*** yamamoto has joined #openstack-fwaas | 00:34 | |
*** yamamoto has quit IRC | 00:39 | |
openstackgerrit | Yushiro FURUKAWA proposed openstack/neutron-fwaas master: Remove unused plugin.get_plugin_name() https://review.openstack.org/557669 | 00:40 |
---|---|---|
*** hoangcx has joined #openstack-fwaas | 00:43 | |
*** obre_ has joined #openstack-fwaas | 00:46 | |
*** obre has quit IRC | 00:51 | |
*** Swami has quit IRC | 01:15 | |
*** yamamoto has joined #openstack-fwaas | 01:35 | |
*** yamamoto has quit IRC | 01:41 | |
*** yamamoto has joined #openstack-fwaas | 02:37 | |
*** yamamoto has quit IRC | 02:43 | |
*** yamamoto has joined #openstack-fwaas | 03:39 | |
*** yamamoto has quit IRC | 03:45 | |
*** yamamoto has joined #openstack-fwaas | 03:52 | |
*** wkite has joined #openstack-fwaas | 04:22 | |
*** wkite has quit IRC | 04:35 | |
*** wkite has joined #openstack-fwaas | 04:36 | |
*** wkite has quit IRC | 04:38 | |
*** Swami has joined #openstack-fwaas | 06:07 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 06:38 | |
*** Swami has quit IRC | 06:44 | |
*** hoangcx has quit IRC | 06:47 | |
*** hoangcx has joined #openstack-fwaas | 06:50 | |
*** velizarx has joined #openstack-fwaas | 07:01 | |
*** velizarx has quit IRC | 07:18 | |
*** velizarx has joined #openstack-fwaas | 07:57 | |
*** xgerman_ has quit IRC | 08:25 | |
*** xgerman_ has joined #openstack-fwaas | 08:25 | |
*** velizarx has quit IRC | 09:14 | |
*** velizarx has joined #openstack-fwaas | 09:15 | |
*** velizarx has quit IRC | 09:27 | |
*** velizarx has joined #openstack-fwaas | 09:29 | |
*** velizarx has quit IRC | 09:59 | |
*** velizarx has joined #openstack-fwaas | 10:01 | |
openstackgerrit | Cuong Nguyen proposed openstack/neutron-fwaas master: [WIP] [log] Logging driver based iptables for FWaaS https://review.openstack.org/553738 | 10:04 |
*** velizarx has quit IRC | 12:15 | |
*** velizarx has joined #openstack-fwaas | 12:37 | |
*** piepmatz has joined #openstack-fwaas | 12:57 | |
*** piepmatz has quit IRC | 13:00 | |
*** piepmatz has joined #openstack-fwaas | 13:01 | |
*** hoangcx_ has joined #openstack-fwaas | 13:05 | |
piepmatz | hi, I am trying to set up fwaas 2.0 in a dvr setup. the tempest tests are failing because the created router is distributed. when creating the firewall group the port validation fails because the port's device_owner is network:router_interface_distributed instead of network:router_interface. I am trying to understand if dvr + fwaas work together. a promising blueprint (https://blueprints.launchpad.net/neutron/+spec/neutron-dvr-fwaa | 13:10 |
piepmatz | completed long ago, but those changes were done before version 2 existed. can anyone tell me if fwaas_v2 and dvr work in combination? | 13:10 |
piepmatz | (please don't hesitate to answer when I am offline. I'll check the logs and will come back) | 13:36 |
*** wkite has joined #openstack-fwaas | 13:49 | |
*** ndefigueiredo has joined #openstack-fwaas | 13:51 | |
*** chandanc has joined #openstack-fwaas | 13:53 | |
*** yushiro has joined #openstack-fwaas | 13:57 | |
*** SridarK has joined #openstack-fwaas | 13:57 | |
*** annp has joined #openstack-fwaas | 13:59 | |
SridarK | Hi FWaaS folks | 13:59 |
chandanc | Hello All | 13:59 |
annp | Hi All | 13:59 |
SridarK | #startmeeting fwaas | 14:00 |
openstack | Meeting started Thu Apr 5 14:00:01 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:00 | |
openstack | The meeting name has been set to 'fwaas' | 14:00 |
SridarK | #chair xgerman_ yushiro | 14:00 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:00 |
xgerman_ | o/ | 14:00 |
SridarK | yushiro: i see u are on sched but u ran the mtg last time too | 14:00 |
xgerman_ | yeah. it’s my turn | 14:00 |
SridarK | ah ok | 14:01 |
SridarK | pls go ahead xgerman_ | 14:01 |
xgerman_ | #topic Announcements | 14:01 |
yushiro | Ah, Thanks SridarK and xgerman_ | 14:01 |
*** openstack changes topic to "Announcements (Meeting topic: fwaas)" | 14:01 | |
xgerman_ | So R-1 is in two weeks | 14:01 |
xgerman_ | time flies — | 14:01 |
SridarK | :-) | 14:01 |
xgerman_ | Also if you like to use your PTG code/speaker code for Vancouver registration - deadline is 5/11 | 14:02 |
SridarK | Hope a few folks can make it to the summit | 14:04 |
xgerman_ | there is some new proposal by keystone on how to do policies | 14:04 |
xgerman_ | https://review.openstack.org/#/c/523973/ | 14:04 |
xgerman_ | with the goal to make it a community goal | 14:04 |
xgerman_ | #topic AddressGroups | 14:05 |
*** openstack changes topic to "AddressGroups (Meeting topic: fwaas)" | 14:05 | |
doude | hi o/ | 14:06 |
SridarK | I wonder if any of the submitters are here | 14:06 |
SridarK | I was hoping to see them here as in the response to the email | 14:06 |
xgerman_ | We got approached by the OpenStack Financial Group and for them Address Groups are of uttermost importance and they filed spec | 14:07 |
xgerman_ | #link https://review.openstack.org/#/c/557137 | 14:07 |
wkite | i am here | 14:07 |
xgerman_ | welcome | 14:07 |
yushiro | wkite, Hi. Welocome to fwaas :) | 14:07 |
SridarK | ah great hi wkite | 14:07 |
xgerman_ | Now we already had address groups in our original spec so I am questioning if we need a new spec - thoughts? | 14:07 |
SridarK | I think fundamentally we are in agreement on the feature | 14:08 |
SridarK | which is why we put it in the orig spec | 14:08 |
SridarK | but was lower priority | 14:08 |
SridarK | i think to xgerman_'s point we only need to figure out the process | 14:09 |
yushiro | SridarK, xgerman_ +1 | 14:09 |
chandanc | +1 | 14:09 |
SridarK | would a RFE be simpler to adapt the orig proposal | 14:09 |
wkite | the address of the orion spec does not support ip range objects and multi address groups in a rule. | 14:10 |
SridarK | wkite: agreed, that would be diffence with the new proposal | 14:11 |
xgerman_ | well, our orig. spec is two years old so having a new one puts it top of mind | 14:12 |
wkite | should I modify the original spec? | 14:12 |
xgerman_ | I think we can either do the RfE or a new spec — just wanted to get consensus what works best for everybody | 14:13 |
SridarK | An RFE will be simpler with the deviation proposed | 14:14 |
SridarK | but we should discuss the additional support | 14:14 |
SridarK | wkite: when do u want to target the feature implementation ? | 14:14 |
xgerman_ | well, there is the R-2 deadline | 14:15 |
wkite | i wrote some codes for this implementation last two months. | 14:16 |
SridarK | wkite: ok but are u targetting to be in the R release or in the S after this cycle ? | 14:16 |
xgerman_ | I would like to see it in R if possible | 14:17 |
xgerman_ | but with Horizon/client/neutron-lib might be too many moving parts | 14:17 |
SridarK | xgerman_: +1 | 14:18 |
yushiro | xgerman_, +1 Yes, it is not so small.. | 14:18 |
wkite | xgerman_: +1 | 14:18 |
SridarK | atlease will need to have OSC | 14:18 |
yushiro | SridarK, +1 | 14:18 |
SridarK | wkite: also we will need to evaluate the driver side of things | 14:18 |
wkite | SridarK, +1 | 14:19 |
chandanc | +1 | 14:19 |
SridarK | maybe for now shall we continue the conversation on the spec | 14:19 |
xgerman_ | +1 | 14:19 |
SridarK | It seems the spec may be a better place to capture the comments than an RFE | 14:19 |
xgerman_ | #action cores will review spec | 14:20 |
SridarK | xgerman_: +1 | 14:20 |
yushiro | +1+1 | 14:20 |
SridarK | wkite: lets do that then - we can continue on the spec | 14:21 |
wkite | +1 | 14:21 |
njohnston | +1 | 14:21 |
xgerman_ | #topic Rocky | 14:21 |
*** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:21 | |
SridarK | wkite: will u be able to attend this mtg going fwd ? | 14:21 |
wkite | mtg? | 14:22 |
xgerman_ | our Thursday FWaaS meeting | 14:22 |
SridarK | xgerman_: +1 | 14:22 |
wkite | no problem | 14:23 |
SridarK | ok great | 14:23 |
yushiro | wkite, http://eavesdrop.openstack.org/#Firewall_as_a_Service_(FWaaS)_Team_Meeting | 14:23 |
annp | +1 | 14:24 |
xgerman_ | 1. Pluggable backend driver https://review.openstack.org/#/c/480265/ | 14:24 |
xgerman_ | I have seen doude | 14:24 |
xgerman_ | posting a new revision | 14:24 |
SridarK | doude: I will publish some comments soon - i am on the review | 14:25 |
yushiro | I've tested doube's patch with multi-nodes | 14:25 |
xgerman_ | nice | 14:26 |
SridarK | yushiro: great, things good ? | 14:26 |
yushiro | SridarK, Yeah, but I found that there was an issue about devstack plugin. Some configuration didn't set correctly in compute-node. | 14:27 |
doude | ok xgerman_ | 14:27 |
SridarK | yushiro: hmm should we address that separately ? | 14:27 |
yushiro | SridarK, Yes, there is no relation with this patch. | 14:28 |
doude | yushiro: I saw you post some error log in the etherpad, did you find issues? | 14:28 |
yushiro | doude, Now I'm finding but I think there is no relation with this patch. | 14:29 |
doude | #link https://etherpad.openstack.org/p/fwaas-pluggable-backend-testing | 14:29 |
yushiro | chandanc, annp Did you remember this error message?? I think that was race: OVSFWaaSPortNotFound: Port d74ff04c-4f81-459c-9f18-0b96f81a8c3c is not managed by this agent. | 14:29 |
chandanc | yushiro: sorry i dont remember, but can get back | 14:30 |
doude | ok yushiro | 14:30 |
yushiro | annp, Can you try to deploy multi-node with master branch? I'd like to verify this error doesn't relate to doube's patch. | 14:31 |
annp | Yushiro, sure. I'll do it. | 14:32 |
annp | Yushiro, let's discuss tomorrow. :-) | 14:32 |
xgerman_ | 2. [WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:34 |
yushiro | SridarK, in multi-node case, there was OVSFWaaSPortNotFound and changed "ERROR" status for fwg but finally will change "ACTIVE". So, please let me check more.. | 14:34 |
SridarK | yushiro: ok | 14:35 |
xgerman_ | I am still aiming for R-2 but things have been busy | 14:37 |
SridarK | xgerman_: sounds good | 14:38 |
yushiro | +1 | 14:38 |
xgerman_ | 3. Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ | 14:38 |
xgerman_ | annp: and njohnston commented on that | 14:39 |
yushiro | annp, njohnston Thanks. | 14:39 |
xgerman_ | +1 | 14:39 |
xgerman_ | it looks like we are close | 14:39 |
yushiro | annp, You specified iptables format by using NFLOG ? | 14:40 |
annp | yushiro, you're welcome. :-) | 14:40 |
SridarK | and the plan is support L3 first ? | 14:40 |
annp | Yushiro, yes. What do you think about iptables structure? | 14:41 |
yushiro | annp, I have some opinion. But let's discuss after or tomorrow. | 14:41 |
annp | Sridark, yes, we intend to support L3 first. | 14:42 |
SridarK | annp: thx | 14:42 |
annp | Yushiro, ok. Let's discuss in tomorrow. | 14:42 |
yushiro | If necessary, do we need to describe "L3 first" on the spec? | 14:42 |
annp | I think it should be mentioned in spec as our target in rocky | 14:43 |
SridarK | yushiro: annp: i will add a comment | 14:44 |
yushiro | OK | 14:44 |
annp | Do you think so?:) | 14:44 |
yushiro | SridarK, Thanks :) | 14:44 |
hoangcx_ | I don't think we need to mention that in the spec | 14:44 |
annp | Sridark, thanks. | 14:44 |
SridarK | I think it will be good to call out the implementation phases | 14:45 |
SridarK | and then we can have reno cover some of it | 14:45 |
hoangcx_ | +1 | 14:45 |
xgerman_ | +1 | 14:45 |
SridarK | so we dont have to have a new spec for L2 | 14:45 |
yushiro | Aha, OK. Thanks hoangcx_ | 14:46 |
hoangcx_ | xgerman_: right, that is my opinion | 14:46 |
*** annp has quit IRC | 14:46 | |
yushiro | OK, we can define "community decision". Anyway, let's focus on L3 logging first :) | 14:47 |
xgerman_ | +1 | 14:47 |
xgerman_ | code talks | 14:47 |
SridarK | :-) | 14:47 |
njohnston | :-) | 14:48 |
*** annp_ has joined #openstack-fwaas | 14:49 | |
*** annp__ has joined #openstack-fwaas | 14:49 | |
yushiro | welcome | 14:50 |
annp__ | sorry, my connection is lost suddently. :( | 14:50 |
xgerman_ | 4. policy-in-code: https://governance.openstack.org/tc/goals/queens/policy-in-code.html | 14:50 |
xgerman_ | I think this relates to the link I posted earlier | 14:50 |
yushiro | yes | 14:51 |
xgerman_ | so if we can defer until the dust settles that would be good — otherwise we might face rework | 14:52 |
xgerman_ | ok, with 7 min left let’s move to | 14:53 |
xgerman_ | #OpenDiscussion | 14:54 |
xgerman_ | #topic OpenDiscussion | 14:54 |
*** openstack changes topic to "OpenDiscussion (Meeting topic: fwaas)" | 14:54 | |
yushiro | doude, I'll comment your patch ASAP if I finished multi-node testing. | 14:56 |
doude | great yushiro | 14:56 |
SridarK | doude: same here - just give me a day to finish | 14:57 |
doude | ok next week will be a busy week for me :) | 14:57 |
SridarK | Do folks have clarity on if they can make the summit | 14:57 |
SridarK | doude: :-) yes we will push for R-1 | 14:57 |
yushiro | doude, +busy +1 :) | 14:57 |
xgerman_ | I will be there at the summit | 14:58 |
yushiro | Next week, we can get reply from TSP. Hopefully I can go there but not sure now... | 14:58 |
xgerman_ | fingers crossed | 14:58 |
SridarK | that seems to be for everything now a days, my fingers are now realigned :-) | 14:59 |
yushiro | I wish!! | 14:59 |
xgerman_ | yeah, they rebranded the local OpenStack meeting here as OpenInfrastructure | 15:00 |
SridarK | hmm very interesting | 15:00 |
xgerman_ | time — | 15:01 |
yushiro | :) | 15:01 |
xgerman_ | #endmeeting | 15:01 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:01 | |
njohnston | o/ | 15:01 |
openstack | Meeting ended Thu Apr 5 15:01:10 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.html | 15:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.txt | 15:01 |
SridarK | Bye all | 15:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-05-14.00.log.html | 15:01 |
piepmatz | now that everyone is here, please excuse re-posting my earlier question: hi, I am trying to set up fwaas 2.0 in a dvr setup. the tempest tests are failing because the created router is distributed. when creating the firewall group the port validation fails because the port's device_owner is network:router_interface_distributed instead of network:router_interface. I am trying to understand if dvr + fwaas work together. a promising b | 15:01 |
piepmatz | (https://blueprints.launchpad.net/neutron/+spec/neutron-dvr-fwaas) was completed long ago, but those changes were done before version 2 existed. can anyone tell me if fwaas_v2 and dvr work in combination? | 15:01 |
xgerman_ | thanks everybody | 15:01 |
yushiro | bye bye | 15:02 |
SridarK | piepmatz: hi | 15:02 |
*** hoangcx_ has quit IRC | 15:02 | |
piepmatz | SridarK: hi :) | 15:02 |
SridarK | piepmatz: i am looking into a validation issue with HA scenario | 15:02 |
doude | I could not attend the summit | 15:03 |
*** Swami has joined #openstack-fwaas | 15:03 | |
*** chandanc has quit IRC | 15:03 | |
piepmatz | SridarK: How is HA related to this? | 15:04 |
SridarK | piepmatz: It is not | 15:04 |
SridarK | piepmatz: it is in the validation issue | 15:04 |
SridarK | piepmatz: let me work on this | 15:04 |
piepmatz | SridarK: so does this mean that fwaas actually should work with dvr but at the moment some doesn't? | 15:05 |
piepmatz | *somehow | 15:05 |
SridarK | piepmatz: it can only filter the N - S traffic | 15:05 |
SridarK | piepmatz: and not any E - W (as we can have assymetric routing and conntrack will have issues) | 15:06 |
piepmatz | SridarK: ok, that a limitation I can live with. I was just wondering if it can work at all if the port validation accepts nothing but network:router_interface as device_owner | 15:07 |
SridarK | piepmatz: we did have some checks to ensure that N - S would always works in a DVR env | 15:07 |
piepmatz | well, what I said is not right, "compute:*" is also fine. | 15:08 |
SridarK | piepmatz: currently that is the validation in place - we do need to fix that, but let me understand if we had a change in device_owner | 15:09 |
SridarK | piepmatz: yes as we can support on L2 ports now | 15:09 |
SridarK | i assume u are on Queens ? | 15:09 |
piepmatz | ocata :/ | 15:09 |
SridarK | piepmatz: hm ok | 15:09 |
SridarK | piepmatz: le me dig more on this | 15:10 |
piepmatz | well, I also tried with the master branch, same problem | 15:10 |
SridarK | piepmatz: do u want to file a bug - or i can file one too ? | 15:10 |
piepmatz | the validation was introduced in https://review.openstack.org/#/c/323971/ | 15:10 |
SridarK | piepmatz: yes | 15:11 |
*** yushiro has quit IRC | 15:11 | |
piepmatz | SridarK: please file it. thanks :) | 15:11 |
SridarK | piepmatz: will do | 15:12 |
*** chandanc has joined #openstack-fwaas | 15:12 | |
SridarK | piepmatz: what will be the best way to reach u ? | 15:12 |
piepmatz | SridarK: email: dev@matthias-bastian.de | 15:13 |
SridarK | piepmatz: got it, i will keep u posted so u can track the bug and will also send u an email so u can get a hold of me if u dont find me here | 15:14 |
piepmatz | SridarK: sound good, thanks a lot! | 15:14 |
SridarK | piepmatz: no worries thx | 15:14 |
piepmatz | I actually never tried the ocata release of neutron-fwaas. I started straight with the latest release on PyPI and later on the master branch. so I don't know how the problem behaves in ocata. | 15:17 |
SridarK | piepmatz: the changes with compute will only be avail from Queens onwards | 15:18 |
SridarK | Ocata only checks with device_owner:router_interface | 15:19 |
SridarK | what i need to check is DVR had a change with the device_owner getting marked as router_interface_distributed | 15:19 |
SridarK | I recall doing a check differently a while back to ensure that we work with DVR | 15:20 |
SridarK | will validate it | 15:20 |
piepmatz | SridarK: thx again! | 15:21 |
SridarK | piepmatz: no worries at all - will get u an email late in my day (i am in US Pacific time zone) | 15:22 |
SridarK | thx for bringing it up | 15:22 |
*** annp__ has quit IRC | 15:28 | |
*** openstackgerrit has quit IRC | 15:34 | |
*** wkite has quit IRC | 15:35 | |
*** annp_ has quit IRC | 15:36 | |
*** Swami has quit IRC | 15:54 | |
*** velizarx has quit IRC | 15:56 | |
*** AlexeyAbashkin has quit IRC | 16:10 | |
*** annp has joined #openstack-fwaas | 16:12 | |
*** annp has quit IRC | 16:13 | |
piepmatz | SridarK: in cental europe it's time to go home. have a good one! | 16:47 |
*** piepmatz has quit IRC | 16:47 | |
*** ndefigueiredo has quit IRC | 17:00 | |
*** SridarK has quit IRC | 17:17 | |
*** SumitNaiksatam has joined #openstack-fwaas | 17:34 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 17:34 | |
*** AlexeyAbashkin has quit IRC | 17:38 | |
*** yamamoto has quit IRC | 19:45 | |
*** yamamoto has joined #openstack-fwaas | 20:46 | |
*** yamamoto has quit IRC | 20:52 | |
*** Swami has joined #openstack-fwaas | 21:28 | |
*** yamamoto has joined #openstack-fwaas | 21:48 | |
*** yamamoto has quit IRC | 21:53 | |
*** yamamoto has joined #openstack-fwaas | 22:49 | |
*** yamamoto has quit IRC | 22:55 | |
*** threestrands has joined #openstack-fwaas | 23:02 | |
*** threestrands has quit IRC | 23:02 | |
*** threestrands has joined #openstack-fwaas | 23:02 | |
*** SumitNaiksatam has quit IRC | 23:26 | |
*** yamamoto has joined #openstack-fwaas | 23:51 | |
*** yamamoto has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!