*** threestrands has joined #openstack-lbaas | 00:24 | |
*** hongbin has joined #openstack-lbaas | 00:37 | |
*** rcernin has quit IRC | 01:13 | |
*** rcernin has joined #openstack-lbaas | 02:13 | |
*** psachin has joined #openstack-lbaas | 03:33 | |
*** ramishra has joined #openstack-lbaas | 03:36 | |
*** hongbin has quit IRC | 04:13 | |
*** gcheresh has joined #openstack-lbaas | 05:18 | |
*** gcheresh has quit IRC | 05:27 | |
*** trident has quit IRC | 07:00 | |
*** trident has joined #openstack-lbaas | 07:10 | |
*** ivve has joined #openstack-lbaas | 07:17 | |
*** sapd1_x has joined #openstack-lbaas | 07:25 | |
*** threestrands has quit IRC | 07:32 | |
*** rcernin has quit IRC | 07:40 | |
*** nmagnezi has joined #openstack-lbaas | 08:06 | |
*** tkajinam has quit IRC | 08:07 | |
*** gcheresh has joined #openstack-lbaas | 09:03 | |
openstackgerrit | Carlos Goncalves proposed openstack/octavia master: Add VIP access control list https://review.opendev.org/659626 | 09:05 |
---|---|---|
*** ajay33 has joined #openstack-lbaas | 09:31 | |
*** psachin has quit IRC | 09:37 | |
*** psachin has joined #openstack-lbaas | 09:41 | |
*** psachin has quit IRC | 09:48 | |
openstackgerrit | Carlos Goncalves proposed openstack/octavia master: Add new algorithm SOURCE_IP_PORT https://review.opendev.org/672463 | 09:56 |
openstackgerrit | Carlos Goncalves proposed openstack/python-octaviaclient master: Add support for SOURCE_IP_PORT algorithm https://review.opendev.org/672416 | 09:58 |
*** sapd1_x has quit IRC | 09:59 | |
*** cgoncalves has quit IRC | 10:04 | |
*** cgoncalves has joined #openstack-lbaas | 10:04 | |
*** tesseract has joined #openstack-lbaas | 11:11 | |
openstackgerrit | Carlos Goncalves proposed openstack/python-octaviaclient master: Add support to VIP access control list https://review.opendev.org/659627 | 11:53 |
*** gcheresh has quit IRC | 12:10 | |
*** gcheresh has joined #openstack-lbaas | 12:12 | |
*** gcheresh has quit IRC | 12:26 | |
*** KeithMnemonic has joined #openstack-lbaas | 13:14 | |
*** boden has joined #openstack-lbaas | 13:17 | |
*** ajay33 has quit IRC | 13:46 | |
*** Vorrtex has joined #openstack-lbaas | 14:17 | |
*** Vorrtex has quit IRC | 14:17 | |
*** Vorrtex has joined #openstack-lbaas | 14:19 | |
openstackgerrit | Swaminathan Vasudevan proposed openstack/octavia master: (WIP): Modify the diskimage elements to support SUSE packages https://review.opendev.org/678460 | 15:54 |
openstackgerrit | Carlos Goncalves proposed openstack/octavia master: Add VIP access control list https://review.opendev.org/659626 | 16:01 |
*** ivve has quit IRC | 16:22 | |
*** amotoki is now known as amotoki_ | 16:42 | |
*** psachin has joined #openstack-lbaas | 16:53 | |
*** cjloader has joined #openstack-lbaas | 16:58 | |
*** boden has quit IRC | 17:22 | |
*** boden_ has joined #openstack-lbaas | 17:22 | |
*** ivve has joined #openstack-lbaas | 17:25 | |
*** ivve has quit IRC | 17:26 | |
*** ivve has joined #openstack-lbaas | 17:27 | |
colin- | friendly reminder to anyone who changes amp OS distributions, however obvious it may seem the username for key based ssh auth will change with the distribution heh | 17:28 |
colin- | had to ask someone before realizing centos for centos, ubuntu for ubuntu, etc | 17:29 |
*** psachin has quit IRC | 17:29 | |
*** tesseract has quit IRC | 17:30 | |
*** psachin has joined #openstack-lbaas | 17:33 | |
cgoncalves | cloud-user for RHEL :) | 17:34 |
johnsom | cirros for cirros. | 17:35 |
cgoncalves | but, but... no more cubswin:) password :( | 17:44 |
*** psachin has quit IRC | 17:45 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 17:54 |
johnsom | Let's see if that works.... grin | 17:55 |
johnsom | At least it will setup devstack in the gates for a more realistic PKI deployment. | 17:55 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 18:07 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 18:08 |
johnsom | Argh, tabs | 18:08 |
cgoncalves | what happened to State of Denial? :D | 18:17 |
johnsom | lol, I forgot about that. That might be a worthy nit comment to put it back | 18:18 |
*** ramishra has quit IRC | 18:43 | |
colin- | do we override the `hosts` section of /etc/nsswitch.conf in diskimage builder for amphora? | 18:45 |
colin- | to specifically only use the `files` value? | 18:45 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 18:46 |
johnsom | colin- We completely disable DNS and hostnames in nssswitch | 18:46 |
johnsom | https://opendev.org/openstack/octavia/src/branch/master/elements/no-resolvconf/finalise.d/99-disable-resolv-conf | 18:47 |
colin- | what's our position with that, don't want the added dependency service wise? | 18:52 |
colin- | speed? | 18:52 |
johnsom | Both. Amphora do not naturally have a path to DNS infrastructure (private nets only use case), We don't have a need for DNS inside the amphora, it significantly improves startup time as there is always some new package that thinks it needs to go out to the internet, and it's nice to have anything that attempts to do DNS fail fast. | 18:53 |
colin- | i see. it makes it really difficult to access anything from the amphora. i'm disinclined to fork the diskimage builder to write individually maintained host file entries | 18:56 |
colin- | any suggestions? | 18:56 |
johnsom | Yeah, in general the amphora are not setup by default to call out to anything.... | 19:02 |
johnsom | If you must, I would recommend you create local DIB elements that customize it to your liking. | 19:03 |
johnsom | https://opendev.org/openstack/octavia/src/branch/master/diskimage-create | 19:03 |
johnsom | There are environment variables that allow you to manipulate the DIB process. Of interest would be "DIB_LOCAL_ELEMENTS" that allows you to define a list of local elements. All elements have a ordering number, so you can create local elements that override settings we make by default. | 19:04 |
johnsom | Personally, I consider the amphora an "un-trusted" element and don't want it to be able to do much of anything beyond what we have it doing. I.e. I don't want it to be able to look up DNS names and reach out to the outside world. I.e. make it hard to pull in hostile packages, etc. | 19:06 |
johnsom | They are not "pets" as the saying goes.... | 19:07 |
*** gcheresh has joined #openstack-lbaas | 19:22 | |
johnsom | I am screaming but you all can't hear it.... | 19:46 |
johnsom | usage: ca args | 19:47 |
johnsom | unknown option --days | 19:47 |
johnsom | centos7 and it's ancient code.... | 19:47 |
johnsom | Yes, I did it wrong, but at least ubuntu's version acknowledges that openssl has been in the wrong and accepts it. | 19:48 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 19:49 |
*** Vorrtex has quit IRC | 20:15 | |
*** gcheresh has quit IRC | 20:30 | |
*** nmagnezi has quit IRC | 20:42 | |
*** nmagnezi has joined #openstack-lbaas | 21:01 | |
*** ivve has quit IRC | 21:25 | |
colin- | understood. i think the days of stric egress may be in the rear view mirror for me | 21:54 |
colin- | will look into a customization of the builder | 21:54 |
*** boden_ has quit IRC | 21:59 | |
*** trident has quit IRC | 22:05 | |
*** trident has joined #openstack-lbaas | 22:13 | |
*** rcernin has joined #openstack-lbaas | 22:15 | |
johnsom | rm_work I'm looking at https://review.opendev.org/#/c/667484, should additive only also do updates? It's not clear to me if that is add-only or (add and update)-only | 23:00 |
*** tkajinam has joined #openstack-lbaas | 23:06 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Use dual intermediate CAs for devstack https://review.opendev.org/678923 | 23:28 |
openstackgerrit | Merged openstack/octavia master: Force DIB Python version for py2 in diskimage-create https://review.opendev.org/673805 | 23:49 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!