnConnectionState` only does work for VPC routers: `getConnectionsForRouter` returns an empty list when `vpcId` is null (`Site2SiteVpnManagerImpl.java:887-896`). Selecting routers by isolated-tier membership is the wrong join for this step. `CheckRouterTask` already iterates `_vpcDao.listAll()` for its redundant-state half (`:1083-1088`); passing `_routerDao.listByVpcId(vpcId)` (`DomainRouterDaoImpl.java:415-420`) for each VPC that owns site-to-site connections into the VPN check, keeping its existing Running / redundant-PRIMARY / INTERNAL_LB_VM filters, polls the router for as long as it exists. A DAO method listing routers with `vpc_id IS NOT NULL` would do the same. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
