*** jamesdenton has quit IRC | 01:04 | |
*** jamesden_ has joined #openstack-lbaas | 01:05 | |
*** osmanlicilegi has joined #openstack-lbaas | 01:20 | |
*** sapd1 has joined #openstack-lbaas | 01:22 | |
*** sapd1 has quit IRC | 01:28 | |
*** rcernin has quit IRC | 02:31 | |
*** rcernin has joined #openstack-lbaas | 02:38 | |
openstackgerrit | Merged openstack/octavia master: Fix pool ALPN compatibility with older amphora https://review.opendev.org/c/openstack/octavia/+/783576 | 02:44 |
---|---|---|
openstackgerrit | Merged openstack/octavia stable/wallaby: Fix pool ALPN compatibility with older amphora https://review.opendev.org/c/openstack/octavia/+/783916 | 02:44 |
openstackgerrit | Merged openstack/octavia stable/train: Fix incorrect ERROR status with IPv6 UDP members https://review.opendev.org/c/openstack/octavia/+/781486 | 02:45 |
johnsom | Wahoo. | 02:51 |
johnsom | Ok, I think all of the critical patches for Wallaby are in. We should release RC2 tomorrow to get those in the release. | 02:52 |
johnsom | If you think there is another patch that is critical, now is the time to speak up. grin | 02:53 |
*** armax has quit IRC | 02:55 | |
*** armax has joined #openstack-lbaas | 02:59 | |
*** rcernin has quit IRC | 03:07 | |
*** rcernin has joined #openstack-lbaas | 03:07 | |
*** rcernin has quit IRC | 03:07 | |
*** rcernin has joined #openstack-lbaas | 03:09 | |
*** dulek has quit IRC | 03:09 | |
*** rcernin has quit IRC | 03:11 | |
*** rcernin has joined #openstack-lbaas | 03:12 | |
*** rcernin has quit IRC | 03:14 | |
*** rcernin has joined #openstack-lbaas | 03:14 | |
*** rcernin has quit IRC | 03:16 | |
*** rcernin has joined #openstack-lbaas | 03:16 | |
*** rcernin has quit IRC | 03:18 | |
*** rcernin has joined #openstack-lbaas | 03:19 | |
*** dulek has joined #openstack-lbaas | 03:19 | |
*** sapd1 has joined #openstack-lbaas | 03:36 | |
*** psachin has joined #openstack-lbaas | 03:41 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Adds a pool re-encryption scenario test https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/760465 | 03:47 |
*** tamas_erdei has joined #openstack-lbaas | 03:49 | |
*** terdei has quit IRC | 03:53 | |
*** armax has quit IRC | 03:57 | |
*** vishalmanchanda has joined #openstack-lbaas | 04:30 | |
*** sapd1 has quit IRC | 04:42 | |
*** sapd1 has joined #openstack-lbaas | 04:43 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Adds a pool re-encryption scenario test https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/760465 | 05:19 |
openstackgerrit | Piotr Mossakowski proposed openstack/octavia stable/victoria: Add docs for centos8 installation https://review.opendev.org/c/openstack/octavia/+/784004 | 06:20 |
*** luksky has joined #openstack-lbaas | 06:42 | |
*** jamesden_ has quit IRC | 07:08 | |
*** jamesdenton has joined #openstack-lbaas | 07:10 | |
*** rcernin has quit IRC | 07:25 | |
*** sapd1 has quit IRC | 07:30 | |
*** tamas_erdei is now known as terdei | 07:32 | |
openstackgerrit | Piotr Mossakowski proposed openstack/octavia master: Add docs for centos8 installation https://review.opendev.org/c/openstack/octavia/+/784022 | 08:01 |
*** psachin has quit IRC | 08:30 | |
*** vishalmanchanda has quit IRC | 08:39 | |
*** vishalmanchanda has joined #openstack-lbaas | 09:11 | |
*** yamamoto has quit IRC | 10:00 | |
*** rcernin has joined #openstack-lbaas | 10:06 | |
*** rcernin has quit IRC | 10:08 | |
*** rcernin has joined #openstack-lbaas | 10:08 | |
*** jamesdenton has quit IRC | 10:20 | |
*** jamesden_ has joined #openstack-lbaas | 10:21 | |
*** yamamoto has joined #openstack-lbaas | 10:33 | |
*** yamamoto has quit IRC | 10:46 | |
*** mugsie__ is now known as mugsie | 11:01 | |
*** oklhost_ has joined #openstack-lbaas | 12:18 | |
*** oklhost_ is now known as oklhost | 12:18 | |
*** yamamoto has joined #openstack-lbaas | 12:30 | |
*** rcernin has quit IRC | 12:31 | |
openstackgerrit | Gregory Thiemonge proposed openstack/octavia master: Fix devstack cleanup when using amphorav2 https://review.opendev.org/c/openstack/octavia/+/782938 | 12:34 |
*** yamamoto has quit IRC | 12:39 | |
*** yamamoto has joined #openstack-lbaas | 13:10 | |
*** yamamoto has quit IRC | 13:15 | |
*** yamamoto has joined #openstack-lbaas | 13:15 | |
*** yamamoto has quit IRC | 13:55 | |
*** rcernin has joined #openstack-lbaas | 14:12 | |
*** rcernin has quit IRC | 14:17 | |
*** armax has joined #openstack-lbaas | 14:18 | |
*** jamesden_ has quit IRC | 14:24 | |
*** gcheresh has quit IRC | 14:24 | |
*** jamesdenton has joined #openstack-lbaas | 14:24 | |
*** rcernin has joined #openstack-lbaas | 14:31 | |
*** rcernin has quit IRC | 14:35 | |
*** yamamoto has joined #openstack-lbaas | 14:35 | |
*** yamamoto has quit IRC | 14:42 | |
*** __ministry1 has joined #openstack-lbaas | 15:10 | |
*** sapd1 has joined #openstack-lbaas | 15:20 | |
*** rcernin has joined #openstack-lbaas | 15:26 | |
*** rcernin has quit IRC | 15:31 | |
zigo | Hi there ! | 15:35 |
zigo | What do you guys think about this bug I just filled ? | 15:35 |
zigo | https://storyboard.openstack.org/#!/story/2008790 | 15:35 |
zigo | johnsom: ^ | 15:35 |
johnsom | zigo It sounds like you have HTTPS enabled on barbican, but forgot to add the CA cert in octavia.conf [certificates] ca_certificates_file = <path to ca cert> | 15:41 |
zigo | johnsom: We do have a real certificate, so no need to have a CA. | 15:42 |
johnsom | It is a guess as I didn't see a link to logs | 15:42 |
johnsom | hmm, does keystoneauth pick up the system bundle? | 15:43 |
johnsom | I think I have always had to force keystoneauth to use a ca cert | 15:43 |
zigo | I'll try tomorrow. | 15:44 |
zigo | Time for me to go back home. | 15:44 |
zigo | johnsom: Thanks for your input. | 15:44 |
johnsom | Ok, attach some logs if not | 15:44 |
zigo | Will do. | 15:44 |
*** sapd1 has quit IRC | 16:01 | |
*** __ministry1 has quit IRC | 16:01 | |
johnsom | #startmeeting Octavia | 16:02 |
openstack | Meeting started Wed Mar 31 16:02:17 2021 UTC and is due to finish in 60 minutes. The chair is johnsom. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:02 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:02 |
*** openstack changes topic to " (Meeting topic: Octavia)" | 16:02 | |
openstack | The meeting name has been set to 'octavia' | 16:02 |
haleyb | should have run when i had the chance | 16:02 |
johnsom | Hi everyone | 16:02 |
gthiemon1e | hi | 16:02 |
johnsom | Yeah, got distracted commenting on a story | 16:02 |
*** gthiemon1e is now known as gthiemonge | 16:02 | |
johnsom | #topic Announcements | 16:03 |
*** openstack changes topic to "Announcements (Meeting topic: Octavia)" | 16:03 | |
johnsom | RC2 release today - Should be the final release for Wallaby | 16:03 |
johnsom | Any comments on the RC2 release? | 16:03 |
johnsom | I will post it right after the meeting | 16:03 |
gthiemonge | +1 | 16:03 |
haleyb | lgtm | 16:03 |
johnsom | PTG (virtual and free) registration is open | 16:04 |
johnsom | #link https://www.openstack.org/ptg/ | 16:04 |
johnsom | gthiemonge set up the PTG etherpad | 16:04 |
johnsom | #link https://etherpad.opendev.org/p/xena-ptg-octavia | 16:04 |
johnsom | Please note if you plan to join and add any topics you think we should discuss | 16:04 |
johnsom | Any other announcements this week? | 16:05 |
johnsom | #topic Brief progress reports / bugs needing review | 16:05 |
*** openstack changes topic to "Brief progress reports / bugs needing review (Meeting topic: Octavia)" | 16:06 | |
johnsom | I have been mostly focused on getting the patches merged for RC2. | 16:06 |
johnsom | I fixed the bug with older amphora and the new pools ALPN feature. This will be included in RC2 | 16:06 |
johnsom | Currently I am looking into why the tempest tests for pool re-encryption are failing now. It looks like the floating IP (test created) is not passing traffic for some reason. Not sure if that is a known neutron issue or not | 16:07 |
gthiemonge | I've been working on some updates in the Octavia integration in tripleo | 16:07 |
gthiemonge | and I'm still looking at the ipv6+tcp+least_connection+allowed_cidrs scenario test that fails randomly | 16:09 |
haleyb | and i've been working on the ovn-provider and some downstream gate issues | 16:09 |
johnsom | Thanks, that is annoying | 16:09 |
johnsom | #topic Open Discussion | 16:10 |
*** openstack changes topic to "Open Discussion (Meeting topic: Octavia)" | 16:10 | |
johnsom | Any other topics today? | 16:10 |
gthiemonge | yep | 16:11 |
gthiemonge | one question | 16:11 |
johnsom | Just in time, lol | 16:11 |
gthiemonge | a user reported on the ML that not configuring "heartbeat_key" breaks the heartbeat message encryption | 16:11 |
gthiemonge | when not setting heartbeat_key, the default is None | 16:12 |
gthiemonge | in the amp we encrypt using "str(heartbeat_key)" while in the hm we decrypt using "heartbeat_key" | 16:12 |
gthiemonge | so in the case of None, str(None) != None | 16:13 |
haleyb | i'm assuming this review was from that, https://review.opendev.org/c/openstack/octavia/+/784022 | 16:13 |
johnsom | hmmm, I would have expected that to be marked "required" in config.py as well.. | 16:13 |
gthiemonge | my question is: should we fix it? or should we set another default value for heartbeat_key | 16:13 |
cgoncalves | ah, reminds me of https://review.opendev.org/c/openstack/octavia/+/595578/1/octavia/common/config.py@196 | 16:14 |
johnsom | cgoncalves Yeah, good point | 16:14 |
gthiemonge | https://opendev.org/openstack/octavia/src/branch/master/octavia/certificates/common/local.py#L32-L33 | 16:15 |
gthiemonge | ^ we already have insecure defaults for some other config settings | 16:15 |
johnsom | Well, that is different. That key is only used for internal to the controller content, not stuff that goes over the wire. | 16:16 |
johnsom | It's a poorly named setting IMO | 16:16 |
johnsom | Hmm, yeah, the heartbeat key is an interesting one. There is no harm in setting it even if the amphora drivers are not used. | 16:18 |
johnsom | It is bad to have that content unprotected by allowing None | 16:18 |
johnsom | But we also shouldn't fail like it is | 16:18 |
gthiemonge | it's encrypted, but the key is None ;-) | 16:18 |
johnsom | It's actually not encrypted, but it's signed | 16:19 |
gthiemonge | the heartbeat_key was missing in the install-ubuntu doc, and there's a patch to add it | 16:19 |
gthiemonge | but I think we also need to have a working default value | 16:20 |
johnsom | Or require it be set to something | 16:20 |
gthiemonge | yeah that could be a good fix | 16:21 |
gthiemonge | with the fix in the doc | 16:21 |
gthiemonge | I'll propose a patch | 16:22 |
johnsom | Ok. It is a bit cheesy to require it even for providers that don't use it, but that might just be simpler | 16:23 |
*** jamesdenton has quit IRC | 16:24 | |
*** jamesdenton has joined #openstack-lbaas | 16:25 | |
johnsom | Ok, anything else today? | 16:26 |
johnsom | Ok, thanks everyone | 16:27 |
johnsom | #endmeeting | 16:27 |
*** openstack changes topic to "Discussions for OpenStack Octavia | Priority bug review list: https://etherpad.openstack.org/p/octavia-priority-reviews" | 16:27 | |
openstack | Meeting ended Wed Mar 31 16:27:24 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:27 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/octavia/2021/octavia.2021-03-31-16.02.html | 16:27 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/octavia/2021/octavia.2021-03-31-16.02.txt | 16:27 |
openstack | Log: http://eavesdrop.openstack.org/meetings/octavia/2021/octavia.2021-03-31-16.02.log.html | 16:27 |
gthiemonge | thanks johnsom | 16:27 |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Adds a pool re-encryption scenario test https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/760465 | 16:48 |
mnaser | this looks like the case, but it looks like octavia does not issue any notifications, correct? | 16:52 |
mnaser | things like when a load balancer has been successfully created, .exists, deleted | 16:52 |
mnaser | other than pycadf which doesnt necessarily reflect the completion of the async operation | 16:52 |
johnsom | Maybe there was a netsplit, I only saw "this looks like the case" and two more lines | 16:53 |
johnsom | But to answer your question, status update notifications have not yet been implemented. It stalled at needing a specification detailed out as we were getting widely different use cases that was confusing the need. | 16:55 |
johnsom | Yes, there is API auditing, which can be configured for notifications, but no other notifications. | 16:55 |
mnaser | johnsom: ah i see, i was just hoping for some basic notifications similar to all the other projects :( | 17:00 |
johnsom | Just the audit information. | 17:01 |
johnsom | It needs a sponsor really | 17:01 |
johnsom | FYI, I have posted the RC2 release for Octavia: https://review.opendev.org/c/openstack/releases/+/784139/1/deliverables/wallaby/octavia.yaml | 17:23 |
*** rcernin has joined #openstack-lbaas | 17:27 | |
*** rcernin has quit IRC | 17:35 | |
*** vishalmanchanda has quit IRC | 17:51 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Adds a pool re-encryption scenario test https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/760465 | 18:17 |
johnsom | Sorry for the noise around that patch. I can't reproduce this locally, so have to debug in zuul. Ignore that patch for a few days | 18:18 |
* johnsom notes it's been up for review since October, so probably not a problem to ignore | 18:18 | |
*** gcheresh has joined #openstack-lbaas | 18:30 | |
openstackgerrit | Merged openstack/octavia stable/victoria: Fix incorrect ERROR status with IPv6 UDP members https://review.opendev.org/c/openstack/octavia/+/781483 | 18:31 |
johnsom | FYI, I guess there is some zuul debugging going on (hopefully to help with the painful last two weeks), so it is running super slow. My patch has sat for over fifteen minutes and still not entered the check pipeline. | 18:38 |
openstackgerrit | Merged openstack/octavia stable/ussuri: Fix incorrect ERROR status with IPv6 UDP members https://review.opendev.org/c/openstack/octavia/+/781485 | 18:42 |
*** yamamoto has joined #openstack-lbaas | 18:50 | |
*** yamamoto has quit IRC | 18:54 | |
*** jamesdenton has quit IRC | 18:56 | |
*** jamesden_ has joined #openstack-lbaas | 18:57 | |
*** rcernin has joined #openstack-lbaas | 19:31 | |
*** rcernin has quit IRC | 19:36 | |
*** gcheresh has quit IRC | 19:38 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Adds a pool re-encryption scenario test https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/760465 | 20:16 |
*** rcernin has joined #openstack-lbaas | 20:30 | |
*** jamesden_ has quit IRC | 20:38 | |
*** jamesdenton has joined #openstack-lbaas | 20:39 | |
*** mloza has joined #openstack-lbaas | 20:54 | |
*** rcernin has quit IRC | 21:05 | |
*** rcernin has joined #openstack-lbaas | 21:05 | |
mloza | hello, is it possible to restrict access to an certain IP to an LB ? | 21:11 |
cgoncalves | mloza, hi. yes, you can per listener. see https://docs.openstack.org/octavia/latest/user/guides/basic-cookbook.html#deploy-a-load-balancer-with-access-control-list | 21:12 |
mloza | cgoncalves: This is what I'm looking for. Thanks a bunch | 21:19 |
*** rcernin has quit IRC | 21:30 | |
*** rcernin has joined #openstack-lbaas | 21:55 | |
*** rcernin has quit IRC | 22:00 | |
*** rcernin has joined #openstack-lbaas | 22:13 | |
*** rcernin has quit IRC | 22:18 | |
*** yamamoto has joined #openstack-lbaas | 22:30 | |
*** luksky has quit IRC | 22:30 | |
*** rcernin has joined #openstack-lbaas | 22:32 | |
*** rcernin has quit IRC | 22:32 | |
*** rcernin has joined #openstack-lbaas | 22:33 | |
*** jamesdenton has quit IRC | 22:57 | |
*** jamesden_ has joined #openstack-lbaas | 22:57 | |
*** yamamoto has quit IRC | 23:34 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!