*** yamamoto has joined #openstack-fwaas | 03:47 | |
*** yamamoto has quit IRC | 03:47 | |
*** yamamoto has joined #openstack-fwaas | 03:51 | |
*** threestrands_ has joined #openstack-fwaas | 05:09 | |
*** threestrands_ has quit IRC | 05:09 | |
*** threestrands_ has joined #openstack-fwaas | 05:09 | |
*** threestrands has quit IRC | 05:09 | |
*** threestrands_ has quit IRC | 05:10 | |
*** threestrands_ has joined #openstack-fwaas | 05:11 | |
*** threestrands has joined #openstack-fwaas | 05:15 | |
*** threestrands has quit IRC | 05:15 | |
*** threestrands has joined #openstack-fwaas | 05:15 | |
*** threestrands_ has quit IRC | 05:18 | |
*** threestrands has quit IRC | 05:28 | |
*** threestrands has joined #openstack-fwaas | 07:09 | |
*** threestrands has quit IRC | 07:09 | |
*** threestrands has joined #openstack-fwaas | 07:09 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:08 | |
*** threestrands_ has joined #openstack-fwaas | 09:21 | |
*** threestrands has quit IRC | 09:21 | |
*** yamamoto has quit IRC | 11:01 | |
*** yamamoto has joined #openstack-fwaas | 11:06 | |
*** yamamoto has quit IRC | 12:09 | |
*** yamamoto has joined #openstack-fwaas | 12:22 | |
*** yamamoto has quit IRC | 12:39 | |
*** yamamoto has joined #openstack-fwaas | 12:54 | |
*** yamamoto has quit IRC | 13:05 | |
xgerman_ | o/ | 14:00 |
---|---|---|
*** yamamoto has joined #openstack-fwaas | 14:00 | |
*** SridarK has joined #openstack-fwaas | 14:00 | |
SridarK | Hi FWaaS folks | 14:00 |
xgerman_ | #startmeeting fwaas | 14:01 |
openstack | Meeting started Thu Feb 15 14:01:24 2018 UTC and is due to finish in 60 minutes. The chair is xgerman_. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:01 | |
openstack | The meeting name has been set to 'fwaas' | 14:01 |
xgerman_ | #chair SridarK | 14:01 |
openstack | Current chairs: SridarK xgerman_ | 14:01 |
xgerman_ | yushiro can’t make it today… | 14:01 |
*** chandanc has joined #openstack-fwaas | 14:01 | |
xgerman_ | #topic Announcements | 14:02 |
*** openstack changes topic to "Announcements (Meeting topic: fwaas)" | 14:02 | |
xgerman_ | PTG in Dublin coming up: | 14:02 |
xgerman_ | #link https://etherpad.openstack.org/p/fwaas-rocky-planning | 14:02 |
xgerman_ | RC1 went out last week - not sure if Neutron does an RC-2 | 14:03 |
SridarK | Hopefully there are no critical issues | 14:04 |
xgerman_ | +1 | 14:05 |
xgerman_ | Vancouver is coming up as well | 14:05 |
xgerman_ | #link https://www.openstack.org/summit/vancouver-2018/ | 14:05 |
chandanc | SridarK: xgerman_ are you goint to attend the summit ? | 14:06 |
SridarK | chandanc: yes i think i will make Vancouver | 14:06 |
chandanc | ok | 14:07 |
xgerman_ | I put in two talks — if I get accepted I will be there and worst case self-fund | 14:07 |
SridarK | at least as of now - i did make the booking but who knows | 14:07 |
chandanc | :) all the best | 14:07 |
SridarK | chandanc: do u think u can make it ? | 14:07 |
chandanc | SridarK: i dont think i can | 14:07 |
xgerman_ | you can always ask for travel support | 14:08 |
SridarK | ok i think budgets are tight for all | 14:08 |
chandanc | xgerman_: is that open to all ? | 14:08 |
chandanc | i though for Core devs | 14:08 |
xgerman_ | I think it’s all | 14:08 |
chandanc | ok will try | 14:08 |
SridarK | chandanc: i think yushiro has used it in the past - so may know some details also | 14:08 |
xgerman_ | I did, too, you fill out some form and they give you money or not | 14:09 |
chandanc | let me speak to him and find out | 14:09 |
xgerman_ | but I only asked for hotel which is probably easier | 14:09 |
chandanc | let me check | 14:09 |
xgerman_ | (since they have a number of rooms they need to fill) | 14:09 |
chandanc | :) | 14:10 |
xgerman_ | aka money is already spent; flights are a different story | 14:10 |
chandanc | ok | 14:10 |
xgerman_ | definitely worth a try ;-) | 14:10 |
SridarK | +1 | 14:10 |
chandanc | ya xgerman_ +1 | 14:10 |
xgerman_ | #topic FWaaS Dashboard | 14:11 |
*** openstack changes topic to "FWaaS Dashboard (Meeting topic: fwaas)" | 14:11 | |
xgerman_ | #link https://etherpad.openstack.org/p/fwaas-v2-dashboard | 14:11 |
xgerman_ | We are still aiming to release a “Queens” version | 14:12 |
SridarK | I think among amotoki: 's list - #link https://review.openstack.org/#/c/541030/ was most important | 14:13 |
SridarK | I looked but will do some tests to understand more | 14:13 |
xgerman_ | yes, makes sense | 14:14 |
SridarK | chandanc: if SarathMekala is available can u pls have him look too | 14:14 |
chandanc | SridarK: i spoke to him, he was busy with some work this week, but said he will review them | 14:14 |
SridarK | I think we will also need to support Default FWG | 14:15 |
SridarK | chandanc: ok cool thx | 14:15 |
xgerman_ | that was working a while back… | 14:15 |
SridarK | ah so we had support already added in the Dashboard - sorry i had not tested that | 14:16 |
SridarK | will look | 14:16 |
xgerman_ | well, it pulls up the groups on the ports — not sure how much changing they allow | 14:17 |
SridarK | ok we probab need something for admin role | 14:18 |
SridarK | let me check too and we can discuss | 14:19 |
xgerman_ | +1 | 14:20 |
chandanc | SridarK: xgerman_ as we are on the topic of dashboard, i have onne suggestion | 14:20 |
xgerman_ | sure | 14:20 |
chandanc | As the creation of FWG by choosing individual ports is difficult, can we cllow creation of FWG based on VM metadata ? | 14:21 |
chandanc | like tags/base os(derived from image)/etc | 14:21 |
SridarK | ah interesting | 14:21 |
xgerman_ | yes, we had some vm_name proposal in the Google doc | 14:22 |
chandanc | this is available on vmware for creation of SG | 14:22 |
chandanc | we can start a discussion, i think it is mostly UI change right ? | 14:23 |
chandanc | xgerman_: yes that too | 14:23 |
xgerman_ | well, thinking of it that might also be an API thing so you cna have different default FWG based on OS… | 14:24 |
chandanc | yes, can be | 14:24 |
xgerman_ | we should probably file an RfE for it and flesh it out further | 14:25 |
SridarK | maybe it can be at ui but u will want the non dasboard approach to also use it | 14:25 |
SridarK | so i am not so sure | 14:25 |
chandanc | only think that need to be verified is how to keep FWG updated | 14:25 |
chandanc | *thing | 14:25 |
xgerman_ | When I understand you right if it’s say a WindowsVM you want an other Default FWG as opposed to a Linux VM | 14:27 |
chandanc | but the Default FWG association based on attributes can be done | 14:27 |
chandanc | actually iwas think more simple | 14:27 |
chandanc | now we create a fwg and add ports | 14:27 |
xgerman_ | I don’t think we have that — right now we use the same Default FWG for all VM ports | 14:28 |
chandanc | waht i was thinking was to allow auery on vm attributes to gather port snd create FWG | 14:28 |
xgerman_ | ah, so not automatically but user needs to do that | 14:28 |
chandanc | yes | 14:28 |
chandanc | just for the creation | 14:29 |
chandanc | but we can take it in steps | 14:29 |
SridarK | but we want this on when the VM comes up | 14:29 |
xgerman_ | ok, I see benefits in both | 14:30 |
xgerman_ | user wants to apply FWG to all vms with a certian property | 14:30 |
chandanc | SridarK: on boot it can be in Default FWG and then let the user update/create based on attributes for easy port selection | 14:30 |
SridarK | chandanc: yes defn leads to better user experience | 14:31 |
chandanc | ya, i think that part was only UI change | 14:31 |
xgerman_ | yeah, as I said we should look into both… they are orthogonal | 14:31 |
xgerman_ | chandanc: +1 | 14:32 |
chandanc | +1 | 14:32 |
SridarK | as it is defn harder for VM ports to go seek out ports | 14:32 |
SridarK | chandanc: may be we can discuss more on a google doc and then file a RFE | 14:32 |
chandanc | yes | 14:32 |
xgerman_ | SridarK: +1 | 14:32 |
chandanc | sure | 14:32 |
xgerman_ | we can add the UI one to the UI doc | 14:32 |
chandanc | yes | 14:33 |
*** doude has quit IRC | 14:33 | |
xgerman_ | now, If I had the link handy… | 14:34 |
chandanc | I can start a doc with the first draft | 14:35 |
xgerman_ | sounds good | 14:35 |
xgerman_ | #topic Service Driver Refactor | 14:36 |
*** openstack changes topic to "Service Driver Refactor (Meeting topic: fwaas)" | 14:36 | |
xgerman_ | trying to track that since it’s our R-1 goal | 14:36 |
xgerman_ | I don’t think we have doude… | 14:36 |
SridarK | yes we seem to have lost him | 14:37 |
SridarK | but i think we have a plan and once the release is done - he can take it to drivers | 14:38 |
xgerman_ | yeah, maybe next week… | 14:38 |
xgerman_ | SridarK: +1 | 14:38 |
xgerman_ | #topic remote FWG | 14:38 |
*** openstack changes topic to "remote FWG (Meeting topic: fwaas)" | 14:38 | |
xgerman_ | #link https://review.openstack.org/#/c/521207/ | 14:38 |
xgerman_ | now as we have the neutron_lib changes unit tests pass :-) | 14:39 |
*** threestrands_ has quit IRC | 14:39 | |
xgerman_ | I will try to get the other tests to work, too… and then I need to figure out how to get the ports into OVS | 14:39 |
chandanc | xgerman_: for remote FWG, am i correctly in thinking that the RFWG will define the source/dest ip address in a rule | 14:40 |
*** yamamoto has quit IRC | 14:41 | |
xgerman_ | well, the remote FWG contains ports and ports have the IP — so if we could do port that might be better but is only L2 | 14:41 |
xgerman_ | I am not sure if ports can change their IP easily | 14:42 |
chandanc | oh ok got it | 14:42 |
SridarK | If i am not mistaken - we are stating "traffic from any port that is a member of the Remote FWG" is allowed | 14:43 |
SridarK | for processing the FWG | 14:43 |
SridarK | * processing in the FWG | 14:43 |
xgerman_ | it’s on a rule so the traffic specified in that rule ;-) | 14:43 |
SridarK | oh yes | 14:44 |
SridarK | on the rule | 14:44 |
*** doude has joined #openstack-fwaas | 14:44 | |
*** doude has quit IRC | 14:44 | |
*** doude has joined #openstack-fwaas | 14:44 | |
chandanc | hmm, will have to think 🤔 | 14:44 |
xgerman_ | yep, I will see how SecurityGroup solves that ;-) | 14:45 |
doude | Hi sorry just realized my irc bouncer was down | 14:45 |
chandanc | xgerman_: +1 | 14:45 |
xgerman_ | doude: no worries we have time to revisit | 14:46 |
doude | ok | 14:46 |
SridarK | ok i think we can move on this and we dont really need another RFE | 14:46 |
xgerman_ | +1 | 14:46 |
xgerman_ | #topic Service Driver Refactor | 14:46 |
*** openstack changes topic to "Service Driver Refactor (Meeting topic: fwaas)" | 14:46 | |
SridarK | xgerman_: since this is part of the spec | 14:46 |
xgerman_ | +! | 14:47 |
*** yamamoto has joined #openstack-fwaas | 14:48 | |
xgerman_ | ok, doude go ahead | 14:48 |
doude | nothing much to say | 14:49 |
doude | I did nt have time to work on FWaaS since last week | 14:50 |
doude | I plan to do the RFE tomorrow | 14:50 |
xgerman_ | Sounds good. | 14:50 |
doude | and look on the rebasing work after | 14:50 |
doude | that's all for me | 14:50 |
xgerman_ | Ok | 14:51 |
SridarK | doude: sounds good | 14:51 |
xgerman_ | #topic Open Discussion | 14:51 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:51 | |
chandanc | xgerman_: SridarK do we need doc for the service driver | 14:52 |
SridarK | doude: has a google doc already | 14:52 |
chandanc | oh, will take a look | 14:52 |
doude | yes linked in the launchpad bug | 14:53 |
*** yamamoto has quit IRC | 14:53 | |
chandanc | sure doude | 14:53 |
doude | http://john.bitsurge.net/public/biglist.p2p.gz | 14:53 |
doude | oops wrong url | 14:53 |
SridarK | doude: maybe all u need to do is to tag ur current bug with RFE ? | 14:53 |
doude | https://docs.google.com/presentation/d/1_9KkNgIbWYE6tucoym8N7J2xfcQ1XwN8Zuu-ALEUD3U/edit#slide=id.p | 14:53 |
doude | may be SridarK | 14:53 |
SridarK | xgerman_: do u think that should do ? | 14:54 |
doude | I have to document to know exactly what is a RFE | 14:54 |
doude | but yes if the bug is enough I can use as RFE | 14:54 |
SridarK | All u need is a tag | 14:54 |
SridarK | look at some neutron drivers mtg logs - and u can see what usually happens | 14:55 |
doude | https://bugs.launchpad.net/neutron/+bug/1702312 | 14:55 |
openstack | Launchpad bug 1702312 in neutron "[FWaaS v2] Does not work with core plugin non based on Neutron DB model" [Undecided,In progress] - Assigned to Édouard Thuleau (ethuleau) | 14:55 |
xgerman_ | yeah, that should be enough | 14:55 |
doude | ok so I can set the RFE tag myself? | 14:56 |
SridarK | doude: https://bugs.launchpad.net/neutron/+bug/1738738 | 14:56 |
openstack | Launchpad bug 1738738 in neutron "[Neutron][Firewall] Extend FWaaS to provide DSCP filtering" [Wishlist,Confirmed] - Assigned to Reedip (reedip-banerjee) | 14:56 |
SridarK | i think u need to the put the tag in the title - maybe bad example | 14:57 |
xgerman_ | yes, you cna set the tag and assign to yourself | 14:57 |
SridarK | i think if u look at neutron driver logs u can see some example | 14:57 |
xgerman_ | +1 | 14:58 |
xgerman_ | also not sure when and if Neutron switches to storyboard | 14:58 |
xgerman_ | (that’s another thing to watch out for) | 14:58 |
SridarK | oh ok | 14:58 |
doude | I updated it with prefix '[RFE]' in the title and the tag 'rfe' | 14:59 |
xgerman_ | +1 | 14:59 |
doude | and it was already assigned to me | 14:59 |
SridarK | +1 | 14:59 |
xgerman_ | that should do it ;-) | 14:59 |
xgerman_ | #endmeeting | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu Feb 15 15:00:29 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-02-15-14.01.html | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-02-15-14.01.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-02-15-14.01.log.html | 15:00 |
SridarK | Thanks all | 15:00 |
xgerman_ | and that’s a wrap… | 15:00 |
xgerman_ | Thanks all - gotta get breakfast ;-) | 15:01 |
chandanc | bye all | 15:01 |
SridarK | :-) | 15:01 |
doude | bye | 15:04 |
*** yamamoto has joined #openstack-fwaas | 15:33 | |
*** yamamoto has quit IRC | 15:38 | |
*** chandanc has quit IRC | 16:12 | |
*** yamamoto has joined #openstack-fwaas | 16:18 | |
*** yamamoto has quit IRC | 16:23 | |
*** AlexeyAbashkin has quit IRC | 16:37 | |
*** yamamoto has joined #openstack-fwaas | 17:03 | |
*** yamamoto has quit IRC | 17:08 | |
*** chandanc has joined #openstack-fwaas | 17:29 | |
*** chandanc has quit IRC | 17:31 | |
*** yamamoto has joined #openstack-fwaas | 17:32 | |
*** yamamoto has quit IRC | 17:33 | |
*** yamamoto has joined #openstack-fwaas | 17:41 | |
*** yamamoto has quit IRC | 17:46 | |
*** lnicolas has joined #openstack-fwaas | 17:53 | |
*** SridarK has quit IRC | 17:53 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 18:01 | |
*** AlexeyAbashkin has quit IRC | 18:06 | |
*** SumitNaiksatam has joined #openstack-fwaas | 18:11 | |
*** yamamoto has joined #openstack-fwaas | 18:11 | |
*** yamamoto has quit IRC | 18:16 | |
*** yamamoto has joined #openstack-fwaas | 18:35 | |
*** yamamoto has quit IRC | 18:35 | |
*** yamamoto has joined #openstack-fwaas | 19:35 | |
*** yamamoto has quit IRC | 19:45 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 20:15 | |
*** AlexeyAbashkin has quit IRC | 20:19 | |
*** openstack has joined #openstack-fwaas | 21:45 | |
*** ChanServ sets mode: +o openstack | 21:45 | |
*** threestrands has joined #openstack-fwaas | 22:43 | |
*** threestrands has quit IRC | 22:43 | |
*** threestrands has joined #openstack-fwaas | 22:43 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!