| *** yamamoto has joined #openstack-fwaas | 00:34 | |
| *** yamamoto has quit IRC | 00:39 | |
| openstackgerrit | Yushiro FURUKAWA proposed openstack/neutron-fwaas master: Remove unused plugin.get_plugin_name() https://review.openstack.org/557669 | 00:40 |
|---|---|---|
| *** hoangcx has joined #openstack-fwaas | 00:43 | |
| *** obre_ has joined #openstack-fwaas | 00:46 | |
| *** obre has quit IRC | 00:51 | |
| *** Swami has quit IRC | 01:15 | |
| *** yamamoto has joined #openstack-fwaas | 01:35 | |
| *** yamamoto has quit IRC | 01:41 | |
| *** yamamoto has joined #openstack-fwaas | 02:37 | |
| *** yamamoto has quit IRC | 02:43 | |
| *** yamamoto has joined #openstack-fwaas | 03:39 | |
| *** yamamoto has quit IRC | 03:45 | |
| *** yamamoto has joined #openstack-fwaas | 03:52 | |
| *** wkite has joined #openstack-fwaas | 04:22 | |
| *** wkite has quit IRC | 04:35 | |
| *** wkite has joined #openstack-fwaas | 04:36 | |
| *** wkite has quit IRC | 04:38 | |
| *** Swami has joined #openstack-fwaas | 06:07 | |
| *** AlexeyAbashkin has joined #openstack-fwaas | 06:38 | |
| *** Swami has quit IRC | 06:44 | |
| *** hoangcx has quit IRC | 06:47 | |
| *** hoangcx has joined #openstack-fwaas | 06:50 | |
| *** velizarx has joined #openstack-fwaas | 07:01 | |
| *** velizarx has quit IRC | 07:18 | |
| *** velizarx has joined #openstack-fwaas | 07:57 | |
| *** xgerman_ has quit IRC | 08:25 | |
| *** xgerman_ has joined #openstack-fwaas | 08:25 | |
| *** velizarx has quit IRC | 09:14 | |
| *** velizarx has joined #openstack-fwaas | 09:15 | |
| *** velizarx has quit IRC | 09:27 | |
| *** velizarx has joined #openstack-fwaas | 09:29 | |
| *** velizarx has quit IRC | 09:59 | |
| *** velizarx has joined #openstack-fwaas | 10:01 | |
| openstackgerrit | Cuong Nguyen proposed openstack/neutron-fwaas master: [WIP] [log] Logging driver based iptables for FWaaS https://review.openstack.org/553738 | 10:04 |
| *** velizarx has quit IRC | 12:15 | |
| *** velizarx has joined #openstack-fwaas | 12:37 | |
| *** piepmatz has joined #openstack-fwaas | 12:57 | |
| *** piepmatz has quit IRC | 13:00 | |
| *** piepmatz has joined #openstack-fwaas | 13:01 | |
| *** hoangcx_ has joined #openstack-fwaas | 13:05 | |
| piepmatz | hi, I am trying to set up fwaas 2.0 in a dvr setup. the tempest tests are failing because the created router is distributed. when creating the firewall group the port validation fails because the port's device_owner is network:router_interface_distributed instead of network:router_interface. I am trying to understand if dvr + fwaas work together. a promising blueprint (https://blueprints.launchpad.net/neutron/+spec/neutron-dvr-fwaa | 13:10 |
| piepmatz | completed long ago, but those changes were done before version 2 existed. can anyone tell me if fwaas_v2 and dvr work in combination? | 13:10 |
| piepmatz | (please don't hesitate to answer when I am offline. I'll check the logs and will come back) | 13:36 |
| *** wkite has joined #openstack-fwaas | 13:49 | |
| *** ndefigueiredo has joined #openstack-fwaas | 13:51 | |
| *** chandanc has joined #openstack-fwaas | 13:53 | |
| *** yushiro has joined #openstack-fwaas | 13:57 | |
| *** SridarK has joined #openstack-fwaas | 13:57 | |
| *** annp has joined #openstack-fwaas | 13:59 | |
| SridarK | Hi FWaaS folks | 13:59 |
| chandanc | Hello All | 13:59 |
| annp | Hi All | 13:59 |
| SridarK | #startmeeting fwaas | 14:00 |
| openstack | Meeting started Thu Apr 5 14:00:01 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
| openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
| *** openstack changes topic to " (Meeting topic: fwaas)" | 14:00 | |
| openstack | The meeting name has been set to 'fwaas' | 14:00 |
| SridarK | #chair xgerman_ yushiro | 14:00 |
| openstack | Current chairs: SridarK xgerman_ yushiro | 14:00 |
| xgerman_ | o/ | 14:00 |
| SridarK | yushiro: i see u are on sched but u ran the mtg last time too | 14:00 |
| xgerman_ | yeah. it’s my turn | 14:00 |
| SridarK | ah ok | 14:01 |
| SridarK | pls go ahead xgerman_ | 14:01 |
| xgerman_ | #topic Announcements | 14:01 |
| yushiro | Ah, Thanks SridarK and xgerman_ | 14:01 |
| *** openstack changes topic to "Announcements (Meeting topic: fwaas)" | 14:01 | |
| xgerman_ | So R-1 is in two weeks | 14:01 |
| xgerman_ | time flies — | 14:01 |
| SridarK | :-) | 14:01 |
| xgerman_ | Also if you like to use your PTG code/speaker code for Vancouver registration - deadline is 5/11 | 14:02 |
| SridarK | Hope a few folks can make it to the summit | 14:04 |
| xgerman_ | there is some new proposal by keystone on how to do policies | 14:04 |
| xgerman_ | https://review.openstack.org/#/c/523973/ | 14:04 |
| xgerman_ | with the goal to make it a community goal | 14:04 |
| xgerman_ | #topic AddressGroups | 14:05 |
| *** openstack changes topic to "AddressGroups (Meeting topic: fwaas)" | 14:05 | |
| doude | hi o/ | 14:06 |
| SridarK | I wonder if any of the submitters are here | 14:06 |
| SridarK | I was hoping to see them here as in the response to the email | 14:06 |
| xgerman_ | We got approached by the OpenStack Financial Group and for them Address Groups are of uttermost importance and they filed spec | 14:07 |
| xgerman_ | #link https://review.openstack.org/#/c/557137 | 14:07 |
| wkite | i am here | 14:07 |
| xgerman_ | welcome | 14:07 |
| yushiro | wkite, Hi. Welocome to fwaas :) | 14:07 |
| SridarK | ah great hi wkite | 14:07 |
| xgerman_ | Now we already had address groups in our original spec so I am questioning if we need a new spec - thoughts? | 14:07 |
| SridarK | I think fundamentally we are in agreement on the feature | 14:08 |
| SridarK | which is why we put it in the orig spec | 14:08 |
| SridarK | but was lower priority | 14:08 |
| SridarK | i think to xgerman_'s point we only need to figure out the process | 14:09 |
| yushiro | SridarK, xgerman_ +1 | 14:09 |
| chandanc | +1 | 14:09 |
| SridarK | would a RFE be simpler to adapt the orig proposal | 14:09 |
| wkite | the address of the orion spec does not support ip range objects and multi address groups in a rule. | 14:10 |
| SridarK | wkite: agreed, that would be diffence with the new proposal | 14:11 |
| xgerman_ | well, our orig. spec is two years old so having a new one puts it top of mind | 14:12 |
| wkite | should I modify the original spec? | 14:12 |
| xgerman_ | I think we can either do the RfE or a new spec — just wanted to get consensus what works best for everybody | 14:13 |
| SridarK | An RFE will be simpler with the deviation proposed | 14:14 |
| SridarK | but we should discuss the additional support | 14:14 |
| SridarK | wkite: when do u want to target the feature implementation ? | 14:14 |
| xgerman_ | well, there is the R-2 deadline | 14:15 |
| wkite | i wrote some codes for this implementation last two months. | 14:16 |
| SridarK | wkite: ok but are u targetting to be in the R release or in the S after this cycle ? | 14:16 |
| xgerman_ | I would like to see it in R if possible | 14:17 |
| xgerman_ | but with Horizon/client/neutron-lib might be too many moving parts | 14:17 |
| SridarK | xgerman_: +1 | 14:18 |
| yushiro | xgerman_, +1 Yes, it is not so small.. | 14:18 |
| wkite | xgerman_: +1 | 14:18 |
| SridarK | atlease will need to have OSC | 14:18 |
| yushiro | SridarK, +1 | 14:18 |
| SridarK | wkite: also we will need to evaluate the driver side of things | 14:18 |
| wkite | SridarK, +1 | 14:19 |
| chandanc | +1 | 14:19 |
| SridarK | maybe for now shall we continue the conversation on the spec | 14:19 |
| xgerman_ | +1 | 14:19 |
| SridarK | It seems the spec may be a better place to capture the comments than an RFE | 14:19 |
| xgerman_ | #action cores will review spec | 14:20 |
| SridarK | xgerman_: +1 | 14:20 |
| yushiro | +1+1 | 14:20 |
| SridarK | wkite: lets do that then - we can continue on the spec | 14:21 |
| wkite | +1 | 14:21 |
| njohnston | +1 | 14:21 |
| xgerman_ | #topic Rocky | 14:21 |
| *** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:21 | |
| SridarK | wkite: will u be able to attend this mtg going fwd ? | 14:21 |
| wkite | mtg? | 14:22 |
| xgerman_ | our Thursday FWaaS meeting | 14:22 |
| SridarK | xgerman_: +1 | 14:22 |
| wkite | no problem | 14:23 |
| SridarK | ok great | 14:23 |
| yushiro | wkite, http://eavesdrop.openstack.org/#Firewall_as_a_Service_(FWaaS)_Team_Meeting | 14:23 |
| annp | +1 | 14:24 |
| xgerman_ | 1. Pluggable backend driver https://review.openstack.org/#/c/480265/ | 14:24 |
| xgerman_ | I have seen doude | 14:24 |
| xgerman_ | posting a new revision | 14:24 |
| SridarK | doude: I will publish some comments soon - i am on the review | 14:25 |
| yushiro | I've tested doube's patch with multi-nodes | 14:25 |
| xgerman_ | nice | 14:26 |
| SridarK | yushiro: great, things good ? | 14:26 |
| yushiro | SridarK, Yeah, but I found that there was an issue about devstack plugin. Some configuration didn't set correctly in compute-node. | 14:27 |
| doude | ok xgerman_ | 14:27 |
| SridarK | yushiro: hmm should we address that separately ? | 14:27 |
| yushiro | SridarK, Yes, there is no relation with this patch. | 14:28 |
| doude | yushiro: I saw you post some error log in the etherpad, did you find issues? | 14:28 |
| yushiro | doude, Now I'm finding but I think there is no relation with this patch. | 14:29 |
| doude | #link https://etherpad.openstack.org/p/fwaas-pluggable-backend-testing | 14:29 |
| yushiro | chandanc, annp Did you remember this error message?? I think that was race: OVSFWaaSPortNotFound: Port d74ff04c-4f81-459c-9f18-0b96f81a8c3c is not managed by this agent. | 14:29 |
| chandanc | yushiro: sorry i dont remember, but can get back | 14:30 |
| doude | ok yushiro | 14:30 |
| yushiro | annp, Can you try to deploy multi-node with master branch? I'd like to verify this error doesn't relate to doube's patch. | 14:31 |
| annp | Yushiro, sure. I'll do it. | 14:32 |
| annp | Yushiro, let's discuss tomorrow. :-) | 14:32 |
| xgerman_ | 2. [WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:34 |
| yushiro | SridarK, in multi-node case, there was OVSFWaaSPortNotFound and changed "ERROR" status for fwg but finally will change "ACTIVE". So, please let me check more.. | 14:34 |
| SridarK | yushiro: ok | 14:35 |
| xgerman_ | I am still aiming for R-2 but things have been busy | 14:37 |
| SridarK | xgerman_: sounds good | 14:38 |
| yushiro | +1 | 14:38 |
| xgerman_ | 3. Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ | 14:38 |
| xgerman_ | annp: and njohnston commented on that | 14:39 |
| yushiro | annp, njohnston Thanks. | 14:39 |
| xgerman_ | +1 | 14:39 |
| xgerman_ | it looks like we are close | 14:39 |
| yushiro | annp, You specified iptables format by using NFLOG ? | 14:40 |
| annp | yushiro, you're welcome. :-) | 14:40 |
| SridarK | and the plan is support L3 first ? | 14:40 |
| annp | Yushiro, yes. What do you think about iptables structure? | 14:41 |
| yushiro | annp, I have some opinion. But let's discuss after or tomorrow. | 14:41 |
| annp | Sridark, yes, we intend to support L3 first. | 14:42 |
| SridarK | annp: thx | 14:42 |
| annp | Yushiro, ok. Let's discuss in tomorrow. | 14:42 |
| yushiro | If necessary, do we need to describe "L3 first" on the spec? | 14:42 |
| annp | I think it should be mentioned in spec as our target in rocky | 14:43 |
| SridarK | yushiro: annp: i will add a comment | 14:44 |
| yushiro | OK | 14:44 |
| annp | Do you think so?:) | 14:44 |
| yushiro | SridarK, Thanks :) | 14:44 |
| hoangcx_ | I don't think we need to mention that in the spec | 14:44 |
| annp | Sridark, thanks. | 14:44 |
| SridarK | I think it will be good to call out the implementation phases | 14:45 |
| SridarK | and then we can have reno cover some of it | 14:45 |
| hoangcx_ | +1 | 14:45 |
| xgerman_ | +1 | 14:45 |
| SridarK | so we dont have to have a new spec for L2 | 14:45 |
| yushiro | Aha, OK. Thanks hoangcx_ | 14:46 |
| hoangcx_ | xgerman_: right, that is my opinion | 14:46 |
| *** annp has quit IRC | 14:46 | |
| yushiro | OK, we can define "community decision". Anyway, let's focus on L3 logging first :) | 14:47 |
| xgerman_ | +1 | 14:47 |
| xgerman_ | code talks | 14:47 |
| SridarK | :-) | 14:47 |
| njohnston | :-) | 14:48 |
| *** annp_ has joined #openstack-fwaas | 14:49 | |
| *** annp__ has joined #openstack-fwaas | 14:49 | |
| yushiro | welcome | 14:50 |
| annp__ | sorry, my connection is lost suddently. :( | 14:50 |
| xgerman_ | 4. policy-in-code: https://governance.openstack.org/tc/goals/queens/policy-in-code.html | 14:50 |
| xgerman_ | I think this relates to the link I posted earlier | 14:50 |
| yushiro | yes | 14:51 |
| xgerman_ | so if we can defer until the dust settles that would be good — otherwise we might face rework | 14:52 |
| xgerman_ | ok, with 7 min left let’s move to | 14:53 |
| xgerman_ | #OpenDiscussion | 14:54 |
| xgerman_ | #topic OpenDiscussion | 14:54 |
| *** openstack changes topic to "OpenDiscussion (Meeting topic: fwaas)" | 14:54 | |
| yushiro | doude, I'll comment your patch ASAP if I finished multi-node testing. | 14:56 |
| doude | great yushiro | 14:56 |
| SridarK | doude: same here - just give me a day to finish | 14:57 |
| doude | ok next week will be a busy week for me :) | 14:57 |
| SridarK | Do folks have clarity on if they can make the summit | 14:57 |
| SridarK | doude: :-) yes we will push for R-1 | 14:57 |
| yushiro | doude, +busy +1 :) | 14:57 |
| xgerman_ | I will be there at the summit | 14:58 |
| yushiro | Next week, we can get reply from TSP. Hopefully I can go there but not sure now... | 14:58 |
| xgerman_ | fingers crossed | 14:58 |
| SridarK | that seems to be for everything now a days, my fingers are now realigned :-) | 14:59 |
| yushiro | I wish!! | 14:59 |
| xgerman_ | yeah, they rebranded the local OpenStack meeting here as OpenInfrastructure | 15:00 |
| SridarK | hmm very interesting | 15:00 |
| xgerman_ | time — | 15:01 |
| yushiro | :) | 15:01 |
| xgerman_ | #endmeeting | 15:01 |
| *** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:01 | |
| njohnston | o/ | 15:01 |
| openstack | Meeting ended Thu Apr 5 15:01:10 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:01 |
| openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.html | 15:01 |
| openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.txt | 15:01 |
| SridarK | Bye all | 15:01 |
| openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.log.html | 15:01 |
| piepmatz | now that everyone is here, please excuse re-posting my earlier question: hi, I am trying to set up fwaas 2.0 in a dvr setup. the tempest tests are failing because the created router is distributed. when creating the firewall group the port validation fails because the port's device_owner is network:router_interface_distributed instead of network:router_interface. I am trying to understand if dvr + fwaas work together. a promising b | 15:01 |
| piepmatz | (https://blueprints.launchpad.net/neutron/+spec/neutron-dvr-fwaas) was completed long ago, but those changes were done before version 2 existed. can anyone tell me if fwaas_v2 and dvr work in combination? | 15:01 |
| xgerman_ | thanks everybody | 15:01 |
| yushiro | bye bye | 15:02 |
| SridarK | piepmatz: hi | 15:02 |
| *** hoangcx_ has quit IRC | 15:02 | |
| piepmatz | SridarK: hi :) | 15:02 |
| SridarK | piepmatz: i am looking into a validation issue with HA scenario | 15:02 |
| doude | I could not attend the summit | 15:03 |
| *** Swami has joined #openstack-fwaas | 15:03 | |
| *** chandanc has quit IRC | 15:03 | |
| piepmatz | SridarK: How is HA related to this? | 15:04 |
| SridarK | piepmatz: It is not | 15:04 |
| SridarK | piepmatz: it is in the validation issue | 15:04 |
| SridarK | piepmatz: let me work on this | 15:04 |
| piepmatz | SridarK: so does this mean that fwaas actually should work with dvr but at the moment some doesn't? | 15:05 |
| piepmatz | *somehow | 15:05 |
| SridarK | piepmatz: it can only filter the N - S traffic | 15:05 |
| SridarK | piepmatz: and not any E - W (as we can have assymetric routing and conntrack will have issues) | 15:06 |
| piepmatz | SridarK: ok, that a limitation I can live with. I was just wondering if it can work at all if the port validation accepts nothing but network:router_interface as device_owner | 15:07 |
| SridarK | piepmatz: we did have some checks to ensure that N - S would always works in a DVR env | 15:07 |
| piepmatz | well, what I said is not right, "compute:*" is also fine. | 15:08 |
| SridarK | piepmatz: currently that is the validation in place - we do need to fix that, but let me understand if we had a change in device_owner | 15:09 |
| SridarK | piepmatz: yes as we can support on L2 ports now | 15:09 |
| SridarK | i assume u are on Queens ? | 15:09 |
| piepmatz | ocata :/ | 15:09 |
| SridarK | piepmatz: hm ok | 15:09 |
| SridarK | piepmatz: le me dig more on this | 15:10 |
| piepmatz | well, I also tried with the master branch, same problem | 15:10 |
| SridarK | piepmatz: do u want to file a bug - or i can file one too ? | 15:10 |
| piepmatz | the validation was introduced in https://review.openstack.org/#/c/323971/ | 15:10 |
| SridarK | piepmatz: yes | 15:11 |
| *** yushiro has quit IRC | 15:11 | |
| piepmatz | SridarK: please file it. thanks :) | 15:11 |
| SridarK | piepmatz: will do | 15:12 |
| *** chandanc has joined #openstack-fwaas | 15:12 | |
| SridarK | piepmatz: what will be the best way to reach u ? | 15:12 |
| piepmatz | SridarK: email: dev@matthias-bastian.de | 15:13 |
| SridarK | piepmatz: got it, i will keep u posted so u can track the bug and will also send u an email so u can get a hold of me if u dont find me here | 15:14 |
| piepmatz | SridarK: sound good, thanks a lot! | 15:14 |
| SridarK | piepmatz: no worries thx | 15:14 |
| piepmatz | I actually never tried the ocata release of neutron-fwaas. I started straight with the latest release on PyPI and later on the master branch. so I don't know how the problem behaves in ocata. | 15:17 |
| SridarK | piepmatz: the changes with compute will only be avail from Queens onwards | 15:18 |
| SridarK | Ocata only checks with device_owner:router_interface | 15:19 |
| SridarK | what i need to check is DVR had a change with the device_owner getting marked as router_interface_distributed | 15:19 |
| SridarK | I recall doing a check differently a while back to ensure that we work with DVR | 15:20 |
| SridarK | will validate it | 15:20 |
| piepmatz | SridarK: thx again! | 15:21 |
| SridarK | piepmatz: no worries at all - will get u an email late in my day (i am in US Pacific time zone) | 15:22 |
| SridarK | thx for bringing it up | 15:22 |
| *** annp__ has quit IRC | 15:28 | |
| *** openstackgerrit has quit IRC | 15:34 | |
| *** wkite has quit IRC | 15:35 | |
| *** annp_ has quit IRC | 15:36 | |
| *** Swami has quit IRC | 15:54 | |
| *** velizarx has quit IRC | 15:56 | |
| *** AlexeyAbashkin has quit IRC | 16:10 | |
| *** annp has joined #openstack-fwaas | 16:12 | |
| *** annp has quit IRC | 16:13 | |
| piepmatz | SridarK: in cental europe it's time to go home. have a good one! | 16:47 |
| *** piepmatz has quit IRC | 16:47 | |
| *** ndefigueiredo has quit IRC | 17:00 | |
| *** SridarK has quit IRC | 17:17 | |
| *** SumitNaiksatam has joined #openstack-fwaas | 17:34 | |
| *** AlexeyAbashkin has joined #openstack-fwaas | 17:34 | |
| *** AlexeyAbashkin has quit IRC | 17:38 | |
| *** yamamoto has quit IRC | 19:45 | |
| *** yamamoto has joined #openstack-fwaas | 20:46 | |
| *** yamamoto has quit IRC | 20:52 | |
| *** Swami has joined #openstack-fwaas | 21:28 | |
| *** yamamoto has joined #openstack-fwaas | 21:48 | |
| *** yamamoto has quit IRC | 21:53 | |
| *** yamamoto has joined #openstack-fwaas | 22:49 | |
| *** yamamoto has quit IRC | 22:55 | |
| *** threestrands has joined #openstack-fwaas | 23:02 | |
| *** threestrands has quit IRC | 23:02 | |
| *** threestrands has joined #openstack-fwaas | 23:02 | |
| *** SumitNaiksatam has quit IRC | 23:26 | |
| *** yamamoto has joined #openstack-fwaas | 23:51 | |
| *** yamamoto has quit IRC | 23:57 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!