andrijapanicsb opened a new pull request, #14300: URL: https://github.com/apache/cloudstack/pull/14300
### Description This reopens #13684, which was merged as commit `e0f3006764d00f18a59945861b50bf55d01f64eb` and then reverted by #14116. The dev@ discussion on whether to change this default is still ongoing, so the change should not have landed on `main` yet. This PR restores the **identical** change for continued review (it is a revert of the revert — the diff is byte-for-byte the same as the merged #13684). Reference: - Original PR: #13684 (merged `e0f3006764`) - Revert: #14116 (`8afd1148a2`) ### Background Isolated guest networks created from the built-in default network offerings (`DefaultIsolatedNetworkOfferingWithSourceNatService` and `DefaultIsolatedNetworkOffering`) deny all egress by default, because they are seeded with a `NetworkOfferingVO` constructor that leaves `egressdefaultpolicy` at the Java primitive default (`false` = deny). Meanwhile `createNetworkOffering` without an explicit `egressdefaultpolicy` already defaults to **allow**, and VPC tiers (NetworkACL) allow egress out of the box. So the shipped defaults are inconsistent, and the default "simple Isolated network" is the surprising one — freshly deployed VMs cannot reach package mirrors, NTP, metadata, etc. until an allow-all egress rule is added. ### Changes - `ConfigurationServerImpl` seeds the two built-in Isolated network offerings with egress default policy **Allow**, on **fresh installations only**. - `AddNetworkOffering.vue` default flipped from `deny` to `allow`, so the UI no longer sends an explicit `deny` that overrides the `createNetworkOffering` API default. - `NetworkOfferingVO.setEgressDefaultPolicy` setter. - Unit tests: `ConfigurationServerImplTest` (seeding) and `CreateNetworkOfferingCmdTest` (API default). ### Backward compatibility - **Existing deployments are untouched.** The default offerings are seeded once, at first initialization; upgrades do not re-seed them and `persistDefaultNetworkOffering` never updates existing rows. No data migration / upgrade SQL runs against existing `network_offerings` or networks. - Only **fresh installations** get allow-by-default; the `egressdefaultpolicy` parameter and per-offering behaviour are unchanged. - The `egress_default_policy` DB column default is intentionally not changed. The one consideration is security posture on **new** clouds, which is exactly why there is an open dev@ discussion; this PR exists to keep the change reviewable while that concludes. ### Types of changes - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] New feature (non-breaking change which adds functionality) - [x] Enhancement (improves an existing feature and functionality) - [ ] Cleanup (Code refactoring and cleanup, that may add test cases) - [ ] build/CI ### How Has This Been Tested? Change is identical to the previously merged #13684. `ConfigurationServerImplTest` and `CreateNetworkOfferingCmdTest` cover the seeded default and the API default respectively. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
