*** lnicolas has quit IRC | 00:06 | |
*** hoangcx has joined #openstack-fwaas | 00:39 | |
*** chandanc__ has joined #openstack-fwaas | 02:54 | |
*** yushiro has quit IRC | 04:00 | |
*** padkrish has joined #openstack-fwaas | 06:32 | |
*** padkrish has quit IRC | 06:42 | |
*** yamamoto has quit IRC | 07:47 | |
*** fandi has joined #openstack-fwaas | 08:00 | |
*** yamamoto has joined #openstack-fwaas | 08:24 | |
*** amotoki has joined #openstack-fwaas | 09:21 | |
*** chandanc__ has quit IRC | 09:25 | |
*** yamamoto has quit IRC | 09:31 | |
*** chandanc__ has joined #openstack-fwaas | 09:38 | |
*** yamamoto has joined #openstack-fwaas | 10:05 | |
*** hoangcx has quit IRC | 10:07 | |
*** mickeys has quit IRC | 10:09 | |
*** yamamoto has quit IRC | 10:12 | |
*** fandi has quit IRC | 10:51 | |
*** chandanc__ has quit IRC | 11:02 | |
*** yamamoto has joined #openstack-fwaas | 11:04 | |
*** yamamoto has quit IRC | 11:04 | |
*** yamamoto has joined #openstack-fwaas | 11:05 | |
*** yamamoto has quit IRC | 11:07 | |
*** mickeys has joined #openstack-fwaas | 11:10 | |
*** mickeys has quit IRC | 11:14 | |
*** amotoki has quit IRC | 12:02 | |
*** chandanc__ has joined #openstack-fwaas | 12:05 | |
*** yamamoto has joined #openstack-fwaas | 12:08 | |
*** mickeys has joined #openstack-fwaas | 12:11 | |
*** yamamoto has quit IRC | 12:14 | |
*** mickeys has quit IRC | 12:15 | |
*** yamamoto has joined #openstack-fwaas | 12:17 | |
*** chandanc__ has quit IRC | 12:27 | |
*** mickeys has joined #openstack-fwaas | 13:11 | |
*** amotoki has joined #openstack-fwaas | 13:13 | |
*** mickeys has quit IRC | 13:16 | |
*** yamamoto has quit IRC | 13:45 | |
*** yamamoto has joined #openstack-fwaas | 13:55 | |
*** chandanc_ has joined #openstack-fwaas | 13:57 | |
*** yamamoto has quit IRC | 14:00 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 14:06 | |
*** hoangcx_ has joined #openstack-fwaas | 14:08 | |
*** mickeys has joined #openstack-fwaas | 14:40 | |
*** yamamoto has joined #openstack-fwaas | 14:40 | |
*** mfranc213 has quit IRC | 14:43 | |
*** mickeys has quit IRC | 14:44 | |
*** yamamoto has quit IRC | 14:45 | |
*** mfranc213 has joined #openstack-fwaas | 14:50 | |
*** yamamoto has joined #openstack-fwaas | 14:57 | |
*** yamamoto has quit IRC | 14:57 | |
*** yushiro has joined #openstack-fwaas | 15:00 | |
yushiro | I'm home. | 15:00 |
---|---|---|
yushiro | ZZelle, tuhv, Could you wait a moment? I just take coffee. | 15:01 |
*** yushiro is now known as yushiro_afk | 15:01 | |
*** hoangcx_ has quit IRC | 15:03 | |
*** yushiro_afk is now known as yushiro | 15:05 | |
yushiro | OK | 15:05 |
*** chandanc_ has quit IRC | 15:06 | |
yushiro | ZZelle, here is today's IRC log: http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-02-14-14.00.log.html | 15:07 |
ZZelle | yushiro, ok | 15:08 |
yushiro | I'd like to sync a direction and next action about https://bugs.launchpad.net/neutron/+bug/1664294 | 15:08 |
openstack | Launchpad bug 1664294 in neutron "Netlink solution not enough mature for Ocata" [Undecided,In progress] - Assigned to Cedric Brandily (cbrandily) | 15:08 |
*** AlexeyAbashkin has quit IRC | 15:08 | |
yushiro | oh, tuhv is not here... | 15:08 |
yushiro | OK, I'll tell him tomorrow. | 15:09 |
ZZelle | yushiro, tuhv created to change to allow to choose between legacy/netlink driver | 15:09 |
yushiro | ZZelle, yes, and he just add functional test. | 15:09 |
*** reedip_ has joined #openstack-fwaas | 15:10 | |
reedip_ | Hi yushiro | 15:10 |
yushiro | reedip_, hi | 15:10 |
ZZelle | yushiro, i am working on correctly handling moves between netns https://review.openstack.org/433633 | 15:10 |
reedip_ | Can i take a look at the stadium bug which was mentioned by njohnston | 15:11 |
xgerman | sure | 15:11 |
yushiro | reedip_, sure | 15:11 |
reedip_ | Thnx | 15:12 |
yushiro | ZZelle, good. | 15:13 |
yushiro | https://review.openstack.org/#/c/433598/1 Make conntrack driver be configurable | 15:13 |
ZZelle | yushiro, we should correct fd usage also and add FT | 15:13 |
yushiro | ZZelle, Yes. BTW, I think UT is also necessary for it. What do you think? | 15:14 |
ZZelle | yushiro, yes but UT are easier because the framework exists :s | 15:15 |
ZZelle | yushiro, it seems the 1st FT will be really costly | 15:15 |
yushiro | ZZelle, Aha, yes. I just understood what tuhv wanted to say in today's IRC meeting :) | 15:16 |
yushiro | ZZelle, So, we just focus on improving netlink solution patch without reverting. Are we on same page? | 15:18 |
yushiro | ZZelle, I just want to check about that with you. | 15:18 |
ZZelle | yushiro, yes, we should backport in ocata https://review.openstack.org/433598 when it will merged | 15:18 |
yushiro | ZZelle, OK. We're on same page now. | 15:19 |
yushiro | ZZelle, apologize for my strange e-mail :( | 15:20 |
xgerman | backporting of features is a bit tricky | 15:20 |
xgerman | so don’t get your hopes up just yet :-) | 15:20 |
yushiro | xgerman, thanks. | 15:26 |
yushiro | xgerman, So, if it is hard to backport that, we should take an alternative plan. | 15:27 |
xgerman | it’s a policy thing - not technically hard | 15:28 |
yushiro | xgerman, I see. | 15:28 |
xgerman | there is a grey area and Neutron has been on the no-backport side of things so far | 15:28 |
yushiro | xgerman, OK. Usually, backportable patch is only fixing critical bug or security one I know. | 15:29 |
xgerman | yep, and it’s controversial to call performance issues critical bugs… but we can go for it | 15:31 |
ZZelle | xgerman, which means we should revert netlink driver in Ocata? | 15:32 |
xgerman | if it’s in the release we can :fix” it | 15:32 |
*** reedip_1 has joined #openstack-fwaas | 15:47 | |
reedip_1 | o/ | 15:48 |
ZZelle | xgerman, not sure to understand what you mean | 15:50 |
reedip_1 | are you guys still available to discuss the shared vs public discussion ? | 15:50 |
xgerman | ZZelle the decision what’s being backported and what’s not is done by the stable team and usually cores are not members. So, not sure, if they will let us backport or not. | 15:51 |
xgerman | reedip_1 yes | 15:52 |
reedip_1 | xgerman : okay, bascially I was of the opinion that instead of the public keyword, we can rename it to shared | 15:53 |
reedip_1 | but while I was thinking that, the other thing that crossed my mind ( which may not be linked directly to this ) is an rbac implementation for the firewalls themselves | 15:53 |
reedip_1 | share a set of firewall /firewall groups /firewall rules with a set of members , but share others with a wider generation | 15:54 |
xgerman | yeah, I think RBAC is what we want eventually | 15:54 |
xgerman | now, what’s the step in between which is attainable today | 15:55 |
reedip_1 | xgerman : I am goinf back a bit , to neutron .... | 15:55 |
reedip_1 | xgerman : in neutron, we had the -shared option for networks | 15:56 |
reedip_1 | if you enable that option, then the network is SHARED with everyone | 15:56 |
reedip_1 | if not, then it is not visible to anyone | 15:56 |
reedip_1 | xgerman : if seen from the same perspective, the network which is shared with all other tenants is almost similar to a PUBLIC network | 15:57 |
reedip_1 | because it is visible and operatable by anyone | 15:57 |
reedip_1 | anyone can use the network to create a port on the network and connect it to their VM for boot | 15:57 |
*** yamamoto has joined #openstack-fwaas | 15:58 | |
reedip_1 | keeping the analogy similar, we also have the PUBLIC attribute of FW | 15:58 |
reedip_1 | Now the public attribute works similar to the -shared attribute of the network | 15:59 |
xgerman | well, our plan for the next step is have cloud admins make firewalls policies which are applied to ALL ports | 16:00 |
reedip_1 | xgerman : if the policies are applied to all ports, we can use the public attribute | 16:01 |
xgerman | or you can pick from a set of policies | 16:01 |
xgerman | reddip | 16:01 |
reedip_1 | i mean we can use the keyword public | 16:01 |
xgerman | yeah, but then we have other admins in the hierarchy | 16:02 |
xgerman | which would only share with things they are responsible for | 16:02 |
reedip_1 | xgerman : so you want something like a fine tuner | 16:03 |
reedip_1 | i.e. rbac :) | 16:03 |
xgerman | I think for now we can do public and RBAC comes in phase 2 | 16:03 |
xgerman | so it probably makes sense to rename shared->public and then have shared re-introduced in that phase | 16:03 |
reedip_1 | xgerman : I agree with public now , makes more sense | 16:04 |
reedip_1 | xgerman : but I dont think we need a shared attribute if we implement rbac on firewall objects | 16:05 |
xgerman | ok, now we need to tell yushiro ;-) | 16:05 |
*** yamamoto has quit IRC | 16:05 | |
reedip_1 | I will show him this transcript :D | 16:06 |
reedip_1 | njohnston : there ? | 16:07 |
yushiro | xgerman, reedip_1 I'm waking up :) | 16:08 |
yushiro | xgerman, reedip_1 I just read your discussion log above. | 16:08 |
xgerman | k | 16:08 |
reedip_1 | saved me time :D | 16:09 |
njohnston | reedip_1: here | 16:09 |
reedip_1 | mailed you today njohnston regarding the congress integration with fwaas | 16:09 |
njohnston | reedip_1: I saw that you mailed, but I haven | 16:10 |
reedip_1 | ok | 16:10 |
reedip_1 | no | 16:10 |
njohnston | 't had a chance to respond yet, sorry | 16:10 |
reedip_1 | issues | 16:10 |
reedip_1 | no problem njohnston , I understand you are busy, specially as todays valentine's day :D | 16:11 |
reedip_1 | yushiro : we can keep the public attribute, so no issues with that patch. | 16:11 |
yushiro | reedip_1, OK. I hope to put +1 from you :) | 16:11 |
reedip_1 | yeah, if everythinf else is ok :P | 16:12 |
yushiro | xgerman, reedip_1 thanks for your great discussion! | 16:13 |
yushiro | I'll go to bed now. Good night. | 16:14 |
*** amotoki has quit IRC | 16:19 | |
*** yushiro has quit IRC | 16:40 | |
*** faizy has joined #openstack-fwaas | 16:58 | |
*** mickeys has joined #openstack-fwaas | 17:55 | |
*** reedip_1 has quit IRC | 17:55 | |
*** mickeys has quit IRC | 18:01 | |
*** SridarK_ has joined #openstack-fwaas | 19:13 | |
*** faizy has quit IRC | 19:47 | |
*** reedip_1 has joined #openstack-fwaas | 20:56 | |
*** mickeys has joined #openstack-fwaas | 20:57 | |
*** reedip_1 has quit IRC | 20:58 | |
*** mickeys has quit IRC | 21:01 | |
*** SridarK_ has quit IRC | 21:12 | |
*** SridarK_ has joined #openstack-fwaas | 21:13 | |
*** SridarK_ has quit IRC | 21:15 | |
*** SridarK_ has joined #openstack-fwaas | 21:16 | |
*** yamamoto has joined #openstack-fwaas | 22:12 | |
*** greghaynes has quit IRC | 22:42 | |
*** zigo has quit IRC | 22:46 | |
*** njohnston has quit IRC | 22:46 | |
*** njohnston has joined #openstack-fwaas | 22:46 | |
*** greghaynes has joined #openstack-fwaas | 22:49 | |
*** zigo has joined #openstack-fwaas | 22:52 | |
*** zigo is now known as Guest27057 | 22:54 | |
*** mickeys has joined #openstack-fwaas | 23:09 | |
*** mickeys has quit IRC | 23:13 | |
*** SridarK_ has quit IRC | 23:25 | |
*** reedip_1 has joined #openstack-fwaas | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!