Skip to content

VMware NSX network implementation can fail before backing DV port group is visible #13752

Description

@Dogface2k

Problem

On VMware environments using the NSX integration, implementing a guest network can fail during PlugNicCommand even though CreateNsxSegmentCommand has already succeeded.

The NSX segment is created outside vCenter. Its backing distributed virtual port group can therefore take a short time to become visible through the vCenter API. HypervisorHostHelper.prepareNetwork currently performs only one immediate lookup for NSX networks and returns failure when that first lookup is empty.

Sanitized management-server sequence:

CreateNsxSegmentCommand ... NsxAnswer result=true
Prepare network on vmwaredvs <redacted>
Failed to create guest network <redacted>
PlugNicAnswer result=false

The failure rolls back the NIC attachment and prevents the persistent VPC guest network from being implemented.

Versions

  • Apache CloudStack 4.22.1.0
  • VMware vSphere / vCenter 8.0.3
  • CloudStack NSX integration

Steps to reproduce

  1. Configure a VMware zone with the CloudStack NSX integration.
  2. Create an NSX-backed VPC guest network.
  3. Allow the NSX segment command to complete while the backing DV port group is not yet visible through vCenter.
  4. Observe the immediate DV port group lookup fail in HypervisorHostHelper.prepareNetwork, followed by a failed PlugNicCommand.

Expected behavior

After successful NSX segment creation, CloudStack should use its existing bounded DV port group readiness wait before attempting to attach the NIC. If the port group never becomes visible, the existing timeout should still fail the operation cleanly.

Proposed fix

Enable the existing waitForDvPortGroupReady path for NSX broadcast domains and add a regression test covering an empty first vCenter lookup followed by a successful lookup.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions