*** longkb has joined #openstack-fwaas | 01:13 | |
*** annp has joined #openstack-fwaas | 02:22 | |
*** haleyb has quit IRC | 04:07 | |
*** hoangcx has quit IRC | 06:11 | |
*** hoangcx has joined #openstack-fwaas | 06:12 | |
*** longkb has quit IRC | 06:13 | |
*** njohnston has quit IRC | 06:14 | |
*** longkb has joined #openstack-fwaas | 06:14 | |
*** longkb has quit IRC | 07:41 | |
*** longkb has joined #openstack-fwaas | 07:42 | |
*** velizarx has joined #openstack-fwaas | 08:21 | |
*** velizarx has quit IRC | 08:52 | |
*** velizarx has joined #openstack-fwaas | 08:54 | |
*** longkb has quit IRC | 09:38 | |
*** longkb has joined #openstack-fwaas | 09:38 | |
*** longkb has quit IRC | 10:03 | |
*** yamamoto has quit IRC | 10:17 | |
*** yamamoto has joined #openstack-fwaas | 10:25 | |
*** yamamoto has quit IRC | 10:46 | |
*** yamamoto has joined #openstack-fwaas | 10:48 | |
*** yamamoto has quit IRC | 10:49 | |
*** yamamoto has joined #openstack-fwaas | 11:23 | |
*** annp has quit IRC | 12:03 | |
*** yamamoto has quit IRC | 12:14 | |
*** yamamoto has joined #openstack-fwaas | 12:16 | |
*** longkb has joined #openstack-fwaas | 13:02 | |
*** longkb has quit IRC | 13:30 | |
*** yamamoto has quit IRC | 13:31 | |
*** yamamoto has joined #openstack-fwaas | 13:31 | |
*** longkb has joined #openstack-fwaas | 13:54 | |
*** yushiro has joined #openstack-fwaas | 13:58 | |
yushiro | Hi fwaas | 14:00 |
---|---|---|
longkb | hi yushiro :) | 14:00 |
yushiro | #startmeeting fwaas | 14:01 |
openstack | Meeting started Thu Sep 27 14:01:18 2018 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:01 | |
openstack | The meeting name has been set to 'fwaas' | 14:01 |
yushiro | #chair xgerman_ | 14:01 |
openstack | Current chairs: xgerman_ yushiro | 14:01 |
yushiro | I don't see SridarK today. | 14:02 |
*** annp has joined #openstack-fwaas | 14:02 | |
yushiro | OK, let's begin. | 14:02 |
yushiro | #topic announcements | 14:02 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:02 | |
annp | hi | 14:02 |
annp | sorry for come late | 14:03 |
yushiro | annp: Hi. 1 announcement. Currently, we're "announcement" topic. | 14:03 |
longkb | o/ | 14:03 |
*** SridarK has joined #openstack-fwaas | 14:03 | |
yushiro | Hi SridarK :) | 14:03 |
yushiro | #chair SridarK | 14:03 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:03 |
annp | yushiro, thanks. please go ahead. | 14:04 |
yushiro | SridarK: We're "announcement" topic now :) | 14:04 |
*** SridarK_ has joined #openstack-fwaas | 14:04 | |
xgerman_ | o/ | 14:04 |
SridarK_ | oops sorry back | 14:04 |
yushiro | OK | 14:04 |
yushiro | I think there is no more announcements. Let's move on next topic. | 14:05 |
yushiro | #topic Stein | 14:05 |
*** openstack changes topic to "Stein (Meeting topic: fwaas)" | 14:05 | |
xgerman_ | I think TC vote should close | 14:06 |
yushiro | xgerman_: Aha, yes. | 14:06 |
yushiro | Anything else to announce ?? | 14:07 |
yushiro | #chair SridarK_ | 14:07 |
openstack | Current chairs: SridarK SridarK_ xgerman_ yushiro | 14:07 |
yushiro | Today, we're 4 cores :) | 14:07 |
xgerman_ | summit is like 6 weeks away ;-) | 14:08 |
*** SridarK has quit IRC | 14:08 | |
SridarK_ | my evil twin | 14:08 |
SridarK_ | some issues with the connectivity | 14:08 |
SridarK_ | :-) | 14:08 |
yushiro | SridarK_: Don't warry :) | 14:08 |
yushiro | xgerman_: Yeah, Berlin summit. | 14:08 |
SridarK_ | I am multitasking in another mtg so slow | 14:08 |
xgerman_ | me, too | 14:08 |
yushiro | Wow, you are busy now. I see. I'm multi-task too but chat and eating :) | 14:09 |
xgerman_ | oh, I haven’t had breakfast | 14:09 |
SridarK_ | :-) | 14:09 |
yushiro | haha | 14:10 |
annp | :-) | 14:10 |
yushiro | So, annp, regarding regression test for fwg logging result, 2 issues are merged, | 14:10 |
yushiro | right ? | 14:10 |
annp | yushiro, right. | 14:10 |
yushiro | longkb: You're trying to follow-up fwg logging patch, and ready for review, right ? | 14:11 |
longkb | yushiro: yep | 14:11 |
yushiro | OK, I'll definitely review this patch in addition to functional patch. | 14:12 |
annp | yushiro, +1 | 14:12 |
longkb | There are 02 patches that need review: https://review.openstack.org/#/c/600660/ and https://review.openstack.org/#/c/598601/ | 14:12 |
yushiro | longkb: +1 | 14:12 |
yushiro | OK, anything else for fwg logging ? | 14:12 |
longkb | ah, don't forget your python-client patch :D yushiro | 14:13 |
yushiro | longkb: Sure. But it is not for fwg logging but also SNAT one :) | 14:13 |
yushiro | s/not/not only | 14:13 |
longkb | yushiro: +1 | 14:13 |
yushiro | Next: remote fwg | 14:13 |
xgerman_ | yeah, not much progress… lot’s of internal stuff | 14:14 |
xgerman_ | hoping to some stuff inthe next few days | 14:14 |
yushiro | xgerman_: Sure. have you fixed DB issue?? If not, we can take a look. | 14:14 |
xgerman_ | No, my hunch is still some version mismatch… | 14:15 |
yushiro | annp: Can you take a look https://review.openstack.org/#/c/521207/41 if you have bandwidth? | 14:17 |
annp | yushiro, sure. I will take a look. | 14:17 |
yushiro | annp: :) | 14:17 |
yushiro | #topic specs | 14:17 |
*** openstack changes topic to "specs (Meeting topic: fwaas)" | 14:17 | |
yushiro | fwaas 2.0 address groups support: https://review.openstack.org/557137 | 14:18 |
SridarK_ | I recall the contributor had some code in progress | 14:18 |
yushiro | wkite is not here today. | 14:19 |
yushiro | SridarK_: OK | 14:19 |
yushiro | (hongbin) fwaas: add support for dynamic rules https://review.openstack.org/#/c/597724/ | 14:19 |
yushiro | We've discussed at PTG but I haven't reviewed yet. will reflect my comment. | 14:20 |
yushiro | hongbin is not here today. | 14:20 |
yushiro | Same as extend firewall group inclusion https://review.openstack.org/#/c/600261/ | 14:20 |
yushiro | #topic Horizon support | 14:21 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:21 | |
yushiro | Sarath is not here today. I'll figure out what improvements are necessary in Stein. | 14:22 |
yushiro | #topic bugs | 14:23 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:23 | |
yushiro | https://bugs.launchpad.net/neutron/+bug/1595440 | 14:24 |
openstack | Launchpad bug 1595440 in neutron "neutron-fwaas ships /usr/bin/neutron-l3-agent a 2nd time" [High,Confirmed] | 14:24 |
yushiro | I think it is not issue at present. | 14:25 |
yushiro | It's ok to set 'invalid' or other status as reedip said. | 14:25 |
annp | yushiro, +1 | 14:26 |
yushiro | DVR + L3-HA issue: https://review.openstack.org/#/c/580552/ | 14:26 |
yushiro | I'm sorry. I don't have much bandwidth these month. I need volunteer for this patch. | 14:27 |
yushiro | In case of L3-HA, we should apply fwg rules not only 'active' router but also all of 'standby' routers. | 14:28 |
yushiro | annp: longkb: I think fwg logging also includes same issue in case of L3-ha. | 14:28 |
annp | yushiro, I can help you :) | 14:28 |
xgerman_ | thanks | 14:28 |
annp | yushiro, I'm not sure. Let's us dig more. | 14:29 |
longkb | +1 annp :) | 14:29 |
yushiro | annp: NFLOG rules(logging rules in iptables) should be configured both 'active' and 'standby' routers. | 14:30 |
yushiro | When switching over from 'active' to 'standby' router, only conntrack information should be migrated. That is current specification of L3-Ha. | 14:30 |
yushiro | In order to apply fwg rules or fwg logging after switch over, we should apply same rule in advance.. | 14:31 |
*** yamamoto has quit IRC | 14:32 | |
annp | yushiro, yes. I think so. | 14:32 |
yushiro | annp: currently, we are finding router namespace from a neutron port. Current logic can get only namespace with 'standby' router!! | 14:33 |
*** yamamoto has joined #openstack-fwaas | 14:33 | |
*** yamamoto has quit IRC | 14:33 | |
*** yamamoto has joined #openstack-fwaas | 14:34 | |
yushiro | #topic Open Discussion | 14:34 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:34 | |
yushiro | Wow, today is so fast :-) | 14:34 |
annp | yushiro, I'll look at the DVR + L3HA after I gain some knowledge. | 14:34 |
xgerman_ | I am thinking about throwing up. a patch to enabling ovs L2 by default in our devstack plugin…. Thoughts? | 14:35 |
annp | xgerman_ +1 | 14:35 |
SridarK_ | yushiro: sorry had "stepped in" to the other mtg | 14:35 |
yushiro | SridarK_: OK :) | 14:35 |
SridarK_ | yushiro: +1 on the L3 HA - will sched some time to discuss with u | 14:35 |
yushiro | annp: thanks. | 14:36 |
yushiro | xgerman_: +1 | 14:36 |
annp | regards to L7 filtering | 14:36 |
annp | xgerman_, SridarK, yushiro, I've just update spec at https://review.openstack.org/#/c/600714/4/specs/stein/fwaas_l7_filtering.rst | 14:37 |
xgerman_ | sweet | 14:37 |
SridarK_ | annp: oh great | 14:37 |
yushiro | annp: +100 | 14:37 |
annp | So could you take a look at it and give me some comment. | 14:37 |
yushiro | OK. | 14:37 |
*** yamamoto has quit IRC | 14:38 | |
annp | I will make it more better :-) | 14:38 |
annp | one more, | 14:38 |
SridarK_ | annp: so u are thinking eBPF ? | 14:38 |
annp | SridarK_, yes. | 14:39 |
yushiro | cool | 14:39 |
yushiro | I think eBPF is suitable solution. | 14:39 |
SridarK_ | annp: nice | 14:39 |
yushiro | Finally, we can offload some hardwares e.g. smartNIC or FPGA.. | 14:40 |
yushiro | by using eBPF | 14:40 |
annp | yushiro, Not sure. :-) | 14:40 |
SridarK_ | yushiro: +1 | 14:40 |
SridarK_ | i think some vendors are supporting this | 14:40 |
yushiro | wow, that's a good news | 14:41 |
xgerman_ | +1 | 14:41 |
annp | currently, I've just have a very simple http filter with eBPF | 14:41 |
annp | https://github.com/annp1987/http_filter_with_xdp | 14:41 |
annp | So I think eBPF is suitable for L7 filtering. | 14:42 |
*** yamamoto has joined #openstack-fwaas | 14:43 | |
annp | But please note that L7AgentExtension can load other driver except L7 dirver based eBPF | 14:43 |
xgerman_ | yeah, cilium is betting their whole business on that fact :-) | 14:43 |
annp | That's my idea. | 14:43 |
yushiro | xgerman_: +1 Cilium is good example :) | 14:43 |
*** longkb has quit IRC | 14:44 | |
annp | xgerman_, +1 | 14:44 |
annp | One more information from me :-) | 14:44 |
annp | Regards to libnetfilter_log, I'd like to moving this part to neutron-lib | 14:45 |
annp | But neutron-lib doesn't allow eventlet. So I discussed with neutron-folks. | 14:45 |
annp | They suggested libnetfilter_log should place at neutron repo as first implementation for SNAT logging. | 14:46 |
annp | So there's duplicate code of libnetfilter_log between neutron-fwaas and neutron | 14:47 |
yushiro | OK | 14:47 |
annp | Can I moving libnetfilter_log and import back to neutron-fwaas? | 14:47 |
yushiro | annp: In the future, libnetfilter_log should be migrated into neutron-lib, right ? | 14:48 |
annp | Same as way, we call some agent stuff from neutron? | 14:48 |
annp | yushiro, Yes. in next cycle. | 14:49 |
yushiro | annp: So, i think it's OK to keep on current code for fwaas. | 14:49 |
yushiro | annp: In next cycle, we can migrate them. | 14:50 |
annp | yushiro, ok. I see. | 14:50 |
annp | that's all from me | 14:50 |
yushiro | OK, anything else to discuss ? | 14:50 |
SridarK_ | nothing from me | 14:51 |
yushiro | If not, we're closing a little earlier. | 14:51 |
SridarK_ | +1 | 14:51 |
yushiro | OK, thanks fwaas guys today!! | 14:51 |
yushiro | #endmeeting | 14:51 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 14:51 | |
openstack | Meeting ended Thu Sep 27 14:51:32 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:51 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-09-27-14.01.html | 14:51 |
SridarK_ | thanks all | 14:51 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-09-27-14.01.txt | 14:51 |
SridarK_ | bye | 14:51 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-09-27-14.01.log.html | 14:51 |
annp | thanks all, | 14:51 |
annp | See you next week. | 14:52 |
*** yushiro has quit IRC | 14:52 | |
*** yamamoto has quit IRC | 14:52 | |
*** Swami has joined #openstack-fwaas | 14:59 | |
*** annp has quit IRC | 15:02 | |
*** yamamoto has joined #openstack-fwaas | 15:28 | |
*** njohnston has joined #openstack-fwaas | 15:47 | |
*** yamamoto has quit IRC | 16:02 | |
*** velizarx has quit IRC | 16:04 | |
*** Swami has quit IRC | 16:46 | |
*** SridarK_ has quit IRC | 17:25 | |
*** yamamoto has joined #openstack-fwaas | 18:00 | |
*** Swami has joined #openstack-fwaas | 18:10 | |
*** hongbin has joined #openstack-fwaas | 18:47 | |
*** yamamoto has quit IRC | 19:01 | |
*** yamamoto has joined #openstack-fwaas | 20:59 | |
*** openstackgerrit has joined #openstack-fwaas | 21:30 | |
openstackgerrit | German Eichberger proposed openstack/neutron-fwaas master: Make ovs the default option for L2 FWaaS V2 https://review.openstack.org/605866 | 21:30 |
*** yamamoto has quit IRC | 21:48 | |
*** hongbin has quit IRC | 23:26 | |
*** Swami has quit IRC | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!