Tuesday, 2020-09-08

*** hongbin has joined #openstack-containers01:28
*** hongbin_ has joined #openstack-containers01:46
*** noonedeadpunk has quit IRC01:47
*** hongbin has quit IRC01:48
*** noonedeadpunk has joined #openstack-containers01:50
*** openstackgerrit has joined #openstack-containers02:13
openstackgerritZihao Wang proposed openstack/magnum master: requirements: Drop os-testr  https://review.opendev.org/75026702:13
*** sapd1_x has joined #openstack-containers02:22
*** rcernin has quit IRC02:59
*** sapd1_x has quit IRC03:14
*** rcernin has joined #openstack-containers03:14
*** hongbin_ has quit IRC03:15
*** hongbin has joined #openstack-containers03:16
*** vishalmanchanda has joined #openstack-containers03:52
*** ykarel|away has joined #openstack-containers04:29
*** ykarel|away is now known as ykarel04:31
*** ramishra has quit IRC04:31
*** ramishra has joined #openstack-containers04:31
*** ykarel has quit IRC04:42
*** ykarel has joined #openstack-containers04:44
*** hongbin has quit IRC05:12
*** sapd1_x has joined #openstack-containers07:15
openstackgerritwu.shiming proposed openstack/python-magnumclient master: Remove translation sections from setup.cfg  https://review.opendev.org/75028107:16
*** kevko has joined #openstack-containers07:29
*** rcernin has quit IRC08:00
*** kevko has quit IRC08:22
*** nikparasyr has joined #openstack-containers08:24
*** k_mouza has joined #openstack-containers08:26
openstackgerritFeilong Wang proposed openstack/magnum master: Update default k8s admission controller list  https://review.opendev.org/74838908:39
*** flwang1 has joined #openstack-containers08:54
flwang1brtknr: do you think have any concern about https://review.opendev.org/#/c/749893/ ?08:55
brtknrflwang1: yes slightly in that v1.19.0 hyperkube doesnt officially exist08:55
flwang1yep, but anyone can build it08:56
flwang1and without this patch, the v1.19.0 won't work08:56
brtknrwe should introduce a label to specify location of hyperkube image08:56
flwang1until we support binary, we will have to build hyperkube08:56
brtknrbtw I just scanned the image catalystcloud built for vulnerabilities08:57
flwang1i don't really understand why we need it? for community?08:57
flwang1pm me pls08:57
brtknrImage [catalystcloud/hyperkube:v1.19.0] contains 233 total vulnerabilities08:58
flwang1brtknr: i think it's not only for v1.19.008:59
brtknryes all hyperkube images have these issue09:00
brtknrmost of them are negligible09:00
brtknr1 sec, lemme share the report09:00
brtknrhttps://seashells.io/p/Kp9g8vG309:01
brtknr133/233 negligible09:02
flwang1seems most of them come with the base image09:02
brtknr34/233 low09:02
brtknr44/233 medium09:02
brtknr8/233 high09:02
flwang1i see09:03
brtknrand 2/233 critical09:03
brtknrflwang1: can we use a different base image?09:04
flwang1i don't know, but it could be hard comparing the effort switch to binary09:04
flwang1brtknr: we should check with Spyros the progress of binary09:05
flwang1i'm keen to get it in this cycle09:05
flwang1otherwise, cherrypick is also OK for me if we can get it in early next W release09:06
brtknrflwang1: looking at the CVEs, a lot of them are actually related to linux kernel version09:06
brtknrin actual fact, containers use host kernel09:06
flwang1given the k8s community has abandoned the hyperkube, it doesn't make much sense to stick on that way09:09
flwang1we have to move on09:09
flwang1i agree with Spyros, the k8s community is not very responsible for this case09:09
brtknrI tested the PS to support binary and it works for v1.19.009:10
brtknrit just needs fleshing out to support upgrades09:11
flwang1really? sounds good09:12
flwang1i will play it tomorrow09:13
*** kevko has joined #openstack-containers09:17
flwang1brtknr: just to be clear, when you say it works, do you mean this patch https://review.opendev.org/#/c/748141/1/magnum/drivers/common/templates/kubernetes/fragments/configure-kubernetes-master.sh ?09:21
brtknrflwang1:yep09:22
flwang1but looks like it's still using podman to start a kube-xxx container, isn't it?09:22
flwang1i probably missed something09:22
brtknrflwang1:although [k8s.gcr.io/kube-proxy:v1.19.0] contains 53 unapproved vulnerabilities09:23
brtknrflwang1: yes it only uses binary for kubelets09:23
flwang1i see09:24
flwang1i will start to think about the upgrade path09:25
brtknrflwang1: btw rancher uses ubuntu base image for hyperkube09:39
brtknrrancher/hyperkube:v1.19.0-rancher109:39
brtknrflwang1:Image [rancher/hyperkube:v1.19.0-rancher1] contains 28 total vulnerabilities09:39
flwang1interesting09:39
brtknrthis looks much better09:39
flwang1it would be nice if we can understand the dockerfile09:40
brtknrand the worst one is Medium CVE09:40
brtknrthere are no high or critical issue09:40
brtknrthis is why it would be good to introduce a kube_repo label09:41
brtknrso that we can specify location of hyperkube image09:41
*** ykarel_ has joined #openstack-containers09:42
openstackgerritMerged openstack/magnum master: Drop KUBE_API_PORT for kube-apiserver  https://review.opendev.org/74989309:42
flwang1let's add it to tomorrow meeting agenda09:43
*** ykarel has quit IRC09:44
*** ykarel_ is now known as ykarel09:45
flwang1https://github.com/rancher/hyperkube/tree/v1.1909:45
flwang1https://github.com/rancher/hyperkube-base09:47
flwang1i think we found it09:47
flwang1brtknr: ^09:48
brtknryep thats the one09:48
brtknri am less keen on maintaining our own image however :)09:49
brtknrflwang1:09:49
flwang1let's discuss if we can work together with rancher team09:50
flwang1and i think that's how open source works09:50
flwang1i'm off for today :)09:55
brtknrflwang1: cool :) enjoy your day off09:58
*** kevko has quit IRC10:05
openstackgerritBharat Kunwar proposed openstack/magnum master: [k8s] Add vulnerability scanner  https://review.opendev.org/59814210:08
*** k_mouza has quit IRC10:16
*** kevko has joined #openstack-containers10:19
*** kevko has quit IRC10:24
*** ykarel has quit IRC10:33
*** ykarel has joined #openstack-containers10:34
*** ykarel_ has joined #openstack-containers10:40
*** ykarel has quit IRC10:42
*** sapd1_x has quit IRC10:47
*** dave-mccowan has joined #openstack-containers10:59
*** k_mouza has joined #openstack-containers11:08
*** dave-mccowan has quit IRC11:12
*** dave-mccowan has joined #openstack-containers11:13
*** k_mouza has quit IRC11:14
*** mgariepy has quit IRC11:15
*** k_mouza has joined #openstack-containers11:18
*** k_mouza has quit IRC11:18
*** ykarel__ has joined #openstack-containers11:32
*** ykarel_ has quit IRC11:35
*** ykarel__ has quit IRC11:39
*** ykarel has joined #openstack-containers11:42
*** ykarel has quit IRC11:43
*** ykarel has joined #openstack-containers11:45
*** ykarel has quit IRC11:46
*** ykarel has joined #openstack-containers11:48
*** mgariepy has joined #openstack-containers12:05
*** ykarel_ has joined #openstack-containers12:14
*** ykarel has quit IRC12:16
*** flwang1 has quit IRC12:39
*** kevko has joined #openstack-containers12:49
*** k_mouza has joined #openstack-containers13:09
*** kevko has quit IRC13:26
*** ykarel_ is now known as ykarel13:30
*** ykarel_ has joined #openstack-containers13:37
*** ykarel has quit IRC13:37
*** ykarel_ is now known as ykarel13:53
*** k_mouza has quit IRC14:27
*** ykarel_ has joined #openstack-containers14:30
*** ykarel has quit IRC14:30
*** k_mouza has joined #openstack-containers14:51
*** ykarel_ is now known as ykarel|away14:56
*** k_mouza has quit IRC15:03
*** nikparasyr has left #openstack-containers15:09
*** k_mouza has joined #openstack-containers15:10
*** sapd1_x has joined #openstack-containers15:27
*** k_mouza has quit IRC15:29
*** jmlowe has quit IRC15:30
*** jmlowe has joined #openstack-containers15:32
*** k_mouza has joined #openstack-containers15:41
*** ykarel|away has quit IRC15:44
*** k_mouza has quit IRC16:06
*** k_mouza has joined #openstack-containers16:08
*** mgariepy has quit IRC16:09
*** k_mouza has quit IRC16:18
*** vishalmanchanda has quit IRC16:21
*** k_mouza has joined #openstack-containers16:24
*** k_mouza has quit IRC16:30
*** sapd1_x has quit IRC16:33
*** mgariepy has joined #openstack-containers17:10
*** mgariepy has quit IRC17:37
*** mgariepy has joined #openstack-containers17:38
*** mgariepy has quit IRC18:14
*** mgariepy has joined #openstack-containers18:28
*** rcernin has joined #openstack-containers23:02

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!