*** longkb has joined #openstack-fwaas | 00:26 | |
*** yamamoto has joined #openstack-fwaas | 01:14 | |
*** annp has joined #openstack-fwaas | 02:13 | |
*** hoangcx has quit IRC | 03:04 | |
*** longkb1 has quit IRC | 03:04 | |
*** hoangcx has joined #openstack-fwaas | 03:05 | |
openstackgerrit | wangqi proposed openstack/neutron-fwaas master: [sytle] use http code constant instead of int https://review.openstack.org/571367 | 03:05 |
---|---|---|
*** longkb1 has joined #openstack-fwaas | 03:06 | |
*** annp has quit IRC | 03:25 | |
*** annp has joined #openstack-fwaas | 03:31 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 05:04 | |
*** AlexeyAbashkin has quit IRC | 05:23 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 05:28 | |
*** AlexeyAbashkin has quit IRC | 05:35 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 07:30 | |
*** velizarx has joined #openstack-fwaas | 08:11 | |
*** longkb has quit IRC | 10:54 | |
*** annp has quit IRC | 10:57 | |
*** yamamoto has quit IRC | 11:41 | |
*** velizarx has quit IRC | 12:08 | |
*** velizarx has joined #openstack-fwaas | 12:11 | |
*** yamamoto has joined #openstack-fwaas | 12:41 | |
*** yamamoto has quit IRC | 12:46 | |
*** yamamoto has joined #openstack-fwaas | 12:56 | |
*** wkite has joined #openstack-fwaas | 13:46 | |
*** wkite has quit IRC | 13:47 | |
*** wkite has joined #openstack-fwaas | 13:49 | |
*** yushiro has joined #openstack-fwaas | 13:51 | |
*** hongbin has joined #openstack-fwaas | 13:56 | |
*** longkb has joined #openstack-fwaas | 13:56 | |
yushiro | 1 minute | 13:59 |
yushiro | #startmeeting fwaas | 14:00 |
openstack | Meeting started Thu May 31 14:00:20 2018 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:00 | |
openstack | The meeting name has been set to 'fwaas' | 14:00 |
yushiro | Hi | 14:00 |
wkite | hi | 14:00 |
longkb | o/ | 14:01 |
yushiro | #chair yushiro xgerman_ | 14:01 |
openstack | Current chairs: xgerman_ yushiro | 14:01 |
xgerman_ | o/ | 14:01 |
yushiro | I can't see Sridar today.. | 14:01 |
njohnston | o/ | 14:01 |
yushiro | OK, let's start fwaas meeting. | 14:02 |
yushiro | #topic announcements | 14:02 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:02 | |
yushiro | OpenStack summit Vancouver has finished. How was the summit? :) | 14:03 |
*** SridarK has joined #openstack-fwaas | 14:03 | |
yushiro | Hi SridarK :) Welcome. | 14:03 |
SridarK | Hi All Sorry to be late | 14:03 |
yushiro | #chair SridarK | 14:03 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:03 |
xgerman_ | summit was great | 14:03 |
SridarK | xgerman_: +1 | 14:03 |
yushiro | SridarK, Currently, we're talking about OpenStack summit in announcement topic. | 14:04 |
SridarK | thx yushiro | 14:04 |
SridarK | yes lower attendance than prev Vancouver summit | 14:04 |
SridarK | but i heard from folks that deployments are up and more with integrated (VM + Containers + Bare metal) | 14:05 |
xgerman_ | #link https://redmonk.com/sogrady/2018/05/25/openstack-at-a-crossroads/ | 14:05 |
njohnston | excellent | 14:05 |
yushiro | +1 | 14:06 |
xgerman_ | yeah, lot’s of quality people - no longer the ones who are just t=here for parties and T-Shirts… | 14:06 |
SridarK | we had a decent amt of folks in the FWaaS L7 session - not a sellout by any means | 14:06 |
SridarK | but got some good feedback | 14:06 |
njohnston | good! | 14:06 |
yushiro | wow, great. | 14:06 |
* njohnston has some time slated this afternoon to locate and watch the video | 14:07 | |
SridarK | Main take away - we need more investigation on the potential reference implementation | 14:07 |
xgerman_ | yep, one thing to watch: The foundation has been asked to bring in new projects so we likely will see more new faces (like kata containers) | 14:07 |
xgerman_ | lot’s of sessions focused on how we (as a community) can influence that + and how we can get synergies (dwaas on kata would be grand) | 14:08 |
SridarK | xgerman_: +1 yes Kata Containers had a lot attention - i was not able to attend all the sessions but hope to catch the video | 14:08 |
xgerman_ | yep, the seconf top-level “area” is CI wit the zuul project | 14:08 |
SridarK | In our L7 session, possible use case to integrate with SFC to send DPI flows thru an appliance | 14:09 |
xgerman_ | +1 | 14:09 |
yushiro | Aha. | 14:09 |
SridarK | xgerman_: would it be fair to say CI , Kata Containers and Edge Cloud were the focus areas | 14:09 |
xgerman_ | well, there was also multicloud and k8s | 14:10 |
SridarK | xgerman_: yes indeed | 14:10 |
xgerman_ | also shoutout to diversity: for the keynote we had almost 50-50 female-male | 14:12 |
njohnston | nice | 14:12 |
yushiro | :) | 14:13 |
SridarK | there were a few sessions on diversity as well | 14:13 |
xgerman_ | yeah, OT but diversity and ethics will be big in the coming years for IT | 14:14 |
SridarK | We also had a quick sync with mlavalle and Hongbin on the Huawei API proposal and found things to be a quite aligned, a few specs will be proposed for the few additional things needed | 14:14 |
xgerman_ | +1 | 14:14 |
njohnston | +1 | 14:14 |
yushiro | OK | 14:14 |
yushiro | anything else to announce? | 14:16 |
SridarK | nothing more from me | 14:16 |
yushiro | SridarK, thanks. | 14:16 |
xgerman_ | we got a nice shout-out in the neutron project uopdate | 14:17 |
xgerman_ | worth watching the video | 14:17 |
SridarK | oh yes | 14:17 |
yushiro | xgerman_, definitely YES :) | 14:17 |
njohnston | very nice! | 14:17 |
yushiro | OK, let's move on. | 14:18 |
yushiro | #topic Rocky | 14:18 |
*** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:18 | |
yushiro | [WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:19 |
xgerman_ | ok, the plugin is done | 14:19 |
yushiro | xgerman_, cool !! | 14:20 |
xgerman_ | #link https://review.openstack.org/#/c/521207/ | 14:20 |
xgerman_ | started on the client | 14:20 |
njohnston | very nice xgerman_! | 14:20 |
SridarK | oh nice | 14:20 |
xgerman_ | #link https://review.openstack.org/#/c/571331/ | 14:20 |
xgerman_ | and I probably need critical reviews for the cojecture flows: | 14:21 |
xgerman_ | https://review.openstack.org/#/c/564888/ | 14:21 |
xgerman_ | right now trying to adapt what is done in SG | 14:21 |
SridarK | ok makes sense | 14:22 |
xgerman_ | yeah, and we also need to have that for L3 but I haven’t started on that | 14:22 |
yushiro | xgerman_, OK, I can review them. I'll ask some help to annp as well. | 14:22 |
xgerman_ | so if somebody has cycles… | 14:22 |
xgerman_ | yushiro: thanks | 14:22 |
yushiro | OK, next. | 14:23 |
yushiro | Logging for FWaaS(SPEC): https://review.openstack.org/#/c/509725/ | 14:24 |
yushiro | This SPEC has been merged today. Thank you so much for reviewing! | 14:24 |
SridarK | Nice | 14:24 |
longkb | nice :) | 14:24 |
njohnston | Excellent! Looking forward to this implementation. | 14:24 |
SridarK | yushiro: is the plan to start some implementation in Rocky | 14:24 |
yushiro | SridarK, Yes. We're going to support L3 logging in Rocky first. | 14:25 |
SridarK | sounds good | 14:25 |
yushiro | So, hoangcx has been pushed some patches and ready for review. | 14:26 |
SridarK | ah ok will start looking | 14:26 |
yushiro | OK, thanks. | 14:27 |
yushiro | #topic specs | 14:27 |
*** openstack changes topic to "specs (Meeting topic: fwaas)" | 14:27 | |
yushiro | (wkite) fwaas 2.0 address groups support https://review.openstack.org/557137 | 14:27 |
yushiro | wkite, Hi. It's your turn :) | 14:28 |
wkite | ok | 14:28 |
wkite | there are two reviews added today,thx for review | 14:29 |
SridarK | +1 | 14:29 |
yushiro | gooooood :) | 14:29 |
wkite | one problem is the url of address group | 14:29 |
*** longkb has quit IRC | 14:29 | |
SridarK | wkite: yes use it as on the other resources | 14:31 |
SridarK | IIRC 'fw' was for v1 - i will need to double check | 14:31 |
wkite | the old url is /fw | 14:32 |
yushiro | What is the problem? Currently, v2.0/fw/address_groups. I think it should be v2.0/fwaas/address_groups. See https://developer.openstack.org/api-ref/network/v2/#fwaas-v2-0-current-fwaas-firewall-groups-firewall-policies-firewall-rules | 14:32 |
njohnston | +12 | 14:32 |
SridarK | wkite: did u also have an implemtation as PoC | 14:32 |
yushiro | SridarK, Yes, that's correct. | 14:32 |
wkite | yes | 14:32 |
yushiro | Hongbin has commented the same topic. | 14:34 |
wkite | my github https://github.com/wkite/neutron_fwaas | 14:34 |
yushiro | In addition, I'm not sure it will occur 403 by running GET. Let me check on devstack. | 14:35 |
yushiro | wkite, After checking, I'll feedback to your SPEC. | 14:37 |
wkite | thx | 14:37 |
yushiro | OK, | 14:39 |
yushiro | Is there any SPEC ? | 14:39 |
yushiro | OK, let's move on. | 14:40 |
SridarK | wkite: thx | 14:40 |
yushiro | #topic Horizon support | 14:40 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:40 | |
*** longkb has joined #openstack-fwaas | 14:40 | |
yushiro | Sarath is not here today.. | 14:41 |
SridarK | Will need to reach out to SarathMekala | 14:41 |
yushiro | Ya | 14:41 |
SridarK | hopefully next mtg - we can get some plan in place | 14:41 |
yushiro | amotoki has pushed some patches : https://review.openstack.org/#/q/status:open+project:openstack/neutron-fwaas-dashboard | 14:41 |
SridarK | I think we had a few items to close on L2 support as well | 14:42 |
yushiro | ok | 14:43 |
yushiro | #topic bugs | 14:44 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:44 | |
yushiro | Launchpad(filtered by tag 'fwaas'): http://urx2.nu/C7UI | 14:44 |
SridarK | Oh yes we have not done our triage yet | 14:45 |
yushiro | https://bugs.launchpad.net/neutron/+bug/1701487 | 14:47 |
openstack | Launchpad bug 1701487 in neutron "Deletion of ERROR state firewall goes stuck into PENDING_DELETE state" [Medium,New] - Assigned to Reedip (reedip-banerjee) | 14:47 |
yushiro | Oops, sorry, it was v1. | 14:48 |
SridarK | Ah yes - this was seen before but i recall us fixing something like this | 14:48 |
yushiro | yes. How about bug checking in next week? | 14:49 |
SridarK | yushiro: ok lets do that | 14:49 |
yushiro | SridarK, thx! | 14:49 |
yushiro | #topic Open Discussion | 14:50 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:50 | |
yushiro | I wanted to join Vancouver!! I missed fwaas folks :) However, I was very glad to hear that annp could discuss with SridarK and xgerman_ at Vancouver. | 14:52 |
SridarK | yushiro: we met first at Vancouver | 14:52 |
xgerman_ | yes, we got. a lot done | 14:52 |
yushiro | SridarK, Oh, really!? How wonderful. | 14:53 |
SridarK | yes indeed it was a good discussion with annp | 14:53 |
SridarK | yushiro: we certainly missed seeing u | 14:54 |
SridarK | I heard some folks saying that maybe they may combine the PTG and summit like before due to travel costs | 14:54 |
yushiro | SridarK, me too! I really want to take a photo with all FWaaS members :) | 14:54 |
SridarK | :-) | 14:55 |
* njohnston is looking forward to hopefully being at the next PTG | 14:55 | |
SridarK | yushiro: photoshop ;-) | 14:55 |
yushiro | +1 | 14:55 |
yushiro | njohnston, I can join PTG! Hopefully we can meet at Denver ! | 14:55 |
njohnston | I would love to see you again, yushiro! All of you as well! | 14:56 |
SridarK | it seems now with OpenStack summit, PTG, Kubecon and other conferences budgets are getting tight | 14:56 |
SridarK | njohnston: +1 | 14:56 |
yushiro | +100 | 14:56 |
yushiro | SridarK, Indeed. | 14:56 |
yushiro | Folks, we should increase our 'lucky' point. If this point is high, we can get travel support :p | 14:58 |
SridarK | The summit after Berlin will also be at Denver - in case any of u did not see the annoucement | 14:58 |
xgerman_ | +1 | 14:59 |
SridarK | ok folks have a great week | 15:00 |
njohnston | \o | 15:00 |
yushiro | aha, it's time. | 15:00 |
yushiro | #endmeeting | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu May 31 15:00:21 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
SridarK | bye all | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-31-14.00.html | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-31-14.00.txt | 15:00 |
yushiro | Bye bye | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-31-14.00.log.html | 15:00 |
*** wkite has quit IRC | 15:02 | |
*** yushiro has quit IRC | 15:08 | |
*** Swami_ has joined #openstack-fwaas | 15:15 | |
*** AlexeyAbashkin has quit IRC | 15:37 | |
hongbin | SridarK: xgerman_ hi Sridar German, want to have a quick follow-up with our discussion in the summit | 15:40 |
hongbin | in the case that there are multiple firewall policies associate with the same neutron port, is there any way to determine the order of the firewall policies that are applied? | 15:42 |
xgerman_ | mmh, we have order on rules but not policies | 15:43 |
hongbin | i see | 15:43 |
xgerman_ | or fwgs | 15:43 |
hongbin | part of our proposal is to introduce a field to specify the priority | 15:44 |
hongbin | for example, each firewall policies could have a number between 1 and 100 | 15:44 |
hongbin | then, this number determine the applied order | 15:45 |
hongbin | is it a reasonable approach, or there is a better approach to address that? | 15:45 |
xgerman_ | well, a fwg can only have one ingress and one egress policy | 15:46 |
xgerman_ | so in case you have multiple fwg on a port we would just run through each and if any of them denies deny the reaffic | 15:47 |
hongbin | i see | 15:47 |
hongbin | so right now, we assume that the order of applied rules doesn't matter | 15:47 |
xgerman_ | we have an order of the rules inside the policy | 15:48 |
hongbin | yes, i get this part | 15:48 |
xgerman_ | but we dopn’t have an order how we apply the rules from multiple fwg | 15:48 |
hongbin | yes, this is the problem we wan to address | 15:49 |
hongbin | however, if the assumption is that permutation order of fwg to produce the same result, then this model is reasonable | 15:50 |
hongbin | s/any permutation order/ | 15:50 |
xgerman_ | yeah, that’s our assumption | 15:50 |
hongbin | i see | 15:50 |
xgerman_ | so if I wanted the granular control of ordered rules I could always just apply one FWG er port | 15:52 |
xgerman_ | but we don’t have much experience in the filed if that’s practical — or if we need to do soemthign different | 15:53 |
hongbin | i see | 15:54 |
hongbin | i will try to ask why they care the order of the fwg | 15:54 |
hongbin | i guess there are some use cases behind | 15:54 |
hongbin | for me, the model of one fwg per port sounds a bit limited | 15:55 |
xgerman_ | yes, as I said I am not sure if that’s practical and if enough people care about the order among FWG… | 15:56 |
hongbin | sure, i will communicate about that | 15:57 |
hongbin | xgerman_: thanks for your feedback | 15:57 |
*** longkb has quit IRC | 16:06 | |
*** amotoki has quit IRC | 16:35 | |
*** amotoki has joined #openstack-fwaas | 16:38 | |
*** SumitNaiksatam has joined #openstack-fwaas | 16:56 | |
*** SridarK has quit IRC | 17:17 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 17:32 | |
*** AlexeyAbashkin has quit IRC | 17:45 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 17:45 | |
*** AlexeyAbashkin has quit IRC | 17:45 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 17:46 | |
*** Alexey_Abashkin has joined #openstack-fwaas | 18:04 | |
*** AlexeyAbashkin has quit IRC | 18:07 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 18:07 | |
*** AlexeyAbashkin has quit IRC | 18:13 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 20:33 | |
*** AlexeyAbashkin has quit IRC | 20:50 | |
*** Swami_ has quit IRC | 21:57 | |
*** hongbin has quit IRC | 22:41 | |
*** SumitNaiksatam has quit IRC | 23:26 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!