*** jistr has quit IRC | 00:00 | |
*** jistr has joined #openstack-kuryr | 00:01 | |
*** livelace has quit IRC | 00:21 | |
*** livelace has joined #openstack-kuryr | 00:21 | |
*** phuoc_ has quit IRC | 00:52 | |
*** phuoc_ has joined #openstack-kuryr | 00:53 | |
*** atoth has quit IRC | 01:27 | |
*** Exaeta has joined #openstack-kuryr | 01:37 | |
*** Exaeta has quit IRC | 01:43 | |
*** hongbin has joined #openstack-kuryr | 01:47 | |
*** hongbin_ has joined #openstack-kuryr | 01:51 | |
*** hongbin has quit IRC | 01:52 | |
*** eido1on has joined #openstack-kuryr | 01:54 | |
eido1on | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 01:54 |
---|---|---|
eido1on | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 01:54 |
eido1on | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 01:54 |
eido1on | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 01:54 |
*** eido1on has quit IRC | 01:55 | |
*** Humvee14 has joined #openstack-kuryr | 01:56 | |
*** Humvee14 has quit IRC | 01:56 | |
*** BurningPrincess3 has joined #openstack-kuryr | 02:15 | |
BurningPrincess3 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 02:15 |
BurningPrincess3 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 02:15 |
BurningPrincess3 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 02:15 |
BurningPrincess3 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 02:15 |
*** BurningPrincess3 has quit IRC | 02:16 | |
*** jcline27 has joined #openstack-kuryr | 02:23 | |
*** jcline27 has quit IRC | 02:24 | |
*** wsm has joined #openstack-kuryr | 02:27 | |
wsm | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 02:27 |
wsm | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 02:27 |
wsm | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 02:27 |
wsm | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 02:27 |
*** wsm has quit IRC | 02:28 | |
*** duoi1 has joined #openstack-kuryr | 02:28 | |
duoi1 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 02:28 |
duoi1 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 02:28 |
duoi1 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 02:28 |
duoi1 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 02:28 |
*** duoi1 has quit IRC | 02:29 | |
*** EvanR26 has joined #openstack-kuryr | 02:48 | |
*** EvanR26 has quit IRC | 02:48 | |
*** hongbin_ has quit IRC | 02:54 | |
*** tzumainn has quit IRC | 03:01 | |
openstackgerrit | wangqi proposed openstack/kuryr-kubernetes master: fix a typo https://review.openstack.org/587674 | 03:03 |
*** m71220 has joined #openstack-kuryr | 03:05 | |
m71220 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 03:05 |
m71220 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 03:05 |
m71220 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 03:05 |
m71220 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 03:05 |
*** m71220 has quit IRC | 03:06 | |
*** emerson has joined #openstack-kuryr | 03:51 | |
emerson | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 03:51 |
emerson | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 03:51 |
emerson | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 03:51 |
emerson | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 03:51 |
*** emerson is now known as Guest52568 | 03:51 | |
*** Guest52568 has quit IRC | 03:51 | |
*** Hobby7 has joined #openstack-kuryr | 04:00 | |
Hobby7 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 04:00 |
Hobby7 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 04:00 |
Hobby7 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 04:00 |
Hobby7 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 04:01 |
*** Hobby7 has quit IRC | 04:02 | |
*** davidebeatrici6 has joined #openstack-kuryr | 04:04 | |
davidebeatrici6 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 04:04 |
davidebeatrici6 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 04:04 |
davidebeatrici6 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 04:04 |
*** davidebeatrici6 has quit IRC | 04:05 | |
*** snapiri has joined #openstack-kuryr | 04:21 | |
*** matlock has joined #openstack-kuryr | 04:32 | |
matlock | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 04:32 |
matlock | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 04:32 |
matlock | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 04:32 |
matlock | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 04:32 |
*** matlock has quit IRC | 04:34 | |
*** kzaitsev_pi has quit IRC | 05:17 | |
*** yar21 has joined #openstack-kuryr | 05:17 | |
yar21 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 05:17 |
yar21 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 05:18 |
yar21 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 05:18 |
yar21 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 05:18 |
*** yar21 has quit IRC | 05:18 | |
*** kzaitsev_pi has joined #openstack-kuryr | 05:24 | |
*** itzikb has joined #openstack-kuryr | 05:30 | |
*** CoJaBo29 has joined #openstack-kuryr | 05:31 | |
CoJaBo29 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 05:31 |
CoJaBo29 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 05:31 |
CoJaBo29 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 05:31 |
CoJaBo29 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 05:31 |
*** CoJaBo29 has quit IRC | 05:32 | |
*** lannister has joined #openstack-kuryr | 05:43 | |
lannister | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 05:43 |
lannister | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 05:43 |
lannister | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 05:43 |
lannister | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 05:43 |
*** lannister has quit IRC | 05:44 | |
*** Praise5 has joined #openstack-kuryr | 05:52 | |
*** Praise5 has quit IRC | 05:52 | |
*** janki has joined #openstack-kuryr | 05:52 | |
*** ZLSA22 has joined #openstack-kuryr | 05:53 | |
ZLSA22 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 05:53 |
ZLSA22 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 05:53 |
ZLSA22 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 05:53 |
ZLSA22 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 05:53 |
*** ZLSA22 has quit IRC | 05:53 | |
*** Ceber19 has joined #openstack-kuryr | 06:04 | |
Ceber19 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 06:04 |
Ceber19 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 06:04 |
Ceber19 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 06:04 |
Ceber19 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 06:05 |
*** Ceber19 has quit IRC | 06:06 | |
*** dims has quit IRC | 06:13 | |
*** alefir has joined #openstack-kuryr | 06:14 | |
alefir | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 06:14 |
alefir | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 06:14 |
alefir | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 06:14 |
alefir | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 06:15 |
*** dims has joined #openstack-kuryr | 06:15 | |
*** alefir is now known as Guest58486 | 06:15 | |
*** Guest58486 has quit IRC | 06:16 | |
*** dims has quit IRC | 06:22 | |
*** olspookishmagus8 has joined #openstack-kuryr | 06:23 | |
olspookishmagus8 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 06:23 |
olspookishmagus8 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 06:23 |
olspookishmagus8 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 06:23 |
olspookishmagus8 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 06:23 |
*** olspookishmagus8 has quit IRC | 06:24 | |
*** dims has joined #openstack-kuryr | 06:24 | |
*** celebdor1 has joined #openstack-kuryr | 06:41 | |
*** pcaruana has joined #openstack-kuryr | 06:42 | |
*** Theking^15 has joined #openstack-kuryr | 06:47 | |
Theking^15 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 06:47 |
Theking^15 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 06:47 |
Theking^15 | Read what IRC investigative journalists have uncovered on the freenode pedophilia scandal https://encyclopediadramatica.rs/Freenodegate | 06:47 |
Theking^15 | A fascinating blog by freenode staff member Matthew 'mst' Trout https://MattSTrout.com/ | 06:47 |
*** AlexeyPerevalov has quit IRC | 06:48 | |
*** AlexeyPerevalov has joined #openstack-kuryr | 06:48 | |
*** Theking^15 has quit IRC | 06:51 | |
*** MrElendig16 has joined #openstack-kuryr | 06:54 | |
MrElendig16 | With our IRC ad service you can reach a global audience of entrepreneurs and fentanyl addicts with extraordinary engagement rates! https://williampitcock.com/ | 06:54 |
MrElendig16 | I thought you guys might be interested in this blog by freenode staff member Bryan 'kloeri' Ostergaard https://bryanostergaard.com/ | 06:54 |
*** MrElendig16 has quit IRC | 06:54 | |
dmellado | awesome, we've earned our own spammers.... | 06:56 |
*** gcheresh has joined #openstack-kuryr | 06:56 | |
*** ChanServ sets mode: +r | 07:15 | |
celebdor1 | dmellado: are you around? | 07:17 |
celebdor1 | dulek: please, take a look at https://review.openstack.org/#/c/575629/16 | 07:18 |
dulek | celebdor1: I wasn't following those efforts too much. So this is the decided way of implementing multi-vif? | 07:25 |
dulek | IIRC we had 3 of them. :P | 07:25 |
*** threestrands has quit IRC | 07:26 | |
ltomasbo | dulek, celebdor1m, dmellado: also take a look at: https://review.openstack.org/#/c/579181 :D | 07:29 |
ltomasbo | celebdor1, ^ | 07:29 |
celebdor1 | dulek: that's how it looks like in the k8s community | 07:29 |
celebdor1 | ltomasbo: gotcha | 07:31 |
ltomasbo | celebdor1, this should be backported right? | 07:36 |
ltomasbo | https://review.openstack.org/#/c/580198/ | 07:36 |
celebdor1 | ltomasbo: yes | 07:37 |
celebdor1 | please do | 07:37 |
ltomasbo | ok! | 07:37 |
ltomasbo | as there is quite some changes since then, can you take a look if I missed something: https://review.openstack.org/587706 | 07:38 |
ltomasbo | celebdor1, ^^ | 07:38 |
celebdor1 | sure | 07:40 |
dulek | ltomasbo: FYI - stable/queens gate is broken at the moment. I'll take a look after those reviews. :P | 07:44 |
ltomasbo | dulek, I just saw the email! thanks! | 07:48 |
dmellado | dulek, celebdor1, ltomasbo | 07:58 |
dmellado | We'll have a meeting re multi-vif next Mon | 07:58 |
dmellado | Did you see my mail? | 07:58 |
celebdor1 | dmellado: I did not see the email | 07:59 |
celebdor1 | one minute you ask for less meetings, the next you add meetings | 07:59 |
celebdor1 | are you plotting together with my wife to make me doubt my sanity? | 07:59 |
celebdor1 | xD | 07:59 |
ltomasbo | lol | 08:04 |
dmellado | We discussed that in the last meeting xD | 08:09 |
dmellado | You slacker xD | 08:09 |
celebdor1 | oh | 08:13 |
celebdor1 | we did... | 08:13 |
celebdor1 | start calling the asylum for me | 08:13 |
celebdor1 | ltomasbo: did you ensure somehow that with https://review.openstack.org/#/c/579181 the pods can talk to the host k8s monitoring ports? | 08:29 |
ltomasbo | celebdor1, nop, I didn't address that on this patch | 08:30 |
celebdor1 | ok | 08:30 |
celebdor1 | thanks | 08:30 |
celebdor1 | let's tackle that on a follow-up patch | 08:30 |
celebdor1 | then | 08:30 |
ltomasbo | celebdor1, that will depend on the subnet VM security group instead, right? | 08:30 |
ltomasbo | pod egress traffic is not blocked | 08:31 |
dulek | ltomasbo: How does https://review.openstack.org/#/c/575629 relate to pools? | 08:31 |
celebdor1 | VM? This also applies to baremetal and the kubelet interface, doesn't it? | 08:31 |
ltomasbo | (by default_ | 08:31 |
dulek | ltomasbo: I assume it's simply using pool driver if its configured, right? | 08:31 |
ltomasbo | celebdor1, yes, let me see if the traffic is block in that case, perhaps it is already enabled | 08:31 |
celebdor1 | ;-) | 08:32 |
ltomasbo | celebdor1, for the baremetal case, I can ping the host | 08:33 |
ltomasbo | at least with devstack deployment there is nothing preventing that traffic | 08:33 |
celebdor1 | ltomasbo: and talk to other ports? | 08:33 |
celebdor1 | icmp is not a very good signal | 08:33 |
ltomasbo | celebdor1, for the openshift-ansible (nested) we will need to modify the vms sg | 08:33 |
celebdor1 | ltomasbo: yes, I know | 08:34 |
celebdor1 | I'm talking only of devstack and tempest here | 08:34 |
celebdor1 | ltomasbo: is it me or in https://review.openstack.org/#/c/579181/20/doc/source/installation/network_namespace.rst you swapped around SG_ID_2 and SG_ID_1? | 08:35 |
ltomasbo | celebdor1, let me see | 08:35 |
ltomasbo | dulek, I think the pool driver is right, it is used in the same way as before for the main_vif | 08:36 |
ltomasbo | dulek, for the additional vif, as there is just an empty implementation, it will not matter (yet) | 08:36 |
ltomasbo | celebdor1, you mean in lines 57 and 58? | 08:37 |
ltomasbo | celebdor1, it is meant to be like that, sg 1 should enable access from Sg_id_2 | 08:37 |
celebdor1 | yes | 08:37 |
celebdor1 | ltomasbo: those two lines confuse me terribly | 08:38 |
ltomasbo | and viceversa, so that when I add sg sg_allow_from_namespace to the pods on the default namespace | 08:38 |
celebdor1 | sg_allow_from_namespaces | 08:38 |
ltomasbo | it allows traffic from the pods with sg sg_id_2 | 08:38 |
celebdor1 | means that the selected SG will accept connections from all other namespaces, right? | 08:38 |
ltomasbo | celebdor1, so, in a nutshell, SG_1 should have a rule that allows all traffic from sg_2 | 08:38 |
ltomasbo | and viceversa | 08:38 |
ltomasbo | then, I add sg_1 to the pods on the default namespace | 08:39 |
celebdor1 | ok | 08:39 |
ltomasbo | and sg_2 to the pods on the other namespaces | 08:39 |
celebdor1 | those docstrings are confusing | 08:39 |
ltomasbo | (it took me a while to get that right actually) | 08:39 |
celebdor1 | the first one should probably be | 08:39 |
celebdor1 | # Makes SG_ID_1 allow traffic from SG_ID_2 | 08:39 |
celebdor1 | or rather | 08:40 |
celebdor1 | # Makes SG_ID_1 allow traffic from the SG in SG_ALLOW_FROM_DEFAULT | 08:40 |
ltomasbo | ok, I'll update it | 08:41 |
celebdor1 | thanks | 08:41 |
celebdor1 | with that | 08:41 |
celebdor1 | I think I can +2 | 08:41 |
ltomasbo | only that?? nice! | 08:41 |
celebdor1 | well, I'm still finishing the review | 08:42 |
celebdor1 | I may find more | 08:42 |
celebdor1 | but irenab already +2, and I generally trust her reviews | 08:42 |
ltomasbo | btw, you are right, I cannot access port 80 on the host from the pods | 08:42 |
celebdor1 | heh | 08:43 |
celebdor1 | I knew it! | 08:43 |
celebdor1 | xD | 08:43 |
irenab | celebdor1, what did I do? Lost your trust? | 08:45 |
ltomasbo | celebdor1, did you check that without namespaces? | 08:45 |
celebdor1 | irenab: no, no | 08:45 |
celebdor1 | ltomasbo lost it | 08:45 |
celebdor1 | xD | 08:46 |
ltomasbo | xD | 08:46 |
irenab | :-) | 08:46 |
celebdor1 | ltomasbo: no, I have not | 08:46 |
ltomasbo | celebdor1, I did not add any rule to block that traffic... that is why I'm asking... | 08:47 |
celebdor1 | ltomasbo: the docstrings you have in the config options https://review.openstack.org/#/c/579181/20/kuryr_kubernetes/controller/drivers/namespace_security_groups.py is good | 08:49 |
*** pmannidi has quit IRC | 08:49 | |
celebdor1 | ltomasbo: but you are using different SGs | 08:49 |
* dulek ignores ltomasbo patch for now and starts to fix stable/queens. | 08:52 | |
celebdor1 | dulek: good | 08:53 |
ltomasbo | celebdor1, not sure I follow... | 08:54 |
celebdor1 | ltomasbo: before namespaces, all the pods and kubelet interface are all in the default sg of the project, aren't they? | 08:55 |
ltomasbo | yes | 08:55 |
ltomasbo | celebdor1, ahh, I though your 2 comments were related | 08:56 |
ltomasbo | you refer to the help string, first right? | 08:56 |
ltomasbo | and then to the fact that the default sg from the k8s project is not used anymore | 08:57 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Ensure isolation between namespaces https://review.openstack.org/579181 | 08:58 |
celebdor1 | ltomasbo: yes, first the help string | 08:59 |
celebdor1 | right | 08:59 |
ltomasbo | celebdor1, I had to remove that one, otherwise traffic from pod to pod in different namespaces is allowed | 09:00 |
celebdor1 | ltomasbo: of course | 09:00 |
celebdor1 | :-) | 09:00 |
celebdor1 | and the access to the host was lost as a side effect | 09:01 |
celebdor1 | I wonder if you also lost the probes | 09:01 |
ltomasbo | btw, dulek celebdor1: this is an important one: https://review.openstack.org/#/c/587565 | 09:01 |
celebdor1 | I think you should just put the kubelet iface to be in the same SG as the default namespace | 09:01 |
ltomasbo | without that one, services cannot be updated, or better said, once updated, the pools has no members... | 09:01 |
ltomasbo | celebdor1, taht is a good point | 09:02 |
celebdor1 | ;-) | 09:02 |
ltomasbo | let me try that! | 09:02 |
celebdor1 | please, change that in your current patch | 09:02 |
celebdor1 | ltomasbo: can you backport this patch from yossi? | 09:03 |
ltomasbo | celebdor1, he already did (even though it is not yet merged) | 09:03 |
ltomasbo | https://review.openstack.org/#/c/587583/ | 09:03 |
celebdor1 | ah, great! | 09:04 |
ltomasbo | I will update it with the cherry-pick info once the master one gets in | 09:04 |
celebdor1 | perfect | 09:05 |
celebdor1 | thanks | 09:05 |
dulek | celebdor1: Is stable/queens using the same kuryr/demo container as master? | 09:06 |
celebdor1 | dulek: I suppose | 09:07 |
celebdor1 | I don't recall | 09:07 |
celebdor1 | but this is set by tempest | 09:07 |
celebdor1 | and tempest runs the same regardless of branch, doesn't it | 09:08 |
celebdor1 | dmellado: ^^ | 09:08 |
dmellado | That can be set on the ci | 09:08 |
dmellado | Should be the same as of now | 09:08 |
celebdor1 | dulek: why? | 09:09 |
dulek | celebdor1: Basically the issue with stable/queens breakage is fact that from pod to service curl starts to produce progress bar. I'm trying to understand why I don't see that on master. | 09:10 |
dulek | Maybe it's due to kubernetes Python lib… I'll check. | 09:10 |
ltomasbo | dulek, probably not | 09:12 |
*** itzikb has quit IRC | 09:12 | |
ltomasbo | dulek, probably is using celebdor/kuryr-demo | 09:12 |
dulek | ltomasbo: I don't see why - we aren't branching tempest plugin. | 09:12 |
ltomasbo | ahh, true | 09:12 |
ltomasbo | then it should use the kuryr/demo | 09:13 |
celebdor1 | dulek: progress bar? | 09:13 |
celebdor1 | dafuq | 09:13 |
ltomasbo | celebdor1, btw, same security group does not help either... | 09:13 |
dulek | celebdor1: http://logs.openstack.org/83/587583/1/check/kuryr-kubernetes-tempest-octavia/0ee8862/job-output.txt.gz#_2018-07-31_20_00_15_187711 | 09:13 |
celebdor1 | ltomasbo: you sure you are using ovs firewall? | 09:14 |
celebdor1 | dulek: that's weird | 09:14 |
celebdor1 | let me check something | 09:14 |
ltomasbo | ltomasbo, yep, only tap devices, no qbr or such | 09:14 |
ltomasbo | celebdor1, ^^ | 09:14 |
dulek | celebdor1: I suspect older Python kubernetes client ignores stderr=False and prints it. | 09:15 |
dulek | celebdor1: I'll just try `-s`. | 09:15 |
celebdor1 | ltomasbo: please, check on neutron.conf | 09:16 |
dmellado | Dulek | 09:16 |
celebdor1 | dulek: right, that's why I wanted to fix it in tempest | 09:16 |
dmellado | That's branchless | 09:16 |
ltomasbo | 27 firewall_driver = openvswitch | 09:16 |
dmellado | And we won't be branching it but tagging | 09:17 |
dulek | dmellado: Yeah, but global-requirements.txt is different. | 09:17 |
dulek | dmellado: On master and stable/queens. So this must be the cause. | 09:17 |
dmellado | Tag should handle that | 09:17 |
dmellado | Works the same with upstream tempest | 09:17 |
ltomasbo | celebdor1, found the issue | 09:17 |
dmellado | Nevertheless | 09:17 |
dmellado | At the doctor now | 09:18 |
dmellado | Bbl | 09:18 |
celebdor1 | dulek: just pass "--silent" | 09:18 |
celebdor1 | to curl | 09:18 |
celebdor1 | ltomasbo: what's it? | 09:18 |
ltomasbo | celebdor1, it is the iptables rule on the host | 09:18 |
celebdor1 | which? | 09:18 |
dulek | celebdor1: I'll try that, though it might be dependent on curl version. | 09:18 |
ltomasbo | celebdor1, -A INPUT -j REJECT --reject-with icmp-host-prohibited | 09:18 |
dulek | celebdor1: https://stackoverflow.com/questions/7373752/how-do-i-get-curl-to-not-show-the-progress-bar | 09:18 |
ltomasbo | celebdor1, -A FORWARD -j REJECT --reject-with icmp-host-prohibited | 09:18 |
celebdor1 | I think --silent's been there since forever | 09:18 |
dulek | celebdor1: But hopefully version from your container works fine. :) | 09:18 |
celebdor1 | and in kuryr/demo we compile a very recent version anyway | 09:19 |
celebdor1 | 7.58 | 09:19 |
celebdor1 | we use | 09:19 |
celebdor1 | which is just under the one in fedora 7.59 | 09:19 |
dulek | celebdor1: Awesome! | 09:21 |
openstackgerrit | Michał Dulko proposed openstack/kuryr-tempest-plugin master: Add -Ss to curl executions https://review.openstack.org/587736 | 09:22 |
celebdor1 | ;-) | 09:23 |
ltomasbo | celebdor1, so, without the iptable rule works without any changes, no need to change the sg to the kubelet | 09:23 |
celebdor1 | interesting | 09:23 |
celebdor1 | I guess we already allow everything in the default sg | 09:23 |
ltomasbo | celebdor1, egreess traffic is always enabled by default | 09:24 |
ltomasbo | only ingress is restricted | 09:24 |
ltomasbo | so pod -> host is enabled | 09:24 |
ltomasbo | host -> pod is forbidden | 09:24 |
celebdor1 | host -> pod is necessary for the probes! | 09:24 |
celebdor1 | hence my comment of using the default ns sg | 09:25 |
ltomasbo | what probes? for the kuryr-controller and cni? | 09:25 |
*** maysamacedos has quit IRC | 09:28 | |
dmellado | ok, so on my desktop now | 09:28 |
dmellado | what was the issue with the branching, folks | 09:28 |
*** snapiri has quit IRC | 09:29 | |
celebdor1 | ltomasbo: and other ports that may need them | 09:31 |
celebdor1 | a lot of apps use probes for health | 09:31 |
ltomasbo | ok | 09:31 |
ltomasbo | I think we may need to modify the route too | 09:31 |
celebdor1 | dmellado: solved already | 09:31 |
celebdor1 | which route? | 09:31 |
ltomasbo | as it only includes 10.0.0.64/26 | 09:31 |
ltomasbo | for the kubelet | 09:31 |
ltomasbo | and with namespaces it will need to be the subnetpool id I guess | 09:32 |
ltomasbo | to cover all | 09:32 |
celebdor1 | true | 09:32 |
ltomasbo | celebdor1, it will be nice to have a tempest test with a pod with probes | 09:36 |
ltomasbo | we have never tested that, so we can get some surprises... | 09:37 |
ltomasbo | :q | 09:37 |
celebdor1 | ltomasbo: yes, will add that | 09:40 |
celebdor1 | I'm now adding https to kuryr/demo | 09:41 |
openstackgerrit | Merged openstack/kuryr-kubernetes master: Implement multi-vif driver https://review.openstack.org/575629 | 09:41 |
openstackgerrit | Merged openstack/kuryr-kubernetes master: Services: Fix service connectivity after service port edit procedure https://review.openstack.org/587565 | 09:58 |
dulek | celebdor1, dmellado, irenab: zuul.openstack.org tells me that 587738 already passes LBaaSv2 gate, so seems like https://review.openstack.org/#/c/587736/ unblocks stable/queens. | 10:01 |
dulek | (previously no Tempest tests passed). | 10:01 |
celebdor1 | awesome, thanks dulek | 10:02 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-tempest-plugin master: Make Port and http/https configurable for the test container https://review.openstack.org/587746 | 10:03 |
celebdor1 | dulek: ltomasbo: dmellado: gcheresh: https support for the demo container ;-) | 10:04 |
celebdor1 | I'll now rebuild the image and update the patch | 10:05 |
celebdor1 | so far I only tested the binary alone | 10:05 |
openstackgerrit | Michał Dulko proposed openstack/kuryr-tempest-plugin master: Add -Ss to curl executions https://review.openstack.org/587736 | 10:05 |
gcheresh | celebdor1: thanks | 10:05 |
dulek | celebdor1, dmellado, irenab: I've fixed the pep8 error in stable/queens fix. :) | 10:06 |
dulek | celebdor1: golang has tabs preferred? :) | 10:06 |
dmellado | dulek: link? | 10:08 |
celebdor1 | dulek: yest | 10:08 |
celebdor1 | *yes | 10:08 |
dulek | dmellado: https://review.openstack.org/587736 | 10:08 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-tempest-plugin master: Namespace isolation tempest coverage https://review.openstack.org/580678 | 10:28 |
celebdor1 | man... pushing docker images on rural dsl sucks | 10:54 |
celebdor1 | and it took me long to figure out why the cert was not working | 10:55 |
celebdor1 | guess what | 10:55 |
celebdor1 | the volume mount was being blocked by selinux | 10:55 |
celebdor1 | brrrr | 10:55 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-tempest-plugin master: Make Port and http/https configurable for the test container https://review.openstack.org/587746 | 10:56 |
*** threestrands has joined #openstack-kuryr | 11:15 | |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-tempest-plugin master: Namespace svc isolation tempest coverage https://review.openstack.org/587778 | 11:29 |
celebdor1 | irenab: dulek: Can we get https://review.openstack.org/#/c/580701/1 merged? | 11:41 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services https://review.openstack.org/581421 | 11:42 |
*** gcheresh has quit IRC | 11:42 | |
*** janki has quit IRC | 11:44 | |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Ensure isolation between namespaces https://review.openstack.org/579181 | 11:46 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services https://review.openstack.org/581421 | 11:46 |
ltomasbo | celebdor1, I've updated the patch with the devstack modification regarding the sg for the kubelet | 11:47 |
celebdor1 | great. Thanks ltomasbo | 11:48 |
ltomasbo | celebdor1, and the tempest test extension! https://review.openstack.org/#/c/587778 | 11:51 |
celebdor1 | I can't find the change for the kubelet in https://review.openstack.org/#/c/581421/13 | 11:52 |
celebdor1 | oh, it's on the other patch | 11:52 |
celebdor1 | xD | 11:52 |
ltomasbo | celebdor1, yes, at 579181 | 11:53 |
ltomasbo | celebdor1, I'm deploying it to ensure there is no problem with that | 11:53 |
celebdor1 | ltomasbo: why does it need allow_from_default | 11:54 |
celebdor1 | ? | 11:54 |
ltomasbo | I added both to that one to enable access from namespaces and default-namespace | 11:54 |
ltomasbo | so, allow_from_namespaces adds access from namespaces different to default | 11:55 |
ltomasbo | and allow_from_default from pods on the default namespace | 11:55 |
celebdor1 | also -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 --dport $port_number -j ACCEPT || \ | 11:55 |
celebdor1 | allow everything? | 11:55 |
* celebdor1 -> lunch | 11:56 | |
ltomasbo | ohh, I didn't read that one, let me see... | 11:56 |
ltomasbo | celebdor1, we should open the healthcheck ports right? though that for sure belongs to a different patch set | 11:59 |
openstackgerrit | Merged openstack/kuryr-tempest-plugin master: Add -Ss to curl executions https://review.openstack.org/587736 | 12:20 |
celebdor1 | ok | 12:27 |
dmellado | the temperature here in Madrid is awesome | 12:28 |
dmellado | celebdor1: won't you fancy visiting us again? | 12:28 |
celebdor1 | dmellado: temperatures under 50 don't affect me | 12:30 |
celebdor1 | amount of PP voters does | 12:30 |
ltomasbo | lol | 12:30 |
dmellado | celebdor1: that also raises the temperature | 12:31 |
dmellado | celebdor1: https://78.media.tumblr.com/209bd0f9fea465f97fc9ba8f87ad6825/tumblr_pbpobw6uNp1s9y3qio1_1280.jpg | 12:31 |
celebdor1 | facha & facha asociados | 12:32 |
dmellado | you shouldn't have allowed yours to leave Catalonia ever | 12:34 |
*** openstack has joined #openstack-kuryr | 12:56 | |
*** barjavel.freenode.net sets mode: +ns | 12:56 | |
*** barjavel.freenode.net sets mode: -o openstack | 13:00 | |
-barjavel.freenode.net- *** Notice -- TS for #openstack-kuryr changed from 1533128168 to 1448289943 | 13:00 | |
*** barjavel.freenode.net sets mode: +crt-s | 13:00 | |
*** lihi has joined #openstack-kuryr | 13:00 | |
*** leifmadsen_ has joined #openstack-kuryr | 13:00 | |
*** AlexeyPerevalov has joined #openstack-kuryr | 13:00 | |
*** pcaruana has joined #openstack-kuryr | 13:00 | |
*** celebdor1 has joined #openstack-kuryr | 13:00 | |
*** dims has joined #openstack-kuryr | 13:00 | |
*** kzaitsev_pi has joined #openstack-kuryr | 13:00 | |
*** phuoc_ has joined #openstack-kuryr | 13:00 | |
*** livelace has joined #openstack-kuryr | 13:00 | |
*** jistr has joined #openstack-kuryr | 13:00 | |
*** rh-jelabarre has joined #openstack-kuryr | 13:00 | |
*** shadower has joined #openstack-kuryr | 13:00 | |
*** openstackgerrit has joined #openstack-kuryr | 13:00 | |
*** dougbtv_ has joined #openstack-kuryr | 13:00 | |
*** irenab has joined #openstack-kuryr | 13:00 | |
*** kiseok7 has joined #openstack-kuryr | 13:00 | |
*** s1061123 has joined #openstack-kuryr | 13:00 | |
*** dmellado has joined #openstack-kuryr | 13:00 | |
*** oanson has joined #openstack-kuryr | 13:00 | |
*** pc_m has joined #openstack-kuryr | 13:00 | |
*** celebdor[m] has joined #openstack-kuryr | 13:00 | |
*** mrostecki[m] has joined #openstack-kuryr | 13:00 | |
*** dulek has joined #openstack-kuryr | 13:00 | |
*** russellb has joined #openstack-kuryr | 13:00 | |
*** lxkong has joined #openstack-kuryr | 13:00 | |
*** portdirect has joined #openstack-kuryr | 13:00 | |
*** mfedosin has joined #openstack-kuryr | 13:00 | |
*** pliu has joined #openstack-kuryr | 13:00 | |
*** ltomasbo has joined #openstack-kuryr | 13:00 | |
*** juriarte has joined #openstack-kuryr | 13:00 | |
*** spotz has joined #openstack-kuryr | 13:00 | |
*** korean101 has joined #openstack-kuryr | 13:00 | |
*** ajo has joined #openstack-kuryr | 13:00 | |
*** fkautz has joined #openstack-kuryr | 13:00 | |
*** gigo has joined #openstack-kuryr | 13:00 | |
*** ChanServ has joined #openstack-kuryr | 13:00 | |
*** barjavel.freenode.net sets mode: +o ChanServ | 13:00 | |
*** tzumainn has joined #openstack-kuryr | 13:03 | |
openstackgerrit | Michał Dulko proposed openstack/kuryr-kubernetes master: Log traceback on errors in Watcher https://review.openstack.org/587815 | 13:06 |
irenab | celebdor1, merging | 13:12 |
celebdor1 | thanks!!! | 13:13 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-tempest-plugin master: Namespace isolation tempest coverage https://review.openstack.org/580678 | 13:21 |
celebdor1 | dulek: I answered your question about the ENV in the new version of the test container | 13:22 |
celebdor1 | dmellado: did we make the gate build the container or is it still pulling from dockerhub? | 13:22 |
*** ChanServ sets mode: +f #openstack-unregistered | 13:23 | |
dmellado | celebdor1: IIRC you did that patch | 13:24 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services https://review.openstack.org/581421 | 13:29 |
celebdor1 | dmellado: I thought I did it for the tempest devstack patch | 13:30 |
celebdor1 | but it needed to be on some sort of ansible tempest crap | 13:30 |
celebdor1 | and I have no recollection of doing that | 13:30 |
dmellado | oh, just put up a playbook on the playbooks directory | 13:31 |
dmellado | let me get you a patch | 13:31 |
dmellado | https://review.openstack.org/#/c/560313/ | 13:33 |
celebdor1 | thanks dmellado | 13:35 |
celebdor1 | partial thanks only, cause this will force me to write ansible | 13:35 |
celebdor1 | when do the playbooks run? | 13:37 |
celebdor1 | before devstack, don't they? | 13:37 |
dmellado | celebdor1: it kinda depends | 13:37 |
dmellado | you can have them run either before, during or after | 13:38 |
dmellado | pre-run will make them run before, ofc | 13:38 |
dmellado | xD | 13:38 |
celebdor1 | we need it to run after devstack and before tempest | 13:38 |
celebdor1 | so that devstack has already installed docker | 13:38 |
celebdor1 | oh, and tempest must have been cloned already | 13:38 |
celebdor1 | so that there is the container image tarball | 13:39 |
ltomasbo | irenab, I lost your +2 on this one: https://review.openstack.org/#/c/579181 | 13:41 |
ltomasbo | celebdor1, I tested https://review.openstack.org/#/c/579181 | 13:41 |
ltomasbo | celebdor1, with the new addition for the sg, they are applied properly | 13:42 |
openstackgerrit | Michał Dulko proposed openstack/kuryr-kubernetes master: Change Pod annotations format to o.vo https://review.openstack.org/584377 | 13:42 |
openstackgerrit | Michał Dulko proposed openstack/kuryr-kubernetes master: Fix compatiblity with old Pod annotation format https://review.openstack.org/584421 | 13:42 |
ltomasbo | but, should I then expect connectivity from the host (kubelet) to the pods? | 13:42 |
celebdor1 | ltomasbo: good | 13:44 |
celebdor1 | I already +2ed | 13:44 |
celebdor1 | now you need dulek and irenab | 13:44 |
dulek | celebdor1: On it, just a sec. | 13:44 |
celebdor1 | :-) | 13:44 |
celebdor1 | dulek: I'm not hurrying you, that's ltomasbo's job | 13:44 |
celebdor1 | I'm just getting him off my back | 13:45 |
celebdor1 | xD | 13:45 |
dulek | Meanwhile patches with pod annotation format are now tested and rebased after with pliu's patch. :) | 13:45 |
ltomasbo | xD | 13:45 |
celebdor1 | dulek: awesome | 13:46 |
celebdor1 | I'll try to review today | 13:46 |
celebdor1 | but probably will finish tomorrow | 13:46 |
celebdor1 | dmellado: I invoke the zuul in you | 13:47 |
celebdor1 | I wanna hear "There is no Dani, only zuul" | 13:48 |
dmellado | https://i0.wp.com/www.elciudadano.cl/wp-content/uploads/2017/05/Zuul.png | 13:48 |
dulek | celebdor1: I now only wonder about one issue with upgrades. | 13:48 |
celebdor1 | dulek: which | 13:49 |
dmellado | celebdor1: did you know that HP used to run a zuul clone called gozer? | 13:49 |
celebdor1 | dmellado: alright | 13:49 |
dmellado | xD | 13:49 |
dmellado | celebdor1: so what's up | 13:49 |
celebdor1 | IIURC | 13:49 |
celebdor1 | *IIUC | 13:49 |
dmellado | before we go to the httpd restart meeting | 13:49 |
celebdor1 | I should modify .zuul.d/base.yaml | 13:49 |
dulek | celebdor1: Basically if we want to remove compatibility code in Stein we need some way of converting all *untouched* annotations after the Q->R upgrade. | 13:49 |
dulek | celebdor1: And at this moment the code is contained into a small utility method, so I'm tempted to just live with it and don't care about it now. | 13:50 |
celebdor1 | to have a job that is a parent to kuryr-kubernetes-tempest-base | 13:51 |
celebdor1 | that does not include tempest, only all the other stuff | 13:51 |
dmellado | why would you like to have that? | 13:52 |
celebdor1 | well, how can I have something run after tempest is cloned but before it runs the tests? | 13:52 |
dmellado | https://docs.openstack.org/infra/manual/zuulv3.html | 13:54 |
dmellado | I'd check in which phase is tempest actually run | 13:54 |
dmellado | on is parent playbook | 13:54 |
dmellado | http://git.openstack.org/cgit/openstack/tempest/tree/.zuul.yaml#n37 | 13:55 |
dmellado | in any case now that I recall, tempest should be clones as it'd be on required-projects | 13:57 |
*** janki has joined #openstack-kuryr | 14:20 | |
openstackgerrit | Michał Dulko proposed openstack/kuryr-kubernetes master: Log traceback on errors in Watcher https://review.openstack.org/587815 | 14:37 |
* ltomasbo moving from hurrying celebdor1 to hurrying dulek | 14:41 | |
dulek | ltomasbo: :) | 14:41 |
ltomasbo | dulek, it would be great if you can take a look to https://review.openstack.org/#/c/579181/ | 14:42 |
ltomasbo | :D | 14:42 |
ltomasbo | irenab and celebdor1 already did, and you suggested the re-shape of the subnet and sg drivers (which made a lot of sense) | 14:42 |
*** hongbin has joined #openstack-kuryr | 14:42 | |
celebdor1 | dmellado: not sure what you meant with "tempest should be clones" | 14:43 |
dmellado | cloned | 14:47 |
dmellado | not the clone attack | 14:47 |
dmellado | s/s/d | 14:47 |
dulek | ltomasbo: Sure, sure, sorry for the delay, but we've just finished the meeting with interns. | 14:47 |
dmellado | heh, we'll take a look ltomasbo | 14:48 |
ltomasbo | dulek, thanks! | 14:48 |
ltomasbo | dmellado, great! | 14:48 |
*** janki has quit IRC | 14:54 | |
ltomasbo | dulek, this is finally green: https://review.openstack.org/#/c/587706/ | 14:57 |
dulek | ltomasbo: Any reason why this isn't creating SGs on ServiceSubnetsDriver.get_security_groups? | 14:57 |
ltomasbo | it was a project vs tenant-id issue | 14:57 |
dulek | ltomasbo: I mean this gets less and less generic with new drivers and handlers. | 14:57 |
celebdor1 | dmellado: reading https://zuul-ci.org/docs/zuul/user/config.html?highlight=inheritance | 14:58 |
dmellado | celebdor1: enjoy it :D | 14:58 |
celebdor1 | It seems to me that the run: entry on the parent jobs is overriden | 14:58 |
dmellado | https://upload.wikimedia.org/wikipedia/commons/thumb/5/52/Tipos_de_azules.png/250px-Tipos_de_azules.png | 14:59 |
dulek | dmellado: Azules? | 15:00 |
dmellado | dulek: Azuul | 15:00 |
dmellado | xD | 15:00 |
dmellado | celebdor1: did you check this | 15:00 |
dmellado | https://docs.openstack.org/infra/manual/zuulv3.html | 15:00 |
ltomasbo | dulek, umm | 15:00 |
dmellado | intheritance vs roles section? | 15:00 |
dulek | ltomasbo: So IMO namespace handler shouldn't need to create the SG. | 15:01 |
celebdor1 | but that looks unlikely, since it is the run: in the tempest .zuul.yaml of the tempest repo the one that actually runs tempest | 15:01 |
ltomasbo | dulek, I guess to follow the same struct as the subnet driver | 15:01 |
dulek | ltomasbo: It should get created by SG driver, when needed. | 15:01 |
celebdor1 | in he playbook | 15:01 |
dulek | ltomasbo: The question is - is it easy to pass it required params? | 15:01 |
celebdor1 | so how the fuck are the 'run' ordered between parents and children | 15:01 |
*** janki has joined #openstack-kuryr | 15:01 | |
ltomasbo | dulek, but the problem is that we need to annotate the CRD | 15:02 |
dulek | ltomasbo: With the SG id so that we don't "lose" the SG? | 15:02 |
dulek | ltomasbo: And there's an assumption only handlers do that? | 15:02 |
ltomasbo | dulek, the assumption is that crd object gets annotated into the namespace | 15:03 |
ltomasbo | dulek, and the annotation happens after both network and sgs are created | 15:03 |
dulek | ltomasbo: Ah, right… | 15:04 |
celebdor1 | dmellado: ^^ | 15:04 |
ltomasbo | dulek, it can be done in a different way, but then keeping track of possible rollbacks will be more complex | 15:04 |
dulek | ltomasbo: Yeah, now I see dragons in rollbacks. | 15:04 |
dulek | ltomasbo: And race conditions that could happen. | 15:04 |
ltomasbo | xD | 15:04 |
dulek | ltomasbo: Okay, I'm convinced. :) | 15:05 |
ltomasbo | xD | 15:05 |
ltomasbo | celebdor1, dulek: yossi's backport is also green: https://review.openstack.org/#/c/587583 | 15:08 |
celebdor1 | thanks ltomasbo | 15:08 |
dulek | Seems like we've merged some code today. :) | 15:09 |
ltomasbo | xD | 15:09 |
celebdor1 | :-) | 15:15 |
*** pcaruana has quit IRC | 15:15 | |
ltomasbo | celebdor1, and yours backport: https://review.openstack.org/#/c/587706 | 15:19 |
celebdor1 | thanks! | 15:22 |
dmellado | celebdor1: what? | 15:24 |
celebdor1 | so | 15:25 |
celebdor1 | in the zuul documentation it says that if you have a run: in your .zuul | 15:25 |
celebdor1 | it will override the parent one | 15:26 |
celebdor1 | in our case, the base run: is the one that runs devstack and then tempest | 15:26 |
celebdor1 | the problem is that between running devstack and tempest tests with tox | 15:26 |
celebdor1 | we need to do the test container creation | 15:27 |
celebdor1 | from the tar fire | 15:27 |
celebdor1 | *file | 15:27 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-tempest-plugin master: Namespace isolation tempest coverage https://review.openstack.org/580678 | 15:43 |
openstackgerrit | Luis Tomas Bolivar proposed openstack/kuryr-tempest-plugin master: Namespace svc isolation tempest coverage https://review.openstack.org/587778 | 15:43 |
*** janki has quit IRC | 15:55 | |
openstackgerrit | Merged openstack/kuryr-kubernetes master: Ensure isolation between namespaces https://review.openstack.org/579181 | 16:01 |
ltomasbo | dulek, dmellado: seems this is the one to blame: https://github.com/openstack/kuryr-kubernetes/commit/ce3305b9eff3eff736065c9b9a5921bfd593b375 | 16:07 |
ltomasbo | not sure why we didn't hit it | 16:07 |
celebdor1 | so... to sum it up... dulek is the culprit, eh? | 16:10 |
celebdor1 | xD | 16:10 |
celebdor1 | why aren't we setting it when it is containerized? | 16:11 |
celebdor1 | oh, of course | 16:11 |
celebdor1 | xD | 16:11 |
celebdor1 | because then we get it from env vars | 16:11 |
celebdor1 | xD | 16:11 |
celebdor1 | that's an easy fix | 16:12 |
ltomasbo | yep | 16:12 |
ltomasbo | the vars are there | 16:12 |
ltomasbo | so, if the config map is defined with api_root = "" it should work | 16:12 |
celebdor1 | you said it is just 'api_root =' | 16:13 |
celebdor1 | right, without the "" | 16:13 |
*** janki has joined #openstack-kuryr | 16:14 | |
celebdor1 | anyway | 16:14 |
celebdor1 | let me fix it | 16:14 |
celebdor1 | ltomasbo: run again removing lines 376 and 377 from https://github.com/openstack/kuryr-kubernetes/commit/ce3305b9eff3eff736065c9b9a5921bfd593b375#diff-cd9ddf33b5bab44d58ff1f7e5ccc0c53R376 | 16:15 |
celebdor1 | that should fix it | 16:15 |
ltomasbo | yep | 16:17 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-kubernetes master: kuryr-tempest-plugin devstack plugin to build kuryr/demo https://review.openstack.org/587873 | 16:19 |
*** janki has quit IRC | 16:24 | |
dmellado | ltomasbo: maybe as we didn't update the repo until now xD | 16:28 |
dmellado | anyways, I'm off for today | 16:28 |
dmellado | g'night folks! | 16:29 |
*** janki has joined #openstack-kuryr | 17:06 | |
*** maysams has joined #openstack-kuryr | 17:12 | |
*** maysams has left #openstack-kuryr | 17:12 | |
*** maysams has joined #openstack-kuryr | 17:12 | |
*** pfo has joined #openstack-kuryr | 17:33 | |
openstackgerrit | Emilio Garcia proposed openstack/kuryr-kubernetes master: Upstream kuryr Active Active High Availibility Development [Do Not Merge/Do Not Test] https://review.openstack.org/582992 | 18:14 |
*** pfo has quit IRC | 18:34 | |
*** janki has quit IRC | 19:04 | |
*** rh-jelabarre has quit IRC | 19:07 | |
*** rh-jelabarre has joined #openstack-kuryr | 19:10 | |
*** livelace has quit IRC | 19:29 | |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-tempest-plugin master: devstack: Move container build to stack extra https://review.openstack.org/588074 | 20:27 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-kubernetes master: kuryr-tempest-plugin devstack plugin to build kuryr/demo https://review.openstack.org/587873 | 20:28 |
openstackgerrit | Antoni Segura Puimedon proposed openstack/kuryr-kubernetes master: kuryr-tempest-plugin devstack plugin to build kuryr/demo https://review.openstack.org/587873 | 21:23 |
*** rh-jelabarre has quit IRC | 21:33 | |
*** hongbin has quit IRC | 22:20 | |
*** s1061123 has quit IRC | 22:28 | |
*** s1061123 has joined #openstack-kuryr | 22:28 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!