*** yamamoto has joined #openstack-fwaas | 00:47 | |
*** yamamoto has quit IRC | 00:52 | |
*** hoangcx has joined #openstack-fwaas | 00:57 | |
*** openstackgerrit has quit IRC | 05:48 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 05:58 | |
*** threestrands has joined #openstack-fwaas | 06:05 | |
*** threestrands has quit IRC | 06:05 | |
*** threestrands has joined #openstack-fwaas | 06:05 | |
*** hoangcx has quit IRC | 06:20 | |
*** hoangcx has joined #openstack-fwaas | 06:21 | |
*** AlexeyAbashkin has quit IRC | 06:24 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 06:35 | |
*** AlexeyAbashkin has quit IRC | 06:44 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 07:01 | |
*** yamamoto has joined #openstack-fwaas | 07:05 | |
*** piepmatz has joined #openstack-fwaas | 07:50 | |
*** yamamoto has quit IRC | 08:17 | |
*** AlexeyAbashkin has quit IRC | 08:29 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:30 | |
*** yamamoto has joined #openstack-fwaas | 08:32 | |
*** yamamoto has quit IRC | 08:36 | |
*** piepmatz has quit IRC | 09:16 | |
*** yamamoto has joined #openstack-fwaas | 09:46 | |
*** yamamoto has quit IRC | 09:48 | |
*** openstackgerrit has joined #openstack-fwaas | 09:48 | |
openstackgerrit | Cao Xuan Hoang proposed openstack/neutron-fwaas master: [log]: Add rpc stuff for logging https://review.openstack.org/530715 | 09:48 |
---|---|---|
*** yamamoto has joined #openstack-fwaas | 09:49 | |
*** yamamoto has quit IRC | 09:52 | |
openstackgerrit | Cuong Nguyen proposed openstack/neutron-fwaas master: [WIP] Add log validator for FWaaS side https://review.openstack.org/532792 | 09:53 |
*** yamamoto has joined #openstack-fwaas | 09:54 | |
*** yamamoto has quit IRC | 10:00 | |
*** yamamoto has joined #openstack-fwaas | 10:01 | |
*** AlexeyAbashkin has quit IRC | 10:10 | |
*** hoangcx has quit IRC | 10:12 | |
*** threestrands has quit IRC | 10:24 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 10:53 | |
*** yamamoto has quit IRC | 10:56 | |
*** yamamoto has joined #openstack-fwaas | 11:02 | |
*** yamamoto has quit IRC | 11:03 | |
*** yamamoto has joined #openstack-fwaas | 11:08 | |
*** yamamoto has quit IRC | 11:11 | |
*** yamamoto has joined #openstack-fwaas | 11:11 | |
*** yamamoto has quit IRC | 11:33 | |
*** AlexeyAbashkin has quit IRC | 12:28 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 12:29 | |
*** yamamoto has joined #openstack-fwaas | 12:30 | |
*** yamamoto has quit IRC | 12:35 | |
openstackgerrit | Merged openstack/neutron-fwaas master: Fix pep8 new warnings https://review.openstack.org/560303 | 12:47 |
*** yamamoto has joined #openstack-fwaas | 12:47 | |
*** yamamoto has quit IRC | 12:49 | |
*** hoangcx has joined #openstack-fwaas | 12:57 | |
*** yamamoto has joined #openstack-fwaas | 13:01 | |
*** yamamoto has quit IRC | 13:01 | |
*** yamamoto has joined #openstack-fwaas | 13:05 | |
*** yamamoto has quit IRC | 13:09 | |
*** yamamoto has joined #openstack-fwaas | 13:21 | |
*** yamamoto has quit IRC | 13:24 | |
*** yamamoto has joined #openstack-fwaas | 13:43 | |
*** yamamoto has quit IRC | 13:44 | |
*** SridarK has joined #openstack-fwaas | 13:48 | |
*** wkite has joined #openstack-fwaas | 13:48 | |
*** yamamoto has joined #openstack-fwaas | 13:48 | |
*** yamamoto has quit IRC | 13:49 | |
*** yamamoto has joined #openstack-fwaas | 13:49 | |
SridarK | Hi FWaaS folks | 13:59 |
*** chandanc has joined #openstack-fwaas | 13:59 | |
*** annp has joined #openstack-fwaas | 13:59 | |
SridarK | #startmeeting fwaas | 13:59 |
openstack | Meeting started Thu Apr 12 13:59:51 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 13:59 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 13:59 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 13:59 | |
openstack | The meeting name has been set to 'fwaas' | 13:59 |
SridarK | #chair xgerman_ | 14:00 |
openstack | Current chairs: SridarK xgerman_ | 14:00 |
SridarK | yushiro will not be able to join today | 14:00 |
annp | hi | 14:00 |
chandanc | Hello All | 14:00 |
SridarK | We are nearing Rocky R-1 milestone | 14:01 |
xgerman_ | o/ | 14:02 |
SridarK | https://releases.openstack.org/rocky/schedule.html | 14:02 |
*** wkite has quit IRC | 14:03 | |
SridarK | xgerman_: any other announcements that u would like to bring up ? | 14:03 |
*** wkite has joined #openstack-fwaas | 14:03 | |
xgerman_ | for the Vancouver people there is a CI/CD summit colocated with the OopenStack summit | 14:03 |
xgerman_ | #link https://www.openstack.org/news/view/376/opendev-cicd-schedule-now-live-collaborative-technical-event-focuses-on-jenkins-spinnaker-zuul-and-more | 14:04 |
SridarK | xgerman_: oh that is interesting, do u know if the summit registration covers that ? | 14:04 |
xgerman_ | yep, covered with the OpenStack pass | 14:05 |
SridarK | nice, thx for that info xgerman_ | 14:05 |
wkite | Excuse me, what might I have missed? | 14:06 |
SridarK | wkite: will u be at the summit in Vancouver ? | 14:06 |
wkite | This is unlikely | 14:07 |
SridarK | wkite: if so check out the link above for a CI/CD summit that happens colocated | 14:07 |
SridarK | wkite: ok then no impact | 14:07 |
SridarK | but might be good to check out and if there are videos post event - u can catch up | 14:07 |
SridarK | ok lets move on | 14:08 |
SridarK | #topic Rocky: Pluggable backend Driver | 14:08 |
*** openstack changes topic to "Rocky: Pluggable backend Driver (Meeting topic: fwaas)" | 14:08 | |
SridarK | doude: pls go ahead | 14:08 |
doude | Hi | 14:08 |
SridarK | doude: thx for addressing comments | 14:09 |
doude | I had few reviews, one from you SridarK and two others | 14:09 |
doude | I answered them | 14:09 |
SridarK | #link https://review.openstack.org/#/c/480265/ | 14:10 |
doude | and for the moment no issue was reported to me | 14:10 |
SridarK | I think yushiro had some clarifications on the tests | 14:10 |
annp | doude, have you tested with your patch in multi node environemnt? | 14:10 |
doude | #link https://etherpad.openstack.org/p/fwaas-pluggable-backend-testing | 14:10 |
doude | no I did not | 14:10 |
doude | annp | 14:11 |
annp | doube, Today I tried to test your patch, I got same result as yushiro report last metting | 14:11 |
annp | doube, Exception OVSFWaaSPortNotFound was raised. | 14:12 |
doude | ok | 14:12 |
SridarK | doude: it seems yushiro did not have u in he email - just fwd-ed it to u | 14:12 |
SridarK | annp: this was on update of FWG correct ? | 14:13 |
doude | hot it now | 14:13 |
doude | got it now | 14:13 |
annp | SridarK,I have tested with master branch, I don't see OVSFWaasPortNotFound exception | 14:14 |
SridarK | annp: thx | 14:14 |
SridarK | annp: was it updating a FWG with a port ? | 14:14 |
doude | annp can you descibe step you used to reproduce it? | 14:14 |
annp | doube, SridarK, 1st: building 1 controller node and 2 compute node with doube's patch | 14:15 |
annp | then create VM, You can see log in q-agt.service | 14:16 |
annp | Default fwg status change to ERROR | 14:16 |
doude | yushiro said in his email he reproduces it in both cases: all-in-one and multi node | 14:16 |
SridarK | annp: oh ok it is on VM create (which triggers the update on FWG) | 14:17 |
doude | ok I'll look at it | 14:17 |
annp | doude, I just tested with multi node not tested with all-in-one | 14:17 |
doude | ok | 14:17 |
doude | I've a aio ready, I can try | 14:17 |
annp | SridarK, yes | 14:17 |
SridarK | annp: ok thx and as u mention, it seems yushiro sees it in all in one itself | 14:18 |
SridarK | doude: thx can u quickly check that out and debug | 14:18 |
SridarK | annp: would u mind to put a comment on gerrit as well ? | 14:18 |
annp | SridarK, No problem. I will do. | 14:19 |
SridarK | annp: thx | 14:19 |
doude | also, I've comment from NSX developer who said they already have a NSX driver for FWaaSv2 and ask if my patch will break it | 14:20 |
doude | https://review.openstack.org/#/c/480265/19/devstack/plugin.sh@47 | 14:20 |
SridarK | doude: yes I think there has to be some accompanying change but i think it may not be too bad | 14:22 |
doude | ok, but I don't get how their driver work actually | 14:22 |
doude | there is no driver interface | 14:22 |
SridarK | doude: but it will help to get that to a resolution to make sure that there is a clear path for existing users | 14:23 |
SridarK | If someone is using the community version of the pluging and only defining a backend driver - their impact should be minimal ? | 14:24 |
SridarK | just specifying the driver | 14:24 |
doude | yes | 14:24 |
SridarK | but with anyone with their version of the plugin - they will need to conform to the service driver interface | 14:25 |
doude | not sure to understand that | 14:25 |
SridarK | no they will need to specify their plugin as a flavor | 14:26 |
SridarK | doude: possibly a discussion with the reviewer to outline the changes would be good | 14:26 |
SridarK | as we dont really understand their implementation | 14:26 |
doude | ok | 14:27 |
doude | I think they implemented their own service plugin | 14:27 |
SridarK | ok | 14:27 |
doude | so event after my patch, that'll continuing to work | 14:27 |
doude | the service plugin insterface did not change with my patch | 14:28 |
SridarK | and if they want they can implement their plugin as a service driver | 14:28 |
SridarK | but as such they should be fine | 14:28 |
SridarK | ok if they are comfortable we can move on - else maybe a discussion on the channel with them will be good so u can move fwd | 14:29 |
SridarK | ok shall we move on | 14:30 |
SridarK | doude: anything else ? | 14:30 |
doude | oh no they use that driver interface https://github.com/openstack/neutron-fwaas/blob/master/neutron_fwaas/services/firewall/drivers/fwaas_base.py | 14:30 |
doude | no it's ok for me | 14:31 |
SridarK | ok | 14:32 |
SridarK | lets talk more offline | 14:32 |
doude | ok | 14:32 |
SridarK | #topic Rocky Address Group Spec | 14:32 |
*** openstack changes topic to "Rocky Address Group Spec (Meeting topic: fwaas)" | 14:32 | |
SridarK | #link https://review.openstack.org/#/c/557137/ | 14:33 |
SridarK | wkite: pls go ahead | 14:33 |
wkite | ok | 14:33 |
SridarK | I have also added a few comments | 14:33 |
wkite | in | 14:34 |
SridarK | annp: chandanc: also pls take a look in what we can support on the driver | 14:34 |
SridarK | we will need to do both iptables and ovs | 14:34 |
chandanc | sure SridarK | 14:34 |
annp | sure | 14:35 |
SridarK | or rather how we will support on the driver | 14:35 |
SridarK | wkite: i also echo njohnston 's comment on the address range | 14:35 |
SridarK | wkite: is that very critical need - defn it improves usability | 14:36 |
wkite | This is a function we need | 14:36 |
SridarK | to support arbitrary ranges not along a cidr block | 14:36 |
SridarK | wkite: ok | 14:36 |
SridarK | wkite: ok lets continue this on the review | 14:37 |
SridarK | wkite: other things u want to bring up | 14:38 |
wkite | we also need multi address groups | 14:38 |
wkite | I have implemented this function with my own code. | 14:39 |
wkite | But I only implemented the driver of iptables by iprange module | 14:40 |
SridarK | wkite: we only support a single address (or range) but i can see the value of having multiple AG's | 14:41 |
SridarK | wkite: we will need to eval ovs for L2 support | 14:41 |
SridarK | lets continue discussion on the review | 14:42 |
wkite | ok | 14:42 |
SridarK | #topic Rocky FWaaS Logging spec | 14:43 |
*** openstack changes topic to "Rocky FWaaS Logging spec (Meeting topic: fwaas)" | 14:43 | |
SridarK | #link https://review.openstack.org/#/c/509725/ | 14:43 |
SridarK | annp: pls go ahead | 14:43 |
SridarK | I think we just have to resolve some minor things and we should be able to move fwd ? | 14:44 |
hoangcx | SridarK: Yes | 14:44 |
annp | I'm waiting update from submiter :) | 14:44 |
SridarK | annp: ok | 14:44 |
SridarK | annp anything else u would like to bring up here ? | 14:44 |
annp | I think spec is quite close to merge. | 14:44 |
hoangcx | Oops, job failed!!! | 14:45 |
*** AlexeyAbashkin has quit IRC | 14:45 | |
annp | SridarK, that's all from me. | 14:45 |
SridarK | ok sounds good | 14:45 |
SridarK | #topic Rocky Remote FWG | 14:46 |
*** openstack changes topic to "Rocky Remote FWG (Meeting topic: fwaas)" | 14:46 | |
SridarK | xgerman_: pls go ahead | 14:46 |
SridarK | #link https://review.openstack.org/521207 | 14:46 |
xgerman_ | not much progress — but I am firmaly in for R-2 | 14:47 |
SridarK | xgerman_: sounds good | 14:47 |
SridarK | #topic Rocky tempest | 14:47 |
*** openstack changes topic to "Rocky tempest (Meeting topic: fwaas)" | 14:47 | |
SridarK | I have been looking at this and will get something going for R-2 | 14:48 |
SridarK | #topic bugs | 14:48 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:48 | |
SridarK | #link https://bugs.launchpad.net/neutron/+bug/1759773 | 14:49 |
openstack | Launchpad bug 1759773 in neutron "FWaaS: Invalid port error on associating L3 ports (Router in HA) to firewall group" [Undecided,Confirmed] - Assigned to Sridar Kandaswamy (skandasw) | 14:49 |
SridarK | and we had a similar issue for DVR, I will address the DVR issue but on HA would like to get some discussion going on behavior after switchover | 14:49 |
SridarK | I dont know that we had any other bugs come up recently but it is time to do a scrub at some point soon | 14:50 |
SridarK | #topic Open Discussion | 14:50 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:50 | |
annp | Hi xgerman_ | 14:51 |
xgerman_ | hi | 14:51 |
SridarK | We will skip Dashboard as i dont see SarathMekala - he was going to come up with a list of enhancements | 14:51 |
annp | I'm planning to start collect idea for l7 filtering | 14:51 |
SridarK | annp: +1 | 14:51 |
xgerman_ | nice — that’s cilium’s claim to fame | 14:52 |
annp | I think we can bring this topic to forum at vancouver summit. Do you think so? | 14:52 |
annp | xgerman_, yes, cilium is great. | 14:52 |
xgerman_ | yes, we can ;-) | 14:53 |
SridarK | annp: have u had some ideas on the backend ? BPF ? | 14:53 |
annp | SridarK, actually, I just want to collect idea to start chose good solution before I implement it | 14:54 |
xgerman_ | well, we should make it pluggable in any way and then just have a rference implementation | 14:54 |
annp | May be BPF and XDP is good choice. Is there any simpler than BPF and XDP? | 14:54 |
annp | :) | 14:54 |
xgerman_ | iptables? | 14:54 |
SridarK | annp: ok the challenge (and part of the requirements and discussion) is we will need to support a ref implementation | 14:55 |
xgerman_ | (which is BPF under the cover but…) | 14:55 |
annp | yes. maybe but i'm not sure :) | 14:55 |
xgerman_ | we should also look at how Octavia/LBaaS define L7 rules | 14:55 |
SridarK | xgerman_: that would be useful | 14:56 |
xgerman_ | https://developer.openstack.org/api-ref/load-balancer/v2/#l7-policies | 14:56 |
annp | xgerman_ +1 | 14:56 |
xgerman_ | yeah, if we can settle on a common “language” that would make it easier for users | 14:56 |
xgerman_ | I also think CCF was going in that direction | 14:57 |
annp | So I think we can create a etherpad to collect requirement and idea for L7 filtering, Do you think so? | 14:57 |
SridarK | annp: +1 | 14:57 |
SridarK | xgerman_: we should also evaluate where we stand with CCF | 14:57 |
SridarK | and also the progress on CCF | 14:58 |
xgerman_ | +1 | 14:58 |
annp | https://etherpad.openstack.org/p/fwaas-v2-L7-filtering | 14:59 |
SridarK | annp: ok great lets add thoughts there | 14:59 |
SridarK | ok we are at time | 14:59 |
SridarK | thanks all for joining | 14:59 |
SridarK | bye | 15:00 |
annp | thanks all | 15:00 |
SridarK | #endmeeting | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu Apr 12 15:00:14 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-12-13.59.html | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-12-13.59.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-12-13.59.log.html | 15:00 |
annp | bye | 15:00 |
*** chandanc has quit IRC | 15:00 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 15:07 | |
*** annp has quit IRC | 15:07 | |
*** AlexeyAbashkin has quit IRC | 15:12 | |
*** hoangcx has quit IRC | 15:14 | |
*** wkite has quit IRC | 15:14 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 15:32 | |
*** yamamoto has quit IRC | 16:47 | |
*** yamamoto has joined #openstack-fwaas | 16:58 | |
*** yamamoto has quit IRC | 17:03 | |
*** SridarK has quit IRC | 17:10 | |
openstackgerrit | boden proposed openstack/neutron-fwaas master: use rpc Connection rather than create_connection https://review.openstack.org/560995 | 17:58 |
*** yamamoto has joined #openstack-fwaas | 18:04 | |
*** openstackgerrit has quit IRC | 18:19 | |
*** AlexeyAbashkin has quit IRC | 19:06 | |
*** yamamoto has quit IRC | 20:21 | |
*** yamamoto has joined #openstack-fwaas | 20:22 | |
*** openstackstatus has quit IRC | 21:27 | |
*** openstack has joined #openstack-fwaas | 21:29 | |
*** ChanServ sets mode: +o openstack | 21:29 | |
-openstackstatus- NOTICE: The Etherpad service at https://etherpad.openstack.org/ is being restarted to pick up the latest release version; browsers should see only a brief ~1min blip before reconnecting automatically to active pads | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!