*** jamesgu has quit IRC | 00:05 | |
*** cheng1 has joined #airshipit | 00:09 | |
*** irclogbot_0 has quit IRC | 02:23 | |
*** cheng1 has quit IRC | 04:55 | |
*** jamesgu has joined #airshipit | 05:01 | |
*** cheng1 has joined #airshipit | 05:44 | |
*** cheng1 has quit IRC | 05:52 | |
*** lemko has joined #airshipit | 06:54 | |
*** jamesgu has quit IRC | 06:58 | |
*** skatsaounis has joined #airshipit | 07:06 | |
*** pkaralis has joined #airshipit | 07:58 | |
*** dimitris_ has joined #airshipit | 08:22 | |
*** nick_kar has joined #airshipit | 08:27 | |
*** juhak has quit IRC | 09:03 | |
*** juhak has joined #airshipit | 09:04 | |
*** roman_g has joined #airshipit | 09:34 | |
*** dimitris_ has quit IRC | 10:04 | |
*** dimitris_ has joined #airshipit | 10:08 | |
*** lemko has quit IRC | 12:34 | |
*** hemanth_n_ has joined #airshipit | 12:38 | |
*** aaronsheffield has joined #airshipit | 13:04 | |
*** howell has joined #airshipit | 13:42 | |
*** michael-beaver has joined #airshipit | 13:48 | |
*** nishant__ has joined #airshipit | 13:51 | |
*** dustinspecker has joined #airshipit | 14:06 | |
*** jamesgu has joined #airshipit | 14:28 | |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: setting .PEM files permissions to 640 https://review.openstack.org/643102 | 14:30 |
---|---|---|
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: [WIP] Enhance docs rendering https://review.openstack.org/638144 | 14:32 |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: Setting .PEM files permissions to 640 https://review.openstack.org/640775 | 14:35 |
*** lemko has joined #airshipit | 14:48 | |
openstackgerrit | Arijit Bose proposed openstack/airship-in-a-bottle master: [site update] fixing the json syntax https://review.openstack.org/644239 | 15:07 |
openstackgerrit | Lev Morgan proposed openstack/airship-pegleg master: Fix multiple I/O issues in cert generation https://review.openstack.org/643678 | 15:10 |
openstackgerrit | Michael Beaver proposed openstack/airship-treasuremap master: Uplift HAProxy to address CVEs https://review.openstack.org/644245 | 15:28 |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: Set Least Previliage for .PEM files under directory /etc/genesis. https://review.openstack.org/640775 | 16:02 |
*** dustinspecker has quit IRC | 16:03 | |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 16:20 |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 16:34 |
*** arunkant has quit IRC | 16:46 | |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 17:00 |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 17:14 |
*** hemanth_n_ has quit IRC | 17:28 | |
*** michaelbeaver has joined #airshipit | 18:06 | |
*** sthussey has joined #airshipit | 18:06 | |
*** michael-beaver has quit IRC | 18:09 | |
openstackgerrit | James Gu proposed openstack/airship-treasuremap master: Add missing labels to osh charts and ucp chart groups https://review.openstack.org/636240 | 18:11 |
openstackgerrit | Merged openstack/airship-in-a-bottle master: Cert/key related improvements to gate-multinode https://review.openstack.org/642585 | 18:19 |
*** juhak has quit IRC | 18:27 | |
*** juhak has joined #airshipit | 18:28 | |
*** michael-beaver has joined #airshipit | 18:33 | |
*** michaelbeaver has quit IRC | 18:36 | |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 18:56 |
openstackgerrit | Merged openstack/airship-promenade master: Uplift default HAProxy to address CVEs https://review.openstack.org/643475 | 18:57 |
openstackgerrit | James Gu proposed openstack/airship-treasuremap master: Add missing labels to osh charts and ucp chart groups https://review.openstack.org/636240 | 19:34 |
openstackgerrit | Lev Morgan proposed openstack/airship-pegleg master: Fix multiple I/O issues in cert generation https://review.openstack.org/643678 | 19:55 |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: Setting .PEM files permissions to 640 https://review.openstack.org/640775 | 20:04 |
*** irclogbot_0 has joined #airshipit | 20:11 | |
roman_g | Please, review https://review.openstack.org/#/c/638144/ - Enhance docs rendering; update documentation - openstack/airship-divingbell | 20:18 |
roman_g | Thank you. | 20:18 |
*** kranthikirang has joined #airshipit | 20:24 | |
openstackgerrit | Merged openstack/airship-in-a-bottle master: [site update] fixing the json syntax https://review.openstack.org/644239 | 20:25 |
*** irclogbot_0 has quit IRC | 20:25 | |
*** irclogbot_0 has joined #airshipit | 20:26 | |
kranthikirang | Hi All, We have a requirement to deploy Akraino which uses old Airship code; hence trying to deploying latest Airship code. However I have following question at creation of certificates; https://airship-treasuremap.readthedocs.io/en/latest/authoring_and_deployment.html | 20:27 |
kranthikirang | Do you have a list of endpoints with FQDNs to be used while creating certificates? I guess we use these for ingress right | 20:28 |
kranthikirang | Also do we have to define DNS before deployment if so with which node IP we have to register? | 20:28 |
kranthikirang | Appreciate your help to answer these question; | 20:28 |
*** michaelbeaver has joined #airshipit | 20:38 | |
*** michael-beaver has quit IRC | 20:41 | |
*** michaelbeaver has quit IRC | 20:42 | |
roman_g | kranthikirang: Configure certificates in site/${NEW_SITE}/secrets/certificates/ingress.yaml, they need to be issued for domain configured in a section data.dns.ingress_domain of a file ./site/${NEW_SITE}/networks/common-addresses.yaml. A list of endpoints which will be used with these certificates can be found in the following file ./site/${NEW_SITE}/software/config/endpoints.yaml | 20:50 |
roman_g | https://airship-treasuremap.readthedocs.io/en/latest/authoring_and_deployment.html#update-passphrases | 20:50 |
roman_g | Q: do we have to define DNS before deployment? | 20:50 |
roman_g | A: yes | 20:50 |
roman_g | Hope it helps :) | 20:51 |
roman_g | Need to go home. Ask more questions here, some people should be online. | 20:51 |
* roman_g ZzzZzz | 20:51 | |
kranthikirang | roman_g: Thank you for answering. I have read that paragraph. Does my below understanding correct? for an exmaple i have following domain ingress_domain: reg1.company.com and now do I have to put this suffix to each endpoint? Certificate team is asking for FQDNs | 20:55 |
kranthikirang | exmaple like cloudformation.reg1.company.com, compute.reg1.company.com ..etc? | 20:55 |
kranthikirang | coming to DNS, to which FQDNs and what ip address I have to use to register DNS records ? | 20:56 |
kranthikirang | These cloud be basic but gives me good understanding on how Airship works. So far I have used kubespray and deploy openstac-helm | 20:57 |
*** irclogbot_0 has quit IRC | 21:05 | |
evgenyl | kranthikirang: You don't have to change every single endpoint, there is a substitution, that will do it for you https://github.com/openstack/airship-treasuremap/blob/master/site/airship-seaworthy/software/config/endpoints.yaml#L361-L390 | 21:05 |
*** irclogbot_0 has joined #airshipit | 21:06 | |
kranthikirang | so just sign the cert using ca with that domain name as CN? that's all? | 21:07 |
kranthikirang | evgenyl: so just sign the cert using ca with that domain name as CN? that's all? | 21:07 |
evgenyl | kranthikirang: You will need a wildcard cert (i.e. signed for *.reg1.company.com) or for roughly these domains http://paste.openstack.org/show/747983/ | 21:10 |
kranthikirang | evgenyl: thanks a lot; I will talk to them | 21:10 |
kranthikirang | can you please tell me on DNS? | 21:11 |
kranthikirang | which ip I should register the DNS against before deployment? any node ip or genensis ip? | 21:11 |
kranthikirang | for all these FQDNs | 21:11 |
roman_g | all node IPs | 21:11 |
kranthikirang | roman_g: didn't get that; all node IPs? | 21:12 |
evgenyl | kranthikirang: Regarding to what DNS to register, it really depends on your networking layout, and if you e.g. use BGP VIPs for HA, for non-ha configuration you can use management IP of genesis or any other controller node https://github.com/openstack/airship-treasuremap/blob/master/site/airship-seaworthy/networks/physical/networks.yaml#L12 | 21:13 |
kranthikirang | evgenyl: ok; Does Airship support BGP VIPs? I ask this I do not see that VIP configuration in manifests; Also for ingress there is not VIP right? | 21:15 |
kranthikirang | evgenyl: Also another question; these endpoints looks like only for openstack. Do we have to add any DNS for airship components as well? like shipyard.DOMAIN? | 21:15 |
*** michael-beaver has joined #airshipit | 21:19 | |
evgenyl | kranthikirang: There is a way to configure external peers, but you will need to make sure that the switches are configured accordingly, here is some information on configuration configuring BGP peers for Calico https://github.com/openstack/openstack-helm-infra/blob/master/calico/values.yaml#L203-L219 | 21:20 |
evgenyl | kranthikirang: In the list there shipyard.DOMAIN, the rest is being accessed using internal *.cluster.local DNS names, unless if you want to configure it differently. | 21:22 |
kranthikirang | evgenyl: Thanks a lot for clarifying; I will include shipyard and ask to configure DNS with genesis OAM ip and certificate with wildcard | 21:23 |
kranthikirang | evgenyl: coming to bgp peer that's not while building site documents right in Airship; thats in openstack-helm-infra project. So, if I don't make any config then will it use just mesh | 21:24 |
kranthikirang | ? | 21:24 |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 21:26 |
*** howell has quit IRC | 21:26 | |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: Setting .PEM files permissions to 640 https://review.openstack.org/640775 | 21:26 |
*** irclogbot_0 has quit IRC | 21:26 | |
*** irclogbot_0 has joined #airshipit | 21:27 | |
evgenyl | kranthikirang: As far as I remember by default it will have mesh configuration. | 21:27 |
kranthikirang | evgenyl: Will give a try with these details and get back to you | 21:28 |
kranthikirang | evgenyl, roman_g: Appreciate your help and time | 21:29 |
evgenyl | kranthikirang: Sure, np. | 21:31 |
openstackgerrit | Sandeep Reddy Thumma proposed openstack/airship-promenade master: Set Least Previliage for .PEM files under directory /etc/genesis. https://review.openstack.org/640775 | 21:33 |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 21:43 |
openstackgerrit | Roman Gorshunov proposed openstack/airship-divingbell master: Enhance docs rendering; update documentation https://review.openstack.org/638144 | 21:47 |
*** kranthikirang has quit IRC | 22:28 | |
*** kranthikirang has joined #airshipit | 22:42 | |
openstackgerrit | Kaspars Skels proposed openstack/airship-in-a-bottle master: Mount ~/.ssh to allow Pegleg to clone repos https://review.openstack.org/644444 | 22:45 |
openstackgerrit | Dan Crank proposed openstack/airship-deckhand master: Log client-id in UCP API endpoints https://review.openstack.org/634068 | 23:08 |
openstackgerrit | Dan Crank proposed openstack/airship-promenade master: Log client-id in UCP API endpoints https://review.openstack.org/634071 | 23:10 |
*** kranthikirang has quit IRC | 23:12 | |
*** michael-beaver has quit IRC | 23:23 | |
*** aaronsheffield has quit IRC | 23:33 | |
*** kranthikirang has joined #airshipit | 23:34 | |
*** kranthikirang has quit IRC | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!