*** yamamoto has joined #openstack-fwaas | 00:02 | |
*** yamamoto has quit IRC | 00:08 | |
*** Swami has quit IRC | 00:09 | |
*** yamamoto has joined #openstack-fwaas | 01:04 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 01:08 | |
*** yamamoto has quit IRC | 01:09 | |
*** AlexeyAbashkin has quit IRC | 01:13 | |
*** yamamoto has joined #openstack-fwaas | 02:05 | |
*** yamamoto has quit IRC | 02:11 | |
*** yamamoto has joined #openstack-fwaas | 02:47 | |
*** annp has quit IRC | 03:49 | |
*** bbzhao has quit IRC | 03:50 | |
*** bbzhao has joined #openstack-fwaas | 03:51 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 04:09 | |
*** AlexeyAbashkin has quit IRC | 04:14 | |
*** hoangcx has quit IRC | 04:25 | |
*** hoangcx has joined #openstack-fwaas | 04:28 | |
*** hoangcx has quit IRC | 04:50 | |
*** hoangcx has joined #openstack-fwaas | 04:51 | |
*** velizarx has joined #openstack-fwaas | 06:56 | |
*** velizarx has quit IRC | 07:16 | |
*** yamamoto has quit IRC | 07:22 | |
*** yamamoto has joined #openstack-fwaas | 07:23 | |
*** velizarx has joined #openstack-fwaas | 07:31 | |
*** yamamoto_ has joined #openstack-fwaas | 07:32 | |
*** yamamoto has quit IRC | 07:34 | |
*** hoangcx has quit IRC | 07:46 | |
*** hoangcx has joined #openstack-fwaas | 07:46 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:00 | |
*** AlexeyAbashkin has quit IRC | 08:07 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:10 | |
*** Alexey_Abashkin has joined #openstack-fwaas | 08:52 | |
*** AlexeyAbashkin has quit IRC | 08:54 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 08:54 | |
*** AlexeyAbashkin has quit IRC | 08:55 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:58 | |
openstackgerrit | Thomas Morin proposed openstack/neutron-fwaas master: remove unused plugin.get_plugin_name() https://review.openstack.org/557669 | 10:14 |
---|---|---|
*** AlexeyAbashkin has quit IRC | 10:53 | |
*** yamamoto has joined #openstack-fwaas | 11:01 | |
*** yamamoto_ has quit IRC | 11:05 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 11:18 | |
*** velizarx has quit IRC | 11:51 | |
*** velizarx has joined #openstack-fwaas | 11:52 | |
*** velizarx has quit IRC | 13:04 | |
*** velizarx has joined #openstack-fwaas | 13:10 | |
*** hoangcx_ has joined #openstack-fwaas | 13:24 | |
*** SridarK has joined #openstack-fwaas | 13:59 | |
SridarK | Hi FWaaS folks | 13:59 |
*** yushiro has joined #openstack-fwaas | 13:59 | |
SridarK | #startmeeting fwaas | 13:59 |
openstack | Meeting started Thu Mar 29 13:59:39 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:59 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:59 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 13:59 | |
openstack | The meeting name has been set to 'fwaas' | 13:59 |
njohnston | o/ | 13:59 |
SridarK | #chair xgerman_ yushiro | 13:59 |
openstack | Current chairs: SridarK xgerman_ yushiro | 13:59 |
yushiro | Hi | 14:00 |
doude | o/ | 14:00 |
SridarK | hmm oh i think xgerman_ ur turn ? | 14:00 |
yushiro | Yes, but I heard that xgerman_ is PTO. So, I will. | 14:00 |
SridarK | hmm ok | 14:01 |
SridarK | surely go ahead yushiro | 14:01 |
yushiro | OK, | 14:01 |
yushiro | #topic announcements | 14:01 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:01 | |
yushiro | I have 1 suggestion for njohnston. Would it be possible to help chair for fwaas weekly meeting? | 14:03 |
njohnston | Sure! I can help with that. | 14:03 |
yushiro | njohnston, Thank you so much! I'll update the etherpad for chair round :) | 14:04 |
njohnston | Thanks! | 14:04 |
SridarK | yushiro: lets work thru this offline | 14:04 |
yushiro | SridarK, OK. | 14:04 |
yushiro | So, anything else to announcement? | 14:04 |
yushiro | s/announcement/announce | 14:05 |
SridarK | hmm nothing specific i can think off | 14:05 |
yushiro | SridarK, OK, thanks. | 14:05 |
yushiro | #topic Rocky | 14:05 |
*** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:05 | |
yushiro | 1. Pluggable backend driver https://review.openstack.org/#/c/480265/ | 14:06 |
doude | hi | 14:06 |
SridarK | doude: i am on it - a bit slow as i had to be out this week | 14:06 |
doude | I continued tests and I did not find any issue | 14:06 |
SridarK | i will get u first round of comments early next week | 14:06 |
doude | ok SridarK | 14:06 |
doude | right | 14:07 |
SridarK | doude: are u tracking the testing ? | 14:07 |
yushiro | doude, I'm watching your patch either. Now, I'm trying to deploy devstack with your patch. | 14:07 |
doude | I used the etherpad | 14:07 |
doude | I can give you my local.conf | 14:07 |
SridarK | doude: can u pls put it somewhere and point us to it | 14:08 |
yushiro | doude, Did you deploy multiple environment? I mean 2 nodes(controller + compute) | 14:08 |
doude | no | 14:08 |
doude | all-in-one node | 14:08 |
yushiro | I'll try to deploy 1.All-in-one and 2.multi-nodes | 14:08 |
doude | cool | 14:08 |
SridarK | yushiro: great - i think we defn want to cover the multinode | 14:09 |
yushiro | doude, OK, so it will be great if you share your local.conf | 14:09 |
yushiro | SridarK, Yees. After deployed multi-node, I'll try to run basically fwaas feature. | 14:10 |
SridarK | yushiro: +1 and lets exchange info on the etherpad | 14:10 |
doude | https://etherpad.openstack.org/p/fwaas-pluggable-backend-testing | 14:10 |
yushiro | doude, cool! | 14:11 |
*** annp has joined #openstack-fwaas | 14:11 | |
yushiro | doude, OK, I'll try to test in multi-node environment either. | 14:12 |
yushiro | and will update the etherpad. | 14:12 |
yushiro | If all case has passed both All-in-one and multi-nodes, I'm OK to put +2 | 14:13 |
SridarK | agreed | 14:13 |
yushiro | doude, Could you please paste your local.conf into https://etherpad.openstack.org/p/fwaas-pluggable-backend-testing ? | 14:13 |
doude | http://paste.openstack.org/show/717910/ | 14:14 |
doude | my local.conf | 14:14 |
SridarK | doude thx | 14:14 |
yushiro | doude, Thanks! | 14:15 |
yushiro | haha, I just opened link (www.local.conf) This is hyper link for your comment "my local.conf" | 14:16 |
yushiro | OK, let's move on. | 14:16 |
yushiro | 2. [WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:17 |
yushiro | I think there is no update for this patch as of now. | 14:17 |
yushiro | annp and I will follow. | 14:18 |
yushiro | next | 14:18 |
yushiro | 3. Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ | 14:18 |
annp | +1 | 14:18 |
SridarK | i think on the Remote fwg - xgerman_ mentioned targetting R-2 | 14:18 |
SridarK | but sorry go ahead | 14:19 |
yushiro | SridarK, Yes, R-2 is. | 14:19 |
yushiro | I put some minor comments on this Spec. hoangcx will update ASAP :) | 14:20 |
njohnston | does that spec need to be refiled from specs/queens to specs/rocky? | 14:20 |
yushiro | njohnston, Ah, yes, correct | 14:20 |
yushiro | good catch :) | 14:20 |
SridarK | yushiro: and the plan is to target the implementation for R ? | 14:21 |
yushiro | njohnston, could you comment it on this spec as a reminder? | 14:21 |
njohnston | just did :-) | 14:21 |
yushiro | SridarK, Yes, will implement it R. In Rocky cycle, I'll try to focus on L3 logging only. I think it is possible to achieve... | 14:23 |
SridarK | ok that is good to stage it | 14:24 |
yushiro | Rocky: support L3 logging, "S" cycle: support L2 logging | 14:24 |
yushiro | OK, so forks please review the spec :) | 14:25 |
njohnston | Will do | 14:26 |
SridarK | +1 | 14:26 |
yushiro | njohnston, THX!! | 14:26 |
yushiro | 4. policy-in-code: https://governance.openstack.org/tc/goals/queens/policy-in-code.html | 14:27 |
yushiro | Sorry I'm not sure current status. Does anyone know about that? | 14:28 |
SridarK | Will take a look | 14:29 |
yushiro | SridarK, thanks | 14:30 |
yushiro | #topic Horizon support | 14:32 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:32 | |
yushiro | Today, chandan and Sarath aren't here. | 14:32 |
SridarK | yes not sure | 14:33 |
yushiro | amotoki has pushed patch to remove 'mox': https://review.openstack.org/#/q/status:open+project:openstack/neutron-fwaas-dashboard+branch:master+topic:mox-removal | 14:33 |
SridarK | SarathMekala said he will look thru some of the missing pieces and review | 14:33 |
SridarK | lets wait on that | 14:33 |
yushiro | SridarK, Sure. | 14:33 |
yushiro | Regarding to Akihiro's patches, I just rebased and deploy devstack. It worked and I think there is no pleblem. | 14:34 |
yushiro | OK, let's move on. | 14:36 |
yushiro | #topic bugs | 14:37 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:37 | |
yushiro | Today, I'd like to discuss about https://bugs.launchpad.net/neutron/+bug/1759773 | 14:37 |
openstack | Launchpad bug 1759773 in neutron "FWaaS: Invalid port error on associating L3 ports (Router in HA) to firewall group" [Undecided,Confirmed] - Assigned to Sridar Kandaswamy (skandasw) | 14:37 |
SridarK | thx yushiro | 14:37 |
yushiro | SridarK, plz go ahead. | 14:37 |
SridarK | so have had discussion with the submitter | 14:37 |
SridarK | and got some info from him which pointed to an issue on the validation code | 14:38 |
SridarK | we need to support HA configurations | 14:38 |
SridarK | putting a fix as such is quite straightfwd but will need to think thru the implications of HA | 14:39 |
SridarK | something we have not targetted till now | 14:39 |
SridarK | i mean fixing the validation is easy | 14:39 |
SridarK | but need to consider HA implications | 14:40 |
SridarK | will look thru more and update | 14:40 |
SridarK | once we have an handle we can look at backport strategy | 14:40 |
SridarK | the customer is in Ocata (so no backport is possible) but is willing to look to move to Queens | 14:41 |
SridarK | so they can get L2 support as well | 14:41 |
*** Swami has joined #openstack-fwaas | 14:41 | |
SridarK | ok i am done | 14:41 |
yushiro | SridarK, Thanks for your announcement! | 14:41 |
yushiro | As SridarK said, fix is so easy but need to verify with L3 HA environment. | 14:42 |
yushiro | Here is definitions of device_owner for L3: https://github.com/openstack/neutron-lib/blob/master/neutron_lib/constants.py | 14:43 |
SridarK | yushiro: +1 and we only validate basic Router interface | 14:43 |
yushiro | We are targetting to handle not only 'network:router_interface' but also 'network:router_ha_interface' | 14:43 |
SridarK | once the customer provided the port attributes - i could immediately see the issue on validation | 14:44 |
yushiro | 'network:ha_router_replicated_interface' is for keepalive interface b/w HA routers I think. | 14:45 |
SridarK | I will propose a patch for fixing the validation - and we can discuss further | 14:45 |
yushiro | SridarK, OK, thanks. | 14:46 |
yushiro | Swami, Hi! Thanks for backporting https://review.openstack.org/#/c/554294/ | 14:47 |
SridarK | Swami: yes thx for taking care of the long standing DVR related fix | 14:47 |
SridarK | Swami: i think we had been out of sync with the ns changes | 14:48 |
Swami | SridarK: no problem | 14:51 |
Swami | yushiro: you are welcome | 14:51 |
yushiro | :) | 14:51 |
yushiro | #topic Open Discussion | 14:51 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:51 | |
yushiro | ndefigueiredo is not here today.. He proposes stateless firewall: https://bugs.launchpad.net/neutron/+bug/1753466 | 14:53 |
openstack | Launchpad bug 1753466 in neutron "[RFE] Support stateless security groups" [Wishlist,Confirmed] - Assigned to Giel Dops (nuage.gieldops) | 14:53 |
SridarK | yes not sure on the approach with another bp in relation to SG | 14:53 |
yushiro | Yes,, | 14:54 |
SridarK | but last time ndefigueiredo felt that his thought was more in line with fwaas | 14:54 |
yushiro | +1 | 14:55 |
njohnston | Is there much left as far as moving to neutron-lib? | 14:57 |
SridarK | njohnston: I am not sure much happened after u left | 14:58 |
njohnston | Ok, I may take a look | 14:58 |
SridarK | njohnston: but good point to do a scan, u had defnitely taken care of a lot of that | 14:59 |
yushiro | njohnston, I think this exception should move into neutron-lib :) https://github.com/openstack/neutron-fwaas/blob/master/neutron_fwaas/common/exceptions.py | 14:59 |
njohnston | I’ll take a look, thanks yushiro! | 15:00 |
yushiro | NP :) | 15:00 |
yushiro | Oh, this is our timelimit | 15:00 |
yushiro | #endmeeting | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu Mar 29 15:00:25 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-03-29-13.59.html | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-03-29-13.59.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-03-29-13.59.log.html | 15:00 |
SridarK | thanks all for joining | 15:00 |
yushiro | Thanks guys!! Good night :p | 15:00 |
*** yushiro has quit IRC | 15:04 | |
*** hoangcx_ has quit IRC | 15:07 | |
*** annp has quit IRC | 15:11 | |
*** velizarx has quit IRC | 15:35 | |
*** Swami has quit IRC | 15:56 | |
*** yamamoto has quit IRC | 16:04 | |
*** yamamoto has joined #openstack-fwaas | 16:07 | |
openstackgerrit | Merged openstack/neutron-fwaas master: Fix devstack configuration for fwaas v2 https://review.openstack.org/527040 | 16:22 |
*** yamamoto has quit IRC | 16:24 | |
*** yamamoto has joined #openstack-fwaas | 16:29 | |
*** yamamoto has quit IRC | 16:34 | |
*** SridarK has quit IRC | 16:45 | |
*** AlexeyAbashkin has quit IRC | 16:53 | |
*** yamamoto has joined #openstack-fwaas | 17:30 | |
*** yamamoto has quit IRC | 17:37 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 18:18 | |
*** AlexeyAbashkin has quit IRC | 18:23 | |
*** yamamoto has joined #openstack-fwaas | 18:33 | |
*** yamamoto has quit IRC | 18:38 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 19:08 | |
*** AlexeyAbashkin has quit IRC | 19:13 | |
*** yamamoto has joined #openstack-fwaas | 19:35 | |
*** yamamoto has quit IRC | 19:40 | |
*** yamamoto has joined #openstack-fwaas | 20:37 | |
*** yamamoto has quit IRC | 20:42 | |
*** yamamoto has joined #openstack-fwaas | 21:38 | |
*** yamamoto has quit IRC | 21:44 | |
*** yamamoto has joined #openstack-fwaas | 22:40 | |
*** yamamoto has quit IRC | 22:45 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 23:08 | |
*** AlexeyAbashkin has quit IRC | 23:12 | |
*** yamamoto has joined #openstack-fwaas | 23:41 | |
*** yamamoto has quit IRC | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!