Uploaded image for project: 'OpenShift Core Networking'
  1. OpenShift Core Networking
  2. CORENET-5852

Add IPsec metric for every IPsec tunnel

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • openshift-4.19, openshift-4.15, openshift-4.16, openshift-4.17, openshift-4.18
    • OVN Kubernetes
    • None
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • CORENET Sprint 270, CORENET Sprint 271, CORENET Sprint 272, CORENET Sprint 273, CORENET Sprint 274, CORENET Sprint 275, CORENET Sprint 276

      We currently need to rely on looking at various command outputs like:

      ipsec status
      ipsec trafficstatus
      ip xfrm state
      ip xfrm policy
      ovs-appctl -t ovs-monitor-ipsec tunnels/show

       to get know health status for every IPsec tunnel on the cluster between nodes.

      There should be a metric to be introduced on every node and exported to prometheus server which gives status of every tunnel.
      An appropriate alert rule must be defined when ipsec is not configured or not active within particular period. 

              pepalani@redhat.com Periyasamy Palanisamy
              pepalani@redhat.com Periyasamy Palanisamy
              None
              None
              None
              None
              Votes:
              1 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: