Monday, 2019-10-21

*** yamamoto has joined #openstack-lbaas02:00
*** ricolin has joined #openstack-lbaas02:29
*** yamamoto has quit IRC02:59
*** yamamoto has joined #openstack-lbaas02:59
*** ajay33 has joined #openstack-lbaas05:14
*** gcheresh_ has joined #openstack-lbaas05:22
*** gcheresh_ has quit IRC05:42
*** gcheresh_ has joined #openstack-lbaas05:55
*** yamamoto has quit IRC06:05
*** gcheresh_ has quit IRC06:29
*** ianychoi has quit IRC06:51
*** yamamoto has joined #openstack-lbaas06:53
*** ianychoi has joined #openstack-lbaas06:54
*** ccamposr has joined #openstack-lbaas07:12
*** numans has joined #openstack-lbaas07:13
*** gcheresh_ has joined #openstack-lbaas07:16
*** pcaruana has joined #openstack-lbaas07:16
*** maciejjozefczyk has joined #openstack-lbaas07:22
*** tesseract has joined #openstack-lbaas07:22
*** rcernin has quit IRC07:32
*** yamamoto has quit IRC07:44
*** yamamoto has joined #openstack-lbaas07:47
*** rpittau|afk is now known as rpittau07:51
*** yamamoto has quit IRC08:38
*** yamamoto has joined #openstack-lbaas08:40
*** vesper has joined #openstack-lbaas08:40
*** vesper11 has quit IRC08:40
*** brtknr has joined #openstack-lbaas08:49
*** gcheresh_ has quit IRC09:04
*** yamamoto has quit IRC09:24
fricklercgoncalves: could you take a look at my rocky backport again? tests passed after recheck https://review.opendev.org/68895909:27
frickleralso, is there a release planned for rocky/stein on that or should I prepare a release patch myself?09:27
*** yamamoto has joined #openstack-lbaas09:28
cgoncalvesfrickler, done, thanks for the backport. no release planned yet but we can do it anytime we want, no problem09:31
*** openstackgerrit has quit IRC09:37
*** openstackgerrit has joined #openstack-lbaas10:10
openstackgerritAnn Taraday proposed openstack/octavia-tempest-plugin master: Add amphorav2 to provider list  https://review.opendev.org/68912810:10
*** yamamoto has quit IRC10:41
*** rcernin has joined #openstack-lbaas10:42
openstackgerritAnn Taraday proposed openstack/octavia master: Jobboard based controller  https://review.opendev.org/64740610:47
*** rcernin has quit IRC10:52
*** trident has quit IRC11:11
*** trident has joined #openstack-lbaas11:15
*** ricolin_ has joined #openstack-lbaas11:23
*** rcernin has joined #openstack-lbaas11:24
*** ricolin has quit IRC11:25
*** goldyfruit has quit IRC11:26
*** rcernin has quit IRC11:34
*** yamamoto has joined #openstack-lbaas11:52
*** yamamoto has quit IRC11:54
*** another_larsks is now known as larsks12:29
*** yamamoto has joined #openstack-lbaas12:32
openstackgerritAnn Taraday proposed openstack/octavia master: Jobboard based controller  https://review.opendev.org/64740612:40
openstackgerritAnn Taraday proposed openstack/octavia master: Add option to set default ssl ciphers in haproxy  https://review.opendev.org/68533712:40
*** yamamoto has quit IRC12:45
*** yamamoto has joined #openstack-lbaas13:13
*** yamamoto has quit IRC13:14
*** yamamoto has joined #openstack-lbaas13:14
brtknrI'm attempting to use Octavia ingress via Magnum... anyone got it working?13:16
brtknrI can see my loadbalancer spawing but the floating ip doesnt attach13:17
*** yamamoto has quit IRC13:18
*** yamamoto has joined #openstack-lbaas13:18
*** goldyfruit has joined #openstack-lbaas13:32
*** maciejjozefczyk is now known as mjozefcz|lunch13:35
*** mjozefcz|lunch has quit IRC13:40
johnsomSorry, I have never used Magnum. What error is neutron giving you when you add the floating IP? Are you using DVR?13:45
*** mjozefcz|lunch has joined #openstack-lbaas13:51
*** ianychoi has quit IRC14:21
*** ianychoi has joined #openstack-lbaas14:29
*** yamamoto has quit IRC14:32
*** mjozefcz|lunch has quit IRC15:00
*** mloza has joined #openstack-lbaas15:03
*** goldyfruit has quit IRC15:08
*** goldyfruit has joined #openstack-lbaas15:08
*** goldyfruit has quit IRC15:09
*** yamamoto has joined #openstack-lbaas15:14
*** yamamoto has quit IRC15:18
*** trident has quit IRC15:29
*** trident has joined #openstack-lbaas15:32
*** ianychoi has quit IRC15:43
*** ianychoi has joined #openstack-lbaas15:44
*** tesseract has quit IRC16:03
*** mjozefcz|lunch has joined #openstack-lbaas16:11
*** ccamposr has quit IRC16:16
*** mjozefcz|lunch has quit IRC16:22
*** gcheresh_ has joined #openstack-lbaas16:51
*** KeithMnemonic has joined #openstack-lbaas17:05
*** mjozefcz|lunch has joined #openstack-lbaas17:14
*** gcheresh_ has quit IRC17:26
*** gcheresh_ has joined #openstack-lbaas17:35
*** mjozefcz|lunch has quit IRC17:43
*** mjozefcz|lunch has joined #openstack-lbaas18:01
openstackgerritMerged openstack/octavia master: Delete the periodic Fedora 28 amphora image job  https://review.opendev.org/68385018:23
*** mjozefcz|lunch has quit IRC18:27
*** goldyfruit has joined #openstack-lbaas18:43
*** gcheresh_ has quit IRC19:26
*** spatel has joined #openstack-lbaas20:08
*** pcaruana has quit IRC20:16
*** ajay33 has quit IRC20:23
*** spatel has quit IRC20:51
colin-do we avoid any mod_security stuff in haproxy since it seems to be gated by the enterprise version?20:58
johnsomIsn't mod_security an apache thing?20:59
colin-yeah i might have stuck my foot in my mouth with this, i don't think they have an equivalent component for the L7 stuff in haproxy21:00
johnsomWhat are you trying to do?21:00
colin-just remembering how trivial it was to load mod_security into an nginx listener and wondering if it would be low-effort to offer some "waf" thing on our L7s in the future21:00
*** goldyfruit has quit IRC21:01
johnsomWell, haproxy does have a rich ACL engine, but it really depends on what you are trying to solve.21:02
johnsomWe already have ddos to some degree from the kernel, we have basic ACLs. If you want to block based on protocol header, etc. the engine supports it, we would just have to expose it in some way. Or you can of course load a custom haproxy template.21:03
colin-i guess i'd paraphrase it as bare-minimum protection against nefarios traffic matching public threat DBs for application-aware listeners21:03
colin-nefarious*21:03
johnsomSo IPS like functionality21:03
colin-yeah21:03
colin-too far from base camp you think? (LBaaS)21:04
johnsomNot necessarily, it is a good place in the pipeline to do inspection type things....21:04
colin-had roughly imagined it as a boolean available on HTTP and TERMINATED_HTTPS type listeners that when true would modify what the agent configures on the amp with the understanding that performance would suffer (cpu wise)21:06
colin-will make a note here and save it for later, was mostly curious if it had been pursued or not21:06
johnsomYeah, not really something we have worked on yet. It could be added to the roadmap: https://wiki.openstack.org/wiki/Octavia/Roadmap21:07
johnsomcolin- https://github.com/haproxy/haproxy/tree/master/contrib/modsecurity21:10
colin-oh interesting21:11
*** yamamoto has joined #openstack-lbaas21:16
*** yamamoto has quit IRC21:21
openstackgerritMerged openstack/octavia master: Fix log offload file permissions in CentOS devstack  https://review.opendev.org/68793821:37
*** goldyfruit has joined #openstack-lbaas21:38
*** goldyfruit has quit IRC22:01
*** openstackgerrit has quit IRC22:07
*** openstackgerrit has joined #openstack-lbaas22:47
openstackgerritAdam Harwell proposed openstack/octavia master: Allow IPv6 health network in devstack  https://review.opendev.org/66510322:47
openstackgerritAdam Harwell proposed openstack/octavia master: Fix some plug.py unit tests that broke on OSX  https://review.opendev.org/68250122:47
openstackgerritAdam Harwell proposed openstack/octavia master: Fix batch member update error on empty change list  https://review.opendev.org/68854822:51
*** ianychoi has quit IRC23:00
*** ianychoi has joined #openstack-lbaas23:00
*** rcernin has joined #openstack-lbaas23:19
*** rcernin has quit IRC23:19
*** rcernin has joined #openstack-lbaas23:20
*** ianychoi has quit IRC23:24
*** ianychoi has joined #openstack-lbaas23:26
openstackgerritAdam Harwell proposed openstack/octavia master: Allow multiple VIPs per LB  https://review.opendev.org/66023923:54
openstackgerritAdam Harwell proposed openstack/octavia master: WIP: fix plugging member subnets on existing networks  https://review.opendev.org/66540223:54

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!