Monday, 2021-09-27

*** ysandeep|out is now known as ysandeep04:43
*** jpena|off is now known as jpena07:29
*** ykarel is now known as ykarel|lunch07:56
*** ysandeep is now known as ysandeep|lunch08:37
*** ykarel|lunch is now known as ykarel09:00
*** ysandeep|lunch is now known as ysandeep09:30
*** bhagyashris is now known as bhagyashris|rover09:32
*** ykarel is now known as ykarel|afk09:53
*** jcapitao is now known as jcapitao_lunch10:24
*** bhagyashris is now known as bhagyashris|rover10:38
*** ykarel|afk is now known as ykarel10:53
*** rlandy is now known as rlandy|ruck11:00
*** jpena is now known as jpena|lunch11:32
*** jpodivin is now known as jpodivin|ruck11:40
*** jcapitao_lunch is now known as jcapitao11:59
*** jpena|lunch is now known as jpena12:25
*** redrobot is now known as Guest112915:09
opendevreviewDr. Jens Harbott proposed openstack/project-config master: Fix neutron-dynamic-routing grafana dashboard  https://review.opendev.org/c/openstack/project-config/+/81118215:13
opendevreviewMerged openstack/project-config master: Fix neutron-dynamic-routing grafana dashboard  https://review.opendev.org/c/openstack/project-config/+/81118215:40
*** ysandeep is now known as ysandeep|out16:12
*** jpena is now known as jpena|off16:38
clarkbyoctozepto: I've discovered https://docs.openstack.org/kolla-ansible/latest/reference/deployment-and-bootstrapping/bootstrap-servers.html#disabling-firewalls and am wondering if that means kolla is actively undermining the rules we've put in place on the test nodes. Ideally we'd keep those in place as they help prevent a number of problems17:21
fungichief among those, the problem of our donor providers locking out our accounts because of abuse17:23
yoctozeptoclarkb, fungi: yeah, it does disable firewalls atm; what rules are we losing then? it's been like this for years :-( 17:28
clarkbyoctozepto: potentially things like rogue dhcpd prevention, dns resolver reflection, etc17:29
clarkbthe way we set up iptables in the jobs allows the nodes to talk to each other but keeps external stuff out17:29
clarkband you really shouldn't subvert that17:29
fungiadding rules to allow more communication between nodes for the same job is generally fine though17:30
clarkbsome of our clouds also do periodic port scanning and they complain if random services are publicaly available17:33
clarkbthings like dns servers, mecached iirc etc17:33
fungiin the same vein as rogue dhcp servers, our default rules should also effectively prevent rogue router announcements from leaking into the provider's lan17:34
fungiwhich could be part of the picture for https://launchpad.net/bugs/184471217:35
yoctozeptoclarkb, fungi: thankfully, you don't rely on ufw nor firewalld so we leave your rules in place17:55
fungiahh, good17:58
opendevreviewMerged openstack/project-config master: Remove github3.py from our zuul config  https://review.opendev.org/c/openstack/project-config/+/81053018:08
-opendevstatus- NOTICE: Gerrit and Zuul services are being restarted briefly for configuration and code updates but should return to service momentarily20:09

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!