Thursday, 2019-02-14

*** ekultails has quit IRC01:20
*** ricolin has joined #heat01:30
*** neatherweb has joined #heat01:43
*** hongbin has joined #heat02:07
*** k_mouza has joined #heat02:33
*** k_mouza has quit IRC02:38
*** maddtux has joined #heat03:00
*** skramaja has joined #heat03:54
*** skramaja_ has joined #heat03:58
*** skramaja has quit IRC03:59
*** ricolin has quit IRC04:05
*** ramishra has joined #heat04:09
*** ricolin has joined #heat05:02
*** hongbin has quit IRC05:44
*** ramishra_ has joined #heat06:00
*** ramishra has quit IRC06:01
*** _fragatina has quit IRC06:12
*** ramishra_ is now known as ramishra06:17
*** _fragatina has joined #heat06:22
*** e0ne has joined #heat06:29
*** _fragatina has quit IRC06:37
*** e0ne has quit IRC06:46
*** _fragatina has joined #heat06:48
*** neatherweb has quit IRC07:27
*** jtomasek has joined #heat07:35
*** jtomasek has quit IRC07:39
*** jtomasek has joined #heat07:44
*** _fragatina has quit IRC07:57
*** e0ne has joined #heat08:05
*** ramishra has quit IRC08:08
*** e0ne has quit IRC08:08
*** gkadam has joined #heat08:10
*** gkadam is now known as gkadam-brb08:11
*** e0ne has joined #heat08:18
*** e0ne has quit IRC08:18
*** ramishra has joined #heat08:18
*** gkadam-brb is now known as gkadam08:20
*** e0ne has joined #heat08:29
*** e0ne has quit IRC08:35
*** maddtux_ has joined #heat08:57
*** maddtux has quit IRC08:59
*** mikecmpbll has joined #heat09:04
*** aiyengar__ has joined #heat09:09
*** maddtux_ has quit IRC09:11
*** k_mouza has joined #heat09:24
*** hjensas has joined #heat09:32
*** gkadam has quit IRC09:51
*** gkadam has joined #heat09:51
*** k_mouza has quit IRC10:04
*** aiyengar__ has quit IRC10:31
*** k_mouza has joined #heat10:34
*** k_mouza has quit IRC10:34
*** k_mouza has joined #heat10:34
*** maddtux has joined #heat10:35
*** openstackgerrit has joined #heat10:40
openstackgerritRabi Mishra proposed openstack/heat master: WIP Make stack check convergence aware  https://review.openstack.org/63691610:40
*** matoef1 has joined #heat10:53
*** mikecmpb_ has joined #heat10:54
*** mikecmpbll has quit IRC10:54
matoef1Hi folks,11:04
matoef1I would like to enable SSL on my DevStack with magnum (v2.9.2) and heat (v1.14.0) plugins.11:04
matoef111:04
matoef1I used command `enable_service tls-proxy` in DevStack conf.11:04
matoef1This command enables TLS proxy for all endpoints except HEAT.11:04
*** matoef1 has quit IRC11:04
*** matoef1 has joined #heat11:06
matoef1Hi folks,  I would like to enable SSL on my DevStack with magnum (v2.9.2) and heat (v1.14.0) plugins.   I used command `enable_service tls-proxy` in DevStack conf. This command enables TLS proxy for all endpoints except HEAT. ``` stack@devstack-vm-36:~$ openstack endpoint list +----------------------------------+-----------+--------------+-----------------+---------+-----------+------------------------------------------------+ | ID11:07
matoef1Hi folks,11:08
matoef1I would like to enable SSL on my DevStack with magnum (v2.9.2) and heat (v1.14.0) plugins.11:08
matoef1I used command `enable_service tls-proxy` in DevStack conf. This command enables TLS proxy for all endpoints except HEAT.11:08
matoef1I tried to change HEAT configuration via heat.conf file but without any success.11:09
matoef1```11:09
matoef1[heat_api]11:09
matoef1workers = 211:09
matoef1bind_port = 800411:09
matoef1cert_file = /opt/stack/data/devstack-crt.crt11:09
matoef1key_file = /opt/stack/data/devstack-key.pem11:09
matoef1[heat_api_cfn]11:09
matoef1bind_port = 800011:09
matoef1cert_file = /opt/stack/data/devstack-crt.crt11:09
matoef1key_file = /opt/stack/data/devstack-key.pem11:09
matoef1[ssl]11:09
matoef1ca_file = /opt/stack/data/ca-bundle.pem11:10
matoef1cert_file = /opt/stack/data/devstack-crt.crt11:10
matoef1key_file = /opt/stack/data/devstack-key.pem11:10
matoef1```11:10
matoef1How can I enable SSL also for HEAT endpoints ?11:10
matoef1Many Thanks11:10
matoef1Hi folks,  I would like to enable SSL on my DevStack with magnum (v2.9.2) and heat (v1.14.0) plugins.   I used command `enable_service tls-proxy` in DevStack conf. This command enables TLS proxy for all endpoints except HEAT. http://paste.openstack.org/show/745083/ I tried to change HEAT configuration via heat.conf file but without any success. http://paste.openstack.org/show/745084/ How can I enable SSL also for HEAT endpoints ?11:20
matoef1Many Thanks11:20
ramishramatoef1: I don't think we support tls-proxy, I thought there was native SSL support with USE_SSL=True in local.conf. But can't find anything related. But you can try SERVICE_PROTOCOL=https in local.conf, it may work, never tested it, so don't know11:30
matoef1ramishra: Thank you. I will try USE_SSL=True. But What is the purpose of `cert_file` and `key_file` variables in heat.conf file ?12:16
matoef1And also [ssl] group ?12:16
*** k_mouza_ has joined #heat12:17
*** k_mouza has quit IRC12:20
*** skramaja has joined #heat12:22
*** skramaja_ has quit IRC12:23
*** _fragatina has joined #heat12:30
ramishramatoef1: those are cert/key locations for heat_api/heat_api_cfn to use. I think [ssl] keys are for oslo.service, those would be ignored12:37
ramishramatoef1: heat talks to other services, so there are client options too12:37
ramishrabut your issue AFAICT is the endpoints are not added to keystone with the correct SERVICE_PROTOCOL with devstack12:38
*** hjensas has quit IRC12:39
ramishraIf all your services are using https, then you can try setting SERVICE_PROTOCOL, but I can't say that it would work:)12:39
matoef1ramishra: Thanks for explanations, So I will try SERVICE_PROTOCOL and let you know:), thanks12:40
*** ekultails has joined #heat13:01
*** k_mouza_ has quit IRC13:01
*** k_mouza has joined #heat13:08
*** skramaja_ has joined #heat13:11
*** skramaja has quit IRC13:12
*** maddtux has quit IRC13:13
openstackgerritMerged openstack/heat master: Translate tenant_id to project_id in Octavia loadbalancer resource  https://review.openstack.org/62559713:30
matoef1ramishra: SERVICE_PROTOCOL variable works ! Thank you !. Now I have enabled SSL on all HEAT endpoints. Unfortunately, I fell into another issue http://paste.openstack.org/show/745098/13:42
matoef1I think user_data value is still encrypted when it comes into HEAT.13:43
ramishramatoef1: I think that's coming from nova, checking nova api logs would help, may be the data is large, AFAIK there is a limit or something13:50
ramishragotta go, late for me13:50
*** jmlowe has quit IRC13:54
*** matoef1 has quit IRC14:23
*** jmlowe has joined #heat14:25
*** ekultails has quit IRC14:34
*** gfidente has joined #heat14:41
*** skramaja_ has quit IRC14:46
*** ekultails has joined #heat14:53
*** mchlumsky has joined #heat14:57
*** hjensas has joined #heat15:16
*** gkadam has quit IRC15:30
*** gfidente has quit IRC15:56
*** ramishra has quit IRC16:07
*** ricolin_ has joined #heat16:14
*** ricolin has quit IRC16:16
*** _fragatina has quit IRC17:03
*** _fragatina has joined #heat17:06
*** mikecmpb_ has quit IRC17:36
*** k_mouza_ has joined #heat17:48
*** k_mouza has quit IRC17:50
*** k_mouza_ has quit IRC17:52
*** jmlowe has quit IRC17:57
*** ricolin_ has quit IRC18:19
*** ricolin_ has joined #heat18:20
*** ricolin_ has quit IRC18:25
*** shardy has quit IRC18:40
*** sshnaidm is now known as sshnaidm|off18:47
*** mikecmpbll has joined #heat20:01
*** _fragatina has quit IRC20:02
*** jmlowe has joined #heat20:07
*** mchlumsky has quit IRC20:15
*** k_mouza has joined #heat20:20
*** e0ne has joined #heat20:21
*** _fragatina has joined #heat21:15
*** k_mouza has quit IRC21:19
*** jtomasek has quit IRC21:23
-openstackstatus- NOTICE: Jobs are failing due to ssh host key mismatches caused by duplicate IPs in a test cloud region. We are disabling the region and will let you know when jobs can be rechecked.21:30
*** jtomasek has joined #heat21:32
*** hjensas has quit IRC21:33
*** e0ne has quit IRC21:48
*** jtomasek has quit IRC21:54
*** ekultails has quit IRC21:57
-openstackstatus- NOTICE: The test cloud region using duplicate IPs has been removed from nodepool. Jobs can be rechecked now.22:12
*** hjensas has joined #heat23:10
*** neatherweb has joined #heat23:22

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!