Thursday, 2017-10-26

*** bbbbzhao_ has joined #openstack-fwaas01:47
*** AlexeyAbashkin has joined #openstack-fwaas01:51
*** AlexeyAbashkin has quit IRC01:55
*** AlexeyAbashkin has joined #openstack-fwaas02:51
*** AlexeyAbashkin has quit IRC02:55
*** annp has joined #openstack-fwaas03:14
*** yamamoto has joined #openstack-fwaas03:22
*** AlexeyAbashkin has joined #openstack-fwaas03:51
*** AlexeyAbashkin has quit IRC03:55
*** bbbbzhao_ has quit IRC04:47
*** eN_Guruprasad_Rn has joined #openstack-fwaas05:10
*** vks1 has joined #openstack-fwaas05:17
*** yamamoto has quit IRC05:17
*** eN_Guruprasad_Rn has quit IRC05:35
*** eN_Guruprasad_Rn has joined #openstack-fwaas05:38
*** AlexeyAbashkin has joined #openstack-fwaas06:03
*** AlexeyAbashkin has quit IRC06:19
*** yamamoto has joined #openstack-fwaas06:49
*** yamamoto_ has joined #openstack-fwaas07:38
*** yamamoto has quit IRC07:42
*** AlexeyAbashkin has joined #openstack-fwaas08:03
*** yamamoto_ has quit IRC08:18
*** yamamoto has joined #openstack-fwaas08:28
*** yamamoto has quit IRC08:33
*** yamamoto has joined #openstack-fwaas09:01
*** AlexeyAbashkin has quit IRC09:02
*** AlexeyAbashkin has joined #openstack-fwaas09:06
*** AlexeyAbashkin has quit IRC09:37
*** yamamoto has quit IRC09:38
*** AlexeyAbashkin has joined #openstack-fwaas09:46
*** AlexeyAbashkin has quit IRC09:53
*** eN_Guruprasad_Rn has quit IRC10:16
*** eN_Guruprasad_Rn has joined #openstack-fwaas10:18
*** vks1 has quit IRC10:36
*** yamamoto has joined #openstack-fwaas10:39
*** yamamoto has quit IRC10:44
*** yamamoto has joined #openstack-fwaas10:47
*** vks1 has joined #openstack-fwaas11:06
*** AlexeyAbashkin has joined #openstack-fwaas11:07
*** eN_Guruprasad_Rn has quit IRC11:14
*** eN_Guruprasad_Rn has joined #openstack-fwaas11:14
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: FWaaS v2 extension for L2 agent  https://review.openstack.org/32397111:34
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: OVS based l2 Firewall driver for FWaaS v2  https://review.openstack.org/44725111:34
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: [WIP] PoC for fwg and sg work can as a "defense in depth" solution  https://review.openstack.org/51536811:34
*** annp has quit IRC11:46
*** vks1 has quit IRC11:51
*** hoangcx_ has joined #openstack-fwaas12:40
*** vks1 has joined #openstack-fwaas12:51
*** eN_Guruprasad_Rn has quit IRC12:56
*** yamamoto has quit IRC13:26
*** reedip_ has joined #openstack-fwaas13:31
reedip_o/13:35
*** reedip_ has quit IRC13:35
*** reedip_ has joined #openstack-fwaas13:42
*** annp has joined #openstack-fwaas13:53
*** SarathMekala has joined #openstack-fwaas13:57
*** yushiro has joined #openstack-fwaas13:59
openstackgerritNguyen Phuong An proposed openstack/neutron-fwaas master: [WIP] PoC for fwg and sg can work as a "defense in depth" solution  https://review.openstack.org/51536813:59
reedip_??14:00
*** SridarK has joined #openstack-fwaas14:00
annpreedip: hi14:00
reedip_meeting to start ?14:00
yushirohi14:01
SridarKHi FWaaS folks14:01
SarathMekalahi all O/14:01
reedip_whose turn is it ?14:01
annpreedip, hi14:01
SridarKi believe it is xgerman_14:01
yushiroreedip_, Today is xgerman_14:01
reedip_hi annp  :P14:01
reedip_wake up xgerman_ :)14:01
annphi all, :)14:01
SridarKit is early here still14:01
xgerman_O/14:02
SridarK#startmeeting fwaas14:02
openstackMeeting started Thu Oct 26 14:02:13 2017 UTC and is due to finish in 60 minutes.  The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot.14:02
reedip_did the Daylight saving start ?14:02
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:02
*** openstack changes topic to " (Meeting topic: fwaas)"14:02
openstackThe meeting name has been set to 'fwaas'14:02
SridarK#chair xgerman_ yushiro14:02
openstackCurrent chairs: SridarK xgerman_ yushiro14:02
SridarKxgerman_: sorry pls go ahead14:02
SridarKreedip_: no that is Nov 5 i believe14:02
xgerman_One sec my computer is still booting14:03
reedip_i5 or i7 ?14:03
SridarKxgerman_: no worries14:04
xgerman_i5 — but here I am14:04
yushiroNP14:04
xgerman_#topic Announcements14:04
*** openstack changes topic to "Announcements (Meeting topic: fwaas)"14:04
reedip_:)14:04
xgerman_Neutron Q-1 was cut yesterday14:04
xgerman_Newton also went EOL yesterday14:04
xgerman_and we have a new TC14:04
reedip_damn .. it seems only like yesterday that we were working on newton14:05
reedip_:P14:05
doudehi14:05
reedip_hi doude14:05
xgerman_yeah, I don’t have a TC link handy so you’ll need to google that ;-)14:06
reedip_https://www.openstack.org/foundation/tech-committee/ ?14:06
xgerman_thanks reedip_14:07
xgerman_#topic Queens L2 support14:07
*** openstack changes topic to "Queens L2 support (Meeting topic: fwaas)"14:07
xgerman_So we didn’t get that into Q-1 but got close!!14:07
xgerman_yushiro what’s the latest?14:08
yushiroxgerman_, sure.14:08
yushiro#link https://etherpad.openstack.org/p/fwaas-v2-l2   Please refer 'Test cases for OVS firewall driver:' section14:09
SridarKyushiro: thx this i think makes it more clear to test14:09
SridarKand i think we can add more to it14:09
xgerman_+114:09
annpyushiro, thanks14:10
yushiroNow, I tested a few patterns.14:10
SridarKI had some PTO this week so not much progress from me on testing - but will defn do some now14:10
xgerman_I am swamped at work so not much FWaaS testing from me (though found some Octavia bugs I now need to fix)14:10
SridarKbut yushiro this is very clear14:10
yushiroI'm checking diff before/after ovs-ofctl dump-flows br-int for OVS firewall driver.14:11
yushiroe.g. If we add 'allow' icmp rule, it is added http://paste.openstack.org/compare/624411/624408/14:13
xgerman_ok, and we are aiming for FWaaS standalone (switch off SG for test)?14:14
xgerman_just double checking14:14
yushiroxgerman_, yes, sure.  Now I'm testing sg + fwg  with 'openvswitch' driver.14:14
reedip_annp just pushed a patch for SG and FWG14:14
annpyes, https://review.openstack.org/#/c/515368/214:15
xgerman_awesome - I think this needs to be our default14:15
yushiroannp, If we add 'deny' icmp rule, what rule will be added in ovs flow?  I tested before, but no specific rule is added.14:15
annpyushiro, if you add deny icmp, no flows related icmp is added.14:16
annpyushiro, icmp packets will be dropped.14:17
yushiroannp, aha, OK.  thx.14:17
annpregarding to fwg and sg can work as a defense in depth solution14:17
yushiroannp, (start) ---> fwg ---> sg ---> (end)  Is that right?14:18
annpmy patch is under develop, however it can work with security group based ovs, for iptables_hybrid needs more works.14:18
xgerman_yeah, I think most installs have SG and until we offer some sort of migration co-existance is the way to go14:19
annpyushiro, it's right in https://review.openstack.org/#/c/515368/214:19
xgerman_well, let’s get OVS into Q-2 and then we cna worry about hybrid later ;-)14:19
yushiroxgerman_, +1  We should target 'openvswitch' firewall driver first.14:20
annpxgerman_, tomorrow, i will remove hybrid and make it available for testing and reviewing. thanks.14:20
SridarKyes i think that is best14:21
xgerman_+114:21
xgerman_#topic Queens Dashboard14:21
*** openstack changes topic to "Queens Dashboard (Meeting topic: fwaas)"14:21
annpyushiro, regarding to l2 agent patch14:21
yushiroyes14:21
annpyushiro, we're missing allowed_address_pair and 'port_security_enabled' in port_details14:22
annpyushiro, These attrs need for ovs driver14:22
SridarKAlso annp on the driver PS - are u good with things ?14:23
annpyushiro, can i update l2 agent patch?14:23
yushiroannp, OK, plz update.14:23
yushiroannp, I think that is good point.14:23
annpSridarK, yes! we need these attrs14:23
SridarKthx annp14:24
yushiroannp, I still don't get the point why these parameter is necessary for fwaas.  Please tell me after :)14:24
yushiros/is/are14:25
xgerman_well port_security makes sense14:25
annpok, let me paste link for you14:25
yushiroxgerman_, regarding dashboard14:25
xgerman_yep, did we cut the release14:25
xgerman_?14:25
reedip_guys ,I would be leaving now, will check the logs later .. sorry, urgent work14:25
*** reedip_ is now known as reedip_afk14:25
yushiroI'm so sorry  I couldn't have bandwidth to cut release yet.14:25
yushiroin last week.14:25
annphttps://review.openstack.org/#/c/447251/46/neutron_fwaas/services/firewall/drivers/linux/l2/openvswitch_firewall/firewall.py@12514:26
yushiroamotoki, hi,  are you there?14:26
*** yamamoto has joined #openstack-fwaas14:26
yushiroannp, ah, we should allow from/to mac_address which includes 'allowed_address_pairs'.  Thanks.14:27
xgerman_ok, let’s try this week — ping me if you run into trouble and I will lean on some people I know who cut releases frequently (armax ahem)14:27
annpSridarK, xgerman_, yuhsiro, I think allowed_address_pair is added on neutron. So I think we can keep this feature for neutron port14:27
xgerman_yes, we need to support it — most people use it14:28
SridarK+114:28
xgerman_but it’s an extension - so technically need to be able to run without14:28
xgerman_but not Q-214:28
annpxgerman_, you're right.14:28
yushiroxgerman_, I think so.14:28
yushiroxgerman_, sure.  I will.14:29
yushiroxgerman_, And, I'll migrate existing bugs for dashboard into launchpad.14:30
xgerman_ok, thanks14:30
yushirofrom https://etherpad.openstack.org/p/fwaas-v2-dashboard14:30
xgerman_sounds good14:30
annpthat's all from me. :)14:30
xgerman_thanks!14:30
yushiroSarathMekala, If you find another bug on dashboard,  feel fee to file a bug into fwaas dashboard launchpad :)14:31
yushiros/fee/free14:31
amotokiyushiro: hi14:31
xgerman_hi14:31
SarathMekalahi yushiro .. yes... I was planning to sync up with you on that14:31
amotokiah... fwaas meeting time :)14:31
*** yamamoto has quit IRC14:32
xgerman_yes, I was curious about our next development after the Q-1 release14:32
xgerman_or are we focusing on bug fixes?14:32
yushiroamotoki, hi.  Sorry for last week.  I couldn't reach out you to get your help for cutting release.14:32
amotokiyushiro: sorry too. it is not complicated.14:33
yushiroxgerman_, SarathMekala Currently, there is no critical bug on dashboard.14:33
SarathMekalaxgerman_, you are right we need to do both14:33
SarathMekalaI have some thoughts on improving the UI screens.. will do a write up and share to the team14:34
SarathMekalayushiro, good to know :)14:34
xgerman_amotoki should we do a spec for that14:34
xgerman_?14:34
amotokixgerman_: on dashboard imporvements?14:34
xgerman_yep14:34
*** mlavalle has joined #openstack-fwaas14:34
amotokii think it is better to use a blueprint in neutron-fwaas-dashboard launchpad14:35
amotokiif you prefer to RFE bugs, it also works :)14:35
xgerman_ok, SarathMekala if you could do your writeup in a blueprint —much appreciated14:35
SarathMekalaxgerman_, sure.. will do that14:36
amotokithere is no need to discuss with the driver team. it's an UI project14:36
xgerman_thanks14:36
yushiroChanging UI needs spec, OK I understood.14:36
SridarKSarathMekala: but for some prelim discussion with screenshots and to get some discussions going - google doc could be a first step leading to a bp14:36
SarathMekalaSridarK, got it..14:36
xgerman_+114:37
yushiroSridarK, +114:37
amotokithat would be a good idea14:37
SarathMekalawill start with a google doc and will create a blueprint after some priliminary discussions14:37
amotokiSarathMekala: you can create a blueprint and add a link to a google doc14:37
SarathMekalaamotoki, +114:38
yushiroSarathMekala, Could you discuss with me about 'bug' or 'improvement' in https://etherpad.openstack.org/p/fwaas-v2-dashboard14:38
yushirolater ?14:38
SarathMekalayushiro, sure14:39
yushiroSarathMekala, OK, thank you.14:39
SarathMekalawe need to clean up the etherpad as well14:39
amotokiIMHO it is better to file bugs rather than tracking remaining things in the etherpad14:40
xgerman_+114:40
xgerman_especially after release14:41
yushiroamotoki, all of etherpad?14:41
amotokiyushiro: yeah, all *remaining* topics14:41
xgerman_yes, so users don’t file known bugs14:41
yushiroamotoki, Aha OK, will do it.14:42
amotokiyushiro: it is not clear to me what are remaining (in "Blocking Issues" section)14:42
SarathMekalaright.. will sync up with yushiro on this14:42
amotoki"How to Install" should be converted into the in-tree doc14:42
amotokihttps://bugs.launchpad.net/neutron-fwaas-dashboard (with v2-dashboard tag)14:43
xgerman_action convert “How to Install"  into the in-tree doc14:43
xgerman_#action convert “How to Install"  into the in-tree doc14:43
yushiroamotoki, 'Blocking Issues' was mandatory issues to solve before merging v2 dashboard.  So, it's OK to ignore.14:44
amotokiyushiro: okay. I was just not sure the status of each item14:44
amotokifor the install documentation, perhaps https://docs.openstack.org/neutron-fwaas-dashboard/latest/install/index.html and https://docs.openstack.org/neutron-fwaas-dashboard/latest/contributor/devstack-plugin.html covers almost all. if any, let's add it.14:44
SarathMekalaamotoki, true..this doc needs to be cleaned up to track only pending issues...14:45
yushiro'Future improvements' are our next target.14:45
SridarKamotoki: yes Blocking Issues have all been addressed14:45
amotokiSridarK: yushiro: good news. thanks14:46
xgerman_ok, let’s move to14:46
SridarKamotoki: +1 on updating the docs14:46
xgerman_#topic Open Discussion14:46
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)"14:46
xgerman_I know we have some specs which need attention14:46
yushiroyes14:47
yushiro#link https://review.openstack.org/#/c/461657/  I'll reply to ZhaoBo14:49
xgerman_thanks —14:49
xgerman_SridarK any update on CCF?14:50
yushiro#link https://review.openstack.org/#/c/509725/  firewall logging  extension. (However, logging API in neutron is now trying to merge)14:50
yushirostay tuned!!14:50
SridarKxgerman_: no i will write that up too and then link it to a bp14:50
xgerman_ok, great14:51
yushirohoangcx, annp and I are discussing more detail design now.14:51
amotokithis RFE is marked as rfe-postponed. if we have a volunteer to move this forward, we can change the tag to rfe-approved14:51
amotokihttps://bugs.launchpad.net/neutron/+bug/1628627 is the RFE bug for https://review.openstack.org/#/c/461657/14:51
openstackLaunchpad bug 1628627 in neutron "In FWaaS, when someone makes a change to a firewall rule we know, Who, What, When, and Where" [Wishlist,In progress] - Assigned to zhaobo (zhaobo6)14:51
xgerman_yeah, let’s aim for L2 in Q-2 and then we tackle other stuff ;-)14:52
hoangcx_xgerman_: +114:52
doudedid you established the list of 'other stuff'?14:53
amotokiyushiro: for https://review.openstack.org/#/c/509725/, is there a RFE bug?14:53
mlavalleis that the one for audit?14:54
SridarKdoude: i think we can take on ur changes14:54
hoangcx_amotoki: https://bugs.launchpad.net/neutron/+bug/172072714:54
openstackLaunchpad bug 1720727 in neutron "[RFE] (Operator-only) Extend logging feature to support for FWaaS v2" [Wishlist,Confirmed]14:54
doudecool :)14:55
yushiroamotoki, yes14:55
xgerman_SridarK +114:55
doudedid you had time to look at it?14:55
amotokihoangcx_: ah.. I found it in the content, but no reference in the commit msg. just it14:55
SridarKdoude: are u going to be at the summit14:55
doudeyes I'll14:55
hoangcx_amotoki: It will change status of the bug and it will not go to the list of driver team attention14:55
doudeMon-Thu14:55
yushiroamotoki, We need to check 'rfe-approved',  is it necessary from driver-team ?14:56
SridarKdoude: no i have been swamped - perhaps we can sit together with yushiro and others who will be there14:56
mlavalleamotoki: RFE 1628627 is baing actively pursued by zhobo14:56
doudesure14:56
yushirodoude, I'll be there :)14:56
amotokimlavalle: yes, I noticed that a few minutes ago.14:56
doudeI'll prepare that. Is there an FWaaS etherpad to organize the summit?14:56
mlavallecool14:56
SridarK#link https://etherpad.openstack.org/p/fwaas-sydney-discussions14:58
SridarKdoude lets use this to coordinate14:58
xgerman_ok, one minute left14:58
mlavalleSridarK, doude: you both going to Sydney?14:58
amotokibefore closing the meeting, let me share https://review.openstack.org/#/c/501978/ (devstack patch)14:59
SridarKmlavalle: yes14:59
amotokiI think it is related to fwaas as well14:59
SridarKmlavalle: we can discuss the audit bp more in detail in person too14:59
SridarKmlavalle: i think this a useful feature for compliance etc to have14:59
xgerman_let’s try to do that in addition to commenting on the spec14:59
mlavalle++15:00
xgerman_#endmeeting15:00
yushiroamotoki, OK, will check.15:00
*** openstack changes topic to "#openstack-fwaas"15:00
openstackMeeting ended Thu Oct 26 15:00:19 2017 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:00
openstackMinutes:        http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-10-26-14.02.html15:00
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-10-26-14.02.txt15:00
openstackLog:            http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-10-26-14.02.log.html15:00
yushirohoangcx_, Aha, you pushed the patdh :)15:00
yushiropatch15:00
hoangcx_amotoki: Ah, I will update the patch (update comment as yours) tomorrow15:00
xgerman_thanks, everybody — gotta get kids to school now…15:00
hoangcx_yushiro: :p15:00
SridarKthanks all15:00
SarathMekalabye all O/.. time for dinner :)15:00
annpthanks all, see you15:01
mlavalleSridarK: I have the impression that after the round of comments from yushiro and xgerman_ taht spec is not far from being good to go15:01
amotokihoangcx_: thanks. do you already do the similar thing for l2-agent extension?15:01
SridarKmlavalle: yes i will check as well - we have wanted to have this for some time15:01
mlavalle++15:02
hoangcx_amotoki: l2-agent extension existed in neutron repos already15:02
amotokihoangcx_: yeah, i just looked the code15:02
doudeok SridarK I'll use that etherpad15:02
yushiroSridarK, mlavalle I'd like to.15:02
hoangcx_amotoki: https://github.com/openstack/neutron/blob/master/devstack/lib/l2_agent15:02
SridarKdoude: ok perfect15:02
doudemlavalle I'll be at the summit15:02
amotokihoangcx_: configure_l2_agent is called in devstack/plugin.sh, so we can do similar for configure_l3_agent15:03
*** vks1 has quit IRC15:03
hoangcx_amotoki: Yes. But it should be in advanced services like vpn, fw...15:04
yushirohoangcx_, I temporary implemented to set up l2 agent extension as follows: https://review.openstack.org/#/c/323971/72/devstack/plugin.sh15:05
amotokihoangcx_: advanced services can add their own extensions to the list by calling plugin_agent_add_l3_agent_extension15:05
amotokihoangcx_: configure_l3_agent writes it to the config file, so we need to call it somewhere once15:06
yushiroSorry folks,  time to bed....  O ya su mi ( = good night)15:06
*** SarathMekala has quit IRC15:06
amotokigood night15:07
*** yushiro has quit IRC15:07
mlavalleSridar, doude: please add your name here: https://etherpad.openstack.org/p/neutron-sydney-summit-attendees15:09
hoangcx_amotoki: Yes. I do it in vpn15:09
hoangcx_amotoki: good night :-)15:09
*** vks1 has joined #openstack-fwaas15:10
SridarKmlavalle: done thx15:11
*** annp has quit IRC15:13
*** hoangcx_ has quit IRC15:15
*** yamamoto has joined #openstack-fwaas15:28
*** AlexeyAbashkin has quit IRC15:29
*** yamamoto has quit IRC15:33
*** reedip_afk is now known as reedip_16:01
*** yamamoto has joined #openstack-fwaas16:30
*** yamamoto has quit IRC16:34
*** AlexeyAbashkin has joined #openstack-fwaas16:53
*** AlexeyAbashkin has quit IRC16:57
*** SridarK has quit IRC17:10
*** yamamoto has joined #openstack-fwaas17:31
*** yamamoto has quit IRC17:36
*** AlexeyAbashkin has joined #openstack-fwaas17:48
*** reedip_ has quit IRC17:50
*** AlexeyAbashkin has quit IRC17:52
*** SarathMekala has joined #openstack-fwaas18:03
*** SarathMekala has quit IRC18:07
*** SridarK has joined #openstack-fwaas18:18
*** AlexeyAbashkin has joined #openstack-fwaas18:30
*** vks1 has quit IRC18:32
*** yamamoto has joined #openstack-fwaas18:32
*** AlexeyAbashkin has quit IRC18:34
*** yamamoto has quit IRC18:38
*** AlexeyAbashkin has joined #openstack-fwaas18:47
*** AlexeyAbashkin has quit IRC18:52
*** yamamoto has joined #openstack-fwaas19:34
*** yamamoto has quit IRC19:39
*** AlexeyAbashkin has joined #openstack-fwaas20:31
*** AlexeyAbashkin has quit IRC20:35
*** yamamoto has joined #openstack-fwaas20:35
*** yamamoto has quit IRC20:40
*** AlexeyAbashkin has joined #openstack-fwaas20:47
*** AlexeyAbashkin has quit IRC20:52
*** yamamoto has joined #openstack-fwaas21:37
*** yamamoto has quit IRC21:42
*** yamamoto has joined #openstack-fwaas22:39
*** yamamoto has quit IRC22:44
*** AlexeyAbashkin has joined #openstack-fwaas22:46
*** AlexeyAbashkin has quit IRC22:50
*** AlexeyAbashkin has joined #openstack-fwaas23:07
*** AlexeyAbashkin has quit IRC23:11
*** AlexeyAbashkin has joined #openstack-fwaas23:27
*** AlexeyAbashkin has quit IRC23:32
*** SridarK has quit IRC23:33
*** mlavalle has quit IRC23:35
*** yamamoto has joined #openstack-fwaas23:40
*** yamamoto has quit IRC23:46

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!