Skip to content

Commit f367d2e

Browse files
committed
affinity: make the host-tag affinity group admin-controlled
Host tags are set by the operator, so a group whose name is used as a host tag should be admin-controlled too. Override isAdminControlledGroup() to true (as ExplicitDedication does) so a non-admin cannot create a group named after an operator tag to bias their VMs onto those hosts.
1 parent f7317b2 commit f367d2e

2 files changed

Lines changed: 12 additions & 1 deletion

File tree

‎plugins/affinity-group-processors/host-tag-affinity/src/main/java/org/apache/cloudstack/affinity/HostTagAffinityProcessor.java‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
/**
3838
* Soft VM-to-host placement preference: the affinity group name is treated as a host tag, and hosts
3939
* carrying that tag in the VM's zone have their deployment priority raised. A preference, not a
40-
* constraint — no host is excluded. Note: the priority channel is not honored by automatic DRS.
40+
* constraint, so no host is excluded. Note: the priority channel is not honored by automatic DRS.
4141
*/
4242
public class HostTagAffinityProcessor extends AffinityProcessorBase implements AffinityGroupProcessor {
4343

@@ -60,6 +60,11 @@ public void process(VirtualMachineProfile vmProfile, DeploymentPlan plan, Exclud
6060
}
6161
}
6262

63+
@Override
64+
public boolean isAdminControlledGroup() {
65+
return true;
66+
}
67+
6368
protected void processAffinityGroup(AffinityGroupVMMapVO vmGroupMapping, DeploymentPlan plan, VirtualMachine vm) {
6469
AffinityGroupVO group = affinityGroupDao.findById(vmGroupMapping.getAffinityGroupId());
6570
if (group == null || StringUtils.isBlank(group.getName())) {

‎plugins/affinity-group-processors/host-tag-affinity/src/test/java/org/apache/cloudstack/affinity/HostTagAffinityProcessorTest.java‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,4 +132,10 @@ public void testCheckAlwaysTrue() throws Exception {
132132
// A soft preference must never fail a planned destination.
133133
Assert.assertTrue(processor.check(Mockito.mock(VirtualMachineProfile.class), Mockito.mock(DeployDestination.class)));
134134
}
135+
136+
@Test
137+
public void testGroupIsAdminControlled() {
138+
// Host tags are operator-set, so this group type is admin-controlled.
139+
Assert.assertTrue(processor.isAdminControlledGroup());
140+
}
135141
}

0 commit comments

Comments
 (0)