Friday, 2018-07-06

*** jamesmcarthur has quit IRC00:39
*** jamesmcarthur has joined #openstack-trove01:15
*** jamesmcarthur has quit IRC02:28
*** jamesmcarthur has joined #openstack-trove02:33
*** jamesmcarthur has quit IRC02:52
*** jamesmcarthur has joined #openstack-trove03:11
*** jamesmcarthur has quit IRC03:16
*** jamesmcarthur has joined #openstack-trove03:43
*** kei_yama has quit IRC03:49
*** kei_yama has joined #openstack-trove04:02
*** tianhui has joined #openstack-trove04:47
*** tianhui_ has quit IRC04:49
*** jamesmcarthur has quit IRC05:04
*** Bhujay has joined #openstack-trove05:38
*** rcernin has quit IRC07:29
*** tosky has joined #openstack-trove07:36
openstackgerritElod Illes proposed openstack/trove stable/queens: Use neutronclient for floatingip operations  https://review.openstack.org/58058409:04
*** jamesmcarthur has joined #openstack-trove09:16
*** jamesmcarthur has quit IRC09:20
Bhujayhello everybody , need some help in understanding  for the trove networking communication so that it can be implemented with adequate security for my organization09:44
Bhujaycan you refer some doc on this09:45
Bhujayspecifically i am looking for   trove  services and guest VM communication09:46
BhujayDoes the VM requires connection back to  control plane or only one way communication from control plane to VM is enough ?09:47
fanzhangBhujay hi, I find this doc https://wiki.openstack.org/wiki/Trove/guest_agent_communication may be helpful.09:48
Bhujayfanzhang: many thanks , let me check09:49
fanzhangGenerally, trove services use AMQP to communicate with guestagent in vm.09:49
fanzhangBhujay np :)09:49
fanzhangWe began this bp https://review.openstack.org/#/c/553679/, tried to start changing the communication method to a way much more security, but unfortunately, many of us have shifted the focus on other projects or so. You're welcome to leave any messages here in this channel. That would be big help to project Trove.09:53
fanzhangBhujay ^09:53
Bhujayfanzhang: i m still on your first link , this is very helpful let me spend sometime here to see  how i can overcome the challange in my environment ...09:55
Bhujaywe have separated our control plane and the vm/neutron/storage plane  with a firewall with  a view that even in case of a VM breakout ...09:57
Bhujaycontrol plane is secured .. so goal is to prevent any communication from VM back to control plane .. but for Dbass it seems we need one connection back to rabbit on the control plane09:58
fanzhangBhujay yes, guest agent inside vm has to keep a heart beat with control plane09:59
fanzhangBhujay take your time, and welcome to give trove a trial :)09:59
Bhujayfanzhang: thanks , u see unless such services are rolled out users  are not excited just at the IaaS layer :) , its very important  for my org10:01
fanzhangBhujay good to hear that :)10:02
Bhujayfanzhang:  to be more precise , only vm to rabbit connection shd be enough ? ( leaving aside calls to openstack service API which i can route through public endpoints )10:03
fanzhangBhujay sorry I don't follow your question10:10
fanzhangfor internal service, I guess rabbitmq connection is enought, but from user perspective, they have to access db, so hope you have no other security restrictions10:14
Bhujayfanzhang: sorry for not being clear enough , yes understood what you say10:15
fanzhangBhujay I have to go now, leaving messages here or by mailing list is both OK. :)10:15
Bhujayfanzhang: sure , thanks a lot for your responses , I will  try to implement it and posts my experience/views here , in case that helps10:18
fanzhangBhujay big thanks :)10:19
Bhujayu r welcome10:19
*** kei_yama has quit IRC13:26
*** jamesmcarthur has joined #openstack-trove14:28
*** Bhujay has quit IRC14:33
*** openstackgerrit has quit IRC15:19
*** tianhui_ has joined #openstack-trove15:44
*** tianhui has quit IRC15:46
*** tianhui has joined #openstack-trove16:52
*** tianhui_ has quit IRC16:53
*** v12aml has quit IRC17:26
*** v12aml has joined #openstack-trove17:27
*** itlinux has joined #openstack-trove17:28
*** jamesmcarthur has quit IRC17:44
*** itlinux has quit IRC17:56
*** itlinux has joined #openstack-trove17:57
*** itlinux has quit IRC17:57
*** cargonza_ has joined #openstack-trove18:41
*** cargonza_ has quit IRC19:39
*** cargonza_ has joined #openstack-trove19:39
*** openstackgerrit has joined #openstack-trove20:55
openstackgerritKrzysztof Opasiak proposed openstack/trove-tempest-plugin master: Create base class for client to avoid code duplication  https://review.openstack.org/58076320:55
*** rcernin has joined #openstack-trove23:36

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!