)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"ad515c82_36400df9","updated":"2026-07-24 12:59:22.000000000","message":"-1 only for visibility","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"}],"specs/2026.2/bgp-route-leak-geneve-networks.rst":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":true,"context_lines":[{"line_number":109,"context_line":"   corresponding logical switch port (LSP) of type ``router`` is created on"},{"line_number":110,"context_line":"   the tenant LS. This connection\u0027s sole purpose is to make OVN treat the LS"},{"line_number":111,"context_line":"   as \"connected\" to ``bgp-lr-main``, triggering host route advertisement."},{"line_number":112,"context_line":"   No data traffic flows through this link."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"   The LRP/LSP pair is created when the **first** subnet on a network is"},{"line_number":115,"context_line":"   leaked and removed when the **last** leaked subnet on that network has"}],"source_content_type":"text/x-rst","patch_set":3,"id":"efd5165b_e3a728cf","line":112,"updated":"2026-07-24 12:59:22.000000000","message":"So, if I\u0027m not wrong, now will have an extra LRP from the ls-private networks (https://specs.openstack.org/openstack/neutron-specs/specs/2025.2/ovn-bgp-integration.html) to the main BGP router. Won\u0027t be able now to access directly to local BGP router external network, using the nested router SNAT?","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"31e20b8c41316eaa097eb9c06ecd252f413670a3","unresolved":false,"context_lines":[{"line_number":109,"context_line":"   corresponding logical switch port (LSP) of type ``router`` is created on"},{"line_number":110,"context_line":"   the tenant LS. This connection\u0027s sole purpose is to make OVN treat the LS"},{"line_number":111,"context_line":"   as \"connected\" to ``bgp-lr-main``, triggering host route advertisement."},{"line_number":112,"context_line":"   No data traffic flows through this link."},{"line_number":113,"context_line":""},{"line_number":114,"context_line":"   The LRP/LSP pair is created when the **first** subnet on a network is"},{"line_number":115,"context_line":"   leaked and removed when the **last** leaked subnet on that network has"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3707c7d8_0c5f3c6c","line":112,"in_reply_to":"efd5165b_e3a728cf","updated":"2026-07-24 13:30:54.000000000","message":"No because the LRP won\u0027t have any address, IPv6 LLA only. To be extra safe, we can put an ACL on the port to drop all traffic so we\u0027re sure the traffic will go through the right path.","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":true,"context_lines":[{"line_number":124,"context_line":""},{"line_number":125,"context_line":"Because ``bgp-lr-main`` already has"},{"line_number":126,"context_line":"``options:dynamic-routing-redistribute\u003dconnected-as-host,nat`` set at the"},{"line_number":127,"context_line":"router level, no additional per-LRP redistribute option is needed. OVN"},{"line_number":128,"context_line":"automatically redistributes host routes (/32 for IPv4, /128 for IPv6) for"},{"line_number":129,"context_line":"ports on the newly attached logical switch, populates the Advertised_Route"},{"line_number":130,"context_line":"table in the Southbound DB, and the per-chassis FRR instances advertise them"},{"line_number":131,"context_line":"to the BGP peers."},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"Traffic Flows"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9133cf1f_9134703e","line":130,"range":{"start_line":127,"start_character":67,"end_line":130,"end_character":26},"updated":"2026-07-24 12:59:22.000000000","message":"Just creating the LRP from the internal router to main BGP router, OVN provides this functionality?\n\nIf I\u0027m not wrong, what OVN will advertise is the /32-/128 IPs. Then why calling it `leak_routes`?","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"31e20b8c41316eaa097eb9c06ecd252f413670a3","unresolved":false,"context_lines":[{"line_number":124,"context_line":""},{"line_number":125,"context_line":"Because ``bgp-lr-main`` already has"},{"line_number":126,"context_line":"``options:dynamic-routing-redistribute\u003dconnected-as-host,nat`` set at the"},{"line_number":127,"context_line":"router level, no additional per-LRP redistribute option is needed. OVN"},{"line_number":128,"context_line":"automatically redistributes host routes (/32 for IPv4, /128 for IPv6) for"},{"line_number":129,"context_line":"ports on the newly attached logical switch, populates the Advertised_Route"},{"line_number":130,"context_line":"table in the Southbound DB, and the per-chassis FRR instances advertise them"},{"line_number":131,"context_line":"to the BGP peers."},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"Traffic Flows"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3ea3a45d_bb741024","line":130,"range":{"start_line":127,"start_character":67,"end_line":130,"end_character":26},"in_reply_to":"9133cf1f_9134703e","updated":"2026-07-24 13:30:54.000000000","message":"We want to leak routes only from a given LS. The internal router can have multiple networks (LSs) attached that should remain private.","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":true,"context_lines":[{"line_number":185,"context_line":"packets from the external fabric) but will be **blackholed** at"},{"line_number":186,"context_line":"``bgp-lr-main`` because no static route exists for those prefixes."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Operators should therefore leak **all** subnets on a network or be aware of"},{"line_number":189,"context_line":"this asymmetry. A future extension may enforce this constraint automatically."},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Overlapping Subnet Ranges"},{"line_number":192,"context_line":"-------------------------"},{"line_number":193,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"981437b9_c4d583e7","line":190,"range":{"start_line":188,"start_character":0,"end_line":190,"end_character":1},"updated":"2026-07-24 12:59:22.000000000","message":"I think we need to handle this in this spec too. The API should check the network subnets and enforce the `leak_routes` flag in all of them.\n\nMaybe this could be a network flag, instead of a subnet flag.","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"9ac6f03dde9aab4c232bbac7848877c17b33d549","unresolved":false,"context_lines":[{"line_number":185,"context_line":"packets from the external fabric) but will be **blackholed** at"},{"line_number":186,"context_line":"``bgp-lr-main`` because no static route exists for those prefixes."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Operators should therefore leak **all** subnets on a network or be aware of"},{"line_number":189,"context_line":"this asymmetry. A future extension may enforce this constraint automatically."},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Overlapping Subnet Ranges"},{"line_number":192,"context_line":"-------------------------"},{"line_number":193,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"3112600c_f95b0163","line":190,"range":{"start_line":188,"start_character":0,"end_line":190,"end_character":1},"in_reply_to":"74833abe_ddc0c3ba","updated":"2026-07-24 20:10:44.000000000","message":"Acknowledged","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"31e20b8c41316eaa097eb9c06ecd252f413670a3","unresolved":true,"context_lines":[{"line_number":185,"context_line":"packets from the external fabric) but will be **blackholed** at"},{"line_number":186,"context_line":"``bgp-lr-main`` because no static route exists for those prefixes."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Operators should therefore leak **all** subnets on a network or be aware of"},{"line_number":189,"context_line":"this asymmetry. A future extension may enforce this constraint automatically."},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Overlapping Subnet Ranges"},{"line_number":192,"context_line":"-------------------------"},{"line_number":193,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"74833abe_ddc0c3ba","line":190,"range":{"start_line":188,"start_character":0,"end_line":190,"end_character":1},"in_reply_to":"981437b9_c4d583e7","updated":"2026-07-24 13:30:54.000000000","message":"The original proposal (PS1) had it as a network flag but that creates a bit more complexity because we\u0027d need to monitor adding/removing subnets in the leaked network.\n\nWith the subnet attribute it provides better granularity of what is accessible and what is not. I do not have a strong opinion here though. If leaking subnets that are not flagged as such is a concern, we could work it around by reusing the FRR interface from EVPN and filter what IPs are advertised on the FRR layer. That adds additional complexity because it hooks in the agent that needs to be aware of what is exposed and what is not.","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":true,"context_lines":[{"line_number":217,"context_line":"-----------------------"},{"line_number":218,"context_line":""},{"line_number":219,"context_line":"The ``leak_routes`` attribute is only valid on subnets belonging to networks"},{"line_number":220,"context_line":"with ``provider:network_type \u003d geneve``. Attempting to set it on subnets of"},{"line_number":221,"context_line":"other network types is rejected with a ``BadRequest`` (HTTP 400) error."},{"line_number":222,"context_line":""},{"line_number":223,"context_line":"Router Attachment Required"}],"source_content_type":"text/x-rst","patch_set":3,"id":"2c1d1248_83b87db9","line":220,"range":{"start_line":220,"start_character":6,"end_line":220,"end_character":40},"updated":"2026-07-24 12:59:22.000000000","message":"Why?","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"31e20b8c41316eaa097eb9c06ecd252f413670a3","unresolved":false,"context_lines":[{"line_number":217,"context_line":"-----------------------"},{"line_number":218,"context_line":""},{"line_number":219,"context_line":"The ``leak_routes`` attribute is only valid on subnets belonging to networks"},{"line_number":220,"context_line":"with ``provider:network_type \u003d geneve``. Attempting to set it on subnets of"},{"line_number":221,"context_line":"other network types is rejected with a ``BadRequest`` (HTTP 400) error."},{"line_number":222,"context_line":""},{"line_number":223,"context_line":"Router Attachment Required"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c6e5c2db_54f1ec47","line":220,"range":{"start_line":220,"start_character":6,"end_line":220,"end_character":40},"in_reply_to":"2c1d1248_83b87db9","updated":"2026-07-24 13:30:54.000000000","message":"The flat is advertised by default and VLAN private networks can\u0027t work east/west with BGP because the fabric is L3 only and VLAN is an L2 segmentation. Vxlan can be added on demand if needed, the spec considers geneve only to make the feature smaller.","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"a6bb351edf250f7bdce39872d8956a70a72993ca","unresolved":true,"context_lines":[{"line_number":247,"context_line":".. code-block:: python"},{"line_number":248,"context_line":""},{"line_number":249,"context_line":"    class BGPLeakRoutes(model_base.BASEV2):"},{"line_number":250,"context_line":"        __tablename__ \u003d \u0027bgp_leak_routes\u0027"},{"line_number":251,"context_line":""},{"line_number":252,"context_line":"        subnet_id \u003d sa.Column("},{"line_number":253,"context_line":"            sa.String(36),"}],"source_content_type":"text/x-rst","patch_set":3,"id":"4550d701_35561c64","line":250,"updated":"2026-07-24 12:59:22.000000000","message":"Child tables usually have the name of the parent one. For subnets, for example, we have:\n```\n| subnet_dns_publish_fixed_ips         |\n| subnet_service_types                 |\n| subnetpoolprefixes                   |\n| subnetpoolrbacs                      |\n| subnetpools                          |\n| subnetroutes                         |\n| subnets                              |\n\n```","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"31e20b8c41316eaa097eb9c06ecd252f413670a3","unresolved":true,"context_lines":[{"line_number":247,"context_line":".. code-block:: python"},{"line_number":248,"context_line":""},{"line_number":249,"context_line":"    class BGPLeakRoutes(model_base.BASEV2):"},{"line_number":250,"context_line":"        __tablename__ \u003d \u0027bgp_leak_routes\u0027"},{"line_number":251,"context_line":""},{"line_number":252,"context_line":"        subnet_id \u003d sa.Column("},{"line_number":253,"context_line":"            sa.String(36),"}],"source_content_type":"text/x-rst","patch_set":3,"id":"b791e6a5_b6e062d4","line":250,"in_reply_to":"4550d701_35561c64","updated":"2026-07-24 13:30:54.000000000","message":"So `subnets_bgp_leak_routes` would be a better naming?","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"9ac6f03dde9aab4c232bbac7848877c17b33d549","unresolved":false,"context_lines":[{"line_number":247,"context_line":".. code-block:: python"},{"line_number":248,"context_line":""},{"line_number":249,"context_line":"    class BGPLeakRoutes(model_base.BASEV2):"},{"line_number":250,"context_line":"        __tablename__ \u003d \u0027bgp_leak_routes\u0027"},{"line_number":251,"context_line":""},{"line_number":252,"context_line":"        subnet_id \u003d sa.Column("},{"line_number":253,"context_line":"            sa.String(36),"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa72a836_889cded9","line":250,"in_reply_to":"b791e6a5_b6e062d4","updated":"2026-07-24 20:10:44.000000000","message":"Done","commit_id":"b39105aa10c868fe4aa834194a9320d1b3d77f03"}]}
