*** salv-orlando has quit IRC | 00:17 | |
*** gangil has quit IRC | 00:25 | |
*** roger has quit IRC | 00:32 | |
*** shettyg has joined #openstack-neutron-ovn | 00:33 | |
*** chandrav has quit IRC | 00:35 | |
*** armax has quit IRC | 00:37 | |
*** armax has joined #openstack-neutron-ovn | 00:41 | |
*** asuvvari has joined #openstack-neutron-ovn | 00:51 | |
*** asuvvari has quit IRC | 00:56 | |
*** chandrav has joined #openstack-neutron-ovn | 01:12 | |
*** yamamoto has quit IRC | 01:12 | |
*** yamamoto has joined #openstack-neutron-ovn | 01:50 | |
*** azbiswas has joined #openstack-neutron-ovn | 02:00 | |
*** armax has quit IRC | 02:25 | |
*** salv-orlando has joined #openstack-neutron-ovn | 02:34 | |
*** salv-orlando has quit IRC | 02:55 | |
*** chandrav has quit IRC | 02:57 | |
*** chandrav has joined #openstack-neutron-ovn | 02:58 | |
*** azbiswas has quit IRC | 02:59 | |
*** azbiswas has joined #openstack-neutron-ovn | 02:59 | |
*** azbiswas has quit IRC | 03:03 | |
*** shettyg has quit IRC | 03:17 | |
*** armax has joined #openstack-neutron-ovn | 03:21 | |
*** salv-orlando has joined #openstack-neutron-ovn | 03:22 | |
*** chandrav has quit IRC | 03:27 | |
*** salv-orlando has quit IRC | 03:29 | |
*** subscope has joined #openstack-neutron-ovn | 03:42 | |
*** azbiswas has joined #openstack-neutron-ovn | 03:48 | |
*** azbiswas_ has joined #openstack-neutron-ovn | 03:55 | |
*** azbiswas has quit IRC | 03:57 | |
*** armax has quit IRC | 04:33 | |
*** salv-orlando has joined #openstack-neutron-ovn | 04:44 | |
*** salv-orlando has quit IRC | 04:56 | |
*** salv-orlando has joined #openstack-neutron-ovn | 05:23 | |
*** salv-orl_ has joined #openstack-neutron-ovn | 05:31 | |
*** salv-orlando has quit IRC | 05:34 | |
*** gizmoguy has quit IRC | 05:35 | |
*** gangil has joined #openstack-neutron-ovn | 05:55 | |
*** gangil has joined #openstack-neutron-ovn | 05:55 | |
*** fzdarsky__ has joined #openstack-neutron-ovn | 07:01 | |
*** openstackgerrit has quit IRC | 07:46 | |
*** openstackgerrit has joined #openstack-neutron-ovn | 07:47 | |
*** salv-orl_ has quit IRC | 07:56 | |
*** salv-orlando has joined #openstack-neutron-ovn | 08:01 | |
*** salv-orlando has quit IRC | 08:05 | |
*** salv-orlando has joined #openstack-neutron-ovn | 08:05 | |
*** azbiswas_ has quit IRC | 08:08 | |
*** azbiswas has joined #openstack-neutron-ovn | 08:39 | |
*** frickler has quit IRC | 09:05 | |
*** subscope has quit IRC | 10:10 | |
*** subscope has joined #openstack-neutron-ovn | 10:12 | |
*** subscope has quit IRC | 10:13 | |
*** asuvvari has joined #openstack-neutron-ovn | 10:15 | |
*** asuvvari has quit IRC | 10:20 | |
*** gangil has quit IRC | 10:55 | |
*** yamamoto has quit IRC | 11:24 | |
*** salv-orl_ has joined #openstack-neutron-ovn | 11:31 | |
*** salv-orlando has quit IRC | 11:34 | |
*** salv-orl_ has quit IRC | 11:44 | |
*** salv-orlando has joined #openstack-neutron-ovn | 11:45 | |
*** fzdarsky__ is now known as fzdarsky | 11:58 | |
*** yamamoto has joined #openstack-neutron-ovn | 12:20 | |
*** yamamoto has quit IRC | 12:29 | |
*** yamamoto has joined #openstack-neutron-ovn | 12:58 | |
*** regXboi has joined #openstack-neutron-ovn | 13:03 | |
*** azbiswas has quit IRC | 13:10 | |
*** azbiswas has joined #openstack-neutron-ovn | 13:11 | |
*** yamamoto has quit IRC | 13:27 | |
*** yamamoto has joined #openstack-neutron-ovn | 13:40 | |
*** nate_gone is now known as njohnston | 13:42 | |
*** armax has joined #openstack-neutron-ovn | 13:49 | |
ajo | russellb, when you're around, | 13:56 |
---|---|---|
ajo | could you dump me the flows of the bridge you use in OVN, with security groups? | 13:56 |
ajo | I want to check a few things, and I'd like to think about QoS with OVN structure in mind too | 13:56 |
ajo | lots of OvS / linux thinkering lately.. | 13:57 |
ajo | switchcade ^ ;) | 13:57 |
russellb | ajo: http://paste.openstack.org/show/476870/ | 13:58 |
russellb | happened to have it handy | 13:58 |
russellb | trying to get this all working in the tempest job | 13:58 |
russellb | works locally >_< | 13:58 |
ajo | sudo ovs-vsctl show ; sudo ovs-ofctl show <bridge> ; sudo ovs-ofctl dump-flows <bridge> | 13:58 |
ajo | ahh | 13:58 |
ajo | thanks, let me look | 13:58 |
russellb | i guess you need to know which ports are which | 13:58 |
ajo | the ovs-ofctl show helps me understand which port is which | 13:59 |
*** mestery has joined #openstack-neutron-ovn | 13:59 | |
ajo | come'on paste.openstack, serve to meeee! | 13:59 |
russellb | http://paste.openstack.org/show/476871/ | 13:59 |
ajo | russellb++ | 13:59 |
ajo | super thanks | 13:59 |
russellb | np | 14:00 |
russellb | now to figure out which is which, even with that, heh | 14:00 |
russellb | ofport 29 is probably my VM | 14:00 |
russellb | which has the security group applied | 14:00 |
ajo | russellb: neutron meeting :) | 14:01 |
russellb | ah yes | 14:01 |
russellb | ajo: http://paste.openstack.org/show/476872/ | 14:02 |
russellb | now with logical flows too | 14:02 |
ajo | russellb++ | 14:02 |
ajo | super super thanks | 14:02 |
russellb | can you share with kuba too? | 14:03 |
russellb | he was asking yesterday | 14:03 |
*** shettyg has joined #openstack-neutron-ovn | 14:03 | |
russellb | or i guess i can | 14:03 |
*** asuvvari has joined #openstack-neutron-ovn | 14:43 | |
*** yamamoto has quit IRC | 15:04 | |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: Add security group support using OVN ACLs. https://review.openstack.org/223817 | 15:06 |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: Don't log error on expected condition. https://review.openstack.org/237623 | 15:06 |
russellb | need one more review on this quick fix https://review.openstack.org/#/c/237623/1 | 15:07 |
gsagie | done | 15:12 |
russellb | gsagie: thanks! | 15:13 |
*** flaviof has quit IRC | 15:13 | |
*** flaviof has joined #openstack-neutron-ovn | 15:15 | |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: support OVN NB Logical Router name Update. https://review.openstack.org/237069 | 15:15 |
*** yamamoto has joined #openstack-neutron-ovn | 15:16 | |
*** salv-orlando has quit IRC | 15:18 | |
*** azbiswas has quit IRC | 15:25 | |
*** azbiswas has joined #openstack-neutron-ovn | 15:25 | |
*** yamamoto has quit IRC | 15:56 | |
*** yamamoto has joined #openstack-neutron-ovn | 16:06 | |
*** chandrav has joined #openstack-neutron-ovn | 16:06 | |
*** salv-orlando has joined #openstack-neutron-ovn | 16:20 | |
*** salv-orlando has quit IRC | 16:25 | |
*** gangil has joined #openstack-neutron-ovn | 16:47 | |
*** gangil has joined #openstack-neutron-ovn | 16:47 | |
russellb | gsagie: still around? https://review.openstack.org/#/c/237069/3 passed | 16:56 |
*** yamamoto has quit IRC | 17:02 | |
switchcade | ajo: neat demo :) | 17:10 |
ajo | switchcade, thanks, I cleaned it up a lot, it was a bit messy, and got updated :D | 17:10 |
ajo | switchcade, but I'm bad communicating, my video is boring :D | 17:11 |
switchcade | ah, it seems to nail exactly which commands you need to apply this, and pretty good visual with nload. | 17:12 |
switchcade | I only wish Vimeo had a speedup feature like youtube does. | 17:13 |
* russellb having trouble with dhcp with security groups on :/ | 17:13 | |
switchcade | (where you can play any video at 1.5x speed) | 17:13 |
russellb | still digging into it though | 17:13 |
russellb | all of my tests before applied the security group after the VM came up (and got its address via DHCP) | 17:13 |
russellb | at least i'm narrowing in on why things are blowing up | 17:14 |
russellb | yep, confirmed | 17:18 |
russellb | WELL THEN | 17:19 |
russellb | that only took me a day and half | 17:19 |
russellb | switchcade: that's something you'd expect to work, right? | 17:20 |
russellb | i have a from-lport ACL that says allow all output IP traffic (and related return traffic) | 17:20 |
russellb | from-lport 1002 (inport == "380de133-796a-4a6c-8583-c31702a2752e" && ip4) allow-related | 17:20 |
openstackgerrit | Merged openstack/networking-ovn: Don't log error on expected condition. https://review.openstack.org/237623 | 17:22 |
*** salv-orlando has joined #openstack-neutron-ovn | 17:24 | |
*** salv-orlando has quit IRC | 17:24 | |
*** salv-orlando has joined #openstack-neutron-ovn | 17:25 | |
russellb | ... and yep, changing security group to allow all incoming and outgoing IPv4 works | 17:28 |
switchcade | hmm, so DHCP requires l3 broadcast I guess? | 17:28 |
russellb | yeah | 17:28 |
switchcade | I can't say I've tried something like that with the connection tracker before, so I'm not exactly sure how it would be tracked | 17:29 |
russellb | i can probably hardcode a "fix" (dirty hack that makes me feel bad as a person) | 17:29 |
russellb | yeah i don't know either :) | 17:29 |
switchcade | I suspect the right answer is that you don't connection track it | 17:30 |
*** gangil has quit IRC | 17:30 | |
switchcade | let's see, source=0.0.0.0, dst=255.255.255.255 | 17:30 |
russellb | in the interest of "omg make this work as fast as possible", i can hardcode some default ACLs in our plugin that allow the DHCP UDP port numbers through | 17:30 |
switchcade | I think that's the most prudent. | 17:31 |
russellb | k :) | 17:31 |
russellb | but fyi, we'll probably have to revisit this under less time pressure :) | 17:31 |
switchcade | oh, for sure. I think I've heard DHCP mentioned as a separate item before. | 17:32 |
russellb | yes, we were going to do some native DHCP support in OVN | 17:32 |
russellb | right now we use a Python agent that Neutron has, that spins up dnsmasq processes for each network | 17:32 |
russellb | and it shows up on the network as another port | 17:33 |
russellb | gets the job done ... | 17:33 |
switchcade | I see. | 17:33 |
switchcade | yeah, I think the "allow-related" directionality is probably not particularly compatible with a protocol that broadcasts requests and responses and uses different source addresses.. | 17:34 |
switchcade | I wonder if there's such a concept as applying stateful ACLs to DHCP in iptables-land | 17:35 |
russellb | i wonder how this works in neutron today ... | 17:35 |
russellb | ajo: do you know off hand? | 17:35 |
* russellb hesitant to go too far down the rabbit hole of trying to find out this minute | 17:35 | |
switchcade | either way, something we can look at with more detail when Tokyo isn't next week:) | 17:35 |
* switchcade agrees | 17:36 | |
russellb | agree | 17:36 |
* russellb does dirty hack | 17:36 | |
*** gangil has joined #openstack-neutron-ovn | 17:36 | |
*** gangil has joined #openstack-neutron-ovn | 17:36 | |
*** asuvvari has quit IRC | 17:50 | |
*** asuvvari has joined #openstack-neutron-ovn | 17:50 | |
*** asuvvari has quit IRC | 17:55 | |
* russellb confesses his sins ... to-lport 1002 (outport == "8d64160a-e55a-4693-b0e8-cc1aaabe027b" && ip4 && udp && (udp.src == {67,68} || udp.dst == {67,68})) allow-related | 17:58 | |
russellb | switchcade: that fixed it | 17:59 |
russellb | "fixed"... | 17:59 |
russellb | :) | 17:59 |
*** yamamoto has joined #openstack-neutron-ovn | 18:03 | |
russellb | in other news, <3 the powerful / easy ACL syntax | 18:03 |
*** azbiswas has quit IRC | 18:04 | |
*** carl_baldwin has joined #openstack-neutron-ovn | 18:05 | |
*** yamamoto has quit IRC | 18:08 | |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: Add security group support using OVN ACLs. https://review.openstack.org/223817 | 18:09 |
*** gangil1 has joined #openstack-neutron-ovn | 18:11 | |
*** gangil has quit IRC | 18:11 | |
switchcade | russellb: Jury's out on the cardinality of that sin ;) | 18:13 |
*** asuvvari has joined #openstack-neutron-ovn | 18:14 | |
*** carl_baldwin has quit IRC | 18:18 | |
*** carl_baldwin has joined #openstack-neutron-ovn | 18:19 | |
*** flaviof_ has joined #openstack-neutron-ovn | 18:32 | |
*** gsagie_ has joined #openstack-neutron-ovn | 18:34 | |
*** flaviof has quit IRC | 18:35 | |
*** gsagie_ has quit IRC | 18:44 | |
*** carl_baldwin has quit IRC | 18:46 | |
*** carl_baldwin has joined #openstack-neutron-ovn | 18:49 | |
*** thumpba has joined #openstack-neutron-ovn | 19:09 | |
*** armax has quit IRC | 19:10 | |
russellb | switchcade: i swear that fix worked for me locally, but i'm still seeing failures because of VMs not getting DHCP responses :( | 19:16 |
*** azbiswas has joined #openstack-neutron-ovn | 19:17 | |
*** salv-orlando has quit IRC | 19:23 | |
switchcade | russellb: I really do wonder if the connection tracker is still interfering | 19:34 |
russellb | switchcade: yeah... | 19:34 |
switchcade | I don't think there's actually a "bypass conntrack" pipeline | 19:34 |
russellb | switchcade: let's go to #openvswitch actually, i was just talking about it there too | 19:34 |
switchcade | oh, sure., | 19:34 |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: Add security group support using OVN ACLs. https://review.openstack.org/223817 | 19:36 |
*** chandrav has quit IRC | 19:37 | |
*** chandrav has joined #openstack-neutron-ovn | 19:39 | |
russellb | chandrav: hey, how are things going? | 19:39 |
openstackgerrit | Merged openstack/networking-ovn: support OVN NB Logical Router name Update. https://review.openstack.org/237069 | 19:40 |
chandrav | russellb: We faced one issue when the delete router interface request comes with only subnet id and not the port id | 19:41 |
*** BB has joined #openstack-neutron-ovn | 19:41 | |
chandrav | there is no easy way of finding the port id with the current schema | 19:42 |
chandrav | so we duplicated the code from neutron. so that seems to be working now | 19:42 |
russellb | OK, sure, whatever works :) | 19:42 |
russellb | we can stash stuff as external_ids on the OVN schema, but doesn't sound like that would help here | 19:43 |
chandrav | there is also some test cases which test multiple prefixes on the same port, meaning one router interface will carry many subnets | 19:43 |
chandrav | these tests seem to be failing in tempest | 19:43 |
chandrav | yet to get to the root of the problem | 19:43 |
russellb | OK, if you have to, we can disable some tests in devstack/devstackgaterc temporarily | 19:44 |
russellb | if some basic cases seem to work | 19:44 |
chandrav | yeah, i think most of the test cases pass. | 19:45 |
chandrav | the current failures i am seeing in my setup are the following | 19:45 |
chandrav | test_dualnet_multi_prefix_dhcpv6_stateless | 19:45 |
russellb | i've got my fingers crossed on wrapping up security groups today, but i said that yesterday too ... after that i can help more | 19:45 |
chandrav | test_dualnet_multi_prefix_slaac | 19:46 |
russellb | chandrav: I think IPv6 is still a WIP for OVN's L3 support, actually | 19:46 |
russellb | so maybe we should just disable all the IPv6 tests for the moment | 19:46 |
chandrav | actually i have a total of 15 tests that are failing, most of them might not be related to ours | 19:46 |
russellb | we'll have to double check the status with blp in #openvswitch | 19:46 |
chandrav | yes | 19:46 |
chandrav | i'll run through these test cases and make sure our code is not breaking them | 19:47 |
russellb | great | 19:47 |
russellb | russellb> blp: so, OVN L3 IPv6, still a WIP, right? | 19:47 |
russellb | <blp> russellb: Yes. Justin is working on it. | 19:47 |
russellb | <russellb> k, just making sure i didn't miss something, thx | 19:47 |
chandrav | np | 19:48 |
*** armax has joined #openstack-neutron-ovn | 19:49 | |
openstackgerrit | Russell Bryant proposed openstack/networking-ovn: Add security group support using OVN ACLs. https://review.openstack.org/223817 | 19:51 |
*** thumpba has quit IRC | 19:56 | |
*** salv-orlando has joined #openstack-neutron-ovn | 20:05 | |
*** gangil1 has quit IRC | 20:23 | |
*** gizmoguy has joined #openstack-neutron-ovn | 20:26 | |
*** gangil has joined #openstack-neutron-ovn | 20:30 | |
*** gangil has joined #openstack-neutron-ovn | 20:30 | |
*** fzdarsky has quit IRC | 20:56 | |
*** regXboi has quit IRC | 21:03 | |
*** jimchou has joined #openstack-neutron-ovn | 21:16 | |
*** chandrav has quit IRC | 21:28 | |
*** chandrav has joined #openstack-neutron-ovn | 21:28 | |
*** salv-orlando has quit IRC | 21:33 | |
*** salv-orlando has joined #openstack-neutron-ovn | 21:34 | |
*** shettyg has quit IRC | 22:07 | |
*** armax has quit IRC | 22:19 | |
*** asuvvari has quit IRC | 22:34 | |
*** asuvvari has joined #openstack-neutron-ovn | 22:35 | |
*** asuvvari has quit IRC | 22:39 | |
*** jimchou_ has joined #openstack-neutron-ovn | 22:43 | |
*** jimchou has quit IRC | 22:44 | |
*** jimchou_ has quit IRC | 22:48 | |
*** salv-orlando has quit IRC | 23:06 | |
*** armax has joined #openstack-neutron-ovn | 23:22 | |
*** flaviof_ is now known as flaviof | 23:26 | |
*** azbiswas has quit IRC | 23:28 | |
*** yamamoto has joined #openstack-neutron-ovn | 23:28 | |
*** azbiswas has joined #openstack-neutron-ovn | 23:28 | |
*** azbiswas has quit IRC | 23:33 | |
*** jimchou has joined #openstack-neutron-ovn | 23:34 | |
*** yamamoto has quit IRC | 23:34 | |
*** jimchou has quit IRC | 23:39 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!