[ovs-discuss] OVN RBAC role for ovn-northd?

2019-11-07 Thread Frode Nordahl
perhaps based on a centrally managed set of hostnames. -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs-discuss

Re: [ovs-discuss] OVN RBAC role for ovn-northd?

2019-11-07 Thread Frode Nordahl
gt; > > > It is a known fact and have-been discussed before. We use the same > > > > workaround as you mentioned. Alternatively, you can also set role="" > and > > > it > > > > will work for both northd and ovn-controller instead

Re: [ovs-discuss] OVN RBAC role for ovn-northd?

2019-11-07 Thread Frode Nordahl
ernal means such as firewall rules that only allow connections from the machines hosting ovn-northd will at least make it a bit more secure. Apologies for any duplicate questions or discussions. I made an honest attempt to find the information by searching the mailing list archive and existing

Re: [ovs-discuss] OVN RBAC role for ovn-northd?

2019-11-08 Thread Frode Nordahl
191671/ 1: https://github.com/ovn-org/ovn/commit/e60f2f2d074d992ecfa6d9fc905e98a408e2d85e -- Frode Nordahl > > > > > > > > On Thu, Nov 7, 2019 at 2:00 PM Frode Nordahl > wrote: >> >> fwiw; I proposed this small note earlier this evening: >> https

Re: [ovs-discuss] options for OVN mailing lists, with a survey

2020-06-10 Thread Frode Nordahl
ovn.org MX host and turn it over to LF's > service provider to implement closed OVN mailing lists. > > Question: would it be acceptable for OVN mailing lists to be closed, so > that emails from non-subscribers are rejected? (See the defin

[ovs-discuss] OVN Dynamic Routing

2020-12-10 Thread Frode Nordahl
and discussing the proposed design on the mailing list? 0: https://www.openvswitch.org/support/ovscon2020/ -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs-discuss

Re: [ovs-discuss] OVN does not work with vlans when CX5 does UDP tx checksum offload on OEL 7.7 (RHEL 7.7 based) / OEL 7.9 (RHEL 7.9) based

2021-05-10 Thread Frode Nordahl
Hello Brendan, This resembles an issue I have seen with CX5 when not using OVS flow offload. The resolution in my case was to apply a fix [0] to the mlx5 kernel driver. 0: https://www.spinics.net/lists/netdev/msg711911.html -- Frode Nordahl On Wed, May 5, 2021 at 5:00 PM Brendan Doyle wrote

Re: [ovs-discuss] [ovs-dev] Moving of the primary #openvswitch channel to irc.libera.chat ?

2021-05-26 Thread Frode Nordahl
er picture. Our, and some 700 other channels, were just taken over for advertising other IRC networks in topic (see attached screenshot). I think this is the cue to leave Freenode. -- Frode Nordahl > I hope it helps, > Ihar > > On Wed, May 19, 2021 at 4:04 PM Ilya Maximets wrote: &

Re: [ovs-discuss] Unit openvswitch.service could not be found

2021-02-05 Thread Frode Nordahl
commands: `systemctl status openvswitch-switch` `systemctl status ovs-vswitchd` `systemctl status ovsdb-server` You may also add the `.service` suffix to the above commands if you want to. -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.

Re: [ovs-discuss] [OVN] Request: v20.03.02 tag

2021-03-18 Thread Frode Nordahl
On Thu, Feb 18, 2021 at 10:25 AM Lucas Alvares Gomes wrote: > > On Thu, Feb 18, 2021 at 8:54 AM Frode Nordahl > wrote: > > > > On Wed, Feb 17, 2021 at 4:17 PM Frode Nordahl > > wrote: > > > > > > On Wed, Feb 17, 2021 at 3:37 PM Lucas A

Re: [ovs-discuss] ovn-northd-ddlog and rust crate build process

2021-03-07 Thread Frode Nordahl
On Fri, Mar 5, 2021 at 11:17 PM Ben Pfaff wrote: > > On Fri, Mar 05, 2021 at 11:13:09PM +0100, Frode Nordahl wrote: > > However, when I got to the building of the rust crates part I found > > that it would both rebuild stuff when not needed and not do any > > parallelizat

[ovs-discuss] ovn-northd-ddlog and rust crate build process

2021-03-05 Thread Frode Nordahl
thought it would be worthwhile to send this e-mail to the list and ask if anyone has ideas for how to improve re-use of already built objects and parallelization of individual crate builds for a rust build process. -- Frode Nordahl ___ discuss mailing

Re: [ovs-discuss] [OVN] Should we tunnel traffic on localnet switches?

2021-02-15 Thread Frode Nordahl
pctl` or something similar? 0: https://bugs.launchpad.net/ubuntu/+source/ovn/+bug/1865127 1: https://patchwork.ozlabs.org/project/openvswitch/patch/20200519155816.24508-3-ihrac...@redhat.com/ -- Frode Nordahl > Looking forward to hearing f

Re: [ovs-discuss] [OVN] Request: v20.03.02 tag

2021-02-17 Thread Frode Nordahl
be happy to forward these to branch-20.03 if there is appetite for them and it would subsequently be easier for us to bring those bits out to the masses. 3: https://git.launchpad.net/~ubuntu-server-dev/ubuntu/+source/ovn/commit/?h=ubuntu/focal=bd1c02325d9bfc0e746f65e573d98f3415cbb5b2 -- Frode Nord

Re: [ovs-discuss] [OVN] Request: v20.03.02 tag

2021-02-18 Thread Frode Nordahl
On Wed, Feb 17, 2021 at 4:17 PM Frode Nordahl wrote: > > On Wed, Feb 17, 2021 at 3:37 PM Lucas Alvares Gomes > wrote: > > > > Hi, > > > > I would like to request a new tag in OVN 20.03 for the commit [0] > > which was backported to branch-20.03

Re: [ovs-discuss] ovn-controller: unable to reach metadata service after boot

2021-09-30 Thread Frode Nordahl
wonder if other types should be on that list as well, I added the authors of the two last changes in this area to Cc to see if they have any insights and will also have a look at comparing the output of the old and new implementation. -- Frode Nordahl > Regards, > Benjamin > >

Re: [ovs-discuss] ovn-controller: unable to reach metadata service after boot

2021-09-30 Thread Frode Nordahl
On Thu, Sep 30, 2021 at 8:32 AM Frode Nordahl wrote: > > On Mon, Sep 27, 2021 at 2:05 PM Benjamin Reichel > wrote: > > > > Hi everyone, > > > > We are using OVN together with Openstack(Ussuri) with one of the late > > master versions of ovn (83296a42e

Re: [ovs-discuss] Segmentation ID should be lower or equal to 4095

2021-11-16 Thread Frode Nordahl
be allocated by OVN itself. So to solve your concrete problem now you can just set your vni_ranges option to a value below 4095 and unless you are going to create 4096+ networks today this should work fine. OVN does not create datapaths with overlapping VNIs, so you should not have iss

Re: [ovs-discuss] OVN with SSL using self-signed CA Certificate | certificate verify failed

2021-11-08 Thread Frode Nordahl
rtificate so that they can verify the authenticity of the server certificate when establishing the connection. This is usually accomplished by placing the file in a location such as `/usr/local/share/ca-certificates` and then executing the `update-ca-certi

Re: [ovs-discuss] [ovn/ovs] OVS hardware offloading

2021-07-14 Thread Frode Nordahl
RR_CODE_INVALID_PARAMS error. My hunch would be there are some flow attributes in use that the driver/firmware does not support. If this is a 5.4 kernel it might be conntrack, you could try to disable port security for all networks and ports (make sure port-security is enabled in Neutron ML2 though, othe

[ovs-discuss] Remodel OVN Logical_Switch_Port addresses

2022-02-16 Thread Frode Nordahl
/ovn/+bug/1961046 -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs-discuss

Re: [ovs-discuss] WARN: execute ct(commit, zone=...) failed (Invalid argument)

2022-02-24 Thread Frode Nordahl
arted. If not I might try to get that done to help resolve the issue we see here, any pointers, in-flight thoughts or work on how to approach it would be appreciated. -- Frode Nordahl > > Best regards, Ilya Maximets. > __

Re: [ovs-discuss] [ovs-dev] Dealing with extreme kernel memory leaks

2022-03-31 Thread Frode Nordahl
g useful, but it appears to > be a couple of machines trying to access a TCP port on the OVN router. > My OVN router addresses are publicly reachable (45.45.148.136) in this > case, so some amount of port scanning and the like is somewhat common > and the likely cause of this traffic in the f

Re: [ovs-discuss] High latencies due to southdb leadership changes?

2022-04-08 Thread Frode Nordahl
f2aac26897a7ddfe 1: https://review.opendev.org/q/I7442170d015f195a5430e71567fbc7d67b81d385 -- Frode Nordahl Kind regards, > > Christian Stelter > ___ > discuss mailing list > disc...@openvswitch.org > https://mail.openvswitch.org/mailman/listinfo/ovs-discuss >

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-19 Thread Frode Nordahl
On Sat, May 14, 2022 at 2:10 AM Ilya Maximets wrote: > > On 5/13/22 10:36, Frode Nordahl wrote: > > On Fri, Mar 11, 2022 at 2:04 PM Liam Young wrote: > >> > >> Hi, > >> > >> Commit 355fef6f2 seems to break connectivity in my setup > > >

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-21 Thread Frode Nordahl
On Thu, May 19, 2022 at 3:39 PM Frode Nordahl wrote: > > On Sat, May 14, 2022 at 2:10 AM Ilya Maximets wrote: > > > > On 5/13/22 10:36, Frode Nordahl wrote: > > > On Fri, Mar 11, 2022 at 2:04 PM Liam Young > > > wrote: > > >> > >

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-30 Thread Frode Nordahl
On Fri, May 27, 2022 at 10:04 PM Ilya Maximets wrote: > > On 5/26/22 14:53, Frode Nordahl wrote: > > > > > > tor. 26. mai 2022, 14:45 skrev Ilya Maximets > <mailto:i.maxim...@ovn.org>>: > > > > On 5/26/22 13:00, Frode Nordahl wrote: > &g

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-31 Thread Frode Nordahl
On Mon, May 30, 2022 at 5:25 PM Frode Nordahl wrote: > > On Fri, May 27, 2022 at 10:04 PM Ilya Maximets wrote: > > > > On 5/26/22 14:53, Frode Nordahl wrote: > > > > > > > > > tor. 26. mai 2022, 14:45 skrev Ilya Maximets > > <mailto:i.maxim

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-26 Thread Frode Nordahl
On Wed, May 25, 2022 at 9:55 AM Frode Nordahl wrote: > > On Tue, May 24, 2022 at 1:32 PM Ilya Maximets wrote: > > > > On 5/24/22 12:54, Frode Nordahl wrote: > > > On Mon, May 23, 2022 at 3:49 PM Ilya Maximets wrote: > > >> > > >> On 5/21/22

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-26 Thread Frode Nordahl
tor. 26. mai 2022, 14:45 skrev Ilya Maximets : > On 5/26/22 13:00, Frode Nordahl wrote: > > On Wed, May 25, 2022 at 9:55 AM Frode Nordahl > > wrote: > >> > >> On Tue, May 24, 2022 at 1:32 PM Ilya Maximets > wrote: > >>> > >>> On 5/2

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-13 Thread Frode Nordahl
/+source/ovn/+bug/1967856/comments/6 -- Frode Nordahl > I am working on an OpenStack deploy with ovs 2.16 and initially thought the > issue was a neutron problem so have been logging bug information here: > https://bugs.launchpad.net/openvswitch/+bug/1964117 > > It's a fairly standa

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-25 Thread Frode Nordahl
On Tue, May 24, 2022 at 1:32 PM Ilya Maximets wrote: > > On 5/24/22 12:54, Frode Nordahl wrote: > > On Mon, May 23, 2022 at 3:49 PM Ilya Maximets wrote: > >> > >> On 5/21/22 12:49, Frode Nordahl wrote: > >>> On Thu, May 19, 2022 at 3:39 PM Frode Nordahl

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-05-24 Thread Frode Nordahl
On Mon, May 23, 2022 at 3:49 PM Ilya Maximets wrote: > > On 5/21/22 12:49, Frode Nordahl wrote: > > On Thu, May 19, 2022 at 3:39 PM Frode Nordahl > > wrote: > >> > >> On Sat, May 14, 2022 at 2:10 AM Ilya Maximets wrote: > >>> > >>>

Re: [ovs-discuss] OVN and OVS submodule stuff

2022-07-12 Thread Frode Nordahl
rrent OVN LTS release (22.03.x) and OVS LTS release (2.17.x). Would you accept proposals in that direction to the OVN release documentation? 0: https://github.com/openvswitch/ovs/commit/d94cd0d3eec33e4290d7ca81918f5ac61444886e 1: https://wiki.debian.org/UpstreamGuide#No_inclusion_of_third_party_co

Re: [ovs-discuss] Commit 355fef6f2 seems to break connectivity in my setup

2022-06-07 Thread Frode Nordahl
On Tue, Jun 7, 2022 at 12:16 AM Ilya Maximets wrote: > > On 5/31/22 23:48, Ilya Maximets wrote: > > On 5/31/22 21:15, Frode Nordahl wrote: > >> On Mon, May 30, 2022 at 5:25 PM Frode Nordahl > > > > >> I've pushed the first part of the fix here: > >>

Re: [ovs-discuss] OVS Crashing and restarting every 1hr

2023-10-28 Thread Frode Nordahl via discuss
Hello, Gavin, This looks familiar and I wonder if it is fixed by [0]? It is also available in 2.17.7 [1]. 0: https://github.com/openvswitch/ovs/commit/106ef21860c935e5e0017a88bf42b94025c4e511 1: https://github.com/openvswitch/ovs/commit/111c7be3193e15e2acf8af8ceb74a1177a95806d -- Frode Nordahl

Re: [ovs-discuss] OVN: scaling L2 networks beyond 10k chassis - proposals

2023-09-30 Thread Frode Nordahl via discuss
CPU load that is gone from the > > central node needs to be shared across all chassis. > > > >> - The complexity of the ovn-controller grows as it gains nearly all > >> logic of northd > > > > Agreed, but the complexity may not be that high. Since ovn-controller &

Re: [ovs-discuss] OVN: scaling L2 networks beyond 10k chassis - proposals

2023-10-02 Thread Frode Nordahl via discuss
gt; >> underlying networking fabric. It thereby places additional > > > >> requirements on the network fabric that have not been here before and > > > >> that might not be available for all users. > > > > > > > > Are you aware of any fa

Re: [ovs-discuss] OVS container crashing on multiple hypervisors.

2023-09-27 Thread Frode Nordahl via discuss
lable in OVS 2.17.7, 3.1.2 and 3.2.0. 0: https://github.com/openvswitch/ovs/commit/106ef21860c935e5e0017a88bf42b94025c4e511 -- Frode Nordahl > > > Environment and required outputs are below. > > > > OpenStack Zed > > Linux Kernel: Linux version 5.19.0-41-generic > >

Re: [ovs-discuss] vif_plug_representor|INFO|No representor port found

2022-12-22 Thread Frode Nordahl via discuss
hub.com/ovn-org/ovn-vif/blob/ce1a36f300a74b4eae55a7fec7d18da8b9218e29/lib/vif-plug-providers/representor/vif-plug-representor.c#L321-L328 -- Frode Nordahl > On Wed, 21 Dec 2022 at 02:50, Frode Nordahl > wrote: >> >> Hello, Gavin, >> >> Thank you for your interest in the

Re: [ovs-discuss] vif_plug_representor|INFO|No representor port found

2022-12-23 Thread Frode Nordahl via discuss
se does not work well with the current data model for lookup. -- Frode Nordahl > Gav > > On Thu, 22 Dec 2022 at 19:46, Frode Nordahl > wrote: >> >> On Wed, Dec 21, 2022 at 4:08 PM Gavin McKee >> wrote: >> > >> > Hi Frode, >> > >> > Thanks f

Re: [ovs-discuss] vif_plug_representor|INFO|No representor port found

2022-12-21 Thread Frode Nordahl via discuss
sentor module? What kernel version is in use? Does the `hw_addr` show up for the PCI_PF flavoured port in `devlink port show`? 0: https://www.kernel.org/doc/html/latest/networking/devlink/devlink-port.html 1: https://github.com/ovn-org/ovn-vif/blob/ce1a36f300a74b4eae55a7fec7d18da8b9218e29/lib/vif-p

[ovs-discuss] ovsdb: schema conversion for clustered db blocks preventing processing of raft election and inactivity probes

2022-12-13 Thread Frode Nordahl via discuss
in a separate thread [0]. Any other thoughts or ideas? 0: https://github.com/openvswitch/ovs/commit/3cd2cbd684e023682d04dd11d2640b53e4725790 -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs

Re: [ovs-discuss] OVN: SSL "best practice"

2022-12-13 Thread Frode Nordahl via discuss
zation. And since we are not configuring TCP listeners, just re-using the default ones for SSL/TLS makes sense in our deployments. -- Frode Nordahl > Regards, > Jake > > [1] > https://github.com/ovn-org/ovn-kubernetes/blob/master/docs/INSTALL.S

Re: [ovs-discuss] ovsdb: schema conversion for clustered db blocks preventing processing of raft election and inactivity probes

2023-01-23 Thread Frode Nordahl via discuss
On Tue, Jan 3, 2023 at 3:07 PM Ilya Maximets wrote: > > On 12/14/22 08:28, Frode Nordahl via discuss wrote: > > Hello, > > > > When performing an online schema conversion for a clustered DB the > > `ovsdb-client` connects to the current leader of the cluster and >

Re: [ovs-discuss] ovsdb relay server active connection probe interval do not work

2023-03-07 Thread Frode Nordahl via discuss
s, disconnecting > >> 2023-03-06T22:20:27.056Z|00109|reconnect|INFO|ssl:xxx:16642: connection > >> dropped > >> 2023-03-06T22:20:35.111Z|00110|reconnect|INFO|ssl:xxx:16642: connected > >> > >> On the DB cluster this looks like: > >> > >

Re: [ovs-discuss] OVS and OVN compatibility matrix

2023-03-27 Thread Frode Nordahl via discuss
and Jammy from there. 0: https://github.com/ovn-org/ovn/blob/main/lib/features.c 1: https://wiki.ubuntu.com/OpenStack/CloudArchive -- Frode Nordahl > Regards, > Jake > > [1] > https://mail.openvswitch.org/pipermail/ovs-discuss/2023-March/052302

Re: [ovs-discuss] ovsdb: schema conversion for clustered db blocks preventing processing of raft election and inactivity probes

2023-03-27 Thread Frode Nordahl via discuss
On Mon, Mar 27, 2023 at 9:50 PM Ilya Maximets wrote: > > On 1/23/23 11:44, Frode Nordahl wrote: > > On Tue, Jan 3, 2023 at 3:07 PM Ilya Maximets wrote: > >> > >> On 12/14/22 08:28, Frode Nordahl via discuss wrote: > >>> Hello, > >>

Re: [ovs-discuss] openvswitch: ovs-system: deferred action limit reached, drop recirc action

2023-02-10 Thread Frode Nordahl via discuss
ion > ovs-vsctl (Open vSwitch) 3.0.1 > DB Schema 8.3.0 > > (openvswitch-vswitchd)[root@ctrl1 /]# ovs-vswitchd --version > ovs-vswitchd (Open vSwitch) 3.0.1 What version of OVN are you using? I believe this issue has been fixed on the main branch by [0]. 0: https://github.com/ovn-org/o

Re: [ovs-discuss] OVS HW offload not working

2023-05-25 Thread Frode Nordahl via discuss
eds to be connected to an interface wired directly to the embedded switch in the card by attaching a VF or SF to the instance. -- Frode Nordahl > Neither of which shows offloaded > > The commands I'm using to setup the interfaces are: > > echo 2 | tee /sys/class/net/ens15f0np0/devic

Re: [ovs-discuss] OVS HW offload not working

2023-05-25 Thread Frode Nordahl via discuss
On Thu, May 25, 2023 at 9:03 AM Robert Navarro wrote: > > Hi Frode, > > Thanks for the fast reply! > > Replies in-line as well. > > On Wed, May 24, 2023 at 11:41 PM Frode Nordahl > wrote: >> >> Hello, Robert, >> >> See my response in-line

Re: [ovs-discuss] OVS HW offload not working

2023-05-25 Thread Frode Nordahl via discuss
rtio driver. The underlying plumbing to make it work is a bit more involved though, so I'd recommend getting the simpler setup described so far in this thread work before embarking on that journey. I'm learning a lot very quickly, thanks for the information Frode! > Thank you for the feedback, and

Re: [ovs-discuss] OVN North DB (Security)

2023-06-21 Thread Frode Nordahl via discuss
ions from hypervisors. 2. Enable TLS/SSL and use a different certificate chain for NB and SB DBs. When enabled, the ovsdb-server will verify the clients certificate and refuse connections from those it cannot verify. 0: https://docs.ovn.org/en/latest/tutorials/ovn-rbac.html -- Frode Norda

Re: [ovs-discuss] OVN: Fixing direct access to SNATed network

2024-01-24 Thread Frode Nordahl via discuss
les of end users coming from ML2/OVS with this expectation. There are also other facets of this problem complex with issues such as internal IP access to a DNAT'ed address backed by an IP on the same network etc. but I'm sure we will get onto those as part of the discussion. FWIW; there are some descript

[ovs-discuss] [branch-22.x] ICMP to load balancer not working for instance colocated with chassis bound to chassisredirect port

2024-04-22 Thread Frode Nordahl via discuss
or something similar? 0: https://bugs.launchpad.net/microovn/+bug/2060460 -- Frode Nordahl ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs-discuss