*** yamamoto has quit IRC | 00:18 | |
*** hyang has left #openstack-lbaas | 00:45 | |
*** hyang has joined #openstack-lbaas | 00:51 | |
*** gthiemonge has quit IRC | 01:25 | |
*** gthiemonge has joined #openstack-lbaas | 01:25 | |
*** yamamoto has joined #openstack-lbaas | 01:41 | |
*** yamamoto has quit IRC | 02:03 | |
*** yamamoto has joined #openstack-lbaas | 02:39 | |
*** ricolin has joined #openstack-lbaas | 02:42 | |
*** yamamoto has quit IRC | 02:51 | |
*** yamamoto has joined #openstack-lbaas | 02:54 | |
*** psachin has joined #openstack-lbaas | 03:34 | |
*** ramishra has joined #openstack-lbaas | 03:55 | |
*** HVT has joined #openstack-lbaas | 03:55 | |
*** ramishra has quit IRC | 04:03 | |
*** gcheresh has joined #openstack-lbaas | 04:12 | |
*** ramishra has joined #openstack-lbaas | 04:18 | |
*** gcheresh has quit IRC | 04:34 | |
*** ramishra has quit IRC | 04:34 | |
*** gcheresh has joined #openstack-lbaas | 04:44 | |
*** ivve has quit IRC | 04:45 | |
*** gcheresh has quit IRC | 04:54 | |
*** gcheresh has joined #openstack-lbaas | 05:15 | |
*** gcheresh has quit IRC | 05:25 | |
*** ramishra has joined #openstack-lbaas | 05:41 | |
*** yamamoto has quit IRC | 05:42 | |
*** yamamoto has joined #openstack-lbaas | 05:46 | |
*** ivve has joined #openstack-lbaas | 05:49 | |
*** yamamoto has quit IRC | 05:51 | |
*** vishalmanchanda has joined #openstack-lbaas | 05:58 | |
openstackgerrit | Vishal Manchanda proposed openstack/neutron-lbaas-dashboard master: Update hacking version https://review.opendev.org/628478 | 06:07 |
---|---|---|
*** ccamposr has joined #openstack-lbaas | 06:09 | |
*** yamamoto has joined #openstack-lbaas | 06:28 | |
*** yamamoto has quit IRC | 06:29 | |
*** yamamoto has joined #openstack-lbaas | 06:30 | |
openstackgerrit | Gregory Thiemonge proposed openstack/octavia-tempest-plugin master: Add UDP test scenario https://review.opendev.org/656515 | 06:59 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Performance improvement for non-udp health checks https://review.opendev.org/657756 | 07:02 |
*** tesseract has joined #openstack-lbaas | 07:09 | |
*** gcheresh has joined #openstack-lbaas | 07:16 | |
*** rpittau|afk is now known as rpittau | 07:35 | |
*** gcheresh has quit IRC | 07:47 | |
*** mkuf has quit IRC | 08:30 | |
*** mkuf has joined #openstack-lbaas | 08:32 | |
*** mkuf_ has joined #openstack-lbaas | 08:34 | |
*** mkuf has quit IRC | 08:38 | |
*** yamamoto has quit IRC | 09:45 | |
*** ramishra has quit IRC | 10:04 | |
*** yamamoto has joined #openstack-lbaas | 10:06 | |
*** ramishra has joined #openstack-lbaas | 10:13 | |
*** mugsie has quit IRC | 10:25 | |
*** yamamoto has quit IRC | 10:27 | |
*** yamamoto has joined #openstack-lbaas | 10:27 | |
*** yamamoto has quit IRC | 10:28 | |
*** yamamoto has joined #openstack-lbaas | 10:32 | |
*** yamamoto has quit IRC | 10:32 | |
*** yamamoto_ has joined #openstack-lbaas | 10:32 | |
*** yamamoto_ has quit IRC | 10:33 | |
*** mugsie has joined #openstack-lbaas | 10:35 | |
*** mugsie has quit IRC | 10:35 | |
*** mugsie has joined #openstack-lbaas | 10:36 | |
*** HVT has left #openstack-lbaas | 10:36 | |
*** mugsie has quit IRC | 10:38 | |
*** mugsie has joined #openstack-lbaas | 10:39 | |
*** tesseract has quit IRC | 10:40 | |
*** tesseract has joined #openstack-lbaas | 10:41 | |
*** tesseract has quit IRC | 10:45 | |
*** tesseract has joined #openstack-lbaas | 10:45 | |
*** yamamoto has joined #openstack-lbaas | 11:08 | |
*** yamamoto has quit IRC | 11:13 | |
openstackgerrit | Merged openstack/neutron-lbaas-dashboard master: Imported Translations from Zanata https://review.opendev.org/657328 | 11:26 |
*** yamamoto has joined #openstack-lbaas | 11:34 | |
*** zigo has quit IRC | 11:59 | |
*** yamamoto has quit IRC | 12:02 | |
*** yamamoto has joined #openstack-lbaas | 12:07 | |
*** zigo has joined #openstack-lbaas | 12:23 | |
*** yamamoto has quit IRC | 12:40 | |
*** ramishra has quit IRC | 12:56 | |
*** ramishra has joined #openstack-lbaas | 12:56 | |
*** yamamoto has joined #openstack-lbaas | 13:06 | |
*** ramishra has quit IRC | 13:09 | |
*** boden has joined #openstack-lbaas | 13:09 | |
*** boden has quit IRC | 13:13 | |
*** ramishra has joined #openstack-lbaas | 13:20 | |
*** tesseract has quit IRC | 13:35 | |
*** tesseract has joined #openstack-lbaas | 13:35 | |
*** gcheresh has joined #openstack-lbaas | 13:42 | |
*** altlogbot_0 has quit IRC | 13:43 | |
*** altlogbot_2 has joined #openstack-lbaas | 13:45 | |
*** boden has joined #openstack-lbaas | 13:49 | |
*** psachin has quit IRC | 13:51 | |
*** vishalmanchanda has quit IRC | 13:57 | |
*** rpittau is now known as rpittau|afk | 14:08 | |
*** Vorrtex has joined #openstack-lbaas | 14:20 | |
*** tesseract has quit IRC | 14:24 | |
*** happyhemant has joined #openstack-lbaas | 14:28 | |
*** fnaval has joined #openstack-lbaas | 14:29 | |
*** yamamoto has quit IRC | 14:35 | |
*** tesseract has joined #openstack-lbaas | 14:50 | |
*** tesseract has quit IRC | 14:51 | |
*** tesseract has joined #openstack-lbaas | 14:51 | |
*** tesseract has quit IRC | 15:01 | |
*** tesseract has joined #openstack-lbaas | 15:03 | |
*** tesseract has quit IRC | 15:11 | |
*** yamamoto has joined #openstack-lbaas | 15:12 | |
*** tesseract has joined #openstack-lbaas | 15:16 | |
*** yamamoto has quit IRC | 15:17 | |
*** tesseract has quit IRC | 15:18 | |
*** tesseract has joined #openstack-lbaas | 15:20 | |
*** gcheresh has quit IRC | 15:24 | |
*** trident has quit IRC | 15:33 | |
*** trident has joined #openstack-lbaas | 15:35 | |
*** ivve has quit IRC | 15:40 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add provider feature support matrix https://review.opendev.org/651974 | 15:44 |
*** tesseract has quit IRC | 16:01 | |
*** henriqueof has joined #openstack-lbaas | 16:07 | |
cgoncalves | rm_work, ping | 16:14 |
cgoncalves | Allison and Jimmy replied to my email sent yesterday about adding two questions to the survey. they ask if we want to add options + free form area or just the latter | 16:17 |
johnsom | Personally, I lean towards leaving it open and see what we get | 16:18 |
cgoncalves | I'm slightly more for giving options + free form | 16:18 |
cgoncalves | https://etherpad.openstack.org/p/cItdtzi32r | 16:18 |
cgoncalves | names of vendors are ones that have drivers in neutron-lbaas or in octavia | 16:19 |
cgoncalves | this is just a proposal. open to the discussed within the team :) | 16:21 |
cgoncalves | I'm going offline soon for a couple of hours. if you and others could please come to an agrement meanwhile, that would be great! | 16:23 |
*** ricolin has quit IRC | 16:45 | |
*** irclogbot_2 has quit IRC | 16:46 | |
*** irclogbot_0 has joined #openstack-lbaas | 16:47 | |
rm_work | Yeah I like the idea of including the most common vendors we've seen and having a freeform "other", but don't want to be seen as biased if we forget one | 16:47 |
rm_work | And I like having a list of some features too, we could pull the stuff in our roadmap and get some idea of priority | 16:49 |
*** ramishra has quit IRC | 16:50 | |
cgoncalves | rm_work, so what do you suggest to tell to Allison and Jimmy? | 17:01 |
*** ccamposr has quit IRC | 17:02 | |
*** yamamoto has joined #openstack-lbaas | 17:22 | |
eandersson | rm_work, johnsom you guys mentioned some potential race conditions in neutron-lbaas | 17:30 |
johnsom | Yeah, there are a bunch | 17:31 |
johnsom | Any high rate of change via the API can lead to problems. | 17:31 |
eandersson | What was the general cause of that? | 17:32 |
johnsom | This is one reason for Octavia, the whole API in neutron-lbaas needed a re-write | 17:33 |
*** ivve has joined #openstack-lbaas | 17:42 | |
*** livelace has joined #openstack-lbaas | 17:47 | |
rm_work | Sorry I'm out running an errand, be back in a few cgoncalves | 17:56 |
*** yamamoto has quit IRC | 18:11 | |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Performance improvement for non-udp health checks https://review.opendev.org/657756 | 18:15 |
rm_work | fixed, and yeah i'll propose it directly to stable/rocky johnsom | 18:17 |
rm_work | though ... uhh | 18:17 |
rm_work | shouldn't it technically also be in master, even though it doesn't REALLY matter much? | 18:17 |
rm_work | what about for amps that are on old versions | 18:17 |
rm_work | with an updated control-plane | 18:18 |
rm_work | i feel like we should just do a standard backport | 18:18 |
rm_work | not to mention avoiding making further backports PITA because of different code | 18:18 |
rm_work | posted a comment to that effect | 18:27 |
rm_work | cgoncalves: commented on https://review.opendev.org/#/c/657901/ | 18:28 |
rm_work | cgoncalves: up to you on the email thing, i agree with you on providing options+other for both, so either draft up a list of what you think the options should be and we can give feedback, or else just allow it to be freeform (which might be more PC anyway) | 18:29 |
rm_work | I am fine with either | 18:29 |
*** hyang has left #openstack-lbaas | 18:30 | |
johnsom | rm_work Commented. I really don't want to make the "common" path slower in stein/master... | 18:47 |
rm_work | do you think this does so? | 18:47 |
johnsom | Also it looks like a bandit released and is not happy with our code | 18:47 |
rm_work | it's one additional field | 18:48 |
johnsom | Yes | 18:48 |
rm_work | it should be negligable | 18:48 |
johnsom | You also loop over EVERY listener for every call | 18:48 |
rm_work | i could move that inside the `if not ver` | 18:48 |
rm_work | easy | 18:48 |
rm_work | prolly should have anyway | 18:48 |
rm_work | will do that now | 18:49 |
rm_work | done | 18:49 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Performance improvement for non-udp health checks https://review.opendev.org/657756 | 18:49 |
rm_work | that was just an oversight, i was looking for the cleanest place to put it | 18:50 |
*** yamamoto has joined #openstack-lbaas | 18:51 | |
*** happyhemant has quit IRC | 18:58 | |
*** yamamoto has quit IRC | 19:02 | |
colin- | hope that gitweb overall diff link will come back to opendev at some point | 19:44 |
colin- | really liked that | 19:44 |
johnsom | Yeah, I don't know. You would have to ask in #openstack-infra | 19:53 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add provider feature support matrix https://review.opendev.org/651974 | 20:15 |
*** boden_ has joined #openstack-lbaas | 20:15 | |
*** boden has quit IRC | 20:19 | |
*** Vorrtex has quit IRC | 20:25 | |
*** livelace has quit IRC | 20:31 | |
*** logan- has quit IRC | 21:00 | |
*** logan- has joined #openstack-lbaas | 21:03 | |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Performance improvement for non-udp health checks https://review.opendev.org/657756 | 21:41 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Performance improvement for non-udp health checks https://review.opendev.org/657756 | 21:45 |
*** dasp has quit IRC | 21:52 | |
*** boden_ has quit IRC | 21:55 | |
*** emccormick has joined #openstack-lbaas | 22:10 | |
emccormick | Hey all, getting an error building Rocky's amphora image. "There were unauthenticated packages and -y was used without --allow-unauthenticated" | 22:12 |
emccormick | seems to just bomb out after that | 22:12 |
emccormick | it's really just base system packages it's complaining about | 22:13 |
*** trident has quit IRC | 22:19 | |
*** trident has joined #openstack-lbaas | 22:22 | |
emccormick | upgraded my builder box to bionic and it's at least getting farther. | 22:30 |
rm_work | xgerman: so the issue with config is that it's difficult to be consistent | 22:32 |
rm_work | there's two places that need to base their protocol selection off the config value -- in the rest_api_driver where we call out to the amp, and in the agent.py server on the amp which is gunicorn based | 22:32 |
xgerman | yep | 22:33 |
rm_work | in the rest_api_driver I can do a whitelist style thing and allow the user to set "allowed_tls_protocols" | 22:33 |
rm_work | and that is fine | 22:33 |
rm_work | because I can construct a very specific ssl-context | 22:33 |
rm_work | but on the gunicorn side on the agent, I can only specify a single protocol thing | 22:33 |
xgerman | That is sad... | 22:34 |
rm_work | I can't use the fine-grained selection stuff | 22:34 |
rm_work | yeah, there's bugs open | 22:34 |
rm_work | see: https://github.com/benoitc/gunicorn/issues/1680 | 22:34 |
xgerman | ok, the other thing we need to consider on the cleint side if you don’t conenct to an old server | 22:34 |
xgerman | so maybe making the client configurable so it can do old/new and the operator can change that — not that we run a mass replacement | 22:35 |
rm_work | well, an old server SHOULD still *support* higher versions of TLS | 22:35 |
rm_work | so it's just how to limit the negotiation | 22:35 |
*** icey has quit IRC | 22:35 | |
rm_work | an old amp with no protocol-version specified in guniucorn will allow any of SSLv23 and TLS1.0+ | 22:35 |
rm_work | specifying it on the driver side will just force negotiation to start at a higher protocol level, which is what we want | 22:36 |
rm_work | and then for the amps, the same is true | 22:36 |
*** icey has joined #openstack-lbaas | 22:36 | |
rm_work | so no matter which way you upgrade first, it should all be backwards-compatible | 22:36 |
rm_work | AND either one will cause a bump up to the higher version | 22:36 |
colin- | weird behavior on the agent side, that stinks | 22:36 |
*** fnaval has quit IRC | 22:36 | |
rm_work | so, personally I do agree it'd be better to do it with the whitelist/blacklist context flags, but until we can do that on the amp side, i don't know what to say | 22:37 |
rm_work | maybe instead of having it be a list, I can just say "specify which version you want" | 22:37 |
colin- | there's no chance it works as a minimum version right? | 22:37 |
rm_work | it ... does kinda | 22:37 |
xgerman | I think it has value if you cna get rid of things with the config just in case there is a CVE for some version a nd you need to roll quickly | 22:38 |
rm_work | so SSLv23 will allow TLSv1_2 connections | 22:38 |
rm_work | yeah, i agree, but not sure how to do it effectively | 22:38 |
rm_work | so if we just say "min_tls_protocol_version" | 22:38 |
rm_work | I think that could work | 22:39 |
rm_work | we can take one value and I can blacklist anything below that | 22:39 |
rm_work | and that will still work for passing to gunicorn for now | 22:39 |
xgerman | well, we can always commit yoru change and out soemthign in storyboard for when gunicorn evolved (if we only woudl have stayed with flask:-) | 22:39 |
rm_work | lol well, exposing raw flask/werkzeug is not great practice, heh | 22:39 |
rm_work | maybe uwsgi does it better? >_> | 22:39 |
rm_work | no idea | 22:39 |
xgerman | lol | 22:40 |
rm_work | I'll just do "tls_protocol_version" in config and have that set the minimum (I am reasonably sure that's how it works with the deprecated system) | 22:40 |
colin- | o/t but it was so infuriating i have to share it: the old ACE from cisco used to offer a... maximum... tls version. much to my dismay | 22:41 |
rm_work | ugh so the blacklisting fine-grained stuff may not be in py27 at all >_> | 22:43 |
*** fnaval has joined #openstack-lbaas | 22:43 | |
rm_work | and we're moving AWAY from that but technically still have to support it for now... | 22:43 |
rm_work | the NEW new way appears to be `SSLContext.minimum_version` but that isn't available until py37 | 22:43 |
colin- | yea that seems ideal | 22:44 |
rm_work | ah nm the OP_NO_SSLv3 stuff is in 2.7.9 | 22:44 |
rm_work | but SSLContext.minimum_version isn't until 3.7 for real | 22:44 |
rm_work | so can't use that yet | 22:44 |
rm_work | so anyway, I THINK if I set "PROTOCOL_TLSv1_2" then it will work with 1.2+ | 22:46 |
rm_work | so ima try this way | 22:46 |
rm_work | (this is what I had worked up for the blacklisting... but not using it now i guess: http://paste.openstack.org/show/751187/) | 22:47 |
openstackgerrit | Adam Harwell proposed openstack/octavia master: Force amp-agent communication to TLSv1.2 https://review.opendev.org/657901 | 23:03 |
rm_work | OK, I think this is ... better? | 23:03 |
rm_work | I was going to add a quick test too but getting the requests lib (and urllib3) to actually expose the details of the tls session is really hacky | 23:04 |
rm_work | see: https://stackoverflow.com/a/55462022 | 23:05 |
*** fnaval has quit IRC | 23:51 | |
*** fnaval has joined #openstack-lbaas | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!