Security groups and OVS
In Havana the use of LibvirtHybridOVSBridgeDriver has been deprecated. However it is needed for security groups to function.
So on our stack I made the following changes In nova.conf
And I enabled ipfiltering on the bridge:
sysctl -w net.bridge.bridge-nf-call-iptables = 1
This makes security groups work again, however this comes with a rather hefty performance penalty.
I have therefore two questions: - How can I mitigate this performance problem? - If using LibvritHybridOVSBridge is deprecated, what should I actually use in stead?