*** phalmos has quit IRC | 00:09 | |
*** woodard has quit IRC | 00:25 | |
openstackgerrit | Merged openstack/openstack-ansible: Remove reference to the 'one step' script. https://review.openstack.org/272660 | 00:33 |
---|---|---|
openstackgerrit | Merged openstack/openstack-ansible: Update plumlib.ini with connector type https://review.openstack.org/269203 | 00:47 |
*** markvoelker has quit IRC | 00:51 | |
*** michaelgugino has quit IRC | 00:55 | |
*** markvoelker has joined #openstack-ansible | 00:56 | |
*** Bjoern has quit IRC | 00:58 | |
*** eil397 has quit IRC | 01:01 | |
*** cemmason has joined #openstack-ansible | 01:02 | |
*** bryan_att has quit IRC | 01:09 | |
*** woodard has joined #openstack-ansible | 01:12 | |
*** sdake has joined #openstack-ansible | 01:13 | |
*** sdake_ has joined #openstack-ansible | 01:15 | |
*** spotz is now known as spotz_zzz | 01:15 | |
*** sdake has quit IRC | 01:17 | |
*** woodard has quit IRC | 01:22 | |
*** woodard has joined #openstack-ansible | 01:23 | |
*** woodard has quit IRC | 01:27 | |
*** phalmos has joined #openstack-ansible | 01:35 | |
*** sdake has joined #openstack-ansible | 01:36 | |
*** sdake_ has quit IRC | 01:37 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Converted all OS_* roles to use os_crud_ops https://review.openstack.org/272837 | 01:42 |
*** phalmos has quit IRC | 01:42 | |
*** fawadkhaliq has joined #openstack-ansible | 01:58 | |
*** fawadkhaliq has quit IRC | 01:59 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Separate host group var in hosts plays https://review.openstack.org/272869 | 02:00 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Allow neutron services to move around environment https://review.openstack.org/272871 | 02:04 |
logan- | :D thanks | 02:04 |
cloudnull | np. great changes btw | 02:05 |
cloudnull | BTW can you update https://review.openstack.org/#/c/268303/2/tasks/galera_client_pre_install.yml | 02:06 |
cloudnull | theres a typo there. but otherwise im +2 | 02:06 |
logan- | yep one sec | 02:06 |
cloudnull | tyvm | 02:07 |
cloudnull | :) | 02:07 |
cloudnull | odyssey4me: https://review.openstack.org/#/c/269396 should go in soon-ish | 02:08 |
cloudnull | the master commit has gone through | 02:08 |
cloudnull | dido https://review.openstack.org/#/c/269396 | 02:10 |
openstackgerrit | Logan V proposed openstack/openstack-ansible-galera_client: Allow sourcing apt_key from ansible host or URL https://review.openstack.org/268303 | 02:12 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Add ceilometer messaging_url for each service... https://review.openstack.org/269773 | 02:13 |
cloudnull | alextricity25: ^ I rebased that one for you | 02:13 |
cloudnull | should be good now | 02:13 |
*** sdake has quit IRC | 02:16 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Functional backport for the new repo-build process https://review.openstack.org/244215 | 02:16 |
*** Bjoern has joined #openstack-ansible | 02:16 | |
cloudnull | Bjoern: ^ kilo rebased. | 02:16 |
Bjoern | which review ? | 02:17 |
cloudnull | https://review.openstack.org/244215 | 02:17 |
Bjoern | got it, just showed up in mail mail | 02:17 |
cloudnull | ha! | 02:17 |
Bjoern | my mail lol | 02:17 |
cloudnull | gotta love that | 02:17 |
cloudnull | You got Mail! | 02:17 |
Bjoern | Lol, thanks | 02:17 |
cloudnull | https://www.youtube.com/watch?v=gFBLiHpkcOk | 02:18 |
*** weezS has quit IRC | 02:23 | |
*** baker has joined #openstack-ansible | 02:24 | |
*** Bjoern has quit IRC | 02:46 | |
*** baker has quit IRC | 02:46 | |
*** baker has joined #openstack-ansible | 02:48 | |
*** baker_ has joined #openstack-ansible | 02:50 | |
*** flwang has quit IRC | 02:50 | |
*** baker has quit IRC | 02:53 | |
*** sdake has joined #openstack-ansible | 03:04 | |
*** flwang has joined #openstack-ansible | 03:04 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Converted all OS_* roles to use os_crud_ops https://review.openstack.org/272837 | 03:06 |
*** sdake has quit IRC | 03:12 | |
*** woodard has joined #openstack-ansible | 03:19 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: [WIP] Converted all OS_* roles to use os_crud_ops https://review.openstack.org/272837 | 03:20 |
*** tlian2 has joined #openstack-ansible | 03:22 | |
*** woodard has quit IRC | 03:23 | |
*** tlian has quit IRC | 03:24 | |
*** raddaoui has joined #openstack-ansible | 03:41 | |
*** tlian2 has quit IRC | 03:50 | |
*** baker_ has quit IRC | 04:00 | |
prometheanfire | cloudnull: hi | 04:01 |
*** markvoelker has quit IRC | 04:04 | |
*** mattronix has quit IRC | 04:15 | |
*** raddaoui has quit IRC | 04:30 | |
openstackgerrit | Merged openstack/openstack-ansible: Update nova_rpc_backend to correct setting https://review.openstack.org/271285 | 04:34 |
*** fawadkhaliq has joined #openstack-ansible | 04:46 | |
*** CheKoLyN has joined #openstack-ansible | 04:58 | |
*** markvoelker has joined #openstack-ansible | 05:05 | |
*** markvoelker has quit IRC | 05:10 | |
*** sdake has joined #openstack-ansible | 05:13 | |
*** javeriak has joined #openstack-ansible | 05:13 | |
*** CheKoLyN has quit IRC | 05:19 | |
*** shausy has joined #openstack-ansible | 05:29 | |
*** sdake has quit IRC | 05:29 | |
*** fawadkhaliq has quit IRC | 05:31 | |
*** weezS has joined #openstack-ansible | 05:38 | |
*** fawadkhaliq has joined #openstack-ansible | 05:47 | |
*** fawadkhaliq has quit IRC | 05:47 | |
*** fawadkhaliq has joined #openstack-ansible | 05:50 | |
*** sdake has joined #openstack-ansible | 05:51 | |
*** adac has joined #openstack-ansible | 05:55 | |
*** phiche has joined #openstack-ansible | 05:59 | |
*** adac has quit IRC | 06:09 | |
*** gtt116_ has joined #openstack-ansible | 06:13 | |
*** gtt116__ has quit IRC | 06:16 | |
*** flwang has quit IRC | 06:22 | |
*** flwang has joined #openstack-ansible | 06:23 | |
*** gtt116_ has quit IRC | 06:23 | |
*** gtt116 has joined #openstack-ansible | 06:24 | |
*** phiche has quit IRC | 06:32 | |
*** sdake has quit IRC | 06:40 | |
*** javeriak has quit IRC | 06:43 | |
*** kstepniewski has joined #openstack-ansible | 06:46 | |
*** sdake has joined #openstack-ansible | 06:49 | |
*** sdake has quit IRC | 06:50 | |
*** weezS has quit IRC | 06:53 | |
*** javeriak has joined #openstack-ansible | 06:54 | |
*** phiche has joined #openstack-ansible | 06:55 | |
*** markvoelker has joined #openstack-ansible | 07:06 | |
*** javeriak has quit IRC | 07:10 | |
*** javeriak has joined #openstack-ansible | 07:10 | |
*** markvoelker has quit IRC | 07:11 | |
*** targon has joined #openstack-ansible | 07:14 | |
*** javeriak_ has joined #openstack-ansible | 07:14 | |
*** javeriak has quit IRC | 07:15 | |
*** nwonknu has quit IRC | 07:21 | |
*** nwonknu has joined #openstack-ansible | 07:28 | |
*** cemmason has quit IRC | 07:28 | |
*** kstepniewski has quit IRC | 07:40 | |
*** javeriak has joined #openstack-ansible | 07:42 | |
*** javeriak_ has quit IRC | 07:44 | |
*** javeriak_ has joined #openstack-ansible | 07:58 | |
*** javeriak has quit IRC | 07:59 | |
*** cemmason has joined #openstack-ansible | 08:08 | |
*** mattronix has joined #openstack-ansible | 08:26 | |
*** mattronix has quit IRC | 08:27 | |
*** mattronix has joined #openstack-ansible | 08:27 | |
*** adac has joined #openstack-ansible | 08:28 | |
*** shausy has quit IRC | 08:35 | |
*** shausy has joined #openstack-ansible | 08:36 | |
*** mikelk has joined #openstack-ansible | 08:37 | |
*** markvoelker has joined #openstack-ansible | 09:07 | |
evrardjp | hello everyone | 09:08 |
evrardjp | odyssey4me: about https://review.openstack.org/#/c/271406/ , I think the first cause of the issue is that we have an openstack_openrc role that does wiring, and he does it quite badly according to ansible best practices: the openrc_insecure variable is defined with variable value outside of its scope | 09:10 |
evrardjp | redefining openrc_insecure to False in the role, and overriding this in the group_vars makes far more sense when people will consume the role independantly | 09:11 |
mancdaz | anyone who can test and +2 this https://review.openstack.org/#/c/269429/1 | 09:11 |
evrardjp | just my 2 cents for my 5 minutes allowance on openstack-ansible today :p | 09:12 |
mancdaz | I need to get this in and then backported to liberty | 09:12 |
*** markvoelker has quit IRC | 09:12 | |
*** MCoLo has joined #openstack-ansible | 09:15 | |
mattt | mancdaz: what was your use case for that so i can try replicating ? | 09:21 |
mancdaz | mattt so I'm passing an additional location to py_pkgs to parse to find git links (/opt/rpc-openstack/rpcd). It was not picking up the holland_git_* entries because it was in a role defaults/main.yml file. The patch allows it to pick them up properly | 09:22 |
mattt | ah i see | 09:23 |
mattt | looks like hughsaunders has approved it anyway | 09:23 |
hughsaunders | BGBaaS | 09:24 |
mattt | hughsaunders: #YOURETHABAAYYSST | 09:24 |
mancdaz | thanks hughsaunders | 09:24 |
mancdaz | hughsaunders mattt if this merges I'm gonna backport to liberty so I'll hassle you again | 09:25 |
mancdaz | HaaS | 09:26 |
mattt | mancdaz: sure just let us know | 09:26 |
mattt | i'll keep an eye on it also | 09:26 |
mancdaz | thank thee | 09:27 |
*** permalac has joined #openstack-ansible | 09:33 | |
*** shausy has quit IRC | 09:36 | |
*** sura8257 has joined #openstack-ansible | 09:36 | |
*** shausy has joined #openstack-ansible | 09:37 | |
*** mgoddard has joined #openstack-ansible | 09:38 | |
hughsaunders | mattt: Is cirros image upload failure a symptom of the keystone cache bug? Could be if glance is attempting to lookup the swift endpoint? | 09:41 |
mattt | hughsaunders: yeah that is precisely where that bug was surfacing | 09:42 |
mattt | hughsaunders: https://review.openstack.org/#/c/271357/ | 09:42 |
hughsaunders | mattt: thanks, I'll check how far that patch has percolated | 09:47 |
openstackgerrit | Hugh Saunders proposed openstack/openstack-ansible: Reduce keystone cache expiration time https://review.openstack.org/272964 | 09:49 |
hughsaunders | mattt: ^^ cherry-pick to liberty | 09:50 |
mattt | hughsaunders: that bug isn't in liberty tho | 09:52 |
*** sura8257 has quit IRC | 09:53 | |
*** targon has quit IRC | 09:53 | |
mattt | hughsaunders: if you're hitting this in liberty you're hitting something else | 09:54 |
hughsaunders | mattt: I was seeing the symptoms in kilo, so thought it may be the same thing.. | 09:55 |
hughsaunders | ok I'll kill that review | 09:55 |
*** targon has joined #openstack-ansible | 09:55 | |
mattt | hughsaunders: shouldn't be, catalog caching is new in mitaka | 09:56 |
hughsaunders | mattt: ok, must be another problem causing the symptom | 09:58 |
*** sura8257 has joined #openstack-ansible | 09:59 | |
*** markvoelker has joined #openstack-ansible | 10:08 | |
*** markvoelker has quit IRC | 10:13 | |
evrardjp | hello again | 10:15 |
evrardjp | Could someone review this commit: https://review.openstack.org/#/c/264862/ ? | 10:16 |
mattt | evrardjp: just in the midst of something atm, but will add it to my list of things to review | 10:17 |
*** sura8257 has quit IRC | 10:25 | |
openstackgerrit | Merged openstack/openstack-ansible: Process git repos in role defaults at low priority https://review.openstack.org/269429 | 10:25 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Add nova-config tags to nova_virt_detect.yml https://review.openstack.org/272981 | 10:25 |
openstackgerrit | Darren Birkett proposed openstack/openstack-ansible: Process git repos in role defaults at low priority https://review.openstack.org/272982 | 10:25 |
mancdaz | hughsaunders mattt master merged, here's the liberty backport https://review.openstack.org/#/c/272982/ | 10:26 |
* hughsaunders waits for jenkins | 10:27 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: [WIP] Re-deploy the Ceilometer venv if it mismatches the repo https://review.openstack.org/272984 | 10:27 |
mattt | mancdaz: voted | 10:27 |
evrardjp | It's not in a hurry, I just hope it won't be lost somewhere | 10:34 |
evrardjp | omg this sentence doesn't mean anything! I meant that I hope the community will not forget this commit :p | 10:36 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Ceilometer venv if it mismatches the repo https://review.openstack.org/272984 | 10:37 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Aodh venv if it mismatches the repo https://review.openstack.org/272079 | 10:37 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Swift venv if it mismatches the repo https://review.openstack.org/272038 | 10:37 |
*** electrofelix has joined #openstack-ansible | 10:38 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Heat venv if it mismatches the repo https://review.openstack.org/272032 | 10:38 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Nova venv if it mismatches the repo https://review.openstack.org/272027 | 10:38 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Cinder venv if it mismatches the repo https://review.openstack.org/272021 | 10:39 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Glance venv if it mismatches the repo https://review.openstack.org/270229 | 10:39 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Keystone venv if it mismatches the repo https://review.openstack.org/270222 | 10:40 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Neutron venv if it mismatches the repo https://review.openstack.org/272029 | 10:40 |
hughsaunders | evrardjp: reviewed, possibly not the comment you're looking for though :/ | 10:44 |
evrardjp | Thanks | 10:44 |
evrardjp | oh I don't mind, the most important is that we go forward. | 10:44 |
evrardjp | as it's an opinion, I'll wait for another review that goes in the same way. But I think you're right, no need for a new file | 10:47 |
evrardjp | I wouldn't put it in the role though, this will be uselessly done multiple times. It would be right to do it in the playbooks for each role | 10:51 |
evrardjp | Moreover, changing it in a role would make this "part of the role" instead of "part of the glue", which is a decision to take | 10:53 |
*** sdake has joined #openstack-ansible | 11:05 | |
*** mikelk has quit IRC | 11:16 | |
*** mikelk has joined #openstack-ansible | 11:18 | |
*** mikelk has quit IRC | 11:18 | |
*** mikelk has joined #openstack-ansible | 11:19 | |
*** sdake has quit IRC | 11:20 | |
*** evrardjp has quit IRC | 11:23 | |
*** mikelk has quit IRC | 11:25 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Keystone venv if it mismatches the repo https://review.openstack.org/270222 | 11:26 |
*** mgoddard has quit IRC | 11:29 | |
*** evrardjp has joined #openstack-ansible | 11:31 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible: Re-deploy the Keystone venv if it mismatches the repo https://review.openstack.org/270222 | 11:42 |
*** fawadkhaliq has quit IRC | 11:42 | |
*** fawadkhaliq has joined #openstack-ansible | 11:42 | |
*** pcaruana has joined #openstack-ansible | 11:44 | |
mattt | cloudnull: tested and removed the WIP from all those reviews, but spotted a slight issue -- redeploying a venv doesn't restart the service unless something in the configs change ... but from what i can see this is a problem that exists today? | 11:52 |
*** sdake has joined #openstack-ansible | 12:01 | |
*** javeriak_ has quit IRC | 12:02 | |
*** mgoddard has joined #openstack-ansible | 12:06 | |
*** markvoelker has joined #openstack-ansible | 12:09 | |
*** mgoddard has quit IRC | 12:12 | |
*** markvoelker has quit IRC | 12:14 | |
*** pcaruana has quit IRC | 12:37 | |
*** mgoddard has joined #openstack-ansible | 12:42 | |
*** shausy has quit IRC | 12:54 | |
mhayden | morning | 13:03 |
*** mpavone has joined #openstack-ansible | 13:09 | |
*** markvoelker has joined #openstack-ansible | 13:09 | |
*** mpavone has left #openstack-ansible | 13:10 | |
*** markvoelker has quit IRC | 13:14 | |
*** mikelk has joined #openstack-ansible | 13:20 | |
*** mikelk has quit IRC | 13:21 | |
mhayden | mattt: really glad to see those venv redeploy patches :) | 13:21 |
mattt | mhayden: see my comment above to cloudnull :( | 13:23 |
mattt | so they're kinda incomplete still, but the issue i'm hitting seems to have existed prior to the venv patch | 13:23 |
mhayden | you've done the hardest part, though | 13:23 |
mgariepy | mattt, there is currently no restart of service when code changes this affect kilo as well. | 13:29 |
mattt | mgariepy: that's really crappy! | 13:29 |
mgariepy | yes indeed. | 13:29 |
mattt | some roles have configs that change on each run (which is a problem in itself) and that'll cause restarts, but a good few don't | 13:30 |
mgariepy | I had issue with Keystone not restarting ;) | 13:30 |
mgariepy | which isn't good haha | 13:30 |
mattt | the problem is you can't restart them when the packages/venvs are updated | 13:30 |
mattt | actually you probably can | 13:31 |
mattt | i was thinking you wouldn't want services coming up before the db sync and configs are dropped etc. | 13:31 |
mattt | but it will hold off on the restart until the end | 13:31 |
mattt | i'll probably put a patch through for all the services for this | 13:31 |
mgariepy | yes but aren't you just adding a tag for the service restart, and it's done once everything is done ? | 13:32 |
mgariepy | that would be great. I would like to help out, if you need testing on kilo, i'll gladly help, but I don't have much time those days.. | 13:33 |
mattt | mgariepy: sounds good, i'm going to get started on this now | 13:37 |
*** sdake_ has joined #openstack-ansible | 13:40 | |
*** sdake has quit IRC | 13:42 | |
*** mikelk has joined #openstack-ansible | 13:43 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Docs: Update integration with OSA https://review.openstack.org/273050 | 13:44 |
*** markvoelker has joined #openstack-ansible | 13:45 | |
*** fawadkhaliq has quit IRC | 13:55 | |
*** fawadk has joined #openstack-ansible | 13:55 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Docs: Using security-hardening.yml https://review.openstack.org/273056 | 13:58 |
*** tlian has joined #openstack-ansible | 14:00 | |
*** sdake_ is now known as sdake | 14:05 | |
mattt | how do you build a review upon multiple in flight reviews again? | 14:06 |
*** phalmos has joined #openstack-ansible | 14:10 | |
*** Bjoern has joined #openstack-ansible | 14:12 | |
*** fawadk has quit IRC | 14:12 | |
*** woodard has joined #openstack-ansible | 14:12 | |
*** woodard has quit IRC | 14:13 | |
*** woodard has joined #openstack-ansible | 14:13 | |
*** fawadkhaliq has joined #openstack-ansible | 14:15 | |
*** fawadkhaliq has quit IRC | 14:16 | |
*** Bjoern has quit IRC | 14:17 | |
openstackgerrit | Daniele Pizzolli proposed openstack/openstack-ansible: Fix rst code rendering https://review.openstack.org/273062 | 14:18 |
openstackgerrit | Miguel Alex Cantu (alextricity25) proposed openstack/openstack-ansible: Add ceilometer messaging_url for each service... https://review.openstack.org/269773 | 14:28 |
*** galstrom_zzz is now known as galstrom | 14:35 | |
*** alextricity_r has joined #openstack-ansible | 14:46 | |
*** michaelgugino has joined #openstack-ansible | 14:49 | |
*** javeriak has joined #openstack-ansible | 14:49 | |
*** alextricity_r has quit IRC | 14:50 | |
*** automagically has joined #openstack-ansible | 14:50 | |
*** Bofu2U has joined #openstack-ansible | 14:53 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:55 | |
*** cemmason has quit IRC | 14:58 | |
*** spotz_zzz is now known as spotz | 15:02 | |
palendae | mattt: Like dependencies? git-review -d | 15:02 |
mattt | palendae: yeah exactly, was wondering if it would be possible to have a review depend on multiple reviews, but i think that will be a nightmare if something needs rebasing | 15:05 |
palendae | Hm, yeah | 15:05 |
palendae | I'd imagine you could build up a chain of them | 15:05 |
palendae | Like a real git branch | 15:05 |
palendae | But yes, rebasing...gross. | 15:05 |
mattt | yeah doing a chain will work | 15:05 |
mattt | trying to decide if it's worth the effort :P | 15:05 |
*** gparaskevas has joined #openstack-ansible | 15:07 | |
*** alextricity_r has joined #openstack-ansible | 15:15 | |
*** Mudpuppy has joined #openstack-ansible | 15:18 | |
spotz | mhayden quick fix for you on https://review.openstack.org/#/c/273050/1 | 15:22 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client: Allow sourcing apt_key from ansible host or URL https://review.openstack.org/268303 | 15:22 |
*** alextricity_r has quit IRC | 15:30 | |
automagically | odyssey4me and cloudnull - We’ve been testing https://review.openstack.org/#/c/258015 and where it stands now it suits our needs. I see that there is some outstanding discussion on the patchset, but from my read, this looks good to merge as is and we can always address future proofing at a later date. Thoughts on getting this into master as it stands? | 15:36 |
*** baker has joined #openstack-ansible | 15:38 | |
*** fawadkhaliq has joined #openstack-ansible | 15:40 | |
*** fawadkhaliq has quit IRC | 15:40 | |
*** fawadkhaliq has joined #openstack-ansible | 15:40 | |
cloudnull | mattt: RE: venv re-deploy -- that makes sense maybe we can key off off the checksum change and send a signal to the handler for restart if the venv checksum is different | 15:45 |
cloudnull | odyssey4me: might you have a moment to review https://review.openstack.org/#/c/272764/ | 15:46 |
cloudnull | companion patch https://review.openstack.org/#/c/272689/ | 15:46 |
cloudnull | sorry https://review.openstack.org/#/c/272837/ | 15:46 |
* odyssey4me is not here :p I'm actually on leave today - I just couldn't help pick some low hanging fruit. :/ | 15:48 | |
*** alextricity_r has joined #openstack-ansible | 15:48 | |
*** weezS has joined #openstack-ansible | 15:49 | |
*** daneyon has joined #openstack-ansible | 15:49 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: IRR - Implemented for plugins https://review.openstack.org/272689 | 15:52 |
*** phiche has quit IRC | 15:52 | |
automagically | cloudnull Any thoughts on my proposal for the multi_domain_ldap patchset. Should I add it to the agenda for tomorrow’s meeting? | 15:52 |
*** javeriak has quit IRC | 15:52 | |
cloudnull | automagically: i will look at that in a bit for sure. | 15:53 |
automagically | Thx, much appreciated | 15:53 |
*** CheKoLyN has joined #openstack-ansible | 15:53 | |
*** daneyon_ has quit IRC | 15:53 | |
*** targon has quit IRC | 15:54 | |
*** weezS has quit IRC | 15:54 | |
*** javeriak has joined #openstack-ansible | 15:58 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-plugins: Updated repo for new org https://review.openstack.org/273125 | 16:00 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-plugins: Forward port missing patches https://review.openstack.org/273126 | 16:06 |
*** jthorne has joined #openstack-ansible | 16:09 | |
*** alextricity_r has quit IRC | 16:12 | |
*** kstepniewski has joined #openstack-ansible | 16:12 | |
cloudnull | automagically: ++ LGTM -- Idk if we need to have the other bits on the agenda for the meeting. The patch is an improvement and good enough to be stable/prod-ready. | 16:13 |
cloudnull | do we need / want that back in liberty ? | 16:14 |
automagically | cloudnull: I’d really like to get it backported to Liberty, once it merges to master | 16:14 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible: Implement multi-domain LDAP configuration for Keystone https://review.openstack.org/273130 | 16:14 |
cloudnull | Backported, but held until master merges. | 16:15 |
automagically | Nice, looking forward to using this considering how smoothly our testing has gone | 16:15 |
cloudnull | odyssey4me: you around to remove the -2 on https://review.openstack.org/#/c/268676/ ? master patches have merged | 16:17 |
*** daneyon has quit IRC | 16:17 | |
*** kstepniewski has quit IRC | 16:19 | |
*** rETROpunK1991 has joined #openstack-ansible | 16:24 | |
*** rETROpunK has quit IRC | 16:25 | |
*** rETROpunK1991 is now known as rETROpunK | 16:25 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-plugins: Updated repo for new org https://review.openstack.org/273125 | 16:30 |
openstackgerrit | Merged openstack/openstack-ansible: Neutron ML2 template fix https://review.openstack.org/269396 | 16:31 |
openstackgerrit | Merged openstack/openstack-ansible: Allow sourcing apt_key from URL https://review.openstack.org/271447 | 16:31 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-plugins: Updated repo for new org https://review.openstack.org/273125 | 16:31 |
openstackgerrit | Merged openstack/openstack-ansible: Fix rst code rendering https://review.openstack.org/273062 | 16:31 |
*** sdake_ has joined #openstack-ansible | 16:36 | |
openstackgerrit | Merged openstack/openstack-ansible: Update nova_rpc_backend to correct setting https://review.openstack.org/272713 | 16:38 |
bgmccollum | anyone seeing this? -- WARNING: The following packages cannot be authenticated! python-ceph | 16:39 |
bgmccollum | repo shenanigans | 16:39 |
*** sdake has quit IRC | 16:40 | |
*** sdake_ is now known as sdake | 16:40 | |
*** daneyon has joined #openstack-ansible | 16:41 | |
*** jthorne has quit IRC | 16:41 | |
cloudnull | bgmccollum: release ? | 16:43 |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-plugins: Forward port missing patches https://review.openstack.org/273126 | 16:44 |
bgmccollum | cloudnull -- looking | 16:45 |
*** galstrom is now known as galstrom_zzz | 16:46 | |
*** jthorne has joined #openstack-ansible | 16:48 | |
kysse | how can I use something else than qcow2 backing file for new instances? | 16:49 |
bgmccollum | cloudnull -- 11.2.8 | 16:49 |
bgmccollum | cloudnull its just one of my nodes. ill build another. im guessing transient mirror hiccup | 16:50 |
cloudnull | bgmccollum: its possible | 16:51 |
cloudnull | kysse: what did you want to use ? | 16:51 |
kysse | maybe netapp's copy on write clones | 16:52 |
kysse | as iscsi luns | 16:52 |
*** gparaskevas has quit IRC | 16:53 | |
cloudnull | you can setup the vm to use cinder w/ netapp as its boot device. | 16:54 |
cloudnull | vm boot from volume | 16:54 |
cloudnull | and have the volume backend be netapp | 16:54 |
*** admin0 has joined #openstack-ansible | 16:55 | |
kysse | yes but I want instance roots not be separate cinder volumes | 16:55 |
kysse | used as separate cinder volumes | 16:56 |
cloudnull | hum... | 16:57 |
* cloudnull looking | 16:57 | |
*** adac has quit IRC | 16:57 | |
*** mikelk has quit IRC | 16:57 | |
*** galstrom_zzz is now known as galstrom | 16:58 | |
*** jthorne has quit IRC | 16:59 | |
openstackgerrit | git-harry proposed openstack/openstack-ansible: Fix rsync service restart in os_swift https://review.openstack.org/273149 | 16:59 |
cloudnull | logan-: didn't you have instances backed by iscsi ? | 17:00 |
palendae | git-harry: Should that have a liberty-upgrade topic? | 17:00 |
palendae | Or does it apply to more than just liberty upgrades? | 17:00 |
logan- | nope all ceph here sorry | 17:00 |
cloudnull | ok | 17:00 |
git-harry | palendae: that's the fix for master, it will need backporting to liberty | 17:01 |
palendae | Ok | 17:01 |
logan- | bgmccollum: download.ceph.com is down too... maybe related | 17:01 |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible: Don't install openjdk-7-jre into the Utility container https://review.openstack.org/273151 | 17:01 |
bgmccollum | logan- thanks...ill keep an eye on it | 17:02 |
cloudnull | kysse: i mean you could mount /var/lib/nova as an iscsi target but that may not be exactly what you want . | 17:02 |
kysse | yeees but how does it behave with multiple compute nodes accessing same filesystem.. | 17:03 |
cloudnull | I've not specifically done it, so idk ... | 17:04 |
kysse | yee, I have to test it. | 17:04 |
cloudnull | you could do NFFS | 17:04 |
cloudnull | *NFS | 17:04 |
bgmccollum | kysse are you just trying to avoid qcow2 backing files? or any local backing file at all | 17:05 |
cloudnull | mounting /var/lib/nova/instances as NFS would work and I have done that in the past | 17:06 |
cloudnull | works fine assuming your network can support the throughput, but that would be the case w/ iscsi too | 17:06 |
*** doublek has joined #openstack-ansible | 17:06 | |
kysse | well I do not want to use NFS or qcow2 backing files. It's freaking stupid that we would have to use qcow2 image roots when we could use netapps cow clones :b | 17:08 |
* cloudnull reading http://community.netapp.com/fukiw75442/attachments/fukiw75442/virtualization-and-cloud-articles-and-resources/450/1/openstack-deployment-ops-guide.pdf now | 17:10 | |
*** daneyon has quit IRC | 17:11 | |
logan- | have you tried sourcing instances through cinder with raw images instead of qcow and then relying on netapp to do the cow/dedup stuff | 17:11 |
cloudnull | kysse: looks like netapp recommends NFS under the "Instance Storage Options at the Hypervisor" section of their deployment and ops guide | 17:12 |
kysse | yew but It's not good. | 17:12 |
kysse | cuz we prefer iscsi multipath over stupid nfs one tcp stream with bondinh | 17:13 |
kysse | bonding* | 17:13 |
cloudnull | in the netapp guide they call out cinder as the preferred instance boot method. i dont see anything about using iscsi directly ... | 17:17 |
cloudnull | you could do cinder boot from volume + netapp iscsi and then setup multipath on the nova compute node | 17:17 |
cloudnull | which is in the nova.conf | 17:17 |
*** mgoddard has quit IRC | 17:17 | |
cloudnull | which would give you the performance youre looking for | 17:18 |
cloudnull | however it'll create all of those additional volumes | 17:18 |
kysse | mmh yeah.. | 17:18 |
kysse | I'm just thinking those api calls who wants to boot instance from image.. | 17:19 |
kysse | and then it will suck completely | 17:19 |
kysse | cuz of nfs performance | 17:19 |
*** weezS has joined #openstack-ansible | 17:20 | |
cloudnull | well if you do boot from volume + iscsi you wont have the nfs penalty on the root disk. but yes crafting the api call to boot from volume isn’t pretty. | 17:21 |
*** McMurlock has quit IRC | 17:22 | |
*** McMurlock has joined #openstack-ansible | 17:22 | |
*** permalac has quit IRC | 17:22 | |
kysse | yep. | 17:24 |
*** McMurlock has quit IRC | 17:26 | |
*** McMurlock has joined #openstack-ansible | 17:29 | |
*** jthorne has joined #openstack-ansible | 17:30 | |
cloudnull | sorry kysse searching around but i've got nothing right now | 17:30 |
kysse | yep, no problems | 17:31 |
kysse | maybe we have to patcj something into upstream | 17:31 |
kysse | patch | 17:31 |
*** kstepniewski has joined #openstack-ansible | 17:36 | |
*** coolg has joined #openstack-ansible | 17:44 | |
*** adac has joined #openstack-ansible | 17:49 | |
*** dmsimard has quit IRC | 17:51 | |
*** fawadkhaliq has quit IRC | 17:51 | |
*** michaelgugino has quit IRC | 17:52 | |
coolg | hi | 17:53 |
*** sdake has quit IRC | 17:53 | |
coolg | I am using openstack-ansible project to install liberty. I am following this link https://github.com/openstack/openstack-ansible I have installed AIO setup by following the instructions. For multinode setup, can anybody help in providing the steps to do instllation? | 18:00 |
*** dmsimard has joined #openstack-ansible | 18:01 | |
spotz | coolg have you seen these docs? http://docs.openstack.org/developer/openstack-ansible/install-guide/ | 18:07 |
coolg | yeah.. I have gone through the document but not fully. It will be helpful for me if I get steps like provided for AIO setup. | 18:09 |
coolg | main things like where do i have to give my controller and compute ip address.. hosts file location and steps to do installation | 18:11 |
stevelle | coolg: multinode installs require you to do some host preparation steps yourself because we cannot safely make assumptions about the networking environment and connectivity between the hosts. | 18:11 |
stevelle | thus the docs | 18:12 |
stevelle | you will need to customize files which are placed in /etc/openstack_deploy | 18:13 |
stevelle | coolg: chapter 4 of the docs gives more guidance on how to specify the host ips for the deploy | 18:16 |
*** raddaoui has joined #openstack-ansible | 18:16 | |
coolg | thank you stevelle | 18:17 |
coolg | shared-infra_hosts: infra1: ip: 172.29.236.101 | 18:17 |
coolg | this is container ip or node ip? | 18:17 |
logan- | the node, the containers will be created with automatically assigned ips out of the pools you specify | 18:18 |
stevelle | that is the host, not container. container ips are done for you based on the networks you specify above that | 18:18 |
logan- | so the ips you specify in that file are for the nodes where the containers and services will live | 18:18 |
lbragstad | cloudnull o/ | 18:18 |
stevelle | logan has this :) | 18:18 |
*** jthorne has quit IRC | 18:18 | |
lbragstad | cloudnull i heard you guys had to disable catalog caching in keystone because of our broken catalog caching patch in keystone? | 18:19 |
coolg | thanks for the clarification logan and stevelle | 18:19 |
stevelle | lbragstad: truth | 18:20 |
lbragstad | stevelle awesome | 18:20 |
coolg | I will give a try for multinode and will get back if i have any issues | 18:20 |
lbragstad | stevelle we have a patch in the gate that adds caching to the role assignments for a user | 18:20 |
lbragstad | on a project | 18:20 |
coolg | thank you | 18:20 |
lbragstad | and with that we have a fix for invalidating a cache across processes - https://review.openstack.org/#/c/215715/21 | 18:21 |
lbragstad | stevelle based on that - we will have a follow on fix to correct that behavior for get_catalog caching - https://review.openstack.org/#/c/271536/5 | 18:21 |
stevelle | lbragstad: excellent, noting | 18:21 |
lbragstad | stevelle we will back port both of those in keystone to stable/liberty | 18:21 |
lbragstad | once they land in master | 18:22 |
*** mgoddard has joined #openstack-ansible | 18:22 | |
stevelle | lbragstad: I will line up a revert for our workaround based on them | 18:22 |
*** galstrom is now known as galstrom_zzz | 18:23 | |
lbragstad | stevelle sweet - i'll ping with links to the backports when we have them | 18:23 |
stevelle | lbragstad: sounds great, thanks for the follow up | 18:24 |
lbragstad | stevelle no problem - sorry we broke it in the first place ;) | 18:24 |
*** mgoddard has quit IRC | 18:25 | |
*** mgoddard_ has joined #openstack-ansible | 18:25 | |
sigmavirus24 | Hm. In adding a new service to OSA, it seems that the service cannot be reached via any of the URLs registered in the service catalog (which all look correct). Any pointers? | 18:26 |
stevelle | sigmavirus24: haproxy been updated correctly? | 18:27 |
sigmavirus24 | stevelle: that was my first instinct but I can't find a haproxy container. Did we remove that for mitaka? | 18:27 |
stevelle | its on metal | 18:27 |
sigmavirus24 | ah | 18:28 |
*** coolg has left #openstack-ansible | 18:28 | |
*** jthorne has joined #openstack-ansible | 18:28 | |
stevelle | sigmavirus24: https://github.com/stevelle/openstack-ansible-gnocchi/blob/master/ext/bootstrap-aio.sh#L26 is my solution for that | 18:29 |
sigmavirus24 | ewww | 18:29 |
stevelle | yeah, I was thinking last night of trying to use config_templates to merge | 18:29 |
stevelle | we would need to update the role to support that however | 18:30 |
*** mgoddard_ has quit IRC | 18:30 | |
sigmavirus24 | stevelle: right | 18:31 |
sigmavirus24 | anyway, I think that'll get me most of the rest of the way on this. Thank you! | 18:31 |
sigmavirus24 | At least I'm getting 503's now :) | 18:32 |
*** electrofelix has quit IRC | 18:32 | |
bgmccollum | the assemble module might be a good pattern for that HAProxy config | 18:32 |
javeriak | i just hit something wierd on the liberty branch, if i try running the os-neutron.yml on its own it complains that there is no dict object 'bridge' on the computes, but it works fine within the openstack playbook | 18:33 |
stevelle | bgmccollum: similar solution yes, but we should add a task in the role to support it either way | 18:37 |
*** weezS_ has joined #openstack-ansible | 18:37 | |
bgmccollum | stevelle im looking at it now :) | 18:38 |
stevelle | javeriak: that sounds like it isn't picking up the -e @files | 18:38 |
javeriak | stevelle i think i saw them being sourced | 18:38 |
bgmccollum | ansible-playbook vs. openstack-ansible commands? | 18:38 |
javeriak | nope used openstack-ansible | 18:39 |
stevelle | javeriak: and from the playbooks dir? to be sure | 18:39 |
*** weezS has quit IRC | 18:39 | |
*** weezS_ is now known as weezS | 18:39 | |
javeriak | stevelle yep from /opt/openstack-ansible/playbooks | 18:40 |
stevelle | javeriak: very odd. will make a note to try a repro but my queue is many hours deep right now | 18:40 |
javeriak | stevelle no worries, im probably missing something, will go back and check again | 18:41 |
*** jthorne has quit IRC | 18:45 | |
*** galstrom_zzz is now known as galstrom | 18:50 | |
*** raddaoui has quit IRC | 18:50 | |
*** jthorne has joined #openstack-ansible | 18:53 | |
*** phalmos has quit IRC | 18:54 | |
*** sdake has joined #openstack-ansible | 18:54 | |
*** kstepniewski has quit IRC | 18:57 | |
*** galstrom is now known as galstrom_zzz | 19:01 | |
*** phalmos has joined #openstack-ansible | 19:14 | |
*** raddaoui has joined #openstack-ansible | 19:16 | |
openstackgerrit | Kevin Carter proposed openstack/openstack-ansible-specs: IRR - Create the os_crud_ops role https://review.openstack.org/272764 | 19:25 |
*** severion has quit IRC | 19:27 | |
*** kstepniewski has joined #openstack-ansible | 19:39 | |
*** galstrom_zzz is now known as galstrom | 19:40 | |
*** klamath has joined #openstack-ansible | 19:41 | |
klamath | Howdy, anyone know when decoming a swift node if removing the host from swift.yml will remove it from the ring? | 19:41 |
klamath | I see files/swift_rings.py: run_and_wait(rb_main, ["swift-ring-builder", build_file, "remove", is an option but not sure if it functions in real life | 19:41 |
*** javeriak has quit IRC | 19:50 | |
*** javeriak has joined #openstack-ansible | 19:55 | |
*** jthorne has quit IRC | 19:55 | |
bgmccollum | cloudnull logan- -- download.ceph.com just came back online... | 19:58 |
*** admin0 has quit IRC | 19:58 | |
*** weezS has quit IRC | 20:01 | |
*** jthorne has joined #openstack-ansible | 20:02 | |
*** jthorne has joined #openstack-ansible | 20:02 | |
*** jthorne has quit IRC | 20:17 | |
cloudnull | ooo nice! | 20:19 |
palendae | jmccrory: I'm gonna get the scripts that made this output pushed up in a separate patch I think, but here's a list of variable changes between kilo and liberty. https://gist.github.com/nrb/4dc547971e53c8016dd8 | 20:19 |
jmccrory | palendae: wow...quite a bit | 20:21 |
palendae | jmccrory: Yeah, though I think nova in particular is affected by the addition of the config_template module | 20:22 |
palendae | Some of this is gonna require manual comparison to see if stuff's a rename or just new | 20:22 |
palendae | That's also just a straight up diff between the defaults/main.yml files in each role | 20:23 |
palendae | So if there's a var in group_vars or playbooks, this doesn't do anything with it | 20:23 |
neillc | morning | 20:26 |
palendae | Morning neillc | 20:27 |
*** hybridpollo has joined #openstack-ansible | 20:30 | |
*** javeriak has quit IRC | 20:33 | |
openstackgerrit | Steve Lewis proposed openstack/openstack-ansible: Revert workaround disabling Keystone cache https://review.openstack.org/273229 | 20:33 |
sigmavirus24 | stevelle: have another minute? | 20:37 |
stevelle | sigmavirus24: yup | 20:37 |
*** raddaoui has quit IRC | 20:37 | |
sigmavirus24 | so the service is running but it isn't reachable from outside the containers, any ideas? | 20:38 |
palendae | Do the containers have network access? | 20:39 |
stevelle | sigmavirus24: is the service running on localhost or 0.0.0.0 ? | 20:39 |
sigmavirus24 | palendae: yes | 20:39 |
sigmavirus24 | stevelle: I have it configured to do that, let me check | 20:39 |
stevelle | sigmavirus24: also are you able to hit the service port on the container ip direct? | 20:40 |
sigmavirus24 | no, I think this service config is just bonkers. I just noticed that it wants host specified in two places | 20:40 |
* sigmavirus24 restarts service and tries again | 20:40 | |
sigmavirus24 | Ah there we go | 20:41 |
* sigmavirus24 grumbles about having the same config opt declared in [default] and [api] | 20:41 | |
stevelle | yeah, that's dumb | 20:41 |
stevelle | or it's a dumb-trap | 20:42 |
jmccrory | palendae: yeah, separate patch makes sense. think your current one works as an upgrade, but all the variable checks are going to take some time | 20:42 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Provide logrotate config for rsyncd on Swift storage hosts https://review.openstack.org/273231 | 20:42 |
palendae | jmccrory: Yeah, I'm actually digging through git logs now | 20:42 |
palendae | Cause some of these might be dropped for a reason, some might be moved out cause of config_template.. | 20:43 |
palendae | Not sure the best way to account for renamed vars, other than having a list for an upgrader script to look at that gets updated with the commit that renames it | 20:43 |
palendae | jmccrory: Also git-harry added a swift rycnd restart change that we were both hitting when running the upgrade script | 20:44 |
stevelle | palendae: fyi we have fought with that rsyncd restart before in kilo, and it continues to be a problem | 20:44 |
palendae | stevelle: I kind of remember | 20:45 |
stevelle | it was a blocker for multi-region swift | 20:45 |
palendae | https://review.openstack.org/273149 | 20:45 |
palendae | I haven't tried this patch yet, been swimming in diffs today | 20:45 |
*** galstrom is now known as galstrom_zzz | 20:45 | |
*** raddaoui has joined #openstack-ansible | 20:46 | |
stevelle | palendae: yeah, I will be skeptical of that change and I added a comment pointing to the prior troubles | 20:48 |
palendae | stevelle: Thanks | 20:48 |
palendae | I don't have that experience/background, so appreciated | 20:49 |
palendae | Wonder if it's specific to upgrading that hangs it | 20:49 |
Nepoc | Hello, I have a hopefully quick question. How do I add a network mapping in the openstack_user_config.yml. I need the vlan network mapped to a physical interface and all the examples I've found never result in any mappings being created in neutron. | 20:49 |
*** mgariepy has left #openstack-ansible | 20:53 | |
*** mgariepy has joined #openstack-ansible | 20:53 | |
Nepoc | Just to attempt to answer my own question. I assume it is: host_bind_override | 20:53 |
*** baker has quit IRC | 20:53 | |
*** galstrom_zzz is now known as galstrom | 20:54 | |
git-harry | palendae: stevelle It's simple enough to test. Modify /etc/rsyncd.conf then run os-swift-setup.yml | 20:56 |
palendae | jmccrory: One succes - https://review.openstack.org/#/c/227839/ for nova changes | 20:56 |
git-harry | That's failed every time for me as currently configured and worked every time with the patch. Not sure how else to test it. | 20:56 |
*** raddaoui has quit IRC | 20:57 | |
stevelle | git-harry: other fixes have appeared to work but it keeps breaking, that is what bothers me | 20:57 |
jmccrory | oh nice, that's useful | 20:57 |
palendae | stevelle: It breaks mutliregion specifically, or rsyncd? | 20:57 |
stevelle | palendae: we found while testing multi-region that it had been broken and unreported | 20:58 |
jmccrory | is there an easy way to search out UpgradeImpact tagged commits? | 20:58 |
palendae | jmccrory: I was perusing it in git log locally, should be able to git log --grep to at least look for commits locally | 20:58 |
palendae | I'm sure there's a way to search on gerrit | 20:58 |
*** d9k has quit IRC | 20:58 | |
stevelle | jmccrory: add comment: UpgradeImpact in the search text box | 20:59 |
stevelle | or add the equiv to your query string | 20:59 |
palendae | That'll grab any reviews with UpgradeImpact in them, too | 20:59 |
palendae | Like https://review.openstack.org/#/c/227839/ | 20:59 |
stevelle | if you want merged, add status: merged ofc | 21:00 |
palendae | https://review.openstack.org/#/q/message:UpgradeImpact | 21:00 |
palendae | ^ searches only commit messages, not people reviewing asking for the string :p | 21:00 |
stevelle | Fair enough, I assume if someone mentions it in comments you might want to look again :) | 21:01 |
palendae | https://review.openstack.org/#/q/message:UpgradeImpact+project:%255Eopenstack/openstack-ansible | 21:01 |
stevelle | now add liberty branch to that | 21:01 |
palendae | Yeah | 21:01 |
palendae | Hm, no | 21:02 |
stevelle | and now I'm questioning b/c I thought comment: included message: in the search | 21:02 |
palendae | If it got merged while master WAS liberty | 21:02 |
stevelle | also true, I think you can do an OR with updated date | 21:03 |
palendae | Sadly files:*defaults/main.yml seems to be invalid | 21:04 |
jmccrory | thanks stevelle | 21:05 |
palendae | stevelle: https://gerrit-documentation.storage.googleapis.com/Documentation/2.12/user-search.html#comment | 21:05 |
stevelle | palendae: perfect, so my query was less than helpful | 21:05 |
palendae | https://review.openstack.org/#/q/message:UpgradeImpact+project:%255Eopenstack/openstack-ansible++file:%255E.*defaults/main.yml | 21:05 |
palendae | Adding status:merged gets a much smaller pool | 21:06 |
palendae | Relies on people having added UpgradeImpact,but better than going blind | 21:06 |
*** adac has quit IRC | 21:07 | |
*** daneyon has joined #openstack-ansible | 21:08 | |
*** d9k has joined #openstack-ansible | 21:08 | |
*** daneyon_ has joined #openstack-ansible | 21:12 | |
*** galstrom is now known as galstrom_zzz | 21:13 | |
*** daneyon has quit IRC | 21:15 | |
*** phiche has joined #openstack-ansible | 21:17 | |
*** phiche1 has joined #openstack-ansible | 21:21 | |
*** phiche has quit IRC | 21:22 | |
*** baker has joined #openstack-ansible | 21:22 | |
*** weezS has joined #openstack-ansible | 21:22 | |
*** raddaoui has joined #openstack-ansible | 21:33 | |
openstackgerrit | Merged openstack/openstack-ansible: Process git repos in role defaults at low priority https://review.openstack.org/272982 | 21:36 |
mhayden | should openstack-ansible-security get a liberty backport? my guy says yes because there's nothing mitaka-specific in it | 21:58 |
spotz | Your guy or your gut?:) | 22:01 |
*** CheKoLyN has quit IRC | 22:01 | |
palendae | mhayden: Fine with me | 22:02 |
palendae | But I'm only +- 1 | 22:02 |
spotz | I don't see an issue either as it's last release. I don't think I'd go back further | 22:03 |
*** phiche1 has quit IRC | 22:04 | |
*** phiche has joined #openstack-ansible | 22:04 | |
cloudnull | mhayden: I say +2 | 22:06 |
cloudnull | maybe just include it in the ansible-role-requirements.yml file | 22:07 |
cloudnull | in liberty and then provide the play to run it similar to what you've just done in master. | 22:07 |
mhayden | okay | 22:10 |
*** woodard_ has joined #openstack-ansible | 22:10 | |
palendae | Yeah | 22:10 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Add config option + docs for security hardening https://review.openstack.org/273257 | 22:13 |
*** woodard has quit IRC | 22:14 | |
*** woodard_ has quit IRC | 22:14 | |
mhayden | cloudnull: should the status be changed on the BP since the code has merged? | 22:14 |
mhayden | https://blueprints.launchpad.net/openstack-ansible/+spec/security-hardening | 22:14 |
*** mgoddard_ has joined #openstack-ansible | 22:21 | |
*** raddaoui has quit IRC | 22:21 | |
*** phiche has quit IRC | 22:26 | |
*** daneyon has joined #openstack-ansible | 22:34 | |
*** admin0 has joined #openstack-ansible | 22:35 | |
*** daneyon_ has quit IRC | 22:35 | |
*** daneyon_ has joined #openstack-ansible | 22:36 | |
*** daneyon has quit IRC | 22:40 | |
*** automagically has quit IRC | 22:40 | |
*** Mudpuppy has quit IRC | 22:45 | |
*** sdake has quit IRC | 22:45 | |
*** mgoddard_ has quit IRC | 22:49 | |
*** izaakk has quit IRC | 22:53 | |
sigmavirus24 | No one has a barbican role immediately available, right? | 23:00 |
*** raddaoui has joined #openstack-ansible | 23:03 | |
*** baker has quit IRC | 23:12 | |
*** raddaoui has quit IRC | 23:12 | |
stevelle | sigmavirus24: haven't heard of one yet | 23:13 |
sigmavirus24 | guess I have to write that too | 23:13 |
sigmavirus24 | magnum needs a key manager service and what better than barbican? | 23:14 |
stevelle | sigmavirus24: happy to collab on barbican just so I can get familiar | 23:14 |
*** baker has joined #openstack-ansible | 23:14 | |
sigmavirus24 | stevelle: cool | 23:15 |
sigmavirus24 | I'll talk to you tomorrow about it. Heading out for now | 23:15 |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:16 | |
*** baker has quit IRC | 23:19 | |
*** baker has joined #openstack-ansible | 23:20 | |
*** admin0 has quit IRC | 23:21 | |
spotz | sigmavirus24 stevelle if you need an intro to the barbican folk let me know | 23:21 |
*** baker has quit IRC | 23:32 | |
*** spotz is now known as spotz_zzz | 23:40 | |
*** klamath has quit IRC | 23:53 | |
*** Alex___ has joined #openstack-ansible | 23:54 | |
Alex___ | anyone seen this before? /openstack/log/servername-swift is set 755 swift:swift, so rsyslog which drops privs to syslog:syslog can't write to that directory, so you don't get any log files created.. not sure if this always happens, or because I'm playing with openstack-ansible-security and it locked something down. anyone else get this? this is on bare_metal, not in a container | 23:56 |
cloudnull | I've not seen that Alex___ | 23:57 |
Alex___ | what do perms normally look like? rsyslog looks to get swift logging via local1, so it should be up to rsyslog to create the swift logs, yet the dir is 755 swift:swift, so it can't create it... is it normally set different owner? | 23:58 |
Alex___ | or perhaps drop priv got added in -security and normally rsyslog runs as root? | 23:58 |
cloudnull | let me go look | 23:59 |
Alex___ | much appreciated. =) | 23:59 |
cloudnull | which osa release ? | 23:59 |
Alex___ | liberty | 23:59 |
cloudnull | kk i have one of those up | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!