Neutron documentation states that dvr_snat is not supported on compute nodes

Bug #1947300 reported by Trent Lloyd
16
This bug affects 2 people
Affects Status Importance Assigned to Milestone
OpenStack Neutron Open vSwitch Charm
New
Undecided
Unassigned

Bug Description

Currently the majority of new charmed neutron deployments are using dvr_snat mode to have no neutron-gateway nodes and distribute the network function over the compute nodes. Unfortunately upstream has recently clarified this is not intended to be supported:

From: https://bugs.launchpad.net/neutron/+bug/1934666

"It was decided during a meeting that dvr_snat mode is unsupported on Compute nodes, which makes this patch not longer needed. Please refer to the bug report from the commit message for more info as well as the link to the logs of the IRC meeting."

Meeting Log: https://meetings.opendev.org/meetings/networking/2021/networking.2021-07-20-14.00.log.html#l-113

Also noted in https://bugs.launchpad.net/neutron/+bug/1825147 - as explicitly_egress_direct + dvr_snat is broken, which we had recently enabled in neutron-openvswitch and is breaking in various cases. That needs to be reverted but the wider issue of the fact that dvr_snat is commonly used in our deployments on compute needs to be addressed somehow or we need to change the upstream direction. Given we now have many deployments with no nodes capable of running a neutron-gateway node this would be problematic to revert.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.