opendevreview | Ghanshyam proposed openstack/neutron stable/train: DNM: test tempest train-last tag https://review.opendev.org/c/openstack/neutron/+/816597 | 00:47 |
---|---|---|
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: update ACL actions on stateful field change https://review.opendev.org/c/openstack/neutron/+/816600 | 00:57 |
opendevreview | liuyulong proposed openstack/neutron-specs master: Spec for distributed datapath for metadata https://review.opendev.org/c/openstack/neutron-specs/+/802854 | 01:24 |
opendevreview | liuyulong proposed openstack/neutron-specs master: Spec for distributed datapath for metadata https://review.opendev.org/c/openstack/neutron-specs/+/802854 | 01:41 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: enable stateless-security-group api https://review.opendev.org/c/openstack/neutron/+/816612 | 03:04 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron-tempest-plugin master: Add stateless security group test case https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816613 | 03:04 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron-tempest-plugin master: Add stateless security group test case https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816613 | 03:07 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron-tempest-plugin master: Add stateless security group test case https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816613 | 03:08 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: enable stateless-security-group api https://review.opendev.org/c/openstack/neutron/+/816612 | 03:08 |
opendevreview | Cong Nguyen Thanh proposed openstack/neutron master: [OVN] Fix port disable security dead when run neutron-ovn-db-sync-util https://review.opendev.org/c/openstack/neutron/+/816328 | 03:14 |
opendevreview | Cong Nguyen Thanh proposed openstack/neutron master: [OVN] Fix port disable security dead when run neutron-ovn-db-sync-util https://review.opendev.org/c/openstack/neutron/+/816328 | 03:15 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: update ACL actions on stateful field change https://review.opendev.org/c/openstack/neutron/+/816600 | 03:17 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: enable stateless-security-group api https://review.opendev.org/c/openstack/neutron/+/816612 | 03:17 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: Bump OVN version for functional job to 21.06 https://review.opendev.org/c/openstack/neutron/+/816614 | 03:17 |
opendevreview | Merged openstack/neutron stable/victoria: [DVR] Fix update of the MTU in the SNAT namespace https://review.opendev.org/c/openstack/neutron/+/812950 | 03:19 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron-tempest-plugin master: Add stateless security group test case https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816613 | 03:20 |
*** gibi_pto_back_thu is now known as gibi | 07:56 | |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [OVN] Sync QoS policies https://review.opendev.org/c/openstack/neutron/+/813052 | 08:10 |
opendevreview | Lajos Katona proposed openstack/neutron master: Increase the timeout for arm64 jobs https://review.opendev.org/c/openstack/neutron/+/816621 | 08:48 |
opendevreview | Merged openstack/os-ken master: Bugfix now multiple switches can connect with TLS https://review.opendev.org/c/openstack/os-ken/+/813833 | 09:12 |
opendevreview | Merged openstack/os-ken master: Allow user to set cipher list. https://review.opendev.org/c/openstack/os-ken/+/813835 | 09:16 |
opendevreview | Merged openstack/os-ken master: Add support for the MTU ND option. https://review.opendev.org/c/openstack/os-ken/+/813836 | 09:28 |
dulek | Is this normal: https://3e7cdff9e56ac3733874-d434493bb46e5d37fd5df3f066caeb22.ssl.cf5.rackcdn.com/816305/2/check/kuryr-kubernetes-tempest/2ac6084/controller/logs/screen-ovn-northd.txt ? | 09:35 |
slaweq | lucasagomes: hi, can You maybe take a look at ^^ ? | 09:37 |
opendevreview | Merged openstack/neutron stable/ussuri: [DVR] Fix update of the MTU in the SNAT namespace https://review.opendev.org/c/openstack/neutron/+/812951 | 09:40 |
opendevreview | Merged openstack/neutron stable/ussuri: [OVN Migration] Remove trunk's subports from the nodes https://review.opendev.org/c/openstack/neutron/+/815435 | 09:40 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: Increase openstack-tox-py38 timeout in gate https://review.opendev.org/c/openstack/neutron/+/816631 | 09:42 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: Increase openstack-tox-py38 and openstack-tox-py39 timeouts https://review.opendev.org/c/openstack/neutron/+/816631 | 09:45 |
slaweq | ralonsoh: can You check https://review.opendev.org/c/openstack/neutron/+/815235 ? thx in advance | 10:01 |
ralonsoh | sure | 10:01 |
slaweq | thx | 10:03 |
slaweq | and https://review.opendev.org/c/openstack/neutron/+/799439 also :) | 10:03 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Don't enforce scopes in the API policies UT temporary https://review.opendev.org/c/openstack/neutron/+/815838 | 10:10 |
opendevreview | Merged openstack/neutron master: Check quota limits https://review.opendev.org/c/openstack/neutron/+/801470 | 10:10 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Don't enforce scopes in the API policies UT temporary https://review.opendev.org/c/openstack/neutron/+/815838 | 10:10 |
slaweq | ralonsoh: and last one for now https://review.opendev.org/c/openstack/os-ken/+/813985 :) | 10:13 |
slaweq | it's the last not approved os-ken patch | 10:14 |
slaweq | sorry https://review.opendev.org/c/openstack/os-ken/+/815601 | 10:14 |
ralonsoh | yes hehehe | 10:14 |
ralonsoh | I saw it | 10:14 |
slaweq | when those 2 will be merged we can do new os-ken release with all things from ryu merged :) | 10:14 |
ralonsoh | so now we are in sync with ryu | 10:14 |
slaweq | with those 2 we should be :) | 10:15 |
jkulik | hi folks, quick question if this is a bug or somehow intenational: https://github.com/sapcc/neutron/commit/d0c172afa6ea38e94563afb4994471420b27cddf introduce updating the external port of a FIP with project_id, while https://github.com/openstack/neutron/blob/master/neutron/db/l3_db.py#L326 states that this is explicitly not set | 10:27 |
jkulik | this change makes floating ip ports count into quota | 10:27 |
*** lbragstad4 is now known as lbragstad | 10:33 | |
opendevreview | Merged openstack/neutron-tempest-plugin master: Increase "neutron-tempest-plugin-scenario-ovn" timeout to 3h https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816438 | 10:33 |
ralonsoh | jkulik, you are right, this is a corner case but this is adding the project ID to those ports | 10:36 |
ralonsoh | it is worth to, at least, open a LP bug | 10:36 |
*** lbragstad1 is now known as lbragstad | 10:43 | |
opendevreview | Lajos Katona proposed openstack/neutron master: Recheck irrelevant files https://review.opendev.org/c/openstack/neutron/+/816642 | 11:03 |
opendevreview | Lajos Katona proposed openstack/neutron master: Increase the timeout for arm64 jobs https://review.opendev.org/c/openstack/neutron/+/816621 | 11:06 |
*** lbragstad7 is now known as lbragstad | 11:07 | |
opendevreview | Merged openstack/os-ken master: add ofproto 1.3 coverage, check key-error and attribute-error. https://review.opendev.org/c/openstack/os-ken/+/813985 | 11:28 |
opendevreview | Merged openstack/os-ken master: Bump min eventlet version to 0.26.1 https://review.opendev.org/c/openstack/os-ken/+/815601 | 11:28 |
slaweq | lajoskatona: ralonsoh ^^ with those 2 patches merged, I will prepare release patch for os-ken now | 11:29 |
ralonsoh | slaweq, cool, send the releases patch link | 11:30 |
slaweq | ralonsoh: lajoskatona 7911ff1820b83bf1657c322c36ca68dcb5c0a846 | 11:31 |
slaweq | sorry https://review.opendev.org/c/openstack/releases/+/816646 | 11:32 |
slaweq | :) | 11:32 |
opendevreview | Merged openstack/neutron stable/xena: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816454 | 11:53 |
opendevreview | Merged openstack/neutron stable/wallaby: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816348 | 11:53 |
opendevreview | Merged openstack/neutron master: Add "FLAVOR_NAME" to ovn migration resources creation https://review.opendev.org/c/openstack/neutron/+/813972 | 11:53 |
lajoskatona | slaweq: thanks | 12:12 |
slaweq | lajoskatona: yw :) | 12:14 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/train: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816459 | 12:19 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/stein: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816470 | 12:19 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/rocky: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816471 | 12:19 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/queens: Don't setup bridge controller if it is already set https://review.opendev.org/c/openstack/neutron/+/816472 | 12:19 |
opendevreview | Merged openstack/neutron-lib master: Move RULE_TYPE_MINIMUM_PACKET_RATE to neutron-lib https://review.opendev.org/c/openstack/neutron-lib/+/816447 | 12:27 |
slaweq | ralonsoh: when You will have some time, please check jlibosva 's question in https://review.opendev.org/c/openstack/neutron/+/814181 | 12:31 |
ralonsoh | slaweq, let me check | 13:18 |
ralonsoh | slaweq, done | 13:24 |
slaweq | ralonsoh: I just replied to Your comment | 13:26 |
zigo | frickler: I believe we would continue to manually setup the BGP speakers in production, but it's still nice to have. | 13:35 |
opendevreview | Daniel Alvarez proposed openstack/neutron master: [ovn] Add timeout option to ovsdb-client command https://review.opendev.org/c/openstack/neutron/+/816698 | 13:37 |
dalvarez | jlibosva: otherwiseguy ^^ | 13:38 |
dalvarez | lucasagomes: ^im sorry you would prolly want to include this in your list of backports :p | 13:39 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: Bump OVN version for functional job to 21.06 https://review.opendev.org/c/openstack/neutron/+/816614 | 13:40 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: update ACL actions on stateful field change https://review.opendev.org/c/openstack/neutron/+/816600 | 13:40 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: enable stateless-security-group api https://review.opendev.org/c/openstack/neutron/+/816612 | 13:40 |
lucasagomes | dalvarez, nice, I will review but for backports I probably won't be around once it merges tho... The other patches are already backported | 13:40 |
lucasagomes | otherwiseguy, jlibosva maybe can take care of backporting it ? | 13:41 |
jlibosva | sure | 13:43 |
jlibosva | dalvarez: lucasagomes left a comment there | 13:43 |
lucasagomes | jlibosva++ | 13:44 |
opendevreview | Daniel Alvarez proposed openstack/neutron master: [ovn] Add timeout option to ovsdb-client command https://review.opendev.org/c/openstack/neutron/+/816698 | 13:51 |
dalvarez | jlibosva++ thanks done | 13:51 |
dalvarez | ralonsoh++ thanks done | 13:51 |
dalvarez | agh group is 'ovn' not 'ovs' | 13:52 |
opendevreview | Daniel Alvarez proposed openstack/neutron master: [ovn] Add timeout option to ovsdb-client command https://review.opendev.org/c/openstack/neutron/+/816698 | 13:55 |
ihrachys | any reason why we don't bump ovn / ovs in gate? | 13:56 |
ihrachys | I see some references to kernel incompatibility in zuul conf. still relevant? | 13:57 |
ralonsoh | jlibosva, ^ | 13:58 |
jlibosva | ihrachys: ralonsoh do you have a link that gives more details about the incompatibility? I'm all up for bumping the versions | 14:13 |
ralonsoh | jlibosva, I just pinged you because you added this comment in https://review.opendev.org/c/openstack/neutron/+/816614/2/zuul.d/base.yaml | 14:14 |
ralonsoh | # TODO(jlibosva): v2.13.1 is incompatible with kernel 4.15.0-118, sticking to commit hash until new v2.13 tag is created | 14:14 |
ralonsoh | but seems that https://zuul.opendev.org/t/openstack/status#816614 has correctly installed those new versions in the FT job | 14:16 |
ihrachys | we'll see if it passes. that's all I care really :) | 14:17 |
opendevreview | Merged openstack/neutron master: Deprecate 'allow_overlapping_ips' config option https://review.opendev.org/c/openstack/neutron/+/807848 | 14:20 |
opendevreview | Merged openstack/neutron master: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/799439 | 14:20 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron-tempest-plugin master: Add stateless security group test case https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/816613 | 14:21 |
opendevreview | Dr. Jens Harbott proposed openstack/neutron-dynamic-routing master: Add a StaticScheduler without automatic scheduling https://review.opendev.org/c/openstack/neutron-dynamic-routing/+/815265 | 14:22 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Add functional and fullstack jobs with FIPS enabled https://review.opendev.org/c/openstack/neutron/+/814009 | 14:26 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/xena: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/816658 | 14:30 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/wallaby: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/816659 | 14:30 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/victoria: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/816660 | 14:31 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/ussuri: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/816661 | 14:31 |
opendevreview | Slawek Kaplonski proposed openstack/neutron stable/train: [DVR] Fix update of the MTU in the DVR HA routers https://review.opendev.org/c/openstack/neutron/+/816662 | 14:31 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [OVN] Execute OVN migration transactions independently https://review.opendev.org/c/openstack/neutron/+/814181 | 14:42 |
opendevreview | Ghanshyam proposed openstack/neutron stable/train: [stable-only] Remove non-existing networking-midonet job https://review.opendev.org/c/openstack/neutron/+/816708 | 14:52 |
gmann | slaweq: lajoskatona ^^ seems zuul configuration error on stable/train, this fixing it. I found it when doing DNM testing patch there https://review.opendev.org/c/openstack/neutron/+/816597 | 14:53 |
gmann | I mean this is fix - https://review.opendev.org/c/openstack/neutron/+/814181 | 14:53 |
gmann | ahh, sorry, https://review.opendev.org/c/openstack/neutron/+/816708 | 14:53 |
opendevreview | Ghanshyam proposed openstack/neutron stable/train: DNM: test tempest train-last tag https://review.opendev.org/c/openstack/neutron/+/816597 | 14:53 |
slaweq | thx gmann :) | 14:54 |
lajoskatona | thanks gmann, good catch | 14:58 |
EugenMayer | what could be the cause that no matter what i do, the security groups have no effect at all. Adding now security groups at all will still allow connections on all ports, so the default for all instances seems to be INGRESS ALL ACCEPT. the default security group is not configured this way | 15:01 |
EugenMayer | This must have been happened out of a sudden - we had to add security groups for everything beforhand | 15:01 |
gmann | slaweq: may be you can cleanup this too https://github.com/openstack/neutron/blob/master/zuul.d/project.yaml#L35 | 15:02 |
lajoskatona | gmann: https://review.opendev.org/c/openstack/neutron/+/815466/2/zuul.d/project.yaml | 15:03 |
gmann | lajoskatona: ah nice, thanks | 15:15 |
EugenMayer | is it a known bug that in xena, you cannot add security groups when creating an instance and using a port? Neither from the cli, nor from the UI. Both offer it, but they will not save those | 15:23 |
opendevreview | Sebastian Lohff proposed openstack/neutron master: Do not set project_id for floating ip ports https://review.opendev.org/c/openstack/neutron/+/816722 | 16:21 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Use ovs constants from neutron-lib https://review.opendev.org/c/openstack/neutron/+/797120 | 16:36 |
slaweq | ralonsoh: lajoskatona mlavalle if You have some time, please check once again https://review.opendev.org/c/openstack/neutron/+/797120 - I addressed comments there and TBH I agree with obondarev's opinion there | 16:38 |
slaweq | I hope it will be fine for You too | 16:38 |
ralonsoh | sure | 16:38 |
lajoskatona | slaweq: ok | 16:38 |
slaweq | thx guys | 16:38 |
mlavalle | slaweq: yes, I will take a look | 16:38 |
slaweq | thx You too | 16:39 |
opendevreview | Balazs Gibizer proposed openstack/neutron master: Do not block qos for direct-physical ports https://review.opendev.org/c/openstack/neutron/+/815962 | 16:42 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: Bump OVN version for functional job to 21.06 https://review.opendev.org/c/openstack/neutron/+/816614 | 16:46 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: update ACL actions on stateful field change https://review.opendev.org/c/openstack/neutron/+/816600 | 16:46 |
opendevreview | Ihar Hrachyshka proposed openstack/neutron master: ovn: enable stateless-security-group api https://review.opendev.org/c/openstack/neutron/+/816612 | 16:46 |
opendevreview | Lajos Katona proposed openstack/neutron master: Document admin_state_up https://review.opendev.org/c/openstack/neutron/+/816725 | 17:10 |
opendevreview | Lajos Katona proposed openstack/neutron master: Increase the timeout for arm64 jobs https://review.opendev.org/c/openstack/neutron/+/816621 | 17:13 |
EugenMayer | is it a Xena (or always?) default that the default security group is ingress all ACCEPT? | 18:02 |
ihrachys | EugenMayer AFAIU only for members of the same group | 18:09 |
ihrachys | accept all for egress only | 18:09 |
EugenMayer | ihrachys wait so all servers, which are part of the default group having 'ingress accept all'? | 18:26 |
EugenMayer | sounds like this group fills up very fast and it really sound like an unusual default to me, thus the question | 18:26 |
ihrachys | afaiu all ports in a group have free for all | 18:27 |
ihrachys | see https://wiki.openstack.org/wiki/Neutron/SecurityGroups#Behavior | 18:28 |
ihrachys | wait, maybe I misreawd | 18:28 |
EugenMayer | "For the default security group a rule which allows intercommunication among hosts associated with the default security group is defined by default." | 18:29 |
ihrachys | yes, this part. sounds like "free for all" no? | 18:29 |
EugenMayer | i would say, you are right about that. | 18:29 |
EugenMayer | A little shocker to me, but well, good to know. Just means i want to redefine the default group. I guess there is no real setting for that so all project start with 'ingress ALL DROP' | 18:30 |
ihrachys | AFAIR default comes from aws that is mimicked by nova SG api, that comes pre-neutron: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/default-custom-security-groups.html#default-security-group | 18:30 |
EugenMayer | whatever, entirely not the philosophy i use firewalls with. But that might be just me | 18:31 |
ihrachys | openstack originally tried to mimic aws in network scope (not just network, compute too), and then expanded into more elaborate use cases. the roots were kept. | 18:32 |
EugenMayer | i see | 18:32 |
EugenMayer | is it somewhat 'by design' too, that if you create a port first, then create an instance assigning this port and at the same time, add security groups to that instance (in one go, in the API or in the GUI) - the security groups are simply not applied? | 18:34 |
EugenMayer | one can apply the security groups to the port beforehand and those are then applied to the instance. But when applying security groups via instance create, those are just dropped. Interestingly, you can just update the instance security updates after the creation, that works | 18:35 |
EugenMayer | when not using a port (while creating an instance), but rather a network (thus the port is created on the fly), applying security groups via the GUI and API works during creation | 18:36 |
opendevreview | Merged openstack/neutron master: Replace "tenant_id" with "project_id" in metering service https://review.opendev.org/c/openstack/neutron/+/814807 | 20:05 |
opendevreview | Merged openstack/neutron stable/victoria: Check a namespace existence by checking only its own directory https://review.opendev.org/c/openstack/neutron/+/816515 | 20:05 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Add functional and fullstack jobs with FIPS enabled https://review.opendev.org/c/openstack/neutron/+/814009 | 21:44 |
opendevreview | Merged openstack/neutron stable/wallaby: Check a namespace existence by checking only its own directory https://review.opendev.org/c/openstack/neutron/+/816513 | 22:34 |
opendevreview | Merged openstack/neutron-tempest-plugin master: [stable/{train,stein}] Use old guest image for these branches https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/815518 | 23:23 |
opendevreview | Merged openstack/neutron master: Use the DB object when listing the SG rules https://review.opendev.org/c/openstack/neutron/+/816373 | 23:30 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!