Summary

  • RFC 9689's migration example lets legacy nodes keep LDP or RSVP-TE while newer nodes receive PCECC instructions; the PCECC can proxy signalling across the boundary.
  • The proxy creates interoperability, not one atomic transaction. Safe cutover needs an identity map, per-node receipts, explicit ingress authority, orphan-state ownership and proof that former state was cleaned on both sides.

Picture Node3 at the boundary. To its left, Node1 and Node2 still build an LSP with familiar distributed MPLS signalling. To its right, Node4 and Node5 no longer run that signalling; the PCECC programs the out-segment at Node3, the in- and out-segments at Node4 and the in-segment at Node5. Packets may see one path. Operations must not pretend the path has one control history.

That is the overlooked value of Appendix A.1 of RFC 9689. The proxy is not merely a compatibility convenience. It marks the place where one claim changes its evidence. On the legacy side, label state is explained through LDP or RSVP-TE sessions, advertisements, reservations and local tables. On the new side, it is explained through PCEP sessions, Central Controller Instructions, CC-ID values and PCRpt reports. At the seam, somebody must prove that these records describe the same intended LSP generation.

The document is careful about its status. RFC 9689 is Informational, and the appendix collects use cases that were not in active development when it was published. The migration example is architectural evidence, not a deployment report or a turnkey runbook. No cited source establishes that a named operator or product performs this transition.

One path needs an identity ledger

RFC 9050 gives PCECC instructions their own identifiers. A CC-ID is unique inside one PCEP session. A PCECC LSP carries an LSP identifier and source, and the ingress supplies a PLSP-ID that transit and egress instructions can reuse. Those coordinates are useful, but none is automatically the identifier used by an LDP or RSVP-TE neighbour on the legacy portion.

A migration record therefore needs a mapping, not a slogan. It should bind the service or change request, old-path identity, legacy signalling state, boundary node and interface, PCEP session, PCE identity, PLSP-ID, every CC-ID, label direction, intended generation and rollback generation. If Node3 proxies a signal, retain what it received, the rule that transformed it and what it emitted. The transformed record must not impersonate its input.

This is where a single dashboard row called “LSP up” becomes hazardous. It can hide that one label was locally allocated by a PCC, another was assigned by the PCE, an old reservation is awaiting expiry, and the proxy is the only system that knows how the two halves correspond. The label values may be correct while their custody is undocumented.

Every acknowledgement is local

RFC 9050 sends label instructions to each PCC with PCInitiate. Each node returns a PCRpt acknowledging its CCI. A node must return an error when the label is outside the reserved range or when it cannot download the instruction. That is good protocol evidence: the controller can distinguish a failed instruction from silence.

It is still per-node evidence. Three acknowledgements do not become an atomic cross-node commit merely because one controller collected them. The controller must correlate the intended generation, confirm that every required ingress, transit and egress instruction arrived, and refuse cutover if a required receipt is missing or stale. The legacy part requires its own contemporaneous observation.

Updates expose the staging explicitly. RFC 9050 uses make-before-break: download the new instructions, tell the ingress to switch, receive the ingress report, then clean the former instructions. These are three different decisions. Before the switch, spare labels and resources may exist without carrying the service. After the switch but before cleanup, both generations may remain installed. A cleanup report proves removal at one PCC; it does not prove that an old legacy reservation or a proxy mapping also disappeared.

Rollback must name the stage from which it begins. If the new instructions were only partly installed, remove that partial generation without touching the live old path. If ingress has switched, restore forwarding authority before removing the new state. If old legacy state has already been withdrawn, “switch back” may require reconstruction rather than a flag reversal.

Controller failure does not erase its instructions

Continuity creates a second trap. RFC 9050 deliberately avoids immediate service disruption after PCE failure: Central Controller Instructions can remain until a State Timeout Interval expires, and another PCE can take control of orphaned instructions. RFC 8283 likewise explains why controller redundancy depends on state synchronization and why preserving changes across failure is hard.

Retained state is useful running code. It is also an ownership test. During the interval after a controller loss, which authority may cut traffic over, renew legacy signalling, adopt the CCI, or delete it? A new controller's reachability to the nodes does not prove that it has reconstructed the exact proxy mapping or the operator's intended migration stage.

The recovery record should therefore include the last complete generation, acknowledged nodes, unacknowledged nodes, ingress state, legacy signalling state, cleanup state, timeout deadlines, orphan-adoption event and the human or automated policy that authorized the next action. Re-synchronization can compare a PCE view with PCC label allocations. It cannot recover an undocumented business decision or prove that the old side of the seam is safe to retire.

A bounded migration receipt

An operator does not need a universal distributed transaction protocol to manage this honestly. It needs a bounded receipt whose claims match the available evidence:

  1. name the nodes and interfaces on each side of the migration seam;
  2. capture LDP or RSVP-TE state on every legacy hop;
  3. bind the proxy's input, decision and output to one change generation;
  4. record the PCE and PCC capabilities and authenticated sessions;
  5. map the LSP identity to each PLSP-ID, source and CC-ID;
  6. require the expected CCI report from every PCECC node;
  7. authorize ingress cutover separately from instruction download;
  8. observe forwarding without using that observation to replace control evidence;
  9. acknowledge cleanup on the new side and withdrawal on the legacy side;
  10. test controller loss, State Timeout and orphan re-delegation before retiring the old regime.

The standard's hybrid design is strongest when it remains modest. A proxy can lower the cost of gradual adoption. It cannot confer one history, one owner or one rollback law on state created by different protocols.

Sources