Thursday, 2018-07-05

*** dlw has joined #kata-dev01:48
*** zerocoolback has joined #kata-dev02:21
*** zerocoolback has quit IRC02:21
*** zerocoolback has joined #kata-dev02:21
*** zerocoolback has quit IRC03:56
*** sjas_ has joined #kata-dev04:22
*** sjas has quit IRC04:26
*** jodh has joined #kata-dev05:40
*** jodh has quit IRC05:40
*** jodh has joined #kata-dev05:40
*** zerocoolback has joined #kata-dev06:42
*** zerocoolback has quit IRC06:43
*** zerocoolback has joined #kata-dev06:43
*** zerocoolback has quit IRC06:48
*** sameo has joined #kata-dev07:36
*** davidgiluk has joined #kata-dev08:00
*** gwhaley has joined #kata-dev09:24
*** isaagar has quit IRC09:40
*** dlw1 has joined #kata-dev10:03
*** dlw has quit IRC10:03
*** dlw1 is now known as dlw10:03
*** isaagar has joined #kata-dev10:06
*** dlw1 has joined #kata-dev10:36
*** dlw has quit IRC10:37
*** dlw1 is now known as dlw10:37
*** devimc has joined #kata-dev11:47
*** lsm5 has quit IRC11:49
*** lsm5 has joined #kata-dev11:50
*** lsm5 has quit IRC11:54
*** lsm5 has joined #kata-dev11:54
*** zerocoolback has joined #kata-dev12:21
*** dlw has quit IRC12:31
*** isaagar has quit IRC12:36
*** sjas_ is now known as sjas12:48
*** isaagar has joined #kata-dev12:50
*** devimc has quit IRC13:32
*** devimc has joined #kata-dev13:32
kata-irc-bot1<salvador.fuentes> hi clarkb, @sebastien.boeuf, @archana.m.shinde I removed this iptables rule: `13   REJECT     all  --  anywhere             anywhere             reject-with icmp-host-prohibited` from the openstack-INPUT chain and the k8s tests worked correctly14:04
*** lamego has joined #kata-dev14:10
kata-irc-bot1<julio.montes> hi @anne14:10
kata-irc-bot1<julio.montes> me again :D , any update on the canonical review ?14:12
kata-irc-bot1<sebastien.boeuf> @salvador.fuentes that's good news :slightly_smiling_face:14:17
kata-irc-bot1<sebastien.boeuf> @salvador.fuentes so we have a Zuul build succeeding now ?14:18
kata-irc-bot1<salvador.fuentes> @sebastien.boeuf not yet, only on the machine that clarkb provided to us14:19
kata-irc-bot1<salvador.fuentes> not sure what would be the best approach here, but I think that maybe that iptables rule should be removed/changed on the openstack infra job? clarkb, wdyt?14:20
kata-irc-bot1<sebastien.boeuf> yeah let's wait for clarkb input on this14:21
*** fiddletwix has quit IRC15:15
*** LinuxMe has joined #kata-dev15:31
*** p_god_ has joined #kata-dev15:39
*** p_god_ has quit IRC15:39
*** gwhaley1 has joined #kata-dev15:42
*** gwhaley has quit IRC15:42
clarkbsebastien.boeuf salvador.fuentes I wouldn't remove that reject as it is there to protect the test job from other test jobs and the avoid reflection attacks from running services and that sort of thing16:01
clarkbI got a change merged to allow 10.244.0.0/16 to talk to port 6443 on the test node which should fix it too, but that failed testing due to a new crio test failure and I think vexxhost is still having ipv6 issues16:01
clarkb(so I'm not sure if that worked. But that is the sort of thing I would do)16:03
kata-irc-bot1<salvador.fuentes> clarkb, ahh great, thanks clarkb, can you share the change so I can test it on the machine that I have?16:03
clarkbhttps://review.openstack.org/#/c/577590/4/roles/kata-setup/tasks/main.yaml is the change I made16:03
clarkbbasically add a rule to the top of INPUT that allows 10.244.0.0/16 source to dest port 6443 over tcp16:04
kata-irc-bot1<salvador.fuentes> thanks16:04
kata-irc-bot1<salvador.fuentes> and yes, I see that the cri-o test #3 failed, I'll be opening some PRs to fix this, in the meantime I added a recheck to the proxy PR.16:08
clarkbtracing through all of the k8s nat and firewall rules the 10.244.0.2 IP assigned to the kata instance talks to 10.96.0.1 which gets NATed to $actual_host_ip and it was on that last leg of the packet journey that iptables dropped the packet according to the logs. So allowing 10.244.0.2 to talk to $host_ip should fix it16:09
*** annabelleB has joined #kata-dev16:35
*** LinuxMe has quit IRC16:55
*** annabelleB has quit IRC17:01
*** LinuxMe has joined #kata-dev17:07
*** zerocoolback has quit IRC17:19
*** zerocoolback has joined #kata-dev17:19
*** zerocoolback has quit IRC17:23
kata-irc-bot1<salvador.fuentes> clarkb, your change fixed the k8s issue :slightly_smiling_face:17:36
clarkbyay17:36
kata-irc-bot1<salvador.fuentes> now we hit another failure on the docker swarm tests, seems like the interface has several ipv617:37
clarkbit should have one global ip and one link local ip17:37
*** FL1SK has joined #kata-dev17:44
*** gwhaley1 has quit IRC17:46
*** jodh has quit IRC17:46
*** LinuxMe has quit IRC18:38
*** sameo has quit IRC18:41
kata-irc-bot1<salvador.fuentes> clarkb: the machines on the CI have one ipv4 address with scope global and one ipv6 local, do you think we can change this with the zuul machines?19:12
*** davidgiluk has quit IRC19:26
*** devimc has quit IRC20:54
*** LinuxMe has joined #kata-dev21:39
*** LinuxMe has quit IRC21:44
*** lamego has left #kata-dev21:56
*** annabelleB has joined #kata-dev22:15
clarkbwhat would we change it to?23:22
clarkbthis is default vexxhost network setup23:23
clarkbif the ask is to remove ipv6 I dont think we would do that for you bu you could manipulate that in the job if necessary23:24

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!