openstackgerrit | Michael Johnson proposed openstack/octavia master: Don't register cli opts on import https://review.opendev.org/716440 | 00:00 |
---|---|---|
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add ability to set TLS cipher list for listeners https://review.opendev.org/711376 | 00:06 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Don't register cli opts on import https://review.opendev.org/716440 | 00:06 |
johnsom | forgot to bump the requirements minimum version for octavia-lib | 00:07 |
openstackgerrit | Clark Boylan proposed openstack/octavia master: Do not merge testing https://review.opendev.org/717885 | 00:30 |
*** yamamoto has joined #openstack-lbaas | 00:31 | |
*** happyhemant has quit IRC | 01:08 | |
*** yamamoto has quit IRC | 01:33 | |
*** yamamoto has joined #openstack-lbaas | 02:29 | |
*** dayou has quit IRC | 02:50 | |
*** dayou has joined #openstack-lbaas | 02:52 | |
*** psachin has joined #openstack-lbaas | 03:18 | |
*** spatel has joined #openstack-lbaas | 03:24 | |
*** spatel has quit IRC | 03:25 | |
*** gthiemonge has quit IRC | 05:46 | |
*** gthiemonge has joined #openstack-lbaas | 05:47 | |
*** armax_ has joined #openstack-lbaas | 06:05 | |
*** armax has quit IRC | 06:06 | |
*** armax_ is now known as armax | 06:06 | |
*** gcheresh has joined #openstack-lbaas | 06:17 | |
*** rpittau|afk is now known as rpittau | 06:56 | |
*** ataraday_ has joined #openstack-lbaas | 07:03 | |
*** ccamposr__ has joined #openstack-lbaas | 07:06 | |
*** ccamposr has quit IRC | 07:09 | |
openstackgerrit | Merged openstack/octavia-lib stable/ussuri: Update .gitreview for stable/ussuri https://review.opendev.org/716935 | 07:17 |
openstackgerrit | Merged openstack/octavia-lib stable/ussuri: Update TOX/UPPER_CONSTRAINTS_FILE for stable/ussuri https://review.opendev.org/716936 | 07:17 |
openstackgerrit | Merged openstack/octavia-lib master: Update master for stable/ussuri https://review.opendev.org/716937 | 07:18 |
*** gcheresh has quit IRC | 07:28 | |
*** yamamoto has quit IRC | 07:36 | |
*** laerlingsap has joined #openstack-lbaas | 07:40 | |
*** yamamoto has joined #openstack-lbaas | 07:59 | |
*** born2bake has joined #openstack-lbaas | 08:02 | |
*** laerlingsap has left #openstack-lbaas | 08:08 | |
*** gcheresh has joined #openstack-lbaas | 08:13 | |
*** tkajinam has quit IRC | 08:17 | |
*** laerling has joined #openstack-lbaas | 08:33 | |
*** gcheresh has quit IRC | 08:34 | |
*** isakgicu has joined #openstack-lbaas | 08:34 | |
isakgicu | Hi there | 08:35 |
isakgicu | I'm wondering if it is possible to implement in future releases: | 08:35 |
isakgicu | https://github.com/jetstack/cert-manager/issues/466#issuecomment-542686593 | 08:35 |
*** gcheresh has joined #openstack-lbaas | 08:40 | |
isakgicu | I'm using openstack octavia loadbalancer(with proxy protocol enabled) in front of a nginx-ingress controller in a kubernetes cluster | 08:42 |
isakgicu | as described in issue above, there is a problem that octavia LoadBalancer does not add proxy headers when proxy protocol is enabled | 08:42 |
*** gcheresh has quit IRC | 09:34 | |
*** JayLiu has joined #openstack-lbaas | 09:37 | |
JayLiu | hello everyone! I am a fresh man~ | 09:41 |
JayLiu | I have been studied the octavia code for weeks. My company has a active/active framwork for loadbalancer, my leader and I want to transplant it into the octavia project, but at first we want know the community plan for future development :) | 09:45 |
*** ccamposr has joined #openstack-lbaas | 09:47 | |
JayLiu | So how can I participate into the development? Can I do some help at the beginning? | 09:48 |
*** ccamposr__ has quit IRC | 09:50 | |
cgoncalves | JayLiu, hi. active-active load balancing is an important feature the community has been interested for a long time. it would be great having you joining and contributing to active-active in Octavia! I am not aware of anyone working right now on active-active support, so your contributions would be most welcome | 09:51 |
JayLiu | Great! We don't want to conflict with the current community development! | 09:54 |
cgoncalves | JayLiu, there are a few specs about active-active. there is some code merged but it is mostly early code and has not been touched in years. | 09:55 |
cgoncalves | JayLiu, have you check the published specs? how do they compare to your implementation? | 09:56 |
JayLiu | Yeah, I know it from the octavia code, so I have to be careful | 09:57 |
cgoncalves | JayLiu, if you think the proposed architecture or existing code is not ideal, the community would certainly be open to receive your feedback and discuss | 09:58 |
JayLiu | Actually it is quite different from our implementation...So I am thinking how to Submit a proposal and discuss with other developer officially | 10:00 |
cgoncalves | johnsom and rm_work have contributed to active-active support or at least exposed to it way more than I have. they would be better contact points at this time. they are located in the US so offline right now. | 10:00 |
JayLiu | about the active/active feature | 10:01 |
JayLiu | ok, thank you! It is really useful~ | 10:02 |
JayLiu | Maybe I should | 10:02 |
JayLiu | contact | 10:02 |
cgoncalves | JayLiu, I see. I would maybe suggest sharing a document (text, slides or spec file) with your implementation on a high level. it would help in the discussions | 10:02 |
JayLiu | johnsom and rm_work? | 10:02 |
cgoncalves | yes. they should be online in 5-6 hours | 10:03 |
JayLiu | thx! | 10:03 |
*** rpittau is now known as rpittau|bbl | 10:25 | |
*** JayLiu has quit IRC | 10:27 | |
*** vishalmanchanda has joined #openstack-lbaas | 10:40 | |
*** yamamoto has quit IRC | 11:02 | |
*** yamamoto has joined #openstack-lbaas | 11:04 | |
*** gcheresh has joined #openstack-lbaas | 11:07 | |
*** yamamoto has quit IRC | 11:23 | |
*** yamamoto has joined #openstack-lbaas | 11:35 | |
*** yamamoto has quit IRC | 11:40 | |
*** rpittau|bbl is now known as rpittau | 12:06 | |
*** tkajinam has joined #openstack-lbaas | 12:08 | |
*** gcheresh has quit IRC | 12:19 | |
ataraday_ | cgoncalves, Hi! I've got functional job still failing on jobboard change :( Do you know what can be done? I see +1 from zuul on other changes | 12:20 |
cgoncalves | ataraday_, hi. this is the patch that should fix the functional jobs: https://review.opendev.org/#/c/711376/ | 12:22 |
ataraday_ | cgoncalves, oh, a bit weird, OK :) | 12:24 |
ataraday_ | thanks! | 12:25 |
*** gcheresh has joined #openstack-lbaas | 13:41 | |
*** gcheresh has quit IRC | 13:53 | |
*** tkajinam has quit IRC | 14:03 | |
*** tkajinam has joined #openstack-lbaas | 14:03 | |
*** gcheresh has joined #openstack-lbaas | 14:14 | |
*** TrevorV has joined #openstack-lbaas | 14:16 | |
*** dayou has quit IRC | 14:20 | |
*** dayou has joined #openstack-lbaas | 14:21 | |
*** ataraday_ has quit IRC | 14:21 | |
*** yamamoto has joined #openstack-lbaas | 14:38 | |
*** tkajinam has quit IRC | 14:42 | |
*** rcernin has quit IRC | 15:13 | |
*** yamamoto has quit IRC | 15:20 | |
johnsom | isakgicu Hi, I am trying to read and understand the problem. We currently support PROXY v1 in the load balancers. When configured for the PROXY protocol. | 15:30 |
*** gcheresh has quit IRC | 15:31 | |
johnsom | We don't have any open bugs around PROXY protocol, just an RFE to add PROXY v2 | 15:32 |
isakgicu | I understand, to open an issue for this bug there is a need to dig deep into this to find the problem | 15:42 |
johnsom | isakgicu Yeah, I am not sure what is wrong reading that page. If you can provide steps to reproduce, or the issue, please open a story for us: https://storyboard.openstack.org/#!/project/openstack/octavia | 15:43 |
johnsom | We will look into it. | 15:43 |
isakgicu | ok, thank you ! :) | 15:44 |
*** rpittau is now known as rpittau|afk | 16:08 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add ability to specify TLS cipher list for pools https://review.opendev.org/717154 | 16:11 |
johnsom | dawzon FYI, I rebased the pools ciphers for you. I see there is some test work to finish there. Are you able to do that today? | 16:12 |
dawzon | Yeah. Although I was also having some weird amphora issues with that patch, so hopefully that doesn't get in the way | 16:14 |
johnsom | dawzon Awesome. Let me know if I can help! | 16:14 |
johnsom | I'm reviewing now | 16:14 |
openstackgerrit | Merged openstack/octavia master: Add ability to set TLS cipher list for listeners https://review.opendev.org/711376 | 16:45 |
johnsom | dawzon ^^^ Wahoo! | 16:48 |
dawzon | Awesome! | 16:49 |
*** psachin has quit IRC | 16:55 | |
openstackgerrit | Carlos Goncalves proposed openstack/octavia master: Fix listener update with SNI certificates https://review.opendev.org/712790 | 16:57 |
openstackgerrit | Carlos Goncalves proposed openstack/octavia master: Add noop certificate manager https://review.opendev.org/717619 | 16:58 |
openstackgerrit | Merged openstack/octavia master: Don't register cli opts on import https://review.opendev.org/716440 | 17:14 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Jobboard based controller https://review.opendev.org/647406 | 17:24 |
*** vishalmanchanda has quit IRC | 17:47 | |
*** gcheresh has joined #openstack-lbaas | 18:09 | |
*** zasherif has joined #openstack-lbaas | 18:16 | |
*** zasherif has quit IRC | 18:20 | |
*** zasherif has joined #openstack-lbaas | 18:29 | |
*** zasherif has quit IRC | 18:32 | |
*** maciejjozefczyk has quit IRC | 18:39 | |
*** gcheresh has quit IRC | 18:51 | |
openstackgerrit | Brian Haley proposed openstack/octavia master: Remove Neutron SDN-specific code https://review.opendev.org/718192 | 19:12 |
johnsom | haleyb I put a comment on the neutron patch, but I have no idea which one is right Q_AGENT or NEUTRON_AGENT.... | 19:35 |
haleyb | i don't know if it's either or both myself | 19:36 |
johnsom | lol | 19:37 |
johnsom | probably NETWORK_AGENT | 19:37 |
johnsom | grin | 19:37 |
haleyb | depends on if lib/neutron of lib/neutron-legacy is used, which depends on what the user specified - think if you use Q_ in local.conf you get that version | 19:38 |
haleyb | i'm not going to mess with it | 19:38 |
johnsom | Works for me | 19:38 |
johnsom | Well, not messing with it. | 19:38 |
haleyb | right, until we clean up that neutron mess... | 19:39 |
*** zasherif has joined #openstack-lbaas | 20:01 | |
*** zasherif has quit IRC | 20:03 | |
*** TrevorV has quit IRC | 20:55 | |
*** zasherif has joined #openstack-lbaas | 20:59 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Refactor the failover flows https://review.opendev.org/705317 | 21:00 |
*** zasherif has quit IRC | 21:01 | |
*** born2bake has quit IRC | 21:36 | |
openstackgerrit | Mikhail Ushanov proposed openstack/octavia master: fix(elements): fix nf_conntrack sysctl param names https://review.opendev.org/706674 | 21:38 |
*** zasherif has joined #openstack-lbaas | 21:44 | |
*** zasherif has quit IRC | 21:50 | |
rm_work | cgoncalves: noop cert manager? :D | 21:51 |
johnsom | rm_work He lives | 21:52 |
johnsom | rm_work Hey, I have a question for you when you have a minute | 21:52 |
rm_work | Yeah sorry I've been pretty dead, kinda sick for a week or so, sleeping a lot. Not lower respiratory fortunately | 21:53 |
rm_work | What's up? | 21:53 |
johnsom | Oh good | 21:53 |
xgerman | +1 | 21:53 |
johnsom | So, failover patch. Greg noticed that it actually fails over amphora now, where before failover just deleted the amp if it wasn't assigned to an LB. | 21:53 |
johnsom | My thought on this is, it should fail it over and not just delete it. | 21:54 |
johnsom | I'm working on adding an amphora delete to replace that functionality (i.e. you turn off spares pool for some reason). | 21:54 |
johnsom | Thoughs? | 21:54 |
xgerman | filling the spares pool has been our lowest priority (if we run with noiva quotas) | 21:56 |
xgerman | also you might get race cinditions sith whoever fills that pool | 21:56 |
* xgerman disappears in the bush | 21:56 | |
johnsom | This case is, spare enable, you have 2 spare amps. Disable spares pool. | 21:57 |
johnsom | Now you want to delete those spares (instead of just letting them be consumed) | 21:57 |
*** rcernin has joined #openstack-lbaas | 22:11 | |
rm_work | hmm yes | 22:23 |
rm_work | i did sometimes rely on amphora-failover to deal with random extra amps | 22:24 |
rm_work | but, if there is a delete, that's fine | 22:24 |
rm_work | i'm trying to remember the exact case i run into, but we don't even use a spares pool here | 22:24 |
johnsom | Ok, yeah, I think failover should failover. We can add an admin amphora delete | 22:25 |
rm_work | and we would end up with random unowned amps... i think from errors somewhere in the boot process? though traditionally those would be deleted in revert... | 22:25 |
rm_work | might be resolved by jobboard too | 22:25 |
rm_work | OR those might have been relics of failed failovers before | 22:25 |
dawzon | johnsom So when I actually try to test the pool ciphers patch, I'm having troubles with the .pem files for the member not actually showing up on the amphora. They're just... not there, no directory is even created in /var/lib/octavia/certs. | 22:48 |
johnsom | dawzon No hints in the amphora/syslog? | 22:49 |
dawzon | https://www.irccloud.com/pastebin/mjymFuYD/ | 22:54 |
dawzon | Not that I can see. There's a couple 404s but they all seem to be followed up by retries that return 200 | 22:54 |
dawzon | Not that I really know how to interpret this log | 22:55 |
dawzon | , though | 22:55 |
johnsom | That log shows that it accepted the pem files. | 22:56 |
*** tkajinam has joined #openstack-lbaas | 22:56 | |
dawzon | The one for the frontend shows up just fine, but not the other one. I feel like it's gotta be something stupid but I haven't been able to quite nail it down | 22:57 |
dawzon | Only when I add the member does it fail | 22:58 |
johnsom | Do you want to screen share? | 22:58 |
dawzon | Sure | 22:58 |
johnsom | Join the regular hangout room | 22:59 |
*** isakgicu has quit IRC | 23:18 | |
johnsom | Blah, ok, there is probably a bug in the pool CA cert jinja where the file path is getting written out wrong. | 23:23 |
*** zasherif has joined #openstack-lbaas | 23:37 | |
*** zasherif has quit IRC | 23:41 | |
openstackgerrit | Merged openstack/python-octaviaclient master: Add amphora stats show API and CLI https://review.opendev.org/699466 | 23:51 |
nmickus | johnsom for updating the unit tests in the cli is all thats needed is to add `--tls_ciphers, self._listener.tls_ciphers` to the agrlist and verifylist in the test? | 23:54 |
johnsom | Yeah, I think that is all | 23:54 |
johnsom | Just so it puts some data in and checks it comes out on the back | 23:54 |
johnsom | Don't forget to update the create and the set/update tests | 23:54 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!