*** asettle has joined #openstack-ansible | 00:10 | |
*** fawadkhaliq has quit IRC | 00:12 | |
*** fawadkhaliq has joined #openstack-ansible | 00:13 | |
*** sdake_ has joined #openstack-ansible | 00:35 | |
*** sdake has quit IRC | 00:38 | |
*** fawadkhaliq has quit IRC | 00:40 | |
*** fawadkhaliq has joined #openstack-ansible | 00:40 | |
*** sdake_ has quit IRC | 00:47 | |
*** sdake has joined #openstack-ansible | 00:47 | |
*** b3rnard0 is now known as b3rnard0_away | 00:50 | |
*** asettle has quit IRC | 00:54 | |
*** jorge_munoz has quit IRC | 00:54 | |
*** fawadkhaliq has quit IRC | 01:02 | |
*** asettle has joined #openstack-ansible | 01:04 | |
*** fawadkhaliq has joined #openstack-ansible | 01:07 | |
*** asettle has quit IRC | 01:08 | |
*** fawadkhaliq has quit IRC | 01:14 | |
*** asettle has joined #openstack-ansible | 01:23 | |
*** jamielennox|away is now known as jamielennox | 01:29 | |
*** saneax is now known as saneax_AFK | 01:41 | |
*** thorst has quit IRC | 01:59 | |
*** saneax_AFK is now known as saneax | 02:23 | |
*** saneax is now known as saneax_AFK | 02:43 | |
openstackgerrit | Merged openstack/openstack-ansible: Updates all repo SHAs to prepare for Mitaka release https://review.openstack.org/296799 | 03:23 |
---|---|---|
cloudnull | ^ woot! thanks for the reviews spotz_zzz automagically and stevelle | 03:25 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Fail when ansible-galaxy returns error https://review.openstack.org/292285 | 03:26 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Enable SSL termination for all services https://review.openstack.org/277199 | 03:26 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Removed the repo clone mirror play https://review.openstack.org/295941 | 03:27 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Adjust swift plays to use unified os-swift role https://review.openstack.org/293911 | 03:27 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Adding legacy ethx steps to convert enox, enpx etc https://review.openstack.org/294942 | 03:27 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update ansible to the latest release (v1.9.5-1) https://review.openstack.org/296839 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add group_vars for swift_remote_all hosts https://review.openstack.org/297257 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Remove pip_get_pip_options override from group_vars https://review.openstack.org/296594 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add condition to local IP for overlay net https://review.openstack.org/273793 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Include security role in setup-hosts.yml https://review.openstack.org/290526 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: OpenStack services should reach Glance via the internal LB VIP https://review.openstack.org/290844 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add ebtables check for network hosts https://review.openstack.org/289622 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add installation support for os_ironic https://review.openstack.org/293779 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add project scoped token when obtaning token https://review.openstack.org/297563 | 03:28 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Fixing keepalived bug when 2+ backup nodes have the same priority https://review.openstack.org/279730 | 03:32 |
*** winggundamth has quit IRC | 03:49 | |
*** asettle has quit IRC | 03:58 | |
*** thorst has joined #openstack-ansible | 04:00 | |
*** thorst has quit IRC | 04:09 | |
*** fawadkhaliq has joined #openstack-ansible | 04:20 | |
*** fawadk has joined #openstack-ansible | 04:21 | |
*** fawadkhaliq has quit IRC | 04:25 | |
mrda | cloudnull: thanks for the rebase, was getting there | 04:43 |
*** fawadk has quit IRC | 05:00 | |
*** saneax_AFK is now known as saneax | 05:01 | |
*** thorst has joined #openstack-ansible | 05:06 | |
*** pcaruana has quit IRC | 05:09 | |
*** asettle has joined #openstack-ansible | 05:12 | |
*** thorst has quit IRC | 05:14 | |
*** shausy has joined #openstack-ansible | 05:15 | |
*** fawadkhaliq has joined #openstack-ansible | 05:38 | |
*** asettle has quit IRC | 05:39 | |
*** sdake_ has joined #openstack-ansible | 05:50 | |
*** sdake has quit IRC | 05:52 | |
*** winggundamth has joined #openstack-ansible | 05:54 | |
openstackgerrit | Michael Davies proposed openstack/openstack-ansible-os_nova: WIP: Add Nova config for os_ironic role https://review.openstack.org/293315 | 05:54 |
*** asettle has joined #openstack-ansible | 05:54 | |
*** asettle has quit IRC | 05:59 | |
*** thorst has joined #openstack-ansible | 06:01 | |
*** thorst has quit IRC | 06:09 | |
*** jiteka has joined #openstack-ansible | 06:12 | |
*** markvoelker has joined #openstack-ansible | 06:22 | |
*** markvoelker_ has joined #openstack-ansible | 06:23 | |
*** markvoelker has quit IRC | 06:27 | |
*** neilus has joined #openstack-ansible | 06:43 | |
*** markvoelker_ has quit IRC | 06:43 | |
*** markvoelker has joined #openstack-ansible | 06:44 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-ironic: [WIP] Add tests for the ironic CLI https://review.openstack.org/298557 | 06:48 |
*** fawadkhaliq has quit IRC | 06:49 | |
*** neilus has quit IRC | 06:52 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-ironic: [WIP] Add tests for the ironic CLI https://review.openstack.org/298557 | 06:55 |
openstackgerrit | Merged openstack/openstack-ansible: Add ebtables check for network hosts https://review.openstack.org/289622 | 07:05 |
*** thorst has joined #openstack-ansible | 07:06 | |
*** admin0 has joined #openstack-ansible | 07:09 | |
*** markvoelker has quit IRC | 07:12 | |
*** thorst has quit IRC | 07:13 | |
*** javeriak has joined #openstack-ansible | 07:14 | |
admin0 | good morning all | 07:15 |
*** neilus has joined #openstack-ansible | 07:16 | |
*** sdake_ has quit IRC | 07:22 | |
*** gparaskevas has joined #openstack-ansible | 07:25 | |
*** sdake has joined #openstack-ansible | 07:25 | |
mattt | morning admin0 | 07:25 |
admin0 | morning mattt | 07:26 |
admin0 | need a bit of help on neutron .. as soon as I enable any of the neutron_plugin_base, neutron breaks | 07:27 |
admin0 | http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-network-services.html — using like that | 07:29 |
mattt | admin0: logs would be helpful | 07:31 |
admin0 | mattt: btw, ceph is working : https://www.openstackfaq.com/openstack-ansible-ceph/ | 07:31 |
admin0 | documented there :) | 07:31 |
*** javeriak has quit IRC | 07:32 | |
*** javeriak has joined #openstack-ansible | 07:32 | |
mattt | admin0: nice :) | 07:36 |
*** admin0 has quit IRC | 07:43 | |
*** pcaruana has joined #openstack-ansible | 07:48 | |
*** admin0 has joined #openstack-ansible | 07:50 | |
admin0 | mattt: suppose if i enable say just neutron_plugin_base: vpnaas .. is just running os-neutron enough ? | 07:56 |
admin0 | enabled just vpnaas .. running the os-neutron playbook .. will gist the logs from neutron-server | 07:57 |
mattt | admin0: i don't think vpnaas has been implemented in openstack-ansible | 08:03 |
admin0 | mattt: gist: https://gist.github.com/a1git/5d573594062c0501859d | 08:04 |
*** javeriak has quit IRC | 08:06 | |
admin0 | mattt: so none of these work ? | 08:07 |
admin0 | or how to verify which ones work ? | 08:07 |
admin0 | or are enabled | 08:07 |
*** mgoddard has joined #openstack-ansible | 08:07 | |
*** thorst has joined #openstack-ansible | 08:11 | |
*** markvoelker has joined #openstack-ansible | 08:13 | |
mattt | admin0: i'm guessing a bunch are fully implemented by neutron and should just work | 08:14 |
mattt | admin0: but i know openstack-ansible had to be updated for lbaas to work, and imagine similar work needs doing for vpnaas | 08:15 |
admin0 | so if i enabled lbaas, it will work ? | 08:15 |
admin0 | v2 | 08:15 |
admin0 | i will try that one now | 08:15 |
*** markvoelker has quit IRC | 08:17 | |
mattt | admin0: v2 was recently implemented by mhayden i believe, and he has that documented etc. | 08:18 |
*** thorst has quit IRC | 08:18 | |
mattt | admin0: ImportError: No module named neutron_vpnaas.services.vpn.plugin | 08:19 |
admin0 | mattt: i just followed this: http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-network-services.html :D | 08:19 |
admin0 | ImportError: No module named LoadBalancerPluginv2 | 08:20 |
admin0 | so something more needs to be done i think | 08:20 |
*** javeriak has joined #openstack-ansible | 08:20 | |
mattt | admin0: so one thing i know for sure | 08:20 |
mattt | admin0: there are separate neutron packages for lbaas, fwaas, etc. | 08:20 |
mattt | so you want to make sure ansible is installing those | 08:21 |
mattt | because if not you'll get those sorts of errors | 08:21 |
admin0 | got it .. but how to make sure ansible is installing those ? | 08:21 |
admin0 | destroy the containers ? | 08:21 |
mattt | nooo | 08:21 |
*** elo has quit IRC | 08:23 | |
*** elo has joined #openstack-ansible | 08:23 | |
admin0 | how ? | 08:23 |
admin0 | shouldn’t os-neutron check for those ? or fix those | 08:24 |
mattt | admin0: you'll have to look at the code, i didn't write it all :) | 08:25 |
admin0 | i am not a good coder .. i can run setup-infra hoping to see if that helps | 08:26 |
admin0 | there was a way to redo pip-wheel-image something :D ? | 08:26 |
*** asettle has joined #openstack-ansible | 08:26 | |
mattt | admin0: give me a bit, i'm going to spin up a test instance so i can play with this | 08:27 |
mattt | i don't know much about neutron, but i have installed the neutron lbaas plugin before to test migrations | 08:28 |
admin0 | i am running setup-infra playbook | 08:29 |
mattt | okie | 08:31 |
*** tiagogomes_ has quit IRC | 08:37 | |
*** tiagogomes has joined #openstack-ansible | 08:37 | |
*** javeriak has quit IRC | 08:43 | |
mattt | admin0: heh, enabling lbaas broke my neutron too | 08:46 |
admin0 | \o/ :D | 08:46 |
admin0 | the docs mention it so easily that it will just work like that :) | 08:46 |
mattt | i'm not even sure what's wrong with my neutron-server tbh | 08:54 |
mattt | perhaps i'm hitting some other issue | 08:54 |
admin0 | i had the missing plugins in my logs .. none in yours ? | 08:55 |
mattt | admin0: yeah i think my issues are unrelated to re-running neutron playbook | 08:56 |
mattt | keystone is unresponsive which is why the play failed | 08:56 |
mattt | admin0: ok fixed my keystone, neutron play finished with lbaas enabled | 09:00 |
mattt | and i see lbaas in a neutron ext-list | 09:01 |
*** mgagne has quit IRC | 09:08 | |
*** toanster has quit IRC | 09:09 | |
*** spotz_zzz has quit IRC | 09:09 | |
admin0 | mattt: i first did a complete build without any plugins, then just enabled the plugins and run the os-neutron .. broke it | 09:10 |
*** toan has joined #openstack-ansible | 09:11 | |
*** h1nch has quit IRC | 09:11 | |
*** xar- has quit IRC | 09:11 | |
mattt | admin0: let me try v2, i tried just regular lbaas | 09:12 |
admin0 | i hold off to v1 due to “LBaaS v1 was deprecated during the Liberty release and is not recommended for new deployments.” :D | 09:12 |
mattt | yeah i was more testing plugin functionality rather than lbaas itself :) | 09:13 |
*** xar- has joined #openstack-ansible | 09:13 | |
*** mgagne has joined #openstack-ansible | 09:14 | |
admin0 | ImportError: No module named LoadBalancerPluginv2 | 09:14 |
*** h1nch has joined #openstack-ansible | 09:14 | |
*** spotz_zzz has joined #openstack-ansible | 09:14 | |
*** mgagne is now known as Guest68910 | 09:14 | |
mattt | admin0: oh wait, are you on liberty ? | 09:14 |
admin0 | yes | 09:14 |
mattt | admin0 then you should be reading http://docs.openstack.org/developer/openstack-ansible/liberty/install-guide :) | 09:16 |
*** thorst has joined #openstack-ansible | 09:16 | |
mattt | i'm not sure if any of the lbaasv2 stuff was backported to liberty, i'd imagine not | 09:17 |
mattt | admin0: give lbaas a shot, see if that works for you | 09:22 |
*** thorst has quit IRC | 09:24 | |
*** asettle has quit IRC | 09:27 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-os_cinder: [WIP] Do not merge https://review.openstack.org/297071 | 09:32 |
*** Tebro has joined #openstack-ansible | 09:42 | |
Tebro | Hey, is there a guide somewhere on how to use the openshift-ansible scripts with Vagrant to setup an test/demo environment? | 09:43 |
mattt | Tebro: there's no relation between openshift-ansible and openstack-ansible i'm afraid | 09:43 |
Tebro | oops, wrong term xD mean openstack-ansible | 09:44 |
mattt | Tebro: not used vagrant myself, however i believe there is work underway to allow you to spin up an AIO using vagrant | 09:46 |
Tebro | Okay, thanks! Is the AIO something you run on any ubuntu machine or= | 09:47 |
Tebro | *? | 09:47 |
mattt | Tebro: yeah, ubuntu trusty is all we support at the moment | 09:47 |
Tebro | Alright, have to look through the docs on that then. | 09:47 |
mattt | Tebro: http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html#building-an-aio | 09:48 |
Tebro | mattt: Thanks! | 09:50 |
mattt | Tebro: np! | 09:52 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-os_cinder: Update tests to work w/ secure_path update https://review.openstack.org/297071 | 09:52 |
*** asettle has joined #openstack-ansible | 09:52 | |
*** admin0 has quit IRC | 09:55 | |
*** admin0 has joined #openstack-ansible | 09:57 | |
*** asettle has quit IRC | 09:57 | |
admin0 | mattt: is lbaasv1 the only thing that worked ? did you tried anything else ? | 09:59 |
mattt | admin0: nope | 10:02 |
mattt | admin0: like i said i'm pretty sure fwaas and vpnaas need additional development, we don't use them at Rackspace so we haven't implemented anything | 10:02 |
admin0 | ok | 10:03 |
admin0 | if i want to implement them, do I need to use the overrides ? | 10:04 |
mattt | admin0: i'd recommend looking to see how lbaasv1 and lbaasv2 were implemented, you could follow that model to get other things in | 10:04 |
*** gparaskevas has quit IRC | 10:07 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible: Add group_vars for swift_remote_all hosts https://review.openstack.org/297257 | 10:08 |
*** sdake has quit IRC | 10:10 | |
admin0 | mattt: lbaas - working :) | 10:13 |
admin0 | will check to see if i can figure out a similar way for vpnaas | 10:14 |
*** markvoelker has joined #openstack-ansible | 10:14 | |
*** pjm6 has joined #openstack-ansible | 10:15 | |
admin0 | mattt: different issue .. i see that my public endpoints is confired as https:// , but they actually listen on http:// | 10:15 |
admin0 | let me gist my config | 10:15 |
admin0 | so see where it went wrong | 10:15 |
pjm6 | hi there | 10:16 |
mattt | pjm6: howdy | 10:17 |
admin0 | hi pjm6 | 10:19 |
admin0 | mattt: https://gist.github.com/a1git/c69d44ec53d8ed4cef0d | 10:19 |
pjm6 | guys could you correct me if I'm wrong | 10:19 |
pjm6 | in this doc | 10:19 |
pjm6 | http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-networking.html | 10:19 |
pjm6 | the container, tunnel and storage | 10:19 |
admin0 | yes | 10:19 |
pjm6 | shouldn't be | 10:19 |
pjm6 | tabbed? | 10:19 |
pjm6 | because it belongs to the variable (or list) cidr_networks | 10:20 |
admin0 | pjm6: sample config here: https://github.com/a1git/openstack-cloud/blob/master/openstack_deploy/openstack_user_config.yml | 10:20 |
pjm6 | yes, and have space | 10:20 |
*** markvoelker has quit IRC | 10:20 | |
admin0 | can be a whitespace | 10:21 |
admin0 | my vi replaces tabs with spaces | 10:21 |
pjm6 | yes, but if we put in the same line, the yaml will give an error (I think) | 10:21 |
*** thorst has joined #openstack-ansible | 10:21 | |
pjm6 | and thanks for the config file, it seems to have the configuration of the tutorial :) | 10:22 |
admin0 | it belongs to https://www.openstackfaq.com/openstack-liberty-private-cloud-howto/ — overview | 10:23 |
admin0 | so you know were the cXX servers fit | 10:23 |
pjm6 | thanks :D | 10:25 |
pjm6 | but I was suggesting if the whitespaces/tabs are necessary for a correct yaml configuration, is in adding tabs in the doc | 10:25 |
admin0 | as long as it belongs to the necessary groups and is properly aligned | 10:26 |
pjm6 | yes, that was I though :) | 10:27 |
pjm6 | that page didn't refer what's the ip of | 10:27 |
pjm6 | cloud101int.admin0.com ? | 10:27 |
admin0 | i use a VYOS 1:1 nat | 10:28 |
admin0 | between public and private endpoint | 10:28 |
admin0 | pjm6: https://github.com/a1git/openstack-cloud/blob/master/openstack_deploy/user_variables.yml | 10:28 |
admin0 | that has the IPs | 10:28 |
admin0 | towards the end | 10:28 |
*** thorst has quit IRC | 10:29 | |
admin0 | haproxy_keepalived_* vip_cidr | 10:29 |
admin0 | 10.11.12.3 is what i do a 1:1 mapping with my public IP | 10:29 |
admin0 | you can replace that with your direct public IP address | 10:29 |
pjm6 | thanks :) | 10:30 |
pjm6 | when you say 10.11.12.3 1:1 nat | 10:30 |
pjm6 | is that you are using that IP address for public and private lb vip? | 10:30 |
admin0 | actually not :) .. i am using URL | 10:30 |
admin0 | https://gist.github.com/a1git/c69d44ec53d8ed4cef0d | 10:30 |
admin0 | that is how it appears on endpoint list | 10:30 |
admin0 | i am facing ssl issues, but for the VIP and endpoiints, (wthout SSL) just works | 10:31 |
admin0 | trying to fix/figure-out why ssl | 10:31 |
pjm6 | ahh ok, so you put the URL instead of IP and then the domain points to the IPs of the respective services? | 10:32 |
admin0 | yes | 10:32 |
admin0 | since I use the vyos as gateway, and there i have a static dns that points my public to the internal IP .. so it works on either side :) | 10:33 |
admin0 | from outside, it points to the real public IP that lives in vyos | 10:33 |
admin0 | from internal,it points to 10.11.12.3 | 10:33 |
admin0 | so works eitherway | 10:33 |
pjm6 | it's like having an internal and external DNS | 10:34 |
pjm6 | where when you are on the local network it will point to 10.11.12.3 | 10:34 |
pjm6 | and outside gives the public IP, right? | 10:34 |
*** admin0_ has joined #openstack-ansible | 10:35 | |
admin0_ | right now cloud101.admin0.com gives 10.11.12.3 , because i use a different domain .. admin0.com is used for public/testing/<asking help here> etc :) | 10:36 |
*** admin0 has quit IRC | 10:38 | |
*** admin0_ is now known as admin0 | 10:38 | |
pjm6 | hmm i see, that's way you adopt to use domain instead of IP in that configuration =) | 10:38 |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-ironic: [WIP] Add tests for the ironic REST API https://review.openstack.org/298654 | 10:48 |
*** asettle has joined #openstack-ansible | 10:56 | |
*** asettle has quit IRC | 10:56 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-os_nova: [WIP] Standardise nova functional tests and add actual tests https://review.openstack.org/298663 | 11:03 |
pjm6 | where I can find the detailed logs of openstack ansible? | 11:03 |
mattt | pjm6: which part specifically ? | 11:07 |
pjm6 | mattt: when I run openstack-ansible setup-hosts.yml | 11:07 |
pjm6 | it gives me error in Update apt sources | 11:08 |
pjm6 | in all hosts :\ | 11:08 |
pjm6 | it seems that there are no internet conectivity | 11:08 |
pjm6 | but I can access VM inside and outside | 11:08 |
admin0 | pjm6: you can do -vvvv and then use | tee abc.log .. and output to the log | 11:08 |
mattt | ^^^^ | 11:08 |
admin0 | haproxy | 11:08 |
mattt | but try logging into a container and see if you can manually update apt sources | 11:08 |
pjm6 | thanks, i will try that :) | 11:09 |
openstackgerrit | git-harry proposed openstack/openstack-ansible-rabbitmq_server: Remove clustering config from rabbitmq.config https://review.openstack.org/298665 | 11:09 |
pjm6 | well thats odd because now only two nodes failed | 11:10 |
pjm6 | 1 was changed | 11:10 |
*** javeriak has joined #openstack-ansible | 11:10 | |
pjm6 | it seems that the containers are not created yer | 11:13 |
pjm6 | at least I don't have in the machine lxc | 11:13 |
pjm6 | well my storage node and compute node are in the same machine (testing proposes) | 11:15 |
pjm6 | when I run again it seems that he advance (at least is not giving error now and doing configuration) | 11:15 |
pjm6 | and pass that task, maybe is because the openstack ansible made parallel connection | 11:16 |
pjm6 | and as he are trying to access the same machine, it gives timeout ? | 11:16 |
*** markvoelker has joined #openstack-ansible | 11:16 | |
openstackgerrit | git-harry proposed openstack/openstack-ansible-rabbitmq_server: Remove clustering config from rabbitmq.config https://review.openstack.org/298665 | 11:20 |
*** markvoelker has quit IRC | 11:21 | |
*** johnmilton has joined #openstack-ansible | 11:23 | |
*** thorst has joined #openstack-ansible | 11:44 | |
*** thorst has quit IRC | 11:45 | |
*** thorst has joined #openstack-ansible | 11:45 | |
*** thorst has quit IRC | 11:51 | |
admin0 | pjm6: you have 1 node ? | 11:52 |
admin0 | for testing ? | 11:52 |
admin0 | or multiple ? | 11:52 |
admin0 | or 1 big node that you can create VMs ? | 11:52 |
mhayden | morning folks | 11:53 |
mhayden | admin0: let me know if you're still stuck on lbaasv2 | 11:53 |
admin0 | morning | 11:53 |
*** weshay has joined #openstack-ansible | 11:53 | |
admin0 | mhayden: ibaas seems to work .. stuck at SSL :) | 11:53 |
mhayden | that's something i haven't tested | 11:53 |
*** gparaskevas has joined #openstack-ansible | 11:54 | |
mhayden | are you trying ssl offloading? | 11:54 |
admin0 | how :D | 11:54 |
admin0 | : https://gist.github.com/a1git/c69d44ec53d8ed4cef0d | 11:54 |
admin0 | that is what I have so far :) | 11:54 |
*** asettle has joined #openstack-ansible | 11:56 | |
admin0 | so the haproxy that is installed does not do ssl offloading (as expected) ? | 11:56 |
*** pjm6 has quit IRC | 11:58 | |
*** thorst has joined #openstack-ansible | 12:01 | |
mhayden | oh, you're talking about the haproxy deployed on the infra | 12:01 |
mhayden | i was talking about lbaasv2 that tenants consume | 12:02 |
admin0 | oh | 12:02 |
admin0 | functional test is next in my list .. trying to get the infra part proper first | 12:02 |
admin0 | why couldn’t all public endppints be in SSL ( by default ) | 12:02 |
admin0 | who would like to setup non-ssl even internal ? | 12:03 |
admin0 | thats a different discussion :) | 12:04 |
admin0 | how does it work in rackspace :D ? | 12:04 |
admin0 | mattt: mentioned earlier that vpnaas etc is not used in rackspace so not implemented yet, but SSL i guess might be something that is implemented | 12:06 |
mhayden | i'm interested in the fw/vpn stuff in neutron, but the vpn stuff seems to have more value, unless i am overlooking what FWaaS does | 12:10 |
mattt | admin0: yeah i believe all the ssl support is there | 12:13 |
admin0 | fwaas is firewall for whole instances as opposed to individual ones | 12:14 |
admin0 | so yes, vpnaas has more value | 12:14 |
admin0 | mattt: but its not working and i am trying to figure out why | 12:14 |
mattt | cool let me know when you figure it out ;) | 12:15 |
admin0 | :D | 12:15 |
admin0 | i am trying . | 12:15 |
admin0 | and failing | 12:15 |
mattt | admin0: hehe, lemme see | 12:15 |
admin0 | mattt: https://gist.github.com/a1git/c69d44ec53d8ed4cef0d | 12:15 |
mattt | yep looking at that now | 12:16 |
mattt | admin0: each service has an ssl flag iirc | 12:16 |
admin0 | http://docs.openstack.org/developer/openstack-ansible/liberty/install-guide/configure-sslcertificates.html — that listed just 4 services | 12:16 |
mattt | admin0: are you terminating ssl at the LB ? | 12:17 |
admin0 | yes | 12:17 |
admin0 | that is what I assumed the playbooks will do | 12:17 |
*** markvoelker has joined #openstack-ansible | 12:17 | |
mattt | admin0: https://github.com/openstack/openstack-ansible-os_nova/blob/master/defaults/main.yml#L194-L195 | 12:18 |
mattt | let me see how the AIO is set up by default | 12:18 |
admin0 | mattt: the only thing working on ssl with my config is horizon, and there it points to :443 on each individual containers | 12:18 |
admin0 | so as long as there is SSL, i do not think it matters if haproxy does the SSL or the individual services itself does the SSL | 12:19 |
admin0 | requirement: SSL on all public endpoints ways: 1. SSL on haproxy, 2. haproxy just forwards, SSL on each individual services 3. use external LB/vyos — Documentation - none :) | 12:20 |
admin0 | either way SSL works for all, i am happy :) | 12:22 |
*** markvoelker has quit IRC | 12:22 | |
*** javeriak has quit IRC | 12:24 | |
mattt | admin0: did you enable haproxy_ssl /AFTER/ you deployed everything ? | 12:25 |
mattt | admin0: if so you may need to manually update your endpoints or recreate them | 12:27 |
mattt | because they would have been registered with https | 12:27 |
mattt | sorry http instead of https | 12:27 |
admin0 | the first thing i run is openstack-ansible haproxy-setup | 12:33 |
admin0 | oh | 12:33 |
admin0 | hmm | 12:33 |
admin0 | so the settting is correct ? | 12:33 |
*** woodard has joined #openstack-ansible | 12:33 | |
admin0 | how to force-recreate ? | 12:33 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Remove pip_get_pip_options override from group_vars https://review.openstack.org/296594 | 12:34 |
mattt | admin0: wait | 12:34 |
admin0 | i can re-deploy the environment .. if you pass me a user_variable.yml snippet that will create everything on https :) | 12:34 |
mattt | admin0: you already have https:// on your public endpoints | 12:34 |
admin0 | yes .. on openstack, it says https:// | 12:35 |
admin0 | but on reality, haproxy is not listening to it | 12:35 |
admin0 | on haproxy conf.d, there is horizon_ssl, but not keystone_ssl | 12:36 |
mattt | let me see if i can get my aio to use ssl | 12:38 |
admin0 | i can add your keys and lend you this platfrom :D | 12:38 |
admin0 | its a closed test anyway | 12:38 |
admin0 | if you need a non-aio | 12:38 |
mattt | that's ok thanks :) | 12:39 |
mattt | that sounds like a bad time just waiting to happen :P | 12:39 |
*** pjm6 has joined #openstack-ansible | 12:39 | |
pjm6 | morning mhayden | 12:40 |
pjm6 | admin0: I have three nodes | 12:40 |
pjm6 | 1 fotr controller, 1 for storage and compute and other for network | 12:40 |
admin0 | pjm6: to test you can use 2 for controllers and 1 for compute | 12:41 |
admin0 | or 1 storage, 1 controller, 1 compute | 12:41 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: OpenStack services should reach Glance via the internal LB VIP https://review.openstack.org/290844 | 12:41 |
admin0 | or 1 ceph, 1 controller , 1 compute :D | 12:41 |
pjm6 | yes, but as I need to have an network node in the final deployment, I trying to deploy with that way, | 12:42 |
pjm6 | btw: after running again the command 3 times, it worked for setup-host | 12:42 |
pjm6 | I think the problem was about apt-get being lock by the parallel process | 12:42 |
pjm6 | btw: I choose a dedicated network host, but the neutron was installed in infra1 | 12:43 |
pjm6 | when doing setup-hosts.yml | 12:43 |
odyssey4me | o/ | 12:43 |
pjm6 | hi odyssey4me | 12:44 |
admin0 | hello odyssey4me | 12:45 |
admin0 | odyssey4me: this is the document you asked for : https://www.openstackfaq.com/openstack-ansible-ceph/ | 12:46 |
admin0 | :D | 12:46 |
admin0 | is contributiing to documentation also the same as code ? git checkout , edit the file and hope someone will merge it ? | 12:47 |
mattt | admin0: it is yes | 12:49 |
admin0 | ok .. then will give it a try for the ceph integration part | 12:50 |
pegmanm | Hi "http://docs.openstack.org/developer/openstack-ansible/install-guide/overview-requirements.html" states minimum requirements = Ubuntu 14.04 LTS. Is this correct is the project debian based only for now. | 12:50 |
pegmanm | I ask because a lot of the sub-modules are os-agnostic and before I go trying I thought I would ask here. Has anyone used the project to deply on redhat based systems. ? | 12:51 |
pjm6 | pegmanm: I used CentOS but was with devstack, never tried with openstack-ansible, for that i'm using the recommended | 12:52 |
pegmanm | ok - I'll just have to give it a try and see where (if anywhere) I hit issues. Thanks for the reponse. | 12:53 |
odyssey4me | pegmanm we have ongoing work to enable OSA for multiple platforms - it's not yet complete, so no - at the moment there is no support for anything but Ubuntu | 12:53 |
odyssey4me | we're looking for contributors to that effort | 12:53 |
admin0 | pegmanm: if you have no ISO or company requirements, then ubuntu will do fine as well | 12:53 |
admin0 | been using it for years, no issues | 12:53 |
pegmanm | Well I may be able to help with some pull reqs. Unfortunatly this is for a client and they are RH only. Nothing else comes in the door. | 12:54 |
admin0 | mattt: i am still holding for the SSL :D | 12:59 |
mattt | admin0: i think it's working for me, sec | 13:00 |
admin0 | \o/ — i like what i hear | 13:00 |
admin0 | odyssey4me: as soon as there is something to test, i can test our various cases on centos as well and report bugs | 13:05 |
admin0 | mhayden: are you taking/fixing vpnaas ;) ? | 13:06 |
mattt | admin0: can you try connecting to keystone on https ? | 13:09 |
mattt | admin0: you tried glance in that gist, but i want to see if keystone works | 13:09 |
admin0 | one moment | 13:09 |
mattt | admin0: also haproxy doesn't configure https for glance, it looks to be just keystone, horizon, and some nova bits | 13:10 |
admin0 | curl: (52) Empty reply from server | 13:10 |
admin0 | on -I curl | 13:10 |
mattt | admin0: which port ? | 13:11 |
admin0 | 5000 | 13:11 |
admin0 | let me use a proper cleint and do a test | 13:11 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Remove the repo clone mirror play https://review.openstack.org/295941 | 13:11 |
mattt | curl --insecure should work | 13:11 |
mattt | i enabled haproxy_ssl: true and keystone_service_adminuri_proto: https and i can connect to 35357 on https | 13:12 |
*** pjm6 has quit IRC | 13:13 | |
admin0 | i will use the python client on debug mode to test | 13:13 |
admin0 | what actually happens | 13:13 |
mattt | admin0: you are hitting external IP righ t? | 13:13 |
mattt | *right | 13:13 |
admin0 | yes | 13:13 |
admin0 | which is 1:1 nat to the internal one | 13:13 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Update ansible to the latest release (v1.9.5-1) https://review.openstack.org/296839 | 13:14 |
mattt | admin0: can you gist the following? cat /etc/haproxy/conf.d/keystone_* | 13:14 |
mattt | admin0: also one thing i did differently is omit haproxy_user_ssl_cert, haproxy_user_ssl_key, haproxy_user_ssl_ca_cert variables, i just let it auto-generate | 13:15 |
bsv | admin0: did you test instance<->instance (same host) performance the other week? | 13:15 |
admin0 | mattt: https://gist.github.com/a1git/105240417a91efdba196 | 13:15 |
odyssey4me | mattt can you give a final vote on https://review.openstack.org/297465 ? | 13:15 |
*** retreved has joined #openstack-ansible | 13:16 | |
*** markvoelker has joined #openstack-ansible | 13:18 | |
mattt | odyssey4me: sure | 13:18 |
mattt | odyssey4me: shouldn't we leave that at master and then override in osa ? | 13:19 |
mattt | odyssey4me: https://review.openstack.org/#/c/297465/2/defaults/main.yml | 13:19 |
odyssey4me | mattt it's been done like this in the other roles - I figured that we should do this in order to finalise prep for the release | 13:21 |
*** ametts has joined #openstack-ansible | 13:22 | |
*** markvoelker has quit IRC | 13:22 | |
*** markvoelker has joined #openstack-ansible | 13:23 | |
mattt | odyssey4me: k | 13:24 |
automagically | Morning all | 13:26 |
automagically | odyssey4me: Can you advise how I might move forward in moving this repo under the umbrella of OSA? https://github.com/trumant/openstack-ansible-os_rally | 13:27 |
*** markvoelker_ has joined #openstack-ansible | 13:28 | |
*** jthorne has joined #openstack-ansible | 13:30 | |
*** b3rnard0_away is now known as b3rnard0 | 13:30 | |
odyssey4me | automagically I just need to submit a patch to project config for it to be imported | 13:30 |
automagically | Ah cool | 13:31 |
automagically | thx | 13:31 |
odyssey4me | are you happy for it to be imported as it is today? | 13:31 |
automagically | Yes, its passing functional tests, and I’d like to get Gerrit reviews on further enhancements | 13:31 |
*** markvoelker has quit IRC | 13:32 | |
*** pjm6 has joined #openstack-ansible | 13:36 | |
*** michaelgugino has joined #openstack-ansible | 13:42 | |
*** mgoddard_ has joined #openstack-ansible | 13:44 | |
openstackgerrit | Merged openstack/openstack-ansible-os_nova: Switch defaults/tests to use stable/mitaka branch https://review.openstack.org/297465 | 13:45 |
*** mgoddard has quit IRC | 13:47 | |
*** asettle has quit IRC | 13:49 | |
*** neilus has quit IRC | 13:53 | |
*** neilus has joined #openstack-ansible | 13:53 | |
*** asettle has joined #openstack-ansible | 13:55 | |
*** Brew has joined #openstack-ansible | 13:56 | |
cloudnull | morning | 13:56 |
odyssey4me | automagically FYI https://review.openstack.org/298754 | 13:56 |
automagically | cloudnull: Morning. Enjoyed reading your aodh clarification in reply to the Kolla topic in openstack-dev :) | 13:57 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:57 | |
cloudnull | you know me, making friends, influencing people. | 13:57 |
automagically | Awesome! Thanks odyssey4me | 13:58 |
*** asettle has quit IRC | 14:00 | |
admin0 | morning | 14:00 |
automagically | o/ admin0 | 14:00 |
cloudnull | it makes me frustrated when fallacies are stated as fact. especially when you can do something as simple as "https://github.com/openstack?utf8=%E2%9C%93&query=aodh" and see that both OSA and puppet support aodh. | 14:00 |
automagically | Yeah, I facepalmed a bit when I read that | 14:00 |
cloudnull | but thats likely something related to my broken brain... | 14:00 |
admin0 | cloudnull: a lot of fallacies on the docs are stated as facts :D | 14:00 |
cloudnull | we should fix that :) | 14:01 |
cloudnull | any who, hows it today ? | 14:01 |
pjm6 | hi cloudnull | 14:01 |
cloudnull | o/ pjm6 | 14:02 |
*** busterswt has joined #openstack-ansible | 14:02 | |
mattt | admin0: you should fix those then! | 14:03 |
admin0 | i will :D | 14:03 |
admin0 | plan to start with ceph | 14:03 |
mattt | we can't make openstack-ansible great by just bitching about stuff :) | 14:03 |
*** tiagogomes has quit IRC | 14:03 | |
logan- | hows your ceph stuff going admin0 | 14:03 |
admin0 | this is why i am doing all the tests in real 2 environments and blogging | 14:03 |
admin0 | logan-: it works :) | 14:03 |
mattt | admin0: if you need help getting going w/ putting in a change let me know, more than happy to walk you through it | 14:04 |
admin0 | logan-: with examples: https://www.openstackfaq.com/openstack-ansible-ceph/ | 14:04 |
logan- | very nice | 14:04 |
automagically | admin0: Good stuff there! | 14:04 |
admin0 | so ceph page, i will contribute to the documentation | 14:05 |
admin0 | found out that SSL does not work :) | 14:05 |
jduhamel_ | you can always make stuff great by bitching no? | 14:05 |
pjm6 | I'm having problems in installing pip packages in galera client, it is adviced to enter in the galeara_container and install it manually? or at least see why it is failing ? | 14:05 |
admin0 | do it manually :) | 14:05 |
mattt | jduhamel_: why does that nick sound familiar | 14:06 |
logan- | hey admin0, it doesn't matter for liberty but for mitaka you will want client.cinder to have rwx to the images pool so it can do ceph-native snapshotting of instances | 14:06 |
admin0 | pjm6: do it manually, move on, do not get stuck on small things like broken pip packages :) | 14:06 |
admin0 | :D | 14:06 |
jduhamel_ | hmm, Sat in castle working with MikeA for a bit. maybe that's why? | 14:06 |
mattt | jduhamel_: yeah that'd be it | 14:06 |
mattt | jduhamel_: good to see you're 'back' :) | 14:06 |
jduhamel_ | :) Deploying a OS config at a client now. Really like the "ansible" way of doing it. | 14:07 |
admin0 | logan-: i will update the docs after checking | 14:07 |
mattt | on liberty, is there something i need to flip when using SSL w/ haproxy & keystone to get keystone to return https in response? | 14:07 |
mattt | tested on mitaka and i cannot replicate what admin0 is seeing | 14:07 |
admin0 | this is what I have for SSL: https://gist.github.com/anonymous/9cce635852720cf3e670 | 14:08 |
logan- | mattt: I think that is one of the things https://review.openstack.org/#/c/277199/ aims to address | 14:08 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder: Update tests to work w/ secure_path update https://review.openstack.org/297071 | 14:08 |
logan- | if you're talking about the links when you load the keystone api endpoint | 14:08 |
logan- | ie curl https://whatever:5000 giving you http:// links in the response | 14:08 |
mattt | logan-: that is it | 14:09 |
admin0 | yes | 14:09 |
logan- | i have a bp of that patch to liberty and it is working well. ill pastebin it in a min | 14:09 |
automagically | Yep, specifically this: https://review.openstack.org/#/c/277199/17/tests/roles/bootstrap-host/templates/user_variables.aio.yml.j2 | 14:09 |
cloudnull | hi all, question, I smashed together this script to rewire containers in the case where the container is running but has a missing or broken veth pair -- typically happens if someone ifup/ifdown 's a bridge. | 14:10 |
cloudnull | https://gist.github.com/cloudnull/d9c9a85bdfeccbbe5b93 | 14:10 |
cloudnull | is that something useful to have in osa ? | 14:10 |
mattt | automagically: yeah on master when i keystone_service_publicuri_proto: "https" i see https in the response, but i'm testing on mitaka if that makes any diff | 14:10 |
admin0 | logan-: i will re-run haproxy and os-keystone with the variables shown there | 14:11 |
openstackgerrit | Michael Gugino proposed openstack/openstack-ansible-os_neutron: [WIP] Implementing neutron_openvswitch_agent https://review.openstack.org/298765 | 14:11 |
admin0 | and see if it works | 14:11 |
cloudnull | I've used it w/ an adhoc command to ensure everthing is well in an env with the script module. ansible hosts -m script $PATH | 14:11 |
automagically | cloudnull: Definitely find that to be a useful ops/deployer addition | 14:11 |
cloudnull | i would too, im just not sure where to put it . | 14:12 |
michaelgugino | I threw https://review.openstack.org/298765 up for discussion | 14:12 |
automagically | Woot michaelgugino! | 14:12 |
cloudnull | woot! michaelgugino | 14:12 |
michaelgugino | pretty much the same commit I had in the etherpad, but with a nicer commit message. Not sure which direction it needs to go, so I'm looking for input. | 14:12 |
admin0 | no need for keystone_secure_proxy_ssl_header: X-Forwarded-For or haproxy_ssl: true or keystone_ssl: true ??? | 14:13 |
logan- | haproxy_ssl | 14:13 |
mattt | my understanding is that haproxy_ssl and keystone_ssl are mutually exclusive | 14:13 |
mattt | but today is the first time i've looked at ssl in openstack-ansible | 14:14 |
automagically | mattt: Correct, they are | 14:14 |
logan- | the idea of that patch is none of the services besides haproxy need to speak ssl. all of the internal traffic is http | 14:14 |
admin0 | yes | 14:14 |
pjm6 | thanks admin0, i was asking if there was no problem, I prefer doing manually :) | 14:14 |
*** woodard has quit IRC | 14:14 | |
admin0 | pjm6: “i have lost context already” :D | 14:14 |
cloudnull | admin0 mattt: they should be mutually exclusive. I use keystone_secure_proxy_ssl_header: X-Forwarded-For when terminating ssl at the LB | 14:15 |
pjm6 | admin0: about the broken pip packages | 14:15 |
admin0 | oh | 14:15 |
admin0 | :D | 14:15 |
*** woodard has joined #openstack-ansible | 14:15 | |
admin0 | logan-: that patch covers all services or just keystone ? | 14:15 |
*** markvoelker_ has quit IRC | 14:15 | |
admin0 | or every PUBLIC endpoint will be behind ssl with that ? | 14:15 |
logan- | using that you could put any endpoint going thru the LB behind ssl | 14:16 |
logan- | http://cdn.pasteraw.com/nwbb5daa29u5c651i4bdr7bn4d7ks70 bp to liberty | 14:16 |
admin0 | http://cdn.pasteraw.com/nwbb5daa29u5c651i4bdr7bn4d7ks70 — looks cryptic to me :D | 14:17 |
admin0 | can someone merge this so that i can pull and not worry about *manually* fixing it | 14:18 |
lbragstad | cloudnull o/ | 14:18 |
cloudnull | ohai lbragstad | 14:18 |
*** tiagogomes has joined #openstack-ansible | 14:18 | |
lbragstad | cloudnull quick question on the pip-install bits of osa | 14:18 |
cloudnull | sure | 14:19 |
admin0 | but yes, this needs to go in liberty .. because no one will put production on mitaka or latest .. they all want to go wtih proven .. so install liberty, and then wait 1-2 months after mitaka, hear horror stories and then upgrade to mitaka | 14:19 |
cloudnull | ^ truth :) | 14:19 |
lbragstad | cloudnull is there anything that wouldn't allow https://github.com/openstack/openstack-ansible-pip_install/blob/master/tasks/main.yml#L41 to run (it's being skipped but I'm not sure how I'm setting anything that would allow that?) | 14:19 |
logan- | well first we have to get it merged in master :P | 14:19 |
mattt | lbragstad: get_url is funky | 14:20 |
automagically | Not as funky/buggy as uri | 14:20 |
mattt | lbragstad: obviously if hte file exists it won't re-attempt it | 14:20 |
mattt | hehe | 14:20 |
mattt | true automagically | 14:20 |
*** spotz_zzz is now known as spotz | 14:20 | |
cloudnull | lbragstad: using --skip-tags? | 14:21 |
lbragstad | mattt let me check the system I ran this against and see if it's there | 14:21 |
mattt | lbragstad: actually force: yes is set on that task, so it should do it each time | 14:21 |
cloudnull | also what mattt said | 14:21 |
admin0 | so when will https://review.openstack.org/#/c/277199/ be merged ? | 14:21 |
lbragstad | mattt my /opt/ directory does exist but it contain hardware things I think | 14:21 |
lbragstad | (ie. dell/ lsi/ etc..) | 14:21 |
lbragstad | would that be interfering? | 14:22 |
mattt | shouldn't | 14:22 |
mattt | try -vvvv when you run ansible-playbook | 14:22 |
lbragstad | mattt ok | 14:22 |
mattt | see if it shows anything of value when it hits that task | 14:22 |
mattt | it could be failing but the task ignores errors | 14:22 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: zaqar.conf.j2 should use the role's debug var https://review.openstack.org/298772 | 14:22 |
lbragstad | I'm only running with --tags pip-install | 14:22 |
cloudnull | admin0: i hope to work on that a bit today | 14:23 |
lbragstad | and that passes - but when I run the whole play book the Install pip requires step in os_keystone fails | 14:23 |
cloudnull | i have some followup to do after odyssey4me 's last review | 14:23 |
lbragstad | (because pip isn't there) | 14:23 |
lbragstad | mattt good point - rerunning the whole playbook with -vvvv | 14:24 |
*** Mudpuppy has joined #openstack-ansible | 14:24 | |
admin0 | lbragstad: add “ | tee playbook.log” as well | 14:25 |
admin0 | so that you can git/gist/see it easily / compare later | 14:25 |
lbragstad | admin0 ++ | 14:25 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: Removing unused verbose var https://review.openstack.org/298773 | 14:26 |
*** sdake has joined #openstack-ansible | 14:27 | |
lbragstad | mattt it doesn't look like there is any verbose output on skipped tasks. | 14:28 |
lbragstad | and it seems the pip install tasks are skipped right out of the gate | 14:29 |
*** sdake_ has joined #openstack-ansible | 14:30 | |
admin0 | lbragstad: if you are starting agagin, you can destroy the continers and have it rebuild again | 14:31 |
lbragstad | admin0 i'm deploying to metal | 14:31 |
admin0 | everything to metal ? | 14:31 |
*** sdake has quit IRC | 14:32 | |
lbragstad | admin0 I'm only deploying the os_keystone role to metal | 14:32 |
logan- | hey, admin0, updated that liberty patch since it had a merge conflict with liberty head. http://cdn.pasteraw.com/grh1r55gmupeueu0mqv82bait1zhb1x .. you could apply it to a clean liberty clone for testing like: curl http://cdn.pasteraw.com/grh1r55gmupeueu0mqv82bait1zhb1x | git am | 14:33 |
admin0 | i can :D ? | 14:33 |
admin0 | \o/ | 14:33 |
admin0 | will do that right away | 14:33 |
admin0 | showed: Applying: Enable SSL termination for all services :D | 14:34 |
*** gaudenz has joined #openstack-ansible | 14:34 | |
spotz | a little late cloudnull but do we have a directory for useful scripts? If so it could go there and if not maybe we need one? | 14:34 |
cloudnull | we have the general scripts dir | 14:34 |
cloudnull | but i think if it went there it'd just be lost | 14:35 |
cloudnull | we likely need a place for ops tools and such | 14:35 |
admin0 | logan-: i need to start again from setup-host, setup-infra or jump directly to setup-openstack ? | 14:35 |
admin0 | since its not host or intfra, i guess just run the last playbook ? | 14:35 |
spotz | Yeah even calling it ops-tools or ops-scripts:) | 14:35 |
cloudnull | Maybe we need a spec | 14:37 |
*** sdake_ is now known as sdake | 14:37 | |
palendae | spotz: Besides the scripts directory? | 14:39 |
spotz | palendae Well if cloudnull feels it will get lost and it's not really an ansible related one why not? | 14:39 |
palendae | Ah, missed his comments | 14:40 |
logan- | you will need to redeploy haproxy with haproxy_ssl and re-run all of the openstack plays to get endpoints setup with https://. something like http://cdn.pasteraw.com/ef7cseygw5arv4hqmsxk6m5evmv0dfb I guess | 14:40 |
odyssey4me | cloudnull why not just add a note and link to your script in http://docs.openstack.org/developer/openstack-ansible/install-guide/app-tips.html | 14:41 |
mattt | lbragstad: you're not running as a non-user or someone without access to /opt right ? | 14:41 |
mattt | s/non-user/non-root user/ | 14:41 |
mattt | that wouldn't result in a skip tho, you'd get a failure there | 14:41 |
cloudnull | odyssey4me: i thought about that, which i can do. was just curious what the general consensus was | 14:43 |
lbragstad | mattt right - i'm running with a user that has sudo access | 14:43 |
*** jorge_munoz has joined #openstack-ansible | 14:45 | |
*** toddnni has quit IRC | 14:46 | |
*** cloudtrainme has joined #openstack-ansible | 14:48 | |
admin0 | logan-: i am running the playbooks after applying your patch .. | 14:49 |
*** tiagogomes has quit IRC | 14:50 | |
mattt | lbragstad: that's odd, i really have no idea | 14:51 |
*** mgoddard_ has quit IRC | 14:52 | |
*** mgoddard has joined #openstack-ansible | 14:53 | |
lbragstad | mattt very - the step to install required pip packages fail because it can't find the pip executable but only because the "Install Pip" step is skipped. I'll keep digging | 14:55 |
mattt | lbragstad: are you sure something isn't failing ahead in the chain that is causing it to be skipped ? | 14:56 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: Removing unneeded with_items usage https://review.openstack.org/298797 | 14:56 |
lbragstad | mattt checking that now | 14:56 |
lbragstad | mattt after the playbook gathers facts, it pins the apt preferences, creates a pip config directory, drop pip files, and then installs modern pip (which skips) | 14:58 |
lbragstad | all of which are successful | 14:58 |
*** cloudtrainme has quit IRC | 14:59 | |
sdake | odyssey4me arounrd re governance changes | 15:00 |
*** cloudtrainme has joined #openstack-ansible | 15:01 | |
odyssey4me | sdake what's up? | 15:01 |
sdake | odyssey4me can you review https://review.openstack.org/#/c/295528/ at your convience | 15:01 |
*** tiagogomes has joined #openstack-ansible | 15:02 | |
sdake | what i'm after is a non-onerous way to distinguish between projects like osa, tripleo, fuel,kolla vs things like deb/rpm/dib-elements | 15:02 |
sdake | the reason is becuase other tags depend on type tags in their wording | 15:02 |
busterswt | cloudnull i opened this to document the openstack client issue: https://bugs.launchpad.net/openstack-ansible/+bug/1563377 | 15:03 |
openstack | Launchpad bug 1563377 in openstack-ansible "Issues with upgrade due to older openstackclient in Keystone container" [Undecided,New] | 15:03 |
admin0 | logan-: ssl failed for horizon, so horizon not accessible anymore .. that is the setting I have: https://gist.github.com/a1git/0b1930acc3239a5e49f6 after your patch | 15:04 |
odyssey4me | sdake I'll give it another review tomorrow morning with a fresh mind | 15:04 |
logan- | take out the keystone and horizon user_ssl settings for sure. | 15:04 |
logan- | are you settign haproxy_ssl: true in the haproxy config stuff anywhere? | 15:05 |
sdake | odyssey4me are ou in tehe uk? | 15:05 |
admin0 | i have the default liberty checkout with your patch applied | 15:05 |
admin0 | no manual settings | 15:05 |
sdake | odyssey4me ok souns good thanks ;) | 15:05 |
odyssey4me | sdake yes, I work from the UK | 15:05 |
sdake | ya my brain just caught up with yourstatment - 8am caffieine-free diet ftl | 15:06 |
*** openstackgerrit has quit IRC | 15:06 | |
admin0 | taking out keystone and horizon and trying again | 15:07 |
*** openstackgerrit has joined #openstack-ansible | 15:07 | |
logan- | gotcha. I think the review adds the ability but does not default the endpoints to ssl enabled. so for something like keystone you would want to set https://github.com/openstack/openstack-ansible/blob/liberty/playbooks/vars/configs/haproxy_config.yml#L88 haproxy_ssl: true in there | 15:07 |
admin0 | the only thing that stayed are the haproxy ssl and rabbitmq ssl | 15:07 |
logan- | for public endpoints only most of those other services listen on *. so you would rewrite how your haproxy endpoints look by binding separate public/internal endpoints with haproxy_ssl: true on the public ones | 15:08 |
*** gparaskevas has quit IRC | 15:08 | |
logan- | the patch adds the ability for the configuration to be flexible like this, but it adds a lot of config work on your part :) | 15:09 |
admin0 | logan-: i think everyone will wish that all public endpints need to be in ssl .. so with that wish in mind .. and your patch applied, what further needs to be done :D ? | 15:09 |
admin0 | in a gist somewhere :D | 15:10 |
admin0 | another is the html5proxy_base_url for console .. can that also be in ssl ? | 15:12 |
*** toddnni has joined #openstack-ansible | 15:14 | |
admin0 | rerunning the playbooks with the keystone/horizon ssl removed | 15:14 |
logan- | https://gist.github.com/Logan2211/98b3682582f557a12755 example of how i am doing ssl on public endpoints only | 15:15 |
*** michaelgugino has quit IRC | 15:15 | |
admin0 | so your patch + this file + the variables you posted = all ssl on public endpoints :D ? | 15:16 |
logan- | hopefully? :) | 15:17 |
*** woodard has quit IRC | 15:23 | |
*** shausy has quit IRC | 15:28 | |
*** weezS has joined #openstack-ansible | 15:31 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Enable SSL termination for all services https://review.openstack.org/277199 | 15:34 |
*** saneax is now known as saneax_AFK | 15:36 | |
admin0 | logan-: failed on horizon | 15:42 |
admin0 | checking endpoints and via cli | 15:42 |
admin0 | logan, the patch/thing did not changed the openrc on the service container .. changed the URL manually to https:// | 15:45 |
admin0 | checking others | 15:45 |
*** ikp has joined #openstack-ansible | 15:45 | |
logan- | utility container uses internal endpoints I think? | 15:46 |
admin0 | hmm.. none working like neutron or glance | 15:46 |
admin0 | brb | 15:50 |
*** admin0 has quit IRC | 15:51 | |
odyssey4me | jmccrory automagically cloudnull d34dh0r53 stevelle mattt hughsaunders andymccr can we get some eyes on https://review.openstack.org/296594 please? | 15:54 |
*** woodard has joined #openstack-ansible | 15:54 | |
*** ametts has quit IRC | 15:59 | |
*** michaelgugino has joined #openstack-ansible | 16:00 | |
*** jmccrory_ has joined #openstack-ansible | 16:01 | |
*** neilus has quit IRC | 16:03 | |
odyssey4me | bug triage cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, severion, bgmccollum | 16:04 |
spotz | o/ | 16:04 |
cloudnull | o/ | 16:04 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bugs?search=Search&field.status=New | 16:04 |
michaelgugino | here | 16:05 |
serverascode | o/ | 16:05 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bug/1560993 | 16:05 |
openstack | Launchpad bug 1560993 in openstack-ansible "keystone_service returns ignore_other_regions error in liberty" [Undecided,New] | 16:05 |
odyssey4me | this doesn't appear to be related to anything in OSA | 16:06 |
*** woodard has quit IRC | 16:06 | |
odyssey4me | does it? | 16:06 |
*** woodard_ has joined #openstack-ansible | 16:06 | |
izaakk | o/ | 16:07 |
cloudnull | odyssey4me: im going to say no | 16:07 |
cloudnull | it looks like someone using ansible | 16:08 |
cloudnull | but not OSA | 16:08 |
michaelgugino | +1 | 16:08 |
odyssey4me | ok done - next https://bugs.launchpad.net/openstack-ansible/+bug/1562031 | 16:08 |
openstack | Launchpad bug 1562031 in openstack-ansible "gate-openstack-ansible-dsvm-commit CI failed with keystone command" [Undecided,New] | 16:08 |
*** jthorne has quit IRC | 16:08 | |
michaelgugino | close won't fix they can reopen if they have a specific bug they want to file against OSA if they are indeed using it. | 16:08 |
*** jthorne has joined #openstack-ansible | 16:09 | |
odyssey4me | ah, this is already solved | 16:09 |
cloudnull | yes solved with updated sha | 16:09 |
mattt | o/ btw | 16:10 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bug/1562595 | 16:10 |
openstack | Launchpad bug 1562595 in openstack-ansible "Add Open vSwitch support" [Undecided,New] | 16:10 |
openstackgerrit | Hieu LE proposed openstack/openstack-ansible: Add project scoped token when obtaning token https://review.openstack.org/297563 | 16:10 |
odyssey4me | michaelgugino I see that you posted https://review.openstack.org/298765 which relates to the bug. serverascode did you see that review? | 16:11 |
serverascode | yeah I did | 16:11 |
mattt | yeah i thought this was already WIP | 16:11 |
serverascode | yeah sorry I was just trying to follow the documentation, no idea if that was the right process, so feel free to close | 16:12 |
serverascode | wasn't sure if a blueprint was needed or something | 16:12 |
odyssey4me | thanks for doing it serverascode :) we'll keep it as a wishlist bug - at this point I'm not entirely sure how big this body of work will be | 16:13 |
michaelgugino | Yes, I'm working on it. It's WIP, looking for input. I don't think we have a blueprint made | 16:13 |
odyssey4me | I haven't yet taken a look at the review | 16:13 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_designate: Remove redundant rootwrap directory creation https://review.openstack.org/298853 | 16:14 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_neutron: Remove iptables checksum rule script https://review.openstack.org/293067 | 16:14 |
cloudnull | michaelgugino serverascode I've made a comment on the installation bits (i'm not sure how best to handle installing OVS) however what you have up so far looks like a good start. | 16:15 |
michaelgugino | great | 16:15 |
openstackgerrit | Merged openstack/openstack-ansible-os_glance: Updated role using Multi-Distro framework https://review.openstack.org/297320 | 16:16 |
*** jthorne has quit IRC | 16:16 | |
odyssey4me | sorry - got sidetracked into the review - back to bug triage :) | 16:16 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bug/1563024 | 16:17 |
openstack | Launchpad bug 1563024 in openstack-ansible "Upgrade process fails to upgrade RabbitMQ" [Undecided,New] | 16:17 |
*** jthorne has joined #openstack-ansible | 16:17 | |
*** ikp has quit IRC | 16:17 | |
odyssey4me | seems legit - palendae / d34dh0r53 want to pick that one up? | 16:18 |
palendae | odyssey4me: I'll look at it, but this is the first we've seen it. | 16:19 |
cloudnull | ++ thats legit -- denton and I were working on that the other day. | 16:19 |
palendae | cloudnull: Hm, ok | 16:19 |
cloudnull | palendae: seems its something that happens on installs that are going from early kilo to liberty | 16:19 |
odyssey4me | yup | 16:20 |
palendae | Alright | 16:20 |
cloudnull | to fix we just needed to add -e 'rabbitmq_upgrade=true' | 16:20 |
palendae | Yeah | 16:20 |
palendae | I had it in and removed it during reviews | 16:20 |
palendae | I'll add it back | 16:20 |
odyssey4me | palendae can you self assign? | 16:20 |
palendae | Sure | 16:20 |
odyssey4me | https://bugs.launchpad.net/openstack-ansible/+bug/1563377 | 16:21 |
openstack | Launchpad bug 1563377 in openstack-ansible "Issues with upgrade due to older openstackclient in Keystone container" [Undecided,New] | 16:21 |
odyssey4me | hmm, it would seem that the pip option to force a reinstall, or force an upgrade should also happen during a major upgrade | 16:22 |
*** jthorne has quit IRC | 16:22 | |
odyssey4me | this is specifically stuff not installed into venvs | 16:22 |
cloudnull | ++ | 16:23 |
stevelle | legit | 16:24 |
cloudnull | this can also happen on kilo > liberty upgrade. folks may be used to using the global client and not working from the venv | 16:24 |
*** eil397 has joined #openstack-ansible | 16:24 | |
palendae | Ok | 16:24 |
cloudnull | and the older global client may be busted or incompatible with the newer services in some way | 16:24 |
palendae | Again, was asked to remove that during reviews | 16:24 |
odyssey4me | well, this does make me wonder what happens in minor upgrades | 16:25 |
*** cloudtrainme has quit IRC | 16:25 | |
odyssey4me | perhaps we should actually be setting these tasks to always install the 'latest' ? | 16:25 |
stevelle | so long as it respects upper limits | 16:26 |
stevelle | that might work | 16:26 |
cloudnull | odyssey4me: on minor upgrades we replace the venv | 16:26 |
cloudnull | 12.0.8 goes to 12.0.9 | 16:26 |
odyssey4me | cloudnull except that this is specific to non-venv installs | 16:27 |
cloudnull | so long as you work out the venv all is well. | 16:27 |
palendae | To clarify - you're talking about this line https://github.com/openstack/openstack-ansible/blob/liberty/scripts/run-upgrade.sh#L74 right? | 16:27 |
odyssey4me | in the utility container we install all the clients without a venv | 16:27 |
palendae | That's the one difference between the script and the manual steps | 16:27 |
*** jthorne has joined #openstack-ansible | 16:27 | |
busterswt | cloudnull Quick Q: How do I find the defaults to vars in jinja templates? | 16:28 |
cloudnull | odyssey4me: the tough part is, dealing with packages w/ that were date ver going to symver | 16:28 |
odyssey4me | busterswt each role has a defaults/main.yml with all of those | 16:28 |
cloudnull | i think a better fix would be to delegate that task to the utility container or something. | 16:28 |
busterswt | ah hah | 16:29 |
odyssey4me | cloudnull I think we may be talking about different things, but similar intents. | 16:29 |
openstackgerrit | Merged openstack/openstack-ansible: added pip.conf removal task for the repo_servers https://review.openstack.org/294765 | 16:30 |
stevelle | cloudnull: that would then require the utility container and possibly expose other problems | 16:30 |
cloudnull | in test the role could delegate to itself | 16:30 |
cloudnull | as a default | 16:31 |
cloudnull | it would potentially expose other problems but would limit issues caused by left over cruft | 16:31 |
stevelle | seems more complex than really necessary | 16:31 |
cloudnull | that may be true | 16:32 |
stevelle | emphasis on seems | 16:32 |
* cloudnull spitballing | 16:32 | |
* kysse tarballing | 16:32 | |
odyssey4me | so forcing a reinstall for a major upgrade is the simplest way to deal with the semver issue, whereas using 'latest' in the task is the simplest way of handling upgrades within a release | 16:32 |
stevelle | why not force a reinstall with upgrades within a release? | 16:33 |
cloudnull | odyssey4me: thats a good point. | 16:33 |
cloudnull | http://docs.openstack.org/developer/openstack-ansible/kilo/upgrade-guide/process.html#running-the-upgrade-by-hand | 16:33 |
palendae | Note: the script forces reinstall | 16:33 |
cloudnull | ^ in the kilo upgrade we noted that | 16:33 |
jmccrory | would that upgrade packages left behind from kilo outside of a venv? | 16:33 |
palendae | Manual doesn't | 16:33 |
palendae | So the manual steps would need to be updated | 16:34 |
odyssey4me | why bother forcing reinstall within a release? | 16:34 |
* palendae yells into the void | 16:34 | |
odyssey4me | palendae cool - easy to fix then :) | 16:34 |
cloudnull | so maybe we simply add that note back in the manual steps ? | 16:34 |
stevelle | odyssey4me: simpler, always do the same thing the same way to always get the same outcome | 16:34 |
*** elopez has joined #openstack-ansible | 16:34 | |
palendae | use the script is evidently not an accepted answer, but can re-add to the manual steps | 16:34 |
cloudnull | jmccrory: only the items installed on the root disk as provided by the role would be upgraded. | 16:35 |
palendae | https://github.com/openstack/openstack-ansible/blob/liberty/scripts/run-upgrade.sh#L74 | 16:35 |
odyssey4me | stevelle consistency is good | 16:35 |
cloudnull | well those items and their dependencies | 16:35 |
* stevelle is just finding the boundary of reason, not really advocating | 16:36 | |
cloudnull | jmccrory: in liberty that should be something like so https://github.com/openstack/openstack-ansible/blob/liberty/playbooks/roles/os_keystone/defaults/main.yml#L357-L361 | 16:36 |
*** raddaoui has quit IRC | 16:36 | |
odyssey4me | stevelle yeah, let's put it this way - having the task always install the latest will ensure that the desired result is achieved, adding the force-reinstall option to the minor upgrade docs achieves nothing in particular other than re-enforcing a habit, which I support | 16:37 |
cloudnull | I'd be keen on doing both. install the latest and doc the upgrade step. | 16:38 |
*** Guest68910 is now known as mgagne | 16:38 | |
stevelle | I think my actual position is to support your statement before, only force on major and latest within a release. We automate the thing that we are there to automate and which can be automated. | 16:38 |
*** mgagne has quit IRC | 16:38 | |
*** mgagne has joined #openstack-ansible | 16:38 | |
*** elopez has quit IRC | 16:39 | |
*** michaelgugino_ has joined #openstack-ansible | 16:39 | |
odyssey4me | I am happy with that. Does anyone want to pick that task up to modify across the roles? | 16:39 |
cloudnull | in terms of that bug, within a greenfield liberty install the openstack client would not exist in the keystone container | 16:40 |
cloudnull | we only install python-keystoneclient so the ansible module can work | 16:40 |
*** cloudtrainme has joined #openstack-ansible | 16:40 | |
cloudnull | so even with this fix, its quite likely that the openstack client will remain busted which is in the root namespace . | 16:40 |
cloudnull | palendae: if you have that env around still, i'd be curious if you executed the same command for the openstack client out of the venv | 16:41 |
*** jthorne has quit IRC | 16:41 | |
cloudnull | and what the outcome is. | 16:41 |
palendae | cloudnull: ? | 16:41 |
*** michaelgugino has quit IRC | 16:42 | |
palendae | which env? | 16:42 |
cloudnull | sorry denton | 16:42 |
*** jthorne has joined #openstack-ansible | 16:42 | |
cloudnull | which was here and is no longer | 16:42 |
cloudnull | busterswt: ^ | 16:42 |
busterswt | hello hello | 16:42 |
cloudnull | odyssey4me: ill pick up that task | 16:43 |
busterswt | ok - so what do you want me to do? | 16:43 |
busterswt | :) | 16:43 |
odyssey4me | thanks cloudnull | 16:43 |
cloudnull | in that keystone container | 16:43 |
cloudnull | can you run ``openstack project list`` | 16:43 |
busterswt | sure. | 16:43 |
cloudnull | and then again do it from ``/openstack/venvs/os_keystone_$VERSION/bin/openstack project list | 16:43 |
busterswt | It returns projects. | 16:44 |
busterswt | ok one sec | 16:44 |
busterswt | returns projects in both cases | 16:45 |
cloudnull | ok | 16:46 |
busterswt | i had originally only executed the openstack client in the root space, not the venv | 16:46 |
spotz | So no bug needs clearer docs? | 16:46 |
busterswt | i don't know if i had tried the keystone client, to be honest. i can't remember | 16:46 |
cloudnull | odyssey4me: my suspicion is on a kilo>liberty upgrade the most root python packages we installed in kilo will be busted after the upgrade because we've abandoned most of them and transitioned everything into a venv | 16:47 |
jmccrory | thinking that too cloudnull | 16:47 |
odyssey4me | cloudnull ah, and why does that matter? | 16:47 |
palendae | cloudnull: Most likely. We decided not to try to clean them up | 16:47 |
palendae | Should probably make a clear note about that | 16:47 |
palendae | When you upgrade. switch to venv stuff | 16:47 |
cloudnull | that ^ | 16:47 |
cloudnull | odyssey4me: it doesnt matter, | 16:47 |
cloudnull | its not breaking the system | 16:48 |
stevelle | want to maybe revisit the decision to not clean up? | 16:48 |
*** pcaruana has quit IRC | 16:48 | |
cloudnull | but it may confuse folks | 16:48 |
odyssey4me | we're only implementing things we care about, and those will work - yeah, we should probably just have a doc note | 16:48 |
stevelle | +1 | 16:48 |
palendae | Seems like a matter of user expectations either way | 16:48 |
cloudnull | idk that we can or will want to clean everything up. | 16:48 |
palendae | It'll be perceived as broken whether it's present and errors, or is mysteriously gone | 16:48 |
odyssey4me | I don't think we should clean up. | 16:48 |
busterswt | to be clear, too... i waited at least 20 minutes while it hung there on that task | 16:49 |
cloudnull | if we do implement a clean up task I'd suggest we only do it for python-clients. | 16:49 |
busterswt | once i installed the latest client it breezed right through it | 16:49 |
stevelle | Could probably uninstall 20% to clear up 80% of user errors | 16:49 |
stevelle | starting with python-clients | 16:49 |
cloudnull | also idk that the clean up task needs to be in the rol | 16:49 |
palendae | stevelle: Even still, they're probably not going to know to look in the venvs | 16:49 |
cloudnull | *role | 16:49 |
odyssey4me | it can be a manual task | 16:49 |
cloudnull | ^ +1 | 16:49 |
odyssey4me | optional | 16:49 |
cloudnull | ++ | 16:50 |
stevelle | palendae: maybe you and I discussed that before? or was it sigmavirus24 | 16:50 |
palendae | stevelle: Probably; this has been a long running discussion | 16:50 |
palendae | I think, regardless of clean up, we have to make it more clear that venvs are now a thing | 16:50 |
palendae | Do we actually have docs that talk about how to use them/where they are? | 16:50 |
sigmavirus24 | stevelle: you and I discussed this | 16:51 |
stevelle | On that point, I brought up with someone maybe auto-activating the venv in the .bashrc file + MOTD or something | 16:51 |
palendae | Not venvs as a whole, but where openstack-ansible drops it | 16:51 |
*** raddaoui has joined #openstack-ansible | 16:51 | |
sigmavirus24 | stevelle: I had an alternative idea of having a local .bin that we symlink the executables to and add to the path for the user in the utility container | 16:51 |
cloudnull | IMO a clean up effort is really only to assist folks whom may have developed a lot of muscle mem. | 16:51 |
sigmavirus24 | which is a different set of tradeoffs | 16:51 |
cloudnull | i think a manual step is a good approach | 16:52 |
stevelle | ^ that seems to be the consensus still | 16:53 |
stevelle | we ready to move on? | 16:53 |
odyssey4me | well, there's nothing to move on to :) unless someone has a specific bug they wish to discuss? | 16:54 |
stevelle | sorry, looks like palendae's question about venv docs is not yet addressed. | 16:54 |
stevelle | looking | 16:54 |
odyssey4me | as far as I'm aware, we have no docs describing that venvs are used and where they're stored | 16:55 |
openstackgerrit | Merged openstack/openstack-ansible: Remove the repo clone mirror play https://review.openstack.org/295941 | 16:55 |
palendae | odyssey4me: I'm less concerned about describing what they are but rather telling users OSA switched to them | 16:55 |
palendae | And that their global packages are now gone/broken | 16:55 |
odyssey4me | ah, a release note :) | 16:55 |
busterswt | cloudnull verified that the openstack client works in the venv in the other keystone containers where i didn't update the client by hand in root | 16:55 |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Upgrade RabbitMQ on OSA upgrade https://review.openstack.org/298872 | 16:56 |
*** ametts has joined #openstack-ansible | 16:57 | |
cloudnull | busterswt: and its busted in the root ? | 16:57 |
stevelle | confirming, no venv mentions outside of extending osa and adding roles | 16:57 |
busterswt | yes | 16:57 |
*** javeriak has joined #openstack-ansible | 16:57 | |
cloudnull | ok | 16:57 |
*** retreved has quit IRC | 16:57 | |
cloudnull | i'd suspect that will be the case for lots of things . | 16:58 |
odyssey4me | can we have a volunteer to add a release note to liberty indicating that venvs are now the default install method for services? | 16:58 |
stevelle | I'll take it | 16:59 |
busterswt | so hop onto host, hop into container, hop into venv to run the client? O_o | 16:59 |
*** mgagne_ has joined #openstack-ansible | 17:06 | |
*** spotz has quit IRC | 17:07 | |
*** bogeyon18 has quit IRC | 17:07 | |
*** meteorfox has quit IRC | 17:07 | |
*** jasondotstar has quit IRC | 17:07 | |
*** ametts has quit IRC | 17:07 | |
*** mgagne has quit IRC | 17:07 | |
*** neillc has quit IRC | 17:07 | |
*** darrenc has quit IRC | 17:07 | |
*** sigmavirus24 has quit IRC | 17:07 | |
*** eglute has quit IRC | 17:07 | |
*** gus has quit IRC | 17:07 | |
*** dweaver has quit IRC | 17:07 | |
*** cloudnull has quit IRC | 17:07 | |
*** palendae has quit IRC | 17:07 | |
*** jwagner has quit IRC | 17:07 | |
*** b3rnard0 has quit IRC | 17:07 | |
*** saneax_AFK has quit IRC | 17:07 | |
*** jamielennox has quit IRC | 17:07 | |
*** scarlisle has quit IRC | 17:07 | |
*** mcarden has quit IRC | 17:07 | |
*** phschwartz has quit IRC | 17:07 | |
*** mfisch has quit IRC | 17:07 | |
*** d34dh0r53 has quit IRC | 17:07 | |
*** b3rnard0 has joined #openstack-ansible | 17:07 | |
*** eglute has joined #openstack-ansible | 17:07 | |
*** spotz has joined #openstack-ansible | 17:07 | |
*** d34dh0r53 has joined #openstack-ansible | 17:07 | |
*** palendae_ has joined #openstack-ansible | 17:07 | |
*** neillc has joined #openstack-ansible | 17:07 | |
*** sdake_ has joined #openstack-ansible | 17:07 | |
stevelle | are we still wanting to ensure latest in the pip task as well? | 17:07 |
*** admin0 has joined #openstack-ansible | 17:07 | |
*** weezS has quit IRC | 17:07 | |
*** sdake has quit IRC | 17:07 | |
odyssey4me | thanks stevelle | 17:07 |
pjm6 | Sorry to cut conversation, but could I ask how can I debug the [ os_cinder | Ensure api is available]? the infra_host with haproxy returns me 503 service unavailable from port 8776 | 17:07 |
odyssey4me | stevelle I think that cloudnull is picking that one up? | 17:07 |
busterswt | so i had that same problem yesterday, and i found that SQL was maxxed out on connections | 17:07 |
odyssey4me | michaelgugino_ good work on https://review.openstack.org/298765 ! | 17:07 |
busterswt | pjm6 if you can get into mysql, try: SHOW STATUS WHERE `variable_name` = 'Threads_connected'; | 17:07 |
busterswt | pjm6 and compare to: show variables like "max_connections"; | 17:07 |
*** mcarden_ has joined #openstack-ansible | 17:07 | |
*** phschwartz_ has joined #openstack-ansible | 17:07 | |
*** jwagner- has joined #openstack-ansible | 17:07 | |
odyssey4me | pjm6 I would guess that if the cinder api isn't up, then there's likely to be a configuration issue with the cinder back-ends you've configured? | 17:07 |
admin0 | back :) long drive | 17:07 |
michaelgugino_ | thanks | 17:07 |
*** mfisch has joined #openstack-ansible | 17:07 | |
*** ametts_ has joined #openstack-ansible | 17:07 | |
*** scarlisle has joined #openstack-ansible | 17:07 | |
*** _sigmavirus24 has joined #openstack-ansible | 17:07 | |
*** dweaver has joined #openstack-ansible | 17:07 | |
*** mgagne_ has quit IRC | 17:07 | |
*** mgagne_ has joined #openstack-ansible | 17:07 | |
admin0 | so ssl :D ? | 17:08 |
*** mfisch is now known as Guest28049 | 17:08 | |
*** palendae_ is now known as palendae | 17:08 | |
*** cloudnull has joined #openstack-ansible | 17:08 | |
*** jasondotstar has joined #openstack-ansible | 17:08 | |
*** darrenc has joined #openstack-ansible | 17:08 | |
pjm6 | busterswt: will try that | 17:08 |
pjm6 | odyssey4me: I used default config for cinder | 17:09 |
*** gus has joined #openstack-ansible | 17:09 | |
*** bogeyon18 has joined #openstack-ansible | 17:10 | |
pjm6 | busterswt: it gives Threads_connected | 11 | 17:10 |
pjm6 | max_connections are 400 | 17:10 |
busterswt | can you do a 'cinder volume list' right now? | 17:11 |
busterswt | maybe volume-list | 17:11 |
pjm6 | sure, but before that (maybe I think what was my problem) | 17:11 |
pjm6 | i only list the ip of storage node | 17:11 |
pjm6 | and created the LVM as in the docs | 17:12 |
pjm6 | but i need to configure the cinder to use LVM, no? | 17:12 |
busterswt | i can't answer that, unfortunately. | 17:12 |
*** jamielennox has joined #openstack-ansible | 17:12 | |
admin0 | pjm6: if you give a storage host and the cinder-volume lvm is there, it just works | 17:12 |
*** toddnni_ has joined #openstack-ansible | 17:13 | |
*** toddnni has quit IRC | 17:13 | |
*** toddnni_ is now known as toddnni | 17:14 | |
pjm6 | busterswt: that command says that invalid | 17:14 |
pjm6 | but I did "cinder list" | 17:14 |
pjm6 | and gives | 17:14 |
*** _sigmavirus24 is now known as sigmavirus24 | 17:14 | |
*** sigmavirus24 has joined #openstack-ansible | 17:14 | |
pjm6 | ERROR: Service Unavailable (HTTP 503) | 17:14 |
busterswt | pjm6 sorry, cinder list | 17:14 |
pjm6 | busterswt: no problem :) | 17:14 |
pjm6 | admin0: I created the lvm volume | 17:15 |
pjm6 | as here http://docs.openstack.org/developer/openstack-ansible/install-guide/targethosts-prepare.html#configuring-lvm | 17:15 |
pjm6 | and added the IP of the storage node | 17:15 |
*** mgagne_ is now known as mgagne | 17:15 | |
admin0 | yes | 17:15 |
admin0 | vgscan shows it fine ? | 17:15 |
pjm6 | but I saw here that maybe I need to configure this http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-cinder.html#configuring-cinder-to-use-lvm ? | 17:15 |
busterswt | ok, so you may want to try cinder --debug list, to see if your error is keystone or cinder. Plus maybe make sure it's still running in the cinder containers. May want to check from the haproxy node top | 17:15 |
busterswt | *too | 17:15 |
admin0 | for lvm, just give storage IP .. do nothing else .. no other lines required | 17:16 |
admin0 | that is how i used it | 17:16 |
pjm6 | ok, so vgscan execute in the host of storage? | 17:16 |
pjm6 | busterswt: DEBUG:keystoneclient.session:RESP: [503] Connection: close Content-Type: text/html Cache-Control: no-cache gives this | 17:16 |
pjm6 | "No server is available to handle this request" | 17:17 |
*** saneax_AFK has joined #openstack-ansible | 17:17 | |
admin0 | pjm6: https://github.com/a1git/openstack-cloud/blob/master/openstack_deploy/openstack_user_config.yml — towards the end is c20 . my storage host using LVM | 17:17 |
*** saneax_AFK is now known as saneax | 17:17 | |
pjm6 | admin0: it gives me Found volume group "cinder-volumes" using metadata type lvm2 | Found volume group "openstack-node03-vg" using metadata type lvm2 | 17:17 |
admin0 | ok | 17:17 |
pjm6 | yes | 17:17 |
pjm6 | is what config that i used | 17:18 |
admin0 | so looks like your cinder api is not working .. login tot he container and check the logs | 17:18 |
pjm6 | I don't have container in that machine | 17:18 |
admin0 | not in that machine | 17:18 |
admin0 | in the other infra hosts | 17:18 |
pjm6 | ah ok | 17:18 |
pjm6 | is in /var/log? | 17:19 |
admin0 | ssh to infra hosts, do lxc-ls -f .. you will see something like c14_cinder_api_container-e5c97b53 | 17:19 |
admin0 | its /var/log/cinder/cinder-api.log | 17:19 |
*** shanec has joined #openstack-ansible | 17:19 | |
pjm6 | yeah there is no cinder container there | 17:20 |
admin0 | lxc-ls -f —see anything that says cinder ? | 17:20 |
pjm6 | only have heat and nova | 17:20 |
pjm6 | nop :| | 17:20 |
*** meteorfox has joined #openstack-ansible | 17:20 | |
admin0 | then your setup is incomplete :) | 17:20 |
admin0 | how does your user_config looks like ? | 17:21 |
pjm6 | openstack_user_config.yml | 17:22 |
pjm6 | right? | 17:22 |
admin0 | yep | 17:22 |
pjm6 | 1min | 17:22 |
pjm6 | http://pastebin.com/b9BuGUHu | 17:23 |
*** jwagner- is now known as jwagner | 17:28 | |
admin0 | looks identical to mine ( except i used the same hostname for the same ip ) .. | 17:29 |
*** michaelgugino_ has quit IRC | 17:29 | |
admin0 | how many containers are there on your infra host | 17:29 |
admin0 | and did you changed anything else ? | 17:29 |
admin0 | on playbooks or conf or env | 17:29 |
pjm6 | I have 19 containers | 17:30 |
pjm6 | no just the normal | 17:30 |
pjm6 | default | 17:30 |
admin0 | pastebin all the containers lxc-ls -f | 17:30 |
pjm6 | well in user_variables.yml | 17:31 |
pjm6 | I added swift | 17:31 |
pjm6 | as were in docs | 17:31 |
pjm6 | http://pastebin.com/rRzJdEas | 17:32 |
*** sdake has joined #openstack-ansible | 17:33 | |
admin0 | run os-cinder playbook and check what it says | 17:33 |
admin0 | maybe use -vvvv and save the logs | 17:33 |
*** sdake_ has quit IRC | 17:34 | |
admin0 | brb 5 mins | 17:35 |
pjm6 | ok ,tks :) | 17:35 |
*** eil397 has quit IRC | 17:37 | |
pjm6 | http://pastebin.com/g7nwDUN5 | 17:38 |
*** retreved has joined #openstack-ansible | 17:46 | |
*** retreved has quit IRC | 17:47 | |
*** retreved has joined #openstack-ansible | 17:47 | |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible-rabbitmq_server: [WIP] Multi-distro support for rabbitmq_server role https://review.openstack.org/286282 | 17:48 |
openstackgerrit | Merged openstack/openstack-ansible-os_zaqar: Removing unneeded with_items usage https://review.openstack.org/298797 | 17:53 |
*** javeriak has quit IRC | 17:54 | |
*** weezS has joined #openstack-ansible | 17:55 | |
*** sdake has quit IRC | 17:57 | |
*** KLevenstein has joined #openstack-ansible | 17:57 | |
*** asettle has joined #openstack-ansible | 18:00 | |
*** cloudtrainme has quit IRC | 18:02 | |
*** pcaruana has joined #openstack-ansible | 18:02 | |
*** sdake has joined #openstack-ansible | 18:02 | |
pjm6 | it seems that the init script is not creating | 18:05 |
*** sdake has quit IRC | 18:08 | |
*** sdake_ has joined #openstack-ansible | 18:08 | |
*** asettle has quit IRC | 18:10 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: Adding role convergence test https://review.openstack.org/298916 | 18:13 |
*** pjm6 has quit IRC | 18:16 | |
openstackgerrit | Merged openstack/openstack-ansible: Remove pip_get_pip_options override from group_vars https://review.openstack.org/296594 | 18:21 |
*** javeriak has joined #openstack-ansible | 18:23 | |
*** lykinsbd_ has joined #openstack-ansible | 18:25 | |
*** lykinsbd has quit IRC | 18:26 | |
*** jmccrory_ has quit IRC | 18:28 | |
*** jwitko has joined #openstack-ansible | 18:34 | |
mhayden | Apsu: https://review.openstack.org/#/c/285524/ oops | 18:38 |
Apsu | mhayden: omgherd | 18:40 |
*** eil397 has joined #openstack-ansible | 18:40 | |
*** cloudtrainme has joined #openstack-ansible | 18:41 | |
*** admin0 has quit IRC | 18:44 | |
*** phschwartz_ is now known as phschwartz | 18:51 | |
*** Guest28049 is now known as mfisch | 19:01 | |
*** sdake_ is now known as sdake | 19:01 | |
*** mfisch is now known as Guest82454 | 19:01 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Move inventory environment loading to function https://review.openstack.org/290740 | 19:02 |
*** Guest82454 has quit IRC | 19:02 | |
*** Guest82454 has joined #openstack-ansible | 19:02 | |
*** Guest82454 is now known as mfisch | 19:03 | |
*** eil397 has quit IRC | 19:03 | |
*** eil397 has joined #openstack-ansible | 19:05 | |
*** eil397 has quit IRC | 19:06 | |
*** eil397 has joined #openstack-ansible | 19:06 | |
*** krotscheck is now known as krotscheck_dcm | 19:07 | |
*** weezS has quit IRC | 19:20 | |
*** pjm6 has joined #openstack-ansible | 19:23 | |
*** dalees` has quit IRC | 19:25 | |
*** pjm6 has quit IRC | 19:28 | |
*** weezS has joined #openstack-ansible | 19:30 | |
*** dalees` has joined #openstack-ansible | 19:38 | |
*** alextricity has joined #openstack-ansible | 19:39 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Clarify skel_setup parameter documentation https://review.openstack.org/298953 | 19:40 |
*** myabiku has joined #openstack-ansible | 19:45 | |
*** pjm6 has joined #openstack-ansible | 19:52 | |
*** johnmilton has quit IRC | 19:53 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Removing unneeded is_metal param from user_defined_setup https://review.openstack.org/298957 | 19:54 |
*** sdake_ has joined #openstack-ansible | 19:55 | |
*** eil397 has quit IRC | 19:56 | |
*** sdake has quit IRC | 19:58 | |
*** sdake_ is now known as sdake | 20:02 | |
*** pjm9 has joined #openstack-ansible | 20:04 | |
*** myabiku has quit IRC | 20:04 | |
*** bbmbx has joined #openstack-ansible | 20:04 | |
*** bbmbx has joined #openstack-ansible | 20:04 | |
*** pjm6 has quit IRC | 20:07 | |
*** pjm9 has quit IRC | 20:07 | |
*** pjm6 has joined #openstack-ansible | 20:07 | |
pjm6 | Anyone had a problem where the init script of cinder (os_cinder) is not loaded properly | 20:11 |
pjm6 | http://pastebin.com/q8Nd5abi ? | 20:11 |
pjm6 | using the liberty git | 20:11 |
automagically | pjm6: Which tag? | 20:12 |
pjm6 | automagically, liberty | 20:12 |
pjm6 | I went to the host | 20:15 |
automagically | So, the cinder_api upstart conf is not being loaded? | 20:15 |
pjm6 | Yes, I think that is the problem | 20:15 |
pjm6 | because the file is there | 20:15 |
pjm6 | /etc/init/cinder-volume.conf | 20:16 |
pjm6 | I did "initctl reload-configuration | 20:16 |
pjm6 | " as in the playbook but nothin | 20:16 |
automagically | Right, but your log shows that cinder-api is what is going wrong, not cinder-volume | 20:17 |
stevelle | "No server is available to handle this request." that is HAProxy there | 20:18 |
pjm6 | true | 20:18 |
pjm6 | is only the cinder-api, cinder-scheduler and cinder-backup | 20:18 |
stevelle | you have cinder-volume on another host don't you or am I confusing your env with someone else? | 20:19 |
pjm6 | stevelle, but that error is not caused because the failure of the service not being found? | 20:19 |
pjm6 | I have in another host yes | 20:19 |
pjm6 | 1 node with compute and storage, 1 node for network and other for control (infra) | 20:19 |
stevelle | ok, HAProxy doesn't see cinder-api responding, that is where you need to start | 20:19 |
automagically | pjm6: Cinder components are typically split across the storage-infra_containers group and the storage_containers group | 20:19 |
automagically | the volume and backups should be on the host(s) you’ve put in the storage_hosts group | 20:20 |
pjm6 | stevelle, so the problem is with HAProxy? I discarded that because the other services were working (like the repo for instance) | 20:21 |
pjm6 | yes automagically | 20:21 |
automagically | The API would be in storage_infra | 20:21 |
pjm6 | they are | 20:21 |
pjm6 | I do a vgscan | 20:21 |
pjm6 | in the host where storage are | 20:21 |
pjm6 | and "Found volume group "cinder-volumes" using metadata type lvm2 | 20:21 |
pjm6 | " | 20:21 |
stevelle | pjm6: I suspect haproxy is fine, but you have to look downstream from there, automagically is pointing you at cinder-api and I agree | 20:21 |
automagically | Yep, specifically pointing out that you should be looking for cinder-api on a different host | 20:22 |
stevelle | that would be on the control (infra) hosts | 20:22 |
*** alextricity has quit IRC | 20:22 | |
pjm6 | ah sorry, I didn't understand that | 20:22 |
pjm6 | I will look in the infra host :) | 20:22 |
*** alextricity has joined #openstack-ansible | 20:22 | |
pjm6 | well, in the infrahost i didn't see any cinder container | 20:23 |
*** eil397 has joined #openstack-ansible | 20:26 | |
*** mcarden_ is now known as mcarden | 20:26 | |
pjm6 | is there a way to make sure tha the conf file is reading well? | 20:28 |
pjm6 | that command initctl reload | 20:29 |
automagically | http://mwhiteley.com/scripts/2012/12/11/dbus-init-checkconf.html | 20:29 |
pjm6 | tks automagically :) | 20:29 |
*** eil397 has quit IRC | 20:30 | |
automagically | Also, pjm6 make sure you have defined storage-infra_hosts | 20:30 |
stevelle | ^ | 20:30 |
*** eil397 has joined #openstack-ansible | 20:30 | |
automagically | That is where the cinder_api service will be running in a container | 20:30 |
pjm6 | that is put the host of storage in the user_config right? | 20:30 |
pjm6 | the syntax is ok | 20:31 |
automagically | Your openstack_user_config for Cinder should define two host groups: storage-infra_hosts and storage_hosts | 20:31 |
pjm6 | ohh okkk | 20:31 |
pjm6 | thats the problem (probably) | 20:32 |
automagically | cinder-api and cinder-scheduler should be running on the former and cinder-volume and cinder-backup on the latter | 20:32 |
pjm6 | I onmly put | 20:32 |
pjm6 | the storage_hosts... | 20:32 |
pjm6 | lol | 20:32 |
pjm6 | It should be the same host? | 20:32 |
automagically | It _could_ be | 20:32 |
pjm6 | but should be in the | 20:32 |
stevelle | you should have storage-infra_hosts on infra usually | 20:32 |
pjm6 | shared-infra-host => controller | 20:32 |
pjm6 | right? | 20:32 |
*** woodard_ has quit IRC | 20:32 | |
pjm6 | I read now in the docs | 20:32 |
stevelle | you got it | 20:33 |
*** woodard has joined #openstack-ansible | 20:33 | |
pjm6 | probably that was the error... thanks a lot guys :) | 20:34 |
pjm6 | one more thing, its recommend that I use the playbook from the beginning | 20:34 |
pjm6 | or using with --limit retry? | 20:34 |
stevelle | you will want to use a few playbooks since your inventory was incomplete. | 20:35 |
pjm6 | so its better run all again | 20:36 |
stevelle | lxc-containers-create.yml and os-cinder-install.yml | 20:36 |
pjm6 | I will give the feedback | 20:37 |
*** sigmavirus24 is now known as sigmavirus24_awa | 20:37 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 20:37 | |
pjm6 | btw: why storage API are not in the shared-infra group? | 20:37 |
pjm6 | its to provide more redundancy or because this service could be heavy in terms of requests? | 20:37 |
palendae | Allows deployers finer control | 20:38 |
palendae | At scale it could be separated out should someone want/need it | 20:38 |
pjm6 | ok, so its for control and not performance matters :) | 20:38 |
stevelle | usually you would want cinder-api and cinder-scheduler at least to be close to the infra it uses (db, queues) | 20:38 |
palendae | Well, might be performance at scale | 20:40 |
palendae | To isolate services from each other | 20:40 |
palendae | That's why we started breaking more infra groups out | 20:40 |
palendae | Used to just be infra_hosts | 20:40 |
*** asettle has joined #openstack-ansible | 20:43 | |
pjm6 | yes and is good to making | 20:48 |
pjm6 | an generic deployment playbook :) | 20:48 |
pjm6 | maybe considering adding in the docs http://docs.openstack.org/developer/openstack-ansible/install-guide/configure-hostlist.html | 20:51 |
pjm6 | about the storage-infra_hosts ? | 20:51 |
spotz | pjm6 that was just added into the cinder-ceph documentation | 20:52 |
pjm6 | spotz, you're right. I miss that because I skipped the topic of Configuring the Block Storage service | 20:54 |
pjm6 | my bad | 20:54 |
spotz | I only know because I put it in after we got a bug:) | 20:54 |
pjm6 | Nice, now I hope not to forget :) | 20:55 |
*** alextricity has quit IRC | 21:04 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible: Refactor user config loading into function https://review.openstack.org/298981 | 21:05 |
*** cloudtrainme has quit IRC | 21:09 | |
*** lykinsbd_ has quit IRC | 21:11 | |
*** eil397 has quit IRC | 21:13 | |
*** eil397 has joined #openstack-ansible | 21:13 | |
cloudnull | for me osic.org didnt go down at least | 21:14 |
cloudnull | ha ^ wrong window. | 21:15 |
cloudnull | which is good btw :) | 21:15 |
*** javeriak has quit IRC | 21:18 | |
*** Mudpuppy has quit IRC | 21:20 | |
*** retreved has quit IRC | 21:21 | |
*** eil397 has quit IRC | 21:23 | |
spotz | hehehe | 21:27 |
*** eil397 has joined #openstack-ansible | 21:28 | |
*** thorst has quit IRC | 21:33 | |
*** thorst has joined #openstack-ansible | 21:33 | |
*** sdake_ has joined #openstack-ansible | 21:35 | |
*** cloudtrainme has joined #openstack-ansible | 21:35 | |
*** thorst has quit IRC | 21:38 | |
*** sdake has quit IRC | 21:38 | |
*** fawadkhaliq has joined #openstack-ansible | 21:44 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:47 | |
pjm6 | automagically, stevelle the problem persists, but now I have the cinder_api_container and scheduler in infra | 21:47 |
pjm6 | but it's different, now is in the playbook Ensure cinder api is available | 21:49 |
*** Nepoc has joined #openstack-ansible | 21:49 | |
cloudnull | pjm6: whats going on ? | 21:50 |
cloudnull | sorry been hectic today | 21:50 |
stevelle | pjm6: iirc you will need to run the haproxy play as well | 21:50 |
Nepoc | Hello... what version of glace should I have if I'm running liberty? I currently have 1.2.0 and it doesn't seem to have the --copy-from for image-create. | 21:50 |
Nepoc | glance | 21:50 |
pjm6 | cloudnull, no problem :) | 21:50 |
stevelle | now that the cinder-api group is not empty, haproxy needs to know about the hosts to set up forwarding | 21:50 |
pjm6 | stevelle, I forgot that... | 21:50 |
stevelle | I forgot to mention | 21:51 |
pjm6 | no problem, I thank you for all the help/support | 21:51 |
stevelle | when this doesn't quite fix it, I'll let cloudnull help you further :) | 21:51 |
cloudnull | Nepoc: if i remember right the glance community removed copy from | 21:51 |
pjm6 | hope that in near future I would be more helping than being rescue =) | 21:52 |
pjm6 | thanks once again ste | 21:52 |
pjm6 | stevelle, | 21:52 |
cloudnull | Nepoc: in a liberty deploy i did the other day I had to do this https://github.com/os-cloud/osic-ref-impl/blob/master/post-deployment-setup.sh#L47-L54 | 21:52 |
fawadkhaliq | hey guys, quick question..does os-ansible support Nova cells based deployment? | 21:53 |
cloudnull | fawadkhaliq: no. | 21:53 |
cloudnull | we have cells v2 code for the nova-api | 21:53 |
cloudnull | which is in mitaka | 21:53 |
Nepoc | cloudnull: strange... I've been using the same format used in tempest for a while now. Using image_url and I had no need to do a wget first. | 21:53 |
cloudnull | but not for cells v1 | 21:53 |
fawadkhaliq | cloudnull: okay, thanks. | 21:54 |
cloudnull | fawadkhaliq: do you need cells ? | 21:54 |
cloudnull | cells v1 that is ? | 21:54 |
fawadkhaliq | cloudnull: Nope, I am agnostic of cells v1 vs v2. Since whatever is going to be there is going to be new deployments, so cells v2 makes sense. | 21:55 |
cloudnull | ok. well for mitaka the cellsv2 bits exist and you can configure them for nova however ive not given them a spin, so idk the state of nova cells v2 | 21:56 |
fawadkhaliq | cloudnull: no worries, thanks. Just collecting data at this point. | 21:56 |
cloudnull | cool | 21:56 |
cloudnull | ping if you have questions . | 21:56 |
fawadkhaliq | cloudnull: will do, thanks. | 21:57 |
*** busterswt has quit IRC | 21:58 | |
*** fawadkhaliq has quit IRC | 22:01 | |
pjm6 | stevelle, at least that task pass without error. Thanks =D | 22:02 |
*** fawadkhaliq has joined #openstack-ansible | 22:02 | |
*** thorst has joined #openstack-ansible | 22:02 | |
stevelle | onto the next error! :D | 22:02 |
cloudnull | ^ truth :) | 22:02 |
pjm6 | loool yes | 22:03 |
pjm6 | one question, its normal having some errors in deploying | 22:03 |
pjm6 | or is just me that i'm pretty good at it? xD ahah | 22:03 |
Nepoc | cloudnull: Like this https://github.com/openstack/openstack-ansible/blob/liberty/playbooks/roles/os_tempest/tasks/tempest_resources.yml#L16-L32 | 22:03 |
cloudnull | Nepoc: maybe the api call still works but the cli not? | 22:05 |
cloudnull | for the glance ansible lib we're importing python-glanceclient directly (if i remember right) | 22:05 |
*** thorst has quit IRC | 22:07 | |
Nepoc | Well there we go ERROR glance.api.v1.images [-] Copy from external source 'file' failed for image It's my fault it seems | 22:09 |
*** cloudtrainme has quit IRC | 22:09 | |
cloudnull | is that with the CLI ? | 22:10 |
cloudnull | or the ansible module ? | 22:10 |
Nepoc | Ansible module | 22:12 |
*** markvoelker has joined #openstack-ansible | 22:13 | |
Nepoc | found the problem... file permissions :) | 22:13 |
cloudnull | ah. ok. | 22:13 |
* cloudnull was code diving | 22:13 | |
Nepoc | Hopefully you didn't dive too deep | 22:14 |
cloudnull | never | 22:14 |
Nepoc | :) | 22:14 |
*** Brew has quit IRC | 22:14 | |
*** ametts_ has quit IRC | 22:15 | |
*** fawadkhaliq has quit IRC | 22:15 | |
*** fawadkhaliq has joined #openstack-ansible | 22:16 | |
*** markvoelker has quit IRC | 22:20 | |
*** markvoelker has joined #openstack-ansible | 22:21 | |
*** markvoelker_ has joined #openstack-ansible | 22:22 | |
openstackgerrit | Steve Lewis proposed openstack/openstack-ansible: Add release note for services in venvs https://review.openstack.org/299008 | 22:23 |
*** markvoelker has quit IRC | 22:26 | |
spotz | stevelle: I think your 's may cause an issue not sure. content looks good but I'm gonna wait for jenkins | 22:26 |
*** sdake has joined #openstack-ansible | 22:26 | |
stevelle | spotz: they should be ` rather than ' and the reno guide said I could use RST but I was skeptical also | 22:27 |
*** sdake_ has quit IRC | 22:28 | |
spotz | Well jenkins approved, stevelle. Let me +1 | 22:29 |
*** Mudpuppy has joined #openstack-ansible | 22:29 | |
*** spotz is now known as spotz_zzz | 22:31 | |
*** markvoelker_ has quit IRC | 22:39 | |
*** fawadkhaliq has quit IRC | 22:44 | |
*** fawadkhaliq has joined #openstack-ansible | 22:44 | |
*** fawadkhaliq has quit IRC | 22:46 | |
rromans | stevelle: curious, why the triple backtick? | 22:46 |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-ironic: [WIP] Add tests for the ironic REST API https://review.openstack.org/298654 | 22:47 |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-ironic: [WIP] Add tests for the ironic REST API https://review.openstack.org/298654 | 22:48 |
stevelle | rromans: because I'm bad at rst? :) | 22:48 |
stevelle | -1 with the right syntax please, maybe I'll remember this time | 22:48 |
rromans | lol ok | 22:48 |
stevelle | I have it in my head that single backtick is md | 22:49 |
*** fawadkhaliq has joined #openstack-ansible | 22:52 | |
*** galstrom_zzz is now known as galstrom | 22:55 | |
rromans | stevelle: mind if I put just up a new patch? | 22:56 |
rromans | *put up | 22:56 |
stevelle | rromans: be my guest | 22:56 |
rromans | kk | 22:56 |
*** weezS has quit IRC | 22:57 | |
*** KLevenstein has quit IRC | 22:57 | |
*** eil397 has quit IRC | 23:00 | |
cloudnull | stevelle: is anyone good at rst ? | 23:01 |
stevelle | cloudnull: searching... | 23:02 |
openstackgerrit | Robb Romans proposed openstack/openstack-ansible: Add release note for services in venvs https://review.openstack.org/299008 | 23:06 |
*** cloudtrainme has joined #openstack-ansible | 23:07 | |
*** cloudtrainme has quit IRC | 23:10 | |
*** jorge_munoz has quit IRC | 23:15 | |
*** fawadkhaliq has quit IRC | 23:18 | |
*** fawadkhaliq has joined #openstack-ansible | 23:20 | |
*** fawadkhaliq has quit IRC | 23:22 | |
*** galstrom is now known as galstrom_zzz | 23:31 | |
*** woodard_ has joined #openstack-ansible | 23:32 | |
*** eil397 has joined #openstack-ansible | 23:32 | |
*** woodard has quit IRC | 23:36 | |
*** woodard_ has quit IRC | 23:36 | |
*** fawadkhaliq has joined #openstack-ansible | 23:41 | |
*** sdake has quit IRC | 23:43 | |
pjm6 | I will go out guys | 23:43 |
pjm6 | finally could deploy succesfully openstack-ansible, thank you all for all the support and see you tomorrow :9 | 23:44 |
pjm6 | :) | 23:44 |
*** sdake has joined #openstack-ansible | 23:44 | |
*** sdake has quit IRC | 23:44 | |
pjm6 | have a good rest of day | 23:44 |
*** sdake has joined #openstack-ansible | 23:44 | |
stevelle | grats pjm6 | 23:49 |
*** pjm6 has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!