Managing Security bewteen account in Advanced Zone without SG

2023-05-16 Thread Pratik Chandrakar
Hi all, Curious to know how others are managing isolation between VMs of different accounts in the Advanced Zone without SG deployment, as most users opt for default_allow policy for their VPC. Because of default_allow policy all ports are opened between public ip (static nat) irrespective of VLAN

Re: [VOTE] Upgrade Log4j to Log4j2

2023-05-16 Thread Daniel Salvador
Hello, João Considering the discussion we had in the thread[1] and that the conflicts will be mostly regarding loggers names (which is simple to fix), I am +1 on the proposal. Best regards, Daniel Salvador (gutoveronezi) [1] https://lists.apache.org/thread/261j7m0p5mr4q7yclvo49mwhkxz4yov2 On

[VOTE] Upgrade Log4j to Log4j2

2023-05-16 Thread João Jandre Paraquetti
Hello guys, I am opening this voting thread as result of the discussion in thread "ACS upgrade to Log4J2 version 2.19"[1]. The voting aims to continue the efforts and conclude the upgrade of the ACS logging library to Log4j2 through PR 7131[2]; merge the PR as soon as possible and provide

Re: ACS upgrade to Log4J2 version 2.19

2023-05-16 Thread João Jandre Paraquetti
Hello guys, This thread has been going on for some time, and a good amount of people have spoken their opinions on it, and nobody has been explicitly against the upgrade. Some concerns have been raised during the thread: - Testing: we have already tested this change against multiple

Re: preventing VM Live migration between Pods

2023-05-16 Thread Granwille Strauss
While I understand the concern, using the 'host-model' should solve the migration issue. I currently have a Intel Xeon E5-2620 v4 (32) KVM host and my VMs shows as Intel (Broadwell, IBRS). A massive difference, but migrations work fine and VM performance drop is not that noticeable. You could

Re: preventing VM Live migration between Pods

2023-05-16 Thread Simon Weller
Gary, There are some global settings you can enable/disable to prevent certain VM (and storage) movements. migrate.vm.across.clusters - indicates whether the VM can be migrated to different cluster if no host is found in same cluster enable.storage.migration - Enable/disable storage migration

RE: preventing VM Live migration between Pods

2023-05-16 Thread Gary Dixon
We have tried host-model – however virsh capabilities on the newer servers doesn’t even pick up the correct cpu map xml definition – the actual CPU is a AMD EPYC 7763 (codename Milan) and libvirt thinks it’s a ‘Rome’ cpu – a whole generation earlier !!! Gary Dixon Senior Technical Consultant

Re: preventing VM Live migration between Pods

2023-05-16 Thread Granwille Strauss
Hi Gary I am still fairly new to ACS myself, but as far as I can recall, using the 'host-passthrough' option is prone to cause problems during migrations, this is also mentioned in the documentation:

preventing VM Live migration between Pods

2023-05-16 Thread Gary Dixon
Hi everyone Other than disabling a Pod – is there a way to prevent live migration of VM’s between Pods in ACS ? We are on version 4.15.2 with Ubuntu 20.04 KVM hosts. Each Pod contains a single cluster of Homogenous hosts – however there are only slight differences between the CPU’s on the

EXT4 Fs corruption

2023-05-16 Thread Bram Gillemon
Hi, i'm having some issues with filesystems that are having filesystem corruption when fstrim is triggered by systemd. When searching the internet i found some posts mentioning i should disable the storage cache. Anyone else who has noticed this problem? How can i change the cache mode on