*** rcernin has quit IRC | 03:10 | |
*** rcernin has joined #openstack-containers | 03:18 | |
*** ramishra has joined #openstack-containers | 03:21 | |
*** ykarel|away has joined #openstack-containers | 04:06 | |
*** ykarel|away is now known as ykarel | 04:11 | |
*** logan- has joined #openstack-containers | 04:40 | |
*** johanssone has quit IRC | 06:04 | |
*** tobberydberg has quit IRC | 06:05 | |
*** ricolin has quit IRC | 06:08 | |
*** johanssone has joined #openstack-containers | 06:11 | |
*** tobberydberg has joined #openstack-containers | 06:11 | |
*** nikparasyr has joined #openstack-containers | 06:20 | |
*** rcernin has quit IRC | 07:07 | |
*** yolanda has quit IRC | 07:32 | |
*** sapd1 has joined #openstack-containers | 07:33 | |
*** yolanda has joined #openstack-containers | 07:33 | |
*** yasemind has joined #openstack-containers | 07:49 | |
*** born2bake has joined #openstack-containers | 08:14 | |
*** udesale has joined #openstack-containers | 08:27 | |
*** udesale has quit IRC | 08:27 | |
*** udesale has joined #openstack-containers | 08:27 | |
*** sapd1 has quit IRC | 08:42 | |
*** udesale has quit IRC | 08:50 | |
*** flwang1 has joined #openstack-containers | 08:59 | |
flwang1 | strigazi: brtknr: meeting? | 09:00 |
---|---|---|
brtknr | flwang1: morning! | 09:00 |
brtknr | yes :) | 09:00 |
brtknr | how are you stranger? | 09:00 |
brtknr | long time | 09:00 |
brtknr | btw the topic on this channel has been roll call for 3 weeks :P | 09:01 |
jakeyip | :) | 09:01 |
jakeyip | hi all | 09:01 |
flwang1 | :( | 09:02 |
flwang1 | #endmeeting | 09:02 |
*** openstack changes topic to "OpenStack Containers Team | Meeting: every Wednesday @ 9AM UTC | Agenda: https://etherpad.openstack.org/p/magnum-weekly-meeting" | 09:02 | |
openstack | Meeting ended Wed Aug 12 09:02:11 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 09:02 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-29-08.59.html | 09:02 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-29-08.59.txt | 09:02 |
openstack | Log: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-07-29-08.59.log.html | 09:02 |
flwang1 | brtknr: sorry about that :( | 09:02 |
flwang1 | i was busy for house moving | 09:02 |
brtknr | hehe no worries | 09:02 |
brtknr | mornig jakeyip | 09:03 |
flwang1 | #startmeeting magnum | 09:03 |
openstack | Meeting started Wed Aug 12 09:03:52 2020 UTC and is due to finish in 60 minutes. The chair is flwang1. Information about MeetBot at http://wiki.debian.org/MeetBot. | 09:03 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 09:03 |
*** openstack changes topic to " (Meeting topic: magnum)" | 09:03 | |
openstack | The meeting name has been set to 'magnum' | 09:03 |
flwang1 | i only have one thing to bring to you guys attention | 09:04 |
flwang1 | but i'd like to allow you guys talk first | 09:04 |
flwang1 | brtknr: anything from your side? | 09:04 |
*** ioni has quit IRC | 09:05 | |
brtknr | well there's a bunch of open reviews which would be good to deal with: https://review.opendev.org/#/q/project:openstack/magnum+status:open | 09:06 |
flwang1 | brtknr: sure, i will start to review them soon | 09:08 |
flwang1 | just had a quick look, most of them are small changes | 09:08 |
brtknr | atm, k8s-atomic is broken on master without this patch: https://review.opendev.org/#/c/745359/ | 09:08 |
brtknr | thats about it really | 09:09 |
brtknr | what do you need to talk about? | 09:09 |
flwang1 | brtknr: is the failure of magnum-tempest-plugin-tests-api related? | 09:10 |
flwang1 | brtknr: i'd like to propose a patch to support separate CA for etcd and front-proxy | 09:10 |
flwang1 | it's a security risk | 09:10 |
brtknr | flwang1: no magnum-tempest-plugin-tests-api only deploys coreos | 09:11 |
brtknr | flwang1: no magnum-tempest-plugin-tests-api only deploys fedora-coreos | 09:12 |
brtknr | flwang1: ok how is it a security risk? | 09:12 |
*** ioni has joined #openstack-containers | 09:12 | |
flwang1 | now we're sharing the same ca cert for kubelet, etcd and front-proxy | 09:13 |
flwang1 | which means user can use the ca cert in any node to access etcd | 09:13 |
brtknr | but a user that has access to a node also has access to any cert | 09:14 |
flwang1 | we're talking about the case that the node is hacked | 09:17 |
flwang1 | it's a typical best practice by any k8s install tool or managed services | 09:18 |
*** udesale has joined #openstack-containers | 09:20 | |
flwang1 | i can't find the link on k8s doc, i will show you later | 09:21 |
brtknr | flwang1: | 09:22 |
brtknr | i guess it makes sense from the POV of separating CA for kubelet and etcd | 09:22 |
brtknr | since etcd is usually running on master | 09:22 |
brtknr | and normal workload only runs on minions | 09:22 |
flwang1 | yes, it's | 09:23 |
flwang1 | brtknr: did you get a chance to revisit the ca rotate patch? | 09:24 |
jakeyip | I'd like to know more about this too, can share the doc here if you don't mind? | 09:24 |
flwang1 | jakeyip: which one? | 09:25 |
jakeyip | security best practice of separating certs | 09:25 |
flwang1 | https://github.com/kubernetes/kubeadm/issues/710 | 09:26 |
flwang1 | https://kubernetes.io/docs/reference/setup-tools/kubeadm/implementation-details/ | 09:26 |
flwang1 | jakeyip: does that make sense? | 09:30 |
flwang1 | it's actually quite straighforward to implement | 09:30 |
flwang1 | we may need a db schema change to add extra fields | 09:31 |
*** yolanda has quit IRC | 09:34 | |
jakeyip | I don't think I'm knowledgable enough to give comments | 09:34 |
jakeyip | stupid question - do the minions not need to contact etcd to report in their status? | 09:34 |
*** yolanda has joined #openstack-containers | 09:38 | |
*** yolanda has quit IRC | 09:38 | |
*** yolanda has joined #openstack-containers | 09:38 | |
flwang1 | minions only talk to api server | 09:38 |
jakeyip | ok I will need to read up more | 09:42 |
jakeyip | what is this etcd used for? | 09:43 |
jakeyip | anyway I've got a question if no one is discussing anything else? | 09:44 |
brtknr | re | 09:46 |
brtknr | sure | 09:46 |
jakeyip | anyone uses istio? any idea if deploying a service mesh with magnum is a good idea? | 09:47 |
brtknr | flwang1: thanks for reminding me about CA rotate patch, I will take a look at it when I have some free time next week, busy all week this week on a scheduled piece of work Im afraid | 09:47 |
flwang1 | brtknr: thanks | 09:48 |
flwang1 | jakeyip: we're not using istio yet | 09:48 |
brtknr | jakeyip: ive tried istio last year, the older version seemed to work okay, the newer version i had some issues with | 09:48 |
flwang1 | but i'm happy to see if you want to contribute it | 09:48 |
jakeyip | brtknr: what kind of issues? | 09:49 |
brtknr | i cant remember, it didnt deploy cleanly | 09:49 |
brtknr | i was just following the docs | 09:49 |
jakeyip | flwang1: sure. all these are pretty new to us and is just a question from users for now | 09:49 |
flwang1 | anything else? | 09:54 |
flwang1 | i'm going to off now | 09:55 |
flwang1 | #endmeeting | 09:57 |
*** openstack changes topic to "OpenStack Containers Team | Meeting: every Wednesday @ 9AM UTC | Agenda: https://etherpad.openstack.org/p/magnum-weekly-meeting" | 09:57 | |
openstack | Meeting ended Wed Aug 12 09:57:16 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 09:57 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-08-12-09.03.html | 09:57 |
flwang1 | thank you, team | 09:57 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-08-12-09.03.txt | 09:57 |
openstack | Log: http://eavesdrop.openstack.org/meetings/magnum/2020/magnum.2020-08-12-09.03.log.html | 09:57 |
*** yolanda has quit IRC | 10:44 | |
*** yolanda has joined #openstack-containers | 10:46 | |
*** vishalmanchanda has joined #openstack-containers | 10:57 | |
*** yolanda has quit IRC | 11:03 | |
*** yolanda has joined #openstack-containers | 11:06 | |
*** yolanda has quit IRC | 11:12 | |
*** k_mouza has joined #openstack-containers | 11:12 | |
*** yolanda has joined #openstack-containers | 11:25 | |
*** k_mouza has quit IRC | 11:52 | |
*** yolanda has quit IRC | 12:03 | |
*** yolanda has joined #openstack-containers | 12:16 | |
*** ianychoi has quit IRC | 12:40 | |
*** dave-mccowan has joined #openstack-containers | 12:57 | |
*** ykarel is now known as ykarel|afk | 12:58 | |
*** yolanda has quit IRC | 13:07 | |
*** ricolin has joined #openstack-containers | 13:22 | |
*** sapd1 has joined #openstack-containers | 13:35 | |
*** mgariepy has quit IRC | 13:36 | |
*** hongbin has joined #openstack-containers | 13:40 | |
*** ianychoi has joined #openstack-containers | 13:44 | |
*** yolanda has joined #openstack-containers | 13:51 | |
*** ykarel|afk is now known as ykarel | 14:00 | |
*** ykarel_ has joined #openstack-containers | 14:13 | |
*** hongbin has quit IRC | 14:14 | |
*** mgariepy has joined #openstack-containers | 14:15 | |
*** ykarel has quit IRC | 14:15 | |
*** ykarel_ is now known as ykarel | 14:16 | |
*** mgariepy has quit IRC | 14:25 | |
*** hongbin has joined #openstack-containers | 14:39 | |
*** udesale_ has joined #openstack-containers | 14:44 | |
*** udesale has quit IRC | 14:46 | |
*** mgariepy has joined #openstack-containers | 14:59 | |
*** nikparasyr has left #openstack-containers | 15:21 | |
brtknr | flwang1: thanks | 15:29 |
*** ykarel has quit IRC | 16:13 | |
*** sapd1 has quit IRC | 16:31 | |
*** hongbin has quit IRC | 16:43 | |
*** mgariepy has quit IRC | 16:47 | |
*** mgariepy has joined #openstack-containers | 16:48 | |
*** udesale_ has quit IRC | 16:52 | |
*** mgoddard has quit IRC | 16:56 | |
*** hongbin has joined #openstack-containers | 17:00 | |
*** mgariepy has quit IRC | 17:49 | |
*** mgoddard has joined #openstack-containers | 18:02 | |
*** mgariepy has joined #openstack-containers | 18:03 | |
*** pcaruana has quit IRC | 18:20 | |
*** gouthamr has quit IRC | 18:20 | |
*** pcaruana has joined #openstack-containers | 18:21 | |
*** ioni has quit IRC | 18:21 | |
*** gouthamr has joined #openstack-containers | 18:22 | |
*** mgoddard has quit IRC | 18:23 | |
*** ricolin has quit IRC | 18:23 | |
*** mgariepy has quit IRC | 18:25 | |
*** ioni has joined #openstack-containers | 18:27 | |
*** mgariepy has joined #openstack-containers | 18:38 | |
*** k_mouza has joined #openstack-containers | 19:23 | |
*** hongbin has quit IRC | 19:26 | |
*** k_mouza has quit IRC | 19:27 | |
*** hongbin has joined #openstack-containers | 19:44 | |
*** mgoddard has joined #openstack-containers | 20:08 | |
*** vishalmanchanda has quit IRC | 21:55 | |
*** ramishra has quit IRC | 22:37 | |
*** rcernin has joined #openstack-containers | 22:43 | |
*** born2bake has quit IRC | 22:51 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!