14:00:07 #startmeeting fwaas 14:00:08 Meeting started Thu Apr 26 14:00:07 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:09 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:00:12 The meeting name has been set to 'fwaas' 14:00:19 #chair yushiro xgerman_ 14:00:23 Current chairs: SridarK xgerman_ yushiro 14:00:25 o/ 14:00:27 Hi all :) 14:00:36 yushiro: hi - i think ur turn today 14:00:43 SridarK, sure! 14:00:56 OK folks, let's begin :) 14:01:12 #topic announcements 14:01:40 o/ 14:01:44 Good news about OpenStack summit Vancouver's forum. 14:02:32 Our fwaas L7 session has approved. 14:02:41 annp: congrats 14:02:47 +1 14:02:54 I forgot a link... annp, Do you have some link? 14:03:52 #link http://forumtopics.openstack.org/cfp/details/144 14:03:56 ? 14:04:23 i think not 14:04:35 that was the submission 14:04:36 SridarK, Hmm, it returns 404 .. 14:04:50 yes just saw that too 14:05:26 Thanks. Anyway, let's discuss topic about our forum later :) 14:05:43 but that is good that 14:05:48 it was accepted 14:06:07 sorry go ahead yushiro 14:06:14 OK 14:06:19 Hi 14:06:48 We are now Rocky-2 cycle. R-2 is until 4th Jun. https://releases.openstack.org/rocky/schedule.html 14:07:16 So, anything else to announce? 14:07:28 TC elections are open — so if you got an e-mail make sure to vote 14:07:35 doude, hi 14:07:57 aha, yes, thanks xgerman_ 14:09:16 OK, so next topic. 14:09:25 #topic Rocky 14:09:54 Pluggable backend driver https://review.openstack.org/#/c/480265/ 14:10:10 doude, Hi. It's your turn :) 14:12:37 yes sorry 14:13:16 so I just started to look at the issue for the port auto association to default FG 14:13:30 I've a patch, I 'm just finishing to validate unit tests 14:13:43 I also rebase the patch on master 14:13:43 OK, good 14:14:03 I'll push new patch set in the hour 14:14:51 wow, cool. I'll test tomorrow with 'nova boot' command and check default fwg association again. 14:14:53 just a question, that specific port association is only in case a port is automatically associated to the default FG? 14:16:35 doude, auto association target is VM port (newly created or bind) 14:17:04 And it is associated with default fwg. 14:17:06 if we create a port not binded to a host, and associating that port to FG, do we just need to set the association in the DB and don't send RPC FG update ? 14:17:24 ha ok it's only for port VM 14:17:31 understood 14:17:44 If we try to associate non-bind port with any fwg, it returns 409 error. 14:17:50 Aha, Ok. 14:17:52 ok 14:17:55 thanks 14:19:05 So, doude, if you update your patch, please check the q-agt.service log while running 'nova boot'. If there is no 'error' message and FWG is associated with a port, it is good. 14:19:33 Of course, I'll test as well :) 14:19:38 oterwise, I did not had time to discuss with NSX dev about their FWaaS driver 14:19:55 sure yushiro 14:20:13 doude: ok it will be good to close on the NSX driver too 14:20:13 I was able to reproduce and see that error before I patch the code 14:20:18 i think it should be o 14:20:20 k 14:20:27 yes me to SridarK 14:20:34 maybe just needs clarification 14:20:38 thx doude 14:21:06 doude, In addition, current devstack is a little strange. Please set [fwaas]firewall_l2_driver = ovs at /etc/neutron/l3_agent.ini not /etc/neutron/plugins/ml2/ml2_conf.ini 14:21:36 Latter case wasn't loaded correctly. 14:22:17 OK, next 14:22:22 WIP] Adds remote firewall group: https://review.openstack.org/521207 14:22:38 xgerman_, go ahead :p 14:22:50 thanks yushiro 14:22:51 not much to report. 14:22:58 OK 14:23:02 Need yo make the gates work for my patch 14:23:17 there have been gate issues the pas few weeks in OpenStack 14:23:30 wow :( 14:24:00 yeah, from pip versions, to neutron purging FKs, etc. 14:24:22 hey hi guys 14:24:26 xgerman_, Ahhhh, Yes, I remembered.. 14:24:39 hi reedip 14:24:43 reedip, Hi! 14:25:02 I was able to join the meeting atlast :) 14:25:09 reedip, cool!! 14:25:10 o/ 14:25:22 reedip: long time, hi :-) 14:25:22 o/ 14:25:40 yes, was pretty messed up with the work and other activities :| 14:25:57 :-) 14:26:33 Good news! I wanted to announce about that in announce topic :p 14:26:46 OK, next 14:26:54 Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ 14:27:23 Sorry i forgot earlier but it looks good to me too 14:27:31 and i added Miguel for +A 14:27:31 Thanks for your review SridarK 14:28:01 good :) In addition, your comment is reasonable to start L3 first. 14:28:23 Thanks cuong for update. 14:29:11 +1 14:29:23 and thanks for all reviewing :) 14:29:39 #topic Horizon support 14:30:13 Today, chandan and Sarath are not here. 14:30:37 Yes, i will send a note to them to see if they can join next week 14:30:52 SridarK, OK, thanks. 14:32:01 #topic bugs 14:32:07 http://urx2.nu/C7UI 14:33:00 There are 13 bugs are 'UNDECIDED' status. 14:33:36 time for a bug scrub? 14:33:45 any assigned to me ?? :P 14:33:56 +1 on bug scrub 14:34:02 +1 for the bug scrub 14:34:06 xgerman_, GOOD! 14:34:18 maybe we can run thru this after we take a look offline 14:34:27 and update them 14:34:29 +1 14:34:35 https://bugs.launchpad.net/neutron/+bug/1618244 14:34:36 Launchpad bug 1618244 in neutron "Possible scale issues with neutron-fwaas requesting all tenants with firewalls after RPC failures" [Undecided,In progress] - Assigned to Bertrand Lallau (bertrand-lallau) 14:34:39 I will look at them a bit tomorrow morning ( I have some bandwidth tomorrow ) 14:35:24 somehow i recall some work on this area done maybe by Cedric ? 14:35:29 i am a bit foggy 14:36:21 SridarK, OK 14:37:29 It seems to be backported to ocata 14:38:19 I'll set 'low' for now. 14:38:31 k 14:39:08 yes that seemed quite familiar 14:39:14 https://bugs.launchpad.net/neutron/+bug/1626642 14:39:16 Launchpad bug 1626642 in neutron "Cleanup and add more UT for FWaaS v2 plugin" [Undecided,Confirmed] - Assigned to Sridar Kandaswamy (skandasw) 14:39:33 It's you, SridarK :) 14:39:52 let me look to see if that is relevant 14:40:01 Ok 14:40:06 brb 14:40:17 i recall we had some coverage needed for rule updates 14:40:32 but will take a look 14:40:57 Aha. OK, so, I'll set medium. 14:41:17 https://bugs.launchpad.net/neutron/+bug/1656754 14:41:19 Launchpad bug 1656754 in neutron "Fwaas (bind a firewall to DVR router when its floating-ip count is zero): the firewall rules does not take effect for a VM after binding a floating ip to the VM." [Undecided,New] - Assigned to wujun (wujun) 14:43:03 I think this is about fwaas v1. 14:43:52 yushiro: most likely will need to look 14:46:17 OK, there are many bugs. Let's continue next week. 14:46:25 yushiro: +1 14:46:33 +1 14:46:34 we can do some digging on the list offline 14:46:43 yeah 14:46:57 #topic specs 14:47:04 Lets put a google doc for it ? 14:47:41 fwaas 2.0 address groups support https://review.openstack.org/557137 14:48:30 I have committed a new proposafor e 14:48:42 sorry 14:49:29 reedip, about bug? 14:50:20 I have committed a new spec to the gerrit. 14:50:51 wkite, OK, could you paste a link for the spec?? 14:51:11 i modified some inappropriate places. 14:52:13 Ah, you updated existing spec, did you? 14:52:38 http://logs.openstack.org/37/557137/4/check/build-openstack-sphinx-docs/3c4e754/html/specs/rocky/fwaas-2.0-address-groups-support.html 14:53:00 yushiro: yes 14:53:19 I cannot review last week, so I'll review tomorrow. 14:53:36 s/cannot/couldn't 14:53:43 wkite: thx i see u have addressed most comments - i think - will go thru again also 14:54:08 yushiro: thanks for your review 14:55:03 :) 14:55:20 Ah, 5 minutes left !! :p 14:55:21 SridarK: thx 14:55:31 wkite: np 14:55:41 Everyone, plz review his spec :) 14:55:46 +1 14:55:51 #topic Open Discussion 14:56:56 I'll take a holiday from 28th Apr. to 6th May a.k.a "Golden week". 14:57:26 yushiro: have a nice break 14:57:28 If you'd like to ask me something, please send e-mail 14:57:43 SridarK, Yeah, thanks. 14:58:32 stable/queens fwaas-dashboard gate is broken now. the fix is here: https://review.openstack.org/#/c/564523/ please take a look. 14:58:52 amotoki, Thank you so much 14:59:11 +1 14:59:41 I need more time to contribute on OpenStack!! :p 15:00:01 yushiro: ah yes same here 15:00:05 :-) 15:00:07 +1 — 15:00:16 Same feeling :) 15:00:20 oh time 15:00:23 Ok, this is time. 15:00:28 #endmeeting