*** yamamoto has quit IRC | 00:53 | |
*** yamamoto has joined #openstack-fwaas | 00:53 | |
*** hoangcx has joined #openstack-fwaas | 01:12 | |
*** annp has joined #openstack-fwaas | 03:39 | |
*** hoangcx has quit IRC | 06:43 | |
*** hoangcx has joined #openstack-fwaas | 06:44 | |
*** yamamoto has quit IRC | 07:16 | |
*** yamamoto has joined #openstack-fwaas | 07:17 | |
*** doude_ has quit IRC | 07:32 | |
*** doude_ has joined #openstack-fwaas | 07:44 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 07:45 | |
*** threestrands_ has quit IRC | 07:52 | |
*** doude_ is now known as doude | 08:04 | |
*** doude has quit IRC | 08:04 | |
*** doude has joined #openstack-fwaas | 08:04 | |
*** yamamoto has quit IRC | 08:11 | |
*** yamamoto has joined #openstack-fwaas | 08:27 | |
*** Alexey_Abashkin has joined #openstack-fwaas | 08:57 | |
*** AlexeyAbashkin has quit IRC | 09:01 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 09:01 | |
*** hoangcx has quit IRC | 09:27 | |
*** hoangcx has joined #openstack-fwaas | 09:28 | |
bzhao__ | xgerman_: Thanks german, sorry for late reply. I saw the spec, it seem also a big change for FW. And thanks for your answer. I think there may be a huge change comes from my company... Hmm, but we also face the resource issue.. :(. Haha | 10:07 |
---|---|---|
*** hoangcx has quit IRC | 10:11 | |
bzhao__ | May I change the default FW rule from deny to other actions(drop)? I'm not sure whether it is designed to drop the traffic at the last of fw rule list. Just a question, should we allow to change the default fw rule action? | 10:18 |
*** yamamoto has quit IRC | 10:55 | |
*** threestrands_ has joined #openstack-fwaas | 11:01 | |
*** yamamoto has joined #openstack-fwaas | 11:50 | |
*** yamamoto has quit IRC | 11:50 | |
*** hoangcx has joined #openstack-fwaas | 12:05 | |
*** yamamoto has joined #openstack-fwaas | 12:18 | |
*** threestrands_ has quit IRC | 12:58 | |
*** SridarK has joined #openstack-fwaas | 13:50 | |
*** wkite has joined #openstack-fwaas | 13:53 | |
*** yamamoto has quit IRC | 13:56 | |
SridarK | Hi FWaaS folks | 13:59 |
*** yushiro has joined #openstack-fwaas | 13:59 | |
SridarK | #startmeeting fwaas | 14:00 |
openstack | Meeting started Thu Apr 26 14:00:07 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:00 | |
openstack | The meeting name has been set to 'fwaas' | 14:00 |
SridarK | #chair yushiro xgerman_ | 14:00 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:00 |
njohnston | o/ | 14:00 |
yushiro | Hi all :) | 14:00 |
SridarK | yushiro: hi - i think ur turn today | 14:00 |
yushiro | SridarK, sure! | 14:00 |
yushiro | OK folks, let's begin :) | 14:00 |
yushiro | #topic announcements | 14:01 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:01 | |
xgerman_ | o/ | 14:01 |
yushiro | Good news about OpenStack summit Vancouver's forum. | 14:01 |
yushiro | Our fwaas L7 session has approved. | 14:02 |
SridarK | annp: congrats | 14:02 |
xgerman_ | +1 | 14:02 |
yushiro | I forgot a link... annp, Do you have some link? | 14:02 |
SridarK | #link http://forumtopics.openstack.org/cfp/details/144 | 14:03 |
SridarK | ? | 14:03 |
SridarK | i think not | 14:04 |
SridarK | that was the submission | 14:04 |
yushiro | SridarK, Hmm, it returns 404 .. | 14:04 |
SridarK | yes just saw that too | 14:04 |
yushiro | Thanks. Anyway, let's discuss topic about our forum later :) | 14:05 |
SridarK | but that is good that | 14:05 |
SridarK | it was accepted | 14:05 |
SridarK | sorry go ahead yushiro | 14:06 |
yushiro | OK | 14:06 |
doude | Hi | 14:06 |
yushiro | We are now Rocky-2 cycle. R-2 is until 4th Jun. https://releases.openstack.org/rocky/schedule.html | 14:06 |
yushiro | So, anything else to announce? | 14:07 |
xgerman_ | TC elections are open — so if you got an e-mail make sure to vote | 14:07 |
yushiro | doude, hi | 14:07 |
yushiro | aha, yes, thanks xgerman_ | 14:07 |
yushiro | OK, so next topic. | 14:09 |
yushiro | #topic Rocky | 14:09 |
*** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:09 | |
yushiro | Pluggable backend driver https://review.openstack.org/#/c/480265/ | 14:09 |
yushiro | doude, Hi. It's your turn :) | 14:10 |
doude | yes sorry | 14:12 |
doude | so I just started to look at the issue for the port auto association to default FG | 14:13 |
doude | I've a patch, I 'm just finishing to validate unit tests | 14:13 |
doude | I also rebase the patch on master | 14:13 |
yushiro | OK, good | 14:13 |
doude | I'll push new patch set in the hour | 14:14 |
yushiro | wow, cool. I'll test tomorrow with 'nova boot' command and check default fwg association again. | 14:14 |
doude | just a question, that specific port association is only in case a port is automatically associated to the default FG? | 14:14 |
*** annp_ has joined #openstack-fwaas | 14:15 | |
*** annp_ has quit IRC | 14:15 | |
yushiro | doude, auto association target is VM port (newly created or bind) | 14:16 |
yushiro | And it is associated with default fwg. | 14:17 |
doude | if we create a port not binded to a host, and associating that port to FG, do we just need to set the association in the DB and don't send RPC FG update ? | 14:17 |
doude | ha ok it's only for port VM | 14:17 |
doude | understood | 14:17 |
yushiro | If we try to associate non-bind port with any fwg, it returns 409 error. | 14:17 |
yushiro | Aha, Ok. | 14:17 |
doude | ok | 14:17 |
doude | thanks | 14:17 |
yushiro | So, doude, if you update your patch, please check the q-agt.service log while running 'nova boot'. If there is no 'error' message and FWG is associated with a port, it is good. | 14:19 |
yushiro | Of course, I'll test as well :) | 14:19 |
doude | oterwise, I did not had time to discuss with NSX dev about their FWaaS driver | 14:19 |
doude | sure yushiro | 14:19 |
SridarK | doude: ok it will be good to close on the NSX driver too | 14:20 |
doude | I was able to reproduce and see that error before I patch the code | 14:20 |
SridarK | i think it should be o | 14:20 |
SridarK | k | 14:20 |
doude | yes me to SridarK | 14:20 |
SridarK | maybe just needs clarification | 14:20 |
SridarK | thx doude | 14:20 |
yushiro | doude, In addition, current devstack is a little strange. Please set [fwaas]firewall_l2_driver = ovs at /etc/neutron/l3_agent.ini not /etc/neutron/plugins/ml2/ml2_conf.ini | 14:21 |
yushiro | Latter case wasn't loaded correctly. | 14:21 |
yushiro | OK, next | 14:22 |
yushiro | WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:22 |
yushiro | xgerman_, go ahead :p | 14:22 |
doude | thanks yushiro | 14:22 |
xgerman_ | not much to report. | 14:22 |
yushiro | OK | 14:22 |
xgerman_ | Need yo make the gates work for my patch | 14:23 |
xgerman_ | there have been gate issues the pas few weeks in OpenStack | 14:23 |
yushiro | wow :( | 14:23 |
xgerman_ | yeah, from pip versions, to neutron purging FKs, etc. | 14:24 |
*** reedip has joined #openstack-fwaas | 14:24 | |
reedip | hey hi guys | 14:24 |
yushiro | xgerman_, Ahhhh, Yes, I remembered.. | 14:24 |
njohnston | hi reedip | 14:24 |
yushiro | reedip, Hi! | 14:24 |
reedip | I was able to join the meeting atlast :) | 14:25 |
yushiro | reedip, cool!! | 14:25 |
xgerman_ | o/ | 14:25 |
SridarK | reedip: long time, hi :-) | 14:25 |
reedip | o/ | 14:25 |
reedip | yes, was pretty messed up with the work and other activities :| | 14:25 |
SridarK | :-) | 14:25 |
yushiro | Good news! I wanted to announce about that in announce topic :p | 14:26 |
yushiro | OK, next | 14:26 |
yushiro | Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ | 14:26 |
SridarK | Sorry i forgot earlier but it looks good to me too | 14:27 |
SridarK | and i added Miguel for +A | 14:27 |
yushiro | Thanks for your review SridarK | 14:27 |
yushiro | good :) In addition, your comment is reasonable to start L3 first. | 14:28 |
yushiro | Thanks cuong for update. | 14:28 |
njohnston | +1 | 14:29 |
yushiro | and thanks for all reviewing :) | 14:29 |
yushiro | #topic Horizon support | 14:29 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:29 | |
yushiro | Today, chandan and Sarath are not here. | 14:30 |
SridarK | Yes, i will send a note to them to see if they can join next week | 14:30 |
yushiro | SridarK, OK, thanks. | 14:30 |
yushiro | #topic bugs | 14:32 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:32 | |
yushiro | http://urx2.nu/C7UI | 14:32 |
yushiro | There are 13 bugs are 'UNDECIDED' status. | 14:33 |
xgerman_ | time for a bug scrub? | 14:33 |
reedip | any assigned to me ?? :P | 14:33 |
SridarK | +1 on bug scrub | 14:33 |
reedip | +1 for the bug scrub | 14:34 |
yushiro | xgerman_, GOOD! | 14:34 |
SridarK | maybe we can run thru this after we take a look offline | 14:34 |
SridarK | and update them | 14:34 |
xgerman_ | +1 | 14:34 |
yushiro | https://bugs.launchpad.net/neutron/+bug/1618244 | 14:34 |
openstack | Launchpad bug 1618244 in neutron "Possible scale issues with neutron-fwaas requesting all tenants with firewalls after RPC failures" [Undecided,In progress] - Assigned to Bertrand Lallau (bertrand-lallau) | 14:34 |
reedip | I will look at them a bit tomorrow morning ( I have some bandwidth tomorrow ) | 14:34 |
SridarK | somehow i recall some work on this area done maybe by Cedric ? | 14:35 |
SridarK | i am a bit foggy | 14:35 |
yushiro | SridarK, OK | 14:36 |
yushiro | It seems to be backported to ocata | 14:37 |
yushiro | I'll set 'low' for now. | 14:38 |
xgerman_ | k | 14:38 |
SridarK | yes that seemed quite familiar | 14:39 |
yushiro | https://bugs.launchpad.net/neutron/+bug/1626642 | 14:39 |
openstack | Launchpad bug 1626642 in neutron "Cleanup and add more UT for FWaaS v2 plugin" [Undecided,Confirmed] - Assigned to Sridar Kandaswamy (skandasw) | 14:39 |
yushiro | It's you, SridarK :) | 14:39 |
SridarK | let me look to see if that is relevant | 14:39 |
yushiro | Ok | 14:40 |
njohnston | brb | 14:40 |
SridarK | i recall we had some coverage needed for rule updates | 14:40 |
SridarK | but will take a look | 14:40 |
yushiro | Aha. OK, so, I'll set medium. | 14:40 |
yushiro | https://bugs.launchpad.net/neutron/+bug/1656754 | 14:41 |
openstack | Launchpad bug 1656754 in neutron "Fwaas (bind a firewall to DVR router when its floating-ip count is zero): the firewall rules does not take effect for a VM after binding a floating ip to the VM." [Undecided,New] - Assigned to wujun (wujun) | 14:41 |
yushiro | I think this is about fwaas v1. | 14:43 |
SridarK | yushiro: most likely will need to look | 14:43 |
yushiro | OK, there are many bugs. Let's continue next week. | 14:46 |
SridarK | yushiro: +1 | 14:46 |
xgerman_ | +1 | 14:46 |
SridarK | we can do some digging on the list offline | 14:46 |
yushiro | yeah | 14:46 |
yushiro | #topic specs | 14:46 |
*** openstack changes topic to "specs (Meeting topic: fwaas)" | 14:46 | |
reedip | Lets put a google doc for it ? | 14:47 |
yushiro | fwaas 2.0 address groups support https://review.openstack.org/557137 | 14:47 |
wkite | I have committed a new proposafor e | 14:48 |
wkite | sorry | 14:48 |
yushiro | reedip, about bug? | 14:49 |
wkite | I have committed a new spec to the gerrit. | 14:50 |
yushiro | wkite, OK, could you paste a link for the spec?? | 14:50 |
wkite | i modified some inappropriate places. | 14:51 |
yushiro | Ah, you updated existing spec, did you? | 14:52 |
wkite | http://logs.openstack.org/37/557137/4/check/build-openstack-sphinx-docs/3c4e754/html/specs/rocky/fwaas-2.0-address-groups-support.html | 14:52 |
wkite | yushiro: yes | 14:53 |
yushiro | I cannot review last week, so I'll review tomorrow. | 14:53 |
yushiro | s/cannot/couldn't | 14:53 |
SridarK | wkite: thx i see u have addressed most comments - i think - will go thru again also | 14:53 |
wkite | yushiro: thanks for your review | 14:54 |
yushiro | :) | 14:55 |
yushiro | Ah, 5 minutes left !! :p | 14:55 |
wkite | SridarK: thx | 14:55 |
SridarK | wkite: np | 14:55 |
yushiro | Everyone, plz review his spec :) | 14:55 |
xgerman_ | +1 | 14:55 |
yushiro | #topic Open Discussion | 14:55 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:55 | |
yushiro | I'll take a holiday from 28th Apr. to 6th May a.k.a "Golden week". | 14:56 |
SridarK | yushiro: have a nice break | 14:57 |
yushiro | If you'd like to ask me something, please send e-mail <y.furukawa8@gmail.com> | 14:57 |
*** yamamoto has joined #openstack-fwaas | 14:57 | |
yushiro | SridarK, Yeah, thanks. | 14:57 |
amotoki | stable/queens fwaas-dashboard gate is broken now. the fix is here: https://review.openstack.org/#/c/564523/ please take a look. | 14:58 |
yushiro | amotoki, Thank you so much | 14:58 |
SridarK | +1 | 14:59 |
yushiro | I need more time to contribute on OpenStack!! :p | 14:59 |
SridarK | yushiro: ah yes same here | 15:00 |
SridarK | :-) | 15:00 |
xgerman_ | +1 — | 15:00 |
yushiro | Same feeling :) | 15:00 |
SridarK | oh time | 15:00 |
yushiro | Ok, this is time. | 15:00 |
yushiro | #endmeeting | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu Apr 26 15:00:28 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
SridarK | bye all | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-26-14.00.html | 15:00 |
xgerman_ | o/ | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-26-14.00.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-04-26-14.00.log.html | 15:00 |
yushiro | bye bye~~~~~~ | 15:00 |
wkite | bye | 15:00 |
*** wkite has quit IRC | 15:01 | |
*** yamamoto has quit IRC | 15:03 | |
-openstackstatus- NOTICE: We've successfully troubleshooted the issue that prevented paste.openstack.org from loading and it's now back online, thank you for your patience. | 15:05 | |
*** reedip has quit IRC | 15:08 | |
*** hoangcx has quit IRC | 15:18 | |
*** yushiro has quit IRC | 15:22 | |
*** openstackgerrit has joined #openstack-fwaas | 15:23 | |
openstackgerrit | Édouard Thuleau proposed openstack/neutron-fwaas master: Implements a plugable backend driver https://review.openstack.org/480265 | 15:23 |
doude | SridarK, annp --^ | 15:24 |
SridarK | doude: thx | 15:24 |
*** AlexeyAbashkin has quit IRC | 15:56 | |
*** yamamoto has joined #openstack-fwaas | 15:59 | |
*** yamamoto has quit IRC | 16:04 | |
*** SridarK has quit IRC | 16:47 | |
*** yamamoto has joined #openstack-fwaas | 17:01 | |
*** yamamoto has quit IRC | 17:06 | |
*** SumitNaiksatam has joined #openstack-fwaas | 17:33 | |
*** yamamoto has joined #openstack-fwaas | 18:02 | |
*** yamamoto has quit IRC | 18:07 | |
*** SumitNaiksatam has left #openstack-fwaas | 18:34 | |
*** yamamoto has joined #openstack-fwaas | 19:04 | |
*** yamamoto has quit IRC | 19:09 | |
*** yamamoto has joined #openstack-fwaas | 20:05 | |
*** yamamoto has quit IRC | 20:11 | |
*** yamamoto has joined #openstack-fwaas | 21:07 | |
*** yamamoto has quit IRC | 21:13 | |
*** yamamoto has joined #openstack-fwaas | 22:09 | |
*** yamamoto has quit IRC | 22:14 | |
*** yamamoto has joined #openstack-fwaas | 23:11 | |
*** annp has quit IRC | 23:13 | |
*** annp has joined #openstack-fwaas | 23:14 | |
*** yamamoto has quit IRC | 23:16 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!