scheduler: network domain scope filter

This commit is contained in:
Zexi
2019-06-14 10:27:00 +08:00
parent e2198b5641
commit 0a511523d6
@@ -26,6 +26,7 @@ import (
schedapi "yunion.io/x/onecloud/pkg/apis/scheduler"
"yunion.io/x/onecloud/pkg/scheduler/api"
"yunion.io/x/onecloud/pkg/scheduler/core"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type NetworkSchedtagPredicate struct {
@@ -103,6 +104,13 @@ func (p *NetworkSchedtagPredicate) IsResourceFitInput(u *core.Unit, _ core.Candi
if !network.IsPublic {
return fmt.Errorf("Network %s is private", network.Name)
}
if rbacutils.TRbacScope(network.PublicScope) == rbacutils.ScopeDomain {
netDomain := network.DomainId
reqDomain := net.Domain
if netDomain != reqDomain {
return fmt.Errorf("Network domain scope %s not owner by %s", netDomain, reqDomain)
}
}
}
if len(net.Address) > 0 {
ipAddr, err := netutils.NewIPV4Addr(net.Address)