Hi,

We're still doing some scale tests of OpenStack ussuri with ml2/ovn driver. 
We've deployed 140 virtualized compute nodes, and started creating routers that 
share single external network between them. Additionally, each router is 
connected to a private network.
Previously[1] we hit a problem of too many logical flows being generated per 
router connected to the same "external" network - this put too much stress on 
ovn-controller and ovs-vswitchd on compute nodes, and we've applied a patch[2] 
to limit a number of logical flows created per router.
After we dealt with that we've done more testing and created 200 routers 
connected to single external network. After that we've noticed the following 
logs in ovs-vswitchd.log:

---8<---8<---8<---
2020-09-28T11:10:18.938Z|18401|ofproto_dpif_xlate(handler9)|WARN|over 4096 
resubmit actions on bridge br-int while processing 
icmp6,in_port=1,vlan_tci=0x0000,dl_src=fa:16:3e:9b:77:c3,dl_dst=33:33:00:00:00:02,ipv6_src=fe80::f816:3eff:fe9b:77c3,ipv6_dst=ff02::2,ipv6_label=0x2564e,nw_tos=0,nw_ecn=0,nw_ttl=255,icmp_type=133,icmp_code=0
---8<---8<---8<---

That starts happening after I create ~178 routers connected to the same 
external network.

IPv6 RS ICMP packets are coming from the external network - that's due to the 
fact that all virtual compute nodes have IPv6 address on their interface used 
for the external network and are trying to discover a gateway. That's by 
accident, and we can remove IPv6 address from that interface, however I'm 
worried that it would just hide some bigger issue with flows generated by OVN.

software stack:

ovn: 20.06.2
ovs: 2.13.1
neutron: 16.1.0

[1] 
http://lists.openstack.org/pipermail/openstack-discuss/2020-September/017370.html
[2] https://review.opendev.org/#/c/752678/

-- 
  Krzysztof Klimonda
  kklimo...@syntaxhighlighted.com
_______________________________________________
discuss mailing list
disc...@openvswitch.org
https://mail.openvswitch.org/mailman/listinfo/ovs-discuss

Reply via email to