Thursday, 2018-03-22

eumel8good morning06:59
eumel8anyone there for i18n team meeting07:00
eumel8#startmeeting OpenStack I18n Meeting07:01
openstackMeeting started Thu Mar 22 07:01:02 2018 UTC and is due to finish in 60 minutes.  The chair is eumel8.
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.07:01
*** openstack changes topic to " (Meeting topic: OpenStack I18n Meeting)"07:01
openstackThe meeting name has been set to 'openstack_i18n_meeting'07:01
*** jungleboyj has joined #openstack-meeting07:27
eumel8btw: a nice comment from clarkb in
*** sparkycollier has joined #openstack-meeting07:27
*** jiaopengju has joined #openstack-meeting07:27
*** armax has joined #openstack-meeting07:27
eumel8we should keep that in mind to move logical things out in project repos07:27
*** edwarnicke_ has joined #openstack-meeting07:27
gibi#startmeeting nova14:00
openstackMeeting started Thu Mar 22 14:00:27 2018 UTC and is due to finish in 60 minutes.  The chair is gibi.
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
*** openstack changes topic to " (Meeting topic: nova)"14:00
openstackThe meeting name has been set to 'nova'14:00
gibihi! I will be your host today14:00
gibi#topic Release News14:01
*** openstack changes topic to "Release News (Meeting topic: nova)"14:01
gibi#link Rocky release schedule:
gibiApr 19: r-1 milestone, nova spec freeze14:01
gibiApr 27: spec review focus day14:02
mriedemmarch 27?14:02
gibimriedem: correct :)14:02
gibiMarch 27: spec review focus day14:03
*** anilvenkata has quit IRC14:03
* johnthetubaguy hides in the back of the room14:03
*** felipemonteiro_ has joined #openstack-meeting14:03
gibi#link os-vif 1.10.0 was released on 2018-03-21:
*** diman has joined #openstack-meeting14:04
gibianything else about the release?14:04
gibi#topic Bugs (stuck/critical)14:04
*** openstack changes topic to "Bugs (stuck/critical) (Meeting topic: nova)"14:04
gibi30 new untriaged bugs right now #link
*** annp_ has joined #openstack-meeting14:05
mriedemwent through a lot of garbage bugs yesterday14:05
gibithat was 47 on the agenda so thanks for the triaging14:06
gibiwe dont have critical bugs14:06
gibithere are 4 untriaged and untagged bug in our queue*&field.status%3Alist=NEW14:07
gibitagging helps to route bugs to experts for triage14:07
gibi#help tag untagged untriaged bugs with appropriate tags to categorize them14:07
*** felipemonteiro__ has quit IRC14:07
bauzasyeah I need to help :(14:08
*** yamamoto has joined #openstack-meeting14:08
*** diman has quit IRC14:08
gibiGate status14:08
gibi#link check queue gate status
gibiI don't see any major nova related failure in the list14:09
mriedemit seems to be oddly slow, but overall no known big failures14:09
gibithere was some hanging functional tests the other day14:09
gibiI don't know what was the cause14:09
johnthetubaguymeltdown fixes?14:10
mriedemi would be interested to know what % of nodes are not running openstack stuff now14:10
mriedemwith the new CI/CD zuulv3 split thingy with the foundatoin14:10
mriedembut that's another topic for another channel14:10
* johnthetubaguy nods14:10
dansmithdo we share a nodepool with other projects?14:10
gibi3rd party CI #link
*** links has quit IRC14:10
gibidansmith: I guess we run tests triggered from github14:11
dansmithI didn't think _our_ zuul did14:11
mriedemdon't know, probably a question for that thread in the ML14:11
dansmithwe'd see them in our status dashboard I would think14:12
* alex_xu_ waves late14:12
dansmithunless it's just nodepool that is shared14:12
dansmithanyway, sorry to derail14:12
bauzasI thought it was a separate nodepool14:12
gibigoing back to 3rd party CI14:12
gibiI don't kknow what I have to look for in
gibidoes the recent redness of IBM PowerKVM CI relevant?14:13
*** naichuans has joined #openstack-meeting14:13
mriedemwe can ask mmedvede later14:13
*** yamamoto has quit IRC14:13
*** hongbin has joined #openstack-meeting14:13
*** zhouyaguo has quit IRC14:13
gibianything else about bugs or CI ?14:14
gibi#topic Reminders14:14
*** openstack changes topic to "Reminders (Meeting topic: nova)"14:14
gibi#link Rocky Review Priorities
gibi#info Rocky spec review day: next week Tuesday March 27, let's focus a day on reviewing specs14:15
gibionce again ^^ :)14:15
*** kiennt26_ has joined #openstack-meeting14:15
*** dklyle has joined #openstack-meeting14:15
* stephenfin walks in late14:16
gibiRunaway proposal #link
*** browny_ has joined #openstack-meeting14:16
gibianything else for reminders?14:16
gibi#topic Stable branch status14:17
*** openstack changes topic to "Stable branch status (Meeting topic: nova)"14:17
gibi#link stable/queens:,n,z14:17
mriedemgonna do another queens release shortly14:17
mriedemonce a couple of other fixes land,14:18
mriedemwe had a revert that impacts hard reboots for libvirt that we need to get released14:18
mriedemsame for pike14:18
gibi#link stable/pike:,n,z14:18
gibithanks mat14:18
gibithanks mriedem14:18
gibi#link stable/ocata:,n,z14:18
gibianything else for stable branches?14:19
mriedemthe stable eol thing is likely getting approval tomorrow14:19
mriedemby the TC14:19
mmedvedemriedem: we have some problems in CI we are addressing, something internal14:19
gibimmedvede: thanks for the info14:20
mmedvedeturned off reporting14:20
* bauzas needs to leave early (as today is buggy for most people in my country)14:20
gibi#topic Subteam Highlights14:20
*** openstack changes topic to "Subteam Highlights (Meeting topic: nova)"14:20
gibiCells v2 (dansmith)14:20
dansmithno meeting this week14:20
*** browny_ has quit IRC14:21
gibiScheduler (edleafe)14:21
edleafeDiscussed whether mirroring Nova host aggregates to Placement was a proxy API, or whether it was a necessary duplication, due to them being used for different purposes. No clear consensus was reached.14:21
edleafeefried admitted to being a PITA14:21
edleafejaypipes expressed his opinion that we have already done enough in terms of extracting placement for Rocky, and to hold off on any further work. cdent disagreed, and will continue to push forward.14:21
edleafeWe agreed that we need to focus on the work for nesting providers in allocation_candidates.14:22
edleafecdent wondered if he is a bug.14:22
*** alexchad_ has quit IRC14:22
edleafeThat's it.14:22
gibiNotification (gibi)14:22
gibievery bp I tracked got discussion and most of them is approved14:22
gibilist and status is in #link Notification (gibi)14:22
gibiI mean #link
mriedembut some have been approved for awhile with no code yet right?14:23
gibimriedem: yes14:23
mriedemwhich is... :/14:23
gibimriedem: I share your pain14:23
*** yamamoto has joined #openstack-meeting14:24
gibiStuck Reviews14:24
gibi#topic Stuck Reviews14:24
*** openstack changes topic to "Stuck Reviews (Meeting topic: nova)"14:24
gibinothing on the agenda14:24
gibido we have something to bring up here?14:24
stephenfinI have one thing14:24
gibistephenfin: go ahead14:25
stephenfinsahid's patch on TX/RX queue sizes14:25
* bauzas leaves now14:25
* stephenfin get's link14:25
mriedemha as bauzas leaves14:25
*** rpioso|afk is now known as rpioso14:25
stephenfin*gets, even14:25
stephenfinAs discussed on the spec, we were pretty sure we were going with the global nova.conf option but there's been some disagreement on that14:26
johnthetubaguydoesn't this need guest support, I should re-read that thing14:26
stephenfinThe spec has been rewritten to use extra spec keys. I'm OK with that but want to make sure this is OK for everyone else14:26
*** browny_ has joined #openstack-meeting14:26
mriedemthe original patch from nic used extra specs right?14:27
dansmithjohnthetubaguy: it's virtio only14:27
stephenfinjohnthetubaguy: More hypervisor support than guest support, if I understand it correctly14:27
stephenfinmriedem: Correct14:27
gibimriedem, stephenfin: If it is OK to add yet another flavor extra_spec key that is libvirt specific then I'm OK with the rest14:27
mriedemthe point of the extra spec is it doesn't have to be libvirt-specific,14:27
johnthetubaguyI thought these things needed specific kernel versions in the guest for virtio to negociate, but I could be miss-remembering, its probably like 2.20 or something14:27
mriedembut a config option would be14:27
mriedemjohnthetubaguy: correct,14:27
mriedemit's super use case specific14:27
stephenfinand we (mostly I) pushed him away from that given previous opposition to yet more extra spec knobs14:27
dansmithbut a config option being libvirt-specific isn't a huge proble14:27
*** wanghao_ has joined #openstack-meeting14:28
*** wanghao has quit IRC14:28
stephenfinYeah, it's easy move it to another group if we need to14:28
*** yamamoto has quit IRC14:28
mriedema config option isn't a huge problem no14:28
stephenfinBut I feel bad about pushing him one way when he's now being dragged back, heh14:28
dansmithextra spec keys that are in libvirt-specific units (i.e. queues) is less palatable to me than a config option in conf.libvirt14:28
johnthetubaguywhy would you not want to set it, extra memory usage?14:28
mriedemis there no way that other virt drivers would never be able to do this same thing?14:29
johnthetubaguyxen has something quite similar brewing upstream14:29
dansmithif it's in extra_specs I would like it to be something like shares or percentage of the total, where the total (or max)  is configured by compute in conf or something like that14:29
stephenfinjohnthetubaguy: gibi raised that, yeah. Realistically though, this is going to be set everywhere and not touched again14:29
stephenfinUntil the hardware is upgraded to 40 or 100 Gig, anyway14:29
johnthetubaguyso if you want it everywhere, feels like it should be a config option?14:30
johnthetubaguyright, feels mostly a property of the host capabilities14:30
dansmithconfig option feels like the easy way to go here for now, IMHO14:30
stephenfinThat was my feeling, yes14:30
johnthetubaguy++ config option here, as much as the churn on the spec sucks14:30
mriedemi'm happy to bow out of the spec review if dansmith and johnthetubaguy want to take over14:30
stephenfinNo one has asked for this to be per guest, so the benefits of that feature are slight at best14:30
*** gman-tx has quit IRC14:31
gibiadding a config option now, and if the use case comes up to set it per VM then addign an extra spec later is doable14:31
stephenfinYeah, I'm also going to bow out14:31
dansmithmriedem: sure14:31
stephenfinOn account of the "go this way, no this way" thing14:31
dansmithstephenfin: wait, aren't you the one that asked for it to be extra_specs?14:31
dansmithstephenfin: no fair bowing out now :)14:31
*** alexchadin has joined #openstack-meeting14:31
mriedemi did14:31
stephenfinNope, that was mriedem14:31
mriedemi didn't realize this couldn't be used by other virt drivers14:31
dansmithokay, then all the more reason for stephenfin to stick around for his victory lap14:31
*** browny_ has quit IRC14:31
stephenfinsahid is going to be pi******ed :D14:32
dansmithanyway, johnthetubaguy you'll help review?14:32
mriedemall he has to do is revert to an older patchset14:32
stephenfinbut eh, good to get a move on this14:32
dansmithI'll comment that we had a big discussion14:32
gibiDo I sense properly that we have an agreement to use config option?14:32
johnthetubaguydansmith: yes14:32
dansmithhe hates me anyway :)14:32
*** wanghao_ has quit IRC14:32
* dansmith -> lightning rod14:32
stephenfingibi: +1 from me14:32
gibidansmith: thanks for taking the bad guy role :)14:33
gibilet's move on14:33
*** njohnston_ is now known as njohnston14:33
gibi#topic Open discussion14:33
*** openstack changes topic to "Open discussion (Meeting topic: nova)"14:33
* mriedem prepares for the deluge of powervm blueprints14:33
gibithere is a long list of specless bps on the agenda14:33
gibi(melwitt): seeking approval for specless blueprint for improving the xenapi image handler:
jianghuawIt’s to change a XenAPI config option to specify the image handler, so that xenapi can support non-FS based storage repositories (LVM, ISCSI).14:34
jianghuawWe also talked about it in PTG.14:34
mriedemit was discussed at the ptg14:34
mriedemsame thing as the libvirt imagebacked right14:34
*** amodi has quit IRC14:34
mriedemimage_type or whatever that option is14:34
jianghuawmriedem, yes. similarly.14:34
jianghuawbut not image type but the image handler.14:34
gibiany objection against approving it?14:35
*** nickthetait has joined #openstack-meeting14:35
gibithen it is approved14:36
* johnthetubaguy remembers something about me reviewing that14:36
gibi(melwitt): seeking approval for specless blueprint for removing execs of system commands:
dansmithno reason not to do this, IMHO14:37
mriedem"Also, it makes us look silly at social occasions."14:37
dansmithnow that we have privsep, it's possible, but wasn't before14:37
stephenfin+1 from me. I've been reviewing those already thinking it was just another one of mikal's daft topics :)14:37
mriedemi'm fine with it14:37
gibiSee we are in agreement, so It is approved14:37
gibi(melwitt): Based on replies to the spec review day ML thread:
gibiCan we have an informal vote on when people would like to start using runways? (Start immediately vs start after spec freeze, and let's go with the consensus)14:38
* gibi votes for starting after the spec freeze14:38
*** yamamoto has joined #openstack-meeting14:39
mriedemas someone that also reviews specs, i'm a big meh on this one14:39
johnthetubaguy+1 "Obviously this will be an experiment and we won't get14:39
johnthetubaguyit right the first time."14:39
dansmithnobody replied to me, which tells me I'm the only one (and efried)14:39
dansmithso we should just do it late I guess14:39
dansmithand we'll just approve a bunch of stuff that won't land, like usual :)14:39
johnthetubaguyhow about after the spec review day, we do everything else on a runway?14:40
mriedemanyone else going to speak up in this meeting?14:40
efriedCan anyone tell me why we shouldn't a) allow things like specs in runways, and b) start TODAY?14:40
mriedemspecs in runways is an idea i haven't had14:41
* stephenfin still has to read that email and will stay quiet for this bit14:41
cdentI pretty much agreed with dansmith, but have little enough of an opinion that I didn't bother to response on the email. I also agree with efried just said14:41
efriedstephenfin: That's the gist of it.  Let's start now.14:41
mriedemthe idea is to flush out the approved stuff14:41
gibimy reason to vote for after the spec freeze is the amount of time I need to spend on the bandwidth spec these days14:41
dansmithspecs in runways is a little hard because we'd need to have a way to say "okay, we're not going to do this this cycle, so we eject it from the runway without merging", IMHO14:41
dansmithwhich is a little awkward, but I guess we could14:41
efriedokay, but it's clear that not everybody will be able to focus all their time all the time.14:42
dansmithright, I don't really understand why we can't do specs in the background,14:42
efriedSo gibi is focusing on that spec right now, but joebob will be focusing on a feature after spec freeze etc.14:42
dansmithand I don't understand why we can't ramp up more spec review/approval when we're getting low on approved things to go in the queue14:42
dansmithefried: yeah agreed14:42
johnthetubaguydansmith: yeah, I think that is what I was wanting to see, at least eventually14:42
mriedemi think what i said on the etherpad and in dubling,14:42
mriedemwas if we're going to do both at the same time,14:43
mriedemis we should extend spec freeze to basically feature freeze14:43
mriedemor milestone 2, something like that14:43
dansmithyeah we'd kinda have to,14:43
*** yamamoto has quit IRC14:43
dansmithas we'd be approving things later to keep the pipeline full as necessary14:43
efriedI'm not opposed to that in principle, though I think that decision can be made later.14:43
mriedemso if we're cool with extending the spec freeze to at least milestone 2, i'm ok with doing runways now14:43
johnthetubaguywell, its like all specs need an exception, you get granted when there is a slot for you?14:43
dansmithso we'd be shooting for smaller things to be approved later14:43
johnthetubaguyso a bit I missed, is how were we going to track the runways?14:44
mriedemi'm also ok with doing runways now w/o extending the spec freeze, i should say, that's why i said 'meh'14:44
mriedemjohnthetubaguy: etherpad14:44
stephenfinthe only issue I have with extending the deadline is increased difficulty getting less obvious specs landed14:44
johnthetubaguymriedem: I was wondering if trello might work, but not sure if that excludes folks14:44
stephenfinwithout the pressure of said deadline14:45
*** iyamahat has joined #openstack-meeting14:45
dansmithjohnthetubaguy: it excludes people with a soul14:45
mriedemstephenfin: umm,14:45
jaypipesdansmith: shit, I'm out then.14:45
mriedemwell that's kind of the thing - you can have us all focus on runways and a few do spec reviews,14:45
mriedemor we extend the spec review deadline so there is time for both for the few that actually review specs14:46
johnthetubaguyOK, I missed its just a list of three, ignore me, etherpad is perfect14:46
dansmithcan we just have people reply with this stuff on that thread as the votes?14:46
stephenfinmriedem: Good point. I guess it'll just shuffle things around a bit14:46
johnthetubaguyI am tempted to say we just grant exceptions when needed14:46
*** yamamoto has joined #openstack-meeting14:46
*** yamamoto has quit IRC14:46
* johnthetubaguy goes to email thread14:47
gibidansmith: let's do that14:47
mriedemkind of sucks to have this discussion without the PTL here,14:47
mriedemso yeah ML it is14:47
dansmithmriedem: right that's my point14:47
johnthetubaguytimezones suck14:47
gibi#action vote on the ML14:47
gibimoving on14:47
gibi(esberglu): PowerVM specless blueprints14:47
gibiNetwork Hotplug:
edmondswwe originally had a spec for this, but mriedem and melwitt agreed yesterday these could be specless14:48
efriedPerfect example of how we can use runways for bp+feature as we go.14:48
edmondswthat one is already up and ready for review once the bp is approved14:48
edmondswthe impl I mean14:48
efriedQueue up the first couple.  Get 'em in a runway.  Get 'em approved.  Queue up the next couple.  Repeat until we run out of... runway.14:48
edmondswvscsi and snapshot are also essentially implemented... a little more subteam review needed14:49
gibiefried: do you mean not take the whole list of 6 bp now just the first 3?14:49
mriedemhow we handle priority for a runway slot is up for debate probably14:49
efriedgibi: I think queueing them up individually would be appropriate.14:49
mriedemi.e. i think the certs api stuff from john hopkins all trumps the powervm bp's14:49
edmondswI'd like to get at least the first 3 approved today, since they're implemented...14:50
efriedmriedem: One of the main purposes of runways was to allow focus on lower-priority work.  We already have high focus on high-priority work.14:50
mriedemthe certs api thing is low priority work,14:50
mriedemit's been so gd low priority,14:50
mriedemit's deferred since ocata14:50
dansmiththe priority thing is hard, and more important later in the cycle, which is one reason I want to start now14:50
efriedPoint was that, with some (but few) exceptions, the queue is FIFO14:50
mriedemso at this point, it's kind of high priority right?14:50
dansmithso things that are low priority but ready can go ahead and benefit14:50
efriedIf the cert thing is ready, queue it tf up and it'll bubble to the top in order.14:51
dansmithefried: it's already in the queue actually :)14:51
mriedemso i can approve right?14:51
gibiany objection?14:51
efried+1 from me :)14:51
*** browny_ has joined #openstack-meeting14:51
*** lhinds has joined #openstack-meeting14:51
gibiseems there is no objectsion so it is approved14:52
edmondswand vscsi and snapshot?14:52
gibivSCSI cinder volumes:
edmondswthis was actually ready to go in Queens but didn't get reviews14:52
* bauzas is silently (well, not really) back14:53
edmondswwe've made a few small improvements while we've been waiting14:53
*** felipemonteiro__ has joined #openstack-meeting14:53
gibiany objection?14:53
*** eeiden has joined #openstack-meeting14:53
gibiInstance Snapshot:
* gibi waiting for objectsion 14:54
edmondswimpl for this is up and tested. I think efried and I both had comments that were getting addressed and then we'd open it up for wider review14:54
edmondswprobably a few days14:54
mriedemyou guys are also enabling CI testing for all of these right?14:54
mriedemb/c tempest tests attach interface and snapshot14:54
esbergluNot vSCSI14:54
mriedemi will -1 the living hell out of these patches if i don't see it14:54
mriedemi know not that one14:54
esbergluSnapshot and attach yes14:55
mriedemok, fair warning14:55
gibido we want to go further down the list of powervm bps or it is enough for now and we will take the rest when this 3 are merged?14:55
gibi*these 314:55
mriedemi'll just hit the rest in the agenda14:55
mriedemafter the meeting14:55
*** VW has joined #openstack-meeting14:55
mriedemor melwitt can14:55
gibimriedem: does hit means approve?14:55
mriedemthese were all in a spec that was basically approved,14:56
mriedembut we didn't need a spec,14:56
gibimriedem: ohh I see14:56
mriedemso they were split out as feature parity blueprints14:56
gibithen I agree14:56
*** browny_ has quit IRC14:56
mriedembecause a spec with a laundry list is annoying14:56
gibiso the last item on the agenda14:56
gibi(jianghuaw): seeking approval for specless blueprint for "vGPU work in rocky":
jianghuawThis BP is for tracking the work in Rocky for the vGPU functions which have not been done in Queens.14:56
mriedemwe talked about this in dublin14:57
mriedemit's just closing gaps14:57
jianghuawcool mriedem:-)14:57
*** gagehugo has joined #openstack-meeting14:57
mriedemeveryone agree?14:57
*** felipemonteiro_ has quit IRC14:57
* gibi doesn't see any objections14:57
*** Swami has joined #openstack-meeting14:57
gibianything else to discuss in the next 2 minutes?14:57
*** bobh has quit IRC14:57
jianghuawThanks all:-)14:58
gibiOK. let's close this14:58
gibithanks for the meeting14:58
*** alexchadin has quit IRC14:58
*** openstack changes topic to "OpenStack Meetings ||"14:58
openstackMeeting ended Thu Mar 22 14:58:58 2018 UTC.  Information about MeetBot at . (v 0.1.4)14:59
openstackMinutes (text):
*** dustins_ is now known as dustins14:59
lhindsping gagehugo15:00
lhinds#startmeeting security15:00
openstackMeeting started Thu Mar 22 15:00:38 2018 UTC and is due to finish in 60 minutes.  The chair is lhinds.
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
*** openstack changes topic to " (Meeting topic: security)"15:00
*** cdent has left #openstack-meeting15:00
openstackThe meeting name has been set to 'security'15:00
lhindsanyone else around (security folks?)15:00
lhindscool! we have some life.15:01
fungii am here though also have tc office hour starting now15:01
*** hoangcx_ has quit IRC15:01
lhindsack fungi15:01
fungiping me if you need me and i'll catch up15:01
*** erlon has quit IRC15:01
*** cloudrancher has quit IRC15:02
*** cloudrancher has joined #openstack-meeting15:02
lhindsnickthetait: just approved your membership15:02
lhinds#topic agenda15:02
*** openstack changes topic to "agenda (Meeting topic: security)"15:02
*** tpsilva has joined #openstack-meeting15:03
lhindsanything interesting last week gagehugo we need to continue on?15:03
*** gman-tx has joined #openstack-meeting15:03
gagehugolhinds not really, ttx followed up on some of the spectre/meltdown15:03
lhindsok cool15:04
lhindshow about the LCOO, do they have plans to seed some stuff in the SIG?15:04
*** jessegler has joined #openstack-meeting15:04
gagehugoeeiden o/15:04
nickthetaitthanks lhinds15:05
gagehugolhinds decided to wait until this week to discuss LCOO15:06
gagehugolast week was pretty light15:06
lhindsgagehugo: ack, eeiden will ping you when the topic is on15:06
lhinds#topic Docs15:06
*** openstack changes topic to "Docs (Meeting topic: security)"15:06
lhindsnothing new here, just a patch to remove `os`, I don't think we need that for spinx / tox stuff, but will double check15:07
lhinds#topic Keystone Threat Analysis15:08
*** openstack changes topic to "Keystone Threat Analysis (Meeting topic: security)"15:08
gagehugoprobably something that used to be used in there and leftover15:08
gagehugore: import os15:08
lhindsgagehugo: I think so too.15:08
gagehugoI added the pycrypto findings into the KSM vmt doc15:08
lhindsthanks gagehugo15:09
gagehugolhinds was there anything else that you think should be added to the review findings?15:09
lhinds#action look into new central store for TA15:09
lhindsgagehugo: nope, that should be it now..15:09
lhindsI just need to look at the above and find a better more easily searched home for them.15:10
*** annp_ has quit IRC15:10
*** erlon has joined #openstack-meeting15:10
*** sidx64 has quit IRC15:10
lhindsand fungi we need to look at bringing the above into VMT's loving care15:10
fungicool. next step i suppose is for the keystone team to propose the addition of the vulnerability:managed tag to that deliverable in the governance repo's reference/projects.yaml file?15:11
fungiand make sure to refer to any threat analysis artifacts in the commit message15:12
lhindsgagehugo: I guess you would be a good candidate for the above.15:12
gagehugolbragstad ^15:12
lhindsI don't mean to keep piling actions onto you bud, but being a keystone core that would work15:12
lhindshey lbragstad15:12
gagehugoyeah that's fine :)15:12
lhindsgreat, so nice to have that one in the bag15:12
fungiyeah, it's just best when tag additions like that come from the team responsible for the project in question (and get acknowledged by the ptl for it)15:13
fungiraises fewer questions at the tc level15:13
gagehugofungi sounds good15:13
nickthetaitWhat does tc stand for?15:13
fungitechnical committee15:13
lhindslbragstad: gagehugo there are some other keystone siblings that were going to be proposed for TA iirc?15:14
fungi#link OpenStack Technical Committee15:14
gagehugolhinds yes15:14
gagehugopycadf, keystoneauth, oslo.policy15:15
lhindsgreat, I addded those to the pad, so we can look at kicking those off perhaps next meeting or two.15:16
lhinds#topic Spectre/Meltdown mitigation15:16
*** openstack changes topic to "Spectre/Meltdown mitigation (Meeting topic: security)"15:16
lhindsanything else here, ttx ?15:16
lhindsI guess he might be busy in the other meeting.15:16
*** sidx64 has joined #openstack-meeting15:16
*** sidx64 has quit IRC15:17
fungiyeah, tc office hours15:17
ttxDon't have much to add to what I said on the topic last week :)15:18
lhindsno worries..I think we can skip POlicy Roadmap too, I need to contact some patrole folks and find out where we are15:18
lhinds#topic LCOO15:18
*** openstack changes topic to "LCOO (Meeting topic: security)"15:18
lhindseeiden, floor is yours :)15:19
*** spilla has joined #openstack-meeting15:19
*** Leo_m has joined #openstack-meeting15:19
eeidenThanks lhinds!15:19
*** sidx64 has joined #openstack-meeting15:20
eeidenI'm the current chair for LCOO [stands for Large Contributing OpenStack Operators -- essentially a group of larger companies working to promote and address operator-specific concerns within the community]15:20
*** amodi has joined #openstack-meeting15:20
nickthetaitwhich company do you work for eeiden ?15:21
*** felipemonteiro__ has quit IRC15:21
eeidenNo solid plans from my end at the moment, but was hoping to sync up on priorities so that we can learn about/promote important security initiatives as a working group15:21
*** sidx64 has quit IRC15:21
*** felipemonteiro__ has joined #openstack-meeting15:21
lhindseeiden: sounds good. so we moved to a sig in the hope of getting more users involved, so this fits us well.15:22
lhindshave you found any topics have come up around sec yet, and what the 'in demand' features are for ops?15:23
lhindsthings that are making it a challenge to go to production for example (compliance maybe)?15:23
gagehugoI know policy is a big one15:24
eeidenI'm relatively new to the group, so haven't heard much from others. We'll be having a meeting shortly to discuss current priorities, so that's something I'll queue up for discussion.15:25
eeidenBut ghugo -- definitely policy15:25
lhindsplease do eeiden , I am happy to join...could you email the sig mailing list and with a date / agenda when set?15:26
lhindsothers will likely jump on to then15:26
eeidenwould love to have you guys there15:26
lhindswe will keep LCOO as an agenda item (ongoing), even if nothing new, its a touchstone15:26
*** kiennt26_ has quit IRC15:27
lhindsok. lets skip thorugh the other items, as close to the 30 min mark15:27
lhindsdoes not look like ebrown is here, regaring bandit migration to python QA tools15:28
*** bobh has joined #openstack-meeting15:28
lhindsI also don't think Mr Tatu is here.15:28
nickthetaitis bandit being abandoned?15:28
lhindsnickthetait: no, far from it.15:28
lhindsnickthetait: its going to move to being part of the main python test tools15:29
nickthetaitoh neat :)15:29
lhindsso will live alongside tools like pep8 lint etc.15:29
*** Swami has quit IRC15:29
fungiso relocating it's perceived association out of openstack and into the python testing community15:29
fungier, its15:29
*** bobh has quit IRC15:30
*** bobh has joined #openstack-meeting15:30
lhindsgagehugo: just noticed some new patches from ebrown, we could review those15:30
gagehugolhinds one is pretty simple, the other looks like still wip15:30
lhindsoh sorry, you already have :)15:30
lhindsthat yaml typo is on its way in.15:31
lhindsso last but not least.15:31
lhinds#topic OSSN and OSSA15:31
*** openstack changes topic to "OSSN and OSSA (Meeting topic: security)"15:31
lhindsraises guilty hand, I need to work on clearing the OSSN back log15:31
lhindsin the mean time if anyone is interested in writing some security notes, I will support you lots on your first one.15:32
lhindsyou and your company get a credit in the note.15:32
lhindsbest to read this if you're interested <goes to get link>...15:32
lhindscheck it out nickthetait / eeiden see if its something you would like to get involved in.15:33
lhindsfungi: anything big in OSSA that's public and needs some more eyes / views?15:33
eeidenoh awesome, will do15:33
nickthetaitsounds like a good fit for me right now. invovles research and documentation right lhinds?15:34
lhindsnickthetait: yes, very much. its a very good intro to working in openstack sec.15:34
lhindsits how I started out15:34
lhindshave a read, and you can email me or ping in irc15:35
lhindsthe current list is:15:35
lhindsok, we are over time.15:35
lhindsthanks all15:35
lhindsnice to see some new names, you're very welcome here, please do come back again :)15:35
*** openstack changes topic to "OpenStack Meetings ||"15:36
openstackMeeting ended Thu Mar 22 15:36:01 2018 UTC.  Information about MeetBot at . (v 0.1.4)15:36
openstackMinutes (text):
mlavalle#startmeeting neutron_drivers22:00
openstackMeeting started Thu Mar 22 22:00:05 2018 UTC and is due to finish in 60 minutes.  The chair is mlavalle.
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.22:00
*** openstack changes topic to " (Meeting topic: neutron_drivers)"22:00
openstackThe meeting name has been set to 'neutron_drivers'22:00
mlavallehaleyb: you joining today?22:01
haleybmlavalle: yes, with beer in hand22:01
mlavallewelcome haleyb22:02
mlavalleand welcome hongbin22:02
mlavalleWe have quorum22:02
mlavalle#topic Brian Haley new member of the Drivers team22:03
*** openstack changes topic to "Brian Haley new member of the Drivers team (Meeting topic: neutron_drivers)"22:03
mlavalleFirst of all I want to welcome Brian to the drivers team22:03
mlavalleI think you will make great contributions to this team22:03
*** amodi has quit IRC22:03
haleybgood to officially be here now that i have some time to help out22:04
*** awaugama has quit IRC22:04
mlavalleI want also to mention that ihrachys will be transitioning out of this team and Neutron in general over the next few weeks22:05
mlavalleHe has set hig sights and goals in another project out of the OpenStack community22:05
mlavalleWe thanks him for his many contributions to Neutron and wish him luck in his next challenge22:06
*** archit has joined #openstack-meeting22:06
* mlavalle know that he doesn't need any luck.... he is great regardless22:06
mlavalleThat is relevant from the point of view of the logistics of this meeting22:07
mlavalleyamamoto: what is better for you? this time slot or Friday morning?22:07
mlavallewell, night for you22:08
yamamotoeither fine for me22:08
mlavalleand you haleyb?22:08
mlavalleRemember, it has to be sustainable during standard time22:09
haleybmlavalle: friday is better for me, this isn't terrible, i just sometimes have conflicts22:09
mlavalleso I will check with amotoki. If he is ok with it. we can move the meeting to Friday morning in the US / Friday night Japan22:10
mlavallethat way we are happier22:10
haleybmy kids thank you mlavalle :)22:11
mlavallewith that, these are the RFEs we have to discuss today:22:12
*** archit has quit IRC22:12
mlavalleI am going to skip the first two, since I don't think we have much to discuss around those two today22:12
mlavalleSo first one for today is
openstackLaunchpad bug 1723026 in neutron "[RFE]Support get device_ids from floatingips" [Wishlist,Confirmed] - Assigned to Hongbin Lu (
mlavallewhich is associated to
openstackLaunchpad bug 1754123 in neutron "[RFE] Support filter with floating IP address substring" [Wishlist,New] - Assigned to Hongbin Lu (
hongbini think those two bugs can be separated if it helps the discussion22:14
hongbinfor the first one, the requirement is to retrieve the uuid of the nova instance , with the floating ip address given22:15
hongbinthis is in the critical call path, so we want to do it in a single api call / db transation22:15
hongbinone option is to add the device_id to the floating ip address resource, perhaps other alternatives can solve the problem as well22:17
hongbinthat is all from me as a brief introduction22:18
mlavalleIt seems a reasonable request for me22:19
mlavalleI must say, though, that it comes from my employer22:19
haleybi just don't understand the mapping between the device_id and the nova uuid, but assume if i looked at the code it would all make sense22:19
mlavalleit's like in the case of a port22:20
*** Leo_m has quit IRC22:20
hongbinbasically, the device_id can be set as the device_id of the associated port22:21
*** Leo_m has joined #openstack-meeting22:21
haleybnext time i stack i will have to look (and go ah-ha)22:21
*** Leo_m has quit IRC22:22
mlavallefor your viewing pleasure22:24
mlavallejust created that VM for you22:24
haleybmlavalle: thanks, now it all makes sense :)22:24
hongbinit worths to mentioned that amotoki left a comment in the bug report (comment #18) as a suggested amendment of the proposal22:24
openstackLaunchpad bug 1723026 in neutron "[RFE]Support get device_ids from floatingips" [Wishlist,Confirmed] - Assigned to Hongbin Lu (
mlavallethat makes sene22:26
*** diman has joined #openstack-meeting22:27
mlavalleso amotoki seems to be on-board with this requirement22:27
yamamotofor you it's often known that the ip in question is a floating ip?22:29
*** pchavva has quit IRC22:29
hongbinperhaps no, but a floatingip list call will figure it out22:30
yamamotoso if there's "what's this ip" api, it's more convenient for you?22:31
hongbinmaybe, depending on how this api looks like22:32
*** diman has quit IRC22:32
*** rcernin has joined #openstack-meeting22:34
mlavallethat's an interesting idea yamamoto.... so that "what is this ip" api could answer whether the IP is fixed or floaing and provide additional the relevant information, depending of the case, including the device_id?22:34
mlavalleand for floating ips include the port information as proposed by amotoki22:36
yamamotoyea.  it might be a router (or something snat'ed behind it) as well.22:37
*** hongbin_ has joined #openstack-meeting22:37
mlavallewould that work, hongbin?22:37
yamamotoi thought the motivation of the snat logging proposal was something similar. don't your use case need the history?22:38
hongbinmlavalle: i am still trying to understand the advice22:39
hongbinsuppose a new api is proposed, what is the list of attributes ?22:39
* hongbin am not familiar with the snat logging22:40
mlavallewhat I understood  is we could have a new resource /ip-address/{ip-address}22:41
mlavallewhen you do a GET against it, it will determine whether it {ip-address} is fixed and floating and then respond with the relevant data22:41
mlavalleincluding, for floating ips, the port data that amotoki proposed22:42
mlavalleis that your idea yamamoto?22:42
hongbin_the key is what kind of data returned by the /ip-address endpoint22:42
mlavallein principle, for floating ips, the same you currently when you do GET /floting_ips + amotoki's proposal22:43
mlavalleand for fixed IPs, ports data22:44
mlavallebut this way, when you see "suspicious" activity in an ip address, you don't have to determine first whether it if floating or fixed22:44
mlavalleright yamamoto?22:44
hongbin_sounds good to me, i can communicate this with my team to get further feedback22:45
yamamotosnat logging is this one
openstackLaunchpad bug 1752290 in neutron "[RFE] (Operator-only) Add support 'snat' for loggable resource type" [Wishlist,Confirmed]22:45
mlavallein other words, it is a way to address the requirement that we have already in the RFE but with yamamoto's proposal, giving it a more general solution22:46
*** fnaval has quit IRC22:46
*** edmondsw has joined #openstack-meeting22:46
*** andreas_s has joined #openstack-meeting22:47
mlavalledoes it make sense?22:47
mlavallewhat do you think haleyb?22:47
yamamotobasically they want to know which vm was using the given ip at the given time in the past. as we can re-associate floating ips, i was wondering you might need similar historical data for your purpose.22:48
mlavallethat's also true22:48
haleybsorry, did not read this rfe, but do know from experience that operators want to know the timeframe an IP was being used22:49
mlavallethat can be a second step in the implementation of this new api22:49
mlavallehaleyb: that's a good point. that is why I say the historical data could be a second step22:49
haleybmlavalle: topic is still all about me btw22:50
openstackRemoving item from minutes: #link
mlavalle#topic RFEs22:50
*** openstack changes topic to "RFEs (Meeting topic: neutron_drivers)"22:50
haleybit doesn't matter at this point i guess22:51
mlavalleanyway, I think we (the Huawei guys) can ask our public cloud bretheren if the logging data is soemthing they would appreciate22:51
*** andreas_s has quit IRC22:52
mlavalledoes that make sense?22:52
mlavallewhat do you think haleyb?22:53
mlavalleNext one is
openstackLaunchpad bug 1738738 in neutron "[Neutron][Firewall] Extend FWaaS to provide DSCP filtering" [Wishlist,Confirmed] - Assigned to Reedip (reedip-banerjee)22:54
mlavalleSridark responded to our question from one of the previous meetings22:55
mlavalleThe FWaaS team feels that the API is ready for this functionality22:55
mlavalleso I am for approving this RFE22:55
*** masber has joined #openstack-meeting22:56
mlavallehow about you haleyb?22:59
mlavalleok, cool23:00
mlavalletime's up23:00
*** openstack changes topic to "OpenStack Meetings ||"23:00
openstackMeeting ended Thu Mar 22 23:00:28 2018 UTC.  Information about MeetBot at . (v 0.1.4)23:00
openstackMinutes (text):
mlavallethaks for attending23:00
*** hongbin has quit IRC23:01
mlavalleexpect a patch proposing the move of all the meetings to the Friday time slot23:01
mlavalleyamamoto, haleyb ^^^^23:01
*** hongbin_ has quit IRC23:01
mlavalleand haleyb, everything is about you anyway, don't you know it?23:01
haleybriiight :)23:02
*** felipemonteiro has quit IRC23:03
*** mlavalle has quit IRC23:03
