*** JRobinson__ is now known as JRobinson__afk | 00:11 | |
*** miguelgrinberg has quit IRC | 00:26 | |
*** darrenc is now known as darrenc_afk | 00:26 | |
*** JRobinson__afk is now known as JRobinson__ | 00:47 | |
*** darrenc_afk is now known as darrenc | 00:58 | |
*** miguelgrinberg has joined #openstack-ansible | 01:28 | |
*** markvoelker has joined #openstack-ansible | 01:30 | |
*** markvoelker has quit IRC | 01:35 | |
*** javeriak has joined #openstack-ansible | 01:50 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Remove all of the rpc_release.link files https://review.openstack.org/196497 | 02:28 |
---|---|---|
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Updated tempest isolation options https://review.openstack.org/195225 | 02:36 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Updated keystone to use fernet as the default https://review.openstack.org/195226 | 02:37 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Updated default fernet key usage https://review.openstack.org/196499 | 02:38 |
*** sigmavirus24_awa is now known as sigmavirus24 | 03:15 | |
*** markvoelker has joined #openstack-ansible | 03:19 | |
*** markvoelker has quit IRC | 03:23 | |
*** javeriak has quit IRC | 03:31 | |
*** sdake has joined #openstack-ansible | 03:32 | |
*** sdake has quit IRC | 03:36 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 03:38 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 03:39 | |
*** sdake has joined #openstack-ansible | 03:39 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 03:49 | |
*** sdake_ has joined #openstack-ansible | 03:58 | |
*** sdake has quit IRC | 04:02 | |
*** JRobinson__ is now known as JRobinson__afk | 04:09 | |
openstackgerrit | Merged stackforge/os-ansible-deployment: Added flag to instruct yaprt to ignore tempest https://review.openstack.org/195232 | 04:36 |
openstackgerrit | Merged stackforge/os-ansible-deployment: Added options for enabling instance_passwords https://review.openstack.org/195222 | 04:42 |
*** JRobinson__afk is now known as JRobinson__ | 05:07 | |
*** markvoelker has joined #openstack-ansible | 05:08 | |
*** markvoelker has quit IRC | 05:12 | |
*** shausy has joined #openstack-ansible | 05:43 | |
*** javeriak has joined #openstack-ansible | 06:19 | |
*** markvoelker has joined #openstack-ansible | 06:56 | |
*** markvoelker has quit IRC | 07:01 | |
evrardjp | good morning everyone | 08:16 |
*** javeriak has quit IRC | 08:41 | |
*** markvoelker has joined #openstack-ansible | 08:45 | |
*** JRobinson__ has quit IRC | 08:47 | |
*** markvoelker has quit IRC | 08:50 | |
odyssey4me | o/ evrardjp | 09:06 |
evrardjp | I have some issues and comments about my last week OSAD deployment... but in overall it's really easy to deploy, so congrats | 09:08 |
*** shausy has quit IRC | 09:11 | |
*** shausy has joined #openstack-ansible | 09:12 | |
openstackgerrit | git-harry proposed stackforge/os-ansible-deployment: Add role system-crontab-coordination https://review.openstack.org/196586 | 09:12 |
odyssey4me | evrardjp oh? this was your first time? | 09:13 |
evrardjp | with osad, yes | 09:14 |
evrardjp | I used rpc in the past | 09:14 |
odyssey4me | ah - which branch did you deploy from? | 09:14 |
evrardjp | kilo | 09:14 |
evrardjp | I guess I'll work with Sam-I-Am on documentation, for the topics "what's next?" | 09:15 |
evrardjp | also on testing about the installation... The current documentation is only talking about testing the web interface, which is definitely not enough... (use Tempest maybe?) | 09:15 |
odyssey4me | evrardjp You could add a topic for feedback to the Thu meeting for discussion. | 09:17 |
odyssey4me | If there are specific enhancements/bugs that need attention, the best feedback is in the form of bugs with the appropriate details. | 09:17 |
odyssey4me | Tempest can be used to test an environment, but it needs some very specific setup which isn't ideal - and if it fails then it doesn't always clean up well either. That said, if some docs were put together on how to use it, that may be quite beneficial. | 09:18 |
svg | good morning evrardjp odyssey4me | 09:23 |
evrardjp | hello svg | 09:23 |
odyssey4me | o/ svg | 09:23 |
svg | evrardjp: did you deploy wit ceph in the picture yet? | 09:23 |
evrardjp | not yet | 09:23 |
evrardjp | we have to fix our internal ceph routing first | 09:24 |
evrardjp | but that's our internal business :p | 09:24 |
evrardjp | no worries, I'll definitely keep you informed | 09:24 |
svg | I got recently some new and good feedback on the review, I need to attend, not sure yet when I will find the time though. | 09:25 |
evrardjp | odyssey4me: I'll feed bugs when I'll have my CLA signed... | 09:25 |
evrardjp | sorry for the delay | 09:25 |
*** fawadkhaliq has joined #openstack-ansible | 09:30 | |
*** vdo has joined #openstack-ansible | 09:33 | |
*** openstackgerrit has quit IRC | 09:53 | |
*** openstackgerrit has joined #openstack-ansible | 09:53 | |
openstackgerrit | Merged stackforge/os-ansible-deployment: Make swift_proxy_vars not a required variable https://review.openstack.org/196012 | 09:55 |
openstackgerrit | Merged stackforge/os-ansible-deployment: Upgrade to ansible 1.9.2 https://review.openstack.org/196144 | 09:56 |
openstackgerrit | Merged stackforge/os-ansible-deployment: Ensure flush-net-cache on local host https://review.openstack.org/196216 | 10:01 |
*** sdake_ is now known as sdake | 10:01 | |
*** uschreiber_ has joined #openstack-ansible | 10:03 | |
*** uschreiber_ has quit IRC | 10:05 | |
*** markvoelker has joined #openstack-ansible | 10:34 | |
*** markvoelker has quit IRC | 10:40 | |
svg | Is there a practical example to be found somewhere on how one would handle traffic to the external vip to be forwarded to the internal one? | 10:40 |
svg | I remain confused on which endpoints *must* be avaailable externally, and which not | 10:40 |
*** subscope has joined #openstack-ansible | 10:42 | |
*** eandersson has joined #openstack-ansible | 10:45 | |
eandersson | Morning | 10:45 |
eandersson | Is support for Keystone V3 planned? | 10:46 |
odyssey4me | eandersson it's already there | 10:46 |
eandersson | Oh | 10:46 |
odyssey4me | svg the public endpoints are what you'd generally want available 'externally' | 10:46 |
odyssey4me | svg whether it's truly external (ie on the internet) would depend on your use-case though | 10:47 |
odyssey4me | eandersson within the plays we largely still make use of the v2 endpoints, but the v3 endpoints are setup and usable | 10:48 |
svg | well, say I'd think that I only need horizon externally | 10:48 |
odyssey4me | svg then that's fine - the other endpoints will only be needed if you're providing access to the API's in a public manner | 10:48 |
*** lkoranda_ has joined #openstack-ansible | 10:49 | |
eandersson | I wonder if the Keystone V3 support is set up so that it can handle domain tokens. :p | 10:50 |
odyssey4me | eandersson we're doing some federation work at the moment which involves working with the v3 API and it seems like everything's working ok - do you have a specific issue that you're seeing? | 10:51 |
svg | !/ IIRC, one needs the spice connection available at least on the pub ip if horizon is used | 10:52 |
openstack | svg: Error: "/" is not a valid command. | 10:52 |
svg | IIRC, one needs the spice connection available at least on the pub ip if horizon is used | 10:52 |
eandersson | We just started to evauluate the use of Ansible, and while viewing the implementation it did not look like it was supported. | 10:52 |
svg | and we als noticed internal components doing calls to the public ip | 10:52 |
*** subscope has quit IRC | 10:52 | |
*** lkoranda has quit IRC | 10:52 | |
*** fawadkhaliq has quit IRC | 10:53 | |
svg | but that might be a biug in neutron | 10:54 |
*** lkoranda_ has quit IRC | 10:55 | |
odyssey4me | svg oh yeah, that is another one that would be useful | 10:56 |
odyssey4me | eandersson ah, ok - are you referring to the Ansible openstack modules, or the stackforge project os-ansible-deployment? | 10:56 |
eandersson | We were looking at the ansible-modules-core modules. | 10:57 |
odyssey4me | svg although we do try to set the various components to use the internal/admin URL's where possible, there are often bugs in the clients or modules which ignore such settings... it would be advisable that you allow your internal environment to access your public endpoints | 10:58 |
eandersson | What is the difference if you mind me asking? :D | 10:58 |
odyssey4me | eandersson ah, this channel is focused on deploying openstack with ansible with https://github.com/stackforge/os-ansible-deployment | 10:59 |
odyssey4me | however, I can inform you that Ansible v2 will include vastly updated modules for working with openstack | 10:59 |
*** lkoranda has joined #openstack-ansible | 10:59 | |
eandersson | That is exactly what we are looking for, so sounds like I am in the right place, but with the wrong idea. :p | 10:59 |
odyssey4me | eandersson: https://github.com/ansible/ansible/blob/devel/CHANGELOG.md has the list of stuff that will be in Ansible v2 | 11:00 |
openstackgerrit | Darren Birkett proposed stackforge/os-ansible-deployment: Handle proxies through environment variables https://review.openstack.org/192717 | 11:00 |
odyssey4me | eandersson we have some docs published from our source tree, fyi: http://osad.readthedocs.org/en/latest/ | 11:02 |
eandersson | Basically we are looking into using Ansible for our orchestration needs. | 11:03 |
eandersson | for Openstack | 11:03 |
eandersson | Thanks | 11:03 |
odyssey4me | eandersson well, that's still a little ambiguous - are you looking to work with an existing openstack environment to do client type tasks like build instances, etc? | 11:04 |
odyssey4me | or are you looking to build your own openstack environment back-end (ie deploy glance, nova, cinder, keystone, etc)? | 11:05 |
eandersson | I would say both =] | 11:06 |
eandersson | but having that said we would probably start with client tasks. | 11:06 |
eandersson | Since we already have our infrastructure. | 11:06 |
odyssey4me | eandersson this project is for the latter, whereas the ansible core modules are for the former | 11:06 |
eandersson | Makes sense. I was just reading up on the documentation. | 11:07 |
eandersson | Thanks for the help odyssey4me. | 11:07 |
odyssey4me | eandersson many of the people in this channel have been involved in the development of the updated ansible core modules too :) | 11:07 |
openstackgerrit | Darren Birkett proposed stackforge/os-ansible-deployment: [WIP] Updated MariaDB to the new release version (10.0) https://review.openstack.org/178259 | 11:07 |
vincent_vdk | svg, the internal components use this ip too afaik | 11:14 |
openstackgerrit | Jesse Pretorius proposed stackforge/os-ansible-deployment: [WIP] Keystone SP configuration https://review.openstack.org/194395 | 11:30 |
evrardjp | svg: we experienced a lot of discrepencies in the past with clients, but remember that you can overwrite endpoints with the clients... just check their CLI in detail... | 11:33 |
*** markvoelker has joined #openstack-ansible | 11:35 | |
*** fawadkhaliq has joined #openstack-ansible | 11:36 | |
*** markvoelker has quit IRC | 11:40 | |
odyssey4me | evrardjp fyi the CLA only applies to code submissions afaik... bug registering or feature requests have no reliance on the CLA | 11:40 |
*** sdake has quit IRC | 11:43 | |
evrardjp | I know, I'm not striclty linked to it... I prefer waiting for a clear management decision on about what I may do or not. Internal policy only, sorry to speak about that on the channel | 11:44 |
evrardjp | Quick question about quotas: I've seen neutron is deployed using the db driver quota so it's easy to adapt quotas with whatever (CLI, SDK...) | 11:45 |
evrardjp | I don't see anything in the configuration of quotas for cinder, I only see something in the role os_cinder, namely seomthing in files/policy.json | 11:46 |
*** fawadkhaliq has quit IRC | 11:46 | |
evrardjp | is this enough to use the CLI to define quotas for cinder? | 11:46 |
evrardjp | configuration of default quotas used to be in cinder.conf | 11:47 |
odyssey4me | evrardjp I'm not entirely sure, but as I recall the config files only ever defined defaults | 11:48 |
evrardjp | yeah | 11:48 |
odyssey4me | you could always override via CLI | 11:48 |
evrardjp | but that's what I am looking for | 11:49 |
evrardjp | defining default cinder values | 11:49 |
evrardjp | policy.json brings the RBAC to who can do what, but not setting anything default, right? | 11:49 |
odyssey4me | evrardjp yep | 11:51 |
odyssey4me | and yeah, I don't see any quota_ entries in the cinder.conf template, which means none are set at the moment | 11:51 |
*** javeriak has joined #openstack-ansible | 11:52 | |
evrardjp | So I guess quota_driver = cinder.quota.DbQuotaDriver could be added in the template :) | 11:52 |
evrardjp | Ok i'll write it in my list | 11:52 |
odyssey4me | evrardjp isn't that a default? | 11:53 |
evrardjp | I thought it was conf | 11:53 |
evrardjp | I'll check | 11:53 |
odyssey4me | evrardjp it's a default value - ie when cinder loads, if there's no alternative conf set then it assumes that it must use that one | 11:54 |
*** markvoelker has joined #openstack-ansible | 11:55 | |
odyssey4me | evrardjp these are all the defaults which are set in the environment we build as we don't provide anything to override a default: https://github.com/openstack/cinder/blob/master/cinder/quota.py#L37-L76 | 11:56 |
evrardjp | I was on it, I was interrupted before sending my message: "you were right, it's the default" | 11:58 |
evrardjp | my point was also about the difference between neutron.conf.j2 and cinder.conf.j2 | 12:00 |
evrardjp | anyway, it will be fine for me | 12:00 |
*** tlian has joined #openstack-ansible | 12:02 | |
*** eandersson has quit IRC | 12:12 | |
openstackgerrit | Jesse Pretorius proposed stackforge/os-ansible-deployment: [WIP] Keystone SP configuration https://review.openstack.org/194395 | 12:25 |
openstackgerrit | Darren Birkett proposed stackforge/os-ansible-deployment: Allow Swift middleware to be set via a variable https://review.openstack.org/181560 | 12:32 |
openstackgerrit | Matt Thompson proposed stackforge/os-ansible-deployment: Use the correct upstream repos. https://review.openstack.org/185099 | 12:37 |
openstackgerrit | Darren Birkett proposed stackforge/os-ansible-deployment: Allow Swift middleware to be set via a variable https://review.openstack.org/181560 | 12:38 |
*** fawadkhaliq has joined #openstack-ansible | 12:47 | |
*** fawadkhaliq has quit IRC | 12:51 | |
openstackgerrit | Jesse Pretorius proposed stackforge/os-ansible-deployment: [WIP] Keystone SP configuration https://review.openstack.org/194395 | 12:56 |
*** javeriak has quit IRC | 12:58 | |
*** jlvillal has quit IRC | 13:08 | |
evrardjp | ok again a question for you... I have a network for public access, that is currently mapped to a vlan on my openstack hosts | 13:13 |
evrardjp | I'd like to give it to neutron as a provider network | 13:13 |
odyssey4me | evrardjp as a floating ip network, as a shared external network, or as a provider network for a particular project? | 13:16 |
evrardjp | shoudl I use the provider_networks in openstack_user_config.yml and create a network with type raw on a bridge that I create on each host or a type vlan ? | 13:16 |
evrardjp | floating ip | 13:16 |
evrardjp | at least for v4 | 13:16 |
odyssey4me | evrardjp is this in addition to other floating ip networks? | 13:16 |
evrardjp | v6 is another story | 13:16 |
evrardjp | nope | 13:17 |
evrardjp | atm I don't have anything setup with OSAD | 13:17 |
evrardjp | so I need a floating IP | 13:17 |
evrardjp | for v4 | 13:17 |
odyssey4me | so this will be your only floating ip network at this stage | 13:17 |
evrardjp | yup | 13:17 |
evrardjp | will there be problems later? | 13:17 |
odyssey4me | typically, although I'm a bit rusty at this stuff, the floating ip network is implemented as a flat network (ie you handle the vlan tagging on the OS - neutron does not do this) | 13:18 |
odyssey4me | but you can do it other ways if you create the network correctlyin neutron | 13:18 |
evrardjp | that completely answers my question... you'd rather do it on a flat net | 13:19 |
evrardjp | :) | 13:19 |
evrardjp | thanksè! | 13:19 |
evrardjp | thanks* | 13:19 |
*** jlvillal has joined #openstack-ansible | 13:19 | |
odyssey4me | Sam-I-Am any thoughts on that? | 13:20 |
evrardjp | was this the purpose of the type "flat" in the openstack_user_config.yml.example? | 13:21 |
Sam-I-Am | odyssey4me: wat | 13:21 |
* Sam-I-Am scrolls back | 13:21 | |
Sam-I-Am | evrardjp: do you want the host or neutron to tag the vlan? | 13:22 |
odyssey4me | flat = host tags the vlan (or it's a default/untagged network on that interface) | 13:23 |
evrardjp | I don't mind, I'd rather do it according to rackspace/OSAD best practices | 13:23 |
evrardjp | if it's a flat, I'll add what's needed on the hosts | 13:24 |
evrardjp | if the best practice is to say to neutron it's a vlan network, I'll adapt myself | 13:24 |
evrardjp | at the end of the openstack_user_config.yml.example there is a flat network | 13:25 |
evrardjp | that uses br-vlan | 13:25 |
evrardjp | it seems that untagged traffic will be used for this network | 13:25 |
Sam-I-Am | its probably best to have neutron do the tagging so you can add more networks later without adjusting the host configuration | 13:25 |
evrardjp | which I disabled, I don't see the point | 13:26 |
evrardjp | (in my system) | 13:26 |
evrardjp | that's what I thought | 13:26 |
evrardjp | so I had a type vlan with range something | 13:26 |
odyssey4me | yeah, that makes more sense | 13:26 |
evrardjp | and in this range, I have a vlan that can be used for my floating ips | 13:26 |
evrardjp | so I planned to have a provider network for that | 13:27 |
evrardjp | so that's the best practice then? | 13:27 |
Sam-I-Am | you can always have 1 flat network on any vlan map | 13:27 |
Sam-I-Am | because its just the untagged vlan | 13:27 |
evrardjp | right | 13:27 |
evrardjp | what do you think about helping operators in the deployment by mentionning something about providers network here: http://osad.readthedocs.org/en/latest/install-guide/targethosts-networkrefarch.html | 13:28 |
evrardjp | most of the people will need a floating IP network at some point, and it's never mentionned... | 13:29 |
Sam-I-Am | two totally different topics | 13:29 |
Sam-I-Am | that page references the host config | 13:29 |
Sam-I-Am | do you want provider networks or floating ips? | 13:31 |
evrardjp | floating IPs | 13:31 |
*** TheIntern has joined #openstack-ansible | 13:31 | |
Sam-I-Am | thats out of the scope of the install guide | 13:32 |
evrardjp | but still, it has to end on the host, there is no magic... | 13:32 |
evrardjp | ok | 13:32 |
Sam-I-Am | you need the br-vlan and br-vxlan | 13:32 |
Sam-I-Am | your tenant networks (vxlan) will use br-vxlan, and your external networks will usually use br-vlan | 13:32 |
Sam-I-Am | although you can do vlan tenant networks too | 13:32 |
Sam-I-Am | but need an additional bridge and mapping | 13:32 |
evrardjp | I fully agree with you | 13:33 |
Sam-I-Am | the ref arch more or less handles the tenant -> router -> external scenario | 13:33 |
evrardjp | and external isn't mentionned in the doc, that's my point | 13:34 |
evrardjp | just mentionning what you just said clarifies everything on the doc | 13:35 |
Sam-I-Am | at some point i'm planning to add a simpler architecture | 13:36 |
Sam-I-Am | the one thats there is from rackspace | 13:36 |
Sam-I-Am | i just dont have the time | 13:36 |
evrardjp | There is no need to have a simpler architecture if this one is fine... The thing is: it wasn't clear for me how to link my tenant networks/routers to outside world, because it wasn't mentionned in the docs... There are so many ways to do it... | 13:39 |
evrardjp | I'll take your advice, use a vlan from br-vlan and define it publicly | 13:39 |
evrardjp | (If I understood correctly) | 13:39 |
Sam-I-Am | yeah, and its the neutron net-create command that defines it as external | 13:41 |
Sam-I-Am | when you use --provider:physical_network | 13:42 |
evrardjp | yeah ofc, but that's standard openstack | 13:44 |
evrardjp | -but | 13:44 |
evrardjp | there was no link for me in terms of best practices, that's just it... I'm used to define br-flat networks for my floating ips... | 13:44 |
evrardjp | and I understand I can do it too with OSAD | 13:45 |
evrardjp | sorry for these questions | 13:45 |
evrardjp | thanks for the help | 13:46 |
Sam-I-Am | hmm | 13:46 |
Sam-I-Am | maybe this is more helpful? | 13:46 |
Sam-I-Am | http://docs.openstack.org/networking-guide/deploy_scenario1b.html | 13:46 |
evrardjp | I was reading 4b | 13:47 |
Sam-I-Am | provider networks dont do floating IPs though | 13:47 |
Sam-I-Am | at least provider networks in the sense of that scenario | 13:47 |
evrardjp | but that's the idea of what I thought that should be linked to the reference implementation of OSAD | 13:47 |
evrardjp | to understand more how to link the two | 13:48 |
Sam-I-Am | that scenario connects vms directly to an external/public network | 13:48 |
Sam-I-Am | it sounded like you wanted 1b, except the external network on which you allocate floating IPs is vlan tagged rather than flat (untagged) | 13:49 |
*** Mudpuppy has joined #openstack-ansible | 13:51 | |
evrardjp | I'll check the network configuration again, including these 1b/4b pages... I want to have IPv6 support, so I'll have to be smart :) | 13:51 |
Sam-I-Am | are you using kilo? | 13:52 |
*** Mudpuppy has quit IRC | 13:52 | |
*** Mudpuppy has joined #openstack-ansible | 13:53 | |
evrardjp | yup | 13:54 |
Sam-I-Am | we havent tested v6 in osad, but i know v6 works in theory in kilo | 13:55 |
Sam-I-Am | i'd be interested to see what happens :) | 13:56 |
Sam-I-Am | palendae: the readthedocs thing just publishes from the osad repo, right? | 13:56 |
evrardjp | that's why I prefer talking with you, staying close to the standard, etc. ;) | 13:56 |
palendae | Sam-I-Am: Yeah, and it's a manual build process right now | 13:57 |
evrardjp | I am using make html myself, but it was easier to give you a public link ;) | 13:57 |
Sam-I-Am | palendae: hmm, we need to tox/automate it up | 13:58 |
Sam-I-Am | probably sooner than later | 13:58 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:58 | |
palendae | Sam-I-Am: We do...but I was waiting for the big tent move | 13:58 |
palendae | RTD's not gonna be a permanent home | 13:59 |
Sam-I-Am | good point | 13:59 |
Sam-I-Am | well, put it on the docket for post-tentage | 13:59 |
*** subscope has joined #openstack-ansible | 13:59 | |
Sam-I-Am | evrardjp: while the install guide doesnt cover creating neutron networks (merely the infrastructure beneath them) i might either link people to the networking guide (legacy/linuxbridge scenario) or draw out the 2 supported neutron architectures (provider only, or provider+tenant) | 14:01 |
Sam-I-Am | not sure yet | 14:01 |
*** fawadkhaliq has joined #openstack-ansible | 14:03 | |
*** subscope has quit IRC | 14:04 | |
cloudnull | Morning | 14:05 |
Sam-I-Am | moo | 14:06 |
*** KLevenstein has joined #openstack-ansible | 14:06 | |
*** fawadkhaliq has quit IRC | 14:08 | |
openstackgerrit | Jesse Pretorius proposed stackforge/os-ansible-deployment: [WIP] Keystone SP configuration https://review.openstack.org/194395 | 14:13 |
evrardjp | Sam-I-Am: I think this would be great for the future | 14:17 |
evrardjp | good morning cloudnull | 14:17 |
*** subscope has joined #openstack-ansible | 14:24 | |
*** jwagner_away is now known as jwagner | 14:25 | |
*** jwagner is now known as jwagner_away | 14:26 | |
*** jwagner_away is now known as jwagner | 14:28 | |
openstackgerrit | Jesse Pretorius proposed stackforge/os-ansible-deployment: [WIP] Keystone SP configuration https://review.openstack.org/194395 | 14:29 |
*** galstrom_zzz is now known as galstrom | 14:33 | |
*** sdake has joined #openstack-ansible | 14:37 | |
*** sdake_ has joined #openstack-ansible | 14:40 | |
*** sdake has quit IRC | 14:43 | |
*** shausy has quit IRC | 14:48 | |
*** fawadkhaliq has joined #openstack-ansible | 14:49 | |
*** fawadk has joined #openstack-ansible | 14:57 | |
*** fawadkhaliq has quit IRC | 15:00 | |
openstackgerrit | Hugh Saunders proposed stackforge/os-ansible-deployment: Create Junit XML Report from tempest run https://review.openstack.org/191103 | 15:07 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 15:10 |
*** KLevenstein has quit IRC | 15:10 | |
*** KLevenstein has joined #openstack-ansible | 15:11 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 15:12 |
openstackgerrit | Hugh Saunders proposed stackforge/os-ansible-deployment: Create Junit XML Report from tempest run https://review.openstack.org/191103 | 15:13 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added in keystone reserved port https://review.openstack.org/196702 | 15:19 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Make swift_proxy_vars not a required variable https://review.openstack.org/196705 | 15:22 |
*** vdo has quit IRC | 15:42 | |
*** vdo has joined #openstack-ansible | 15:50 | |
*** fawadk has quit IRC | 16:01 | |
*** TheIntern has quit IRC | 16:08 | |
*** radek__ has joined #openstack-ansible | 16:12 | |
*** TheIntern has joined #openstack-ansible | 16:16 | |
*** galstrom is now known as galstrom_zzz | 16:17 | |
cloudnull | Cores: there are more than a few items that need reviewing for the upcoming 11.0.4 / 11.1.0 releases . If you have some time it would be great to get some of these things nailed down before too long. | 16:17 |
*** eandersson has joined #openstack-ansible | 16:19 | |
*** fawadkhaliq has joined #openstack-ansible | 16:27 | |
prometheanfire | cloudnull: fancy link? | 16:31 |
cloudnull | https://review.openstack.org/#/q/status:open+project:stackforge/os-ansible-deployment+branch:master,n,z | 16:32 |
cloudnull | https://review.openstack.org/#/q/status:open+project:stackforge/os-ansible-deployment+branch:kilo,n,z | 16:32 |
prometheanfire | neato | 16:33 |
*** radek_ has joined #openstack-ansible | 16:33 | |
*** radek__ has quit IRC | 16:34 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 16:36 |
*** vdo has quit IRC | 16:40 | |
*** radek_ has quit IRC | 16:41 | |
*** Mudpuppy has quit IRC | 16:43 | |
*** Mudpuppy has joined #openstack-ansible | 16:44 | |
*** radek_ has joined #openstack-ansible | 16:47 | |
*** galstrom_zzz is now known as galstrom | 16:52 | |
*** TheIntern has quit IRC | 16:55 | |
*** KLevenstein has quit IRC | 16:57 | |
cloudnull | prometheanfire: of particular interest is https://review.openstack.org/#/c/195853/ which is for fernet | 17:07 |
*** javeriak has joined #openstack-ansible | 17:09 | |
*** javeriak_ has joined #openstack-ansible | 17:12 | |
*** javeriak has quit IRC | 17:14 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:15 | |
*** sdake has joined #openstack-ansible | 17:16 | |
*** KLevenstein has joined #openstack-ansible | 17:16 | |
*** javeriak_ has quit IRC | 17:16 | |
*** sdake_ has quit IRC | 17:20 | |
*** jwagner is now known as jwagner_away | 17:31 | |
*** dontalton has joined #openstack-ansible | 17:32 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Updated the clone process to exclude unneeded files https://review.openstack.org/195399 | 17:40 |
*** abitha has joined #openstack-ansible | 18:00 | |
*** eandersson has quit IRC | 18:01 | |
*** TheIntern has joined #openstack-ansible | 18:01 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:03 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 18:20 |
*** openstackgerrit has quit IRC | 18:30 | |
*** openstackgerrit has joined #openstack-ansible | 18:30 | |
sigmavirus24 | Stupid question | 18:31 |
Sam-I-Am | sigmavirus24: this is new? | 18:32 |
sigmavirus24 | Why can't you find by a uuid in keystone of a user? | 18:32 |
sigmavirus24 | I mean, apparently name+id is fine, or just name alone, but not id alone? | 18:32 |
sigmavirus24 | oh wrong channel | 18:32 |
sigmavirus24 | heh | 18:32 |
cloudnull | heh | 18:43 |
*** fawadkhaliq has quit IRC | 18:44 | |
*** markvoelker_ has joined #openstack-ansible | 18:51 | |
*** markvoelker has quit IRC | 18:52 | |
*** jwagner_away is now known as jwagner | 18:54 | |
*** markvoelker_ has quit IRC | 18:57 | |
*** markvoelker has joined #openstack-ansible | 18:57 | |
*** javeriak has joined #openstack-ansible | 19:02 | |
*** javeriak has quit IRC | 19:06 | |
*** javeriak has joined #openstack-ansible | 19:12 | |
*** fawadkhaliq has joined #openstack-ansible | 19:17 | |
*** fawadk has joined #openstack-ansible | 19:26 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Add support for specifying custom static routes https://review.openstack.org/191020 | 19:26 |
*** fawadkhaliq has quit IRC | 19:27 | |
*** javeriak has quit IRC | 19:33 | |
*** javeriak_ has joined #openstack-ansible | 19:33 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Create Junit XML Report from tempest run https://review.openstack.org/191103 | 19:38 |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Document some of the common scripts https://review.openstack.org/193277 | 19:42 |
*** fawadk has quit IRC | 19:46 | |
palendae | cloudnull: Thansk for that ^ | 19:53 |
*** galstrom is now known as galstrom_zzz | 19:54 | |
*** galstrom_zzz is now known as galstrom | 19:58 | |
*** galstrom is now known as galstrom_zzz | 20:01 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Support an externally hosted keystone https://review.openstack.org/192015 | 20:11 |
cloudnull | palendae: np | 20:12 |
palendae | Sam-I-Am: https://review.openstack.org/#/c/193277/3 eyes on that when you've got time would be appreciated | 20:14 |
Sam-I-Am | palendae: downloading at 1200 baud | 20:15 |
Sam-I-Am | yeah, this needs some work | 20:15 |
palendae | You need some work | 20:16 |
Sam-I-Am | agreed | 20:16 |
*** galstrom_zzz is now known as galstrom | 20:17 | |
palendae | Sam-I-Am: Also made a bug to track moving the docs build stuff to tox: https://bugs.launchpad.net/openstack-ansible/+bug/1469870 | 20:17 |
openstack | Launchpad bug 1469870 in openstack-ansible "Use tox for automating documentation builds" [Undecided,New] | 20:17 |
sigmavirus24 | https://bugs.launchpad.net/openstack-ansible/+bug/1469868 for our next bug triage :D | 20:18 |
openstack | Launchpad bug 1469868 in openstack-ansible "OpenStack Ansible Does Not Ship Glance Metadata Definitions" [Wishlist,New] | 20:18 |
*** dontalton has quit IRC | 20:26 | |
stevelle | miguelgrinberg: has there been any talk of supporting user-provided root/intermediate ca files for https://review.openstack.org/#/c/194474 | 20:27 |
miguelgrinberg | stevelle: not much talk about that patch. We will likely not need it for federation, we'll terminate SSL at the load balancer, like we've been doing. | 20:28 |
miguelgrinberg | the patch supports user-provided certs, but there's nothing to install a CA | 20:29 |
miguelgrinberg | the level of support is similar to what we have for horizon more or less | 20:29 |
cloudnull | sigmavirus24: i dont think the setup.conf for glance packages up https://github.com/openstack/glance/tree/master/etc/metadefs ? | 20:32 |
sigmavirus24 | cloudnull: right, that's the related bug I filed against glance | 20:32 |
cloudnull | ok. | 20:32 |
sigmavirus24 | cloudnull: context, Matt Dorn was asking about metadefs in Glance and osad | 20:33 |
sigmavirus24 | Which made me realize both bugs | 20:33 |
stevelle | miguelgrinberg: definitely not enthusiastic about that detail, but I suppose good enough. | 20:33 |
sigmavirus24 | For now we could track all of those in osad like we do with other files (sort of templated) but I'd really rather not | 20:33 |
sigmavirus24 | I'm chatting in #openstack-glance about the best way to get glance to ship those appropriately | 20:33 |
cloudnull | so fixed in libert? | 20:34 |
cloudnull | :) | 20:35 |
cloudnull | *liberty | 20:35 |
cloudnull | miguelgrinberg: i just posed a review on that patch. | 20:37 |
cloudnull | and id like to see the same pattern made available for other services too. | 20:38 |
cloudnull | eg horizon, spice, repo servers . | 20:38 |
cloudnull | but thats in the future. | 20:38 |
sigmavirus24 | cloudnull: probably | 20:39 |
sigmavirus24 | cloudnull: if I ever find time to work on Glance, etc. again | 20:39 |
cloudnull | :( - sorry. | 20:39 |
* cloudnull knows he a time suck | 20:39 | |
sigmavirus24 | no you're not | 20:39 |
sigmavirus24 | life is | 20:39 |
sigmavirus24 | real life is kicking my ass this last week | 20:40 |
cloudnull | you and me both brother. | 20:40 |
sigmavirus24 | Most people assume my drop in GitHub activity is burn out but it's just RL responsibilities | 20:40 |
cloudnull | well take it slow so it doesn't become burnout. | 20:40 |
miguelgrinberg | cloudnull: yes, saw it. I still have an issue with that patch that I haven't decided how to address. If you upgrade from a no-ssl to an ssl setup, the keystone play fails, because it needs to access the keystone API, so it's a chicken-and-egg situation. | 20:40 |
palendae | sigmavirus24: real life > internet-people's demands | 20:41 |
sigmavirus24 | This is why I work remote though. Secondary caregiving is pretty much the only thing determining why I life here | 20:41 |
sigmavirus24 | palendae: nos hit | 20:41 |
sigmavirus24 | palendae: macports redistributors are super weird | 20:41 |
palendae | sigmavirus24: good to know | 20:41 |
sigmavirus24 | Yeah | 20:41 |
sigmavirus24 | Don't ever have code that's redistributed by macports | 20:41 |
sigmavirus24 | They're assholes | 20:41 |
cloudnull | lol | 20:41 |
palendae | I'll try not to write any useful code | 20:42 |
palendae | Cause then people just want more | 20:42 |
sigmavirus24 | Good idea | 20:42 |
sigmavirus24 | Yeah no joke | 20:42 |
cloudnull | palendae: ++ | 20:42 |
palendae | Feature request? No, fork it and make it yourself | 20:42 |
palendae | Forks welcome | 20:42 |
cloudnull | lol | 20:42 |
sigmavirus24 | palendae: no | 20:42 |
sigmavirus24 | more like a demand to use broken dependencies | 20:42 |
palendae | sigmavirus24: That's how I work | 20:42 |
sigmavirus24 | and introduce new warnings/errors etc to stable versions | 20:43 |
palendae | Well it's macports | 20:43 |
cloudnull | im a fan of making changes so distro like rhel can use things i write. | 20:43 |
palendae | Obviously stable version of thing A + stable version of thing B must automatically work together because stable | 20:43 |
palendae | stable in software should always come with air quotes, too | 20:43 |
stevelle | I want a sticker that says "Fork Away" that I can place just under the github sticker on the laptop | 20:45 |
palendae | Haha | 20:45 |
palendae | Fork and gtfo | 20:45 |
stevelle | Fork yourself | 20:45 |
cloudnull | i have that shirt . | 20:45 |
palendae | I believe GitHub had to change some wording for that | 20:45 |
palendae | Making a fork of a repo used to say "Hardcore forking action" | 20:46 |
lbragstad | keep calm and fork on | 20:47 |
sigmavirus24 | cloudnull: I'm perfectly cool with letting people on distros use my stuff | 20:48 |
sigmavirus24 | I'm not cool with breaking it so packagers don't have to think too hard about packaging it | 20:48 |
sigmavirus24 | that fundamentally doesn't serve the users | 20:49 |
*** galstrom is now known as galstrom_zzz | 21:00 | |
*** JTen has joined #openstack-ansible | 21:05 | |
sigmavirus24 | so cloudnull for the keystone v3 work for federation, I'm going to initially keep compatibility with the old playbook syntax (ensure_tenant, etc.) while adding new syntax (ensure_project, etc.) to replace them to keep the patch small. Then I'll | 21:05 |
sigmavirus24 | submit a second patch to upgrade the playbooks and a final third one to remove the old syntax if that is cool with you | 21:06 |
cloudnull | sounds like a plan to me | 21:07 |
cloudnull | is there any chance to pull in what is going upstream with the os_identity modules ? | 21:07 |
cloudnull | IE https://github.com/ansible/ansible-modules-core/blob/devel/cloud/openstack/os_auth.py | 21:09 |
* cloudnull doesn't know if that ^ even works | 21:09 | |
cloudnull | seems like https://github.com/ansible/ansible-modules-core/blob/devel/cloud/openstack/os_auth.py is missing pieces | 21:11 |
cloudnull | like all of it | 21:11 |
*** radek_ has quit IRC | 21:13 | |
cloudnull | nevermind, its doesn't seem that this is a keystone module upstream that will do much of anything. | 21:14 |
cloudnull | 's/this/there/' | 21:14 |
dstanek | os_auth is very bare bones :-( | 21:15 |
cloudnull | yup | 21:15 |
cloudnull | we should fix that. | 21:15 |
* sigmavirus24 forgot to check | 21:16 | |
dstanek | sigh...i started too, but i've turned by plate into an overflowing mess | 21:16 |
cloudnull | well nevermind it seems its a work in progress | 21:16 |
cloudnull | https://github.com/ansible/ansible-modules-core/pulls?utf8=%E2%9C%93&q=is%3Apr+is%3Aopen+keystone+ | 21:16 |
cloudnull | sigmavirus24: one module is a domain specific module. | 21:16 |
sigmavirus24 | cloudnull: also, I think that's more for using ansible to deploy to clouds | 21:16 |
sigmavirus24 | instead of to deploy clouds | 21:16 |
*** KLevenstein has quit IRC | 21:18 | |
cloudnull | looks like monty has roles for just about all of the keystone related functions. | 21:18 |
*** tlian has quit IRC | 21:18 | |
cloudnull | but anyways, sigmavirus24 your plan of attack is solid | 21:20 |
*** galstrom_zzz is now known as galstrom | 21:23 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 21:24 |
*** javeriak has joined #openstack-ansible | 21:24 | |
openstackgerrit | Kevin Carter proposed stackforge/os-ansible-deployment: Added openstack_kernel options for gc_thresh https://review.openstack.org/196699 | 21:26 |
*** javeriak_ has quit IRC | 21:26 | |
*** galstrom is now known as galstrom_zzz | 21:29 | |
*** galstrom_zzz is now known as galstrom | 21:36 | |
* cloudnull out. | 21:41 | |
cloudnull | have a good night | 21:41 |
*** Mudpuppy has quit IRC | 21:45 | |
*** Mudpuppy has joined #openstack-ansible | 21:46 | |
*** Mudpuppy_ has joined #openstack-ansible | 21:48 | |
*** Mudpuppy has quit IRC | 21:51 | |
*** Mudpuppy_ has quit IRC | 21:52 | |
*** sdake_ has joined #openstack-ansible | 22:01 | |
*** sdake has quit IRC | 22:04 | |
*** jwagner is now known as jwagner_away | 22:13 | |
*** daneyon has joined #openstack-ansible | 22:15 | |
*** tlian has joined #openstack-ansible | 22:16 | |
*** daneyon_ has joined #openstack-ansible | 22:16 | |
*** daneyon has quit IRC | 22:20 | |
*** galstrom is now known as galstrom_zzz | 22:43 | |
*** daneyon_ has quit IRC | 23:00 | |
*** sdake has joined #openstack-ansible | 23:02 | |
*** sdake_ has quit IRC | 23:05 | |
*** JRobinson__ has joined #openstack-ansible | 23:08 | |
*** markvoelker has quit IRC | 23:13 | |
*** TheIntern has quit IRC | 23:23 | |
*** galstrom_zzz is now known as galstrom | 23:29 | |
*** tlian2 has joined #openstack-ansible | 23:47 | |
*** tlian has quit IRC | 23:49 | |
*** markvoelker has joined #openstack-ansible | 23:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!