*** longkb has joined #openstack-fwaas | 00:34 | |
*** yamamoto has joined #openstack-fwaas | 00:46 | |
*** yamamoto has quit IRC | 00:52 | |
*** yamamoto has joined #openstack-fwaas | 01:48 | |
*** yamamoto has quit IRC | 01:54 | |
*** yamamoto has joined #openstack-fwaas | 02:50 | |
*** yamamoto has quit IRC | 02:54 | |
*** yamamoto has joined #openstack-fwaas | 03:51 | |
*** hoangcx has quit IRC | 03:54 | |
*** yamamoto has quit IRC | 03:56 | |
*** hoangcx has joined #openstack-fwaas | 04:07 | |
*** yamamoto has joined #openstack-fwaas | 04:41 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 05:58 | |
*** AlexeyAbashkin has quit IRC | 06:43 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 06:43 | |
*** hoangcx has quit IRC | 06:48 | |
*** hoangcx has joined #openstack-fwaas | 06:49 | |
*** Alexey_Abashkin has joined #openstack-fwaas | 07:23 | |
*** AlexeyAbashkin has quit IRC | 07:24 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 07:24 | |
*** annp has joined #openstack-fwaas | 07:34 | |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 08:09 |
---|---|---|
openstackgerrit | Yushiro FURUKAWA proposed openstack/neutron-fwaas master: WIP: Add python binding for libnetfilter_log https://review.openstack.org/530694 | 08:42 |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 08:43 |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 09:12 |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 09:21 |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 09:24 |
openstackgerrit | Nguyen Phuong An proposed openstack/neutron-fwaas master: Firewall L3 logging extension https://review.openstack.org/576338 | 09:29 |
openstackgerrit | Yushiro FURUKAWA proposed openstack/neutron-fwaas master: Migrate to stestr as unit tests runner https://review.openstack.org/505526 | 09:51 |
*** annp has quit IRC | 10:20 | |
*** yamamoto has quit IRC | 11:05 | |
*** yamamoto has joined #openstack-fwaas | 11:06 | |
*** yamamoto has quit IRC | 11:10 | |
*** yamamoto has joined #openstack-fwaas | 12:04 | |
*** longkb has quit IRC | 12:28 | |
*** yamamoto has quit IRC | 12:51 | |
*** yamamoto has joined #openstack-fwaas | 13:25 | |
*** annp has joined #openstack-fwaas | 13:34 | |
*** yamamoto has quit IRC | 13:36 | |
*** yamamoto has joined #openstack-fwaas | 13:48 | |
*** wkite has joined #openstack-fwaas | 13:56 | |
*** longkb has joined #openstack-fwaas | 14:00 | |
xgerman_ | o/ | 14:00 |
longkb | o/ | 14:00 |
*** SridarK has joined #openstack-fwaas | 14:00 | |
SridarK | Hi FWaaS folks | 14:01 |
annp | hi | 14:01 |
wkite | hi | 14:01 |
SridarK | #startmeeting fwaas | 14:01 |
openstack | Meeting started Thu Jun 21 14:01:42 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:01 | |
openstack | The meeting name has been set to 'fwaas' | 14:01 |
SridarK | #chair xgerman_ | 14:01 |
openstack | Current chairs: SridarK xgerman_ | 14:01 |
*** yushiro has joined #openstack-fwaas | 14:02 | |
*** annp has quit IRC | 14:02 | |
yushiro | Hi | 14:02 |
yushiro | Sorry I was late. | 14:02 |
xgerman_ | #chairs yushiro | 14:02 |
xgerman_ | #chair yushiro | 14:02 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:02 |
SridarK | ok lets get started | 14:03 |
SridarK | yushiro: ur turn today ? | 14:03 |
yushiro | Yes, SridarK . | 14:03 |
SridarK | yushiro: pls go ahead :-) | 14:03 |
yushiro | #topic announcements | 14:03 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:03 | |
*** annp has joined #openstack-fwaas | 14:04 | |
yushiro | Does anyone have any announcement? | 14:04 |
xgerman_ | travel support for PTG ends 6/30 or so | 14:04 |
xgerman_ | Programming Comittee nomination for Berlin end 6/28 | 14:05 |
yushiro | xgerman_, +1 :) | 14:05 |
yushiro | #link https://www.openstack.org/ptg/#tab_travel | 14:05 |
annp | +1 | 14:06 |
xgerman_ | CfP for Berlin ends 7/17 | 14:06 |
njohnston | o/ | 14:06 |
xgerman_ | and R3 is near | 14:06 |
yushiro | Ah, Yes. That's a good information. > CFP (7/17) | 14:06 |
yushiro | We're R-10 now : https://releases.openstack.org/rocky/schedule.html | 14:08 |
yushiro | OK | 14:08 |
yushiro | #topic Rocky | 14:08 |
*** openstack changes topic to "Rocky (Meeting topic: fwaas)" | 14:08 | |
yushiro | [WIP] Adds remote firewall group: https://review.openstack.org/521207 | 14:09 |
yushiro | xgerman_, Please go ahead :) | 14:09 |
xgerman_ | didn’t do much progress (internal priorities) but deployed FWaaS V2 with it and it ddn’t blow up | 14:10 |
yushiro | OK | 14:10 |
yushiro | In Japan, Jun is also very busy with another task(writing report and presentation to our boss or something...) | 14:11 |
yushiro | Haha, so, I'm glad to join today's meeting :p | 14:12 |
annp | yushiro, you're boss :D | 14:12 |
xgerman_ | ;-) | 14:12 |
yushiro | Next. Logging for FWaaS v2 | 14:12 |
longkb | yushiro. I saw it. There is holiday this week in Japan | 14:13 |
yushiro | annp, Please go ahead | 14:13 |
yushiro | longkb, Yes, Please keep in you mind :p | 14:13 |
longkb | hi folks, I am a new comer in fwaas, from Fujitsu Vietnam Limitted. | 14:13 |
SridarK | longkb: welcome | 14:13 |
longkb | SridarK, thanks | 14:14 |
annp | regards to logging, we're making progress. | 14:14 |
xgerman_ | welcome | 14:15 |
longkb | thanks xgerman :) | 14:15 |
yushiro | welcome!! ( I knew it :p | 14:15 |
annp | I'd like to get your eyes in https://review.openstack.org/#/c/529814/ as first of serial logging | 14:15 |
annp | here is list patch for logging https://review.openstack.org/#/q/topic:bug/1720727+(status:open) | 14:16 |
annp | I'd like to get more review on https://review.openstack.org/#/c/574683/ | 14:17 |
longkb | annp +1 | 14:18 |
yushiro | Today, I had bandwidth for reviewing. I'll review them. | 14:18 |
annp | yushiro, thank you so much . | 14:18 |
annp | That's all for firewall logging. | 14:18 |
annp | yushiro, please go ahead. | 14:19 |
yushiro | Again, we're targeting fwg L3 logging in this cycle(Rocky). | 14:19 |
yushiro | OK, thanks annp | 14:19 |
*** mlavalle has joined #openstack-fwaas | 14:19 | |
annp | yushiro, +1 | 14:19 |
yushiro | #topic specs | 14:19 |
*** openstack changes topic to "specs (Meeting topic: fwaas)" | 14:19 | |
yushiro | (wkite) fwaas 2.0 address groups support https://review.openstack.org/557137 | 14:20 |
wkite | ok | 14:20 |
wkite | i have pushed some patches to gerrit.All the questions raised have been resolved. | 14:21 |
annp | wkite +1. | 14:21 |
yushiro | wkite, Could you reply my comments? | 14:22 |
yushiro | wkite, Thanks for your update. | 14:22 |
wkite | yushiro: All right. I'll get back to you as soon as possible. | 14:22 |
annp | wkite: will we start with l2 ovs reference implementation, right? | 14:22 |
* mlavalle would like to bring up a point in the bugs section (if there is one) or in the open discussion section | 14:22 | |
SridarK | wkite: thx once the comments are addressed - i think we can move fwd | 14:23 |
wkite | annp: I'm not sure ether I can do it. | 14:24 |
yushiro | mlavalle, Of course!!!! | 14:24 |
mlavalle | :-) | 14:24 |
yushiro | Let's review more on this SPEC> | 14:25 |
yushiro | #topic Horizon support | 14:25 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:25 | |
annp | wkite: Let's discuss on gerrit. :) | 14:26 |
wkite | SridarK: +1 | 14:26 |
SridarK | Oh looks like SarathMekala is not on today | 14:26 |
wkite | annp: ok | 14:26 |
yushiro | Sarath is not here today. SridarK,did you get any reply from him? | 14:26 |
SridarK | yushiro: he did attend last week | 14:26 |
yushiro | SridarK, wow, sorry. I missed it. | 14:27 |
SridarK | he is evaluating any gaps to be addressed in R | 14:27 |
amotoki | what are expected as feature gaps in the current v2.0 dashboard? | 14:27 |
SridarK | amotoki: i think we need to validate with L2 support - something Sarath was investigating | 14:27 |
SridarK | He mentioned he was in the tail end of an internal release - will follow up on this | 14:28 |
amotoki | yeah, L2 support is one of gaps. I am not sure we have others or not. | 14:28 |
SridarK | amotoki: i think most others u have squashed too | 14:28 |
longkb | SridarK: +1 | 14:28 |
amotoki | I have no actual list of such gaps. | 14:29 |
SridarK | anyways let me check in and see if he can attend next week or provide an update on email | 14:29 |
amotoki | it would be nice if we have an up-to-date list :) | 14:29 |
SridarK | amotoki: +1 | 14:29 |
yushiro | Aha. Currently, fwaas dashboard can filter L2 port. I cannot catch up the latest state for dashboard. We need to enhance more regarding L2 port? | 14:29 |
xgerman_ | we should show the compute name/id along port if available | 14:30 |
longkb | yushiro: IMO, we cannot add fwg to l2 port | 14:30 |
longkb | from Horizon | 14:30 |
yushiro | xgerman_, Aha. Thanks. | 14:30 |
xgerman_ | I just did yesterday | 14:30 |
yushiro | longkb, Oh, really? I just fixed to filter L2 port...( Am I missing something..) | 14:31 |
amotoki | I tend to avoid writing patches by myself as I usually fail to get reviews :( and :) | 14:31 |
yushiro | amotoki, yeeeees. I always think it is very helpful and so sorry for lack of review... | 14:32 |
xgerman_ | +1 | 14:32 |
SridarK | longkb: maybe u can capture into a bug - so we can track | 14:32 |
annp | SridarK +1 | 14:33 |
yushiro | I'D LIKE TO REVIEW/WRITE PATCHES!!! I hope I had a 4 hands and 2 keyboards... :P | 14:33 |
SridarK | I did not think we had an issue here either from the CLI | 14:33 |
longkb | SridarK +1 I will report this bug asap | 14:33 |
njohnston | yushiro +100 | 14:33 |
xgerman_ | I sleep too much, but that’s me | 14:33 |
annp | yushiro ++ | 14:34 |
yushiro | njohnston, now I'm only 2 hands. Haha | 14:34 |
SridarK | yushiro: :-) i think u can add stand up comedy to ur many talents :-) | 14:34 |
yushiro | SridarK, Hahaha | 14:34 |
yushiro | OK, next topic. | 14:35 |
yushiro | #topic bugs | 14:35 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:35 | |
yushiro | mlavalle, Hi :) | 14:35 |
mlavalle | hi | 14:35 |
SridarK | yushiro: we shd do a triage | 14:35 |
yushiro | SridarK, Ah, yes. | 14:35 |
SridarK | lets defn get this done early next week | 14:35 |
xgerman_ | +1 | 14:35 |
SridarK | maybe Mon ? | 14:36 |
xgerman_ | sure | 14:36 |
SridarK | but pls go ahead | 14:36 |
mlavalle | I just want to make sure this bug is in the radar screen of the team: https://bugs.launchpad.net/neutron/+bug/1762454 | 14:36 |
openstack | Launchpad bug 1762454 in neutron "FWaaS: Invalid port error on associating ports (distributed router) to firewall group" [Medium,Triaged] - Assigned to Sridar Kandaswamy (skandasw) | 14:36 |
SridarK | mlavalle: yes | 14:36 |
mlavalle | It was discussed last week in the L3 sub-team meeting | 14:36 |
mlavalle | and I took the action of item of bringing it up here | 14:36 |
SridarK | mlavalle: i have discussed it with Swami | 14:36 |
mlavalle | Thank you SridarK | 14:37 |
SridarK | will get some traction on it - adding the validation fix is easy - we need to evaluate if the namespace mappings etc dont mess up the datapath | 14:37 |
mlavalle | thanks for the update | 14:38 |
SridarK | mlavalle: thx for the kick to remind :-) will sync up with Swami and get it moving | 14:38 |
mlavalle | :-) | 14:38 |
yushiro | :))) | 14:38 |
SridarK | as u can see, i am trying to get together with yushiro on his act :-) | 14:39 |
njohnston | Should I bring up the issue with debian/wsgi/l3 agent/fwaas in the bugs section, or wait to see if there is time in the open discussion section? | 14:39 |
SridarK | njohnston: pls yes | 14:39 |
yushiro | SridarK, Sure. | 14:39 |
yushiro | njohnston, Yes, please! | 14:39 |
SridarK | njohnston: thx for the detailed email | 14:39 |
yushiro | SridarK, njohnston ++1 Your mail is so helpful for sync up with current state. | 14:40 |
SridarK | so it seems agent rpc is lost on debian | 14:40 |
njohnston | It does, yes, but I cannot pinpoint why that would be happening | 14:40 |
njohnston | and why it would only happen with the specific combination of wsgi, debian, and fwaas | 14:41 |
njohnston | it occurs regardless of fwaas v1 or v2 | 14:41 |
njohnston | but it does not happen when wsgi is not engaged | 14:41 |
njohnston | and it does not happen on centos or ubuntu | 14:41 |
SridarK | njohnston: do u think it is something on some package versions across the distros | 14:41 |
yushiro | annp, Did you reproduce njohnston's situation?? I thought that you used to deploy with Debian. | 14:41 |
njohnston | I only sent the email to the cores, but perhaps I should sent to openstack-dev | 14:42 |
xgerman_ | yeah, I am no debian expert — test on ubuntu | 14:42 |
SridarK | njohnston: +1 | 14:42 |
xgerman_ | so broader audience is useful | 14:42 |
annp | yushiro, yes. I did. | 14:42 |
yushiro | njohnston, I'll also try to deploy on Ubuntu16.04 and will share the state. | 14:43 |
njohnston | Just to note, wsgi is essential because zigo is attempting to package an all-python 3 set of packages, and eventlet has some kind of issue with python 2 IIRC | 14:44 |
yushiro | annp, OK, so, could you reply njohnston's mail with your detail situation? | 14:44 |
njohnston | Let me send it to openstack-dev and annp then perhaps you can reply to that | 14:44 |
annp | njohnston, yushiro, yes. I will. | 14:45 |
yushiro | njohnston, +1 | 14:46 |
annp | njohnston: +1 | 14:47 |
zigo | njohnston: The issue is SSL + Python 3 + Eventlet == SSL handshake crash. | 14:47 |
zigo | This is known since 2015... | 14:47 |
yushiro | zigo, Oh, it is potential bug.. | 14:48 |
njohnston | Ah, thanks for refreshing my memory zigo | 14:48 |
zigo | I don't think the issue is Debian specific. | 14:48 |
zigo | It is specific to using neutron-api and neutron-rpc-server, maybe also python 3 ... | 14:49 |
njohnston | yushiro: the SSL handshake crash is relevant to why wsgi is important, but not relevant to the issue in question | 14:49 |
yushiro | njohnston, OK. | 14:49 |
njohnston | OK, mail sent to openstack-dev, so we can all pool our info there | 14:50 |
yushiro | njohnston, Thanks!! | 14:50 |
annp | zigo, How can I update fwaas source with up-to-date in the vm? | 14:50 |
yushiro | #topic Open Discussion | 14:51 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:51 | |
annp | zigo, because I saw fwaas source in the vm not update to date. | 14:51 |
zigo | annp: You mean with HEAD of git? | 14:52 |
zigo | annp: Well, it's just in /usr/lib/python3/dist-packages ... | 14:52 |
zigo | annp: I guess you could simply replace the code there. | 14:52 |
zigo | Quick and dirty rm -r and a cp -r should do. | 14:52 |
yushiro | Today, ndefigueiredo is not here. So, let's skip Stateless security | 14:52 |
xgerman_ | +1 | 14:52 |
annp | zigo, thanks. I got it. :) | 14:53 |
zigo | yushiro: njohnston: The thing is, in the Py3 + SSL situation, we have no choice but to use neutron-api + neutron-rpc-server instead of neutron-server daemon, and that may be source of new bugs. annp already fixed one with the ovn driver ... | 14:54 |
zigo | Not sure, just double-guessing what's possible.\ | 14:54 |
njohnston | zigo: When you deploy on centos or ubuntu you're using the same setup, though, right? I would expect that if that was the issue, it would manifest on ubuntu and centos as well. | 14:55 |
zigo | njohnston: No you're not. neutron-server runs instead of neutron-api and neutron-rpc-server. | 14:55 |
njohnston | ah, ok | 14:55 |
zigo | Because they're using Python 2, then can run neutron-server using Eventlet and SSL. | 14:55 |
zigo | I can't... | 14:56 |
zigo | So, instead, in Debian, neutron-api does the requests over uwsgi, and rpc-server does the rabbitmq stuff. | 14:56 |
yushiro | zigo, could you reply e-mail that your local.conf of devstack? I'll try it. | 14:57 |
zigo | yushiro: I'm not using devstack, I'm using Debian packages. | 14:57 |
xgerman_ | packaging is downstream from us | 14:57 |
yushiro | zigo, Aha. OK. | 14:57 |
annp | njohnston: I also have a patch in devstack for deploy neutron-api in uwsgi and rpc-server in eventlet at https://review.openstack.org/#/c/473718/ | 14:57 |
zigo | yushiro: What you could do is run puppet-openstack to get it installed. | 14:58 |
zigo | That's very easy. | 14:58 |
yushiro | zigo, Thanks. puppet-openstack. | 14:58 |
zigo | yushiro: I can reply with the way to do it with puppet-openstack if you like? | 14:58 |
annp | njohnston: you can ./stack with the patch. | 14:58 |
njohnston | Thanks annp that is very helpful | 14:58 |
*** Swami has joined #openstack-fwaas | 14:59 | |
yushiro | zigo, Please send us !! It is very helpful. | 14:59 |
SridarK | time check | 14:59 |
yushiro | annp's patch can reproduce similar environment by using devstack,. | 14:59 |
yushiro | Wow, 1 minutes. | 14:59 |
njohnston | Thanks everyone | 15:00 |
zigo | I need to go back home now (2 hours driving from Geneva), but I'll reply tonight. | 15:00 |
*** longkb1 has joined #openstack-fwaas | 15:00 | |
yushiro | OK guys, that's good discussion. will sync up e-mail more. Thanks!! | 15:00 |
SridarK | thx all | 15:00 |
xgerman_ | +1 | 15:00 |
yushiro | #endmeeting | 15:00 |
xgerman_ | o/ | 15:00 |
longkb1 | o/ | 15:00 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 15:00 | |
openstack | Meeting ended Thu Jun 21 15:00:22 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-06-21-14.01.html | 15:00 |
annp | yushiro, will sync up via email. | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-06-21-14.01.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-06-21-14.01.log.html | 15:00 |
yushiro | annp, Thanks. | 15:00 |
mlavalle | zigo: safe driving! | 15:00 |
annp | thank all. | 15:01 |
*** longkb1 has quit IRC | 15:01 | |
*** longkb has quit IRC | 15:02 | |
*** annp has quit IRC | 15:03 | |
*** wkite has quit IRC | 15:09 | |
*** SridarK has quit IRC | 15:23 | |
*** mlavalle has left #openstack-fwaas | 15:33 | |
*** yushiro has quit IRC | 15:36 | |
*** yushiro has joined #openstack-fwaas | 15:42 | |
*** yushiro has quit IRC | 16:01 | |
*** raopajay has joined #openstack-fwaas | 16:33 | |
*** yamamoto has quit IRC | 16:38 | |
*** yamamoto has joined #openstack-fwaas | 16:46 | |
*** yamamoto has quit IRC | 16:51 | |
*** yamamoto has joined #openstack-fwaas | 16:55 | |
*** yamamoto has quit IRC | 17:00 | |
*** Swami has quit IRC | 17:15 | |
*** SumitNaiksatam has joined #openstack-fwaas | 17:26 | |
*** yamamoto has joined #openstack-fwaas | 17:56 | |
*** yamamoto has quit IRC | 18:04 | |
*** AlexeyAbashkin has quit IRC | 18:10 | |
*** SumitNaiksatam has quit IRC | 18:31 | |
*** yamamoto has joined #openstack-fwaas | 19:01 | |
*** yamamoto has quit IRC | 19:06 | |
*** yamamoto has joined #openstack-fwaas | 20:02 | |
*** yamamoto has quit IRC | 20:07 | |
*** yamamoto has joined #openstack-fwaas | 21:04 | |
*** yamamoto has quit IRC | 21:09 | |
*** yamamoto has joined #openstack-fwaas | 22:06 | |
*** yamamoto has quit IRC | 22:11 | |
*** yamamoto has joined #openstack-fwaas | 23:07 | |
*** yamamoto has quit IRC | 23:12 | |
*** yamamoto has joined #openstack-fwaas | 23:36 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!