*** elo has quit IRC | 00:01 | |
*** elo has joined #openstack-ansible | 00:17 | |
*** shoutm has quit IRC | 00:17 | |
*** daneyon_ has quit IRC | 00:19 | |
*** shoutm has joined #openstack-ansible | 00:20 | |
*** shoutm_ has joined #openstack-ansible | 00:29 | |
*** shoutm has quit IRC | 00:32 | |
*** darrenc is now known as darrenc_afk | 00:37 | |
*** markvoelker has joined #openstack-ansible | 00:37 | |
*** markvoelker has quit IRC | 00:42 | |
*** tlian has joined #openstack-ansible | 00:48 | |
*** markvoelker has joined #openstack-ansible | 00:51 | |
*** elo has quit IRC | 00:54 | |
*** darrenc_afk is now known as darrenc | 01:00 | |
*** k_stev has quit IRC | 01:22 | |
*** abitha has quit IRC | 01:38 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 01:44 |
---|---|---|
*** javeriak has joined #openstack-ansible | 02:00 | |
*** javeriak has quit IRC | 02:04 | |
*** sdake_ has joined #openstack-ansible | 02:09 | |
*** sdake has quit IRC | 02:13 | |
*** shoutm_ has quit IRC | 02:38 | |
prometheanfire | cloudnull: hoe many should I expect a night? | 02:40 |
*** shoutm has joined #openstack-ansible | 02:49 | |
*** markvoelker has quit IRC | 03:01 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 03:21 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 03:24 |
*** fawadkhaliq has joined #openstack-ansible | 03:26 | |
*** sdake has joined #openstack-ansible | 03:28 | |
*** sdake_ has quit IRC | 03:32 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adding docs for HAProxy SSL configuration https://review.openstack.org/224980 | 03:34 |
*** sdake_ has joined #openstack-ansible | 03:38 | |
*** sdake_ has quit IRC | 03:39 | |
*** sdake_ has joined #openstack-ansible | 03:40 | |
*** sdake_ has quit IRC | 03:40 | |
*** sdake_ has joined #openstack-ansible | 03:40 | |
*** sdake has quit IRC | 03:41 | |
*** sdake_ is now known as sdake | 03:48 | |
*** shoutm_ has joined #openstack-ansible | 04:00 | |
*** markvoelker has joined #openstack-ansible | 04:02 | |
*** shoutm has quit IRC | 04:02 | |
*** markvoelker has quit IRC | 04:06 | |
*** woodard has quit IRC | 04:08 | |
*** abitha has joined #openstack-ansible | 04:28 | |
*** fawadkhaliq has quit IRC | 04:50 | |
*** tlian has quit IRC | 04:54 | |
*** shoutm has joined #openstack-ansible | 04:55 | |
*** shoutm_ has quit IRC | 04:59 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Install and configure chrony for time sync https://review.openstack.org/225006 | 04:59 |
*** shoutm_ has joined #openstack-ansible | 05:17 | |
*** shoutm has quit IRC | 05:17 | |
*** fawadkhaliq has joined #openstack-ansible | 05:17 | |
*** shoutm has joined #openstack-ansible | 05:20 | |
*** shoutm_ has quit IRC | 05:22 | |
*** openstackgerrit has quit IRC | 05:31 | |
*** openstackgerrit has joined #openstack-ansible | 05:31 | |
*** shausy has joined #openstack-ansible | 05:32 | |
*** abitha has quit IRC | 05:36 | |
*** abitha has joined #openstack-ansible | 05:45 | |
*** sdake has quit IRC | 05:49 | |
*** javeriak has joined #openstack-ansible | 06:00 | |
*** shoutm has quit IRC | 06:03 | |
*** markvoelker has joined #openstack-ansible | 06:03 | |
*** shoutm has joined #openstack-ansible | 06:06 | |
*** markvoelker has quit IRC | 06:07 | |
*** javeriak has quit IRC | 06:10 | |
*** palendae has quit IRC | 06:25 | |
*** dolphm has quit IRC | 06:26 | |
*** b3rnard0 has quit IRC | 06:26 | |
*** abitha has quit IRC | 06:26 | |
*** jwagner_away has quit IRC | 06:27 | |
*** jroll has quit IRC | 06:27 | |
*** jwagner_away has joined #openstack-ansible | 06:27 | |
*** dolphm has joined #openstack-ansible | 06:27 | |
*** eglute has quit IRC | 06:27 | |
*** jwagner_away is now known as jwagner | 06:27 | |
*** palendae has joined #openstack-ansible | 06:28 | |
*** b3rnard0 has joined #openstack-ansible | 06:29 | |
*** jroll has joined #openstack-ansible | 06:33 | |
*** eglute has joined #openstack-ansible | 06:33 | |
*** shoutm has quit IRC | 06:40 | |
*** shoutm has joined #openstack-ansible | 06:45 | |
*** shausy has quit IRC | 07:11 | |
*** fawadkhaliq has quit IRC | 07:30 | |
*** fawadkhaliq has joined #openstack-ansible | 07:36 | |
*** gparaskekevas has joined #openstack-ansible | 07:38 | |
*** markvoelker has joined #openstack-ansible | 08:04 | |
*** markvoelker has quit IRC | 08:08 | |
*** javeriak has joined #openstack-ansible | 08:20 | |
*** shoutm has quit IRC | 08:36 | |
*** javeriak has quit IRC | 08:37 | |
*** javeriak has joined #openstack-ansible | 09:16 | |
*** javeriak has quit IRC | 09:18 | |
tiagogomes | morning, I finish installing OpenStack but I can't create a tenant: | 09:27 |
tiagogomes | [tiagogomes@localhost ~]$ keystone tenant-create --name demo --description "Demo Tenant" | 09:27 |
tiagogomes | The resource could not be found. (HTTP 404) (Request-ID: req-1d87cd36-313f-49a5-9312-abdc1dacc237) | 09:27 |
*** javeriak has joined #openstack-ansible | 09:28 | |
*** javeriak_ has joined #openstack-ansible | 09:29 | |
*** javeriak has quit IRC | 09:32 | |
evrardjp | mhayden: I like the ideas you've got the time to work on: the inventory-manage group visibility, the lxc container improvement, the security... | 09:40 |
evrardjp | mhayden: however for the chrony, I'm not sure about where you are getting at... it's mentionned in the documentation that you should have your ntp configured (we are using ntpdate in cron because we are disappointed by ntpd in the past) | 09:41 |
evrardjp | so why adding chrony? | 09:42 |
evrardjp | please note that I'd happy to learn more about chrony. | 09:42 |
evrardjp | when I'll have time ;) | 09:42 |
*** markvoelker has joined #openstack-ansible | 10:04 | |
*** markvoelker has quit IRC | 10:10 | |
odyssey4me | tiagogomes you should be using the openstack client instead of the keystone client | 10:11 |
*** fawadkhaliq has quit IRC | 10:15 | |
*** javeriak has joined #openstack-ansible | 10:19 | |
*** javeriak_ has quit IRC | 10:22 | |
*** javeriak has quit IRC | 10:24 | |
*** javeriak has joined #openstack-ansible | 10:25 | |
*** javeriak has quit IRC | 10:35 | |
*** javeriak has joined #openstack-ansible | 10:35 | |
*** javeriak has quit IRC | 10:40 | |
*** fawadkhaliq has joined #openstack-ansible | 10:55 | |
*** markvoelker has joined #openstack-ansible | 11:21 | |
*** markvoelker has quit IRC | 11:26 | |
*** jaypipes has joined #openstack-ansible | 11:28 | |
tiagogomes | Now I can't launch instances. On nova-compute logs I see an `NovaException: Unexpected vif_type=binding_failed`error. Not sure what's the problem but it seems network related | 11:29 |
mattt | tiagogomes: andymccr hit this the other day | 11:34 |
tiagogomes | oh, let's hope that he shares a solution | 11:36 |
andymccr | thats usually if the physical network you are trying to set it up on isn't setup right or cant be used then you will get that error. I'm guessing nova compute said "no valid host found" | 11:37 |
tiagogomes | yep | 11:37 |
andymccr | it means nova cant use the neutron its trying to use - i think its quite a vague explanation :) but it really depends a lot on what networks are setup etc. | 11:38 |
tiagogomes | but which one? I have severals. I am a bit confused at the moment, on my openstack_user_config I specified a flat, a vlan and a vxlan network. Which network is chosen for tenant traffic | 11:38 |
andymccr | tiagogomes: did you set up neutron networks? using the neutron commands? | 11:39 |
andymccr | tiagogomes: also if you have all 3 of those setup you probably have an error there - you shouldn't have 2 networks on the same physical interface. | 11:40 |
andymccr | e.g. the container_bridge for each provider network should be different | 11:40 |
andymccr | that could be your issue - i have seen that, the sample conf just shows some example networks so if you use all 3 it will probably not work | 11:41 |
tiagogomes | right, I was also hoping that I could use the same physical interface for the management network and for the VM data network | 11:42 |
*** javeriak has joined #openstack-ansible | 11:52 | |
andymccr | tiagogomes: i think that should work ok | 11:53 |
mgariepy | good morning everyone | 11:55 |
*** javeriak_ has joined #openstack-ansible | 12:03 | |
*** javeriak has quit IRC | 12:04 | |
*** gparaskekevas has quit IRC | 12:12 | |
*** tobasco has quit IRC | 12:13 | |
*** javeriak_ has quit IRC | 12:14 | |
*** javeriak has joined #openstack-ansible | 12:17 | |
*** javeriak has quit IRC | 12:19 | |
*** javeriak has joined #openstack-ansible | 12:19 | |
*** markvoelker has joined #openstack-ansible | 12:20 | |
*** javeriak_ has joined #openstack-ansible | 12:22 | |
*** javeriak has quit IRC | 12:23 | |
mhayden | evrardjp: ah, valid question -- chrony has been more reliable for most folks than ntpd (which has burned me multiple times) | 12:29 |
evrardjp | yeah same for us mhayden | 12:29 |
evrardjp | and good morning everyone I missed! | 12:30 |
* mhayden wishes everyone a happy friday | 12:30 | |
mhayden | evrardjp: chrony comes with a daemon and a client but it has some updated ntp bits | 12:31 |
mhayden | the daemon will sync time and serve as a ntp server | 12:32 |
mhayden | evrardjp: i might need help on the security part soon! :) | 12:41 |
*** woodard has joined #openstack-ansible | 12:43 | |
evrardjp | cloudnull: you're there? | 12:47 |
*** jaypipes is now known as leakypipes | 12:48 | |
evrardjp | mhayden: sure | 12:48 |
*** fawadkhaliq has quit IRC | 12:50 | |
*** woodard has quit IRC | 12:54 | |
*** woodard has joined #openstack-ansible | 12:54 | |
*** javeriak_ has quit IRC | 12:54 | |
*** fawadkhaliq has joined #openstack-ansible | 12:59 | |
*** javeriak has joined #openstack-ansible | 13:01 | |
mhayden | just sent a little inquiry to the ML about ntp and openstack-ansible -- would love feedback | 13:04 |
mattt | mhayden: just rolled in, thanks for sending | 13:14 |
mhayden | anything for you, mattt | 13:15 |
*** woodard has quit IRC | 13:25 | |
*** woodard has joined #openstack-ansible | 13:25 | |
*** woodard_ has joined #openstack-ansible | 13:27 | |
*** woodard has quit IRC | 13:30 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Set Keystone httpd processes and threads to match upstream https://review.openstack.org/225145 | 13:33 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adds group support to inventory-manage.py https://review.openstack.org/224977 | 13:39 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Install and configure chrony for time sync https://review.openstack.org/225006 | 13:40 |
*** woodard has joined #openstack-ansible | 13:41 | |
*** woodard_ has quit IRC | 13:43 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adding docs for HAProxy SSL configuration https://review.openstack.org/224980 | 13:45 |
*** openstackgerrit has quit IRC | 13:46 | |
*** openstackgerrit has joined #openstack-ansible | 13:46 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Temporarily pin os_client_config https://review.openstack.org/225156 | 13:50 |
* mhayden hugs mattt for the osc_password fixy fix | 13:52 | |
cloudnull | evrardjp: i am now | 13:54 |
mattt | mhayden: yeah, not sure how long it's going to take to fix upstream :-. | 13:56 |
mattt | :-/ | 13:56 |
*** markvoelker has quit IRC | 13:57 | |
odyssey4me | mattt yeah, it seems like there is not yet a decision on how to fix it appropriately | 13:57 |
odyssey4me | some are advocating for a revert of a commit, others are advocating for a fix on top of the breaking commit | 13:57 |
odyssey4me | meanwhile, the rest of us just get on with it by pinning until they sort it out :p | 13:58 |
odyssey4me | thanks for the patch - hopefully it does the trick, otherwise we can do it the other way I usually do it which is simply in requirements.txt :) | 13:59 |
mattt | seems to be working locally | 13:59 |
*** galstrom_zzz is now known as galstrom | 14:00 | |
*** davhou has joined #openstack-ansible | 14:00 | |
*** markvoelker_ has joined #openstack-ansible | 14:00 | |
evrardjp | cloudnull: I've seen there was a dict merge in the update_template (or whatever the name is) | 14:00 |
odyssey4me | mattt what's odd though is that the failures are happening with 1.6.0 | 14:01 |
evrardjp | I was wondering if this could be used somewhere else, like in a vars plugin | 14:01 |
evrardjp | I'm not an ansible expert, but I think this could be interesting | 14:01 |
*** spotz_zzz is now known as spotz | 14:01 | |
*** KLevenstein has joined #openstack-ansible | 14:01 | |
evrardjp | sadly I really don't have time these days, production is close ;) | 14:02 |
mattt | odyssey4me: yeah that just pins the os_client_config, not openstackclient | 14:02 |
evrardjp | I'll have a look at it later and will ask you questions if you don't mind | 14:02 |
odyssey4me | mattt ah, my eyeballs didn't catch that :p | 14:02 |
mattt | mhayden: while you're at it, maybe you can make repo-build playbook go faster too :D | 14:03 |
mattt | i seem to wait around for taht far too much | 14:03 |
odyssey4me | yeah, I see that os_client_config 1.7.1 is the broken one | 14:03 |
mhayden | hah same here | 14:03 |
mattt | odyssey4me: that's what they say, but it's actually 1.7.0 | 14:04 |
odyssey4me | mattt mhayden so we could potentially do without the repo build altogether if we do all our python installs into python venvs | 14:05 |
odyssey4me | mattt I'm looking at the jobs that failed yesterday and the version of the wheel built is 1.7.1 ? | 14:06 |
mattt | odyssey4me: i dunno, 1.7.0 was released 2 days ago, i tried downgrading to that but still had issues | 14:06 |
mattt | odyssey4me: but you are right we're getting 1.7.1 now | 14:06 |
mattt | odyssey4me: would we prebuild the venvs ? | 14:06 |
*** arbrandes has joined #openstack-ansible | 14:07 | |
odyssey4me | mattt mhayden the venv install idea was something cloudnull and I were discussing as becoming more and more urgently needed - otherwise we keep hitting stupid bugs like https://bugs.launchpad.net/openstack-ansible/+bug/1488315 | 14:07 |
openstack | Launchpad bug 1488315 in openstack-ansible trunk "The python-requests package is pulled in by apt via dependency" [High,Confirmed] - Assigned to Jesse Pretorius (jesse-pretorius) | 14:07 |
mattt | yeah that's been a long-standing issue :( | 14:07 |
odyssey4me | cloudnull did you put any time into that, or should mhayden go ahead and do a proof of concept to figure it out, then spec it? | 14:08 |
mhayden | odyssey4me: cloudnull is currently deploying coffee via openstack-keurig | 14:09 |
mattt | hehe | 14:09 |
odyssey4me | lol | 14:09 |
*** Mudpuppy has joined #openstack-ansible | 14:10 | |
cloudnull | upgrade complete | 14:11 |
cloudnull | :) | 14:12 |
cloudnull | odyssey4me: i have an instance up running all the things in venvs | 14:12 |
cloudnull | I should write a spec | 14:12 |
* cloudnull has been lazy | 14:13 | |
odyssey4me | wow, that must have been some beer session! | 14:13 |
cloudnull | it wasn't hard I took from what we're already doing in tempest | 14:13 |
cloudnull | but and modified the init scripts to support it | 14:14 |
odyssey4me | aha, that makes sense | 14:14 |
cloudnull | 's/but//g' | 14:14 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:14 | |
odyssey4me | well, if it's pretty much done then perhap you can recruit major to help you get the spec done and to get all the patches up for review :) | 14:15 |
odyssey4me | mhayden ^ | 14:15 |
*** fawadkhaliq has quit IRC | 14:15 | |
cloudnull | odyssey4me: have you had a chance to look at what I did using your download template bits ? | 14:20 |
cloudnull | IE: https://gist.github.com/cloudnull/34ff32c4f2dd9edc9902 | 14:20 |
*** phalmos has joined #openstack-ansible | 14:21 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Set Keystone httpd processes and threads to match upstream https://review.openstack.org/225145 | 14:22 |
mhayden | odyssey4me: i'm up for more optimization but i didn't want to steal your thunder (or cloudnull's) | 14:23 |
* mhayden scurries off for meeeeeetings | 14:23 | |
cloudnull | not my thunder at all | 14:23 |
cloudnull | its odyssey4me :) | 14:23 |
*** k_stev has joined #openstack-ansible | 14:23 | |
*** k_stev has quit IRC | 14:23 | |
cloudnull | he's the one that created the bits ;) | 14:23 |
*** k_stev has joined #openstack-ansible | 14:23 | |
odyssey4me | cloudnull I'm looking through that now and have a few questions about it | 14:25 |
odyssey4me | why do we do https://gist.github.com/cloudnull/34ff32c4f2dd9edc9902#file-container-cached-image-create-sh-L83-L84 at all? | 14:26 |
odyssey4me | it seemed to me that python2.7 is in trusty as a default | 14:26 |
odyssey4me | is this a carried habit from when the project was still trying to use precise? | 14:26 |
javeriak | hello everyone, so why do we have duplicate definitions for "neutron_service_program_*_enabled" parameters, in the os_neutron role vars and in the inventory /group_vars; and must we keep it that way? | 14:27 |
*** sdake has joined #openstack-ansible | 14:27 | |
odyssey4me | javeriak the role defaults are defaults and have the lowest priority | 14:27 |
odyssey4me | in the group_vars, typically we only add values there if other roles need those values | 14:28 |
odyssey4me | or if we want to override the role defaults for whatever reason | 14:28 |
cloudnull | odyssey4me: no the container image from trusty doesn't, or didnt, have it installed by default. | 14:29 |
javeriak | odyssey4me, okay, the neutron agent config definitions in the os_neutron role can be optimized, i was wondering if I should at all mess with them or leave them as is.. | 14:29 |
odyssey4me | cloudnull ok, but if we install it - why remove what's there and do the link? | 14:29 |
odyssey4me | javeriak you're free to submit any patch for review :) | 14:30 |
odyssey4me | and optimisation is good! | 14:30 |
*** jroll is now known as jroll|dupe | 14:31 | |
*** galstrom is now known as galstrom_zzz | 14:31 | |
*** jroll|dupe is now known as brickednick | 14:31 | |
*** brickednick is now known as jroll | 14:31 | |
javeriak | odyssey4me: cool :), i'll take a stab at it, but it might need limiting those parameters to one location only, btw i don't see them used anywhere else so the duplication is for overriding then, i was wondering if you would be open to that | 14:31 |
cloudnull | odyssey4me: its to ensure that python command is running 2.7 only. | 14:31 |
odyssey4me | javeriak if they are unnecessarily duplicated in group_vars (or anywhere other than the defaults), then the duplication should be removed | 14:33 |
javeriak | odyssey4me, right thanks | 14:33 |
odyssey4me | cloudnull ok, so that protects against the possibility of an ubuntu switch to using python3 as a default or something like that? | 14:34 |
cloudnull | yes | 14:34 |
cloudnull | i think that is the default, if you simply take the trusty container image as is | 14:34 |
odyssey4me | cool, alright - that makes sense now | 14:34 |
odyssey4me | now - on to the package list | 14:35 |
*** agireud has quit IRC | 14:35 | |
odyssey4me | are there any package additions or removals which seem unnecessary? | 14:35 |
odyssey4me | it seemed to me like a lot of the packages there or not there might just have been happenstance rather than functional? | 14:36 |
odyssey4me | javeriak looking forward to seeing the improvements :) | 14:36 |
javeriak | odyssey4me :), sure | 14:36 |
*** agireud has joined #openstack-ansible | 14:37 | |
cloudnull | odyssey4me: idk for sure. | 14:39 |
*** tlian has joined #openstack-ansible | 14:40 | |
cloudnull | Ideally I'd like to run with the containers bare and figure out all the packages that we actually need on a more per role basis . | 14:40 |
odyssey4me | cloudnull agreed - I'd prefer to have the containers only build with the essentials, then perhaps add the list of packages common to all roles once those are figured out | 14:41 |
odyssey4me | let me prep a patch to switch to something like this but with a minimal package set, then work it from there | 14:42 |
*** shoutm has joined #openstack-ansible | 14:42 | |
cloudnull | yes itll take a bit of banging on im sure. | 14:42 |
*** Mudpuppy_ has joined #openstack-ansible | 14:42 | |
*** Mudpuppy_ has quit IRC | 14:43 | |
*** Mudpuppy_ has joined #openstack-ansible | 14:45 | |
*** Mudpuppy has quit IRC | 14:46 | |
odyssey4me | cloudnull fyi I think that the pin for os_client_config in https://review.openstack.org/225156 might be the key to unblocking master until upstream sorts out a solution for it | 14:48 |
odyssey4me | there doesn't seem to be all that much urgency being put into fixing it upstream just yet - although I expect that it should get sorted out soon as it'll be needed for the Liberty RC's | 14:48 |
cloudnull | sounds good +1 waiting on gate | 14:49 |
tiagogomes | Does OSAD supports live migratting VMs? | 14:52 |
odyssey4me | tiagogomes all the tunable values are available to configure it, so yes | 14:53 |
*** Mudpuppy_ has quit IRC | 14:53 | |
odyssey4me | it would depend more on whether you have the appropriate storage to support it | 14:53 |
odyssey4me | ie NFS, Ceph or some other shared storage | 14:54 |
tiagogomes | But it doesn't setup an NFS/ceph server and configure /var/nova/intances to be a shared directory | 14:54 |
odyssey4me | tiagogomes no, storage setup is outside of openstack-ansible's scope | 14:54 |
tiagogomes | odyssey4me got it, ta | 14:55 |
*** Mudpuppy has joined #openstack-ansible | 14:55 | |
*** Mudpuppy has quit IRC | 14:58 | |
cloudnull | tiagogomes: https://github.com/ceph/ceph-ansible should work fairly well for that | 14:58 |
tiagogomes | cloudnull thanks for the pointer :) | 14:59 |
cloudnull | or when this goes through rpc-openstack will make that go to https://github.com/rcbops/rpc-openstack/pull/380 | 15:00 |
*** woodard has quit IRC | 15:01 | |
cloudnull | ^ that should do all of the integration to make what youre looking for happen. that said its in review over there. if you have some time to give it a look im sure those guys would appreciate it. | 15:01 |
cloudnull | -cc git-harry palendae mattt | 15:01 |
*** woodard has joined #openstack-ansible | 15:01 | |
*** woodard_ has joined #openstack-ansible | 15:02 | |
palendae | Yeah, that review from rpc-openstack is kind of sitting as we're doing some other things with our product first before we merge | 15:03 |
*** Mudpuppy has joined #openstack-ansible | 15:04 | |
*** woodard has quit IRC | 15:06 | |
*** arbrandes has quit IRC | 15:07 | |
mattt | odyssey4me cloudnull : https://review.openstack.org/225156 seems to have gated | 15:13 |
odyssey4me | mattt awesome, +2 | 15:13 |
*** fawadkhaliq has joined #openstack-ansible | 15:16 | |
*** fawadkhaliq has quit IRC | 15:20 | |
*** javeriak has quit IRC | 15:22 | |
odyssey4me | mattt cloudnull can we get these rolling too? https://review.openstack.org/224562 and https://review.openstack.org/224559 | 15:22 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Remove unused Juno-specific groups from inventory https://review.openstack.org/223097 | 15:22 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Install nfs-common with nova-compute https://review.openstack.org/223604 | 15:23 |
mattt | odyssey4me: looking now | 15:26 |
*** fawadkhaliq has joined #openstack-ansible | 15:27 | |
mattt | odyssey4me: question, in the juno review, why did we not unlock keystonemiddleware and oslo_messaging/oslo_utils when we did https://review.openstack.org/#/c/217098/ ? | 15:31 |
mattt | were those needed for something? | 15:32 |
odyssey4me | mattt I wanted to do it in two steps - one for clients, another for libraries | 15:32 |
odyssey4me | I actually did want to do it then, but I saw a squirrel | 15:32 |
odyssey4me | there was impetus to do it this time because the one library - I forget which - broke, so I opted to pull them out this time and let global requirements figure it out instead | 15:33 |
mattt | ok | 15:33 |
*** galstrom_zzz is now known as galstrom | 15:34 | |
*** jwagner is now known as jwagner_away | 15:34 | |
*** arbrandes has joined #openstack-ansible | 15:41 | |
*** phalmos has quit IRC | 15:47 | |
*** metral_zzz is now known as metral | 15:58 | |
*** phalmos has joined #openstack-ansible | 16:01 | |
*** jwagner_away is now known as jwagner | 16:02 | |
*** alop has joined #openstack-ansible | 16:19 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adding docs for HAProxy SSL configuration https://review.openstack.org/224980 | 16:22 |
mhayden | Sam-I-Am / KLevenstein: we now have a few sections in the docs talking about ssl certificates, and there's a bunch of duplications... would it make sense to merge those and just have one documentation section on ssl certs? | 16:23 |
mhayden | and explain there how to handle ssl certs for each service? | 16:23 |
KLevenstein | anytime we can merge random duplications is good | 16:23 |
mhayden | and maybe a link from each service's docs over to the main ssl docs | 16:23 |
KLevenstein | sure | 16:23 |
mhayden | okay, cool | 16:23 |
* mhayden tickets himself :P | 16:24 | |
Sam-I-Am | mhayden: duplication from upstream docs? | 16:24 |
mhayden | Sam-I-Am: nah, horizon, haproxy, and rabbit all have their own SSL docs | 16:24 |
Sam-I-Am | or of | 16:24 |
mhayden | so i thought about merging them | 16:24 |
Sam-I-Am | oh within osad | 16:24 |
mhayden | since they essentially say the same thing | 16:24 |
mhayden | yeah | 16:24 |
KLevenstein | merge the things | 16:24 |
Sam-I-Am | fewer words no one will read | 16:25 |
*** fawadkhaliq has quit IRC | 16:28 | |
*** Mudpuppy has quit IRC | 16:45 | |
*** Mudpuppy has joined #openstack-ansible | 16:46 | |
*** KLevenstein has quit IRC | 16:49 | |
*** Mudpuppy has quit IRC | 16:51 | |
sigmavirus24 | *fewer copies of words that no one will read | 16:52 |
*** fawadkhaliq has joined #openstack-ansible | 16:56 | |
openstackgerrit | Merged openstack/openstack-ansible: Update juno for new dev work - 17 Sep 2015 https://review.openstack.org/224559 | 17:11 |
*** abitha has joined #openstack-ansible | 17:12 | |
*** phalmos has quit IRC | 17:20 | |
*** javeriak has joined #openstack-ansible | 17:32 | |
openstackgerrit | Merged openstack/openstack-ansible: Update kilo for new dev work - 17 Sep 2015 https://review.openstack.org/224562 | 17:32 |
*** fawadkhaliq has quit IRC | 17:33 | |
*** fawadkhaliq has joined #openstack-ansible | 17:33 | |
*** javeriak has quit IRC | 17:47 | |
*** javeriak has joined #openstack-ansible | 17:52 | |
*** KLevenstein has joined #openstack-ansible | 17:55 | |
*** harlowja has quit IRC | 17:58 | |
*** harlowja has joined #openstack-ansible | 17:58 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Remove unused Juno-specific groups from inventory https://review.openstack.org/223097 | 17:59 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Break apart and document the upgrade process https://review.openstack.org/224137 | 18:01 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Support base64 padding in federated tokens https://review.openstack.org/224339 | 18:01 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add auth version for legacy OpenStack clients https://review.openstack.org/223692 | 18:01 |
tiagogomes | I don't have any neutron process running on the compute node. Shouldn't an agent be running? | 18:04 |
*** fawadkhaliq has quit IRC | 18:04 | |
tiagogomes | at least for openvswitch one agent was running in the compute nodes | 18:04 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: [WIP] Set lxc image cache to build locally https://review.openstack.org/225264 | 18:08 |
*** gparaskevas has joined #openstack-ansible | 18:08 | |
*** javeriak has quit IRC | 18:09 | |
*** javeriak_ has joined #openstack-ansible | 18:09 | |
cloudnull | tiagogomes: the neutron-linuxbridge-agent should be running | 18:13 |
tiagogomes | that's what I thought | 18:13 |
tiagogomes | I only have nova-compute running | 18:13 |
*** javeriak_ has quit IRC | 18:13 | |
tiagogomes | no errors in the deployment | 18:13 |
tiagogomes | do I need to add the compute node IP address to the network-infrastructure nodes? | 18:14 |
*** javeriak has joined #openstack-ansible | 18:15 | |
*** phalmos has joined #openstack-ansible | 18:23 | |
cloudnull | no you shouldnt' | 18:31 |
cloudnull | maybe run the os-neutron.install.yml play again | 18:32 |
cloudnull | it installs the neutron bits everywhere theres is a server within the neutron group, which nova compute nodes are within the neutron_agent group. | 18:32 |
openstackgerrit | Merged openstack/openstack-ansible: Added post and pre hook script for veth cleanup https://review.openstack.org/222695 | 18:38 |
openstackgerrit | Merged openstack/openstack-ansible: More complete explanation of availability zones https://review.openstack.org/223010 | 18:38 |
*** cloudtrainme has joined #openstack-ansible | 18:44 | |
*** phalmos has quit IRC | 18:55 | |
*** woodard has joined #openstack-ansible | 18:57 | |
*** woodard has quit IRC | 18:57 | |
*** woodard has joined #openstack-ansible | 18:58 | |
*** phalmos has joined #openstack-ansible | 18:58 | |
*** woodard_ has quit IRC | 19:00 | |
*** Mudpuppy has joined #openstack-ansible | 19:11 | |
*** Mudpuppy has quit IRC | 19:14 | |
*** Mudpuppy has joined #openstack-ansible | 19:14 | |
*** gparaskevas has quit IRC | 19:26 | |
dstanek | where is the task that builds the wheels for each project? | 19:32 |
cloudnull | dstanek: https://github.com/openstack/openstack-ansible/blob/master/playbooks/repo-build.yml | 19:32 |
dstanek | cloudnull: thx | 19:32 |
*** fawadkhaliq has joined #openstack-ansible | 19:43 | |
*** sdake has quit IRC | 19:46 | |
*** arbrandes has quit IRC | 19:48 | |
*** sdake has joined #openstack-ansible | 19:53 | |
*** javeriak has quit IRC | 19:54 | |
*** elo has joined #openstack-ansible | 19:54 | |
*** woodard_ has joined #openstack-ansible | 19:57 | |
*** woodard has quit IRC | 20:00 | |
evrardjp | Hey, I'm back because I have a few minutes to kill | 20:07 |
evrardjp | mhayden: are you there? | 20:07 |
*** woodard has joined #openstack-ansible | 20:13 | |
*** woodard_ has quit IRC | 20:16 | |
mhayden | cloudnull: this failure is unusual http://logs.openstack.org/04/224304/4/check/gate-openstack-ansible-dsvm-commit/af3bfa3/console.html#_2015-09-18_14_07_18_230 | 20:18 |
mhayden | evrardjp: yup yup | 20:18 |
evrardjp | you're already working on the SSL regrouping? | 20:19 |
evrardjp | (in the docs) | 20:19 |
evrardjp | to know if I review this: https://review.openstack.org/#/c/224980/3/doc/source/install-guide/configure-haproxy.rst | 20:19 |
cloudnull | mhayden: thats hpb4 | 20:19 |
cloudnull | it hates us | 20:19 |
mhayden | oh, well darn | 20:20 |
mhayden | i'll rechecky | 20:20 |
cloudnull | yesir | 20:20 |
*** KLevenstein has quit IRC | 20:22 | |
*** KLevenstein has joined #openstack-ansible | 20:22 | |
*** elo has quit IRC | 20:22 | |
*** phalmos has quit IRC | 20:28 | |
*** woodard_ has joined #openstack-ansible | 20:39 | |
evrardjp | I should pay attention more to the error messages, because right now, I'm just rechecking all the time (cause I'm confident it should work) | 20:39 |
evrardjp | I have the feeling we have more and more rechecks | 20:39 |
palendae | evrardjp: Yeah, rechecking has a thing for a while...this is a complicated stack, and sometimes infra is touchy | 20:42 |
palendae | Biggest thing, I think, is making sure the failure relates to the change somehow | 20:42 |
*** woodard has quit IRC | 20:42 | |
evrardjp | yeah, I'm grepping error and if see it's not linked, I recheck | 20:43 |
evrardjp | but it's still painfull | 20:43 |
palendae | Agreed | 20:43 |
*** k_stev1 has joined #openstack-ansible | 20:44 | |
*** fawadkhaliq has quit IRC | 20:44 | |
*** fawadkhaliq has joined #openstack-ansible | 20:45 | |
*** tlian has quit IRC | 20:45 | |
*** k_stev has quit IRC | 20:47 | |
*** fawadkhaliq has quit IRC | 20:48 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Adding docs for HAProxy SSL configuration https://review.openstack.org/224980 | 20:48 |
*** k_stev1 has quit IRC | 20:48 | |
evrardjp | mhayden: thanks for the change | 20:49 |
mhayden | evrardjp: no prob - thanks for looking it over | 20:50 |
evrardjp | about this: haproxy_ssl_self_signed_regen: True | 20:50 |
mhayden | tracing the logic is kinda wild | 20:50 |
evrardjp | I've seen you've moved to a "=" | 20:50 |
mhayden | it breaks on the commandline without a = | 20:51 |
evrardjp | so I guess you tested it... but did you test it if someone already set something in a user_* file? | 20:51 |
evrardjp | because I'm not sure that adding a -e in the command line will be taken afterwards in the variable overriding in ansible | 20:52 |
mhayden | the main.yml in there should prevent the playbook with the regen from running | 20:52 |
mhayden | there's a "when" in main.yml in the os-horizon role that will prevent it from running if user-provided certs are defined | 20:52 |
evrardjp | I remember a discussion about switching the order of the tasks to reduce the amount of "when" ;) | 20:53 |
evrardjp | anyway It's working, and the doc is clear | 20:54 |
evrardjp | except for my little question | 20:54 |
evrardjp | ;) | 20:54 |
mhayden | i have a bug open to centralize the ssl docs | 20:54 |
evrardjp | I've seen that | 20:55 |
evrardjp | It's a great addition | 20:55 |
mhayden | i'd kinda like to make the SSL handling *identical* between horizon, haproxy, rabbitmq | 20:55 |
mhayden | in the actual playbooks | 20:55 |
evrardjp | I don't see a problem with that | 20:55 |
evrardjp | keep in mind the components are different | 20:55 |
mhayden | agreed | 20:55 |
*** galstrom is now known as galstrom_zzz | 20:55 | |
mhayden | the variable names won't be identical | 20:55 |
mhayden | but the logic can be very similar | 20:55 |
mhayden | if not the same | 20:56 |
evrardjp | for haproxy, I remember that the key create was there and we had to add a way to drop keys, but we wanted to keep everything simple | 20:58 |
evrardjp | so we put all the ssl in one yml file | 20:58 |
evrardjp | if you have all in one file, you don't have the same conditions ;) | 21:00 |
mhayden | every time i see "Drop" in a playbook, i feel like something is getting removed | 21:00 |
*** k_stev has joined #openstack-ansible | 21:01 | |
evrardjp | oh, that was my first feeling! I thought it was because I'm not a native english speaker | 21:02 |
evrardjp | I adapted my vocabulary | 21:03 |
evrardjp | anyway, if you want to merge the behaviour for haproxy, it would just need to move the "Drop user provided ssl cert and key / CA" further in the task succession | 21:04 |
*** k_stev1 has joined #openstack-ansible | 21:09 | |
*** k_stev1 has quit IRC | 21:09 | |
*** k_stev1 has joined #openstack-ansible | 21:09 | |
*** k_stev has quit IRC | 21:10 | |
*** galstrom_zzz is now known as galstrom | 21:12 | |
*** KLevenstein has quit IRC | 21:31 | |
*** KLevenstein has joined #openstack-ansible | 21:32 | |
*** woodard has joined #openstack-ansible | 21:34 | |
*** woodard_ has quit IRC | 21:38 | |
mhayden | will do | 21:44 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-specs: Adding security hardening spec https://review.openstack.org/222619 | 21:45 |
*** galstrom is now known as galstrom_zzz | 22:17 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:32 | |
*** KLevenstein has quit IRC | 22:32 | |
*** markvoelker_ has quit IRC | 22:36 | |
*** sdake_ has joined #openstack-ansible | 22:39 | |
*** spotz is now known as spotz_zzz | 22:40 | |
*** sdake has quit IRC | 22:43 | |
*** openstackgerrit has quit IRC | 22:46 | |
*** openstackgerrit has joined #openstack-ansible | 22:46 | |
*** sdake has joined #openstack-ansible | 22:48 | |
*** arbrandes has joined #openstack-ansible | 22:50 | |
*** sdake_ has quit IRC | 22:51 | |
*** alop has quit IRC | 22:54 | |
*** elo has joined #openstack-ansible | 23:10 | |
*** cloudtrainme has quit IRC | 23:16 | |
*** cloudtrainme has joined #openstack-ansible | 23:16 | |
*** cloudtrainme has quit IRC | 23:21 | |
*** leakypipes has quit IRC | 23:22 | |
*** elo has quit IRC | 23:24 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: adds the config_template to tempest https://review.openstack.org/223342 | 23:27 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Update cached LXC image in place https://review.openstack.org/224304 | 23:27 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: adds the config_template to galera_server https://review.openstack.org/223348 | 23:27 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: adds the config_template to galera_client https://review.openstack.org/223349 | 23:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Adds the config_template to keystone https://review.openstack.org/223307 | 23:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: adds the config_template to pip_lock_down https://review.openstack.org/223350 | 23:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Adds the config_template to heat https://review.openstack.org/223299 | 23:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: adds the config_template to neutron https://review.openstack.org/223314 | 23:28 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Adds the config_template to glance https://review.openstack.org/223288 | 23:29 |
*** pradk has quit IRC | 23:32 | |
*** Mudpuppy has quit IRC | 23:35 | |
*** markvoelker has joined #openstack-ansible | 23:37 | |
*** markvoelker has quit IRC | 23:42 | |
*** abitha has quit IRC | 23:52 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Removes over zealous net cache flushing https://review.openstack.org/225367 | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!