| johnsom | Haven’t seen the ticket, but we were very careful about this. Security keys are delivered via config drive and no other way. All command and control actions are via two-way TLS authentication with each amp having it’s own certs. Plus, tenant key info is push only from the controllers, so I don’t see how one amp could access another amp’ key content. | 05:03 |
|---|---|---|
| johnsom | As for root, pretty sure gunicorn is configured to drop from root to another account on startup. | 05:15 |
| gthiemonge | johnsom: it's an injection in the haproxy config file, the master runs as root | 09:04 |
| gthiemonge | johnsom: right, the amphora should not have access to other tenant/amp's content | 09:05 |
| opendevreview | Austin Russell proposed openstack/octavia-tempest-plugin master: Add test for LB/amphora failover when vip-subnet is full https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/1005728 | 14:45 |
| johnsom | Haproxy does not run as root, it runs under the haproxy account | 15:57 |
| gthiemonge | johnsom: I'll double check after the meeting but only the workers run as haproxy | 16:00 |
| gthiemonge | #startmeeting Octavia | 16:01 |
| opendevmeet | Meeting started Wed Sep 23 16:01:00 2026 UTC and is due to finish in 60 minutes. The chair is gthiemonge. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:01 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:01 |
| opendevmeet | The meeting name has been set to 'octavia' | 16:01 |
| gthiemonge | o/ | 16:01 |
| rcruise-redhat | o/ | 16:01 |
| raineszm | o/ | 16:01 |
| viniciusr | o/ | 16:01 |
| gthiemonge | #topic Announcements | 16:04 |
| gthiemonge | * 2026.2 Hibiscus Release Schedule: R-1 | 16:04 |
| gthiemonge | we're in the Final RCs week | 16:04 |
| gthiemonge | Next week is the GA | 16:04 |
| gthiemonge | afaik we're good for Octavia, RC1 will be our GA | 16:05 |
| gthiemonge | * Octavia CVEs | 16:05 |
| gthiemonge | 2 CVEs were requested for 2 issues reported last month (already fixed on master and maintained stable branches) | 16:05 |
| gthiemonge | https://www.cve.org/CVERecord?id=CVE-2026-94571 | 16:05 |
| gthiemonge | https://www.cve.org/CVERecord?id=CVE-2026-94572 | 16:05 |
| gthiemonge | IMHO the score (CRITICAL 9.4) is higher than expected | 16:06 |
| gthiemonge | FYI at Red Hat, these CVEs are classified as IMPORTANT 7.4 | 16:06 |
| gthiemonge | 17.0.1 (flamingo) and 18.0.1 (gazpacho) were released yesterday with the bugfixes | 16:07 |
| gthiemonge | * Octavia PTG | 16:07 |
| gthiemonge | time flies... PTG is really close: October 12-16, 2026 | 16:08 |
| gthiemonge | I haven't reserved a room yet, I'll do it soon | 16:08 |
| gthiemonge | I will also prepare the PTG etherpad so you can add your topics there | 16:08 |
| gthiemonge | I'll keep you updated | 16:09 |
| gthiemonge | any additional announcements? or questions? | 16:09 |
| gthiemonge | ok | 16:11 |
| gthiemonge | #topic Brief progress reports / bugs needing review | 16:11 |
| gthiemonge | well I was on PTO last week, my activity was really limited | 16:11 |
| gthiemonge | I plan to prepare the PTG and review patches of features that we didn't merge in H | 16:11 |
| rcruise-redhat | I had some downstream stuff to work on so I haven't had time to look at upstream much. I'm hoping to test out this change soon https://review.opendev.org/c/openstack/octavia/+/864308 | 16:12 |
| rcruise-redhat | Other than that, I've a lot of reviews to catch up with | 16:13 |
| gthiemonge | ack | 16:15 |
| gthiemonge | #topic Open Discussion | 16:18 |
| viniciusr | can I go? | 16:18 |
| gthiemonge | johnsom: I'll check if we can improve the security on this side, the haproxy service is started as root, because it needs to jump into the ns, then it also needs root to listen on privileged ports, but they are probably more conveniant ways to do it | 16:19 |
| gthiemonge | viniciusr: sure | 16:19 |
| viniciusr | I've been reorganizing the patches for active active load balancing using bgp, reducing the total number of patches and putting it in a better shape | 16:20 |
| gthiemonge | cool | 16:22 |
| viniciusr | How should I proceed on gerrit? the bgp-exp topic has many many patches, but I'm afraid of replacing everything and loosing comments after the squash | 16:22 |
| gthiemonge | I would say that it's almost safe to squash patches that are in the same component (like patches for amphora-agent, patches for the flows), or if one patch of the chain fixes an issue introduced in the chain, it doesn't make sense to have 2 patches | 16:24 |
| gthiemonge | if we lose comments.. I mean it's better to have clearly defined patches for specific areas, than to review code that will be modified in another patch | 16:25 |
| johnsom | gthiemonge It does start as root (for ports, and FDs, etc.) but drops privilege to the haproxy account. | 16:26 |
| gthiemonge | johnsom: we have https://github.com/openstack/octavia/blob/master/octavia/common/jinja/haproxy/combined_listeners/templates/base.j2#L19 | 16:27 |
| gthiemonge | but it looks like it only impacts the workers | 16:27 |
| viniciusr | but after squashing (for example two commits into one) the old patches will not disappear from the whole topic (bgp-exp), right? | 16:29 |
| gthiemonge | root 1063 0.0 1.1 93860 11732 ? Ss 09:10 0:00 /usr/sbin/haproxy -Ws -f /var/lib/octavia/dfe2be40-ee | 16:30 |
| gthiemonge | nobody 1356 0.0 1.8 106572 18492 ? S 09:10 0:01 /usr/sbin/haproxy -sf 1265 -x sockpair@5 -Ws -f /var/ | 16:30 |
| gthiemonge | viniciusr: we'll have to abandon them | 16:30 |
| viniciusr | hmm ok | 16:31 |
| viniciusr | thanks! | 16:32 |
| raineszm | Quick Question on my end: So I had a request to allow increasing the header size for the amphora provider, basically corresponding to exposing the tune.bufsize haproxy option in the config. I'm curious if y'all think that is a useful configuration knob to expose, and whether it would be backportable. | 16:32 |
| rcruise-redhat | Well if someone is looking for it, then it's probably worth adding as something that can be configured. As to whether it can be backported, I'm not sure | 16:34 |
| raineszm | Currently it's doable by wholesale replacing the haproxy template, but that seems really painful for just changing the one option | 16:35 |
| rcruise-redhat | Yeah that seems like a messy solution, a config option would be a lot neater | 16:36 |
| rcruise-redhat | I'm not sure if a change to the provider can be backported though | 16:36 |
| gthiemonge | we usually don't backport changes that introduce new settings, however if the default value of the setting doesn't change the behavior of octavia, I think it's possible | 16:36 |
| gthiemonge | need to check in the project guide | 16:37 |
| raineszm | The ask in this case is because their workloads need to receive headers above 16Kb, so things are broken right now. | 16:37 |
| gthiemonge | interesting | 16:37 |
| raineszm | As to what they fill 20 some odd Kb of headers with, I don't know | 16:37 |
| raineszm | But apparently it happens | 16:37 |
| gthiemonge | lol | 16:38 |
| gthiemonge | open a launchpad that explains the problem (the bug), it will be backportable.. don't open a launchpad that requests a new feature for bufsize, that would be not backportable | 16:39 |
| * raineszm nods | 16:39 | |
| gthiemonge | IMHO it's a bug | 16:39 |
| rcruise-redhat | This is how you work the system :) | 16:39 |
| raineszm | Cool. I'll file an LP bug and look at writing a patch | 16:39 |
| gthiemonge | great, thanks! | 16:40 |
| rm_work | Oh gross that whole structure still exists with combined listeners vs not lol, I still feel icky about that | 16:40 |
| rm_work | That was supposed to be like… for backwards compat briefly for migration, people weren’t supposed to use both indefinitely lol | 16:40 |
| gthiemonge | rm_work: the split listeners dir was removed :D | 16:40 |
| rm_work | lol ok good so it’s just cruft in the path | 16:41 |
| rm_work | johnsom: well I guess they reproduced? So idk 🤷♂️ | 16:41 |
| rm_work | I just accepted their claim on the root thing since their repro apparently worked | 16:42 |
| rm_work | Just what they got out of it mattered way less than the claim | 16:42 |
| gthiemonge | rm_work: so I reproduced the exploit | 16:42 |
| gthiemonge | I ran "id" and the result was root | 16:43 |
| rm_work | Yeah so that’s valid, maybe we made a different mistake, or haproxy parses config before dropping root | 16:43 |
| gthiemonge | those haproxy config injections are fixed now, but we will try to improve the isolation of the haproxy process | 16:44 |
| gthiemonge | (i hope that will not involve stuff like selinux) | 16:45 |
| rm_work | I’m in the middle of deploying Octavia again finally 🥹 using OVN driver though not amphora | 16:45 |
| gthiemonge | arghh :/ | 16:45 |
| rm_work | What’s wrong with OVN, that’s the same noise johnsom made 😂 | 16:46 |
| gthiemonge | no i'm joking | 16:47 |
| rcruise-redhat | OVN is great, I've no idea how it works though :) | 16:47 |
| rcruise-redhat | Its a bit of a mystery box | 16:48 |
| rm_work | Oh we’re mid meeting, sorry didn’t mean to hijack, carry on 😅 | 16:48 |
| gthiemonge | lol | 16:49 |
| gthiemonge | any other topics for this meeting folks? | 16:49 |
| rcruise-redhat | None from me | 16:49 |
| gthiemonge | ack, then have a good one! | 16:50 |
| gthiemonge | rm_work: johnsom: it was good to see you here! | 16:50 |
| gthiemonge | #endmeeting | 16:50 |
| opendevmeet | Meeting ended Wed Sep 23 16:50:26 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:50 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.html | 16:50 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.txt | 16:50 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/octavia/2026/octavia.2026-09-23-16.01.log.html | 16:50 |
| raineszm | o/ | 16:50 |
| viniciusr | Thank you guys! | 16:50 |
| rcruise-redhat | Thanks folks! | 16:51 |
| rm_work | o/ | 17:09 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!