In environment where single network (net-create --shared) is shared beetwen multiple tenants, all tenants except one who is owning network are unable to spawn new instances as there's no 'default' security group for them.
2013-04-23 15:45:00.100 ERROR nova.compute.manager [req-077e253e-9fe4-4dee-adfc-4535996a19e5 3735b2c7b83d43b4be0b9a4c4ae1d2ae 4d979b29cec04703aa67ec6ee70efd97] [instance: 4631ea86-c258-4928-9b2d-ae15a9eb94b6] Error: ['Traceback (most recent call last):\n', ' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 831, in _run_instance\n requested_networks, macs, security_groups)\n', ' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 1075, in _allocate_network\n instance=instance)\n', ' File "/usr/lib64/python2.7/contextlib.py", line 24, in __exit__\n self.gen.next()\n', ' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 1071, in _allocate_network\n security_groups=security_groups)\n', ' File "/usr/lib/python2.7/site-packages/nova/network/api.py", line 46, in wrapper\n res = f(self, context, *args, **kwargs)\n', ' File "/usr/lib/python2.7/site-packages/nova/network/quantumv2/api.py", line 212, in allocate_for_instance\n security_group_id=security_group)\n', 'SecurityGroupNotFound: Security group default not found.\n']
2013-04-23 15:45:00.123 ERROR nova.scheduler.filter_scheduler [req-077e253e-9fe4-4dee-adfc-4535996a19e5 3735b2c7b83d43b4be0b9a4c4ae1d2ae 4d979b29cec04703aa67ec6ee70efd97] [instance: 4631ea86-c258-4928-9b2d-ae15a9eb94b6] Error from last host: linux-tsn9 (node linux-tsn9): [u'Traceback (most recent call last):\n', u' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 831, in _run_instance\n requested_networks, macs, security_groups)\n', u' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 1075, in _allocate_network\n instance=instance)\n', u' File "/usr/lib64/python2.7/contextlib.py", line 24, in __exit__\n self.gen.next()\n', u' File "/usr/lib/python2.7/site-packages/nova/compute/manager.py", line 1071, in _allocate_network\n security_groups=security_groups)\n', u' File "/usr/lib/python2.7/site-packages/nova/network/api.py", line 46, in wrapper\n res = f(self, context, *args, **kwargs)\n', u' File "/usr/lib/python2.7/site-packages/nova/network/quantumv2/api.py", line 212, in allocate_for_instance\n security_group_id=security_group)\n', u'SecurityGroupNotFound: Security group default not found.\n']
Hi,
I which plugin are you using? I tested this with OVS and wasn't able to reproduce:
$ quantum port-show adae2775- fe06-4d7e- a1b6-6d6bba9522 b5 ------- ----+-- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ----+ ------- ----+-- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ----+ b1e8-409e- 9e14-ff5284c140 c0 | c85d-4ed4- b706-cb84a6ef66 3d", "ip_address": "23.23.23.2"} | fe06-4d7e- a1b6-6d6bba9522 b5 | 5a5d-43c0- a884-9dea4e6802 a4 | c19a-41d8- bd63-71b72c0102 35 | a930086de3e945f f8 | ------- ----+-- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- ----+ arosen- laptop: /opt/stack/ quantum/ quantum/ plugins/ linuxbridge$ quantum net-show sha ------- ----+-- ------- ------- ------- ------- ------- -+ ------- ----+-- ------- ------- ------- ------- ------- -+ 5a5d-43c0- a884-9dea4e6802 a4 | c85d-4ed4- b706-cb84a6ef66 3d | 2a62045084e8a38 da | ------- ----+-- ------- ------- ------- ------- ------- -+ arosen- laptop: /opt/stack/ quantum/ quantum/ plugins/ linuxbridge$ quantum security-group-list ------- ------- ------- ------- ----+-- ------- +------ ------- + ------- ------- ------- ------- ----+-- ------- +------ ------- + c19a-41d8- bd63-71b72c0102 35 | default | default |
+------
| Field | Value |
+------
| admin_state_up | True |
| device_id | 42db0dfd-
| device_owner | compute:None |
| fixed_ips | {"subnet_id": "19d64df4-
| id | adae2775-
| mac_address | fa:16:3e:8a:72:90 |
| name | |
| network_id | f97f3160-
| security_groups | 28d96f12-
| status | ACTIVE |
| tenant_id | 1da517566c1147e
+------
arosen@
+------
| Field | Value |
+------
| admin_state_up | True |
| id | f97f3160-
| name | sha |
| router:external | False |
| shared | True |
| status | ACTIVE |
| subnets | 19d64df4-
| tenant_id | 81ed5d500bae4b5
+------
arosen@
+------
| id | name | description |
+------
| 28d96f12-