*** achanda_ has joined #openstack-containers | 00:02 | |
*** eghobo_ has quit IRC | 00:04 | |
*** achanda has quit IRC | 00:05 | |
*** achanda_ has quit IRC | 00:07 | |
*** vilobhmm1 has joined #openstack-containers | 00:09 | |
*** manjeets has quit IRC | 00:11 | |
*** harshs has joined #openstack-containers | 00:13 | |
*** gangil has quit IRC | 00:16 | |
*** eghobo has joined #openstack-containers | 00:18 | |
*** banix has quit IRC | 00:19 | |
*** gangil has joined #openstack-containers | 00:26 | |
*** vilobhmm1 has quit IRC | 00:29 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add CertManager to store CA and client certificate https://review.openstack.org/212395 | 00:29 |
---|---|---|
*** eghobo_ has joined #openstack-containers | 00:34 | |
*** eghobo has quit IRC | 00:37 | |
*** suro-patz has quit IRC | 00:41 | |
*** dims has joined #openstack-containers | 00:46 | |
*** dims_ has quit IRC | 00:47 | |
*** gangil has quit IRC | 00:49 | |
*** eghobo_ has quit IRC | 00:51 | |
*** vahidh has quit IRC | 00:51 | |
*** zz_dimtruck is now known as dimtruck | 00:52 | |
*** dims has quit IRC | 00:56 | |
*** dims has joined #openstack-containers | 00:56 | |
*** ganeshna has joined #openstack-containers | 00:59 | |
*** Tango has quit IRC | 00:59 | |
*** ctrath has joined #openstack-containers | 01:02 | |
*** liudong has joined #openstack-containers | 01:05 | |
*** unicell has left #openstack-containers | 01:07 | |
*** ganeshna has quit IRC | 01:08 | |
*** zhenguo has joined #openstack-containers | 01:09 | |
*** sthillma has quit IRC | 01:11 | |
*** banix has joined #openstack-containers | 01:11 | |
*** y_sawai has joined #openstack-containers | 01:12 | |
*** s3wong has quit IRC | 01:16 | |
*** y_sawai has quit IRC | 01:17 | |
*** SourabhP has quit IRC | 01:17 | |
*** SourabhP has joined #openstack-containers | 01:17 | |
*** SourabhP has quit IRC | 01:17 | |
*** erkules_ has joined #openstack-containers | 01:23 | |
*** y_sawai has joined #openstack-containers | 01:23 | |
*** julim has joined #openstack-containers | 01:24 | |
*** ctrath has quit IRC | 01:24 | |
*** wanghua has joined #openstack-containers | 01:25 | |
*** erkules has quit IRC | 01:26 | |
*** liangbo has joined #openstack-containers | 01:26 | |
*** y_sawai has quit IRC | 01:28 | |
*** liangbo has quit IRC | 01:31 | |
*** banix has quit IRC | 01:32 | |
*** dave-mccowan has quit IRC | 01:36 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Initialize RPC notification service https://review.openstack.org/214411 | 01:43 |
*** mathspanda has joined #openstack-containers | 01:43 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Remove deprecated config 'verbose' https://review.openstack.org/214415 | 01:55 |
*** y_sawai has joined #openstack-containers | 01:56 | |
*** liangbo has joined #openstack-containers | 01:58 | |
*** humble_ has joined #openstack-containers | 01:59 | |
*** wanghua has quit IRC | 02:00 | |
*** y_sawai has quit IRC | 02:02 | |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Remove unsed file magnum/config.py https://review.openstack.org/214418 | 02:03 |
*** hongbin has quit IRC | 02:04 | |
*** eghobo has joined #openstack-containers | 02:07 | |
*** y_sawai has joined #openstack-containers | 02:08 | |
*** liudong has left #openstack-containers | 02:08 | |
*** dimtruck is now known as zz_dimtruck | 02:08 | |
openstackgerrit | Eli Qiao proposed openstack/magnum: proxy-blue print for docker swarm https://review.openstack.org/212629 | 02:09 |
*** humble_ has quit IRC | 02:15 | |
*** sankarshan_away is now known as sankarshan | 02:16 | |
*** junhongl has joined #openstack-containers | 02:25 | |
*** achanda has joined #openstack-containers | 02:32 | |
*** dane_leblanc_ has quit IRC | 02:36 | |
*** dane_leblanc has joined #openstack-containers | 02:44 | |
*** madhuri has joined #openstack-containers | 02:51 | |
*** dims has quit IRC | 02:55 | |
*** mathspanda has quit IRC | 02:57 | |
*** dave-mccowan has joined #openstack-containers | 03:00 | |
*** y_sawai has quit IRC | 03:01 | |
*** liangbo has quit IRC | 03:09 | |
*** agireud has joined #openstack-containers | 03:09 | |
*** andreluiz has quit IRC | 03:18 | |
*** chandankumar has joined #openstack-containers | 03:20 | |
*** andreluiz has joined #openstack-containers | 03:21 | |
*** raginbajin has quit IRC | 03:27 | |
*** adrian_otto has joined #openstack-containers | 03:29 | |
*** raginbajin has joined #openstack-containers | 03:29 | |
*** logan2 has quit IRC | 03:31 | |
*** harshs has quit IRC | 03:32 | |
*** agireud has quit IRC | 03:33 | |
*** agireud has joined #openstack-containers | 03:38 | |
*** dane_leblanc has quit IRC | 03:43 | |
*** adrian_otto has quit IRC | 03:45 | |
*** adrian_otto has joined #openstack-containers | 03:46 | |
*** unicell has joined #openstack-containers | 03:48 | |
*** diga has joined #openstack-containers | 03:49 | |
*** adrian_otto has quit IRC | 03:57 | |
*** julim has quit IRC | 03:59 | |
*** adrian_otto has joined #openstack-containers | 04:01 | |
*** gangil has joined #openstack-containers | 04:04 | |
*** apuimedo has joined #openstack-containers | 04:05 | |
sdake | suro-patz to debug further ask in #heat - they may have some idea | 04:07 |
*** dave-mccowan has quit IRC | 04:07 | |
*** raginbajin has quit IRC | 04:10 | |
*** chandankumar has quit IRC | 04:15 | |
*** chandankumar has joined #openstack-containers | 04:15 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add a tool to manage x509 objects https://review.openstack.org/212321 | 04:22 |
*** diga has quit IRC | 04:26 | |
*** mathspanda has joined #openstack-containers | 04:26 | |
*** raginbajin has joined #openstack-containers | 04:28 | |
*** sdake has quit IRC | 04:29 | |
*** mathspanda has quit IRC | 04:30 | |
*** mathspanda has joined #openstack-containers | 04:31 | |
*** VikasC has joined #openstack-containers | 04:32 | |
*** adrian_otto has quit IRC | 04:34 | |
*** diga has joined #openstack-containers | 04:35 | |
*** y_sawai has joined #openstack-containers | 04:36 | |
*** madhuri has quit IRC | 04:39 | |
*** y_sawai has quit IRC | 04:42 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add CertManager to store CA and client certificate https://review.openstack.org/212395 | 04:44 |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add a tool to manage x509 objects https://review.openstack.org/212321 | 04:45 |
*** coolsvap|away is now known as coolsvap | 04:46 | |
*** y_sawai has joined #openstack-containers | 04:48 | |
*** agireud has quit IRC | 04:48 | |
*** agireud has joined #openstack-containers | 04:55 | |
*** irenab has quit IRC | 04:58 | |
*** eghobo has quit IRC | 05:00 | |
*** eghobo has joined #openstack-containers | 05:01 | |
*** coolsvap is now known as coolsvap|away | 05:08 | |
*** adrian_otto has joined #openstack-containers | 05:08 | |
*** y_sawai has quit IRC | 05:11 | |
*** liangbo has joined #openstack-containers | 05:12 | |
*** vilobhmm1 has joined #openstack-containers | 05:14 | |
*** wanghua has joined #openstack-containers | 05:14 | |
*** suro-patz has joined #openstack-containers | 05:14 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Check before _update_stack https://review.openstack.org/212951 | 05:17 |
*** eghobo_ has joined #openstack-containers | 05:17 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add cert_uuid attributes to Bay https://review.openstack.org/214450 | 05:17 |
*** y_sawai has joined #openstack-containers | 05:19 | |
*** y_sawai has quit IRC | 05:20 | |
*** ashishb has joined #openstack-containers | 05:20 | |
*** eghobo has quit IRC | 05:21 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add cert_uuid attributes to Bay https://review.openstack.org/214450 | 05:22 |
*** harshs has joined #openstack-containers | 05:22 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Check before _update_stack https://review.openstack.org/212951 | 05:23 |
*** coolsvap|away is now known as coolsvap | 05:23 | |
*** harshs has quit IRC | 05:26 | |
*** liangbo has quit IRC | 05:27 | |
*** irenab has joined #openstack-containers | 05:30 | |
*** apuimedo has quit IRC | 05:31 | |
*** suro-patz has quit IRC | 05:35 | |
*** adrian_otto has quit IRC | 05:35 | |
*** suro-patz has joined #openstack-containers | 05:38 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Check before _update_stack https://review.openstack.org/212951 | 05:42 |
*** rbradfor has quit IRC | 05:48 | |
*** suro-patz has quit IRC | 05:48 | |
*** Tango has joined #openstack-containers | 05:49 | |
*** ganeshna has joined #openstack-containers | 06:01 | |
*** agireud has quit IRC | 06:04 | |
*** rbradfor has joined #openstack-containers | 06:05 | |
*** coolsvap is now known as coolsvap|away | 06:10 | |
*** vilobhmm1 has quit IRC | 06:11 | |
*** adrian_otto has joined #openstack-containers | 06:11 | |
*** adrian_otto has quit IRC | 06:22 | |
*** adrian_otto has joined #openstack-containers | 06:26 | |
*** suro-patz has joined #openstack-containers | 06:27 | |
*** y_sawai has joined #openstack-containers | 06:27 | |
*** ganeshna has quit IRC | 06:27 | |
*** ganeshna has joined #openstack-containers | 06:31 | |
*** ddepaoli has joined #openstack-containers | 06:32 | |
*** achanda has quit IRC | 06:34 | |
*** Drago has quit IRC | 06:36 | |
*** SourabhP has joined #openstack-containers | 06:37 | |
*** adrian_otto has quit IRC | 06:38 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Add cert_uuid attributes to Bay https://review.openstack.org/214450 | 06:38 |
*** SourabhP_ has joined #openstack-containers | 06:40 | |
*** Drago has joined #openstack-containers | 06:40 | |
*** wshao has joined #openstack-containers | 06:40 | |
*** wshao has quit IRC | 06:41 | |
*** SourabhP has quit IRC | 06:42 | |
*** SourabhP_ is now known as SourabhP | 06:42 | |
*** BertrandN has joined #openstack-containers | 06:47 | |
*** sthillma has joined #openstack-containers | 06:56 | |
*** VikasC has quit IRC | 06:59 | |
*** suro-patz has quit IRC | 06:59 | |
*** y_sawai has quit IRC | 07:00 | |
openstackgerrit | Hua Wang proposed openstack/magnum: Fix race condition in bay_update https://review.openstack.org/212922 | 07:01 |
*** BertrandN has quit IRC | 07:07 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: [WIP] Generate certs while creating bay https://review.openstack.org/214480 | 07:07 |
*** j___ has joined #openstack-containers | 07:09 | |
*** ajayaa has joined #openstack-containers | 07:13 | |
*** suro-patz has joined #openstack-containers | 07:14 | |
*** ganeshna has quit IRC | 07:20 | |
*** Tango has quit IRC | 07:22 | |
*** fawadkhaliq has joined #openstack-containers | 07:23 | |
*** BertrandN has joined #openstack-containers | 07:24 | |
*** alex_klimov has joined #openstack-containers | 07:26 | |
*** y_sawai has joined #openstack-containers | 07:27 | |
*** belmoreira has joined #openstack-containers | 07:28 | |
*** alex_klimov has quit IRC | 07:29 | |
*** alex_klimov has joined #openstack-containers | 07:29 | |
*** suro-patz has quit IRC | 07:30 | |
*** suro-patz has joined #openstack-containers | 07:30 | |
*** apuimedo has joined #openstack-containers | 07:31 | |
*** SourabhP has quit IRC | 07:33 | |
*** suro-patz has quit IRC | 07:35 | |
*** mathspanda has quit IRC | 07:44 | |
*** ganeshna has joined #openstack-containers | 07:53 | |
*** BertrandN has quit IRC | 08:00 | |
*** eghobo_ has quit IRC | 08:04 | |
*** apuimedo has quit IRC | 08:19 | |
*** timbyr_ has joined #openstack-containers | 08:21 | |
*** sthillma has quit IRC | 08:25 | |
*** liangbo has joined #openstack-containers | 08:25 | |
*** BertrandN has joined #openstack-containers | 08:28 | |
ganeshna | hi, one question on Magnum | 08:31 |
ganeshna | if I run magnum bay-create with node-count of 2, it creates 3 nova instances in total (including the master), do I need 6 GB of RAM in my virtual machine in that case ? | 08:32 |
Kennan2 | hi ganeshna: for that nova instances, it defaults falvor is m1.small | 08:36 |
Kennan2 | if I remember correctly | 08:36 |
*** fawadkhaliq has quit IRC | 08:36 | |
Kennan2 | and instances memroy can overcommit | 08:37 |
ganeshna | Kennan2: correct, I am running devstack on Ubuntu (as a VM) on my macbook which has 16 GB ram in toal | 08:37 |
ganeshna | *total* | 08:37 |
Kennan2 | 16GB would be OK for devstack | 08:38 |
Kennan2 | as devstack consumes much memorty | 08:38 |
Kennan2 | memory | 08:38 |
ganeshna | 16 GB is total, I am allocating only 8GB for the ubuntu instance, as I need memory for macbook (for my other work) | 08:38 |
ganeshna | so for development purposes, will it be fine if I use just 1 node (master + 1 node) ? Because with 3 nova instances (m1.small), the 3rd instance doesn't boot up | 08:39 |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Generate certs while creating bay https://review.openstack.org/214480 | 08:40 |
Kennan2 | hi ganeshna: 8GB maybe OK. As devstack itself sometimes consume much memory | 08:40 |
Kennan2 | I think it depends on system configuration that devstack maybe slow if less memory | 08:41 |
Kennan2 | ganeshna: why the 3rd instance not boot up? | 08:41 |
Kennan2 | what erros does nova say ? | 08:42 |
ganeshna | i checked the console logs from horizon for the fedora atomic image, | 08:42 |
ganeshna | the kernel crashes | 08:42 |
ganeshna | I thought it was because of low memory | 08:42 |
Kennan2 | maybe, I think set node = 1 is ok for test | 08:43 |
ganeshna | Kenna2: if I want to contribute to bug fixes or blueprint, will set node = 1 be fine ? | 08:43 |
*** mathspanda has joined #openstack-containers | 08:45 | |
Kennan2 | hi ganeshna: | 08:48 |
Kennan2 | I am glad to hear you want to contribute to magnum | 08:48 |
Kennan2 | yes, when you create bay. you could set node =1 | 08:48 |
*** achanda has joined #openstack-containers | 08:48 | |
Kennan2 | if you want to test other functions like update bay related | 08:49 |
Kennan2 | node > 1 maybe required | 08:49 |
Kennan2 | so it depends on what functions bug you are fixing | 08:49 |
Kennan2 | I think | 08:49 |
Kennan2 | ganeshna: did your company have VMs ? | 08:49 |
Kennan2 | I suggest you could use that if possible. That may contain much resource | 08:50 |
ganeshna | thanks Kennan2: I am from Cisco | 08:50 |
ganeshna | let me check that in that case | 08:50 |
Kennan2 | ok let me know if you have other questions | 08:51 |
ganeshna | btw, it took around 3 days to bring the magnum up, the fedora atomic image is getting stuck at fsck in ubuntu | 08:51 |
ganeshna | Kennan2: don't have other questions now, thank you | 08:51 |
Kennan2 | wcl :) | 08:51 |
*** achanda has quit IRC | 09:17 | |
*** ishant has joined #openstack-containers | 09:19 | |
*** liangbo has quit IRC | 09:19 | |
*** wanghua has quit IRC | 09:21 | |
openstackgerrit | Motohiro/Yuanying Otsuka proposed openstack/magnum: Generate certs while creating bay https://review.openstack.org/214480 | 09:21 |
*** ddepaoli has quit IRC | 09:27 | |
*** fawadkhaliq has joined #openstack-containers | 09:28 | |
*** mathspanda has quit IRC | 09:35 | |
*** madhuri has joined #openstack-containers | 09:35 | |
*** ddepaoli has joined #openstack-containers | 09:43 | |
*** apuimedo has joined #openstack-containers | 09:57 | |
*** ganeshna_ has joined #openstack-containers | 09:58 | |
*** ddepaoli has quit IRC | 09:59 | |
*** ganeshna has quit IRC | 10:01 | |
*** ganeshna has joined #openstack-containers | 10:02 | |
*** ganeshna_ has quit IRC | 10:04 | |
*** f1ller has quit IRC | 10:05 | |
*** apmelton has quit IRC | 10:06 | |
*** belmoreira has quit IRC | 10:08 | |
*** f1ller has joined #openstack-containers | 10:09 | |
*** apmelton has joined #openstack-containers | 10:09 | |
*** belmoreira has joined #openstack-containers | 10:09 | |
*** belmoreira has quit IRC | 10:14 | |
*** belmoreira has joined #openstack-containers | 10:15 | |
*** y_sawai has quit IRC | 10:24 | |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/magnum: Indirection API implementation https://review.openstack.org/184791 | 10:31 |
*** ganeshna has quit IRC | 10:39 | |
*** Drago has quit IRC | 10:42 | |
*** ganeshna has joined #openstack-containers | 10:43 | |
*** belmoreira has quit IRC | 10:48 | |
*** fawadkhaliq has quit IRC | 10:53 | |
*** dims has joined #openstack-containers | 10:56 | |
*** dims_ has joined #openstack-containers | 11:03 | |
*** dims has quit IRC | 11:07 | |
*** ddepaoli has joined #openstack-containers | 11:08 | |
*** ishant has quit IRC | 11:10 | |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/magnum: Indirection API implementation https://review.openstack.org/184791 | 11:10 |
*** ganeshna has quit IRC | 11:14 | |
*** ddepaoli has quit IRC | 11:15 | |
openstackgerrit | Merged openstack/magnum: Remove unsed file magnum/config.py https://review.openstack.org/214418 | 11:20 |
openstackgerrit | Madhuri Kumari proposed openstack/magnum: [WIP] Add CA controller for TLS support. https://review.openstack.org/214179 | 11:27 |
*** ddepaoli has joined #openstack-containers | 11:27 | |
*** dims has joined #openstack-containers | 11:29 | |
*** dims_ has quit IRC | 11:31 | |
*** dims_ has joined #openstack-containers | 11:31 | |
*** dims has quit IRC | 11:34 | |
*** fawadkhaliq has joined #openstack-containers | 11:35 | |
*** diga has quit IRC | 11:55 | |
*** irenab has quit IRC | 11:55 | |
madhuri | apmelton: Hi you there? | 12:06 |
*** dave-mccowan has joined #openstack-containers | 12:06 | |
*** julim has joined #openstack-containers | 12:10 | |
*** belmoreira has joined #openstack-containers | 12:19 | |
*** belmoreira has quit IRC | 12:19 | |
*** sankarshan is now known as sankarshan_away | 12:22 | |
*** ashishb has quit IRC | 12:24 | |
*** j___ has quit IRC | 12:32 | |
*** logan2 has joined #openstack-containers | 12:39 | |
*** ashishb has joined #openstack-containers | 12:40 | |
*** julim has quit IRC | 12:41 | |
*** julim has joined #openstack-containers | 12:42 | |
*** fawadkhaliq has quit IRC | 12:46 | |
*** rpothier has joined #openstack-containers | 12:49 | |
apmelton | madhuri: hey, I'm here now | 12:56 |
*** irenab has joined #openstack-containers | 13:01 | |
*** erkules_ is now known as erkules | 13:01 | |
*** erkules has joined #openstack-containers | 13:01 | |
*** yuanying-alt has joined #openstack-containers | 13:01 | |
madhuri | Hi apmelton | 13:03 |
madhuri | apmelton: how are you? | 13:04 |
apmelton | madhuri: little groggy, still waiting for the coffee to kick in :) | 13:04 |
apmelton | how about you? | 13:04 |
madhuri | Yes, is it early for you? | 13:05 |
madhuri | I just went for coffee | 13:05 |
*** hongbin has joined #openstack-containers | 13:06 | |
apmelton | it's around 9, I"m just not a morning person | 13:06 |
madhuri | So when do you go office? | 13:06 |
*** junhongl has quit IRC | 13:06 | |
madhuri | I wake up at 6:30 everyday and then run for office | 13:06 |
madhuri | :( | 13:07 |
apmelton | I ususally sit down around 9:45 or 10 | 13:07 |
madhuri | Ok. Sorry for disturbing you | 13:07 |
madhuri | So can we start the discussion? | 13:07 |
apmelton | madhuri: no worries! | 13:08 |
apmelton | sure | 13:08 |
madhuri | Let me check for yuanying yuanying-alt if he is here | 13:08 |
madhuri | He also wanted to join | 13:08 |
yuanying-alt | yes, I'm here | 13:08 |
madhuri | Hi | 13:08 |
yuanying-alt | If I have a question, I'll interupt you | 13:09 |
madhuri | Ok so let's start our discussion | 13:09 |
yuanying-alt | Hi, madhuri, apmelton | 13:09 |
madhuri | sure | 13:09 |
apmelton | hey yuanying-alt | 13:09 |
madhuri | apmelton: I would like to know whether the TLS implementation for docker will differ from Kubernetes or not? | 13:10 |
apmelton | madhuri: I think it will differ slightly, in that there may be two different keys/certs on each node | 13:11 |
apmelton | the docker daemon has one with serverAuth, and the swarm manager (the public api of sorts) has one with clientAuth and serverAuth | 13:11 |
madhuri | Yes it is so with Kubernetes | 13:11 |
madhuri | One i.e server key will be with kube-apiserver | 13:12 |
madhuri | And the other i.e. the client key will be used my m-conductor | 13:12 |
madhuri | Am I right yuanying-alt ? | 13:12 |
apmelton | docker-swarm will also need the client key for the m-conductor | 13:12 |
yuanying-alt | And also, minion daemon will use clientAuth key | 13:13 |
apmelton | all in all, there's probably 4 keys, 1) swarm manager, 2) docker daemon, 3) m conductor, 4) end user | 13:13 |
madhuri | The key 2, 3 and 4 can be same | 13:14 |
apmelton | technically, 1, 3, and 4 could be the same | 13:14 |
*** banix has joined #openstack-containers | 13:14 | |
apmelton | generally 1) will have subject alt name details of the server | 13:15 |
apmelton | so it shouldn't be used by 3 and 4 | 13:15 |
apmelton | since 3 and 4 will be pure clientAuth, they won't have any subject alt name details | 13:15 |
apmelton | and could be the same | 13:15 |
*** madhuri__ has joined #openstack-containers | 13:16 | |
madhuri__ | apmelton: yuanying-alt Sorry I got disconnected | 13:16 |
apmelton | <apmelton> generally 1) will have subject alt name details of the server | 13:16 |
apmelton | <apmelton> so it shouldn't be used by 3 and 4 | 13:16 |
apmelton | <apmelton> since 3 and 4 will be pure clientAuth, they won't have any subject alt name details | 13:16 |
apmelton | <apmelton> and could be the same | 13:16 |
madhuri__ | Did I miss something? | 13:16 |
apmelton | also for 1), in an HA config where the swarm manager is running on more than one node, each node will need a different cert | 13:17 |
madhuri__ | Agree | 13:17 |
madhuri__ | yuanying-alt has submitted patch alt name support I guess | 13:17 |
madhuri__ | Sorry subject alt name support I mean | 13:18 |
*** madhuri has quit IRC | 13:18 | |
apmelton | yea, I think his x509 tool should be able to support the differences | 13:18 |
madhuri__ | Yes | 13:18 |
yuanying-alt | I guess subject alt name should be validated? | 13:19 |
apmelton | tcammann: might have an opinion on this actually | 13:19 |
apmelton | I believe he was saying we should do come validatity checking on where each request is coming from | 13:19 |
yuanying-alt | yes | 13:20 |
yuanying-alt | Anchor implementation check it | 13:20 |
apmelton | what kind of details does it check? | 13:20 |
yuanying-alt | but it was come from static config file | 13:20 |
yuanying-alt | check request contect and network address | 13:21 |
apmelton | so, what happens if our certificate has not only the public address, but also the private address? | 13:21 |
yuanying-alt | I think we can't check private address now | 13:22 |
apmelton | hmmmm | 13:22 |
yuanying-alt | ah, now I don't understand, what happend | 13:22 |
yuanying-alt | because these are only used for kubernetes and swarm in tenant | 13:23 |
madhuri__ | I aslo have the same opinion | 13:23 |
apmelton | so, the reason we need the private address on the certificate is because the swarm-manager to docker daemon traffic happens over the private net | 13:23 |
madhuri__ | But guess tcammann can better answer it | 13:23 |
apmelton | so when the docker daemon tries to validate the cert of the swarm manager, it's going to try to validate it with the private address | 13:24 |
yuanying-alt | yes | 13:24 |
apmelton | what we could potentally do is take the ip address of the request coming in, then find the nova instance associated with that | 13:25 |
apmelton | and from that we would have both the valid public and private address | 13:25 |
apmelton | that seems really heavy handed though | 13:26 |
madhuri__ | That is a solutin but not sure how much efficient | 13:26 |
apmelton | yea | 13:26 |
apmelton | I'm not really sure what this validation really buys us | 13:27 |
madhuri__ | apmelton: we need to discuss about it with team also. | 13:27 |
apmelton | the request is going to be authenticated with a trust token | 13:27 |
yuanying-alt | yes | 13:28 |
madhuri__ | Can we mark action item for this? | 13:28 |
*** dims_ has quit IRC | 13:29 | |
madhuri__ | #action: Discuss about certificate validation and private key to be by docker daemon for swarm | 13:29 |
*** dims has joined #openstack-containers | 13:29 | |
madhuri__ | apmelton: Would you like to take this up? | 13:29 |
apmelton | sure, hopefully I can catch tcammann and get his insight on this | 13:30 |
madhuri__ | Thanks | 13:30 |
madhuri__ | apmelton: Do you have more to discuss about secure docker TLS support? | 13:31 |
apmelton | not about the docker piece specifically | 13:31 |
apmelton | just wondering if there's any thing I can be doing to help with the core feature | 13:31 |
madhuri__ | Ok sure | 13:32 |
madhuri__ | apmelton: yuanying-alt https://etherpad.openstack.org/p/magnum-tls-support | 13:32 |
madhuri__ | Please have a look at the Final Action Item section | 13:32 |
madhuri__ | apmelton: We are sorry. The document might be jumbled. It was just for internal use :) | 13:33 |
apmelton | no worries, I think I follow | 13:33 |
madhuri__ | apmelton: We are left with the Keystone trust token work | 13:34 |
apmelton | someone on my team was actually planning to work on the keystone trust token | 13:34 |
madhuri__ | It would be great | 13:34 |
apmelton | he's implemented it for solum, so it should be pretty quick for him | 13:34 |
madhuri__ | That would be a great help | 13:35 |
madhuri__ | Could you please introduce us to him? | 13:36 |
apmelton | madhuri__: I don't see him around yet | 13:36 |
madhuri__ | Moreover first him please? | 13:36 |
apmelton | madhuri__: not sure I understand that second question | 13:37 |
madhuri__ | I mean do we know him/her? | 13:37 |
*** eghobo has joined #openstack-containers | 13:37 | |
madhuri__ | Can you please introduce him? :) | 13:38 |
apmelton | I don't think he's been introduced yet | 13:38 |
apmelton | his name is murali | 13:38 |
madhuri__ | Oh I have heard his name :) | 13:38 |
madhuri__ | Ok so could you talk to him about it? | 13:39 |
apmelton | madhuri__: sure | 13:39 |
madhuri__ | Thanks :) | 13:40 |
apmelton | so madhuri__, looking at this list of work items, y'all pretty much have the core feature covered | 13:41 |
madhuri__ | So as status of TLS work for kubernetes, we are left with few more supporting patches, existing patches maintainence and the Keystone trust work | 13:41 |
madhuri__ | Yes hopefully apmelton | 13:41 |
madhuri__ | apmelton: Please let us know if we can help with docker stuff | 13:42 |
madhuri__ | #action: apmelton to follow up Keystone trust support with murali | 13:42 |
madhuri__ | apmelton: yuanying-alt Do we anything left to discuss? | 13:43 |
apmelton | yup | 13:43 |
yuanying-alt | especially none | 13:43 |
apmelton | so at the mid-cycle the barbican team asked if we could send someone to their weekly meeting | 13:44 |
yuanying-alt | hopefully, someone review these ;) | 13:44 |
apmelton | I volunteered since it was at a pretty bad time for y'all | 13:44 |
madhuri__ | What was that for? | 13:44 |
madhuri__ | Thanks for it apmelton | 13:44 |
apmelton | please let me know if there's anything you'd like me to bring up in that meeting | 13:45 |
yuanying-alt | ok thanks | 13:45 |
madhuri__ | When is the meetup? | 13:45 |
apmelton | it's 4pm EST | 13:46 |
apmelton | on mondays | 13:46 |
madhuri__ | One point might be the CA support | 13:46 |
madhuri__ | It is not much adaptable with Dogtag | 13:46 |
apmelton | they mentioned at the mid-cycle that support for individual CAs is coming | 13:47 |
madhuri__ | I am sure of an alternative but yes it is less adaptable | 13:47 |
apmelton | I'll ask for an update on that feature at the next meeting | 13:47 |
madhuri__ | Cool. So might be in future we will be using Barbican for CA also :) | 13:48 |
madhuri__ | Thanks apmelton | 13:48 |
apmelton | definitely, thanks for syncing up with me on all this! | 13:48 |
madhuri__ | Great help for us too :) | 13:49 |
madhuri__ | Ok I will send a mail to you with the action item listed | 13:49 |
apmelton | sounds good | 13:49 |
madhuri__ | Could you please share your id? | 13:49 |
apmelton | andrew.melton@rackspace.com | 13:50 |
madhuri__ | Thanks :) | 13:50 |
madhuri__ | Are we all done so that I wrap up? | 13:50 |
*** eghobo_ has joined #openstack-containers | 13:50 | |
apmelton | yes, I think we're done | 13:51 |
madhuri__ | Ok thanks apmelton yuanying-alt for your valuable time :) | 13:51 |
madhuri__ | Have a good day apmelton :) | 13:52 |
yuanying-alt | thanks apmelton, madhuri__ | 13:52 |
madhuri__ | Have a good night yuanying-alt ;) | 13:52 |
*** dane_leblanc has joined #openstack-containers | 13:52 | |
apmelton | thanks! have a good evening madhuri__ yuanying-alt | 13:52 |
*** ctrath has joined #openstack-containers | 13:54 | |
*** eghobo has quit IRC | 13:54 | |
*** sdake has joined #openstack-containers | 13:56 | |
*** sdake_ has joined #openstack-containers | 13:58 | |
*** sankarshan_away is now known as sankarshan | 13:58 | |
*** dane_leblanc has quit IRC | 13:59 | |
*** j___ has joined #openstack-containers | 14:01 | |
*** sdake has quit IRC | 14:01 | |
*** yuanying-alt has quit IRC | 14:02 | |
*** chandankumar has left #openstack-containers | 14:03 | |
*** zz_dimtruck is now known as dimtruck | 14:03 | |
*** dane_leblanc has joined #openstack-containers | 14:03 | |
*** muralia has joined #openstack-containers | 14:04 | |
*** kbyrne has quit IRC | 14:07 | |
*** timbyr_ has quit IRC | 14:07 | |
*** ajayaa has quit IRC | 14:08 | |
*** kbyrne has joined #openstack-containers | 14:11 | |
*** sdake_ is now known as sdake | 14:13 | |
*** absubram has joined #openstack-containers | 14:23 | |
*** dave-mccowan has quit IRC | 14:24 | |
*** muralia has quit IRC | 14:25 | |
*** muralia has joined #openstack-containers | 14:25 | |
*** harshs has joined #openstack-containers | 14:36 | |
*** eghobo_ has quit IRC | 14:38 | |
*** dave-mccowan has joined #openstack-containers | 14:38 | |
*** eghobo has joined #openstack-containers | 14:39 | |
*** sdake_ has joined #openstack-containers | 14:41 | |
*** sdake has quit IRC | 14:44 | |
*** madhuri__ has quit IRC | 14:44 | |
*** diga has joined #openstack-containers | 14:49 | |
*** gangil has quit IRC | 14:50 | |
*** Tango has joined #openstack-containers | 14:56 | |
*** dims has quit IRC | 15:01 | |
*** logan2 has quit IRC | 15:01 | |
*** dims has joined #openstack-containers | 15:01 | |
*** agireud has joined #openstack-containers | 15:02 | |
*** dims_ has joined #openstack-containers | 15:05 | |
*** logan2 has joined #openstack-containers | 15:05 | |
*** eghobo has quit IRC | 15:05 | |
*** dims has quit IRC | 15:06 | |
*** zul has joined #openstack-containers | 15:07 | |
*** chadix has quit IRC | 15:16 | |
*** agireud has quit IRC | 15:16 | |
*** coolsvap|away is now known as coolsvap | 15:18 | |
*** dims_ has quit IRC | 15:19 | |
*** dims has joined #openstack-containers | 15:19 | |
*** ashishb has quit IRC | 15:22 | |
*** coolsvap is now known as coolsvap|away | 15:22 | |
*** irenab has quit IRC | 15:22 | |
*** daneyon has joined #openstack-containers | 15:22 | |
*** zul has quit IRC | 15:23 | |
*** daneyon_ has quit IRC | 15:26 | |
*** Drago has joined #openstack-containers | 15:29 | |
*** Drago has quit IRC | 15:30 | |
*** Drago has joined #openstack-containers | 15:30 | |
*** agireud has joined #openstack-containers | 15:30 | |
*** irenab has joined #openstack-containers | 15:31 | |
*** ganeshna has joined #openstack-containers | 15:31 | |
*** adrian_otto has joined #openstack-containers | 15:40 | |
*** adrian_otto has quit IRC | 15:41 | |
*** j___ has quit IRC | 15:43 | |
*** j______ has joined #openstack-containers | 15:43 | |
*** harshs has quit IRC | 15:43 | |
*** zul has joined #openstack-containers | 15:45 | |
*** ganeshna_ has joined #openstack-containers | 15:46 | |
*** ganeshna has quit IRC | 15:47 | |
*** dims has quit IRC | 15:49 | |
*** sdake_ is now known as sdake | 15:49 | |
*** dims has joined #openstack-containers | 15:49 | |
*** ganeshna_ has quit IRC | 15:51 | |
*** alex_klimov has quit IRC | 15:52 | |
*** dims_ has joined #openstack-containers | 15:53 | |
*** dims has quit IRC | 15:54 | |
*** zul has quit IRC | 15:55 | |
*** eghobo has joined #openstack-containers | 15:59 | |
*** daneyon_ has joined #openstack-containers | 16:05 | |
*** irenab has quit IRC | 16:07 | |
*** fawadkhaliq has joined #openstack-containers | 16:08 | |
*** daneyon has quit IRC | 16:08 | |
*** irenab has joined #openstack-containers | 16:08 | |
*** sthillma has joined #openstack-containers | 16:10 | |
*** dflorea_ has joined #openstack-containers | 16:13 | |
*** adrian_otto has joined #openstack-containers | 16:13 | |
*** dflorea_ has quit IRC | 16:13 | |
*** dflorea has joined #openstack-containers | 16:14 | |
*** ddepaoli has quit IRC | 16:15 | |
*** jjfreric has joined #openstack-containers | 16:15 | |
*** unicell has quit IRC | 16:23 | |
*** manjeets has joined #openstack-containers | 16:23 | |
*** ctrath has quit IRC | 16:24 | |
*** vilobhmm1 has joined #openstack-containers | 16:30 | |
openstackgerrit | Manjeet Singh Bhatia proposed openstack/magnum: Adding more information in dev-quickstart.rst https://review.openstack.org/214374 | 16:31 |
*** sankarshan is now known as sankarshan_away | 16:32 | |
*** ctrath has joined #openstack-containers | 16:37 | |
*** ashishb has joined #openstack-containers | 16:37 | |
*** BertrandN has quit IRC | 16:38 | |
*** dims_ has quit IRC | 16:39 | |
*** dims has joined #openstack-containers | 16:39 | |
*** zul has joined #openstack-containers | 16:40 | |
*** jjfreric has quit IRC | 16:43 | |
*** Marga_ has quit IRC | 16:47 | |
*** zul has quit IRC | 16:47 | |
*** SourabhP has joined #openstack-containers | 16:48 | |
*** eghobo has quit IRC | 16:48 | |
*** zul has joined #openstack-containers | 16:49 | |
*** erkules_ has joined #openstack-containers | 16:50 | |
*** SourabhP_ has joined #openstack-containers | 16:50 | |
*** SourabhP has quit IRC | 16:52 | |
*** SourabhP_ is now known as SourabhP | 16:52 | |
*** erkules has quit IRC | 16:53 | |
*** jjfreric has joined #openstack-containers | 16:55 | |
*** erkules has joined #openstack-containers | 16:55 | |
*** unicell has joined #openstack-containers | 16:55 | |
*** erkules_ has quit IRC | 16:56 | |
*** suro-patz has joined #openstack-containers | 16:57 | |
*** dflorea has quit IRC | 16:57 | |
*** dflorea has joined #openstack-containers | 16:59 | |
*** diga has quit IRC | 17:02 | |
*** muralia has quit IRC | 17:03 | |
*** unicell has quit IRC | 17:04 | |
*** unicell has joined #openstack-containers | 17:04 | |
*** apuimedo has quit IRC | 17:05 | |
*** suro-patz1 has joined #openstack-containers | 17:08 | |
*** suro-patz has quit IRC | 17:09 | |
*** suro-patz1 has quit IRC | 17:09 | |
*** suro-patz2 has joined #openstack-containers | 17:09 | |
*** ashishb has quit IRC | 17:12 | |
*** dflorea_ has joined #openstack-containers | 17:13 | |
*** dflorea has quit IRC | 17:13 | |
*** sthillma has quit IRC | 17:16 | |
*** sdake_ has joined #openstack-containers | 17:17 | |
*** SourabhP has quit IRC | 17:17 | |
*** muralia has joined #openstack-containers | 17:18 | |
*** sthillma has joined #openstack-containers | 17:20 | |
*** fawadk has joined #openstack-containers | 17:20 | |
*** sdake has quit IRC | 17:20 | |
*** fawadkhaliq has quit IRC | 17:21 | |
*** zul has quit IRC | 17:23 | |
*** rpothier has quit IRC | 17:27 | |
*** dave-mcc_ has joined #openstack-containers | 17:29 | |
*** dave-mccowan has quit IRC | 17:30 | |
*** sdake has joined #openstack-containers | 17:37 | |
*** sthillma has quit IRC | 17:38 | |
*** sdake_ has quit IRC | 17:40 | |
*** achanda has joined #openstack-containers | 17:42 | |
*** Tango|2 has joined #openstack-containers | 17:43 | |
*** dane_leblanc has quit IRC | 17:43 | |
*** Tango has quit IRC | 17:45 | |
*** sdake has quit IRC | 17:47 | |
*** dflorea_ has quit IRC | 17:50 | |
*** sdake has joined #openstack-containers | 17:51 | |
*** eghobo has joined #openstack-containers | 17:51 | |
*** ameybhide has joined #openstack-containers | 17:51 | |
*** SourabhP has joined #openstack-containers | 17:52 | |
*** achanda_ has joined #openstack-containers | 17:54 | |
*** achanda has quit IRC | 17:55 | |
*** dflorea has joined #openstack-containers | 17:56 | |
*** harshs has joined #openstack-containers | 17:56 | |
*** dflorea has quit IRC | 18:00 | |
*** dflorea has joined #openstack-containers | 18:01 | |
*** gangil has joined #openstack-containers | 18:02 | |
*** chandankumar has joined #openstack-containers | 18:03 | |
*** dflorea has quit IRC | 18:03 | |
*** Tango|2 has quit IRC | 18:06 | |
*** adrian_otto has quit IRC | 18:08 | |
*** dane_leblanc has joined #openstack-containers | 18:08 | |
*** adrian_otto has joined #openstack-containers | 18:10 | |
openstackgerrit | Manjeet Singh Bhatia proposed openstack/magnum: Adding more information in dev-quickstart.rst https://review.openstack.org/214374 | 18:15 |
openstackgerrit | Hongbin Lu proposed openstack/magnum: Move 'all_tenants' options to context https://review.openstack.org/214744 | 18:29 |
*** sthillma has joined #openstack-containers | 18:32 | |
*** banix has quit IRC | 18:33 | |
*** jwang has quit IRC | 18:34 | |
*** Marga_ has joined #openstack-containers | 18:35 | |
*** eghobo has quit IRC | 18:39 | |
*** jwang has joined #openstack-containers | 18:40 | |
openstackgerrit | Manjeet Singh Bhatia proposed openstack/magnum: proxy-blue print for docker swarm https://review.openstack.org/212629 | 18:45 |
*** kebray has joined #openstack-containers | 18:46 | |
*** Tango|2 has joined #openstack-containers | 18:48 | |
manjeets | ._. | 18:48 |
*** zul has joined #openstack-containers | 18:50 | |
*** banix has joined #openstack-containers | 18:53 | |
*** dflorea has joined #openstack-containers | 19:03 | |
*** fawadk has quit IRC | 19:04 | |
*** dflorea has quit IRC | 19:06 | |
*** dflorea has joined #openstack-containers | 19:06 | |
*** dimtruck is now known as zz_dimtruck | 19:10 | |
openstackgerrit | Daneyon Hansen proposed openstack/magnum: Refactors Heat templates to Support Container Networking Model https://review.openstack.org/214762 | 19:11 |
openstackgerrit | Daneyon Hansen proposed openstack/magnum: WIP: Refactors Heat templates for Container Networking Model https://review.openstack.org/214762 | 19:14 |
*** jjfreric_ has joined #openstack-containers | 19:15 | |
*** jjfreric has quit IRC | 19:18 | |
*** achanda_ has quit IRC | 19:37 | |
*** belmoreira has joined #openstack-containers | 19:50 | |
*** achanda has joined #openstack-containers | 19:51 | |
*** alex_klimov has joined #openstack-containers | 19:51 | |
*** adrian_otto has quit IRC | 19:53 | |
*** zz_dimtruck is now known as dimtruck | 19:53 | |
*** alejandrito has joined #openstack-containers | 19:59 | |
*** alejandrito_ has joined #openstack-containers | 20:00 | |
*** alejandrito has quit IRC | 20:00 | |
*** chandankumar has quit IRC | 20:06 | |
manjeets | ._. | 20:10 |
*** dane_leblanc has quit IRC | 20:11 | |
*** alejandrito_ has quit IRC | 20:18 | |
*** julim has quit IRC | 20:25 | |
*** Drago has quit IRC | 20:27 | |
*** belmoreira has quit IRC | 20:44 | |
*** achanda has quit IRC | 20:47 | |
*** eghobo has joined #openstack-containers | 20:49 | |
*** Drago has joined #openstack-containers | 20:50 | |
openstackgerrit | Manjeet Singh Bhatia proposed openstack/magnum: Adding more information in dev-quickstart.rst https://review.openstack.org/214374 | 20:51 |
*** Drago has quit IRC | 20:52 | |
*** Drago has joined #openstack-containers | 20:52 | |
*** achanda has joined #openstack-containers | 20:52 | |
*** zul has quit IRC | 21:00 | |
*** eghobo_ has joined #openstack-containers | 21:00 | |
*** dave-mcc_ has quit IRC | 21:01 | |
*** adrian_otto has joined #openstack-containers | 21:02 | |
*** eghobo has quit IRC | 21:04 | |
*** Marga_ has quit IRC | 21:06 | |
*** rpothier has joined #openstack-containers | 21:06 | |
*** achanda has quit IRC | 21:06 | |
*** jjfreric_ has quit IRC | 21:27 | |
*** rpothier has quit IRC | 21:36 | |
*** s3wong has joined #openstack-containers | 21:44 | |
*** unicell has quit IRC | 21:45 | |
*** unicell has joined #openstack-containers | 21:45 | |
*** dflorea has quit IRC | 21:54 | |
*** dave-mccowan has joined #openstack-containers | 22:02 | |
*** y_sawai has joined #openstack-containers | 22:02 | |
*** absubram has quit IRC | 22:03 | |
*** belmoreira has joined #openstack-containers | 22:06 | |
*** eghobo_ has quit IRC | 22:08 | |
*** gangil has quit IRC | 22:08 | |
*** y_sawai has quit IRC | 22:08 | |
*** y_sawai has joined #openstack-containers | 22:10 | |
*** y_sawai_ has joined #openstack-containers | 22:11 | |
*** unicell has quit IRC | 22:12 | |
*** unicell has joined #openstack-containers | 22:12 | |
*** y_sawai has quit IRC | 22:14 | |
*** y_sawai_ has quit IRC | 22:16 | |
*** ctrath has quit IRC | 22:18 | |
*** gangil has joined #openstack-containers | 22:23 | |
*** dave-mccowan has quit IRC | 22:24 | |
manjeets | ._. | 22:28 |
*** agireud has quit IRC | 22:34 | |
*** dimtruck is now known as zz_dimtruck | 22:38 | |
*** VikasC has joined #openstack-containers | 22:45 | |
*** dave-mccowan has joined #openstack-containers | 22:47 | |
Tango|2 | manjeets: ping | 22:51 |
manjeets | tango[2: | 22:52 |
*** VikasC has quit IRC | 23:00 | |
*** banix has quit IRC | 23:02 | |
Tango|2 | manjeets: Hi Manjeet, you mentioned you would be interested in writing a patch to set template parameters for Kubernetes? | 23:06 |
*** zul has joined #openstack-containers | 23:07 | |
*** adrian_otto has quit IRC | 23:07 | |
*** adrian_otto has joined #openstack-containers | 23:08 | |
*** zul has quit IRC | 23:12 | |
*** dave-mccowan has quit IRC | 23:13 | |
*** hongbin has quit IRC | 23:15 | |
*** adrian_otto has quit IRC | 23:20 | |
*** adrian_otto has joined #openstack-containers | 23:22 | |
*** banix has joined #openstack-containers | 23:31 | |
*** achanda has joined #openstack-containers | 23:33 | |
*** adrian_otto has quit IRC | 23:33 | |
*** dims_ has joined #openstack-containers | 23:33 | |
*** dims has quit IRC | 23:36 | |
*** gangil has quit IRC | 23:36 | |
*** alex_klimov has quit IRC | 23:38 | |
*** dims_ has quit IRC | 23:39 | |
*** dims has joined #openstack-containers | 23:39 | |
*** dave-mccowan has joined #openstack-containers | 23:40 | |
*** zul has joined #openstack-containers | 23:41 | |
*** dims has quit IRC | 23:44 | |
*** gangil has joined #openstack-containers | 23:44 | |
*** ameybhide has quit IRC | 23:46 | |
*** kebray has quit IRC | 23:47 | |
*** rpothier has joined #openstack-containers | 23:48 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!