*** ileixe_ has quit IRC | 00:07 | |
*** ayoung has quit IRC | 00:11 | |
*** brinzhang has joined #openstack-meeting | 00:13 | |
*** ayoung has joined #openstack-meeting | 00:13 | |
*** ekcs has joined #openstack-meeting | 00:14 | |
*** brinzhang_ has quit IRC | 00:16 | |
*** diablo_rojo has quit IRC | 00:21 | |
*** ayoung has quit IRC | 00:21 | |
*** ayoung has joined #openstack-meeting | 00:22 | |
*** hyunsikyang has joined #openstack-meeting | 00:22 | |
*** hyunsikyang__ has quit IRC | 00:26 | |
*** gyee has quit IRC | 00:40 | |
*** brinzhang_ has joined #openstack-meeting | 00:41 | |
*** ayoung has quit IRC | 00:42 | |
*** ayoung has joined #openstack-meeting | 00:43 | |
*** brinzhang has quit IRC | 00:45 | |
*** kaisers has quit IRC | 00:45 | |
*** ayoung has quit IRC | 00:52 | |
*** ayoung has joined #openstack-meeting | 00:53 | |
*** kaisers has joined #openstack-meeting | 00:57 | |
*** dviroel has quit IRC | 01:01 | |
*** slaweq has joined #openstack-meeting | 01:10 | |
*** brinzhang has joined #openstack-meeting | 01:13 | |
*** rbudden has quit IRC | 01:15 | |
*** brinzhang_ has quit IRC | 01:16 | |
*** slaweq has quit IRC | 01:16 | |
*** yaawang has quit IRC | 01:28 | |
*** yaawang has joined #openstack-meeting | 01:28 | |
*** whoami-rajat has joined #openstack-meeting | 01:32 | |
*** dklyle has quit IRC | 01:35 | |
*** brinzhang_ has joined #openstack-meeting | 01:49 | |
*** dklyle has joined #openstack-meeting | 01:50 | |
*** brinzhang has quit IRC | 01:52 | |
*** ekcs has quit IRC | 01:55 | |
*** brinzhang has joined #openstack-meeting | 01:57 | |
*** brinzhang_ has quit IRC | 02:00 | |
*** apetrich has quit IRC | 02:09 | |
*** ayoung has quit IRC | 02:10 | |
*** markvoelker has joined #openstack-meeting | 02:11 | |
*** ayoung has joined #openstack-meeting | 02:13 | |
*** brinzhang_ has joined #openstack-meeting | 02:13 | |
*** brinzhang has quit IRC | 02:16 | |
*** markvoelker has quit IRC | 02:21 | |
*** markvoelker has joined #openstack-meeting | 02:22 | |
*** markvoelker has quit IRC | 02:26 | |
*** hongbin has joined #openstack-meeting | 02:37 | |
*** brinzhang has joined #openstack-meeting | 02:39 | |
*** brinzhang_ has quit IRC | 02:42 | |
*** diablo_rojo has joined #openstack-meeting | 02:59 | |
*** ayoung has quit IRC | 03:01 | |
*** ayoung has joined #openstack-meeting | 03:01 | |
*** slaweq has joined #openstack-meeting | 03:02 | |
*** slaweq has quit IRC | 03:06 | |
*** ayoung has quit IRC | 03:07 | |
*** ayoung has joined #openstack-meeting | 03:08 | |
*** yaawang has quit IRC | 03:13 | |
*** yaawang has joined #openstack-meeting | 03:15 | |
*** yaawang has quit IRC | 03:16 | |
*** yaawang has joined #openstack-meeting | 03:16 | |
*** brinzhang_ has joined #openstack-meeting | 03:19 | |
*** brinzhang has quit IRC | 03:22 | |
*** hongbin has quit IRC | 03:24 | |
*** lbragstad_ has joined #openstack-meeting | 03:31 | |
*** lbragstad has quit IRC | 03:31 | |
*** ayoung has quit IRC | 03:35 | |
*** ayoung has joined #openstack-meeting | 03:36 | |
*** whoami-rajat has quit IRC | 03:41 | |
*** ociuhandu has joined #openstack-meeting | 04:01 | |
*** ociuhandu has quit IRC | 04:06 | |
*** slaweq has joined #openstack-meeting | 04:11 | |
*** slaweq has quit IRC | 04:16 | |
*** lbragstad has joined #openstack-meeting | 04:25 | |
*** diablo_rojo has quit IRC | 04:26 | |
*** lbragstad_ has quit IRC | 04:28 | |
*** lbragstad_ has joined #openstack-meeting | 04:33 | |
*** lbragstad has quit IRC | 04:34 | |
*** boxiang has quit IRC | 04:36 | |
*** boxiang has joined #openstack-meeting | 04:36 | |
*** lbragstad has joined #openstack-meeting | 04:40 | |
*** lbragstad_ has quit IRC | 04:41 | |
*** pcaruana has joined #openstack-meeting | 04:55 | |
*** ekcs has joined #openstack-meeting | 04:55 | |
*** ekcs has quit IRC | 05:04 | |
*** ykatabam has quit IRC | 05:05 | |
*** ykatabam has joined #openstack-meeting | 05:06 | |
*** ekcs has joined #openstack-meeting | 05:06 | |
*** brinzhang_ has quit IRC | 05:08 | |
*** brinzhang_ has joined #openstack-meeting | 05:08 | |
*** ekcs has quit IRC | 05:21 | |
*** ekcs has joined #openstack-meeting | 05:22 | |
*** radeks_ has joined #openstack-meeting | 05:23 | |
*** brinzhang has joined #openstack-meeting | 05:28 | |
*** ayoung has quit IRC | 05:28 | |
*** ayoung has joined #openstack-meeting | 05:29 | |
*** brinzhang_ has quit IRC | 05:31 | |
*** ekcs has quit IRC | 05:38 | |
*** jamespage_ has joined #openstack-meeting | 05:47 | |
*** ayoung has quit IRC | 05:48 | |
*** ayoung has joined #openstack-meeting | 05:50 | |
*** ktsuyuzaki has joined #openstack-meeting | 05:53 | |
*** jamespage has quit IRC | 05:54 | |
*** tbarron has quit IRC | 05:54 | |
*** kota_ has quit IRC | 05:55 | |
*** jamespage_ is now known as jamespage | 05:55 | |
*** irclogbot_2 has quit IRC | 05:56 | |
*** irclogbot_0 has joined #openstack-meeting | 05:57 | |
*** lbragstad_ has joined #openstack-meeting | 06:00 | |
*** brinzhang has quit IRC | 06:00 | |
*** brinzhang has joined #openstack-meeting | 06:01 | |
*** lbragstad has quit IRC | 06:01 | |
*** lpetrut has joined #openstack-meeting | 06:04 | |
*** slaweq has joined #openstack-meeting | 06:08 | |
*** slaweq_ has joined #openstack-meeting | 06:13 | |
*** brinzhang_ has joined #openstack-meeting | 06:14 | |
*** slaweq has quit IRC | 06:14 | |
*** ayoung has quit IRC | 06:16 | |
*** brinzhang has quit IRC | 06:17 | |
*** kopecmartin|off is now known as kopecmartin | 06:17 | |
*** ayoung has joined #openstack-meeting | 06:17 | |
*** jawad_axd has joined #openstack-meeting | 06:21 | |
*** jawad_axd has quit IRC | 06:21 | |
*** jawad_axd has joined #openstack-meeting | 06:22 | |
*** jawad_axd has quit IRC | 06:25 | |
*** jawad_axd has joined #openstack-meeting | 06:26 | |
*** baojg has quit IRC | 06:31 | |
*** ayoung has quit IRC | 06:43 | |
*** ayoung has joined #openstack-meeting | 06:43 | |
*** brinzhang has joined #openstack-meeting | 06:46 | |
*** slaweq_ is now known as slaweq | 06:48 | |
*** brinzhang_ has quit IRC | 06:49 | |
*** jbadiapa has joined #openstack-meeting | 06:51 | |
*** trident has quit IRC | 06:53 | |
*** trident has joined #openstack-meeting | 06:55 | |
*** ttsiouts has joined #openstack-meeting | 07:00 | |
*** ykatabam has quit IRC | 07:01 | |
*** rcernin has quit IRC | 07:03 | |
*** tesseract has joined #openstack-meeting | 07:03 | |
*** tssurya has joined #openstack-meeting | 07:09 | |
*** _pewp_ has quit IRC | 07:14 | |
*** _pewp_ has joined #openstack-meeting | 07:14 | |
*** lpetrut has quit IRC | 07:15 | |
*** brinzhang_ has joined #openstack-meeting | 07:18 | |
*** tobberydberg has quit IRC | 07:20 | |
*** brinzhang has quit IRC | 07:21 | |
*** whoami-rajat has joined #openstack-meeting | 07:21 | |
*** cheng1 has quit IRC | 07:23 | |
*** cheng1 has joined #openstack-meeting | 07:24 | |
*** ttsiouts has quit IRC | 07:24 | |
*** jbadiapa has quit IRC | 07:25 | |
*** ttsiouts has joined #openstack-meeting | 07:25 | |
*** jbadiapa has joined #openstack-meeting | 07:25 | |
*** tobberydberg has joined #openstack-meeting | 07:26 | |
*** brinzhang has joined #openstack-meeting | 07:29 | |
*** apetrich has joined #openstack-meeting | 07:29 | |
*** ttsiouts has quit IRC | 07:30 | |
*** brinzhang_ has quit IRC | 07:33 | |
*** lpetrut has joined #openstack-meeting | 07:34 | |
*** ayoung has quit IRC | 07:45 | |
*** brinzhang_ has joined #openstack-meeting | 07:47 | |
*** ayoung has joined #openstack-meeting | 07:48 | |
*** brinzhang_ has quit IRC | 07:48 | |
*** brinzhang_ has joined #openstack-meeting | 07:49 | |
*** brinzhang_ has quit IRC | 07:50 | |
*** brinzhang_ has joined #openstack-meeting | 07:50 | |
*** brinzhang has quit IRC | 07:50 | |
*** brinzhang_ has quit IRC | 07:51 | |
*** rpittau|afk is now known as rpittau | 07:53 | |
*** lpetrut has quit IRC | 07:53 | |
*** ralonsoh has joined #openstack-meeting | 07:56 | |
*** ttsiouts has joined #openstack-meeting | 08:00 | |
*** ayoung has quit IRC | 08:18 | |
*** ayoung has joined #openstack-meeting | 08:21 | |
*** markvoelker has joined #openstack-meeting | 08:25 | |
*** markvoelker has quit IRC | 08:30 | |
*** liuyulong has joined #openstack-meeting | 08:48 | |
*** takamatsu has joined #openstack-meeting | 08:48 | |
*** macz has joined #openstack-meeting | 08:57 | |
*** macz has quit IRC | 09:02 | |
*** liuyulong has quit IRC | 09:03 | |
*** e0ne has joined #openstack-meeting | 09:09 | |
*** samP has quit IRC | 09:28 | |
*** samP has joined #openstack-meeting | 09:28 | |
*** whoami-rajat has quit IRC | 09:41 | |
*** ayoung has quit IRC | 09:45 | |
*** ayoung has joined #openstack-meeting | 09:46 | |
*** ociuhandu has joined #openstack-meeting | 09:49 | |
*** kaisers has quit IRC | 09:52 | |
*** kaisers has joined #openstack-meeting | 09:56 | |
*** ttsiouts has quit IRC | 09:57 | |
*** ttsiouts has joined #openstack-meeting | 09:58 | |
*** ttsiouts has quit IRC | 10:02 | |
*** yamamoto has quit IRC | 10:06 | |
*** brinzhang has joined #openstack-meeting | 10:07 | |
*** rcernin has joined #openstack-meeting | 10:09 | |
*** rpittau is now known as rpittau|bbl | 10:15 | |
*** rcernin has quit IRC | 10:21 | |
*** ociuhandu has quit IRC | 10:25 | |
*** yamamoto has joined #openstack-meeting | 10:41 | |
*** yamamoto has quit IRC | 10:46 | |
*** ykatabam has joined #openstack-meeting | 10:55 | |
*** macz has joined #openstack-meeting | 10:58 | |
*** ttsiouts has joined #openstack-meeting | 11:01 | |
*** rfolco has joined #openstack-meeting | 11:02 | |
*** macz has quit IRC | 11:03 | |
*** ociuhandu has joined #openstack-meeting | 11:04 | |
*** ociuhandu has quit IRC | 11:04 | |
*** ttsiouts has quit IRC | 11:06 | |
*** ttsiouts has joined #openstack-meeting | 11:06 | |
*** rfolco is now known as rfolco|ruck | 11:09 | |
*** brinzhang_ has joined #openstack-meeting | 11:16 | |
*** ociuhandu has joined #openstack-meeting | 11:17 | |
*** brinzhang has quit IRC | 11:19 | |
*** jbadiapa has quit IRC | 11:21 | |
*** brinzhang has joined #openstack-meeting | 11:21 | |
*** yamamoto has joined #openstack-meeting | 11:24 | |
*** brinzhang_ has quit IRC | 11:24 | |
*** brinzhang_ has joined #openstack-meeting | 11:31 | |
*** ykatabam has quit IRC | 11:34 | |
*** brinzhang has quit IRC | 11:34 | |
*** dmacpher has quit IRC | 11:35 | |
*** yamamoto has quit IRC | 11:39 | |
*** ykatabam has joined #openstack-meeting | 11:49 | |
*** yoctozepto has joined #openstack-meeting | 11:52 | |
*** yamamoto has joined #openstack-meeting | 12:09 | |
*** dviroel has joined #openstack-meeting | 12:14 | |
*** yaawang has quit IRC | 12:23 | |
*** ayoung has quit IRC | 12:28 | |
*** markvoelker has joined #openstack-meeting | 12:28 | |
*** yamamoto has quit IRC | 12:29 | |
*** ayoung has joined #openstack-meeting | 12:30 | |
*** markvoelker has quit IRC | 12:33 | |
*** rpittau|bbl is now known as rpittau | 12:33 | |
*** markvoelker has joined #openstack-meeting | 12:34 | |
*** jbadiapa has joined #openstack-meeting | 12:57 | |
*** jbadiapa has quit IRC | 12:58 | |
*** jbadiapa has joined #openstack-meeting | 12:58 | |
*** yamamoto has joined #openstack-meeting | 12:59 | |
*** macz has joined #openstack-meeting | 12:59 | |
*** yamamoto has quit IRC | 13:02 | |
*** macz has quit IRC | 13:03 | |
*** dklyle has quit IRC | 13:11 | |
*** ayoung has quit IRC | 13:12 | |
*** ayoung has joined #openstack-meeting | 13:15 | |
*** lbragstad_ is now known as lbragstad | 13:18 | |
*** ttsiouts has quit IRC | 13:25 | |
*** dklyle has joined #openstack-meeting | 13:26 | |
*** lbragstad has quit IRC | 13:26 | |
*** ttsiouts has joined #openstack-meeting | 13:26 | |
*** rbudden has joined #openstack-meeting | 13:28 | |
*** ttsiouts has quit IRC | 13:31 | |
*** brinzhang_ has quit IRC | 13:32 | |
*** brinzhang_ has joined #openstack-meeting | 13:32 | |
*** yamamoto has joined #openstack-meeting | 13:34 | |
*** enriquetaso has joined #openstack-meeting | 13:34 | |
*** jawad_axd has quit IRC | 13:51 | |
*** eharney has joined #openstack-meeting | 13:52 | |
*** ttsiouts has joined #openstack-meeting | 13:55 | |
*** ociuhandu has quit IRC | 13:57 | |
*** ileixe_ has joined #openstack-meeting | 13:58 | |
*** mlavalle has joined #openstack-meeting | 13:59 | |
*** dmacpher has joined #openstack-meeting | 13:59 | |
*** lbragstad has joined #openstack-meeting | 13:59 | |
slaweq | #startmeeting neutron_drivers | 14:00 |
---|---|---|
openstack | Meeting started Fri Oct 11 14:00:19 2019 UTC and is due to finish in 60 minutes. The chair is slaweq. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: neutron_drivers)" | 14:00 | |
slaweq | welcome :) | 14:00 |
openstack | The meeting name has been set to 'neutron_drivers' | 14:00 |
yamamoto | hi | 14:00 |
mlavalle | o/ | 14:00 |
ileixe_ | o/ | 14:00 |
njohnston | o/ | 14:00 |
*** artom has joined #openstack-meeting | 14:00 | |
haleyb | hi | 14:00 |
*** ykatabam has quit IRC | 14:01 | |
slaweq | we have a quorum already so let's start | 14:02 |
slaweq | #topic RFEs | 14:02 |
*** openstack changes topic to "RFEs (Meeting topic: neutron_drivers)" | 14:02 | |
slaweq | first one for today is: | 14:02 |
slaweq | https://bugs.launchpad.net/neutron/+bug/1759790 | 14:02 |
openstack | Launchpad bug 1759790 in neutron "[RFE] metric for the route" [Wishlist,In progress] - Assigned to Bin Lu (369283883-o) | 14:02 |
*** tssurya has quit IRC | 14:03 | |
amotoki | hi | 14:04 |
* njohnston refamiliarizes myself with FRR | 14:08 | |
slaweq | any thought about this one? | 14:09 |
njohnston | What protocol is the route cost being communicated on? MPLS, OSPF, BGP, or something else? | 14:09 |
amotoki | is it specific to some third-party L3 backend? | 14:09 |
*** jawad_axd has joined #openstack-meeting | 14:09 | |
amotoki | njohnston: I think 'metric' here is metric in linux routing tables for example. | 14:11 |
mlavalle | yes | 14:11 |
*** liuyulong has joined #openstack-meeting | 14:12 | |
slaweq | amotoki: that is also my understanding | 14:12 |
amotoki | metrics are populated by routing protocols like OSPF, BGP and so on, but metric is used by the forwarding plane. | 14:12 |
amotoki | The RFE proposes metric to static routes. | 14:13 |
mlavalle | yesh, in the bug description it shows the body of a request to /routers/router_id | 14:13 |
mlavalle | updating the routes attribute | 14:14 |
mlavalle | adding the metric field | 14:14 |
njohnston | ok, so in ML2/OVS does that become an openflow then? | 14:14 |
*** ociuhandu has joined #openstack-meeting | 14:14 | |
amotoki | it sounds reasonable in general. the next question would be about the reference implementation. | 14:15 |
slaweq | njohnston: I believe that in ML2/OVS case with L3 agent it would be set in qrouter- namespace | 14:15 |
mlavalle | amotoki's question is important.... there are comments along the history that seem to imply this won't be implemeneted in "namespace" routers | 14:15 |
mlavalle | I think we should clarify that | 14:16 |
amotoki | mlavalle: agree | 14:16 |
mlavalle | as a pure API addition, seems sensible | 14:17 |
amotoki | Although I haven't checked, linux IP stack supports it, so perhaps it works but it is worth clarifying. | 14:18 |
mlavalle | there is a metric option in the ip command | 14:18 |
mlavalle | seems to be the route command: http://man7.org/linux/man-pages/man8/route.8.html | 14:21 |
amotoki | ip route also supports metric https://www.systutorials.com/docs/linux/man/8-ip-route/ | 14:22 |
slaweq | so let's ask in launchpad for clarification of that, if this will be implemented in qrouter namespace, or only as API change which may be consumed by third party L3 drivers | 14:22 |
slaweq | are You ok with that? | 14:22 |
mlavalle | + | 14:23 |
amotoki | +1 | 14:23 |
yamamoto | +1 | 14:23 |
haleyb | +1 | 14:23 |
njohnston | +1 | 14:23 |
slaweq | do You want to write this question or should I do this? | 14:23 |
amotoki | slaweq: I can | 14:25 |
slaweq | amotoki: thx | 14:25 |
amotoki | I will add it after the meeting | 14:25 |
slaweq | so I think we can move on to the next one than | 14:25 |
slaweq | https://bugs.launchpad.net/neutron/+bug/1845622 | 14:26 |
openstack | Launchpad bug 1845622 in neutron "[RFE] Decouple allow_address_pair service with security_group" [Undecided,Confirmed] | 14:26 |
*** whoami-rajat has joined #openstack-meeting | 14:27 | |
*** ociuhandu has quit IRC | 14:28 | |
njohnston | the use case makes sense to me | 14:29 |
amotoki | I haven't fully understood the motivation of this request.... I am not sure what is the expected use cases of allowed_address_pairs by this proposal. | 14:30 |
amotoki | originally allowed_address_pairs extension was introduced to allow a neutron port to have more IPs/subnets along with security groups. | 14:30 |
mlavalle | I think I saw the submitter join the meeting, ileixe_ | 14:31 |
amotoki | so I wonder what does the standalone allowed-address-pairs mean. | 14:31 |
slaweq | amotoki: I think their use case is described in https://bugs.launchpad.net/neutron/+bug/1845622/comments/ | 14:31 |
openstack | Launchpad bug 1845622 in neutron "[RFE] Decouple allow_address_pair service with security_group" [Wishlist,Confirmed] | 14:31 |
slaweq | sorry: https://bugs.launchpad.net/neutron/+bug/1845622/comments/2 | 14:31 |
slaweq | ileixe_: hi | 14:31 |
slaweq | ileixe_: do You want to elaborate on use case behind this rfe? | 14:32 |
njohnston | basically it sounds like they cannot use octavia when enable_security_group=False because that setting disables allowed_address_pair, right? | 14:32 |
ileixe_ | Yes | 14:32 |
* mlavalle left comments in another of his submissions last night, so got familiar with the nickname | 14:32 | |
ileixe_ | Ys to njohnston | 14:32 |
ileixe_ | hi guys | 14:32 |
mlavalle | well, no in other comment ileixe_ seems to idndicate they have a workaround | 14:33 |
mlavalle | with the noop driver | 14:33 |
ileixe_ | Yes, we had been used like that | 14:33 |
mlavalle | so why change it | 14:33 |
mlavalle | ? | 14:33 |
ileixe_ | Hm.. there were several reasons related to our codes | 14:34 |
*** ociuhandu has joined #openstack-meeting | 14:34 | |
ileixe_ | but my point is | 14:34 |
amotoki | ileixe_: what is the root cause that octavia cannot work when enable_security_group=False? Is it just because octavia assumes allowed_address_pairs exist? | 14:35 |
ileixe_ | Yes for octavia | 14:35 |
ileixe_ | But I did not assume that allowed_address_pairs directly related to security group | 14:35 |
ileixe_ | sorry for my slow response | 14:35 |
ileixe_ | T_ T | 14:35 |
amotoki | ileixe_: no worries | 14:36 |
ileixe_ | but if then | 14:36 |
ileixe_ | it can be invalid | 14:36 |
ileixe_ | I don't know the extension cames from | 14:36 |
johnsom | Our amphora driver requires AAP to manage the VIP address. Basically having a second IP on a port. | 14:36 |
ileixe_ | In fact, we've been used the extension for other purpose | 14:36 |
mlavalle | johnsom: so it is actually used, right? | 14:37 |
johnsom | Yes, AAP is always used with the amphora driver. It is not optional. | 14:37 |
*** macz has joined #openstack-meeting | 14:38 | |
slaweq | johnsom: so if You would e.g. disable port security on such amphora port, octavia would fail to work? | 14:38 |
amotoki | johnsom: what is AAP? | 14:38 |
mlavalle | but if you were to configure the noop firewall, you get AAP and problem is fixed, right? | 14:38 |
mlavalle | AAP == Allowed Address Pairs | 14:39 |
johnsom | Allowed Address Pairs (AAP) (on mobile) | 14:39 |
amotoki | ah... | 14:39 |
*** munimeha1 has joined #openstack-meeting | 14:39 | |
johnsom | mlavalle: I do not know on the firewall noop. | 14:40 |
ileixe_ | mlavalle: Yes we've been used like that | 14:40 |
mlavalle | so again, why fix it if it ain't broke? | 14:40 |
*** diablo_rojo has joined #openstack-meeting | 14:40 | |
ileixe_ | hm.. I think it's right direction and it do break other our custom code.. | 14:41 |
amotoki | ileixe_: from the historical background, allowed-address-pairs ext was introduced to allow a neutron port to have more IP addresses, so the AAP extension is an enhancement of security group API. | 14:41 |
*** jawad_axd has quit IRC | 14:42 | |
amotoki | ileixe_: if you use allowed-address-pairs for different purposes, it is another topic. | 14:42 |
ileixe_ | Yes, if it couples security group a lot, again I think the request is invald | 14:42 |
mlavalle | and in principle, tailor the reference implementation to your custom code is not a very strong reason to change the reference implementation | 14:42 |
ileixe_ | Ok i understand | 14:43 |
*** macz has quit IRC | 14:43 | |
mlavalle | unless we can show we are going to benefit many other deployers, so we justify the effort and risk of changing the reference implemenatation code | 14:43 |
yamamoto | i guess you should explain what your "custom code" does | 14:43 |
slaweq | I agree with mlavalle | 14:44 |
ileixe_ | What I think about AAP is | 14:44 |
mlavalle | ileixe_: I am not saying no.... I am saying we need to understand a deep reason to do this | 14:44 |
ileixe_ | to provide additional IP for the port | 14:44 |
mlavalle | because this code belongs to a community | 14:44 |
ileixe_ | to enabble ACL | 14:44 |
ileixe_ | so what we have done for the port is to add some routing for the port when AAP is added | 14:45 |
*** enriquetaso has quit IRC | 14:45 | |
johnsom | I cannot seem to open the bug on my phone, so I have no context here | 14:45 |
ileixe_ | But.. I think it's not very common | 14:45 |
*** rbudden has quit IRC | 14:46 | |
njohnston | ileixe_: Why is it that you want to shift from firewall_driver=noop to enable_security_groups=false? | 14:46 |
ileixe_ | That's also because... | 14:46 |
njohnston | ileixe_: Is there a driver for that use case that could be applied to other openstack clouds? | 14:46 |
ileixe_ | we have to add some logics when seucirty group enabled | 14:46 |
ileixe_ | I don't want to | 14:46 |
mlavalle | ileixe_: I think we can explore this further, if you are willing to explain your use case further. So far, you have proposed a "what to do" (detach AAP from sec groups) but maybe the why (your use case) can be benefitial to the community | 14:46 |
ileixe_ | hm.. | 14:47 |
ileixe_ | I think it's better to explain our architecture first | 14:47 |
ileixe_ | And its anothoer RFE | 14:47 |
ileixe_ | can we deal with them first...? | 14:47 |
yamamoto | ileixe_: by somehow watching the updates of aap values? | 14:47 |
ileixe_ | Yes | 14:47 |
slaweq | maybe we can ask community if such use case would be useful for others also? E.g. on openstack-discuss ML? | 14:49 |
ileixe_ | We don't use security group, but when security group enabled, we have to add some logic for that (to bypass arp snooping rule). So I just want to use without security group. | 14:49 |
amotoki | I think ileixe_'s interpretation of allowed-address-pairs is correct. allowed-address-pairs attribute defines what IPs and ranges are behind the port. | 14:49 |
*** rbudden has joined #openstack-meeting | 14:50 | |
amotoki | it was introduced to enhance the security group, but the understanding looks valid. | 14:50 |
njohnston | ileixe_: so the real problem you're trying to overcome is the mac snooping protection? | 14:51 |
ileixe_ | Yes that was root cause | 14:52 |
amotoki | ileixe_: if so, port_security=False doesn't work for you? | 14:53 |
*** e0ne has quit IRC | 14:53 | |
slaweq | IIUC there are already at least 2 valid use cases of using AAP without security groups: ileixe_'s one and Octavia's one, right? | 14:53 |
mlavalle | it's the same, isn't it? | 14:53 |
mlavalle | ileixe_ wants this to use Octavia, right? | 14:53 |
ileixe_ | Yes | 14:53 |
slaweq | ahh, ok | 14:54 |
slaweq | so my understanding wasn't correct | 14:54 |
slaweq | sorry | 14:54 |
mlavalle | but he has a way to do it now, right? | 14:54 |
mlavalle | namely, the noop firewall | 14:54 |
ileixe_ | Yes it's not a problme for whom use reference implemtations | 14:54 |
johnsom | Yeah, to my knowledge the Octavia team is not asking for this change. What we have today works for us in general. | 14:55 |
ileixe_ | amotoki: I think it's not directly related to my issue but I will take a look at it. Thanks. | 14:55 |
mlavalle | and I understand that conceptually, it might be cleaner if AAP wasn't coupled to security groups.... but at this point it only seems conceptual... we don't have a specifc use case to enable at this point | 14:56 |
mlavalle | I mean a broken use case that we need to enable | 14:57 |
liuyulong | Maybe you should separate an isolated AZ for Octavia amphora to run instance without security group (firewall). And run users' normal instances to those hosts which enable the security group? | 14:57 |
slaweq | ok, so should we postpone this rfe until there will be more valid use cases for that? | 14:57 |
amotoki | we have 5mins left. my suggestion on the next step is that ileixe_ clarify what is the real needs. | 14:57 |
ileixe_ | Yes | 14:57 |
ileixe_ | agreed | 14:57 |
slaweq | amotoki: ok | 14:58 |
slaweq | sounds good | 14:58 |
yamamoto | +1 | 14:58 |
ileixe_ | liuyulong: Thanks I gonna look at it also | 14:58 |
njohnston | agreed. In particular ileixe_'s statement "when security group enabled, we have to add some logic for that (to bypass arp snooping rule)" is something that I don't see happening with the noop firewall driver, looking at the code. I don't see arp spoofing protection happening with noop. | 14:58 |
mlavalle | thanks ileixe_. we really appreciate your submission. whatever pushback I gave here is in the interest of identifying use cases valid from a community perspective | 14:59 |
slaweq | ok, thx for attending, we are on top of the hour now | 14:59 |
ileixe_ | my presure | 14:59 |
ileixe_ | :) | 14:59 |
slaweq | have a great weekend everyone :) | 14:59 |
slaweq | o/ | 14:59 |
slaweq | #endmeeting | 15:00 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:00 | |
openstack | Meeting ended Fri Oct 11 15:00:07 2019 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:00 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-10-11-14.00.html | 15:00 |
amotoki | o/ | 15:00 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-10-11-14.00.txt | 15:00 |
openstack | Log: http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-10-11-14.00.log.html | 15:00 |
yamamoto | good night | 15:00 |
slaweq | so ileixe_: please update LP bug with clarifications and we will get back to this on next meetings | 15:00 |
slaweq | thx for attending the meeting | 15:00 |
mlavalle | o/ | 15:00 |
njohnston | thanks ileixe_! | 15:00 |
ileixe_ | slaweq: Ok | 15:00 |
amotoki | ileixe_: thanks | 15:00 |
ileixe_ | o/ good night | 15:00 |
*** ileixe_ has left #openstack-meeting | 15:01 | |
*** mlavalle has left #openstack-meeting | 15:01 | |
*** lpetrut has joined #openstack-meeting | 15:04 | |
*** macz has joined #openstack-meeting | 15:04 | |
*** ttsiouts has quit IRC | 15:08 | |
*** ociuhandu has quit IRC | 15:09 | |
*** ayoung has quit IRC | 15:16 | |
*** rsimai_away has quit IRC | 15:17 | |
*** ayoung has joined #openstack-meeting | 15:19 | |
*** kopecmartin is now known as kopecmartin|off | 15:21 | |
*** ociuhandu has joined #openstack-meeting | 15:27 | |
*** ayoung has quit IRC | 15:28 | |
*** jawad_axd has joined #openstack-meeting | 15:30 | |
*** ayoung has joined #openstack-meeting | 15:31 | |
*** jawad_axd has quit IRC | 15:35 | |
*** jamesmcarthur has joined #openstack-meeting | 15:39 | |
*** bnemec has quit IRC | 15:43 | |
*** rpittau is now known as rpittau|afk | 15:44 | |
*** bnemec has joined #openstack-meeting | 15:44 | |
*** yamamoto has quit IRC | 15:48 | |
*** yamamoto has joined #openstack-meeting | 15:49 | |
*** yamamoto has quit IRC | 15:54 | |
*** macz has quit IRC | 15:55 | |
*** boxiang has quit IRC | 15:59 | |
*** zhubx has joined #openstack-meeting | 15:59 | |
*** zhubx has quit IRC | 16:00 | |
*** zhubx has joined #openstack-meeting | 16:01 | |
*** lpetrut has quit IRC | 16:05 | |
*** jamesmcarthur has quit IRC | 16:19 | |
*** jamesmcarthur has joined #openstack-meeting | 16:23 | |
*** ociuhandu has quit IRC | 16:23 | |
*** e0ne has joined #openstack-meeting | 16:23 | |
*** ociuhandu has joined #openstack-meeting | 16:26 | |
*** e0ne has quit IRC | 16:26 | |
*** yamamoto has joined #openstack-meeting | 16:26 | |
*** bbowen has quit IRC | 16:29 | |
*** yamamoto has quit IRC | 16:31 | |
*** markvoelker has quit IRC | 16:38 | |
*** markvoelker has joined #openstack-meeting | 16:48 | |
*** ayoung has quit IRC | 16:48 | |
*** ayoung has joined #openstack-meeting | 16:51 | |
*** gyee has joined #openstack-meeting | 16:53 | |
*** bnemec has quit IRC | 16:57 | |
*** bnemec has joined #openstack-meeting | 16:58 | |
*** ekcs has joined #openstack-meeting | 17:14 | |
*** dklyle has quit IRC | 17:14 | |
*** markvoelker has quit IRC | 17:18 | |
*** yamamoto has joined #openstack-meeting | 17:27 | |
*** rbudden has quit IRC | 17:29 | |
*** yamamoto has quit IRC | 17:33 | |
*** eharney has quit IRC | 17:34 | |
*** ociuhandu_ has joined #openstack-meeting | 17:34 | |
*** rbudden has joined #openstack-meeting | 17:37 | |
*** ociuhandu has quit IRC | 17:37 | |
*** ekcs has quit IRC | 17:40 | |
*** ayoung has quit IRC | 17:41 | |
*** ociuhandu_ has quit IRC | 17:42 | |
*** ayoung has joined #openstack-meeting | 17:42 | |
*** ociuhandu has joined #openstack-meeting | 17:43 | |
*** ociuhandu has quit IRC | 17:48 | |
*** dklyle has joined #openstack-meeting | 17:49 | |
*** ekcs has joined #openstack-meeting | 17:55 | |
*** dklyle has quit IRC | 17:56 | |
*** e0ne has joined #openstack-meeting | 17:59 | |
*** slaweq has quit IRC | 18:00 | |
*** dklyle has joined #openstack-meeting | 18:02 | |
*** yamamoto has joined #openstack-meeting | 18:06 | |
*** yamamoto has quit IRC | 18:11 | |
*** eharney has joined #openstack-meeting | 18:16 | |
*** slaweq has joined #openstack-meeting | 18:17 | |
*** slaweq has quit IRC | 18:22 | |
*** enriquetaso has joined #openstack-meeting | 18:24 | |
*** e0ne has quit IRC | 18:25 | |
*** e0ne has joined #openstack-meeting | 18:35 | |
*** jbadiapa has quit IRC | 18:45 | |
*** e0ne has quit IRC | 18:53 | |
*** pcaruana has quit IRC | 18:55 | |
*** ayoung has quit IRC | 19:00 | |
*** ayoung has joined #openstack-meeting | 19:03 | |
*** zhubx has quit IRC | 19:14 | |
*** zhubx has joined #openstack-meeting | 19:14 | |
*** eharney has quit IRC | 19:16 | |
*** zhubx has quit IRC | 19:16 | |
*** zhubx has joined #openstack-meeting | 19:16 | |
*** zhubx has quit IRC | 19:18 | |
*** markvoelker has joined #openstack-meeting | 19:18 | |
*** zhubx has joined #openstack-meeting | 19:18 | |
*** yamamoto has joined #openstack-meeting | 19:20 | |
*** zhubx has quit IRC | 19:20 | |
*** zhubx has joined #openstack-meeting | 19:20 | |
*** zhubx has quit IRC | 19:22 | |
*** zhubx has joined #openstack-meeting | 19:22 | |
*** zhubx has quit IRC | 19:24 | |
*** yamamoto has quit IRC | 19:24 | |
*** zhubx has joined #openstack-meeting | 19:24 | |
*** zhubx has quit IRC | 19:26 | |
*** jamesmcarthur has quit IRC | 19:26 | |
*** zhubx has joined #openstack-meeting | 19:26 | |
*** markvoelker has quit IRC | 19:30 | |
*** markvoelker has joined #openstack-meeting | 19:33 | |
*** jamesmcarthur has joined #openstack-meeting | 19:40 | |
*** markvoelker has quit IRC | 19:41 | |
*** ekcs has quit IRC | 19:48 | |
*** jamesmcarthur has quit IRC | 19:52 | |
*** radeks_ has quit IRC | 19:53 | |
*** yamamoto has joined #openstack-meeting | 19:57 | |
*** bbowen has joined #openstack-meeting | 19:58 | |
*** ekcs has joined #openstack-meeting | 19:58 | |
*** yamamoto has quit IRC | 20:02 | |
*** eharney has joined #openstack-meeting | 20:30 | |
*** rbudden has quit IRC | 20:32 | |
*** zhubx has quit IRC | 20:33 | |
*** zhubx has joined #openstack-meeting | 20:33 | |
*** zhubx has quit IRC | 20:34 | |
*** markvoelker has joined #openstack-meeting | 20:49 | |
*** markvoelker has quit IRC | 20:53 | |
*** ekcs has quit IRC | 20:59 | |
*** enriquetaso has quit IRC | 21:06 | |
*** yamamoto has joined #openstack-meeting | 21:12 | |
*** yamamoto has quit IRC | 21:16 | |
*** rfolco|ruck has quit IRC | 21:17 | |
*** bbowen_ has joined #openstack-meeting | 21:17 | |
*** bbowen has quit IRC | 21:18 | |
*** tesseract has quit IRC | 21:18 | |
*** ayoung has quit IRC | 21:19 | |
*** ayoung has joined #openstack-meeting | 21:20 | |
*** munimeha1 has quit IRC | 21:22 | |
*** eharney has quit IRC | 21:25 | |
*** whoami-rajat has quit IRC | 21:27 | |
*** ekcs has joined #openstack-meeting | 21:31 | |
*** yamamoto has joined #openstack-meeting | 21:44 | |
*** ayoung has quit IRC | 21:47 | |
*** ayoung has joined #openstack-meeting | 21:48 | |
*** yamamoto has quit IRC | 21:49 | |
*** rbudden has joined #openstack-meeting | 21:51 | |
*** ekcs has quit IRC | 21:51 | |
*** ekcs has joined #openstack-meeting | 21:54 | |
*** ekcs has quit IRC | 22:01 | |
*** diablo_rojo has quit IRC | 22:03 | |
*** ekcs has joined #openstack-meeting | 22:08 | |
*** ralonsoh has quit IRC | 22:09 | |
*** dviroel has quit IRC | 22:12 | |
*** diablo_rojo has joined #openstack-meeting | 22:29 | |
*** rcernin has joined #openstack-meeting | 22:42 | |
*** jamesmcarthur has joined #openstack-meeting | 22:45 | |
*** bbowen_ has quit IRC | 22:48 | |
*** bbowen has joined #openstack-meeting | 22:54 | |
*** bbowen has quit IRC | 22:54 | |
*** bbowen has joined #openstack-meeting | 22:56 | |
*** yamamoto has joined #openstack-meeting | 23:03 | |
*** yamamoto has quit IRC | 23:07 | |
*** artom has quit IRC | 23:12 | |
*** ayoung has quit IRC | 23:17 | |
*** ayoung has joined #openstack-meeting | 23:19 | |
*** ekcs has quit IRC | 23:22 | |
*** yamamoto has joined #openstack-meeting | 23:41 | |
*** zaneb has quit IRC | 23:45 | |
*** zaneb has joined #openstack-meeting | 23:46 | |
*** yamamoto has quit IRC | 23:46 | |
*** jamesmcarthur has quit IRC | 23:53 | |
*** jamesmcarthur has joined #openstack-meeting | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!