Comment 3 for bug 1658711

Revision history for this message
Inessa Vasilevskaya (ivasilevskaya) wrote :

I'd suggest we add this as known issue to release notes:

In case of openvswitch firewall booting vms with security group that has security group rules with remote_group_id defined may result in drastical performance degradation due to a solid number of ovs flows being generated. This happens because currently the number of ovs flows has quadratic growth if remote_group_id is specified during security group rule creation [https://bugs.launchpad.net/mos/+bug/1658711].
The workaround is to design security groups so that remote_group_id won't be set for security group rules.