Wednesday, 2026-09-23

johnsomHaven’t seen the ticket, but we were very careful about this. Security keys are delivered via config drive and no other way. All command and control actions are via two-way TLS authentication with each amp having it’s own certs. Plus, tenant key info is push only from the controllers, so I don’t see how one amp could access another amp’ key content.05:03
johnsomAs for root, pretty sure gunicorn is configured to drop from root to another account on startup.05:15
gthiemongejohnsom: it's an injection in the haproxy config file, the master runs as root09:04
gthiemongejohnsom: right, the amphora should not have access to other tenant/amp's content09:05
opendevreviewAustin Russell proposed openstack/octavia-tempest-plugin master: Add test for LB/amphora failover when vip-subnet is full  https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/100572814:45
johnsomHaproxy does not run as root, it runs under the haproxy account15:57
gthiemongejohnsom: I'll double check after the meeting but only the workers run as haproxy16:00
gthiemonge#startmeeting Octavia16:01
opendevmeetMeeting started Wed Sep 23 16:01:00 2026 UTC and is due to finish in 60 minutes.  The chair is gthiemonge. Information about MeetBot at http://wiki.debian.org/MeetBot.16:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.16:01
opendevmeetThe meeting name has been set to 'octavia'16:01
gthiemongeo/16:01
rcruise-redhato/16:01
raineszmo/16:01
viniciusro/16:01
gthiemonge#topic Announcements16:04
gthiemonge* 2026.2 Hibiscus Release Schedule: R-116:04
gthiemongewe're in the Final RCs week16:04
gthiemongeNext week is the GA16:04
gthiemongeafaik we're good for Octavia, RC1 will be our GA16:05
gthiemonge* Octavia CVEs16:05
gthiemonge2 CVEs were requested for 2 issues reported last month (already fixed on master and maintained stable branches)16:05
gthiemongehttps://www.cve.org/CVERecord?id=CVE-2026-9457116:05
gthiemongehttps://www.cve.org/CVERecord?id=CVE-2026-9457216:05
gthiemongeIMHO the score (CRITICAL 9.4) is higher than expected16:06
gthiemongeFYI at Red Hat, these CVEs are classified as IMPORTANT 7.416:06
gthiemonge17.0.1 (flamingo) and 18.0.1 (gazpacho) were released yesterday with the bugfixes16:07
gthiemonge* Octavia PTG16:07
gthiemongetime flies... PTG is really close: October 12-16, 202616:08
gthiemongeI haven't reserved a room yet, I'll do it soon16:08
gthiemongeI will also prepare the PTG etherpad so you can add your topics there16:08
gthiemongeI'll keep you updated16:09
gthiemongeany additional announcements? or questions?16:09
gthiemongeok16:11
gthiemonge#topic Brief progress reports / bugs needing review16:11
gthiemongewell I was on PTO last week, my activity was really limited16:11
gthiemongeI plan to prepare the PTG and review patches of features that we didn't merge in H16:11
rcruise-redhatI had some downstream stuff to work on so I haven't had time to look at upstream much. I'm hoping to test out this change soon https://review.opendev.org/c/openstack/octavia/+/864308 16:12
rcruise-redhatOther than that, I've a lot of reviews to catch up with16:13
gthiemongeack16:15
gthiemonge#topic Open Discussion16:18
viniciusrcan I go?16:18
gthiemongejohnsom: I'll check if we can improve the security on this side, the haproxy service is started as root, because it needs to jump into the ns, then it also needs root to listen on privileged ports, but they are probably more conveniant ways to do it16:19
gthiemongeviniciusr: sure16:19
viniciusrI've been reorganizing the patches for active active load balancing using bgp, reducing the total number of patches and putting it in a better shape16:20
gthiemongecool16:22
viniciusrHow should I proceed on gerrit? the bgp-exp topic has many many patches, but I'm afraid of replacing everything and loosing comments after the squash16:22
gthiemongeI would say that it's almost safe to squash patches that are in the same component (like patches for amphora-agent, patches for the flows), or if one patch of the chain fixes an issue introduced in the chain, it doesn't make sense to have 2 patches16:24
gthiemongeif we lose comments.. I mean it's better to have clearly defined patches for specific areas, than to review code that will be modified in another patch16:25
johnsomgthiemonge It does start as root (for ports, and FDs, etc.) but drops privilege to the haproxy account.16:26
gthiemongejohnsom: we have https://github.com/openstack/octavia/blob/master/octavia/common/jinja/haproxy/combined_listeners/templates/base.j2#L1916:27
gthiemongebut it looks like it only impacts the workers16:27
viniciusrbut after squashing (for example two commits into one) the old patches will not disappear from the whole topic (bgp-exp), right? 16:29
gthiemongeroot        1063  0.0  1.1  93860 11732 ?        Ss   09:10   0:00 /usr/sbin/haproxy -Ws -f /var/lib/octavia/dfe2be40-ee16:30
gthiemongenobody      1356  0.0  1.8 106572 18492 ?        S    09:10   0:01 /usr/sbin/haproxy -sf 1265 -x sockpair@5 -Ws -f /var/16:30
gthiemongeviniciusr: we'll have to abandon them16:30
viniciusrhmm ok16:31
viniciusrthanks!16:32
raineszmQuick Question on my end: So I had a request to allow increasing the header size for the amphora provider, basically corresponding to exposing the tune.bufsize haproxy option in the config. I'm curious if y'all think that is a useful configuration knob to expose, and whether it would be backportable.16:32
rcruise-redhatWell if someone is looking for it, then it's probably worth adding as something that can be configured. As to whether it can be backported, I'm not sure16:34
raineszmCurrently it's doable by wholesale replacing the haproxy template, but that seems really painful for just changing the one option16:35
rcruise-redhatYeah that seems like a messy solution, a config option would be a lot neater16:36
rcruise-redhatI'm not sure if a change to the provider can be backported though16:36
gthiemongewe usually don't backport changes that introduce new settings, however if the default value of the setting doesn't change the behavior of octavia, I think it's possible16:36
gthiemongeneed to check in the project guide16:37
raineszmThe ask in this case is because their workloads need to receive headers above 16Kb, so  things are broken right now.16:37
gthiemongeinteresting16:37
raineszmAs to what they fill 20 some odd Kb of headers with, I don't know16:37
raineszmBut apparently it happens16:37
gthiemongelol16:38
gthiemongeopen a launchpad that explains the problem (the bug), it will be backportable.. don't open a launchpad that requests a new feature for bufsize, that would be not backportable16:39
* raineszm nods16:39
gthiemongeIMHO it's a bug16:39
rcruise-redhatThis is how you work the system :)16:39
raineszmCool. I'll file an LP bug and look at writing a patch16:39
gthiemongegreat, thanks!16:40
rm_workOh gross that whole structure still exists with combined listeners vs not lol, I still feel icky about that16:40
rm_workThat was supposed to be like… for backwards compat briefly for migration, people weren’t supposed to use both indefinitely lol16:40
gthiemongerm_work: the split listeners dir was removed :D16:40
rm_worklol ok good so it’s just cruft in the path16:41
rm_workjohnsom: well I guess they reproduced? So idk 🤷‍♂️ 16:41
rm_workI just accepted their claim on the root thing since their repro apparently worked16:42
rm_workJust what they got out of it mattered way less than the claim16:42
gthiemongerm_work: so I reproduced the exploit16:42
gthiemongeI ran "id" and the result was root16:43
rm_workYeah so that’s valid, maybe we made a different mistake, or haproxy parses config before dropping root16:43
gthiemongethose haproxy config injections are fixed now, but we will try to improve the isolation of the haproxy process16:44
gthiemonge(i hope that will not involve stuff like selinux)16:45
rm_workI’m in the middle of deploying Octavia again finally 🥹 using OVN driver though not amphora16:45
gthiemongearghh :/16:45
rm_workWhat’s wrong with OVN, that’s the same noise johnsom made 😂16:46
gthiemongeno i'm joking16:47
rcruise-redhatOVN is great, I've no idea how it works though :)16:47
rcruise-redhatIts a bit of a mystery box16:48
rm_workOh we’re mid meeting, sorry didn’t mean to hijack, carry on 😅16:48
gthiemongelol16:49
gthiemongeany other topics for this meeting folks?16:49
rcruise-redhatNone from me16:49
gthiemongeack, then have a good one!16:50
gthiemongerm_work: johnsom: it was good to see you here!16:50
gthiemonge#endmeeting16:50
opendevmeetMeeting ended Wed Sep 23 16:50:26 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:50
opendevmeetMinutes:        https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.html16:50
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.txt16:50
opendevmeetLog:            https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.log.html16:50
raineszmo/16:50
viniciusrThank you guys! 16:50
rcruise-redhatThanks folks!16:51
rm_worko/17:09

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!