[06:44:13] good morning! [09:00:07] Morning [10:39:15] I was able to make the istio sidecar working with arwiki, but of course I cannot reliably use the circuit breaking settings for some reasons [10:39:36] with siege it seems as if they are no applied [10:39:44] istio is more subtle than expected [11:37:20] * elukey lunch! [11:37:47] after a morning spent between istio and partman, I go with my broken soul to lunch [11:56:49] partman! ontop of istio? Poor man. [14:13:39] luckily separately! [14:13:52] but it was not a nice experience (if you want to laugh https://gerrit.wikimedia.org/r/c/operations/puppet/+/771355) [14:13:58] istio in partman? Now that's something to rival Cthulhu [14:15:04] Oh wow [14:15:12] That double dot thing is just... pain [14:15:33] I must tell Stevie Beth about it, once she's back from sick leave [14:17:57] she would be delighted to know that I spent hours on a bug like that [14:20:15] klausman: about istio, I think that the istio-proxy sidecar makes sense, I'll write down a plan in the task (deb package + configs) so you can tell me what you think about it [14:20:25] it may take 2/3 days to be implemented, but it should work [14:20:32] (without the install-cni daemonset horror) [15:27:22] Sounds good, how much distruption do you think it would be to roll it out? [16:05:04] klausman: I hope not much, I am already testing it on ml-serve1001 and it works fine [16:05:36] basically we'll need to deploy a couple of binaries from istio upstream that are called when a pod is created (with the injection sidecar annotations etc..) [16:06:07] that will inject the iptables nat horrors to make the traffic routes that we configure in istio [16:06:33] plus a user and some network policies, all hopefully handled via helmfile with one command [16:06:44] then we can switch models one by one or similar [16:11:22] Sounds very doable. Thanks for doing all the legwork [16:11:47] np! It seems a nice addendum with the circuit breaking things [16:18:09] Agreed. And while it's a complex beast (and I hope I will never have to understand those NAT rules...), I think the functionality it provides might come in handy [16:20:18] klausman: don't you already picture yourself doing nsenter iptables -t nat -L on a sunday morning ? :D [16:21:17] I... prefer not to [16:23:15] ahahahah [16:31:10] I owe you so many beers by now, you'd have more than Mr. Moretti [16:35:03] \o/ [16:53:16] "Toscana Breweries. We'll make you forget partman." [16:53:31] (or Toscano, if you prefer ;)) [16:59:21] I like it [16:59:27] it could be a new brand [18:18:17] * elukey afk! [21:01:40] accraze: good luck with wherever you're heading