*** Dinesh_Bhor has joined #tacker | 00:33 | |
*** Dinesh__Bhor has joined #tacker | 00:58 | |
*** Dinesh_Bhor has quit IRC | 01:00 | |
*** binh has joined #tacker | 01:34 | |
*** binh has quit IRC | 01:35 | |
*** binh has joined #tacker | 01:35 | |
*** dangtrinhnt has joined #tacker | 01:36 | |
*** Dinesh__Bhor has quit IRC | 02:18 | |
*** Dinesh__Bhor has joined #tacker | 02:20 | |
*** joxyuki has joined #tacker | 02:43 | |
*** dangtrinhnt has quit IRC | 02:52 | |
*** gongysh has joined #tacker | 03:06 | |
*** trinaths has joined #tacker | 04:55 | |
*** dineshbhor__ has joined #tacker | 04:58 | |
*** Dinesh__Bhor has quit IRC | 04:59 | |
*** dineshbhor__ has quit IRC | 05:12 | |
*** Dinesh_Bhor has joined #tacker | 05:12 | |
*** gongysh has quit IRC | 05:12 | |
*** links has joined #tacker | 05:28 | |
*** trinaths has quit IRC | 05:46 | |
*** gongysh has joined #tacker | 05:48 | |
*** mardim has joined #tacker | 06:00 | |
*** egonzalez_afk has joined #tacker | 06:11 | |
*** trinaths has joined #tacker | 06:18 | |
*** tbh has quit IRC | 06:30 | |
*** Dinesh__Bhor has joined #tacker | 06:35 | |
*** Dinesh_Bhor has quit IRC | 06:36 | |
*** trinaths has quit IRC | 06:40 | |
*** janki has joined #tacker | 06:54 | |
*** trinaths has joined #tacker | 07:06 | |
*** trinaths has quit IRC | 07:06 | |
*** binh has quit IRC | 07:07 | |
mardim | gongysh, Hello | 07:08 |
---|---|---|
gongysh | helo | 07:08 |
mardim | gongysh, I updated the presentation for the Summit | 07:08 |
mardim | can you please take a look and tell me your opinion | 07:08 |
mardim | please free to add anything you want | 07:08 |
mardim | fell free* | 07:08 |
mardim | feel* | 07:08 |
*** trinaths has joined #tacker | 07:10 | |
gongysh | ok | 07:11 |
*** Dinesh__Bhor has quit IRC | 07:12 | |
gongysh | mardim, I think we should device a sfc to demo. | 07:18 |
mardim | gongysh, what do you mean can you please explain a bit more | 07:19 |
mardim | ? | 07:19 |
gongysh | for example vm1 -> packet stats vnf -> fw vnf -> target | 07:19 |
gongysh | mardim, do you know how to set up snort ? | 07:20 |
gongysh | if you know, we can set up an IPS/IDS sfc | 07:20 |
nguyenhai | if you can set up an IPS/IDS sfc, please share with us too, thanks :D | 07:22 |
*** Dinesh__Bhor has joined #tacker | 07:22 | |
mardim | gongysh, Do you want to create a sfc demo with snort ? | 07:23 |
mardim | gongysh, Sorry still trying to understand what do you want to do | 07:23 |
gongysh | yes, it is great if we can. if not we can use vm1 -> packet stats vnf -> fw vnf -> target | 07:23 |
mardim | can you please setup a basic topology in google doc | 07:23 |
gongysh | mardim, I mean we should have a live demo for the sfc | 07:24 |
gongysh | not just slides for concepts and tacker feature description. | 07:24 |
mardim | gongysh, I think we can have a live demo but we are a bit limited on the type of VNFs that we are gonna use | 07:24 |
mardim | gongysh, because | 07:24 |
mardim | we need the vxlan_tool to decapsulate the packets | 07:25 |
*** trinaths has quit IRC | 07:25 | |
mardim | and I only tried that with FW SFs | 07:25 |
mardim | not anything else | 07:25 |
mardim | gongysh, ^ | 07:25 |
gongysh | mardim, why do we need vxlan_tool? in VM, the traffic is not in vxlan encapsulation. | 07:25 |
gongysh | it is a normal l2/l3 packet. | 07:26 |
mardim | the vxlan_tool is for the SFs so we can decapsulate the NSH header | 07:26 |
mardim | which is used from the SFChaining | 07:26 |
*** dangtrinhnt has joined #tacker | 07:27 | |
gongysh | you are talking about odl sfc? | 07:27 |
mardim | yes | 07:27 |
gongysh | we can use ovs port-pair chain. | 07:27 |
mardim | I think networking sfc doesn't work right now without ODL | 07:27 |
mardim | it has some bugs | 07:28 |
mardim | which are not fixed | 07:28 |
mardim | I tried to do SFC without ODL | 07:28 |
mardim | and that was not possible | 07:28 |
mardim | gongysh, ^ | 07:28 |
egonzalez_afk | mardim, in what release? its been working without odl | 07:29 |
gongysh | even with odl nsh, the vnf itself does not need to know the vxlan. | 07:29 |
mardim | egonzalez_afk, I think the last time I checked was Pike release | 07:30 |
mardim | and it was not fixed | 07:30 |
mardim | gongysh, yes you are right the vxlan_tool is the tool which decapsulates NSH | 07:30 |
mardim | is not about vxlan tunneling | 07:31 |
mardim | this is just a name | 07:31 |
*** egonzalez_afk is now known as egonzalez | 07:31 | |
mardim | gongysh, I have a video which I was presenting in ONS summit | 07:32 |
mardim | this video is a recorded SFC demo | 07:32 |
mardim | do you think we can use that ? | 07:32 |
mardim | we recorded a sfc demo and we presented that in ONS summit | 07:33 |
gongysh | mardim, if we do not know how to set up a snort vnf, we can also set up a two vnfs chaining: src -> packets stats vnf -> fw vnf -> dst. | 07:33 |
gongysh | mardim, do you have a link for it? | 07:33 |
mardim | let me ask MAnuel Buil first so I can be sure that I can sare that video | 07:34 |
mardim | give me a minute | 07:34 |
mardim | gongysh, ^ | 07:34 |
mardim | share* | 07:35 |
gongysh | mardim, in fact, I want more: we are using a app monitoring on traffic for src -> dst, which will set up a sfc src -> packets stats vnf -> fw vnf -> dst once a suspected attach happens. | 07:36 |
gongysh | this is why I name our topic dynamic sfc. | 07:36 |
mardim | gongysh, ok to understand this completely so you have a monitoring tool which monitors specific src,dst IP adresses ? | 07:42 |
mardim | and then when find a specific adress instructs the traffic to go through some chain ? | 07:42 |
gongysh | tacker has a feature: app monitor which use zabbix | 07:42 |
mardim | gongysh, ok we use tacker-zabbix integration got that | 07:44 |
mardim | gongysh, after that ? | 07:44 |
mardim | I am trying to understand the demo scenario | 07:44 |
mardim | sorry :( | 07:44 |
mardim | gongysh, ^ | 07:45 |
gongysh | and then use zabbix trigger to set up a sfc. | 07:45 |
mardim | why zabbix will trigger a sfc setup ? | 07:46 |
mardim | why will* | 07:47 |
mardim | will it detect something which will cause that triggering of SFC ? | 07:47 |
mardim | I am not so familiar with zabbix sorry | 07:47 |
mardim | gongysh, ^ | 07:48 |
gongysh | mardim, zabbix detect a alarm on dst vm, and then trigger an action, which is to setup a sfc. | 07:49 |
mardim | gongysh, Ah ok so zabbix will detect a specific destination address and when that happens will trigger a sfc setup ? | 07:50 |
gongysh | mardim, you need to get a basic knowlege about zabbix. | 07:50 |
mardim | gongysh, ok I will do that | 07:52 |
*** trinaths has joined #tacker | 08:09 | |
*** trinaths has quit IRC | 08:38 | |
mardim | gongysh, I am thinking about the demo | 09:03 |
mardim | gongysh, the VNFs which will be used as SFs will be already power on and ready | 09:04 |
mardim | ? | 09:04 |
gongysh | yes, that can be | 09:04 |
mardim | and the only thing that zabbix will do is to setup a chain ? | 09:04 |
mardim | ok thanks | 09:05 |
gongysh | could be, be cause we support update a vnffg with vnffg classifier addition. | 09:05 |
mardim | I am trying to figure out our opitons here :) | 09:05 |
mardim | gongysh, yes tacker support update but ODL has bugs | 09:05 |
mardim | and the VNFFG update doesn't work form ODL side | 09:06 |
mardim | So what I am thinking | 09:06 |
mardim | is to have the VNFs already power on and ready to be used as SFs | 09:06 |
mardim | and the zabbix when it will detect a specific traffic will trigger a VNFFG creation | 09:06 |
mardim | gongysh, what do you think ? ^ | 09:07 |
gongysh | mardim, yes. | 09:08 |
gongysh | we can use ovs driver instead of odl driver. | 09:08 |
mardim | gongysh, I think ovs driver has problem in networking-sfc side | 09:08 |
mardim | has some bugs | 09:09 |
mardim | so I will not recommend | 09:09 |
gongysh | we have to test | 09:09 |
mardim | ok cool | 09:09 |
mardim | gongysh, Regarding the SF which will work as packet stat | 09:10 |
mardim | gongysh, If we use the vxlan_tool in a verbose mode and shows just the packets that are passing | 09:10 |
mardim | is it acceptable | 09:10 |
mardim | ? | 09:10 |
mardim | because I think we do not have many options on thsi | 09:11 |
mardim | this | 09:11 |
gongysh | why do you need vxlan-tool? | 09:14 |
*** joxyuki has quit IRC | 09:15 | |
gongysh | first we need to decide what sfc driver we will use. | 09:15 |
gongysh | odl or ovs? | 09:15 |
gongysh | I think we should use ovs. | 09:15 |
gongysh | I am not certain the odl integration with openstack is stable enough. | 09:16 |
mardim | ok I can try a devstack with ovs agent | 09:16 |
mardim | but I did it in pike release and I was not capable to create VNFFG because of networking sfc bugs | 09:17 |
mardim | but I can try again | 09:17 |
mardim | thanks :) | 09:17 |
*** Dinesh__Bhor has quit IRC | 09:24 | |
*** hyunsikyang has quit IRC | 10:06 | |
*** openstackgerrit has joined #tacker | 12:04 | |
openstackgerrit | Cong Phuoc Hoang proposed openstack/tacker master: Support exposing Kubernetes service using Loadbalancer https://review.openstack.org/548109 | 12:04 |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Add Module Index for Tacker docs https://review.openstack.org/559463 | 12:23 |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Add Module Index for Tacker docs https://review.openstack.org/559463 | 12:23 |
*** bobh has joined #tacker | 13:01 | |
*** hyunsikyang has joined #tacker | 13:21 | |
openstackgerrit | Trinh Nguyen proposed openstack/tacker-specs master: Prometheus plugin for container-based VNFs monitoring specs https://review.openstack.org/540416 | 13:34 |
*** links has quit IRC | 13:58 | |
*** gongysh has quit IRC | 14:12 | |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Fix incompatible requirement https://review.openstack.org/560432 | 14:15 |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Add module index for tacker docs https://review.openstack.org/559463 | 14:17 |
*** bobh has quit IRC | 14:25 | |
*** bobh has joined #tacker | 14:57 | |
*** egonzalez has quit IRC | 15:01 | |
*** gongysh has joined #tacker | 15:25 | |
*** gongysh has quit IRC | 15:25 | |
*** bobh has quit IRC | 15:36 | |
*** bobh_ has joined #tacker | 15:36 | |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Add module index for tacker docs https://review.openstack.org/559463 | 15:46 |
openstackgerrit | Merged openstack/tacker master: Remove tox jenkins https://review.openstack.org/558531 | 16:06 |
*** bobh_ has quit IRC | 16:09 | |
*** janki has quit IRC | 16:23 | |
geb | hey | 17:01 |
geb | I am trying to play with the demo in https://github.com/openstack/kolla-ansible/blob/master/contrib/demos/tacker/ & https://docs.openstack.org/tacker/latest/user/vnffg_usage_guide.html on a kolla-ansible 6.0.0 installed tacker | 17:02 |
geb | When I try to destroy vnfs they end in deletion error | 17:02 |
phuoc | Are vnfs status active bebore? | 17:08 |
nguyenhai | did you delete all related using vnf such as vnffg, ns? | 17:10 |
nguyenhai | which version of tacker in kolla-ansible 6.0.0 | 17:10 |
geb | Just rebuilding the installation to reproduce, I'll tell you once its ready :) | 17:33 |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Add module index for tacker docs https://review.openstack.org/559463 | 17:37 |
geb | ok, so, i managed to reproduce | 18:12 |
geb | there are two different problem while launching either https://github.com/openstack/kolla-ansible/blob/master/contrib/demos/tacker/deploy-tacker-demo-sfc or https://docs.openstack.org/tacker/latest/user/vnffg_usage_guide.html which is a bit more complex | 18:13 |
geb | i) tacker vnffg-create fails with Request Failed: internal server error while processing your request. on tacker vnffg-create for example in this line https://github.com/openstack/kolla-ansible/blob/master/contrib/demos/tacker/deploy-tacker-demo-sfc#L68 | 18:15 |
geb | ii) trying to delete vnf, either manually or using https://github.com/openstack/kolla-ansible/blob/master/contrib/demos/tacker/cleanup-tacker put vnf in deletion error | 18:16 |
geb | neutron port-chain-list ; neutron port-pair-group-list ; neutron flow-classifier-list (sent bu phuoc yesterday) result : https://pastebin.com/cU68yPMV | 18:21 |
geb | I am a bit stuck trying to understand what could be the issue, if by any chance you are interested to help me debugging (even if its not today) that would be great :) | 18:22 |
geb | I can provide ssh access if it is easier for you than to ask me to try commands, paste the output etc etc | 18:22 |
geb | (Its a lab server, so sharing access is not a big issue) | 18:23 |
geb | I am running a kolla ansible created install 6.0.0, so it should be queens. I can try to downgrade to 5.0.0 if you beleive it can be interesting. The install is pretty simple : https://pastebin.com/186TwfRe | 18:26 |
openstackgerrit | Nguyen Hai proposed openstack/tacker master: Implement VNF monitoring using Mistral https://review.openstack.org/486924 | 18:28 |
geb | sorry, good version of the install script https://pastebin.com/FQyBWwbR (openstack_release: "queens" and not "pike") | 18:28 |
geb | if you beleive it would be worthly i can also test from devstack, I thought kolla-ansible would be more appropriate for a production-like testbed/lab, but maybe was i wrong .. | 18:31 |
geb | The tracker-server and tracker-conductor logs, don't let anything special appear. The neutron server logs let seems however to log more things, escpecially python errors https://pastebin.com/bGqXxYJ6 (L377 and following) | 18:53 |
geb | 2018-04-11 19:50:58.740 25 ERROR networking_sfc.services.sfc.driver_manager [req-904389a8-d8e9-4a10-8621-8a6c2585fb30 36578caec01c430aacbd87879c2ee55c d990620da62243f68c2404932565c37b - default default] 'PortChainContext' object has no attribute 'session': AttributeError: 'PortChainContext' object has no attribute 'session' | 18:54 |
*** bobh has joined #tacker | 19:58 | |
geb | If you are interested to help me understand what could be the issue causing those python errors (did kolla packaged a non-fonctionnal version ?), i'll be available tomorrow starting by ~14-15h UTC+2 | 20:35 |
geb | If you would like to get a ssh access to perform debugging, feel free to send me requests & ssh keys at mathieu.goessens@imt-atlantique.fr ideally with pgp signature | 20:37 |
geb | (I also tested with openstack vnf graph create instead of tacker vnffg-create, to be sure, same result) | 20:38 |
-openstackstatus- NOTICE: zuul was restarted to updated to the latest code; you may need to recheck changes uploaded or approvals added between 21:30 and 21:45 | 22:31 | |
*** bobh has quit IRC | 22:40 | |
*** bobh has joined #tacker | 22:42 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!