Skip to content

Live security group additions and removals #12976

@llukeell

Description

@llukeell

Problem:
Currently CloudStack requires an instance to be stopped before adding or removing a security group, causing unnecessary downtime. The underlying iptables rules are enforced at the hypervisor level and should not require instance downtime to modify.

Expected behavior:
Security groups can be added or removed from a running instance without a stop/start cycle.

CloudStack version: 4.21.0.0
Zone type: Security Group zone

Metadata

Metadata

Assignees

No one assigned
    No fields configured for Feature.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions