*** yee379 has left #openstack-operators | 00:01 | |
*** Apoorva has quit IRC | 00:03 | |
*** markvoelker has joined #openstack-operators | 00:13 | |
*** zul has quit IRC | 00:14 | |
*** piet has quit IRC | 00:34 | |
*** saneax is now known as saneax-_-|AFK | 00:34 | |
*** wasmum has joined #openstack-operators | 00:37 | |
*** dtrainor has joined #openstack-operators | 00:44 | |
*** dtrainor has quit IRC | 00:52 | |
*** dtrainor has joined #openstack-operators | 00:53 | |
*** simon-AS559 has joined #openstack-operators | 00:56 | |
*** kenhui has joined #openstack-operators | 00:59 | |
*** kenhui has quit IRC | 00:59 | |
*** simon-AS559 has quit IRC | 01:00 | |
*** jamesdenton has quit IRC | 01:07 | |
*** jamesdenton has joined #openstack-operators | 01:08 | |
*** Apoorva has joined #openstack-operators | 01:14 | |
*** jamesdenton has quit IRC | 01:25 | |
*** Apoorva has quit IRC | 01:45 | |
*** piet has joined #openstack-operators | 01:46 | |
*** karad has quit IRC | 02:01 | |
*** karad has joined #openstack-operators | 02:04 | |
*** julian1 has quit IRC | 02:26 | |
*** chlong has joined #openstack-operators | 02:26 | |
*** julian1 has joined #openstack-operators | 02:27 | |
*** clayton has quit IRC | 02:32 | |
*** clayton has joined #openstack-operators | 02:33 | |
*** mriedem has quit IRC | 02:46 | |
*** piet has quit IRC | 02:51 | |
*** piet has joined #openstack-operators | 02:57 | |
*** fragatina has quit IRC | 03:03 | |
*** Apoorva has joined #openstack-operators | 03:21 | |
*** armax has quit IRC | 03:24 | |
*** stanchan has joined #openstack-operators | 03:35 | |
*** sudipto has joined #openstack-operators | 03:47 | |
*** sudipto_ has joined #openstack-operators | 03:47 | |
*** karad has quit IRC | 03:56 | |
*** piet has quit IRC | 04:10 | |
*** fragatina has joined #openstack-operators | 04:26 | |
*** zul has joined #openstack-operators | 04:27 | |
*** fragatina has quit IRC | 04:30 | |
*** VW has joined #openstack-operators | 04:31 | |
*** VW has quit IRC | 04:35 | |
*** Apoorva has quit IRC | 04:58 | |
*** furlongm_ is now known as furlongm | 05:01 | |
*** zul has quit IRC | 05:13 | |
*** zul has joined #openstack-operators | 05:23 | |
*** simon-AS559 has joined #openstack-operators | 05:29 | |
*** chlong_ has joined #openstack-operators | 05:31 | |
*** zul has quit IRC | 05:38 | |
*** lbrune has joined #openstack-operators | 05:53 | |
*** saneax-_-|AFK is now known as saneax | 06:00 | |
*** pcaruana has joined #openstack-operators | 06:23 | |
*** simon-AS559 has joined #openstack-operators | 06:39 | |
*** beddari has quit IRC | 06:45 | |
*** admin0 has joined #openstack-operators | 06:58 | |
*** beddari has joined #openstack-operators | 07:01 | |
*** tesseract- has joined #openstack-operators | 07:07 | |
*** jsheeren has joined #openstack-operators | 07:10 | |
*** matrohon has joined #openstack-operators | 07:12 | |
*** chlong has quit IRC | 07:19 | |
*** chlong_ has quit IRC | 07:19 | |
*** hieulq has quit IRC | 07:27 | |
*** hieulq has joined #openstack-operators | 07:28 | |
*** lbrune has quit IRC | 07:29 | |
*** bvandenh has joined #openstack-operators | 07:32 | |
*** lbrune has joined #openstack-operators | 08:01 | |
*** derekh has joined #openstack-operators | 08:05 | |
*** cgross has quit IRC | 08:09 | |
*** lmiccini_ has joined #openstack-operators | 08:09 | |
*** lmiccini has quit IRC | 08:10 | |
*** cgross has joined #openstack-operators | 08:12 | |
*** snecklifter has joined #openstack-operators | 08:19 | |
*** lmiccini_ is now known as lmiccini | 08:23 | |
*** lutzb has joined #openstack-operators | 08:43 | |
*** ptrlv has quit IRC | 08:46 | |
*** stanchan has quit IRC | 09:11 | |
*** bvandenh_ has joined #openstack-operators | 09:20 | |
*** bvandenh__ has joined #openstack-operators | 09:23 | |
*** bvandenh has quit IRC | 09:24 | |
*** bvandenh_ has quit IRC | 09:25 | |
*** bvandenh has joined #openstack-operators | 09:30 | |
*** bvandenh__ has quit IRC | 09:31 | |
*** Guest52040 has joined #openstack-operators | 09:56 | |
*** lbrune has quit IRC | 10:06 | |
*** hieulq has quit IRC | 10:06 | |
*** cdelatte has joined #openstack-operators | 10:58 | |
*** karad has joined #openstack-operators | 11:15 | |
*** snecklifter has left #openstack-operators | 11:42 | |
*** bvandenh_ has joined #openstack-operators | 11:45 | |
*** bvandenh has quit IRC | 11:48 | |
*** bvandenh_ has quit IRC | 11:50 | |
*** kenhui has joined #openstack-operators | 11:53 | |
*** mriedem has joined #openstack-operators | 12:26 | |
*** VW has joined #openstack-operators | 12:27 | |
*** dminer has joined #openstack-operators | 12:36 | |
*** VW has quit IRC | 12:40 | |
*** VW has joined #openstack-operators | 12:41 | |
*** VW has quit IRC | 12:45 | |
*** kenhui has quit IRC | 13:13 | |
*** mriedem has quit IRC | 13:20 | |
*** mriedem has joined #openstack-operators | 13:22 | |
*** mriedem has quit IRC | 13:26 | |
*** VW has joined #openstack-operators | 13:32 | |
*** VW has quit IRC | 13:32 | |
*** VW has joined #openstack-operators | 13:32 | |
*** Guest52040 has quit IRC | 13:40 | |
*** dansmith is now known as superdan | 13:50 | |
*** alaski is now known as lascii | 13:54 | |
*** hj-hpe has joined #openstack-operators | 13:56 | |
*** mriedem has joined #openstack-operators | 13:59 | |
*** fragatina has joined #openstack-operators | 14:01 | |
*** mriedem1 has joined #openstack-operators | 14:03 | |
*** mriedem has quit IRC | 14:04 | |
*** dminer has quit IRC | 14:04 | |
*** fragatina has quit IRC | 14:06 | |
*** mriedem1 is now known as mriedem | 14:06 | |
*** zul has joined #openstack-operators | 14:16 | |
*** mperazol has joined #openstack-operators | 14:28 | |
*** ducttape_ has joined #openstack-operators | 14:41 | |
*** sudipto has quit IRC | 14:49 | |
*** sudipto_ has quit IRC | 14:49 | |
*** zul has quit IRC | 14:51 | |
*** dtrainor has quit IRC | 14:51 | |
*** dtrainor has joined #openstack-operators | 14:51 | |
*** mperazol_ has joined #openstack-operators | 14:53 | |
*** karad has quit IRC | 14:53 | |
*** mperazol has quit IRC | 14:56 | |
*** rarcea has joined #openstack-operators | 14:59 | |
*** matrohon has quit IRC | 14:59 | |
*** kenhui has joined #openstack-operators | 15:00 | |
*** armax has joined #openstack-operators | 15:02 | |
*** pcaruana has quit IRC | 15:08 | |
*** wasmum has quit IRC | 15:10 | |
*** karad has joined #openstack-operators | 15:19 | |
*** jsheeren has quit IRC | 15:26 | |
*** admin0 has quit IRC | 15:27 | |
*** kenhui has quit IRC | 15:44 | |
*** openstackgerrit has quit IRC | 15:49 | |
*** tesseract- has quit IRC | 15:49 | |
*** openstackgerrit has joined #openstack-operators | 15:49 | |
*** mperazol_ has quit IRC | 15:52 | |
*** zul has joined #openstack-operators | 15:52 | |
*** mperazol has joined #openstack-operators | 16:01 | |
*** VW has quit IRC | 16:19 | |
*** VW has joined #openstack-operators | 16:19 | |
*** sudipto has joined #openstack-operators | 16:20 | |
*** sudipto_ has joined #openstack-operators | 16:20 | |
*** VW has quit IRC | 16:20 | |
*** VW has joined #openstack-operators | 16:20 | |
*** lmiccini has quit IRC | 16:21 | |
*** cgross has quit IRC | 16:22 | |
*** VW has quit IRC | 16:24 | |
*** esker has joined #openstack-operators | 16:31 | |
*** fragatina has joined #openstack-operators | 16:32 | |
*** VW has joined #openstack-operators | 16:33 | |
*** sudipto has quit IRC | 16:35 | |
*** sudipto_ has quit IRC | 16:35 | |
*** VW has quit IRC | 16:38 | |
*** krobzaur has joined #openstack-operators | 16:39 | |
*** cgross has joined #openstack-operators | 16:44 | |
*** lmiccini has joined #openstack-operators | 16:47 | |
*** pilgrimstack has quit IRC | 16:48 | |
*** kenhui has joined #openstack-operators | 16:51 | |
*** markd_ has quit IRC | 16:53 | |
*** derekh has quit IRC | 16:54 | |
simon-AS559 | I spent most of today working on OSSN-0069 https://wiki.openstack.org/wiki/OSSN/OSSN-0069 | 16:54 |
---|---|---|
jlk | I feel like this is a thing we discovered and changed a long time ago | 16:55 |
simon-AS559 | Tried on some instances (that were started under Kilo), and found that I could indeed talk to the hypervisor from the instance using IPv6 LL | 16:55 |
simon-AS559 | Yes, it is fixed in Liberty and above. | 16:55 |
jlk | oh right, Dustin Lundquist. He's old Blue Box | 16:55 |
jlk | you know, a date somewhere on an OSSN would be great | 16:56 |
simon-AS559 | We run Liberty now, but as I said, we still have instances that was started pre-Liberty where the issue can be exploited. | 16:56 |
simon-AS559 | True about the date! The announcement was sent yesterday (8 September) to some openstack mailing lists | 16:57 |
simon-AS559 | (not -operators though) | 16:57 |
simon-AS559 | The "Recommended Actions" section leaves to be desired. | 16:58 |
simon-AS559 | I certainly cannot disable IPv6 globally on *all* interfaces in our installation. | 16:59 |
simon-AS559 | For example, all our RBD access is over IPv6. | 16:59 |
simon-AS559 | When you have the fixed code installed (for example because you have recent Liberty packages or better), new instances are safe... | 17:00 |
simon-AS559 | …and old instances can be made safe by live-migration | 17:00 |
*** VW has joined #openstack-operators | 17:00 | |
simon-AS559 | …or you can manually disable IPv6 on the *RELEVANT* interfaces | 17:00 |
jlk | so what we do is disable ipv6 by default, and then only enable ipv6 on the interfaces where we need ipv6 | 17:01 |
jlk | we turn ipv6 into a whitelist rather than a blacklist | 17:01 |
jlk | The original bug was discovered and filed back in January. | 17:01 |
simon-AS559 | Yes | 17:01 |
simon-AS559 | As I said, I'm scared of turning off IPv6 by default. | 17:02 |
simon-AS559 | How/where do I need to turn it on again? | 17:02 |
simon-AS559 | This seems operationally risky. | 17:02 |
simon-AS559 | If people tell me that the disable_ipv6 is ignored whenever you specify IPv6 addresses (or "ipv6 dhcp") in /etc/network/interfaces, then OK. | 17:03 |
simon-AS559 | The code change is nice—make sure that IPv6 gets disabled on these funny bridge interfaces… | 17:03 |
simon-AS559 | There's even a Kilo backport, though it hasn't appeared in packages yet, at least not in Ubuntu Cloud Archive. | 17:04 |
*** VW has quit IRC | 17:05 | |
simon-AS559 | Kilo backport: https://review.openstack.org/#/c/296659 | 17:05 |
*** markd_ has joined #openstack-operators | 17:05 | |
*** lubirkhahn has joined #openstack-operators | 17:05 | |
jlk | Dustin can explain it better, but at least on Ubuntu there is a fairly easy way to define that a specific interface should have ipv6 on it | 17:06 |
*** vinsh has joined #openstack-operators | 17:09 | |
*** lutzb has quit IRC | 17:10 | |
*** lubirkhahn has quit IRC | 17:10 | |
*** ckonstanski has joined #openstack-operators | 17:12 | |
*** VW has joined #openstack-operators | 17:15 | |
*** zul has quit IRC | 17:15 | |
*** zul has joined #openstack-operators | 17:16 | |
*** albertom has quit IRC | 17:17 | |
simon-AS559 | jlk; Thanks. I really wish there would have been some guidance in the "Recommended Actions" section. | 17:18 |
simon-AS559 | As it is, it is completely useless for us "IPv6 should remain disabled for each interface". | 17:19 |
simon-AS559 | It should remain disabled on the internal interfaces to tenant networks, but in our case it MUST NOT be disabled on the actual interfaces. | 17:19 |
simon-AS559 | Personally I tend towards the following approach: | 17:20 |
simon-AS559 | If you have Liberty or better, you are fine. | 17:21 |
simon-AS559 | If you have Kilo, install the backported patch! | 17:21 |
simon-AS559 | Then for instances that were created before the fix, either live-migrate each of them | 17:21 |
simon-AS559 | or run the following one-liner on each compute node (lightly tested, use at your own risk etc.) | 17:22 |
simon-AS559 | $ for x in `grep -l 0 /proc/sys/net/ipv6/conf/{qbr,qvo,qvb,tap}*/disable_ipv6`; do d=`dirname $x`; b=`basename $d`; echo 1 | sudo tee $x >/dev/null && echo "Disabled IPv6 on $b"; done | 17:22 |
simon-AS559 | (Review welcome) | 17:22 |
simon-AS559 | Probably you'd want to do something similar on the network node, but I'm not sure exactly (what). | 17:22 |
*** VW has quit IRC | 17:24 | |
*** albertom has joined #openstack-operators | 17:25 | |
simon-AS559 | The goal should be that "ip -6 addr list" looks somewhat similar to "ip -4 addr list" (not the addresses, but the set of interfaces *with* addresses) | 17:26 |
simon-AS559 | (heading home now) | 17:26 |
*** simon-AS559 has quit IRC | 17:27 | |
klindgren | yea the mitigation in that announcement is sorely lacking | 17:30 |
*** VW has joined #openstack-operators | 17:32 | |
*** fragatina has quit IRC | 17:39 | |
*** admin0 has joined #openstack-operators | 17:40 | |
*** fragatina has joined #openstack-operators | 17:43 | |
*** VW has quit IRC | 17:46 | |
*** fragatina has quit IRC | 17:48 | |
*** kenhui has quit IRC | 17:59 | |
*** simon-AS559 has joined #openstack-operators | 17:59 | |
*** kenhui has joined #openstack-operators | 18:00 | |
*** mperazol has quit IRC | 18:00 | |
*** VW has joined #openstack-operators | 18:05 | |
*** dalees has quit IRC | 18:06 | |
*** kenhui1 has joined #openstack-operators | 18:07 | |
*** kenhui has quit IRC | 18:07 | |
*** rarcea has quit IRC | 18:11 | |
*** esker is now known as esker[away] | 18:19 | |
*** admin0 has quit IRC | 18:19 | |
*** mperazol has joined #openstack-operators | 18:32 | |
*** fragatina has joined #openstack-operators | 18:34 | |
*** fragatina has quit IRC | 18:34 | |
*** fragatina has joined #openstack-operators | 18:34 | |
*** zul has quit IRC | 18:44 | |
*** esker[away] is now known as esker | 18:47 | |
*** esker has quit IRC | 18:55 | |
*** admin0 has joined #openstack-operators | 18:59 | |
*** zul has joined #openstack-operators | 19:00 | |
*** vinsh has quit IRC | 19:01 | |
*** VW has quit IRC | 19:17 | |
*** VW has joined #openstack-operators | 19:18 | |
*** dminer has joined #openstack-operators | 19:19 | |
*** vijaykc4 has joined #openstack-operators | 19:20 | |
*** cgross has quit IRC | 19:22 | |
*** lmiccini has quit IRC | 19:22 | |
*** VW has quit IRC | 19:22 | |
*** vijaykc4 has quit IRC | 19:31 | |
*** vijaykc4 has joined #openstack-operators | 19:33 | |
*** VW has joined #openstack-operators | 19:41 | |
*** vijaykc4 has quit IRC | 19:42 | |
*** admin0 has quit IRC | 19:43 | |
*** VW has quit IRC | 19:45 | |
*** admin0 has joined #openstack-operators | 19:48 | |
*** vijaykc4 has joined #openstack-operators | 19:49 | |
*** vijaykc4 has quit IRC | 19:52 | |
*** saneax is now known as saneax-_-|AFK | 19:54 | |
*** VW has joined #openstack-operators | 19:55 | |
*** cdelatte has quit IRC | 19:56 | |
*** VW has quit IRC | 19:59 | |
*** ducttape_ has quit IRC | 20:03 | |
*** VW has joined #openstack-operators | 20:09 | |
*** zul has quit IRC | 20:10 | |
*** zul has joined #openstack-operators | 20:10 | |
*** VW has quit IRC | 20:14 | |
*** kenhui1 has quit IRC | 20:16 | |
*** VW has joined #openstack-operators | 20:23 | |
*** superdan is now known as dansmith | 20:27 | |
*** kenhui has joined #openstack-operators | 20:30 | |
*** lmiccini has joined #openstack-operators | 20:39 | |
*** rmcall has quit IRC | 20:39 | |
*** cgross has joined #openstack-operators | 20:40 | |
*** rmcall has joined #openstack-operators | 20:40 | |
*** esker has joined #openstack-operators | 20:41 | |
*** albertom is now known as albertom_afk | 20:47 | |
*** lascii is now known as alaski | 21:04 | |
*** spiette has quit IRC | 21:20 | |
*** admin0 has quit IRC | 21:28 | |
*** simon-AS559 has quit IRC | 21:29 | |
*** kenhui has quit IRC | 21:34 | |
*** wasmum has joined #openstack-operators | 21:39 | |
*** krobzaur has quit IRC | 21:55 | |
*** esker has quit IRC | 21:59 | |
*** mriedem has quit IRC | 22:11 | |
*** VW_ has joined #openstack-operators | 22:29 | |
*** VW has quit IRC | 22:32 | |
*** VW_ has quit IRC | 22:33 | |
*** ckonstanski has quit IRC | 22:33 | |
*** VW has joined #openstack-operators | 22:58 | |
*** VW has quit IRC | 23:02 | |
*** dminer has quit IRC | 23:05 | |
*** mperazol has quit IRC | 23:11 | |
*** armax has quit IRC | 23:20 | |
*** esker has joined #openstack-operators | 23:28 | |
*** zul has quit IRC | 23:33 | |
*** armax has joined #openstack-operators | 23:44 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!