Tuesday, 2020-05-19

openstackgerritAnn Taraday proposed openstack/octavia master: Add option to set default ssl ciphers in haproxy  https://review.opendev.org/68533709:16
openstackgerritCarlos Goncalves proposed openstack/octavia master: Refactor the failover flows  https://review.opendev.org/70531709:51
openstackgerritGregory Thiemonge proposed openstack/octavia master: Fix netcat option in udp_check.sh for CentOS/RHEL  https://review.opendev.org/72923011:57
openstackgerritMerged openstack/octavia stable/ussuri: Remove deprecated exception classes  https://review.opendev.org/72877712:21
openstackgerritMerged openstack/octavia master: Add TLS cipher blacklist to octavia.conf  https://review.opendev.org/72037515:54
openstackgerritMichael Johnson proposed openstack/octavia master: Make sure devstack aborts if DIB fails  https://review.opendev.org/72292016:27
haleybjohnsom: mind if i push an update to https://review.opendev.org/#/c/714004/ ?  just a rebase.  part of me wanted to see the logs for the ovn provider and they're gone now18:05
johnsomSure, NP18:06
haleybsigh, it also needs a rebase on the skip_if_not_implemented patch18:07
openstackgerritKeith Berger proposed openstack/octavia master: Update osutil support for SUSE distro  https://review.opendev.org/54181118:11
haleybjohnsom: i had to give up, git review kept trying to rebase to master and mucking things up, need https://review.opendev.org/#/c/714003/ merged first18:38
johnsomI will take a look after lunch18:39
openstackgerritMichael Johnson proposed openstack/octavia-tempest-plugin master: Add skip_if_not_implemented to the service client  https://review.opendev.org/71400318:45
johnsomWell, that one rebased via gerrit button18:46
haleybjohnsom: well, that's one way to do it :)18:46
haleybyeah, i was trying the second one onto that, and it wasn't working, probably will now though18:47
johnsomWell, I'm just about done, so hang on18:47
haleyboh i have my popcorn out18:47
haleybamazingly it didn't drop all the votes18:48
johnsomYeah, a clean rebase will not18:49
openstackgerritMichael Johnson proposed openstack/octavia-tempest-plugin master: WIP: Adjust scenario tests for NotImplemented skip  https://review.opendev.org/71400418:51
johnsomhaleyb There you go. The only conflict I had was all of the zuul jobs I commented out.18:52
haleybjohnsom: yeah, a file removal was killing me18:52
haleybjohnsom: thanks!18:53
johnsomhaleyb I don't expect everything to pass with the state of that patch, but the "balanced" test should if OVN is fixed18:56
haleybjohnsom: yeah, that's one thing i wanted to check, but i'm not holding my breath18:58
openstackgerritMichael Johnson proposed openstack/octavia master: Add amphora delete API  https://review.opendev.org/71829319:15
openstackgerritMichael Johnson proposed openstack/python-octaviaclient master: Add amphora delete command  https://review.opendev.org/71831119:16
johnsomDay of the rebase! lol19:16
openstackgerritMichael Johnson proposed openstack/octavia-tempest-plugin master: Introduce a simple HTTPS server for TLS test.  https://review.opendev.org/62889119:20
openstackgerritMichael Johnson proposed openstack/octavia-tempest-plugin master: Remove all usage of six library  https://review.opendev.org/72575819:27
openstackgerritBrian Haley proposed openstack/octavia-tempest-plugin master: Drop python 2.7 support and testing  https://review.opendev.org/72937719:59
openstackgerritBrian Haley proposed openstack/octavia master: Allow multiple VIPs per LB  https://review.opendev.org/66023920:37
openstackgerritMichael Johnson proposed openstack/octavia-tempest-plugin master: Switch to using q35 machine type for Octavia jobs  https://review.opendev.org/72939120:54
openstackgerritMichael Johnson proposed openstack/octavia master: DNM: Checking on what CPUs we are ending up with  https://review.opendev.org/72940922:02
rm_workoh geeze there's rebases, indeed22:47
rm_workhaleyb: BTW do you have any context on the shared as readonly security groups thing i'm working on in Neutron?22:48
rm_workif you're familiar with how the SG sharing works, I could possibly use some pointers. I've got a very early start on it but I can't quite tell whether this is going to be super easy or way more complex than I thought22:48
rm_workdougwig wrote the original patch that added sharing support to SGs, but I think he may have run far away from here? :D22:50
dougwigrm_work: what can i help with?22:53
johnsomdougwig How goes it? Long time no chat.22:53
* johnsom now that he summoned you, lol22:54
dougwigjohnsom: heya, not bad, not bad. faring well in this covid mess.  you?22:54
johnsomdougwig Same here. Dumb enough to sign up for another PTL cycle though.22:55
dougwigjohnsom: i think you secretly love it.22:55
johnsomdougwig I passed it off on rm_work for a bit. No takers this time around however.22:56
johnsomdougwig Come on, you know you miss telling us what you think....22:57
dougwigjohnsom: i'm here to give my opinion on sharing objects in neutron, but rm_work has deserted us.22:57
openstackgerritMichael Johnson proposed openstack/octavia master: DNM: Testing the impact of mitigations on the jobs  https://review.opendev.org/72941722:57
johnsomdougwig I think the term is "Oh look, a chicken!" and off he went22:58
rm_workdougwig: ah, i went to try to hook up my other wifi AP :D22:59
dougwigrm_work: the sharing is vanilla neutron RBAC.  what's your question?22:59
dougwigahh, there he is.  what continent are you living on now?22:59
rm_workright so, I am adding an additional sharing "action", `access_as_readonly`22:59
dougwigfor just SG, or all rbac objects?  (i'll presume/hope all)22:59
rm_workit was just a spec for SH23:00
rm_workbut ... yeah now it is looking like it'd be difficult to split that up23:00
dougwigthey're all common objects in an rbac table.  if possible, i'd add it for all, for sanity's sake.23:00
rm_workthat's the kind of advice i was looking for23:00
rm_workI think that makes a little more sense23:01
rm_workhopefully that goes over well23:01
dougwigmakes more sense for the user's, too.  piecemeal rbac is nutso.  :)23:01
rm_worknetwork seems to be a bit... separate tho23:01
dougwig /user's/users/23:01
rm_workprobably since it was "very first"23:01
rm_workdoes it make sense for network too?23:01
dougwigit's in the common db/model class.  the semantic hooks are elsewhere, yeah, but the perms should be in the same spot.23:01
rm_workjust gotta figure out how to make it actually refuse to do actions when it's readonly, but still show it23:02
dougwigthe big downside to "doing them all" is that you'll need 3x the tests.  the big downside of not doing them all is that the RBAC feature starts to make no fucking sense on a cohesive level.23:02
rm_workmight have to split the object lookup function it uses into two different ones depending on context23:02
rm_workyeah i'll ping slawek and miguel and make sure it makes sense to them to expand the scope of the spec they voted on23:03
dougwig(is that opinionated enough for you, johnsom ?)23:03
johnsomBrings back all of the warm fuzzies23:03
rm_worknow can you go back to A10 and fix their octavia implementation plz23:03
dougwigif you join that slack link i sent, you can also bug kevinbenton with questions, who write the network side of that.23:04
dougwighahahha, no.23:04
dougwigi can yell at their devs, if you want.  i don't think i have any pull left, though.  :)23:05
dougwiggotta go feed kids.  @ me if you need me, i don't actively monitor irc.23:11
