Skip to content

Make vpc.max.networks dynamic and return a useful error at the limit - #14373

Open
MitchDrage wants to merge 1 commit into
apache:mainfrom
MitchDrage:vpc-tier-limits
Open

MitchDrage wants to merge 1 commit into
apache:mainfrom
MitchDrage:vpc-tier-limits

Conversation

@MitchDrage

@MitchDrage MitchDrage commented Oct 9, 2026 •

Copy link
Copy Markdown

Description

  • Changed vpc.max.networks to be dynamic, so changes no longer need a restart.
  • Hitting the limit now returns a 431 with a readable message, where it used to return a 530 "Internal error executing command".
  • The key name is unchanged, so existing values carry over without a DB migration.

Messages:
Original (HTTP 530):

  • Non-admin users: Internal error executing command, please contact your system administrator
  • Root admins: Number of networks per VPC cannot surpass [3].

New (HTTP 431, all users):
VPC web-prod has reached the maximum of 3 networks. Delete an unused network or contact your platform administrator to raise the limit.

Closes #14372

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Screenshots (if appropriate):

N/A

How Has This Been Tested?

  • Unit tests: a new test checks the limit is read from the current setting value.
  • Simulator: advanced zone, with tenant calls made as non-admin users:
    • The global limit rejects the extra tier with a 431 and the message above.
    • Changing the global value applies straight away.

How did you try to break this feature and the system with this change?

  • Tested an upgrade from an existing install: a custom value of 4 was kept.
  • Tried to change the setting as a domain admin. It's refused.
  • Ran the full server module test suite. All tests pass.

"3",
"Maximum number of networks per VPC. Can be overridden per domain and per account",
true,
List.of(ConfigKey.Scope.Account, ConfigKey.Scope.Domain));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can a domain admin now raise this for their own domain? they can change account and domain settings, so the operator cap stops being a cap

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Damans. You were right - a domain admin could change the setting for their domain.
Since I've pivoted the idea here, it's no longer applicable as it's back to being a global setting. See the other comment in the PR and the new description.

@MitchDrage MitchDrage changed the title Allow per-Domain/Account VPC tier limits Make vpc.max.networks dynamic and return a useful error at the limit Oct 10, 2026
@MitchDrage

Copy link
Copy Markdown
Author

I've changed direction on this PR. Per-account/domain values aren't needed: the cap exists to handle the technical limitation of the VR's NIC capacity which is the same for every tenant, and VPC tiers already count toward the account and domain guest network limits.
I've removed the per-account/domain values, and this PR now makes the global setting dynamic, with the clearer error. I've updated the title and description to match.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature: Make vpc.max.networks dynamic and improve the limit-reached error

2 participants