*** jmlowe has quit IRC | 00:03 | |
eandersson | strigazi, flwang will have limited time this week for reviewing, but feel free to hit me up for anything with higher priority | 00:26 |
---|---|---|
*** chhagarw has joined #openstack-containers | 00:37 | |
*** chhagarw has quit IRC | 00:51 | |
*** mnasiadka has joined #openstack-containers | 00:59 | |
*** cosss_ has joined #openstack-containers | 00:59 | |
*** sdake has joined #openstack-containers | 01:02 | |
*** _fragatina has quit IRC | 01:37 | |
*** sdake has quit IRC | 01:37 | |
*** sdake has joined #openstack-containers | 01:41 | |
*** sdake has quit IRC | 01:43 | |
*** sdake has joined #openstack-containers | 01:51 | |
*** sdake has quit IRC | 01:51 | |
*** hongbin has joined #openstack-containers | 02:29 | |
*** sapd1 has joined #openstack-containers | 02:47 | |
*** FracKen has quit IRC | 03:11 | |
*** FracKen has joined #openstack-containers | 03:13 | |
*** ricolin has joined #openstack-containers | 03:19 | |
*** ykarel has joined #openstack-containers | 03:26 | |
jakeyip | anyone had an opportunity to look into CVE-2019-5736 yet? | 03:26 |
flwang | i tried to test how to upgrade docker, but i failed | 03:28 |
flwang | that said, i'm aware of this but i haven't figured out a way to fix it | 03:29 |
flwang | not sure if there will be a new fedora image with latest docker version | 03:29 |
jakeyip | thanks flwang! | 03:40 |
*** sdake has joined #openstack-containers | 03:40 | |
*** jmlowe has joined #openstack-containers | 03:43 | |
jakeyip | looks like RH packages have dropped https://bugzilla.redhat.com/show_bug.cgi?id=1664908 there's a link on that page to fedora-all https://bugzilla.redhat.com/show_bug.cgi?id=1674489 | 03:43 |
openstack | bugzilla.redhat.com bug 1664908 in vulnerability "CVE-2019-5736 runc: Execution of malicious containers allows for container escape and access to host filesystem" [High,New] - Assigned to security-response-team | 03:43 |
openstack | bugzilla.redhat.com bug 1674489 in runc "CVE-2019-5736 container-tools:2017.0/runc: Execution of malicious containers allows for container escape and access to host filesystem [fedora-all]" [High,New] - Assigned to jchaloup | 03:43 |
*** dave-mccowan has quit IRC | 03:58 | |
*** sapd1 has quit IRC | 03:59 | |
*** sapd1 has joined #openstack-containers | 03:59 | |
*** sdake has quit IRC | 03:59 | |
*** flwang1 has quit IRC | 04:00 | |
*** udesale has joined #openstack-containers | 04:02 | |
*** ramishra has joined #openstack-containers | 04:06 | |
*** janki has joined #openstack-containers | 04:30 | |
*** ykarel has quit IRC | 04:47 | |
*** jmlowe has quit IRC | 04:50 | |
*** ykarel has joined #openstack-containers | 05:05 | |
*** hongbin has quit IRC | 05:30 | |
*** ArchiFleKs has quit IRC | 05:31 | |
*** ArchiFleKs has joined #openstack-containers | 05:37 | |
*** udesale has quit IRC | 05:37 | |
*** udesale has joined #openstack-containers | 07:09 | |
*** ykarel is now known as ykarel|lunch | 07:33 | |
*** ramishra_ has joined #openstack-containers | 07:37 | |
*** ramishra has quit IRC | 07:38 | |
*** ykarel|lunch has quit IRC | 07:41 | |
*** ykarel has joined #openstack-containers | 07:43 | |
*** ramishra_ is now known as ramishra | 07:56 | |
*** jaewook_oh has joined #openstack-containers | 08:35 | |
*** ricolin has quit IRC | 08:58 | |
*** ricolin has joined #openstack-containers | 09:06 | |
*** ricolin has quit IRC | 09:12 | |
*** ykarel has quit IRC | 09:20 | |
*** ramishra has quit IRC | 09:22 | |
*** ricolin has joined #openstack-containers | 09:24 | |
*** ykarel has joined #openstack-containers | 09:27 | |
*** ramishra has joined #openstack-containers | 09:29 | |
*** belmoreira has joined #openstack-containers | 10:12 | |
*** flwang1 has joined #openstack-containers | 10:37 | |
flwang1 | strigazi: around? | 10:37 |
openstackgerrit | Ricardo Rocha proposed openstack/magnum master: Add hidden flag to cluster template https://review.openstack.org/634948 | 10:38 |
flwang1 | mordred: could you please issue 'shipit' again for https://github.com/ansible/ansible/pull/44686 ? thanks | 10:39 |
flwang1 | mordred: seems it needs another approval | 10:39 |
flwang1 | strigazi: any thought for CVE-2019-5736 ? | 10:39 |
*** sapd1 has quit IRC | 10:45 | |
*** udesale has quit IRC | 10:49 | |
*** lpetrut has joined #openstack-containers | 11:15 | |
*** _fragatina has joined #openstack-containers | 11:56 | |
*** _fragatina has quit IRC | 11:59 | |
*** _fragatina has joined #openstack-containers | 12:00 | |
*** ricolin_ has joined #openstack-containers | 12:15 | |
*** ricolin has quit IRC | 12:17 | |
*** lpetrut has quit IRC | 12:38 | |
*** lpetrut has joined #openstack-containers | 12:39 | |
*** janki has quit IRC | 12:44 | |
*** janki has joined #openstack-containers | 12:44 | |
*** sapd1 has joined #openstack-containers | 12:44 | |
*** ykarel is now known as ykarel|away | 12:48 | |
*** ykarel|away has quit IRC | 12:54 | |
*** mkuf_ has joined #openstack-containers | 12:55 | |
*** _fragatina has quit IRC | 12:56 | |
*** jaewook_oh has quit IRC | 12:56 | |
*** mkuf has quit IRC | 12:58 | |
*** udesale has joined #openstack-containers | 13:10 | |
*** sdake has joined #openstack-containers | 13:31 | |
*** mkuf_ has quit IRC | 13:37 | |
*** openstackgerrit has quit IRC | 13:37 | |
*** ykarel|away has joined #openstack-containers | 13:43 | |
*** ykarel|away is now known as ykarel | 13:51 | |
*** mkuf_ has joined #openstack-containers | 14:01 | |
*** sdake has quit IRC | 14:03 | |
*** zul has joined #openstack-containers | 14:08 | |
*** sapd1 has quit IRC | 14:15 | |
brtknr | ive noticed something rather peculiar, when are are multiple interfaces on a host running kubelet, the pods that are deployed have service endpoints that get assigned ip address on arbitrary choice of interface, rather than a predictable interface. this leads to dialing failure. anyone able to shed light on this? | 14:17 |
*** sdake has joined #openstack-containers | 14:20 | |
*** sdake has quit IRC | 14:21 | |
*** ArchiFleKs has quit IRC | 14:34 | |
*** sdake has joined #openstack-containers | 14:35 | |
*** sdake has quit IRC | 14:37 | |
*** sdake_ has joined #openstack-containers | 14:37 | |
*** janki has quit IRC | 14:47 | |
*** hongbin has joined #openstack-containers | 14:49 | |
*** ArchiFleKs has joined #openstack-containers | 14:49 | |
*** mrodriguez has joined #openstack-containers | 14:49 | |
*** udesale has quit IRC | 14:52 | |
*** udesale has joined #openstack-containers | 15:02 | |
*** sapd1 has joined #openstack-containers | 15:02 | |
*** ianychoi has quit IRC | 15:07 | |
*** ianychoi has joined #openstack-containers | 15:07 | |
*** hongbin has quit IRC | 15:09 | |
*** hongbin has joined #openstack-containers | 15:12 | |
*** sapd1 has quit IRC | 15:32 | |
*** ykarel is now known as ykarel|away | 15:43 | |
*** lpetrut has quit IRC | 16:03 | |
*** udesale has quit IRC | 16:37 | |
*** jmlowe has joined #openstack-containers | 16:43 | |
*** ykarel|away has quit IRC | 16:49 | |
*** ramishra has quit IRC | 16:57 | |
*** hongbin has quit IRC | 16:59 | |
*** sdake_ has quit IRC | 17:01 | |
*** sdake has joined #openstack-containers | 17:02 | |
*** sapd1 has joined #openstack-containers | 17:04 | |
*** sapd1 has quit IRC | 17:14 | |
*** jmlowe has quit IRC | 17:21 | |
*** ricolin_ has quit IRC | 17:21 | |
flwang1 | brtknr: what's your service type? nodeport or lb? | 17:24 |
*** jaewookoh has quit IRC | 17:34 | |
*** spsurya has quit IRC | 17:40 | |
*** flwang1 has quit IRC | 17:43 | |
*** sdake has quit IRC | 17:44 | |
*** sdake has joined #openstack-containers | 17:46 | |
*** sdake has quit IRC | 18:44 | |
*** sdake has joined #openstack-containers | 18:51 | |
*** _fragatina has joined #openstack-containers | 18:55 | |
*** adrianreza has quit IRC | 19:04 | |
*** flwang has quit IRC | 19:04 | |
*** yankcrime has quit IRC | 19:04 | |
*** belmoreira has quit IRC | 19:04 | |
*** zul has quit IRC | 19:04 | |
*** yankcrime has joined #openstack-containers | 19:14 | |
*** flwang has joined #openstack-containers | 19:18 | |
flwang | strigazi: do we have meeting today? | 19:18 |
*** sdake has quit IRC | 19:42 | |
*** zul has joined #openstack-containers | 19:59 | |
strigazi | flwang: yes, we have a meeting | 20:36 |
strigazi | @all, flwang: It seems that in fedora atomic hosts we are not affected by CVE-2019-5736 | 20:37 |
strigazi | since all runc binaries in atomic have the immutable bit | 20:37 |
strigazi | i.e. chattr +i | 20:37 |
strigazi | To be checked with the fedora community | 20:37 |
flwang | strigazi: is there a confirmation from fedora community? | 20:41 |
flwang | I have a team meeting in 20 mins, probably can't join the weekly meeting | 20:41 |
flwang | strigazi: i have approved your heat-container-agent patch, hope it can speed up your rolling upgrade work | 20:42 |
flwang | flwang: i'm doing more test work for auth healing. now i would like to see you guys start to contribute those AC code back | 20:42 |
flwang | strigazi: could you pls revisit https://review.openstack.org/#/c/572897/ ? if we still need it, i think better to get it in soon so that we can test it fully, thanks | 20:44 |
*** dioguerra has quit IRC | 20:47 | |
strigazi | AC? | 20:48 |
strigazi | flwang: tmr we will make a PR to kubernetes/autoscaler. this branch is fully functional: https://github.com/cernops/autoscaler/tree/magnum-autoscaler-release-1.0 | 20:49 |
strigazi | I'll review with Ricardo https://review.openstack.org/#/c/572897/ and get back to you. | 20:51 |
strigazi | flwang: Can you also take a look at the tiller pacth | 20:51 |
*** jmlowe has joined #openstack-containers | 20:55 | |
flwang | strigazi: i have reviewed your tiller patch | 20:55 |
flwang | AC = autoscaler | 20:56 |
strigazi | flwang: in the repo the mention it as CA, hence the confusion :) | 20:56 |
flwang | sorry, CA | 20:56 |
flwang | my typo | 20:56 |
strigazi | eandersson: around? | 20:57 |
flwang | now it's generally working in my test, need some fixes anyway | 20:57 |
flwang | i have replied my comments on the PR on cernops repo | 20:57 |
flwang | is your rolling upgrade patch on track? | 20:58 |
strigazi | flwang: looks like fedora's crazy immutable fs saved us from the CVE. I'll try find a full explanation and send a mail to the ML | 20:58 |
strigazi | flwang: yeap, it is on track | 20:59 |
flwang | strigazi: cool, thanks | 20:59 |
strigazi | flwang: for the CA, I didn't get it, it is ok? | 20:59 |
flwang | it's generally OK, i need some final testing today | 20:59 |
flwang | but we can fix small bugs later, that's fine | 20:59 |
eandersson | o/ | 20:59 |
flwang | i have to offline for meeting, sorry | 21:00 |
colin- | o/ | 21:00 |
schaney | o/ | 21:00 |
flwang | eandersson: i will give the CA another test today and leave comments on, thanks | 21:00 |
strigazi | eandersson: I'll start the meeting to have things logged | 21:00 |
strigazi | #startmeeting containers | 21:00 |
openstack | Meeting started Tue Feb 12 21:00:47 2019 UTC and is due to finish in 60 minutes. The chair is strigazi. Information about MeetBot at http://wiki.debian.org/MeetBot. | 21:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 21:00 |
*** openstack changes topic to " (Meeting topic: containers)" | 21:00 | |
openstack | The meeting name has been set to 'containers' | 21:00 |
strigazi | #topic Roll Call | 21:00 |
*** openstack changes topic to "Roll Call (Meeting topic: containers)" | 21:01 | |
eandersson | o/ | 21:01 |
schaney | o/ | 21:01 |
strigazi | o/ | 21:01 |
*** imdigitaljim has joined #openstack-containers | 21:01 | |
jakeyip | o/ | 21:01 |
colin- | \o | 21:01 |
imdigitaljim | o/ | 21:01 |
strigazi | #topic stories/tasks | 21:02 |
*** openstack changes topic to "stories/tasks (Meeting topic: containers)" | 21:02 | |
strigazi | 1. Regarding CVE-2019-5736 in fedora atomic host, looks like we are covered | 21:02 |
colin- | nice | 21:03 |
strigazi | the fs of fedora atomic is immutable so an exploit can not overwrite the runc binary | 21:03 |
strigazi | also selinux protects users against an exploit of it. | 21:03 |
colin- | oh, i thought you meant you had patched for it | 21:04 |
colin- | i'm not as sure about those things | 21:04 |
strigazi | unfortunately we have it disabled on k8s. I'm testing if we can enable it | 21:04 |
strigazi | I'm checking with the fedora community | 21:04 |
strigazi | I'll let you know | 21:05 |
strigazi | 2. For the the cluster autoscaler, we have a branch public which is fully functional and we'll push it kubernetes/autoscaler. https://github.com/cernops/autoscaler/tree/magnum-autoscaler-release-1.0 | 21:06 |
*** flwang has quit IRC | 21:06 | |
colin- | cool. there's some sample exploit code attached to this report if anyone needs to test https://www.openwall.com/lists/oss-security/2019/02/11/2 | 21:06 |
colin- | (very generic) | 21:06 |
*** imdigitaljim has quit IRC | 21:06 | |
strigazi | colin-: I'll try to repro | 21:06 |
strigazi | 1 and 2 were a bit generic. next: | 21:07 |
strigazi | eandersson: and others can you have a quick look into these two so we can take them: | 21:07 |
strigazi | k8s_fedora: Deploy tiller https://review.openstack.org/#/c/612336/ | 21:08 |
strigazi | [k8s_fedora] Add heat-agent to worker nodes https://review.openstack.org/#/c/561858/ oh, flwang approved it | 21:08 |
strigazi | That's it from me. Does anyone else want to bring something up? | 21:09 |
schaney | mind if I add some comments and questions to the CA PR? | 21:10 |
strigazi | schaney: go for it | 21:11 |
strigazi | schaney: I was thinking we can open the PR to k/a first, but we can bring the discussion there when it is open | 21:11 |
schaney | that works as well | 21:11 |
strigazi | but it is public for that reason, so as you want :) | 21:12 |
strigazi | better comment now so you don't forget :) | 21:12 |
colin- | strigazi: did you ever try using the ipvs transport layer on your clusters? | 21:12 |
colin- | as opposed to iptables or similar | 21:13 |
strigazi | nope | 21:13 |
colin- | ok | 21:13 |
schaney | is this PR up to date? https://github.com/cernops/autoscaler/pull/3 not sure the differences between that and the release branch | 21:13 |
strigazi | the release branch is up to date | 21:14 |
*** imdigitaljim has joined #openstack-containers | 21:14 | |
strigazi | not sure where Thomas left the pr. lemme check | 21:14 |
strigazi | schaney: sorry I can not tell with certainty | 21:15 |
schaney | ok, I'll use the existing PR but make sure the code is consistent with the branch, unless that PR is known to be out of date? | 21:17 |
imdigitaljim | one random question with your autoscaler, have you tried on templates >= queens? | 21:17 |
imdigitaljim | since resources have had some changes since juno | 21:17 |
imdigitaljim | https://github.com/openstack/magnum/blob/master/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml#L1 | 21:18 |
strigazi | schaney: maybe this helps https://github.com/cernops/autoscaler/compare/magnum-autoscaler-release-1.0...tghartland:openstack-provider | 21:18 |
imdigitaljim | well | 21:19 |
strigazi | imdigitaljim: no | 21:19 |
imdigitaljim | if you didnt have the PR with vendor folder | 21:19 |
imdigitaljim | it would be reviewable /shrug | 21:19 |
imdigitaljim | 1307 files is a lot to browse through | 21:19 |
schaney | looks like a lot of extra gophercloud stuff yeah | 21:20 |
strigazi | imdigitaljim: it is reviewable, you can ignore the vendor files | 21:20 |
strigazi | the gopherloud changes are very clear here: https://github.com/cernops/autoscaler/commits/magnum-autoscaler-release-1.0 | 21:21 |
imdigitaljim | well we cant really comment on this PR effectively https://github.com/cernops/autoscaler/pull/3/files | 21:22 |
imdigitaljim | is all i mean | 21:22 |
imdigitaljim | in fact it hardly loads | 21:22 |
imdigitaljim | :P | 21:22 |
strigazi | I'll ping you tmr then, when we the PR will be up | 21:25 |
strigazi | github nicks? | 21:25 |
strigazi | same as here? | 21:25 |
imdigitaljim | jim-bach | 21:25 |
imdigitaljim | or jabach@blizzard.com | 21:26 |
imdigitaljim | i can forward to others | 21:26 |
schaney | scott-chaney or schaney@blizzard.com | 21:26 |
*** sdake has joined #openstack-containers | 21:26 | |
strigazi | excellent | 21:26 |
schaney | thanks! | 21:26 |
strigazi | anything else for the meeting? | 21:28 |
colin- | itsc0lin on git | 21:29 |
colin- | nope | 21:29 |
strigazi | thanks colin- | 21:29 |
jakeyip | nope | 21:29 |
imdigitaljim | thanks spyros!@ | 21:30 |
strigazi | thanks everyone. see you next week o/ | 21:30 |
imdigitaljim | \o | 21:30 |
strigazi | #endmeeting | 21:30 |
*** openstack changes topic to "OpenStack Containers Team" | 21:30 | |
openstack | Meeting ended Tue Feb 12 21:30:37 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 21:30 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-02-12-21.00.html | 21:30 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-02-12-21.00.txt | 21:30 |
openstack | Log: http://eavesdrop.openstack.org/meetings/containers/2019/containers.2019-02-12-21.00.log.html | 21:30 |
*** ArchiFleKs has quit IRC | 21:40 | |
*** sdake has quit IRC | 21:50 | |
*** ArchiFleKs has joined #openstack-containers | 21:52 | |
*** flwang has joined #openstack-containers | 22:04 | |
*** sdake has joined #openstack-containers | 23:43 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!