*** sdake has joined #kolla | 00:01 | |
*** tpot has joined #kolla | 00:02 | |
*** sdake has quit IRC | 00:03 | |
*** cloudnautique has quit IRC | 00:06 | |
*** sdake has joined #kolla | 00:07 | |
*** sacharya has joined #kolla | 00:11 | |
*** achanda has joined #kolla | 00:15 | |
*** sacharya has quit IRC | 00:15 | |
*** achanda has quit IRC | 00:35 | |
*** tzn has quit IRC | 00:47 | |
*** diogogmt has quit IRC | 00:48 | |
*** tzn has joined #kolla | 01:05 | |
*** ssurana has quit IRC | 01:09 | |
*** tzn has quit IRC | 01:09 | |
*** sdake has quit IRC | 01:10 | |
*** signed8bit_ZZZzz is now known as signed8bit | 01:15 | |
*** akwasnie1 has joined #kolla | 01:25 | |
*** mbound has quit IRC | 01:26 | |
*** weiyu has joined #kolla | 01:31 | |
*** signed8bit is now known as signed8bit_ZZZzz | 01:37 | |
*** akwasnie1 has quit IRC | 01:38 | |
*** akwasnie1 has joined #kolla | 01:40 | |
*** akwasnie1 has quit IRC | 01:40 | |
*** sacharya has joined #kolla | 01:54 | |
*** sdake has joined #kolla | 01:56 | |
*** sacharya has quit IRC | 01:59 | |
*** diogogmt has joined #kolla | 02:13 | |
*** signed8bit_ZZZzz is now known as signed8bit | 02:13 | |
*** rhallisey has quit IRC | 02:14 | |
*** sdake has quit IRC | 02:15 | |
*** tzn has joined #kolla | 02:16 | |
*** stvnoyes has quit IRC | 02:21 | |
*** stvnoyes has joined #kolla | 02:21 | |
*** mbound has joined #kolla | 02:26 | |
*** mbound has quit IRC | 02:31 | |
*** sdake has joined #kolla | 02:44 | |
*** achanda has joined #kolla | 02:54 | |
*** cemmason has joined #kolla | 02:55 | |
*** dims has quit IRC | 02:57 | |
*** weiyu has quit IRC | 03:00 | |
*** dims has joined #kolla | 03:07 | |
*** cloudnautique has joined #kolla | 03:07 | |
*** cemmason has quit IRC | 03:08 | |
*** cemmason has joined #kolla | 03:08 | |
*** weiyu has joined #kolla | 03:09 | |
*** cloudnautique has quit IRC | 03:12 | |
*** signed8bit has quit IRC | 03:14 | |
*** dims has quit IRC | 03:14 | |
*** dims has joined #kolla | 03:16 | |
*** weiyu has quit IRC | 03:23 | |
sdake | http://sdake.io/2015/11/11/the-tldr-on-immutable-infrastructure/ | 03:23 |
---|---|---|
*** dims has quit IRC | 03:25 | |
*** weiyu has joined #kolla | 03:27 | |
*** sdake has quit IRC | 03:39 | |
*** sdake has joined #kolla | 03:40 | |
*** mbound has joined #kolla | 04:23 | |
*** mbound has quit IRC | 04:27 | |
*** weiyu has quit IRC | 04:37 | |
*** achanda has quit IRC | 05:04 | |
*** sacharya has joined #kolla | 05:19 | |
*** weiyu_ has joined #kolla | 05:20 | |
*** weiyu_ has quit IRC | 05:34 | |
asalkeld | sdake: seems like lots of people in openstack are all for modifing config "on the go" | 05:36 |
asalkeld | at least a subset of the config - some really makes sense | 05:36 |
asalkeld | personally i am happy with immutable software, less so much config | 05:37 |
sdake | imo that is becuasse htey dont know about ummutaiblity | 05:37 |
asalkeld | meh | 05:37 |
sdake | mdoif yconfig o nthe go - restart containre with new config | 05:39 |
sdake | same outome | 05:40 |
sdake | one with immutabuiltiy one iwthout | 05:40 |
asalkeld | "same outcome" | 05:40 |
*** achanda has joined #kolla | 06:05 | |
openstackgerrit | Michal Rostecki proposed openstack/kolla-mesos: [WIP] Using DCOS library for Marathon https://review.openstack.org/244455 | 06:07 |
*** weiyu has joined #kolla | 06:09 | |
*** achanda has quit IRC | 06:10 | |
*** achanda has joined #kolla | 06:15 | |
*** tpot has quit IRC | 06:18 | |
*** gfidente has quit IRC | 06:21 | |
*** gfidente has joined #kolla | 06:22 | |
*** gfidente has quit IRC | 06:22 | |
*** gfidente has joined #kolla | 06:22 | |
*** ryansb_ has joined #kolla | 06:26 | |
*** ryansb_ has quit IRC | 06:26 | |
*** ryansb_ has joined #kolla | 06:26 | |
*** ryansb has quit IRC | 06:26 | |
*** ryansb_ is now known as ryansb | 06:26 | |
openstackgerrit | Michal Rostecki proposed openstack/kolla-mesos: [WIP] Using DCOS library for Marathon https://review.openstack.org/244455 | 06:33 |
nihilifer | guys, I created a bp regarding ZK https://blueprints.launchpad.net/kolla/+spec/zookeeper | 06:40 |
nihilifer | to use it in all commits regarding ZK | 06:40 |
asalkeld | nihilifer: ok, i thought we were using the "mesos" bp, but doesn't worry me either way | 06:45 |
*** jasonsb has quit IRC | 06:49 | |
*** jasonsb has joined #kolla | 06:51 | |
*** sacharya has quit IRC | 06:54 | |
*** jasonsb has quit IRC | 06:55 | |
*** tfukushima has joined #kolla | 07:13 | |
*** kejlly_ has joined #kolla | 07:16 | |
*** kjelly has quit IRC | 07:18 | |
*** tfukushima has quit IRC | 07:19 | |
*** achanda has quit IRC | 07:20 | |
*** kejlly_ is now known as kjelly | 07:20 | |
*** jasonsb has joined #kolla | 07:20 | |
*** tfukushima has joined #kolla | 07:22 | |
openstackgerrit | Michal Rostecki proposed openstack/kolla: [WIP] Add ZooKeeper support in kolla-ansible https://review.openstack.org/244474 | 07:22 |
*** jasonsb has quit IRC | 07:25 | |
nihilifer | how we should install kazoo? pip or packages? | 07:29 |
nihilifer | or pip for source, packages for binary? | 07:30 |
sdake | the current answer is virtualenv nh | 07:34 |
sdake | nihilifer ping - see PMs pleae | 07:42 |
sdake | for centos binary - pleae use binary pakages | 07:46 |
*** slotti has joined #kolla | 07:46 | |
sdake | i want to stamp otu any remaining pip in binry installs | 07:46 |
*** sacharya has joined #kolla | 07:55 | |
*** sacharya has quit IRC | 07:59 | |
*** tzn has quit IRC | 08:10 | |
openstackgerrit | Steven Dake proposed openstack/kolla: Drop root privileges for mariadb https://review.openstack.org/243480 | 08:13 |
*** egonzalez has joined #kolla | 08:13 | |
nihilifer | @sdake: ok, thx | 08:22 |
*** sdake has quit IRC | 08:24 | |
*** sdake has joined #kolla | 08:25 | |
*** kproskurin has joined #kolla | 08:35 | |
*** tzn has joined #kolla | 08:42 | |
*** achanda has joined #kolla | 08:47 | |
*** tzn has quit IRC | 08:47 | |
*** sdake has quit IRC | 08:49 | |
*** sdake has joined #kolla | 08:49 | |
*** mbound has joined #kolla | 08:51 | |
*** sdake has quit IRC | 09:00 | |
*** mbound has quit IRC | 09:01 | |
*** sdake has joined #kolla | 09:07 | |
*** tfukushima has quit IRC | 09:26 | |
*** tfukushima has joined #kolla | 09:30 | |
*** achanda has quit IRC | 09:34 | |
*** mbound has joined #kolla | 09:38 | |
*** tzn has joined #kolla | 09:43 | |
*** alisonh has quit IRC | 09:45 | |
SamYaple | morning people | 09:45 |
*** openstackgerrit has quit IRC | 09:46 | |
*** openstackgerrit has joined #kolla | 09:46 | |
*** sdake has quit IRC | 09:46 | |
kjelly | morning | 09:49 |
nihilifer | morning SamYaple | 09:49 |
*** tzn has quit IRC | 09:49 | |
*** weiyu has quit IRC | 09:50 | |
nihilifer | SamYaple (or any other Ansible experts too): do you know any good practices how to write tests for Ansible modules? | 09:53 |
*** weiyu has joined #kolla | 09:53 | |
nihilifer | we aldready have hundreds of Python code as modules and the number will grow | 09:54 |
nihilifer | so I'm thinking how we can cover it by init tests | 09:54 |
SamYaple | nihilifer: no | 09:58 |
SamYaple | no good way to write tests | 09:58 |
SamYaple | ansible does some horrible things to that module file | 09:58 |
nihilifer | btw, I'm suffering because of all this imports with "*" which we have to use with Ansible | 09:59 |
SamYaple | nihilifer: you know thats a requirement? | 10:00 |
nihilifer | yes, I know | 10:00 |
SamYaple | its that crazy? | 10:01 |
nihilifer | so I can by only sad about it ;) | 10:01 |
nihilifer | be* | 10:02 |
*** alisonh has joined #kolla | 10:04 | |
*** mbound has quit IRC | 10:05 | |
*** mbound has joined #kolla | 10:07 | |
SamYaple | nihilifer: https://github.com/ansible/ansible/blob/devel/lib/ansible/executor/module_common.py#L96 | 10:10 |
SamYaple | isnt that awful | 10:10 |
nihilifer | omg. why they're doing it to us? | 10:11 |
SamYaple | its so bad | 10:11 |
SamYaple | the first time i saw that i just wanted to throw up | 10:11 |
nihilifer | why we cannot just import modules and objects we need | 10:11 |
nihilifer | like a human beings? :P | 10:11 |
SamYaple | because they actually rewrite that file | 10:12 |
SamYaple | they inject about 1000 lines of code into that file after the fact | 10:12 |
SamYaple | its not an import | 10:12 |
SamYaple | that "import" is a marker to replace a bunch of lines | 10:12 |
nihilifer | ah, ok, I see | 10:13 |
SamYaple | basically that "python file" is only a section of python code, like a jinja2 template | 10:14 |
SamYaple | nihilifer: do you know how to debug the ansible stuff? | 10:15 |
*** openstackgerrit has quit IRC | 10:16 | |
*** pbourke has quit IRC | 10:16 | |
nihilifer | SamYaple: I usually use ansible with ANSIBLE_REMORE_FILES, putting pdb in that file and run it | 10:16 |
*** openstackgerrit has joined #kolla | 10:16 | |
nihilifer | dunno about any better way | 10:16 |
*** pbourke has joined #kolla | 10:17 | |
SamYaple | nihilifer: you mean ANSIBLE_KEEP_REMOTE_FILES ? | 10:17 |
nihilifer | ANSIBLE_KEEP_REMOTE_FILES* | 10:17 |
SamYaple | yea | 10:17 |
nihilifer | yes | 10:17 |
SamYaple | yea thats a good way to do it | 10:17 |
SamYaple | have you ever used rpdb? | 10:17 |
nihilifer | yes | 10:17 |
SamYaple | i tend to use that, cut out the file copy middle man | 10:18 |
nihilifer | rpdb sound good for debugging your own modules | 10:18 |
nihilifer | but no idea how to use it for debugging standard Ansible modules | 10:19 |
SamYaple | well there are two kinds of "modules" | 10:19 |
SamYaple | action plugins, and actual modules | 10:19 |
SamYaple | action plugins run on the deployment host side (template and copy are action plugins) | 10:19 |
SamYaple | modules run on the destination side | 10:19 |
SamYaple | the _modules_ can all me compied so you have a local clone of them | 10:20 |
SamYaple | be* | 10:20 |
SamYaple | so if you want to debug the docker module, just copy it into your libraries directory | 10:20 |
SamYaple | then your playbooks will use that version of the docker module and you can edit it like it was your own | 10:20 |
*** sacharya has joined #kolla | 10:21 | |
nihilifer | sounds good, thanks for this tip | 10:22 |
*** sacharya has quit IRC | 10:25 | |
*** sdake has joined #kolla | 10:25 | |
openstackgerrit | Merged openstack/kolla: Drop root for Horizon service https://review.openstack.org/243400 | 10:30 |
openstackgerrit | Merged openstack/kolla: Move the mariadb expect code to a script https://review.openstack.org/243479 | 10:31 |
openstackgerrit | Merged openstack/kolla: Added Ubuntu support for Vagrant https://review.openstack.org/243635 | 10:31 |
SamYaple | How would everyone feel if we allowed build.py to just print a summary and log each indvidual containers log to an actual file? | 10:31 |
SamYaple | as optional behaviour | 10:31 |
SamYaple | in the gate I want just a summary and then a directory with all the logs | 10:32 |
kproskurin | I acttulay though about same thing. Current build.py logging is kinda bad | 10:33 |
kproskurin | I’d make it default behaviour | 10:33 |
SamYaple | kproskurin: its way better than it was before :D | 10:34 |
SamYaple | as for making it default behaviour, well see... probably not though | 10:34 |
SamYaple | the issue is where would those logs go for default behaviour? | 10:34 |
SamYaple | /var/logs? then build.py would require elevated permissions | 10:34 |
kproskurin | Current one is useless. If you dont add | tee -a or something you cant really read all logs anyway | 10:34 |
SamYaple | see above | 10:35 |
kproskurin | If we talking about using build.py from git repo - I’d put them in users home OR in /tmp/ | 10:36 |
kproskurin | if tools was instelled by pip - I’d create a dir like /var/log/kolla-tools/build or something | 10:36 |
SamYaple | kproskurin: neither of those places are an FHS place for logs | 10:37 |
kproskurin | var/log not FHS place for logs?.. | 10:38 |
SamYaple | oh im sorry I read that as /lib | 10:38 |
*** jmccarthy has joined #kolla | 10:38 | |
kproskurin | :-D | 10:38 |
SamYaple | no that would be fine | 10:38 |
kproskurin | But still, I consider using build.py from git as a “temp action” so /tmp is fine, imo. But we sould encourage users to install pip tools | 10:40 |
kproskurin | kolla tools by pip, I mean | 10:40 |
*** sdake has quit IRC | 10:41 | |
*** sdake has joined #kolla | 10:41 | |
openstackgerrit | Merged openstack/kolla: Fix --retries option to kolla-build https://review.openstack.org/243449 | 10:43 |
openstackgerrit | Sam Yaple proposed openstack/kolla: Convert gate to Ansible setup https://review.openstack.org/244538 | 10:45 |
*** tzn has joined #kolla | 10:46 | |
weiyu | Hi Sam Yaple, I opened a bug again https://bugs.launchpad.net/kolla/+bug/1469891 | 10:49 |
openstack | Launchpad bug 1469891 in kolla "some cinder services enter restarting state" [High,New] - Assigned to Ryan Hallisey (rthall14) | 10:49 |
*** tzn has quit IRC | 10:51 | |
SamYaple | weiyu: no its a new bug. and its a bug with packaging for RDO | 10:56 |
SamYaple | and im 100% we will run into it again | 10:56 |
*** tfukushima has quit IRC | 10:56 | |
*** sdake has quit IRC | 10:57 | |
*** sdake has joined #kolla | 10:57 | |
*** alisonh has quit IRC | 10:58 | |
weiyu | Maybe we can fix it, Like this https://review.openstack.org/#/c/189974/5 | 10:59 |
SamYaple | weiyu: this was already fixed, and the the packages were updated and the fix was removed | 11:00 |
SamYaple | the solution here is to not use rdo | 11:00 |
SamYaple | that packaging is alwasy going to be busted | 11:00 |
SamYaple | you cant package 5 minutes behind trunk | 11:01 |
*** alisonh has joined #kolla | 11:04 | |
openstackgerrit | Merged openstack/kolla-mesos: Add a simplistic bootstrap script to install mesos (AIO) https://review.openstack.org/242911 | 11:07 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla: Add playbook for hosts pre-deployment checks (ports, files) https://review.openstack.org/239882 | 11:11 |
weiyu | Sample: Rdo already repair the cinder dependencies? | 11:12 |
*** sdake has quit IRC | 11:13 | |
*** sdake has joined #kolla | 11:13 | |
*** dims_ has joined #kolla | 11:14 | |
*** weiyu has quit IRC | 11:14 | |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla: Add playbook for hosts pre-deployment checks (ports, files) https://review.openstack.org/239882 | 11:18 |
*** jasonsb has joined #kolla | 11:23 | |
*** jasonsb has quit IRC | 11:28 | |
*** sdake has quit IRC | 11:29 | |
*** tzn has joined #kolla | 11:46 | |
*** tzn has quit IRC | 11:51 | |
*** weiyu_ has joined #kolla | 12:12 | |
*** weiyu_ has quit IRC | 12:15 | |
*** v1k0d3n has quit IRC | 12:40 | |
*** rhallisey has joined #kolla | 12:42 | |
*** sacharya has joined #kolla | 12:45 | |
*** tzn has joined #kolla | 12:47 | |
*** sacharya has quit IRC | 12:49 | |
*** tzn has quit IRC | 12:52 | |
kproskurin | SamYaple: Will you do build.py change regarding loging? | 13:02 |
openstackgerrit | Merged openstack/kolla: Drop root privileges for mariadb https://review.openstack.org/243480 | 13:13 |
SamYaple | kproskurin: eventually I will have too | 13:15 |
SamYaple | if you are offering to implement something yo uare welcome too | 13:15 |
SamYaple | vbel: are you avaialble to talk about the precheck tasks for a moment? | 13:16 |
kproskurin | SamYaple: I just dont want to dublicate work | 13:16 |
vbel | SamYaple: yes, sure | 13:16 |
SamYaple | Im just looking at the pattern that is going on where you specify the dict of variabels and then loop over them | 13:17 |
SamYaple | It doesn't seem like its saving any tpying and im wondering if it would be better to just be listing out each task | 13:17 |
SamYaple | That way there is not a seperate task for failures | 13:17 |
SamYaple | Youve done more with it than me, have you tested just having a task per check? | 13:18 |
vbel | yes, it is possible too. Also wait_for will be ok, otherwise I cannot get status from it | 13:18 |
vbel | that's why i used other utilities because they give status in results | 13:18 |
SamYaple | sure but using shell is actually not best practice for ansible | 13:19 |
SamYaple | which is why we removed it from Kolla | 13:19 |
vbel | yes, true. I will stick to simple loop. | 13:19 |
*** dims_ has quit IRC | 13:24 | |
vbel | SamYaple, I will make a new patchset with this approach | 13:25 |
*** jasonsb has joined #kolla | 13:25 | |
*** dims has joined #kolla | 13:26 | |
*** jasonsb has quit IRC | 13:29 | |
SamYaple | ok vbel thanks for the chat | 13:30 |
mandre | SamYaple: +1 on splitting the build logs per image | 13:33 |
mandre | i have a preference for /tmp but you can put them in /var/log for the pip installed kolla if you really want to | 13:33 |
*** dwalsh has joined #kolla | 13:35 | |
*** diogogmt has quit IRC | 13:37 | |
*** diogogmt has joined #kolla | 13:40 | |
*** sdake has joined #kolla | 13:46 | |
openstackgerrit | Diogo Monteiro proposed openstack/kolla: Get kolla path from settings when provisioning box https://review.openstack.org/244670 | 13:57 |
*** weiyu_ has joined #kolla | 14:00 | |
*** diogogmt has quit IRC | 14:01 | |
*** sdake has quit IRC | 14:02 | |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla: Add playbook for hosts pre-deployment checks (ports, files) https://review.openstack.org/239882 | 14:04 |
SamYaple | mandre: i dont think it should be default | 14:05 |
SamYaple | mandre: the way i planned it for the gate was to have a logdir option, so i could direct the logs to the proper place | 14:05 |
*** sdake has joined #kolla | 14:06 | |
*** cemmason has quit IRC | 14:13 | |
SamYaple | anyone with centos know why the gate is hanging on ssh? | 14:14 |
SamYaple | is there some firewall rules preventing connecting to your own ip over ssh? | 14:14 |
SamYaple | ie: if i setup the appropriate keys can I connect to the ip on a local interface over ssh on centos by default? | 14:14 |
*** cemmason has joined #kolla | 14:15 | |
vbel | SamYaple, I can rename service_ports to just ports, service_files to files in vars. Wonder if there will be unclear for anyone? | 14:17 |
SamYaple | i think looping over all the items would be confusing since it doesn't actually save any lines of code | 14:18 |
SamYaple | for example if you had a named task per port yo uwere checking you wouldn't need all those loops | 14:18 |
SamYaple | but im not sure if you discovered a downside to that approach | 14:18 |
vbel | SamYaple: I have submitted patchset with one task per check | 14:20 |
vbel | just wonder on naming of dictionaries | 14:21 |
*** sdake has quit IRC | 14:21 | |
vbel | it works this way too | 14:21 |
*** sdake has joined #kolla | 14:22 | |
vbel | SamYaple, or you mean different thing like just not using dicts | 14:22 |
SamYaple | vbel: yes building dicts | 14:22 |
SamYaple | its not clear to me the benefit they provide but they do add complexity | 14:22 |
*** dwalsh has quit IRC | 14:22 | |
vbel | i see | 14:23 |
*** weiyu_ has quit IRC | 14:26 | |
*** dwalsh has joined #kolla | 14:27 | |
*** itsuugo has joined #kolla | 14:30 | |
vbel | SamYaple, I will submit one more patchset, without dicts. Will take me some time | 14:32 |
openstackgerrit | Sam Yaple proposed openstack/kolla: Move USER operation after footer https://review.openstack.org/244684 | 14:37 |
*** sdake has quit IRC | 14:37 | |
*** sdake has joined #kolla | 14:38 | |
SamYaple | vbel: if you find it doesn't work for whatever reason, just make a comment as to why its not a good idea or why the current implementation is better even though it has a bit more added complexity | 14:38 |
SamYaple | just some comment explaining why the implemenation was chosen over the traditional ansible tasks | 14:38 |
vbel | SamYaple: ok | 14:41 |
*** itsuugo has quit IRC | 14:43 | |
*** tzn has joined #kolla | 14:47 | |
*** tzn has quit IRC | 14:48 | |
vbel | SamYaple, there are 50 port checks, each uses 7 lines without loop (350), with loop: dict 4 * 50 + 7 (207+) | 14:50 |
vbel | just wanted to save time and separate logic from data :) | 14:51 |
*** ssurana has joined #kolla | 14:51 | |
*** sdake has quit IRC | 14:53 | |
SamYaple | vbel: what what information does it fail with? anything sepcific about that task? or just the prot number? | 14:54 |
*** ashishjain has joined #kolla | 14:55 | |
vbel | failed: [control01] => (item={'interface': u'enp0s3', 'name': 'Keystone Public', 'hostgroup': 'keystone', 'port': u'5000'}) => {"elapsed": 1, "failed": true, "item": {"hostgroup": "keystone", "interface": "enp0s3", "name": "Keystone Public", "port": "5000"}} | 14:55 |
vbel | msg: Timeout when waiting for 192.168.10.10:5000 to stop. | 14:55 |
vbel | so it has interface or address, port, host group and name | 14:55 |
vbel | you mean we can save on "- name" | 14:56 |
*** ashishjain has joined #kolla | 14:56 | |
vbel | ok, 50 port checks * 6 lines | 14:56 |
SamYaple | vbel: im not worried about a few extra lines, im trying to figure out readability here | 14:58 |
SamYaple | which one is esiest to read and understand | 14:58 |
SamYaple | the looping thing isn't complicated, but its not immdeidiately understandable | 14:58 |
vbel | yes, it gives a lot of skipped at least | 14:59 |
*** dwalsh has quit IRC | 14:59 | |
*** dims has quit IRC | 15:01 | |
*** jasonsb has joined #kolla | 15:01 | |
vbel | SamYaple, with normal task it is: | 15:02 |
vbel | TASK: [prechecks | Checking Keystone Admin port] ****************************** | 15:02 |
vbel | skipping: [control02] | 15:02 |
vbel | failed: [control01] => {"elapsed": 1, "failed": true} | 15:02 |
vbel | msg: Timeout when waiting for 192.168.10.10:35357 to stop. | 15:02 |
*** dims has joined #kolla | 15:07 | |
*** diogogmt has joined #kolla | 15:07 | |
*** diogogmt has quit IRC | 15:07 | |
*** diogogmt has joined #kolla | 15:10 | |
*** tzn has joined #kolla | 15:12 | |
*** tzn has quit IRC | 15:15 | |
*** dwalsh has joined #kolla | 15:15 | |
*** ssurana has quit IRC | 15:16 | |
*** signed8bit has joined #kolla | 15:18 | |
*** ssurana has joined #kolla | 15:21 | |
*** dwalsh has quit IRC | 15:34 | |
*** sdake has joined #kolla | 15:35 | |
*** tzn has joined #kolla | 15:35 | |
*** sdake_ has joined #kolla | 15:39 | |
*** sdake has quit IRC | 15:39 | |
sdake_ | rhallisey note debuntian has a idifferent path to chmod | 15:40 |
*** tzn has quit IRC | 15:40 | |
rhallisey | oh really | 15:40 |
rhallisey | I'm still having an issue with: | 15:40 |
rhallisey | %kolla ALL=(root) NOPASSWD: /usr/bin/chown -R rabbitmq\: /var/lib/rabbitmq | 15:40 |
rhallisey | that doesn't give privileges | 15:41 |
sdake_ | on centos that works | 15:42 |
sdake_ | on ubunt yu need /bin/chown | 15:42 |
SamYaple | /bin/chown | 15:42 |
SamYaple | da | 15:42 |
rhallisey | doesn't work for me | 15:42 |
rhallisey | still asking for a pw | 15:42 |
SamYaple | rhallisey: do you have a patchset? | 15:43 |
*** sdake has joined #kolla | 15:43 | |
rhallisey | no. I thought we don't like wip patches | 15:43 |
SamYaple | i was just asking to see what you are talking about | 15:44 |
rhallisey | k | 15:44 |
SamYaple | i dont think we have a problem with them... | 15:44 |
rhallisey | will just post it | 15:44 |
SamYaple | i do them | 15:44 |
sdake | wip pathes are fine | 15:44 |
sdake | as slong as they ar done being wip they are marked as such | 15:44 |
ashishjain | SamYaple: Hi | 15:45 |
SamYaple | 14:15:38 < SamYaple> anyone with centos know why the gate is hanging on ssh? | 15:45 |
SamYaple | 14:15:54 < SamYaple> is there some firewall rules preventing connecting to your own ip over ssh? | 15:45 |
SamYaple | 14:16:20 < SamYaple> ie: if i setup the appropriate keys can I connect to the ip on a local interface over ssh on centos by default? | 15:45 |
SamYaple | sdake: ^ | 15:45 |
SamYaple | ashishjain: hi | 15:45 |
sdake | SamYaple yes that works on my box | 15:45 |
ashishjain | SamYaple: I am trying to setup kolla aio on my laptop and it has got only network interface. I am trying the use the dummy interface as in https://github.com/openstack/kolla/blob/master/tests/deploy_aio.sh#L28 | 15:46 |
sdake | SamYaple dont know why gat would hang on ssh no | 15:46 |
SamYaple | sdake: ok thanks | 15:46 |
ashishjain | However I observe that their are some issues with setting up the external network wherein I am unable to ping the router | 15:46 |
SamYaple | sdake: https://review.openstack.org/#/c/244538/ patch in question | 15:46 |
ashishjain | and even unable to ssh into the VM | 15:46 |
sdake | SamYaple which gte shoudl i look at | 15:47 |
SamYaple | ashishjain: yea the dummy interface like the gate is using doesn't have external connectivity at all | 15:47 |
SamYaple | sdake: the ones that are failing :P | 15:47 |
*** sdake_ has quit IRC | 15:47 | |
SamYaple | they all fail the same way | 15:47 |
SamYaple | ashishjain: the dummy interface is only there to ensure the ansible stuff deployed. the gate is a WIP and im rewritting the network stuff there. | 15:48 |
ashishjain | SamYaple: Okay so that means it is not possible to simulate floatingip address at all? | 15:48 |
SamYaple | ashishjain: you definetely don't want to be following the gate around | 15:48 |
SamYaple | yes you can with a single interface, but its kinda complicated and has its problems | 15:48 |
sdake | SamYaple it looks ike seliux may be in enforcing mode | 15:48 |
SamYaple | but you can make it work | 15:48 |
sdake | try setenforce 0 | 15:48 |
SamYaple | sdake: how can you tell? | 15:48 |
ashishjain | SamYaple: I get it now.. I have been breaking my head for last 2 days to make it work :( | 15:48 |
sdake | "facter_selinux_config_mode": "enforcing", | 15:49 |
SamYaple | ashishjain: the way I do it is like this.... | 15:49 |
* SamYaple goes to make a pastebin | 15:49 | |
openstackgerrit | Ryan Hallisey proposed openstack/kolla: Drop root privileges for rabbitmq https://review.openstack.org/244721 | 15:50 |
SamYaple | ashishjain: http://paste.openstack.org/show/478680/ | 15:50 |
SamYaple | so eth0 has no ip, br1 has an ip | 15:51 |
SamYaple | then i have a veth pair | 15:51 |
SamYaple | i give the neutron interface veth-ovs | 15:51 |
*** achanda has joined #kolla | 15:51 | |
rhallisey | ^^ if anyone has an idea let me know | 15:52 |
sdake | rhallisey chown \: | 15:53 |
sdake | not chown : | 15:53 |
sdake | sudo treats : as a special character | 15:53 |
sdake | according to hte manp age it must be escaped | 15:53 |
rhallisey | so you're saying it should be 'rabbitmq\:' | 15:53 |
rhallisey | that's removes the syntax error, but still asks for a password | 15:54 |
SamYaple | rhallisey: look at mariadb | 15:54 |
ashishjain | SamYaple: How do you go about creating the br1 - is it through brctl util? | 15:54 |
SamYaple | that works | 15:54 |
SamYaple | ashishjain: brctl addbr br1 | 15:54 |
*** jtriley has joined #kolla | 15:54 | |
rhallisey | I copied it | 15:55 |
rhallisey | not in the review, but in previous iterations | 15:55 |
*** JoseMello has joined #kolla | 15:56 | |
sdake | definatelly should be rabbitmq:\ | 15:56 |
sdake | \: | 15:56 |
SamYaple | sdake: so just `setenforce 0`? | 15:57 |
SamYaple | im suprised the gate wroks at all then for centos | 15:57 |
sdake | SamYaple that will turn off seliux i cn't guarantee you have selinux o on | 15:57 |
sdake | youcan sell for sure by running geetenforce | 15:57 |
sdake | in the gate | 15:57 |
sdake | getenforce | 15:57 |
sdake | this will print out selinux stte | 15:58 |
sdake | i dont know what htat factor state thign is | 15:58 |
sdake | but it sure looks like it is indicating selinux is enabled | 15:58 |
rhallisey | still asking for a pw :( | 15:58 |
*** dwalsh has joined #kolla | 15:59 | |
sdake | my next suggestion is not to use a wildcard | 15:59 |
sdake | the sehll will expect the wildcard into the true name | 16:00 |
sdake | sudo wont know the wildcardname though | 16:00 |
sdake | therefore sudo and the shell wont match up | 16:00 |
*** signed8bit is now known as signed8bit_ZZZzz | 16:00 | |
sdake | rhallisey ^^ | 16:00 |
sdake | rhallisey make sense? | 16:01 |
*** achanda has quit IRC | 16:02 | |
rhallisey | ya I've tried this already, but will do it again | 16:02 |
sdake | comon folks we got 1 day to go to knock out the security blueprint !! ;) | 16:02 |
rhallisey | sdake, I've literally copied the mariadb part | 16:02 |
sdake | rhallisey dont use wildcards in the sudo call or sudoers file | 16:02 |
rhallisey | and replaced rabbitmq | 16:02 |
rhallisey | still asking for pw | 16:02 |
sdake | ya its a tricky little thing | 16:03 |
*** achanda has joined #kolla | 16:03 | |
rhallisey | the only thing that's worked has been: %kolla ALL=(root) NOPASSWD: /usr/bin/chown rabbitmq | 16:03 |
rhallisey | the only thing that's worked has been: %kolla ALL=(root) NOPASSWD: /usr/bin/chown | 16:03 |
rhallisey | ^ the second one | 16:03 |
*** achanda has quit IRC | 16:04 | |
*** signed8bit_ZZZzz is now known as signed8bit | 16:04 | |
sdake | i'd prefer to hve the arogument | 16:04 |
sdake | s | 16:04 |
sdake | hmm i bet . is a special character in sudo | 16:05 |
sdake | let me read the man pge | 16:05 |
SamYaple | the arguement is a requirement | 16:06 |
sdake | The following characters must be escaped with a backslash (‘\’) when used | 16:06 |
sdake | as part of a word (e.g. a user name or host name): ‘!’, ‘=’, ‘:’, ‘,’, | 16:06 |
sdake | ‘(’, ‘)’, ‘\’. | 16:06 |
sdake | rhallisey when you get the erland lange up post anothe review please | 16:07 |
SamYaple | rhallisey: whats actually failing btw? | 16:08 |
sdake | SamYaple sudo isn't honoring the sudoers file | 16:08 |
SamYaple | sdake: how is that being determined? | 16:08 |
openstackgerrit | Michal Rostecki proposed openstack/kolla: [WIP] Use trusts in heat.conf https://review.openstack.org/236198 | 16:08 |
sdake | it pritn a password request | 16:08 |
sdake | bts, mariadb is good to go ;) | 16:09 |
rhallisey | one second | 16:10 |
*** vbel has quit IRC | 16:18 | |
*** vbel has joined #kolla | 16:18 | |
openstackgerrit | Sam Yaple proposed openstack/kolla: Convert gate to Ansible setup https://review.openstack.org/244538 | 16:19 |
SamYaple | sdake: https://review.openstack.org/#/c/244684/ | 16:19 |
*** egonzalez has quit IRC | 16:19 | |
sdake | SamYaple ugh - we will need to keep that in mind | 16:20 |
SamYaple | sdake: its cool, the USER operation as the very last step is fine | 16:22 |
SamYaple | it won't affect anything else | 16:22 |
sdake | rhallisey id the gettign rid of the wilcard fix he problem | 16:23 |
rhallisey | ok back sorry | 16:23 |
*** kbyrne has joined #kolla | 16:23 | |
SamYaple | sdake: the setenforce thing seemed to be correct | 16:24 |
*** egonzalez has joined #kolla | 16:24 | |
SamYaple | sdake: gate broke deploying rabbitmq, but thats probbly unrelated | 16:25 |
rhallisey | sdake, %kolla ALL=(root) NOPASSWD: /usr/bin/chown rabbitmq\: /var/lib/rabbitmq, /bin/chown rabbitmq\: /var/lib/rabbitmq | 16:25 |
rhallisey | ^ that didn't work | 16:25 |
sdake | hwon -R? | 16:26 |
rhallisey | I've tried with -R. It didn't make a difference. I'm still getting ask for a pw :( | 16:26 |
rhallisey | ugh | 16:26 |
sdake | rhallisey extend start is: | 16:27 |
sdake | sudo chown -R rabbitmq: /var/lib/rabbitmq | 16:27 |
sdake | run -it bash IP_of_registry:port_of_registry/kollaglue/centos-binary-rabbitmq | 16:28 |
sdake | run -it IP:port/kollaglue/entos/binary/rabbitmq bash | 16:29 |
sdake | grep kolla /etc/group | 16:29 |
*** blahRus has joined #kolla | 16:29 | |
sdake | rhallisey it definately wontwork without he -R | 16:30 |
sdake | lets make sure we make it look right before debugging | 16:30 |
rhallisey | I added the -r to sudo | 16:30 |
rhallisey | now it works | 16:30 |
rhallisey | yes! | 16:30 |
*** dwalsh has quit IRC | 16:30 | |
rhallisey | every time I tested with -R I dropped the '\;'. The false negative threw me off | 16:31 |
sdake | ya sudoers file is tricky | 16:32 |
rhallisey | sdake, thank you | 16:32 |
sdake | enjoy | 16:32 |
openstackgerrit | Ryan Hallisey proposed openstack/kolla: Drop root privileges for rabbitmq https://review.openstack.org/244721 | 16:33 |
rhallisey | ehh need bp hold a second.. | 16:33 |
openstackgerrit | Ryan Hallisey proposed openstack/kolla: Drop root privileges for rabbitmq https://review.openstack.org/244721 | 16:34 |
sdake | i also submitted a -1 which needs attention | 16:34 |
rhallisey | kk | 16:35 |
*** ssurana has quit IRC | 16:36 | |
SamYaple | sdake: why do you not have both chown paths in mariadb but ryan does in rabbitmq? | 16:36 |
SamYaple | oh nvm | 16:37 |
SamYaple | you do | 16:37 |
openstackgerrit | Ryan Hallisey proposed openstack/kolla: Drop root privileges for rabbitmq https://review.openstack.org/244721 | 16:38 |
*** sacharya has joined #kolla | 16:39 | |
*** sdake has quit IRC | 16:40 | |
*** cloudnautique has joined #kolla | 16:40 | |
SamYaple | oh wait sdake i was looking at the wrong job | 16:40 |
SamYaple | setenforce 0 ? | 16:40 |
SamYaple | sudo: setenforce: command not found | 16:40 |
kproskurin | Guys, any reason why horizon apache don’t send logs to rsyslog? | 16:42 |
*** sdake has joined #kolla | 16:42 | |
SamYaple | kproskurin: most of the logging isn't working properly | 16:42 |
SamYaple | kproskurin: it just hasn't been setup properly yet | 16:42 |
SamYaple | feel free to submit a patch | 16:43 |
kproskurin | I actually runs on a problem with ubuntu horizon on master | 16:43 |
kproskurin | it cant create log in /var/log/apache2 | 16:43 |
kproskurin | not sure why | 16:43 |
SamYaple | sdake: ^ | 16:43 |
kproskurin | permission denied but dir permission are ok | 16:43 |
sdake | i canread | 16:43 |
sdake | thanks | 16:44 |
sdake | kproskurin i'll fix the problem | 16:44 |
*** slotti has quit IRC | 16:44 | |
kproskurin | selinux? apparmor? | 16:44 |
SamYaple | sdake: well I asked you a qeustion before and you did not respond | 16:44 |
sdake | i was asleep :) | 16:44 |
SamYaple | hence the ping for this | 16:44 |
kproskurin | sdake: care to explain this problem in few words? | 16:44 |
kproskurin | im curios | 16:44 |
sdake | sure | 16:44 |
SamYaple | and by before, i mean like 2 minutes ago | 16:44 |
sdake | we dded USEr to the continers | 16:44 |
sdake | SamYaple ack | 16:44 |
sdake | the USER drops permissions in the container | 16:45 |
SamYaple | you said 'setenforce 0' but thats not working | 16:45 |
sdake | SamYaple setenforce was just a 100% guess | 16:45 |
kproskurin | sdake: that I understand. What blocking permission? selinux? | 16:45 |
SamYaple | right its not a valid command | 16:45 |
rhallisey | not too bad a guess tho | 16:45 |
SamYaple | 16:42:04 < SamYaple> sudo: setenforce: command not found | 16:45 |
sdake | setenforce is not a valid command? | 16:45 |
sdake | sec | 16:45 |
sdake | i'm not logged in to my lap | 16:46 |
sdake | but it maybe /usr/sbin/setenforce | 16:46 |
sdake | or /sbin/setenforce | 16:46 |
sdake | which is nto in the gate path | 16:46 |
SamYaple | thats probably it | 16:46 |
SamYaple | can you 'which' and tell me the path? | 16:46 |
SamYaple | someone*? | 16:46 |
sdake | rhallisey type which setenforce | 16:47 |
rhallisey | /usr/sbin/setenforce | 16:47 |
SamYaple | thanks | 16:47 |
sdake | kproskurin what is blocking the command is standard unix permissions | 16:47 |
sdake | hoirizon runs as the horizon user, /var/log/apache2 is not howned by horizon | 16:47 |
kproskurin | sdake: That’s not true | 16:48 |
SamYaple | sdake: horizon should run as the apache2 user i think.. | 16:48 |
kproskurin | && chown -R horizon: /var/run/apache2 /var/log/apache2 | 16:48 |
SamYaple | so should keystone for that matter | 16:48 |
kproskurin | in Dockfile | 16:48 |
sdake | SamYaple hard to tell what is more secure | 16:49 |
sdake | horizon has less perissions | 16:49 |
kproskurin | as an example http://fpaste.org/289727/14473469/ | 16:49 |
sdake | the non USER continer runs as apahe and horizon | 16:49 |
SamYaple | sdake: its not about security, its about how it works | 16:50 |
SamYaple | apache starts processes as the horizon user | 16:50 |
openstackgerrit | Vladislav Belogrudov proposed openstack/kolla: Add playbook for hosts pre-deployment checks (ports, files) https://review.openstack.org/239882 | 16:50 |
sdake | kproskurin run docker exec id | 16:51 |
sdake | and ls -ld /var/lib/apache2 | 16:51 |
kproskurin | uid=1000(horizon) gid=1001(horizon) groups=1001(horizon),1000(kolla) | 16:51 |
kproskurin | $ ls -ld /var/lib/apache2 | 16:51 |
kproskurin | drwxr-xr-x 5 root root 4096 Nov 12 15:35 /var/lib/apache2 | 16:51 |
openstackgerrit | Sam Yaple proposed openstack/kolla: Convert gate to Ansible setup https://review.openstack.org/244538 | 16:51 |
kproskurin | may be you mean /var/log/apache ? | 16:52 |
sdake | that dir shouldbe owned by horiozn | 16:52 |
sdake | [09:48:25] <kproskurin> && chown -R horizon: /var/run/apache2 /var/log/apache2 | 16:52 |
sdake | oh /var/lib | 16:53 |
kproskurin | sdake: yep | 16:53 |
kproskurin | log dir IS owned by horizon | 16:53 |
kproskurin | and have w permission | 16:53 |
kproskurin | you can see iit here: http://fpaste.org/289727/14473469/ | 16:54 |
sdake | line 9 should work | 16:55 |
kproskurin | Do we on the same page? :-) | 16:55 |
kproskurin | but it doesnt | 16:55 |
kproskurin | it’s look like a selinux-like problem | 16:55 |
sdake | ae you running wiht selinux? | 16:56 |
kproskurin | On a host system - no. | 16:58 |
kproskurin | I just wondering | 16:58 |
SamYaple | vbel: looking good :) i like it | 16:59 |
SamYaple | Again, for keystone and horizon we should be running as the httpd or apache2 user, _not_ the service user | 16:59 |
SamYaple | thats important | 16:59 |
*** daneyon has joined #kolla | 17:00 | |
vbel | SamYaple: another 300-400 lines. I am happy to have learned touch typing :) | 17:01 |
SamYaple | vbel: dvorak is life | 17:01 |
*** daneyon has quit IRC | 17:01 | |
*** daneyon has joined #kolla | 17:02 | |
*** daneyon_ has joined #kolla | 17:03 | |
openstackgerrit | Sam Yaple proposed openstack/kolla: Fix namespace regression for neutron https://review.openstack.org/244768 | 17:06 |
*** daneyon has quit IRC | 17:06 | |
*** sdake_ has joined #kolla | 17:07 | |
*** sdake has quit IRC | 17:09 | |
*** exploreshaifali has joined #kolla | 17:13 | |
*** rmart04 has joined #kolla | 17:16 | |
*** jtriley has quit IRC | 17:17 | |
*** ssurana has joined #kolla | 17:20 | |
*** rmart04 has quit IRC | 17:21 | |
*** rmart04 has joined #kolla | 17:21 | |
*** rmart04_ has joined #kolla | 17:26 | |
*** itsuugo has joined #kolla | 17:28 | |
*** aojea_ has joined #kolla | 17:28 | |
*** kproskurin has quit IRC | 17:28 | |
*** rmart04 has quit IRC | 17:28 | |
*** rmart04_ is now known as rmart04 | 17:28 | |
*** sdake_ has quit IRC | 17:28 | |
*** sdake has joined #kolla | 17:29 | |
*** sdake has quit IRC | 17:30 | |
*** sdake has joined #kolla | 17:31 | |
openstackgerrit | Merged openstack/kolla: Move USER operation after footer https://review.openstack.org/244684 | 17:31 |
*** itsuugo has quit IRC | 17:31 | |
*** aojea_ has quit IRC | 17:31 | |
*** gfidente has quit IRC | 17:33 | |
*** gfidente has joined #kolla | 17:34 | |
*** mbound has quit IRC | 17:38 | |
*** egonzalez has quit IRC | 17:39 | |
*** cloudnautique has quit IRC | 17:41 | |
*** cloudnautique has joined #kolla | 17:41 | |
*** cloudnautique has joined #kolla | 17:42 | |
*** jtriley has joined #kolla | 17:44 | |
ashishjain | SamYaple: Sorry went away for sometime could not continue the discussion. | 17:48 |
ashishjain | SamYaple: continuing on the paste you provided earlier http://paste.openstack.org/show/478680/ | 17:48 |
*** dwalsh has joined #kolla | 17:49 | |
*** jtriley has quit IRC | 17:50 | |
ashishjain | 1) add a linux bridge 2) Create a veth-pair 3) add veth-bridge to br1 4) In globals.yml specify neutron_external_interface:veth-ovs | 17:50 |
ashishjain | 5) add br1 to eth0 | 17:52 |
ashishjain | Got few questions on it | 17:53 |
ashishjain | 1) So does this means we end up using eth0 as internal as well as external interface? | 17:53 |
*** cloudnautique has quit IRC | 17:53 | |
ashishjain | 2) Why eth0 does not have an ip but br1 has one, I was hoping it would be opposite? | 17:53 |
*** sdake has quit IRC | 17:54 | |
*** dwalsh has quit IRC | 17:54 | |
*** cloudnautique has joined #kolla | 17:56 | |
*** sdake has joined #kolla | 18:02 | |
pbourke | can anyone tell me at what point /var/lib/kolla/dev gets created on the host | 18:03 |
*** signed8bit is now known as signed8bit_ZZZzz | 18:03 | |
pbourke | ok it seems docker creates it | 18:06 |
*** dwalsh has joined #kolla | 18:08 | |
SamYaple | pbourke: thats not a file, but a folder | 18:08 |
pbourke | i know | 18:09 |
SamYaple | pbourke: its a mountpoint so we can share the log dev | 18:09 |
SamYaple | ashishjain: yes that means you have one interface for internal and external | 18:09 |
pbourke | rsyslog root drop is turning out to be a little tricky | 18:09 |
ashishjain | when I run the script tools/cleanup-host isn't it supposed to clean all the various interfaces created br-int ,br-ex,qbr..? | 18:09 |
SamYaple | pbourke: thats cool, nothing external accesses rsyslog pbourke | 18:09 |
SamYaple | i wouldnt have a problem if that must stay root | 18:09 |
SamYaple | just saying | 18:10 |
pbourke | ok, I think it can be done just not as straight forward as the others | 18:10 |
SamYaple | ashishjain: no | 18:10 |
ashishjain | SamYaple: why is that? | 18:10 |
SamYaple | ashishjain: all of those interfaces are controlled by openvswitch | 18:10 |
pbourke | sdake: are we still aiming for root drop work to be finished by tomorrow | 18:10 |
ashishjain | SamYaple: but once I remove all the containers, that means I have removed all the openvswitch service, shouldn't it be cleaned up as well? | 18:11 |
SamYaple | ashishjain: the openvswitch is a module loaded into the kernel | 18:11 |
ashishjain | SamYaple:okay. | 18:11 |
SamYaple | ashishjain: so you have to cleanup the ports before removing the database that knows about the ports | 18:11 |
SamYaple | otherwise you have to reboot | 18:11 |
SamYaple | there is no way to clean them up at that point | 18:12 |
ashishjain | SamYaple: Okay got it | 18:12 |
ashishjain | SamYaple: Talking about your paste, the globals.yml needs two network interfaces one with ip(internal) and one without ip(external) | 18:13 |
ashishjain | so here veth-ovs becomes the external interface, | 18:13 |
ashishjain | without ip ofcourse | 18:13 |
SamYaple | br1 is the network interface | 18:13 |
ashishjain | ohhh okay that is really interesting | 18:15 |
ashishjain | In the past I have done this by using a Libvirt VM but only after creating network bridges but never tried the approach as highlighter by you | 18:16 |
*** tzn has joined #kolla | 18:17 | |
ashishjain | SamYaple: I will cover all that we have discussed into this https://bugs.launchpad.net/kolla/+bug/1514227 | 18:17 |
openstack | Launchpad bug 1514227 in kolla "Update Documentation for bare metal deployment of kolla with single network interface " [Critical,Triaged] - Assigned to Ashish (ashish-jain14) | 18:17 |
SamYaple | ashishjain: thank you. i never got around to writting documentatino for doing a single interface | 18:17 |
*** sdake has quit IRC | 18:18 | |
SamYaple | the thing is, its making a comlpicated networking situation more complicated and without a good grasp on all the technologies going on its impossible to explain or debug | 18:18 |
ashishjain | SamYaple: So do you mean it is not a good approach to setup a dev environment on a bare metal with a single NIC? | 18:19 |
ashishjain | SamYaple: Will it be better if I use a Virtual Box or Libvirt based VM which will provide me as many NIC as I want ? | 18:20 |
SamYaple | ashishjain: no its a good approach for a dev environment if thats all you have | 18:21 |
SamYaple | ashishjain: Vms are slower for dev, but gives a much easier understanding of the networ | 18:21 |
SamYaple | for the record, the setup i described for you is what i use exlusively | 18:22 |
ashishjain | SamYaple: Thanks for this it is really helpful and I am hoping I will make it work. BTW I do agree VM's make life easier when you are short of NIC's and make stuff easier to debug and understand. | 18:23 |
ashishjain | However I will still continue with the approach which you have suggested | 18:23 |
*** achanda has joined #kolla | 18:26 | |
*** jpeeler has quit IRC | 18:30 | |
*** rhallisey_ has joined #kolla | 18:31 | |
*** rhallisey has quit IRC | 18:33 | |
*** itsuugo has joined #kolla | 18:37 | |
*** signed8bit_ZZZzz is now known as signed8bit | 18:41 | |
ashishjain | SamYaple: I got a wireless interface wlan0 and when I try to add interface using the following command "brctl addif br1 wlan0" | 18:42 |
ashishjain | I get an error saying "can't add wlan0 to bridge br1: Operation not supported" | 18:42 |
ashishjain | have you faced a similar situation | 18:42 |
*** jpeeler has joined #kolla | 18:44 | |
*** jpeeler has joined #kolla | 18:44 | |
SamYaple | ashishjain: yea you can't bridge wireless connections | 18:45 |
SamYaple | 3 mac vs 4 mac in the header | 18:45 |
SamYaple | its pretty boring stuff | 18:45 |
SamYaple | long storry short, you can't do it | 18:45 |
ashishjain | SamYaple: Aaah....that makes life little more tough now ;) | 18:47 |
*** jpeeler has quit IRC | 18:47 | |
*** rmart04 has quit IRC | 18:47 | |
SamYaple | if you want to look into it you _can_ make it work but you have to make tweaks to the wireless side that most routers cant to | 18:48 |
SamYaple | cant do* | 18:48 |
SamYaple | the feature you want is 4addr | 18:48 |
SamYaple | iw dev wlan0 set 4addr on | 18:48 |
SamYaple | but that will almost certianly break your stuff | 18:48 |
SamYaple | i don't recommend trying to do it | 18:48 |
ashishjain | SamYaple: Yes it is going to make already complicated networking(atleast for me ) very complicated. | 18:49 |
*** sdake has joined #kolla | 18:49 | |
sdake | pbourke aiming but not looking likely | 18:50 |
*** sdake has quit IRC | 18:51 | |
*** tzn has quit IRC | 18:55 | |
*** jpeeler has joined #kolla | 19:00 | |
*** ashishjain has quit IRC | 19:02 | |
*** tzn has joined #kolla | 19:05 | |
*** ashishjain has joined #kolla | 19:14 | |
*** rhallisey_ has quit IRC | 19:15 | |
*** bmace has quit IRC | 19:15 | |
*** bmace has joined #kolla | 19:15 | |
*** rhallisey_ has joined #kolla | 19:17 | |
*** achanda has quit IRC | 19:21 | |
*** achanda has joined #kolla | 19:21 | |
*** sdake has joined #kolla | 19:22 | |
*** ashishjain has quit IRC | 19:23 | |
*** ashishjain has joined #kolla | 19:26 | |
ashishjain | SamYaple: I loose my net connectivity as soon as I add network interface to bridge | 19:28 |
ashishjain | even if the bridge is setup with IP addr it does not help and network remains unreachable. | 19:29 |
ashishjain | Here are the steps which I have taken 1) add bridge br1 2) create veth pair 3) add one veth pair to br1 4) add eth0 to br1 5) assign an ip to br1 | 19:30 |
ashishjain | in the end I see network is unreachable | 19:30 |
SamYaple | ashishjain: this is basic linux networking stuff | 19:36 |
SamYaple | but you need to remove the ip from eth0 | 19:36 |
SamYaple | possible setup your default route for br1 | 19:37 |
ashishjain | SamYaple: eth0 is set to manual and hence no ip | 19:38 |
*** itsuugo has quit IRC | 19:38 | |
*** suro-patz has joined #kolla | 19:43 | |
*** tzn has quit IRC | 19:44 | |
*** sdake_ has joined #kolla | 19:46 | |
*** vbel has quit IRC | 19:47 | |
*** vbel has joined #kolla | 19:47 | |
*** ashishjain has quit IRC | 19:47 | |
*** sdake has quit IRC | 19:49 | |
*** rmart04 has joined #kolla | 19:51 | |
*** rmart04 has quit IRC | 20:06 | |
*** sdake_ has quit IRC | 20:14 | |
*** JoseMello has quit IRC | 20:14 | |
*** mbound has joined #kolla | 20:16 | |
*** jtriley has joined #kolla | 20:17 | |
*** sdake has joined #kolla | 20:17 | |
*** tzn has joined #kolla | 20:35 | |
*** rhallisey_ is now known as rhallisey | 20:35 | |
*** signed8bit is now known as signed8bit_ZZZzz | 20:41 | |
*** signed8bit_ZZZzz is now known as signed8bit | 20:43 | |
*** tzn has quit IRC | 20:44 | |
*** sdake has quit IRC | 20:54 | |
*** ashishjain has joined #kolla | 21:03 | |
*** suro-patz has quit IRC | 21:10 | |
*** sdake has joined #kolla | 21:11 | |
*** sdake_ has joined #kolla | 21:15 | |
*** sdake has quit IRC | 21:17 | |
*** itsuugo has joined #kolla | 21:17 | |
*** gfidente has quit IRC | 21:17 | |
*** achanda has quit IRC | 21:23 | |
*** achanda has joined #kolla | 21:26 | |
*** achanda has quit IRC | 21:26 | |
*** achanda has joined #kolla | 21:27 | |
*** diogogmt has quit IRC | 21:27 | |
*** tzn has joined #kolla | 21:32 | |
*** shardy has quit IRC | 21:39 | |
*** tzn has quit IRC | 21:44 | |
*** tzn has joined #kolla | 21:47 | |
*** achanda has quit IRC | 21:54 | |
*** achanda has joined #kolla | 21:54 | |
*** jtriley_ has joined #kolla | 21:58 | |
*** jasonsb has quit IRC | 22:00 | |
*** jtriley has quit IRC | 22:00 | |
*** jtriley_ has quit IRC | 22:02 | |
*** rhallisey has quit IRC | 22:03 | |
*** exploreshaifali has quit IRC | 22:05 | |
*** itsuugo has quit IRC | 22:11 | |
*** sacharya has quit IRC | 22:19 | |
*** dims_ has joined #kolla | 22:23 | |
*** dims has quit IRC | 22:25 | |
*** ashishjain has quit IRC | 22:25 | |
*** dwalsh has quit IRC | 22:32 | |
*** sdake_ has quit IRC | 22:44 | |
*** blahRus has quit IRC | 23:16 | |
*** sdake has joined #kolla | 23:23 | |
*** sdake_ has joined #kolla | 23:26 | |
*** sdake has quit IRC | 23:28 | |
*** achanda has quit IRC | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!