*** alex_klimov has quit IRC | 00:01 | |
*** salv-orlando has joined #openstack-security | 00:15 | |
*** salv-orlando has quit IRC | 00:19 | |
*** JAHoagie has quit IRC | 00:21 | |
*** hyakuhei1 has joined #openstack-security | 01:13 | |
*** hyakuhei has quit IRC | 01:14 | |
*** dave-mccowan has joined #openstack-security | 01:15 | |
*** nunbrs has quit IRC | 01:17 | |
*** sdake_ has quit IRC | 01:28 | |
*** browne has quit IRC | 01:29 | |
*** markvoelker has quit IRC | 01:30 | |
*** markvoelker_ has joined #openstack-security | 01:30 | |
*** hyakuhei1 has quit IRC | 01:47 | |
*** hyakuhei has joined #openstack-security | 01:48 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 01:50 | |
*** bpokorny has quit IRC | 02:23 | |
*** browne has joined #openstack-security | 02:29 | |
*** hyakuhei1 has joined #openstack-security | 02:33 | |
*** hyakuhei has quit IRC | 02:33 | |
*** salv-orlando has joined #openstack-security | 02:37 | |
*** salv-orlando has quit IRC | 02:42 | |
*** hyakuhei1 has quit IRC | 02:55 | |
*** hyakuhei has joined #openstack-security | 02:56 | |
*** hyakuhei has quit IRC | 03:03 | |
*** tmcpeak has quit IRC | 03:05 | |
*** hyakuhei has joined #openstack-security | 03:09 | |
*** hyakuhei1 has joined #openstack-security | 03:30 | |
*** hyakuhei has quit IRC | 03:30 | |
*** hyakuhei1 has quit IRC | 03:36 | |
*** hyakuhei has joined #openstack-security | 03:36 | |
*** dave-mccowan has quit IRC | 04:03 | |
*** bpokorny has joined #openstack-security | 04:18 | |
*** JAHoagie has joined #openstack-security | 04:26 | |
*** sdake has joined #openstack-security | 04:39 | |
*** hyakuhei1 has joined #openstack-security | 04:40 | |
*** hyakuhei has quit IRC | 04:40 | |
*** salv-orlando has joined #openstack-security | 04:42 | |
*** hyakuhei has joined #openstack-security | 04:46 | |
*** hyakuhei1 has quit IRC | 04:46 | |
*** openstackgerrit has quit IRC | 04:50 | |
*** openstackgerrit has joined #openstack-security | 04:50 | |
*** sdake_ has joined #openstack-security | 04:50 | |
*** salv-orlando has quit IRC | 04:53 | |
*** sdake has quit IRC | 04:54 | |
*** bpokorny has quit IRC | 04:56 | |
*** hyakuhei has quit IRC | 04:56 | |
*** hyakuhei has joined #openstack-security | 04:56 | |
*** salv-orlando has joined #openstack-security | 05:23 | |
*** JAHoagie has quit IRC | 05:33 | |
*** hyakuhei has quit IRC | 05:56 | |
*** hyakuhei1 has joined #openstack-security | 05:56 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/186266 | 06:01 |
---|---|---|
*** hyakuhei1 has quit IRC | 06:09 | |
*** hyakuhei has joined #openstack-security | 06:09 | |
*** hyakuhei has quit IRC | 06:32 | |
*** hyakuhei has joined #openstack-security | 06:32 | |
*** elmiko has quit IRC | 06:47 | |
openstackgerrit | Merged openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/186266 | 06:57 |
*** hyakuhei has quit IRC | 06:58 | |
*** salv-orlando has quit IRC | 07:00 | |
*** salv-orlando has joined #openstack-security | 07:00 | |
*** hyakuhei has joined #openstack-security | 07:01 | |
*** elmiko has joined #openstack-security | 07:16 | |
*** browne has quit IRC | 07:21 | |
*** alex_klimov has joined #openstack-security | 07:23 | |
*** hyakuhei1 has joined #openstack-security | 07:26 | |
*** hyakuhei has quit IRC | 07:26 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/186307 | 07:35 |
*** salv-orlando has quit IRC | 07:38 | |
*** alex_klimov has quit IRC | 08:04 | |
*** alex_klimov has joined #openstack-security | 08:10 | |
*** salv-orlando has joined #openstack-security | 08:39 | |
*** hyakuhei1 has quit IRC | 08:44 | |
*** salv-orlando has quit IRC | 08:45 | |
*** hyakuhei has joined #openstack-security | 08:45 | |
*** sdake has joined #openstack-security | 08:58 | |
*** sdake_ has quit IRC | 09:01 | |
*** sdake_ has joined #openstack-security | 09:04 | |
*** sdake has quit IRC | 09:07 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/186307 | 09:13 |
*** markvoelker_ has quit IRC | 09:16 | |
*** tmcpeak has joined #openstack-security | 10:07 | |
*** salv-orlando has joined #openstack-security | 10:10 | |
*** markvoelker has joined #openstack-security | 10:17 | |
*** markvoelker has quit IRC | 10:23 | |
*** timkennedy has quit IRC | 10:26 | |
*** timkennedy has joined #openstack-security | 10:27 | |
*** sdake_ has quit IRC | 10:38 | |
*** hyakuhei has quit IRC | 10:41 | |
*** hyakuhei has joined #openstack-security | 10:41 | |
*** salv-orlando has quit IRC | 11:12 | |
openstackgerrit | Merged stackforge/anchor: Updating config.json to be sha256 https://review.openstack.org/185179 | 11:13 |
*** openstackgerrit has quit IRC | 11:39 | |
*** openstackgerrit has joined #openstack-security | 11:39 | |
*** markvoelker has joined #openstack-security | 12:02 | |
*** salv-orlando has joined #openstack-security | 12:12 | |
*** dave-mccowan has joined #openstack-security | 12:23 | |
*** hyakuhei has quit IRC | 12:33 | |
*** hyakuhei has joined #openstack-security | 12:33 | |
*** salv-orlando has quit IRC | 13:11 | |
*** salv-orlando has joined #openstack-security | 13:11 | |
openstackgerrit | Merged openstack/security-doc: Updating Case Studies - Alice's Monitoring & Logging https://review.openstack.org/184104 | 13:14 |
*** bknudson has joined #openstack-security | 13:19 | |
*** nkinder has quit IRC | 13:21 | |
*** jamielennox is now known as jamielennox|away | 13:29 | |
*** singlethink has joined #openstack-security | 13:29 | |
openstackgerrit | Merged openstack/security-doc: Updating Case Studies - Alice's Instance Security Management section https://review.openstack.org/183607 | 13:45 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:02 | |
*** sdake has joined #openstack-security | 14:09 | |
*** sdake_ has joined #openstack-security | 14:10 | |
*** sdake has quit IRC | 14:14 | |
*** voodookid has joined #openstack-security | 14:25 | |
*** nkinder has joined #openstack-security | 14:28 | |
*** sdake has joined #openstack-security | 14:40 | |
*** sdake_ has quit IRC | 14:44 | |
*** dwyde has joined #openstack-security | 14:53 | |
*** sicarie has joined #openstack-security | 15:04 | |
*** bpokorny has joined #openstack-security | 15:22 | |
*** edmondsw has joined #openstack-security | 15:23 | |
*** browne has joined #openstack-security | 15:26 | |
*** hyakuhei has quit IRC | 15:49 | |
*** hyakuhei1 has joined #openstack-security | 15:49 | |
*** singlethink has quit IRC | 15:52 | |
*** sdake_ has joined #openstack-security | 15:58 | |
*** sdake has quit IRC | 15:59 | |
*** sdake has joined #openstack-security | 16:00 | |
*** hyakuhei1 is now known as hyakuhei | 16:03 | |
*** hyakuhei has quit IRC | 16:03 | |
*** hyakuhei has joined #openstack-security | 16:03 | |
*** sdake_ has quit IRC | 16:03 | |
*** tkelsey has joined #openstack-security | 16:04 | |
hyakuhei | I'm not going to be around for the full security meeting today. | 16:04 |
*** alex_klimov has quit IRC | 16:04 | |
nkinder | hyakuhei: Me either. I have a meeting that overlaps with it. Perhaps tmcpeak can run it... | 16:07 |
*** dwyde has quit IRC | 16:24 | |
*** singlethink has joined #openstack-security | 16:25 | |
tmcpeak | hyakuhei, nkinder: I can do it | 16:27 |
hyakuhei | thanks tmcpeak | 16:30 |
*** dwyde has joined #openstack-security | 16:46 | |
*** browne has quit IRC | 17:02 | |
*** pkarikh has joined #openstack-security | 17:08 | |
*** lhcheng has joined #openstack-security | 17:08 | |
*** pkarikh has quit IRC | 17:16 | |
*** dwyde has quit IRC | 17:16 | |
*** michaelxin has joined #openstack-security | 17:25 | |
*** dan has joined #openstack-security | 17:27 | |
*** dwyde has joined #openstack-security | 17:27 | |
*** sicarie_ has joined #openstack-security | 17:31 | |
*** sicarie has left #openstack-security | 17:31 | |
*** bpokorny has quit IRC | 17:31 | |
*** sdake_ has joined #openstack-security | 17:35 | |
*** browne has joined #openstack-security | 17:38 | |
*** sdake has quit IRC | 17:39 | |
*** salv-orlando has quit IRC | 17:43 | |
*** salv-orlando has joined #openstack-security | 17:47 | |
*** nkinder has quit IRC | 18:03 | |
tmcpeak | dstufft: ping | 18:06 |
*** sicarie_ is now known as sicarie | 18:07 | |
*** bknudson has quit IRC | 18:13 | |
*** bknudson has joined #openstack-security | 18:18 | |
dstufft | tmcpeak: pong | 18:18 |
tmcpeak | dstufft: yo yo, check PM por favor | 18:18 |
*** lhcheng has left #openstack-security | 18:18 | |
dstufft | tmcpeak: hm, don't see anything | 18:19 |
tmcpeak | ahh ok I'll send again | 18:19 |
*** nkinder has joined #openstack-security | 18:24 | |
*** pkarikh has joined #openstack-security | 18:27 | |
*** bpokorny has joined #openstack-security | 18:32 | |
*** tkelsey has quit IRC | 18:33 | |
pkarikh | tristanC: hello! | 18:36 |
*** edmondsw has quit IRC | 18:43 | |
*** browne has quit IRC | 18:45 | |
*** nkinder has quit IRC | 18:49 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Updating Case Studies - Alice's Compliance Section https://review.openstack.org/184112 | 18:52 |
*** pkarikh has quit IRC | 19:00 | |
*** nkinder has joined #openstack-security | 19:01 | |
sigmavirus24 | sicarie: thanks for filing the bug | 19:08 |
sicarie | np | 19:08 |
tmcpeak | sicarie: awesome! | 19:09 |
sicarie | I figure if someone can follow the directions to disable the fw, they should be able to follow directions to open the proper ports | 19:09 |
sicarie | I'm going to have to take an action to add a ufw ruleset to Ubuntu installs for the sec guide | 19:10 |
elmiko | makes me wonder if we should provide an openstack.xml service file for firewalld based distros? | 19:10 |
openstackgerrit | Merged openstack/security-doc: Updating Case Studies - Alice's Compliance Section https://review.openstack.org/184112 | 19:18 |
*** sdake has joined #openstack-security | 19:26 | |
*** sdake_ has quit IRC | 19:29 | |
misc | elmiko: it would be helpful and likely make the life of sysadmin easier IMHO | 19:34 |
misc | ( at least mine ) | 19:34 |
elmiko | cool, i'll look at sicarie's change and hopefully follow suit | 19:40 |
sicarie | +1 though that also makes me nervous about what else is in the install/ops/admin guides... | 19:40 |
elmiko | yea, we might have to add it to the reading list | 19:40 |
elmiko | s/it/them/ | 19:40 |
sicarie | misc: how do you handle fw rulesets now? I'm trying to think of the easiest and most secure way to do this - something like "fw_hypervisor.xml: iptables rules allowing nova and mgmt communication" | 19:43 |
*** kutija has joined #openstack-security | 19:43 | |
sicarie | and then "fw_swift.xml: iptables rules for..." | 19:44 |
* sicarie runs off to check his swift cheatsheet | 19:46 | |
misc | sicarie: that's mostly dropping a xml file in /usr/lib/firewalld/services/ | 19:46 |
*** tkelsey has joined #openstack-security | 19:46 | |
misc | and use firewall-cmd | 19:46 |
sicarie | tcp 8080 for api/backup, allowing scp/rsync, container updates over 6001/6002 | 19:47 |
sicarie | ok, yeah, would probably have to do two sets for firewalld/iptables | 19:47 |
misc | I kinda like that because it make my ansible script idempotent by default | 19:47 |
misc | while for iptables, everybody do their own stuff, so there isn't much sharing possible | 19:47 |
sicarie | Yeah, and the networks probably aren't going to be standard, which will be fun | 19:48 |
sicarie | misc: thanks, I'll try to take a look at that! | 19:48 |
elmiko | would be nice if we maintain a set of firewalld services files, and engage the individual projects to review them | 19:49 |
* sicarie volun-scripts elmiko | 19:49 | |
elmiko | hehe, i'll add it to the backlog ;) | 19:50 |
sicarie | Right! | 19:50 |
elmiko | is this something we could maintain in the security-doc repo and link into the document? | 19:51 |
*** tkelsey has quit IRC | 19:51 | |
elmiko | or would there be a better repo for it | 19:51 |
sicarie | elmiko: good question - I think where the security-doc repo will live is an open question | 19:52 |
sicarie | I know the docs team isn't claiming it, and I think there's another security repo that this may eventually fall under, but i'm not 100% sure | 19:53 |
elmiko | ok, cool. i'll leave it up for research then | 19:53 |
sicarie | yeah, I think that's for hyakuhei to determine now that we're an official project | 19:54 |
elmiko | sounds good | 19:54 |
*** nkinder has quit IRC | 19:59 | |
*** singleth_ has joined #openstack-security | 20:00 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Updating Case Studies - Alice's API Endpoints Section https://review.openstack.org/186552 | 20:00 |
*** singlethink has quit IRC | 20:03 | |
*** kutija has quit IRC | 20:05 | |
sicarie | tmcpeak sigmavirus24: bug closed as "wont fix" | 20:16 |
sicarie | "Based on much prior discussion, the installation guide aims to install OpenStack in the easiest way possible for first-time users, not deploy a production environment. If you want to enable the firewall, the documentation includes a list of ports for each service" | 20:16 |
elmiko | i guess that makes sense | 20:16 |
sigmavirus24 | Yeah that's vaguely what I expected | 20:17 |
sicarie | I'll open another to at least have those ports referenced at that point in the guide | 20:19 |
*** browne has joined #openstack-security | 20:20 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Updating Case Studies - Alice's API Endpoints Section https://review.openstack.org/186552 | 20:23 |
*** kutija has joined #openstack-security | 20:24 | |
*** sdake_ has joined #openstack-security | 20:26 | |
*** sdake has quit IRC | 20:30 | |
tmcpeak | sicarie: bummer :( | 20:44 |
*** sdake_ has quit IRC | 20:47 | |
*** sdake has joined #openstack-security | 20:49 | |
*** salv-orlando has quit IRC | 20:49 | |
*** michaelxin has quit IRC | 21:01 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Update Compute Chapter - Introduction https://review.openstack.org/186563 | 21:05 |
*** dave-mccowan has quit IRC | 21:07 | |
openstackgerrit | Merged openstack/security-doc: Updating Case Studies - Alice's API Endpoints Section https://review.openstack.org/186552 | 21:08 |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Update Compute Chapter - Introduction https://review.openstack.org/186563 | 21:09 |
*** sdake_ has joined #openstack-security | 21:11 | |
*** sdake has quit IRC | 21:14 | |
*** hyakuhei has quit IRC | 21:22 | |
*** hyakuhei has joined #openstack-security | 21:23 | |
*** jamielennox|away is now known as jamielennox | 21:34 | |
*** openstackgerrit has quit IRC | 21:36 | |
*** openstackgerrit has joined #openstack-security | 21:36 | |
*** salv-orlando has joined #openstack-security | 21:50 | |
*** alex_klimov has joined #openstack-security | 21:51 | |
*** salv-orlando has quit IRC | 21:55 | |
*** sdake has joined #openstack-security | 21:59 | |
*** sdake_ has quit IRC | 22:03 | |
*** dwyde has quit IRC | 22:11 | |
*** salv-orlando has joined #openstack-security | 22:15 | |
*** nkinder has joined #openstack-security | 22:17 | |
*** singlethink has joined #openstack-security | 22:22 | |
*** sdake_ has joined #openstack-security | 22:23 | |
*** singleth_ has quit IRC | 22:24 | |
*** sdake has quit IRC | 22:27 | |
*** Guest82474 has joined #openstack-security | 22:40 | |
*** Guest82474 has quit IRC | 22:40 | |
*** barra204 has joined #openstack-security | 22:43 | |
*** bknudson has quit IRC | 22:45 | |
*** singlethink has quit IRC | 22:48 | |
*** voodookid has quit IRC | 22:51 | |
*** sicarie has left #openstack-security | 22:54 | |
*** barra204 has quit IRC | 23:01 | |
*** barra204 has joined #openstack-security | 23:15 | |
*** salv-orlando has quit IRC | 23:30 | |
*** alex_klimov has quit IRC | 23:41 | |
*** tkelsey has joined #openstack-security | 23:49 | |
*** tkelsey has quit IRC | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!