bulk delete of ports cost iptables-firewall too much time
Bug #1513765 reported by
shihanzhang
This bug affects 5 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Critical
|
Kevin Benton |
Bug Description
this problem was found in master branch, but I think it also affect liberty.
reproduce steps:
1. create 100 VMs in default security group
2. bulk delete these VMs
I found the ipset can't be clear as soon as possible, because there were much ip_conntrack need to be clean, so the ovs-agent were doing this work.
For this problem, what I can think is letting ovs-agent use eventlet.GreenPool to delete ip_conntrack, do other have good idea?
Changed in neutron: | |
assignee: | nobody → shihanzhang (shihanzhang) |
tags: | added: bridge ovs |
summary: |
- bulk delete ports cost ovs-agent much time + bulk delete of ports cost iptables-firewall too much time |
Changed in neutron: | |
milestone: | mitaka-rc1 → newton-1 |
tags: | added: mitaka-rc-potential |
Changed in neutron: | |
milestone: | newton-1 → mitaka-rc1 |
tags: |
added: linuxbridgeovs removed: liberty-backport-potential linuxbridge mitaka-rc-potential ovs |
tags: |
added: linuxbridge ovs removed: linuxbridgeovs |
tags: | removed: bridge |
To post a comment you must log in.
I suspect this does affect Liberty as well, so if we fix it, lets plan for a backport.