14:00:32 #startmeeting fwaas 14:00:37 Meeting started Thu Nov 2 14:00:32 2017 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:38 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:00:40 The meeting name has been set to 'fwaas' 14:01:01 #chair xgerman_ yushiro 14:01:02 Current chairs: xgerman_ yushiro 14:01:34 #chair SridarK 14:01:35 Current chairs: SridarK xgerman_ yushiro 14:01:39 Hi FWaaS folks 14:01:46 OK folks, let's begin. 14:02:20 #topic Queens 14:03:11 L2-agent: https://review.openstack.org/#/c/323971/ 14:04:04 o/ 14:04:04 Sorry folks, I was in sick this week and there is no update.. 14:04:10 Regarding to L2 agent: i just added allowed_address_pairs and port_security_enabled to port_details 14:04:33 annp_, Great. thanks. 14:04:43 yushrio, i was in sick also :) 14:04:59 annp_, Really. Please take care of it. 14:05:17 yushiro: annp_ hope u guys get better soon 14:05:19 yushiro, yes. I got stomachache hichic 14:05:37 SridarK, Thank you so much. 14:05:45 SridarK, thank so much. 14:05:51 SridarK: +1 14:05:52 I have started a deployment and will run tests - i have been busy on some internal deadlines 14:05:54 SridarK, thanks so much. 14:06:19 SridarK, OK. 14:06:24 yushiro: we can sync on Mon and look thru things and try to merge this next week 14:06:48 SridarK, Sure. will do. 14:07:25 Hopefully we can meet in Sydney with fine condition :) 14:07:55 OVS based L2 firewall driver https://review.openstack.org/#/c/447251 14:08:51 Is there some update, annp_ ? I think we're testing in current patch. 14:09:53 Regarding to l2 driver, I have a concerning to egress_rules and ingress_rule 14:10:08 chandanc, are you here? 14:10:39 SarathMekala, is chandan today ?? 14:10:58 yushiro, currently, I'm focusing to co-existence between sg and fwg 14:11:00 he said he will join.. 14:11:11 SarathMekala, Good news. Thanks :) 14:11:35 I had a discussion in the morning :) 14:11:38 yushiro, SarathMekala, Can you check my comments in l2 driver patch? 14:12:21 Regarding to co-existence: i have a problem with conntrack 14:12:34 annp_, You commented that rules are reversing 'ingress -> egress', right? 14:12:50 yushiro, yes! 14:13:02 annp_, Is it OVS side issue? or firewall driver's issue? 14:14:06 issue related to co-existence: when i create VM1 is attached to SGA and VM2 is attached to SGB 14:14:16 SGA and SGB has icmp rule 14:14:43 I attached VM1 to FWGA has icmp-allow, 14:14:57 I try to ping from VM2 to VM1 it's ok. 14:15:39 annp_: the SGA & SGB - do they have a permit or deny ? 14:15:47 for icmp 14:16:32 But when i delete icmp-allow in FWGA, i try to ping from vm2 to vm1, i expect we couldn't reachout VM1, but result not good\ 14:16:58 SridraK, in security group all rules are allow. 14:17:15 oh sorry SG ok 14:17:39 conntrack state has been changed to +est-rep+rpl, 14:18:31 I guess problem related to conntrack change from per port to per network 14:19:16 https://github.com/openstack/neutron/commit/4f6aa3ffde2fd68b85bc5dfdaf6c2684931f3f61#diff-9639565b2ec91f2afe0f63f0cd4c189b 14:21:46 annp_, Hmm, OK. But, is it possible to fix in firewall side? 14:22:05 yeah, also why would our L2 not work per port? 14:22:32 yushiro, I think we can fix that. 14:23:06 xgerman_, yes. I'm thinking about that. 14:23:43 'per port' is suitable I think. 14:24:07 yeah, my understanding was that FWG and SG worked the same 14:24:12 in L2 14:25:05 xgerman_, yeah, i think so too. But i don't understand, why conntrack state change to OF_STATE_ESTABLISHED_REPLY 14:25:28 https://review.openstack.org/#/c/447251/47/neutron_fwaas/services/firewall/drivers/linux/l2/openvswitch_firewall/firewall.py@646 14:26:19 This flow made co-existence broken in above case! 14:26:19 annp_, Could you write down how to reproduce into the etherpad? https://etherpad.openstack.org/p/fwaas-v2-l2 14:27:15 yushiro, OK. I will do that now. 14:27:22 annp_, Thanks. 14:27:32 Can we comeback this problem later? 14:27:39 So Please go ahead 14:28:00 OK, let's move on. 14:28:00 annp_: do u need to pull in chandanc in to the discussion ? 14:28:58 +1, it's better to sync with chandan about that. 14:28:59 SridarK, Yes. That's great! 14:29:27 annp_, will inform him... please send a mail with him in loop as well 14:29:35 annp_: maybe send an email out and sched a time for discussion 14:29:49 SarathMekala: ditto 14:30:18 :) 14:30:22 +1 It's better to paste etherpad link :) 14:30:40 SridarK, SarathMekala, I will do on tomorrow. I'm in home now. :) 14:30:45 yushiro: maybe we can discuss on Mon as well - i am not too familiar with the driver changes 14:31:01 annp_: +1 14:31:16 SridarK, yes 14:31:25 #topic Horizon support 14:32:02 All of future improvements migrated into launchpad: https://bugs.launchpad.net/neutron-fwaas-dashboard 14:32:53 And sorry for late. I've already pushed release for dashboard: https://review.openstack.org/#/c/516549/ 14:33:09 +1 super 14:33:36 +1 14:33:42 yushiro: thx 14:33:44 Regarding releasing, thanks for your +1. 14:34:48 Regarding v2 dashboard bugs on launchpad, there are 2 points. 'Bug' and 'improvement'. as amotoki said, 'improvement' should be migrated into Blueprint. 14:35:12 I have started a google doc on the enhancements @ https://docs.google.com/document/d/1yKreFzwHsp-TMhB1xDH-EhGHBTGawFAaG1x6ukGJUK4/edit?usp=sharing 14:35:38 its still WIP.. once I get your suggestions will start a blueprint with it 14:35:50 SarathMekala, awesome!!! 14:35:59 SarathMekala: great 14:36:34 SarathMekala, I think it's much more better to refer related bug on launchpad :) 14:37:13 yushiro, sure.. I will do that 14:37:48 I'll also comment on your google doc :) 14:38:04 sure 14:38:12 SarathMekala, Can I paste google doc link on our weekly etherpad? 14:38:30 sure.. go ahead 14:38:35 yushiro: +1 14:39:02 even the etherpad needs some clean up.. I created some sections but could not fill them up 14:39:04 SarathMekala, done. 14:39:45 +1 14:40:15 OK, anything else to discuss about dashboard? 14:40:39 thats for now.. 14:40:50 OK, let's move on. 14:40:51 amotoki, do you have anything to discuss? 14:41:31 I heard that amotoki has not good condition. Maybe he is not here.. 14:42:00 ok.. please carry on 14:42:10 #topic Stadium Compliance 14:43:10 reedip , I think you're busy before summit. Do you have something to update? 14:43:24 i m late... sorry 14:43:53 reedip, OK. Anything to discuss about Stadium Compliance? 14:44:56 nope, but I think there needs to be a report for fwaas, isnt it ? There were some migration patches ( where in neutron functions have been migrated to lib and the same are to be incorporated in our repo ) but I think they took a back seat some time back due to L2 14:45:49 let’s get L2 done unless we get complains 14:45:53 i think most things are done except for the fullstack PS 14:46:03 +1 14:46:05 and reedip_ started on that 14:46:35 but xgerman_ agreed on L2 priority 14:46:45 but I am stuck in that , needed some assistance a while back ... I havent been able to contrbute for some weeks owing to company work... but will start again on weekends and spare time :) 14:47:23 any manager we know and can lean on ? 14:47:50 :-) 14:47:58 umm , not here , but dont worry , I have been multi tasking , so will be back from Saturday 14:48:13 reedip_: no worries - i think everyone is kind of in that boat 14:48:13 give me tomorrow :P 14:48:22 yeah, I know :D 14:48:24 SridarK +1 14:48:34 wow, reedip_ you're preparing Sydney summit presentation, right? multi-task!! 14:48:47 No , I am not coming to Sydney 14:48:56 travel not supported :( 14:49:04 BTW: The foundation wants to play a more active role in devs getting support 14:49:11 I talked to mlavalle about someone else taking my session 14:49:31 reedip 14:49:32 oh, really. I've seen your presentation. I see. 14:49:37 xgerman_ I hope so ... because the attrition is getting higher 14:50:08 yushiro : where ? Can you send the link ? I think I may have skipped it :) 14:50:21 yeah, if you need travel grants, etc. you can reach out to them 14:50:51 I dont think its possible now :) 14:50:57 https://www.openstack.org/summit/sydney-2017/summit-schedule/global-search?t=reedip 14:50:58 for sydney 14:51:42 You're moderator. 14:52:02 sorry, not prezentation but forum. 14:52:19 yeah, thats the catch :( 14:52:25 yep — reedip_ give it a try — they might have hotel rooms they haven’t filled 14:53:23 :) 14:53:57 nevermind, next summit/PTG 14:54:27 xgerman_ btw I think the foundation would like to give travel grants to core devs ;) 14:54:28 #topic Open Discussion 14:54:35 for eg. Yushiro got it for PTG :) 14:54:53 yeah, I got my fair share of grants, too 14:55:03 but I am funded for Dublin ;-) 14:55:05 reedip_, yes, I was so lucky. 14:55:22 +1 14:55:26 bzhao, Thanks for your update your audit notification spec. 14:55:38 bzhao, I'll check the latest version of your spec. 14:55:42 yushiro : we are doing open discussion :) 14:56:02 Yes :) 14:56:10 yeah , i need to get back to help bzhao .. he has been doing a lot of work on the specs , and I am not able to help him out 14:56:45 I reviewed the firewall audit spec and gave some comments today 14:56:48 please take a look 14:56:49 I am a bit worried about availability zones in the spec. 14:57:01 If somebody life migrates info becomes stale 14:57:08 hmm... xgerman ny reason 14:57:28 k 14:57:44 xgerman_, Yeah, I don't catch up a correct reason to handle 'availability_zone' either. 14:58:02 SarathMekala, Good :) 14:58:27 yep, the whole nova AZ, cell, etc. concept is pretty opaque to me 14:58:43 So, folks, how about next week's IRC meeting? 14:58:47 and it seems to mean different things to different operators 14:58:57 yushiro +1 14:59:08 lemme get an opinion on that from a nova core 14:59:28 reedip_ +1 15:00:30 at time 15:00:31 Oh, it's time 15:00:38 #endmeeting