*** elo has quit IRC | 00:00 | |
*** salv-orl_ has quit IRC | 00:03 | |
*** markvoelker has joined #openstack-security | 00:15 | |
*** zul has joined #openstack-security | 00:16 | |
*** markvoelker has quit IRC | 00:21 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:32 | |
*** tmcpeak has quit IRC | 00:43 | |
*** salv-orlando has joined #openstack-security | 01:11 | |
openstackgerrit | KATO Tomoyuki proposed openstack/security-doc: Remove XML entity reference 'mdash' https://review.openstack.org/212234 | 01:14 |
---|---|---|
*** salv-orlando has quit IRC | 01:18 | |
*** tkelsey has joined #openstack-security | 01:36 | |
*** tkelsey has quit IRC | 01:40 | |
*** bpokorny has quit IRC | 01:50 | |
*** markvoelker has joined #openstack-security | 02:05 | |
*** salv-orl_ has joined #openstack-security | 02:23 | |
*** salv-orl_ has quit IRC | 02:31 | |
*** elmiko has quit IRC | 02:53 | |
*** elmiko has joined #openstack-security | 02:55 | |
*** jian5397 has joined #openstack-security | 03:06 | |
*** salv-orlando has joined #openstack-security | 03:33 | |
*** jian5397 has quit IRC | 03:39 | |
*** salv-orlando has quit IRC | 03:45 | |
*** dave-mccowan has quit IRC | 03:46 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Remove Liberty as documented target https://review.openstack.org/212310 | 04:31 |
*** salv-orlando has joined #openstack-security | 04:47 | |
openstackgerrit | Merged openstack/security-doc: Cleanup tox.ini https://review.openstack.org/212127 | 04:55 |
*** salv-orlando has quit IRC | 04:59 | |
*** tkelsey has joined #openstack-security | 05:37 | |
*** markvoelker has quit IRC | 05:41 | |
*** tkelsey has quit IRC | 05:41 | |
*** tjt263 has joined #openstack-security | 05:43 | |
*** yaya has joined #openstack-security | 05:46 | |
*** yaya has quit IRC | 06:00 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/212354 | 06:03 |
*** salv-orlando has joined #openstack-security | 06:04 | |
*** sdake has quit IRC | 06:07 | |
*** shohel has joined #openstack-security | 06:12 | |
*** salv-orlando has quit IRC | 06:13 | |
openstackgerrit | Merged openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/212354 | 06:26 |
*** shohel has quit IRC | 06:33 | |
*** shohel has joined #openstack-security | 06:33 | |
*** markvoelker has joined #openstack-security | 06:41 | |
*** markvoelker has quit IRC | 06:46 | |
*** salv-orlando has joined #openstack-security | 07:11 | |
*** browne has quit IRC | 07:20 | |
*** alex_klimov has joined #openstack-security | 07:40 | |
*** openstackgerrit has quit IRC | 07:41 | |
*** openstackgerrit has joined #openstack-security | 07:42 | |
*** shohel has quit IRC | 07:45 | |
*** openstackgerrit has quit IRC | 07:45 | |
*** shohel has joined #openstack-security | 07:45 | |
*** openstackgerrit has joined #openstack-security | 08:00 | |
*** tkelsey has joined #openstack-security | 08:19 | |
*** markvoelker has joined #openstack-security | 08:43 | |
*** markvoelker has quit IRC | 08:47 | |
openstackgerrit | Merged openstack/anchor: Stop mixing IPs and domains https://review.openstack.org/209867 | 09:13 |
*** jmckind_ has joined #openstack-security | 09:17 | |
*** jmckind has quit IRC | 09:19 | |
*** tkelsey has quit IRC | 10:18 | |
*** markvoelker has joined #openstack-security | 10:43 | |
*** markvoelker has quit IRC | 10:48 | |
*** shohel1 has joined #openstack-security | 11:02 | |
*** shohel has quit IRC | 11:02 | |
*** markvoelker has joined #openstack-security | 11:44 | |
*** markvoelker has quit IRC | 11:49 | |
*** markvoelker has joined #openstack-security | 11:53 | |
*** dave-mccowan has joined #openstack-security | 12:00 | |
*** shohel1 has quit IRC | 12:03 | |
*** sdake has joined #openstack-security | 12:53 | |
*** sdake_ has joined #openstack-security | 12:54 | |
*** sdake has quit IRC | 12:57 | |
*** tjt263 has quit IRC | 12:59 | |
*** openstackgerrit has quit IRC | 13:01 | |
*** openstackgerrit has joined #openstack-security | 13:01 | |
*** tmcpeak has joined #openstack-security | 13:04 | |
*** edmondsw has joined #openstack-security | 13:05 | |
*** shohel has joined #openstack-security | 13:20 | |
*** bebech has joined #openstack-security | 13:24 | |
*** elo has joined #openstack-security | 13:26 | |
*** bebech has quit IRC | 13:27 | |
*** browne has joined #openstack-security | 13:30 | |
*** singlethink has joined #openstack-security | 13:31 | |
*** singleth_ has joined #openstack-security | 13:40 | |
*** singlethink has quit IRC | 13:43 | |
*** jmckind_ has quit IRC | 13:49 | |
*** jmckind has joined #openstack-security | 14:02 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:10 | |
*** jian5397 has joined #openstack-security | 14:27 | |
*** tjt263 has joined #openstack-security | 14:33 | |
*** voodookid has joined #openstack-security | 14:43 | |
*** tjt263 has quit IRC | 14:50 | |
*** jmckind has quit IRC | 14:50 | |
*** sdake_ is now known as sdake | 14:56 | |
*** elo has quit IRC | 14:59 | |
*** singlethink has joined #openstack-security | 15:07 | |
*** singleth_ has quit IRC | 15:08 | |
*** dwyde has joined #openstack-security | 15:09 | |
*** bpokorny has joined #openstack-security | 15:11 | |
*** tjt263 has joined #openstack-security | 15:21 | |
*** tjt263 has quit IRC | 15:39 | |
*** sdake_ has joined #openstack-security | 15:54 | |
*** singleth_ has joined #openstack-security | 15:55 | |
*** sdake has quit IRC | 15:58 | |
*** singlethink has quit IRC | 15:58 | |
*** edmondsw has quit IRC | 16:06 | |
*** bknudson has joined #openstack-security | 16:15 | |
*** alejandrito has joined #openstack-security | 16:22 | |
*** edmondsw has joined #openstack-security | 16:30 | |
*** openstackgerrit has quit IRC | 16:31 | |
*** openstackgerrit has joined #openstack-security | 16:31 | |
*** alex_klimov has quit IRC | 16:32 | |
*** shohel has quit IRC | 16:36 | |
*** sdake has joined #openstack-security | 16:42 | |
*** sicarie has joined #openstack-security | 16:45 | |
*** jamielennox is now known as jamielennox|away | 16:45 | |
*** sdake_ has quit IRC | 16:45 | |
*** browne has quit IRC | 16:54 | |
*** jian5397 is now known as michaelxin | 16:54 | |
*** dwyde has quit IRC | 17:00 | |
*** tkelsey has joined #openstack-security | 17:08 | |
*** sdake_ has joined #openstack-security | 17:29 | |
*** sdake has quit IRC | 17:32 | |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: change to app_support file heading https://review.openstack.org/212672 | 17:34 |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: small changes to compliance rst files https://review.openstack.org/212674 | 17:36 |
alejandrito | Hi guys, just one existence question. suppose im a public cloud provider, how can i handle the amazon like "public address" assigment taking into account that "floating IP" has an internal ip addres space, so, what are the best practices to do a floatingIP -> public internet address, like for example take advantage of my few public ips, but using une public to, for example, redirect traffic to specific tenants floating I | 17:41 |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Add README for common-rst https://review.openstack.org/212677 | 17:41 |
alejandrito | PS. any experience on this ? | 17:41 |
*** browne has joined #openstack-security | 17:42 | |
tmcpeak | alejandrito sounds like you want a router that's got a public facing IP of the public IP you're using and then hooked up into the floating IP space | 17:46 |
tmcpeak | I'm just blowing smoke though, I've never done this | 17:46 |
*** dwyde has joined #openstack-security | 17:46 | |
tmcpeak | seems like a reasonable approach | 17:46 |
elmiko | +1, no direct experience here either, but that seems like a reasonable approach | 17:47 |
openstackgerrit | Merged openstack/security-doc: small changes to compliance rst files https://review.openstack.org/212674 | 17:47 |
alejandrito | tmcpeak, something like that, but ... suppose i just have 10 public ips, and 100's floatings, how public clouds to to take advantage of "fewer publics than floatings" redirection ? | 17:49 |
tmcpeak | I'd think a load balancer can handle something like that | 17:49 |
elmiko | hmm, how would you associate the outside public IP with the private IP though, the use would still need some identifier to make the link happen. unless you are doing it by login name or something? | 17:50 |
elmiko | s/use/user | 17:50 |
tmcpeak | elmiko: yeah, that's true | 17:52 |
elmiko | would be much easier if the user was able to have a domain name that the router could then associate with an internal address | 17:53 |
tmcpeak | unless it sent traffic for that public IP to all attached backends, which dooesn't sound great | 17:53 |
elmiko | yea... | 17:53 |
elmiko | i'm thinking if you have a domain like foobar.com, and then could hand out user1.foobar.com through user1000.foobar.com, you could load balance at the router and make the jump from public IP to private | 17:54 |
tmcpeak | elmiko: +1 | 17:54 |
*** salv-orl_ has joined #openstack-security | 17:55 | |
*** salv-orlando has quit IRC | 17:59 | |
*** salv-orl_ has quit IRC | 18:01 | |
*** salv-orl_ has joined #openstack-security | 18:01 | |
*** bpokorny_ has joined #openstack-security | 18:02 | |
*** salv-orl_ has quit IRC | 18:04 | |
*** salv-orl_ has joined #openstack-security | 18:05 | |
*** bpokorny has quit IRC | 18:05 | |
*** bpokorny_ has quit IRC | 18:08 | |
*** jmckind has joined #openstack-security | 18:09 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Update .gitignore https://review.openstack.org/212685 | 18:09 |
*** salv-orlando has joined #openstack-security | 18:10 | |
elmiko | alejandrito: was any of that useful for you? | 18:10 |
*** salv-orl_ has quit IRC | 18:12 | |
alejandrito | elmiko, makes lots of sense, so this would be for example | 18:19 |
alejandrito | elmiko, user10.foobar.com:80 -> LOADBALANCER/FIREWALL -> floatingip:80 | 18:20 |
elmiko | yea, i would imagine so, as the LB/FW component would know the requested hostname and could perform the translation | 18:21 |
tmcpeak | +1 | 18:21 |
elmiko | you would just need to write the middleware that would allow some easy sync up between users requesting new machines, and plumbing together all the pieces | 18:21 |
tmcpeak | DNSaaS does that, does it not? | 18:22 |
alejandrito | tmcpeak, elmiko amazing, your information its just GOLD! | 18:24 |
alejandrito | tmcpeak, elmiko thanks so much | 18:24 |
tmcpeak | sure :) | 18:24 |
elmiko | tmcpeak: i think so, but i am by no means a designate expert ;) | 18:25 |
elmiko | alejandrito: sure thing, glad to help | 18:25 |
*** bpokorny has joined #openstack-security | 18:29 | |
*** tkelsey has quit IRC | 18:31 | |
openstackgerrit | Merged openstack/security-doc: Update .gitignore https://review.openstack.org/212685 | 18:35 |
*** salv-orlando has quit IRC | 18:39 | |
*** nkinder has joined #openstack-security | 18:49 | |
*** nkinder has quit IRC | 18:50 | |
*** bapalm_ is now known as bapalm | 19:07 | |
*** sdake has joined #openstack-security | 19:09 | |
*** sdake_ has quit IRC | 19:12 | |
*** salv-orlando has joined #openstack-security | 19:31 | |
*** singleth_ has quit IRC | 19:31 | |
*** singlethink has joined #openstack-security | 19:33 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Add README for common-rst https://review.openstack.org/212677 | 19:35 |
*** salv-orlando has quit IRC | 19:36 | |
*** jmckind has quit IRC | 19:38 | |
*** alejandrito has quit IRC | 19:44 | |
openstackgerrit | Merged openstack/security-doc: Add README for common-rst https://review.openstack.org/212677 | 19:47 |
*** salv-orlando has joined #openstack-security | 19:50 | |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: minor change to cookie rst file https://review.openstack.org/212722 | 19:52 |
openstackgerrit | Merged openstack/security-doc: minor change to cookie rst file https://review.openstack.org/212722 | 20:02 |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: change to system-documents rst file https://review.openstack.org/212731 | 20:04 |
elmiko | tmcpeak: looks like i've got approval for the mid-cycle \o/ | 20:04 |
tmcpeak | elmiko: sweet!!! | 20:04 |
elmiko | we have a link for agenda item suggestions? | 20:05 |
elmiko | or just the etherpad | 20:05 |
*** jmckind has joined #openstack-security | 20:08 | |
tmcpeak | elmiko: just etherpad | 20:08 |
elmiko | tmcpeak: ok cool, i'm being asked to bring a few topics. hopefully they'll make the cut | 20:09 |
tmcpeak | elmiko: sure, I can take a look at them if you want or you can just roll them on site :) | 20:09 |
elmiko | tmcpeak: well, i guess given the format of the pad, i have a few topics i could present on that are issues we are experiencing and perhaps it could be the foundation for a discussion about possible solutions? | 20:10 |
tmcpeak | elmiko: cool, sounds good | 20:11 |
elmiko | they are mainly related to control plane <-> tenant plane comms | 20:11 |
tmcpeak | ahh cool, sounds like it could be a good discussion | 20:11 |
elmiko | ok, i'll put something up and list myself as the leader | 20:11 |
tmcpeak | elmiko: cool, sounds good | 20:11 |
elmiko | thanks! | 20:11 |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: change to checklist rst file https://review.openstack.org/212735 | 20:15 |
*** jmckind has quit IRC | 20:17 | |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: small change to federated keystone rst https://review.openstack.org/212746 | 20:17 |
openstackgerrit | Merged openstack/security-doc: change to system-documents rst file https://review.openstack.org/212731 | 20:21 |
*** tkelsey has joined #openstack-security | 20:24 | |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: fix spelling in security-services-for-instances https://review.openstack.org/212776 | 20:25 |
openstackgerrit | Merged openstack/security-doc: change to checklist rst file https://review.openstack.org/212735 | 20:25 |
*** alejandrito has joined #openstack-security | 20:28 | |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: changes to inro to OpenStack rst https://review.openstack.org/212777 | 20:31 |
*** sdake_ has joined #openstack-security | 20:32 | |
openstackgerrit | Merged openstack/security-doc: small change to federated keystone rst https://review.openstack.org/212746 | 20:32 |
*** sdake has quit IRC | 20:36 | |
*** HERMANA has joined #openstack-security | 20:41 | |
*** tkelsey has quit IRC | 20:44 | |
*** HERMANA has quit IRC | 20:46 | |
openstackgerrit | Merged openstack/security-doc: changes to inro to OpenStack rst https://review.openstack.org/212777 | 20:54 |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: change to security-boundaries and threats https://review.openstack.org/212785 | 20:56 |
openstackgerrit | Shilla Saebi proposed openstack/security-doc: made small change to case-studies rst file https://review.openstack.org/212787 | 21:02 |
openstackgerrit | Merged openstack/security-doc: change to security-boundaries and threats https://review.openstack.org/212785 | 21:07 |
*** alex_klimov has joined #openstack-security | 21:19 | |
*** tkelsey has joined #openstack-security | 21:27 | |
*** alex_klimov has quit IRC | 21:27 | |
*** tkelsey has quit IRC | 21:31 | |
*** jmckind has joined #openstack-security | 21:37 | |
*** michaelxin has quit IRC | 21:37 | |
*** alejandrito has quit IRC | 21:41 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:46 | |
*** jmckind has quit IRC | 21:50 | |
*** webhat has quit IRC | 22:05 | |
*** webhat has joined #openstack-security | 22:06 | |
*** sdake has joined #openstack-security | 22:12 | |
*** sdake_ has quit IRC | 22:16 | |
*** dwyde has quit IRC | 22:24 | |
*** jamielennox|away is now known as jamielennox | 22:33 | |
*** tjt263 has joined #openstack-security | 22:34 | |
*** sdake_ has joined #openstack-security | 22:42 | |
*** sdake has quit IRC | 22:46 | |
*** edmondsw has quit IRC | 22:48 | |
*** singlethink has quit IRC | 22:49 | |
*** voodookid has quit IRC | 23:06 | |
*** jamielennox is now known as jamielennox|away | 23:18 | |
tmcpeak | browne: you around? | 23:24 |
browne | yep | 23:27 |
tmcpeak | dude, as far as I can tell virtualenv Bandit install is broken | 23:27 |
browne | so this is a regression? | 23:28 |
tmcpeak | "pip uninstall bandit; virtualenv test_me; source test_me/bin/activate; bandit -r /some/path" —> no config found | 23:28 |
browne | doesn't tox use venv | 23:28 |
tmcpeak | I don't know, can you try that and see if it works for you? | 23:28 |
tmcpeak | tox doesn't gates aren't broken | 23:28 |
tmcpeak | oh yeah | 23:28 |
*** tkelsey has joined #openstack-security | 23:28 | |
tmcpeak | tox does use it, but the gates come with their own config | 23:28 |
tmcpeak | that's the only thing saving us | 23:28 |
tmcpeak | yeah man, it's a regression | 23:30 |
tmcpeak | got broken in 0.13.0 | 23:30 |
tmcpeak | 12 works fine | 23:31 |
tmcpeak | :( | 23:31 |
tmcpeak | we really need unit tests | 23:31 |
tmcpeak | and I'm not sure why this config thing is so complicated but it's killing us | 23:31 |
browne | yeah, i get the same | 23:32 |
*** tkelsey has quit IRC | 23:32 | |
tmcpeak | (sigh) damn | 23:32 |
browne | [bandit]ERRORno config found - tried: ./bandit.yaml, /home/ericwb/.config/bandit/bandit.yaml, /etc/bandit/bandit.yaml, /usr/local/etc/bandit/bandit.yaml | 23:32 |
tmcpeak | yep | 23:32 |
tmcpeak | if you do the same thing with 0.12.0 it's fine | 23:32 |
tmcpeak | well I know what I'm doing tomorrow :| | 23:33 |
browne | its because it doesn't check in bandit/config/bandit.yaml | 23:33 |
tmcpeak | ahh, so we can just add that one back to the end I guess | 23:33 |
browne | well, but we don't really know where that file is and where the cwd is | 23:34 |
browne | shouldn't we be installing to /etc ? | 23:34 |
*** sicarie has quit IRC | 23:34 | |
tmcpeak | we can't if it's not sudo, right? | 23:34 |
tmcpeak | we should be installing to virtualenv/etc | 23:35 |
browne | true | 23:35 |
tmcpeak | I'm surprised virtualenv doesn't handle that | 23:35 |
tmcpeak | shouldn' | 23:36 |
tmcpeak | shouldn't virutalenv/etc for all purposes be /etc? | 23:36 |
browne | yeah, we need to figure out how venv finds data files | 23:36 |
tmcpeak | yeah :| | 23:36 |
tmcpeak | we really need a good test set up now | 23:39 |
tmcpeak | too many variables to manage and be sure we're not breaking stuff | 23:39 |
tmcpeak | allright - well I'll dig into it first thing tomorrow | 23:40 |
browne | same issue with word-list | 23:41 |
*** jamielennox|away is now known as jamielennox | 23:47 | |
*** markvoelker has quit IRC | 23:50 | |
browne | tmcpeak: so we can use the env var to deduce location to the bandit.yaml and word list. | 23:52 |
browne | VIRTUAL_ENV=/home/ericwb/bandit/test_me | 23:52 |
browne | i'll put together a patch | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!