skorchir commented on issue #13687:
URL: https://github.com/apache/cloudstack/issues/13687#issuecomment-5934628711

   Reproduced on a 4.22.1.1 lab with the management DB and router shells open, 
which confirms the mechanism above and adds the garbage-collection variant.
   
   **Setup.** Three VPCs on one KVM host: `vpca` and `vpcb` with one tier and 
one running VM each; `vpcd` with one tier and no VM. Site-to-site VPN between 
`vpcd` and `vpcb`, both sides `passive=false`.
   
   **Observed**
   - `router_network_ref` held one `Isolated` row for `vpca`'s router and one 
for `vpcb`'s. Nothing for `vpcd`'s router, which had only its public NIC.
   - `CheckRouterTask` logged `Found 2 routers to update status` every 30 s 
before and after `vpcd` existed.
   - `vpcb`'s connection toward `vpcd` read `Connected`. `vpcd`'s connection 
toward `vpcb` read `Connecting` for as long as it was left, while `ipsec 
statusall` on **both** routers showed the SA `ESTABLISHED` and the CHILD_SA 
`INSTALLED`. `vpcb`'s router had initiated.
   - On `vpcd`'s router, `ip route get <peer tier address>` sourced from the 
public IP, so its own trigger ping in `configure.py` never matches the 
`leftsubnet` trap policy; a VM-less VPC router can respond to IKE but never 
initiate it.
   
   **The reverse direction, after garbage collection** (`network.gc.interval` 
and `network.gc.wait` lowered to 60 s to make it quick): stopping the only VM 
in `vpcb`'s tier (not destroying it) moved the tier `Implemented → Shutdown → 
Allocated`, removed the router's tier NIC and its `router_network_ref` row, and 
the poller dropped to `Found 3 routers`. `vpcb`'s connections kept reading 
`Connected`. Deleting the far side's connection then removed the SA from 
`vpcb`'s router while the API still read `Connected` 40 s later. Starting the 
VM re-implemented the tier and the state corrected to `Disconnected` within one 
poll.
   
   **Workaround that holds.** A tier on a network offering with 
`ispersistent=true` (a clone of `DefaultIsolatedNetworkOfferingForVpcNetworks` 
with the same services and providers; `createNetworkOffering` accepts the flag 
with `forvpc=true`) is implemented at creation and never garbage-collected, so 
its router carries the row from the start. A VPC built on it reached 
`Connected` within 10 s with no VM, and moving an existing Allocated tier onto 
it with `updateNetwork networkofferingid=` implemented the tier immediately and 
unfroze its connection. Whether the poller should depend on tier implementation 
at all is still the question for the fix in the comment above.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to