Thursday, 2018-07-19

*** longkb has joined #openstack-fwaas00:32
*** njohnston_ has joined #openstack-fwaas00:44
*** njohnston_ has quit IRC01:00
*** haleyb has quit IRC01:05
*** haleyb has joined #openstack-fwaas01:13
*** njohnston_ has joined #openstack-fwaas01:13
*** njohnston_ has quit IRC01:29
*** annp has joined #openstack-fwaas02:16
*** njohnston_ has joined #openstack-fwaas02:27
*** njohnston_ has quit IRC02:43
*** AlexeyAbashkin has joined #openstack-fwaas04:57
*** AlexeyAbashkin has quit IRC05:41
*** njohnston_ has joined #openstack-fwaas05:49
*** threestrands has quit IRC05:49
*** threestrands has joined #openstack-fwaas06:09
*** threestrands has quit IRC06:09
*** threestrands has joined #openstack-fwaas06:09
*** annp has quit IRC06:17
*** njohnston__ has joined #openstack-fwaas06:21
*** threestrands has quit IRC06:36
*** njohnston__ has quit IRC06:37
*** openstackgerrit has quit IRC07:04
*** velizarx has joined #openstack-fwaas07:07
*** annp has joined #openstack-fwaas07:40
*** AlexeyAbashkin has joined #openstack-fwaas07:56
*** velizarx has quit IRC07:57
*** velizarx has joined #openstack-fwaas08:24
*** openstackgerrit has joined #openstack-fwaas09:42
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: WIP: Add python binding for libnetfilter_log  https://review.openstack.org/53069409:42
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: WIP: Add python binding for libnetfilter_log  https://review.openstack.org/53069410:29
*** reedip has joined #openstack-fwaas11:48
*** reedip has quit IRC11:48
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: [firewall_v2]: RPC listener should be served by rpc worker  https://review.openstack.org/57943312:23
*** velizarx has quit IRC12:29
*** velizarx has joined #openstack-fwaas12:37
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: Add log validator for FWaaS  https://review.openstack.org/53279212:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: [log]: Add rpc stuff for logging  https://review.openstack.org/53071512:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: Add notification callback events  https://review.openstack.org/57871812:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: Adding resources callback handler for logging service in FWaaS  https://review.openstack.org/58097612:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: FWaaS v2: L3 logging extension  https://review.openstack.org/57633812:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: Introduce accepted/dropped/rejected chains for future processing  https://review.openstack.org/57412812:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: WIP: Add python binding for libnetfilter_log  https://review.openstack.org/53069412:48
openstackgerritKim Bao Long proposed openstack/neutron-fwaas master: [log] Logging driver based iptables for FWaaS  https://review.openstack.org/55373812:48
*** longkb has quit IRC12:54
-openstackstatus- NOTICE: logs.openstack.org is offline, causing POST_FAILURE results from Zuul. Cause and resolution timeframe currently unknown.12:55
*** ChanServ changes topic to "logs.openstack.org is offline, causing POST_FAILURE results from Zuul. Cause and resolution timeframe currently unknown."12:55
*** yushiro has joined #openstack-fwaas13:11
*** ChanServ changes topic to "Queens (Meeting topic: fwaas)"13:38
-openstackstatus- NOTICE: logs.openstack.org is back on-line. Changes with "POST_FAILURE" job results should be rechecked.13:38
*** hoangcx_ has joined #openstack-fwaas13:49
*** annp_ has joined #openstack-fwaas13:49
yushiroannp, Hi.  I just filed https://bugs.launchpad.net/neutron/+bug/178257613:49
openstackLaunchpad bug 1782576 in neutron "Logging - No SG-log data found at /var/log/syslog" [Undecided,New]13:49
*** wkite has joined #openstack-fwaas13:50
*** longkb has joined #openstack-fwaas13:53
annp_yushiro, Got it. Thanks.13:56
longkbo/ yo13:58
*** SridarK has joined #openstack-fwaas13:58
yushiroHi14:00
annp_hi14:00
SridarKHi FWaaS folks14:00
longkbhi forks14:00
doudehi o/14:00
yushiro#startmeeting fwaas14:00
openstackMeeting started Thu Jul 19 14:00:43 2018 UTC and is due to finish in 60 minutes.  The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot.14:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
*** openstack changes topic to " (Meeting topic: fwaas)"14:00
openstackThe meeting name has been set to 'fwaas'14:00
yushiro#chair SridarK xgerman_14:00
openstackCurrent chairs: SridarK xgerman_ yushiro14:00
yushiroSridarK, Maybe today is my turn :p14:01
xgerman_o/14:01
*** SridarK_ has joined #openstack-fwaas14:02
*** chandanc has joined #openstack-fwaas14:02
yushiroHi chandanc , :p14:02
yushiroOK, let's start.14:02
yushiro#topic announcements14:02
*** openstack changes topic to "announcements (Meeting topic: fwaas)"14:02
chandancHello all14:02
chandancHello yushiro14:03
yushiro:)14:03
yushiroWe're now R-6 https://releases.openstack.org/rocky/schedule.html14:04
yushiroJul 23 - Jul 27, this is Rocky-3 milestone and we need to tell Feature freeze if necessary.14:04
*** SridarK has quit IRC14:04
yushiroOh, network connection looks unstable in SridarK's side..14:05
SridarK_yes i am back14:06
yushiroWelcome back :)14:06
yushiroCALL FOR PRESENTATIONS for Berlin summit has closed. (17th)14:07
yushiroIf you submitted some presentation, please tell us during vote-for-presentation :p14:08
yushiroAnything else to announce?14:08
longkb+1 yushiro14:08
SridarK_yushiro: nothing from me14:09
yushiroOK, thanks.14:09
yushiro#topic Rocky14:09
*** openstack changes topic to "Rocky (Meeting topic: fwaas)"14:09
yushiroLogging for FWaaS v214:10
yushiro#link https://review.openstack.org/#/q/topic:bug/1720727+(status:open)14:10
yushiroannp_, hoangcx , longkb plz go ahead.14:10
SridarK_annp: longkb: I started going thru the patches14:10
longkbI have updated the guide for testing: https://github.com/longkb/logging/blob/master/Ingration%20guideline%20for%20logging%20service%20in%20FWaaS.rst14:11
SridarK_trying to piece things together so pls be tolerant of stupid questions i will continue to ask14:11
longkbthe relation between patches also created :)14:11
yushirolongkb, good document and thanks for rebasing with relation.14:12
longkbSridarK_: please help us to review our patches14:12
yushiroSridarK_, Very helpful for us and that IS core reviewing :)14:12
SridarK_yushiro: +114:13
longkbyushiro: A bug from libnetfilter_log has been fixed by AnNP14:13
SridarK_So have u asked for an FFE ?14:13
longkbWe are able to catch log in /var/log/syslog now14:13
yushiroSridarK_, Not yet but I will ask an FFE tomorrow.14:14
SridarK_yushiro: ok14:14
annp_SridarK, yushiro, longkb: thanks14:14
yushiroSo, annp_ longkb , we need to ask FFE for https://review.openstack.org/#/q/topic:bug/1720727+(status:open) , right?14:14
annp_yushiro:+114:14
longkbannp: thanks for your greate work :D14:14
longkb+100 yushiro14:15
annp_yushiro, yes. Please ask our PTL for FFE14:15
yushiro13 patches( 8: neutron-fwaas,  4:neutron, 1:python-neutronclient)14:15
yushiroOK,14:15
yushiroNext,  "Remote firewall group"14:15
annp_mlavalle, Can we send the FFE email tomorrow?14:16
annp_maybe he is not here.14:16
yushiro#link https://review.openstack.org/#/c/564888/14:16
SridarK_annp_: yes14:16
xgerman_maybe14:16
annp_yushiro, Sorry for interrupt. Please go ahead.14:17
yushiroI'll ask him on neutron channel as well.14:17
xgerman_ok14:17
annp_yushiro, +114:17
*** velizarx has quit IRC14:19
amotokifor python-neutronclient, we don't apply FFE. client FF will be the next week14:19
amotokiwe need to wait neutronclient from Stein for some FFE feature14:19
yushiroamotoki, I see.  Thanks14:19
xgerman_#link https://review.openstack.org/#/c/571331/14:19
xgerman_will address yushiro ’s comment and that should be good14:20
SridarK_xgerman_: shd we close on the ovs driver related conversations14:21
yushiroxgerman_, +114:21
yushiroSridarK_, +1 Yes, I wanted to decide about this specification.14:21
yushirochandanc, Thanks for your investigation about remote firewall group.14:21
xgerman_I am good with the outcome of the discussion14:21
*** hongbin_ has joined #openstack-fwaas14:22
xgerman_chandanc: +114:22
SridarK_chandanc: yes many thx for ur time14:22
chandancSure yushiro , xgerman_ . I will try to get into the ovs rules part14:22
xgerman_thank you so much!!!14:22
SridarK_xgerman_: yes that seems reasonable14:22
yushiroSo, we should follow SG behavior first. It means, we should add 'remote_group_id' into firewall_rule.14:23
chandancyushiro: yes,14:24
SridarK_yushiro: +114:24
xgerman_there already is a remote_group_id on the inside14:24
yushiroxgerman_, Aha!  That's nice.14:24
yushiroOK, so, client patch should also fix to align with this specification.14:25
chandancyushiro: can i have the client patch link ?14:25
yushiroI think that we don't need to specify 'source/destination' for remote_group_id.14:26
yushirochandanc, https://review.openstack.org/#/c/571331/14:26
chandancthanks14:26
chandancyushiro: +114:26
xgerman_yeah, I don’t really want to change the client around since that would mean an API change for an API we merged in Q14:26
chandancxgerman_: yushiro i will go through the client code and sumarize in mail,14:28
yushiroAha.  Thanks chandanc.14:28
xgerman_the client is on top of a neutron-lib change from Q14:28
chandancxgerman_: i agree, we need to be careful with the client14:28
yushiroxgerman_, I see.14:28
SridarK_xgerman_: oh ok14:28
SridarK_xgerman_: need to understand that more if we need to have options for both src and dst fwg14:29
xgerman_https://developer.openstack.org/api-ref/network/v2/#fwaas-v2-0-current-fwaas-firewall-groups-firewall-policies-firewall-rules14:30
yushiroSridarK_, Yes.  I still don't clear if we have such option in the future.14:31
yushiroIt's simple to allow ingress/egress traffic with remote_group_id ( align with SG )14:31
chandancSridarK_: yushiro my only worry about client changes is , if we remove src rfwg and dst rfwg and replace with only rfwg, the rules will loose its standalone meaning14:32
xgerman_if we want to get rid of src/dst we need to start a deprecation cycle14:32
chandancso have to tink abit more, may be i am out of touch and need to catch up14:32
xgerman_chandanc: +114:32
SridarK_Also may be if we look at it from the perspective of an L3 port then maybe it makes sense as in the API14:33
xgerman_yep14:33
yushiroxgerman_, Ah, I see. Our API reference has been added source/destination firewall_group ID.14:33
xgerman_yes, we did that in Queens — so changing will be tough…14:34
xgerman_I think we should start with L2 and add L3 in S14:34
SridarK_we can always have some validation logic to ignore one of the them appropriately depending on whethere the rule is in an ingress or egress policy14:34
chandancMay be we can discuss over mail, but +1 to SridarK_14:34
SridarK_ok more thought is needed14:34
chandancthat can be an option14:35
SridarK_chandanc: yes14:35
xgerman_=114:35
SridarK_it is some complexity but that can take care of the situation14:35
SridarK_ok lets discuss on email so we are more clear14:35
yushiroSridarK_, xgerman_ +114:35
*** hoangcx_ has quit IRC14:35
yushiroI see. Thank you.14:36
yushiro#topic specs14:36
*** openstack changes topic to "specs (Meeting topic: fwaas)"14:36
SridarK_i agree with xgerman_ that making changes to the API is a no no now14:36
yushiroI see.  Existing API shouldn't change.14:37
SridarK_I sent a reminder to the PTL on the address group spec - i think it is ready to go14:37
SridarK_maybe it happens now, but if it is punted to S - will that need to fresh review ?14:37
SridarK_not that it is a big deal14:38
yushiroSridarK_, Yes.  I think directory should change from rocky to stein.  Super nit :p14:39
SridarK_yes14:39
yushirowkite, I'm sorry I didn't have enough time to do these week.14:40
yushiro#topic Horizon support14:40
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)"14:40
wkiteyushiro: Never mind.14:41
SridarK_wkite: no worries - we shd get a response soon14:41
SridarK_i think it shd get in14:41
wkiteSridarK_: Thank you for your efforts.14:42
yushiro+114:42
SridarK_wkite: no issue at all -14:42
SridarK_I think SarathMekala is tied up with an internal release14:43
yushiroOK14:44
yushiro#topic bugs14:44
*** openstack changes topic to "bugs (Meeting topic: fwaas)"14:44
SridarK_chandanc: if u can remind him - we can try to discuss the issues he was tracking14:44
chandancSridarK_: sure will do14:44
yushiroSridarK_, chandanc +1  And say hello to him :)14:44
SridarK_thx chandanc14:45
chandancyushiro: sure14:45
yushirohttps://bugs.launchpad.net/neutron/+bug/176245414:46
openstackLaunchpad bug 1762454 in neutron "FWaaS: Invalid port error on associating ports (distributed router) to firewall group" [Medium,In progress] - Assigned to Yushiro FURUKAWA (y-furukawa-2)14:46
yushiro#link https://bugs.launchpad.net/neutron/+bug/176245414:46
SridarK_yushiro: were u able to test the HA router scenario ?14:46
yushiroSridarK_, I'm sorry.  I didn't have any update for it.  But I'll target L3-HA first.14:47
SridarK_yushiro: ok we can sync up14:47
SridarK_my concern is on on the HA14:47
SridarK_*only on14:48
yushiroI believe that devstack can deploy 2 network nodes and 1 compute node.14:48
SridarK_yushiro: ok14:48
yushiroSridarK_, I thought that in case of DVR, we can use L2 port for it.  Is there any meaning to put firewall_group into DVR port?14:49
SridarK_yushiro: DVR is not an issue - i verified on how the rules get put into ns14:50
SridarK_the issue is only on the naming used14:50
*** velizarx has joined #openstack-fwaas14:51
yushiroI think E-W traffic in DVR can be filtered at VM port.  Ah, we can filter N-S traffic by putting DVR port.14:51
yushiroSridarK_, yes, naming is little different ;)14:51
SridarK_yushiro: yes it is only relevant to N - S14:51
SridarK_here14:51
yushiroSridarK_, I see.14:51
yushiroOK, so, I'll test L3-HA case.14:52
SridarK_I will update gerrit and lets sync on this HA14:52
yushiro#topic Open Discussion14:52
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)"14:52
SridarK_Are we maintaining an etherpad for the Logging testing ?14:52
yushiroannp_, I think etherpad is hyperlink page for google doc(testing) and github(devstack configuration), right?14:54
annp_SridarK, https://etherpad.openstack.org/p/Logging_service_for_FWaaS_review_plan14:54
annp_yushiro, right.14:55
SridarK_sorry got it thx annp_14:55
SridarK_will be easy to reference that14:55
annp_SridarK_, Thanks a ton for your great reviewing14:55
SridarK_annp_: no i have not done much - just trying to get the pieces to fit together14:56
annp_SridarK, regards to L7 filtering I'd like to discuss with you and xgerman at PTG if I go there14:56
SridarK_I have run the neutron patches and the first 4 fwaas patches14:56
SridarK_* I have gone thru14:57
SridarK_annp_: surely14:57
SridarK_annp_: sorry i forgot to respond to ur email but we can defn talk14:57
openstackgerritMerged openstack/neutron-fwaas-dashboard master: fix tox python3 overrides  https://review.openstack.org/57393414:57
longkbSridarK_: if you got any problem, please ping me or annp :D14:57
SridarK_longkb: yes i will do that14:57
annp_SridarK_, No worries.14:58
longkb+10 SridarK_14:58
annp_longkb, SridarK_: +10014:58
SridarK_almost time14:59
yushiroal15:00
yushiroOK, bye bye !!15:00
yushiro#endmeeting15:00
*** openstack changes topic to "Queens (Meeting topic: fwaas)"15:00
openstackMeeting ended Thu Jul 19 15:00:18 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:00
chandancbye15:00
openstackMinutes:        http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-07-19-14.00.html15:00
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-07-19-14.00.txt15:00
openstackLog:            http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-07-19-14.00.log.html15:00
SridarK_byE ALL15:00
yushiroHappy weekend!15:00
longkbbuy guys15:00
*** chandanc has quit IRC15:00
annp_thank you, bye15:00
*** annp_ has quit IRC15:01
*** longkb has quit IRC15:12
*** longkb has joined #openstack-fwaas15:26
*** velizarx has quit IRC15:27
*** longkb has quit IRC15:31
*** njohnston_ has quit IRC15:33
*** wkite has quit IRC15:35
*** AlexeyAbashkin has quit IRC15:40
*** hoangcx_ has joined #openstack-fwaas15:47
*** hoangcx has quit IRC15:48
*** yushiro has quit IRC16:07
*** SridarK_ has quit IRC17:01
*** njohnston has joined #openstack-fwaas17:34
openstackgerritMerged openstack/neutron-fwaas-dashboard master: Add release note in README  https://review.openstack.org/58313321:28
openstackgerritMerged openstack/neutron-fwaas master: [FWaaS v1] RPC listener should be served by rpc worker  https://review.openstack.org/58032722:30
openstackgerritMerged openstack/neutron-fwaas master: use autonested_transaction from neutron-lib  https://review.openstack.org/58332622:33
openstackgerritMerged openstack/neutron-fwaas master: Add release note in README  https://review.openstack.org/58326522:33
*** hongbin_ has quit IRC22:34
openstackgerritMerged openstack/neutron-fwaas master: python3: fix netlink_lib delete_entries  https://review.openstack.org/58160222:48

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!