Thursday, 2018-10-04

*** longkb has joined #openstack-fwaas00:50
*** longkb has quit IRC00:51
*** longkb has joined #openstack-fwaas00:52
*** longkb has quit IRC01:37
*** longkb has joined #openstack-fwaas01:37
*** annp has joined #openstack-fwaas01:43
*** yamamoto has quit IRC02:47
*** yamamoto has joined #openstack-fwaas02:47
*** velizarx has joined #openstack-fwaas06:48
*** velizarx has quit IRC07:14
*** velizarx has joined #openstack-fwaas07:16
*** yamamoto has quit IRC09:22
*** yamamoto has joined #openstack-fwaas09:22
*** longkb has quit IRC10:01
*** yamamoto has quit IRC10:49
*** yamamoto has joined #openstack-fwaas10:49
*** yamamoto has quit IRC10:54
*** yamamoto has joined #openstack-fwaas11:38
*** annp has quit IRC12:09
*** velizarx has quit IRC13:42
*** SridarK has joined #openstack-fwaas13:59
SridarKHi FWaaS folks14:01
*** njohnston has joined #openstack-fwaas14:03
SridarK#startmeeting fwaas14:05
openstackMeeting started Thu Oct  4 14:05:19 2018 UTC and is due to finish in 60 minutes.  The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot.14:05
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:05
*** openstack changes topic to " (Meeting topic: fwaas)"14:05
openstackThe meeting name has been set to 'fwaas'14:05
xgerman_o/14:05
*** SridarK_ has joined #openstack-fwaas14:06
xgerman_mmh, we prob. loast control14:06
SridarK_xgerman_: back14:06
SridarK_got bounced14:06
xgerman_ok14:06
SridarK_dont see much in terms of quorum14:07
xgerman_yeah14:07
SridarK_perhaps some local holiday14:07
SridarK_may be we can wait for a few mins14:07
xgerman_maybe - people told me Monday is a holiday in UT14:07
SridarK_there was nothing major to go thru anyways14:08
*** SridarK has quit IRC14:09
*** SridarK_ has quit IRC14:09
xgerman_yeah, makes sense. Wanted to let people know that I need to cut back my OpenStack involvements a bit…14:09
*** SridarK has joined #openstack-fwaas14:10
xgerman_I need to see how that k8s stuff shakes out…14:10
SridarKoops bounced again14:10
xgerman_ok14:10
SridarKxgerman_: +114:10
njohnstonxgerman_: Good luck in k8s land, they are lucky to have you :-)14:10
xgerman_well, you made it back — so there is hope14:10
SridarKxgerman_: so pls what happened - i think i missed something as i got bounced14:11
*** velizarx has joined #openstack-fwaas14:11
*** annp has joined #openstack-fwaas14:11
xgerman_ah, RAX is emphasizing k8s a lot and wnats me to focus more on that and less on OpenStack14:11
annpHi14:11
annpSorry I'm late14:11
SridarKxgerman_: ah yes ok - u have been on that path for some time now anyways14:12
SridarKannp: hi14:12
SridarKno worries - not much quorum today14:12
annpHi SridarK, thanks. :-)14:12
xgerman_yep, and they are now more looking into k8s on AWS, Azure, GKE p less on OpenStack14:12
SridarKxgerman_: i think a bit of that is in the air everywhere14:13
xgerman_yeah, I think Redhat/Suse/Huawei are the last bullwark14:13
SridarKit seems that the SPs and the Edge Cloud folks are driving OpenStack more and more14:14
SridarKxgerman_: +114:14
SridarKannp: we are just chatting14:14
SridarKannp: anything specific u would like to discuss ?14:14
annpSridarK, I want to mention Firewall group with L3HA14:15
xgerman_ok14:15
SridarKok lets run thru the topics14:15
SridarK#chair xgerman_14:15
openstackCurrent chairs: SridarK xgerman_14:15
SridarK#topic Bugs : FWG and L3HA14:16
*** openstack changes topic to "Bugs : FWG and L3HA (Meeting topic: fwaas)"14:16
SridarKgo ahead annp14:16
annphttps://review.openstack.org/#/c/580552/14:16
SridarKhow is that looking14:16
annpRegards this bug: I've tested the patch, it's work fine.14:16
SridarKannp: ok14:17
annpI guess that yushiro was missing configure enable fwaas_v2 in network node14:17
SridarKand did u verify that conntrack entries are replicated by HA infra ?14:17
annpso there no firewall rule is applied on active router.14:17
SridarKthat was my concern14:17
*** hongbin has joined #openstack-fwaas14:17
annpSridarK, From my understanding, we no need to migrate conntrack entries14:18
SridarKah ok - this was something that was puzzling initially as to why it was not applied correctly14:18
SridarKannp: yes we dont have to but i thought they are migrated automatically ?14:18
annpSridarK, Have you check my comment in gerrit?14:18
SridarKsorry not yet14:18
annpBecause the first packet in router HA is not SYN sent, so It will not marked as INVALID14:19
annpSo it will be accepted by firewall rule in router HA14:19
annpThis is my understanding.14:20
SridarKHmm14:20
SridarKSo:14:20
SridarK1) We have an active connection - with the 3 way handshake happened on the ACTIVE14:21
SridarK2) after some time the switchover happens14:21
SridarK3) Now this flow is seen on the new ACTIVE (which has not seen the 3 way handshake)14:21
SridarKwhat is the behavior on this new ACTIVE ?14:22
annpyou mean first packet in new session?14:22
SridarKyes14:22
annpit's will be accept or drop by firewall rule in router ACTIVE14:23
SridarKis it a new session ?14:23
SridarKIs an ICMP sent back to trigger a new session14:23
annpYes. I think so.14:23
SridarKor is it the old session continued14:23
SridarKoh so it will be a new session ?14:24
annpI think it will be a new session14:24
SridarKok - i thought conntrack entries are migrated by the HA code (just that we dont need to do it). yushiro spoke to some folks at the PTG - atleast this is how i understood him14:25
SridarKok14:25
annpBut, actually I'm not sure. Let's me check it and will confirm to you14:25
SridarKannp: ok - we can discuss with yushiro and close this i believe14:25
SridarKthx annp for debugging further14:25
annpSridarK, you're always welcome. :-)14:26
SridarKok lets move on14:26
SridarK#topic Remote FWG14:26
*** openstack changes topic to "Remote FWG (Meeting topic: fwaas)"14:26
SridarKxgerman_: anything u would like to bring up14:26
SridarKok perhaps xgerman_ walked away14:30
xgerman_MO, STILL HERE14:30
SridarKouch sorry14:30
SridarK:-)14:30
SridarKpls go ahead14:30
xgerman_caps lock got stuck14:30
xgerman_sorry14:30
SridarK:-)14:30
SridarKnew Mac keyboard ?14:30
SridarK:-)14:31
xgerman_no, I have one of those tiny external mac BT keyboards14:31
xgerman_missing keys half the time14:31
xgerman_anyhow, didn’t do much. I am hoping to get a minute here and there but if someone has cycles14:32
SridarKok14:32
SridarKxgerman_: understand14:32
SridarKok14:33
SridarK#topic Open Discussion14:33
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)"14:33
xgerman_TC got elected…14:33
SridarK+114:33
annp+114:34
xgerman_also never heard criticism of deleting FWaaS V1 - so if someone could prepare a patch14:34
njohnstonin the neutron ci meeting we are talking about the transition to zuul v3 jobs and python3-first patches.  One thing that has not really been talked about is that according to governance, we should be testing on the latest LTS release available as fo the start of the cycle14:35
SridarKyes so it seems - someone will ask most likely after it is removed14:36
xgerman_;-)14:36
annp:-)14:36
njohnstonwhich in this case is now ubuntu-bionic, so that transition will start to get rolling and will take some CI sensitivity because the transition may not be smooth14:36
SridarKnjohnston: thx for the heads up14:36
xgerman_yep, johnso(m) was having trouble with bionic and multinode14:36
njohnstonit's definitely not something you can take for granted14:37
xgerman_no, but I am hoping this will clean up our tests — still thinking we don’t pull in the latest neutron somehow14:37
SridarKok14:39
SridarKok if nothing else we can end and hopefully next week will have more quorum14:40
xgerman_+!14:40
SridarKOk all thx for joining and have a great week.14:40
SridarK#endmeeting14:40
*** openstack changes topic to "Queens (Meeting topic: fwaas)"14:40
openstackMeeting ended Thu Oct  4 14:40:43 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:40
openstackMinutes:        http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-10-04-14.05.html14:40
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-10-04-14.05.txt14:40
openstackLog:            http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-10-04-14.05.log.html14:40
annpThank you, see you14:41
*** Swami has joined #openstack-fwaas15:00
*** annp has quit IRC15:16
*** velizarx has quit IRC15:20
*** longkb has joined #openstack-fwaas15:24
*** longkb has quit IRC15:26
*** SridarK has quit IRC17:26
*** Swami has quit IRC17:36
*** yamamoto has quit IRC17:51
*** yamamoto has joined #openstack-fwaas17:52
*** yamamoto has quit IRC17:57
*** Swami has joined #openstack-fwaas18:04
*** yamamoto has joined #openstack-fwaas18:30
*** hongbin has quit IRC22:57

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!