SONiC icon indicating copy to clipboard operation
SONiC copied to clipboard

Add time-based ACL High Level Design document

Open wsycqyz opened this issue 2 years ago • 1 comments

This is new feature: time-based ACL HLD. The related code PR is: https://github.com/sonic-net/sonic-utilities/pull/2354 https://github.com/sonic-net/sonic-buildimage/pull/11989

wsycqyz avatar Sep 07 '22 03:09 wsycqyz

Comments from community:

  1. Support different format for start_time and end_time (might be we can do this in cli's implementation )
  2. Add optional field to existing acl rule instead create new table
  3. Cli to create time_based acl rule based relative semantic such as add acl rule *** expire in 2hrs which will use system current time as start automatically then no time sync consideration here
  4. For general use case, if user want to provide absolute time, the time sync is required
  5. Who can cleanup the config_db? In current HLD, stale rule will be removed by mgr after it expired, however it will change config_db. We suppose sonic will not touch/change config db since it is the system that consuming the config_db. But left stale rules in config_db can be also lead some unnecessary overhead, may be we can provide an option to user and let user to decide if remove the stale rule automatically?

Blueve avatar Nov 01 '22 16:11 Blueve