Monday, 2021-02-01

*** zzzeek has quit IRC00:04
*** zzzeek has joined #openstack-lbaas00:05
*** yamamoto has joined #openstack-lbaas00:37
*** sapd1 has joined #openstack-lbaas00:53
*** sapd1 has quit IRC01:01
*** sapd1 has joined #openstack-lbaas01:02
*** spatel has joined #openstack-lbaas01:28
*** spatel has quit IRC01:28
*** sapd1 has quit IRC01:42
*** sapd1 has joined #openstack-lbaas01:47
*** rcernin has quit IRC02:21
*** rcernin has joined #openstack-lbaas02:36
*** yamamoto has quit IRC02:38
*** yamamoto has joined #openstack-lbaas02:39
*** rcernin has quit IRC02:45
*** rcernin has joined #openstack-lbaas02:45
*** yamamoto has quit IRC03:07
*** yamamoto_ has joined #openstack-lbaas03:07
*** rcernin has quit IRC04:00
*** rcernin has joined #openstack-lbaas04:02
*** vishalmanchanda has joined #openstack-lbaas04:14
*** rcernin has quit IRC04:27
*** rcernin has joined #openstack-lbaas04:35
*** sapd1 has quit IRC05:32
*** yamamoto_ has quit IRC05:33
*** yamamoto has joined #openstack-lbaas05:36
*** gcheresh has joined #openstack-lbaas06:38
*** gmann has quit IRC06:45
*** gmann has joined #openstack-lbaas06:46
*** ccamposr__ has joined #openstack-lbaas07:08
*** sapd1 has joined #openstack-lbaas07:09
*** ccamposr has quit IRC07:10
*** rcernin has quit IRC07:25
openstackgerritMerged openstack/python-octaviaclient master: Add ALPN support for pools  https://review.opendev.org/c/openstack/python-octaviaclient/+/75209607:58
*** rcernin has joined #openstack-lbaas08:07
*** rpittau|afk is now known as rpittau08:11
*** rcernin has quit IRC08:24
*** rcernin has joined #openstack-lbaas08:26
*** rcernin has quit IRC08:31
*** rcernin has joined #openstack-lbaas08:37
*** rcernin has quit IRC09:27
openstackgerritMerged openstack/python-octaviaclient master: Add support for PROXYV2 protocol  https://review.opendev.org/c/openstack/python-octaviaclient/+/75693609:36
*** rcernin has joined #openstack-lbaas09:39
*** rcernin has quit IRC10:06
*** sshnaidm|off is now known as sshnaidm|ruck10:35
*** sapd1 has quit IRC11:04
*** rcernin has joined #openstack-lbaas11:16
*** sapd1 has joined #openstack-lbaas11:17
*** sapd1 has quit IRC11:25
*** sapd1 has joined #openstack-lbaas11:39
*** sapd1 has quit IRC11:55
*** yamamoto has quit IRC12:16
*** ilush has joined #openstack-lbaas12:22
*** rcernin has quit IRC12:33
*** sapd1 has joined #openstack-lbaas12:40
*** yamamoto has joined #openstack-lbaas12:44
*** rcernin has joined #openstack-lbaas12:47
*** yamamoto has quit IRC13:23
*** rcernin has quit IRC13:38
*** yamamoto has joined #openstack-lbaas13:54
*** yamamoto has quit IRC14:05
*** ilush has quit IRC15:16
*** malymuwme has joined #openstack-lbaas15:30
*** malymuwme has quit IRC16:27
johnsomrm_work Taskflow fix is merged, plan is to release this week.16:28
rm_worknice16:28
rm_workBTW my sleep schedule is flipped so I'll make the meeting this week hopefully :D16:29
johnsomNice16:29
johnsomDarn, that probably means I can't slack on the bug review meeting before it now. You will be doing the agenda prep.16:30
johnsomgrin16:30
*** vishalmanchanda has quit IRC16:32
rm_worklol16:32
rm_workcgoncalves: so we're moving away from having a driver/plugin for UDP handling and cementing in LVS? then reusing it for other types? https://review.opendev.org/c/openstack/octavia/+/75324716:46
johnsomIf I remember right, the conversation went along the lines of hanging a driver inside a driver is of little value at the moment. The abstraction is at the amphora API, so whatever is implemented behind that is up to the amphora implementation.16:48
*** sapd1 has quit IRC16:48
johnsomBut I will let Carlos/Greg also chime in16:48
rm_workk, guess I'm fine with that then16:49
rm_worki halted my review because I wasn't sure if that's really what we wanted16:49
rm_workbut I think I see the argument16:49
rm_workcomplexity probably isn't worth it considering I can't even think of a viable alternative at the moment :D16:49
johnsomYeah, HAProxy is coming, but ... Slowly16:50
cgoncalvesthe proposed SCTP code was originally mixed with the UDP driver so I was of the opinion to s/UDP/LVS the driver16:50
johnsomYeah16:51
cgoncalvessuch approach has its trade-offs, I know16:51
rm_workyeah, i think it's ... fine16:51
rm_workwe can leave it as the "Lvs" driver, and swap UDP off LVS to HAProxy if we want16:52
cgoncalvesI'm happy to discuss more, I can be easily convinced/manipulated :D16:52
rm_workbut I think likely generic UDP will stay LVS and any UDP handled by HAProxy will be application-specific, from what I can tell16:52
rm_workwas doing a bit of reading over the weekend16:52
rm_workWilly seemed very against doing generic UDP :P16:53
rm_workI don't know for sure but the points he and others raised made some sense16:53
johnsomYeah, Willy is pretty heavy on the by-protocol approach, which I agree with.16:54
rm_work5 day16:54
rm_workerr16:54
rm_workwrong window16:54
rm_workdo you understand wtf is breaking here? https://zuul.opendev.org/t/openstack/build/e41109f82f474e1faff674415d7e68ce/log/controller/logs/devstacklog.txt17:01
rm_workthat's from the scenario gate on https://review.opendev.org/c/openstack/octavia/+/75286417:01
rm_workstable/train17:01
rm_workit seems like ... it looks for the ssh key, it isn't there, so it makes it? and then breaks17:01
rm_workweirdness17:01
haleybrm_work: that's failing in DIB17:02
haleybhttps://4b0f853d1681e8f27e36-70474520a2e562b88d6ff63e0bb37737.ssl.cf1.rackcdn.com/752864/1/gate/octavia-v2-dsvm-scenario/e41109f/controller/logs/dib-build/amphora-x64-haproxy.qcow2_log.txt17:02
haleybsearch for the last ERROR17:02
haleybhttps://review.opendev.org/c/openstack/diskimage-builder/+/772254 is the answer17:03
rm_workah for that too?17:03
haleybstein and train are at least affected17:03
rm_workand victoria?17:04
rm_workper your comment in https://review.opendev.org/c/openstack/octavia/+/77047617:04
haleybi don't think so, only py217:04
*** vishalmanchanda has joined #openstack-lbaas17:05
rm_workyou commented "Failing in DIB", it's a different cause then?17:05
haleybrm_work: maybe ussuri too, because grenade does the -1 release17:06
rm_workoh, right. well that'd do it17:06
haleybyup, same SyntaxError :(17:06
haleybwhich explains why https://review.opendev.org/c/openstack/octavia-tempest-plugin/+/771888 is red on ussuri/train/stein17:07
haleyband there is no victoria job (yet)17:07
haleybthe gate is unrelenting in its ability to create failures17:08
rm_workyes17:10
rm_worki played this game for years :D17:10
haleybyou're still in the matrix17:10
*** rpittau is now known as rpittau|afk17:21
openstackgerritGregory Thiemonge proposed openstack/octavia master: Small fix in loadbalancer POST api-ref  https://review.opendev.org/c/openstack/octavia/+/77346018:01
*** yamamoto has joined #openstack-lbaas18:02
*** yamamoto has quit IRC18:07
*** rm_work has quit IRC18:10
*** rm_work has joined #openstack-lbaas18:22
*** rm_work has quit IRC18:22
*** rm_work has joined #openstack-lbaas18:23
*** rm_work has quit IRC18:23
*** rm_work has joined #openstack-lbaas18:25
*** rm_work has quit IRC18:25
*** rm_work has joined #openstack-lbaas18:25
*** rm_work has quit IRC18:26
*** rm_work has joined #openstack-lbaas18:27
*** rm_work has quit IRC18:27
*** rm_work has joined #openstack-lbaas18:28
*** rm_work has quit IRC18:28
*** rm_work has joined #openstack-lbaas18:32
*** rm_work has quit IRC18:32
*** rm_work has joined #openstack-lbaas18:39
*** rm_work has quit IRC18:39
*** rm_work has joined #openstack-lbaas18:50
*** rm_work has quit IRC18:50
*** rm_work has joined #openstack-lbaas18:53
*** rm_work has quit IRC18:54
*** gcheresh has quit IRC18:54
openstackgerritGhanshyam proposed openstack/octavia master: [goal] Deprecate the JSON formatted policy file  https://review.opendev.org/c/openstack/octavia/+/76457818:55
*** rm_work has joined #openstack-lbaas19:00
*** rm_work has quit IRC19:01
*** rm_work has joined #openstack-lbaas19:04
*** rm_work has quit IRC19:04
*** gcheresh has joined #openstack-lbaas19:10
*** rm_work has joined #openstack-lbaas19:15
*** rm_work has quit IRC19:15
*** rm_work has joined #openstack-lbaas19:22
*** rm_work has quit IRC19:22
cgoncalveshmm, ^ this looks familiar... https://review.opendev.org/c/openstack/octavia/+/73245319:34
johnsomYeah, I said the same. See the comments on the new patch19:35
*** rm_work has joined #openstack-lbaas19:47
*** rm_work has quit IRC19:48
*** jrosser_ has joined #openstack-lbaas20:18
*** guilhermesp__ has joined #openstack-lbaas20:18
*** fyx_ has joined #openstack-lbaas20:18
*** rm_work has joined #openstack-lbaas20:23
*** andy__ has joined #openstack-lbaas20:23
*** jrosser has quit IRC20:26
*** guilhermesp has quit IRC20:26
*** fyx has quit IRC20:26
*** f0o has quit IRC20:26
*** andy_ has quit IRC20:26
*** zigo has quit IRC20:26
*** sorrison has quit IRC20:26
*** andy__ is now known as andy_20:26
*** f0o has joined #openstack-lbaas20:26
*** jrosser_ is now known as jrosser20:26
*** guilhermesp__ is now known as guilhermesp20:26
*** fyx_ is now known as fyx20:26
*** zigo has joined #openstack-lbaas20:32
openstackgerritMerged openstack/octavia master: Add default value for enabled column in l7rule table  https://review.opendev.org/c/openstack/octavia/+/76128321:05
*** vishalmanchanda has quit IRC21:45
*** ccamposr has joined #openstack-lbaas21:45
*** ccamposr__ has quit IRC21:48
*** gcheresh has quit IRC21:49
*** xgerman has joined #openstack-lbaas21:55
*** yamamoto has joined #openstack-lbaas22:10
*** rouk has joined #openstack-lbaas22:13
*** yamamoto has quit IRC22:17
*** rcernin has joined #openstack-lbaas22:20
roukjohnsom: so i have a potential exploit a user managed to do, apparently with a project-scoped appcred, someone was able to make a LB with a vip network of another tenant, by mentioning the network by id, even though they dont have access to that network.22:20
roukis there no verification that the requesting user has adequate perms on the network requested before sending it off?22:21
johnsomYou must have an older release22:21
roukuhh, i just updated to fix the last issue regarding rebuilds, im running ussuri/master as of a few days ago.22:22
johnsomHmm, give me a minute to find the patch I added for the token issue22:22
roukmaybe didnt get backported?22:22
johnsomWell, maybe it didn't get merged in the backport.22:23
johnsomOk, forgot, I didn't do that one, it is here: https://review.opendev.org/c/openstack/octavia/+/72155022:24
johnsomIt does appear to be in Ussuri.22:25
johnsomI'm going to look at the code and see if there was a mistake there22:26
roukyeah, i for sure have a newer release than april 2020, heh.22:27
roukcould there perhaps also be a hole for appcreds? as these were made with appcreds.22:32
johnsomYeah, ok, he missed the path where they pass a network, but not a subnet ID. So this is a valid bug.22:34
roukOops.22:35
johnsomThis was previously deemed class C1 issue as the other person must know the UUID of the other network/subnet.22:35
johnsomSo it wasn't a CVE or such.22:36
johnsomWhelp, that needs fixed.22:36
johnsomrouk Can you open a story for it?22:36
rouktenants are divisions of prod/pte/dev by product for us, so users work across many tenants22:36
roukso... someone entered the wrong id and made a mess.22:37
johnsomYeah, I get it.22:37
roukyeah i can open a story.22:37
johnsomrm_work Do you have some cycles to fix this?22:37
johnsomHmm, he might be off for the day22:40
rouknice, internal server error when logging into storyboard, thanks ubuntu one.22:44
johnsomSigh, reload and try again, it usually works22:44
johnsomWe will get someone on it.22:45
rouki have 2 ubuntu one accounts cause one randomly breaks, currently both dont work..22:47
johnsomSigh, can you paste.openstack.org some reproduction steps? I can open it for you22:47
roukyeah, waiting for user to send me whatever they used, but its probably some trashy terraform nonsense.22:51
johnsomlol22:51
johnsomIt seems straight forward, but I want to capture it just in case there is something odd22:51
roukyeah, ill get you what they actually used whenever they send it to me in 0 to infinite time.22:56
openstackgerritBrian Haley proposed openstack/octavia master: Use more inclusive language for amphora roles  https://review.opendev.org/c/openstack/octavia/+/76348123:07
*** mchlumsky has quit IRC23:55

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!