*** pcaruana has quit IRC | 00:25 | |
*** hyang has quit IRC | 00:26 | |
*** yamamoto has joined #openstack-lbaas | 00:43 | |
*** yamamoto has quit IRC | 00:47 | |
*** velizarx has joined #openstack-lbaas | 01:37 | |
*** velizarx has quit IRC | 01:54 | |
*** velizarx has joined #openstack-lbaas | 02:07 | |
*** yamamoto has joined #openstack-lbaas | 02:22 | |
*** hongbin has joined #openstack-lbaas | 02:42 | |
*** aojea has joined #openstack-lbaas | 03:24 | |
*** aojea has quit IRC | 03:29 | |
*** velizarx has quit IRC | 04:10 | |
openstackgerrit | YAMAMOTO Takashi proposed openstack/neutron-lbaas master: Revert "Updated "create_pool" method in plugin" https://review.openstack.org/616763 | 04:25 |
---|---|---|
*** velizarx has joined #openstack-lbaas | 04:35 | |
*** velizarx has quit IRC | 04:45 | |
*** openstackstatus has quit IRC | 04:59 | |
*** hongbin has quit IRC | 05:07 | |
*** openstack has joined #openstack-lbaas | 07:11 | |
*** ChanServ sets mode: +o openstack | 07:11 | |
openstackgerrit | zhangzhaoshan proposed openstack/octavia-tempest-plugin master: Clean up .gitignore references to personal tools https://review.openstack.org/616838 | 07:19 |
*** pcaruana has joined #openstack-lbaas | 07:21 | |
*** Emine has joined #openstack-lbaas | 09:18 | |
*** salmankhan has joined #openstack-lbaas | 09:54 | |
*** abaindur has quit IRC | 09:57 | |
openstackgerrit | YAMAMOTO Takashi proposed openstack/neutron-lbaas master: Revert "Updated "create_pool" method in plugin" https://review.openstack.org/616763 | 10:44 |
openstackgerrit | ZhaoBo proposed openstack/python-octaviaclient master: Add 'client_auth_option' in Listener on client side https://review.openstack.org/616879 | 10:57 |
openstackgerrit | ZhaoBo proposed openstack/octavia master: Add client_ca_tls_container_ref to Octavia v2 listener API https://review.openstack.org/612267 | 10:58 |
openstackgerrit | ZhaoBo proposed openstack/octavia master: Add an option to the Octavia V2 listener API for client cert https://review.openstack.org/612268 | 10:58 |
openstackgerrit | Merged openstack/octavia master: Fix VIP plug failure if netns directory exists https://review.openstack.org/616382 | 11:31 |
openstackgerrit | Carlos Goncalves proposed openstack/octavia stable/rocky: Fix VIP plug failure if netns directory exists https://review.openstack.org/616899 | 12:39 |
openstackgerrit | Carlos Goncalves proposed openstack/octavia stable/queens: Fix VIP plug failure if netns directory exists https://review.openstack.org/616900 | 12:39 |
*** velizarx has joined #openstack-lbaas | 13:07 | |
openstackgerrit | chenxiangui proposed openstack/octavia-dashboard master: Modify the wrong url https://review.openstack.org/616942 | 14:01 |
*** aojea_ has joined #openstack-lbaas | 14:01 | |
*** Emine has quit IRC | 14:11 | |
*** aojea_ has quit IRC | 14:49 | |
*** velizarx has quit IRC | 14:49 | |
*** aojea_ has joined #openstack-lbaas | 14:58 | |
*** Emine has joined #openstack-lbaas | 15:31 | |
*** yamamoto has quit IRC | 16:18 | |
*** aojea_ has quit IRC | 16:20 | |
*** aojea_ has joined #openstack-lbaas | 16:21 | |
*** yamamoto has joined #openstack-lbaas | 16:21 | |
*** yamamoto has quit IRC | 16:27 | |
*** ivve has joined #openstack-lbaas | 18:00 | |
*** Swami has joined #openstack-lbaas | 18:07 | |
xgerman_ | rm_work: need some Octavia recovery advice | 18:10 |
*** emccormick has joined #openstack-lbaas | 18:12 | |
colin- | not strictly octavia related but thought this might interest folks, saw it on HN: https://www.haproxy.com/blog/application-layer-ddos-attack-protection-with-haproxy/ | 18:15 |
johnsom | colin- Yeah, enabling the DDoS protections in the amphorae is on our roadmap: https://wiki.openstack.org/wiki/Octavia/Roadmap | 18:16 |
colin- | read my mind | 18:16 |
johnsom | There are a number things we can do that aren't super hard, just needs someone to do the work. | 18:16 |
xgerman_ | you can always use QoS to limit DDos | 18:16 |
johnsom | I think it should be a combination of kernel level settings (some are already on) and haproxy settings | 18:17 |
colin- | do you guys set any of that on your amphorae? | 18:17 |
colin- | just curious | 18:17 |
xgerman_ | you can set the Neutron QoS - i dont think we do much on the amp level | 18:18 |
johnsom | No, we mostly run with the defaults in the DDoS case. So the syn cookies stuff is enabled after a threshold, etc. | 18:18 |
*** salmankhan has quit IRC | 18:38 | |
*** emccormick has quit IRC | 18:42 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Migrate constants to use octavia-lib - Part 1 https://review.openstack.org/617015 | 18:47 |
johnsom | I'm trying to see if I can touch every file in octavia.... lol | 18:49 |
*** ivve has quit IRC | 19:12 | |
*** zigo has quit IRC | 19:25 | |
*** Emine has quit IRC | 19:48 | |
*** abaindur has joined #openstack-lbaas | 19:55 | |
*** abaindur has quit IRC | 19:56 | |
*** abaindur has joined #openstack-lbaas | 19:56 | |
*** salmankhan has joined #openstack-lbaas | 20:32 | |
*** salmankhan has quit IRC | 20:36 | |
rm_work | xgerman_: sorry whats up | 21:01 |
rm_work | xgerman_: am i too late to be helpful? | 21:01 |
rm_work | definitely have a LOT of recovery experience :P | 21:01 |
*** hvhaugwitz has quit IRC | 21:18 | |
*** hvhaugwitz has joined #openstack-lbaas | 21:25 | |
*** yamamoto has joined #openstack-lbaas | 21:37 | |
johnsom | rm_work He had a DB go out to lunch on an old Pike install, so they got the "THIS IS NOT GOOD" and one amp down, one amp up situation. | 21:38 |
rm_work | yeah | 21:38 |
rm_work | that's not too bad to fix | 21:38 |
rm_work | at least for me, i wonder if it's different on the default net driver | 21:39 |
rm_work | like, 30s and done | 21:39 |
rm_work | (per LB) | 21:39 |
johnsom | Yeah, I think it's just create a fake amp record, post an old health, mark back to active. | 21:40 |
*** yamamoto has quit IRC | 21:41 | |
rm_work | yeah | 21:44 |
rm_work | basically | 21:44 |
johnsom | Since they have no failover api, etc.... | 21:45 |
rm_work | oh right ugh | 21:54 |
rm_work | but yeah that's when i was doing it too | 21:54 |
*** celebdor has quit IRC | 22:27 | |
xgerman_ | I got them to just recreate the servcie | 22:31 |
xgerman_ | that’s what we are documenting | 22:31 |
rm_work | ?? like, new LB? | 22:34 |
johnsom | push pin meet sledge hammer | 22:36 |
xgerman_ | well, so we are sure that database stuff works and I should make them do that instead | 22:40 |
xgerman_ | ? | 22:40 |
xgerman_ | for all I know they might have half deleted ports and such | 22:41 |
rm_work | it works for me, but i don't know if it's different for your thing | 22:43 |
xgerman_ | yeah, on a customer site is probably the wromg place to find out :-) | 22:43 |
johnsom | The downside is the rebuild approach causes downtime | 22:45 |
rm_work | ah for me it doesn't? | 22:45 |
rm_work | unless it's already down | 22:45 |
xgerman_ | if I learned anyhting is that downtime is not a concern if it saves the operator time | 22:48 |
rm_work | lol | 22:48 |
johnsom | Right, I meant the approach of deleting the whole thing and rebuilding causes downtime, where the fix-in-place does not | 22:48 |
rm_work | ah lol | 22:48 |
rm_work | well not if you do it right | 22:48 |
rm_work | spin up the new thing, swing the DNS over to the new VIP | 22:48 |
johnsom | Best long term solution for them is to get off pike | 22:48 |
rm_work | ^^ this lol | 22:48 |
xgerman_ | yep, and this has now new urgency | 22:49 |
rm_work | it's not even hard | 22:49 |
rm_work | just upgrade the control-plane | 22:49 |
rm_work | easy peasy done | 22:49 |
rm_work | doesn't require any major changes to your cloud | 22:50 |
rm_work | if you're containerized it's just "use this image instead of that one" but i assume you are using OSA | 22:50 |
xgerman_ | if you try to run 100s of clouds you don’t do things differently for one | 22:51 |
rm_work | yeah i mean you should do that with all of them :P | 22:51 |
cgoncalves | "here's 1M bucks, do this differently for me now" -- you wouldn't? ;) | 22:52 |
rm_work | i would dance like a trained monkey for that money :P | 22:52 |
rm_work | (admittedly, probably worse than a trained monkey, but only for lack of said training) | 22:53 |
*** aojea_ has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!