*** neex has joined #openstack-kuryr | 00:32 | |
*** dougbtv__ has quit IRC | 00:47 | |
*** limao has joined #openstack-kuryr | 00:49 | |
*** kiennt has joined #openstack-kuryr | 00:49 | |
*** caowei has joined #openstack-kuryr | 00:53 | |
*** kiennt has quit IRC | 00:55 | |
*** neex has quit IRC | 01:32 | |
*** edisonxiang has joined #openstack-kuryr | 01:57 | |
*** gouthamr has quit IRC | 02:10 | |
*** hongbin has joined #openstack-kuryr | 02:14 | |
*** wangbo has joined #openstack-kuryr | 02:24 | |
*** kiennt has joined #openstack-kuryr | 02:32 | |
*** robust has quit IRC | 02:37 | |
*** lakerzhou has joined #openstack-kuryr | 03:00 | |
*** gouthamr has joined #openstack-kuryr | 03:01 | |
*** gouthamr has quit IRC | 03:17 | |
*** robust has joined #openstack-kuryr | 03:20 | |
*** hongbin has quit IRC | 03:25 | |
*** hongbin has joined #openstack-kuryr | 03:25 | |
*** lakerzhou1 has joined #openstack-kuryr | 03:40 | |
*** lakerzhou has quit IRC | 03:44 | |
*** hongbin has quit IRC | 03:45 | |
*** kiennt has quit IRC | 04:01 | |
*** robust has quit IRC | 04:07 | |
*** janki has joined #openstack-kuryr | 04:19 | |
*** wangbo has quit IRC | 04:28 | |
*** caowei has quit IRC | 04:53 | |
*** wangbo has joined #openstack-kuryr | 05:04 | |
*** caowei has joined #openstack-kuryr | 05:21 | |
*** aojea has joined #openstack-kuryr | 06:16 | |
*** kiennt has joined #openstack-kuryr | 06:51 | |
*** limao has quit IRC | 07:05 | |
*** limao has joined #openstack-kuryr | 07:06 | |
*** kiennt has quit IRC | 07:13 | |
apuimedo | deepika08: did you try running some pods with kubectl? | 07:14 |
---|---|---|
apuimedo | livelace2: let me check | 07:14 |
*** kiennt has joined #openstack-kuryr | 07:15 | |
apuimedo | livelace2: you mean that if two pods talk to other two pods at the same time it fails? | 07:16 |
livelace2 | apuimedo, Hello. Yes, but not only other two pods, all network connectivity was broken for those pods. I suppose to forget what I wrote to you, I will recheck that case today, a little bit later. | 07:19 |
apuimedo | irenab: thanks for merging the first containerized patch | 07:19 |
apuimedo | livelace2: thanks. If that were indeed the case it would be a big bug in Neutron | 07:20 |
apuimedo | livelace2: you are using ml2/ovs, right? | 07:20 |
livelace2 | yes | 07:20 |
apuimedo | irenab: https://review.openstack.org/#/c/504027/ | 07:21 |
apuimedo | livelace2: which firewall driver? Hybrid or ovs? | 07:21 |
*** pcaruana has joined #openstack-kuryr | 07:21 | |
livelace2 | apuimedo, Now I have one important question: in your installation, do you have multiple working pods on the same VM node ? | 07:22 |
livelace2 | apuimedo, I tried both | 07:22 |
apuimedo | livelace2: how do you test it? | 07:22 |
livelace2 | apuimedo, More details will be later, I should be ensure | 07:23 |
apuimedo | thanks | 07:23 |
livelace2 | apuimedo, Could you answer my question ? | 07:23 |
livelace2 | apuimedo, Now I have one important question: in your installation, do you have multiple working pods on the same VM node ? | 07:23 |
irenab | apuimedo, done | 07:23 |
apuimedo | livelace2: let me try. I usually try it via services. I have three pods and I access through the service clusterip | 07:25 |
apuimedo | and all the pods reply | 07:25 |
apuimedo | one at a time | 07:25 |
apuimedo | is the malfunction you observed when multiple pods try to ping something outside at the same time? | 07:25 |
livelace2 | Yes | 07:26 |
apuimedo | ok | 07:26 |
apuimedo | so I'll try | 07:26 |
apuimedo | I haven't tried that recently (I did try it for a previous demo in the summit) | 07:26 |
livelace2 | But I think it will be work fine, because you had access to service IPs | 07:27 |
livelace2 | apuimedo, + what are you using ? standard OVS/hybrid ? | 07:27 |
*** kiennt has quit IRC | 07:28 | |
apuimedo | ovs+firewall. Hybrid doesn't work for me | 07:30 |
ltomasbo | yep, there is a problem with sg and non ovs-firewall for trunk ports | 07:30 |
ltomasbo | but that is not on kuryr side, but neutron | 07:31 |
livelace2 | I tried both | 07:32 |
livelace2 | ltomasbo, Could you send a link to a bug/whatever ? | 07:32 |
livelace2 | I saw mention about firewall types on the page of Trunk Ports | 07:33 |
ltomasbo | livelace2, let me check if I can find it! | 07:33 |
livelace2 | But there are no details | 07:33 |
livelace2 | + I understand difference between OVS native vs OVS hybrid firewall types | 07:34 |
livelace2 | But without much details about problems with Trunk Ports | 07:35 |
ltomasbo | there was also some problem with same macs for trunk ports: https://bugs.launchpad.net/neutron/+bug/1626010 | 07:35 |
openstack | Launchpad bug 1626010 in neutron "OVS Firewall cannot handle non unique MACs" [High,Fix released] - Assigned to Thomas Morin (tmmorin-orange) | 07:35 |
ltomasbo | though that one was already fixed | 07:36 |
openstackgerrit | Merged openstack/kuryr-kubernetes master: Fix local.conf.sample in without Octavia https://review.openstack.org/504027 | 07:40 |
*** janki is now known as janki|lunch | 07:42 | |
*** kiennt has joined #openstack-kuryr | 07:45 | |
apuimedo | irenab: are you going to try to run today https://review.openstack.org/#/c/490378/ ? | 07:51 |
apuimedo | I just fired it up | 07:51 |
apuimedo | with devstack-heat | 07:51 |
*** janki|lunch is now known as janki | 07:55 | |
irenab | apuimedo, just take it and run devstack? | 07:56 |
apuimedo | yeah | 07:58 |
apuimedo | to verify the branch | 07:58 |
apuimedo | and get it all in finally | 07:58 |
irenab | sure, will verify asap | 07:59 |
apuimedo | thanks irenab! | 08:00 |
vikasc | i verifed apuimedo and that worked | 08:03 |
openstackgerrit | Merged openstack/fuxi master: Don't access etcd via localhost https://review.openstack.org/500848 | 08:11 |
*** egonzalez has joined #openstack-kuryr | 08:12 | |
*** kiennt has quit IRC | 08:14 | |
*** wangbo has quit IRC | 08:15 | |
*** wangbo has joined #openstack-kuryr | 08:16 | |
openstackgerrit | Merged openstack/kuryr-kubernetes master: Add support to install Kuryr as a network addon https://review.openstack.org/466675 | 08:18 |
*** wangbo has quit IRC | 08:18 | |
openstackgerrit | Merged openstack/kuryr-kubernetes master: CNI container: parametrize and clean up https://review.openstack.org/490377 | 08:18 |
openstackgerrit | Merged openstack/kuryr-kubernetes master: devstack: optionally run kuryr containerized https://review.openstack.org/490378 | 08:18 |
*** wangbo has joined #openstack-kuryr | 08:27 | |
apuimedo | vikasc: great | 08:46 |
*** limao has quit IRC | 09:27 | |
*** jchhatbar has joined #openstack-kuryr | 10:21 | |
*** jchhatbar has quit IRC | 10:22 | |
*** jchhatbar has joined #openstack-kuryr | 10:22 | |
*** janki has quit IRC | 10:24 | |
*** jchhatbar is now known as janki | 10:25 | |
*** caowei has quit IRC | 10:29 | |
*** egonzalez has quit IRC | 10:29 | |
*** jchhatbar has joined #openstack-kuryr | 10:33 | |
*** jchhatbar has quit IRC | 10:33 | |
*** jchhatbar has joined #openstack-kuryr | 10:33 | |
*** janki has quit IRC | 10:35 | |
*** egonzalez has joined #openstack-kuryr | 10:45 | |
*** gsagie has joined #openstack-kuryr | 10:48 | |
*** gsagie has quit IRC | 10:49 | |
*** jchhatbar is now known as janki | 11:04 | |
*** limao has joined #openstack-kuryr | 11:18 | |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Avoid port update neutron call during pods boot up https://review.openstack.org/504915 | 11:25 |
*** egonzalez has quit IRC | 11:26 | |
ltomasbo | apuimedo, ^^ | 11:28 |
ltomasbo | this is the first version of the modification to not need port/subports naming during pod creation | 11:28 |
ltomasbo | I'll adapt the kuryr-manager patch sets so that they are also aware of this | 11:29 |
apuimedo | ltomasbo: thanks | 11:29 |
apuimedo | I'll check | 11:29 |
ltomasbo | and still need to fix the unittests, but wanted to get it available for early comments | 11:29 |
*** wangbo has quit IRC | 11:39 | |
*** lakerzhou1 has quit IRC | 11:44 | |
*** wangbo has joined #openstack-kuryr | 11:48 | |
*** limao_ has joined #openstack-kuryr | 11:51 | |
*** limao has quit IRC | 11:52 | |
*** atoth has joined #openstack-kuryr | 12:01 | |
*** mattmceuen has quit IRC | 12:05 | |
*** egonzalez has joined #openstack-kuryr | 12:07 | |
*** janki is now known as janki|afk | 12:28 | |
*** limao_ has quit IRC | 12:42 | |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add Pool Manager to handle subports https://review.openstack.org/498698 | 12:49 |
*** lakerzhou has joined #openstack-kuryr | 12:51 | |
irenab | ltomasbo, I posted some comments on pools manager patch on previous patchset | 12:59 |
ltomasbo | great! thanks! I was just rebasing it (and putting it on top of the new one that does not require the ports-name) | 13:00 |
irenab | I was lazy to repost them :-) | 13:01 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add list and show pool commands to Pool Manager https://review.openstack.org/504410 | 13:05 |
*** wangbo has quit IRC | 13:06 | |
ltomasbo | irenab, :D don't worry! | 13:12 |
ltomasbo | I'll reply asap | 13:12 |
openstackgerrit | Merged openstack/kuryr-libnetwork master: Fix post gate hook to accommodate for new os-testr https://review.openstack.org/504342 | 13:26 |
ltomasbo | irenab, I replied to you questions/comments. Thanks for the feedback! | 13:27 |
*** deepika has joined #openstack-kuryr | 13:34 | |
apuimedo | ltomasbo: did you see the comments on https://review.openstack.org/#/c/504915/1 | 13:48 |
apuimedo | ? | 13:48 |
ltomasbo | yep | 13:48 |
ltomasbo | apuimedo, even reply to them! | 13:48 |
ltomasbo | apuimedo, what do you prefer for the BM case? | 13:49 |
ltomasbo | also double check with k8s API? | 13:49 |
ltomasbo | ports should be down (for now) if not in use by the containers | 13:49 |
apuimedo | ltomasbo: not sure I get it | 13:51 |
apuimedo | ltomasbo: yes, yes, BM should also check with k8s api | 13:51 |
ltomasbo | why? | 13:51 |
ltomasbo | race-condition? | 13:51 |
apuimedo | ltomasbo: do you have any idea how slow is changing port names?! | 13:51 |
ltomasbo | no idea, but I assume a couple of second each... | 13:52 |
apuimedo | I'm doing it now for a lot of ports and the averagae speed is 0.225ports/s | 13:52 |
ltomasbo | normal ports? or subports? | 13:52 |
apuimedo | does it make a difference? I'd hope not | 13:53 |
apuimedo | since it's only a darned name change | 13:53 |
ltomasbo | ahh, ok | 13:53 |
ltomasbo | I was thinking about delete | 13:53 |
ltomasbo | not update | 13:53 |
ltomasbo | update is just changing a field in the db | 13:54 |
ltomasbo | it should be faster... | 13:54 |
apuimedo | yeah | 13:54 |
irenab | ltomasbo, I am not sure about pool manager security. Who is allowed to call it? | 13:54 |
apuimedo | it definitely should | 13:54 |
apuimedo | irenab: can you try it in DF? | 13:54 |
ltomasbo | and getting back to the BM case, why do you want the k8s API check also for BM? | 13:54 |
apuimedo | ltomasbo: why do you think it not necessary? | 13:54 |
irenab | apuimedo, try what? | 13:55 |
apuimedo | irenab: port name change speed | 13:55 |
ltomasbo | for the nested case, as the ports are connected, you don't know if they are in use by containers or not (as they are active) | 13:55 |
ltomasbo | but for the BM, if there is no container using the port, the status is down | 13:55 |
ltomasbo | so you already know there is no container there, no need to ask k8s | 13:56 |
*** zengchen1 has joined #openstack-kuryr | 13:56 | |
irenab | let me know what you measure and I will back with the number | 13:56 |
irenab | apuimedo, so we will compare apples to apples | 13:56 |
apuimedo | ltomasbo: my point was that it doesn't need to be down in the future if it is kept as a veth in a namespace | 13:58 |
apuimedo | ltomasbo: have you timed how long it takes to filter? | 13:58 |
ltomasbo | apuimedo, no, but I don't have a big env to test it | 13:59 |
apuimedo | ok, let me check | 13:59 |
apuimedo | if this port renaming ever ends | 14:00 |
ltomasbo | I can check with a few ports and containers and let you know | 14:00 |
apuimedo | that is | 14:00 |
irenab | apuimedo, let me know what is your test for the name change speed | 14:00 |
ltomasbo | and I'll change the patch to also do the checking for the BM, to make it ready for the future! | 14:00 |
apuimedo | irenab: I have 900 ports | 14:01 |
apuimedo | and then I do this | 14:01 |
apuimedo | for port in $(openstack port list --device-owner compute:kuryr -f value -c ID -c Status -c Name | awk '/demo-/ {print $1}'); do echo openstack port set --name "available-port" $port; openstack port set --name "available-port" $port; done | 14:01 |
*** dimak has joined #openstack-kuryr | 14:02 | |
ltomasbo | apuimedo, are you changing the name twice? | 14:02 |
apuimedo | dulek_: how's it going with janonymous' cni split? | 14:02 |
apuimedo | ltomasbo: no, no. First I just print the command I execute afterwarsd | 14:03 |
apuimedo | :-) | 14:03 |
ltomasbo | ahh, I see the echo now :D | 14:03 |
*** janonymous_ has joined #openstack-kuryr | 14:04 | |
dulek_ | apuimedo: DevStack is spinning once again - I hope I've enabled it correctly this time. Meanwhile I'm learning how this thing works. | 14:04 |
*** dulek_ is now known as dulek | 14:04 | |
janonymous_ | apuimedo: Hi, Meeting today? | 14:05 |
apuimedo | cool | 14:05 |
apuimedo | right! | 14:05 |
apuimedo | I was forgetting | 14:05 |
janonymous_ | :D | 14:06 |
*** kiennt has joined #openstack-kuryr | 14:24 | |
*** zengchen1 has quit IRC | 14:29 | |
*** hongbin has joined #openstack-kuryr | 14:32 | |
*** robust has joined #openstack-kuryr | 14:34 | |
*** yasha has joined #openstack-kuryr | 14:37 | |
janonymous_ | apuimedo: https://etherpad.openstack.org/p/kuryr-queens-vPTG , can we set this in this channel's topic? for easy access | 14:38 |
apuimedo | janonymous_: I don't know how xD | 14:39 |
janonymous_ | apuimedo: :D | 14:40 |
*** robust has quit IRC | 14:45 | |
*** yasha has quit IRC | 14:51 | |
*** livelace has joined #openstack-kuryr | 14:55 | |
*** yasha has joined #openstack-kuryr | 14:59 | |
*** janonymous_ has quit IRC | 15:01 | |
*** gouthamr has joined #openstack-kuryr | 15:06 | |
*** janki|afk is now known as janki | 15:14 | |
livelace | apuimedo, ping | 15:20 |
livelace | Now, I have a problem with a ping of one host | 15:20 |
livelace | I created two ns, a21 and a22 | 15:21 |
livelace | inside VM created two VLAN, eth0.201, eth0.202 | 15:21 |
livelace | set those VLANs to NS, eth0.201/a21, eth0.202/a22 | 15:22 |
livelace | VLAN with appropriate MAC addresses, for port_security avoiding | 15:22 |
apuimedo | which is the problem? | 15:23 |
livelace | problem is, that I can ping only one host (full VM) inside this network | 15:24 |
livelace | https://paste.fedoraproject.org/paste/StM5z7vXNTMWRXyfBaZKUA | 15:25 |
*** yasha has quit IRC | 15:25 | |
livelace | https://paste.fedoraproject.org/paste/Md9CSVgewzenIXaOhHxiSA | 15:26 |
apuimedo | livelace: who has 172.16.2.8 | 15:27 |
livelace | https://paste.fedoraproject.org/paste/tTc6CTTShKHL2geSZCsNIw | 15:27 |
livelace | 2.8 in the same net as 2.9 | 15:27 |
apuimedo | livelace: and in which host do the containers run? 2.8 or 2.9? | 15:28 |
livelace | there is no containers at all | 15:28 |
livelace | I'm trying to reproduce the problem in clean environment | 15:28 |
livelace | without any abstraction layers | 15:29 |
apuimedo | livelace: right, sorry. I meant namespaces | 15:29 |
apuimedo | on which host did you create the namespaces | 15:29 |
livelace | On moment, with a diagram it will much simpler | 15:30 |
apuimedo | thanks! | 15:32 |
livelace | https://ibb.co/fYC2B5 | 15:34 |
livelace | CENTRAL works with TRUNK, both subport inside one NET, 2.8 and 2.9 sit in NET | 15:35 |
*** kiennt has quit IRC | 15:53 | |
livelace | apuimedo, two Pods on one VM, https://paste.fedoraproject.org/paste/7g0L0SYQXxdO7tM7v8Ze4w | 15:56 |
livelace | apuimedo, Did you try this situation in your environment ? | 15:56 |
*** dougbtv__ has joined #openstack-kuryr | 16:01 | |
*** egonzalez has quit IRC | 16:16 | |
livelace | brb | 16:16 |
*** pcaruana has quit IRC | 16:16 | |
*** dougbtv__ has quit IRC | 16:16 | |
*** janki has quit IRC | 16:49 | |
*** robust has joined #openstack-kuryr | 16:56 | |
*** c00281451_ has joined #openstack-kuryr | 16:57 | |
*** zengchen has quit IRC | 17:00 | |
*** gouthamr has quit IRC | 17:04 | |
livelace | apuimedo, ping | 17:08 |
*** livelace has quit IRC | 17:44 | |
*** egonzalez has joined #openstack-kuryr | 18:02 | |
*** deepika has quit IRC | 18:23 | |
*** yasha has joined #openstack-kuryr | 18:47 | |
*** atoth has quit IRC | 19:37 | |
yasha | apuimedo: I have gone through the code on github ( https://github.com/openstack/kuryr-kubernetes )and the bugs on launchpad(https://bugs.launchpad.net/kuryr-kubernetes). Moreover , According to the First timers' documentation (https://wiki.openstack.org/wiki/Documentation/HowTo/FirstTimers),I have cloned the repository and setup respective virtualenvs. Could you pls help with a issue to start with ? | 20:13 |
*** yasha has quit IRC | 21:16 | |
*** lakerzhou has quit IRC | 21:29 | |
*** gouthamr has joined #openstack-kuryr | 21:30 | |
*** aojea has quit IRC | 21:47 | |
*** gouthamr has quit IRC | 22:05 | |
*** egonzalez has quit IRC | 22:39 | |
openstackgerrit | Hongbin Lu proposed openstack/kuryr-libnetwork master: [WIP][NOT_READY_TO_REVIEW] Support create with unaddresses port https://review.openstack.org/504798 | 23:31 |
*** hongbin has quit IRC | 23:34 | |
*** yamamoto has joined #openstack-kuryr | 23:36 | |
*** lakerzhou has joined #openstack-kuryr | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!