*** markstur has quit IRC | 00:06 | |
*** jmlowe has joined #openstack-manila | 00:19 | |
*** eharney has quit IRC | 00:47 | |
*** markstur has joined #openstack-manila | 00:51 | |
*** harlowja has quit IRC | 01:10 | |
*** threestrands_ has joined #openstack-manila | 01:33 | |
*** threestrands has quit IRC | 01:36 | |
*** kaisers_ has joined #openstack-manila | 01:37 | |
*** kaisers has quit IRC | 01:40 | |
*** markstur has quit IRC | 01:57 | |
*** chrisyang_0660 has joined #openstack-manila | 02:45 | |
chrisyang_0660 | Hi team, may I ask a core to review our patch? https://review.openstack.org/#/c/570771/ | 02:46 |
---|---|---|
*** jmlowe has quit IRC | 02:47 | |
*** jmlowe has joined #openstack-manila | 02:56 | |
*** markstur has joined #openstack-manila | 03:00 | |
openstackgerrit | liushi proposed openstack/manila master: Config for cephfs volume and namespace prefixes https://review.openstack.org/572022 | 03:03 |
*** masuberu has quit IRC | 04:04 | |
*** boris_42_ has quit IRC | 04:06 | |
*** mvenesio has joined #openstack-manila | 04:13 | |
*** harlowja has joined #openstack-manila | 04:17 | |
*** kaisers_ has quit IRC | 04:35 | |
*** kaisers has joined #openstack-manila | 04:36 | |
*** kaisers has quit IRC | 04:40 | |
*** harlowja has quit IRC | 04:45 | |
*** kaisers has joined #openstack-manila | 05:08 | |
*** kaisers has quit IRC | 05:13 | |
*** mvenesio has quit IRC | 05:28 | |
*** e0ne has joined #openstack-manila | 05:32 | |
*** kaisers has joined #openstack-manila | 05:41 | |
*** e0ne has quit IRC | 05:54 | |
*** e0ne has joined #openstack-manila | 05:56 | |
*** e0ne has quit IRC | 05:56 | |
*** markstur has quit IRC | 05:58 | |
*** masber has joined #openstack-manila | 06:04 | |
*** pcaruana has joined #openstack-manila | 06:44 | |
*** openstackgerrit has quit IRC | 07:19 | |
*** rishabh has joined #openstack-manila | 07:20 | |
*** rishabh is now known as Guest99274 | 07:21 | |
*** masber has quit IRC | 07:27 | |
*** dsariel has joined #openstack-manila | 07:28 | |
*** masber has joined #openstack-manila | 07:35 | |
*** masuberu has joined #openstack-manila | 07:39 | |
*** masber has quit IRC | 07:43 | |
*** openstackgerrit has joined #openstack-manila | 07:50 | |
openstackgerrit | Yong Huang proposed openstack/manila stable/queens: [Manila Unity] Set unity_server_meta_pool option as required https://review.openstack.org/572687 | 07:50 |
*** e0ne has joined #openstack-manila | 07:51 | |
*** a-pugachev has joined #openstack-manila | 07:59 | |
*** threestrands_ has quit IRC | 08:03 | |
*** dsariel has quit IRC | 08:14 | |
*** kaisers has quit IRC | 08:15 | |
*** e0ne has quit IRC | 08:34 | |
*** e0ne has joined #openstack-manila | 08:35 | |
*** kaisers has joined #openstack-manila | 08:45 | |
*** e0ne_ has joined #openstack-manila | 08:50 | |
*** e0ne has quit IRC | 08:51 | |
openstackgerrit | zhongjun proposed openstack/manila master: Added share server in ensure shares method https://review.openstack.org/572705 | 08:57 |
*** e0ne has joined #openstack-manila | 09:00 | |
*** e0ne_ has quit IRC | 09:00 | |
*** YuYangWang has joined #openstack-manila | 09:29 | |
*** rraja__ has joined #openstack-manila | 09:43 | |
*** dsariel has joined #openstack-manila | 10:14 | |
*** e0ne_ has joined #openstack-manila | 10:22 | |
*** e0ne has quit IRC | 10:24 | |
tbarron | chrisyang_0660: reviewed. It looks good except that the release note needs a tweak. | 10:42 |
*** ganso has joined #openstack-manila | 10:52 | |
ganso | zhongjun_: ping | 10:56 |
*** erlon has joined #openstack-manila | 11:02 | |
*** scorcoran_afk has joined #openstack-manila | 11:05 | |
*** scorcoran_afk is now known as scorcoran | 11:06 | |
*** ubijtsa has joined #openstack-manila | 11:10 | |
*** ubijtsa is now known as assassin | 11:10 | |
*** Guest99274 has quit IRC | 11:13 | |
*** luizbag has joined #openstack-manila | 11:30 | |
*** a-pugachev has quit IRC | 11:39 | |
*** assassin has quit IRC | 11:44 | |
*** vgreen has joined #openstack-manila | 11:57 | |
*** rraja_ has joined #openstack-manila | 12:00 | |
*** rraja__ has quit IRC | 12:03 | |
*** scorcoran is now known as scorcoran_mtg | 12:05 | |
*** radmacher has joined #openstack-manila | 12:18 | |
*** AlexeyAbashkin has joined #openstack-manila | 12:29 | |
*** rraja_ has quit IRC | 12:30 | |
*** tpsilva has joined #openstack-manila | 12:30 | |
*** eharney has joined #openstack-manila | 12:34 | |
*** rraja_ has joined #openstack-manila | 12:39 | |
openstackgerrit | Nir Gilboa proposed openstack/manila-tempest-plugin master: Move shared logic to base scenario test class https://review.openstack.org/536059 | 12:42 |
*** sapcc-bot2 has quit IRC | 12:49 | |
*** sapcc-bot has quit IRC | 12:49 | |
*** sapcc-bot has joined #openstack-manila | 12:50 | |
*** sapcc-bot9 has joined #openstack-manila | 12:50 | |
*** rishabh has joined #openstack-manila | 13:04 | |
*** rishabh has quit IRC | 13:04 | |
radmacher | Does anyone here have experience with the NetApp driver? Im trying to figure out some supported implementation options and how to deal with multi tennant security. | 13:06 |
*** dustins has joined #openstack-manila | 13:07 | |
tbarron | ganso: bswartz ^^^^^ | 13:22 |
tbarron | radmacher: probably just go on and ask your questions and people will pick up as they are able | 13:22 |
ganso | radmacher: Hi | 13:22 |
*** kaisers has quit IRC | 13:23 | |
*** kaisers has joined #openstack-manila | 13:23 | |
tbarron | radmacher: also this is a good guide: http://netapp.github.io/openstack-deploy-ops-guide/ocata/content/ch_manila.html | 13:24 |
radmacher | Hey. I am curious about how to secure and isolate multi tenant access over a shared storage vlan. I spoke with someone at NetApp at the OpenStack Summit and he mentioned a design that let instances have a private tenant network used for storage but then use neutron to translate that access down into a shared provider vlan network via floating IPs. This would provide tenant isolation and let us | 13:25 |
radmacher | manage nfs mount access on the NetApp side via the floating IPs. | 13:25 |
radmacher | The problem is that I cant find any documentation describing this. | 13:26 |
tbarron | radmacher: and see https://www.openstack.org/assets/presentation-media/What-the-heck-DHSS.pdf w.r.t. multi-tenancy options | 13:26 |
radmacher | Thank you for those links. The first deployment guide is something I have run across already and from what I can parse does not cover the situation I was thinking of. Ill read this PDF now. | 13:28 |
*** kambiz has quit IRC | 13:33 | |
*** kambiz has joined #openstack-manila | 13:33 | |
*** Alexey_Abashkin has joined #openstack-manila | 13:51 | |
*** AlexeyAbashkin has quit IRC | 13:53 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 13:53 | |
*** dustins has quit IRC | 13:57 | |
ganso | radmacher: sorry for the delay, I'm in a meeting. You can find instructions how to set up the DHSS=True (or Multi-SVM in NetApp vocabulary) in https://netapp-openstack-dev.github.io/openstack-docs/queens/ch_manila.html | 13:58 |
*** DorZ has joined #openstack-manila | 13:59 | |
DorZ | Hey there. How can I get up the web dashboard? | 13:59 |
DorZ | or is it by default up and I dont know the port? | 14:00 |
ganso | radmacher: there are several ways to configure your network, but the one described in the guide is that you configure neutron to create tenant networks with VLANs from a provider network which is directly connected to the storage. The VMs will be created on this network as well, so they talk directly to the storage over this VLAN securely | 14:01 |
ganso | radmacher: on the storage side, a new vserver will be created for each share network, making sure that one VM that is in one share network cannot access resources from another share network that it is not in | 14:02 |
radmacher | ganso: what if we were not able to use vservers/svms | 14:07 |
DorZ | hey. how can I create new (first) project on manila? tried to execute manila create but it ask me for alot of details | 14:17 |
ganso | radmacher: not sure if I understand your use case, "vserver"/"svm" is how netapp storage segregates tenants, so you need to have at least 1 in your storage. Whether it will be 1 vserver/svm per tenant or 1 shared across all tenants depends on how you configure the manila driver mode | 14:19 |
radmacher | Yeah, it will be one vserver/svm shared between all of our openstack tenants | 14:23 |
radmacher | the model I had in my head, that I understood from the conversation I had with the NetApp person, was that we would have a single storage vlan with a single vserver attached to all of our compute hosts. That VLAN would be presented as a provider vlan of which we pulled floating IPs from. Tenants would then have private tenant netwokrs attached to their instance storage interfaces that would | 14:26 |
radmacher | then use the previously mentioned floating IPs to associate to specific instances and allow access to the vserver. | 14:26 |
*** AlexeyAbashkin has quit IRC | 14:28 | |
*** AlexeyAbashkin has joined #openstack-manila | 14:36 | |
ganso | radmacher: oh I understand it know, it is a DHSS=False / Single-SVM setup | 14:36 |
ganso | radmacher: in that case the network is a wildcard and the storage configuration is not that relevant in that case | 14:36 |
radmacher | ok, thats helpful. Ill keep that in mind as I go through this slide deck. Thank You. | 14:38 |
*** scorcoran_mtg is now known as scorcoran | 14:38 | |
ganso | radmacher: in the link that tbarron said you can see some tips to achieve isolation using DHSS=False. It would be good to get your neutron expert involved to weigh in as well | 14:39 |
ganso | radmacher: ideally (IMOO) you shouldn't have to rely on floating ips to allow connectivity to the storage | 14:39 |
radmacher | for what reason? | 14:39 |
ganso | radmacher: s/IMOO/IMO | 14:40 |
ganso | radmacher: in a regular environment floating ips usually connect VMs to the external world, most of the times that is not ideal to connect VMs to the storage network. There should be a network path from VMs to the storage network that doesn't go through the external network | 14:40 |
*** scorcoran is now known as scorcoran_food | 14:41 | |
radmacher | I can agree with that. My problem is that given the requirement for us to not use multiple vservers Im not sure how else to provide isolation. | 14:42 |
radmacher | This would also not be an "external" network. But a seperate storage only interface that the instance uses to mount NFS. Its external in openstack parlance but not out to the public network. | 14:43 |
rraja_ | batrick, ping | 14:44 |
ganso | radmacher: oh cool, but in that I believe floating ips are not necessary to connect to that storage network. Just a virtual router should be enough | 14:44 |
rraja_ | batrick, can you take a look at this patch, https://review.openstack.org/#/c/572022/ | 14:44 |
radmacher | ganso: this is true. For some reason I had both fused together in my head. The storage system would just route traffic to the tenant networks via the attached virtual router. no need for translations. Is this something that can be end to end provisioned with Manila? | 14:46 |
rraja_ | batrick, the code itself is fine. I just feel that the configurables need a better description or something is missing. please add your comments if any to that review | 14:47 |
tbarron | radmacher: with a different backend (ceph-nfs) and DHSS=false we use a separate isolated network in the data centre for the NFS exports | 14:48 |
tbarron | radmacher: we make a neutron provider network (shared) that maps to this data center network | 14:49 |
tbarron | radmacher: and we boot VMs with two nics | 14:49 |
tbarron | rraja_: the first nic is on the tenant private network and can get floating IPs with a tenant-owned router | 14:50 |
tbarron | rraja_: sorry | 14:50 |
radmacher | tbarron: that is exactly what we are thinking of. How do you manage tenant isolation though? Is it a seperate isolated network per tenant or do they all share that network? | 14:50 |
tbarron | radmacher: ^^ | 14:50 |
tbarron | radmacher: that nic has nothing to do with the nfs service | 14:50 |
tbarron | radmacher: the second nic acquires an address on the "StorageNFS" network and mounts shares over it | 14:51 |
tbarron | radmacher: no floating IPs are required; they get IPs from that net's allocation pool directly | 14:51 |
*** scorcoran_food is now known as scorcoran_mtg | 14:51 | |
ganso | radmacher: not sure what you mean by Manila provisioning that end-to-end, in DHSS=False mode all network configuration is manual, done by the admnistrator, and manila doesn't get involved like in DHSS=True where Manila does all the setup for you | 14:51 |
tbarron | radmacher: default security rules disallow ping, ssh among VMs on that network belonging to different tenants | 14:52 |
tbarron | radmacher: they share the same network and server, so there is potential resource contention but | 14:52 |
tbarron | radmacher: there should not be direct VM to VM access issues | 14:52 |
radmacher | tbarron: and you are trusting that neutron wont let an instance change its IP so it would then be allowed to mount a share that it shouldnt? | 14:53 |
tbarron | radmacher: need to have arp spoofing protection on that net | 14:53 |
tbarron | radmacher: but if you have a netapp I'd be inclined to go with the DHSS=True approach | 14:54 |
ganso | tbarron: depends if radmacher needs replication or manage features | 14:55 |
radmacher | tbarron: what you described is how we have it currently. I was just wondering if we could get further isolation. What gansol and I were discussing sounds like it might be that ticket. | 14:55 |
tbarron | radmacher: in the future we want to take a similar approach for cephfs-nfs but are atm constrained by the current ganesha (nfs-gateway) implementation | 14:55 |
tbarron | radmacher: which is being worked on | 14:55 |
ganso | too bad those features are not yet available in DHSS=True | 14:55 |
tbarron | ganso: ack | 14:56 |
radmacher | ganso: Im not sure what you mean about replication/manage features. | 14:56 |
tbarron | DorZ: don't mean to be ignoring your questions. Did you succeed in accessing the OpenStack dashboard? | 15:00 |
*** dsariel has quit IRC | 15:00 | |
*** markstur has joined #openstack-manila | 15:09 | |
*** dsariel has joined #openstack-manila | 15:13 | |
*** AlexeyAbashkin has quit IRC | 15:14 | |
*** AlexeyAbashkin has joined #openstack-manila | 15:16 | |
*** pcaruana has quit IRC | 15:23 | |
ganso | radmacher: those are manila features that NetApp backend supports, but only in DHSS=False | 15:40 |
*** rraja_ has quit IRC | 15:42 | |
radmacher | ganso: ah. gotcha | 15:47 |
*** erlon_ has joined #openstack-manila | 15:54 | |
*** erlon has quit IRC | 15:54 | |
*** dustins has joined #openstack-manila | 15:58 | |
*** scorcoran_mtg is now known as scorcoran_biab | 16:02 | |
*** scorcoran_biab is now known as scorcoran | 16:28 | |
batrick | tbarron: how do I submit a comment in gerrit? | 16:49 |
batrick | i am trying to reply to the patchset linked to by rraja | 16:49 |
batrick | my comment is in "draft" but i don't see a way to submit lol | 16:49 |
tbarron | batrick: are you logged in to gerrit? | 16:49 |
batrick | i think so | 16:50 |
batrick | it had me go to ubuntu one or something to create an account | 16:51 |
batrick | and my name is at the top-right | 16:51 |
gouthamr | there's a "Reply" button | 16:53 |
gouthamr | on the landing page for the change.. | 16:53 |
tbarron | batrick: ok, the hard part is done, use 'Reply' as gouthamr said | 16:54 |
tbarron | batrick: and thanks for helping on that review | 16:55 |
batrick | oh, the reply button is on the main changeset page | 16:56 |
batrick | i was looking for it on the place i made the comment: https://review.openstack.org/#/c/572022/6//COMMIT_MSG | 16:56 |
*** AlexeyAbashkin has quit IRC | 16:57 | |
tbarron | batrick: that's too reasonable | 16:57 |
gouthamr | batrick: you can make comments on all the files that are in the change, and then post them at once with the "Reply" and your vote on the code -1,0,+1 | 16:57 |
*** e0ne_ has quit IRC | 17:01 | |
*** dustins_ has joined #openstack-manila | 17:22 | |
*** dustins has quit IRC | 17:25 | |
*** kaisers has quit IRC | 17:47 | |
*** e0ne has joined #openstack-manila | 17:58 | |
*** boris_42_ has joined #openstack-manila | 18:07 | |
*** jmlowe has quit IRC | 18:23 | |
*** kaisers has joined #openstack-manila | 18:24 | |
*** scorcoran is now known as scorcoran_afk | 18:25 | |
*** dsariel has quit IRC | 18:57 | |
*** kaisers has quit IRC | 19:00 | |
*** jmlowe has joined #openstack-manila | 19:03 | |
*** jmlowe has quit IRC | 19:04 | |
*** jmlowe has joined #openstack-manila | 19:05 | |
*** vgreen has quit IRC | 19:22 | |
*** e0ne has quit IRC | 19:22 | |
*** scorcoran_afk has quit IRC | 19:30 | |
openstackgerrit | Nir Gilboa proposed openstack/manila-tempest-plugin master: Move shared logic to base scenario test class https://review.openstack.org/536059 | 19:33 |
*** kaisers has joined #openstack-manila | 19:41 | |
*** kaisers has quit IRC | 19:46 | |
*** jmlowe has quit IRC | 19:50 | |
*** luizbag has quit IRC | 19:55 | |
*** scorcoran_afk has joined #openstack-manila | 20:00 | |
*** e0ne has joined #openstack-manila | 20:01 | |
*** jmlowe has joined #openstack-manila | 20:07 | |
*** ganso has quit IRC | 20:08 | |
*** dsariel has joined #openstack-manila | 20:18 | |
radmacher | /script load usercount.pl | 20:24 |
*** e0ne has quit IRC | 20:30 | |
*** jmlowe has quit IRC | 21:05 | |
openstackgerrit | Sean McGinnis proposed openstack/manila master: Default pylint to run using python3 https://review.openstack.org/572991 | 21:14 |
*** jmlowe has joined #openstack-manila | 21:25 | |
*** batrick has quit IRC | 21:31 | |
*** dims has left #openstack-manila | 21:32 | |
*** batrick has joined #openstack-manila | 21:34 | |
*** kaisers has joined #openstack-manila | 21:42 | |
*** dustins_ has quit IRC | 22:00 | |
*** kaisers has quit IRC | 22:06 | |
*** markstur has quit IRC | 22:18 | |
*** jmlowe has quit IRC | 22:24 | |
*** DorZ has quit IRC | 22:37 | |
*** tpsilva has quit IRC | 22:40 | |
*** jmlowe has joined #openstack-manila | 22:45 | |
*** threestrands has joined #openstack-manila | 22:51 | |
*** jmlowe has quit IRC | 23:22 | |
*** jmlowe has joined #openstack-manila | 23:24 | |
*** kaisers has joined #openstack-manila | 23:45 | |
*** kaisers has quit IRC | 23:50 | |
openstackgerrit | Goutham Pacha Ravi proposed openstack/manila master: Use class name in invocation of super https://review.openstack.org/573040 | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!