*** mattw4 has joined #openstack-neutron | 00:01 | |
*** slaweq has joined #openstack-neutron | 00:11 | |
*** slaweq has quit IRC | 00:15 | |
*** mattw4 has quit IRC | 00:17 | |
*** armax has joined #openstack-neutron | 00:20 | |
*** betherly has joined #openstack-neutron | 00:26 | |
*** betherly has quit IRC | 00:31 | |
*** ivve has quit IRC | 00:32 | |
*** whoami-rajat has quit IRC | 00:34 | |
*** markvoelker has joined #openstack-neutron | 00:39 | |
*** tbachman has joined #openstack-neutron | 00:50 | |
*** mriedem has quit IRC | 00:52 | |
openstackgerrit | ZhouHeng proposed openstack/neutron master: fix update neutron resource with incorrect body key server return 500 https://review.opendev.org/674153 | 00:56 |
---|---|---|
*** spsurya has joined #openstack-neutron | 01:05 | |
*** betherly has joined #openstack-neutron | 01:09 | |
*** yamamoto has joined #openstack-neutron | 01:12 | |
*** betherly has quit IRC | 01:14 | |
*** baojg has joined #openstack-neutron | 01:23 | |
*** igordc has quit IRC | 01:25 | |
*** betherly has joined #openstack-neutron | 01:30 | |
*** whoami-rajat has joined #openstack-neutron | 01:32 | |
*** betherly has quit IRC | 01:35 | |
*** kevinz has joined #openstack-neutron | 02:10 | |
*** slaweq has joined #openstack-neutron | 02:11 | |
*** slaweq has quit IRC | 02:15 | |
*** betherly has joined #openstack-neutron | 02:34 | |
*** yamamoto has quit IRC | 02:36 | |
*** yamamoto has joined #openstack-neutron | 02:37 | |
*** betherly has quit IRC | 02:39 | |
*** altlogbot_1 has quit IRC | 02:44 | |
*** altlogbot_0 has joined #openstack-neutron | 02:45 | |
*** betherly has joined #openstack-neutron | 02:55 | |
*** betherly has quit IRC | 03:00 | |
*** dsneddon has quit IRC | 03:03 | |
*** dsneddon has joined #openstack-neutron | 03:11 | |
*** ramishra has joined #openstack-neutron | 03:14 | |
*** dsneddon has quit IRC | 03:16 | |
*** markvoelker has quit IRC | 03:18 | |
*** betherly has joined #openstack-neutron | 03:28 | |
*** betherly has quit IRC | 03:32 | |
*** dsneddon has joined #openstack-neutron | 03:57 | |
*** baojg has quit IRC | 04:03 | |
*** dsneddon has quit IRC | 04:05 | |
*** slaweq has joined #openstack-neutron | 04:11 | |
*** slaweq has quit IRC | 04:16 | |
*** betherly has joined #openstack-neutron | 04:21 | |
*** dave-mccowan has quit IRC | 04:25 | |
*** betherly has quit IRC | 04:26 | |
*** dsneddon has joined #openstack-neutron | 04:34 | |
*** betherly has joined #openstack-neutron | 04:43 | |
*** baojg has joined #openstack-neutron | 04:44 | |
*** betherly has quit IRC | 04:47 | |
*** markvoelker has joined #openstack-neutron | 04:48 | |
*** markvoelker has quit IRC | 04:52 | |
*** ratailor has joined #openstack-neutron | 04:56 | |
*** slaweq has joined #openstack-neutron | 05:11 | |
*** yamamoto has quit IRC | 05:13 | |
*** yamamoto has joined #openstack-neutron | 05:14 | |
*** yamamoto has quit IRC | 05:14 | |
*** betherly has joined #openstack-neutron | 05:15 | |
*** slaweq has quit IRC | 05:15 | |
*** yamamoto has joined #openstack-neutron | 05:18 | |
*** yamamoto has quit IRC | 05:18 | |
*** betherly has quit IRC | 05:19 | |
*** dave-mccowan has joined #openstack-neutron | 05:33 | |
openstackgerrit | Merged openstack/networking-midonet master: Disable ubuntu integration jobs https://review.opendev.org/674404 | 05:38 |
*** yamamoto has joined #openstack-neutron | 05:45 | |
*** yamamoto has quit IRC | 05:45 | |
*** yamamoto has joined #openstack-neutron | 05:45 | |
*** panda has quit IRC | 05:47 | |
*** panda has joined #openstack-neutron | 05:48 | |
*** yamamoto has quit IRC | 05:54 | |
*** dsneddon has quit IRC | 05:54 | |
*** betherly has joined #openstack-neutron | 06:08 | |
*** slaweq has joined #openstack-neutron | 06:11 | |
*** betherly has quit IRC | 06:13 | |
*** slaweq has quit IRC | 06:15 | |
*** yamamoto has joined #openstack-neutron | 06:20 | |
*** dsneddon has joined #openstack-neutron | 06:21 | |
*** ramishra has quit IRC | 06:23 | |
*** betherly has joined #openstack-neutron | 06:29 | |
*** betherly has quit IRC | 06:35 | |
*** kevinz has quit IRC | 06:36 | |
*** dsneddon has quit IRC | 06:42 | |
*** slaweq has joined #openstack-neutron | 06:42 | |
*** ramishra has joined #openstack-neutron | 06:48 | |
*** betherly has joined #openstack-neutron | 06:51 | |
*** rpittau|afk is now known as rpittau | 06:52 | |
*** frankwang has joined #openstack-neutron | 06:56 | |
*** betherly has quit IRC | 06:56 | |
*** dsneddon has joined #openstack-neutron | 07:00 | |
*** tesseract has joined #openstack-neutron | 07:04 | |
*** yamamoto has quit IRC | 07:10 | |
*** betherly has joined #openstack-neutron | 07:12 | |
*** betherly has quit IRC | 07:17 | |
*** tssurya has joined #openstack-neutron | 07:18 | |
*** yamamoto has joined #openstack-neutron | 07:22 | |
*** mjozefcz has joined #openstack-neutron | 07:23 | |
*** yamamoto has quit IRC | 07:30 | |
*** yamamoto has joined #openstack-neutron | 07:31 | |
*** betherly has joined #openstack-neutron | 07:34 | |
*** takamatsu has joined #openstack-neutron | 07:35 | |
*** betherly has quit IRC | 07:38 | |
*** rcernin has quit IRC | 07:46 | |
*** ratailor has quit IRC | 07:49 | |
*** bobmel has joined #openstack-neutron | 08:00 | |
*** yamamoto_ has joined #openstack-neutron | 08:00 | |
*** yamamoto has quit IRC | 08:02 | |
*** betherly has joined #openstack-neutron | 08:05 | |
*** ralonsoh has joined #openstack-neutron | 08:06 | |
*** betherly has quit IRC | 08:10 | |
*** yamamoto has joined #openstack-neutron | 08:12 | |
*** yamamoto_ has quit IRC | 08:13 | |
*** ivve has joined #openstack-neutron | 08:15 | |
*** lucasagomes has joined #openstack-neutron | 08:16 | |
*** ociuhandu has joined #openstack-neutron | 08:18 | |
*** betherly has joined #openstack-neutron | 08:22 | |
*** ratailor has joined #openstack-neutron | 08:22 | |
*** david-lyle has joined #openstack-neutron | 08:24 | |
*** dklyle has quit IRC | 08:24 | |
*** jistr is now known as jistr|afk | 08:24 | |
*** kevko has joined #openstack-neutron | 08:27 | |
*** ramishra_ has joined #openstack-neutron | 08:27 | |
kevko | hi, anybody here ? i want to little bit discuss https://review.opendev.org/#/c/612617/ | 08:28 |
*** ramishra has quit IRC | 08:29 | |
openstackgerrit | Bernard Cafarelli proposed openstack/neutron master: Sort network_ids in test_dhcp_agent_scheduler.test_filter_bindings https://review.opendev.org/675556 | 08:30 |
bcafarel | ralonsoh: slaweq: ^ this is for https://bugs.launchpad.net/neutron/+bug/1839595 I just filled, if you could take a look and confirm I am not going crazy | 08:31 |
openstack | Launchpad bug 1839595 in neutron "neutron.tests.unit.scheduler.test_dhcp_agent_scheduler.TestNetworksFailover.test_filter_bindings test can fail depending on generated UUIDs" [Undecided,In progress] - Assigned to Bernard Cafarelli (bcafarel) | 08:31 |
bcafarel | I am not sure why the test always works in gates but mostly fails for me, but I hope I described the issue correctly | 08:32 |
*** dsneddon has quit IRC | 08:37 | |
ralonsoh | bcafarel, I'll need to check this manually, but do you think the problem is in the net_id order? | 08:39 |
ralonsoh | bcafarel, if you don't order the net_id, where is the test failing? | 08:39 |
bcafarel | ralonsoh: I think so, also I left the test running overnight with a sorted list and not a single failure | 08:40 |
bcafarel | it's failing the assert in https://github.com/openstack/neutron/blob/master/neutron/tests/unit/scheduler/test_dhcp_agent_scheduler.py#L522 (I gave an example in the LP) | 08:41 |
slaweq | bcafarel: looking now | 08:41 |
*** kevinz has joined #openstack-neutron | 08:48 | |
slaweq | bcafarel: I didn't run tests but it makes sense for me what You are saying | 08:48 |
slaweq | bcafarel: but isn't problem caused by L514 (network_obj.NetworkDhcpAgentBinding.get_objects(self.ctx)) which IMO not guarantee order of returned objects | 08:49 |
slaweq | ? | 08:49 |
ralonsoh | slaweq, exactly | 08:52 |
ralonsoh | slaweq, the problem is there. The order of the dhcpagents must be the same as the order of construction. | 08:53 |
slaweq | ralonsoh: yes, I agree | 08:53 |
ralonsoh | bcafarel, you should order the NetworkDhcpAgentBinding objects depending on the network_id | 08:54 |
slaweq | that is at least my understanding of the issue | 08:54 |
ralonsoh | must be the same as the order of the network list | 08:54 |
bcafarel | oh I was looking at https://github.com/openstack/neutron/blob/master/neutron/objects/network.py#L172 but that's not the correct get_objects indeed | 08:54 |
bcafarel | ralonsoh: slaweq: thanks it makes more sense now :) | 08:55 |
*** frankwang has quit IRC | 09:05 | |
*** frankwang has joined #openstack-neutron | 09:05 | |
*** dsneddon has joined #openstack-neutron | 09:10 | |
*** markvoelker has joined #openstack-neutron | 09:18 | |
*** markvoelker has quit IRC | 09:23 | |
*** tesseract has quit IRC | 09:28 | |
*** tesseract has joined #openstack-neutron | 09:28 | |
*** tesseract has quit IRC | 09:29 | |
*** tesseract has joined #openstack-neutron | 09:29 | |
*** frankwang has quit IRC | 09:41 | |
bcafarel | that also explains why changing sqlite version impacted that test | 09:42 |
openstackgerrit | Merged openstack/neutron stable/stein: Check for agent restarted after checking for DVR port https://review.opendev.org/671964 | 09:44 |
openstackgerrit | Michal Arbet proposed openstack/neutron-fwaas master: Default firewall group rules from configuration file https://review.opendev.org/612617 | 09:44 |
openstackgerrit | Bernard Cafarelli proposed openstack/neutron master: Fix sort issue in test_dhcp_agent_scheduler.test_filter_bindings https://review.opendev.org/675556 | 09:46 |
openstackgerrit | Bernard Cafarelli proposed openstack/neutron stable/ocata: fix update port bug https://review.opendev.org/674971 | 09:54 |
tbarron | gregwork: tidwellr: so iiuc on a shared provider network one doesn't have the anti-arp attack stuff based on ebtables that's on by default on other neutron networks? | 09:57 |
*** hoonetorg has quit IRC | 09:57 | |
tbarron | gregwork: tidwellr: I'd been thinking that ebtables in concert with neutron security rules to disallow ingress would yield reasonable isolation between the nfs clients | 09:58 |
*** davidsha has joined #openstack-neutron | 10:05 | |
*** aedc has quit IRC | 10:06 | |
*** aedc has joined #openstack-neutron | 10:06 | |
*** gcheresh has joined #openstack-neutron | 10:08 | |
*** yamamoto has quit IRC | 10:17 | |
*** jistr|afk is now known as jistr | 10:18 | |
*** hoonetorg has joined #openstack-neutron | 10:20 | |
*** yamamoto has joined #openstack-neutron | 10:34 | |
*** tbachman has quit IRC | 10:38 | |
*** betherly has quit IRC | 10:38 | |
*** gcheresh has quit IRC | 10:40 | |
*** dsneddon has quit IRC | 10:40 | |
*** yamamoto has quit IRC | 10:49 | |
*** tbachman has joined #openstack-neutron | 10:57 | |
*** yamamoto has joined #openstack-neutron | 10:59 | |
*** dsneddon has joined #openstack-neutron | 11:15 | |
*** gcheresh has joined #openstack-neutron | 11:17 | |
*** keesm has joined #openstack-neutron | 11:24 | |
*** cheng1 has quit IRC | 11:26 | |
*** cheng1 has joined #openstack-neutron | 11:27 | |
*** yamamoto has quit IRC | 11:28 | |
*** yamamoto has joined #openstack-neutron | 11:29 | |
*** yamamoto has quit IRC | 11:29 | |
*** kevinz has quit IRC | 11:32 | |
*** kevinz has joined #openstack-neutron | 11:32 | |
*** yamamoto has joined #openstack-neutron | 11:36 | |
*** ramishra_ has quit IRC | 11:38 | |
*** gcheresh has quit IRC | 11:40 | |
openstackgerrit | Merged openstack/networking-ovn master: Fix gateway blockers https://review.opendev.org/674574 | 11:47 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Update port_status to ACTIVE during live-migration https://review.opendev.org/673803 | 11:51 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Enable live-migration tempest test for OVN https://review.opendev.org/673884 | 11:52 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Update OVN LB Algorithm to SOURCE_IP_PORT https://review.opendev.org/660369 | 11:54 |
keesm | hi there, is there anyone out there familiar with the "Could not load networking_l2gw.services.l2gateway.service_drivers.rpc_l2gw.L2gwRpcDriver" error in regard to networking-l2gw? | 11:59 |
*** markvoelker has joined #openstack-neutron | 11:59 | |
*** kevinz has quit IRC | 12:01 | |
keesm | markvoelker: are you familiar with networking-l2gw, by any chance? | 12:01 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/stein: Do not modify passed by reference variables in mechanism_driver https://review.opendev.org/675602 | 12:08 |
*** yamamoto has quit IRC | 12:10 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/rocky: Do not modify passed by reference variables in mechanism_driver https://review.opendev.org/675603 | 12:11 |
*** cheng1 has quit IRC | 12:15 | |
*** jamesdenton has quit IRC | 12:17 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/queens: Do not modify passed by reference variables in mechanism_driver https://review.opendev.org/675607 | 12:17 |
*** cheng1 has joined #openstack-neutron | 12:18 | |
*** dsneddon has quit IRC | 12:18 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Handle events in separate IDL https://review.opendev.org/673269 | 12:22 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Don't allow mixing IPv4/IPv6 configuration https://review.opendev.org/674255 | 12:22 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: WIP Add missing unittests to OVN provider driver https://review.opendev.org/674261 | 12:22 |
openstackgerrit | Bence Romsics proposed openstack/neutron-lib master: New api-def: extraroute-atomic https://review.opendev.org/670849 | 12:25 |
openstackgerrit | Lucas Alvares Gomes proposed openstack/networking-ovn master: Add fragmentation support https://review.opendev.org/671766 | 12:26 |
*** ramishra has joined #openstack-neutron | 12:32 | |
*** kevinz has joined #openstack-neutron | 12:34 | |
*** keesm has quit IRC | 12:34 | |
*** dsneddon has joined #openstack-neutron | 12:41 | |
*** dsneddon has quit IRC | 12:45 | |
openstackgerrit | Bence Romsics proposed openstack/neutron master: New extension: extraroute-atomic https://review.opendev.org/670850 | 12:46 |
openstackgerrit | Bence Romsics proposed openstack/neutron master: Implement extension: extraroute-atomic https://review.opendev.org/670851 | 12:47 |
*** yamamoto has joined #openstack-neutron | 12:49 | |
*** kevinz has quit IRC | 12:55 | |
*** yamamoto has quit IRC | 12:57 | |
*** kevinz has joined #openstack-neutron | 12:57 | |
*** henriqueof has joined #openstack-neutron | 12:58 | |
*** nweinber has joined #openstack-neutron | 12:59 | |
*** nweinber has quit IRC | 13:02 | |
*** nweinber has joined #openstack-neutron | 13:02 | |
*** ociuhandu has quit IRC | 13:03 | |
*** ociuhandu has joined #openstack-neutron | 13:03 | |
AJaeger | networking-odl team, we moved api-ref documents, could you update one link, please? here's a trival patch https://review.opendev.org/673599 | 13:05 |
*** ociuhandu has quit IRC | 13:07 | |
*** tbachman has quit IRC | 13:09 | |
*** mriedem has joined #openstack-neutron | 13:10 | |
*** ramishra has quit IRC | 13:10 | |
*** panda has quit IRC | 13:14 | |
*** panda has joined #openstack-neutron | 13:15 | |
*** yamamoto has joined #openstack-neutron | 13:17 | |
*** jamesdenton has joined #openstack-neutron | 13:21 | |
*** jamesdenton has quit IRC | 13:22 | |
tidwellr | tbarron: you get anti-spoofing, the discussion was about taking that a step farther | 13:23 |
*** kevinz has quit IRC | 13:23 | |
*** Conqueror has quit IRC | 13:24 | |
*** kevinz has joined #openstack-neutron | 13:24 | |
tbarron | tidwellr: thanks, just wanted to make sure. I guess I'm trying to get a sense of how vulnerable nfs-clients belonging to difft tenants would be to one another | 13:24 |
tbarron | tidwellr: if they have the ebtables protection and appropriate neutron security policy disallowing ingress connections | 13:25 |
tidwellr | tbarron: yeah, that's all there | 13:25 |
tbarron | tidwellr: not against "another level" with pvlan at all, just educating myself | 13:25 |
*** kevinz has quit IRC | 13:25 | |
tidwellr | tbarron: when dealing with auditors and compliance, sometimes that's not isolated enough | 13:26 |
tbarron | tidwellr: cool. pvlan would provide protection even if the nfs clients didn't use appropriate security policies. | 13:26 |
tbarron | tidwellr: ack w.r.t. auditors | 13:27 |
*** ociuhandu has joined #openstack-neutron | 13:27 | |
*** BjoernT has joined #openstack-neutron | 13:28 | |
tidwellr | tbarron: on the flip side of that coin, if the concern is there don't expose a shared network to untrusted tenants | 13:28 |
*** jistr is now known as jistr|call | 13:29 | |
tbarron | tidwellr: eventually we want separate ganesha servers for each tenant, in which case we can attach them directly to tenant owned nets but | 13:30 |
tbarron | tidwellr: today there is only one ganesha server, with one NFS interface | 13:30 |
tidwellr | and the only way to expose it is through a provider network? | 13:30 |
tidwellr | you'll have to forgive my ignorance around manila and ganesha | 13:31 |
tbarron | tidwellr: well in our downstream implementation it's on its own data centre vlan | 13:31 |
tbarron | tidwellr: could be flat, it's own isolated network | 13:31 |
tbarron | its | 13:32 |
tidwellr | can tenants access it from behind a router, from their own network which is isolated by the overlay? | 13:32 |
tbarron | tidwellr: we could have an unshared provider net and route it | 13:32 |
*** Conqueror has joined #openstack-neutron | 13:33 | |
*** ivve has quit IRC | 13:33 | |
tbarron | tidwellr: then if we have one shared overlay network we have the same kind of issue there | 13:33 |
tbarron | tidwellr: if we have one overlay network per tenatn | 13:33 |
tbarron | tenant | 13:33 |
tbarron | tidwellr: then I don't know how that can be a tenant-self-provisioned network and | 13:34 |
tbarron | tidwellr: get the return routes to the tenant network set up automatically | 13:34 |
tidwellr | BGP | 13:34 |
tidwellr | neutron-dynamic-routing | 13:34 |
tidwellr | or floating IP's | 13:34 |
tbarron | tidwellr: i've thought of floating IPs but want to avoid that | 13:35 |
tbarron | tidwellr: would rather not NAT this and would rather have a solution that works the same way for IPv4 and IPv6 | 13:35 |
tidwellr | neutron-dynamic-routing gets the job done, no NAT involved | 13:36 |
tidwellr | but it's not for everyone | 13:36 |
tbarron | tidwellr: with BGP can I have a tenant-owned overlay network and tenant-owned router that attaches to the common provider net and | 13:36 |
*** jamesdenton has joined #openstack-neutron | 13:36 | |
tidwellr | is ganesha being stood up on a neutron-managed network? | 13:37 |
tbarron | the tenant-owned router would announce the return routes without having similar trust issues? | 13:37 |
tbarron | ganesha is being stood up on a controller node with a pacemaker-corosync managed VIP for NFS service | 13:38 |
*** jistr|call is now known as jistr | 13:38 | |
tbarron | on a data centre network (typically a vlan) | 13:39 |
tbarron | and we set up a neutron provider network mapped to that data centre network | 13:39 |
tbarron | tidwellr: today it is shared so tenant vms can attach to it directly | 13:40 |
tbarron | tidwellr: ganesha is just a daemon running on a controller node, not a process running in a VM or somehting like that | 13:42 |
*** ociuhandu has quit IRC | 13:43 | |
tidwellr | if you present it on something other than a neutron-managed network, it could actually be cleaner in the case where a tenant directly routes their floating IP's | 13:43 |
*** ociuhandu has joined #openstack-neutron | 13:44 | |
tidwellr | traffic just goes out the external network, and at that point you just need to route it (which you're likely already doing) | 13:44 |
*** lbragstad has joined #openstack-neutron | 13:45 | |
*** bnemec is now known as beekneemech | 13:45 | |
tidwellr | tbarron: the tenant can choose to use floating IP's for connectivity as well. Embedding the NFS endpoint on a provider network seems unnecessary, running it elsewhere allows you to put more controls in place without involving neutron | 13:46 |
*** zufar has joined #openstack-neutron | 13:47 | |
zufar | Hi all, happy friday | 13:47 |
zufar | anyone here know article or videos explain in deep and detail about networking neutron in OVN? | 13:47 |
*** david-lyle is now known as dklyle | 13:48 | |
zufar | something like this, https://www.youtube.com/watch?v=uKgMp5c6R-4 but this video using ovs as backend. | 13:48 |
*** ociuhandu has quit IRC | 13:49 | |
tbarron | tidwellr: ack, I need to review why we had a hard requirement to use a separate isolated network and keep the traffic from traversing the external network | 13:50 |
*** tbachman has joined #openstack-neutron | 13:53 | |
*** spsurya has quit IRC | 13:54 | |
*** mlavalle has joined #openstack-neutron | 13:55 | |
*** ociuhandu has joined #openstack-neutron | 13:55 | |
*** lbragstad has quit IRC | 13:58 | |
*** gcheresh has joined #openstack-neutron | 14:03 | |
*** lbragstad has joined #openstack-neutron | 14:04 | |
*** lbragstad has quit IRC | 14:14 | |
openstackgerrit | Merged openstack/neutron master: Clear skb mark on encapsulating packets https://review.opendev.org/675054 | 14:15 |
*** liuyulong has joined #openstack-neutron | 14:28 | |
*** ociuhandu has quit IRC | 14:34 | |
*** ociuhandu has joined #openstack-neutron | 14:35 | |
*** gcheresh has quit IRC | 14:36 | |
*** ivve has joined #openstack-neutron | 14:39 | |
*** ociuhandu has quit IRC | 14:40 | |
*** ociuhandu has joined #openstack-neutron | 14:41 | |
*** dsneddon has joined #openstack-neutron | 14:42 | |
*** ociuhandu has quit IRC | 14:42 | |
*** ramishra has joined #openstack-neutron | 14:44 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn master: Update OVN LB Algorithm to SOURCE_IP_PORT https://review.opendev.org/660369 | 14:46 |
*** yamamoto has quit IRC | 14:46 | |
*** dsneddon has quit IRC | 14:46 | |
*** ratailor has quit IRC | 14:47 | |
*** yamamoto has joined #openstack-neutron | 14:48 | |
*** yamamoto has quit IRC | 14:48 | |
*** yamamoto has joined #openstack-neutron | 14:49 | |
*** liuyulong_ has joined #openstack-neutron | 14:50 | |
liuyulong_ | mlavalle, slaweq: https://review.opendev.org/#/c/658511/5/specs/train/l3-ips-metering.rst@66 I tested the TC filter without polices, it will NOT have statistic data. | 14:51 |
liuyulong_ | So we need a default rate/burst value for the TC filter when L3 agent fip_qos and gateway_ip_qos are not enabled. What do you think? | 14:51 |
*** yamamoto has quit IRC | 14:52 | |
*** yamamoto has joined #openstack-neutron | 14:52 | |
*** Conqueror has left #openstack-neutron | 14:55 | |
slaweq | liuyulong_: IMO, if it is needed, we may make it maybe discoverable by checking banwidth of all physical NICs in the node and set as this default limit highest value of them | 14:57 |
slaweq | liuyulong_: what do You think about this? | 14:57 |
*** dklyle has quit IRC | 14:58 | |
*** david-lyle has joined #openstack-neutron | 14:58 | |
*** liuyulong has quit IRC | 14:59 | |
mlavalle | slaweq: ++ | 14:59 |
liuyulong_ | slaweq: network nodes may be various. But it is achievable. So each node may have different bandwidth. | 15:01 |
slaweq | liuyulong_: but that will only make that each router's port will have limit set as max as possible physical limit on the node where it is | 15:04 |
slaweq | so in fact there will be no limit and You will have Your counters, right? | 15:04 |
liuyulong_ | Correct | 15:04 |
*** ramishra has quit IRC | 15:06 | |
liuyulong_ | slaweq, mlavalle: I will upload the POC today. | 15:08 |
mlavalle | liuyulong_: thanks! | 15:09 |
*** tbachman has quit IRC | 15:15 | |
slaweq | liuyulong_: thx | 15:15 |
*** david-lyle is now known as dklyle | 15:16 | |
*** panda has quit IRC | 15:19 | |
*** panda has joined #openstack-neutron | 15:20 | |
*** yamamoto has quit IRC | 15:31 | |
*** yamamoto has joined #openstack-neutron | 15:32 | |
*** mjozefcz has quit IRC | 15:34 | |
*** yamamoto has quit IRC | 15:37 | |
henriqueof | Can someone helps with a question I have? | 15:39 |
henriqueof | I created a gateway port on the router that never switches to the active state, but if I create a router with another provider network gateway ip it does. | 15:40 |
henriqueof | The network that does not work is the same that my controller public IP is located, so there is a vlan tagged interface on the controller addressed to that IP. | 15:40 |
henriqueof | Can this be the reason? | 15:41 |
*** tbachman has joined #openstack-neutron | 15:49 | |
henriqueof | My l3 agent logs show: RouterNotCompatibleWithAgent: Router 'fddaa8c6-9483-4f8e-890f-bc9b6526c591' is not compatible with this agent. | 15:51 |
*** ccamposr has quit IRC | 15:53 | |
*** ccamposr has joined #openstack-neutron | 15:54 | |
*** ash2307 has joined #openstack-neutron | 15:55 | |
*** ash2307 has left #openstack-neutron | 15:57 | |
*** tssurya has quit IRC | 16:03 | |
openstackgerrit | LIU Yulong proposed openstack/neutron master: L3 agent metering extension https://review.opendev.org/675654 | 16:04 |
*** dklyle has quit IRC | 16:06 | |
*** atmark has quit IRC | 16:08 | |
*** guimaluf has quit IRC | 16:09 | |
AJaeger | mlavalle, slaweq, we moved api-ref documents, could you review updating one link, please? here's a trival patch https://review.opendev.org/673599 | 16:11 |
*** lucasagomes has quit IRC | 16:12 | |
mlavalle | AJaeger: done. Thanks! | 16:14 |
*** henriqueof has quit IRC | 16:14 | |
slaweq | AJaeger: sorry, mlavalle was faster :) | 16:15 |
mlavalle | LOL | 16:15 |
mlavalle | you can pile in if you want | 16:15 |
slaweq | mlavalle: no, it's fine :) | 16:16 |
* mlavalle thinks the correct expression is "pile on" | 16:17 | |
*** ash2307 has joined #openstack-neutron | 16:18 | |
*** aedc has quit IRC | 16:20 | |
*** davidsha has quit IRC | 16:26 | |
*** dklyle has joined #openstack-neutron | 16:26 | |
AJaeger | thanks! | 16:27 |
*** mattw4 has joined #openstack-neutron | 16:28 | |
openstackgerrit | Merged openstack/networking-odl master: Update api-ref location https://review.opendev.org/673599 | 16:34 |
*** rpittau is now known as rpittau|afk | 16:35 | |
AJaeger | yeah! | 16:36 |
*** AJaeger has left #openstack-neutron | 16:36 | |
*** dklyle has quit IRC | 16:37 | |
*** tidwellr has quit IRC | 16:37 | |
*** dklyle has joined #openstack-neutron | 16:37 | |
*** markvoelker has quit IRC | 16:41 | |
*** dsneddon has joined #openstack-neutron | 16:42 | |
*** markvoelker has joined #openstack-neutron | 16:44 | |
*** ccamposr__ has joined #openstack-neutron | 16:46 | |
*** irclogbot_3 has quit IRC | 16:47 | |
*** dsneddon has quit IRC | 16:47 | |
*** irclogbot_3 has joined #openstack-neutron | 16:48 | |
*** irclogbot_3 has quit IRC | 16:49 | |
*** ccamposr has quit IRC | 16:50 | |
*** irclogbot_3 has joined #openstack-neutron | 16:50 | |
*** tesseract has quit IRC | 17:00 | |
*** dklyle has quit IRC | 17:07 | |
*** jcosmao has left #openstack-neutron | 17:07 | |
*** david-lyle has joined #openstack-neutron | 17:07 | |
*** david-lyle has quit IRC | 17:10 | |
*** david-lyle has joined #openstack-neutron | 17:10 | |
*** dsneddon has joined #openstack-neutron | 17:13 | |
*** igordc has joined #openstack-neutron | 17:17 | |
*** betherly has joined #openstack-neutron | 17:22 | |
*** ash2307 has left #openstack-neutron | 17:24 | |
*** zufar has quit IRC | 17:27 | |
*** betherly has quit IRC | 17:39 | |
*** betherly has joined #openstack-neutron | 17:50 | |
openstackgerrit | Merged openstack/networking-ovn master: Update port_status to ACTIVE during live-migration https://review.opendev.org/673803 | 17:51 |
gregwork | tbarron: hey tom | 17:56 |
gregwork | just reading up (greg from symcor) | 17:57 |
gregwork | so i think the issue here is we dont want to assume the tenants/clients are doing the right thing from a security pov | 17:57 |
gregwork | pvlan set by the cloud admin on the storage nfs network makes this pretty secure and layer 2 | 17:57 |
gregwork | pvlan in general would make doing l2 shared services pretty nice | 17:59 |
*** betherly has quit IRC | 18:03 | |
*** betherly has joined #openstack-neutron | 18:15 | |
*** betherly has quit IRC | 18:23 | |
gregwork | cisco has a really nice overview of the utility of pvlan: https://www.cisco.com/c/dam/en/us/td/i/100001-200000/180001-190000/182001-183000/182773.eps/_jcr_content/renditions/182773.jpg | 18:26 |
gregwork | so the ganesha port would be in promisc mode | 18:26 |
gregwork | all client ports would be in isolated mode | 18:26 |
gregwork | there are a lot of interesting applications for this capability in neutron i think | 18:27 |
*** yamamoto has joined #openstack-neutron | 18:29 | |
*** yamamoto has quit IRC | 18:34 | |
tbarron | gregwork:hi greg was afk but am now reading your cisco pvlan link | 18:36 |
gregwork | https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/6-x/layer2/configuration/guide/b_Cisco_Nexus_9000_Series_NX-OS_Layer_2_Switching_Configuration_Guide/b_Cisco_Nexus_9000_Series_NX-OS_Layer_2_Switching_Configuration_Guide_chapter_0101.html#con_1344155 | 18:37 |
tbarron | gregwork: looking at, rather :) | 18:37 |
gregwork | i mean thats the actual writeup | 18:37 |
gregwork | they have a blurb on how it works but that picture is a thousand words | 18:37 |
tbarron | gregwork: yup, i like it | 18:37 |
gregwork | i feel that a significant amount of network complexity for segmentation could be reduced by neutron adding pvlan capability | 18:38 |
gregwork | seems like a big enough deal to almost deserve its own spot as a subset of security groups | 18:38 |
gregwork | only for layer 2 | 18:38 |
gregwork | aka | 18:41 |
gregwork | http://www.reactiongifs.com/r/mgc.gif | 18:41 |
tbarron | gregwork: and until you get this magic you'd need clients to attach to regular overlay networks that are routed to the StorageNFS network? | 18:43 |
gregwork | well so the way we built our cloud we used the rh doc method we piloted with you a year ago, so storageNFS is a dc vlan | 18:44 |
gregwork | maybe it should be something else today, but regardless of that | 18:45 |
gregwork | given two tenants, both have to plug in a dedicated nic on that vlan to access ganesha | 18:45 |
*** brault has joined #openstack-neutron | 18:45 | |
gregwork | non existant or badly configured security groups on those instance tenants == exposure | 18:45 |
gregwork | cant trust tenants to do the right thing | 18:45 |
tbarron | gregwork: ack | 18:45 |
gregwork | pvlan lets me deploy ganesha and the clients are isolated from each other | 18:47 |
gregwork | they can only see their destination | 18:47 |
tbarron | gregwork: we document what they should do here but I take the point anyways: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/13/html/storage_guide/ch-shares | 18:47 |
tbarron | gregwork: got it, but I've been thinking about routed solutions as well since we need those for spine-leaf topologies | 18:48 |
tbarron | gregwork: there we can't extend the vlan (even pvlan) to all leaves | 18:49 |
*** brault has quit IRC | 18:49 | |
gregwork | thats definitely another use case, but the folks that want to offer fast layer 2 securely is a good one | 18:50 |
tbarron | gregwork: yeah, I'm not arguing against neutron supporting pvlan if that can happen :) | 18:50 |
openstackgerrit | Ryan Tidwell proposed openstack/neutron-tempest-plugin master: Move neutron-dynamic-routing BGP tests from stadium https://review.opendev.org/652099 | 19:00 |
*** betherly has joined #openstack-neutron | 19:25 | |
*** betherly has quit IRC | 19:34 | |
*** BjoernT has quit IRC | 19:44 | |
*** ralonsoh has quit IRC | 19:57 | |
openstackgerrit | Ryan Tidwell proposed openstack/neutron-tempest-plugin master: Move neutron-dynamic-routing BGP tests from stadium https://review.opendev.org/652099 | 20:09 |
*** whoami-rajat has quit IRC | 20:12 | |
*** betherly has joined #openstack-neutron | 20:17 | |
*** betherly has quit IRC | 20:27 | |
*** betherly has joined #openstack-neutron | 20:36 | |
*** nweinber has quit IRC | 20:37 | |
*** dsneddon has quit IRC | 20:42 | |
*** ccamposr__ has quit IRC | 20:43 | |
*** ccamposr__ has joined #openstack-neutron | 20:43 | |
*** ccamposr__ has quit IRC | 20:46 | |
*** ccamposr__ has joined #openstack-neutron | 20:46 | |
*** ijw has joined #openstack-neutron | 20:48 | |
*** mjozefcz has joined #openstack-neutron | 20:52 | |
*** betherly has quit IRC | 20:53 | |
openstackgerrit | Brian Haley proposed openstack/neutron-specs master: [WIP] Toward Convergence of ML2+OVS+DVR and OVN https://review.opendev.org/658414 | 20:55 |
TheJulia | Greetings Neutron folks, We're seeing a weird falure with networking-baremetal that may seem to trace back to neturon/tests/base.py. https://logs.opendev.org/98/673598/1/check/openstack-tox-py27/9d72845/testr_results.html.gz which makes me think that the ml2 mech interface has changed subtly. Is anyone aware of any sort of change? | 20:57 |
*** mjozefcz has quit IRC | 20:57 | |
TheJulia | looks like its a recent change... in the behavior | 21:00 |
*** igordc has quit IRC | 21:01 | |
*** markvoelker has quit IRC | 21:01 | |
*** armax has quit IRC | 21:01 | |
*** shachar has quit IRC | 21:01 | |
*** shachar has joined #openstack-neutron | 21:01 | |
*** armax has joined #openstack-neutron | 21:01 | |
TheJulia | and without a release... we can't run unit tests downstream, and ugh | 21:03 |
gregwork | tbarron: is there a proper way to request features like pvlan? should we just go bug redhat or is there a more vendor agnostic way | 21:03 |
gregwork | TheJulia: hello :) | 21:04 |
tbarron | gregwork: when I was a customer I always did a earth-land-sea attack :) | 21:04 |
tbarron | gregwork: that is, I'd propose the idea upstream, perhaps on neutron meeting agenda -- others in this channel can advise better | 21:05 |
tbarron | gregwork: and then there's the matter of getting resources aligned to work on YourCoolIdea | 21:06 |
gregwork | where is the place to make such an upstream proposal ? | 21:06 |
tbarron | gregwork: so working the account people etc. whom you pay money to always helps | 21:06 |
tbarron | gregwork: i can answer for manila but not for neutron | 21:07 |
gregwork | or is this raiding the neutron PTG meeting at summit and providing beer | 21:07 |
gregwork | :P | 21:07 |
TheJulia | beer ++ | 21:07 |
tbarron | gregwork: if you do that pls invite me | 21:07 |
gregwork | haha | 21:07 |
TheJulia | gregwork: you may have just committed to something.... | 21:07 |
TheJulia | ;) | 21:07 |
tbarron | gregwork: but yes, if you are coming to Shanghai go to neutron forums and PTG | 21:07 |
tbarron | gregwork: and I will join you even w/o beer | 21:08 |
gregwork | i wish i could get the shanghai trip approved :/ | 21:08 |
gregwork | ive already done my openstack summit trip this year at denver | 21:08 |
gregwork | are they keeping the name open infra | 21:09 |
gregwork | or going back to openstack | 21:09 |
tbarron | gregwork: open infra | 21:09 |
* tbarron is talking a lot in this channel and he's not really a neutron guy, color me apologetic but brash | 21:10 | |
*** slaweq has quit IRC | 21:10 | |
TheJulia | the flight to PVG was surprisingly inexpensive.... | 21:10 |
*** markvoelker has joined #openstack-neutron | 21:11 | |
tbarron | TheJulia: yeah, it's a good deal but a bit knee-cramped | 21:11 |
tbarron | TheJulia: reportedly even hotels are reasonable | 21:11 |
TheJulia | As long as I can get to the restroom I'll be happy | 21:13 |
*** dsneddon has joined #openstack-neutron | 21:13 | |
haleyb | TheJulia: https://review.opendev.org/#/c/645645/ is most likely the culprit - there are now default vif details | 21:13 |
TheJulia | haleyb: thanks, I just found that about a minute ago and shipped a patch into networking-baremetal to rip the validation of it out since we don't use it and it seems senseless to not just let that pass-through | 21:14 |
haleyb | TheJulia: you might want to add Rodolfo (ralansoh) so he knows he broke something, although he's on pto... | 21:15 |
TheJulia | haleyb: thanks! | 21:16 |
openstackgerrit | Brian Haley proposed openstack/networking-ovn master: Start enforcing E125 flake8 directive https://review.opendev.org/675702 | 21:20 |
*** markvoelker has quit IRC | 21:21 | |
*** slaweq has joined #openstack-neutron | 21:26 | |
*** betherly has joined #openstack-neutron | 21:31 | |
*** slaweq has quit IRC | 21:32 | |
*** dsneddon has quit IRC | 21:47 | |
*** betherly has quit IRC | 21:48 | |
*** dsneddon has joined #openstack-neutron | 21:50 | |
*** slaweq has joined #openstack-neutron | 21:51 | |
*** slaweq has quit IRC | 21:56 | |
*** dsneddon has quit IRC | 22:10 | |
*** betherly has joined #openstack-neutron | 22:11 | |
*** betherly has quit IRC | 22:15 | |
*** mriedem has quit IRC | 22:17 | |
*** betherly has joined #openstack-neutron | 22:22 | |
*** markvoelker has joined #openstack-neutron | 22:23 | |
*** betherly has quit IRC | 22:27 | |
*** markvoelker has quit IRC | 22:28 | |
*** panda has quit IRC | 22:30 | |
*** panda has joined #openstack-neutron | 22:32 | |
*** weifan has joined #openstack-neutron | 23:19 | |
*** weifan has quit IRC | 23:22 | |
*** mattw4 has quit IRC | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!