14:01:42 #startmeeting fwaas 14:01:43 Meeting started Thu Jun 21 14:01:42 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:44 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:01:47 The meeting name has been set to 'fwaas' 14:01:54 #chair xgerman_ 14:01:55 Current chairs: SridarK xgerman_ 14:02:33 Hi 14:02:40 Sorry I was late. 14:02:51 #chairs yushiro 14:02:58 #chair yushiro 14:02:59 Current chairs: SridarK xgerman_ yushiro 14:03:16 ok lets get started 14:03:23 yushiro: ur turn today ? 14:03:38 Yes, SridarK . 14:03:46 yushiro: pls go ahead :-) 14:03:50 #topic announcements 14:04:42 Does anyone have any announcement? 14:04:57 travel support for PTG ends 6/30 or so 14:05:33 Programming Comittee nomination for Berlin end 6/28 14:05:40 xgerman_, +1 :) 14:05:48 #link https://www.openstack.org/ptg/#tab_travel 14:06:01 +1 14:06:14 CfP for Berlin ends 7/17 14:06:32 o/ 14:06:40 and R3 is near 14:06:57 Ah, Yes. That's a good information. > CFP (7/17) 14:08:08 We're R-10 now : https://releases.openstack.org/rocky/schedule.html 14:08:32 OK 14:08:41 #topic Rocky 14:09:09 [WIP] Adds remote firewall group: https://review.openstack.org/521207 14:09:43 xgerman_, Please go ahead :) 14:10:25 didn’t do much progress (internal priorities) but deployed FWaaS V2 with it and it ddn’t blow up 14:10:55 OK 14:11:59 In Japan, Jun is also very busy with another task(writing report and presentation to our boss or something...) 14:12:21 Haha, so, I'm glad to join today's meeting :p 14:12:43 yushiro, you're boss :D 14:12:44 ;-) 14:12:50 Next. Logging for FWaaS v2 14:13:04 yushiro. I saw it. There is holiday this week in Japan 14:13:21 annp, Please go ahead 14:13:36 longkb, Yes, Please keep in you mind :p 14:13:41 hi folks, I am a new comer in fwaas, from Fujitsu Vietnam Limitted. 14:13:52 longkb: welcome 14:14:10 SridarK, thanks 14:14:19 regards to logging, we're making progress. 14:15:04 welcome 14:15:15 thanks xgerman :) 14:15:45 welcome!! ( I knew it :p 14:15:49 I'd like to get your eyes in https://review.openstack.org/#/c/529814/ as first of serial logging 14:16:59 here is list patch for logging https://review.openstack.org/#/q/topic:bug/1720727+(status:open) 14:17:51 I'd like to get more review on https://review.openstack.org/#/c/574683/ 14:18:11 annp +1 14:18:20 Today, I had bandwidth for reviewing. I'll review them. 14:18:41 yushiro, thank you so much . 14:18:57 That's all for firewall logging. 14:19:21 yushiro, please go ahead. 14:19:30 Again, we're targeting fwg L3 logging in this cycle(Rocky). 14:19:38 OK, thanks annp 14:19:48 yushiro, +1 14:19:54 #topic specs 14:20:06 (wkite) fwaas 2.0 address groups support https://review.openstack.org/557137 14:20:34 ok 14:21:27 i have pushed some patches to gerrit.All the questions raised have been resolved. 14:21:39 wkite +1. 14:22:04 wkite, Could you reply my comments? 14:22:13 wkite, Thanks for your update. 14:22:38 yushiro: All right. I'll get back to you as soon as possible. 14:22:45 wkite: will we start with l2 ovs reference implementation, right? 14:22:50 * mlavalle would like to bring up a point in the bugs section (if there is one) or in the open discussion section 14:23:24 wkite: thx once the comments are addressed - i think we can move fwd 14:24:17 annp: I'm not sure ether I can do it. 14:24:24 mlavalle, Of course!!!! 14:24:33 :-) 14:25:42 Let's review more on this SPEC> 14:25:57 #topic Horizon support 14:26:21 wkite: Let's discuss on gerrit. :) 14:26:23 SridarK: +1 14:26:33 Oh looks like SarathMekala is not on today 14:26:34 annp: ok 14:26:42 Sarath is not here today. SridarK,did you get any reply from him? 14:26:52 yushiro: he did attend last week 14:27:12 SridarK, wow, sorry. I missed it. 14:27:13 he is evaluating any gaps to be addressed in R 14:27:15 what are expected as feature gaps in the current v2.0 dashboard? 14:27:43 amotoki: i think we need to validate with L2 support - something Sarath was investigating 14:28:15 He mentioned he was in the tail end of an internal release - will follow up on this 14:28:20 yeah, L2 support is one of gaps. I am not sure we have others or not. 14:28:39 amotoki: i think most others u have squashed too 14:28:42 SridarK: +1 14:29:09 I have no actual list of such gaps. 14:29:21 anyways let me check in and see if he can attend next week or provide an update on email 14:29:43 it would be nice if we have an up-to-date list :) 14:29:52 amotoki: +1 14:29:53 Aha. Currently, fwaas dashboard can filter L2 port. I cannot catch up the latest state for dashboard. We need to enhance more regarding L2 port? 14:30:22 we should show the compute name/id along port if available 14:30:32 yushiro: IMO, we cannot add fwg to l2 port 14:30:41 from Horizon 14:30:43 xgerman_, Aha. Thanks. 14:30:59 I just did yesterday 14:31:15 longkb, Oh, really? I just fixed to filter L2 port...( Am I missing something..) 14:31:17 I tend to avoid writing patches by myself as I usually fail to get reviews :( and :) 14:32:22 amotoki, yeeeees. I always think it is very helpful and so sorry for lack of review... 14:32:35 +1 14:32:43 longkb: maybe u can capture into a bug - so we can track 14:33:10 SridarK +1 14:33:21 I'D LIKE TO REVIEW/WRITE PATCHES!!! I hope I had a 4 hands and 2 keyboards... :P 14:33:21 I did not think we had an issue here either from the CLI 14:33:34 SridarK +1 I will report this bug asap 14:33:39 yushiro +100 14:33:58 I sleep too much, but that’s me 14:34:01 yushiro ++ 14:34:03 njohnston, now I'm only 2 hands. Haha 14:34:13 yushiro: :-) i think u can add stand up comedy to ur many talents :-) 14:34:38 SridarK, Hahaha 14:35:00 OK, next topic. 14:35:03 #topic bugs 14:35:08 mlavalle, Hi :) 14:35:14 hi 14:35:32 yushiro: we shd do a triage 14:35:50 SridarK, Ah, yes. 14:35:50 lets defn get this done early next week 14:35:52 +1 14:36:00 maybe Mon ? 14:36:04 sure 14:36:05 but pls go ahead 14:36:05 I just want to make sure this bug is in the radar screen of the team: https://bugs.launchpad.net/neutron/+bug/1762454 14:36:06 Launchpad bug 1762454 in neutron "FWaaS: Invalid port error on associating ports (distributed router) to firewall group" [Medium,Triaged] - Assigned to Sridar Kandaswamy (skandasw) 14:36:18 mlavalle: yes 14:36:27 It was discussed last week in the L3 sub-team meeting 14:36:40 and I took the action of item of bringing it up here 14:36:59 mlavalle: i have discussed it with Swami 14:37:20 Thank you SridarK 14:37:49 will get some traction on it - adding the validation fix is easy - we need to evaluate if the namespace mappings etc dont mess up the datapath 14:38:08 thanks for the update 14:38:15 mlavalle: thx for the kick to remind :-) will sync up with Swami and get it moving 14:38:47 :-) 14:38:52 :))) 14:39:19 as u can see, i am trying to get together with yushiro on his act :-) 14:39:31 Should I bring up the issue with debian/wsgi/l3 agent/fwaas in the bugs section, or wait to see if there is time in the open discussion section? 14:39:39 njohnston: pls yes 14:39:46 SridarK, Sure. 14:39:54 njohnston, Yes, please! 14:39:56 njohnston: thx for the detailed email 14:40:27 SridarK, njohnston ++1 Your mail is so helpful for sync up with current state. 14:40:34 so it seems agent rpc is lost on debian 14:40:52 It does, yes, but I cannot pinpoint why that would be happening 14:41:13 and why it would only happen with the specific combination of wsgi, debian, and fwaas 14:41:22 it occurs regardless of fwaas v1 or v2 14:41:37 but it does not happen when wsgi is not engaged 14:41:45 and it does not happen on centos or ubuntu 14:41:47 njohnston: do u think it is something on some package versions across the distros 14:41:50 annp, Did you reproduce njohnston's situation?? I thought that you used to deploy with Debian. 14:42:09 I only sent the email to the cores, but perhaps I should sent to openstack-dev 14:42:31 yeah, I am no debian expert — test on ubuntu 14:42:38 njohnston: +1 14:42:43 so broader audience is useful 14:42:55 yushiro, yes. I did. 14:43:10 njohnston, I'll also try to deploy on Ubuntu16.04 and will share the state. 14:44:18 Just to note, wsgi is essential because zigo is attempting to package an all-python 3 set of packages, and eventlet has some kind of issue with python 2 IIRC 14:44:21 annp, OK, so, could you reply njohnston's mail with your detail situation? 14:44:40 Let me send it to openstack-dev and annp then perhaps you can reply to that 14:45:24 njohnston, yushiro, yes. I will. 14:46:40 njohnston, +1 14:47:42 njohnston: +1 14:47:50 njohnston: The issue is SSL + Python 3 + Eventlet == SSL handshake crash. 14:47:54 This is known since 2015... 14:48:35 zigo, Oh, it is potential bug.. 14:48:37 Ah, thanks for refreshing my memory zigo 14:48:44 I don't think the issue is Debian specific. 14:49:04 It is specific to using neutron-api and neutron-rpc-server, maybe also python 3 ... 14:49:04 yushiro: the SSL handshake crash is relevant to why wsgi is important, but not relevant to the issue in question 14:49:41 njohnston, OK. 14:50:06 OK, mail sent to openstack-dev, so we can all pool our info there 14:50:24 njohnston, Thanks!! 14:50:32 zigo, How can I update fwaas source with up-to-date in the vm? 14:51:26 #topic Open Discussion 14:51:39 zigo, because I saw fwaas source in the vm not update to date. 14:52:09 annp: You mean with HEAD of git? 14:52:25 annp: Well, it's just in /usr/lib/python3/dist-packages ... 14:52:33 annp: I guess you could simply replace the code there. 14:52:48 Quick and dirty rm -r and a cp -r should do. 14:52:53 Today, ndefigueiredo is not here. So, let's skip Stateless security 14:52:59 +1 14:53:07 zigo, thanks. I got it. :) 14:54:23 yushiro: njohnston: The thing is, in the Py3 + SSL situation, we have no choice but to use neutron-api + neutron-rpc-server instead of neutron-server daemon, and that may be source of new bugs. annp already fixed one with the ovn driver ... 14:54:42 Not sure, just double-guessing what's possible.\ 14:55:17 zigo: When you deploy on centos or ubuntu you're using the same setup, though, right? I would expect that if that was the issue, it would manifest on ubuntu and centos as well. 14:55:44 njohnston: No you're not. neutron-server runs instead of neutron-api and neutron-rpc-server. 14:55:57 ah, ok 14:55:59 Because they're using Python 2, then can run neutron-server using Eventlet and SSL. 14:56:01 I can't... 14:56:35 So, instead, in Debian, neutron-api does the requests over uwsgi, and rpc-server does the rabbitmq stuff. 14:57:08 zigo, could you reply e-mail that your local.conf of devstack? I'll try it. 14:57:39 yushiro: I'm not using devstack, I'm using Debian packages. 14:57:55 packaging is downstream from us 14:57:56 zigo, Aha. OK. 14:57:56 njohnston: I also have a patch in devstack for deploy neutron-api in uwsgi and rpc-server in eventlet at https://review.openstack.org/#/c/473718/ 14:58:00 yushiro: What you could do is run puppet-openstack to get it installed. 14:58:08 That's very easy. 14:58:20 zigo, Thanks. puppet-openstack. 14:58:22 yushiro: I can reply with the way to do it with puppet-openstack if you like? 14:58:23 njohnston: you can ./stack with the patch. 14:58:41 Thanks annp that is very helpful 14:59:08 zigo, Please send us !! It is very helpful. 14:59:37 time check 14:59:41 annp's patch can reproduce similar environment by using devstack,. 14:59:45 Wow, 1 minutes. 15:00:04 Thanks everyone 15:00:10 I need to go back home now (2 hours driving from Geneva), but I'll reply tonight. 15:00:16 OK guys, that's good discussion. will sync up e-mail more. Thanks!! 15:00:20 thx all 15:00:21 +1 15:00:22 #endmeeting