*** mrodriguez has quit IRC | 00:24 | |
*** sdake has quit IRC | 00:26 | |
*** sdake has joined #openstack-containers | 00:46 | |
*** ricolin_ has joined #openstack-containers | 01:01 | |
*** yankcrime has quit IRC | 01:08 | |
*** sdake has quit IRC | 01:14 | |
*** sdake has joined #openstack-containers | 01:17 | |
*** sapd1 has joined #openstack-containers | 01:26 | |
*** sdake has quit IRC | 01:29 | |
*** sdake has joined #openstack-containers | 01:32 | |
*** sdake has quit IRC | 01:39 | |
*** ramishra has joined #openstack-containers | 01:52 | |
*** yankcrime has joined #openstack-containers | 02:01 | |
*** _fragatina has quit IRC | 02:02 | |
*** hongbin has joined #openstack-containers | 02:21 | |
*** openstackgerrit has joined #openstack-containers | 02:39 | |
openstackgerrit | Feilong Wang proposed openstack/magnum master: [fedora_atomic] Support auto healing for k8s https://review.openstack.org/631378 | 02:39 |
---|---|---|
*** sdake has joined #openstack-containers | 03:06 | |
*** ricolin_ has quit IRC | 03:48 | |
*** spsurya has joined #openstack-containers | 03:55 | |
*** udesale has joined #openstack-containers | 03:55 | |
*** ykarel|away has joined #openstack-containers | 04:04 | |
*** ykarel|away is now known as ykarel | 04:08 | |
*** sdake has quit IRC | 04:15 | |
*** janki has joined #openstack-containers | 04:32 | |
*** ArchiFleKs has quit IRC | 04:40 | |
*** ArchiFleKs has joined #openstack-containers | 04:50 | |
*** hongbin has quit IRC | 04:55 | |
*** zul has quit IRC | 05:26 | |
*** udesale has quit IRC | 05:36 | |
*** udesale has joined #openstack-containers | 05:42 | |
*** ricolin has joined #openstack-containers | 05:46 | |
*** udesale has quit IRC | 05:48 | |
*** udesale has joined #openstack-containers | 05:48 | |
*** sdake has joined #openstack-containers | 06:28 | |
*** sdake has quit IRC | 07:07 | |
*** udesale has quit IRC | 07:12 | |
*** belmoreira has joined #openstack-containers | 07:19 | |
*** udesale has joined #openstack-containers | 07:19 | |
*** ricolin has quit IRC | 07:19 | |
*** ricolin_ has joined #openstack-containers | 07:19 | |
*** udesale has quit IRC | 07:24 | |
*** udesale has joined #openstack-containers | 07:25 | |
*** ricolin_ has quit IRC | 07:45 | |
*** ricolin has joined #openstack-containers | 07:46 | |
*** ykarel is now known as ykarel|lunch | 08:36 | |
*** flwang1 has joined #openstack-containers | 08:41 | |
flwang1 | strigazi: around? | 08:41 |
strigazi | flwang1: hello | 08:52 |
flwang1 | do you have a few mins? | 08:53 |
flwang1 | some random things i'd like to get your comments | 08:53 |
strigazi | yes | 08:53 |
flwang1 | 1. any plan to Fedora Atomic 29 or just go for Ubuntu or whatever you named here | 08:54 |
strigazi | f29 | 08:54 |
strigazi | flwang1: we are using it here a bit | 08:54 |
flwang1 | ok, the reaction from Fedora Atomic about the cve 5736 make me nervous | 08:54 |
strigazi | ? | 08:54 |
flwang1 | i haven't seen any response about this | 08:55 |
flwang1 | from FA side | 08:55 |
flwang1 | that makes me feeling the community is not really active now | 08:55 |
flwang1 | we're lucky this time, but next time maybe not | 08:56 |
flwang1 | we probably still need a way to patch Fedora Atomic to build new image before we migrate to any other OS | 08:56 |
strigazi | I think you are exaggerating | 08:56 |
strigazi | you can go to ubuntu | 08:56 |
flwang1 | ok, fair enough | 08:57 |
strigazi | builds here for moby-engine https://koji.fedoraproject.org/koji/packageinfo?packageID=27395 | 08:57 |
strigazi | fedora atomic is a read-only fs plus with selinux it is not affected | 08:58 |
flwang1 | i would say we have different PoV, so we are thinking from different perspective | 08:58 |
flwang1 | we're not enabling selinux | 08:58 |
flwang1 | for k8s | 08:58 |
strigazi | I just tried it because of this CVE and it works. I'm running conformance. | 08:59 |
strigazi | Also the exploit does not work on fedora atomic. | 08:59 |
strigazi | even with selinux off, based on my tests. | 08:59 |
flwang1 | how did you test it? | 09:00 |
flwang1 | i haven't see a test script yet, could you share? | 09:00 |
strigazi | gitlab-registry.cern.ch/strigazi/containers/cve-2019-5736-poc | 09:00 |
strigazi | https://github.com/q3k/cve-2019-5736-poc | 09:01 |
strigazi | we can work on moving to kubeadm and be distro agnostic. | 09:01 |
strigazi | there is also this: https://gist.github.com/singe/0ad4078848d85dc0d03f9f9013796e45 | 09:02 |
flwang1 | and you know the coreOS/Fedora atomic strategy is still very unclear | 09:02 |
strigazi | you comment on the reaction time from the community is based on what? can you elaborate? | 09:02 |
flwang1 | strigazi: is there any response from fedora atomic community about this cve? | 09:04 |
flwang1 | i googled a lot, can't see any | 09:04 |
flwang1 | and i also popped up into #atomic irc channel, asked question, no response as well | 09:04 |
strigazi | I asked in #fedora-coreos and they told me they want a reproducer. | 09:05 |
strigazi | where is the response from ubuntu? | 09:05 |
flwang1 | don't get me wrong, i could be too concerned, but i think it's not the first time we think about this migrating | 09:05 |
flwang1 | i'm not saying Ubuntu doing a better job here, and i'm not arguing who is the best community | 09:08 |
strigazi | also, just to note here. google container os didn't neet an upgrade, just like fedora. | 09:09 |
strigazi | I think an effort to be more flexible on the distro can be made. | 09:10 |
*** ricolin has quit IRC | 09:19 | |
openstackgerrit | Spyros Trigazis proposed openstack/magnum master: [k8s_fedora] Add heat-agent to worker nodes https://review.openstack.org/561858 | 09:36 |
*** ykarel|lunch is now known as ykarel | 09:49 | |
*** adrianreza has joined #openstack-containers | 09:59 | |
*** mkuf_ is now known as mkuf | 10:01 | |
openstackgerrit | Merged openstack/magnum master: k8s_fedora: Deploy tiller https://review.openstack.org/612336 | 10:20 |
*** udesale has quit IRC | 11:13 | |
*** janki has quit IRC | 11:40 | |
*** janki has joined #openstack-containers | 11:40 | |
*** sapd1 has quit IRC | 11:45 | |
openstackgerrit | Merged openstack/magnum master: [k8s_fedora] Add heat-agent to worker nodes https://review.openstack.org/561858 | 11:48 |
*** sdake has joined #openstack-containers | 12:03 | |
*** _fragatina has joined #openstack-containers | 12:11 | |
*** _fragatina_ has joined #openstack-containers | 12:12 | |
*** _fragatina has quit IRC | 12:16 | |
*** sdake has quit IRC | 12:16 | |
*** udesale has joined #openstack-containers | 12:50 | |
*** janki has quit IRC | 13:00 | |
*** sapd1 has joined #openstack-containers | 13:08 | |
*** ykarel is now known as ykarel|afk | 13:23 | |
*** janki has joined #openstack-containers | 13:28 | |
*** jmlowe has quit IRC | 13:54 | |
*** sdake has joined #openstack-containers | 14:07 | |
*** sdake has quit IRC | 14:09 | |
*** sdake has joined #openstack-containers | 14:11 | |
*** ykarel|afk is now known as ykarel | 14:11 | |
*** sdake has quit IRC | 14:13 | |
*** sdake has joined #openstack-containers | 14:13 | |
*** sdake has quit IRC | 14:23 | |
*** dave-mccowan has joined #openstack-containers | 14:25 | |
*** dave-mccowan has quit IRC | 14:30 | |
*** lpetrut has joined #openstack-containers | 14:38 | |
*** _fragatina_ has quit IRC | 14:42 | |
*** zul has joined #openstack-containers | 14:43 | |
*** mrodriguez has joined #openstack-containers | 14:46 | |
*** sapd1 has quit IRC | 14:52 | |
*** jmlowe has joined #openstack-containers | 14:59 | |
*** sapd1 has joined #openstack-containers | 15:08 | |
*** jmlowe has quit IRC | 15:18 | |
*** janki has quit IRC | 15:21 | |
*** jmlowe has joined #openstack-containers | 15:23 | |
*** jmlowe has quit IRC | 15:54 | |
*** jmlowe has joined #openstack-containers | 15:58 | |
*** ykarel is now known as ykarel|away | 15:58 | |
*** lpetrut has quit IRC | 16:00 | |
*** sdake has joined #openstack-containers | 16:05 | |
*** ianychoi has quit IRC | 16:08 | |
*** ramishra has quit IRC | 16:29 | |
openstackgerrit | Diogo Guerra proposed openstack/magnum master: [k8s] helm install metrics service https://review.openstack.org/632392 | 16:38 |
*** jmlowe has quit IRC | 16:38 | |
*** jmlowe has joined #openstack-containers | 16:44 | |
*** sdake has quit IRC | 16:46 | |
*** sdake has joined #openstack-containers | 16:47 | |
*** ykarel|away has quit IRC | 16:58 | |
*** sdake has quit IRC | 16:58 | |
*** _fragatina has joined #openstack-containers | 16:59 | |
*** _fragatina has quit IRC | 17:00 | |
*** itlinux has joined #openstack-containers | 17:05 | |
*** itlinux has quit IRC | 17:09 | |
*** ykarel|away has joined #openstack-containers | 17:09 | |
*** itlinux_ has joined #openstack-containers | 17:09 | |
*** itlinux_ has quit IRC | 17:14 | |
*** itlinux has joined #openstack-containers | 17:15 | |
*** sapd1 has quit IRC | 17:16 | |
imdigitaljim | @strigazi @flwang1 this vulnerability is *not* blocked by the default AppArmor policy, nor | 17:23 |
imdigitaljim | by the default SELinux policy on Fedora[++] | 17:23 |
*** udesale has quit IRC | 17:23 | |
*** jmlowe has quit IRC | 17:23 | |
imdigitaljim | https://www.openwall.com/lists/oss-security/2019/02/11/2 | 17:24 |
*** ricolin has joined #openstack-containers | 17:25 | |
*** sapd1 has joined #openstack-containers | 17:29 | |
imdigitaljim | also | 17:29 |
imdigitaljim | strigazi | 17:29 |
*** itlinux has quit IRC | 17:30 | |
imdigitaljim | the ro file-system doesnt protect you if you're root, you can just mount -o remount,rw /anything | 17:30 |
*** _fragatina has joined #openstack-containers | 17:31 | |
*** ykarel|away has quit IRC | 17:31 | |
*** itlinux has joined #openstack-containers | 17:36 | |
*** sapd1 has quit IRC | 17:37 | |
*** itlinux_ has joined #openstack-containers | 17:40 | |
*** itlinux has quit IRC | 17:41 | |
*** ricolin has quit IRC | 17:58 | |
*** jmlowe has joined #openstack-containers | 18:08 | |
*** itlinux_ has quit IRC | 18:08 | |
*** hongbin has joined #openstack-containers | 18:15 | |
*** sdake has joined #openstack-containers | 18:19 | |
*** sapd1 has joined #openstack-containers | 18:27 | |
*** hongbin has quit IRC | 18:27 | |
*** hongbin has joined #openstack-containers | 18:27 | |
*** sdake has quit IRC | 18:37 | |
openstackgerrit | Ricardo Rocha proposed openstack/magnum master: [k8s] Add trustee as a secret in kube-system https://review.openstack.org/636725 | 19:10 |
*** ArchiFleKs has quit IRC | 19:13 | |
*** ArchiFleKs has joined #openstack-containers | 19:14 | |
*** _fragatina has quit IRC | 20:05 | |
*** jmlowe has quit IRC | 20:28 | |
*** hongbin has quit IRC | 20:40 | |
*** hongbin has joined #openstack-containers | 20:49 | |
*** hongbin has quit IRC | 20:54 | |
*** itlinux has joined #openstack-containers | 21:04 | |
*** hongbin has joined #openstack-containers | 21:06 | |
*** jmlowe has joined #openstack-containers | 21:15 | |
*** _fragatina has joined #openstack-containers | 21:45 | |
openstackgerrit | Ricardo Rocha proposed openstack/magnum master: [k8s] Add trustee as a secret in kube-system https://review.openstack.org/636725 | 21:52 |
*** itlinux has quit IRC | 21:58 | |
brtknr | strigazi: I am using the patch you mentioned for queens and I am getting the same problem related to region_name with my heat-container-agent | 22:20 |
*** openstackgerrit has quit IRC | 22:22 | |
brtknr | strigazi: the weird thing is, the problem is surfacing on one deployment and not on the other | 22:23 |
brtknr | i'm pretty sure that the two are using the same docker image underneath! | 22:23 |
*** eandersson has quit IRC | 22:33 | |
*** sapd1 has quit IRC | 22:40 | |
*** sapd1 has joined #openstack-containers | 22:55 | |
brtknr | is there an easy way to debug heat-container-agent? | 22:56 |
*** sapd1 has quit IRC | 23:16 | |
*** mrodriguez has quit IRC | 23:21 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!