From 91118558b5331c53ce45733cfaed4d080092f691 Mon Sep 17 00:00:00 2001 From: Suresh Kumar Anaparti Date: Mon, 1 Jun 2026 20:27:57 +0530 Subject: [PATCH 1/5] Deprecate AppCookie (App session) based stickiness type policy for Virtual Router --- .../VirtualRoutingResource.java | 24 +++++++++++-- .../facade/LoadBalancerConfigItem.java | 6 ++-- .../cloud/network/HAProxyConfigurator.java | 2 ++ .../VirtualRoutingResourceTest.java | 34 +++++++++++++++++++ .../com/cloud/network/element/OvsElement.java | 2 +- .../network/element/VirtualRouterElement.java | 25 -------------- 6 files changed, 61 insertions(+), 32 deletions(-) diff --git a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java index fb04193271ee..1c0a7d1aaa2c 100644 --- a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java +++ b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java @@ -34,6 +34,9 @@ import javax.naming.ConfigurationException; +import com.cloud.agent.api.routing.LoadBalancerConfigCommand; +import com.cloud.agent.api.to.LoadBalancerTO; +import com.cloud.network.rules.LbStickinessMethod; import org.apache.cloudstack.agent.routing.ManageServiceCommand; import com.cloud.agent.api.routing.UpdateNetworkCommand; import com.cloud.agent.api.to.IpAddressTO; @@ -157,6 +160,7 @@ public Answer executeRequest(final NetworkElementCommand cmd) { return new Answer(cmd); } + checkAndFailForAppCookieStickinessTypeInLoadBalancerConfigCommand(cmd); List cfg = generateCommandCfg(cmd); if (cfg == null) { return Answer.createUnsupportedCommandAnswer(cmd); @@ -170,7 +174,21 @@ public Answer executeRequest(final NetworkElementCommand cmd) { if (!aggregated) { ExecutionResult rc = _vrDeployer.cleanupCommand(cmd); if (!rc.isSuccess()) { - logger.error("Failed to cleanup VR command due to " + rc.getDetails()); + logger.error("Failed to cleanup VR command due to {}", rc.getDetails()); + } + } + } + } + + private void checkAndFailForAppCookieStickinessTypeInLoadBalancerConfigCommand(NetworkElementCommand cmd) { + if (!(cmd instanceof LoadBalancerConfigCommand)) { + return; + } + LoadBalancerConfigCommand lbConfigCmd = (LoadBalancerConfigCommand) cmd; + for (final LoadBalancerTO lbTO : lbConfigCmd.getLoadBalancers()) { + for (final LoadBalancerTO.StickinessPolicyTO stickinessPolicy : lbTO.getStickinessPolicies()) { + if (stickinessPolicy != null && LbStickinessMethod.StickinessMethodType.AppCookieBased.getName().equalsIgnoreCase(stickinessPolicy.getMethodName())) { + throw new IllegalArgumentException("App cookie based stickiness type not supported for Virtual Router, as 'appsession' support is not available from HAProxy 1.6)"); } } } @@ -302,7 +320,7 @@ private ExecutionResult applyConfigToVR(String routerAccessIp, ConfigItem c, Dur ScriptConfigItem configItem = (ScriptConfigItem)c; return _vrDeployer.executeInVR(routerAccessIp, configItem.getScript(), configItem.getArgs(), timeout); } - throw new CloudRuntimeException("Unable to apply unknown configitem of type " + c.getClass().getSimpleName()); + throw new CloudRuntimeException("Unable to apply unknown config item of type " + c.getClass().getSimpleName()); } private Answer applyConfig(NetworkElementCommand cmd, List cfg) { @@ -591,7 +609,7 @@ private List generateCommandCfg(NetworkElementCommand cmd) { * [TODO] Still have to migrate LoadBalancerConfigCommand and BumpUpPriorityCommand * [FIXME] Have a look at SetSourceNatConfigItem */ - logger.debug("Transforming " + cmd.getClass().getCanonicalName() + " to ConfigItems"); + logger.debug("Transforming {} to ConfigItems", cmd.getClass().getCanonicalName()); final AbstractConfigItemFacade configItemFacade = AbstractConfigItemFacade.getInstance(cmd.getClass()); diff --git a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java index 4832c906699e..c81e7aa98ee2 100644 --- a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java +++ b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java @@ -38,8 +38,8 @@ public class LoadBalancerConfigItem extends AbstractConfigItemFacade { public List generateConfig(final NetworkElementCommand cmd) { final LoadBalancerConfigCommand command = (LoadBalancerConfigCommand) cmd; - final LoadBalancerConfigurator cfgtr = new HAProxyConfigurator(); - final String[] configuration = cfgtr.generateConfiguration(command); + final LoadBalancerConfigurator configurator = new HAProxyConfigurator(); + final String[] configuration = configurator.generateConfiguration(command); String routerIp = command.getNic().getIp(); if (command.getVpcId() == null) { @@ -49,7 +49,7 @@ public List generateConfig(final NetworkElementCommand cmd) { final String tmpCfgFilePath = "/etc/haproxy/"; final String tmpCfgFileName = "haproxy.cfg.new." + String.valueOf(System.currentTimeMillis()); - final String[][] allRules = cfgtr.generateFwRules(command); + final String[][] allRules = configurator.generateFwRules(command); final String[] addRules = allRules[LoadBalancerConfigurator.ADD]; final String[] removeRules = allRules[LoadBalancerConfigurator.REMOVE]; diff --git a/core/src/main/java/com/cloud/network/HAProxyConfigurator.java b/core/src/main/java/com/cloud/network/HAProxyConfigurator.java index 6e00e7cdc96d..92c09ca8db10 100644 --- a/core/src/main/java/com/cloud/network/HAProxyConfigurator.java +++ b/core/src/main/java/com/cloud/network/HAProxyConfigurator.java @@ -399,6 +399,8 @@ private String getLbSubRuleForStickiness(final LoadBalancerTO lbTO) { sb.append("\t").append("stick-table type ip size ").append(tablesize).append(" expire ").append(expire); sb.append("\n\t").append("stick on src"); } else if (StickinessMethodType.AppCookieBased.getName().equalsIgnoreCase(stickinessPolicy.getMethodName())) { + // This is not needed for Virtual Router - 'appsession' is not supported since HAProxy 1.6. + // In case this is used only for Virtual Router, remove it in the later release. /* * FORMAT : appsession len timeout * [request-learn] [prefix] [mode diff --git a/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java b/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java index 201242564ba6..4fe42f0596c0 100644 --- a/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java +++ b/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java @@ -20,6 +20,7 @@ package com.cloud.agent.resource.virtualnetwork; import static org.junit.Assert.assertEquals; +import static org.junit.Assert.assertFalse; import static org.junit.Assert.assertTrue; import static org.junit.Assert.fail; @@ -31,6 +32,9 @@ import javax.naming.ConfigurationException; +import com.cloud.network.lb.LoadBalancingRule; +import com.cloud.network.rules.LbStickinessMethod; +import com.cloud.utils.Pair; import org.joda.time.Duration; import org.junit.Before; import org.junit.Ignore; @@ -805,6 +809,36 @@ protected LoadBalancerConfigCommand generateLoadBalancerConfigCommand2() { return cmd; } + @Test + public void testLoadBalancerConfigCommandForAppCookie() { + _count = 0; + _file = ""; + + Answer answer = _resource.executeRequest(generateLoadBalancerConfigCommandWithAppCookie()); + assertFalse(answer.getResult()); + } + + protected LoadBalancerConfigCommand generateLoadBalancerConfigCommandWithAppCookie() { + final List lbs = new ArrayList<>(); + final List dests = new ArrayList<>(); + dests.add(new LbDestination(80, 8080, "10.1.10.2", false)); + dests.add(new LbDestination(80, 8080, "10.1.10.2", true)); + final List stickinessPolicies = new ArrayList<>(); + final List> params = new ArrayList<>(); + params.add(new Pair<>("cookie", "testcookie")); + params.add(new Pair<>("name", "JSESSIONID")); + stickinessPolicies.add(new LoadBalancingRule.LbStickinessPolicy(LbStickinessMethod.StickinessMethodType.AppCookieBased.getName(), params)); + lbs.add(new LoadBalancerTO(UUID.randomUUID().toString(), "64.10.1.10", 80, "tcp", "algo", false, false, false, dests, stickinessPolicies)); + final LoadBalancerTO[] arrayLbs = new LoadBalancerTO[lbs.size()]; + lbs.toArray(arrayLbs); + final NicTO nic = new NicTO(); + nic.setIp("10.1.10.2"); + final LoadBalancerConfigCommand cmd = new LoadBalancerConfigCommand(arrayLbs, "64.10.2.10", "10.1.10.2", "192.168.1.2", nic, Long.valueOf(1), "1000", false); + cmd.setAccessDetail(NetworkElementCommand.ROUTER_IP, "10.1.10.2"); + cmd.setAccessDetail(NetworkElementCommand.ROUTER_NAME, ROUTERNAME); + return cmd; + } + protected void verifyFile(final LoadBalancerConfigCommand cmd, final String path, final String filename, final String content) { _count ++; switch (_count) { diff --git a/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java b/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java index b8f4e0c73ff2..c797413202c1 100644 --- a/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java +++ b/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java @@ -333,7 +333,7 @@ public static String getHAProxyStickinessCapability() { "This is App session based sticky method. Define session stickiness on an existing application cookie. " + "It can be used only for a specific http traffic"); method.addParam("cookie-name", false, "This is the name of the cookie used by the application and which LB will " + - "have to learn for each new session. Default value: Auto geneared based on ip", false); + "have to learn for each new session. Default value: Auto generated based on ip", false); method.addParam("length", false, "This is the max number of characters that will be memorized and checked in " + "each cookie value. Default value:52", false); method.addParam( diff --git a/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java b/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java index 5938c1e4c569..1f9d1f8b804c 100644 --- a/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java +++ b/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java @@ -472,31 +472,6 @@ public static String getHAProxyStickinessCapability() { + "For the record, sending 10 domains to MSIE 6 or Firefox 2 works as expected.", false); methodList.add(method); - method = new LbStickinessMethod(StickinessMethodType.AppCookieBased, - "This is App session based sticky method. Define session stickiness on an existing application cookie. " + "It can be used only for a specific http traffic"); - method.addParam("cookie-name", false, "This is the name of the cookie used by the application and which LB will " - + "have to learn for each new session. Default value: Auto geneared based on ip", false); - method.addParam("length", false, "This is the max number of characters that will be memorized and checked in " + "each cookie value. Default value:52", false); - method.addParam("holdtime", false, "This is the time after which the cookie will be removed from memory if unused. The value should be in " - + "the format Example : 20s or 30m or 4h or 5d . only seconds(s), minutes(m) hours(h) and days(d) are valid," - + " cannot use th combinations like 20h30m. Default value:3h ", false); - method.addParam( - "request-learn", - false, - "If this option is specified, then haproxy will be able to learn the cookie found in the request in case the server does not specify any in response. This is typically what happens with PHPSESSID cookies, or when haproxy's session expires before the application's session and the correct server is selected. It is recommended to specify this option to improve reliability", - true); - method.addParam( - "prefix", - false, - "When this option is specified, haproxy will match on the cookie prefix (or URL parameter prefix). " - + "The appsession value is the data following this prefix. Example : appsession ASPSESSIONID len 64 timeout 3h prefix This will match the cookie ASPSESSIONIDXXXX=XXXXX, the appsession value will be XXXX=XXXXX.", - true); - method.addParam("mode", false, "This option allows to change the URL parser mode. 2 modes are currently supported : - path-parameters " - + ": The parser looks for the appsession in the path parameters part (each parameter is separated by a semi-colon), " - + "which is convenient for JSESSIONID for example.This is the default mode if the option is not set. - query-string :" - + " In this mode, the parser will look for the appsession in the query string.", false); - methodList.add(method); - method = new LbStickinessMethod(StickinessMethodType.SourceBased, "This is source based Stickiness method, " + "it can be used for any type of protocol."); method.addParam("tablesize", false, "Size of table to store source ip addresses. example: tablesize=200k or 300m" + " or 400g. Default value:200k", false); method.addParam("expire", false, "Entry in source ip table will expire after expire duration. units can be s,m,h,d ." From 5bdd22a4b60511b05f294cb807f221d7bfe72bd6 Mon Sep 17 00:00:00 2001 From: Suresh Kumar Anaparti Date: Tue, 2 Jun 2026 13:09:16 +0530 Subject: [PATCH 2/5] some code improvements --- .../element/InternalLoadBalancerElement.java | 2 -- .../lb/LoadBalancingRulesManagerImpl.java | 6 ++-- .../cloud/network/router/NetworkHelper.java | 36 +++++++++---------- 3 files changed, 21 insertions(+), 23 deletions(-) diff --git a/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java b/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java index 4a095826d5bc..4f0e476cd98a 100644 --- a/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java +++ b/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java @@ -404,8 +404,6 @@ protected Map> groupBySourceIp(List rules = new ArrayList(); - rules.add(rule); if (canHandle(network, rule.getScheme())) { List routers = _routerDao.listByNetworkAndRole(network.getId(), Role.INTERNAL_LB_VM); if (routers == null || routers.isEmpty()) { diff --git a/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java b/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java index 4283f81ffe2a..7b95d5e641d4 100644 --- a/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java +++ b/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java @@ -711,11 +711,11 @@ public boolean validateLbRule(LoadBalancingRule lbRule) { Network network = _networkDao.findById(lbRule.getNetworkId()); Purpose purpose = lbRule.getPurpose(); if (purpose != Purpose.LoadBalancing) { - logger.debug("Unable to validate network rules for purpose: " + purpose.toString()); + logger.debug("Unable to validate network rules for purpose: {}", purpose.toString()); return false; } - for (LoadBalancingServiceProvider ne : _lbProviders) { - boolean validated = ne.validateLBRule(network, lbRule); + for (LoadBalancingServiceProvider lbProvider : _lbProviders) { + boolean validated = lbProvider.validateLBRule(network, lbRule); if (!validated) return false; } diff --git a/server/src/main/java/com/cloud/network/router/NetworkHelper.java b/server/src/main/java/com/cloud/network/router/NetworkHelper.java index c9daa5eedb47..19901377cc51 100644 --- a/server/src/main/java/com/cloud/network/router/NetworkHelper.java +++ b/server/src/main/java/com/cloud/network/router/NetworkHelper.java @@ -44,19 +44,19 @@ public interface NetworkHelper { - public abstract boolean sendCommandsToRouter(VirtualRouter router, - Commands cmds) throws AgentUnavailableException, ResourceUnavailableException; + boolean sendCommandsToRouter(VirtualRouter router, + Commands cmds) throws AgentUnavailableException, ResourceUnavailableException; - public abstract void handleSingleWorkingRedundantRouter( + void handleSingleWorkingRedundantRouter( List connectedRouters, List disconnectedRouters, String reason) throws ResourceUnavailableException; - public abstract NicTO getNicTO(VirtualRouter router, Long networkId, - String broadcastUri); + NicTO getNicTO(VirtualRouter router, Long networkId, + String broadcastUri); - public abstract VirtualRouter destroyRouter(long routerId, Account caller, - Long callerUserId) throws ResourceUnavailableException, + VirtualRouter destroyRouter(long routerId, Account caller, + Long callerUserId) throws ResourceUnavailableException, ConcurrentOperationException; /** @@ -65,35 +65,35 @@ public abstract VirtualRouter destroyRouter(long routerId, Account caller, * @param router * @return */ - public abstract boolean checkRouterVersion(VirtualRouter router); - public abstract boolean checkRouterTemplateVersion(VirtualRouter router); + boolean checkRouterVersion(VirtualRouter router); + boolean checkRouterTemplateVersion(VirtualRouter router); - public abstract List startRouters( + List startRouters( RouterDeploymentDefinition routerDeploymentDefinition) throws StorageUnavailableException, InsufficientCapacityException, ConcurrentOperationException, ResourceUnavailableException; - public abstract DomainRouterVO startVirtualRouter(DomainRouterVO router, - User user, Account caller, Map params) + DomainRouterVO startVirtualRouter(DomainRouterVO router, + User user, Account caller, Map params) throws StorageUnavailableException, InsufficientCapacityException, ConcurrentOperationException, ResourceUnavailableException; - public abstract DomainRouterVO deployRouter( + DomainRouterVO deployRouter( RouterDeploymentDefinition routerDeploymentDefinition, boolean startRouter) throws InsufficientAddressCapacityException, InsufficientServerCapacityException, InsufficientCapacityException, StorageUnavailableException, ResourceUnavailableException; - public abstract void reallocateRouterNetworks(RouterDeploymentDefinition routerDeploymentDefinition, VirtualRouter router, VMTemplateVO template, HypervisorType hType) + void reallocateRouterNetworks(RouterDeploymentDefinition routerDeploymentDefinition, VirtualRouter router, VMTemplateVO template, HypervisorType hType) throws ConcurrentOperationException, InsufficientAddressCapacityException, InsufficientCapacityException; - public abstract LinkedHashMap> configureDefaultNics(RouterDeploymentDefinition routerDeploymentDefinition) + LinkedHashMap> configureDefaultNics(RouterDeploymentDefinition routerDeploymentDefinition) throws ConcurrentOperationException, InsufficientAddressCapacityException; - public abstract LinkedHashMap> configureGuestNic(RouterDeploymentDefinition routerDeploymentDefinition) + LinkedHashMap> configureGuestNic(RouterDeploymentDefinition routerDeploymentDefinition) throws ConcurrentOperationException, InsufficientAddressCapacityException; - public boolean validateHAProxyLBRule(final LoadBalancingRule rule); + boolean validateHAProxyLBRule(final LoadBalancingRule rule); - public Map> getHypervisorRouterTemplateConfigMap(); + Map> getHypervisorRouterTemplateConfigMap(); } From 7404a5233c0c80c10d9683327170b4d48aa8023f Mon Sep 17 00:00:00 2001 From: Suresh Kumar Anaparti Date: Thu, 1 Oct 2026 17:26:58 +0530 Subject: [PATCH 3/5] Revert "some code improvements" This reverts commit 5bdd22a4b60511b05f294cb807f221d7bfe72bd6. --- .../element/InternalLoadBalancerElement.java | 2 ++ .../lb/LoadBalancingRulesManagerImpl.java | 6 ++-- .../cloud/network/router/NetworkHelper.java | 36 +++++++++---------- 3 files changed, 23 insertions(+), 21 deletions(-) diff --git a/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java b/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java index 4f0e476cd98a..4a095826d5bc 100644 --- a/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java +++ b/plugins/network-elements/internal-loadbalancer/src/main/java/org/apache/cloudstack/network/element/InternalLoadBalancerElement.java @@ -404,6 +404,8 @@ protected Map> groupBySourceIp(List rules = new ArrayList(); + rules.add(rule); if (canHandle(network, rule.getScheme())) { List routers = _routerDao.listByNetworkAndRole(network.getId(), Role.INTERNAL_LB_VM); if (routers == null || routers.isEmpty()) { diff --git a/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java b/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java index 7b95d5e641d4..4283f81ffe2a 100644 --- a/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java +++ b/server/src/main/java/com/cloud/network/lb/LoadBalancingRulesManagerImpl.java @@ -711,11 +711,11 @@ public boolean validateLbRule(LoadBalancingRule lbRule) { Network network = _networkDao.findById(lbRule.getNetworkId()); Purpose purpose = lbRule.getPurpose(); if (purpose != Purpose.LoadBalancing) { - logger.debug("Unable to validate network rules for purpose: {}", purpose.toString()); + logger.debug("Unable to validate network rules for purpose: " + purpose.toString()); return false; } - for (LoadBalancingServiceProvider lbProvider : _lbProviders) { - boolean validated = lbProvider.validateLBRule(network, lbRule); + for (LoadBalancingServiceProvider ne : _lbProviders) { + boolean validated = ne.validateLBRule(network, lbRule); if (!validated) return false; } diff --git a/server/src/main/java/com/cloud/network/router/NetworkHelper.java b/server/src/main/java/com/cloud/network/router/NetworkHelper.java index 19901377cc51..c9daa5eedb47 100644 --- a/server/src/main/java/com/cloud/network/router/NetworkHelper.java +++ b/server/src/main/java/com/cloud/network/router/NetworkHelper.java @@ -44,19 +44,19 @@ public interface NetworkHelper { - boolean sendCommandsToRouter(VirtualRouter router, - Commands cmds) throws AgentUnavailableException, ResourceUnavailableException; + public abstract boolean sendCommandsToRouter(VirtualRouter router, + Commands cmds) throws AgentUnavailableException, ResourceUnavailableException; - void handleSingleWorkingRedundantRouter( + public abstract void handleSingleWorkingRedundantRouter( List connectedRouters, List disconnectedRouters, String reason) throws ResourceUnavailableException; - NicTO getNicTO(VirtualRouter router, Long networkId, - String broadcastUri); + public abstract NicTO getNicTO(VirtualRouter router, Long networkId, + String broadcastUri); - VirtualRouter destroyRouter(long routerId, Account caller, - Long callerUserId) throws ResourceUnavailableException, + public abstract VirtualRouter destroyRouter(long routerId, Account caller, + Long callerUserId) throws ResourceUnavailableException, ConcurrentOperationException; /** @@ -65,35 +65,35 @@ VirtualRouter destroyRouter(long routerId, Account caller, * @param router * @return */ - boolean checkRouterVersion(VirtualRouter router); - boolean checkRouterTemplateVersion(VirtualRouter router); + public abstract boolean checkRouterVersion(VirtualRouter router); + public abstract boolean checkRouterTemplateVersion(VirtualRouter router); - List startRouters( + public abstract List startRouters( RouterDeploymentDefinition routerDeploymentDefinition) throws StorageUnavailableException, InsufficientCapacityException, ConcurrentOperationException, ResourceUnavailableException; - DomainRouterVO startVirtualRouter(DomainRouterVO router, - User user, Account caller, Map params) + public abstract DomainRouterVO startVirtualRouter(DomainRouterVO router, + User user, Account caller, Map params) throws StorageUnavailableException, InsufficientCapacityException, ConcurrentOperationException, ResourceUnavailableException; - DomainRouterVO deployRouter( + public abstract DomainRouterVO deployRouter( RouterDeploymentDefinition routerDeploymentDefinition, boolean startRouter) throws InsufficientAddressCapacityException, InsufficientServerCapacityException, InsufficientCapacityException, StorageUnavailableException, ResourceUnavailableException; - void reallocateRouterNetworks(RouterDeploymentDefinition routerDeploymentDefinition, VirtualRouter router, VMTemplateVO template, HypervisorType hType) + public abstract void reallocateRouterNetworks(RouterDeploymentDefinition routerDeploymentDefinition, VirtualRouter router, VMTemplateVO template, HypervisorType hType) throws ConcurrentOperationException, InsufficientAddressCapacityException, InsufficientCapacityException; - LinkedHashMap> configureDefaultNics(RouterDeploymentDefinition routerDeploymentDefinition) + public abstract LinkedHashMap> configureDefaultNics(RouterDeploymentDefinition routerDeploymentDefinition) throws ConcurrentOperationException, InsufficientAddressCapacityException; - LinkedHashMap> configureGuestNic(RouterDeploymentDefinition routerDeploymentDefinition) + public abstract LinkedHashMap> configureGuestNic(RouterDeploymentDefinition routerDeploymentDefinition) throws ConcurrentOperationException, InsufficientAddressCapacityException; - boolean validateHAProxyLBRule(final LoadBalancingRule rule); + public boolean validateHAProxyLBRule(final LoadBalancingRule rule); - Map> getHypervisorRouterTemplateConfigMap(); + public Map> getHypervisorRouterTemplateConfigMap(); } From 46864a0c1d7abe71a53286d5fef58af39dedc30c Mon Sep 17 00:00:00 2001 From: Suresh Kumar Anaparti Date: Thu, 1 Oct 2026 17:27:05 +0530 Subject: [PATCH 4/5] Revert "Deprecate AppCookie (App session) based stickiness type policy for Virtual Router" This reverts commit 91118558b5331c53ce45733cfaed4d080092f691. --- .../VirtualRoutingResource.java | 24 ++----------- .../facade/LoadBalancerConfigItem.java | 6 ++-- .../cloud/network/HAProxyConfigurator.java | 2 -- .../VirtualRoutingResourceTest.java | 34 ------------------- .../com/cloud/network/element/OvsElement.java | 2 +- .../network/element/VirtualRouterElement.java | 25 ++++++++++++++ 6 files changed, 32 insertions(+), 61 deletions(-) diff --git a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java index 1c0a7d1aaa2c..fb04193271ee 100644 --- a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java +++ b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResource.java @@ -34,9 +34,6 @@ import javax.naming.ConfigurationException; -import com.cloud.agent.api.routing.LoadBalancerConfigCommand; -import com.cloud.agent.api.to.LoadBalancerTO; -import com.cloud.network.rules.LbStickinessMethod; import org.apache.cloudstack.agent.routing.ManageServiceCommand; import com.cloud.agent.api.routing.UpdateNetworkCommand; import com.cloud.agent.api.to.IpAddressTO; @@ -160,7 +157,6 @@ public Answer executeRequest(final NetworkElementCommand cmd) { return new Answer(cmd); } - checkAndFailForAppCookieStickinessTypeInLoadBalancerConfigCommand(cmd); List cfg = generateCommandCfg(cmd); if (cfg == null) { return Answer.createUnsupportedCommandAnswer(cmd); @@ -174,21 +170,7 @@ public Answer executeRequest(final NetworkElementCommand cmd) { if (!aggregated) { ExecutionResult rc = _vrDeployer.cleanupCommand(cmd); if (!rc.isSuccess()) { - logger.error("Failed to cleanup VR command due to {}", rc.getDetails()); - } - } - } - } - - private void checkAndFailForAppCookieStickinessTypeInLoadBalancerConfigCommand(NetworkElementCommand cmd) { - if (!(cmd instanceof LoadBalancerConfigCommand)) { - return; - } - LoadBalancerConfigCommand lbConfigCmd = (LoadBalancerConfigCommand) cmd; - for (final LoadBalancerTO lbTO : lbConfigCmd.getLoadBalancers()) { - for (final LoadBalancerTO.StickinessPolicyTO stickinessPolicy : lbTO.getStickinessPolicies()) { - if (stickinessPolicy != null && LbStickinessMethod.StickinessMethodType.AppCookieBased.getName().equalsIgnoreCase(stickinessPolicy.getMethodName())) { - throw new IllegalArgumentException("App cookie based stickiness type not supported for Virtual Router, as 'appsession' support is not available from HAProxy 1.6)"); + logger.error("Failed to cleanup VR command due to " + rc.getDetails()); } } } @@ -320,7 +302,7 @@ private ExecutionResult applyConfigToVR(String routerAccessIp, ConfigItem c, Dur ScriptConfigItem configItem = (ScriptConfigItem)c; return _vrDeployer.executeInVR(routerAccessIp, configItem.getScript(), configItem.getArgs(), timeout); } - throw new CloudRuntimeException("Unable to apply unknown config item of type " + c.getClass().getSimpleName()); + throw new CloudRuntimeException("Unable to apply unknown configitem of type " + c.getClass().getSimpleName()); } private Answer applyConfig(NetworkElementCommand cmd, List cfg) { @@ -609,7 +591,7 @@ private List generateCommandCfg(NetworkElementCommand cmd) { * [TODO] Still have to migrate LoadBalancerConfigCommand and BumpUpPriorityCommand * [FIXME] Have a look at SetSourceNatConfigItem */ - logger.debug("Transforming {} to ConfigItems", cmd.getClass().getCanonicalName()); + logger.debug("Transforming " + cmd.getClass().getCanonicalName() + " to ConfigItems"); final AbstractConfigItemFacade configItemFacade = AbstractConfigItemFacade.getInstance(cmd.getClass()); diff --git a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java index c81e7aa98ee2..4832c906699e 100644 --- a/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java +++ b/core/src/main/java/com/cloud/agent/resource/virtualnetwork/facade/LoadBalancerConfigItem.java @@ -38,8 +38,8 @@ public class LoadBalancerConfigItem extends AbstractConfigItemFacade { public List generateConfig(final NetworkElementCommand cmd) { final LoadBalancerConfigCommand command = (LoadBalancerConfigCommand) cmd; - final LoadBalancerConfigurator configurator = new HAProxyConfigurator(); - final String[] configuration = configurator.generateConfiguration(command); + final LoadBalancerConfigurator cfgtr = new HAProxyConfigurator(); + final String[] configuration = cfgtr.generateConfiguration(command); String routerIp = command.getNic().getIp(); if (command.getVpcId() == null) { @@ -49,7 +49,7 @@ public List generateConfig(final NetworkElementCommand cmd) { final String tmpCfgFilePath = "/etc/haproxy/"; final String tmpCfgFileName = "haproxy.cfg.new." + String.valueOf(System.currentTimeMillis()); - final String[][] allRules = configurator.generateFwRules(command); + final String[][] allRules = cfgtr.generateFwRules(command); final String[] addRules = allRules[LoadBalancerConfigurator.ADD]; final String[] removeRules = allRules[LoadBalancerConfigurator.REMOVE]; diff --git a/core/src/main/java/com/cloud/network/HAProxyConfigurator.java b/core/src/main/java/com/cloud/network/HAProxyConfigurator.java index 92c09ca8db10..6e00e7cdc96d 100644 --- a/core/src/main/java/com/cloud/network/HAProxyConfigurator.java +++ b/core/src/main/java/com/cloud/network/HAProxyConfigurator.java @@ -399,8 +399,6 @@ private String getLbSubRuleForStickiness(final LoadBalancerTO lbTO) { sb.append("\t").append("stick-table type ip size ").append(tablesize).append(" expire ").append(expire); sb.append("\n\t").append("stick on src"); } else if (StickinessMethodType.AppCookieBased.getName().equalsIgnoreCase(stickinessPolicy.getMethodName())) { - // This is not needed for Virtual Router - 'appsession' is not supported since HAProxy 1.6. - // In case this is used only for Virtual Router, remove it in the later release. /* * FORMAT : appsession len timeout * [request-learn] [prefix] [mode diff --git a/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java b/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java index 4fe42f0596c0..201242564ba6 100644 --- a/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java +++ b/core/src/test/java/com/cloud/agent/resource/virtualnetwork/VirtualRoutingResourceTest.java @@ -20,7 +20,6 @@ package com.cloud.agent.resource.virtualnetwork; import static org.junit.Assert.assertEquals; -import static org.junit.Assert.assertFalse; import static org.junit.Assert.assertTrue; import static org.junit.Assert.fail; @@ -32,9 +31,6 @@ import javax.naming.ConfigurationException; -import com.cloud.network.lb.LoadBalancingRule; -import com.cloud.network.rules.LbStickinessMethod; -import com.cloud.utils.Pair; import org.joda.time.Duration; import org.junit.Before; import org.junit.Ignore; @@ -809,36 +805,6 @@ protected LoadBalancerConfigCommand generateLoadBalancerConfigCommand2() { return cmd; } - @Test - public void testLoadBalancerConfigCommandForAppCookie() { - _count = 0; - _file = ""; - - Answer answer = _resource.executeRequest(generateLoadBalancerConfigCommandWithAppCookie()); - assertFalse(answer.getResult()); - } - - protected LoadBalancerConfigCommand generateLoadBalancerConfigCommandWithAppCookie() { - final List lbs = new ArrayList<>(); - final List dests = new ArrayList<>(); - dests.add(new LbDestination(80, 8080, "10.1.10.2", false)); - dests.add(new LbDestination(80, 8080, "10.1.10.2", true)); - final List stickinessPolicies = new ArrayList<>(); - final List> params = new ArrayList<>(); - params.add(new Pair<>("cookie", "testcookie")); - params.add(new Pair<>("name", "JSESSIONID")); - stickinessPolicies.add(new LoadBalancingRule.LbStickinessPolicy(LbStickinessMethod.StickinessMethodType.AppCookieBased.getName(), params)); - lbs.add(new LoadBalancerTO(UUID.randomUUID().toString(), "64.10.1.10", 80, "tcp", "algo", false, false, false, dests, stickinessPolicies)); - final LoadBalancerTO[] arrayLbs = new LoadBalancerTO[lbs.size()]; - lbs.toArray(arrayLbs); - final NicTO nic = new NicTO(); - nic.setIp("10.1.10.2"); - final LoadBalancerConfigCommand cmd = new LoadBalancerConfigCommand(arrayLbs, "64.10.2.10", "10.1.10.2", "192.168.1.2", nic, Long.valueOf(1), "1000", false); - cmd.setAccessDetail(NetworkElementCommand.ROUTER_IP, "10.1.10.2"); - cmd.setAccessDetail(NetworkElementCommand.ROUTER_NAME, ROUTERNAME); - return cmd; - } - protected void verifyFile(final LoadBalancerConfigCommand cmd, final String path, final String filename, final String content) { _count ++; switch (_count) { diff --git a/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java b/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java index c797413202c1..b8f4e0c73ff2 100644 --- a/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java +++ b/plugins/network-elements/ovs/src/main/java/com/cloud/network/element/OvsElement.java @@ -333,7 +333,7 @@ public static String getHAProxyStickinessCapability() { "This is App session based sticky method. Define session stickiness on an existing application cookie. " + "It can be used only for a specific http traffic"); method.addParam("cookie-name", false, "This is the name of the cookie used by the application and which LB will " + - "have to learn for each new session. Default value: Auto generated based on ip", false); + "have to learn for each new session. Default value: Auto geneared based on ip", false); method.addParam("length", false, "This is the max number of characters that will be memorized and checked in " + "each cookie value. Default value:52", false); method.addParam( diff --git a/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java b/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java index 1f9d1f8b804c..5938c1e4c569 100644 --- a/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java +++ b/server/src/main/java/com/cloud/network/element/VirtualRouterElement.java @@ -472,6 +472,31 @@ public static String getHAProxyStickinessCapability() { + "For the record, sending 10 domains to MSIE 6 or Firefox 2 works as expected.", false); methodList.add(method); + method = new LbStickinessMethod(StickinessMethodType.AppCookieBased, + "This is App session based sticky method. Define session stickiness on an existing application cookie. " + "It can be used only for a specific http traffic"); + method.addParam("cookie-name", false, "This is the name of the cookie used by the application and which LB will " + + "have to learn for each new session. Default value: Auto geneared based on ip", false); + method.addParam("length", false, "This is the max number of characters that will be memorized and checked in " + "each cookie value. Default value:52", false); + method.addParam("holdtime", false, "This is the time after which the cookie will be removed from memory if unused. The value should be in " + + "the format Example : 20s or 30m or 4h or 5d . only seconds(s), minutes(m) hours(h) and days(d) are valid," + + " cannot use th combinations like 20h30m. Default value:3h ", false); + method.addParam( + "request-learn", + false, + "If this option is specified, then haproxy will be able to learn the cookie found in the request in case the server does not specify any in response. This is typically what happens with PHPSESSID cookies, or when haproxy's session expires before the application's session and the correct server is selected. It is recommended to specify this option to improve reliability", + true); + method.addParam( + "prefix", + false, + "When this option is specified, haproxy will match on the cookie prefix (or URL parameter prefix). " + + "The appsession value is the data following this prefix. Example : appsession ASPSESSIONID len 64 timeout 3h prefix This will match the cookie ASPSESSIONIDXXXX=XXXXX, the appsession value will be XXXX=XXXXX.", + true); + method.addParam("mode", false, "This option allows to change the URL parser mode. 2 modes are currently supported : - path-parameters " + + ": The parser looks for the appsession in the path parameters part (each parameter is separated by a semi-colon), " + + "which is convenient for JSESSIONID for example.This is the default mode if the option is not set. - query-string :" + + " In this mode, the parser will look for the appsession in the query string.", false); + methodList.add(method); + method = new LbStickinessMethod(StickinessMethodType.SourceBased, "This is source based Stickiness method, " + "it can be used for any type of protocol."); method.addParam("tablesize", false, "Size of table to store source ip addresses. example: tablesize=200k or 300m" + " or 400g. Default value:200k", false); method.addParam("expire", false, "Entry in source ip table will expire after expire duration. units can be s,m,h,d ." From e91b9e5d35df21433635ec70399672ba8566f3ed Mon Sep 17 00:00:00 2001 From: Suresh Kumar Anaparti Date: Thu, 1 Oct 2026 17:38:26 +0530 Subject: [PATCH 5/5] Reject AppCookie LB stickiness policy on Virtual Router networks --- .../network/router/NetworkHelperImpl.java | 22 +-------- .../network/router/NetworkHelperImplTest.java | 46 +++++++++++++++++++ 2 files changed, 48 insertions(+), 20 deletions(-) diff --git a/server/src/main/java/com/cloud/network/router/NetworkHelperImpl.java b/server/src/main/java/com/cloud/network/router/NetworkHelperImpl.java index 4baa19f8f845..92253a6d76e7 100644 --- a/server/src/main/java/com/cloud/network/router/NetworkHelperImpl.java +++ b/server/src/main/java/com/cloud/network/router/NetworkHelperImpl.java @@ -945,26 +945,8 @@ public boolean validateHAProxyLBRule(final LoadBalancingRule rule) { } } else if (LbStickinessMethod.StickinessMethodType.AppCookieBased.getName().equalsIgnoreCase(stickinessPolicy.getMethodName())) { - String length = null; // optional - String holdTime = null; // optional - - for (final Pair paramKV : paramsList) { - final String key = paramKV.first(); - final String value = paramKV.second(); - if ("length".equalsIgnoreCase(key)) { - length = value; - } - if ("holdtime".equalsIgnoreCase(key)) { - holdTime = value; - } - } - - if (length != null && !containsOnlyNumbers(length, null)) { - throw new InvalidParameterValueException(String.format("Failed LB in validation rule id: %s Cause: length is not a number: %s", rule.getLb(), length)); - } - if (holdTime != null && !containsOnlyNumbers(holdTime, timeEndChar) && !containsOnlyNumbers(holdTime, null)) { - throw new InvalidParameterValueException(String.format("Failed LB in validation rule id: %s Cause: holdtime is not in timeformat: %s", rule.getLb(), holdTime)); - } + throw new InvalidParameterValueException(String.format("Failed LB in validation rule: %s Cause: AppCookie based stickiness " + + "(HAProxy 'appsession') is not supported on a Virtual Router, as this directive was removed in HAProxy 1.6", rule.getLb())); } } return true; diff --git a/server/src/test/java/com/cloud/network/router/NetworkHelperImplTest.java b/server/src/test/java/com/cloud/network/router/NetworkHelperImplTest.java index 4237ef7f6f65..9680b3cebe22 100644 --- a/server/src/test/java/com/cloud/network/router/NetworkHelperImplTest.java +++ b/server/src/test/java/com/cloud/network/router/NetworkHelperImplTest.java @@ -29,7 +29,15 @@ import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; +import com.cloud.configuration.Config; +import com.cloud.exception.InvalidParameterValueException; +import com.cloud.network.lb.LoadBalancingRule; +import com.cloud.network.rules.LbStickinessMethod; +import com.cloud.network.rules.LoadBalancer; +import com.cloud.utils.Pair; +import com.cloud.utils.net.Ip; import org.apache.cloudstack.engine.orchestration.service.NetworkOrchestrationService; +import org.apache.cloudstack.framework.config.dao.ConfigurationDao; import org.apache.cloudstack.network.router.deployment.RouterDeploymentDefinition; import org.junit.Before; import org.junit.Test; @@ -57,6 +65,10 @@ import com.cloud.vm.dao.DomainRouterDao; import com.cloud.vm.dao.NicDao; +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; + @RunWith(MockitoJUnitRunner.class) public class NetworkHelperImplTest { @@ -91,10 +103,15 @@ public class NetworkHelperImplTest { @Mock private VMTemplateVO template; + @Mock + private ConfigurationDao configDao; + @Before public void setUp() { nwHelper._networkDao = networkDao; nwHelper._networkModel = networkModel; + nwHelper._configDao = configDao; + lenient().when(configDao.getValue(Config.NetworkLBHaproxyStatsPort.key())).thenReturn("8081"); when(template.getId()).thenReturn(1L); when(template.isDynamicallyScalable()).thenReturn(true); when(virtualProvider.getId()).thenReturn(1L); @@ -268,4 +285,33 @@ public void testUpdateDomainRouter() { assertEquals(Hypervisor.HypervisorType.KVM, result.getHypervisorType()); assertTrue(result.isDynamicallyScalable()); } + + @Test(expected = InvalidParameterValueException.class) + public void testValidateHAProxyLBRuleRejectsAppCookieStickiness() { + LoadBalancer lb = mock(LoadBalancer.class); + when(lb.getSourcePortStart()).thenReturn(80); + + List> params = new ArrayList<>(); + params.add(new Pair<>("cookie-name", "JSESSIONID")); + LoadBalancingRule.LbStickinessPolicy stickinessPolicy = + new LoadBalancingRule.LbStickinessPolicy(LbStickinessMethod.StickinessMethodType.AppCookieBased.getName(), params); + LoadBalancingRule rule = new LoadBalancingRule(lb, new ArrayList<>(), Collections.singletonList(stickinessPolicy), new ArrayList<>(), mock(Ip.class)); + + nwHelper.validateHAProxyLBRule(rule); + } + + @Test + public void testValidateHAProxyLBRuleAllowsSourceBasedStickiness() { + LoadBalancer lb = mock(LoadBalancer.class); + when(lb.getSourcePortStart()).thenReturn(80); + + List> params = new ArrayList<>(); + params.add(new Pair<>("tablesize", "200k")); + params.add(new Pair<>("expire", "30m")); + LoadBalancingRule.LbStickinessPolicy stickinessPolicy = + new LoadBalancingRule.LbStickinessPolicy(LbStickinessMethod.StickinessMethodType.SourceBased.getName(), params); + LoadBalancingRule rule = new LoadBalancingRule(lb, new ArrayList<>(), Collections.singletonList(stickinessPolicy), new ArrayList<>(), mock(Ip.class)); + + assertTrue(nwHelper.validateHAProxyLBRule(rule)); + } }