*** dasm|afk is now known as dasm | 00:20 | |
opendevreview | Pedro Henrique Pereira Martins proposed openstack/neutron master: Extend database to support portforwardings with port range https://review.opendev.org/c/openstack/neutron/+/798961 | 01:03 |
---|---|---|
opendevreview | liuyulong proposed openstack/neutron master: [Doc] packet rete limit user workflow and notes https://review.opendev.org/c/openstack/neutron/+/828673 | 02:36 |
opendevreview | liuyulong proposed openstack/neutron master: Add policy for packet rate limit rules https://review.opendev.org/c/openstack/neutron/+/829161 | 02:36 |
opendevreview | liuyulong proposed openstack/neutron master: Meter flows and ovsdb action for ovs bridge https://review.opendev.org/c/openstack/neutron/+/816800 | 02:36 |
opendevreview | liuyulong proposed openstack/neutron master: Support pps limitation for openvswitch agent https://review.opendev.org/c/openstack/neutron/+/816802 | 02:36 |
opendevreview | liuyulong proposed openstack/neutron master: Fullstack tests of packet rate limit for ovs qos driver https://review.opendev.org/c/openstack/neutron/+/819418 | 02:36 |
opendevreview | yangjianfeng proposed openstack/neutron master: [docs] L3 router support ndp proxy https://review.opendev.org/c/openstack/neutron/+/822253 | 02:58 |
opendevreview | liuyulong proposed openstack/neutron master: Meter flows and ovsdb action for ovs bridge https://review.opendev.org/c/openstack/neutron/+/816800 | 05:15 |
opendevreview | liuyulong proposed openstack/neutron master: Support pps limitation for openvswitch agent https://review.opendev.org/c/openstack/neutron/+/816802 | 05:15 |
opendevreview | liuyulong proposed openstack/neutron master: Fullstack tests of packet rate limit for ovs qos driver https://review.opendev.org/c/openstack/neutron/+/819418 | 05:15 |
opendevreview | Luis Tomas Bolivar proposed openstack/neutron stable/yoga: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/neutron/+/833730 | 08:05 |
opendevreview | Luis Tomas Bolivar proposed openstack/neutron stable/xena: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/neutron/+/833731 | 08:06 |
opendevreview | Luis Tomas Bolivar proposed openstack/neutron stable/wallaby: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/neutron/+/833732 | 08:07 |
opendevreview | Luis Tomas Bolivar proposed openstack/neutron stable/victoria: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/neutron/+/833733 | 08:08 |
opendevreview | Luis Tomas Bolivar proposed openstack/neutron stable/ussuri: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/neutron/+/833734 | 08:10 |
opendevreview | Luis Tomas Bolivar proposed openstack/networking-ovn stable/train: Ensure no GARPs are sent for Load Balancer VIPs on tenant networks https://review.opendev.org/c/openstack/networking-ovn/+/833728 | 08:23 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [OVN] Remove maintenance "check_for_igmp_snoop_support" https://review.opendev.org/c/openstack/neutron/+/833655 | 08:50 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [OVN] Remove maintenance "check_for_fragmentation_support" https://review.opendev.org/c/openstack/neutron/+/833656 | 08:51 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [OVN] Remove maintenance "check_metadata_ports" https://review.opendev.org/c/openstack/neutron/+/833657 | 08:53 |
ralonsoh | folks, if you have time to review these patches | 08:58 |
ralonsoh | https://review.opendev.org/c/openstack/neutron/+/833377 | 08:58 |
ralonsoh | https://review.opendev.org/c/openstack/neutron/+/827683 | 08:58 |
ralonsoh | thanks! | 08:58 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [QoS][L3] Use floating IP OVO QoS fields https://review.opendev.org/c/openstack/neutron/+/833667 | 09:14 |
opendevreview | Merged openstack/neutron master: Use python3-devel in bindep for rpm distros https://review.opendev.org/c/openstack/neutron/+/833101 | 10:16 |
opendevreview | Merged openstack/neutron master: Open Zed DB branch https://review.opendev.org/c/openstack/neutron/+/833377 | 11:06 |
opendevreview | Rodolfo Alonso proposed openstack/neutron master: [DNM] [WIP] Refactor the DB contexts https://review.opendev.org/c/openstack/neutron/+/833247 | 11:09 |
opendevreview | yatin proposed openstack/neutron master: [OVN][port-forwarding] Add lb also to logical_switches https://review.opendev.org/c/openstack/neutron/+/833620 | 11:11 |
opendevreview | Merged openstack/ovn-octavia-provider master: Retry logical switch associations to load balancers https://review.opendev.org/c/openstack/ovn-octavia-provider/+/829126 | 11:21 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Fix ingress bandwidth limit in the openvswitch agent https://review.opendev.org/c/openstack/neutron/+/832662 | 11:43 |
slaweq | ralonsoh: when You will have some time, please check ^^ | 11:44 |
slaweq | thx in advance :) | 11:44 |
ralonsoh | sure | 11:44 |
slaweq | thx | 11:54 |
opendevreview | Pedro Henrique Pereira Martins proposed openstack/neutron master: Extend database to support portforwardings with port range https://review.opendev.org/c/openstack/neutron/+/798961 | 12:10 |
opendevreview | yatin proposed openstack/neutron master: Update tox-override template with py38 jobs https://review.opendev.org/c/openstack/neutron/+/833779 | 13:12 |
ykarel | ralonsoh, slaweq ^ was missed with zed template switch | 13:13 |
ykarel | i noticed when tox-py38 job timedout with 42 minutes | 13:13 |
opendevreview | yatin proposed openstack/neutron master: [OVN][port-forwarding] Add lb also to logical_switches https://review.opendev.org/c/openstack/neutron/+/833620 | 13:15 |
opendevreview | Lajos Katona proposed openstack/neutron master: Add grenade-skip-level (tick-tick) job https://review.opendev.org/c/openstack/neutron/+/833080 | 13:46 |
lajoskatona | #startmeeting networking | 14:00 |
opendevmeet | Meeting started Tue Mar 15 14:00:22 2022 UTC and is due to finish in 60 minutes. The chair is lajoskatona. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
opendevmeet | The meeting name has been set to 'networking' | 14:00 |
lajoskatona | Hi | 14:00 |
mlavalle | o/ | 14:00 |
ralonsoh | hi | 14:00 |
obondarev | hi | 14:00 |
amotoki | hi | 14:00 |
isabek | Hi | 14:00 |
slaweq | Hi | 14:01 |
lajoskatona | We can start as I see | 14:02 |
lajoskatona | #topic Announcements | 14:02 |
lajoskatona | For one of the last times Yoga cycle calendar https://releases.openstack.org/yoga/schedule.html | 14:02 |
lajoskatona | We have a release countdown mail from elod: R-2: http://lists.openstack.org/pipermail/openstack-discuss/2022-March/027679.html | 14:03 |
lajoskatona | what is interesting that RC1 is out (20.0.0.0rc1 for Neutron) | 14:03 |
lajoskatona | we have Yoga branch, and all the fancy things for the release, great work everybody :-) | 14:04 |
ralonsoh | congrats! | 14:05 |
mlavalle | ++ | 14:05 |
obondarev | cool! | 14:05 |
slaweq | Yay! | 14:06 |
lajoskatona | We can check if wee need an RC2 | 14:06 |
slaweq | Btw do we have any potential patches for RC2? | 14:06 |
lajoskatona | I remember this one: https://review.opendev.org/c/openstack/neutron/+/832662 (Fix ingress bandwidth limit in the openvswitch agent ) | 14:07 |
lajoskatona | but not sure if we really need to have RC2 for it | 14:07 |
slaweq | I don't think so | 14:08 |
slaweq | We can backport it later probably | 14:08 |
lajoskatona | ok, | 14:08 |
lajoskatona | We have ~1 week for it | 14:09 |
slaweq | Ok | 14:11 |
lajoskatona | The Zed schedule: https://releases.openstack.org/zed/schedule.html | 14:11 |
lajoskatona | And the Zed PTG etherpad: https://etherpad.opendev.org/p/neutron-zed-ptg | 14:11 |
lajoskatona | We have the Grizzly room from 13:00 - 16:00 UTC Monday-thursday | 14:12 |
lajoskatona | and 14:00-16:00 UTC for Friday | 14:12 |
slaweq | Thursday and Friday neutron sessions overlaps with TC sessions so I will probably be not available | 14:13 |
slaweq | Or not all time at least | 14:13 |
slaweq | And on Monday there is TC and PTLs session too | 14:14 |
lajoskatona | slaweq: ok, | 14:14 |
lajoskatona | the TC - PTL session will be on Monday | 14:14 |
lajoskatona | slaweq: ok, than I have good note for it :-) | 14:14 |
lajoskatona | so please add your topics to the etherpad | 14:15 |
lajoskatona | If there's no more question forr announcements, we can jump to the next topic | 14:17 |
lajoskatona | #topic Bugs | 14:17 |
lajoskatona | Report from amotoki: http://lists.openstack.org/pipermail/openstack-discuss/2022-March/027708.html | 14:17 |
lajoskatona | I saw one bug which needs attention: | 14:18 |
lajoskatona | [OVN Octavia Provider] OVN provider tests using too old version of OVN (#link https://bugs.launchpad.net/neutron/+bug/1964339 ) | 14:18 |
lajoskatona | amotoki: do you have something to highlight | 14:18 |
lajoskatona | ? | 14:18 |
amotoki | regarding the bug lajoskatona mentioned, looking at some recent job results, local.conf seems not to be confiugred properly. | 14:19 |
amotoki | it might be related to a gate configuration. | 14:19 |
*** jlibosva is now known as Guest2218 | 14:19 | |
amotoki | hopefully ovn-octavia-folks can look into it. | 14:20 |
ralonsoh | amotoki, I'll ping Luis | 14:20 |
amotoki | ralonsoh: thanks | 14:20 |
lajoskatona | ralonsoh, amotoki: thanks | 14:20 |
amotoki | I also added "rfe" tags to two bugs. they needs discussions for enhancements. | 14:21 |
lajoskatona | amotoki: thanks, I will add them to the drivers meeting agenda for Friday | 14:21 |
amotoki | that's all from me. | 14:22 |
lajoskatona | amotokig: thanks again | 14:22 |
lajoskatona | This week mlavalle is the deputy, and next week rubasov will be. | 14:22 |
mlavalle | on it, my fearless leader! | 14:22 |
lajoskatona | mlavalle: :-) | 14:23 |
lajoskatona | ok, next topic | 14:23 |
lajoskatona | liuyulong, liuyulong_: do you have something for L3 perhaps? | 14:24 |
mlavalle | he just dropped off | 14:26 |
lajoskatona | ok, it seems liuyulong has some network issues | 14:26 |
lajoskatona | We can move on then | 14:27 |
liuyulong_ | We have L3 ndp merged. | 14:27 |
liuyulong_ | #link https://review.opendev.org/q/topic:bug%252F1877301 | 14:27 |
liuyulong_ | The rest of the code can continue to move forward now. | 14:28 |
lajoskatona | liuyulong_: good news | 14:28 |
liuyulong_ | #link https://review.opendev.org/c/openstack/neutron-specs/+/832660 I add this RA "speaker" spec for ovs agent, a simple solution, please take a look, if you guys interest. | 14:29 |
liuyulong_ | an alternative for radvd. | 14:30 |
lajoskatona | liuyulong_: sure, I will check it | 14:31 |
liuyulong_ | Last one, the feature of port range for port forwarding https://review.opendev.org/c/openstack/neutron/+/798961 | 14:31 |
liuyulong_ | A really big patch which mixed the server side and agent side works. | 14:32 |
opendevreview | Lucas Alvares Gomes proposed openstack/ovn-octavia-provider master: Fix zuul templates for functional tests https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833798 | 14:32 |
liuyulong_ | This is very useful, since our customers are creating tons of port forwarding entries under one router, because it is 1-1 pair now. | 14:33 |
lajoskatona | liuyulong_: thanks for bringing it here, I will check it, but it is indeed huge patch | 14:33 |
liuyulong_ | OK, then, no more from me now. | 14:34 |
lajoskatona | liuyulong_: thanks | 14:34 |
lajoskatona | #topic On Demand Agenda | 14:35 |
lajoskatona | I added one topic but I just chekced and I think it will be short dicussion | 14:35 |
lajoskatona | (lajoskatona): tick-tick upgrade / grenade-skip-level jobs: | 14:35 |
lajoskatona | mail from Dan: http://lists.openstack.org/pipermail/openstack-discuss/2022-March/027639.html | 14:35 |
*** liuyulong_ is now known as liuyulong | 14:36 | |
lajoskatona | the base of this is the new release cadence resolution (#link https://governance.openstack.org/tc/resolutions/20220210-release-cadence-adjustment.html ) | 14:36 |
lajoskatona | which allows operators to upgrade to every second release (that is tick I think) | 14:37 |
slaweq | yes | 14:37 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider master: Fix deletion of members without subnet_id https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833799 | 14:37 |
ralonsoh | so everything must be compatible with version-2 ? | 14:37 |
lajoskatona | but we as community keep the middle releases also maintained (tock releases) and keep the upgrade working from tock to tick release also | 14:37 |
ralonsoh | not as is now, that should be version - 1? | 14:37 |
amotoki | yes for "tick" releases | 14:38 |
ralonsoh | understood | 14:38 |
lajoskatona | ralonsoh: yes, so for example there questions to keep RPC compatibility for N-2 | 14:38 |
opendevreview | Lucas Alvares Gomes proposed openstack/ovn-octavia-provider master: Fix zuul templates for functional tests https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833798 | 14:38 |
opendevreview | Luis Tomas Bolivar proposed openstack/ovn-octavia-provider master: Make release job use more up-to-date ovn/ovs branches https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833800 | 14:38 |
slaweq | ralonsoh: if You are asking e.g. about RPC compatibility, then no | 14:38 |
slaweq | it still can be just N to N-1 | 14:38 |
slaweq | tick-tick don't need to be live upgrade, according to the TC resolution | 14:39 |
lajoskatona | slaweq: ok, I thought that we go for N-2 RPC compatiblity | 14:39 |
amotoki | the resolution does not necessarily cover live upgrade from N-2 to N but perhaps it is nice to have. | 14:39 |
ralonsoh | ok, I think we'll get used to this | 14:39 |
slaweq | please check https://governance.openstack.org/tc/resolutions/20220210-release-cadence-adjustment.html#details and point 6 | 14:39 |
frickler | it would be nice to support that still, even if TC doesn't require it, yes | 14:39 |
slaweq | yes, but that's not hard requirement | 14:40 |
lajoskatona | The AA release will be the first tick if I understand well | 14:40 |
frickler | it's the only thing that would make the whole effort worthwhile for a project like kolla without having to invent a new deployment type | 14:40 |
lajoskatona | so the whole thing in hard requirements will have to work first between AA and CC (whatever these will be) am I right? | 14:41 |
slaweq | lajoskatona: yes, that's my understanding too | 14:42 |
amotoki | According to the resolution, Y -> AA upgrade will be supported as experimental | 14:42 |
lajoskatona | so if we start testing it now we can have few releases to decide on these and fix it if there is a community agreement on it | 14:42 |
lajoskatona | amotoki: yes, this is why we start the testing with grenade | 14:43 |
lajoskatona | but it is more a test time , am I understand it correctly? | 14:43 |
amotoki | perhaps we need one more grenade job. | 14:44 |
lajoskatona | slaweq and I started to add it: https://review.opendev.org/c/openstack/neutron/+/833080 | 14:45 |
lajoskatona | one for ovs and one for OVN | 14:45 |
lajoskatona | In the patch i added ovs job to periodic and OVN to experimental (as current grenade ovn also in experimental) | 14:45 |
lajoskatona | the ovs upgrade works ( checked it as experimental: https://zuul.opendev.org/t/openstack/build/b71ebe5826f64492a47c2a6e7feed31a | 14:46 |
lajoskatona | but OVN fails: https://zuul.opendev.org/t/openstack/build/8314af7d9257424da71c8ddf3eba7a4d | 14:47 |
slaweq | I think that OVN grenade jobs are broken for long time | 14:48 |
slaweq | and it's not related to the tick-tock upgrades probably | 14:48 |
lajoskatona | slaweq: true, the "simple" grenade also failed | 14:48 |
lajoskatona | I am not sure as OVN is the default in devstack, isn't that something that cross this community goal? | 14:49 |
ralonsoh | it should, I think | 14:50 |
lajoskatona | ralonsoh: ok, so it is something that we have to focus on, perhaps even discuss during the PTG | 14:51 |
slaweq | I think that when we were switching devstack's default we changed grenade jobs to explicitly use ml2/ovs | 14:51 |
slaweq | and we never came back to update it | 14:51 |
slaweq | but I may be wrong here, it should be checked | 14:51 |
lajoskatona | slaweq: ok, thanks, I will check history :-) | 14:52 |
slaweq | ++ | 14:52 |
frickler | having a job testing ovs => ovn migration would also be nice, btw | 14:52 |
lajoskatona | ok, thanks, that's it from me | 14:52 |
ralonsoh | frickler, that's not trivial | 14:52 |
slaweq | frickler: but currently such migration is only supported for the tripleo based deployment | 14:52 |
lajoskatona | jlibosva presented it during the last PTG | 14:52 |
ralonsoh | we have templates for tripleo | 14:53 |
slaweq | not in devstack | 14:53 |
lajoskatona | I will add this topic to the PTG etherpad | 14:53 |
frickler | would be really nice to also support the rest of the world | 14:53 |
frickler | ack | 14:54 |
mlavalle1 | Good idea | 14:54 |
lajoskatona | If there is nothing more to discuss, we can close the meeting | 14:54 |
lajoskatona | #endmeeting | 14:56 |
opendevmeet | Meeting ended Tue Mar 15 14:56:01 2022 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:56 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/networking/2022/networking.2022-03-15-14.00.html | 14:56 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/networking/2022/networking.2022-03-15-14.00.txt | 14:56 |
opendevmeet | Log: https://meetings.opendev.org/meetings/networking/2022/networking.2022-03-15-14.00.log.html | 14:56 |
lajoskatona | Bye | 14:56 |
mlavalle1 | o/ | 14:56 |
amotoki | o/ | 14:56 |
ralonsoh | bye | 14:56 |
slaweq | o/ | 14:56 |
lajoskatona | slaweq: I can't participate today's CI meeting (sorry for late notice) | 14:56 |
slaweq | lajoskatona: sure, thx for the heads up | 14:56 |
slaweq | I think it will be low attendence meeting today | 14:57 |
obondarev | me either, sorry | 14:57 |
slaweq | ok, thx obondarev | 14:57 |
slaweq | #startmeeting neutron_ci | 15:00 |
opendevmeet | Meeting started Tue Mar 15 15:00:35 2022 UTC and is due to finish in 60 minutes. The chair is slaweq. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
opendevmeet | The meeting name has been set to 'neutron_ci' | 15:00 |
slaweq | ralonsoh: ykarel anyone else who wants to join ci meeting, it's video meeting today | 15:00 |
slaweq | #link https://meetpad.opendev.org/neutron-ci-meetings | 15:01 |
ralonsoh | slaweq, thanks! | 15:01 |
ykarel | o/ | 15:01 |
ralonsoh | slaweq, but I have another video meeting now | 15:01 |
slaweq | ralonsoh: ok | 15:01 |
ralonsoh | slaweq, I can help in IRC, if needed | 15:01 |
slaweq | ykarel: ralonsoh wdyt if we cancel this meeting today? | 15:02 |
ralonsoh | ykarel, why? | 15:02 |
ralonsoh | slaweq, ? | 15:02 |
slaweq | there isn't anything very urgent really on the agenda and attendance is seems to be very low | 15:02 |
ralonsoh | ah ok, no problem for me | 15:02 |
ralonsoh | sorry for that | 15:03 |
ykarel | ok from my side | 15:03 |
slaweq | so I'm not sure if there's really need to do it today | 15:03 |
slaweq | no problem at all ralonsoh | 15:03 |
slaweq | it's fine | 15:03 |
slaweq | ok, let's move our video meeting for next week simply | 15:03 |
ralonsoh | perfect | 15:03 |
slaweq | and cancel it today | 15:03 |
slaweq | #endmeeting | 15:03 |
opendevmeet | Meeting ended Tue Mar 15 15:03:45 2022 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:03 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/neutron_ci/2022/neutron_ci.2022-03-15-15.00.html | 15:03 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/neutron_ci/2022/neutron_ci.2022-03-15-15.00.txt | 15:03 |
opendevmeet | Log: https://meetings.opendev.org/meetings/neutron_ci/2022/neutron_ci.2022-03-15-15.00.log.html | 15:03 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider master: Fix deletion of members without subnet_id https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833799 | 15:16 |
opendevreview | Rodolfo Alonso proposed openstack/ovn-octavia-provider master: Fix zuul templates for functional tests https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833798 | 15:40 |
opendevreview | Merged openstack/neutron master: Run configure_for_func_testing script after enable fips https://review.opendev.org/c/openstack/neutron/+/833177 | 15:42 |
opendevreview | Merged openstack/neutron master: Enable sctp module in the fullstack Centos node https://review.opendev.org/c/openstack/neutron/+/833258 | 15:42 |
opendevreview | Merged openstack/neutron master: Support filtering for QoS rule type list https://review.opendev.org/c/openstack/neutron/+/827683 | 15:42 |
mlavalle | slaweq: so didn't miss the meeting after all :-) | 15:57 |
slaweq | mlavalle: yes, almost everyone had to leave today or had different meeting | 15:58 |
slaweq | so we cancelled it :) | 15:58 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider stable/yoga: Retry logical switch associations to load balancers https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833872 | 16:07 |
opendevreview | Merged openstack/neutron master: Update tox-override template with py38 jobs https://review.opendev.org/c/openstack/neutron/+/833779 | 16:11 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider stable/wallaby: Retry logical switch associations to load balancers https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833882 | 16:54 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider stable/victoria: Retry logical switch associations to load balancers https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833884 | 16:58 |
opendevreview | Fernando Royo proposed openstack/ovn-octavia-provider stable/xena: Retry logical switch associations to load balancers https://review.opendev.org/c/openstack/ovn-octavia-provider/+/833885 | 16:59 |
opendevreview | Terry Wilson proposed openstack/networking-ovn stable/train: [OVN] Do not fail when processing SG rule deletion https://review.opendev.org/c/openstack/networking-ovn/+/833890 | 17:36 |
hyang[m] | Hi team, I'm facing some issue when using the latest Neutron (OVS firewall) with VIP supporting L3DSR. In L3DSR (https://github.com/yahoo/l3dsr/blob/master/docs/nanog51.pdf) the server (VM) will respond to the client directly, the server will also update the response packet's source IP to the VIP's IP. After configuring the VIP's IP as additional allowed-address-pair of the port, I found the packet is still dropped at hypervisor | 18:58 |
hyang[m] | unless I disable the port-security. Can someone please help to shed some light on how to resolve it? Or is the behavior of modifying the source IP of the response packet will never work for Neutron's openflow rules? Thanks! | 18:58 |
frickler | hyang[m]: I'm not sure about the details right now, but you need stateless firewall rules for that, while the default is stateful | 19:31 |
frickler | (the default with OVS firewall) we solved it some time age by reverting to iptables_hybrid, but iirc there is an option for stateless with OVS now | 19:32 |
hyang[m] | frickler: ah the stateless SG is something I've not explored yet but sounds promising, I'll give it a try. Thanks for your info! | 19:35 |
opendevreview | Slawek Kaplonski proposed openstack/neutron master: Fix ingress bandwidth limit in the openvswitch agent https://review.opendev.org/c/openstack/neutron/+/832662 | 19:54 |
hyang[m] | frickler: after some searching I found the stateless SG is not supported in the current OVS firewall yet https://bugs.launchpad.net/neutron/+bug/1885261 and based on the previous meeting notes it sounds like adding the support won't be some trivial work and we may need a new driver for it. | 20:48 |
*** dasm is now known as dasm|off | 21:41 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!