Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SDN-1364] Add Network Policy audit logging Enhancement #617

Merged
merged 2 commits into from
Mar 25, 2021

Conversation

astoycos
Copy link
Contributor

@astoycos astoycos commented Feb 1, 2021

Creat an enhancemnt for the feature relating to
the Jira Epic SDN-1364

Signed-off-by: Andrew Stoycos [email protected]

@openshift-ci-robot openshift-ci-robot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Feb 1, 2021
@astoycos astoycos changed the title [WIP[SDN-1364] Add Network Policy audit logging Enhancement [WIP][SDN-1364] Add Network Policy audit logging Enhancement Feb 1, 2021
@astoycos astoycos force-pushed the add-np-audit-logging branch 2 times, most recently from f13ec8f to cdc7a64 Compare February 1, 2021 14:48
@russellb russellb requested review from russellb, knobunc, vpickard, Billy99 and abhat and removed request for stbenjam February 1, 2021 20:18
@russellb
Copy link
Member

russellb commented Feb 1, 2021

updated the reviewers list to match what's in the enhancement doc

@russellb
Copy link
Member

russellb commented Feb 1, 2021

@astoycos note the markdown lint job failure. you can run it locally with make lint

enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
@astoycos astoycos force-pushed the add-np-audit-logging branch 2 times, most recently from e98b42b to 078309a Compare February 2, 2021 07:34
Copy link
Contributor

@danielmellado danielmellado left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @astoycos , thanks for getting this ready! Overall LGTM, just a few nits!

enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
enhancements/network/network-policy-audit-logging.md Outdated Show resolved Hide resolved
Creat an enhancemnt for the feature relating to
the Jira Epic [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

Signed-off-by: Andrew Stoycos <[email protected]>
Copy link
Member

@russellb russellb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We've got some open questions remaining, and they're mostly captured in "open questions".

If you want to change this to "provisional" instead of "implemented", we can probably land it sooner and iterate with further PRs to get it to "implementable" once we have the open questions sorted.

astoycos added a commit to astoycos/api that referenced this pull request Mar 10, 2021
API changes For [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 15, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 15, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 15, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 15, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 15, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 16, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 16, 2021
Changes or [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/api that referenced this pull request Mar 17, 2021
API changes For [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 18, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 18, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 23, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 23, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 23, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

Signed-off-by: Andrew Stoycos <[email protected]>
Copy link
Contributor

@knobunc knobunc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

@openshift-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: knobunc

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 25, 2021
Copy link
Member

@russellb russellb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Mar 25, 2021
@openshift-merge-robot openshift-merge-robot merged commit 2848f2b into openshift:master Mar 25, 2021
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 25, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 29, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Mar 31, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
astoycos added a commit to astoycos/cluster-network-operator that referenced this pull request Apr 1, 2021
Changes for [SDN-1364](https://issues.redhat.com/browse/SDN-1364)

See [Enhancement](openshift/enhancements#617) for
details on the changes

Changed `ovn-kubernetes.go` to digest new api fields

Added new sidecar container to the ovnkube-node daemonset that handles
tailing the logs, and log rotation.

add resource limits to the new sidecar container

Signed-off-by: Andrew Stoycos <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

9 participants