[apic-mapping] Need single_tenant_mode similar to ML2 for Cisco IT
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Group Based Policy |
In Progress
|
Undecided
|
Kent Wu |
Bug Description
Cisco IT wants to create all the GBP resources under a single APIC tenant. After discussion we decided to introduce the single_tenant_mode from ML2 to GBP. And below is the related email thread.
XXXXXXXXXXXXXXX
Kent Wu <email address hidden>
Oct 20 (7 days ago)
to Jishnu, Mandeep, Sumit, Amit
Just to clarify: this potential issue already exists as of today and has nothing to do with this feature. Basically openStack allows objects with the same name as internally they use uuid to distinguish however in APIC they will all map to the same object....
-Kent
On Thu, Oct 20, 2016 at 4:12 PM, Jishnu Banerjee <email address hidden> wrote:
Referring to my reply.. the caveat will happen if the PTGs are in the same tenant(project)
On Thu, Oct 20, 2016 at 4:07 PM, Jishnu Banerjee <email address hidden> wrote:
Incase of use_name + GBP mode, we have a bug/caveat here:
Say user:
1.Creates a ptg: A, hosts a VM
2.Later point in time, he 'by mistake' creates another PTG but with same name as #1. Please note: this step will NOT create any new EPG on the APIC
3. He decides to delete the #2 ptg
Effect: Traffic will stop from the above VM. Expectation: not to impact anything other than deleting the 2nd PTG
Reason: We apparently delete the ptg-A from the ACI since the POST req to APIC contains the data-set in which the 'rn" attribute of fvAEPg is the name of the ptg
data = {"fvTenant": {"attributes": {"rn": "tn-_noirolab_
Regards,
jishnu
On Thu, Oct 20, 2016 at 10:53 AM, Mandeep Dhami <email address hidden> wrote:
Sadly True. With nameAlias implementation, we will "eventually" get rid of it. For now, they are both production. In fact CiscoIT will be using use_name :-(
On Thu, Oct 20, 2016 at 10:30 AM, Kent Wu <email address hidden> wrote:
On Wed, Oct 19, 2016 at 9:23 PM, Sumit Naiksatam <email address hidden> wrote:
Changed in group-based-policy: | |
status: | New → In Progress |
assignee: | nobody → Kent Wu (wu-o) |
Reviewed: https:/ /review. openstack. org/390994 /git.openstack. org/cgit/ openstack/ group-based- policy/ commit/ ?id=dfef8cae604 d0e7e0f65945af3 40ca120e35b20f
Committed: https:/
Submitter: Jenkins
Branch: master
commit dfef8cae604d0e7 e0f65945af340ca 120e35b20f
Author: Kent Wu <email address hidden>
Date: Wed Oct 26 18:03:04 2016 -0700
[apic-mapping] Introduce single_tenant_mode to GBP workflow
Cisco IT wants to create all the GBP resources and maps them to a tenant_ mode in ML2 to GBP to achieve this then.
single tenant only under APIC. We will introduce the
single_
Change-Id: I62a668142564f8 549651f19c717f8 f7679660e54
Partial-Bug: 1637278