Friday, 2019-06-28

*** lseki has quit IRC00:02
*** mriedem_afk is now known as mriedem00:03
*** cheng1 has quit IRC00:24
*** brault has quit IRC00:27
*** rbudden has quit IRC00:29
*** diablo_rojo has quit IRC00:44
*** lbragstad has quit IRC01:11
*** njohnston has quit IRC01:16
*** baojg has joined #openstack-meeting01:43
*** yaawang has quit IRC01:45
*** gouthamr has quit IRC01:49
*** dmellado has quit IRC01:51
*** gouthamr has joined #openstack-meeting01:52
*** dmellado has joined #openstack-meeting01:54
*** mriedem has quit IRC01:54
*** rajinir has quit IRC01:55
*** apetrich has quit IRC01:58
*** gouthamr has quit IRC02:02
*** dmellado has quit IRC02:02
*** dmellado has joined #openstack-meeting02:05
*** gouthamr has joined #openstack-meeting02:06
*** brinzhang has joined #openstack-meeting02:07
*** gouthamr has quit IRC02:07
*** dmellado has quit IRC02:14
*** gouthamr has joined #openstack-meeting02:14
*** gouthamr has quit IRC02:17
*** dmellado has joined #openstack-meeting02:17
*** gouthamr has joined #openstack-meeting02:19
*** ricolin has joined #openstack-meeting02:20
*** gouthamr has quit IRC02:29
*** gouthamr has joined #openstack-meeting02:35
*** dmellado has quit IRC02:35
*** dmellado has joined #openstack-meeting02:38
*** gouthamr has quit IRC02:42
*** dmellado has quit IRC02:42
*** dmellado has joined #openstack-meeting02:45
*** gouthamr has joined #openstack-meeting02:49
*** dmellado has quit IRC02:52
*** dmellado has joined #openstack-meeting02:54
*** gouthamr has quit IRC02:54
*** gouthamr has joined #openstack-meeting02:58
*** dmellado has quit IRC03:02
*** dmellado has joined #openstack-meeting03:04
*** whoami-rajat has joined #openstack-meeting03:05
*** gouthamr has quit IRC03:05
*** tonyb has quit IRC03:05
*** gouthamr has joined #openstack-meeting03:10
*** dmellado has quit IRC03:11
*** dmellado has joined #openstack-meeting03:13
*** gouthamr has quit IRC03:27
*** dmellado has quit IRC03:29
*** gouthamr has joined #openstack-meeting03:31
*** dmellado has joined #openstack-meeting03:32
*** gouthamr has quit IRC03:33
*** dmellado has quit IRC03:34
*** tonyb has joined #openstack-meeting03:36
*** gouthamr has joined #openstack-meeting03:37
*** dmellado has joined #openstack-meeting03:39
*** psachin has joined #openstack-meeting03:40
*** rbudden has joined #openstack-meeting03:46
*** gouthamr has quit IRC03:49
*** dmellado has quit IRC03:51
*** dmellado has joined #openstack-meeting03:55
*** gouthamr has joined #openstack-meeting03:58
*** akhil_jain has joined #openstack-meeting04:00
*** gouthamr has quit IRC04:00
*** ekcs has joined #openstack-meeting04:03
ekcs#startmeeting congressteammeeting04:04
openstackMeeting started Fri Jun 28 04:04:45 2019 UTC and is due to finish in 60 minutes.  The chair is ekcs. Information about MeetBot at http://wiki.debian.org/MeetBot.04:04
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.04:04
*** openstack changes topic to " (Meeting topic: congressteammeeting)"04:04
openstackThe meeting name has been set to 'congressteammeeting'04:04
ekcshello! topics go here as usual: https://etherpad.openstack.org/p/congress-meeting-topics04:06
*** gouthamr has joined #openstack-meeting04:06
*** imsurit has joined #openstack-meeting04:06
akhil_jainHi, ekcs04:08
ekcshello akhil_jain ! how’s it been?04:08
ekcsand hello imsurit ! if you’re here to join the meeting, welcome!04:08
akhil_jainEverything good, what about you?04:08
*** dmellado has quit IRC04:09
*** gouthamr has quit IRC04:10
*** imsurit_ofc has joined #openstack-meeting04:10
*** imsurit has quit IRC04:11
*** imsurit_ofc is now known as imsurit04:11
ekcsim alright too!04:11
ekcsa little bit of a stressful week but reasonably productive = )04:12
ekcsok I guess we’ll dive in then.04:12
ekcs#topic intelligent overprovisioning for high availability04:13
*** openstack changes topic to "intelligent overprovisioning for high availability (Meeting topic: congressteammeeting)"04:13
*** dmellado has joined #openstack-meeting04:13
ekcsI just want to give a quick update to this use case I’ve been working on.04:14
ekcsit’s mentioned in our talks in the denver summit, but I’m working on formalizing it for the self-healing SIG04:15
ekcsand also fleshing out all the reference deployment setup.04:15
*** dmellado has quit IRC04:15
*** gouthamr has joined #openstack-meeting04:16
ekcsthe concept is to use predictive analytics (maybe monasca-analytics) to warn of possible failures. and based on those failure severetiy, likelihood, and the load on the affected services, decide how much to overprovision to guard against service disruption/degradation if the failure occurs.04:17
*** gouthamr has quit IRC04:17
ekcsso something like monasca analytics would provide the predictive data, and something like congress would combine with other data to make provisioning decisions.04:18
ekcsone difficulty right now is to find someone who is familiar with the predictive piece to drive that. but currently i’m working on the congress side.04:19
akhil_jainit sounds interesting04:20
ekcsthe numerical aggregations and calculations in the postgres engine for congress has been very helpful. will update as I progress.04:20
*** dmellado has joined #openstack-meeting04:20
akhil_jainare you docuenting it in self healing sig ?04:20
ekcsyea I think it makes sense to document for self healing SIG and also auto-scaling SIG.04:21
akhil_jainis patch up?04:22
ekcsbut also if I can find a monasca-analytics person or someone who is familiar with predictive analytics it may make sense to submit a talk for shanghai.04:22
ekcsno not yet. will add you to review when I submit a patch though.04:22
akhil_jainok thanks04:22
*** gouthamr has joined #openstack-meeting04:22
ekcsis that something you’d be interested in collaborating on for a presentation?04:23
*** rbudden has quit IRC04:23
akhil_jaindonot know of any such person, but i can be one by studying,04:23
akhil_jainalways ready:D04:23
ekcshaha ok well we can talk more about level of interest and work.04:24
akhil_jainor maybe asking witek can help here04:24
ekcsanyway that’s all the uupdate from me on that topic.04:25
*** _alastor_ has quit IRC04:25
*** gouthamr has quit IRC04:25
akhil_jainok great, thanks for updating04:25
ekcsok moving on then.04:26
ekcs#topic summit presentations04:26
*** openstack changes topic to "summit presentations (Meeting topic: congressteammeeting)"04:26
*** brault has joined #openstack-meeting04:26
ekcson the same line of thought, just want to see if there are any ideas or discussions around talks or forums for the summit04:27
ekcsor it’s something we can discuss more over email if they come up.04:29
akhil_jainI am not sure about the way we can add idea of prometheus-openstack monitoring, I have written down rough abstract, will share it with you over mail by tomorrow04:30
*** gouthamr has joined #openstack-meeting04:30
ekcsok great!04:30
ekcsok moving on then.04:31
ekcs#topic open discussion04:31
*** openstack changes topic to "open discussion (Meeting topic: congressteammeeting)"04:31
ekcsnot sure if we have anything else to talk about right now.04:31
akhil_jainyea, nothing from my side04:32
ekcsok nothing for me either. I guess we can end then!04:32
akhil_jainok, later then04:33
ekcshappy friday and have a great weekend!04:33
akhil_jainThanks and same to you, Bye!04:34
ekcsbye04:34
ekcs#endmeeting04:34
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"04:34
openstackMeeting ended Fri Jun 28 04:34:30 2019 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)04:34
openstackMinutes:        http://eavesdrop.openstack.org/meetings/congressteammeeting/2019/congressteammeeting.2019-06-28-04.04.html04:34
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/congressteammeeting/2019/congressteammeeting.2019-06-28-04.04.txt04:34
openstackLog:            http://eavesdrop.openstack.org/meetings/congressteammeeting/2019/congressteammeeting.2019-06-28-04.04.log.html04:34
*** gouthamr has quit IRC04:35
*** pcaruana has joined #openstack-meeting04:36
*** dmellado has quit IRC04:37
*** dmellado has joined #openstack-meeting04:41
*** gouthamr has joined #openstack-meeting04:41
*** gouthamr has quit IRC04:50
*** ekcs has quit IRC04:50
*** dmellado has quit IRC04:56
*** gouthamr has joined #openstack-meeting04:57
*** dmellado has joined #openstack-meeting05:00
*** gouthamr has quit IRC05:06
*** dmellado has quit IRC05:11
*** gouthamr has joined #openstack-meeting05:12
*** dmellado has joined #openstack-meeting05:13
*** gouthamr has quit IRC05:19
*** gouthamr has joined #openstack-meeting05:24
*** Luzi has joined #openstack-meeting05:26
*** gouthamr has quit IRC05:31
*** dmellado has quit IRC05:35
*** gouthamr has joined #openstack-meeting05:37
*** dmellado has joined #openstack-meeting05:38
*** bbowen__ has quit IRC05:42
*** gouthamr has quit IRC05:44
*** jbadiapa has quit IRC05:46
*** dmellado has quit IRC05:48
*** dmellado has joined #openstack-meeting05:51
*** imsurit_ofc has joined #openstack-meeting05:51
*** gouthamr has joined #openstack-meeting05:51
*** imsurit has quit IRC05:52
*** imsurit_ofc is now known as imsurit05:52
*** gouthamr has quit IRC05:52
*** dmellado has quit IRC05:58
*** gouthamr has joined #openstack-meeting05:58
*** slaweq has joined #openstack-meeting06:00
*** imsurit_ofc has joined #openstack-meeting06:00
*** dmellado has joined #openstack-meeting06:01
*** imsurit has quit IRC06:02
*** imsurit_ofc is now known as imsurit06:02
*** gouthamr has quit IRC06:03
*** yamamoto has joined #openstack-meeting06:06
*** yamamoto_ has joined #openstack-meeting06:06
*** dmellado has quit IRC06:08
*** gouthamr has joined #openstack-meeting06:08
*** lpetrut has joined #openstack-meeting06:09
*** lpetrut has quit IRC06:09
*** lpetrut has joined #openstack-meeting06:10
*** yamamoto has quit IRC06:10
*** dmellado has joined #openstack-meeting06:11
*** gouthamr has quit IRC06:11
*** gouthamr has joined #openstack-meeting06:16
*** gouthamr has quit IRC06:16
*** gouthamr has joined #openstack-meeting06:22
hyunsikyangeterpad06:23
*** kopecmartin|off is now known as kopecmartin06:24
*** dmellado has quit IRC06:27
*** gouthamr has quit IRC06:29
*** dmellado has joined #openstack-meeting06:30
*** gouthamr has joined #openstack-meeting06:36
*** bcafarel has quit IRC06:41
*** dmellado has quit IRC06:44
*** rsimai has joined #openstack-meeting06:46
*** gouthamr has quit IRC06:46
*** dmellado has joined #openstack-meeting06:47
*** artom has joined #openstack-meeting06:54
*** artom is now known as artom|gmtplus306:54
*** dmellado has quit IRC06:57
*** gouthamr has joined #openstack-meeting06:58
*** dmellado has joined #openstack-meeting07:00
*** jbadiapa has joined #openstack-meeting07:04
*** gouthamr has quit IRC07:04
*** dmellado has quit IRC07:05
*** dmellado has joined #openstack-meeting07:06
*** gouthamr has joined #openstack-meeting07:12
*** dmellado has quit IRC07:13
*** gouthamr has quit IRC07:15
*** ykatabam has quit IRC07:16
*** dmellado has joined #openstack-meeting07:16
*** rcernin has quit IRC07:16
*** tesseract has joined #openstack-meeting07:17
*** dmellado has quit IRC07:21
*** dmellado has joined #openstack-meeting07:21
*** dmellado has quit IRC07:21
*** gouthamr has joined #openstack-meeting07:23
*** dmellado has joined #openstack-meeting07:24
*** ttsiouts has joined #openstack-meeting07:26
*** dmellado has quit IRC07:30
*** tesseract has quit IRC07:30
*** gouthamr has quit IRC07:30
*** tesseract has joined #openstack-meeting07:32
*** itssurya has joined #openstack-meeting07:34
*** dmellado has joined #openstack-meeting07:34
*** gouthamr has joined #openstack-meeting07:39
*** dmellado has quit IRC07:39
*** dmellado has joined #openstack-meeting07:44
*** apetrich has joined #openstack-meeting07:45
*** brault has quit IRC07:49
*** gouthamr has quit IRC07:51
*** dmellado has quit IRC07:51
*** dmellado has joined #openstack-meeting07:54
*** dmellado has quit IRC07:54
*** dmellado has joined #openstack-meeting07:55
*** lpetrut has quit IRC07:56
*** gouthamr has joined #openstack-meeting07:57
*** gouthamr has quit IRC07:59
*** brault has joined #openstack-meeting07:59
*** ralonsoh has joined #openstack-meeting08:01
*** dmellado has quit IRC08:03
*** brault has quit IRC08:04
*** gouthamr has joined #openstack-meeting08:04
*** psachin has quit IRC08:08
*** dmellado has joined #openstack-meeting08:08
*** gouthamr has quit IRC08:09
*** Lucas_Gray has joined #openstack-meeting08:11
*** gouthamr has joined #openstack-meeting08:14
*** gouthamr has quit IRC08:17
*** bcafarel has joined #openstack-meeting08:18
*** dmellado has quit IRC08:19
*** dmellado has joined #openstack-meeting08:22
*** imsurit_ofc has joined #openstack-meeting08:22
*** imsurit has quit IRC08:23
*** imsurit_ofc is now known as imsurit08:23
*** dmellado has quit IRC08:23
*** gouthamr has joined #openstack-meeting08:23
*** dmellado has joined #openstack-meeting08:24
*** psachin has joined #openstack-meeting08:24
*** gouthamr has quit IRC08:30
*** dmellado has quit IRC08:33
*** whoami-rajat has quit IRC08:34
*** dmellado has joined #openstack-meeting08:34
*** dmellado has quit IRC08:37
*** dmellado has joined #openstack-meeting08:39
*** gouthamr has joined #openstack-meeting08:40
*** dmellado has quit IRC08:46
*** gouthamr has quit IRC08:47
*** dmellado has joined #openstack-meeting08:50
*** dmellado has quit IRC08:50
*** dmellado has joined #openstack-meeting08:51
*** gouthamr has joined #openstack-meeting08:53
*** dmellado has quit IRC08:54
*** gouthamr has quit IRC08:56
*** dmellado has joined #openstack-meeting08:57
*** gouthamr has joined #openstack-meeting09:02
*** dmellado has quit IRC09:02
*** gouthamr has quit IRC09:05
*** imsurit has quit IRC09:05
*** dmellado has joined #openstack-meeting09:05
*** jbadiapa has quit IRC09:09
*** jbadiapa has joined #openstack-meeting09:10
*** dmellado has quit IRC09:12
*** dmellado has joined #openstack-meeting09:14
*** gouthamr has joined #openstack-meeting09:14
*** psachin has quit IRC09:16
*** gouthamr has quit IRC09:19
*** ricolin has quit IRC09:21
*** gouthamr has joined #openstack-meeting09:23
*** gouthamr has quit IRC09:25
*** trident has quit IRC09:27
*** trident has joined #openstack-meeting09:29
*** dmellado has quit IRC09:29
*** gouthamr has joined #openstack-meeting09:32
*** dmellado has joined #openstack-meeting09:32
*** dmellado has quit IRC09:32
*** dmellado has joined #openstack-meeting09:35
*** gouthamr has quit IRC09:37
*** gouthamr has joined #openstack-meeting09:42
*** gouthamr has quit IRC09:43
*** dmellado has quit IRC09:44
*** dmellado has joined #openstack-meeting09:47
*** dmellado has quit IRC09:54
*** itssurya has quit IRC09:54
*** gouthamr has joined #openstack-meeting09:54
*** dmellado has joined #openstack-meeting09:56
*** gouthamr has quit IRC10:00
*** dmellado has quit IRC10:02
*** bbowen has joined #openstack-meeting10:04
*** dmellado has joined #openstack-meeting10:06
*** gouthamr has joined #openstack-meeting10:06
*** ociuhandu has joined #openstack-meeting10:07
*** dmellado has quit IRC10:11
*** carloss has joined #openstack-meeting10:14
*** ociuhandu has quit IRC10:14
*** dmellado has joined #openstack-meeting10:15
*** ociuhandu has joined #openstack-meeting10:17
*** gouthamr has quit IRC10:18
*** dmellado has quit IRC10:22
*** dmellado has joined #openstack-meeting10:24
*** gouthamr has joined #openstack-meeting10:26
*** gouthamr has quit IRC10:35
*** brinzhang has quit IRC10:38
*** shilpasd has joined #openstack-meeting10:39
*** gouthamr has joined #openstack-meeting10:41
*** gouthamr has quit IRC10:43
*** dmellado has quit IRC10:44
*** dmellado has joined #openstack-meeting10:49
*** whoami-rajat has joined #openstack-meeting10:51
*** gouthamr has joined #openstack-meeting10:52
*** aloga has quit IRC10:53
*** ttsiouts has quit IRC10:56
*** ttsiouts has joined #openstack-meeting10:57
*** gouthamr has quit IRC10:57
*** yamamoto_ has quit IRC11:02
*** dmellado has quit IRC11:04
*** dmellado has joined #openstack-meeting11:05
*** gouthamr has joined #openstack-meeting11:06
*** njohnston has joined #openstack-meeting11:06
*** yamamoto has joined #openstack-meeting11:13
*** rbudden has joined #openstack-meeting11:15
*** Lucas_Gray has quit IRC11:38
*** Lucas_Gray has joined #openstack-meeting11:41
*** dviroel has quit IRC11:48
*** hyunsikyang__ has joined #openstack-meeting12:01
*** EmilienM is now known as EvilienM12:02
*** hyunsikyang has quit IRC12:04
*** electrofelix has joined #openstack-meeting12:29
*** lbragstad has joined #openstack-meeting12:31
*** jbadiapa has quit IRC12:37
*** pcaruana has quit IRC12:40
*** pcaruana has joined #openstack-meeting12:41
*** rbudden has quit IRC12:44
*** raildo has joined #openstack-meeting12:44
*** lseki has joined #openstack-meeting12:48
*** baojg has quit IRC12:51
*** eharney has joined #openstack-meeting12:53
*** rbudden has joined #openstack-meeting12:58
*** lbragstad has quit IRC13:08
*** lbragstad has joined #openstack-meeting13:08
*** lpetrut has joined #openstack-meeting13:23
*** mriedem has joined #openstack-meeting13:24
*** enriquetaso has joined #openstack-meeting13:30
*** enriquetaso has quit IRC13:31
*** enriquetaso has joined #openstack-meeting13:31
*** yamamoto has quit IRC13:31
*** baojg has joined #openstack-meeting13:36
*** jbadiapa has joined #openstack-meeting13:42
*** mlavalle has joined #openstack-meeting13:55
*** boden has joined #openstack-meeting13:56
*** trident has quit IRC13:56
*** shilpasd has quit IRC13:57
*** woojay has left #openstack-meeting13:58
*** trident has joined #openstack-meeting13:58
mlavalle#startmeeting neutron_drivers14:00
openstackMeeting started Fri Jun 28 14:00:04 2019 UTC and is due to finish in 60 minutes.  The chair is mlavalle. Information about MeetBot at http://wiki.debian.org/MeetBot.14:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
*** openstack changes topic to " (Meeting topic: neutron_drivers)"14:00
openstackThe meeting name has been set to 'neutron_drivers'14:00
slaweqhi14:00
mlavalleboden: to optimize your time, we are talkijg about https://bugs.launchpad.net/neutron/+bug/183275814:00
openstackLaunchpad bug 1832758 in neutron "[RFE] Allow/deny custom ethertypes in security groups" [Wishlist,New]14:00
*** dviroel has joined #openstack-meeting14:01
ralonsohhi14:01
mlavallethe question that we have is whether NSX allows other ethertypes in security groups?14:01
njohnstono/14:01
mlavallei.e. can you say in a security group rule that non ip traffic is enabled? or is non ip trafiic enabled by deafult in NSX?14:02
*** Luzi has quit IRC14:02
bodenmlavalle I would have to dig.. I didn't write much of that code, I mainly just maintain the gate and some bugs14:03
njohnstonboden: Common examples would be InfiniBand or FCoE14:03
bodenmlavalle can we propose the question in the bug and I will ask the dev team to look14:03
mlavalleboden: yeah, don't dig too much. Just ask your devs to look at the RFE and give their opinion14:04
haleybhi14:04
bodenmlavalle will do... I could guess here, but better to let them peek since they know the deep details of the integration14:04
*** yamamoto has joined #openstack-meeting14:05
mlavalleboden: that's all I wanted to ask, in case you need to take care of your parental duties. you afe also welcome to stay :-)14:05
mlavalle#topic RFEs14:06
*** openstack changes topic to "RFEs (Meeting topic: neutron_drivers)"14:06
mlavalleok, we have quorum14:06
mlavalleLet's go back to https://bugs.launchpad.net/neutron/+bug/183275814:07
openstackLaunchpad bug 1832758 in neutron "[RFE] Allow/deny custom ethertypes in security groups" [Wishlist,New]14:07
*** davidsha has joined #openstack-meeting14:07
njohnstonThank you all for getting started talking about this last week while I was on PTO14:07
njohnstonglad to get the ball rolling14:08
mlavalleLet me try to summarize last week's discussion:14:08
mlavalle1) The team seemed to agree that we have to allow other ethertypes beyond IP14:09
mlavalle2) We got bogged down on the transition from the current situation to the new one14:09
*** liuyulong has joined #openstack-meeting14:10
mlavallewhether just to allow those ethertypes by default or requiring explicit rules to enable them14:10
mlavalleis that a good summary?14:10
slaweqIMO yes14:11
*** lpetrut has quit IRC14:11
slaweqand we should think about some solution which will be backportable to stable releases IMHO14:11
njohnstonmlavalle: Sounds right based on my reading of the transcript14:11
haleyb+114:11
*** jbadiapa has quit IRC14:12
njohnstonRegarding allowing the ethertypes by default, I think this should be treated like IP traffic: default deny, allow only with exception.14:12
*** jbadiapa has joined #openstack-meeting14:12
*** yamamoto has quit IRC14:12
*** boden has left #openstack-meeting14:13
mlavallenjohnston: that was also my position14:13
mlavallebut the rest of the team seemed to be inclined towards allowing them by default14:13
mlavalleat least that was my take away after reading the log last night14:14
njohnstonIf a bank or governmental institution, for example, wants to lock down their network completely then saying "You're locked down unless a hacker uses a custom ethertype, then he can exfiltrate data freely" is not a good answer14:14
slaweq+114:14
mlavalleagree14:15
mlavalleI think that is the crux of the discussion14:16
mlavallethe user should be locked down / secure by default14:16
mlavallethe flip side of the coin is that deployments using custom ethertypes under hybrid fw will have to enable them explicitely when migration to ovs fw14:19
mlavalleright?14:19
amotokisorry for late. I second "deny" by default. we see different behaviors in iptables-hybrid and ovs-fw at least. it sounds better to have an explicit rule when close the gap. I think it allows users to be aware of what happens.14:19
njohnstonmlavalle: yes, which would be an improvement on the current situation where they are broken without recourse for a fix14:19
amotokimlavalle: agree14:19
*** vishalmanchanda has joined #openstack-meeting14:20
mlavalleok, so are we ready to approve implementing:14:20
mlavalle1) custom ethertypes in security groups14:20
mlavalle2) with deny as the default bahavior?14:21
njohnstonmlavalle: Yes.  Additionally I think some documentation to help operators sample traffic looking for custom ethertypes so they can see what is actually in use befor ethey migrate would be a good way to help the pain of a transition from iptables to ovsfw14:22
mlavalledocumentation at a minimum.... ideally some tool14:22
slaweqone question: what about iptables driver? Will we also implement blocking such custom ethertypes in it?14:23
haleybmy internet connection is going down, so i'll put in a preemptive +1 on Nate's back-portable solution14:24
njohnstonwould it make sense to consider that as a separate RFE once this one is implemented, and pull the security team into the discussion at that time14:24
njohnston?14:24
amotokione idea on iptables driver is to define explicit rules to allow such traffic and block to drip them.14:24
haleybamotoki: it would be an ebtables-type driver, so would be more work in the hybrid case14:25
amotokithis RFE is about ovs-fw behaviro. we can tackle how to close the gap between ovs-fw and iptable drivers in another RFE.14:25
slaweqI agree that it may be separate RFE, but I would just want to not forget about it :)14:26
njohnstonamotoki: +114:26
amotokihaleyb: yes, I learned that last week. it would need more work and it might be moree complicated.14:26
mlavallehere's what I propose. approve the RFE....14:27
slaweqbecause if we will have something like: ovs-fw blocks such traffic by default, iptables always allows this traffic (which is also now) - this sounds a bit like CVE for me even14:27
mlavalleand start a disucssion right away with the security team14:27
njohnstonmlavalle: +114:27
mlavalleslaweq: it is CVE14:27
amotokiat least OSSN (openstack security notice) is worth mentioned.14:28
mlavalleand that is why we have to start discussing with the security team14:28
slaweqok14:28
mlavallebecause our deployer have a hole there and I bet most of them don't even realize it14:28
mlavalledeployers^^^^14:28
njohnstonI'd like to talk a little about how we address this in master vs. stable14:29
njohnstonI'd like to propose - and get the drivers blessing - that we create an RFE and figure out the API changes, DB changes, etc. to create this as a proper API extension for the security groups API for master.  But that seems too much to backport to old releases, per our backports policy.14:30
*** mattw4 has joined #openstack-meeting14:30
njohnstonSo I would like to address this with a minimalistic change that just uses an ovs agent config option to define the permitted ethertypes, as a way to address the situation in stable with a light touch.  I started on such an approach here: https://review.opendev.org/#/c/667207/14:31
mlavalleahh, I saw that patch. Now I understand14:32
njohnston(this is what haleyb was referring to earlier)14:32
*** _alastor_ has joined #openstack-meeting14:32
mlavalleit never comes into master14:33
mlavallestarts in stable/steain14:34
mlavalleit makes sense to me14:34
njohnstonmlavalle: precisely14:34
njohnstonSince this is CVE territory I think something we can have out there for existing customers soon is a good thing, plus it addresses the "sideways regression" for customers going from iptables_hybrid to ovsfw and having their Infiniband application break.14:34
slaweqnjohnston: but as this is only for Stein and older, are You sure that proper fix with API changes will be ready for Train for sure?14:35
ralonsohagree with slaweq, this patch can be merged in master and then, if the feature is implemented, removed14:36
slaweqmaybe that would be "safer" solution14:36
*** lbragstad has quit IRC14:36
njohnstonOK, I'd be very open to that14:36
*** artom|gmtplus3 has quit IRC14:37
mlavallesounds sensible to me14:37
mlavalleamotoki, haleyb: what do you think?14:38
* njohnston wonders if we lost haleyb14:39
mlavalleprobably14:40
-amotoki- was disconnected for a while during train under ground14:40
amotokiI followed the discussion and it makes sense to me.14:40
mlavallecool14:41
mlavallewe have an agreement14:41
mlavalleI will document this discussion in the RFE and mark it approved14:41
mlavallethat was the only RFE we had for today14:42
njohnstonAll right.  I will take my code on stable/stein and propose it for master, adding TODO statements to remove when we have a full implementation... and then I'll get a spec going for the full change14:42
mlavallebut before leaving, I have two questions for the team14:42
mlavalle1) Last night I was looking at the RFE, just freshly submitted: https://bugs.launchpad.net/neutron/+bug/183417414:43
openstackLaunchpad bug 1834174 in neutron "[RFE] Add support for IPoIB interface driver" [Wishlist,New] - Assigned to Adrian Chiris (adrian.chiris)14:43
mlavallebut given the previous ethertypes disucssion, do we need infiniband drivers?14:43
mlavalledeployers are connecting infiniband fabrics in their OpenStack systems, right?14:44
*** rsimai has quit IRC14:44
mlavalleat least the RH folks know of one, as far as I can glean out14:44
njohnstonIn the case I know about, the application is using the infiniband protocol natively (I believe, would want to confirm it)14:45
slaweqI don't know IB but for me it looks like proposal for new dhcp/L3 driver that dhcp/router namespace can be connected that way14:45
mlavalleok, please leave some comments there if you have time14:46
*** lpetrut has joined #openstack-meeting14:46
njohnstonbut infiniband can also be implemented in hardware so perhaps this is to create ports on an interface that is an infiniband network interface rather than an ethernet one14:46
* njohnston will comment14:46
mlavalle2) Thursday of Next week is July 4th, Independence Day in the USA. I am taking Friday 5th off and I suspect haleyb and njohnston might do the same14:47
ralonsohI'll do the same!!14:47
* slaweq is sad that he will have to be at work :(14:48
*** panda has quit IRC14:48
*** panda has joined #openstack-meeting14:48
mlavalleso it might be slaweq, amotoki and yamamoto only attending the meeting14:48
* njohnston offers July 4th as a holiday for anyone who is sorting out their issues with Britain14:49
mlavalledo you want to have it anyway or do you want to cancel?14:49
amotokicanceling the meeting sounds good to. we can spend reviewing others :)14:49
amotoki*good to me*14:49
slaweqyes, I think that we can cancel it14:49
mlavallecool14:49
mlavalleI'll send a notice  to the ML14:50
mlavalleThat's all for today team14:50
njohnstonthank you all very much14:50
mlavalleGreat discussion, btw14:50
slaweqthank You all14:50
ralonsohbye!14:50
slaweqhave a great weekend :)14:50
slaweqo/14:50
mlavallehave a great weekend!14:50
mlavalle#endmeeting14:51
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"14:51
openstackMeeting ended Fri Jun 28 14:51:01 2019 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:51
openstackMinutes:        http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-06-28-14.00.html14:51
amotokithe meeting will end before I get off the train :) yay14:51
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-06-28-14.00.txt14:51
openstackLog:            http://eavesdrop.openstack.org/meetings/neutron_drivers/2019/neutron_drivers.2019-06-28-14.00.log.html14:51
mlavalleamotoki: that's good!14:51
*** mlavalle has left #openstack-meeting14:52
*** ttsiouts has quit IRC14:53
*** ttsiouts has joined #openstack-meeting14:54
*** ttsiouts has quit IRC14:54
*** ayoung has quit IRC14:59
*** mattw4 has quit IRC15:04
*** lpetrut has quit IRC15:05
*** yamamoto has joined #openstack-meeting15:08
*** bobh has joined #openstack-meeting15:09
*** whoami-rajat has quit IRC15:11
*** rajinir has joined #openstack-meeting15:12
*** igordc has joined #openstack-meeting15:17
*** whoami-rajat has joined #openstack-meeting15:19
*** baojg has quit IRC15:19
*** baojg has joined #openstack-meeting15:19
*** raildo has quit IRC15:28
*** baojg has quit IRC15:29
*** enriquetaso has quit IRC15:30
*** _alastor_ has quit IRC15:33
*** enriquetaso has joined #openstack-meeting15:44
*** enriquetaso has quit IRC15:44
*** enriquetaso has joined #openstack-meeting15:44
*** raildo has joined #openstack-meeting15:50
*** davidsha has quit IRC16:07
*** mattw4 has joined #openstack-meeting16:08
*** mattw4 has quit IRC16:12
*** mattw4 has joined #openstack-meeting16:15
*** ociuhandu has quit IRC16:16
*** yamamoto has quit IRC16:16
*** yamamoto has joined #openstack-meeting16:17
*** mriedem is now known as mriedem_away16:18
*** Lucas_Gray has quit IRC16:19
*** wwriverrat has joined #openstack-meeting16:21
*** diablo_rojo has joined #openstack-meeting16:36
*** cmurphy is now known as cmorpheus16:41
*** kmalloc is now known as needscoffee16:47
*** enriquetaso has quit IRC16:59
*** ralonsoh has quit IRC17:18
*** ricolin has joined #openstack-meeting17:19
*** raildo has quit IRC17:24
*** ekcs has joined #openstack-meeting17:25
*** e0ne has joined #openstack-meeting17:26
*** mriedem_away is now known as mriedem17:27
*** bbowen has quit IRC17:27
*** electrofelix has quit IRC17:30
*** raildo has joined #openstack-meeting17:35
*** ricolin has quit IRC17:45
*** enriquetaso has joined #openstack-meeting17:48
*** whoami-rajat has quit IRC17:51
*** akhil_jain has quit IRC18:10
*** e0ne has quit IRC18:12
*** e0ne has joined #openstack-meeting18:13
*** tesseract has quit IRC18:13
*** raildo has quit IRC18:16
*** e0ne has quit IRC18:16
*** raildo has joined #openstack-meeting18:18
*** e0ne has joined #openstack-meeting18:26
*** e0ne has quit IRC18:28
*** vishalmanchanda has quit IRC18:30
*** raildo has quit IRC18:46
*** carloss has quit IRC19:03
*** enriquetaso has quit IRC19:03
*** EvilienM is now known as EmilienM19:05
*** bbowen has joined #openstack-meeting19:14
*** whoami-rajat has joined #openstack-meeting19:14
*** yamamoto has quit IRC19:14
*** diablo_rojo has quit IRC19:23
*** dklyle has quit IRC19:36
*** yamamoto has joined #openstack-meeting19:50
*** mattw4 has quit IRC19:51
*** diablo_rojo has joined #openstack-meeting19:52
*** yamamoto has quit IRC20:01
*** mattw4 has joined #openstack-meeting20:02
*** raildo has joined #openstack-meeting20:09
*** enriquetaso has joined #openstack-meeting20:10
*** diablo_rojo has quit IRC20:16
*** dklyle has joined #openstack-meeting20:18
*** slaweq has quit IRC20:23
*** diablo_rojo has joined #openstack-meeting20:32
*** raildo_ has joined #openstack-meeting20:40
*** raildo has quit IRC20:43
*** ekcs has quit IRC20:59
*** ekcs has joined #openstack-meeting21:01
*** diablo_rojo has quit IRC21:10
*** slaweq has joined #openstack-meeting21:11
*** kopecmartin has quit IRC21:13
*** slaweq has quit IRC21:15
*** pcaruana has quit IRC21:16
*** rfolco is now known as rfolco|off21:16
*** bobh has quit IRC22:01
*** diablo_rojo has joined #openstack-meeting22:09
*** dviroel has quit IRC22:10
*** slaweq has joined #openstack-meeting22:11
*** slaweq has quit IRC22:16
*** raildo_ has quit IRC22:20
*** ekcs has quit IRC22:29
*** ekcs has joined #openstack-meeting22:35
*** rajinir has quit IRC22:42
*** diablo_rojo has quit IRC22:53
*** mattw4 has quit IRC23:11
*** whoami-rajat has quit IRC23:13
*** Lucas_Gray has joined #openstack-meeting23:14
*** enriquetaso has quit IRC23:15
*** yamamoto has joined #openstack-meeting23:36
*** Wryhder has joined #openstack-meeting23:39
*** Lucas_Gray has quit IRC23:40
*** Wryhder is now known as Lucas_Gray23:40
*** _alastor_ has joined #openstack-meeting23:58

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!