| -@gerrit:opendev.org- Anil Shashikumar Belur proposed: | 03:10 | |
| - [opendev/system-config] 1000071: Support both firewall backends in testinfra https://review.opendev.org/c/opendev/system-config/+/1000071 | ||
| - [opendev/system-config] 999195: Add an opt-in native nftables backend to the iptables role https://review.opendev.org/c/opendev/system-config/+/999195 | ||
| -@gerrit:opendev.org- Anil Shashikumar Belur proposed: [opendev/system-config] 999195: Add an opt-in native nftables backend to the iptables role https://review.opendev.org/c/opendev/system-config/+/999195 | 03:56 | |
| @abelur:matrix.org | Clark fungi Thanks for merging the HAPROXY change; good to know it's on prod now. The credit should goes to Clark since that was his initial work and change. I only did some tweaking. :) | 03:59 |
|---|---|---|
| @abelur:matrix.org | nftables change 999195 is at PS8 with replies to all of Clark's review comments. PS7 was my own bug - an apostrophe in a comment inside a free-form shell: block, which makes Ansible fail to parse the whole tasks file. Also replied to Michal re 1000664: happy to go either way, but I'd want to keep the conversion cleanup and the `nft -c` validation whichever template we land on. Would be good to settle which approach we're taking before either grows more patchsets. thank you. | 04:00 |
| -@gerrit:opendev.org- Moritz Haase proposed: [zuul/zuul-jobs] 991770: roles: Add 'ensure-pipx' role https://review.opendev.org/c/zuul/zuul-jobs/+/991770 | 05:27 | |
| -@gerrit:opendev.org- Michal Nasiadka proposed: [openstack/project-config] 1001093: Add tenks to openstack-kolla notifications https://review.opendev.org/c/openstack/project-config/+/1001093 | 08:30 | |
| -@gerrit:opendev.org- Zuul merged on behalf of Stephen Finucane: [openstack/project-config] 993628: Remove packaging configuration https://review.opendev.org/c/openstack/project-config/+/993628 | 11:23 | |
| -@gerrit:opendev.org- Zuul merged on behalf of Moritz Haase: [zuul/zuul-jobs] 991770: roles: Add 'ensure-pipx' role https://review.opendev.org/c/zuul/zuul-jobs/+/991770 | 14:35 | |
| @clarkb:matrix.org | Anil Belur: Eric Ball ya I'm going to try and catch up on both options there today. | 14:59 |
| @clarkb:matrix.org | but first monday morning software updates | 15:37 |
| -@gerrit:opendev.org- yatin proposed: [openstack/project-config] 1001183: [neutron] Update dasboard to include new job https://review.opendev.org/c/openstack/project-config/+/1001183 | 15:40 | |
| -@gerrit:opendev.org- Roja Eswaran proposed: [openstack/diskimage-builder] 999989: debootstrap: add DIB_MMDEBSTRAP_EXTRA_ARGS support https://review.opendev.org/c/openstack/diskimage-builder/+/999989 | 15:48 | |
| -@gerrit:opendev.org- yatin proposed: [openstack/project-config] 1001183: [neutron] Update dasboard to include new job https://review.opendev.org/c/openstack/project-config/+/1001183 | 16:16 | |
| -@gerrit:opendev.org- Roja Eswaran proposed: [openstack/diskimage-builder] 999989: debootstrap: add DIB_MMDEBSTRAP_EXTRA_ARGS support https://review.opendev.org/c/openstack/diskimage-builder/+/999989 | 16:38 | |
| @clarkb:matrix.org | Eric Ball: I meant to ask if you saw my comments on https://review.opendev.org/c/opendev/system-config/+/996553 I think we can proceed with that effort if it we split it into a few smaller changes (to limit potential impact as we deploy things) | 17:01 |
| @clarkb:matrix.org | I've just done a first pass on a meeting agenda update. Let me know if there are other updates to make or feel free to add them yourselves | 17:02 |
| -@gerrit:opendev.org- Zuul merged on behalf of yatin: [openstack/project-config] 1001183: [neutron] Update dasboard to include new job https://review.opendev.org/c/openstack/project-config/+/1001183 | 20:10 | |
| @clarkb:matrix.org | Anil Belur: Eric Ball ok I've caught up on the two implementations of nftables conversion. I like portions of both :) In particular I think Eric Ball's change represents a better long term ideal state for moving forward with nftables along whereas Anil Belur's captures a bit more of the how do we get there I think (by relying on the existing ruleset converted over). That said having a single ruleset file rather than two is nice as is capturing the nftables rules directly in configuration management so you don't have to look at converted rules to understand them. | 21:09 |
| Thinking out loud here a combo of the testing in Anil Belur's change with the end stage results from Eric Ball's change is probably ideal. Then we would just need to think about how we transition with Eric Ball's rulesets? And maybe that is one host or service at a time ripping the band aid off and verifying as we go? | ||
| This is one opinion others may have different preferences or ideas. I think we can discuss this more during tomorrow's meeting (don't worry about waking up for that Anil Belur ) then take it from there? | ||
| @clarkb:matrix.org | And if we need to we can schedule some time to talk about it on meetpad or similar for lower latency discussion | 21:10 |
| -@gerrit:opendev.org- Roja Eswaran proposed: [openstack/diskimage-builder] 999989: debootstrap: add DIB_MMDEBSTRAP_EXTRA_ARGS support https://review.opendev.org/c/openstack/diskimage-builder/+/999989 | 21:10 | |
| @clarkb:matrix.org | infra-root if you get a chance to review https://review.opendev.org/c/opendev/system-config/+/999195/ and https://review.opendev.org/c/opendev/system-config/+/1000664 that would be great so that we can decide on a path forward and continue to make progress | 21:11 |
| @clarkb:matrix.org | ok last call on meeting updates otherwise I'll get that sent out in 15-20 minutes | 21:44 |
| @clarkb:matrix.org | * ok last call on meeting agenda updates otherwise I'll get that sent out in 15-20 minutes | 21:44 |
| @abelur:matrix.org | Clark: that split sounds right to me, happy to go that way. Eric's ruleset as the end state, our testing + rollout mechanics to get there. | 22:37 |
| Most of 999195 survives that: the opt-in nftables group and the sibling-base-iptables job are backend-agnostic, as are the testinfra changes (small tweak needed - I key on "openstack-INPUT", Eric's chains are openstack_input). | ||
| Two bits I'd keep regardless: the `nft -c` validation gate before install, and the legacy cleanup - with a separate `inet openstack` table the old ip filter chains and netfilter-persistent stay loaded on a converted host until something removes them. That's what makes one-host-at-a-time safe. The transpile step goes away, no loss. | ||
| @abelur:matrix.org | * Clark: that split sounds right to me, happy to go that way. Eric's ruleset as the end state, our testing + rollout mechanics to get there. Most of 999195 survives that: the opt-in nftables group and the sibling-base-iptables job are backend-agnostic, as are the testinfra changes (small tweak needed - I key on "openstack-INPUT", Eric's chains are openstack\_input). | 22:37 |
| Two bits I'd keep regardless: the `nft -c` validation gate before install, and the legacy cleanup - with a separate `inet openstack` table the old ip filter chains and netfilter-persistent stay loaded on a converted host until something removes them. That's what makes one-host-at-a-time safe. The transpile step goes away, no loss. | ||
| @abelur:matrix.org | On transition: one host at a time is already how 999195 is built - empty nftables group, add one host, revert if it goes wrong. So we | 22:38 |
| can just point that at Eric's ruleset. Happy to start with a low-risk single host (codesearch02?) and go from there. | ||
| @abelur:matrix.org | One thing worth decidiing before we start converting: today the role sets -P FORWARD DROP. Eric drops the forward chain deliberately, which is correct for a separate table (a drop policy there would override Docker's accepts) but converted hosts do lose that default. Fine either way, just better settled up front than after a few hosts. Can cover it in the meeting or meetpad, whichever. | 22:40 |
| @clarkb:matrix.org | ya I think it would be good to get a few other opinions before we proceed (if possible) but I'm glad my ideas seem to make sense | 23:09 |
| @clarkb:matrix.org | Anil Belur: you're saying eric's change doesn't include a forward chain at all rather than making it a drop policy for the chain? | 23:11 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!