*** zhanglong has quit IRC | 00:03 | |
*** njohnston_ has quit IRC | 00:23 | |
*** igordc has quit IRC | 00:25 | |
*** igordc has joined #openstack-neutron | 00:25 | |
openstackgerrit | norman shen proposed openstack/neutron stable/stein: DVR: Ignore DHCP port during DVR host query https://review.opendev.org/700955 | 00:36 |
---|---|---|
*** zhanglong has joined #openstack-neutron | 00:41 | |
*** igordc has quit IRC | 00:49 | |
*** ayoung has quit IRC | 00:54 | |
*** ayoung has joined #openstack-neutron | 00:57 | |
*** mithilarun has quit IRC | 00:58 | |
*** mithilarun has joined #openstack-neutron | 01:03 | |
*** xiaolin has joined #openstack-neutron | 01:03 | |
*** yamamoto has joined #openstack-neutron | 01:15 | |
*** jistr has quit IRC | 01:17 | |
*** mithilarun has quit IRC | 01:19 | |
*** jistr has joined #openstack-neutron | 01:19 | |
*** lseki has quit IRC | 01:40 | |
*** dsneddon has quit IRC | 01:48 | |
*** ircuser-1 has joined #openstack-neutron | 02:02 | |
*** macz has joined #openstack-neutron | 02:15 | |
*** hoonetorg has quit IRC | 02:17 | |
*** yamamoto has quit IRC | 02:19 | |
*** macz has quit IRC | 02:20 | |
*** dsneddon has joined #openstack-neutron | 02:24 | |
*** goldyfruit has quit IRC | 02:30 | |
*** hoonetorg has joined #openstack-neutron | 02:31 | |
*** ociuhandu has joined #openstack-neutron | 02:47 | |
*** dsneddon has quit IRC | 02:49 | |
*** awalende has joined #openstack-neutron | 02:50 | |
*** ociuhandu has quit IRC | 02:51 | |
*** awalende has quit IRC | 02:55 | |
*** zhanglong has quit IRC | 03:03 | |
*** yamamoto has joined #openstack-neutron | 03:14 | |
*** dsneddon has joined #openstack-neutron | 03:16 | |
*** dsneddon has quit IRC | 03:22 | |
*** dsneddon has joined #openstack-neutron | 03:50 | |
*** dsneddon has quit IRC | 03:59 | |
*** hongbin has joined #openstack-neutron | 04:03 | |
*** dsneddon has joined #openstack-neutron | 04:26 | |
*** dsneddon has quit IRC | 04:31 | |
*** goldyfruit has joined #openstack-neutron | 04:34 | |
*** hongbin has quit IRC | 04:39 | |
openstackgerrit | Taoyunxiang proposed openstack/neutron master: Update QoS related code from networkig-ovn https://review.opendev.org/703537 | 04:42 |
*** dsneddon has joined #openstack-neutron | 05:03 | |
*** dsneddon has quit IRC | 05:08 | |
*** sridharg has joined #openstack-neutron | 05:09 | |
*** macz has joined #openstack-neutron | 05:20 | |
openstackgerrit | Merged openstack/neutron master: [OVN] Add missing pyOpenSSL requirement https://review.opendev.org/702248 | 05:21 |
*** macz has quit IRC | 05:22 | |
*** lajoskatona has joined #openstack-neutron | 05:40 | |
*** dsneddon has joined #openstack-neutron | 05:41 | |
*** dsneddon has quit IRC | 05:46 | |
*** gcheresh has joined #openstack-neutron | 05:57 | |
*** lpetrut has joined #openstack-neutron | 06:08 | |
*** lpetrut has quit IRC | 06:09 | |
*** lpetrut has joined #openstack-neutron | 06:10 | |
*** dsneddon has joined #openstack-neutron | 06:20 | |
*** abdysn has joined #openstack-neutron | 06:24 | |
*** dsneddon has quit IRC | 06:25 | |
*** waleedm has joined #openstack-neutron | 06:33 | |
*** lpetrut has quit IRC | 06:49 | |
*** dsneddon has joined #openstack-neutron | 06:57 | |
*** dsneddon has quit IRC | 07:02 | |
*** gcheresh has quit IRC | 07:10 | |
*** ociuhandu has joined #openstack-neutron | 07:30 | |
*** dsneddon has joined #openstack-neutron | 07:33 | |
*** gcheresh has joined #openstack-neutron | 07:35 | |
*** ociuhandu has quit IRC | 07:35 | |
*** dsneddon has quit IRC | 07:38 | |
*** lpetrut has joined #openstack-neutron | 07:38 | |
*** maciejjozefczyk_ has joined #openstack-neutron | 07:48 | |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-fwaas master: Update FW group status upon admin-state update https://review.opendev.org/683817 | 07:52 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/networking-midonet master: Imported Translations from Zanata https://review.opendev.org/700311 | 07:52 |
*** slaweq has joined #openstack-neutron | 08:00 | |
*** jlibosva has joined #openstack-neutron | 08:04 | |
*** bnemec has joined #openstack-neutron | 08:06 | |
*** awalende has joined #openstack-neutron | 08:07 | |
*** tkajinam has quit IRC | 08:10 | |
*** dsneddon has joined #openstack-neutron | 08:13 | |
*** tmorin has joined #openstack-neutron | 08:18 | |
*** dsneddon has quit IRC | 08:19 | |
*** tesseract has joined #openstack-neutron | 08:20 | |
*** priteau has joined #openstack-neutron | 08:29 | |
*** ralonsoh has joined #openstack-neutron | 08:30 | |
*** waleedm has quit IRC | 08:32 | |
*** abdysn has quit IRC | 08:32 | |
*** abdysn has joined #openstack-neutron | 08:32 | |
*** waleedm has joined #openstack-neutron | 08:33 | |
openstackgerrit | Alex Katz proposed openstack/neutron-tempest-plugin master: Security group assignment negative tests https://review.opendev.org/703556 | 08:41 |
dulek | ayoung: Just a thought - there's some LB support in OpenStack cloud provider, maybe you have it enabled there? | 08:44 |
*** alti_17 has joined #openstack-neutron | 08:46 | |
*** dsneddon has joined #openstack-neutron | 08:48 | |
*** rpittau|afk is now known as rpittau | 08:48 | |
*** jpena|off is now known as jpena | 08:52 | |
*** dsneddon has quit IRC | 08:53 | |
*** yamamoto has quit IRC | 08:53 | |
openstackgerrit | Maciej Józefczyk proposed openstack/neutron master: [OVN] Add OVN functional tests - part 1 https://review.opendev.org/701733 | 08:55 |
*** dtantsur|afk is now known as dtantsur | 08:57 | |
*** tosky has joined #openstack-neutron | 09:07 | |
*** njohnston has joined #openstack-neutron | 09:09 | |
*** goldyfruit has quit IRC | 09:11 | |
*** yamamoto has joined #openstack-neutron | 09:14 | |
*** lucasagomes has joined #openstack-neutron | 09:14 | |
openstackgerrit | Maciej Józefczyk proposed openstack/neutron master: [OVN] Add OVN functional tests - part 1 https://review.opendev.org/701733 | 09:15 |
*** tmorin has quit IRC | 09:18 | |
*** yamamoto has quit IRC | 09:18 | |
*** dsneddon has joined #openstack-neutron | 09:25 | |
*** dsneddon has quit IRC | 09:30 | |
openstackgerrit | Slawek Kaplonski proposed openstack/neutron master: Update release-checklist doc page https://review.opendev.org/702822 | 09:31 |
*** tmorin has joined #openstack-neutron | 09:38 | |
*** sapd1_x has joined #openstack-neutron | 09:59 | |
*** dsneddon has joined #openstack-neutron | 10:00 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Fix py2 vs py3 dict keys comparison in functional test https://review.opendev.org/703574 | 10:04 |
*** ivve has joined #openstack-neutron | 10:07 | |
openstackgerrit | Adit Sarfaty proposed openstack/neutron-fwaas master: Stop running PY27 test & complete removal of py27 support https://review.opendev.org/703576 | 10:08 |
*** dsneddon has quit IRC | 10:09 | |
*** openstackgerrit has quit IRC | 10:12 | |
*** openstackgerrit has joined #openstack-neutron | 10:20 | |
openstackgerrit | Roman Safronov proposed openstack/networking-ovn stable/train: Use 'container image prepare' in prepare-migration https://review.opendev.org/702905 | 10:20 |
openstackgerrit | Taoyunxiang proposed openstack/neutron master: [OVN] Update QoS related code from networkig-ovn https://review.opendev.org/703537 | 10:23 |
openstackgerrit | Aditya Reddy Nagaram proposed openstack/neutron master: Support for stateless security groups https://review.opendev.org/572767 | 10:25 |
*** davidsha has joined #openstack-neutron | 10:26 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Fix py2 vs py3 dict keys comparison in functional test https://review.opendev.org/703574 | 10:26 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Don't send malformed status update to Octavia https://review.opendev.org/703097 | 10:27 |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Don't fail if VIP already exist or has been deleted before https://review.opendev.org/703110 | 10:27 |
*** sapd1_x has quit IRC | 10:29 | |
*** priteau has quit IRC | 10:41 | |
*** dsneddon has joined #openstack-neutron | 10:42 | |
*** CeeMac has joined #openstack-neutron | 10:43 | |
*** goldyfruit has joined #openstack-neutron | 10:47 | |
*** dsneddon has quit IRC | 10:47 | |
openstackgerrit | Alex Katz proposed openstack/neutron-tempest-plugin master: Security group assignment negative tests https://review.opendev.org/703556 | 10:50 |
openstackgerrit | Bernard Cafarelli proposed openstack/neutron-dynamic-routing master: Switch functional job to Zuulv3 syntax https://review.opendev.org/703582 | 10:51 |
slaweq | ralonsoh: amotoki hi, can You take a look at https://review.opendev.org/#/c/526218/ if You will have some time? | 10:55 |
amotoki | slaweq: sure | 10:55 |
ralonsoh | slaweq, of course | 10:55 |
slaweq | thx :) | 10:55 |
slaweq | it's very old patch which I found and wanted to finally merge | 10:55 |
bcafarel | spring cleaning time already? | 11:01 |
frickler | bcafarel: well, it'll be spring festival on Saturday, so just in time, I'd say ;) | 11:06 |
*** tmorin has quit IRC | 11:07 | |
*** goldyfruit has quit IRC | 11:10 | |
*** awalende has quit IRC | 11:13 | |
*** awalende has joined #openstack-neutron | 11:14 | |
*** rpittau is now known as rpittau|bbl | 11:15 | |
*** dsneddon has joined #openstack-neutron | 11:22 | |
*** dsneddon has quit IRC | 11:27 | |
slaweq | bcafarel: frickler sure, weather is nice, so we can start earlier ;) | 11:29 |
*** rodolof has quit IRC | 11:30 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Centralize traffic when LB and member has FIP https://review.opendev.org/702831 | 11:40 |
*** alti_17 has quit IRC | 11:42 | |
*** zhanglong has joined #openstack-neutron | 11:44 | |
*** maciejjozefczyk_ has quit IRC | 11:45 | |
openstackgerrit | Jens Harbott (frickler) proposed openstack/neutron-dynamic-routing master: Clean up workaround in https://review.opendev.org/703592 | 11:51 |
ralonsoh | slaweq, I would like to do something like https://review.opendev.org/#/c/621572/ | 11:51 |
ralonsoh | for functional testing | 11:51 |
ralonsoh | because we have a lot of ovsdb timeouts in the gate | 11:52 |
ralonsoh | and I can't find the problem or the possible blocker there | 11:52 |
slaweq | ralonsoh: yes, we have them often again | 11:53 |
slaweq | I even added that to the list of bugs for today's CI meeting :) | 11:53 |
*** zhanglong has quit IRC | 11:53 | |
slaweq | but do You want to set ovsdb_debug to True by default or only in functional/fullstack tests? | 11:53 |
ralonsoh | only in FT tests | 11:54 |
slaweq | ralonsoh: fine for me | 11:56 |
slaweq | but You can also add it in fullstack job too | 11:56 |
ralonsoh | perfect | 11:56 |
*** gcheresh has quit IRC | 11:58 | |
slaweq | thx ralonsoh :) | 11:59 |
slaweq | I hope this will help finally solve this issue | 11:59 |
*** dsneddon has joined #openstack-neutron | 12:00 | |
*** dtantsur is now known as dtantsur|bbl | 12:01 | |
*** S4ren has joined #openstack-neutron | 12:01 | |
ralonsoh | slaweq, https://review.opendev.org/#/c/526218 | 12:02 |
ralonsoh | we should merge this today | 12:03 |
ralonsoh | there is no reason to keep it there | 12:03 |
slaweq | ralonsoh: amotoki thx a lot, patch from 2017 will be merged in 2020 :) | 12:03 |
slaweq | that's long time | 12:03 |
*** maciejjozefczyk_ has joined #openstack-neutron | 12:04 | |
*** dsneddon has quit IRC | 12:05 | |
*** priteau has joined #openstack-neutron | 12:07 | |
*** aedc has quit IRC | 12:09 | |
*** aedc has joined #openstack-neutron | 12:09 | |
*** ociuhandu has joined #openstack-neutron | 12:12 | |
*** ociuhandu has quit IRC | 12:13 | |
openstackgerrit | Rodolfo Alonso Hernandez proposed openstack/neutron master: Assign local variable before being referred https://review.opendev.org/703236 | 12:14 |
*** tkajinam has joined #openstack-neutron | 12:14 | |
*** aedc has quit IRC | 12:20 | |
*** aedc has joined #openstack-neutron | 12:20 | |
*** jpena is now known as jpena|lunch | 12:21 | |
*** rcernin has quit IRC | 12:28 | |
*** Luzi has joined #openstack-neutron | 12:28 | |
openstackgerrit | Rodolfo Alonso Hernandez proposed openstack/neutron master: Use tuple comparison to check dnsmasq supported version https://review.opendev.org/702847 | 12:29 |
*** dsneddon has joined #openstack-neutron | 12:31 | |
*** tmorin has joined #openstack-neutron | 12:32 | |
*** nweinber__ has joined #openstack-neutron | 12:34 | |
*** dsneddon has quit IRC | 12:35 | |
amotoki | yeah, that's a good cleanup :) | 12:38 |
openstackgerrit | Bernard Cafarelli proposed openstack/networking-bgpvpn master: [WIP] Switch functional/install jobs to Zuulv3 syntax https://review.opendev.org/703601 | 12:39 |
*** gcheresh has joined #openstack-neutron | 12:42 | |
*** nicolasbock has joined #openstack-neutron | 12:50 | |
*** ociuhandu has joined #openstack-neutron | 12:52 | |
openstackgerrit | Roman Safronov proposed openstack/networking-ovn stable/train: Use 'container image prepare' in prepare-migration https://review.opendev.org/702905 | 12:55 |
*** lseki has joined #openstack-neutron | 12:57 | |
*** ociuhandu has quit IRC | 13:01 | |
*** priteau has quit IRC | 13:05 | |
*** rpittau|bbl is now known as rpittau | 13:05 | |
*** rouk has joined #openstack-neutron | 13:05 | |
openstackgerrit | Maciej Józefczyk proposed openstack/networking-ovn stable/train: Centralize traffic when LB and member has FIP https://review.opendev.org/702831 | 13:07 |
*** dsneddon has joined #openstack-neutron | 13:07 | |
rouk | is there any purge to properly clean up a project's fwaas before project deletion, seems that fwaas resources can get orphan'd rather easily. | 13:07 |
rouk | dont see any in the docs, and resources can easily get stuck active | 13:08 |
openstackgerrit | Merged openstack/os-ken master: Drop Python2 support and testing https://review.opendev.org/703238 | 13:11 |
*** dsneddon has quit IRC | 13:17 | |
*** zbr|drover has quit IRC | 13:18 | |
*** zbr has joined #openstack-neutron | 13:19 | |
*** jpena|lunch is now known as jpena | 13:23 | |
openstackgerrit | Bence Romsics proposed openstack/neutron master: Follow up to change of exception raised https://review.opendev.org/698261 | 13:25 |
openstackgerrit | Taoyunxiang proposed openstack/neutron master: [OVN] Update QoS related code from networkig-ovn https://review.opendev.org/703537 | 13:27 |
openstackgerrit | Daniel Alvarez proposed openstack/neutron master: [ovn] Agent liveness - allow time to propagate checks https://review.opendev.org/703612 | 13:29 |
openstackgerrit | Rodolfo Alonso Hernandez proposed openstack/os-ken master: Replace deprecated brctl with ip commands https://review.opendev.org/703234 | 13:36 |
frickler | rouk: resources can also get stuck in some pending state. for me, fwaas is completely broken and unmaintained, so I suggest not to deploy it | 13:36 |
rouk | fwaasv2 seems somewhat active | 13:36 |
rouk | is it dead? | 13:36 |
rouk | im not using v1, sorry for the confusion | 13:37 |
frickler | I'm talking about v2. v1 was fine as long as it existed | 13:37 |
frickler | http://lists.openstack.org/pipermail/openstack-discuss/2020-January/011833.html | 13:37 |
rouk | so... what replaces it? | 13:38 |
frickler | nothing | 13:38 |
rouk | kinda need support for an edge firewall in my setup... | 13:39 |
rouk | havnt really had any major issues with fwaasv2 myself since deploying it, but i figured it would get better not be abandoned. not sure what to do with this information, not sure im the guy to maintain it. | 13:42 |
frickler | sean-k-mooney has written some nice final words on it http://lists.openstack.org/pipermail/openstack-discuss/2020-January/012108.html | 13:42 |
rouk | yeah, my use case is exactly the one mentioned, inter-project firewalling. | 13:46 |
rouk | security groups dont really cover that. | 13:46 |
*** ociuhandu has joined #openstack-neutron | 13:47 | |
sean-k-mooney | rouk: inter project no. inter applciation withine the same project maybe | 13:47 |
*** dsneddon has joined #openstack-neutron | 13:48 | |
rouk | we route every project subnet to their openstack routers, then handoff to the tenant to firewall themselves in via fwaas, not sure how to replace that workflow. | 13:48 |
sean-k-mooney | if you block incomming traffic by default an then use remote security groups to allow only the conenction form specific application(which have that securtion group) you can selectivly allow the communication | 13:49 |
rouk | but that would require turning 200vm projects into 1200vm projects. | 13:50 |
rouk | and putting multiple teams into a single big giant project | 13:50 |
rouk | unless theres a cross-tenant security group im unaware of | 13:50 |
sean-k-mooney | no not that i am aware of | 13:51 |
sean-k-mooney | is your env an telco deployment or some other usecase | 13:52 |
rouk | private cloud, for our own products. | 13:52 |
sean-k-mooney | ok | 13:52 |
rouk | telco is one of them, but not really. | 13:52 |
rouk | in terms of workflow, its nothing different for the telco bits | 13:52 |
*** dsneddon has quit IRC | 13:53 | |
*** ociuhandu has quit IRC | 13:53 | |
sean-k-mooney | well so telcos tended to not use FWaaS because it could not meet there perfomace requiremetns | 13:53 |
sean-k-mooney | they tended to prefer deploying a VNF to act as there firewall instead or offload to a hardware appliace | 13:54 |
rouk | openstack routers already kinda tie you down to ~4-5gbit, and we accepted that loss, we have alternatives for 100gbit+ | 13:54 |
sean-k-mooney | ya so because of the kenrel ovs/iptables bandwith resticiton telco largely ignored FWaaS and did there own thing | 13:55 |
*** tbachman has joined #openstack-neutron | 13:55 | |
rouk | we are not using ovs, so our perf is... okay. going to look like a fool to the devs cause they are working with fwaas right now because its what i provided. | 13:57 |
rouk | had no idea it was being abandoned | 13:57 |
rouk | we have cumulus stuff on trident3s so we can get some decent iptables/kernel acceleration if we want it, we dont bother currently. | 13:58 |
rouk | been getting 100gbit routing on a kernel table just fine on tridents | 13:58 |
sean-k-mooney | i see. well its not abandoned entirly yet | 13:59 |
sean-k-mooney | but it does need peole to help maintian it. but its not a trivail task | 14:00 |
openstackgerrit | Bernard Cafarelli proposed openstack/networking-bgpvpn master: [WIP] Switch functional/install jobs to Zuulv3 syntax https://review.opendev.org/703601 | 14:00 |
*** waleedm has quit IRC | 14:00 | |
*** dtantsur|bbl is now known as dtantsur | 14:01 | |
rouk | well, i can technically do it, but im not currently involved in any of the trees, so my specific knowledge on fwaas is 1/10. | 14:01 |
rouk | but if theres something else i should be doing, id rather do that and not fight the flow | 14:02 |
sean-k-mooney | honestly without changin how you deploy application im not aware of good solution. that said i mainly work on nova these days so i could very easily be missing something obvious | 14:05 |
rouk | well, as long as its something i can sell to my devs im a happy guy. | 14:05 |
rouk | what have you been doing? | 14:05 |
sean-k-mooney | i dont have a need to run firwall as a service and its not supported in Redhat OSP as far as im aware so we dont have customer using it | 14:06 |
rouk | is directly routing blocks into tenants also not a thing in redhat? | 14:07 |
sean-k-mooney | generally not although there is some support for routed networks | 14:07 |
sean-k-mooney | in general customer deploy with private networks and floatign ips | 14:07 |
sean-k-mooney | rather then making the private network routable | 14:08 |
rouk | and you can get enough perf from floating ips and nat? | 14:08 |
sean-k-mooney | for our non telco cusotmer yes | 14:08 |
sean-k-mooney | for telco customer they tend to use sriov or dpdk and turn off firewalling | 14:09 |
rouk | fwaas also allowed security to kinda have authority over that edge while letting teams do whatever they wanted within their sandbox, as another use case. | 14:11 |
sean-k-mooney | yes is support a more tradtional non cloud deployment model where you have a seperate network security team that manages that vs the more typical self service model | 14:12 |
rouk | i just coded some auditing so it would ensure their rules were within what they were approved of. bit harder to assemble that picture from secgroups | 14:14 |
*** awalende has quit IRC | 14:16 | |
sean-k-mooney | rouk: do you deploy your applciaiton using a declaritval tool like heat templates | 14:18 |
rouk | up to the devs, heat kinda fell apart in a lot of places so the devs mostly settled on terraform. | 14:18 |
rouk | some just use the openstack api directly. | 14:18 |
sean-k-mooney | ok | 14:18 |
sean-k-mooney | well i was just going to suggest if that is standardised | 14:19 |
sean-k-mooney | then you could have your securtiy team mange the dinition of the security groups | 14:19 |
rouk | we are battling "developer freedom" :p | 14:19 |
rouk | security wanted a different tier that would be free from the day-to-day, which only fwaas provided. | 14:20 |
*** abdysn has quit IRC | 14:20 | |
sean-k-mooney | well your other option is to pull the firewalling out side of openstack | 14:20 |
sean-k-mooney | so before you route the traffic into openstack implement a firewall there | 14:21 |
rouk | well, i need to check on how well cumulus could do the transit while filtering ports. | 14:21 |
sean-k-mooney | integration wise that is obviosly a step back however from using FWaas | 14:21 |
*** yamamoto has joined #openstack-neutron | 14:21 | |
rouk | all the last mile is cumulus, into the openstack routers. but im not sure how much firewalling they can handle while sustaining 100gbit per port. | 14:22 |
sean-k-mooney | ya that is always the tradeoff | 14:22 |
rouk | i am almost done coding a "project management" tool, to allow users to manage their members and project creation acording to our standard bases, routing, etc. | 14:23 |
rouk | i could put firewalling in there, and maybe be ready before fwaas goes away. assuming trident3s can filter that fast if we centralized it | 14:23 |
sean-k-mooney | what release of openstack are you currently running | 14:24 |
rouk | stein, was waiting on a10 to finish their integration for octavia theyre stringing me along with before moving to train, but probably just going to roll train in the next few weeks. | 14:25 |
*** dsneddon has joined #openstack-neutron | 14:26 | |
sean-k-mooney | ok well FWaaS will be still there in train and maybe removed in ussuri so you do have asome time before you would need to find another solution | 14:26 |
openstackgerrit | Bernard Cafarelli proposed openstack/networking-bgpvpn master: [WIP] Switch functional/install jobs to Zuulv3 syntax https://review.opendev.org/703601 | 14:27 |
rouk | yeah, assuming the hardware can take it. | 14:28 |
rouk | havnt tested tcp level filtering on them. | 14:28 |
rouk | if its just code i have to write, i can live with that. | 14:29 |
sean-k-mooney | the solution that telcos wanted to use was using network level service fucntion chain to steer traffic to a VNF firwwall and then redirect it to applciations | 14:30 |
*** ayoung has quit IRC | 14:30 | |
sean-k-mooney | that way they coudl swap out the VNF with different vendor solution to meet there requirements or extend the chain of services to supprot other usecasues | 14:30 |
*** dsneddon has quit IRC | 14:31 | |
rouk | yeah, we dont need that level of flexibility, hardware is something i can fully control at least. | 14:31 |
*** yamamoto has quit IRC | 14:36 | |
*** S4r3n has joined #openstack-neutron | 14:43 | |
frickler | sean-k-mooney: is that SFC/VNF functionality available within vanilla neutron? or would one need some vendor solution for it? | 14:46 |
*** Luzi has quit IRC | 14:46 | |
*** S4ren has quit IRC | 14:46 | |
*** sridharg has quit IRC | 14:47 | |
frickler | oh, I guess that'd be tacker, something like https://docs.openstack.org/tacker/latest/install/deploy_openwrt.html | 14:49 |
sean-k-mooney | frickler: i was tinkg more of networking-sfc | 14:52 |
sean-k-mooney | tacker might be able to do it too | 14:52 |
sean-k-mooney | the have an alternivite sfc api | 14:53 |
*** gcheresh has quit IRC | 14:53 | |
sean-k-mooney | as far as i am aware networking-sfc still works with ml2/ovs and has backend driver support in ovn odl and a few other sdn contolers | 14:54 |
frickler | why have one standard, when you can have two for the same price ... scnr | 14:54 |
*** gcheresh has joined #openstack-neutron | 14:54 | |
frickler | but thanks for the pointer, I'll take a closer look at it | 14:54 |
sean-k-mooney | well tacker was asked not to intoduce an sfc api and leave that to netwrokign sfc but if you really are interested there is also ate least 3 other solutions | 14:55 |
sean-k-mooney | there was the intent api propsal form huawei, group based policy form cisco | 14:56 |
sean-k-mooney | and there was once other proposal in this area that escapes me currently | 14:56 |
*** tbachman has quit IRC | 14:58 | |
*** yamamoto has joined #openstack-neutron | 14:59 | |
*** yamamoto has quit IRC | 14:59 | |
*** yamamoto has joined #openstack-neutron | 14:59 | |
openstackgerrit | Bernard Cafarelli proposed openstack/networking-bgpvpn master: [WIP] Switch functional/install jobs to Zuulv3 syntax https://review.opendev.org/703601 | 15:00 |
sean-k-mooney | oh i remember it was not that there was a third solution althogh there proably is but tacker orginally bypased neutorn and talked directly to odl ti instanciate its vnf frowardign graphs directly via odls sfc api and then was later rebased to build on top of networking-sfc | 15:02 |
*** yamamoto has quit IRC | 15:04 | |
*** dsneddon has joined #openstack-neutron | 15:05 | |
*** dsneddon has quit IRC | 15:10 | |
*** tkajinam has quit IRC | 15:16 | |
*** gcheresh has quit IRC | 15:25 | |
*** ociuhandu has joined #openstack-neutron | 15:30 | |
openstackgerrit | Brian Haley proposed openstack/neutron master: Use tuple comparison to check dnsmasq supported version https://review.opendev.org/702847 | 15:30 |
openstackgerrit | Brian Haley proposed openstack/neutron master: Use distutils.version to check dnsmasq supported version https://review.opendev.org/702847 | 15:34 |
*** dsneddon has joined #openstack-neutron | 15:37 | |
ralonsoh | slaweq, https://review.opendev.org/#/c/703642/ | 15:37 |
ralonsoh | A limit, in requirements, for n-lib | 15:38 |
ralonsoh | This will prevent the errors we have in tempest-plugin Rocky | 15:38 |
ralonsoh | https://bugs.launchpad.net/neutron/+bug/1860033 | 15:38 |
openstack | Launchpad bug 1860033 in tempest "Tempest jobs broken on stable branches due to requirements neutron-lib upgrade (the EOLing python2 drama)" [Critical,In progress] - Assigned to Ghanshyam Mann (ghanshyammann) | 15:38 |
ralonsoh | (I think so) | 15:38 |
slaweq | ralonsoh: +1 | 15:39 |
slaweq | thx | 15:39 |
openstackgerrit | Maciej Józefczyk proposed openstack/neutron master: [OVN] Add OVN functional tests - part 1 https://review.opendev.org/701733 | 15:39 |
*** hjensas has quit IRC | 15:39 | |
openstackgerrit | Terry Wilson proposed openstack/ovsdbapp master: Log invalid address values in lsp_set_addresses https://review.opendev.org/703644 | 15:42 |
*** dsneddon has quit IRC | 15:42 | |
openstackgerrit | Merged openstack/networking-ovn stable/queens: Fix revision number race condition with attaching router interfaces https://review.opendev.org/701951 | 15:44 |
*** lpetrut has quit IRC | 15:46 | |
openstackgerrit | Bernard Cafarelli proposed openstack/networking-bgpvpn master: [WIP] Switch functional/install jobs to Zuulv3 syntax https://review.opendev.org/703601 | 15:46 |
openstackgerrit | Merged openstack/networking-ovn stable/stein: Exclude all device_ids that belong to Neutron DHCP Agent https://review.opendev.org/703192 | 15:46 |
*** tidwellr has joined #openstack-neutron | 15:46 | |
*** brokoli__ has joined #openstack-neutron | 15:47 | |
*** S4r3n has quit IRC | 15:50 | |
*** ociuhandu has quit IRC | 15:51 | |
bcafarel | ralonsoh: that an alternative to https://review.opendev.org/#/c/703476/ then? | 15:55 |
ralonsoh | bcafarel, IMO, instead of changing the CI jobs, what we need is to properly limit the library versions | 15:55 |
ralonsoh | in this case, n-lib 2.0.0 is only available for py3 | 15:56 |
ralonsoh | this patch could not be needed | 15:56 |
*** gcheresh has joined #openstack-neutron | 15:59 | |
*** ccamposr__ has quit IRC | 16:01 | |
*** ccamposr__ has joined #openstack-neutron | 16:01 | |
*** lajoskatona has quit IRC | 16:02 | |
*** maciejjozefczyk_ has quit IRC | 16:04 | |
openstackgerrit | Jens Harbott (frickler) proposed openstack/neutron stable/stein: Stop verifying unique external_net_id https://review.opendev.org/703067 | 16:12 |
*** openstackgerrit has quit IRC | 16:13 | |
*** gcheresh has quit IRC | 16:17 | |
*** dsneddon has joined #openstack-neutron | 16:17 | |
*** gcheresh has joined #openstack-neutron | 16:17 | |
haleyb | ralonsoh: i had a patch setting specific constraints that i just abandoned, PS1 was my initial hack (albeit the wrong lib version), https://review.opendev.org/#/c/702986/1/upper-constraints.txt | 16:21 |
haleyb | there seemed to be lots of other libraries doing the same thing | 16:22 |
*** dsneddon has quit IRC | 16:22 | |
ralonsoh | haleyb, I didn't see this patch | 16:23 |
*** ociuhandu has joined #openstack-neutron | 16:23 | |
ralonsoh | but I think this is the correct way | 16:23 |
haleyb | ralonsoh: i can restore back to PS1-like change if you want, think i had a test patch in stable/rocky | 16:24 |
ralonsoh | haleyb, I have this https://review.opendev.org/#/c/703642/ | 16:24 |
haleyb | ralonsoh: oh, the same thing, let's see if it works :) | 16:25 |
*** gcheresh has quit IRC | 16:27 | |
*** ociuhandu has quit IRC | 16:28 | |
*** tbachman has joined #openstack-neutron | 16:29 | |
*** mithilarun has joined #openstack-neutron | 16:31 | |
*** macz has joined #openstack-neutron | 16:31 | |
*** tosky has quit IRC | 16:33 | |
*** ociuhandu has joined #openstack-neutron | 16:36 | |
*** openstackgerrit has joined #openstack-neutron | 16:37 | |
openstackgerrit | Aditya Reddy Nagaram proposed openstack/neutron master: Support for stateless security groups https://review.opendev.org/572767 | 16:37 |
*** mattw4 has joined #openstack-neutron | 16:41 | |
*** jpena is now known as jpena|brb | 16:46 | |
*** bnemec has quit IRC | 16:48 | |
*** dsneddon has joined #openstack-neutron | 16:53 | |
*** mithilarun has quit IRC | 16:54 | |
*** nweinber__ has quit IRC | 16:55 | |
*** dsneddon has quit IRC | 16:58 | |
*** hjensas has joined #openstack-neutron | 17:00 | |
*** tesseract has quit IRC | 17:01 | |
*** rpittau is now known as rpittau|afk | 17:04 | |
*** lucasagomes has quit IRC | 17:05 | |
bcafarel | slaweq: interesting comments by gmann in the end of https://bugs.launchpad.net/neutron/+bug/1859988 on EM branches and tempest plugins | 17:13 |
openstack | Launchpad bug 1859988 in neutron "neutron-tempest-plugin tests fail for stable/queens" [Critical,In progress] - Assigned to Bernard Cafarelli (bcafarel) | 17:13 |
*** tmorin has quit IRC | 17:15 | |
gmann | bcafarel: slaweq yeah, we need these 3 things compatible Tempest + plugins + u-c otherwise we never know when we can face the incompatibility issue on requirement or code. doing it all 3 together on devstack side is preferred way. | 17:15 |
gmann | or one more use case it can be other plugin using neutron-tempest-plugin and running as master on stable/queens. | 17:17 |
ralonsoh | btw, neutron-tempest-plugin is now failing in rocky | 17:18 |
bcafarel | gmann++ ok so in the end we should not need anything specific in queens job definition, nice - I can push a cleanup patch once everything is merged on devstack side | 17:20 |
gmann | bcafarel: +1. i am working on that and should push patch on devstack by today. | 17:21 |
*** davidsha has quit IRC | 17:23 | |
*** jpena|brb is now known as jpena | 17:26 | |
*** Coolp has joined #openstack-neutron | 17:27 | |
*** Coolp has left #openstack-neutron | 17:29 | |
*** dsneddon has joined #openstack-neutron | 17:34 | |
*** dsneddon has quit IRC | 17:39 | |
*** tbachman has quit IRC | 17:42 | |
*** tbachman_ has joined #openstack-neutron | 17:42 | |
*** brokoli__ has quit IRC | 17:56 | |
*** macz has quit IRC | 18:03 | |
*** dsneddon has joined #openstack-neutron | 18:08 | |
*** mithilarun has joined #openstack-neutron | 18:11 | |
*** dtantsur is now known as dtantsur|afk | 18:11 | |
*** ociuhandu_ has joined #openstack-neutron | 18:13 | |
*** dsneddon has quit IRC | 18:14 | |
*** ociuhandu has quit IRC | 18:17 | |
*** ociuhandu_ has quit IRC | 18:18 | |
openstackgerrit | Merged openstack/os-vif master: [Follow Up] OVS DPDK port representors support https://review.opendev.org/665965 | 18:21 |
*** slaweq_ has joined #openstack-neutron | 18:26 | |
*** slaweq has quit IRC | 18:27 | |
*** ralonsoh has quit IRC | 18:31 | |
*** jpena is now known as jpena|off | 18:34 | |
*** ayoung has joined #openstack-neutron | 18:36 | |
*** tbachman has joined #openstack-neutron | 18:40 | |
*** ramishra has quit IRC | 18:41 | |
*** tbachman_ has quit IRC | 18:41 | |
*** dsneddon has joined #openstack-neutron | 18:45 | |
*** mithilarun has quit IRC | 18:50 | |
*** jlibosva has quit IRC | 18:50 | |
*** dsneddon has quit IRC | 18:50 | |
*** CeeMac has quit IRC | 18:51 | |
openstackgerrit | Adrian Chiris proposed openstack/os-vif master: Revert "[Follow Up] OVS DPDK port representors support" https://review.opendev.org/703672 | 18:57 |
openstackgerrit | Adrian Chiris proposed openstack/os-vif master: Revert "[Follow Up] OVS DPDK port representors support" https://review.opendev.org/703672 | 19:00 |
*** gcheresh has joined #openstack-neutron | 19:10 | |
*** mithilarun has joined #openstack-neutron | 19:12 | |
*** dsneddon has joined #openstack-neutron | 19:15 | |
*** jlibosva has joined #openstack-neutron | 19:19 | |
*** jlibosva has quit IRC | 19:24 | |
*** tosky has joined #openstack-neutron | 19:25 | |
*** jlibosva has joined #openstack-neutron | 19:28 | |
*** jlibosva has quit IRC | 19:32 | |
openstackgerrit | Merged openstack/neutron master: [OVN] Re-enable test_port_security_macspoofing_port https://review.opendev.org/702250 | 19:34 |
openstackgerrit | Ghanshyam Mann proposed openstack/neutron stable/queens: DNM: testing with Temepst pinned on devstack stable/queens https://review.opendev.org/703680 | 19:39 |
*** nicolasbock has quit IRC | 19:57 | |
*** jlibosva has joined #openstack-neutron | 20:01 | |
openstackgerrit | Brian Haley proposed openstack/neutron master: Un-quote metadata address if it is IPv6 https://review.opendev.org/703685 | 20:02 |
openstackgerrit | Ghanshyam Mann proposed openstack/neutron stable/rocky: DNM: Testing with stable/rocky fix on devstack & Tempest https://review.opendev.org/703686 | 20:04 |
gmann | bcafarel: pushed devstack patch (depends-on one) and testing on https://review.opendev.org/#/c/703686/ | 20:11 |
*** yamamoto has joined #openstack-neutron | 20:11 | |
gmann | bcafarel: i have not caped plugins as logic needs to be investigate more. I need to check tomorrow if that can done generically or not because each plugins tag are diff and no stable branch for plugins. so keep neutron-tempest-plugin pin on neutron jobs till we figure that out. | 20:12 |
*** jlibosva has quit IRC | 20:13 | |
*** mlavalle has joined #openstack-neutron | 20:15 | |
*** yamamoto has quit IRC | 20:16 | |
*** jlibosva has joined #openstack-neutron | 20:17 | |
*** jlibosva has quit IRC | 20:21 | |
*** jlibosva has joined #openstack-neutron | 20:22 | |
*** jlibosva has quit IRC | 20:27 | |
*** rcernin has joined #openstack-neutron | 20:42 | |
openstackgerrit | Brian Haley proposed openstack/neutron master: Change ResourceAllocator tests to not use /tmp https://review.opendev.org/581461 | 20:44 |
openstackgerrit | Brian Haley proposed openstack/neutron master: Change ResourceAllocator tests to not use /tmp https://review.opendev.org/581461 | 20:45 |
*** gcheresh has quit IRC | 20:45 | |
*** mithilarun has quit IRC | 20:46 | |
*** jlibosva has joined #openstack-neutron | 20:47 | |
*** jlibosva has quit IRC | 20:51 | |
openstackgerrit | Brian Haley proposed openstack/neutron master: Support encapsulated DHCP options https://review.opendev.org/681466 | 21:00 |
*** jmlowe has joined #openstack-neutron | 21:00 | |
*** jlibosva has joined #openstack-neutron | 21:15 | |
slaweq_ | gmann: bcafarel thx for working on fix for that | 21:16 |
*** jlibosva has quit IRC | 21:19 | |
*** armax has joined #openstack-neutron | 21:22 | |
*** maciejjozefczyk_ has joined #openstack-neutron | 21:28 | |
*** seba has quit IRC | 21:29 | |
*** maciejjozefczyk_ has quit IRC | 21:35 | |
*** nweinber__ has joined #openstack-neutron | 21:36 | |
*** seba has joined #openstack-neutron | 21:37 | |
*** mithilarun has joined #openstack-neutron | 21:37 | |
*** jlibosva has joined #openstack-neutron | 21:44 | |
*** jlibosva has quit IRC | 21:48 | |
*** mithilarun has quit IRC | 21:50 | |
*** nweinber__ has quit IRC | 21:51 | |
*** mattw4 has quit IRC | 22:06 | |
*** mattw4 has joined #openstack-neutron | 22:06 | |
*** jmlowe has quit IRC | 22:09 | |
*** mithilarun has joined #openstack-neutron | 22:11 | |
*** jmlowe has joined #openstack-neutron | 22:13 | |
*** mattw4 has quit IRC | 22:14 | |
*** mattw4 has joined #openstack-neutron | 22:15 | |
*** slaweq_ has quit IRC | 22:16 | |
*** jmlowe has quit IRC | 22:17 | |
openstackgerrit | Terry Wilson proposed openstack/neutron master: Ensure we don't pass empty addresses to lsp_set_addresses https://review.opendev.org/703703 | 22:25 |
*** slaweq_ has joined #openstack-neutron | 22:27 | |
*** slaweq_ has quit IRC | 22:32 | |
openstackgerrit | Merged openstack/networking-ovn stable/queens: Exclude all device_ids that belong to Neutron DHCP Agent https://review.opendev.org/703195 | 22:35 |
openstackgerrit | Merged openstack/networking-ovn stable/train: Exclude all device_ids that belong to Neutron DHCP Agent https://review.opendev.org/703191 | 22:35 |
openstackgerrit | Merged openstack/networking-ovn stable/rocky: Exclude all device_ids that belong to Neutron DHCP Agent https://review.opendev.org/703193 | 22:35 |
*** jlibosva has joined #openstack-neutron | 22:38 | |
openstackgerrit | Bernard Cafarelli proposed openstack/neutron stable/rocky: DNM: Testing with stable/rocky fix on devstack & Tempest https://review.opendev.org/703686 | 22:39 |
bcafarel | gmann: got it, will wait for results there! Thanks again for the help :) | 22:40 |
*** jlibosva has quit IRC | 22:43 | |
*** jlibosva has joined #openstack-neutron | 22:47 | |
*** jlibosva has quit IRC | 22:51 | |
*** tkajinam has joined #openstack-neutron | 22:57 | |
*** jlibosva has joined #openstack-neutron | 23:17 | |
*** jlibosva has quit IRC | 23:21 | |
openstackgerrit | Ghanshyam Mann proposed openstack/neutron stable/queens: DNM: testing with Temepst pinned on devstack stable/queens https://review.opendev.org/703680 | 23:35 |
*** dsneddon has quit IRC | 23:39 | |
*** armax has quit IRC | 23:41 | |
*** tosky has quit IRC | 23:47 | |
openstackgerrit | Brian Haley proposed openstack/neutron master: Check dvr local router is up during port creation https://review.opendev.org/633871 | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!