*** markvoelker has joined #openstack-ansible | 00:36 | |
*** scarlisle has quit IRC | 00:38 | |
*** markvoelker has quit IRC | 00:41 | |
*** galstrom_zzz is now known as galstrom | 00:46 | |
*** fawadkhaliq has joined #openstack-ansible | 01:00 | |
*** abitha has quit IRC | 01:10 | |
*** galstrom is now known as galstrom_zzz | 01:20 | |
*** galstrom_zzz is now known as galstrom | 01:20 | |
*** galstrom is now known as galstrom_zzz | 01:22 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Make the container cache resolvers configurable https://review.openstack.org/238223 | 01:34 |
---|---|---|
*** dolpher has quit IRC | 01:39 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Make the container cache resolvers configurable https://review.openstack.org/238223 | 01:48 |
*** fawadkhaliq has quit IRC | 01:48 | |
*** davidself has joined #openstack-ansible | 02:03 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement shippable venvs https://review.openstack.org/236183 | 02:11 |
*** markvoelker has joined #openstack-ansible | 02:37 | |
*** markvoelker has quit IRC | 02:42 | |
*** dolpher1 has joined #openstack-ansible | 02:43 | |
*** tlian has quit IRC | 03:21 | |
*** markvoelker has joined #openstack-ansible | 03:38 | |
*** markvoelker has quit IRC | 03:43 | |
*** g3rms_ has quit IRC | 04:08 | |
*** fawadkhaliq has joined #openstack-ansible | 04:18 | |
*** galstrom_zzz is now known as galstrom | 04:27 | |
*** abitha has joined #openstack-ansible | 04:30 | |
*** abitha has quit IRC | 04:37 | |
*** rajalokan has joined #openstack-ansible | 04:45 | |
*** subscope has joined #openstack-ansible | 04:47 | |
*** galstrom is now known as galstrom_zzz | 04:52 | |
*** WeeIX has joined #openstack-ansible | 05:12 | |
*** rajalokan has quit IRC | 05:16 | |
*** rajalokan has joined #openstack-ansible | 05:34 | |
*** subscope has quit IRC | 05:37 | |
*** markvoelker has joined #openstack-ansible | 05:39 | |
*** markvoelker has quit IRC | 05:43 | |
*** mpavone has joined #openstack-ansible | 07:04 | |
*** subscope has joined #openstack-ansible | 07:14 | |
*** gparaskevas has joined #openstack-ansible | 07:23 | |
*** gardenshed has joined #openstack-ansible | 07:26 | |
*** gardenshed has quit IRC | 07:36 | |
*** markvoelker has joined #openstack-ansible | 07:40 | |
*** gardenshed has joined #openstack-ansible | 07:42 | |
*** markvoelker has quit IRC | 07:44 | |
*** gparaskevas has quit IRC | 07:48 | |
*** karimb has joined #openstack-ansible | 08:03 | |
*** gparaskevas has joined #openstack-ansible | 08:22 | |
*** subscope has quit IRC | 08:48 | |
openstackgerrit | Merged openstack/openstack-ansible-security: V-38681: GID's in /etc/passwd & /etc/group https://review.openstack.org/234215 | 08:49 |
odyssey4me | o/ morning all | 08:50 |
*** openstackgerrit has quit IRC | 09:01 | |
*** openstackgerrit has joined #openstack-ansible | 09:02 | |
*** dolpher1 has quit IRC | 09:03 | |
*** subscope has joined #openstack-ansible | 09:08 | |
*** gardenshed has quit IRC | 09:13 | |
*** neilus has quit IRC | 09:14 | |
*** karimb has quit IRC | 09:22 | |
*** karimb has joined #openstack-ansible | 09:23 | |
*** neilus has joined #openstack-ansible | 09:30 | |
*** gardenshed has joined #openstack-ansible | 09:30 | |
tiagogomes__ | Morning! So I configured my deployment to use LDAP for identity. The OpenStack internal users (admin user, cinder user, nova user...) are in LDAP as well | 09:35 |
tiagogomes__ | However the task "Ensure Admin user" is failing with an unauthorized error | 09:36 |
tiagogomes__ | I ssh to an container and set OS_TOKEN, OS_AUTH and OS_IDENTITY_API_VERSION and verified that `openstack user list` is not authorized; but openstack user list --domain Default` works | 09:38 |
tiagogomes__ | So, is there a bug that you need to give the domain when verifying if the admin user exists? Or I am missing something | 09:38 |
*** ashishjain has joined #openstack-ansible | 09:40 | |
ashishjain | hello hughsaunders u there? | 09:40 |
*** markvoelker has joined #openstack-ansible | 09:40 | |
*** markvoelker has quit IRC | 09:45 | |
*** openstackgerrit has quit IRC | 09:46 | |
*** openstackgerrit has joined #openstack-ansible | 09:47 | |
hughsaunders | ashishjain: pong | 09:55 |
*** subscope has quit IRC | 09:55 | |
ashishjain | hughsaunders: hello | 09:55 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Ignore tempest requirements for repo build https://review.openstack.org/238429 | 09:56 |
*** subscope has joined #openstack-ansible | 09:56 | |
ashishjain | hughsaunders: I did as you suggested and enabled the same interface/bridges in the compute node ran the playbooks for neutron | 09:56 |
ashishjain | hughsaunders: Post that I use the external network when spinnng of a nova instance with tcpdump on compute node | 09:56 |
ashishjain | I see only a request and no response | 09:57 |
ashishjain | 13:58:12.432458 IP 0.0.0.0.bootpc > 255.255.255.255.bootps: BOOTP/DHCP, Request from fa:16:3e:6e:58:20 (oui Unknown), length 298 | 09:57 |
ashishjain | How does dhcp work is it nova_instance->compute->neutronAgent->? | 09:57 |
ashishjain | Does it mean my dhcp request is unable to go out of compute node to neutron node ? | 09:58 |
ashishjain | Looked at the iptables on compute node which looks very cryptic so manny entries probably made by linux bridge | 09:58 |
ashishjain | this mac address "fa:16:3e:6e:58:20" is from the new VM | 09:59 |
ashishjain | In the dnsmasq log in the neutron agent container their is no entry for any of such dhcp request | 10:02 |
hughsaunders | ashishjain: Yeah, the dhcp agent is in a namespace on the neutron agent node. So the request goes from instance > host > neutron node > dhcp agent namespace > dnsmasq | 10:05 |
hughsaunders | you should be able to follow the request along that path. The simplest case is when your provider network is flat and the instance has an interface directly on the provider network | 10:06 |
ashishjain | hughsaunders: Yes that is what I have done by hosting a nova instance directly on the external provider network, and tcpdump reveals nothing on the neutron agent node, I just see entries on the compute node | 10:07 |
hughsaunders | tiagogomes__: the openrc sets the domain so you shouldn't need to specify it | 10:08 |
ashishjain | for dhcp request | 10:08 |
hughsaunders | tiagogomes__: and it probably is a bug if we don't specify the domain for ensure admin user | 10:08 |
ashishjain | hughsaunders: There is no connectivity issue b/w my compute and neutron agent node as I just now spinned off a VM using the tenant network and everything works fine | 10:09 |
hughsaunders | ashishjain: but the issue is your provider network | 10:09 |
hughsaunders | you need to ensure that your compute and agent nodes can communicate on that network | 10:10 |
ashishjain | okay I get your point | 10:10 |
tiagogomes__ | hughsaunders I don't think openrc is used when ensuring that the admin user exits | 10:11 |
ashishjain | hughsaunders: Any advice on how can I check that out as both these networks does not come with an ip address | 10:12 |
hughsaunders | tiagogomes__: it isn't but should be when you're testing with the cli | 10:12 |
hughsaunders | ashishjain: theres nothing to stop you adding IPs to the compute and neutron node's interfaces on the provider network | 10:13 |
ashishjain | okay I will try that out | 10:14 |
hughsaunders | tiagogomes__: also the keystone module uses 'Default' as the default domain so that should be fine also... https://github.com/openstack/openstack-ansible/blob/master/playbooks/library/keystone#L709 | 10:15 |
hughsaunders | tiagogomes__: any issues in the keystone apache log? | 10:16 |
tiagogomes__ | 2015-10-22 11:25:42.816 4417 WARNING keystone.common.controller [-] Invalid token found while getting domain ID for list request | 10:26 |
tiagogomes__ | 2015-10-22 11:25:42.817 4417 WARNING keystone.common.wsgi [-] Authorization failed. The request you have made requires authentication. from 10.10.0.10 | 10:26 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: [WIP] Add more known conflicting packages https://review.openstack.org/238442 | 10:32 |
openstackgerrit | Merged openstack/openstack-ansible-security: Updating getting started docs https://review.openstack.org/236066 | 10:47 |
*** rajalokan has quit IRC | 10:48 | |
*** markvoelker has joined #openstack-ansible | 10:56 | |
*** markvoelker has quit IRC | 11:01 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Add pre-tempest instance info output https://review.openstack.org/238454 | 11:09 |
*** ashishjain has quit IRC | 11:23 | |
tiagogomes__ | ok, I solved my problem by adding 'domain=default' as an argument here: https://github.com/openstack/openstack-ansible/blob/master/playbooks/library/keystone#L660 | 11:23 |
tiagogomes__ | so this looks to be a bug | 11:23 |
tiagogomes__ | you need to specify the domain when retrieving the users | 11:24 |
tiagogomes__ | I experienced the same observation when using the openstack command line tool | 11:24 |
odyssey4me | tiagogomes__ nice! perhaps you can add a patch for this? | 11:24 |
*** subscope has quit IRC | 11:25 | |
odyssey4me | tiagogomes__ I think what you found may relate to this bug: https://bugs.launchpad.net/openstack-ansible/+bug/1506285 | 11:25 |
openstack | Launchpad bug 1506285 in openstack-ansible "11.2.1 : openstack client with V3 auth causes usability issues" [Undecided,New] - Assigned to Ian Cordasco (icordasc) | 11:25 |
tiagogomes__ | odyssey4me authentication in OpenStack is getting so confused, the error messages don't help | 11:29 |
*** gardenshed has quit IRC | 11:29 | |
odyssey4me | tiagogomes__ yeah, unfortunately a lot of things get swallowed/hidden in the auth environment | 11:42 |
openstackgerrit | Merged openstack/openstack-ansible: Update kilo for new dev work - 21 Oct 2015 https://review.openstack.org/237907 | 11:43 |
openstackgerrit | Merged openstack/openstack-ansible: Removing package patch versions from APT pinning https://review.openstack.org/238230 | 11:51 |
*** subscope has joined #openstack-ansible | 11:54 | |
*** gparaskevas has quit IRC | 11:58 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: [WIP] Disable prevent_arp_spoofing https://review.openstack.org/238472 | 12:02 |
*** karimb has quit IRC | 12:03 | |
*** jaypipes has joined #openstack-ansible | 12:05 | |
*** gardenshed has joined #openstack-ansible | 12:05 | |
*** gardenshed has quit IRC | 12:06 | |
*** markvoelker has joined #openstack-ansible | 12:12 | |
*** woodard has joined #openstack-ansible | 12:28 | |
odyssey4me | mattt hughsaunders I think this would be useful on an ongoing basis: https://review.openstack.org/238454 | 12:31 |
*** woodard has quit IRC | 12:31 | |
*** woodard has joined #openstack-ansible | 12:32 | |
*** fawadkhaliq has quit IRC | 12:36 | |
mhayden | morning | 12:36 |
mgariepy | good morning everyone | 12:39 |
tiagogomes__ | Hi, I am trying to push a change to gerrit but I am getting Unauthorized | 12:40 |
*** woodard has quit IRC | 12:41 | |
*** karimb has joined #openstack-ansible | 12:43 | |
tiagogomes__ | hmm, the launchpad password didn't work, but I set a http password on gerrit and that worked better | 12:46 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement L3HA support https://review.openstack.org/233389 | 12:48 |
*** woodard has joined #openstack-ansible | 12:50 | |
*** woodard has quit IRC | 12:52 | |
*** woodard has joined #openstack-ansible | 12:52 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Updated the repo-build process https://review.openstack.org/230716 | 12:53 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement shippable venvs https://review.openstack.org/236183 | 12:56 |
*** tlian has joined #openstack-ansible | 12:56 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-3869{2,4}: Lock inactive accounts https://review.openstack.org/233255 | 12:59 |
mhayden | odyssey4me / mattt: just a rebase here to fix a merge conflict ^^ | 12:59 |
cloudnull | mattt i updated the https://review.openstack.org/#/c/236183/ and https://review.openstack.org/#/c/230716/ prs / commented inline on your reviews thats for that btw | 13:00 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38683: Check for non-unique usernames https://review.openstack.org/234209 | 13:01 |
*** gparaskevas has joined #openstack-ansible | 13:01 | |
mattt | mhayden: no worries -- you seem to have a few reviews that have been sitting around w/ feedback for a good few days | 13:03 |
mhayden | mattt: yeah, i was in training yesterday ;) | 13:03 |
* mhayden is catching up | 13:03 | |
mattt | mhayden: you slacker | 13:03 |
mattt | cloudnull: i'm not sure anyone would ever do anything w/ a venv manually, but i hate untaring a tarball and finding it doesn't have everything in a single dir :) | 13:04 |
odyssey4me | hughsaunders this is the package list from the successful job: http://pastebin.com/XdCGh76U | 13:05 |
odyssey4me | those are packages on the host which aren't on the failing job host | 13:05 |
odyssey4me | these are the packages on the filing host which aren't on the working host http://pastebin.com/U9WPX2JL | 13:05 |
cloudnull | mattt: ha im on the inverse of that | 13:07 |
mattt | cloudnull: really! | 13:07 |
cloudnull | i typically use tar -C and hate finding i have to go and move things around | 13:07 |
cloudnull | but the current archive format stores the tar in /var/cache and then unarchives it to the proper location | 13:08 |
cloudnull | which is taken care of by the ansible unarchive module | 13:08 |
mhayden | mattt: i think i shored up the issues you found on https://review.openstack.org/#/c/233071/ | 13:09 |
cloudnull | i have to run for a bit bbs | 13:09 |
mattt | cloudnull: yeah everything is handled nicely in ansible atm | 13:09 |
mattt | cloudnull: i was thinking more in the event people would be doing things manually w/ the venvs | 13:09 |
openstackgerrit | Merged openstack/openstack-ansible-security: V-3869{2,4}: Lock inactive accounts https://review.openstack.org/233255 | 13:09 |
mattt | then you may want to have the release in the tarball name, etc. | 13:09 |
mattt | but perhaps these are use cases that will never exist | 13:09 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-58901: sudo requires auth https://review.openstack.org/234239 | 13:11 |
*** neilus has quit IRC | 13:12 | |
odyssey4me | Apsu if you've had your coffee, we have a networking conundrum for you. | 13:14 |
Apsu | Hoo boy | 13:14 |
Apsu | Fire away. | 13:14 |
*** elo has quit IRC | 13:15 | |
odyssey4me | right, so since enabling arp_spoofing_protection in master we're getting a consistent pass in our voting gate check, but a consistent fail in the non-voting gate check | 13:15 |
Apsu | Ok | 13:15 |
odyssey4me | when disabling the arp spoofing protection, both pass just fine | 13:15 |
mhayden | mattt: for https://review.openstack.org/#/c/234264/11, what do you think about an async job? | 13:16 |
odyssey4me | so clearly something is going on in the non voting check that causes a failure when ebtables is in the mix | 13:16 |
Apsu | Have you made sure that the appropriate extension is also enabled in the ml2 conf? Sam-I-Am identified the missing piece back when I ran into a problem before | 13:16 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38683: Check for non-unique usernames https://review.openstack.org/234209 | 13:16 |
Apsu | It was specifically an issue with floating IP communication, due to improper ebtables rules | 13:17 |
odyssey4me | Apsu yes, as it's passing consistently in one gate and not in the other, it is clearly not an issue with config or packages in the containers themselves - it can only be something to do with the host | 13:17 |
Apsu | Well, depends on what's being tested and how, I suppose. | 13:17 |
odyssey4me | the openstack configs are exactly the same both ways | 13:17 |
Apsu | Do you know what exactly the other check is doing? | 13:18 |
odyssey4me | and the test process is the same both ways | 13:18 |
odyssey4me | there is a difference in the packages on the pre-built image between the two tests | 13:18 |
mattt | mhayden: do you think it makes sense to block or not? | 13:18 |
mattt | mhayden: i'm still in two minds on it | 13:18 |
odyssey4me | and there may be a difference in the networking config too | 13:18 |
odyssey4me | Apsu you can inspect the result of https://review.openstack.org/238454 | 13:18 |
mattt | mhayden: i just suspect sending it to root account is as useful as /dev/null | 13:19 |
odyssey4me | Apsu the actual issue is that the instance that's built by tempest doesn't get DHCP | 13:19 |
mhayden | mattt: hmm, i'd rather avoid blocking and let the playbook just get going, but we could make it configurable perhaps | 13:20 |
mhayden | people might not notice | 13:20 |
mhayden | might not notice the configurable option, i mean | 13:20 |
mattt | mhayden: would be good to get some other opinions on it | 13:21 |
cloudnull | Mattt do you think it best to have the name in the tarball stored on the target ? | 13:22 |
mhayden | mattt: i'll poke the ML | 13:22 |
mattt | mhayden: i suppose aide can write to a file right? perhaps the first task can be to check if the file exists (from previous run) and to fatal if it's not empty | 13:22 |
mhayden | mattt: well the handler is only run if the aide package was *just* installed | 13:22 |
mattt | mhayden: that way you may not notice on first run if there is a serious problem, but if sufficient time has passed between runs and there has been a compromise then you'll know on subsequent runs | 13:23 |
cloudnull | The tarball on the repo is in a version tagged folder | 13:23 |
mattt | cloudnull: my thought was that if i was downloading them locally and doing crap with different venvs, it'd be nice to have the release reflected in name so i can have multiple in the same dir | 13:23 |
mattt | cloudnull: but i'm not sure what the likelihood of that ever happening is | 13:23 |
Apsu | odyssey4me: In http://logs.openstack.org/54/238454/1/check/gate-openstack-ansible-commit-nv/e1897fa/logs/aio1_neutron_agents_container-d8275275/neutron-linuxbridge-agent.log there's this fun error http://paste.openstack.org/show/477162/ | 13:24 |
cloudnull | Multiple vens like running different versions of nova ? | 13:24 |
mattt | cloudnull: yep | 13:24 |
mattt | mhayden: hmm, that kinda sucks | 13:25 |
cloudnull | OK. I can see that case, I'll update to support that. | 13:25 |
mattt | mhayden: is the idea to run this role 1x and hten never run it again? | 13:25 |
mhayden | mattt: nah, it can be run again | 13:25 |
mhayden | but if you have aide installed already, the init is skipped | 13:25 |
mattt | mhayden: that doesn't seem right, right? | 13:25 |
mattt | because a lot could have changed between runs | 13:25 |
* Apsu holds up a sign that says IDEMPOTENT | 13:25 | |
mhayden | the init should only run if you just installed aide a few minutes earlier | 13:25 |
mhayden | mattt: there is a cron job that runs aide nightly | 13:26 |
Apsu | Idempotence happens to everyone at some point in their life. It's normal. | 13:26 |
mattt | mhayden: ah! | 13:26 |
mhayden | the init is only for the first run ever | 13:26 |
mhayden | you can skip the init if you REALLY want to, and the init happens late that night | 13:26 |
mhayden | but most folks like to init and then copy that file off the box | 13:26 |
mgariepy | cloudnull, thanks for the resolver patch ;) | 13:26 |
mattt | cloudnull: we may be solving for something that may never happen, but i think it makes sense to version the file | 13:27 |
mhayden | mattt: the idea is that you init in a known good state | 13:27 |
mhayden | then the nightly checks look for diffs | 13:27 |
mattt | mhayden: ah, ok | 13:27 |
mattt | mhayden: that makes more sense then ... if you're expecting the state to be good then it makes little sense to sit around waiting for the init to finish | 13:28 |
*** gardenshed has joined #openstack-ansible | 13:28 | |
Apsu | odyssey4me: Conversely, it appears that in the aio1-neutron LBA log, ebtables works fine. | 13:28 |
Apsu | odyssey4me: So that's neat. | 13:28 |
mattt | mhayden: i'm going to +2 this then | 13:29 |
* mhayden hugs mattt | 13:29 | |
cloudnull | Mgariepy everything working ? | 13:30 |
*** gardenshed has quit IRC | 13:30 | |
cloudnull | Ah just saw the review. | 13:31 |
*** mgoddard_ has joined #openstack-ansible | 13:31 | |
odyssey4me | Apsu yep, so now what - note that in a cloud server AIO build, everything works just fine :/ | 13:32 |
*** gardenshed has joined #openstack-ansible | 13:32 | |
mhayden | mattt: how it feels when those patches land: http://i.imgur.com/yChPXoX.gifv | 13:33 |
mattt | mhayden: can you do away with wc -l in https://review.openstack.org/#/c/234209 and just rely on exit code? | 13:33 |
* mhayden ganders | 13:33 | |
mhayden | mattt: the return codes were ugly on this one | 13:33 |
mhayden | that's why i went with wc -l to be 100% sure | 13:34 |
mattt | mhayden: ok cool | 13:34 |
*** mgoddard has quit IRC | 13:34 | |
Apsu | odyssey4me: Welp, lets see if we get the same error in the voting gate, first. | 13:35 |
odyssey4me | Apsu since the merge of the enablement of the arp spoofing protection, not a single voting job has failed | 13:35 |
Apsu | Nope. There's Other fun errors, but seem transient | 13:36 |
Apsu | (interface does not exist, which is super happy funtimes netlink race conditions) | 13:36 |
Apsu | odyssey4me: So, you're *certain* the policy.json in the neutron-agents container doesn't differ between these two check environments? You mentioned packages may be different | 13:37 |
*** gardenshed has quit IRC | 13:37 | |
odyssey4me | Apsu also, to confirm that arp spoofing protection is the culprit, this job passed on both counts: https://review.openstack.org/238472 | 13:37 |
Apsu | haha, nice. | 13:37 |
odyssey4me | Apsu yes, apt package are different - nothing we put down | 13:37 |
Apsu | Neat. | 13:37 |
odyssey4me | Apsu this is the list of packages on the working job that aren't on the broken job: http://pastebin.com/XdCGh76U | 13:38 |
odyssey4me | ^ apt packages | 13:38 |
Apsu | Because "operation not permitted" on modprobe (insmod, here) generally means you're not root, or there's some kind of lxc access issue (apparmor) | 13:39 |
Apsu | odyssey4me: Huh. Is there a kernel version difference? | 13:39 |
Apsu | Because there's linux-{headers,image} packages there. | 13:39 |
openstackgerrit | Tiago Gomes proposed openstack/openstack-ansible: Pass domain to some calls in the keystone library https://review.openstack.org/238509 | 13:41 |
odyssey4me | Apsu yep | 13:41 |
Apsu | odyssey4me: Can we make there not be? :P | 13:42 |
odyssey4me | linux-image-3.13.0-63 on the broken one, and linux-image-3.13.0-65 on the working | 13:42 |
Apsu | Wonder if there's a difference in apparmor versions too. | 13:43 |
Apsu | Wouldn't show up in your package name diff, but... | 13:43 |
Apsu | Let's see if we can find an apparmor complaint to accompany this | 13:43 |
Apsu | Because... in the same LBA log... there's multiple errors of "Network not available" | 13:43 |
tiagogomes__ | odyssey4me, https://review.openstack.org/#/c/238509/ | 13:43 |
Apsu | And that sounds to me like the surface of the issue -- no DHCP because Neutron can't activate the network ports, because (presumably) ebtables failures. | 13:44 |
odyssey4me | Apsu could be - do you need another log added to the list for diagnostics? | 13:45 |
Apsu | odyssey4me: Looking for syslog right now, don't see it. | 13:45 |
Apsu | odyssey4me: Also, http://logs.openstack.org/54/238454/1/check/gate-openstack-ansible-commit-nv/e1897fa/logs/ansible_cmd_logs/flush_net_cache.log | 13:46 |
Apsu | Why are we flushing net caches still? | 13:46 |
odyssey4me | Apsu that happens very early on - before the playbooks run: https://github.com/openstack/openstack-ansible/blob/master/scripts/run-playbooks.sh#L87 | 13:46 |
Apsu | Well In that log, there's a bunch of container IP entries. No earthly reason to flush them -- just like there's never any reason to actually flush the table, ever. | 13:47 |
Apsu | So just saying, should probably fix that :) | 13:48 |
Apsu | Might save you some timeout retries or other transient issues now and then, shave some minutes off the runtimes. | 13:48 |
Apsu | But yeah, syslog. | 13:48 |
Apsu | Need to see if apparmor is puking | 13:48 |
*** dolpher has joined #openstack-ansible | 13:51 | |
mhayden | mattt: i think this one is ready to roll, too -> https://review.openstack.org/#/c/233198/ | 13:52 |
odyssey4me | Apsu ok, will add that - do you need the compute host syslog, or the neutron agent container syslog - or both? | 13:53 |
mhayden | wow, 12 openstack-ansible-security reviews left (originally ~ 48) | 13:53 |
odyssey4me | cloudnull mattt hughsaunders this one should probably go in for the liberty release: https://review.openstack.org/238429 | 13:53 |
Apsu | odyssey4me: Probably only host, but might as well add both I suppose. Aren't the container logs all being shipped anyway? | 13:53 |
cloudnull | odyssey4me: ill point out that if we make https://review.openstack.org/#/c/230716 go then we dont have to deal with yaprt for liberty :) | 13:55 |
mattt | ++ | 13:55 |
openstackgerrit | Tiago Gomes proposed openstack/openstack-ansible: Pass domain to some calls in the keystone library https://review.openstack.org/238515 | 13:55 |
*** fawadkhaliq has joined #openstack-ansible | 14:00 | |
*** k_stev has joined #openstack-ansible | 14:02 | |
* mhayden tips his hat to mattt | 14:04 | |
palendae | cloudnull: Looks like the jobs failed to grab the ref for my patch | 14:04 |
*** fawadkhaliq has quit IRC | 14:04 | |
*** mgoddard has joined #openstack-ansible | 14:05 | |
*** mgoddard_ has quit IRC | 14:05 | |
cloudnull | hum... going to go look | 14:05 |
cloudnull | palendae: i fat fingered it | 14:07 |
cloudnull | running a new build now | 14:07 |
mattt | cloudnull: how do we handle upgradation of yaprt ? | 14:11 |
cloudnull | how so ? | 14:11 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:11 | |
mattt | cloudnull: i just checked out 11.2.4 on a 11.2.2 deploy and repo-server.yml failed as yaprt was expecting some flag which didn't exist on my version of yaprt | 14:11 |
*** jimchou has joined #openstack-ansible | 14:11 | |
mattt | cloudnull: hopefully not something we have to solve but if that other patch doesn't go through we'll need to look into it i guess | 14:12 |
cloudnull | the repo server needs to have yaprt upgraded | 14:12 |
cloudnull | the repo-server play should take care of that for you. | 14:12 |
mattt | cloudnull: yeah but we don't specify a version | 14:13 |
mattt | so if you have an old versoin installed the plays fail | 14:13 |
cloudnull | repo-build failed right ? | 14:13 |
mattt | yeah repo-build not repo-server | 14:13 |
mattt | yaprt: error: unrecognized arguments: --git-repo-path /var/www/repo/openstackgit | 14:13 |
cloudnull | you'd have to run repo-server then repo-build | 14:13 |
mattt | already have yaprt installed is my point :P | 14:14 |
mattt | rerunning repo-server doesn't upgrade yaprt | 14:14 |
cloudnull | right the repo-server play pulls for pypi which should see the new version | 14:14 |
cloudnull | if not then thats something we need to go solve | 14:14 |
mattt | i'll add a bug | 14:15 |
mattt | conditional on your deprecate yaprt review | 14:15 |
cloudnull | unless we make that specific problem go away: https://review.openstack.org/#/c/230716/ :) | 14:15 |
* mattt +2 | 14:15 | |
mattt | hehe | 14:15 |
cloudnull | f5 | 14:15 |
cloudnull | f5 | 14:15 |
cloudnull | f5 | 14:15 |
cloudnull | =P | 14:16 |
hughsaunders | haproxy | 14:16 |
odyssey4me | re-run repo-server with pip reinstall args, as is specified in the upgrade steps: http://docs.openstack.org/developer/openstack-ansible/install-guide/app-minorupgrade.html | 14:21 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Added log-store for the gate https://review.openstack.org/238531 | 14:21 |
cloudnull | ah mattt thatll do it | 14:22 |
cloudnull | what odyssey4me said | 14:22 |
*** Mudpuppy has joined #openstack-ansible | 14:22 | |
*** Mudpuppy has quit IRC | 14:22 | |
*** Mudpuppy has joined #openstack-ansible | 14:23 | |
mattt | cloudnull: ah! | 14:23 |
mattt | thanks openstackgerrit | 14:23 |
mattt | odyssey4me: :P | 14:23 |
cloudnull | i do that all the time | 14:23 |
cloudnull | odyssey4me: you need to change your name =P | 14:24 |
odyssey4me | mattt rtfd :p | 14:24 |
cloudnull | lol | 14:24 |
mhayden | i think openstackgerrit is the best ptl we've had | 14:29 |
* mhayden giggles | 14:29 | |
mattt | next time the PTL tells me to rtfd i won't vote for him again | 14:29 |
mattt | oh wait | 14:29 |
mattt | :P | 14:29 |
mhayden | mattt: i voted liberal | 14:29 |
hughsaunders | mattt: maybe you could stand next time | 14:30 |
*** mgoddard_ has joined #openstack-ansible | 14:31 | |
mattt | hughsaunders: http://i.kinja-img.com/gawker-media/image/upload/japbcvpavbzau9dbuaxf.jpg | 14:31 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement shippable venvs https://review.openstack.org/236183 | 14:32 |
hughsaunders | mattt: that is not a prereq for political positions | 14:32 |
cloudnull | mattt: ^ updated for versioned tarball | 14:32 |
mattt | cloudnull: nice will have a look! | 14:33 |
*** scarlisle has joined #openstack-ansible | 14:34 | |
cloudnull | it was a fairly simple change , updated the archive task for the name and changed the url in the play. idk if its functionality people will use but from a debugging / development prospective i can see how versioned files will be helpful. | 14:35 |
*** mgoddard has quit IRC | 14:35 | |
mattt | cloudnull: fully agree | 14:35 |
scarlisle | good morning | 14:35 |
cloudnull | o/ scarlisle | 14:35 |
mattt | howdy scarlisle | 14:35 |
scarlisle | hey cloudnull mattt | 14:36 |
scarlisle | I know this channel is for openstack-ansible, but I'm hitting a problem when running the setup_maas playbook. However, I'm not sure if the problem itself lies in the maas stuff or the openstack-ansible stuff | 14:38 |
mattt | scarlisle: what's the error ? | 14:38 |
scarlisle | error while evaluating conditional: inventory_hostname in groups['ceph_all'] | 14:38 |
mattt | scarlisle: ah ok, i know what it is | 14:39 |
scarlisle | I'm not able to find that group, so I guess its esssentially trying to check a Null reference with groups['ceph_all'] | 14:40 |
mattt | scarlisle: yeah i'm guessing you don't have a ceph.yml in /etc/openstack_deploy/env.d ? | 14:40 |
mattt | scarlisle: this is a kilo or later deploy i'm guessing ? | 14:41 |
scarlisle | I don't | 14:41 |
scarlisle | its an upgrade from 10.1.15 to 11.2.4 using r11.0.2 | 14:41 |
andymccr | scarlisle, mattt: https://github.com/rcbops/rpc-openstack/issues/492 | 14:43 |
scarlisle | ahh, thanks andymccr | 14:44 |
andymccr | scarlisle: might be easiest to just edit the main.yml in the way linked in that issue - that'll make it work. it was a logic issue unfortunatley :( | 14:44 |
mattt | andymccr: if you had ceph.yml in your env wouldn't ceph_all be defined ? | 14:44 |
andymccr | mattt: it would | 14:45 |
andymccr | but if you never install ceph you probably wouldnt have ceph.yml | 14:45 |
andymccr | which is why that issue exists really | 14:45 |
mattt | andymccr: https://github.com/rcbops/rpc-openstack/blob/master/rpcd/etc/openstack_deploy/env.d/ceph.yml | 14:45 |
mattt | i assumed that would always get copied in | 14:45 |
mattt | but perhaps not | 14:46 |
tiagogomes__ | is there any reason for the existence of the openrc_os_username, openrc_os_password variables? Can't those be inferred from the other variables | 14:46 |
*** mgoddard_ has quit IRC | 14:46 | |
andymccr | mattt: because its a manual copy | 14:46 |
andymccr | on existing deploys you probably wouldnt copy it in | 14:46 |
mattt | i see | 14:46 |
*** mgoddard has joined #openstack-ansible | 14:46 | |
scarlisle | andymccr exactly | 14:46 |
andymccr | i kinda wish it would just evaluate it and say "well its not in that group since the group doesnt exist!" :D | 14:46 |
mattt | hehe | 14:47 |
mattt | yea | 14:47 |
cloudnull | tiagogomes__: its defined here playbooks/inventory/group_vars/hosts.yml:218:openrc_os_password: "{{ keystone_auth_admin_password }}" however yes that functionality could likely be smarter | 14:47 |
tiagogomes__ | cloudnull unfortunately not openrc_os_username | 14:48 |
cloudnull | which play cadence to moving some of the CRUD ops to specific roles to make that interaction better | 14:49 |
tiagogomes__ | that one was forgiven | 14:49 |
cloudnull | well you can define openrc_os_username to override it if needed | 14:49 |
mhayden | mattt: https://review.openstack.org/#/c/233284/2 | 14:50 |
tiagogomes__ | that's what I did, but not what I should do :) | 14:50 |
cloudnull | ++ agreeded | 14:50 |
cloudnull | It'd be great to spec out a process to improve that whole process | 14:51 |
cloudnull | same w/ db create and administrative api interactions | 14:51 |
*** phalmos has joined #openstack-ansible | 14:52 | |
*** gardenshed has joined #openstack-ansible | 14:53 | |
*** subscope has quit IRC | 14:54 | |
*** karimb_ has joined #openstack-ansible | 14:56 | |
*** markvoelker_ has joined #openstack-ansible | 14:57 | |
*** darrenc_ has joined #openstack-ansible | 14:58 | |
*** matt______ has joined #openstack-ansible | 14:59 | |
*** mcarden_ has joined #openstack-ansible | 14:59 | |
*** neillc_ has joined #openstack-ansible | 15:00 | |
*** gus_ has joined #openstack-ansible | 15:00 | |
*** fawadkhaliq has joined #openstack-ansible | 15:01 | |
*** daneyon has joined #openstack-ansible | 15:02 | |
*** palendae_ has joined #openstack-ansible | 15:03 | |
*** bgmccollum_ has joined #openstack-ansible | 15:03 | |
*** b3rnard0- has joined #openstack-ansible | 15:04 | |
*** dolphm_ has joined #openstack-ansible | 15:04 | |
*** timrc_ has joined #openstack-ansible | 15:04 | |
*** jroll|dupe has joined #openstack-ansible | 15:04 | |
*** eglute_s has joined #openstack-ansible | 15:04 | |
*** _d34dh0r53_ has joined #openstack-ansible | 15:04 | |
*** palendae_ has quit IRC | 15:04 | |
*** jimchou has quit IRC | 15:05 | |
*** fawadkhaliq has quit IRC | 15:05 | |
*** mgagne_ has joined #openstack-ansible | 15:05 | |
*** _sigmavirus24 has joined #openstack-ansible | 15:05 | |
*** palendae_ has joined #openstack-ansible | 15:05 | |
*** persia_ has joined #openstack-ansible | 15:06 | |
*** persia_ has quit IRC | 15:06 | |
*** persia_ has joined #openstack-ansible | 15:06 | |
*** palendae_ has quit IRC | 15:06 | |
*** karimb has quit IRC | 15:06 | |
*** markvoelker has quit IRC | 15:06 | |
*** persia has quit IRC | 15:06 | |
*** tiagogomes__ has quit IRC | 15:06 | |
*** neillc has quit IRC | 15:06 | |
*** timrc has quit IRC | 15:06 | |
*** palendae has quit IRC | 15:06 | |
*** mgagne has quit IRC | 15:06 | |
*** sigmavirus24 has quit IRC | 15:06 | |
*** meteorfox has quit IRC | 15:06 | |
*** eglute has quit IRC | 15:06 | |
*** d34dh0r53 has quit IRC | 15:06 | |
*** jroll has quit IRC | 15:06 | |
*** bgmccollum has quit IRC | 15:06 | |
*** dolphm has quit IRC | 15:06 | |
*** gus has quit IRC | 15:06 | |
*** mcarden has quit IRC | 15:06 | |
*** mattoliverau has quit IRC | 15:06 | |
*** darrenc has quit IRC | 15:06 | |
*** errr has quit IRC | 15:06 | |
*** odyssey4me has quit IRC | 15:06 | |
*** b3rnard0 has quit IRC | 15:06 | |
*** spotz_zzz has quit IRC | 15:06 | |
*** dolphm_ is now known as dolphm | 15:06 | |
*** jroll|dupe is now known as jroll | 15:06 | |
*** daneyon_ has joined #openstack-ansible | 15:06 | |
scarlisle | commenting out that section seems to have gotten me past that. Thanks andymccr mattt | 15:07 |
*** spotz_zzz has joined #openstack-ansible | 15:07 | |
*** persia_ is now known as persia | 15:07 | |
andymccr | scarlisle: excellent - that should be fixed in the near future | 15:07 |
*** palendae has joined #openstack-ansible | 15:07 | |
*** _sigmavirus24 is now known as sigmavirus24 | 15:08 | |
*** sigmavirus24 has joined #openstack-ansible | 15:08 | |
*** phalmos has quit IRC | 15:09 | |
*** meteorfox has joined #openstack-ansible | 15:09 | |
*** daneyon has quit IRC | 15:09 | |
*** phalmos has joined #openstack-ansible | 15:10 | |
*** odyssey4me has joined #openstack-ansible | 15:17 | |
*** galstrom_zzz is now known as galstrom | 15:21 | |
logan2 | is there a way to set container_vars across a group of hosts rather than individually? I have 61 lines of cinder_backends to set on each cinder_volume host and it seems like the only documented way to set that up is under each individual storage_host entry for every single host. since the backends are identical across all of these hosts (rbd setup) i would like to group it all together | 15:22 |
logan2 | if possible | 15:22 |
*** fawadkhaliq has joined #openstack-ansible | 15:32 | |
*** neilus has joined #openstack-ansible | 15:33 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 15:37 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:37 | |
*** tiagogomes__ has joined #openstack-ansible | 15:38 | |
*** mgoddard_ has joined #openstack-ansible | 15:45 | |
*** mgoddard has quit IRC | 15:48 | |
*** mpavone has quit IRC | 15:48 | |
*** errr has joined #openstack-ansible | 15:51 | |
*** phalmos has quit IRC | 15:54 | |
odyssey4me | Apsu heh, good timing - we have a dhcp failure in both jobs - and now also have the syslogs: http://logs.openstack.org/31/238531/1/check/gate-openstack-ansible-dsvm-commit/ff7c5e0/logs/log-storage/ | 15:57 |
odyssey4me | also http://logs.openstack.org/31/238531/1/check/gate-openstack-ansible-commit-nv/d654d5d/ | 15:57 |
odyssey4me | the syslogs are in logs/log-storage/ | 15:58 |
*** mgoddard_ has quit IRC | 16:00 | |
*** mgoddard has joined #openstack-ansible | 16:00 | |
odyssey4me | community meeting in #openstack-meeting-4 cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, mancdaz, dolphm, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle | 16:02 |
Apsu | odyssey4me: Er... sizes are all 0.... | 16:02 |
Apsu | We'll talk after meeting. | 16:02 |
*** phalmos has joined #openstack-ansible | 16:02 | |
Apsu | Seemingly every log in every directory, lol | 16:02 |
openstackgerrit | Miguel Grinberg proposed openstack/openstack-ansible: Update heat keystone_authtoken config https://review.openstack.org/235978 | 16:02 |
miguelgrinberg | odyssey4me: pls take a look at what I changed in ^ | 16:03 |
miguelgrinberg | I added the auth_plugin that was missing, and a new set of trustee vars | 16:04 |
tiagogomes__ | odd, I can't override neutron_service_user_name | 16:12 |
*** jwagner_away is now known as jwagner | 16:13 | |
tiagogomes__ | I had to comment out neutron_service_user_name in inventory/group_vars/hosts.yml | 16:16 |
*** b3rnard0- is now known as b3rnard0 | 16:16 | |
*** gparaskevas has quit IRC | 16:17 | |
odyssey4me | thanks miguelgrinberg - will check it... hopefully it gates! | 16:19 |
Sam-I-Am | miguelgrinberg: why two [trustee] sections? | 16:25 |
*** neilus has quit IRC | 16:26 | |
Sam-I-Am | with some of the same values | 16:26 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Updated for a couple nits https://review.openstack.org/238607 | 16:28 |
miguelgrinberg | Sam-I-Am: did I put two? Let me check | 16:30 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Disable prevent_arp_spoofing https://review.openstack.org/238472 | 16:30 |
miguelgrinberg | Sam-I-Am: oh, I forgot to remove the one odyssey4me added | 16:31 |
*** Bjoern_ has joined #openstack-ansible | 16:31 | |
Sam-I-Am | odyssey4me: re arp spoof, where are you seeing these problems? | 16:31 |
openstackgerrit | Miguel Grinberg proposed openstack/openstack-ansible: Update heat keystone_authtoken config https://review.openstack.org/235978 | 16:31 |
miguelgrinberg | Sam-I-Am: fixed | 16:32 |
Sam-I-Am | miguelgrinberg: cool. i might be using this for the upstream install guide, and then following up to figure out docs for it | 16:32 |
Sam-I-Am | because right now its definitely magic | 16:32 |
*** karimb_ has quit IRC | 16:33 | |
miguelgrinberg | Sam-I-Am: if the trustee section is missing keystone_authtoken is used in its place | 16:34 |
miguelgrinberg | it's not ideal, but in 99% of the cases they'll be configured the same | 16:34 |
Sam-I-Am | sure, but [trustee] doesnt appear via oslo.config yet | 16:34 |
Sam-I-Am | we need to fix those bits | 16:34 |
*** _d34dh0r53_ is now known as d34dh0r53 | 16:34 | |
miguelgrinberg | yes, I agree. That was something we missed | 16:34 |
*** rajalokan has joined #openstack-ansible | 16:41 | |
*** g3rms_ has joined #openstack-ansible | 16:44 | |
*** g3rms_ has quit IRC | 16:47 | |
*** dolpher has quit IRC | 16:48 | |
*** elo has joined #openstack-ansible | 16:48 | |
Bjoern_ | what's next on the triaging ? | 16:50 |
*** Bjoern_ is now known as BjoernT | 16:50 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy https://review.openstack.org/220365 | 16:52 |
cloudnull | BjoernT: ^ i rebased that off of master for a merge conflict | 16:52 |
BjoernT | nice | 16:53 |
BjoernT | I want to look at this monday to get the latest comments covered | 16:53 |
odyssey4me | BjoernT it needs to be finalised today - if it's not in tomorrow, then it'll have to wait for 12.1.0 | 16:53 |
BjoernT | ok | 16:53 |
BjoernT | then earlier | 16:53 |
BjoernT | i guess | 16:54 |
odyssey4me | :) | 16:54 |
*** jwagner is now known as jwagner_away | 16:54 | |
odyssey4me | Apsu yeah, I see the zero sized files :/ | 16:54 |
BjoernT | We still have few bugs committed to juno but no release tag on them like https://bugs.launchpad.net/openstack-ansible/+bug/1508207 | 16:54 |
openstack | Launchpad bug 1508207 in openstack-ansible juno "Checking additional RabbitMQ metrics: fd, sockets and processes" [Undecided,In progress] - Assigned to Bjoern Teipel (bjoern-teipel) | 16:55 |
BjoernT | or https://bugs.launchpad.net/openstack-ansible/+bug/1483877 | 16:55 |
openstack | Launchpad bug 1483877 in openstack-ansible juno "lxc pinning to 1.0.7-0ubuntu0.1 is causing issues" [Undecided,Fix committed] - Assigned to Bjoern Teipel (bjoern-teipel) | 16:55 |
BjoernT | 10.1.16 was today right ? | 16:55 |
odyssey4me | BjoernT nope, tomorrow | 16:55 |
odyssey4me | thanks for raising those - I usually do a sweep through the patches to pick up on orphans, but sometimes they slip through the cracks | 16:56 |
BjoernT | yeah they are pretty fresh comitted | 16:57 |
odyssey4me | BjoernT if you can test and add your experience on https://review.openstack.org/236151 and https://review.openstack.org/226621 it would be helpful | 16:58 |
BjoernT | yes I can | 16:59 |
odyssey4me | awesome, thanks | 16:59 |
*** gardenshed has quit IRC | 17:02 | |
*** daneyon_ has quit IRC | 17:08 | |
*** g3rms_ has joined #openstack-ansible | 17:11 | |
*** daneyon has joined #openstack-ansible | 17:15 | |
*** daneyon_ has joined #openstack-ansible | 17:16 | |
*** daneyon has quit IRC | 17:20 | |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Load glance metadata definitions https://review.openstack.org/235425 | 17:23 |
*** mgoddard has quit IRC | 17:28 | |
*** sdake has joined #openstack-ansible | 17:33 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Load glance metadata definitions https://review.openstack.org/235425 | 17:42 |
cloudnull | sigmavirus24: if you get a chance that should load the metadata defs | 17:43 |
sigmavirus24 | cloudnull: published a -1 | 17:53 |
*** jimchou has joined #openstack-ansible | 17:58 | |
*** mgagne_ is now known as mgagne | 18:03 | |
*** sdake_ has joined #openstack-ansible | 18:03 | |
*** sdake has quit IRC | 18:05 | |
cloudnull | haha thats a problem | 18:06 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Load glance metadata definitions https://review.openstack.org/235425 | 18:07 |
cloudnull | updated | 18:07 |
odyssey4me | sigmavirus24 cloudnull thanks for picking that up | 18:11 |
odyssey4me | miguelgrinberg https://review.openstack.org/235978 looks good to me now, and passed the gate! | 18:13 |
odyssey4me | Sam-I-Am ^ | 18:13 |
odyssey4me | cloudnull sigmavirus24 https://review.openstack.org/235978 needs some voting :) | 18:13 |
odyssey4me | d34dh0r53 sigmavirus24 we need a second vote on https://review.openstack.org/238472 to unblock the gate - arp spoofing protection is causing high volume failure in gate checks | 18:15 |
odyssey4me | stevelle ^ | 18:15 |
cloudnull | d34dh0r53 sigmavirus24 stevelle andymccr mattt hughsaunders can we get this through https://review.openstack.org/#/c/238472 that functionality is blocking the gate at this point | 18:15 |
cloudnull | hahaha | 18:15 |
cloudnull | odyssey4me: beat me to it | 18:15 |
odyssey4me | lol | 18:15 |
lbragstad | Hey osa folks - quick keystone question for you. Does openstack-ansible provide a generic/default mapping when setting up a keystone service provider? https://github.com/openstack/openstack-ansible/blob/master/playbooks/library/keystone#L1127-L1134 | 18:15 |
odyssey4me | lbragstad we provide examples | 18:16 |
lbragstad | odyssey4me ok, but then it's up to the service provider to actually do the real mapping | 18:16 |
*** rajalokan has quit IRC | 18:17 | |
odyssey4me | lbragstad https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/os_keystone/defaults/main.yml#L244-L266 | 18:17 |
odyssey4me | lbragstad yes, the mappings are based on whatever the SP wants - we provide a basic functional example | 18:17 |
odyssey4me | it's only an example because it depends on how the IdP has setup the attributes they share | 18:18 |
lbragstad | odyssey4me ah interesting | 18:18 |
odyssey4me | lbragstad this will work for a standard shibboleth IdP https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/os_keystone/defaults/main.yml#L281-L292 | 18:18 |
lbragstad | right, so for that example, as long as the idp has openstack_user set as an attribute, the keystone service provider will map that to the default domain | 18:18 |
odyssey4me | and this for adfs3 https://github.com/openstack/openstack-ansible/blob/master/playbooks/roles/os_keystone/defaults/main.yml#L307-L321 | 18:18 |
lbragstad | with the fedgroup | 18:19 |
odyssey4me | yeah, so in each case all federated users will be added to the group 'fedgroup' which is setup in the domain with the name 'Default' | 18:19 |
lbragstad | odyssey4me cool, that makes sense | 18:19 |
odyssey4me | we provide some docs here http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-federation.html | 18:20 |
odyssey4me | they're not perfect, but they try to explain how to do it with openstack-ansible and also to explain how the mappings and keystone bits work in a basic way | 18:21 |
odyssey4me | I'll be prepping a blog post asap on the state in Liberty, and submit patches for it too. It'll likely only happen after the summit though. | 18:22 |
odyssey4me | Liberty has some changed bits which we haven't yet worked through - but those configs are good for Kilo. | 18:22 |
lbragstad | odyssey4me cool, thanks for the information! | 18:22 |
odyssey4me | lbragstad no problem :) | 18:23 |
odyssey4me | will we be seeing you in Tokyo? | 18:23 |
lbragstad | odyssey4me yes sir! | 18:23 |
odyssey4me | excellent, we shall have to have a suitable beverage and share war stories :p | 18:24 |
*** CheKoLyN has joined #openstack-ansible | 18:24 | |
lbragstad | odyssey4me ++ | 18:24 |
d34dh0r53 | odyssey4me: cloudnull done | 18:26 |
odyssey4me | rocking, thanks d34dh0r53 | 18:26 |
*** sdake_ has quit IRC | 18:26 | |
d34dh0r53 | odyssey4me: cloudnull no problem, either of you seen this with juno http://paste.openstack.org/show/477185/ | 18:27 |
odyssey4me | d34dh0r53 was that a fresh aio, or did you teardown and rebuild? | 18:28 |
d34dh0r53 | trying to upgrade with https://review.openstack.org/#/c/226621 applied | 18:29 |
*** gardenshed has joined #openstack-ansible | 18:29 | |
odyssey4me | odd, never seen that - but it would seem like the bindmount is still being held by a previous process or something | 18:30 |
odyssey4me | are you sure that the container isn't already running? | 18:30 |
d34dh0r53 | it's state is stopped, and there is only 1 cinder volumes container | 18:30 |
d34dh0r53 | I found the error really odd | 18:31 |
d34dh0r53 | google has nothing :/ | 18:31 |
*** jwagner_away is now known as jwagner | 18:32 | |
*** gardenshed has quit IRC | 18:32 | |
odyssey4me | d34dh0r53 I'm out for the night. Sorry - hope you find a solution. :/ | 18:32 |
*** sdake has joined #openstack-ansible | 18:35 | |
d34dh0r53 | odyssey4me: no worries mate, have a good evening | 18:35 |
*** sdake has quit IRC | 18:39 | |
*** daneyon_ has quit IRC | 18:42 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: [WIP] Use full command when reporting upgrade failure https://review.openstack.org/237689 | 18:46 |
*** phalmos has quit IRC | 18:50 | |
*** phalmos has joined #openstack-ansible | 18:52 | |
*** phalmos has quit IRC | 18:54 | |
*** phalmos has joined #openstack-ansible | 18:54 | |
*** phalmos has quit IRC | 19:00 | |
*** gardenshed has joined #openstack-ansible | 19:01 | |
cloudnull | d34dh0r53: what kernel are you running ? | 19:03 |
*** gardenshed has quit IRC | 19:04 | |
cloudnull | 3.16.51 is busted | 19:04 |
d34dh0r53 | 3.13.0-62 | 19:04 |
cloudnull | oh, i have seen this specific error | 19:04 |
cloudnull | one sec | 19:04 |
d34dh0r53 | cool | 19:05 |
cloudnull | that was an upgrade using the old busted script which was fixed here https://github.com/openstack/openstack-ansible/blob/kilo/scripts/upgrade-utilities/playbooks/cinder-adjustments.yml | 19:05 |
cloudnull | its caused by a double udev entry | 19:05 |
cloudnull | in the container config | 19:05 |
d34dh0r53 | ohh, sweet | 19:05 |
cloudnull | so if you run that part it will fix it for you | 19:06 |
cloudnull | info found here http://docs.openstack.org/developer/openstack-ansible/kilo/upgrade-guide/upgrade-playbooks.html#cinder-adjustments-yml | 19:06 |
d34dh0r53 | so from 10.1.15 to 10.1.16 we'll need that backported to juno? | 19:06 |
cloudnull | its a kilo upgrade issue | 19:07 |
d34dh0r53 | I'm running into in on juno -> juno | 19:07 |
cloudnull | oh then its an issue there too then | 19:07 |
cloudnull | :) | 19:07 |
cloudnull | i had thought palendae got that into juno already https://github.com/openstack/openstack-ansible/commit/f0db75ce27649e092fb5c3f651dbf07cb3f9a8d0 | 19:08 |
palendae | Hm | 19:08 |
cloudnull | however it may not be processing that conditional correctly. | 19:08 |
cloudnull | or blowing up prior to the fix being run | 19:09 |
palendae | Also, worth mentioning, it's a post action because if it was a pre, the task itself would just override the 'fix' | 19:09 |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Use full command when reporting upgrade failure https://review.openstack.org/237689 | 19:13 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Make the container cache resolvers configurable https://review.openstack.org/238223 | 19:19 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Load glance metadata definitions https://review.openstack.org/235425 | 19:22 |
openstackgerrit | Merged openstack/openstack-ansible: Disable prevent_arp_spoofing https://review.openstack.org/238472 | 19:26 |
cloudnull | d34dh0r53: was it the container config that was causing the issue ? | 19:27 |
d34dh0r53 | cloudnull: looking now | 19:27 |
cloudnull | would someone like to review the browsable source fix https://review.openstack.org/#/c/238042/ ? | 19:28 |
cloudnull | that'd be nice to have wrapped up | 19:28 |
d34dh0r53 | cloudnull: yep http://paste.openstack.org/show/477192/ | 19:29 |
*** gardenshed has joined #openstack-ansible | 19:32 | |
*** jwagner is now known as jwagner_away | 19:34 | |
*** gardensh_ has joined #openstack-ansible | 19:34 | |
*** gardenshed has quit IRC | 19:37 | |
cloudnull | so we might need to have a pre-step for upgrades of juno or somehow wedge that in as a pretask | 19:38 |
palendae | >.< | 19:38 |
palendae | cloudnull: Yeah, in my tests, if I had it only as a pre-task, the actual task would override it | 19:38 |
*** phalmos has joined #openstack-ansible | 19:38 | |
*** phalmos has quit IRC | 19:40 | |
cloudnull | we could fix the actual task and then add a pre-task too ? | 19:40 |
*** fawadkhaliq has quit IRC | 19:40 | |
palendae | Probably the right way to do it | 19:42 |
palendae | Have a pre-task to fix it if broken, lay down the right one if it's not there | 19:43 |
palendae | Wasn't the problem in the lxc module, though? | 19:43 |
cloudnull | palendae: nope its in the config entry | 19:48 |
palendae | Hm, I thought we fixed that | 19:48 |
cloudnull | the issue is here rpc_deployment/vars/config_vars/container_config_cinder_volume.yml: - "lxc.mount.entry = udev dev devtmpfs defaults 0 0" | 19:48 |
cloudnull | which should be rpc_deployment/vars/config_vars/container_config_cinder_volume.yml: - "lxc.mount.entry=udev dev devtmpfs defaults 0 0" | 19:48 |
cloudnull | for juno | 19:49 |
palendae | Ahhh | 19:49 |
openstackgerrit | Jesse Pretorius proposed openstack/openstack-ansible: Updated the repo-build process https://review.openstack.org/230716 | 20:04 |
*** jwagner_away is now known as jwagner | 20:05 | |
*** sdake has joined #openstack-ansible | 20:12 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Mysql file handles not correctly configured https://review.openstack.org/238683 | 20:15 |
openstackgerrit | Merged openstack/openstack-ansible: Add theme fix for browsable source code https://review.openstack.org/238042 | 20:23 |
*** mcarden_ is now known as mcarden | 20:23 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Mysql file handles not correctly configured https://review.openstack.org/238685 | 20:26 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy https://review.openstack.org/220365 | 20:34 |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Implement Neutron LBAAS using haproxy https://review.openstack.org/220365 | 20:37 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Enable encryption between nova/RabbitMQ https://review.openstack.org/238691 | 20:44 |
*** matt______ is now known as mattoliverau | 20:46 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: Mysql file handles not correctly configured https://review.openstack.org/238685 | 20:47 |
*** jaypipes has quit IRC | 20:47 | |
*** sdake has quit IRC | 20:48 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Enable encryption between nova/RabbitMQ https://review.openstack.org/238691 | 20:50 |
*** galstrom is now known as galstrom_zzz | 20:59 | |
*** KLevenstein has joined #openstack-ansible | 21:03 | |
*** k_stev has quit IRC | 21:04 | |
*** k_stev has joined #openstack-ansible | 21:17 | |
*** sdake has joined #openstack-ansible | 21:29 | |
*** sdake has quit IRC | 21:30 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Allow protocol to be set per endpoint-type https://review.openstack.org/226621 | 21:32 |
*** jwagner is now known as jwagner_away | 21:33 | |
*** timrc_ is now known as timrc | 21:37 | |
*** sdake has joined #openstack-ansible | 21:39 | |
*** sdake_ has joined #openstack-ansible | 21:42 | |
*** sdake has quit IRC | 21:43 | |
*** KLevenstein has quit IRC | 21:53 | |
*** alop has joined #openstack-ansible | 21:53 | |
*** sdake_ has quit IRC | 22:00 | |
*** sdake has joined #openstack-ansible | 22:00 | |
*** CheKoLyN has quit IRC | 22:00 | |
*** darrenc_ is now known as darrenc | 22:03 | |
*** Mudpuppy has quit IRC | 22:05 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:08 | |
openstackgerrit | Merged openstack/openstack-ansible: Load glance metadata definitions https://review.openstack.org/235425 | 22:09 |
openstackgerrit | Merged openstack/openstack-ansible: Updated the repo-build process https://review.openstack.org/230716 | 22:10 |
*** jimchou has quit IRC | 22:12 | |
*** gardensh_ has quit IRC | 22:12 | |
*** neillc_ is now known as neillc | 22:25 | |
openstackgerrit | Merged openstack/openstack-ansible: Adding new RabbitMQ alarms (fd,proc,sockets) https://review.openstack.org/237783 | 22:28 |
BjoernT | hey guys did we recently upgrade galera in kilo ? | 22:30 |
BjoernT | I can't get galera up and the reason is a crashing xtrabackup on the first node | 22:30 |
*** darrenc is now known as darrenc_afk | 22:36 | |
*** darrenc_afk is now known as darrenc | 22:45 | |
openstackgerrit | Merged openstack/openstack-ansible-security: V-386**: Disabling various unneeded services https://review.openstack.org/233198 | 22:48 |
openstackgerrit | Merged openstack/openstack-ansible-security: V-38683: Check for non-unique usernames https://review.openstack.org/234209 | 22:50 |
*** sdake has quit IRC | 23:01 | |
stevelle | BjoernT: seeing the same thing in master, actually | 23:13 |
openstackgerrit | Merged openstack/openstack-ansible: Allow protocol to be set per endpoint-type https://review.openstack.org/226621 | 23:15 |
*** alop has quit IRC | 23:16 | |
*** k_stev has quit IRC | 23:18 | |
palendae | BjoernT, stevelle I know MariaDB was moved to 10 for master (which is Liberty), but I'm pretty confident that wasn't done in Kilo | 23:20 |
stevelle | the work that was planned to go to kilo (I don't recall seeing it yet) was only the cluster management. 10 was not scheduled for kilo. | 23:22 |
palendae | No, I'm on the cluster management and haven | 23:22 |
palendae | 't gotten a patch proposed yet | 23:22 |
stevelle | error: 'Can't connect to local MySQL server through socket ... (111 "Connection refused")' | 23:23 |
stevelle | that's what I have now | 23:23 |
*** gus_ is now known as gus | 23:24 | |
*** woodard_ has joined #openstack-ansible | 23:24 | |
*** woodard has quit IRC | 23:25 | |
*** alop has joined #openstack-ansible | 23:29 | |
*** alop has quit IRC | 23:29 | |
BjoernT | palendae: I got closer to the issue that --galera-info cause the innobackupex to crash. I did rebuilt the database on the master and now it's fixed. Now I'm on the 2nd node which fails additionally really stange | 23:30 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Enable encryption between nova/RabbitMQ https://review.openstack.org/238691 | 23:32 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Pass domain to some calls in the keystone library https://review.openstack.org/238509 | 23:32 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Updated for a couple nits https://review.openstack.org/238607 | 23:33 |
*** woodard_ has quit IRC | 23:34 | |
*** sdake has joined #openstack-ansible | 23:34 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement shippable venvs https://review.openstack.org/236183 | 23:35 |
*** tlian2 has joined #openstack-ansible | 23:38 | |
*** tlian has quit IRC | 23:40 | |
*** sdake has quit IRC | 23:46 | |
*** sdake has joined #openstack-ansible | 23:50 | |
cloudnull | stevelle: BjoernT: you still seeing the galera crashing ? | 23:56 |
stevelle | cloudnull: I am | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!