1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["4068"],{81815(e,n,t){t.r(n),t.d(n,{metadata:()=>r,default:()=>h,frontMatter:()=>s,contentTitle:()=>a,toc:()=>l,assets:()=>c});var r=JSON.parse('{"id":"networking/openstack/neutron-api","title":"Calico\'s interpretation of Neutron API calls","description":"Effects of the Neutron API calls on the network.","source":"@site/calico_versioned_docs/version-3.29/networking/openstack/neutron-api.mdx","sourceDirName":"networking/openstack","slug":"/networking/openstack/neutron-api","permalink":"/calico/3.29/networking/openstack/neutron-api","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.29/networking/openstack/neutron-api.mdx","tags":[],"version":"3.29","frontMatter":{"description":"Effects of the Neutron API calls on the network."},"sidebar":"calicoSidebar","previous":{"title":"Kuryr","permalink":"/calico/3.29/networking/openstack/kuryr"},"next":{"title":"Network policy","permalink":"/calico/3.29/network-policy/"}}'),o=t(70689),i=t(3413);let s={description:"Effects of the Neutron API calls on the network."},a="Calico's interpretation of Neutron API calls",c={},l=[{value:"Networks",id:"networks",level:2},{value:"Extended Attributes: Provider Networks",id:"extended-attributes-provider-networks",level:2},{value:"Subnets",id:"subnets",level:2},{value:"Ports",id:"ports",level:2},{value:"Extended Attributes: Port Binding Attributes",id:"extended-attributes-port-binding-attributes",level:3},{value:"Quotas",id:"quotas",level:2},{value:"Security Groups",id:"security-groups",level:2},{value:"Floating IPs",id:"floating-ips",level:2},{value:"Neutron Routers",id:"neutron-routers",level:2},{value:"QoS",id:"qos",level:2},{value:"Load Balancer as a Service",id:"load-balancer-as-a-service",level:2},{value:"Horizon",id:"horizon",level:2},{value:"Section: Project",id:"section-project",level:3},{value:"Tab: Compute -> Instances",id:"tab-compute---instances",level:4},{value:"Tab: Compute -> Access & Security",id:"tab-compute---access--security",level:4},{value:"Tab: Network -> Network Topology",id:"tab-network---network-topology",level:4},{value:"Tab: Network -> Networks",id:"tab-network---networks",level:4},{value:"Tab: Network -> Routers",id:"tab-network---routers",level:4},{value:"Section: Admin",id:"section-admin",level:3},{value:"Tab: System Panel -> Networks",id:"tab-system-panel---networks",level:4},{value:"Tab: System Panel -> Routers",id:"tab-system-panel---routers",level:4}];function d(e){let n={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",h4:"h4",header:"header",li:"li",p:"p",ul:"ul",...(0,i.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(n.header,{children:(0,o.jsx)(n.h1,{id:"calicos-interpretation-of-neutron-api-calls",children:"Calico's interpretation of Neutron API calls"})}),"\n",(0,o.jsxs)(n.p,{children:["When running in an OpenStack deployment, Calico receives and interprets\ncertain Neutron API actions, to program those actions down into\nthe network. However, because Calico is substantially simpler than much\nof what Neutron generally allows (see ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity",children:"IP addressing and connectivity"}),") and because it's a purely layer 3 model (see ",(0,o.jsx)(n.a,{href:"/calico/3.29/reference/architecture/data-path",children:"The Calico data path"}),", not all Neutron API calls will have the same effect as they would with other backends."]}),"\n",(0,o.jsxs)(n.p,{children:["This document will go into detail on the full range of Neutron API\ncalls, and will discuss the effect they have on the network. It uses the ",(0,o.jsx)(n.a,{href:"http://developer.openstack.org/api-ref-networking-v2.html",children:"Networking API v2.0"}),"\ndocument from OpenStack as a basis for listing the various objects that\nthe Neutron API uses: see that document for more information about what\nNeutron expects more generally."]}),"\n",(0,o.jsxs)(n.p,{children:["Additionally, there is a ",(0,o.jsx)(n.a,{href:"#horizon",children:"section of this document"})," that briefly covers\nHorizon actions."]}),"\n",(0,o.jsx)(n.h2,{id:"networks",children:"Networks"}),"\n",(0,o.jsx)(n.p,{children:"Networks are the basic networking concept in Neutron. A Neutron network\nis considered to be roughly equivalent to a physical network in terms of\nfunction: it defines a single layer 2 connectivity graph."}),"\n",(0,o.jsx)(n.p,{children:"In vanilla Neutron, these can map to the underlay network in various\nways, either by being encapsulated over it or by being directly mapped\nto it."}),"\n",(0,o.jsx)(n.p,{children:"Generally speaking, Neutron networks can be created by all tenants. The\nadministrator tenant will generally create some public Neutron networks\nthat map to the underlay physical network directly for providing\nfloating IPs: other tenants will create their own private Neutron\nnetworks as necessary."}),"\n",(0,o.jsxs)(n.p,{children:["In Calico, because all traffic is L3 and routed, the role of Neutron\nnetwork as L2 connectivity domain is not helpful. Therefore, in Calico,\nNeutron networks are simply containers for subnets. Best practices for\noperators configuring Neutron networks in Calico deployments can be\nfound in ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity#part-2-set-up-openstack",children:"Set up OpenStack"}),"."]}),"\n",(0,o.jsx)(n.p,{children:"It is not useful for non-administrator tenants to create their own\nNeutron networks. Although Calico will allow non-administrator tenants\nto create Neutron networks, generally speaking administrators should use\nNeutron quotas to prevent non-administrator tenants from doing this."}),"\n",(0,o.jsx)(n.p,{children:"Network creation events on the API are no-op events in Calico: a\npositive (2XX) response will be sent but no programming will actually\noccur."}),"\n",(0,o.jsx)(n.h2,{id:"extended-attributes-provider-networks",children:"Extended Attributes: Provider Networks"}),"\n",(0,o.jsxs)(n.p,{children:["Neutron Provider networks are not used in Calico deployments. Setting\nprovider network extended attributes will have no effect. See\n",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity",children:"IP addressing and connectivity"})," to understand why Neutron provider networks are not\nneeded."]}),"\n",(0,o.jsx)(n.h2,{id:"subnets",children:"Subnets"}),"\n",(0,o.jsx)(n.p,{children:"Neutron subnets are child objects of Neutron networks. In vanilla\nNeutron, a subnet is a collection of IP addresses and other network\nconfiguration (e.g. DNS servers) that is associated with a single\nNeutron network. A single Neutron network may have multiple Neutron\nsubnets associated with it. Eac
1h Neutron subnet represents either an\nIPv4 or IPv6 block of addresses."}),"\n",(0,o.jsxs)(n.p,{children:["Best practices for configuring Neutron subnets in Calico deployments can\nbe found in ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity#part-2-set-up-openstack",children:"Set up OpenStack"}),"."]}),"\n",(0,o.jsx)(n.p,{children:"In Calico, these roles for the Neutron subnet are preserved in their\nentirety. All properties associated with these Neutron subnets are\npreserved and remain meaningful except for:"}),"\n",(0,o.jsxs)("dl",{children:[(0,o.jsx)("dt",{children:(0,o.jsx)("code",{children:"host_routes"})}),(0,o.jsx)("dd",{children:"These have no effect, as the compute nodes will route traffic\nimmediately after it egresses the VM."})]}),"\n",(0,o.jsx)(n.h2,{id:"ports",children:"Ports"}),"\n",(0,o.jsx)(n.p,{children:"In vanilla Neutron, a port represents a connection from a VM to a single\nlayer 2 Neutron network. Obviously, the meaning of this object changes\nin a Calico deployment: instead, a port is a connection from a VM to the\nshared layer 3 network that Calico builds in Neutron."}),"\n",(0,o.jsx)(n.p,{children:"All properties on a port work as normal, except for the following:"}),"\n",(0,o.jsxs)("dl",{children:[(0,o.jsx)("dt",{children:(0,o.jsx)("code",{children:"network_id"})}),(0,o.jsxs)("dd",{children:["The network ID still controls which Neutron network the port is\nattached to, and therefore still controls which Neutron subnets it\nwill be placed in. However, as per the ",(0,o.jsx)("a",{href:"#networks",children:"note above"}),",\nthe Neutron network that a port is placed in does not affect which\nmachines in the deployment it can contact."]})]}),"\n",(0,o.jsx)(n.h3,{id:"extended-attributes-port-binding-attributes",children:"Extended Attributes: Port Binding Attributes"}),"\n",(0,o.jsxs)(n.p,{children:["The ",(0,o.jsx)(n.code,{children:"binding:host-id"})," attribute works as normal. The following notes\napply to the other attributes:"]}),"\n",(0,o.jsxs)("dl",{children:[(0,o.jsx)("dt",{children:(0,o.jsxs)("code",{children:["binding",":profile"]})}),(0,o.jsx)("dd",{children:"This is unused in Calico."}),(0,o.jsx)("dt",{children:(0,o.jsxs)("code",{children:["binding",":vnic_type"]})}),(0,o.jsxs)("dd",{children:["This field, if used, ",(0,o.jsx)("strong",{children:"must"})," be set to ",(0,o.jsx)("code",{children:"normal"}),". If set to any\nother value, Calico will not correctly function!"]})]}),"\n",(0,o.jsx)(n.h2,{id:"quotas",children:"Quotas"}),"\n",(0,o.jsx)(n.p,{children:"Neutron quotas function unchanged."}),"\n",(0,o.jsxs)(n.p,{children:["In most deployments we recommend setting non-administrator tenant quotas\nfor almost all Neutron objects to zero. For more information, see ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity#part-2-set-up-openstack",children:"Set up OpenStack"}),"."]}),"\n",(0,o.jsx)(n.h2,{id:"security-groups",children:"Security Groups"}),"\n",(0,o.jsx)(n.p,{children:"Security groups in vanilla OpenStack provide packet filtering processing\nto individual ports. They can be used to limit the traffic a port may\nissue."}),"\n",(0,o.jsx)(n.p,{children:"In Calico, security groups have all the same function. Additionally,\nthey serve to provide the connectivity-limiting function that in vanilla\nOpenStack is provided by Neutron networks."}),"\n",(0,o.jsx)(n.p,{children:"All the attributes of security groups remain unchanged in Calico."}),"\n",(0,o.jsx)(n.h2,{id:"floating-ips",children:"Floating IPs"}),"\n",(0,o.jsxs)(n.p,{children:["Floating IPs are supported at beta level. For more information, see ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/floating-ips",children:"Floating IPs"}),"."]}),"\n",(0,o.jsx)(n.h2,{id:"neutron-routers",children:"Neutron Routers"}),"\n",(0,o.jsxs)(n.p,{children:["Calico provides connectivity by default between all Neutron networks,\nregardless of whether there are Router objects between them in the Neutron data\nmodel. See ",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/semantics",children:"Detailed semantics"})," for a\nfuller explanation. Where isolation of a particular Neutron network is\ndesired, we recommend expressing that through security group rules."]}),"\n",(0,o.jsx)(n.h2,{id:"qos",children:"QoS"}),"\n",(0,o.jsxs)(n.p,{children:["Calico for OpenStack implements some Neutron QoS policy fields: the ",(0,o.jsx)(n.code,{children:"max_kbps"}),"\nand ",(0,o.jsx)(n.code,{children:"max_burst_kbps"})," fields of bandwidth limit rules, and the ",(0,o.jsx)(n.code,{children:"max_kpps"})," field\nof packet rate limit rules. Calico also honours the ",(0,o.jsx)(n.code,{children:"direction"})," field of these\nrules, so these limits can be set independently for both ingress and egress\ndirections."]}),"\n",(0,o.jsx)(n.admonition,{type:"note",children:(0,o.jsxs)(n.p,{children:["There is uncertainty as to whether ",(0,o.jsx)(n.code,{children:"max_burst_kbps"}
1)," is intended to configure\nthe burst ",(0,o.jsx)(n.em,{children:"rate"})," or the burst ",(0,o.jsx)(n.em,{children:"size"}),". Calico interprets it as the burst ",(0,o.jsx)(n.em,{children:"rate"}),"\nand honours ",(0,o.jsx)(n.code,{children:"neutron.conf"})," fields for configuring the burst ",(0,o.jsx)(n.em,{children:"size"}),"."]})}),"\n",(0,o.jsxs)(n.p,{children:["There are also new Calico Neutron driver settings (cluster-wide, set in ",(0,o.jsx)(n.code,{children:"neutron.conf"}),"):"]}),"\n",(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] max_ingress_connections_per_port"})," for imposing a maximum number of\ningress connections per Neutron port, and"]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] max_egress_connections_per_port"})," for imposing a maximum number of\negress connections per Neutron port."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] ingress_burst_kbits"}),", if non-zero, configures the maximum allowed\nburst at peakrate, in the ingress direction."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] egress_burst_kbits"}),", if non-zero, configures the maximum allowed\nburst at peakrate, in the egress direction."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] ingress_minburst_bytes"}),", if non-zero, configures the minimum burst\nsize for peakrate data, in the ingress direction."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.code,{children:"[calico] egress_minburst_bytes"}),", if non-zero, configures the minimum burst\nsize for peakrate data, in the egress direction."]}),"\n"]}),"\n"]}),"\n",(0,o.jsx)(n.h2,{id:"load-balancer-as-a-service",children:"Load Balancer as a Service"}),"\n",(0,o.jsx)(n.p,{children:"Load Balancer as a Service (LBaaS) does not function in a Calico network. Any\nattempt to create one will fail."}),"\n",(0,o.jsx)(n.admonition,{type:"note",children:(0,o.jsx)(n.p,{children:"It is possible that in a future version of Calico LBaaS may be\nfunctional. Watch this space."})}),"\n",(0,o.jsx)(n.h2,{id:"horizon",children:"Horizon"}),"\n",(0,o.jsx)(n.p,{children:"Horizon makes many provisioning actions available that mirror options on\nthe Neutron API. This section lists them, and indicates whether they can\nbe used or not, and any subtleties that might be present in them."}),"\n",(0,o.jsx)(n.p,{children:"Much of the detail has been left out of this section, and is instead\npresent in the relevant Neutron API sections above: please consult them\nfor more."}),"\n",(0,o.jsx)(n.h3,{id:"section-project",children:"Section: Project"}),"\n",(0,o.jsx)(n.h4,{id:"tab-compute---instances",children:"Tab: Compute -> Instances"}),"\n",(0,o.jsxs)(n.p,{children:["When launching instances, remember that security groups are used to\ndetermine reachability, not networks. Choose networks based on whether\nyou need an external or an internal IP address, and choose security\ngroups based on the machines you'd like to talk to in the cloud. See\n",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity",children:"IP addressing and connectivity"})," for more."]}),"\n",(0,o.jsx)(n.h4,{id:"tab-compute---access--security",children:"Tab: Compute -> Access & Security"}),"\n",(0,o.jsx)(n.p,{children:"As noted above, tenants should ensure they configure their security\ngroups to set up their connectivity appropriately."}),"\n",(0,o.jsx)(n.h4,{id:"tab-network---network-topology",children:"Tab: Network -> Network Topology"}),"\n",(0,o.jsxs)(n.p,{children:["For the 'Create Network' button, see the ",(0,o.jsx)(n.a,{href:"#networks",children:"Networks"})," section.\nFor the 'Create Router' button, see the ",(0,o.jsx)(n.a,{href:"#neutron-routers",children:"Layer 3 Routing"})," section."]}),"\n",(0,o.jsx)(n.h4,{id:"tab-network---networks",children:"Tab: Network -> Networks"}),"\n",(0,o.jsxs)(n.p,{children:["For networks and subnets, see the sections on ",(0,o.jsx)(n.a,{href:"#networks",children:"Networks"})," and\n",(0,o.jsx)(n.a,{href:"#subnets",children:"Subnets"}),"."]}),"\n",(0,o.jsx)(n.h4,{id:"tab-network---routers",children:"Tab: Network -> Routers"}),"\n",(0,o.jsxs)(n.p,{children:["Tenants should be prevented from creating routers, as they serve no\npurpose in a Calico network. See ",(0,o.jsx)(n.a,{href:"#neutron-routers",children:"Layer 3 Routing"})," for more."]}),"\n",(0,o.jsx)(n.h3,{id:"section-admin",children:"Section: Admin"}),"\n",(0,o.jsx)(n.h4,{id:"tab-system-panel---networks",children:"Tab: System Panel -> Networks"}),"\n",(0,o.jsxs)(n.p,{children:["In the course of general operation administrators are not expected to\nmake changes to their networking configuration. However, for initial\nnetwork setup, this panel may be used to make changes. See\n",(0,o.jsx)(n.a,{href:"/calico/3.29/networking/openstack/connectivity",children:"IP addressing and connectivity"})," for details on how to achieve this setup."]}),"\n",(0,o.jsx)(n.h4,{id:"tab-system-panel---routers",children:"Tab: System Panel -> Routers"}),"\n",(0,o.jsxs)(n.p,{children:["Administrators should not create routers, as they serve no purpose in a\nCalico network. See ",(0,o.jsx)(n.a,{href:"#neutron-routers",children:"Layer 3 Routing"})," for more."]})]})}function h(e={}){let{wrapper:n}={...(0,i.R)(),...e.components};return n?(0,o.jsx)(n,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},3413(e,n,t){t.d(n,{R:()=>s,x:()=>a});var r=t(16645);let o={},i=r.createContext(o);function s(e){let n=r.useContext(i);return r.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:s(e.components),r.createElement(i.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.