*** hongbin has joined #openstack-kuryr | 02:05 | |
*** irclogbot_1 has quit IRC | 02:19 | |
*** hongbin has quit IRC | 04:17 | |
*** janki has joined #openstack-kuryr | 06:21 | |
*** ccamposr has joined #openstack-kuryr | 06:24 | |
*** gcheresh has joined #openstack-kuryr | 06:50 | |
openstackgerrit | Daniel Mellado proposed openstack/kuryr-kubernetes master: Add support for text ports on Network Policy Spec https://review.openstack.org/648905 | 06:54 |
---|---|---|
*** pcaruana has joined #openstack-kuryr | 06:58 | |
*** maysams has joined #openstack-kuryr | 06:58 | |
*** aperevalov_ has quit IRC | 07:01 | |
*** pcaruana has quit IRC | 07:02 | |
*** pcaruana has joined #openstack-kuryr | 07:02 | |
*** maysams has quit IRC | 07:08 | |
*** maysams has joined #openstack-kuryr | 07:16 | |
maysams | dmellado: ping | 07:20 |
dmellado | maysams: pong | 07:20 |
dmellado | I was rebasing your patch | 07:20 |
dmellado | had to regenerate the commit id as there's a gerrit limitation in terms of PS | 07:21 |
dmellado | so I can't rebase 11 onto 10 and so... | 07:21 |
dmellado | what's up? ;) | 07:21 |
maysams | dmellado: right, thanks for rebasing it. But regarding the named-port support with IPBlock that I mentioned in the PS | 07:23 |
dmellado | so, what's your concern into that? | 07:23 |
dmellado | as a first glance I don't think it'd be an issue | 07:24 |
maysams | dmellado: The problem is that I did not add support for named-port + ipblock yet | 07:24 |
maysams | dmellado: in order to give support I need to go over the containers in the pods that matches the ipBlock section | 07:26 |
maysams | dmellado: so, I think it might be good to address this case in another PS, because this PS is already too big | 07:27 |
dmellado | yeah, sounds good to me, let's finish with the rebases and add a new PS for this | 07:29 |
dmellado | otherwise it'll be tough to handle it | 07:29 |
*** celebdor has joined #openstack-kuryr | 07:30 | |
maysams | dmellado, but you already rebase it right? | 07:31 |
dmellado | I did rebase on PS10 | 07:35 |
dmellado | but you changed some stuff on PS11 | 07:35 |
dmellado | gerrit doesn't allow you to do rebase in between PS | 07:35 |
dmellado | so I published another change so I can do PS10-11 rebase | 07:36 |
dmellado | which is being a pain so far xD | 07:37 |
*** maysams has quit IRC | 07:49 | |
*** aperevalov has joined #openstack-kuryr | 07:50 | |
openstackgerrit | Alexey Perevalov proposed openstack/kuryr-kubernetes master: Support sriovdp arbitrary resource names https://review.openstack.org/642491 | 07:53 |
openstackgerrit | Daniel Mellado proposed openstack/kuryr-kubernetes master: Add support for text ports on Network Policy Spec https://review.openstack.org/648905 | 07:53 |
dmellado | maysams ^^ | 07:53 |
dmellado | pls do take a look when you're back aroudn | 07:53 |
*** maysams has joined #openstack-kuryr | 07:59 | |
*** gkadam has joined #openstack-kuryr | 08:02 | |
maysams | dmellado: thanks for rebasing with my last PS | 08:04 |
dmellado | yw! | 08:04 |
dmellado | aperevalov: btw, I'm seeing some trivial errors on your patch docs | 08:04 |
dmellado | will leave some comments | 08:05 |
dmellado | basically you need to leave a space below the code block, otherwise it'll treat the code block itself as arguments | 08:05 |
aperevalov | dmellado, ok. Yes, I'm not yet generated it to view. | 08:05 |
maysams | dulek, morning. | 08:18 |
maysams | dulek, I just remembered you've mentioned on Friday an issue regarding allowed_cidrs, while running the tests. Do you remember what was that? | 08:19 |
dmellado | allowed_cidrs won't even be there anymore | 08:20 |
dulek | maysams: It haven't manifested again, I was probably seeing some false alarm back then. | 08:26 |
dulek | maysams: Because it started to work fine with your patch applied after restacking. | 08:26 |
maysams | dulek: great, thanks! | 08:27 |
dmellado | dulek: if after maysams patch you still see allowed_cidrs, then that'd be bad xD | 08:31 |
*** gkadam has quit IRC | 08:32 | |
openstackgerrit | Alexey Perevalov proposed openstack/kuryr-kubernetes master: Support sriovdp arbitrary resource names https://review.openstack.org/642491 | 08:36 |
dmellado | btw, folks, I'll be changing the upstream meeting time to 14:00 UTC | 08:58 |
dmellado | so we follow DST, otherwise I won't really be able to attend myself | 08:58 |
*** ccamposr has quit IRC | 09:01 | |
*** ccamposr has joined #openstack-kuryr | 09:01 | |
*** ccamposr has quit IRC | 09:04 | |
*** ccamposr has joined #openstack-kuryr | 09:05 | |
dulek | dmellado: I was to ask you about that when I looked at the calendar. :) Good call. | 09:21 |
*** gkadam has joined #openstack-kuryr | 09:28 | |
dmellado | https://review.openstack.org/#/c/648927/ | 09:33 |
dmellado | dulek: ^^ | 09:33 |
dulek | dmellado: I guess an email to the ML is also required. | 09:34 |
dmellado | dulek: I was already writing that xD | 09:34 |
dulek | :) | 09:35 |
dmellado | dulek: in any case I'm shifting today's meeting to openstack-kuryr, as I'm not sure if the time slot would already be taken | 09:36 |
dulek | dmellado: It's not. | 09:38 |
dulek | http://eavesdrop.openstack.org/ | 09:38 |
dmellado | oh, great, then we'll hijack it | 09:39 |
dmellado | xD | 09:39 |
dulek | dmellado: I think the tests on your patch would fail if there was a conflict. | 09:39 |
dmellado | allright, done | 09:40 |
openstackgerrit | Alexey Perevalov proposed openstack/kuryr-kubernetes master: Support sriovdp arbitrary resource names https://review.openstack.org/642491 | 10:10 |
*** celebdor has quit IRC | 10:12 | |
openstackgerrit | Daniel Mellado proposed openstack/kuryr-kubernetes master: Add support for text ports on Network Policy Spec https://review.openstack.org/648905 | 10:14 |
dulek | ltomasbo, maysams: "should allow ingress access on one named port [Feature:NetworkPolicy]" - Pod client-a should be able to connect to service svc-server, but was not able to connect | 10:56 |
dulek | It's with ltomasbo's patch applied. | 10:56 |
maysams | dulek: and also mine, right? | 10:57 |
dulek | maysams: Yup. And both mine. | 10:58 |
maysams | dulek: hmm.. okay. I will setup this in my env and run the test, to analyze it better | 11:00 |
maysams | dulek: or you still have the client and server SGs? | 11:04 |
*** gcheresh_ has joined #openstack-kuryr | 11:05 | |
*** gcheresh has quit IRC | 11:05 | |
*** gcheresh_ has quit IRC | 11:10 | |
*** gcheresh has joined #openstack-kuryr | 11:10 | |
*** rh-jelabarre has joined #openstack-kuryr | 11:41 | |
openstackgerrit | Alexey Perevalov proposed openstack/kuryr-kubernetes master: Support sriovdp arbitrary resource names https://review.openstack.org/642491 | 11:41 |
*** celebdor has joined #openstack-kuryr | 12:25 | |
*** maysams has quit IRC | 12:44 | |
*** maysams has joined #openstack-kuryr | 12:45 | |
dulek | Hm, those failures look very odd… | 12:56 |
*** irclogbot_0 has joined #openstack-kuryr | 13:26 | |
maysams | dulek: I just remembered one thing | 13:34 |
maysams | dulek: Openshift folks mentioned they were skipping 2 tests | 13:35 |
maysams | dulek: and one of them is the one that is failing | 13:35 |
maysams | dulek: https://github.com/openshift/origin/blob/master/test/extended/util/test.go#L372 | 13:35 |
dulek | Ha, interesting! | 13:35 |
dulek | I'll refer to them if I don't find the reason it's failing with Kuryr. | 13:36 |
maysams | dulek: this is the skip list ^ defined in the testMaps variable | 13:36 |
maysams | dulek, okay. But the test seems correct to me | 13:46 |
maysams | dulek: Ah, I think I know why it's wrong. When allowing ingress in the named-port "serve-80" we need to look for all the pods selected by that policy and search for that port in them | 13:55 |
maysams | dulek: the client pods created do not have "serve-80" | 13:55 |
dulek | maysams: Sounds right! | 14:04 |
maysams | dulek: The documentation is not clear about which pod should be looked in order to find the port number. If it's the selected in the spec or the ones selected in the ingress/egress section | 14:04 |
*** gcheresh has quit IRC | 14:11 | |
maysams | dulek: maybe ltomasbo has some idea regarding this ^ | 14:11 |
dulek | maysams: I guess the test is best documentation on how this is supposed to work. | 14:12 |
maysams | dulek: so, I need to rework the ps | 14:14 |
maysams | dulek: I was thinking the other way around | 14:15 |
maysams | dulek: There is no rule with port 80 in the client nor in the server right? | 14:17 |
dulek | maysams: https://paste.fedoraproject.org/paste/O8KqWmIgnnM0yfiEZGZfDg | 14:18 |
dulek | maysams: fb87af95-481f-4451-8e25-5a33d206ecda was added by me and fixed the connectivity. | 14:18 |
maysams | dulek: is this the svc subnet? | 14:21 |
maysams | '10.1.1.212/32' | 14:21 |
dulek | maysams: This is IP of client-a. And I added that rule myself. :P | 14:21 |
dulek | 10.1.1.206/32 - this is in subnet. Actually this is IP of the Service. | 14:22 |
dulek | dmellado: Guess which project seems to behave badly in the gate. :P | 14:29 |
dulek | dmellado: Obviously it's always Octavia. :D | 14:29 |
dmellado | dulek: hmmmm | 14:29 |
dmellado | damn, I shou've known? | 14:29 |
dmellado | octavia-dashboard? | 14:29 |
dmellado | kinda recall listening something about issues with npm | 14:30 |
dmellado | xD | 14:30 |
dmellado | dulek: of course, whenever there's any issue, I blame octavia and celebdor | 14:30 |
dulek | dmellado: Hm, I don't know yet. But the root cause is lack of connectivity to K8s API through it's LB. | 14:30 |
dmellado | hmm, I'm checking what could've been within their code | 14:31 |
dmellado | https://github.com/openstack/octavia/commits/master | 14:31 |
dmellado | doesn't look like anything outrageous | 14:31 |
*** gcheresh has joined #openstack-kuryr | 14:33 | |
celebdor | and rightly so | 14:36 |
celebdor | (even the order) | 14:36 |
*** gcheresh has quit IRC | 14:37 | |
*** janki has quit IRC | 14:47 | |
*** janki has joined #openstack-kuryr | 14:47 | |
dmellado | dulek: did you reproduce it on your environment? | 14:49 |
dulek | dmellado: I'm working on that. | 14:50 |
dmellado | I'm deploying one environment as well | 14:50 |
dmellado | will go now on kid duty, so let's sync later ;) | 14:50 |
*** premsankar has joined #openstack-kuryr | 15:06 | |
*** aperevalov has quit IRC | 15:14 | |
*** maysams has quit IRC | 15:21 | |
*** gcheresh has joined #openstack-kuryr | 15:26 | |
*** janki has quit IRC | 15:37 | |
*** ccamposr has quit IRC | 15:44 | |
*** maysams has joined #openstack-kuryr | 15:56 | |
*** gcheresh has quit IRC | 15:59 | |
*** gkadam has quit IRC | 17:05 | |
dulek | Damn, looks like the issue is not manifesting locally. | 17:18 |
dulek | At least on my env. :( | 17:18 |
*** maysams has quit IRC | 19:29 | |
*** spsurya has quit IRC | 19:36 | |
*** rh-jelabarre has quit IRC | 20:22 | |
*** rh-jelabarre has joined #openstack-kuryr | 20:26 | |
*** pcaruana has quit IRC | 21:17 | |
*** rh-jelabarre has quit IRC | 22:55 | |
*** openstackgerrit has quit IRC | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!