Monday, 2024-04-08

*** feld8 is now known as feld01:52
servagemHello11:39
servagemI've been reviewing the specification for custom security groups for VIP ports (https://review.opendev.org/c/openstack/octavia/+/915114/1/specs/version14.0/custom-security-groups-for-VIP-ports.rst).11:39
servagemI am interested in understanding whether the new custom SG will be available for use in the project (tenant) of the members. Specifically, can the new SG be created and utilized as a remote SG for the LB members?!11:40
servagemThe goal is to restrict LB members so they only accept traffic from the LB IPs. This is a security measure intended to prevent other VMs from directly accessing the LB backends. AFAIK, currently, I must allow access on the LB backends from the entire subnet CIDR of the VIP.11:40
gthiemon1eservagem: Hi, IMHO the custom SG belongs to the user/tenant that created the LB12:05
gthiemon1eservagem: it could be used as a remote_group_id of the members only in case of a one-arm LB (only subnets of the same network for the VIP and members)12:06
gthiemon1eservagem: we will discuss it tomorrow during the PTG, see line 70-77 https://etherpad.opendev.org/p/apr2024-ptg-octavia12:07
gthiemon1eservagem: I wrote "potential followup feature: SGs for member ports (shared readonly to allow their use as remote_group_id in users' SGs)", so anyways, for the backend, I think it will be another RFE12:07
*** gthiemon1e is now known as gthiemonge12:08
servagemgthiemonge: Understood. In my opinion, this feature significantly enhances security design for applications. It's a common architectural approach in cloud environments12:18
gthiemongeservagem: ack, please leave a comment in gerrit12:20
servagemI not sure I got you. You mean in the spec or etherpad?12:25
gthiemongeservagem: the spec12:57
gthiemongeservagem: it's always good to get feedback in the reviews12:58
servagemgthiemonge: sure. Thank you13:11
opendevreviewNickKush proposed openstack/octavia-lib master: Add support for 'X-Client-IP', 'X-Forwarded-IP', 'X-Real-IP' headers.  https://review.opendev.org/c/openstack/octavia-lib/+/91528215:12
opendevreviewNickKush proposed openstack/octavia master: Add support for 'X-Client-IP', 'X-Forwarded-IP', 'X-Real-IP' headers.  https://review.opendev.org/c/openstack/octavia/+/91528315:13
opendevreviewNickKush proposed openstack/octavia-lib master: Add support for 'X-Client-IP', 'X-Forwarded-IP', 'X-Real-IP' headers.  https://review.opendev.org/c/openstack/octavia-lib/+/91528215:22
opendevreviewNickKush proposed openstack/octavia master: Add support for 'X-Client-IP', 'X-Forwarded-IP', 'X-Real-IP' headers.  https://review.opendev.org/c/openstack/octavia/+/91528315:22

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!