andrijapanicsb opened a new pull request, #14300:
URL: https://github.com/apache/cloudstack/pull/14300

   ### Description
   
   This reopens #13684, which was merged as commit 
`e0f3006764d00f18a59945861b50bf55d01f64eb` and then reverted by #14116. The 
dev@ discussion on whether to change this default is still ongoing, so the 
change should not have landed on `main` yet. This PR restores the **identical** 
change for continued review (it is a revert of the revert — the diff is 
byte-for-byte the same as the merged #13684).
   
   Reference:
   - Original PR: #13684 (merged `e0f3006764`)
   - Revert: #14116 (`8afd1148a2`)
   
   ### Background
   
   Isolated guest networks created from the built-in default network offerings 
(`DefaultIsolatedNetworkOfferingWithSourceNatService` and 
`DefaultIsolatedNetworkOffering`) deny all egress by default, because they are 
seeded with a `NetworkOfferingVO` constructor that leaves `egressdefaultpolicy` 
at the Java primitive default (`false` = deny). Meanwhile 
`createNetworkOffering` without an explicit `egressdefaultpolicy` already 
defaults to **allow**, and VPC tiers (NetworkACL) allow egress out of the box. 
So the shipped defaults are inconsistent, and the default "simple Isolated 
network" is the surprising one — freshly deployed VMs cannot reach package 
mirrors, NTP, metadata, etc. until an allow-all egress rule is added.
   
   ### Changes
   
   - `ConfigurationServerImpl` seeds the two built-in Isolated network 
offerings with egress default policy **Allow**, on **fresh installations only**.
   - `AddNetworkOffering.vue` default flipped from `deny` to `allow`, so the UI 
no longer sends an explicit `deny` that overrides the `createNetworkOffering` 
API default.
   - `NetworkOfferingVO.setEgressDefaultPolicy` setter.
   - Unit tests: `ConfigurationServerImplTest` (seeding) and 
`CreateNetworkOfferingCmdTest` (API default).
   
   ### Backward compatibility
   
   - **Existing deployments are untouched.** The default offerings are seeded 
once, at first initialization; upgrades do not re-seed them and 
`persistDefaultNetworkOffering` never updates existing rows. No data migration 
/ upgrade SQL runs against existing `network_offerings` or networks.
   - Only **fresh installations** get allow-by-default; the 
`egressdefaultpolicy` parameter and per-offering behaviour are unchanged.
   - The `egress_default_policy` DB column default is intentionally not changed.
   
   The one consideration is security posture on **new** clouds, which is 
exactly why there is an open dev@ discussion; this PR exists to keep the change 
reviewable while that concludes.
   
   ### Types of changes
   
   - [ ] Breaking change (fix or feature that would cause existing 
functionality to change)
   - [x] New feature (non-breaking change which adds functionality)
   - [x] Enhancement (improves an existing feature and functionality)
   - [ ] Cleanup (Code refactoring and cleanup, that may add test cases)
   - [ ] build/CI
   
   ### How Has This Been Tested?
   
   Change is identical to the previously merged #13684. 
`ConfigurationServerImplTest` and `CreateNetworkOfferingCmdTest` cover the 
seeded default and the API default respectively.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to