Skip to content

Support VPC public gateway rate throttling, built on NIC/network rate persistence and precedence fixes - #13325

Open
sudo87 wants to merge 40 commits into
apache:mainfrom
shapeblue:networkThrottling
Open

sudo87 wants to merge 40 commits into
apache:mainfrom
shapeblue:networkThrottling

Conversation

@sudo87

@sudo87 sudo87 commented Jun 3, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds an operator-configurable data transfer rate for a VPC's public/internet-facing gateway, independent of the per-tier rates that network offerings already control.

Precedence:

VPC offering  rate >  vpc.public.network.throttling.rate (default unlimited)

In addition to vpc, there is a change in precedence order for network rate for NIC and VRs being added in this PR.

For NICs:

Default used to select network rate based on below:

Bandwidth from compute offering  > "vm.network.throttling.rate" config

Other NICs use:

Bandwidth from Network offering > "network.throttling.rate" config

Going forward Default NIC precedence will be used for all NICs

For VR's guest interface:

Old precendence:

Bandwidth from Network offering > "network.throttling.rate" config

New one:

Bandwidth from System offering > Network offering > "network.throttling.rate" config

Also persists the effective network rate per NIC and Network and exposes the effective network rate (bandwidth throttling) configured for NICs and guest networks in the API responses and UI.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

Verified end-to-end in a lab: API responses, the actual libvirt bandwidth configuration on the router, and measured live throughput across a multi-tier VPC confirming tiers correctly share one capped public-gateway.

How did you try to break this feature and the system with this change?

@sudo87 sudo87 changed the title persist and expose effective network rate for NIC, Network and compute offering Persist and expose effective network rate for NIC, Network and compute offering Jun 3, 2026
@sudo87
sudo87 marked this pull request as draft June 3, 2026 09:56
@codecov

codecov Bot commented Jun 3, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 3.70%. Comparing base (510d0ec) to head (007bf8b).

❗ There is a different number of reports uploaded between BASE (510d0ec) and HEAD (007bf8b). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (510d0ec) HEAD (007bf8b)
unittests 1 0
Additional details and impacted files
@@              Coverage Diff              @@
##               main   #13325       +/-   ##
=============================================
- Coverage     19.91%    3.70%   -16.21%     
=============================================
  Files          6373      487     -5886     
  Lines        577230    41999   -535231     
  Branches      70696     7945    -62751     
=============================================
- Hits         114942     1558   -113384     
+ Misses       449722    40214   -409508     
+ Partials      12566      227    -12339     
Flag Coverage Δ
uitests 3.70% <ø> (-0.01%) ⬇️
unittests ?

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@bernardodemarco
bernardodemarco requested a review from hsato03 June 3, 2026 12:23
@github-actions

github-actions Bot commented Jun 8, 2026

Copy link
Copy Markdown

This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch.

@weizhouapache weizhouapache added this to the 4.24.0 milestone Jun 29, 2026
@DaanHoogland DaanHoogland moved this from Backlog to conflict/waiting for author in CloudStack Testing Aug 31, 2026
# Conflicts:
#	server/src/main/java/com/cloud/vm/UserVmManagerImpl.java
#	ui/src/config/section/network.js
- Add network_rate column to nics table (schema-42300to42400.sql)
- Add DB upgrade path: Upgrade42300to42400 registered in DatabaseUpgradeChecker
- Add network_rate field and getter/setter to NicVO
- Set network_rate on NicVO in NetworkOrchestrator.allocateNic() where rate
  is already computed, eliminating secondary per-NIC update calls
- Add getNetworkRate() to Nic interface so ApiResponseHelper.createNicResponse
  can call result.getNetworkRate() without casting or extra DB queries
- Add nic_network_rate to user_vm_view and UserVmJoinVO so listVirtualMachines
  reads rate from the join without extra per-NIC findNicById calls
- Update UserVmJoinDaoImpl to use uvo.getNicNetworkRate() directly
- Expose network_rate in NicResponse as Integer (null = unlimited)
- Refresh NIC rates on VM start via refreshNicNetworkRates in UserVmManagerImpl
@sudo87

sudo87 commented Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@sudo87 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19103

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch.

@sudo87

sudo87 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@sudo87 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19139

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved schema, persistence, API, and UI issues remain.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)
What changed in this PR

Adds configurable VPC public-gateway throttling, effective rate persistence, API/UI exposure, and migration support.

Changes:

  • Adds VPC offering and zone-level rate configuration.
  • Persists and backfills effective NIC and network rates.
  • Extends APIs, UI views, tests, and schema migration.
File Description
ui/​src/​views/​offering/​AddVpcOffering.vue Adds public gateway rate input.
ui/​src/​views/​network/​NicsTable.vue Displays NIC rates.
ui/​src/​config/​section/​offering.js Adds offering rate fields.
ui/​src/​config/​section/​network.js Adds network rate details.
ui/​src/​components/​view/​ListView.vue Formats rate values.
ui/​src/​components/​view/​DetailsTab.vue Formats rate details.
ui/​public/​locales/​en.json Adds rate label.
server/​src/​test/​java/​com/​cloud/​vpc/​MockConfigurationManagerImpl.java Updates the test mock.
server/​src/​test/​java/​com/​cloud/​network/​vpc/​VpcManagerImplTest.java Tests VPC rate validation.
server/​src/​test/​java/​com/​cloud/​network/​NetworkModelImplTest.java Tests rate precedence.
server/​src/​main/​java/​com/​cloud/​network/​vpc/​VpcManagerImpl.java Handles VPC rate persistence.
server/​src/​main/​java/​com/​cloud/​network/​NetworkServiceImpl.java Persists network rates.
server/​src/​main/​java/​com/​cloud/​network/​NetworkModelImpl.java Resolves effective rates.
server/​src/​main/​java/​com/​cloud/​network/​NetworkMigrationManagerImpl.java Persists rates during migration.
server/​src/​main/​java/​com/​cloud/​configuration/​ConfigurationManagerImpl.java Resolves VPC rate configuration.
server/​src/​main/​java/​com/​cloud/​api/​query/​vo/​VpcOfferingJoinVO.java Adds offering rate projection.
server/​src/​main/​java/​com/​cloud/​api/​query/​vo/​UserVmJoinVO.java Adds VM NIC rate projection.
server/​src/​main/​java/​com/​cloud/​api/​query/​vo/​DomainRouterJoinVO.java Adds router NIC rate projection.
server/​src/​main/​java/​com/​cloud/​api/​query/​dao/​VpcOfferingJoinDaoImpl.java Maps offering rates.
server/​src/​main/​java/​com/​cloud/​api/​query/​dao/​UserVmJoinDaoImpl.java Maps VM NIC rates.
server/​src/​main/​java/​com/​cloud/​api/​query/​dao/​DomainRouterJoinDaoImpl.java Maps router NIC rates.
server/​src/​main/​java/​com/​cloud/​api/​ApiResponseHelper.java Adds rate fields to responses.
plugins/​network-elements/​juniper-contrail/​src/​main/​java/​org/​apache/​cloudstack/​network/​contrail/​management/​ContrailManagerImpl.java Updates offering API usage.
engine/​schema/​src/​main/​resources/​META-INF/​db/​views/​cloud.vpc_offering_view.sql Adds offering rate to the view.
engine/​schema/​src/​main/​resources/​META-INF/​db/​views/​cloud.user_vm_view.sql Adds VM NIC rate to the view.
engine/​schema/​src/​main/​resources/​META-INF/​db/​views/​cloud.domain_router_view.sql Adds router NIC rate to the view.
engine/​schema/​src/​main/​resources/​META-INF/​db/​schema-42300to2400.sql Adds migration columns.
engine/​schema/​src/​main/​java/​com/​cloud/​vm/​NicVO.java Persists NIC rates.
engine/​schema/​src/​main/​java/​com/​cloud/​upgrade/​NetworkRateBackfill.java Backfills effective rates.
engine/​schema/​src/​main/​java/​com/​cloud/​upgrade/​dao/​Upgrade42300to2400.java Runs the migration.
engine/​schema/​src/​main/​java/​com/​cloud/​network/​vpc/​VpcOfferingVO.java Persists VPC offering rates.
engine/​orchestration/​src/​main/​java/​org/​apache/​cloudstack/​engine/​orchestration/​NetworkOrchestrator.java Computes and stores NIC rates.
engine/​components-api/​src/​main/​java/​com/​cloud/​configuration/​ConfigurationManager.java Adds rate-resolution APIs.
engine/​api/​src/​main/​java/​org/​apache/​cloudstack/​engine/​orchestration/​service/​NetworkOrchestrationService.java Adds public throttling configuration.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​VpcResponse.java Exposes VPC public rate.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​VpcOfferingResponse.java Exposes offering public rate.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​NicResponse.java Exposes NIC rate.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​NetworkResponse.java Exposes network rate.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​command/​admin/​vpc/​UpdateVPCOfferingCmd.java Adds update parameter.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​command/​admin/​vpc/​CreateVPCOfferingCmd.java Adds creation parameter.
api/​src/​main/​java/​org/​apache/​cloudstack/​api/​ApiConstants.java Adds the rate constant.
api/​src/​main/​java/​com/​cloud/​vm/​Nic.java Extends the NIC contract.
api/​src/​main/​java/​com/​cloud/​network/​vpc/​VpcProvisioningService.java Extends offering provisioning.
api/​src/​main/​java/​com/​cloud/​network/​vpc/​VpcOffering.java Extends the offering contract.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +22 to +24
ALTER TABLE `cloud`.`nics` ADD COLUMN `network_rate` int DEFAULT NULL COMMENT 'effective network rate in Mb/s for this NIC, -1 means unlimited';

ALTER TABLE `cloud`.`vpc_offerings` ADD COLUMN `public_nw_rate` smallint unsigned DEFAULT NULL COMMENT 'public gateway (internet-facing) network rate throttle mbits/s';
Comment thread engine/schema/src/main/resources/META-INF/db/schema-42300to2400.sql Outdated
Comment thread server/src/main/java/com/cloud/network/vpc/VpcManagerImpl.java Outdated
# Conflicts:
#	engine/schema/src/main/resources/META-INF/db/schema-42300to2400.sql
@github-actions

Copy link
Copy Markdown

This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch.

@sudo87
sudo87 marked this pull request as ready for review September 29, 2026 04:20
Copilot AI review requested due to automatic review settings September 29, 2026 04:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A critical migration failure-handling issue and several moderate correctness issues remain unresolved.

Review effort: Lite
Findings: 2 High severity · 1 Medium severity

Open (3)
Resolved since last review (3)

Comment thread ui/src/config/section/offering.js
# Conflicts:
#	engine/schema/src/main/resources/META-INF/db/schema-42300to2400.sql
Copilot code review flagged this: newVpcOfferingResponse normalizes an
unset/zero public network rate to -1 for display, but UpdateVPCOfferingCmd
only accepts 0 as the unlimited sentinel and rejects any negative value.
The generic edit form pre-fills from the resource and resubmits unchanged
fields, so editing any VPC offering with an unlimited public rate failed.

Map -1 back to 0 before submitting an updateVPCOffering edit.
Copilot AI review requested due to automatic review settings September 29, 2026 05:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved persistence, migration, restart-ordering, and UI/API contract issues remain.

Review effort: Lite
Findings: 2 High severity · 3 Medium severity · 1 Low severity

Open (6)

Comment thread server/src/main/java/com/cloud/network/vpc/VpcManagerImpl.java Outdated
Comment thread api/src/main/java/org/apache/cloudstack/api/response/VpcOfferingResponse.java Outdated
…entry is missing

createNetworkResponse only set networkRate when the 'networkrate'
network_details row existed. If it's missing (e.g. NetworkRateBackfill
failed for that network during upgrade), the field was left null and
silently omitted from the API response instead of falling back to -1,
unlike the equivalent NIC and VPC rate fields.
Copilot AI review requested due to automatic review settings September 29, 2026 05:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A critical upgrade-path issue and multiple unresolved persistence, update, and UI correctness issues remain.

Review effort: Lite
Findings: 3 High severity · 3 Medium severity · 1 Low severity

Open (7)
Previously missed (3)

In code that hasn't changed since last review

Medium severity Refresh NIC rates after network offering changes

server/​src/​main/​java/​com/​cloud/​network/​NetworkServiceImpl.java:3608

When a network offering changes, this refreshes only the network-level snapshot. Existing NIC rows keep their previous network_rate, while the replug path is limited to running VMware user VMs; other attached VMs/routers can therefore continue to expose the old rate through the new NIC API (and retain it until a later allocate/prepare). Recompute and persist the effective rate for each attached NIC as part of the offering update.

Medium severity Pass explicit zero rate when creating VPC offerings

ui/​src/​views/​offering/​AddVpcOffering.vue:735

A value of 0 is the documented explicit unlimited setting, but this truthiness check omits it from createVPCOffering. On a zone with a nonzero vpc.public.network.throttling.rate, entering 0 therefore applies the zone cap instead of the requested unlimited offering. Test for presence rather than truthiness so zero is sent.

Low severity Document -1 representation for unset offering values

api/​src/​main/​java/​org/​apache/​cloudstack/​api/​response/​VpcOfferingResponse.java:110

The response mapper now normalizes both an unset offering value and explicit 0 to -1, but this description still promises null for an unset value. That contradicts the actual API payload and the UI's -1 handling; document the -1 representation and clarify that an unset value may fall back to the zone/global default.

Comment thread engine/schema/src/main/resources/META-INF/db/schema-42300to2400.sql
- importNic: persist the computed effective network rate on the NIC
  instead of leaving network_rate NULL for imported NICs.
- restartVpc: only refresh the persisted public network rate snapshot
  after a restart actually succeeds, not before either restart path
  runs, so a failed restart can't leave a stale/premature snapshot.
- VpcOfferingResponse: fix stale doc string; the response normalizes
  unset/unlimited to -1, not null.
Copilot AI review requested due to automatic review settings September 29, 2026 05:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved moderate issues can leave persisted effective rates and API/UI values inconsistent after offering changes.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (6)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Recompute NIC rates when network offering changes

server/​src/​main/​java/​com/​cloud/​network/​NetworkServiceImpl.java:3608

Updating the network offering changes the persisted network-level rate here, but it never recomputes nics.network_rate for NICs already attached to this network. This leaves API responses and the applied VR bandwidth stale; in particular, a router guest NIC whose system offering has no rate should now fall back to the new network-offering rate, but will continue to expose/use its old persisted value. Update the affected NICs as part of the offering change or make the reconfiguration path persist the recomputed rate.

@sudo87

sudo87 commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@sudo87 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19344

private Boolean conserveMode;

@Parameter(name = ApiConstants.PUBLIC_NETWORK_RATE, type = CommandType.INTEGER,
since = "4.24.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

24.0

private Integer sortKey;

@Parameter(name = ApiConstants.PUBLIC_NETWORK_RATE, type = CommandType.INTEGER,
since = "4.24.0",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

24.0

private Integer privateMtu;

@SerializedName(ApiConstants.NETWORKRATE)
@Param(description = "Network rate (in Mb/s) configured for the Guest interface of this network; -1 if unlimited", since = "4.24.0")

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

24.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what about PUBLIC_NETWORK_RATE ?
do we consider in this PR, or a further PR ?


@Parameter(name = ApiConstants.PUBLIC_NETWORK_RATE, type = CommandType.INTEGER,
since = "4.24.0",
description = "Data transfer rate in megabits per second allowed for a VPC's public gateway (internet-facing network), created with this offering. Use 0 for unlimited")

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Default is unlimited
Use 0 for unlimited
-1 if unlimited

can they be consistent ?

@Parameter(name = ApiConstants.SORT_KEY, type = CommandType.INTEGER, description = "Sort key of the VPC offering, integer")
private Integer sortKey;

@Parameter(name = ApiConstants.PUBLIC_NETWORK_RATE, type = CommandType.INTEGER,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

normally we do not change the properties of existing offerings, for example cpu/memor of service offering, size of disk offering, supported network services of network offering,

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants