Uploaded image for project: 'OpenShift Core Networking'
  1. OpenShift Core Networking
  2. CORENET-2600

Introduce multi-net policies - IPAM via OVN-K only

XMLWordPrintable

    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None

      Update the multi-net controller to:

      • build default deny-all port group for each of the flat L2 networks targeted by multi-net policy
      • build policies port-group + translated ACLs for each of the provisioned multi-net policies

      Must also update the direction of the ACL flows for egress:

      • current direction for allow ACLs is `to-lport`
      • `to-lport` is evaluated in the egress pipepine
      • when ports are on different nodes, `to-lport` is evaluated in the dst node.

      Definition of done:

      • PRs implementing the above merged
      • e2e tests asserting these work merged

              mduarted@redhat.com Miguel Duarte de Mora Barroso
              mduarted@redhat.com Miguel Duarte de Mora Barroso
              None
              Jaime CaamaƱo Ruiz
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: