*** sdake has quit IRC | 00:22 | |
*** sdake has joined #openstack-kuryr | 00:32 | |
*** tonanhngo has joined #openstack-kuryr | 00:49 | |
*** tonanhngo has quit IRC | 00:51 | |
*** yamamoto_ has joined #openstack-kuryr | 01:03 | |
*** hongbin has joined #openstack-kuryr | 01:25 | |
*** yamamoto_ has quit IRC | 01:26 | |
*** yamamoto_ has joined #openstack-kuryr | 01:38 | |
*** tonanhngo has joined #openstack-kuryr | 01:57 | |
*** tonanhngo has quit IRC | 01:57 | |
*** yedongcan has joined #openstack-kuryr | 02:12 | |
*** sdake has quit IRC | 02:35 | |
*** yuanying has quit IRC | 02:52 | |
*** huikang has joined #openstack-kuryr | 02:57 | |
*** huikang_ has joined #openstack-kuryr | 03:02 | |
*** yamamoto_ has quit IRC | 03:03 | |
*** huikang has quit IRC | 03:05 | |
*** yedongcan1 has joined #openstack-kuryr | 03:05 | |
*** yedongcan has quit IRC | 03:07 | |
*** huikang_ has quit IRC | 03:08 | |
*** yedongcan1 has quit IRC | 03:23 | |
*** janonymous has joined #openstack-kuryr | 03:32 | |
*** tonanhngo has joined #openstack-kuryr | 03:42 | |
*** tonanhngo has quit IRC | 03:42 | |
*** yamamoto_ has joined #openstack-kuryr | 03:44 | |
*** yuanying has joined #openstack-kuryr | 03:47 | |
*** yuanying has quit IRC | 03:49 | |
*** yuanying has joined #openstack-kuryr | 03:55 | |
*** hongbin has quit IRC | 04:18 | |
*** yedongcan has joined #openstack-kuryr | 04:30 | |
openstackgerrit | Jaivish Kothari(janonymous) proposed openstack/kuryr-libnetwork: call start in sys.exit(start()) instead of start() https://review.openstack.org/376162 | 04:46 |
---|---|---|
*** limao has joined #openstack-kuryr | 04:55 | |
*** lezbar__ has joined #openstack-kuryr | 05:13 | |
*** lezbar has quit IRC | 05:21 | |
openstackgerrit | Dongcan Ye proposed openstack/kuryr-libnetwork: [TrivialFix] Fix README https://review.openstack.org/376173 | 05:27 |
*** irenab_ has joined #openstack-kuryr | 05:45 | |
*** tonanhngo has joined #openstack-kuryr | 05:46 | |
*** tonanhngo has quit IRC | 05:48 | |
*** yedongcan has quit IRC | 05:51 | |
*** yedongcan has joined #openstack-kuryr | 05:57 | |
*** yedongcan1 has joined #openstack-kuryr | 05:59 | |
*** yedongcan has quit IRC | 06:02 | |
*** tonanhngo has joined #openstack-kuryr | 07:01 | |
*** tonanhngo has quit IRC | 07:02 | |
*** oanson has joined #openstack-kuryr | 07:40 | |
*** pablochacin has joined #openstack-kuryr | 08:00 | |
*** janki has joined #openstack-kuryr | 08:29 | |
yedongcan1 | apuimedo, vikasc: ping, hello | 08:33 |
*** dingboopt_ has joined #openstack-kuryr | 09:04 | |
*** irenaber has joined #openstack-kuryr | 09:14 | |
*** irenab_ has quit IRC | 09:18 | |
*** irenab_ has joined #openstack-kuryr | 09:28 | |
*** irenaber has quit IRC | 09:32 | |
*** tonanhngo has joined #openstack-kuryr | 09:32 | |
*** tonanhngo has quit IRC | 09:33 | |
*** ivc_ has joined #openstack-kuryr | 09:42 | |
*** tonanhngo has joined #openstack-kuryr | 09:53 | |
*** tonanhngo has quit IRC | 09:54 | |
*** sdake has joined #openstack-kuryr | 10:06 | |
*** yamamoto_ has quit IRC | 10:07 | |
apuimedo | yedongcan1: pong | 10:21 |
*** limao has quit IRC | 10:22 | |
yedongcan1 | apuimedo: Hello, today I had tracked the bug in https://bugs.launchpad.net/kuryr/, I saw that some bugs had already fixed, but status is not marked correctly. | 10:24 |
yedongcan1 | apuimedo: Can you please mark it? | 10:25 |
apuimedo | yedongcan1: that is great | 10:25 |
apuimedo | which need to be fixed? | 10:25 |
apuimedo | (status fix) | 10:25 |
yedongcan1 | apuimedo: I will give you a link | 10:25 |
apuimedo | thanks | 10:26 |
yedongcan1 | https://bugs.launchpad.net/kuryr/+bug/1578356 fixed in: https://review.openstack.org/#/c/314245/ | 10:26 |
openstack | Launchpad bug 1578356 in kuryr "new libnetwork API" [Medium,New] | 10:26 |
apuimedo | cool | 10:27 |
yedongcan1 | https://bugs.launchpad.net/kuryr/+bug/1604180 Fixed in: https://review.openstack.org/#/c/341891/ | 10:27 |
openstack | Launchpad bug 1604180 in kuryr "Add Python 3.5 classifier and venv in kuryr-libnetwork" [Undecided,New] - Assigned to Liping Mao (limao) | 10:27 |
yedongcan1 | Forgive me, I had marked a bug, https://bugs.launchpad.net/kuryr/+bug/1569142. Maybe I had no right here. | 10:28 |
openstack | Launchpad bug 1569142 in kuryr "Exposing ports" [Medium,Fix committed] - Assigned to Mohammad Banikazemi (mb-s) | 10:28 |
apuimedo | cool, yedongcan1. I updated them ;-) | 10:31 |
yedongcan1 | apuimedo: Thanks. | 10:32 |
apuimedo | yedongcan1: thanks to you | 10:33 |
apuimedo | yedongcan1: if you'd like to keep helping with triaging it will be great | 10:33 |
yedongcan1 | apuimedo: Sure, I will | 10:36 |
apuimedo | yedongcan1: if you can't mark bugs as triaged let me know so I can sort out the permissions | 10:36 |
apuimedo | irenab: could you raise https://review.openstack.org/#/c/371432/ to +2 ? | 10:37 |
apuimedo | I want to merge this stuff and move forward | 10:37 |
yedongcan1 | apuimedo: Thanks, I will told you if I meet. | 10:37 |
apuimedo | cool | 10:38 |
yedongcan1 | vikasc: ping | 10:39 |
apuimedo | yedongcan1: he's not online | 10:44 |
yedongcan1 | apuimedo: Got it, I will ping he in future. | 10:45 |
apuimedo | I thought you said that now it is a dictionary | 10:47 |
apuimedo | oops, wrong channel | 10:47 |
apuimedo | :P | 10:47 |
*** prithiv has joined #openstack-kuryr | 10:56 | |
*** yedongcan1 has quit IRC | 10:59 | |
*** sdake has quit IRC | 11:04 | |
*** sdake_ has joined #openstack-kuryr | 11:04 | |
*** yamamoto has joined #openstack-kuryr | 11:05 | |
*** yamamoto has quit IRC | 11:11 | |
*** yedongcan has joined #openstack-kuryr | 11:12 | |
*** sdake_ has quit IRC | 11:43 | |
*** prithiv has joined #openstack-kuryr | 12:06 | |
*** janki has quit IRC | 12:11 | |
*** yamamoto has joined #openstack-kuryr | 12:12 | |
irenab_ | apuimedo, sure | 12:18 |
*** yamamoto has quit IRC | 12:19 | |
irenab_ | apuimedo, can you please refer to the question I posted regarding accompaning documentation, i.e wiki or README | 12:20 |
*** tonanhngo has joined #openstack-kuryr | 12:25 | |
*** tonanhngo has quit IRC | 12:27 | |
*** prithiv has joined #openstack-kuryr | 12:27 | |
*** yamamoto has joined #openstack-kuryr | 12:31 | |
*** yamamoto has quit IRC | 12:37 | |
*** yamamoto has joined #openstack-kuryr | 12:39 | |
apuimedo | irenab_: I'll add info on the readme, sorry I forgot your question | 12:55 |
apuimedo | (follow up patches) | 12:55 |
irenab_ | apuimedo, thanks | 12:55 |
*** mchiappero has joined #openstack-kuryr | 12:57 | |
*** sdake has joined #openstack-kuryr | 12:58 | |
*** yamamoto has quit IRC | 12:59 | |
*** yamamoto has joined #openstack-kuryr | 13:00 | |
*** yamamoto has quit IRC | 13:00 | |
openstackgerrit | Merged openstack/kuryr-kubernetes: devstack: First version of kuryr-kubernetes plugin https://review.openstack.org/371432 | 13:02 |
*** sdake_ has joined #openstack-kuryr | 13:03 | |
*** sdake has quit IRC | 13:06 | |
*** pablochacin has quit IRC | 13:07 | |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-kubernetes: move config and opt generation to new kuryr-lib https://review.openstack.org/374144 | 13:11 |
*** limao has joined #openstack-kuryr | 13:15 | |
*** pablochacin has joined #openstack-kuryr | 13:19 | |
openstackgerrit | Merged openstack/kuryr-kubernetes: move config and opt generation to new kuryr-lib https://review.openstack.org/374144 | 13:27 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr: Add 'deployment_type' configuration parameter https://review.openstack.org/362023 | 13:29 |
*** banix has joined #openstack-kuryr | 13:32 | |
*** tonanhngo has joined #openstack-kuryr | 13:39 | |
*** tonanhngo has quit IRC | 13:40 | |
*** limao_ has joined #openstack-kuryr | 13:42 | |
*** limao has quit IRC | 13:45 | |
*** sdake has joined #openstack-kuryr | 13:48 | |
*** yamamoto has joined #openstack-kuryr | 13:48 | |
openstackgerrit | Merged openstack/kuryr: Add 'deployment_type' configuration parameter https://review.openstack.org/362023 | 13:48 |
apuimedo | Yay | 13:48 |
apuimedo | I love merging sprees | 13:48 |
*** vikasc has joined #openstack-kuryr | 13:49 | |
*** sdake_ has quit IRC | 13:50 | |
*** pablochacin has quit IRC | 13:51 | |
*** sdake_ has joined #openstack-kuryr | 13:51 | |
*** lmdaly has joined #openstack-kuryr | 13:52 | |
*** sdake has quit IRC | 13:54 | |
apuimedo | https://wiki.openstack.org/wiki/Meetings/Kuryr#Meeting_September_26th.2C_2016 | 13:55 |
apuimedo | banix: irenab_ ivc_ janonymous limao_ lmdaly vikasc yedongcan: just posted the agenda | 13:56 |
apuimedo | I keep doing it later and later, sorry | 13:56 |
*** tonanhngo has joined #openstack-kuryr | 14:02 | |
*** hongbin has joined #openstack-kuryr | 14:03 | |
*** yamamoto has quit IRC | 14:05 | |
*** yamamoto has joined #openstack-kuryr | 14:06 | |
*** yamamoto has quit IRC | 14:11 | |
*** yamamoto has joined #openstack-kuryr | 14:23 | |
*** prithiv has quit IRC | 14:33 | |
*** yamamoto has quit IRC | 14:57 | |
*** sdake_ has quit IRC | 14:59 | |
apuimedo | Ok, here we are! | 15:01 |
apuimedo | we can follow the discussions | 15:01 |
apuimedo | banix: you're not going to ask be about el5, right? | 15:02 |
apuimedo | in general the limit is pyroute2 | 15:02 |
banix | yeah wondering if pyroute2 has a requirement | 15:02 |
apuimedo | though svinota very kindly added some ioctl backwards compatibility code last week for us | 15:02 |
apuimedo | now it should work with 3.10+ | 15:02 |
banix | cool | 15:02 |
limao_ | hi apuimedo, vikasc, | 15:04 |
apuimedo | limao_: hi | 15:06 |
limao_ | in macvlan/ipvlan case, all the containers on one vm will share the sg of the vm. If we have two containers on the vm, one want to open 22 port, another want to open 80. sg of the vm will open 22 and 80 at same time. Is this right? | 15:07 |
apuimedo | limao_: it depends on the vendor | 15:08 |
yedongcan | apuimode: Lauchpad is oops, so I paste comments here | 15:10 |
apuimedo | yedongcan: thanks | 15:10 |
apuimedo | I tried to look at it before and it went "boom" | 15:10 |
apuimedo | limao_: I would hope that if we update SGs for the address of one of the container ports | 15:11 |
apuimedo | the iptables on the host where it is not bound would still allow it to be open | 15:11 |
apuimedo | but the opening is usually per address, not per port | 15:11 |
apuimedo | so opening for one container, should not impact the others | 15:11 |
*** pablochacin has joined #openstack-kuryr | 15:12 | |
yedongcan | The problem is caused by multiple networks with same cidrs in Neutron side and Kuryr.I had a subnet created in Neutron already. | 15:12 |
apuimedo | ah, I see | 15:12 |
*** yamamoto has joined #openstack-kuryr | 15:12 | |
yedongcan | So, I had some thoughts here, I think we can check overlapping cidrs in ipam_request_pool, and if exists overlapping cidrs, we can give a warning message for user. | 15:13 |
apuimedo | yedongcan: this sounds like what vikasc had raised about address scopes | 15:13 |
apuimedo | vikasc: could you weigh in on that? | 15:13 |
*** sdake has joined #openstack-kuryr | 15:15 | |
*** reedip has quit IRC | 15:16 | |
yedongcan | Meanwhile, should we add the logic in network_driver_create_network(Like the patch I had commit) if user really forget passing pool_name in options? We can't assure that user check in Neutron side. Actually we also | 15:16 |
yedongcan | provides a case that pool_name not passed in options when we requesting pool. | 15:16 |
limao_ | apuimedo: In case we have Nested VM which ip is 100.0.0.2, there are two containers on it , they are 100.0.0.3(need to open 22 port) and 100.0.0.4(need to open 80 port). How to add rules only open 100.0.0.3:22 and 100.0.0.4:80 in security group? | 15:17 |
limao_ | I mean in the security group of 100.0.0.2 | 15:17 |
apuimedo | yedongcan: I think we should just error out saying that there is no pool in Neutron and maybe we can link to the documentation saying how to create it | 15:18 |
apuimedo | limao_: you mean Neutron API wise? | 15:19 |
apuimedo | or ovs agent wise? | 15:19 |
vikasc | apuimedo, we already have it under limitations in kuryr-lib readme | 15:19 |
vikasc | apuimedo, yedongcan we should move it to kuryr-libnetwork | 15:19 |
apuimedo | vikasc: but I think we should put a meaninful error when that happens | 15:19 |
apuimedo | with a link to documentation | 15:19 |
apuimedo | so the user can see it and go to solve it | 15:20 |
vikasc | apuimedo, thats what i suggested to yedongcan other day | 15:20 |
apuimedo | yedongcan: what do you think about it? | 15:21 |
vikasc | apuimedo, we can add warning message | 15:21 |
yedongcan | vikasc: apuimedo: oh, I find it. | 15:21 |
*** prithiv has joined #openstack-kuryr | 15:22 | |
yedongcan | There was one question, how about existing Neutron subnet and kuryr created subnet? | 15:22 |
apuimedo | yedongcan: for that specific thing is why we need the address scopes, right vikasc ? | 15:23 |
*** prithiv has quit IRC | 15:23 | |
limao_ | apuimedo: I mean in the security group of 100.0.0.2, there is no way to only open 22 for 100.0.0.3, once you open 22 port, it will open all 22 for both of the container. | 15:23 |
apuimedo | limao_: the security group will usually be the same for all the ports in the subnet | 15:24 |
*** yedongcan1 has joined #openstack-kuryr | 15:24 | |
vikasc | apuimedo, right | 15:24 |
apuimedo | shouldn't it be possible to open port 22 for 100.0.0.3 | 15:24 |
apuimedo | ? | 15:24 |
apuimedo | it has no relation to ports, or at least that was my understanding | 15:24 |
yedongcan1 | vikasc, I will add a warning message in next patch. | 15:24 |
vikasc | thanks yedongcan | 15:24 |
yedongcan1 | Do you mean option is forcing? | 15:25 |
vikasc | yedongcan, sorry could not get your question | 15:25 |
vikasc | yedongcan, would you mind reword | 15:26 |
apuimedo | limao_: (me checking what happens on ovs ) | 15:26 |
* vikasc need to go | 15:26 | |
limao_ | apuimedo: >the security group will usually be the same for all the ports in the subnet , if all sg on the subnet are same, you can use fwaas in vrouter :) | 15:26 |
*** yedongcan has quit IRC | 15:26 | |
apuimedo | limao_: I actually have never tried fwaas | 15:27 |
apuimedo | :P | 15:27 |
limao_ | Chain neutron-openvswi-i4f8b9d33-4 (1 references) | 15:28 |
limao_ | pkts bytes target prot opt in out source destination | 15:28 |
limao_ | 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED /* Direct packets associated with a known session to the RETURN chain. */ | 15:28 |
limao_ | 0 0 RETURN udp -- * * 10.225.14.202 0.0.0.0/0 udp spt:67 udp dpt:68 | 15:28 |
limao_ | 0 0 RETURN udp -- * * 10.225.14.201 0.0.0.0/0 udp spt:67 udp dpt:68 | 15:28 |
limao_ | 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 match-set NIPv405015ba4-6203-430d-b67c- src | 15:28 |
limao_ | 0 0 RETURN tcp -- * * 10.0.0.0/16 0.0.0.0/0 tcp dpt:333 | 15:28 |
limao_ | 0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 | 15:28 |
limao_ | 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID /* Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack. */ | 15:28 |
limao_ | 0 0 neutron-openvswi-sg-fallback all -- * * 0.0.0.0/0 0.0.0.0/0 /* Send unmatched traffic to the fallback chain. */ | 15:29 |
yedongcan1 | I mean the pool name option is necessary ? | 15:29 |
*** reedip has joined #openstack-kuryr | 15:29 | |
apuimedo | the question is whether the iptables rule will be pushed to all the hosts or only if the port is bound | 15:29 |
limao_ | apuimedo: only the port is bound | 15:30 |
*** jerms has quit IRC | 15:30 | |
apuimedo | limao_: well, that is a problem then | 15:31 |
*** jerms has joined #openstack-kuryr | 15:31 | |
apuimedo | means that security group rules will not work with the ipvlan approach with the current state of ovs | 15:31 |
apuimedo | but maybe we can patch ovs-agent iptables to take allowed address pairs into account | 15:32 |
*** devvesa has joined #openstack-kuryr | 15:32 | |
*** devvesa has quit IRC | 15:32 | |
limao_ | that's why I'm saying if sg can't work, why do not we disable port security directly | 15:32 |
limao_ | apuimedo: I'm afraid kuryr can't do it, since it is running in vm, not the compute host | 15:33 |
apuimedo | limao_: I'm saying to fix this in Neutron | 15:33 |
apuimedo | if they accept it | 15:34 |
ivc_ | limao_: it would probably work but do you think users would want to disable port security? | 15:34 |
apuimedo | IMHO it should be doable, that the subscriber for security groups checks if the address is allowed | 15:34 |
limao_ | ivc_: I'm not sure, but if you need ACL, you still can use fwaas(which is network based, not port based) | 15:35 |
ivc_ | i mean the whole point of kuryr is to bring neutron power to containers | 15:36 |
*** irenab_ has quit IRC | 15:40 | |
*** reedip has quit IRC | 15:40 | |
*** yamamoto has quit IRC | 15:44 | |
apuimedo | ivc_: limao_: I was now asking and it seems that the SG rules would apply | 15:45 |
*** yamamoto has joined #openstack-kuryr | 15:45 | |
limao_ | ivc_: Yeap, try fix it then :-) | 15:45 |
apuimedo | that the ovs subscriber that modifies rules only checks if there is a port of that SG in the host | 15:45 |
apuimedo | so I don't think we need a fix | 15:46 |
apuimedo | because there will always be a port of the containers SG bound in the host (the instance port) | 15:46 |
limao_ | apuimedo: there will be sg bound in the vm port | 15:48 |
apuimedo | limao_: I think that works for us | 15:49 |
limao_ | apuimedo: but for sg of the container ports (ipvlan/macvlan), ovs will not process. because ovs only detect the port plug in br-int | 15:50 |
*** yamamoto has quit IRC | 15:50 | |
*** pablochacin has quit IRC | 15:50 | |
apuimedo | limao_: are you sure about that? | 15:51 |
limao_ | apuimedo: 100% sure.. | 15:51 |
apuimedo | I was talking with jlibosva of the neutron folk and he thought it would apply since the VM port has membersihp | 15:51 |
apuimedo | *membership | 15:51 |
apuimedo | on the SG | 15:51 |
limao_ | apuimedo: did he talked about trunk/sub port? | 15:52 |
apuimedo | limao_: no, regular ports | 15:52 |
apuimedo | he said that the only check there is for processing SG rules is if there is a bound port of the SG | 15:52 |
apuimedo | if we use the same SG for the VM port and for the container ports, we should be fine | 15:53 |
limao_ | limao_: our container port even did not bind, how did neutron know he should set up the sg rules on which compute node | 15:53 |
*** reedip has joined #openstack-kuryr | 15:53 | |
limao_ | Yes, if we use same SG for all the containers on one vm, it should be ok | 15:54 |
ivc_ | but then we need to enforce it somehow | 15:54 |
apuimedo | limao_: I think that until we have the trunk subport, we must enforce same SG | 15:56 |
limao_ | apuimedo: +1 | 15:56 |
apuimedo | I don't like it, but it is the path of least resistance for now | 15:56 |
apuimedo | lmdaly: ^^ | 15:57 |
apuimedo | ivc_: I think it won't be hard to enforce | 15:57 |
apuimedo | it's what we would do by default, we'll just fail the operations that specify a different SG | 15:57 |
apuimedo | when running in container-in-vm mode | 15:57 |
apuimedo | (when in ipvlan/macvlan mode) | 15:58 |
hongbin | +1 | 15:59 |
*** banix has quit IRC | 16:00 | |
apuimedo | hongbin: thanks for following the discussion! | 16:00 |
limao_ | apuimedo: hongbin: looks like magnum can accept this limitation :) | 16:00 |
hongbin | I guess it is ok | 16:00 |
hongbin | at least, sounds better than disable port security :) | 16:01 |
limao_ | :) | 16:02 |
apuimedo | indeed | 16:03 |
limao_ | BTW, here is the reason why we have limitation of 10 allowed address pairs for one port :https://bugs.launchpad.net/neutron/+bug/1336207 | 16:05 |
openstack | Launchpad bug 1336207 in OpenStack Security Advisory "[OSSA 2014-025] There is no quota for allowed address pair (CVE-2014-3555)" [High,Fix released] - Assigned to Tristan Cacqueray (tristan-cacqueray) | 16:05 |
apuimedo | limao_: I imagined something of the sort | 16:06 |
apuimedo | iptables get slow when there are too many | 16:06 |
limao_ | yes | 16:06 |
apuimedo | so it's good that Neutron adds the ovs rules instead | 16:06 |
limao_ | then ovs ruls will be many :) | 16:07 |
apuimedo | limao_: they are much better performant I think | 16:09 |
limao_ | I'm not sure ovs can support how much flow, I tested iptables before, if we have more than 2000 iptables rule, the performance will be sharp down | 16:09 |
*** reedip has quit IRC | 16:10 | |
limao_ | Thanks apuimedo and ivc_ for your kindly explain and discuss. c u later. | 16:13 |
apuimedo | thank you limao | 16:14 |
openstackgerrit | Dongcan Ye proposed openstack/kuryr-libnetwork: Check overlapping subnet cidr when creating subnetpool https://review.openstack.org/373977 | 16:14 |
openstackgerrit | Dongcan Ye proposed openstack/kuryr-libnetwork: Check overlapping subnet cidr when creating subnetpool https://review.openstack.org/373977 | 16:16 |
*** limao_ has quit IRC | 16:16 | |
*** limao has joined #openstack-kuryr | 16:16 | |
yedongcan1 | apuimedo: vikasc: Updated a new patch. | 16:19 |
apuimedo | thanks yedongcan1 | 16:20 |
*** limao has quit IRC | 16:20 | |
yedongcan1 | apuimedo: you're welcome. :) | 16:21 |
*** banix has joined #openstack-kuryr | 16:22 | |
*** reedip has joined #openstack-kuryr | 16:22 | |
mchiappero | Yes, ovs is probably a better performer | 16:41 |
mchiappero | But what's the reason for having an ipchain rule by default? | 16:41 |
*** reedip has quit IRC | 16:45 | |
*** lmdaly has quit IRC | 16:51 | |
*** reedip has joined #openstack-kuryr | 16:59 | |
*** ivc_ has quit IRC | 17:02 | |
*** yamamoto has joined #openstack-kuryr | 17:02 | |
*** yedongcan1 has quit IRC | 17:04 | |
*** ivc_ has joined #openstack-kuryr | 17:09 | |
*** yamamoto has quit IRC | 17:11 | |
*** mchiappero has quit IRC | 17:15 | |
*** ivc_ has quit IRC | 17:16 | |
*** ivc_ has joined #openstack-kuryr | 17:19 | |
*** devvesa has joined #openstack-kuryr | 17:21 | |
*** tonanhngo has quit IRC | 17:40 | |
*** salv-orlando has joined #openstack-kuryr | 17:43 | |
*** devvesa has left #openstack-kuryr | 17:47 | |
*** irenab has quit IRC | 17:51 | |
*** irenab has joined #openstack-kuryr | 17:52 | |
*** ivc_ has quit IRC | 17:58 | |
*** tonanhngo has joined #openstack-kuryr | 18:03 | |
*** tonanhngo has quit IRC | 18:04 | |
*** hongbin has quit IRC | 18:20 | |
*** banix has quit IRC | 18:31 | |
*** tonanhngo has joined #openstack-kuryr | 18:46 | |
*** tonanhngo_ has joined #openstack-kuryr | 18:47 | |
*** tonanhngo_ has quit IRC | 18:48 | |
*** tonanhngo_ has joined #openstack-kuryr | 18:49 | |
*** tonanhngo has quit IRC | 18:50 | |
*** tonanhngo has joined #openstack-kuryr | 19:02 | |
*** tonanhngo_ has quit IRC | 19:05 | |
*** banix has joined #openstack-kuryr | 19:30 | |
*** sdake has quit IRC | 19:33 | |
*** tonanhngo_ has joined #openstack-kuryr | 19:34 | |
*** irenab has quit IRC | 19:36 | |
*** irenab has joined #openstack-kuryr | 19:37 | |
*** tonanhngo has quit IRC | 19:37 | |
*** salv-orl_ has joined #openstack-kuryr | 19:42 | |
*** salv-orlando has quit IRC | 19:45 | |
*** sdake has joined #openstack-kuryr | 19:46 | |
*** tonanhngo_ has quit IRC | 20:36 | |
*** tonanhngo has joined #openstack-kuryr | 20:37 | |
*** portdirect has joined #openstack-kuryr | 21:08 | |
portdirect | Hi, I've put OpenStack in Kubernetes, which makes quite extensive use of Kuryr - both libnetwork and cni to replace flannel and the kube-proxy. I've put the code up here: https://github.com/portdirect/harbor and plan to have AMI's and an ISO to download in the next few days - if anyone has any feedback I'd really appreciate it. | 21:11 |
*** salv-orl_ has quit IRC | 21:30 | |
*** salv-orlando has joined #openstack-kuryr | 21:32 | |
*** sdake has quit IRC | 21:33 | |
*** salv-orlando has quit IRC | 22:08 | |
*** huikang has joined #openstack-kuryr | 22:16 | |
*** huikang has quit IRC | 22:32 | |
*** huikang has joined #openstack-kuryr | 22:33 | |
*** portdirect_ has joined #openstack-kuryr | 22:35 | |
*** portdirect has quit IRC | 22:36 | |
*** portdirect_ is now known as portdirect | 22:36 | |
*** huikang has quit IRC | 22:37 | |
*** banix has quit IRC | 22:42 | |
*** reedip has quit IRC | 23:18 | |
*** reedip has joined #openstack-kuryr | 23:30 | |
*** salv-orlando has joined #openstack-kuryr | 23:39 | |
*** vikasc has quit IRC | 23:44 | |
*** sdake has joined #openstack-kuryr | 23:44 | |
*** salv-orlando has quit IRC | 23:45 | |
*** tonanhngo has quit IRC | 23:50 | |
*** reedip has quit IRC | 23:50 | |
*** tonanhngo_ has joined #openstack-kuryr | 23:55 | |
*** tonanhngo has joined #openstack-kuryr | 23:57 | |
*** tonanhng_ has joined #openstack-kuryr | 23:58 | |
*** tonanhngo_ has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!