[08:27:05] morning [08:27:30] arturo: very quick review https://gitlab.wikimedia.org/repos/cloud/toolforge/jobs-api/-/merge_requests/126 [08:32:53] ๐Ÿ‘€ [08:39:04] blancadesal: +1ยกd [08:41:19] thanks! [13:03:17] topranks: because the debuging session from the other day, I created this https://github.com/aborrero/nftables-tracer [13:04:54] arturo: ooooh [13:04:57] that's awesome! [13:05:12] really nice idea, I'm a sucker for colour output in my terminal too <3 [13:05:42] and now with increased nftables usage across the servers, it may be of additional help somewhere else [13:07:10] yeah totally [13:07:34] so, just trying to understand it fully [13:08:08] you create a matching rule in raw that the packet will hit first, with "nftrace set 1" on it? [13:08:27] which means that subsequent rules that same packet hits are traced? [13:09:05] yeah, basically the script automates the steps in here https://wiki.nftables.org/wiki-nftables/index.php/Ruleset_debug/tracing [13:09:12] plus colors, plus cleanup when done [13:09:16] cool, that's really nice yeah [13:09:48] I moved my home router from iptables to nftables about a year ago [13:09:58] was somewhat painful getting all the rules right [13:10:09] Really wish I had of known about the tracing functionality back then!! [13:11:49] I have used this many times here for neutron, cloudgw, even kubernetes [14:08:44] arturo: not urgent, but review appreciated when you have a moment: https://gitlab.wikimedia.org/repos/cloud/toolforge/lima-kilo/-/merge_requests/200 [14:13:01] ๐Ÿ‘€ [14:16:03] blancadesal: +1'd [14:16:14] thanks arturo [16:00:25] * arturo offline