Monday, 2018-08-06

*** hongbin has joined #openstack-kuryr01:39
*** kiseok7 has quit IRC02:35
*** hongbin has quit IRC04:09
*** janki has joined #openstack-kuryr05:38
*** pcaruana has joined #openstack-kuryr06:07
ltomasbogood morning irenab06:30
*** gcheresh_ has joined #openstack-kuryr06:35
irenabltomasbo, good morning07:06
ltomasbogood morning! I'm taking a look at your comments on https://review.openstack.org/#/c/581421/2107:07
ltomasboI replied to a couple of them, but wanted to discuss possible solutions for the lbaas driver functions names07:07
irenaba sec, taking a look on your replies07:08
ltomasboirenab, do you feel it will be enough to add a fixme note about removing the lbaasv2 specific methos (once we drop support for it) and rename the xxx_octavia one?07:08
ltomasboirenab, or do you think it will be better to rename then already with a different name, for instance, I can change the xxx_lbaasv2 one as:07:09
ltomasbo_ensure_lb_security_group_rule07:09
ltomasboand the octavia one as:07:09
ltomasbo_extend_lb_security_group_rules07:09
*** ajo has joined #openstack-kuryr07:09
ltomasboor actually a merge of the two approaches07:10
irenabltomasbo, second option is better imho. It would be good if there was not the type specific check in the v2 driver07:12
ltomasboyep, I already removed that07:13
ltomasboand changed it to ClusterIP and out of that function07:13
ltomasbook, I'll go for option 2, I'll send a new patch soon-ish07:14
ltomasbothanks!07:14
irenabthank you!07:15
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services  https://review.openstack.org/58142107:28
ltomasboirenab, done! ^^07:28
irenabltomasbo, much better, waiting for the CI07:34
ltomasbogreat!07:34
dulekcelebdor[m]: Hi! This looks a bit bad, isn't it: http://logs.openstack.org/21/581421/22/check/kuryr-kubernetes-tempest-daemon-openshift-octavia/6818168/job-output.txt.gz#_2018-08-06_08_10_20_690322 ?09:06
dulekcelebdor[m]: I'll just go and add sudo there now.09:06
openstackgerritMichał Dulko proposed openstack/kuryr-kubernetes master: Add sudo for OpenShift registry CA cert copy  https://review.openstack.org/58908409:09
dulekltomasbo: http://logs.openstack.org/21/581421/22/experimental/kuryr-kubernetes-tempest-daemon-containerized-octavia-namespace/ad538cb/controller/logs/kubernetes/pod_logs/kube-system-kuryr-controller-7db7c944fb-7pwn6.txt.gz#_2018-08-06_08_50_22_70909:11
openstackgerritDaniel Mellado proposed openstack/kuryr-kubernetes master: Implement NP SG create/delete actions  https://review.openstack.org/58354009:36
dmelladoirenab: could you have a look at ^`09:37
dmelladothanks!09:37
dmelladoltomasbo: dulek celebdor[m] feel free to review it as well xD09:37
irenabdmellado,  sure09:38
irenabasap09:38
dmelladoirenab: thanks!, it's a wip for now, as I intend to do follow-up patches on this09:38
openstackgerritMichał Dulko proposed openstack/kuryr-kubernetes master: Add sudo for OpenShift registry CA cert copy  https://review.openstack.org/58908410:30
openstackgerritMichał Dulko proposed openstack/kuryr-kubernetes master: WIP: Add HA gate  https://review.openstack.org/58822310:52
irenabdmellado, I won't be able to attend the call on SRIOV today due to some personal stuff11:03
dmelladoirenab: no worries, I'm also a li'l bit feverish so I might have dulek cover that for me11:03
dmelladoirenab: in any case we'll get to discuss it in some follow-ups11:04
dmelladoAlexeyPerevalov: ^^ FYI11:04
irenabdmellado, this would be great11:04
dulekdmellado: If celebdor[m] is also not going to join we might want to reschedule it.11:04
dmelladodulek: celebdor[m] told me he'd make it but might be some minutes late11:04
dmelladoirenab: would it be ok for you any other day this week?11:04
irenabyes, both Wed and Thu11:05
irenaband Tue11:05
dmelladolet's it make tentative to Wed if by any chance there's no quorum today11:05
irenabbut do not hold it if only I cannot make it today, I will follow up11:06
irenabdmellado, +111:06
dmelladodulek: irenab  rescheduling this then for Wed then11:10
dmelladodulek: now you'd just have to handle the usual meeting, thanks in any case ;)11:10
irenabdmellado, possible one hour earlier, 15:00 CET?11:11
dmelladoirenab: sure, no problems from my side11:11
dmelladodone and invites sent ;)11:13
AlexeyPerevalovdmellado: I got email, thank you, it's convinient time )11:21
dmelladoawesome, glad to hear11:21
*** rh-jelabarre has joined #openstack-kuryr11:33
*** maysams has joined #openstack-kuryr11:44
openstackgerritDaniel Mellado proposed openstack/kuryr-kubernetes master: Implement NP SG create/delete actions  https://review.openstack.org/58354012:14
openstackgerritGenadi Chereshnya proposed openstack/kuryr-tempest-plugin master: Create service with unsupported type  https://review.openstack.org/58133712:49
openstackgerritGenadi Chereshnya proposed openstack/kuryr-tempest-plugin master: Create service with UDP protocol  https://review.openstack.org/58569412:53
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services  https://review.openstack.org/58142113:10
*** janki has quit IRC13:24
*** tzumainn has joined #openstack-kuryr13:37
*** kailun has joined #openstack-kuryr13:45
openstackgerritEmilio Garcia proposed openstack/kuryr-kubernetes master: Upstream kuryr Active Active High Availibility Development [Do Not Merge/Do Not Test]  https://review.openstack.org/58299213:48
*** spotz has joined #openstack-kuryr14:08
*** celebdor has joined #openstack-kuryr14:17
celebdordulek: did the sudo help?14:36
dulekcelebdor: https://review.openstack.org/#/c/589084/ - seems so.14:36
celebdordulek: ltomasbo made a good suggestion14:43
ltomasboxD14:43
openstackgerritMichał Dulko proposed openstack/kuryr-kubernetes master: Add sudo for OpenShift registry CA cert copy  https://review.openstack.org/58908414:44
dulekltomasbo: Thanks! :)14:44
ltomasboyw!14:45
*** dougbtv_ has quit IRC14:45
dmelladocelebdor: a really good summer one14:46
celebdordmellado: good summer what?14:47
dmelladosuggestion14:47
dmellado'sudo'14:47
dmelladoxD14:47
celebdordmellado: merge Michał 's patch before the fever takes you down14:47
celebdorI can see that it already took your humor14:47
celebdorxD14:47
ltomasbolol14:48
dmelladobtw folks, I would appretiate reviews on https://review.openstack.org/#/c/583540/14:48
dmelladowith this, I go back to the shower/sofa14:48
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services  https://review.openstack.org/58142114:51
*** gcheresh_ has quit IRC14:51
celebdordmellado: is NP=P14:53
celebdor?14:53
dmelladocelebdor: it depends14:54
dmelladoif NP means "No Playa" I'm totally up for that now14:55
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Ensure OpenShift gate uses the namespace subnet/sg drivers  https://review.openstack.org/58068014:58
*** celebdor has quit IRC15:07
*** celebdor has joined #openstack-kuryr15:09
*** pcaruana has quit IRC15:12
*** janki has joined #openstack-kuryr15:17
ltomasbocelebdor, irenab: finally passing the gates: https://review.openstack.org/#/c/58142116:10
celebdor:-)16:13
*** janki has quit IRC16:15
ltomasbocelebdor, dulek: I have an issue I'm not sure how to solve16:36
ltomasbocelebdor, dulek: one of the tempest test (test_pod_pod_ping) is using a FIP to ping from one pod to another16:36
ltomasbocelebdor, dulek: with the namespace isolation feature that will not be allowed as I cannot add the public-subnet cidr into the security group as that is not meant to be known by the demo tenant16:38
celebdorand?16:38
celebdorFIPs should work16:38
celebdorcause that's how the loadbalancer service type works as well16:38
celebdoror does that work because it's an LB?16:38
dulekltomasbo: Yep, FIP should be accessible from everywhere.16:38
ltomasboloadbalancer subnet can ping pod subnet16:39
ltomasboso, loadbalancer servie type is fine16:39
ltomasboand I can curl/ping the pod ip as the access is from the kubelet16:40
ltomasbokubelet-port16:40
celebdordidn't we decide to just make the public cidr configurable?16:40
ltomasboreally?16:40
ltomasbowe decided that we didn't need the public subnet id, and just the public network id is enough16:41
ltomasbobut security group rules don't take network id16:41
ltomasbobut cidr and that is not accessible from a demo tenant16:41
ltomasboof course I can fix it on devstack deployment if that is find16:41
ltomasbo*fine16:41
celebdorltomasbo: Correct me if I'm wrong, but I think horizon somehow gets the cidr16:42
ltomasboreally?16:42
ltomasbolet me see if it is on the extended version or something16:42
ltomasboor simply not on the python-client16:42
celebdorok16:45
ltomasboI don't see where to get that information16:51
ltomasbocelebdor, from the neutron API it seems you can only get subnet id from the network object16:51
*** hongbin has joined #openstack-kuryr16:52
celebdorltomasbo: ask on the neutron channel16:52
celebdormaybe they'll have an idea16:53
celebdorI'll be thinking about it too16:53
ltomasbook16:54
ltomasbobut I'm not sure why this is working by default usually, I may be missing something stupid16:54
ltomasbocelebdor, dulek actually, that is the same we have16:59
celebdorltomasbo: what is?17:00
ltomasbofips only work because we have a default sg enabling icmp and ssh from everywhere17:00
ltomasboso, I guess I need to do the same (just with icmp)17:00
ltomasbowe will still have the isolation on the namespace, but ping will work between namespaces17:00
dulekltomasbo: Hey, but we shouldn't really depend in Tempest tests on Default SG settings. It can be anything on other clouds.17:01
dulekltomasbo: So I guess tests should set SG explicitly, but that seems troublesome with Kuryr's assumptions.17:02
ltomasbodulek, I actually removed the default sg (that tempest depends on) if namespace feature is enabled17:03
ltomasbobut tempest plugging that accounts on FIP, will depend on the security groups applied to the ports always17:03
ltomasboone option is to not use the fip to check pod to pod17:03
celebdordulek: ltomasbo: that test should actually be testing pod to pod on the same k8s namespace17:03
celebdorand not using fip17:03
ltomasboI agree17:04
ltomasboand if l3 was the intention, it will be enough to have pod to pod in different namespace, one being the default one17:04
ltomasboso, should I change the test instead then?17:04
dulekltomasbo, celebdor: Yeah, for pod-pod it makes total sense.17:04
ltomasbodulek, what make sense? not using the fip?17:05
dulekltomasbo: Yup!17:05
ltomasbook, I'll update the tempest test then!17:05
ltomasbothanks!17:06
celebdorltomasbo: but IIRC there's VM to pod as well17:06
celebdorand the VM, again IIRC, is not running on the pod subnet17:06
celebdorbut in that case, I'd say the test should just check the VM subnet cidr17:07
ltomasbocelebdor, but it is connected to the same router?17:07
celebdorand add access17:07
celebdorltomasbo: I guess17:07
celebdormaybe it uses FIP17:07
celebdorI do not recall17:07
celebdor(but possible)17:07
ltomasboI'll check17:07
ltomasbopod to VM FIP will work17:07
ltomasboas the VM-subnet will have the default security group with the icmp/ssh enabledf17:08
ltomasboumm, it is pod->vm and vm->pod17:09
ltomasboI wonder how that works...17:09
ltomasbowell, looking at the test I'm not sure is self.assertEqual('0', result.rstrip('\n')) is doing the right checking anyway17:12
openstackgerritMerged openstack/kuryr-kubernetes master: Add sudo for OpenShift registry CA cert copy  https://review.openstack.org/58908417:15
ltomasboohhh17:20
ltomasbomy mistake17:20
ltomasboI only added tcp to allow_from_default and allow_from_namespace17:20
ltomasboI'll fix it to add icmp...17:20
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Add namespace isolation for services  https://review.openstack.org/58142117:34
openstackgerritLuis Tomas Bolivar proposed openstack/kuryr-kubernetes master: Ensure OpenShift gate uses the namespace subnet/sg drivers  https://review.openstack.org/58068017:34
ltomasbodulek, celebdor ^^ now it should work even without changing the test17:35
*** celebdor has quit IRC21:07
*** hongbin has quit IRC23:19

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!