Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -4846,6 +4846,8 @@ protected long getMemoryFreeInKBs(Domain dm) throws LibvirtException {
}

private boolean canBridgeFirewall(final String prvNic) {
if (getAllowNestedVMAccess())
return true; // If nested VM is allowed, then we skip call to security group and allow bypassing firewall
final Script cmd = new Script(securityGroupPath, timeout, LOGGER);
cmd.add("can_bridge_firewall");
cmd.add("--privnic", prvNic);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -329,6 +329,9 @@ public class IpAddressManagerImpl extends ManagerBase implements IpAddressManage

public static final ConfigKey<Integer> PUBLIC_IP_ADDRESS_QUARANTINE_DURATION = new ConfigKey<>("Network", Integer.class, "public.ip.address.quarantine.duration",
"0", "The duration (in minutes) for the public IP address to be quarantined when it is disassociated.", true, ConfigKey.Scope.Domain);

public static final ConfigKey<Boolean> AllowNestedVMAccess = new ConfigKey<>("Advanced", Boolean.class, "allow.nested.vm.access",
"false", "Allows nested VM access by bypassing security group restrictions. Use with caution.", true, ConfigKey.Scope.Global);

private Random rand = new Random(System.currentTimeMillis());

Expand Down Expand Up @@ -2453,6 +2456,10 @@ public static ConfigKey<Boolean> getSystemvmpublicipreservationmodestrictness()
return SystemVmPublicIpReservationModeStrictness;
}

public static ConfigKey<Boolean> getAllowNestedVMAccess() {
return AllowNestedVMAccess;
}

@Override
public boolean canPublicIpAddressBeAllocated(IpAddress ip, Account newOwner) {
PublicIpQuarantineVO publicIpQuarantineVO = publicIpQuarantineDao.findByPublicIpAddressId(ip.getId());
Expand Down
10 changes: 10 additions & 0 deletions server/src/test/java/com/cloud/network/IpAddressManagerTest.java
Original file line number Diff line number Diff line change
Expand Up @@ -491,4 +491,14 @@ public void checkIfIpResourceCountShouldBeUpdatedTestIpIsAssociatedToVpcAndNotDe

Assert.assertTrue(result);
}

@Test
public void testCanBridgeFirewallWithNestedVMAccessEnabled() {
// Force config to return true for AllowNestedVMAccess
Mockito.doReturn(true).when(ipAddressManager).getAllowNestedVMAccessConfig();

boolean result = ipAddressManager.canBridgeFirewall("eth0");

Assert.assertTrue("Should return true when AllowNestedVMAccess is enabled", result);
}
}