*** openstackgerrit has quit IRC | 00:01 | |
*** openstackgerrit has joined #openstack-ansible | 00:02 | |
*** dolpher has joined #openstack-ansible | 00:19 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Updated container_images path https://review.openstack.org/239552 | 00:55 |
---|---|---|
*** abitha has quit IRC | 01:08 | |
*** harlowja has quit IRC | 01:09 | |
bgmccollum | cloudnull: juno downloads from a different url, which is still returning a 403 -- https://mirror.rackspace.com/rackspaceprivatecloud/rpc-trusty-container.tgz -- https://github.com/openstack/openstack-ansible/blob/juno/rpc_deployment/roles/lxc_common/tasks/lxc_container_cache.yml#L18 -- https://github.com/openstack/openstack-ansible/blob/juno/rpc_deployment/inventory/group_vars/all.yml#L51 | 01:11 |
bgmccollum | cloudnull: just say the review... | 01:12 |
bgmccollum | saw* | 01:12 |
cloudnull | the mirror will take a few hours to update | 01:12 |
cloudnull | I updated the index and links to all be relative but to "resolve" the issue for real I updated the review | 01:13 |
cloudnull | view-source:http://rpc-repo.rackspace.com/ | 01:13 |
cloudnull | that should hit the mirror in the next 4-6 hours | 01:13 |
*** daneyon has joined #openstack-ansible | 01:14 | |
bgmccollum | cool | 01:14 |
cloudnull | its frustrating that https://mirror.rackspace.com/rackspaceprivatecloud/rpc-trusty-container.tgz is broken w/ curl but works in a browser :) | 01:15 |
cloudnull | but all will be better soon | 01:15 |
*** sdake has joined #openstack-ansible | 01:16 | |
*** sdake has quit IRC | 01:20 | |
bgmccollum | cloudnull: from the browser, because is HTML, its actually a different URL | 01:20 |
bgmccollum | ill hold for mirror sync | 01:21 |
bgmccollum | thanks | 01:21 |
*** tlian has quit IRC | 01:22 | |
*** daneyon_ has joined #openstack-ansible | 01:28 | |
*** tlian has joined #openstack-ansible | 01:29 | |
*** daneyon has quit IRC | 01:31 | |
*** dolpher has quit IRC | 01:34 | |
*** woodard has joined #openstack-ansible | 01:40 | |
*** daneyon_ has quit IRC | 01:53 | |
*** woodard has quit IRC | 01:57 | |
*** daneyon has joined #openstack-ansible | 01:59 | |
*** daneyon_ has joined #openstack-ansible | 02:02 | |
*** daneyon has quit IRC | 02:04 | |
*** daneyon has joined #openstack-ansible | 02:06 | |
*** daneyon_ has quit IRC | 02:06 | |
*** daneyon_ has joined #openstack-ansible | 02:15 | |
*** daneyon has quit IRC | 02:17 | |
*** markvoelker has joined #openstack-ansible | 02:18 | |
openstackgerrit | Merged openstack/openstack-ansible: Small spelling fix in dynamic_inventory.py https://review.openstack.org/239509 | 02:30 |
*** daneyon has joined #openstack-ansible | 02:50 | |
*** markvoelker has quit IRC | 02:50 | |
*** daneyon_ has quit IRC | 02:51 | |
*** markvoelker has joined #openstack-ansible | 02:56 | |
*** rebase has joined #openstack-ansible | 02:58 | |
*** rebase has quit IRC | 03:01 | |
*** harlowja has joined #openstack-ansible | 03:01 | |
*** harlowja has quit IRC | 03:02 | |
openstackgerrit | yapeng Yang proposed openstack/openstack-ansible: Add source into README.rst https://review.openstack.org/239438 | 03:05 |
*** spotz_zzz is now known as spotz | 03:10 | |
*** rebase has joined #openstack-ansible | 03:11 | |
*** dolpher has joined #openstack-ansible | 03:15 | |
*** daneyon has quit IRC | 03:15 | |
*** spotz is now known as spotz_zzz | 03:16 | |
*** markvoelker has quit IRC | 03:16 | |
*** rebase has quit IRC | 03:16 | |
*** daneyon has joined #openstack-ansible | 03:17 | |
*** markvoelker has joined #openstack-ansible | 03:30 | |
*** daneyon_ has joined #openstack-ansible | 03:36 | |
*** rebase has joined #openstack-ansible | 03:36 | |
*** markvoelker has quit IRC | 03:37 | |
*** daneyon has quit IRC | 03:37 | |
*** skamithi13 has quit IRC | 03:39 | |
*** jhesketh has quit IRC | 03:44 | |
*** jhesketh has joined #openstack-ansible | 03:47 | |
*** rebase has quit IRC | 03:47 | |
*** rromans has quit IRC | 03:58 | |
*** tlian has quit IRC | 04:04 | |
*** abitha has joined #openstack-ansible | 04:16 | |
*** daneyon_ has quit IRC | 04:21 | |
*** rebase has joined #openstack-ansible | 04:44 | |
*** rebase has quit IRC | 04:47 | |
*** harlowja has joined #openstack-ansible | 04:49 | |
*** harlowja has quit IRC | 04:50 | |
*** abitha has quit IRC | 05:06 | |
*** abitha has joined #openstack-ansible | 05:07 | |
*** abitha has quit IRC | 05:11 | |
*** harlowja has joined #openstack-ansible | 05:19 | |
*** harlowja has quit IRC | 05:24 | |
*** javeriak has joined #openstack-ansible | 05:42 | |
*** javeriak has quit IRC | 05:54 | |
*** shausy has joined #openstack-ansible | 05:56 | |
*** openstackgerrit has quit IRC | 06:01 | |
*** daneyon has joined #openstack-ansible | 06:14 | |
*** openstackgerrit has joined #openstack-ansible | 06:14 | |
*** daneyon_ has joined #openstack-ansible | 06:16 | |
*** daneyon has quit IRC | 06:20 | |
-openstackstatus- NOTICE: CI will be disrupted for an indeterminate period while our service provider reboots systems for a security fix | 06:28 | |
*** ChanServ changes topic to "CI will be disrupted for an indeterminate period while our service provider reboots systems for a security fix" | 06:28 | |
*** javeriak has joined #openstack-ansible | 06:41 | |
*** Sam-I-Am has quit IRC | 07:00 | |
*** sura8257 has joined #openstack-ansible | 07:28 | |
*** jhesketh has quit IRC | 07:29 | |
*** jhesketh has joined #openstack-ansible | 07:32 | |
*** javeriak has quit IRC | 07:34 | |
*** javeriak_ has joined #openstack-ansible | 07:34 | |
*** javeriak_ has quit IRC | 07:40 | |
*** antonym has quit IRC | 07:43 | |
*** mpavone has joined #openstack-ansible | 07:58 | |
*** neilus1 has joined #openstack-ansible | 07:59 | |
*** erikmwilson has quit IRC | 08:04 | |
*** sura8257__ has joined #openstack-ansible | 08:11 | |
*** daneyon_ has quit IRC | 08:12 | |
*** gardenshed has joined #openstack-ansible | 08:14 | |
*** gardenshed has quit IRC | 08:14 | |
*** gardenshed has joined #openstack-ansible | 08:15 | |
*** sura8257 has quit IRC | 08:15 | |
*** metral_zzz is now known as metral | 08:19 | |
evrardjp | FYI, the talk about optimizing rabbitmq of this morning is also talking about the clustering of rabbitmq, that maybe worth checking | 08:25 |
*** metral is now known as metral_zzz | 08:29 | |
*** dolpher has quit IRC | 08:30 | |
*** karimb has joined #openstack-ansible | 09:13 | |
*** sura8257__ has quit IRC | 09:15 | |
*** subscope has joined #openstack-ansible | 09:22 | |
tiagogomes | cloudnull I'll test it, but I doubt that it will help debugging the cinder problem | 09:25 |
tiagogomes | evrardjp are you on the OpenStack submit? | 09:26 |
*** openstackgerrit_ has joined #openstack-ansible | 09:43 | |
*** javeriak has joined #openstack-ansible | 09:52 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Allow scripts-library.sh to be sourced anywhere https://review.openstack.org/239631 | 10:01 |
*** sura8257_ has joined #openstack-ansible | 10:11 | |
*** gparaskevas has joined #openstack-ansible | 10:23 | |
*** subscope has quit IRC | 10:26 | |
*** javeriak has quit IRC | 10:26 | |
*** javeriak has joined #openstack-ansible | 10:28 | |
*** subscope has joined #openstack-ansible | 10:33 | |
*** subscope has quit IRC | 10:37 | |
tiagogomes | cloudnull, my haproxy log http://paste.openstack.org/show/477450/ for the cinder problem | 10:38 |
openstackgerrit | Merged openstack/openstack-ansible-security: Add theme fix for browsable source code https://review.openstack.org/238045 | 10:44 |
openstackgerrit | Merged openstack/openstack-ansible-specs: Add theme fix for browsable source code https://review.openstack.org/238061 | 11:07 |
*** openstackgerrit_ has quit IRC | 11:16 | |
*** Mudpuppy has joined #openstack-ansible | 11:24 | |
*** sura8257_ has quit IRC | 11:30 | |
mattt | cloudnull odyssey4me : hey guys, can you have a peek at https://bugs.launchpad.net/openstack-ansible/+bug/1509837 ? | 11:30 |
openstack | Launchpad bug 1509837 in openstack-ansible "Ceph python libraries are missing - liberty" [High,Confirmed] | 11:30 |
*** gardenshed has quit IRC | 11:36 | |
*** javeriak_ has joined #openstack-ansible | 11:43 | |
*** javeriak has quit IRC | 11:46 | |
*** javeriak_ has quit IRC | 11:50 | |
*** javeriak has joined #openstack-ansible | 11:51 | |
*** woodard has joined #openstack-ansible | 11:53 | |
*** woodard has quit IRC | 11:54 | |
*** Mudpuppy has quit IRC | 11:54 | |
*** woodard has joined #openstack-ansible | 11:54 | |
*** javeriak has quit IRC | 11:56 | |
*** javeriak has joined #openstack-ansible | 11:56 | |
*** subscope has joined #openstack-ansible | 11:56 | |
*** javeriak_ has joined #openstack-ansible | 12:07 | |
mhayden | morning folks | 12:09 |
mhayden | mattt: if jenkins returns "NOT_REGISTERED", is that a recheck kinda moment? | 12:09 |
mattt | mhayden: i want to say that's an infra problem, but i could be wrong :( | 12:10 |
*** javeriak has quit IRC | 12:11 | |
mattt | mhayden: from my irc logs | 12:11 |
mattt | 2015-07-22 14:13:35 -- Notice(openstackstatus): NOTICE: CI is currently recovering from an outage overnight. It is safe to recheck results with NOT_REGISTERED errors. It may take some time for zuul to work through the backlog. | 12:11 |
mhayden | gotcha | 12:11 |
mhayden | can i make a 'recheck' comment on the review for the gate job? | 12:11 |
mhayden | i have only done it for check jobs before | 12:11 |
mhayden | ah yeah that does work | 12:14 |
* mhayden woots | 12:14 | |
mhayden | thanks mattt | 12:14 |
*** javeriak_ has quit IRC | 12:16 | |
mattt | mhayden: that was an old message, but you get the idea :) | 12:17 |
*** woodard has quit IRC | 12:17 | |
mhayden | i ended up burning the midnight oil trying to figure out macvlans and ipv6 | 12:17 |
mattt | mhayden: that sounds like a poor life choice right there | 12:19 |
mhayden | ugh | 12:19 |
mhayden | so it will use the IP it gets via SLAAC w/o issue | 12:19 |
mhayden | but if you add a second one, the traffic never makes it to the vm :| | 12:20 |
*** woodard has joined #openstack-ansible | 12:20 | |
*** subscope has quit IRC | 12:21 | |
*** slotti has joined #openstack-ansible | 12:28 | |
*** shausy has quit IRC | 12:29 | |
*** rromans has joined #openstack-ansible | 12:36 | |
*** subscope has joined #openstack-ansible | 12:37 | |
*** javeriak has joined #openstack-ansible | 12:37 | |
*** javeriak has quit IRC | 12:40 | |
*** tlian has joined #openstack-ansible | 12:45 | |
*** javeriak has joined #openstack-ansible | 12:46 | |
*** openstackgerrit has quit IRC | 12:46 | |
*** openstackgerrit has joined #openstack-ansible | 12:47 | |
*** Mudpuppy has joined #openstack-ansible | 12:50 | |
*** javeriak_ has joined #openstack-ansible | 12:50 | |
*** javeriak has quit IRC | 12:51 | |
*** Mudpuppy has quit IRC | 13:05 | |
openstackgerrit | Merged openstack/openstack-ansible-security: V-3865{6,7}: Samba https://review.openstack.org/233215 | 13:11 |
openstackgerrit | Merged openstack/openstack-ansible-security: V-38699: Public directories exception https://review.openstack.org/234235 | 13:17 |
*** dolpher has joined #openstack-ansible | 13:19 | |
*** mattoliverau has quit IRC | 13:34 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:41 | |
*** mattoliverau has joined #openstack-ansible | 13:48 | |
*** woodard has quit IRC | 13:49 | |
*** harlowja has joined #openstack-ansible | 13:50 | |
*** woodard has joined #openstack-ansible | 13:52 | |
*** Mudpuppy has joined #openstack-ansible | 13:56 | |
*** Mudpuppy has quit IRC | 13:56 | |
*** darrenc has quit IRC | 13:57 | |
*** Mudpuppy has joined #openstack-ansible | 13:57 | |
*** mrda has quit IRC | 13:57 | |
*** jhesketh has quit IRC | 13:58 | |
*** jhesketh has joined #openstack-ansible | 14:01 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 14:06 |
*** Mudpuppy has quit IRC | 14:07 | |
mhayden | mattt: ^^ rebase for 233226 | 14:07 |
*** erikmwilson_ has joined #openstack-ansible | 14:07 | |
*** darrenc has joined #openstack-ansible | 14:07 | |
*** Mudpuppy has joined #openstack-ansible | 14:07 | |
*** erikmwilson_ is now known as erikmwilson | 14:08 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-3864{2,5,7,9}, V-38651: Umask adjustments https://review.openstack.org/233120 | 14:09 |
mhayden | mattt: https://review.openstack.org/#/c/233120/ <-- tidied up | 14:09 |
*** matt___ has joined #openstack-ansible | 14:12 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-3857{4,6,7}: Password hashing algorithms https://review.openstack.org/233071 | 14:13 |
mhayden | mattt: also cleaned up ^^ | 14:14 |
gparaskevas | hello | 14:16 |
*** k_stev has joined #openstack-ansible | 14:16 | |
mhayden | ohai gparaskevas | 14:16 |
gparaskevas | didnt you go to the summit? | 14:17 |
mhayden | not i :/ | 14:17 |
gparaskevas | me neither :/ | 14:18 |
gparaskevas | maybe next year! | 14:18 |
*** harlowja has quit IRC | 14:19 | |
javeriak_ | hey guys | 14:21 |
javeriak_ | doing an install from kilo head, and ive hit something, in https://github.com/openstack/openstack-ansible/blob/kilo/playbooks/os-nova-install.yml, line 115 should use 'management_address' instead of 'container_address'. Am i missing something, beacuse thats what my hostvars looks like | 14:21 |
tiagogomes | regarding https://review.openstack.org/#/c/233389, should enabling l3ha based on l2_population depend on the tenant network type? In the networking guide it only mentions problems using l3ha+l2_population for gre and vxla | 14:22 |
javeriak_ | sorry meant line 117* | 14:22 |
gparaskevas | i think container address is management | 14:24 |
gparaskevas | containers are bind to management network | 14:25 |
mattt | mhayden: two questions on https://review.openstack.org/#/c/233226/7/tasks/misc.yml | 14:27 |
mhayden | ah yeah, the dreaded snmp | 14:27 |
mattt | mhayden: why don't we just check if snmpd is installed w/ dpkg, and also why are we checking for 'community' when https://www.stigviewer.com/stig/red_hat_enterprise_linux_6/2015-03-06/finding/V-38660 makes no mention of that? | 14:27 |
mhayden | mattt: that was eric's suggestion since he had some SME experience with snmp | 14:28 |
mhayden | someone could use the 'rocommunity' configuration option, which is terrible for security | 14:28 |
mattt | ah yeah, i see his comment now | 14:29 |
mhayden | i can do a pkg check instead of a config file check if needed | 14:29 |
*** sawangpongm has joined #openstack-ansible | 14:30 | |
javeriak_ | gparaskevas, yes but the host_vars[container_networks] json doesn't contain a 'container_address' key.. | 14:30 |
mattt | mhayden: ubuntu only has 1 snmpd server, so i'd imagine it's ok to check w/ dpkg ? | 14:30 |
*** phalmos has joined #openstack-ansible | 14:31 | |
mhayden | probably so | 14:32 |
* mhayden fixes | 14:32 | |
mattt | mhayden: the reason why i mentioned it is because you rely on dpkg's exit code in https://github.com/openstack/openstack-ansible-security/blob/master/tasks/auth.yml#L250-L258 | 14:33 |
mhayden | oh damn, that's a bug then | 14:33 |
mhayden | the vsftpd one | 14:33 |
mattt | ah ok | 14:33 |
* mhayden wanders over to launchpad | 14:34 | |
mhayden | mattt: i'll fix up the snmp stuff and fix that vsftpd check after | 14:35 |
*** jhesketh has quit IRC | 14:36 | |
mattt | mhayden: nice, will review when they're up | 14:37 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 14:38 |
mhayden | mattt: there's one ^^ | 14:38 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Fixing vsftpd install check https://review.openstack.org/239677 | 14:41 |
mhayden | mattt: and the vsftpd fix ^^ | 14:41 |
mattt | mhayden: when: v38660_snmpd_conf.stat.exists == True | 14:41 |
mattt | mhayden: that is no longer getting registered | 14:42 |
mhayden | ah, good call | 14:42 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Enable encryption for all RabbitMQ connections https://review.openstack.org/238691 | 14:43 |
mhayden | jenkins has it out for me today | 14:43 |
mhayden | wait, i have two vsftpd checks in different places | 14:44 |
mhayden | that makes little sense | 14:44 |
*** dolpher has quit IRC | 14:45 | |
mattt | mhayden: wuuuut | 14:45 |
*** sawangpongm has left #openstack-ansible | 14:45 | |
mhayden | in auth.yml and misc.yml | 14:45 |
mhayden | imma corral those together | 14:45 |
*** sawangpongm has joined #openstack-ansible | 14:45 | |
*** jimchou has joined #openstack-ansible | 14:45 | |
*** jhesketh has joined #openstack-ansible | 14:48 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 14:50 |
gparaskevas | javeriak_: let me check | 14:50 |
*** sawangpongm has quit IRC | 14:52 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Fixing vsftpd install check https://review.openstack.org/239677 | 14:56 |
mhayden | hughsaunders: grepgrepgrepgrepgrep | 14:56 |
hughsaunders | mhayden: grep pam_unix.so /etc/pam.d/common-password | grep sha512 | grep -v '^#'" --> grep '^\s*password.*pam_unix.*sha512' /etc/pam.d/common-password | 14:56 |
mhayden | but but, i lose the pipes | 14:57 |
mhayden | pipes are fun | 14:57 |
mhayden | they're like slashes but vertical | 14:57 |
hughsaunders | fork, do it m04R | 14:57 |
mhayden | MOAR | 14:57 |
mhayden | but if i use pipes, it makes it looks like i'm doing something amazing | 14:58 |
mhayden | kinda like when i use lambdas | 14:58 |
hughsaunders | about that... | 14:58 |
mhayden | :P | 14:58 |
mhayden | hughsaunders: i'm totally being facetious | 14:58 |
mhayden | as mattt can attest, i'm full of crap most of the time :) | 14:58 |
hughsaunders | mhayden: you seem to do well out of it | 14:59 |
*** gus has quit IRC | 15:00 | |
mhayden | awww :) | 15:00 |
hughsaunders | now get out of my office and eradicate all those multi-greps :p | 15:01 |
* mhayden is trying to push that (hopefully) last SNMPv3 fixyfix | 15:01 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 15:01 |
mhayden | hughsaunders: still one pipe left ^^ | 15:02 |
*** jimchou_ has joined #openstack-ansible | 15:03 | |
*** jimchou has quit IRC | 15:03 | |
hughsaunders | mhayden: better though | 15:04 |
mhayden | whew | 15:04 |
mhayden | only four osas reviews left -- so much excitement | 15:04 |
*** javeriak_ has quit IRC | 15:06 | |
*** woodard has quit IRC | 15:07 | |
mattt | mhayden: that snmpd grep is no good | 15:08 |
*** ysm has joined #openstack-ansible | 15:08 | |
mattt | mhayden: actually wait, maybe i herped | 15:08 |
mattt | mhayden: ah yeah | 15:08 |
* mhayden is in another irc meeting and is moving slowly | 15:09 | |
mattt | mhayden: https://gist.githubusercontent.com/mattt416/d34f1e67e3a8a5c91540/raw/c11d34cd6f017fc352341c40dead87dcbae8037e/gistfile1.txt | 15:10 |
*** woodard has joined #openstack-ansible | 15:10 | |
*** gus has joined #openstack-ansible | 15:11 | |
mattt | mhayden: there's also a rocommunity in the stock config :( | 15:11 |
*** jwagner_away is now known as jwagner | 15:13 | |
*** woodard has quit IRC | 15:15 | |
*** woodard has joined #openstack-ansible | 15:16 | |
*** woodard has quit IRC | 15:16 | |
hughsaunders | mattt: ah yes :( | 15:16 |
*** neillc has quit IRC | 15:16 | |
openstackgerrit | Radoslaw Smigielski proposed openstack/openstack-ansible: Fix docs build unknown target name error https://review.openstack.org/239691 | 15:17 |
*** woodard has joined #openstack-ansible | 15:17 | |
mhayden | darn, this regex is a tricky one | 15:17 |
hughsaunders | mhayden: egrep 'v1|v2c|com2sec|community' /etc/snmp/snmpd.conf | grep -v '^\s*#' | 15:17 |
hughsaunders | haven't managed to eliminate the double yet :/ | 15:17 |
mhayden | hah, alrighty | 15:19 |
mhayden | that one works? | 15:19 |
hughsaunders | mhayden: seems to. | 15:21 |
*** woodard_ has joined #openstack-ansible | 15:22 | |
*** mcarden has quit IRC | 15:23 | |
*** woodard has quit IRC | 15:25 | |
mhayden | i shall go and do the fixing | 15:25 |
*** gparaskevas has quit IRC | 15:26 | |
*** phalmos has quit IRC | 15:27 | |
*** neilus1 has quit IRC | 15:29 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 15:30 |
openstackgerrit | Radoslaw Smigielski proposed openstack/openstack-ansible: Fix docs build "literal block expected" warning https://review.openstack.org/239694 | 15:32 |
*** neillc has joined #openstack-ansible | 15:33 | |
hughsaunders | grep -P '(?=^((?!#).)*$).*(v1|v2c|com2sec|community)' /etc/snmp/snmpd.conf in this case the single grep approach is so hideous that double is actually better for readability | 15:37 |
sigmavirus24 | hughsaunders: don't be ridiculous | 15:50 |
*** mgoddard has quit IRC | 15:50 | |
*** ysm has quit IRC | 16:01 | |
*** alop has joined #openstack-ansible | 16:04 | |
*** metral_zzz is now known as metral | 16:05 | |
mhayden | mattt: https://review.openstack.org/#/c/238691/ <-- check finished... i think it might just need a W+1 if i'm reading it correctly | 16:05 |
mhayden | or hughsaunders | 16:05 |
*** metral is now known as metral_zzz | 16:05 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: V-38660: SNMPv3 https://review.openstack.org/233226 | 16:06 |
*** mgoddard has joined #openstack-ansible | 16:08 | |
*** phalmos has joined #openstack-ansible | 16:11 | |
*** Bjoern_ has joined #openstack-ansible | 16:12 | |
*** jimchou has joined #openstack-ansible | 16:13 | |
*** alextricity_w has joined #openstack-ansible | 16:15 | |
alextricity_w | Hey | 16:15 |
*** jimchou_ has quit IRC | 16:15 | |
alextricity_w | Does anybody know how to tell the openstack client to use a certain IP for it's endpoint throughout the entire auth process? | 16:15 |
alextricity_w | I'm trying to access my APIs through a floating IP, but the client seems to revert back to what's configured as my public endpoint | 16:16 |
*** Bjoern_ is now known as BjoernT | 16:17 | |
hughsaunders | alextricity_w: you are trying to access openstack APIs via a neutron floating ip? | 16:17 |
BjoernT | Is the triaging meeting taking place ? | 16:17 |
alextricity_w | Yeah | 16:17 |
alextricity_w | So this environment is build on another cloud | 16:17 |
alextricity_w | hughsaunders: The floating IP is public, but the client always refers me back to my public endpoint IP: https://gist.github.com/elextro/76da737d4d9858cf18c8 | 16:18 |
*** neilus1 has joined #openstack-ansible | 16:22 | |
hughsaunders | alextricity_w: you could use --os-endpoint for the specific service you want to use, but thats post auth. | 16:25 |
*** mpavone has quit IRC | 16:27 | |
alextricity_w | hughsaunders: What do you mean post-auth? The client is making the auth request to the right ip (the floating ip), but after that it uses the public endpoint(which is not the floating ip). I need a way to override what it uses | 16:28 |
alextricity_w | After auth | 16:28 |
hughsaunders | alextricity_w: I mean, if you use --os-endpoint I think you need to have a token already to supply to the service | 16:28 |
alextricity_w | hughsaunders. Oh I see. So you would have to get a token before requesting any resources...hmm.. | 16:31 |
alextricity_w | hughsaunders I'm still surprised there is no easy way to override this | 16:32 |
*** javeriak has joined #openstack-ansible | 16:37 | |
*** javeriak_ has joined #openstack-ansible | 16:45 | |
*** javeriak has quit IRC | 16:45 | |
*** subscope has quit IRC | 16:46 | |
*** ysm has joined #openstack-ansible | 16:48 | |
*** javeriak has joined #openstack-ansible | 16:49 | |
*** javeriak_ has quit IRC | 16:50 | |
*** phalmos has quit IRC | 16:54 | |
*** neilus1 has quit IRC | 17:02 | |
*** ysm has quit IRC | 17:04 | |
mhayden | mattt / hughsaunders: thanks for the hlep today | 17:09 |
mhayden | echo "hlep" | grep -v help | sed 's/le/el/' | sort | 17:10 |
mhayden | bah, the rabbitmq job failed **again** but this time due to a failed apt-get update :P | 17:16 |
* mhayden looks at jenkins with consternation | 17:16 | |
*** jwagner is now known as jwagner_lunch | 17:18 | |
sigmavirus24 | mhayden: don't have the job runner, hate the infrastructure | 17:21 |
*** abitha has joined #openstack-ansible | 17:24 | |
*** woodard_ has quit IRC | 17:25 | |
*** woodard has joined #openstack-ansible | 17:25 | |
*** slotti has quit IRC | 17:33 | |
*** ysm has joined #openstack-ansible | 17:34 | |
*** karimb has quit IRC | 17:52 | |
*** phalmos has joined #openstack-ansible | 17:55 | |
*** woodard has quit IRC | 17:56 | |
*** greg_a has joined #openstack-ansible | 17:56 | |
mhayden | so i'm converting the bootstrap-aio.sh script to ansible but i can't seem to get the fallocate right... i run out of disk space immediately | 18:08 |
*** ysm has quit IRC | 18:08 | |
mhayden | oh nvm | 18:09 |
mhayden | can'tread | 18:09 |
*** alextricity_w has quit IRC | 18:13 | |
sigmavirus24 | mhayden: more like failocate, amirite? | 18:13 |
*** jwagner_lunch is now known as jwagner | 18:16 | |
*** ysm has joined #openstack-ansible | 18:26 | |
openstackgerrit | Merged openstack/openstack-ansible: Updated ansible version https://review.openstack.org/239516 | 18:27 |
mhayden | oooh new shiny | 18:27 |
odyssey4me | o/ mhayden | 18:28 |
mhayden | howdy odyssey4me -- how is tokyo? | 18:28 |
odyssey4me | yes, I should be asleep - the story of my life :p | 18:28 |
mhayden | 3:28AM there? ouch | 18:28 |
odyssey4me | it's a bit crazy at first - being in an entirely foreign city makes me feel like an alien | 18:29 |
odyssey4me | but it's also a great reset in your brain to make you realise that there are places in the world that have a completely different base premise in their cultures, beliefs, body language, etc | 18:30 |
odyssey4me | quite a mind blower | 18:30 |
odyssey4me | cloudnull and I had an interesting chat with a AU government rep who was using OSA (Juno) and who raised something I thought would pique your interest | 18:30 |
mhayden | wait, did i screw up here? https://review.openstack.org/#/c/238691/ | 18:31 |
mhayden | it ran the check again, then ran the gate | 18:31 |
mhayden | or is that normal | 18:31 |
odyssey4me | he basically said that it would be really great if we could do some sort of security audit (which you're doing) and to publish the hit list of items to do... then anyone can pick up those items to work on them, but also deployers are informed of the current shortfalls and can see when they get addressed | 18:32 |
odyssey4me | mhayden so you did a recheck - the recheck starts the whole process from scratch | 18:33 |
mhayden | odyssey4me: ah, i have some of that listed privately, but it might be nice to open it up | 18:33 |
*** sdake has joined #openstack-ansible | 18:33 | |
mhayden | odyssey4me: should i have put something else in the comment? | 18:33 |
odyssey4me | so yeah, it's normal - it's already kicked into the next phase | 18:33 |
odyssey4me | mhayden we used to be able to do 'reverify' and it would only retry the last bit - but reverify now restarts the process from scratch too | 18:33 |
odyssey4me | so no, you did it all good :) | 18:33 |
mhayden | alrighty | 18:34 |
mhayden | odyssey4me: good food there? | 18:34 |
odyssey4me | I have yet to find sashimi, because every sushi shop only does nigiri. | 18:34 |
odyssey4me | But good ramen is easy to find. | 18:34 |
odyssey4me | Some of the local beers are surprisingly good. | 18:34 |
mhayden | getcha some of this -> https://en.wikipedia.org/wiki/Katsudon | 18:35 |
mhayden | changed my life | 18:35 |
odyssey4me | I got lbragstad and mancdaz to have some Fugu this evening. | 18:35 |
odyssey4me | :) | 18:35 |
mhayden | not sure if i could do that | 18:35 |
odyssey4me | heh, it is quite frightening if you think of it too much... but meh :p | 18:36 |
odyssey4me | anyway , let me try and get back to sleep - I just thought I'd give you that feedback | 18:37 |
*** manas has joined #openstack-ansible | 18:37 | |
*** manas has quit IRC | 18:38 | |
openstackgerrit | Merged openstack/openstack-ansible: Update reference for rpc-maas repo https://review.openstack.org/239057 | 18:46 |
mhayden | thanks, odyssey4me | 18:46 |
*** Sam-I-Am has joined #openstack-ansible | 18:51 | |
cloudnull | Tiagogomes I think we need to improve he api up check that is being done for cinder to give it better insight on if the api is up or not. In tracking down that issue the only thing I found was to give the api backends more time to come online so the wait_for assertion on a functional cinder api needs to do a bit more to guarantee all is well. | 19:10 |
cloudnull | Morning / afternoon BTW | 19:10 |
*** sura8257 has joined #openstack-ansible | 19:26 | |
*** sdake has quit IRC | 19:27 | |
*** phalmos has quit IRC | 19:30 | |
odyssey4me | lol, cloudnull you can't sleep either? | 19:39 |
cloudnull | Nope :-/ | 19:39 |
sigmavirus24 | So sorry odyssey4me and cloudnull | 19:40 |
openstackgerrit | Merged openstack/openstack-ansible: Enable encryption for all RabbitMQ connections https://review.openstack.org/238691 | 19:40 |
cloudnull | How's it BTW ? | 19:40 |
openstackgerrit | Merged openstack/openstack-ansible: Make the container cache resolvers configurable https://review.openstack.org/238962 | 19:40 |
Sam-I-Am | cloudnull: sleep is optional | 19:42 |
cloudnull | Sigmavirus24 is a bitch my internal clock is all jacked up. | 19:42 |
sigmavirus24 | yeah I get it cloudnull, it's the worst | 19:43 |
Sam-I-Am | i dont shift time zones well | 19:45 |
cloudnull | I already don't sleep ... | 19:46 |
mhayden | holy mackerel, the rabbitmq SSL thing finally merged | 19:47 |
Sam-I-Am | openstack less, sleep more | 19:47 |
* mhayden woots | 19:47 | |
mhayden | i take back about 40% of what i said about jenkins | 19:47 |
sigmavirus24 | mhayden: bad choice | 19:50 |
logan2 | awesome @ #238962, i have been using a custom container base just because of that exact issue | 19:50 |
cloudnull | ++ logan2 hope it ends up helping out. | 19:56 |
cloudnull | Mhayden that's awesome. Rabbit SSL is fantastic and something most aren't doing. | 19:57 |
mhayden | it hasn't broken anything for me yet | 19:57 |
mhayden | i'd still like to figure out how to assemble a CA first, though | 19:57 |
mhayden | but i'm wallowing in that bootstrap-aio.sh -> ansible spec :P | 19:58 |
cloudnull | Haha. Hope its not so terribad | 19:58 |
mhayden | it's okay | 19:59 |
mhayden | i'm on line 312 of the aio script now | 19:59 |
cloudnull | Mhayden do you think you can cherry pick that SSL change to liberty ? | 19:59 |
cloudnull | Wow nice progress. | 19:59 |
mhayden | it should be straightfoward enough to cherry picicicicicic | 19:59 |
mhayden | the ssl listener stuff is in kilo, so it should already be in liberty | 20:00 |
mhayden | cloudnull: https://review.openstack.org/#/c/239744/ | 20:00 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Added logging for haproxy to rsyslog https://review.openstack.org/239505 | 20:01 |
openstackgerrit | Merged openstack/openstack-ansible: Add source into README.rst https://review.openstack.org/239438 | 20:01 |
*** openstackgerrit has quit IRC | 20:01 | |
*** openstackgerrit has joined #openstack-ansible | 20:02 | |
cloudnull | Idk if we should back port that to kilo but liberty for sure. Odyssey4me thoughts? | 20:02 |
odyssey4me | I would strongly recommend that we do not proactively backport any 'feature' into kilo without a specific request to do so and a very good reason. | 20:03 |
mhayden | i'm fine with leaving it in liberty only | 20:04 |
odyssey4me | Liberty, on the other hand - I'd say we can happily pull back any work until mitaka-1, then we need to be more picky. | 20:04 |
odyssey4me | Kilo should be considered stable in my view. | 20:04 |
sigmavirus24 | odyssey4me: define stable | 20:05 |
sigmavirus24 | ;) | 20:05 |
odyssey4me | sigmavirus24 :p | 20:05 |
odyssey4me | the code base should only receive bug fixes | 20:05 |
sigmavirus24 | I wonder if its stable if we should call the branch "stable/kilo" | 20:05 |
odyssey4me | sigmavirus24 we can't now - it affects documentation, deployments, etc - but for Mitaka we can | 20:06 |
odyssey4me | I would like to do both that, and actually shift to a full stable branch model. | 20:07 |
odyssey4me | If our deployers want repeatability, reliability and stable delivery - then there should be no major code base changes once the branch is cut. | 20:08 |
sigmavirus24 | odyssey4me: I was mostly trolling but *shrug* | 20:12 |
sigmavirus24 | Anyway, we've already fixed all the tooling to use our current branch naming strategy | 20:12 |
odyssey4me | sigmavirus24 the supertroll is back :) | 20:12 |
sigmavirus24 | And people are becoming familiar with our naming so I don't see a reason to bother changing it at this point | 20:12 |
sigmavirus24 | But yeah, I don't disagree about repeatability, reliability and stability except that we'll have to start adopting new features in openstack cycles a lot earlier than we historically have | 20:13 |
odyssey4me | sigmavirus24 agreed, but I don't see that it would be too hard | 20:13 |
sigmavirus24 | We can add support for new features without breaking things (e.g., add support for Federation without switching to Keystone v3 in a .1 release) | 20:14 |
sigmavirus24 | odyssey4me: it's more work than we currently have capacity to deal with | 20:14 |
sigmavirus24 | We can't be on top of all the services and accomodating their new features/etc so quickly with so few active contributors and reviewers | 20:14 |
sigmavirus24 | Also we'll need to be testing those features to see if we actually want to support their deployment, no? | 20:14 |
sigmavirus24 | I would not (in the next 2 or 3 cycles) bother supporting Artifacts until its API finishes changing and it actually works | 20:15 |
odyssey4me | sigmavirus24 sure, but also bear in mind that we have the config_template overrides now... ao 'new features' are largely figuring out how to configure things, documenting that, perhaps implementing some conveniences, and then moving through an organisational preparation process | 20:15 |
sigmavirus24 | (Artifacts being v3 in Glance) | 20:15 |
sigmavirus24 | odyssey4me: true, but that's not always the only work to be done either | 20:16 |
sigmavirus24 | fernet tokens for example required us to set up rsync between keystone containers when we're using fernet | 20:16 |
odyssey4me | yep, so I'd like us to think about implementing tooling to also make that sort of stuff simple and not require a dev cycle if at all possible | 20:17 |
odyssey4me | let's try to work smarter and do things in simpler ways | 20:17 |
*** greg_a has quit IRC | 20:21 | |
*** woodard has joined #openstack-ansible | 20:25 | |
*** phalmos has joined #openstack-ansible | 20:27 | |
*** sura8257__ has joined #openstack-ansible | 20:31 | |
*** sura8257 has quit IRC | 20:35 | |
*** sura8257__ has quit IRC | 20:40 | |
*** jwagner is now known as jwagner_away | 20:40 | |
*** ChanServ changes topic to "Topic: Launchpad: https://launchpad.net/openstack-ansible Weekly Meetings: https://wiki.openstack.org/wiki/Meetings/openstack-ansible || Repo rename from stackforge/os-ansible-deployment to openstack/openstack-ansible happens Sept 11 2015 23:00 to 23:30. See https://review.openstack.org/#/c/200730/" | 20:45 | |
odyssey4me | cloudnull ping? | 20:47 |
odyssey4me | mhayden sorry for the distraction, but I took a peek through https://review.openstack.org/239525 and made some comments :) | 20:47 |
mattt | isn't it like 6 AM in tokyo right now? | 20:53 |
*** javeriak has quit IRC | 20:53 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] AIO bootstrap in Ansible https://review.openstack.org/239525 | 20:54 |
mhayden | odyssey4me: just saw your msg :P | 20:54 |
mhayden | and pushed up a boatload of changes | 20:54 |
mhayden | i think i have about 95% of what's in the script done, but there are probably plenty of bugs and prettying-up required | 20:54 |
cloudnull | Odyssey4me yes ? | 20:55 |
*** woodard has quit IRC | 20:58 | |
*** woodard has joined #openstack-ansible | 20:59 | |
mhayden | odyssey4me: new WIP review coming with all of your changes addresses but one | 21:02 |
mhayden | any moment now | 21:02 |
mhayden | at the speed of gerrit | 21:02 |
mhayden | then again, this is a fairly fat commit | 21:02 |
*** ysm has quit IRC | 21:02 | |
mhayden | sigh | 21:04 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] AIO bootstrap in Ansible https://review.openstack.org/239525 | 21:05 |
mhayden | there we go | 21:05 |
mhayden | odyssey4me: obviously this thing needs tubloads of polish, too | 21:05 |
Sam-I-Am | mhayden: aaaaack filenames with cap letters | 21:06 |
mhayden | ah, i meant to toss a lower in there | 21:06 |
Sam-I-Am | mhayden: how come swap creation uses dd instead of fallocate? | 21:08 |
mhayden | fallocate was giving me trouble there | 21:08 |
mhayden | i need to revisit it | 21:08 |
Sam-I-Am | what sort of trouble? | 21:08 |
mhayden | i can't quite remember now -- but i'll try to revisit it tomorrow | 21:09 |
mhayden | feel free to toss in a comment to remind me :) | 21:09 |
Sam-I-Am | mhayden: dun | 21:11 |
mhayden | thanks | 21:12 |
*** woodard has quit IRC | 21:14 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] AIO bootstrap in Ansible https://review.openstack.org/239525 | 21:15 |
mhayden | Sam-I-Am: seems to work for me now | 21:15 |
Sam-I-Am | mhayden: magic | 21:16 |
mhayden | https://pbs.twimg.com/media/CSWl6akVEAAi_NX.jpg:large | 21:16 |
mhayden | ^^ gave me a chuckle | 21:16 |
mhayden | got an openstack recruiter email that said something similar to that today | 21:16 |
Sam-I-Am | sounds about right | 21:17 |
Sam-I-Am | or just 30 years experience on something that's only 5 years old | 21:17 |
mhayden | whoa, that commit is exactly 1,000 lines | 21:18 |
mhayden | definitely not planned | 21:18 |
sigmavirus24 | mhayden: yeah sure =P | 21:19 |
mhayden | gotta make it 1337 lines by the end | 21:19 |
mhayden | perhaps some eye-pleasing ascii art for odyssey4me | 21:20 |
*** ysm has joined #openstack-ansible | 21:21 | |
mhayden | breaking news -> Intel x86 considered harmful http://blog.invisiblethings.org/papers/2015/x86_harmful.pdf | 21:21 |
odyssey4me | mhayden we used to use dd, but fallocate was cleaner - but then fallocate doesn't work on ext3/4 I think it was | 21:22 |
mhayden | it works on ext4 now | 21:22 |
mhayden | perhaps that's why i got hosed | 21:22 |
odyssey4me | but hey - I just thought I'd peek through it... great job so far! | 21:22 |
mhayden | ln -s /usr/bin/fallocate /usr/bin/faillocate | 21:22 |
mhayden | thanks | 21:22 |
mhayden | i'll pick back up on it tomorrow and clean it up a bit | 21:23 |
sigmavirus24 | mhayden: is it a carcinogen? | 21:23 |
Sam-I-Am | i've been using fallocate on ext4 for a while | 21:23 |
Sam-I-Am | maybe its ext3? | 21:23 |
odyssey4me | and yeah, mhayden I personally prefer | lower: https://github.com/odyssey4me/ansible-openvas/blob/master/tasks/install_common.yml#L16-L20 | 21:23 |
*** phalmos has quit IRC | 21:24 | |
odyssey4me | it means all the file names are perdy :p | 21:24 |
mhayden | odyssey4me: check the latest patch | 21:24 |
odyssey4me | haha, nice! | 21:25 |
odyssey4me | anyway, time for me to get on with my day - time for breakfast! | 21:26 |
*** ysm has quit IRC | 21:31 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:31 | |
*** mcarden has joined #openstack-ansible | 21:32 | |
*** Mudpuppy has quit IRC | 21:40 | |
*** sdake has joined #openstack-ansible | 21:55 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: [WIP] AIO bootstrap in Ansible https://review.openstack.org/239525 | 22:00 |
openstackgerrit | Radoslaw Smigielski proposed openstack/openstack-ansible: Fix docs build unknown target name error https://review.openstack.org/239691 | 22:07 |
*** karimb has joined #openstack-ansible | 22:07 | |
*** karimb has quit IRC | 22:08 | |
*** karimb has joined #openstack-ansible | 22:08 | |
*** karimb has quit IRC | 22:09 | |
*** karimb has joined #openstack-ansible | 22:10 | |
*** karimb has quit IRC | 22:10 | |
*** karimb has joined #openstack-ansible | 22:11 | |
*** sdake has quit IRC | 22:26 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible: [WIP] AIO bootstrap in Ansible https://review.openstack.org/239525 | 22:28 |
*** jimchou has quit IRC | 22:40 | |
*** dolpher has joined #openstack-ansible | 22:55 | |
*** erikmwilson has quit IRC | 23:13 | |
*** erikmwilson has joined #openstack-ansible | 23:14 | |
*** openstackgerrit has quit IRC | 23:16 | |
*** openstackgerrit has joined #openstack-ansible | 23:16 | |
*** alop has quit IRC | 23:31 | |
*** tlian has quit IRC | 23:40 | |
*** sdake has joined #openstack-ansible | 23:48 | |
*** dolpher has quit IRC | 23:50 | |
*** k_stev has quit IRC | 23:52 | |
*** tlian has joined #openstack-ansible | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!