Bug 1471531 - [RFE] Add TripleO validation of VLANs using introspected LLDP data
[RFE] Add TripleO validation of VLANs using introspected LLDP data
Status: ON_QA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-validations (Show other bugs)
13.0 (Queens)
All Linux
medium Severity high
: Upstream M1
: 13.0 (Queens)
Assigned To: Bob Fournier
Omri Hochman
: FutureFeature, Triaged
Depends On: 1554248
  Show dependency treegraph
Reported: 2017-07-16 13:22 EDT by Bob Fournier
Modified: 2018-04-18 05:54 EDT (History)
10 users (show)

See Also:
Fixed In Version: openstack-tripleo-validations-8.1.1-0.20180119231917.2ff3c79.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
OpenStack gerrit 512375 None master: MERGED tripleo-validations: Add validation to check VLANs against switch info in Ironic intospection data (I5adeefea1534db0ede6... 2018-02-07 09:23 EST

  None (edit)
Description Bob Fournier 2017-07-16 13:22:29 EDT
Description of problem:
TripleO Heat Templates can define VLANs per NIC for roles (controller, compute etc.) for isolated networks.  The problem is that the network switches that the NICs are attached to may not have been set up properly for these VLANs.  As of OSP-11, LLDP data for baremetal nodes is captured during the Ironic inspection process which may have VLAN info for the attached switch ports.  This VLAN info can be checked during a pre-deployment validation to ensure that the VLANs configured in THT nic config files are also configured on the switch.  

The NIC alias to real NIC name conversion must be done during this validation similar to what os-net-config does in order to map the NICs configured in nic config files to actual NIC names in the introspected data.

Since roles can use different VLANs, e.g. the controller may use additional networks than compute so would use additional VLANs, the challenge is to map the roles to Ironic nodes in the pre-deployment phase.  This mapping may not be available in this pre-deployment validation phase.  It may be necessary to only check that ALL configured VLANs per switch port are available on the switches. In other words, if a role in THT has eth0 with VLANs 10, 11, and 12, all Ironic nodes must have LLDP data indicating that the switch port attached to eth0 has VLANs 10, 11, 12.  If it is possible to map the roles to Ironic nodes in this phase then it will be possible to check, for  example, that all controller nodes have a switch port mapped to eth0 with VLANs 10, 11, and 12.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.  Incorrectly configure network switch VLANs different than THT nic config files
2.  Run deployment

Actual results:
Deployment may fail eventually depending on which VLANs are incorrect.

Expected results:
Pre-deployment validation will detect that switch is incorrectly configured and return error.

Additional info:
Comment 4 Bob Fournier 2018-04-13 12:42:31 EDT
Verification is pending fix for https://bugzilla.redhat.com/show_bug.cgi?id=1554248

Note You need to log in before you can comment on or make changes to this bug.