From: Numan Siddique <[email protected]>
start_ovsdb__() derives every per-database variable from its DB
argument, so for DB=OVNBR it reads $OVN_OVNBR_LOG and
$OVN_OVNBR_DB_SSL_*. Neither was defined: set_defaults() defined
OVNBR_DB_SSL_* instead, and nothing defined a log variable. As a
result:
- The --ovnbr-db-ssl-* options were accepted and silently ignored,
so the OVN_Bridge_Controller ovsdb-server always took its TLS
settings from the database, whatever was passed on the command
line.
- --ovn-br-db-log was rejected as an unknown option, and the
ovsdb-server was started with no logging parameters at all,
unlike every other database server.
- --ovsdb-br-wrapper was rejected as an unknown option, and
start_ovnbr_ovsdb() did not pass a wrapper in any case.
Name the options after the variables start_ovsdb__() reads, the way
the NB, SB and IC databases already do and the way the existing
--ovn-ovnbr-logfile option is named: --ovn-ovnbr-db-ssl-*,
--ovn-ovnbr-log (defaulting to "-vconsole:off -vfile:info", as for
the other database servers) and --ovsdb-ovnbr-wrapper. None of the
old names ever took effect, so no working configuration is broken by
the rename.
Also fix the example in the ovn-br-db systemd unit, which used
--db-br-create-insecure-remote; the option is
--db-ovnbr-create-insecure-remote.
Fixes: 22dbd8021359 ("ovn-ctl: Add commands to start OVN bridge controller
services.")
Reported-by: Dumitru Ceara <[email protected]>
Assisted-by: Claude Opus 5.5, Claude Code
Signed-off-by: Numan Siddique <[email protected]>
---
rhel/usr_lib_systemd_system_ovn-br-db.service | 4 +--
utilities/ovn-ctl | 33 ++++++++++---------
utilities/ovn-ctl.8.xml | 29 +++++++++-------
3 files changed, 37 insertions(+), 29 deletions(-)
diff --git a/rhel/usr_lib_systemd_system_ovn-br-db.service
b/rhel/usr_lib_systemd_system_ovn-br-db.service
index 6de2a22f1e..a6f6631b09 100644
--- a/rhel/usr_lib_systemd_system_ovn-br-db.service
+++ b/rhel/usr_lib_systemd_system_ovn-br-db.service
@@ -7,11 +7,11 @@
# /etc/systemd/system/ovn-br-db.d/local.conf:
#
# [System]
-# Environment="OVN_BR_DB_OPTS=--db-br-create-insecure-remote=yes"
+# Environment="OVN_BR_DB_OPTS=--db-ovnbr-create-insecure-remote=yes"
#
# Alternatively, you may specify environment variables in the file
/etc/sysconfig/ovn-br-db:
#
-# OVN_BR_DB_OPTS="--db-br-create-insecure-remote=yes"
+# OVN_BR_DB_OPTS="--db-ovnbr-create-insecure-remote=yes"
[Unit]
Description=OVN Bridge Controller OVSDB server
diff --git a/utilities/ovn-ctl b/utilities/ovn-ctl
index 788f1c14ba..8b73132e32 100755
--- a/utilities/ovn-ctl
+++ b/utilities/ovn-ctl
@@ -461,7 +461,8 @@ start_ic_ovsdb () {
start_ovnbr_ovsdb() {
- start_ovsdb__ OVNBR br OVN_Bridge_Controller BR_Global
+ start_ovsdb__ OVNBR br OVN_Bridge_Controller BR_Global \
+ "$OVSDB_OVNBR_WRAPPER"
}
sync_status() {
@@ -1134,7 +1135,9 @@ set_defaults () {
OVNBR_CONTROLLER_WRAPPER=
OVNBR_CONTROLLER_LOG="-vconsole:emer -vsyslog:err -vfile:info"
+ OVN_OVNBR_LOG="-vconsole:off -vfile:info"
OVN_OVNBR_LOGFILE="$ovn_logdir/ovsdb-server-ovnbr.log"
+ OVSDB_OVNBR_WRAPPER=
OVNBR_CONTROLLER_SSL_KEY=""
OVNBR_CONTROLLER_SSL_CERT=""
@@ -1149,12 +1152,12 @@ set_defaults () {
DB_OVNBR_DETACH="yes"
DB_OVNBR_USE_REMOTE_IN_DB="yes"
- OVNBR_DB_SSL_KEY=""
- OVNBR_DB_SSL_CERT=""
- OVNBR_DB_SSL_CA_CERT=""
- OVNBR_DB_SSL_PROTOCOLS=""
- OVNBR_DB_SSL_CIPHERS=""
- OVNBR_DB_SSL_CIPHERSUITES=""
+ OVN_OVNBR_DB_SSL_KEY=""
+ OVN_OVNBR_DB_SSL_CERT=""
+ OVN_OVNBR_DB_SSL_CA_CERT=""
+ OVN_OVNBR_DB_SSL_PROTOCOLS=""
+ OVN_OVNBR_DB_SSL_CIPHERS=""
+ OVN_OVNBR_DB_SSL_CIPHERSUITES=""
}
set_option () {
@@ -1333,15 +1336,15 @@ Options:
--ovnbr-controller-ssl-protocols=PROTOCOLS OVN Bridge Controller SSL/TLS
protocols
--ovnbr-controller-ssl-ciphers=CIPHERS OVN Bridge Controller SSL/TLS cipher
list
--ovnbr-controller-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller
TLSv1.3+ ciphersuite list
- --ovnbr-db-ssl-key=KEY OVN Bridge Controller DB SSL/TLS private key file
- --ovnbr-db-ssl-cert=CERT OVN Bridge Controller DB SSL/TLS certificate file
- --ovnbr-db-ssl-ca-cert=CERT OVN Bridge Controller DB SSL/TLS CA certificate
file
- --ovnbr-db-ssl-protocols=PROTOCOLS OVN Bridge Controller DB SSL/TLS protocols
- --ovnbr-db-ssl-ciphers=CIPHERS OVN Bridge Controller DB SSL/TLS cipher list
- --ovnbr-db-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller DB TLSv1.3+
ciphersuite list
+ --ovn-ovnbr-db-ssl-key=KEY OVN Bridge Controller DB SSL/TLS private key file
+ --ovn-ovnbr-db-ssl-cert=CERT OVN Bridge Controller DB SSL/TLS certificate
file
+ --ovn-ovnbr-db-ssl-ca-cert=CERT OVN Bridge Controller DB SSL/TLS CA
certificate file
+ --ovn-ovnbr-db-ssl-protocols=PROTOCOLS OVN Bridge Controller DB SSL/TLS
protocols
+ --ovn-ovnbr-db-ssl-ciphers=CIPHERS OVN Bridge Controller DB SSL/TLS cipher
list
+ --ovn-ovnbr-db-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller DB
TLSv1.3+ ciphersuite list
--ovnbr-controller-log=STRING ovn-br-controller process logging
params (default: $OVNBR_CONTROLLER_LOG)
- --ovn-br-db-log=STRING ovn brdb ovsdb-server processes logging
params (default: $OVN_BR_DB_LOG)
- --ovsdb-br-wrapper=WRAPPER run with a wrapper like valgrind for debugging
+ --ovn-ovnbr-log=STRING ovn bridge controller ovsdb-server process
logging params (default: $OVN_OVNBR_LOG)
+ --ovsdb-ovnbr-wrapper=WRAPPER run with a wrapper like valgrind for debugging
-h, --help display this help message
File location options:
diff --git a/utilities/ovn-ctl.8.xml b/utilities/ovn-ctl.8.xml
index 478487e755..9389397cef 100644
--- a/utilities/ovn-ctl.8.xml
+++ b/utilities/ovn-ctl.8.xml
@@ -219,6 +219,8 @@
database server under the specified wrapper.</p>
<p><code>--ovsdb-sb-wrapper=<var>WRAPPER</var></code> runs the Southbound
database server under the specified wrapper.</p>
+ <p><code>--ovsdb-ovnbr-wrapper=<var>WRAPPER</var></code> runs the OVN
+ bridge controller database server under the specified wrapper.</p>
<p><code>--ovn-user=<var>USER[:GROUP]</var></code> runs OVN daemons as the
specified user and optional group.</p>
<p><code>--ovn-manage-ovsdb=<var>yes|no</var></code> controls whether
@@ -330,11 +332,11 @@
ovn-br-controller SSL/TLS CA certificate file.</p>
<p><code>--ovnbr-controller-ssl-bootstrap-ca-cert=<var>CERT</var></code>
bootstraps the ovn-br-controller SSL/TLS CA certificate file.</p>
- <p><code>--ovnbr-db-ssl-key=<var>KEY</var></code> sets the
+ <p><code>--ovn-ovnbr-db-ssl-key=<var>KEY</var></code> sets the
ovn-br-controller database SSL/TLS private key file.</p>
- <p><code>--ovnbr-db-ssl-cert=<var>CERT</var></code> sets the
+ <p><code>--ovn-ovnbr-db-ssl-cert=<var>CERT</var></code> sets the
ovn-br-controller database SSL/TLS certificate file.</p>
- <p><code>--ovnbr-db-ssl-ca-cert=<var>CERT</var></code> sets the
+ <p><code>--ovn-ovnbr-db-ssl-ca-cert=<var>CERT</var></code> sets the
ovn-br-controller database SSL/TLS CA certificate file.</p>
<p><code>--db-ovnbr-sock=<var>SOCKET</var></code> sets the OVN bridge
controller database socket.</p>
@@ -372,10 +374,12 @@
<p><code>--ovn-nb-log=<var>STRING</var></code>,
<code>--ovn-sb-log=<var>STRING</var></code>,
<code>--ovn-ic-nb-log=<var>STRING</var></code>,
- <code>--ovn-ic-sb-log=<var>STRING</var></code>, and
- <code>--ovn-sb-relay-log=<var>STRING</var></code> set database-server
- logging parameters. The defaults for the NB, SB, IC-NB, and IC-SB
- database servers are <code>-vconsole:off -vfile:info</code>. The
+ <code>--ovn-ic-sb-log=<var>STRING</var></code>,
+ <code>--ovn-sb-relay-log=<var>STRING</var></code>, and
+ <code>--ovn-ovnbr-log=<var>STRING</var></code> set database-server
+ logging parameters. The defaults for the NB, SB, IC-NB, IC-SB, and
+ OVN bridge controller database servers are
+ <code>-vconsole:off -vfile:info</code>. The
default for the SB relay database server is
<code>-vconsole:emer -vsyslog:err -vfile:info</code>.</p>
<p><code>--ovn-northd-logfile=<var>FILE</var></code>,
@@ -398,7 +402,7 @@
<code>ovn-controller</code>, <code>ovn-northd</code>,
<code>ovn-ic</code>, <code>ovn-nb-db</code>, <code>ovn-sb-db</code>,
<code>ovn-ic-nb-db</code>, <code>ovn-ic-sb-db</code>,
- <code>ovn-sb-relay-db</code>, and <code>ovnbr-db</code>;
+ <code>ovn-sb-relay-db</code>, and <code>ovn-ovnbr-db</code>;
append <code>-ssl-key</code>, <code>-ssl-cert</code>,
or <code>-ssl-ca-cert</code>. Controller prefixes also accept
<code>-ssl-bootstrap-ca-cert</code>. Empty values leave the normal
@@ -445,12 +449,13 @@
ovn-br-controller SSL/TLS cipher list.</p>
<p><code>--ovnbr-controller-ssl-ciphersuites=<var>CIPHERSUITES</var></code>
sets the ovn-br-controller TLS 1.3 and later ciphersuite list.</p>
- <p><code>--ovnbr-db-ssl-protocols=<var>PROTOCOLS</var></code> sets the
+ <p><code>--ovn-ovnbr-db-ssl-protocols=<var>PROTOCOLS</var></code> sets the
ovn-br-controller database SSL/TLS protocols.</p>
- <p><code>--ovnbr-db-ssl-ciphers=<var>CIPHERS</var></code> sets the
+ <p><code>--ovn-ovnbr-db-ssl-ciphers=<var>CIPHERS</var></code> sets the
ovn-br-controller database SSL/TLS cipher list.</p>
- <p><code>--ovnbr-db-ssl-ciphersuites=<var>CIPHERSUITES</var></code> sets
- the ovn-br-controller database TLS 1.3 and later ciphersuite list.</p>
+ <p><code>--ovn-ovnbr-db-ssl-ciphersuites=<var>CIPHERSUITES</var></code>
+ sets the ovn-br-controller database TLS 1.3 and later ciphersuite
+ list.</p>
<h1>Address and port options</h1>
<p><code>--db-nb-sync-from-addr=<var>IP ADDRESS</var></code>.</p>
--
2.55.0
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev