*** schwicht has quit IRC | 00:01 | |
*** schwicht has joined #openstack-ansible | 00:09 | |
*** woodard has joined #openstack-ansible | 00:28 | |
*** woodard has quit IRC | 00:33 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 00:40 |
---|---|---|
*** Ger-chervyak has joined #openstack-ansible | 01:13 | |
*** Ger-chervyak has quit IRC | 01:14 | |
*** thorst has joined #openstack-ansible | 01:35 | |
*** thorst has quit IRC | 01:39 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-repo_build: update repo-build for ansible 2.1 compat https://review.openstack.org/299689 | 01:45 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_aodh: Updated role using the Multi-Distro framework https://review.openstack.org/295620 | 01:47 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 01:56 |
*** thorst has joined #openstack-ansible | 02:04 | |
*** johnmilton has quit IRC | 02:18 | |
*** schwicht has quit IRC | 02:18 | |
*** sdake has joined #openstack-ansible | 02:24 | |
*** thorst has quit IRC | 02:24 | |
*** sdake_ has joined #openstack-ansible | 02:27 | |
*** sdake has quit IRC | 02:28 | |
*** asettle has quit IRC | 02:33 | |
*** sdake has joined #openstack-ansible | 02:39 | |
*** sdake_ has quit IRC | 02:43 | |
*** jayc has joined #openstack-ansible | 02:49 | |
*** Maeca has joined #openstack-ansible | 02:51 | |
*** retreved has quit IRC | 03:02 | |
*** retreved has joined #openstack-ansible | 03:03 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 03:09 |
*** mfisch has quit IRC | 03:11 | |
*** mfisch has joined #openstack-ansible | 03:12 | |
*** mfisch is now known as Guest89657 | 03:12 | |
*** Guest89657 has quit IRC | 03:13 | |
*** Guest89657 has joined #openstack-ansible | 03:13 | |
*** Guest89657 is now known as mfisch | 03:14 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-ironic: Add tests for the ironic CLI https://review.openstack.org/303104 | 03:31 |
*** woodard has joined #openstack-ansible | 03:46 | |
*** shausy has joined #openstack-ansible | 04:23 | |
*** thorst has joined #openstack-ansible | 04:25 | |
*** thorst has quit IRC | 04:29 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 04:44 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Change the default thread pool size https://review.openstack.org/303079 | 04:44 |
cloudnull | im back out, cheers everyone | 04:44 |
*** schwicht has joined #openstack-ansible | 04:46 | |
*** schwicht has quit IRC | 04:51 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: updated Ironic role to fix tftp-hpa issues https://review.openstack.org/303633 | 04:55 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: updated ironic playbook inclusion for tftp network https://review.openstack.org/303659 | 04:58 |
*** saneax_AFK is now known as saneax | 05:18 | |
*** sdake_ has joined #openstack-ansible | 05:23 | |
*** sdake has quit IRC | 05:24 | |
*** asettle has joined #openstack-ansible | 05:28 | |
*** shausy has quit IRC | 05:34 | |
*** shausy has joined #openstack-ansible | 05:35 | |
*** pcaruana has joined #openstack-ansible | 05:39 | |
*** agireud has quit IRC | 05:41 | |
*** sdake_ is now known as sdake | 05:45 | |
*** agireud has joined #openstack-ansible | 05:45 | |
*** joker_ has joined #openstack-ansible | 05:52 | |
*** jayc has quit IRC | 05:54 | |
*** tricksters has joined #openstack-ansible | 05:56 | |
*** eric_lopez has quit IRC | 05:58 | |
*** admin0 has joined #openstack-ansible | 05:58 | |
*** javeriak has joined #openstack-ansible | 06:04 | |
*** admin0 has quit IRC | 06:17 | |
odyssey4me | v1k0d3n uh, nope - the AIO for mitaka should work almost the same as in any other branch as we try to keep the gate testing as close as possible in style and method and the circumstances it works in are the same - so I'm curious regarding what you saw | 06:17 |
odyssey4me | deadnull if your auth endpoint is the public one, and the auth_type is publicURL then it should use the public URL's - if you can post the list of public endpoints and the output of the CLI's command (with --debug on the CLI) then we can help take a look | 06:19 |
*** ChrisBenson has quit IRC | 06:20 | |
javeriak | odyssey4me morning | 06:34 |
*** admin0 has joined #openstack-ansible | 06:34 | |
javeriak | i hit the "Memcache key not found" error in the horizon plays too and there doesnt seem to be any fix related to this in master branch | 06:35 |
odyssey4me | javeriak ah, so I think we've fixed it up for all the ssh keys but didn't quite get it all done for the ssl keys | 06:41 |
odyssey4me | so it would appear that should be resolved - can you put in a patch for that please? | 06:42 |
*** admin0 has quit IRC | 06:43 | |
*** neilus has joined #openstack-ansible | 06:43 | |
*** woodard has quit IRC | 06:49 | |
javeriak | odyssey4me sure, but i seem to be missing something beacuse when i applied the changes to the horizon ssl playbooks; i got a checksum/crc error | 06:49 |
*** woodard has joined #openstack-ansible | 06:49 | |
javeriak | even tried clearing the facts since i thought i might need to clear up some old values | 06:50 |
openstackgerrit | Michael Davies proposed openstack/openstack-ansible: Add installation support for os_ironic https://review.openstack.org/293779 | 06:54 |
*** woodard has quit IRC | 06:54 | |
odyssey4me | javeriak hmm, was that a checksum error in tests or in deployment? | 06:57 |
javeriak | odyssey4me the horizon playbooks threw it for the key_distribute task, the contents that it extracts for the copy later were producing that error | 07:01 |
*** markvoelker has joined #openstack-ansible | 07:01 | |
odyssey4me | javeriak can you upload the review for inspection so I can take a look at the changes made? | 07:02 |
javeriak | odyssey4me sure, they should the same as we did for rabbitmq right? | 07:04 |
odyssey4me | javeriak yep, pretty much - clurp is more reliable than using the shell/command module to collect facts | 07:05 |
*** arslan has quit IRC | 07:05 | |
openstackgerrit | Michael Davies proposed openstack/openstack-ansible-os_nova: Add Nova config for os_ironic role https://review.openstack.org/293315 | 07:05 |
javeriak | odyssey4me also cloudnull mentioned some horizon nova experts based in australia that would be available monday to help look at my cluster? any idea if they're around? | 07:05 |
*** markvoelker has quit IRC | 07:06 | |
javeriak | oh and btw the ssl patch for horizon needs to go in master/mitaka too i think? | 07:06 |
odyssey4me | I'm not sure if neillc is around, or can help connect you with the right people. | 07:07 |
odyssey4me | javeriak yeah - but to start with let's get it into master, once it's merged we'll look to backporting | 07:08 |
javeriak | odyssey4me okay pushing shortly | 07:08 |
*** mikelk has joined #openstack-ansible | 07:11 | |
*** jamielennox is now known as jamielennox|away | 07:15 | |
openstackgerrit | Michael Davies proposed openstack/openstack-ansible-ironic: Copy required PXE files without prejudice https://review.openstack.org/303927 | 07:16 |
odyssey4me | javeriak it looks like the Horizon experts are off ill today, it may be worth jumping into #openstack-horizon and asking your questions there? | 07:18 |
neillc | javeriak: richard jones is your best bet r1chardjon3s in the openstack-horizon channel | 07:23 |
*** xek has quit IRC | 07:24 | |
openstackgerrit | Merged openstack/openstack-ansible-ironic: Change the default thread pool size https://review.openstack.org/303079 | 07:25 |
javeriak | odyssey4me neillc i dont have any specific query, its just horizon has gone realllly slow and doesnt respond with the scale im working with; so was hoping you guys could help and let me know if im missing some configs for larger installations | 07:34 |
javeriak | atcually its the whole of openstack; the calls are just going through really slow on cli as well, and horizon is not working | 07:34 |
neillc | richard is still the best person to speak to, but I think the basic answer is that horizon does not work well at scale | 07:34 |
neillc | mostly because of the apis | 07:35 |
neillc | work is being done to try and improve things (lie the new swift panel in horizon) | 07:35 |
odyssey4me | javeriak yeah, it souds to me like the starting point would be to identify the issue at the API level | 07:35 |
javeriak | guys seen this before: lxc: confile.c: config_string_item_max: 314 8d494692_etcontroller-1 is too long (>= 16) ? | 07:35 |
neillc | but some of it is just that the apis are not good | 07:35 |
javeriak | odyssey4me neillc so there must be some way to improve it; i mean what do you do at larger scales and this is still hardly a 130 node cluster; now openstack has just stopped cooperating | 07:41 |
odyssey4me | javeriak that's odd, because we've had tests done at larger scale without performance degredation - can you pastebin your user_vars and openstack_user_config somewhere I can view it? | 07:44 |
*** goretoxo has joined #openstack-ansible | 07:44 | |
javeriak | odyssey4me sure, i'll copy them out | 07:45 |
*** Oku_OS-away is now known as Oku_OS | 07:45 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-ironic: Add tests for the ironic CLI https://review.openstack.org/303104 | 07:46 |
javeriak | hey is there a limit to the hostnames you can set in the user_config? my lxc's wont start with that error "lxc: confile.c: config_string_item_max: 314 8d494692_etcontroller-1 is too long (>= 16) ?" | 07:46 |
odyssey4me | that's odd - is this a master build? | 07:47 |
javeriak | odyssey4me nope kilo; (the lxc error right?) | 07:47 |
odyssey4me | javeriak hmm, I need to relocate but I think there was a patch to later versions which may have fixed that - let me get going to the office and check that out | 07:50 |
*** admin0 has joined #openstack-ansible | 07:50 | |
javeriak | odyssey4me i found the problem, someone had messed up the user config file and replaced the container interface names :P | 07:52 |
openstackgerrit | Merged openstack/openstack-ansible-os_nova: Add Nova config for os_ironic role https://review.openstack.org/293315 | 08:03 |
admin0 | good morning | 08:04 |
*** admin0 has quit IRC | 08:08 | |
*** asettle has quit IRC | 08:09 | |
*** admin0 has joined #openstack-ansible | 08:09 | |
odyssey4me | javeriak ah, if that's done then it needs to be known that the interface names have a length limit | 08:15 |
odyssey4me | I wonder if we shouldn't hard fail before changing anything if that's done, but perhaps someone doing that is an edge case and they should know what they're doing. | 08:15 |
*** javeriak has quit IRC | 08:20 | |
*** admin0 has quit IRC | 08:24 | |
*** admin0 has joined #openstack-ansible | 08:26 | |
odyssey4me | mrda does the suggested change in https://review.openstack.org/303927 make sense? | 08:29 |
mrda | odyssey4me: yes, I will update and re-push | 08:33 |
* mrda is currently debugging cloudnull's patch against my lab testing environment | 08:33 | |
odyssey4me | mcarden if you're still around, sorry about changing things up again but it seems that https://review.openstack.org/303104 may need another round to keep Ansible 2.1 compatibility, which is a goal for Master/Mitaka. | 08:34 |
odyssey4me | ah cool thanks mrda - we're close :) | 08:34 |
mrda | So I haven't completed my audit against what andymccr and i had working in a lab, so I'd like to do that before we merge this one | 08:36 |
odyssey4me | mrda from my conversation with cloudnull on the w/end, it seems that what you guys had working would only ever work on a flat network - whereas cloudnull's changes are more flexible | 08:38 |
odyssey4me | the change to the listening address for the tftp server is also necessary as the default only ever listens on ipv6 | 08:38 |
mrda | sure | 08:39 |
odyssey4me | just for funsies :) | 08:39 |
mrda | just asking questions, happy for answers :) | 08:39 |
odyssey4me | cloudnull engaged with #openstack-ironic and ended up getting fantastic feedback and assistance with overcoming the hurdles | 08:39 |
* mrda is very grateful for all the help from cloudnull, andymccr and odyssey4me | 08:39 | |
mrda | \o/ | 08:39 |
openstackgerrit | Michael Davies proposed openstack/openstack-ansible-ironic: Copy required PXE files without prejudice https://review.openstack.org/303927 | 08:42 |
mcarden | odyssey4me: NP, sorting that now. | 08:42 |
odyssey4me | mcarden it may not apply at all, but if it works then let's do it | 08:42 |
mcarden | Yep. It passes linting with that change. Just doing a full run now. | 08:43 |
mrda | oh, btw thanks all for merging https://review.openstack.org/#/c/293315/ while I was on the train *yay* | 08:44 |
odyssey4me | evrardjp could you revise https://review.openstack.org/279730 to take care of the merge conflict please? | 08:47 |
odyssey4me | relocating from train to office - bbiab | 08:48 |
*** schwicht has joined #openstack-ansible | 08:49 | |
*** fishcried has joined #openstack-ansible | 08:52 | |
*** pjm6 has joined #openstack-ansible | 08:52 | |
*** schwicht has quit IRC | 08:54 | |
pjm6 | Hi everyone | 08:55 |
*** fishcried1 has joined #openstack-ansible | 08:58 | |
*** pcaruana has quit IRC | 09:00 | |
*** fishcried has quit IRC | 09:01 | |
*** fishcried1 is now known as fishcried | 09:01 | |
*** markvoelker has joined #openstack-ansible | 09:02 | |
evrardjp | hey | 09:02 |
evrardjp | odyssey4me sure | 09:02 |
*** markvoelker has quit IRC | 09:07 | |
openstackgerrit | Merged openstack/openstack-ansible-os_rally: Removing unused handlers file https://review.openstack.org/303584 | 09:08 |
*** javeriak has joined #openstack-ansible | 09:10 | |
mrda | odyssey4me: Just added a comment on https://review.openstack.org/#/c/303633/2 for yours and cloudnull's consideration. You're welcome :) | 09:11 |
javeriak | odyssey4me yea it was more of a typo in this case, the person was using find and replace in the file and accidently replaced the interface names aswell | 09:11 |
openstackgerrit | Merged openstack/openstack-ansible-lxc_hosts: Minor tweak to the lxc-system-manage template https://review.openstack.org/303714 | 09:12 |
openstackgerrit | Merged openstack/openstack-ansible-os_tempest: Updates for tempest in functional tests https://review.openstack.org/302697 | 09:30 |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-ironic: Add tests for the ironic CLI https://review.openstack.org/303104 | 09:37 |
*** woodard has joined #openstack-ansible | 09:47 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-ironic: Copy required PXE files without prejudice https://review.openstack.org/303927 | 09:47 |
*** schwicht has joined #openstack-ansible | 09:51 | |
*** woodard has quit IRC | 09:52 | |
*** schwicht has quit IRC | 09:55 | |
*** thorst has joined #openstack-ansible | 10:04 | |
*** thorst has quit IRC | 10:27 | |
*** mgoddard_ has joined #openstack-ansible | 10:27 | |
*** thorst has joined #openstack-ansible | 10:27 | |
*** mgoddard has quit IRC | 10:30 | |
odyssey4me | evrardjp this may also be of interest to you: https://review.openstack.org/301343 | 10:32 |
*** thorst has quit IRC | 10:32 | |
evrardjp | :) | 10:32 |
evrardjp | indeed | 10:32 |
openstackgerrit | Merged openstack/openstack-ansible-ironic: Copy required PXE files without prejudice https://review.openstack.org/303927 | 10:34 |
*** sdake_ has joined #openstack-ansible | 10:45 | |
*** thorst has joined #openstack-ansible | 10:46 | |
*** sdake has quit IRC | 10:48 | |
*** markvoelker has joined #openstack-ansible | 11:03 | |
*** thorst has quit IRC | 11:04 | |
*** thorst has joined #openstack-ansible | 11:05 | |
*** markvoelker has quit IRC | 11:07 | |
*** jayc has joined #openstack-ansible | 11:08 | |
*** thorst has quit IRC | 11:09 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-galera_server: Update min_ansible_version to 1.9.0 https://review.openstack.org/304037 | 11:09 |
*** johnmilton has joined #openstack-ansible | 11:10 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-ironic: Update min_ansible_version to 1.9.0 https://review.openstack.org/304038 | 11:11 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-galera_server: Update min_ansible_version to 1.9 https://review.openstack.org/304037 | 11:12 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-ironic: Update min_ansible_version to 1.9 https://review.openstack.org/304038 | 11:12 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder: Update min_ansible_version to 1.9 https://review.openstack.org/304039 | 11:13 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_glance: Update min_ansible_version to 1.9 https://review.openstack.org/304040 | 11:14 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_gnocchi: Update min_ansible_version to 1.9 https://review.openstack.org/304041 | 11:15 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_heat: Update min_ansible_version to 1.9 https://review.openstack.org/304042 | 11:16 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_horizon: Update min_ansible_version to 1.9 https://review.openstack.org/304043 | 11:16 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone: Update min_ansible_version to 1.9 https://review.openstack.org/304044 | 11:17 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_neutron: Update min_ansible_version to 1.9 https://review.openstack.org/304045 | 11:17 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_nova: Update min_ansible_version to 1.9 https://review.openstack.org/304046 | 11:18 |
*** schwicht has joined #openstack-ansible | 11:33 | |
*** weshay has quit IRC | 11:36 | |
deadnull | odyssey4me you're on fire | 11:44 |
* admin0 searches for the fire extingusiher | 11:51 | |
*** Oku_OS is now known as Oku_OS-away | 11:55 | |
odyssey4me | lol, repetitive patches hardly qualify :p | 11:56 |
*** sdake_ is now known as sdake | 11:59 | |
*** mgoddard_ has quit IRC | 12:00 | |
*** thorst has joined #openstack-ansible | 12:04 | |
*** jayc has quit IRC | 12:07 | |
*** retreved has quit IRC | 12:08 | |
*** retreved has joined #openstack-ansible | 12:08 | |
*** pjm6 has quit IRC | 12:10 | |
*** sdake_ has joined #openstack-ansible | 12:10 | |
*** sdake has quit IRC | 12:12 | |
*** b3rnard0_away is now known as b3rnard0 | 12:17 | |
*** sdake_ has quit IRC | 12:18 | |
*** clickboom has joined #openstack-ansible | 12:18 | |
*** markvoelker has joined #openstack-ansible | 12:19 | |
*** johnmilton has quit IRC | 12:21 | |
*** weshay has joined #openstack-ansible | 12:25 | |
*** saneax is now known as saneax_AFK | 12:26 | |
*** Oku_OS-away is now known as Oku_OS | 12:29 | |
*** neilus has quit IRC | 12:29 | |
*** neilus has joined #openstack-ansible | 12:30 | |
*** retreved_ has joined #openstack-ansible | 12:33 | |
*** retreved_ has quit IRC | 12:33 | |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-security: [WIP] Unattended upgrades https://review.openstack.org/304096 | 12:34 |
*** retreved has quit IRC | 12:36 | |
*** schwicht has quit IRC | 12:36 | |
*** mgoddard has joined #openstack-ansible | 12:40 | |
*** jayc has joined #openstack-ansible | 12:41 | |
*** johnmilton has joined #openstack-ansible | 12:42 | |
*** clickboom has quit IRC | 12:43 | |
*** woodard has joined #openstack-ansible | 12:45 | |
*** woodard has quit IRC | 12:45 | |
*** woodard has joined #openstack-ansible | 12:46 | |
*** johnmilton has quit IRC | 12:50 | |
*** johnmilton has joined #openstack-ansible | 12:50 | |
*** clickboom has joined #openstack-ansible | 12:51 | |
*** clickboom has quit IRC | 12:53 | |
v1k0d3n | odyssey4me: good morning. i'll try again, and let you know what happens on my end. couple of things though for sure, which you guys are aware of and i just missed is adding the security repo's, right? that threw errors on my end about the service accounts not being locked for AIO. | 12:54 |
*** clickboom has joined #openstack-ansible | 12:55 | |
*** johnmilton has quit IRC | 12:55 | |
*** johnmilton has joined #openstack-ansible | 12:55 | |
*** schwicht has joined #openstack-ansible | 12:56 | |
*** clickboom has quit IRC | 12:56 | |
*** pjm6 has joined #openstack-ansible | 12:59 | |
*** schwicht has quit IRC | 13:00 | |
*** neilus1 has joined #openstack-ansible | 13:00 | |
*** clickboom has joined #openstack-ansible | 13:01 | |
*** clickboom has quit IRC | 13:02 | |
*** neilus has quit IRC | 13:04 | |
odyssey4me | v1k0d3n it'll only be fatal if your base image is really bad :) | 13:06 |
odyssey4me | we only skip one tag in the security check for the gate, and that's the check for unauthenticated packages from apt - and that's because we're forced to use those by OpenStack-CI | 13:07 |
*** clickboom has joined #openstack-ansible | 13:07 | |
openstackgerrit | Javeria Khan proposed openstack/openstack-ansible-os_horizon: Update SSL key / cert distribution for Horizon https://review.openstack.org/304113 | 13:08 |
javeriak | odyssey4me ^ ; please see if im going about it correctly | 13:09 |
odyssey4me | javeriak that looks right to me | 13:14 |
*** Ger-chervyak has joined #openstack-ansible | 13:16 | |
*** automagically has joined #openstack-ansible | 13:19 | |
automagically | Morning all | 13:23 |
pjm6 | hi automagically | 13:23 |
*** xek has joined #openstack-ansible | 13:24 | |
odyssey4me | o/ | 13:24 |
*** neilus1 has quit IRC | 13:29 | |
openstackgerrit | Lance Bragstad proposed openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 13:30 |
javeriak | odyssey4me are there any special settings to getting the nova novnc console to work? my nova_console backends are always down | 13:32 |
javeriak | trying to access my VMs directly.. | 13:32 |
*** clickboom has quit IRC | 13:34 | |
v1k0d3n | odyssey4me: so this was just a default installation of ubuntu with the prereqs as suggested in the wiki. | 13:34 |
v1k0d3n | i wonder if listing deb repositories as a replacement for what a user could have (by default) could help? | 13:35 |
*** pjm6 has quit IRC | 13:36 | |
*** thorst has quit IRC | 13:36 | |
v1k0d3n | when i have some time (which is becoming harder and harder these days) i can go back and see what issues i ran into specifically and report back. | 13:37 |
*** clickboom has joined #openstack-ansible | 13:37 | |
*** pjm6 has joined #openstack-ansible | 13:38 | |
odyssey4me | lbragstad comments in https://review.openstack.org/303592 | 13:38 |
lbragstad | odyssey4me thanks! | 13:38 |
odyssey4me | javeriak that's off | 13:38 |
odyssey4me | *odd | 13:38 |
pjm6 | for instance is here anyone who knows horizon or worked with it? | 13:39 |
pjm6 | i'm developing a dashboard and know that exists permissions (with role) | 13:39 |
pjm6 | but i would like to know if its possible to use group xD | 13:40 |
odyssey4me | javeriak are you using vnc instead of spice? the check configs are here and if you're using novnc then the 'nova_console' backend will always be down because it uses the spice port | 13:40 |
pjm6 | *group members | 13:40 |
javeriak | odyssey4me the spice ones are down as well.. | 13:40 |
javeriak | my nova plays are failing :( error: /openstack/venvs/nova-12.0.5 does not refer to a python installation in Update virtualenv path | 13:41 |
odyssey4me | v1k0d3n which tests/tasks failed in the security role? | 13:41 |
v1k0d3n | let me check and see if i can find it specifically. | 13:42 |
odyssey4me | pjm do you mean keystone group members? if so then you need to change the policies to check keystone membership and adjust the tasks shown - that's not all that easy :/ | 13:42 |
cloudnull | morning | 13:42 |
odyssey4me | pjm6 that's what https://review.openstack.org/264862 was trying to help resolve | 13:42 |
openstackgerrit | Lance Bragstad proposed openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 13:43 |
javeriak | cloudnull morning! really happy to see you :D | 13:43 |
lbragstad | cloudnull o/ | 13:44 |
cloudnull | hows it :) | 13:44 |
*** busterswt has joined #openstack-ansible | 13:44 | |
*** neilus has joined #openstack-ansible | 13:46 | |
pjm6 | thanks odyssey4me, gotta look at that =) | 13:46 |
pjm6 | hi cloudnull | 13:46 |
admin0 | https://cerberus.office.xl-is.net/index.php/profiles/ticket/KWE-98454-613/conversation/read_all | 13:48 |
admin0 | oops | 13:48 |
mattt | why do so many roles include apt_package_pinning ? | 13:48 |
admin0 | :D | 13:48 |
mattt | is that deliberate ? | 13:48 |
admin0 | hoi all | 13:48 |
cloudnull | mattt: you mean as a dep? | 13:49 |
mattt | cloudnull: yep! | 13:49 |
cloudnull | in the meta file? | 13:49 |
cloudnull | or in a test? | 13:49 |
mattt | cloudnull: yep, meta ... ie. https://github.com/openstack/openstack-ansible-os_cinder/blob/master/meta/main.yml#L39 | 13:50 |
*** Oku_OS is now known as Oku_OS-away | 13:50 | |
*** schwicht has joined #openstack-ansible | 13:51 | |
v1k0d3n | odyssey4me: it choked on V-38496 (default system accounts other than root that aren't locked). | 13:51 |
cloudnull | apt_package_pinning gives the user the ability to pin packages. you don't have that otherwise, especially as we move to var files that are included at run time which are immutable variables. | 13:51 |
cloudnull | idk that many folks are using outside of RPC however thats why its there. | 13:52 |
cloudnull | do we want to remove it ? | 13:52 |
odyssey4me | it seems odd to have the role, but we never use it for any pinning we do anywhere | 13:52 |
v1k0d3n | it was a pretty vanilla install, but nothing installed that wasn't needed either. | 13:52 |
*** michaelgugino has joined #openstack-ansible | 13:52 | |
odyssey4me | for example, we pin the mariadb repo but don't use our role to do it | 13:52 |
openstackgerrit | Flávio Ramalho proposed openstack/openstack-ansible-os_neutron: Fix neutron lbaasv2 upstart init scrtipt placement https://review.openstack.org/304143 | 13:53 |
cloudnull | odyssey4me: we should do that :) | 13:53 |
mattt | cloudnull: i was more curious why it was there when we didn't appear to be using it :) | 13:53 |
cloudnull | to my knowledge RPC is the only folks I know do(did?). | 13:54 |
*** Bjoern_ has joined #openstack-ansible | 13:54 | |
cloudnull | if its no longer useful we should cut it | 13:54 |
*** Oku_OS-away is now known as Oku_OS | 13:55 | |
odyssey4me | it makes more sense to me to use one or the better apt configuration roles in ansible galaxy to facilitate this function | 13:55 |
cloudnull | or we should start using it in places where we pin things :)_ | 13:55 |
*** schwicht has quit IRC | 13:55 | |
*** ametts has joined #openstack-ansible | 13:55 | |
odyssey4me | it'd also be nice to have it work in the same way as the apt_package_pinning role - if we add a repo or a pin then it replaces the existing file, so we never leave junk behind | 13:55 |
*** Ger-chervyak has quit IRC | 13:56 | |
*** clickboom has quit IRC | 13:56 | |
odyssey4me | for example, when we change the repo use for mariadb (or even the scheme) then we end up leaving an apt.sources.d file behind which causes apt-get failures until it's cleaned up | 13:56 |
cloudnull | odyssey4me: the trick with those other roles is they generally do a lot which is going to extend run time. | 13:56 |
*** Ger-chervyak has joined #openstack-ansible | 13:56 | |
cloudnull | yea thats a mess. | 13:56 |
cloudnull | in 2.x we get the ability to set that file name | 13:57 |
odyssey4me | I know that there's a patch into Ansible 2.1 that allows you to set the target file name in the Ansible module. | 13:57 |
cloudnull | 2.1 it seems | 13:57 |
cloudnull | http://docs.ansible.com/ansible/apt_repository_module.html | 13:57 |
cloudnull | yea looks like its there now | 13:57 |
odyssey4me | v1k0d3n there was a patch recently to improve that: https://github.com/openstack/openstack-ansible-security/commit/9058a3f084961a52408dd1576dd386db8ff4d0d0 | 13:57 |
odyssey4me | does that perhaps work for your environment? | 13:58 |
cloudnull | 2.1 does with just a few changes which ive already submitted | 13:58 |
*** aludwar has joined #openstack-ansible | 13:58 | |
v1k0d3n | well, i'd have to try again. i was working with this over the weekend for 13.0.0. | 13:58 |
* cloudnull realized that odyssey4me was not talking to me | 13:58 | |
*** clickboom has joined #openstack-ansible | 13:58 | |
* odyssey4me is talking to everyone :p | 13:59 | |
*** jthorne has joined #openstack-ansible | 14:00 | |
stian__ | What is the correct way to restart a galera cluster after a config change? It looks like all nodes are restarted at the same time... | 14:02 |
odyssey4me | stian__ hmm, they shouldn't be - unless you fed it the var to ignore the cluster state | 14:03 |
cloudnull | openstack-ansible galeral-install.yml --tags galera-bootstrap | 14:03 |
stian__ | So if I change something in my.cnf.j2 template and run the playbook again, it should restart every node seperately? | 14:05 |
cloudnull | stian__: http://docs.openstack.org/developer/openstack-ansible/install-guide/ops-galera-recovery.html | 14:05 |
*** KLevenstein has joined #openstack-ansible | 14:06 | |
cloudnull | stian__: yes | 14:06 |
cloudnull | https://github.com/openstack/openstack-ansible/blob/master/playbooks/galera-install.yml#L62 | 14:06 |
cloudnull | that play is executed in serial | 14:06 |
*** mgoddard has quit IRC | 14:07 | |
*** mgoddard has joined #openstack-ansible | 14:08 | |
*** KLevenstein has quit IRC | 14:08 | |
stian__ | Thanks cloudnull | 14:09 |
odyssey4me | automagically it've been better to wait for https://review.openstack.org/304143 to merge so that the merged SHA shows in the commit msg - now we'll have to update it after the master patch merges | 14:09 |
michaelgugino | greetings all. I am back from my travels. | 14:10 |
odyssey4me | wb michaelgugino | 14:10 |
michaelgugino | ty | 14:10 |
automagically | odyssey4me: D’oh! | 14:10 |
automagically | I’ll just abandon it | 14:10 |
automagically | And we’ll recreate the pick post-merge | 14:10 |
michaelgugino | I'm still looking for some reviews on https://review.openstack.org/#/c/298765/ It has turned into quite the sizeable patch set. | 14:10 |
odyssey4me | pjm6 I think that evrardjp knows how the Horizon permissions/policies work. | 14:11 |
odyssey4me | best to ask questions in channel though, then we can all learn | 14:11 |
pjm6 | sure, thanks | 14:12 |
odyssey4me | automagically you can't re-do a pick into a branch with the same change-id, so we'll have to edit the commit msg after the fact :) | 14:12 |
pjm6 | i was talking if its possible to use members of group | 14:12 |
pjm6 | instead of roles | 14:12 |
pjm6 | in permissions | 14:12 |
pjm6 | http://docs.openstack.org/developer/horizon/ref/horizon.html#horizon.Panel.permissions | 14:12 |
evrardjp | who called me? | 14:12 |
evrardjp | :D | 14:12 |
evrardjp | oh | 14:13 |
evrardjp | I didn't develop with groups | 14:13 |
evrardjp | but I don't see why it would be different | 14:14 |
*** Mudpuppy has joined #openstack-ansible | 14:14 | |
evrardjp | I guess you should have something that maps your groups to a permission, keystone will take care of that | 14:15 |
*** schwicht has joined #openstack-ansible | 14:16 | |
odyssey4me | lbragstad more comments based on the gate results: https://review.openstack.org/303592 | 14:16 |
pjm6 | evrardjp: what I do was creating a group | 14:16 |
pjm6 | and then | 14:16 |
pjm6 | in pemrissions have something like this | 14:17 |
pjm6 | openstack.groups.mygroup | 14:17 |
odyssey4me | you may have to map a role to a user group, then the policy can have the roles referenced? | 14:17 |
odyssey4me | but there may be a simpler way of dealing with that, not sure | 14:17 |
cloudnull | welcome back michaelgugino | 14:17 |
michaelgugino | ty | 14:17 |
evrardjp | odyssey4me I think thats the way of doing it | 14:17 |
odyssey4me | I'm not sure if policies can reference groups, but they definitely can reference roles. | 14:18 |
*** shausy has quit IRC | 14:18 | |
pjm6 | hmm but to map role to user group | 14:18 |
pjm6 | I have to map with a project, right? | 14:18 |
odyssey4me | pjm6 nope, as far as I recall any user can map to any role - I think you may have to map the role to either a domain or a project | 14:19 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder: Updated role using Multi-Distro framework https://review.openstack.org/299603 | 14:19 |
odyssey4me | somehow the role has to map to a domain, but it's been a very long time since I went digging into that | 14:19 |
cloudnull | michaelgugino: RE: ovs -- https://review.openstack.org/#/c/302941/ <-- thats a spec for PowerVM as a compute option, they're going to need access to OVS for their bits to work at present we might want to reach out to those folks -- I mentioned that in the review. | 14:19 |
cloudnull | odyssey4me: maybe we can add the spec writers as reviewers | 14:19 |
pjm6 | ohh domain.. didn't see that | 14:19 |
lbragstad | odyssey4me awesome, thanks again | 14:19 |
pjm6 | but to a project do | 14:20 |
cloudnull | they might be able to provide some thoughts on the current impl too | 14:20 |
* lbragstad board the struggle bus with 303592 | 14:20 | |
pjm6 | but domain is used | 14:20 |
odyssey4me | cloudnull oh, good idea to add the spec writers to related reviews | 14:20 |
pjm6 | when we want to contact an external entitiy? | 14:20 |
*** spotz_zzz is now known as spotz | 14:20 | |
odyssey4me | pjm6 all users must be in a domain of some sort | 14:21 |
openstackgerrit | Marc Gariépy proposed openstack/openstack-ansible: Fix configuration string for haproxy https://review.openstack.org/304157 | 14:21 |
odyssey4me | the Default domain is currently a default and is typically recommended to be used for services | 14:21 |
openstackgerrit | Lance Bragstad proposed openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 14:21 |
pjm6 | so if I want to specify for instance some users to use the dashboard, I could use a domain | 14:22 |
pjm6 | and then use | 14:22 |
pjm6 | openstack.domain.users_using_dashboard?* | 14:22 |
pjm6 | I was trying to digging http://docs.openstack.org/developer/horizon/ref/horizon.html#horizon.Panel.can_register but even if I put in the class return False, the panel appears | 14:22 |
evrardjp | pjm6 I think what you're trying to achieve is fairly recent, and you should try to speak with horizon team | 14:23 |
pjm6 | evrardjp: yes already asked question there | 14:24 |
evrardjp | groups didn't exist before, and the only way to map users to permissions was tenants | 14:24 |
pjm6 | yeah, that's my problem :\ | 14:24 |
evrardjp | now domains support can help scoping this | 14:24 |
evrardjp | but real RBAC was on the plan for keystone team and horizon team | 14:25 |
evrardjp | don't know the current status 'though | 14:25 |
pjm6 | well that helps :) thanks evrardjp | 14:25 |
pjm6 | what I do (but it's wrong) | 14:26 |
evrardjp | is there a reason to not use projects? | 14:26 |
odyssey4me | erm, when I see patches like this I begin to wonder how haproxy ever worked for us: https://review.openstack.org/304157 | 14:26 |
pjm6 | is to see if the user don't have permissions | 14:26 |
pjm6 | change the view zone | 14:26 |
pjm6 | yes evrardjp | 14:26 |
pjm6 | the users that could access that dashboard is indenpent of project | 14:26 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-repo_build: Adjusting dependency to supply required var https://review.openstack.org/304162 | 14:27 |
evrardjp | what is your authentication method? | 14:28 |
evrardjp | doing everything standard keystone? | 14:28 |
pjm6 | yes | 14:29 |
openstackgerrit | Merged openstack/openstack-ansible-os_neutron: Fix neutron lbaasv2 upstart init scrtipt placement https://review.openstack.org/304143 | 14:29 |
pjm6 | Well idk if this is a good solution | 14:29 |
evrardjp | and the users are dyamic right | 14:29 |
evrardjp | dynamic | 14:29 |
evrardjp | I mean it can change all the time | 14:29 |
evrardjp | else you could do it in an ugly manner with django | 14:30 |
pjm6 | http://docs.openstack.org/developer/horizon/sourcecode/horizon/horizon.base.html#horizon.base.HorizonComponent.can_access => i'm using can_access | 14:30 |
pjm6 | the users changing | 14:30 |
pjm6 | is like changing username or something? | 14:30 |
pjm6 | So my solution is, the panel that I want for some users to access (in a separate database) | 14:31 |
pjm6 | I use | 14:31 |
pjm6 | def can_access(self, context): | 14:31 |
pjm6 | and then return True (to acess) and False to deny | 14:31 |
pjm6 | works but don't know if its the best way | 14:31 |
michaelgugino | cloudnull: I have read that powervm review. I don't see anything that would conflict, seems they just need an OVS driver | 14:32 |
pjm6 | evrardjp: so in keystone/horizon way its not really sure how things work, right? | 14:33 |
*** jayc has quit IRC | 14:34 | |
*** schwicht has quit IRC | 14:34 | |
*** schwicht has joined #openstack-ansible | 14:34 | |
*** tiagogomes has quit IRC | 14:35 | |
*** tiagogomes has joined #openstack-ansible | 14:35 | |
odyssey4me | jmccrory FYI mancdaz has been digging into the Galera restart issue | 14:36 |
evrardjp | pjm6 not sure what you mean here | 14:37 |
pjm6 | using members of group for permissions using keystone is not possible right know, because is being developed? | 14:38 |
evrardjp | possibly | 14:39 |
odyssey4me | automagically FYI https://review.openstack.org/304143 is correct in Liberty somehow | 14:39 |
evrardjp | I was away for quite a long time so I think the best guys to help you on this are the horizon ones | 14:39 |
odyssey4me | pjm6 yeah, with advanced features like that your best bet will be to try and connect with the Horizon guys in #openstack-horizon | 14:39 |
odyssey4me | generally they're better placed to help you with cusomtisations of the interface, permissions, panels, etc | 14:40 |
pjm6 | sure, thanks odyssey4me evrardjp =) | 14:40 |
pjm6 | btw: for know i'm using the can_access method but with that I can't access to the user that are authenticated | 14:40 |
pjm6 | but maybe could be useful in the future :) | 14:41 |
evrardjp | sorry I couldn't help you better | 14:42 |
pjm6 | don't need for sorry, I thank you guys for helping :D | 14:43 |
pjm6 | anyway when I found a solution I tell :D | 14:43 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 14:46 |
*** Ger-chervyak has quit IRC | 14:58 | |
*** mgoddard_ has joined #openstack-ansible | 15:01 | |
*** woodard has quit IRC | 15:01 | |
*** fawadkhaliq has joined #openstack-ansible | 15:01 | |
*** galstrom_zzz is now known as galstrom | 15:01 | |
*** mgoddard has quit IRC | 15:04 | |
*** neilus has quit IRC | 15:06 | |
*** javeriak has quit IRC | 15:11 | |
pjm6 | evrardjp: odyssey4me: problem solved :) with the help of a user from openstack-horizon | 15:11 |
pjm6 | what I was using | 15:11 |
pjm6 | def allowed(self, context): | 15:12 |
pjm6 | return get_user_status(context['request'].user.id).status | 15:12 |
pjm6 | in the panel | 15:12 |
pjm6 | instead of self.request.user.id, use context['request'].user.id | 15:12 |
pjm6 | so in this way its possible to manipulate access of a panel with custom permissions :) | 15:12 |
*** Brew has joined #openstack-ansible | 15:13 | |
*** openstackgerrit has quit IRC | 15:18 | |
*** openstackgerrit has joined #openstack-ansible | 15:18 | |
*** fawadkhaliq has quit IRC | 15:18 | |
*** schwicht has quit IRC | 15:19 | |
*** thorst has joined #openstack-ansible | 15:20 | |
*** fawadkhaliq has joined #openstack-ansible | 15:21 | |
evrardjp | pjm6 interesting | 15:22 |
evrardjp | I'd be happy to know more about how you'll add the permissions though | 15:22 |
evrardjp | get | 15:23 |
evrardjp | nevermind | 15:23 |
*** thorst has quit IRC | 15:25 | |
pjm6 | evrardjp: I used that function | 15:31 |
pjm6 | that will return the user status, if True, Panel with appear to user, if False not :D | 15:31 |
pjm6 | (idk if its best solution :\ ) | 15:31 |
odyssey4me | automagically jmccrory logan- I don't know if you guys have some time to work on this, but it may be useful to you. In a test environment with ~120 compute nodes with many instances/networks we found that using these settings took API return time from ~35 secs down to ~6 secs: https://github.com/openstack/openstack-ansible-os_nova/blob/master/defaults/main.yml#L69-L91 | 15:37 |
*** sanjay__u has joined #openstack-ansible | 15:37 | |
odyssey4me | I'd like us to try and figure out some sort of resource-based determined formulae to make those settings scale automatically. | 15:37 |
odyssey4me | ie based on the number of CPU's or the amount of RAM, figure out an appropriate default that makes sense | 15:38 |
automagically | Wow, that’s good to know | 15:38 |
automagically | Do you know if you were more messaging bound, than db bound | 15:38 |
odyssey4me | automagically unfortunately this was done as a quick fix to give access to the environment for other testing, so we'll only be able to look deeper once that testing is done and if we still have access to the resources | 15:39 |
*** admin0 has quit IRC | 15:39 | |
odyssey4me | I'm posting this here in the hope that perhaps we can all dig into it in some time to figure out better defaults and to post reviews to do implement them | 15:40 |
*** jayc has joined #openstack-ansible | 15:40 | |
odyssey4me | oops - I posted the wrong link - these are the settings: https://github.com/rcbops/rpc-openstack/blob/master/rpcd/etc/openstack_deploy/user_variables.yml#L16-L37 | 15:40 |
odyssey4me | I'm not fond of hard settings the var values as it will negatively affect dev/test/AIO environments. I'd prefer something that scales automatically. | 15:41 |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: Adding role convergence test https://review.openstack.org/298916 | 15:47 |
*** fawadkhaliq has quit IRC | 15:47 | |
*** weezS has joined #openstack-ansible | 15:52 | |
michaelgugino | I'm not certain having the variables scaled on some amount is a great solution. Where I've seen that elsewhere, it's really ugly and not at all obvious how an end user should modify the value. | 15:55 |
michaelgugino | I prefer something like the mysql approach, where they offer various config files out of the box; ie small, med, large. | 15:56 |
*** thorst has joined #openstack-ansible | 15:56 | |
odyssey4me | michaelgugino sure, maybe a small/medium/large set of options will work - but I'm not suggesting replacing the exiting override vars | 15:58 |
*** schwicht has joined #openstack-ansible | 15:58 | |
odyssey4me | so the vars are always available to override to a deployers content | 15:58 |
*** mikelk has quit IRC | 15:58 | |
odyssey4me | also, if it's a small/medium/large then it's pretty easy to implement a formula for a default | 15:59 |
odyssey4me | we just need ot figure out the pertinent scaling vars | 15:59 |
openstackgerrit | Matt Thompson proposed openstack/openstack-ansible-security: [WIP] Unattended upgrades https://review.openstack.org/304096 | 16:01 |
*** jayc has quit IRC | 16:07 | |
*** deadnull has quit IRC | 16:08 | |
openstackgerrit | Travis Truman (automagically) proposed openstack/openstack-ansible-os_zaqar: Adding role convergence test https://review.openstack.org/298916 | 16:09 |
*** fishcried has quit IRC | 16:09 | |
*** openstackstatus has joined #openstack-ansible | 16:09 | |
*** ChanServ sets mode: +v openstackstatus | 16:09 | |
*** fishcried1 has joined #openstack-ansible | 16:09 | |
openstackgerrit | Hector I Gonzalez Mendoza proposed openstack/openstack-ansible-os_barbican: Updated role using the Multi-Distro framework https://review.openstack.org/304209 | 16:11 |
*** fishcried1 is now known as fishcried | 16:12 | |
cloudnull | odyssey4me: ping | 16:15 |
cloudnull | https://github.com/openstack/openstack-ansible-ironic/blob/master/tests/test-rest-api.yml | 16:15 |
cloudnull | that set of tests is broken | 16:15 |
*** fawadkhaliq has joined #openstack-ansible | 16:16 | |
cloudnull | its testing the API however providing no creds | 16:16 |
cloudnull | so all the returns are 401 | 16:16 |
*** fawadkhaliq has quit IRC | 16:16 | |
cloudnull | maybe it works in ironic standalone mode but with the addition of keystone in the those tests can not work. | 16:17 |
cloudnull | so should I remove the tests? | 16:17 |
-openstackstatus- NOTICE: Reminder, Gerrit will be offline from 20:00 to 21:00 UTC for a server replacement http://lists.openstack.org/pipermail/openstack-dev/2016-April/091274.html | 16:17 | |
cloudnull | which unblocks the couple of dependent patches we have | 16:18 |
cloudnull | or should i work on fixing them and rebase the deps? | 16:18 |
odyssey4me | cloudnull it's meant to run against a standalone mode implementation | 16:18 |
*** clickboom has quit IRC | 16:19 | |
cloudnull | right but if we add https://github.com/openstack/openstack-ansible-ironic/blob/master/tests/test-install-keystone.yml it no longer works | 16:19 |
cloudnull | and thats because the auth section in the old config was broken | 16:19 |
cloudnull | which we're fixing here https://review.openstack.org/#/c/301712/17/templates/ironic.conf.j2 | 16:20 |
odyssey4me | I've been wondering whether the functional test should perhaps do both a standalone and non-standalone container and validate both, but at this stage I would vote for doing whatever delivers the most value in testing. Perhaps the existing tests should be commented out with a note saying that they will be re-added once a standalone test build is implemented as a functional test? | 16:20 |
cloudnull | the "keystone_authtoken" section did nothing before | 16:20 |
odyssey4me | cloudnull yep, but that was part of my comment - the conf file needs to adapt appropriately based on whether it's standalone or not | 16:21 |
odyssey4me | we can't put values there if there's no infra backing it | 16:21 |
*** jayc has joined #openstack-ansible | 16:21 | |
cloudnull | Do we want that on our first pass ? IMO proper openstack integration should be our first goal. | 16:22 |
cloudnull | which requires functional keystone | 16:22 |
odyssey4me | It may be best to have the functional test implement standalone mode first, then test against it, then implement non-standalone mode and then test again. | 16:22 |
odyssey4me | functional tests with full integration was more of a stretch goal for the role in the first iteration | 16:23 |
odyssey4me | if it can be done, great, but I don't want to negate the existing work | 16:23 |
cloudnull | the issue is wtihout the keystone+swift changes we cant make ironic work in nova | 16:24 |
*** metral_zzz is now known as metral | 16:24 | |
*** schwicht has quit IRC | 16:27 | |
*** schwicht has joined #openstack-ansible | 16:28 | |
*** fawadkhaliq has joined #openstack-ansible | 16:28 | |
*** goretoxo has quit IRC | 16:31 | |
odyssey4me | ok, then we may have to ditch the curl-based API tests and use https://review.openstack.org/303104 instead, which uses the CLI and consumes openrc which should provide the same coverage in a more flexible way | 16:32 |
odyssey4me | ideally we need to test both standalone and non-standalone, but if we're stuck for time/resources then perhaps it'd be better to err on the side of making it work for the integrated build and leaving the standalone test as a stretch goal | 16:33 |
lbragstad | any thoughts as to why https://review.openstack.org/#/c/303592/7/tasks/keystone_ssl_key_create.yml doesn't seem to take the permissions specified in the plays? | 16:37 |
hughsaunders | Bofu2U: would be useful to note the order of galera shutdown | 16:39 |
*** Oku_OS is now known as Oku_OS-away | 16:39 | |
odyssey4me | lbragstad it is odd - I see that some tasks are quoting th evalue, and some are not - that may be significant? maybe quote them all due to the leading zero so that it doesn't get mistaken for an integer | 16:41 |
*** jthorne has quit IRC | 16:41 | |
lbragstad | odyssey4me i'll give that a shot | 16:42 |
*** jthorne has joined #openstack-ansible | 16:42 | |
*** LiftedKilt has joined #openstack-ansible | 16:42 | |
odyssey4me | lbragstad it may be key for the test tasks to also ensure that it's evaluating string versus string | 16:42 |
lbragstad | odyssey4me so - quote it all | 16:43 |
*** jthorne has quit IRC | 16:43 | |
*** jthorne has joined #openstack-ansible | 16:44 | |
openstackgerrit | Lance Bragstad proposed openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 16:44 |
*** elgertam has joined #openstack-ansible | 16:46 | |
openstackgerrit | Merged openstack/openstack-ansible: Add convenience links for install workflow doc https://review.openstack.org/303330 | 16:48 |
*** weezS has quit IRC | 16:48 | |
*** fawadkhaliq has quit IRC | 16:48 | |
*** fawadkhaliq has joined #openstack-ansible | 16:49 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 16:52 |
*** javeriak has joined #openstack-ansible | 16:52 | |
*** admin0 has joined #openstack-ansible | 16:55 | |
*** schwicht has quit IRC | 16:58 | |
automagically | odyssey4me: Care to take a quick review of https://review.openstack.org/#/c/298957/ ? Its almost 2 weeks old and has one +2. | 16:59 |
cloudnull | ++ | 17:00 |
cloudnull | ^ | 17:00 |
odyssey4me | automagically hmm... looking | 17:04 |
odyssey4me | <--- bad at python | 17:04 |
odyssey4me | but, if I read this right, it would mean that none of our plays would ever have to make reference to is_metal unless it's specifically using the var? | 17:04 |
*** fawadkhaliq has quit IRC | 17:06 | |
automagically | odyssey4me: I believe its used elsewhere in other functions, just not within that one | 17:06 |
odyssey4me | oh I see | 17:06 |
odyssey4me | so this is simply just removing an option that's never used | 17:06 |
stevelle | do we have known issues right now? | 17:06 |
automagically | Exactly | 17:06 |
odyssey4me | how sure are we that this is never used? | 17:06 |
odyssey4me | ie does this affect any env.d files where the variable is changed? | 17:06 |
cloudnull | test passed :) | 17:06 |
automagically | cloudnull: ++ | 17:07 |
* cloudnull is a helper | 17:07 | |
automagically | But yes, the AIO and inventory unit tests passed | 17:07 |
odyssey4me | well, the test would pass for cinder-volume inside or outside a container - it would just perform poorly and have horrible side-effects in production | 17:07 |
automagically | The function scope is ~30 lines and only a single caller, so it was easy to see | 17:07 |
automagically | odyssey4me: True dat | 17:08 |
odyssey4me | I don't have enough understanding of the context in which that's used to make an educated call, and I need to run off to catch a train. | 17:09 |
automagically | np, have a good night | 17:09 |
odyssey4me | maybe stevelle or jmccrory can take a peek at it? | 17:09 |
*** fawadkhaliq has joined #openstack-ansible | 17:09 | |
*** pjm6 has quit IRC | 17:09 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible: Fixing idempotency bug hitted while running successive bootstrap aios https://review.openstack.org/304227 | 17:10 |
automagically | stevelle and jmccrory https://review.openstack.org/#/c/298957/ if you have a moment. Trying to keep it from sitting out there in the queue for longer than 2 weeks | 17:10 |
stevelle | automagically: so the fact that I cannot get an aio to build is blocking me from verifying things | 17:10 |
automagically | Fair enough | 17:10 |
stevelle | I don't understand how we are gating | 17:10 |
odyssey4me | I'm firing up an AIO while on the train, so I'll bring it in and try it out to validate - just in case no-one else gets there first. | 17:11 |
*** schwicht has joined #openstack-ansible | 17:11 | |
cloudnull | stevelle: whats it failing on ? | 17:11 |
automagically | stevelle: You talking about master? | 17:11 |
stevelle | master, yes. bootstrap-aio is laying down a /etc/openstack_deploy/user_conf_files.yml that isn't valid right now | 17:11 |
odyssey4me | stevelle that's what evrardjp just put a patch in for: https://review.openstack.org/304227 | 17:12 |
odyssey4me | but you can delete the file and hit the bootstrap again | 17:12 |
stevelle | this is why I asked about known issues | 17:12 |
odyssey4me | this wasn't known until 5 mins ago :) | 17:12 |
odyssey4me | ok, lemme relocate | 17:13 |
cloudnull | ah, i wouldve never his that | 17:13 |
evrardjp | :) | 17:13 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Fix idempotency bug in AIO bootstrap https://review.openstack.org/304227 | 17:14 |
*** Gayathri has joined #openstack-ansible | 17:14 | |
odyssey4me | ^ just a quick commit subject fix :) | 17:14 |
*** clickboom has joined #openstack-ansible | 17:15 | |
Gayathri | Hi guyz.. I m trying to install ceilometer using OSA.. I hav created mongo db and did the configurations in conf.d/ceilometer.yaml..When I install it using os_ceilometer.yaml I did not get any error.. It ran successfully.. | 17:16 |
*** mgoddard has joined #openstack-ansible | 17:16 | |
*** mgoddard_ has quit IRC | 17:17 | |
Gayathri | For the verification part, I logged into utility container and gave the command ceilometer meter-list | 17:17 |
Gayathri | it shows service unavailable(503) | 17:17 |
Gayathri | no errors in the logs | 17:17 |
Gayathri | whats gone wrong?Can anybody help out | 17:17 |
cloudnull | is this a deployment where you hadn't deployed celiometer before ? | 17:18 |
Gayathri | yeah | 17:18 |
cloudnull | maybe you need to re-execute the haproxy play to ensure the correct conf is in place? | 17:19 |
* cloudnull is assuming you have hap | 17:19 | |
Gayathri | yeah.. I have haproxy | 17:19 |
Gayathri | I ran haproxy and installed all the service one by one..when i tried ceilometer m facing this issue | 17:19 |
cloudnull | can you login to the ceilo api containers ? | 17:21 |
cloudnull | is the service running ? | 17:21 |
Gayathri | yeah | 17:21 |
cloudnull | anything notable in the logs ? | 17:21 |
Gayathri | yes the service is running | 17:21 |
Gayathri | in api container.. i checkd for the logs also.. I din get any error | 17:21 |
cloudnull | does ``curl $CEILO_IP_ADDRESS:8777`` work | 17:22 |
Gayathri | let me check and tell you | 17:22 |
openstackgerrit | Michael Gugino proposed openstack/openstack-ansible: Fix missing bool haproxy_use_keepalived https://review.openstack.org/304231 | 17:23 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 17:24 |
LiftedKilt | are there plans to support lxd in ubuntu server 16.04? | 17:25 |
*** pjm6 has joined #openstack-ansible | 17:25 | |
lbragstad | odyssey4me doesn't look like it failed the tests that were introduced in the commit - https://review.openstack.org/#/c/303592/8 | 17:29 |
lbragstad | so your suggestion about strings versus ints must have done the trick | 17:29 |
cloudnull | LiftedKilt: i want to say yes. | 17:29 |
cloudnull | and a few folks have looked into lxd in the path | 17:30 |
cloudnull | *past | 17:30 |
cloudnull | --cc palendae | 17:30 |
cloudnull | personally i've not played with it in a bit but it'd be neat to have it as an option | 17:30 |
cloudnull | LiftedKilt: why do you ask ? | 17:30 |
cloudnull | interested in working on LXD integration ? | 17:31 |
LiftedKilt | cloudnull: I need it for our openstack deployment | 17:31 |
LiftedKilt | I need lxd and I'm reasonably sure that I need calico networks integration as well | 17:32 |
cloudnull | project calico is interesting | 17:33 |
cloudnull | there are a couple folks using it with OSA currently | 17:33 |
cloudnull | though I dont have any documentation on how to make it go at this point. | 17:33 |
cloudnull | logan-: didnt you do some calico work ? | 17:33 |
LiftedKilt | I've got a 1500 node deployment on a layer2 fabric, each running full system openvz containers, managed with homegrown bash scripts. I inherited this nightmare, and want to move to openstack | 17:33 |
* cloudnull may be remember things wrong | 17:33 | |
cloudnull | that does sound like a virtuozzo nightmare | 17:34 |
cloudnull | we currently work w/ lxc and have libs in ansible to make all that go. | 17:34 |
cloudnull | our control plain is lxc containers. | 17:35 |
LiftedKilt | I started playing with mirantis fuel, but everything was too out of date. Then I looked at juju, but I'm hesitant to trust juju with that many nodes | 17:35 |
cloudnull | did you want to do LXD as a hypervisor ? | 17:35 |
LiftedKilt | cloudnull: yes | 17:35 |
cloudnull | ah, i was going the other way :) | 17:35 |
cloudnull | LXD integration in nova shouldnt be too hard. | 17:36 |
LiftedKilt | cloudnull: assuming logan- is the same logan as this, then it looks like he's been working on calico https://github.com/Logan2211/ansible-calico | 17:36 |
*** weezS has joined #openstack-ansible | 17:36 | |
cloudnull | potentially? | 17:36 |
LiftedKilt | cloudnull: awesome - I wasn't sure, because I'd read something about it being restricted to the ubuntu version of openstack | 17:36 |
cloudnull | yea i think so . looking at the github account | 17:37 |
LiftedKilt | something about them submitting it and getting rejected | 17:37 |
cloudnull | yea that happened | 17:37 |
cloudnull | https://linuxcontainers.org/lxd/getting-started-openstack/ -- though you'd likely want to find the source and install from there, instead of deploying their apt package. | 17:38 |
*** jayc has quit IRC | 17:38 | |
cloudnull | https://github.com/lxc/nova-lxd | 17:38 |
LiftedKilt | cloudnull: that looks like a great start - thanks so much | 17:40 |
LiftedKilt | cloudnull: when I watched your talk from the vancouver summit on openstack-ansible and you mentioned that there was great support in the openstack-ansible irc channel I didn't know it meant you would personally be answering questions haha | 17:41 |
michaelgugino | I've been working with 16.04 for the last week or so. lxc is going smoothly so far | 17:41 |
cloudnull | looks like nova-lxd is a fairly straight forward py app. if you add that repo+sha to https://github.com/openstack/openstack-ansible/blob/master/playbooks/defaults/repo_packages/openstack_services.yml and then set the package using the eggname (nova-lxd) here https://github.com/openstack/openstack-ansible-os_nova/blob/master/defaults/main.yml#L383 it should be fairly close to usable once you get the config bits sorted. | 17:42 |
cloudnull | hahhaa. | 17:42 |
cloudnull | welcome :) | 17:42 |
cloudnull | michaelgugino: awesome! | 17:42 |
cloudnull | how is their current systemd inplementation ? | 17:42 |
*** admin0 has quit IRC | 17:42 | |
cloudnull | im hoping its not all kinds of crazy buggy . | 17:42 |
michaelgugino | seems to work flawlessly out of the box on 16.04. I haven't had to do anything to get the containers spun up | 17:43 |
cloudnull | was it included for your install? | 17:43 |
michaelgugino | yes, lxc and lxd are installed in the default server release on 16.04 | 17:43 |
cloudnull | i tested it a bit when i saw this issue https://bugs.launchpad.net/ubuntu/+source/ubuntu-meta/+bug/1563026 -- but have not really dove into 1604 quite yet | 17:43 |
openstack | Launchpad bug 1563026 in ubuntu-meta (Ubuntu) "LXC/LXD installed by default on Ubuntu server" [Wishlist,Opinion] - Assigned to Dustin Kirkland (kirkland) | 17:43 |
odyssey4me | michaelgugino I expect that you're using Xenial on the host only at this stage, with the container image still being trusty? | 17:44 |
*** schwicht has quit IRC | 17:44 | |
michaelgugino | no, xenial hosting xenial | 17:44 |
cloudnull | sweet! | 17:44 |
michaelgugino | running lxc_containers_create play works well | 17:44 |
*** schwicht has joined #openstack-ansible | 17:45 | |
michaelgugino | https://github.com/michaelgugino/openstack-ansible-lxc_container_create/commit/6eb6a8dfbe47569d5cf708a7d2ca4c08fb569177 | 17:45 |
michaelgugino | the only issue I have run into is lxc_hosts | 17:45 |
cloudnull | because of the upstart bits, likely ? | 17:45 |
michaelgugino | I just commented out all the cache stuff. I plan on baking the host keys into the lxc_container_create script, since RPC is not hosting xenial images | 17:45 |
*** TheIntern has joined #openstack-ansible | 17:46 | |
cloudnull | so disk-image-builder can do bare images, i wonder if we might be able to use it to create our base image. | 17:46 |
michaelgugino | ideally, I'd like to see lxc_hosts go away as far as the container cache goes, or at least a massive refactor on how that is done | 17:46 |
cloudnull | then we wouldn’t need to rely on some external repo to have a base image available and us munge it about . | 17:47 |
cloudnull | michaelgugino: ++ | 17:47 |
cloudnull | its functional now, but I think it could be a lot better. | 17:47 |
michaelgugino | yeah, it's really painful right now. lxd ships 'lxc remote' command which lets you connect to an lxd agent seemlessly. Perhaps we should backport lxc 2.0 to 14.04 | 17:48 |
odyssey4me | oh neat, we can get an experimental job added for Xenial testsing - I'll see if I can get that done tonight | 17:48 |
cloudnull | that'd be nice | 17:49 |
cloudnull | getting lxc 2.0 in 14.04 | 17:49 |
odyssey4me | michaelgugino yeah, we've been wanting to revamp the container build process for two cycles | 17:49 |
odyssey4me | it's just never managed to get completely done | 17:49 |
michaelgugino | if we're going to hit multi-distro / 16.04 in newton, then the container build process has to happen. | 17:49 |
*** jayc has joined #openstack-ansible | 17:50 | |
cloudnull | i did a POC role a while back for multi distro container images https://github.com/os-cloud/lxc_image_cache | 17:50 |
odyssey4me | michaelgugino if you have a gap and inclination, I worked on https://review.openstack.org/272743 to make the build of the image transparent | 17:50 |
cloudnull | which will create an image cache / repo | 17:50 |
cloudnull | but never did much with it | 17:50 |
odyssey4me | and yeah, cloudnull did some extra stuff on top of that a while back | 17:50 |
*** Gayathri has quit IRC | 17:51 | |
michaelgugino | I'll check those out | 17:51 |
*** admin0 has joined #openstack-ansible | 17:52 | |
jmccrory | mancdaz: were you also seeing issues with galera restarts outside of the role's gate testing? | 17:53 |
admin0 | hello all .. https://review.openstack.org/#/c/303427/ — how do I fix a patch-in-merge-conflict ? | 17:53 |
admin0 | or it is something beyond me and i need to wait ? | 17:53 |
*** javeriak has quit IRC | 17:54 | |
automagically | admin0 - Fetch it local with git review -d and rebase it and fix the conflict | 17:54 |
automagically | Then submit your changes | 17:54 |
admin0 | ok | 17:54 |
admin0 | i will do that | 17:54 |
admin0 | and for the other one — https://review.openstack.org/#/c/301922/ which I see +1 +1 and no further followups, is there something more I need to do ? | 17:55 |
*** flaviosr has quit IRC | 17:56 | |
openstackgerrit | Sashi Dahal proposed openstack/openstack-ansible: make hostname,network and ip-address on all examples consistent https://review.openstack.org/303427 | 17:57 |
*** flaviosr has joined #openstack-ansible | 17:57 | |
admin0 | i did not see anything special .. so did the review/rebase and submitted again | 17:57 |
openstackgerrit | Michael Gugino proposed openstack/openstack-ansible: Fix missing bool haproxy_use_keepalived https://review.openstack.org/304231 | 17:59 |
*** alejandrito has joined #openstack-ansible | 17:59 | |
*** eil397 has joined #openstack-ansible | 18:04 | |
cloudnull | admin0: nothing to do there. just need to get a couple of folks to review the bits | 18:09 |
*** TheIntern has quit IRC | 18:09 | |
cloudnull | i'll add it to my queue, but may be a day or so | 18:10 |
logan- | cloudnull: yes @ calico | 18:11 |
cloudnull | hows that going btw | 18:11 |
cloudnull | i read the other day that calico no longer needs forked services. is that right ? | 18:11 |
cloudnull | maybe we can add it into the neutron role for broader inclusion ? | 18:12 |
logan- | that is correct, as of liberty it is a neutron networking driver | 18:12 |
logan- | it is going ok.. just fighting with blade switching modules atm holding up launch :( | 18:12 |
cloudnull | thats awesome ! | 18:12 |
cloudnull | buu... blades... | 18:12 |
logan- | i have a liberty branch w/ calico integration here: https://github.com/logan2211/openstack-ansible/tree/liberty-calico | 18:12 |
cloudnull | LiftedKilt: ^ | 18:12 |
logan- | it is not too hard to do. just a few extra containers needed on the controller for etcd servers | 18:12 |
cloudnull | awesome! | 18:13 |
logan- | and some extra python packages | 18:13 |
cloudnull | I'd be keen on seeing that get into the mainline. | 18:13 |
logan- | yeah I am hoping to get that done this cycle | 18:13 |
cloudnull | sweet ! | 18:13 |
*** tricksters is now known as elopez | 18:14 | |
*** elopez is now known as eric_lopez | 18:15 | |
cloudnull | thanks for sharing that repo logan- LiftedKilt was talking about calico earlier. so may be of some immediate use . | 18:15 |
*** sdake has joined #openstack-ansible | 18:18 | |
logan- | yea was just reading the back log.. LiftedKilt, I think that should be pretty complete for liberty even though there are no commits lately. if you decide to try it let me know if you run into any problems and I'll be happy to help. it could use a rebase.. I'll see if I can get to it soon | 18:19 |
openstackgerrit | Sashi Dahal proposed openstack/openstack-ansible: make hostname,network and ip-address on all examples consistent https://review.openstack.org/303427 | 18:19 |
*** fawadkhaliq has quit IRC | 18:20 | |
*** fawadkhaliq has joined #openstack-ansible | 18:21 | |
LiftedKilt | logan- cloudnull: I'm getting my feet wet on an AIO install on 14.04 with base config just to play with the playbooks and whatnot, and then I will dive into the calico portion. Thanks a lot to both of you guys for all your input. I really appreciate it | 18:26 |
cloudnull | ++ ping w/ questions. have fun | 18:28 |
cloudnull | LiftedKilt: im assuming youve seen http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html ? | 18:29 |
LiftedKilt | cloudnull: yes - I'm in the midst of the run-playbooks | 18:30 |
cloudnull | cool | 18:30 |
*** admin0 has quit IRC | 18:30 | |
cloudnull | just make sure :) | 18:30 |
LiftedKilt | cloudnull: as an odd note, the first time I ran the boostrap-aio.sh script, it wiped the urls from the apt sources.list file | 18:31 |
cloudnull | hum. | 18:31 |
*** jayc_ has joined #openstack-ansible | 18:31 | |
LiftedKilt | I just put them back in manually, but somewhere the script I'm assuming has an option for configuring alternative sources and repleced the sources with null | 18:32 |
cloudnull | when i do AIO work i generally will build vm, clone repo, fire up tmux and then run scripts/gate-check-commit.sh | 18:32 |
cloudnull | that script will setup the env like our gate job and i go from there. | 18:32 |
*** jayc has quit IRC | 18:32 | |
cloudnull | its quite possible that is the case | 18:32 |
LiftedKilt | I deployed a clean machine from maas, ssh'd in and started from there | 18:32 |
* cloudnull hasnt looked into the aio in a bit | 18:32 | |
openstackgerrit | Lance Bragstad proposed openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 18:32 |
*** jayc_ is now known as jayc | 18:33 | |
cloudnull | if you have nodes, you can give https://github.com/cloudnull/osa-multi-node-aio a go , which is what i do dev on for the most part. | 18:33 |
*** fawadkhaliq has quit IRC | 18:33 | |
cloudnull | its a single node, but builds a 14 node cloud env | 18:33 |
cloudnull | using kvm and such | 18:33 |
*** fawadkhaliq has joined #openstack-ansible | 18:34 | |
cloudnull | that said, im getting ahead of myself, its likely best to start out with an AIO and go from there. | 18:34 |
LiftedKilt | 14 nodes on these machines sounds like a terrible idea haha | 18:34 |
LiftedKilt | cloudnull: they are whitebox 1Us | 18:34 |
cloudnull | hahahaha | 18:34 |
cloudnull | oh. | 18:34 |
LiftedKilt | 32gb of ram, gig networking, off the shelf midrange xeon | 18:34 |
openstackgerrit | Merged openstack/openstack-ansible: Removing unneeded is_metal param from user_defined_setup https://review.openstack.org/298957 | 18:34 |
LiftedKilt | 1tb ssd though, so that's something at least | 18:35 |
cloudnull | SYNNEX? | 18:35 |
cloudnull | I have a loath / hate relationship with those whiteboxes :) | 18:35 |
LiftedKilt | no these bad boys are built in house | 18:36 |
cloudnull | that sounds like a good time | 18:37 |
LiftedKilt | management found some discount imported 1U chassis company, and we buy atx boards and components in bulk and assemble ourselves | 18:37 |
LiftedKilt | yeah it's a blast | 18:37 |
LiftedKilt | welcome to Liferay haha | 18:38 |
cloudnull | im sure its a good time -- rackin' servers can be relaxing ;) | 18:38 |
*** rohanp has joined #openstack-ansible | 18:38 | |
palendae | cloudnull: I haven't actually looked in depth at LXD | 18:39 |
*** admin0 has joined #openstack-ansible | 18:40 | |
*** admin0 has quit IRC | 18:40 | |
openstackgerrit | Merged openstack/openstack-ansible-repo_build: update repo-build for ansible 2.1 compat https://review.openstack.org/299689 | 18:46 |
cloudnull | one more ansible 2.x compat change and we're good to go w/ 2.1. at this point https://review.openstack.org/#/c/299685/ | 18:48 |
*** admin0 has joined #openstack-ansible | 18:55 | |
openstackgerrit | Hector I Gonzalez Mendoza proposed openstack/openstack-ansible-os_designate: Updated role using the Multi-Distro framework https://review.openstack.org/304291 | 18:56 |
spotz | Ok when were you guys going to tell me I was moderating a session?:) | 18:56 |
lbragstad | cloudnull finally got a pass https://review.openstack.org/#/c/303592/9 | 18:56 |
lbragstad | https://media.giphy.com/media/5wWf7Hh2za2PyRZuDtu/giphy.gif | 18:56 |
admin0 | question: https://review.openstack.org/#/c/303427/ — can I now add other pages ( all pages ) making the hostname and ip consistent ( into this same review ) .. or wait for this to get merged and then do the othe rone ? | 18:57 |
admin0 | *other ones | 18:58 |
openstackgerrit | Merged openstack/openstack-ansible: Remove local swift ring directory check https://review.openstack.org/280844 | 18:58 |
automagically | Nice work lbragstad | 18:59 |
lbragstad | automagically o/ | 19:00 |
*** agireud has quit IRC | 19:00 | |
*** yarkot_ has joined #openstack-ansible | 19:00 | |
*** schwicht_ has joined #openstack-ansible | 19:01 | |
*** schwicht has quit IRC | 19:01 | |
*** agireud has joined #openstack-ansible | 19:01 | |
cloudnull | lbragstad: awesome! | 19:03 |
lbragstad | cloudnull automagically thanks for the reviews! | 19:04 |
cloudnull | admin0: you can do all of them , do them as separate commits making them be dependent on one another | 19:04 |
admin0 | and later squash them ? | 19:05 |
LiftedKilt | d34dp@@l | 19:05 |
admin0 | you know, i went into this wierd thing when i tried to do that | 19:05 |
admin0 | wrong paste window LiftedKilt | 19:05 |
admin0 | now you know your bank pass :D | 19:05 |
LiftedKilt | nah - I justwanted you guys to feel free to hop into my lab haha | 19:05 |
*** clickboom has quit IRC | 19:06 | |
LiftedKilt | admin0: I do that at least once a week - thinking that I'm logging into my dev vm | 19:07 |
*** Brew has quit IRC | 19:10 | |
*** Brew has joined #openstack-ansible | 19:10 | |
*** clickboom has joined #openstack-ansible | 19:15 | |
*** schwicht_ has quit IRC | 19:17 | |
*** schwicht has joined #openstack-ansible | 19:19 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone: Use ansible facts for distributing SSL certs/keys https://review.openstack.org/303592 | 19:22 |
*** falanx has joined #openstack-ansible | 19:22 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 19:24 |
*** michaelgugino has quit IRC | 19:24 | |
cloudnull | LiftedKilt: i thought you we're trying to ping d34dh0r53 :) | 19:25 |
*** sanjay__u has quit IRC | 19:29 | |
LiftedKilt | cloudnull: I mean yeah... that's totally what I meant to do | 19:32 |
*** schwicht has quit IRC | 19:34 | |
*** schwicht has joined #openstack-ansible | 19:35 | |
*** pjm6 has quit IRC | 19:35 | |
cloudnull | odyssey4me: https://review.openstack.org/#/c/301712/ fixed the broken tests. will work in stand alone or integrated mode | 19:38 |
*** fawadkhaliq has quit IRC | 19:39 | |
*** fawadkhaliq has joined #openstack-ansible | 19:40 | |
*** schwicht_ has joined #openstack-ansible | 19:41 | |
*** schwicht has quit IRC | 19:41 | |
-openstackstatus- NOTICE: Gerrit will be offline from 20:00 to 21:00 UTC (starting 10 minutes from now) for a server replacement http://lists.openstack.org/pipermail/openstack-dev/2016-April/091274.html | 19:49 | |
*** fawadkhaliq has quit IRC | 19:51 | |
*** fawadkhaliq has joined #openstack-ansible | 19:51 | |
*** fawadkhaliq has quit IRC | 19:54 | |
*** fawadkhaliq has joined #openstack-ansible | 19:55 | |
*** elgertam has quit IRC | 19:56 | |
openstackgerrit | Flávio Ramalho proposed openstack/openstack-ansible-os_neutron: Fix missing 'qos' in extension drivers https://review.openstack.org/304305 | 20:00 |
*** clickboom has quit IRC | 20:00 | |
*** automagically has quit IRC | 20:01 | |
-openstackstatus- NOTICE: Gerrit is offline until 21:00 UTC for a server replacement http://lists.openstack.org/pipermail/openstack-dev/2016-April/091274.html | 20:04 | |
*** ChanServ changes topic to "Gerrit is offline until 21:00 UTC for a server replacement http://lists.openstack.org/pipermail/openstack-dev/2016-April/091274.html" | 20:04 | |
*** admin0 has quit IRC | 20:04 | |
*** openstackgerrit has quit IRC | 20:05 | |
*** yarkot_ has quit IRC | 20:09 | |
*** Bjoern_ is now known as BjoernT | 20:13 | |
*** schwicht has joined #openstack-ansible | 20:13 | |
*** schwicht_ has quit IRC | 20:13 | |
*** phalmos has joined #openstack-ansible | 20:16 | |
*** automagically has joined #openstack-ansible | 20:18 | |
*** johnmilton has quit IRC | 20:18 | |
*** schwicht_ has joined #openstack-ansible | 20:20 | |
*** schwicht has quit IRC | 20:20 | |
*** openstackgerrit has joined #openstack-ansible | 20:27 | |
*** alejandrito has quit IRC | 20:30 | |
*** alejandrito has joined #openstack-ansible | 20:37 | |
*** openstackgerrit has quit IRC | 20:41 | |
*** grumpycatt has quit IRC | 20:43 | |
odyssey4me | LiftedKilt the AIO will grab the hosts's sources.list hosts, then rebuild the sources.list with all the required bits. | 20:44 |
spotz | odyssey4me - being that you're up are there any details for the session you put me down for moderating?:) | 20:45 |
odyssey4me | spotz haha, I thought you wanted to moderate it? | 20:46 |
LiftedKilt | odyssey4me: It failed when I ran the run-playbooks and I had to manually put in the archive.ubuntu.com urls | 20:46 |
odyssey4me | if you'd prefer I can do so - but I thought you'd want to give it a go | 20:46 |
spotz | I can do it, just need to know what I'm supposed to cover | 20:47 |
odyssey4me | LiftedKilt the bootstrap-aio process will do it - so if that didn't work then it may have been because the awk that grabs the host didn't work for your host | 20:47 |
spotz | I only found out cause I was looking for my conflicts. Why are all the good ones on Monday at 11:15? I didn't think I had conflicts until Wednesday | 20:47 |
LiftedKilt | odyssey4me: ok - it wasn't a big deal either way, just thought I'd mention it | 20:47 |
odyssey4me | LiftedKilt otherwise look at the customised options in http://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html#building-an-aio | 20:48 |
odyssey4me | the options are https://github.com/openstack/openstack-ansible/blob/master/tests/roles/bootstrap-host/defaults/main.yml#L99-L102 | 20:48 |
odyssey4me | the awk that picks up the hosts is here: https://github.com/openstack/openstack-ansible/blob/master/tests/roles/bootstrap-host/tasks/install-apt.yml#L29-L36 | 20:48 |
*** schwicht_ has quit IRC | 20:51 | |
*** openstackgerrit has joined #openstack-ansible | 20:55 | |
*** schwicht has joined #openstack-ansible | 20:56 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Remove global-requirements build from the build process https://review.openstack.org/300589 | 20:56 |
odyssey4me | automagically cloudnull ^ that's a rebase after the merge conflict | 20:57 |
spotz | I think the gerrit web portal is down:( | 20:57 |
*** Mudpuppy has quit IRC | 20:58 | |
stevelle | until 21:00 UTC for a server replacement | 20:58 |
odyssey4me | spotz if possible, I'd like us to discuss any thoughts on having the documentation details done in the roles and to leave the install guide to be a fast path to a generally decent install which leaves many of the defaults in play - so basically the install guide shouldn't cover too many options, whereas the role docs should provide all the options and contain details of how things fit together | 20:59 |
*** johnmilton has joined #openstack-ansible | 20:59 | |
odyssey4me | altnernatively, we can just discuss any thoughts you have on improving the docs generally and how we can cover more of the details in the roles | 20:59 |
*** schwicht has quit IRC | 21:00 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-ironic: updated Ironic role to fix tftp-hpa issues https://review.openstack.org/303633 | 21:01 |
*** weshay has quit IRC | 21:03 | |
*** johnmilton has quit IRC | 21:03 | |
*** ChanServ changes topic to "Austin Design Summit Schedule: https://goo.gl/WSRblf || Launchpad: https://launchpad.net/openstack-ansible || Weekly Meetings: https://wiki.openstack.org/wiki/Meetings/openstack-ansible || Review Dashboard: https://goo.gl/tTmdgs" | 21:03 | |
-openstackstatus- NOTICE: Gerrit move maintenance completed successfully; note that DNS has been updated to new IP addresses as indicated in http://lists.openstack.org/pipermail/openstack-dev/2016-April/091274.html | 21:04 | |
spotz | odyssey4me - so ultimately the install guide should be streamlined and then have links to the role docs for more detailed drill down? | 21:04 |
odyssey4me | spotz that's my suggestion | 21:05 |
odyssey4me | if possible I'd like you to take a look at that suggestion and see if you can make it work, or have alternative suggestions | 21:05 |
mrda | Morning OSA | 21:05 |
spotz | hey mrda | 21:05 |
odyssey4me | spotz something like this uniformly applied to all roles is a great start: http://docs.openstack.org/developer/openstack-ansible-os_keystone/ | 21:06 |
mrda | o/ | 21:06 |
odyssey4me | but I thought that perhaps the way the functional tests are designed to run could be added as additional documentation to illustrate how to use the role | 21:06 |
*** weezS has quit IRC | 21:07 | |
spotz | Sounds good odyssey4me. It'll definitely be cleaner for people not wanting to do customized installs. I'll plan it out | 21:07 |
odyssey4me | thanks! :) | 21:07 |
*** fawadkhaliq has quit IRC | 21:10 | |
*** fawadkhaliq has joined #openstack-ansible | 21:10 | |
openstackgerrit | Merged openstack/openstack-ansible-plugins: Update py_pkgs.py to support ansible v2.1 https://review.openstack.org/299685 | 21:10 |
*** fawadkhaliq has quit IRC | 21:11 | |
*** schwicht has joined #openstack-ansible | 21:11 | |
*** fawadkhaliq has joined #openstack-ansible | 21:12 | |
*** schwicht has quit IRC | 21:16 | |
*** eil397 has left #openstack-ansible | 21:16 | |
*** schwicht has joined #openstack-ansible | 21:23 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Remove global-requirements build from the build process https://review.openstack.org/300589 | 21:25 |
*** fawadkhaliq has quit IRC | 21:26 | |
*** fawadkhaliq has joined #openstack-ansible | 21:26 | |
*** schwicht has quit IRC | 21:28 | |
odyssey4me | cloudnull I think you may have done the rename incorrectly in https://review.openstack.org/303633 - and the template task doesn't refer to the template file | 21:31 |
*** admin0 has joined #openstack-ansible | 21:32 | |
*** schwicht has joined #openstack-ansible | 21:36 | |
odyssey4me | jmccrory automagically cloudnull d34dh0r53 stevelle mattt hughsaunders andymccr can we please get another review on https://review.openstack.org/303770 ? | 21:36 |
*** schwicht has quit IRC | 21:40 | |
odyssey4me | automagically stevelle ok, https://review.openstack.org/300589 has been properly rebased now | 21:42 |
*** admin0 has quit IRC | 21:43 | |
*** schwicht has joined #openstack-ansible | 21:46 | |
*** schwicht has quit IRC | 21:50 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: updated Ironic role to fix tftp-hpa issues https://review.openstack.org/303633 | 21:51 |
odyssey4me | cloudnull the template file name is wrong - the actual file name | 21:52 |
cloudnull | ah i see it now | 21:52 |
* cloudnull needs better glasses | 21:53 | |
odyssey4me | ie execute 'mv templates/tftpf-hpa.j2 templates/tftpfd-hpa.j2' :) | 21:53 |
*** schwicht has joined #openstack-ansible | 21:53 | |
*** b3rnard0 is now known as b3rnard0_away | 21:54 | |
*** busterswt has quit IRC | 21:54 | |
*** elgertam has joined #openstack-ansible | 21:55 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: updated Ironic role to fix tftp-hpa issues https://review.openstack.org/303633 | 21:56 |
odyssey4me | that looks better :) | 21:57 |
cloudnull | i went to the school for kids who can't read good | 21:57 |
cloudnull | :p | 21:57 |
*** elgertam has quit IRC | 22:00 | |
*** Brew has quit IRC | 22:03 | |
odyssey4me | cloudnull if you would hazard a guess at where the limits lie in terms of RPC connections, would you think it's limited based on #CPU's or #RAM ? | 22:09 |
*** schwicht has quit IRC | 22:09 | |
*** alejandrito has quit IRC | 22:11 | |
cloudnull | ram | 22:12 |
odyssey4me | and DB connections? | 22:13 |
cloudnull | ram | 22:13 |
cloudnull | :) | 22:13 |
odyssey4me | yeah, I'm inclined to agree | 22:13 |
cloudnull | we generally use cpu because its easy math and produces round numbers. | 22:13 |
cloudnull | but ram is the answer. IMO | 22:14 |
openstackgerrit | Ala Raddaoui proposed openstack/openstack-ansible: modify how services are configured in haproxy https://review.openstack.org/301343 | 22:15 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_aodh: Updated role using the Multi-Distro framework https://review.openstack.org/295620 | 22:16 |
*** raddaoui has joined #openstack-ansible | 22:16 | |
cloudnull | raddaoui: ++ great update! -- adding to review q | 22:17 |
raddaoui | thanks cloudnull | 22:19 |
*** schwicht has joined #openstack-ansible | 22:24 | |
*** galstrom is now known as galstrom_zzz | 22:31 | |
*** phalmos has quit IRC | 22:32 | |
*** thorst has quit IRC | 22:33 | |
*** thorst has joined #openstack-ansible | 22:33 | |
*** markvoelker has quit IRC | 22:33 | |
*** automagically has quit IRC | 22:34 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Update ansible to the latest release (v1.9.5-1) https://review.openstack.org/296839 | 22:34 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Add condition to local IP for overlay net https://review.openstack.org/273793 | 22:36 |
*** asettle has joined #openstack-ansible | 22:36 | |
openstackgerrit | Steve Lewis (stevelle) proposed openstack/openstack-ansible-os_gnocchi: Enabling bashate and pep8 lint checks https://review.openstack.org/304328 | 22:37 |
cloudnull | mhayden logan- automagically odyssey4me i'd like to discuss https://review.openstack.org/#/c/277199/ | 22:37 |
cloudnull | if you have a moment | 22:37 |
cloudnull | thats something I'd like to see in giving us the proper ability to ssl on just about everything | 22:38 |
*** thorst has quit IRC | 22:38 | |
odyssey4me | yup, agreed | 22:38 |
cloudnull | however for the purposes of the gate, im inclined to say we only terminate | 22:38 |
cloudnull | thoughts? | 22:38 |
odyssey4me | what do you mean? | 22:39 |
cloudnull | terminate at the lb only | 22:39 |
odyssey4me | I would suggest that we only setup the public interface with https, terminated on the LB. | 22:39 |
odyssey4me | we should leave the internals without HTTPS | 22:39 |
odyssey4me | internal/admin | 22:39 |
cloudnull | right now we have https://review.openstack.org/#/c/277199/19/playbooks/inventory/group_vars/hosts.yml | 22:39 |
cloudnull | which enables it for all the things | 22:39 |
cloudnull | so im saying set that to false generally and enable it for public termination only | 22:40 |
logan- | i think that just turns on the handler right? | 22:40 |
cloudnull | i guess odyssey4me and i are saying the same thing :) | 22:40 |
logan- | the haproxy settings actually control the ssl on/off switches | 22:40 |
cloudnull | yes | 22:40 |
odyssey4me | yeah, I agree - just public | 22:40 |
cloudnull | kk. | 22:40 |
odyssey4me | we do need to understand whether internal SSL termination is important and whether we should cater for it too | 22:40 |
logan- | but yea public only is what i'm doing--and i'd imagine most do the same | 22:41 |
cloudnull | so then im going to write that up in reno, rebase the patch, and go from there | 22:41 |
odyssey4me | ie SSL to the LB, then SSL from the LB to Keystone (for instance) - mhayden is that a requirement ? | 22:41 |
odyssey4me | if it's not a requirement, then we can strip some of the internal logic out of it - we're doing quite a bit of funky stuff to cater for that with keystone | 22:42 |
cloudnull | i also need to back this out https://review.openstack.org/#/c/277199/18/tests/roles/bootstrap-host/templates/user_variables.aio.yml.j2 | 22:42 |
cloudnull | so it only effects public | 22:42 |
*** spotz is now known as spotz_zzz | 22:42 | |
odyssey4me | yeah, to my knowledge most environments want https on the public endpoints and are happy with not having it on internal endpoints | 22:43 |
logan- | is the intent to actually get public-only ssl term in the default setup? because theres a lot of haproxy configuration left to do in that review if thats the case | 22:43 |
cloudnull | ++ thats been common in the deployments i've done | 22:43 |
odyssey4me | logan- it should still be opt-in, but we want to enable it by default in the gate tests | 22:44 |
logan- | ah | 22:44 |
odyssey4me | so yeah, if more needs to be done then comments in the review should be added | 22:44 |
odyssey4me | or patches elsewhere | 22:44 |
*** schwicht has quit IRC | 22:45 | |
*** jthorne has quit IRC | 22:48 | |
*** ametts has quit IRC | 22:48 | |
*** thorst has joined #openstack-ansible | 22:50 | |
*** fawadkhaliq has quit IRC | 22:51 | |
*** fawadkhaliq has joined #openstack-ansible | 22:51 | |
odyssey4me | I'm out for the night | 22:51 |
odyssey4me | cheerio all | 22:52 |
*** sdake_ has joined #openstack-ansible | 22:53 | |
*** sdake has quit IRC | 22:55 | |
*** BjoernT has quit IRC | 23:02 | |
*** jayc has quit IRC | 23:06 | |
*** keedya has joined #openstack-ansible | 23:10 | |
*** weezS has joined #openstack-ansible | 23:18 | |
*** busterswt has joined #openstack-ansible | 23:20 | |
openstackgerrit | Merged openstack/openstack-ansible-ironic: Update min_ansible_version to 1.9 https://review.openstack.org/304038 | 23:22 |
*** jamielennox|away is now known as jamielennox | 23:22 | |
*** markvoelker has joined #openstack-ansible | 23:34 | |
*** markvoelker has quit IRC | 23:39 | |
*** keedya has quit IRC | 23:41 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible: Enable SSL termination for all services https://review.openstack.org/277199 | 23:44 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ironic: Update ironic.conf for swift and keystone compat https://review.openstack.org/301712 | 23:45 |
*** v1k0d3n has quit IRC | 23:48 | |
*** sdake has joined #openstack-ansible | 23:52 | |
*** sdake_ has quit IRC | 23:53 | |
openstackgerrit | Steve Lewis (stevelle) proposed openstack/openstack-ansible-os_gnocchi: Enable docs task https://review.openstack.org/304336 | 23:55 |
*** keedya has joined #openstack-ansible | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!