Wednesday, 2023-04-12

mnaserahhhh i think i found the one00:28
mnaserhttps://bugzilla.redhat.com/show_bug.cgi?id=193952400:28
opendevreviewMiguel Lavalle proposed openstack/neutron master: [DNM] Add rate-limiting to metadata agents  https://review.opendev.org/c/openstack/neutron/+/85887900:29
opendevreviewMiguel Lavalle proposed openstack/neutron master: [DNM] Add rate-limiting to metadata agents  https://review.opendev.org/c/openstack/neutron/+/85887900:33
opendevreviewMiguel Lavalle proposed openstack/neutron master: [DNM] Add rate-limiting to metadata agents  https://review.opendev.org/c/openstack/neutron/+/85887900:36
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991301:02
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991301:56
opendevreviewMiguel Lavalle proposed openstack/neutron master: [DNM] Add rate-limiting to metadata agents  https://review.opendev.org/c/openstack/neutron/+/85887903:47
opendevreviewyatin proposed openstack/neutron-tempest-plugin master: [DNM] non nested virt jammy nodes with workaround  https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/87903604:46
lajoskatonaslaweq, ralonsoh: Hi, could you please check this patch from isabek for sfc: https://review.opendev.org/c/openstack/networking-sfc/+/876944 ? Thanks in advance05:58
ralonsohsure, let me check06:13
ionihi guys, i was wondering if you can point me in the right direction. I want to block some ports in the default security group but I don't want that particular rule to be edited or removed unless is admin 07:02
opendevreviewRodolfo Alonso proposed openstack/neutron master: Checkout "sqlalchemy/alembic" main branch in sqlalchmey-master jobs  https://review.opendev.org/c/openstack/neutron/+/88012607:02
ionibut other security groups can be attached or detached without problem07:02
ionimostly I want to block outgoing 25/587 ports07:03
ralonsohioni, if a regular user has access to a network within a project, he/she will have access to add/remove rules in the default SG07:10
ralonsohyou can, as admin, create a network and share it07:10
ralonsohif I'm not wrong, the SG used will be the default one and this SG will be owned by the admin only07:10
ralonsohbut, in any case, the port owner can add/remove any SG 07:11
ioniyes, that was my understanding regarding SG as well. but i was trying to find a way, that I didn't know, to handle this case07:12
lajoskatonaioni, ralonsoh: I am not sure but perhaps this can be helpful if ready for ioni's problem: https://specs.openstack.org/openstack/neutron-specs/specs/2023.1/configurable-default-sg-rules.html07:56
fricklerlajoskatona: that would only affect newly created security groups, tenants could still change those07:58
fricklerneutron-fwaas is what used to be the solution for that issue07:58
ioni"Of course, those rules created by default by Neutron can be easily removed by the security group owner"08:07
ioniit resolves the default block ports having a template if that spec is implemented08:07
ionibut not the permission related to that block rule08:07
opendevreviewMerged openstack/networking-sfc master: Use neutron-lib policy rules  https://review.opendev.org/c/openstack/networking-sfc/+/87694408:12
opendevreviewSlawek Kaplonski proposed openstack/neutron master: [S-RBAC] Allow network owners to get ports from that network  https://review.opendev.org/c/openstack/neutron/+/87989108:15
opendevreviewSahid Orentino Ferdjaoui proposed openstack/neutron master: dhcp: fix network.segments condition when no segments  https://review.opendev.org/c/openstack/neutron/+/88013108:23
opendevreviewyatin proposed openstack/neutron master: [DNM] debug ovn skip level  https://review.opendev.org/c/openstack/neutron/+/87876108:51
opendevreviewMerged openstack/ovsdbapp master: Add new function ls_get_localnet_ports  https://review.opendev.org/c/openstack/ovsdbapp/+/87385309:13
lajoskatonaralonsoh: Hi, Nova has some lines for the Vancouver PTG in their etherpad: https://etherpad.opendev.org/p/nova-bobcat-ptg#L62309:49
lajoskatonaralonsoh: it has some thought to have common discussion/handson for CI issues and similar, quite interesting as I see, hope many of us can be there :-)09:49
ralonsohlajoskatona, nice to see that. But sorry, I have the same feeling as before: the vPTG was enough for the cycle planning 09:50
ralonsohplus we have the weekly meetings09:50
ralonsohI'll ping gibi to check what cross meetings sessions will be needed09:51
lajoskatonaralonsoh: ack09:52
slaweqralonsoh yet another bug related to S-RBAC: https://bugs.launchpad.net/neutron/+bug/201598710:04
slaweqI will send patch in 5 minutes10:04
opendevreviewSlawek Kaplonski proposed openstack/neutron-lib master: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88014310:05
ralonsohslaweq, we'll need to backport it, right? Up to Zed10:05
ralonsohand release a new n-lib version10:05
slaweqralonsoh yes10:05
slaweqonce it will be merged in u/s I will propose backports too10:06
ralonsohperfect, once we have all patches merged, we'll release a new n-lib version10:06
slaweqthx10:06
ralonsohslaweq, in L183, for consistency, do we need is_admin=True? you removed it from L179 and is set in "elevated" function10:08
ralonsoh--> https://review.opendev.org/c/openstack/neutron-lib/+/880143/1/neutron_lib/context.py#b18110:12
slaweqof course it's not needed10:14
slaweqlet me update it :)10:14
slaweqsorry10:14
opendevreviewSlawek Kaplonski proposed openstack/neutron-lib master: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88014310:14
slaweqdone ^^10:14
opendevreviewSlawek Kaplonski proposed openstack/neutron-lib master: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88014310:28
opendevreviewBence Romsics proposed openstack/neutron master: port-hints: api extension  https://review.opendev.org/c/openstack/neutron/+/87008111:35
opendevreviewBence Romsics proposed openstack/neutron master: port-hint-ovs-tx-steering: agent side  https://review.opendev.org/c/openstack/neutron/+/87290511:35
opendevreviewBence Romsics proposed openstack/neutron master: port-hint-ovs-tx-steering: shim extension  https://review.opendev.org/c/openstack/neutron/+/87311311:35
opendevreviewBence Romsics proposed openstack/neutron master: DNM debug logs and dev helper scripts  https://review.opendev.org/c/openstack/neutron/+/87290611:35
opendevreviewLajos Katona proposed openstack/neutron-dynamic-routing master: Add neutron and neutron-lib projects to SQLAlchemy main branch job  https://review.opendev.org/c/openstack/neutron-dynamic-routing/+/87933711:56
opendevreviewLajos Katona proposed openstack/neutron-dynamic-routing master: Add neutron and neutron-lib projects to SQLAlchemy main branch job  https://review.opendev.org/c/openstack/neutron-dynamic-routing/+/87933711:57
opendevreviewLajos Katona proposed openstack/networking-bgpvpn master: CI: add oslo_master and sqlalchemy to periodic weekly  https://review.opendev.org/c/openstack/networking-bgpvpn/+/86196012:12
opendevreviewLajos Katona proposed openstack/networking-bagpipe master: CI: Add periodic weekly job with sqlalchemy main  https://review.opendev.org/c/openstack/networking-bagpipe/+/87240812:15
opendevreviewLajos Katona proposed openstack/networking-sfc master: Add neutron and neutron-lib projects to SQLAlchemy main branch job  https://review.opendev.org/c/openstack/networking-sfc/+/87933612:24
ralonsohmlavalle2, https://review.opendev.org/c/openstack/neutron-lib/+/88014312:59
ralonsohif you have time, we would need to backport this patch asap12:59
mlavalle2ralonsoh: done13:05
ralonsohthanks13:07
opendevreviewRodolfo Alonso proposed openstack/neutron-lib stable/2023.1: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88010213:07
opendevreviewRodolfo Alonso proposed openstack/neutron-lib stable/zed: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88010313:07
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991313:19
opendevreviewBrian Haley proposed openstack/neutron master: Delete network namespace on last port deletion  https://review.opendev.org/c/openstack/neutron/+/88000614:20
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991314:30
opendevreviewMerged openstack/neutron-lib master: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88014314:42
opendevreviewMerged openstack/ovn-octavia-provider stable/yoga: Add new FTs for health monitoring basic operations  https://review.opendev.org/c/openstack/ovn-octavia-provider/+/87650314:49
opendevreviewMerged openstack/ovn-octavia-provider stable/wallaby: Add new FTs for health monitoring basic operations  https://review.opendev.org/c/openstack/ovn-octavia-provider/+/87651114:53
opendevreviewMiro Tomaska proposed openstack/neutron master: Fix intermittent failures in finding metada port in SB DB  https://review.opendev.org/c/openstack/neutron/+/87854915:02
opendevreviewyatin proposed openstack/neutron master: [CI][fullstack/functional] Report slowest tests  https://review.opendev.org/c/openstack/neutron/+/88016115:09
opendevreviewSlawek Kaplonski proposed openstack/neutron master: WIP [S-RBAC] Switch to new policies by default  https://review.opendev.org/c/openstack/neutron/+/87982715:13
opendevreviewMerged openstack/neutron master: Filter out unsatisfied routers in SQL  https://review.opendev.org/c/openstack/neutron/+/84214115:19
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991315:39
opendevreviewMerged openstack/neutron master: Increase port name size and type to internal  https://review.opendev.org/c/openstack/neutron/+/87311816:06
opendevreviewRodolfo Alonso proposed openstack/networking-bagpipe master: [sqlalchemy-20] Remove subtransactions=True  https://review.opendev.org/c/openstack/networking-bagpipe/+/87946316:55
opendevreviewMerged openstack/ovn-octavia-provider stable/zed: Add new FTs for health monitoring basic operations  https://review.opendev.org/c/openstack/ovn-octavia-provider/+/87650017:04
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991317:44
opendevreviewSlawek Kaplonski proposed openstack/neutron-lib stable/2023.1: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88010218:08
opendevreviewSlawek Kaplonski proposed openstack/neutron-lib stable/zed: Return properly elevated context by get_admin_context() helper  https://review.opendev.org/c/openstack/neutron-lib/+/88010318:08
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991319:13
opendevreviewMiro Tomaska proposed openstack/neutron master: Fix intermittent failures in finding metada port in SB DB  https://review.opendev.org/c/openstack/neutron/+/87854919:15
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991320:24
opendevreviewBrian Haley proposed openstack/neutron master: OVN: Always try and create a metadata port on subnets  https://review.opendev.org/c/openstack/neutron/+/87991322:47

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!