*** erhudy has quit IRC | 00:00 | |
*** sdake_ has quit IRC | 00:04 | |
*** BjoernT has quit IRC | 00:14 | |
*** phalmos_ has quit IRC | 00:18 | |
*** thorst has quit IRC | 00:25 | |
*** thorst has joined #openstack-ansible | 00:26 | |
*** weezS has quit IRC | 00:31 | |
*** sdake has joined #openstack-ansible | 00:34 | |
*** thorst has quit IRC | 00:35 | |
*** thorst has joined #openstack-ansible | 00:35 | |
*** thorst_ has joined #openstack-ansible | 00:36 | |
*** thorst has quit IRC | 00:39 | |
*** thorst_ has quit IRC | 00:41 | |
*** thorst has joined #openstack-ansible | 00:43 | |
*** hw_wutianwei has joined #openstack-ansible | 00:44 | |
*** thorst has quit IRC | 00:48 | |
*** vnogin has quit IRC | 00:48 | |
*** asettle has joined #openstack-ansible | 00:50 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-os_ironic: Make tox tests use the ansible 1.9.x version of plugins https://review.openstack.org/409991 | 00:51 |
---|---|---|
*** asettle has quit IRC | 00:55 | |
*** javeriak has joined #openstack-ansible | 00:56 | |
*** thorst has joined #openstack-ansible | 01:03 | |
*** thorst_ has joined #openstack-ansible | 01:07 | |
*** thorst has quit IRC | 01:08 | |
*** thorst_ has quit IRC | 01:12 | |
*** chhavi has joined #openstack-ansible | 01:13 | |
*** javeriak has quit IRC | 01:28 | |
*** cathrich_ has joined #openstack-ansible | 01:35 | |
*** cathrichardson has quit IRC | 01:35 | |
*** thorst has joined #openstack-ansible | 01:35 | |
*** thorst_ has joined #openstack-ansible | 01:38 | |
*** thorst has quit IRC | 01:42 | |
*** thorst_ has quit IRC | 01:44 | |
*** sdake has quit IRC | 01:44 | |
*** jlockwood has quit IRC | 01:46 | |
*** thorst has joined #openstack-ansible | 01:49 | |
*** thorst_ has joined #openstack-ansible | 01:51 | |
*** asettle has joined #openstack-ansible | 01:52 | |
*** thorst has quit IRC | 01:53 | |
*** adrian_otto has quit IRC | 01:54 | |
*** thorst has joined #openstack-ansible | 01:55 | |
*** thorst_ has quit IRC | 01:56 | |
*** asettle has quit IRC | 01:56 | |
*** sdake has joined #openstack-ansible | 01:57 | |
*** thorst has quit IRC | 02:00 | |
*** thorst has joined #openstack-ansible | 02:01 | |
*** thorst has quit IRC | 02:06 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-os_ironic: Make tox tests use the ansible 1.9.x version of plugins https://review.openstack.org/409991 | 02:06 |
*** weezS has joined #openstack-ansible | 02:09 | |
*** thorst has joined #openstack-ansible | 02:11 | |
*** thorst has quit IRC | 02:13 | |
*** thorst has joined #openstack-ansible | 02:13 | |
*** chhavi has quit IRC | 02:14 | |
*** javeriak has joined #openstack-ansible | 02:16 | |
*** sdake has quit IRC | 02:17 | |
openstackgerrit | Michael Carden proposed openstack/openstack-ansible-os_ironic: Add tests/common to .gitignore https://review.openstack.org/410003 | 02:19 |
*** sdake has joined #openstack-ansible | 02:20 | |
*** chhavi has joined #openstack-ansible | 02:23 | |
*** thorst has quit IRC | 02:23 | |
*** thorst has joined #openstack-ansible | 02:25 | |
*** javeriak has quit IRC | 02:27 | |
*** sdake has quit IRC | 02:40 | |
*** thorst_ has joined #openstack-ansible | 02:40 | |
*** admin0 has quit IRC | 02:41 | |
*** admin0 has joined #openstack-ansible | 02:42 | |
*** sdake has joined #openstack-ansible | 02:42 | |
*** thorst has quit IRC | 02:43 | |
*** thorst has joined #openstack-ansible | 02:44 | |
*** thorst_ has quit IRC | 02:45 | |
*** sdake_ has joined #openstack-ansible | 02:45 | |
*** chhavi has quit IRC | 02:46 | |
*** sdake has quit IRC | 02:49 | |
*** asettle has joined #openstack-ansible | 02:52 | |
*** thorst_ has joined #openstack-ansible | 02:53 | |
*** thorst__ has joined #openstack-ansible | 02:55 | |
*** thorst has quit IRC | 02:56 | |
*** asettle has quit IRC | 02:57 | |
*** thorst_ has quit IRC | 02:58 | |
*** thorst has joined #openstack-ansible | 02:58 | |
*** thorst__ has quit IRC | 03:01 | |
*** v1k0d3n has quit IRC | 03:09 | |
*** thorst_ has joined #openstack-ansible | 03:17 | |
*** pmannidi_ has joined #openstack-ansible | 03:18 | |
*** pmannidi has quit IRC | 03:19 | |
*** thorst has quit IRC | 03:19 | |
*** thorst has joined #openstack-ansible | 03:19 | |
*** thorst_ has quit IRC | 03:22 | |
*** v1k0d3n has joined #openstack-ansible | 03:23 | |
*** thorst_ has joined #openstack-ansible | 03:23 | |
*** pramodrj07 has quit IRC | 03:25 | |
*** PramodJayathirth has quit IRC | 03:25 | |
*** agrebennikov_ has quit IRC | 03:26 | |
*** thorst has quit IRC | 03:27 | |
*** raginbajin has quit IRC | 03:27 | |
*** raginbajin has joined #openstack-ansible | 03:32 | |
*** thorst has joined #openstack-ansible | 03:36 | |
*** thorst_ has quit IRC | 03:39 | |
*** thorst has quit IRC | 03:44 | |
*** ianychoi has joined #openstack-ansible | 03:44 | |
*** thorst has joined #openstack-ansible | 03:51 | |
*** javeriak has joined #openstack-ansible | 03:52 | |
*** asettle has joined #openstack-ansible | 03:53 | |
*** Disova has quit IRC | 03:55 | |
*** Disova has joined #openstack-ansible | 03:55 | |
*** thorst has quit IRC | 03:56 | |
*** asettle has quit IRC | 03:58 | |
*** Jeffrey4l has quit IRC | 03:58 | |
*** thorst has joined #openstack-ansible | 03:59 | |
*** winggundamth has quit IRC | 04:02 | |
*** Jeffrey4l has joined #openstack-ansible | 04:03 | |
*** thorst has quit IRC | 04:04 | |
*** winggundamth has joined #openstack-ansible | 04:06 | |
*** williamcaban has quit IRC | 04:15 | |
*** williamcaban has joined #openstack-ansible | 04:16 | |
*** adreznec has quit IRC | 04:18 | |
*** Jack_Iv has joined #openstack-ansible | 04:19 | |
*** williamcaban has quit IRC | 04:20 | |
*** adreznec has joined #openstack-ansible | 04:21 | |
*** Jack_Iv has quit IRC | 04:23 | |
*** cathrich_ has quit IRC | 04:26 | |
*** cathrichardson has joined #openstack-ansible | 04:26 | |
*** cathrichardson has quit IRC | 04:31 | |
*** sdake_ has quit IRC | 04:31 | |
*** adrian_otto has joined #openstack-ansible | 04:41 | |
*** v1k0d3n has quit IRC | 04:41 | |
*** weezS has quit IRC | 04:47 | |
*** dfflanders has quit IRC | 04:48 | |
*** asettle has joined #openstack-ansible | 04:54 | |
*** whiteveil has joined #openstack-ansible | 04:55 | |
*** whiteveil has quit IRC | 04:58 | |
*** asettle has quit IRC | 04:59 | |
*** sdake has joined #openstack-ansible | 05:00 | |
*** thorst has joined #openstack-ansible | 05:02 | |
*** sdake_ has joined #openstack-ansible | 05:03 | |
*** sdake has quit IRC | 05:05 | |
*** poopcat has quit IRC | 05:07 | |
*** hybridpollo has quit IRC | 05:07 | |
*** sdake_ has quit IRC | 05:07 | |
*** Mudpuppy has quit IRC | 05:08 | |
*** thorst has quit IRC | 05:08 | |
*** agrebennikov_ has joined #openstack-ansible | 05:08 | |
*** Mudpuppy has joined #openstack-ansible | 05:08 | |
*** Mudpuppy has quit IRC | 05:13 | |
*** hybridpollo has joined #openstack-ansible | 05:15 | |
*** maeker has quit IRC | 05:27 | |
*** hybridpollo has quit IRC | 05:30 | |
*** shausy has joined #openstack-ansible | 05:31 | |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-os_searchlight: [WIP] Import initial os_searchlight role. https://review.openstack.org/404419 | 05:35 |
*** Jack_Iv has joined #openstack-ansible | 05:37 | |
*** hybridpollo has joined #openstack-ansible | 05:38 | |
*** adrian_otto has quit IRC | 05:39 | |
*** adrian_otto has joined #openstack-ansible | 05:40 | |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-os_searchlight: [WIP] Import initial os_searchlight role. https://review.openstack.org/404419 | 05:41 |
*** hybridpollo has quit IRC | 05:46 | |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-os_searchlight: [WIP] Import initial os_searchlight role. https://review.openstack.org/404419 | 05:49 |
*** asettle has joined #openstack-ansible | 05:55 | |
*** asettle has quit IRC | 06:00 | |
*** thorst has joined #openstack-ansible | 06:06 | |
*** whiteveil has joined #openstack-ansible | 06:09 | |
*** thorst has quit IRC | 06:13 | |
*** whiteveil has quit IRC | 06:14 | |
*** Jack_Iv_ has joined #openstack-ansible | 06:20 | |
*** rgogunskiy has joined #openstack-ansible | 06:24 | |
*** Jack_Iv_ has quit IRC | 06:24 | |
*** whiteveil has joined #openstack-ansible | 06:24 | |
*** whiteveil has quit IRC | 06:29 | |
*** Jack_Iv_ has joined #openstack-ansible | 06:36 | |
*** agrebennikov_ has quit IRC | 06:36 | |
*** adrian_otto has quit IRC | 06:42 | |
*** javeriak has quit IRC | 06:49 | |
*** asettle has joined #openstack-ansible | 06:56 | |
*** Oku_OS-away is now known as Oku_OS | 06:56 | |
*** asettle has quit IRC | 07:01 | |
*** h5t4 has joined #openstack-ansible | 07:07 | |
*** Jack_Iv_ has quit IRC | 07:07 | |
*** fxpester has joined #openstack-ansible | 07:09 | |
*** thorst has joined #openstack-ansible | 07:11 | |
*** thorst has quit IRC | 07:19 | |
*** Jeffrey4l has quit IRC | 07:24 | |
*** Jeffrey4l has joined #openstack-ansible | 07:25 | |
*** cuongnv has joined #openstack-ansible | 07:39 | |
*** sacharya has quit IRC | 07:42 | |
*** Jack_Iv_ has joined #openstack-ansible | 07:48 | |
*** asettle has joined #openstack-ansible | 07:57 | |
*** Jack_Iv_ has quit IRC | 07:59 | |
*** sacharya has joined #openstack-ansible | 08:00 | |
*** asettle has quit IRC | 08:02 | |
*** basilAB has quit IRC | 08:04 | |
*** sacharya has quit IRC | 08:05 | |
*** whiteveil has joined #openstack-ansible | 08:05 | |
*** basilAB has joined #openstack-ansible | 08:09 | |
*** whiteveil has quit IRC | 08:10 | |
*** pcaruana has joined #openstack-ansible | 08:10 | |
*** aludwar has quit IRC | 08:10 | |
*** oanson has joined #openstack-ansible | 08:11 | |
*** thorst has joined #openstack-ansible | 08:16 | |
*** maeker has joined #openstack-ansible | 08:18 | |
*** maeker has quit IRC | 08:23 | |
*** thorst has quit IRC | 08:23 | |
openstackgerrit | Neill Cox proposed openstack/openstack-ansible-os_searchlight: [WIP] Import initial os_searchlight role. https://review.openstack.org/404419 | 08:30 |
Adri2000 | hello | 08:45 |
Adri2000 | what's the official "policy" regarding running specific roles in a more recent version than the rest of openstack-ansible | 08:46 |
Adri2000 | specifically, in my example, running os_magnum master with the rest of openstack-ansible stable/newton | 08:46 |
*** karimb has joined #openstack-ansible | 08:46 | |
Adri2000 | issue being that os_magnum master has incompatible changes with Ansible 2.1 (and openstack-ansible stable/newton means Ansible 2.1) | 08:47 |
*** ArchiFleKs has quit IRC | 08:53 | |
*** vnogin has joined #openstack-ansible | 09:04 | |
*** gouthamr has joined #openstack-ansible | 09:06 | |
*** fxpester has quit IRC | 09:13 | |
*** fxpester has joined #openstack-ansible | 09:14 | |
*** jlockwood has joined #openstack-ansible | 09:17 | |
*** karimb has quit IRC | 09:20 | |
*** asettle has joined #openstack-ansible | 09:20 | |
*** thorst has joined #openstack-ansible | 09:21 | |
openstackgerrit | Omer Anson proposed openstack/openstack-ansible-os_neutron: Implement Dragonflow deployment https://review.openstack.org/391524 | 09:22 |
*** asettle has quit IRC | 09:22 | |
*** asettle has joined #openstack-ansible | 09:22 | |
*** Jack_Iv_ has joined #openstack-ansible | 09:25 | |
*** vnogin has quit IRC | 09:27 | |
*** thorst has quit IRC | 09:29 | |
*** jlockwood has quit IRC | 09:29 | |
*** Jack_Iv_ has quit IRC | 09:30 | |
*** gouthamr has quit IRC | 09:33 | |
*** Jack_Iv_ has joined #openstack-ansible | 09:35 | |
*** karimb has joined #openstack-ansible | 09:36 | |
evrardjp | Adri2000: I think that chris_hultin|AWA is working on this right now | 09:39 |
evrardjp | odyssey4me: could you confirm? | 09:39 |
odyssey4me | Adri2000 you can do whatever you like, but based on the changes we had to make in master for Ansible 2.2 it's very unlikely to work without modification | 09:39 |
odyssey4me | Why would you want to run os_magnum from master in a Newton environment? | 09:40 |
evrardjp | magnum broken in N I guess :p | 09:40 |
odyssey4me | flaviodsr mrda we are busy removing Trusty support in Ocata, yes | 09:40 |
odyssey4me | cloudnull the patch at the bottom of the chain has a -1 | 09:42 |
evrardjp | Adri2000: technically you can do whatever you want, but we don't test hybrid/mixed environments in our gates | 09:42 |
evrardjp | so at your own risk | 09:42 |
evrardjp | but like I said earlier maybe a discussion with chris_hultin|AWA is worth it | 09:43 |
odyssey4me | logan- stevelle andymccr so some roles have the concept of 'test packages' - packages which get installed when testing only... why not use that concept for the role tests to resolve the need for packages when testing via the roles (without the repo server) | 09:44 |
evrardjp | makes sense to me | 09:44 |
odyssey4me | we could actually remove the concept from the roles and just have them in the test repo | 09:44 |
odyssey4me | for example, remove this https://github.com/openstack/openstack-ansible-memcached_server/blob/master/vars/debian.yml#L21 | 09:44 |
andymccr | odyssey4me: we'd have to duplicate the same packages in a whole bunch of roles, which seems like a lot of duplication - additionally, those packages are needed when you're not using a repo server (to build packages) | 09:45 |
odyssey4me | move it to the tests repo where we have a common set of distro packages used for role tests | 09:45 |
evrardjp | well I like the role to be self contained as much as possible | 09:45 |
andymccr | so its not just testing - its whenever you build the packages locally | 09:45 |
evrardjp | but not to the risk of duplication | 09:45 |
evrardjp | we've been there | 09:45 |
odyssey4me | my thinking was to have a playbook and common set in the tests repo which all roles consume for role tests | 09:45 |
andymccr | and its needed for that in itself, having those inside nova role (for example) seems odd - when i only need those packages if im building pip packages | 09:45 |
odyssey4me | yep, that's why I'm advocating for it not to be in the roles | 09:46 |
evrardjp | file a bug? | 09:46 |
andymccr | its only in the pip_install role now, which imo makes sense - since it's needed to run the pip install role if you don't have an existing repo server - since teh pip install role will attempt to build the pip packages (it cant without those packages,) | 09:46 |
odyssey4me | the pip install role is failing? | 09:47 |
andymccr | no but installing pip packages etc would - since that role is a requirement and defines how pip packages are installed it makes sense to me at least, or way more sense that having it in other roles. | 09:48 |
odyssey4me | I thought that other roles were failing to install, not that role. | 09:48 |
andymccr | its other roles, because testing on that role is minimal | 09:48 |
andymccr | but they all fail on installing pip packages | 09:48 |
odyssey4me | well, sure - much of a muchness | 09:48 |
andymccr | the argument against puting it in the testing repo is that its not an option that is just for testing | 09:48 |
odyssey4me | if this is something that matter for *production* then it should be in the roles | 09:48 |
evrardjp | well we should test in the pip install role that we can use pip afterwards, don't you think? | 09:49 |
andymccr | its an optional include now | 09:49 |
evrardjp | like pip wheel/pip install | 09:49 |
odyssey4me | otherwise I advocate for it to be in the tests repo, because that's where *non-production* things should live IMO | 09:49 |
*** vnogin has joined #openstack-ansible | 09:51 | |
*** vnogin has quit IRC | 09:52 | |
*** vnogin has joined #openstack-ansible | 09:52 | |
*** Jack_Iv_ has quit IRC | 09:53 | |
*** vnogin has quit IRC | 09:57 | |
*** vnogin has joined #openstack-ansible | 09:58 | |
odyssey4me | andymccr https://github.com/openstack/openstack-ansible/blob/master/playbooks/defaults/repo_packages/openstack_services.yml#L191 | 10:00 |
*** drifterza has joined #openstack-ansible | 10:02 | |
*** Jack_Iv_ has joined #openstack-ansible | 10:04 | |
drifterza | greetings | 10:06 |
*** Mudpuppy has joined #openstack-ansible | 10:07 | |
*** karimb has quit IRC | 10:09 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Make git clone script idempotent https://review.openstack.org/383709 | 10:10 |
*** Mudpuppy has quit IRC | 10:12 | |
*** karimb has joined #openstack-ansible | 10:13 | |
*** sdake has joined #openstack-ansible | 10:15 | |
*** cuongnv has quit IRC | 10:26 | |
*** thorst has joined #openstack-ansible | 10:27 | |
*** asettle has quit IRC | 10:30 | |
openstackgerrit | Omer Anson proposed openstack/openstack-ansible-os_neutron: Implement Dragonflow deployment https://review.openstack.org/391524 | 10:33 |
*** thorst has quit IRC | 10:34 | |
*** ArchiFleKs has joined #openstack-ansible | 10:35 | |
*** asettle has joined #openstack-ansible | 10:36 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_ceilometer: Update paste, policy and rootwrap configurations 2016-12-13 https://review.openstack.org/410139 | 10:36 |
*** asettle has quit IRC | 10:37 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_cinder: Update paste, policy and rootwrap configurations 2016-12-13 https://review.openstack.org/410140 | 10:37 |
*** asettle has joined #openstack-ansible | 10:37 | |
*** karimb has quit IRC | 10:38 | |
*** karimb has joined #openstack-ansible | 10:41 | |
*** stuartgr has joined #openstack-ansible | 10:42 | |
*** Jack_Iv_ has quit IRC | 10:47 | |
*** pester has joined #openstack-ansible | 11:05 | |
*** fxpester has quit IRC | 11:08 | |
*** vnogin has quit IRC | 11:12 | |
*** karimb has quit IRC | 11:13 | |
*** karimb has joined #openstack-ansible | 11:16 | |
odyssey4me | evrardjp I need an extra set of eyes: https://review.openstack.org/#/c/383709/7/templates/op-clone-script.sh.j2 | 11:16 |
odyssey4me | the patch is failing consistently with the rally repo not cloning, even though it should | 11:16 |
*** vnogin has joined #openstack-ansible | 11:16 | |
odyssey4me | http://logs.openstack.org/09/383709/7/check/gate-openstack-ansible-repo_build-ansible-func-ubuntu-xenial/a149376/console.html#_2016-12-13_10_18_13_740425 | 11:17 |
odyssey4me | that shows that it hits line 56 | 11:17 |
odyssey4me | but notice that it doesn't hit line 65 for some reason | 11:18 |
*** askb has quit IRC | 11:19 | |
*** sdake_ has joined #openstack-ansible | 11:30 | |
*** whiteveil has joined #openstack-ansible | 11:30 | |
*** thorst has joined #openstack-ansible | 11:32 | |
*** shausy has quit IRC | 11:33 | |
*** sdake has quit IRC | 11:34 | |
*** whiteveil has quit IRC | 11:35 | |
*** sdake_ has quit IRC | 11:36 | |
*** thorst has quit IRC | 11:38 | |
*** deadnull has joined #openstack-ansible | 11:39 | |
*** sdake has joined #openstack-ansible | 11:45 | |
*** thorst has joined #openstack-ansible | 11:48 | |
*** thorst has quit IRC | 11:53 | |
*** sdake has quit IRC | 11:55 | |
*** whiteveil has joined #openstack-ansible | 12:06 | |
*** sdake has joined #openstack-ansible | 12:08 | |
*** askb has joined #openstack-ansible | 12:08 | |
*** askb has quit IRC | 12:08 | |
*** sdake has quit IRC | 12:10 | |
openstackgerrit | Omer Anson proposed openstack/openstack-ansible-os_neutron: Implement Dragonflow deployment https://review.openstack.org/391524 | 12:10 |
*** whiteveil has quit IRC | 12:11 | |
*** williamcaban has joined #openstack-ansible | 12:11 | |
*** thorst has joined #openstack-ansible | 12:19 | |
*** williamcaban has quit IRC | 12:22 | |
*** williamcaban has joined #openstack-ansible | 12:22 | |
*** maeker has joined #openstack-ansible | 12:23 | |
*** sdake has joined #openstack-ansible | 12:25 | |
*** sdake has quit IRC | 12:26 | |
*** maeker has quit IRC | 12:28 | |
evrardjp | mhayden: [WARNING]: Failure using method (v2_runner_on_ok) in callback plugin (</etc/ansible/roles/plugins/callback/debug_message_collector.CallbackModule object at 0x7f5b3ca0ad10>): 'msg' | 12:29 |
evrardjp | in newton | 12:29 |
evrardjp | 2.1 I guess | 12:29 |
evrardjp | FYI | 12:29 |
openstackgerrit | Merged openstack/openstack-ansible-plugins: Catch only debug tasks w/callback https://review.openstack.org/409859 | 12:30 |
*** karimb has quit IRC | 12:33 | |
evrardjp | mhayden: ^ well it may be on master too, I was a little confused for a moment | 12:46 |
*** hw_wutianwei has quit IRC | 12:46 | |
*** Jack_Iv_ has joined #openstack-ansible | 12:47 | |
*** sdake has joined #openstack-ansible | 12:51 | |
*** Jack_Iv_ has quit IRC | 12:52 | |
andymccr | odyssey4me: https://bugs.launchpad.net/openstack-ansible/+bug/1649329 | 12:55 |
openstack | Launchpad bug 1649329 in openstack-ansible "14.0.3 repo build error on Ubuntu 14.04" [High,New] - Assigned to Andy McCrae (andrew-mccrae) | 12:55 |
*** fguillot has joined #openstack-ansible | 13:00 | |
*** retreved has joined #openstack-ansible | 13:02 | |
*** GheRivero has left #openstack-ansible | 13:02 | |
*** whiteveil has joined #openstack-ansible | 13:03 | |
*** whiteveil has quit IRC | 13:08 | |
*** johnmilton has joined #openstack-ansible | 13:11 | |
*** karimb has joined #openstack-ansible | 13:14 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set user/group/modes on user init files [+Docs] https://review.openstack.org/408736 | 13:17 |
*** asettle has quit IRC | 13:19 | |
*** asettle has joined #openstack-ansible | 13:19 | |
*** stuartgr has quit IRC | 13:19 | |
*** fguillot has quit IRC | 13:20 | |
mhayden | evrardjp: i didn't intend for that patch to affect newton | 13:20 |
*** fguillot has joined #openstack-ansible | 13:20 | |
evrardjp | k | 13:21 |
*** tomaluca95 has left #openstack-ansible | 13:22 | |
evrardjp | mhayden: my instance where I had all of this was kinda in a mixed model, so don't pay attention to my comment | 13:22 |
mhayden | ah okay | 13:22 |
evrardjp | if I see this issue returning I'll either submit a bug or fix it... but anyway it's low prio: it was just a warning | 13:22 |
*** drifterza has quit IRC | 13:23 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer: Update paste, policy and rootwrap configurations 2016-12-13 https://review.openstack.org/410139 | 13:32 |
*** Jack_Iv has quit IRC | 13:37 | |
*** Jack_Iv has joined #openstack-ansible | 13:39 | |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder: Update paste, policy and rootwrap configurations 2016-12-13 https://review.openstack.org/410140 | 13:39 |
*** woodard has joined #openstack-ansible | 13:40 | |
*** woodard has quit IRC | 13:41 | |
*** woodard has joined #openstack-ansible | 13:42 | |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 13:45 |
*** kjw3 has joined #openstack-ansible | 13:49 | |
*** jheroux has joined #openstack-ansible | 13:51 | |
mhayden | jmccrory: i think i addressed your concern here -> https://review.openstack.org/#/c/406329/17/tasks/rhel7stig/file_perms.yml | 13:52 |
mhayden | let me know if i didn't ;) | 13:52 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 13:53 |
*** karimb has quit IRC | 14:00 | |
*** v1k0d3n has joined #openstack-ansible | 14:02 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: host net config bond0 static -> manual https://review.openstack.org/410230 | 14:10 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 14:11 |
*** sdake_ has joined #openstack-ansible | 14:12 | |
*** cathrichardson has joined #openstack-ansible | 14:14 | |
*** karimb has joined #openstack-ansible | 14:15 | |
*** sdake has quit IRC | 14:15 | |
*** whiteveil has joined #openstack-ansible | 14:18 | |
*** woodard has quit IRC | 14:19 | |
*** dmsimard has quit IRC | 14:21 | |
*** dmsimard has joined #openstack-ansible | 14:21 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set user/group/modes on user init files [+Docs] https://review.openstack.org/408736 | 14:21 |
*** agrebennikov_ has joined #openstack-ansible | 14:22 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Unblock Newton gate https://review.openstack.org/409913 | 14:22 |
*** johnmilton has quit IRC | 14:22 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_ceilometer: Remove dependency on oslo.vmware https://review.openstack.org/410238 | 14:22 |
*** whiteveil has quit IRC | 14:23 | |
*** johnmilton has joined #openstack-ansible | 14:23 | |
agrebennikov_ | folks, I have a question about "keystone with ssl" approach. It seems that during the deployment only keystone containers get the CA | 14:23 |
agrebennikov_ | this is why services don't work since they cannot validate keystone cert | 14:23 |
*** pester has quit IRC | 14:26 | |
*** Jack_Iv_ has joined #openstack-ansible | 14:26 | |
*** pester has joined #openstack-ansible | 14:27 | |
*** pabelanger has left #openstack-ansible | 14:27 | |
*** dmsimard has quit IRC | 14:28 | |
*** dmsimard has joined #openstack-ansible | 14:28 | |
*** dmsimard has quit IRC | 14:28 | |
*** dmsimard has joined #openstack-ansible | 14:30 | |
*** Jack_Iv_ has quit IRC | 14:31 | |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible: Update apt after proxy config is dropped https://review.openstack.org/410241 | 14:32 |
*** adrian_otto has joined #openstack-ansible | 14:35 | |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible: Update apt after proxy config is dropped https://review.openstack.org/410241 | 14:36 |
*** adrian_otto1 has joined #openstack-ansible | 14:39 | |
*** adrian_otto has quit IRC | 14:40 | |
*** BjoernT has joined #openstack-ansible | 14:40 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Make git clone script idempotent https://review.openstack.org/383709 | 14:44 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Make git clone process idempotent https://review.openstack.org/383709 | 14:44 |
*** cathrich_ has joined #openstack-ansible | 14:44 | |
*** cathrichardson has quit IRC | 14:44 | |
*** michaelgugino has joined #openstack-ansible | 14:45 | |
evrardjp | dear cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, | 14:46 |
evrardjp | spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, severion, bgmccollum, darrenc, JRobinson__, asettle, colinmcnamara, thorst, adreznec, eil397 : | 14:46 |
evrardjp | the osa bug triage will start in 1h15’. Please have a look at the bug list before starting: https://etherpad.openstack.org/p/osa-bugtriage | 14:46 |
*** aludwar has joined #openstack-ansible | 14:52 | |
asettle | Suresies | 14:53 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 14:53 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Make git clone process idempotent https://review.openstack.org/383709 | 14:54 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_ironic: Add tests/common to .gitignore https://review.openstack.org/410003 | 14:57 |
*** cathrich_ is now known as cathrichardson | 14:58 | |
*** whiteveil has joined #openstack-ansible | 14:58 | |
*** weezS has joined #openstack-ansible | 14:59 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ironic: Make tox tests use the ansible 1.9.x version of plugins https://review.openstack.org/409991 | 14:59 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 15:01 |
*** TxGirlGeek has joined #openstack-ansible | 15:05 | |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [ops-guide] Adding new content to guide https://review.openstack.org/409854 | 15:06 |
*** phalmos has joined #openstack-ansible | 15:11 | |
asettle | odyssey4me: do you remember how long ago you implemented the openstack manuals doc theme on top of the osa install guide? | 15:11 |
asettle | Trying to find the patch, and this is like wading through fucking mud | 15:11 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [Docs] Update for RHEL7 STIG https://review.openstack.org/410258 | 15:12 |
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer: Remove Trusty support from os_ceilometer role https://review.openstack.org/409743 | 15:14 |
*** rgogunskiy has quit IRC | 15:14 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ironic: Add tests/common to .gitignore https://review.openstack.org/410003 | 15:15 |
*** phalmos_ has joined #openstack-ansible | 15:15 | |
*** h5t4 has quit IRC | 15:15 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Updates for CentOS 7 changes https://review.openstack.org/409913 | 15:18 |
*** jmckind has joined #openstack-ansible | 15:18 | |
*** phalmos has quit IRC | 15:18 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [Docs] Fix missing code-block property https://review.openstack.org/410263 | 15:18 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Mitaka gate testing https://review.openstack.org/410265 | 15:19 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Fix issues from new CentOS 7 release https://review.openstack.org/409913 | 15:20 |
odyssey4me | asettle I can help you with that in a bit, after a meeting I'm in. | 15:22 |
*** Jack_Iv_ has joined #openstack-ansible | 15:23 | |
asettle | odyssey4me: no sweat. I can't read anymore of your commit messages or I'll do something drastic :p | 15:24 |
*** jamesdenton has joined #openstack-ansible | 15:28 | |
michaelgugino | . | 15:29 |
*** h5t4 has joined #openstack-ansible | 15:30 | |
*** whiteveil has quit IRC | 15:30 | |
*** whiteveil has joined #openstack-ansible | 15:32 | |
*** karimb has quit IRC | 15:40 | |
*** galstrom_zzz is now known as galstrom | 15:43 | |
*** karimb has joined #openstack-ansible | 15:44 | |
mhayden | , | 15:44 |
odyssey4me | ` | 15:44 |
*** Jack_Iv_ has quit IRC | 15:45 | |
*** Jack_Iv_ has joined #openstack-ansible | 15:46 | |
*** adrian_otto has joined #openstack-ansible | 15:48 | |
*** adrian_otto1 has quit IRC | 15:49 | |
*** h5t4 has quit IRC | 15:51 | |
odyssey4me | evrardjp andymccr for that git issue we discussed earlier: https://review.openstack.org/383709 | 15:53 |
andymccr | odyssey4me: testing it now | 15:53 |
agrebennikov_ | folks, I have a question about "keystone with ssl" approach. It seems that during the deployment only keystone containers get the CA | 15:55 |
agrebennikov_ | this is why services don't work since they cannot validate keystone cert | 15:55 |
odyssey4me | agrebennikov_ it's designed to be used with real CA's, not internal CA's | 15:55 |
agrebennikov_ | how come? | 15:56 |
agrebennikov_ | why then there is an option "keystone_ssl_ca_cert"? | 15:56 |
odyssey4me | there are probably some gaps if you're using SSL internally - no-one's really put much effort into that design | 15:56 |
*** chris_hultin|AWA is now known as chris_hultin | 15:56 | |
agrebennikov_ | well, you need to puth the chain anyway | 15:56 |
agrebennikov_ | *put | 15:57 |
odyssey4me | that's for when you may need to implement a ca cert or intermediate+ca combo in order for Apache to start... but it's largely legacy from before we did SSL offloading at the LB | 15:57 |
agrebennikov_ | odyssey4me, what do you mean by "real"? | 15:57 |
evrardjp | agrebennikov_: there used to have chain support | 15:57 |
openstackgerrit | Omer Anson proposed openstack/openstack-ansible-os_neutron: Implement Dragonflow deployment https://review.openstack.org/391524 | 15:57 |
odyssey4me | if internal SSL is a need for your deployment, it'd be great to see some focused patches around that | 15:58 |
agrebennikov_ | odyssey4me, what about turning on ssl on the services? | 15:58 |
odyssey4me | agrebennikov_ internally? | 15:58 |
agrebennikov_ | not even blueprinted? | 15:58 |
odyssey4me | exterally is already catered for | 15:58 |
odyssey4me | internally is not | 15:58 |
agrebennikov_ | I mean, each service terminating ssl | 15:58 |
odyssey4me | ie currently we do it at the public endpoint, but not at the admin/internal endpoint | 15:59 |
agrebennikov_ | well, externally - you don't have to do Anything with it in fact ;) just put the cert to the F5 and that's it, and keep dealing with plain http within the cloud | 15:59 |
odyssey4me | historically openstack has been very bad at testing SSL so the clients have often broken when using SSL everywhere | 16:00 |
*** TxGirlGeek has quit IRC | 16:00 | |
agrebennikov_ | same as I proposed to the customer, but they are very stricts about security :/ | 16:00 |
*** TxGirlGeek has joined #openstack-ansible | 16:00 | |
agrebennikov_ | saying all traffic should be encrypted | 16:00 |
odyssey4me | I think there is better testing upstream now, and we're in a far better position to poke upstream when something breaks due to SSL usage (assuming we implement this in testing) | 16:01 |
odyssey4me | sure, I've known that this would become a need at some point - but obviously it's just not been enough of a priority for any contributors up until now | 16:01 |
agrebennikov_ | I already see veeeery bad behaviour of keystone under ssl | 16:01 |
agrebennikov_ | like each api call takes 3 seconds | 16:01 |
agrebennikov_ | vs 0.2 without ssl | 16:02 |
odyssey4me | so if your customer needs it, it'd be an ideal time to blueprint it up and start working on a pattern to implement it with one of the roles | 16:02 |
andymccr | i think it links in quite nicely with the talk we had around moving to use uwsgi/apache/nginx on all api hosts | 16:02 |
odyssey4me | andymccr agreed | 16:02 |
dstanek | agrebennikov_: what is doing the termination? | 16:02 |
agrebennikov_ | noooo!!!! :) | 16:02 |
andymccr | id personally rather see work go into that (and adding ssl into that because its much simpler) | 16:02 |
odyssey4me | it'd certainly simpler if we have aa uniform way of deploying the API services | 16:02 |
evrardjp | when this discussion is over I'd like to go for the bug triage | 16:02 |
andymccr | ahh yeah bug triage | 16:02 |
evrardjp | it seems a go to me! | 16:02 |
evrardjp | Bug triage cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, spotz, vdo, jmccrory, alextricity25, jasondotstar, admin0, michaelgugino, ametts, v1k0d3n, seve | 16:03 |
evrardjp | rion, bgmccollum, darrenc, JRobinson__, asettle, colinmcnamara, thorst, adreznec, eil397, qwang,nishpatwa_, cathrichardson, drifterza | 16:03 |
evrardjp | Here is our bug list for today https://etherpad.openstack.org/p/osa-bugtriage | 16:03 |
agrebennikov_ | how much time it will take for you guys? | 16:03 |
evrardjp | the bug triage last 1h | 16:03 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649416 | 16:03 |
openstack | Launchpad bug 1649416 in openstack-ansible "Apt pkgs could not be authenticated" [Undecided,In progress] - Assigned to Kyle L. Henderson (kyleh) | 16:03 |
agrebennikov_ | ok, I'll bug you in an hour then | 16:03 |
evrardjp | thanks | 16:03 |
*** TxGirlGeek has quit IRC | 16:04 | |
evrardjp | in progress good | 16:04 |
evrardjp | next | 16:04 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649381 | 16:04 |
openstack | Launchpad bug 1649381 in openstack-ansible "config_template does not support {% raw %}" [Undecided,New] | 16:04 |
*** TxGirlGeek has joined #openstack-ansible | 16:04 | |
odyssey4me | this time it wasn't mhayden's fault | 16:04 |
logan- | low imo. | 16:04 |
evrardjp | k | 16:05 |
evrardjp | it's still a bug | 16:05 |
andymccr | im not sure we can be sure its not mhayden's fault | 16:05 |
evrardjp | I'd like to see it confirmed by someone else just for the principle but it sounds reasonable to me | 16:05 |
mhayden | WAIT WHAT | 16:05 |
evrardjp | low unconfirmed atm? | 16:05 |
mhayden | THIS TIME I DIDN'T BREAK SOMETHING? | 16:05 |
andymccr | sounds good evrardjp | 16:05 |
* mhayden is headed to the pub | 16:05 | |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649339 | 16:06 |
openstack | Launchpad bug 1649339 in openstack-ansible "apt-cacher files have incorrect authorities" [Undecided,New] | 16:06 |
evrardjp | alextricity25: will probably follow this one soon, to test if it's the case in his latest deploys ;) | 16:06 |
evrardjp | maybe someone else could confirm this? | 16:07 |
andymccr | i saw something similar on an aio i was messing about with earlier today, but may not be related at all | 16:07 |
evrardjp | I'd like to make sure there was nothing weird in the containers in terms of user permissions/process or whatever | 16:07 |
evrardjp | in all the cases I think we should properly ensure permissions/users in our processes, so I think there is a bug anyway | 16:07 |
evrardjp | the criticality changes depending on what the status/cause is | 16:08 |
evrardjp | in the meantime, we could keep it as new, and not change the criticality? | 16:08 |
kylek3h | The cause is lsyncd using rsh as nginx user. | 16:08 |
odyssey4me | actually I think this apt-cacher thing is high | 16:08 |
evrardjp | kylek3h: yes and? | 16:08 |
odyssey4me | basically it renders the apt-cacher backup services useless, but they will still try to serve | 16:08 |
*** Jack_Iv_ has quit IRC | 16:09 | |
odyssey4me | and yes, in my checking earlier I confirm what kylek3h is noting | 16:09 |
kylek3h | and we could use a precmd and postcmd to change the auths...but it's tricky | 16:09 |
*** pcaruana has quit IRC | 16:09 | |
evrardjp | I think until it's confirmed we cannot take assumptions | 16:09 |
kylek3h | I've been discussing a fix with folks here on my team. | 16:09 |
evrardjp | oh | 16:09 |
odyssey4me | we either need to ensure that the apt-cacher user is in the group that will allow it to read/modify those files | 16:09 |
evrardjp | did you see our comments kylek3h? | 16:09 |
kylek3h | in the bug? yes. | 16:10 |
odyssey4me | or we need to modify the sudo so that lsyncd can switch to the apt cacher user | 16:10 |
*** Mudpuppy has joined #openstack-ansible | 16:10 | |
odyssey4me | unless you can come up with a nicer option | 16:10 |
odyssey4me | oh, of course another option is not to sync the cached content at all - if it switches to another container, it must cache from scratch | 16:10 |
evrardjp | I propose then to leave the bug as is, and when a patch will be linked, it will auto move to in progress | 16:10 |
andymccr | sounds good to me | 16:10 |
evrardjp | if someone confirms it, we could rethink of it in the next triage meeting | 16:11 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Handle SELinux properly when it is disabled https://review.openstack.org/410294 | 16:11 |
evrardjp | and then move to the appropriate classification | 16:11 |
odyssey4me | or if kylek3h comes up with a smart patch, it will progress too :) | 16:11 |
evrardjp | that's what I meant :D | 16:11 |
kylek3h | I'll work on something today | 16:11 |
kylek3h | just had to pass the idea by the security folks...I may email mhayden | 16:12 |
mhayden | ;) | 16:12 |
evrardjp | next | 16:12 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649298 | 16:12 |
openstack | Launchpad bug 1649298 in openstack-ansible "multiple fixed ips assigned to newly spawned instance" [Undecided,New] | 16:12 |
evrardjp | this one was an UFO to me | 16:13 |
*** Oku_OS is now known as Oku_OS-away | 16:13 | |
evrardjp | move to nova/ and mark it invalid? :D | 16:13 |
evrardjp | or incomplete? | 16:14 |
jmccrory | that does sound like more of a nova/neutron bug, i've seen it before when message queues weren't keeping up or some service was misbehaving. i'll try to track down the bug we found about it before and link it there | 16:14 |
evrardjp | jmccrory: great! | 16:14 |
evrardjp | I'll still mark as targeting other projects | 16:14 |
logan- | i see it all the time if the scheduler has to retry | 16:15 |
*** Mudpuppy has quit IRC | 16:15 | |
logan- | :( | 16:15 |
evrardjp | :( | 16:15 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [Docs] Fix missing code-block property https://review.openstack.org/410263 | 16:15 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [Docs] Update for RHEL7 STIG https://review.openstack.org/410258 | 16:15 |
evrardjp | I'll leave it targetted in osa until jmccrory comments on the bug. in the meantime, already targetting other projects | 16:16 |
evrardjp | next | 16:16 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649114 | 16:16 |
openstack | Launchpad bug 1649114 in openstack-ansible "variable config for public domain" [Undecided,New] | 16:16 |
michaelgugino | https://bugs.launchpad.net/openstack-ansible/+bug/1649298 I believe mhayden blogged about this situation | 16:16 |
openstack | Launchpad bug 1649298 in OpenStack Compute (nova) "multiple fixed ips assigned to newly spawned instance" [Undecided,New] | 16:16 |
evrardjp | good to know michaelgugino.. mhayden feel free to share your blog post on the bug | 16:18 |
evrardjp | so next is: https://bugs.launchpad.net/openstack-ansible/+bug/1649114 | 16:18 |
openstack | Launchpad bug 1649114 in openstack-ansible "variable config for public domain" [Undecided,New] | 16:18 |
michaelgugino | https://major.io/2016/08/03/openstack-instances-come-online-with-multiple-network-ports-attached/ | 16:18 |
evrardjp | is my understanding wrong? | 16:18 |
*** Mudpuppy has joined #openstack-ansible | 16:19 | |
mhayden | evrardjp: blog post added ;) | 16:19 |
evrardjp | thanks | 16:19 |
evrardjp | so... for our bug... is my understanding wrong? | 16:20 |
andymccr | hmm yeah why would we need to set an external_lb_vip, maybe for listen addresses? | 16:20 |
andymccr | or rather, why cant we just set that to the fqdn | 16:20 |
evrardjp | we can | 16:20 |
evrardjp | I deployed today as PoC | 16:21 |
evrardjp | it works | 16:21 |
andymccr | ok then im not sure there is a need to comlicate it by adding a second var | 16:21 |
evrardjp | ok | 16:21 |
evrardjp | agreed | 16:21 |
andymccr | *complicate | 16:21 |
evrardjp | I'm not sure what was tried to be achieved here | 16:21 |
evrardjp | I'll mark it as incomplete | 16:22 |
andymccr | if there was a reason you needed an external_lb_vip to be assigned as an IP then it would make sense i guess | 16:22 |
evrardjp | asking what more should we have | 16:22 |
-openstackstatus- NOTICE: Launchpad SSO is not currently working, so logins to our services like review.openstack.org and wiki.openstack.org are failing; the admins at Canonical are looking into the issue but there is no estimated time for a fix yet. | 16:22 | |
*** ChanServ changes topic to "Launchpad SSO is not currently working, so logins to our services like review.openstack.org and wiki.openstack.org are failing; the admins at Canonical are looking into the issue but there is no estimated time for a fix yet." | 16:22 | |
evrardjp | andymccr: we should rename properly this variable in next cycle | 16:22 |
evrardjp | and have proper lookup of this for haproxy config | 16:22 |
evrardjp | this way we would reduce the vars | 16:22 |
evrardjp | but it's a big change right now, so I suggest we don't change right now | 16:22 |
*** zz_pwnall1337 is now known as pwnall1337 | 16:23 | |
evrardjp | it works for me | 16:23 |
evrardjp | :p | 16:23 |
andymccr | ok cool | 16:23 |
andymccr | yeah i agree | 16:23 |
*** maeker has joined #openstack-ansible | 16:24 | |
evrardjp | so | 16:24 |
evrardjp | next | 16:24 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1648064 | 16:24 |
openstack | Launchpad bug 1648064 in openstack-ansible "Error "Table 'neutron.ml2_vlan_allocations' doesn't exist" in neutron server" [Undecided,New] | 16:24 |
cloudnull | odyssey4me: evrardjp: logan-: anyone else: I know we're are triaging bugs but when you have moment it'd be great to get some feedback on https://review.openstack.org/#/c/409490 | 16:24 |
evrardjp | cloudnull: starred | 16:24 |
logan- | will do cloudnull | 16:24 |
*** vnogin has quit IRC | 16:25 | |
cloudnull | tyvm | 16:25 |
odyssey4me | cloudnull yeah, when I last tried to read that my brain leaked out of my ears... will try again though | 16:26 |
evrardjp | We leave the bug as is, the bug reporter is an *ss | 16:26 |
cloudnull | odyssey4me: :) | 16:26 |
evrardjp | I meant it's not really in our hands | 16:26 |
odyssey4me | that looks like the migrations aren't happening properly | 16:27 |
evrardjp | indeed but we don't touch these right? | 16:27 |
odyssey4me | we should actively make contact with #openstack-neutron | 16:27 |
evrardjp | already started with the intermediary of john | 16:28 |
andymccr | evrardjp: i think that may be fixed | 16:28 |
evrardjp | oh great | 16:28 |
odyssey4me | no we don't, but it's important to be proactive with these, otherwise it gets harder o find the culprit | 16:28 |
andymccr | i mean we'd need to confirm, but it looks like the logs have stopped being generated like that | 16:28 |
evrardjp | andymccr: recent patchset don't show this? | 16:28 |
evrardjp | cool | 16:28 |
andymccr | hmm | 16:28 |
andymccr | could be wrong then | 16:28 |
andymccr | its neutron-server log? | 16:28 |
evrardjp | yup | 16:28 |
odyssey4me | evrardjp FYI logstash.openstack.org has a longer history than the gate logs themselves | 16:29 |
*** maeker has quit IRC | 16:29 | |
*** uthng has joined #openstack-ansible | 16:29 | |
evrardjp | I thought it was the opposite | 16:29 |
evrardjp | good to know | 16:29 |
uthng | hi all | 16:30 |
evrardjp | let's move to next one? | 16:30 |
evrardjp | or someone have something to add? | 16:30 |
odyssey4me | sure | 16:30 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1645979 | 16:30 |
openstack | Launchpad bug 1645979 in openstack-ansible "neutron_l3_agent and neutron_l3_metadata groups include physical host" [Undecided,New] | 16:30 |
evrardjp | this one we'll wait for Travis input IIRC | 16:30 |
palendae | evrardjp: Yeah, that's what I remember | 16:31 |
uthng | anyone can tell me why I got this error now ? Authorization failed. The request you have made requires authentication ? | 16:31 |
uthng | after ugrading glance or cinder to newton ? | 16:31 |
odyssey4me | automagically ^ | 16:31 |
evrardjp | ok next ones haven't changed | 16:32 |
uthng | I cannot find it out why ? I checked all password etc. All seem ok | 16:32 |
evrardjp | a few remaining ones in different cases: | 16:32 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1646124 | 16:32 |
openstack | Launchpad bug 1646124 in openstack-ansible "Swift is generating audit.log errors on CentOS with selinux enabled" [Wishlist,New] | 16:32 |
evrardjp | uthng: we are triaging for now, could you come in 30 minutes or when the triage is ended? ty | 16:32 |
evrardjp | mhayden: did you see that happening? | 16:33 |
uthng | ok | 16:33 |
*** karimb has quit IRC | 16:34 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_keystone: All handlers should be tagged "config" https://review.openstack.org/410304 | 16:34 |
evrardjp | or anyone else | 16:34 |
evrardjp | maybe andymccr? | 16:34 |
andymccr | evrardjp: i believe mgariepy didnt view that one as critical | 16:36 |
evrardjp | that's what we discussed indeed | 16:36 |
andymccr | or impactful | 16:36 |
andymccr | im not sure on the legitimacy of it | 16:36 |
evrardjp | but I know we kill puppies when setenforce 0 | 16:36 |
logan- | that DVR group one is waiting on me. i'm going to push a patch dynamically adding the hosts to the group with add_host, just have been tied up-- i should get it in the next day or two | 16:36 |
evrardjp | logan-: that's true | 16:37 |
evrardjp | the feedback of automagically was for the review indeed | 16:37 |
evrardjp | :D | 16:37 |
evrardjp | anyway, I suggest we don't change the status of the last bug | 16:37 |
*** sacharya has joined #openstack-ansible | 16:38 | |
evrardjp | so I think we are done then | 16:38 |
evrardjp | thanks everyone | 16:38 |
andymccr | thanks evrardjp! | 16:38 |
*** sdake_ is now known as sdake | 16:38 | |
openstackgerrit | Merged openstack/openstack-ansible: Update apt after proxy config is dropped https://review.openstack.org/410241 | 16:38 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set home dir mode/owner/group owner [+Docs] https://review.openstack.org/406329 | 16:41 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Find world-writable dirs with bad group owners https://review.openstack.org/407157 | 16:42 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set cron.allow owner/group owner [+Docs] https://review.openstack.org/407178 | 16:42 |
odyssey4me | andymccr we should probably get https://review.openstack.org/408549 through the door some time soon | 16:47 |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible: Update apt after proxy config is dropped https://review.openstack.org/410313 | 16:48 |
*** asettle__ has joined #openstack-ansible | 16:49 | |
odyssey4me | cloudnull FYI https://github.com/odyssey4me/lxc_cache_build/ | 16:51 |
odyssey4me | andymccr ^ should I push the patch to add that repo? | 16:51 |
andymccr | odyssey4me: sure, that'd be good. i'll +1 it once its up. | 16:51 |
*** vnogin has joined #openstack-ansible | 16:52 | |
andymccr | im looking at the trusty patch, and testing the git clone patch - i'd like to get that fix through too | 16:52 |
cloudnull | cool | 16:52 |
*** asettle has quit IRC | 16:53 | |
cloudnull | odyssey4me: curious if you have had a look at https://review.openstack.org/#/c/409490 effort being that we can build images without having a specialized role to do so which should allow us to remove the general base cache process in the future. | 16:55 |
agrebennikov_ | odyssey4me, can we continue on the ssl for a while please? | 16:56 |
cloudnull | obviously that effort could go into a role . but im thinking a general purpose playbook may be more flexible | 16:56 |
*** vnogin has quit IRC | 16:56 | |
odyssey4me | cloudnull my intent with https://github.com/odyssey4me/lxc_cache_build/ is to provide a general purpose role for cache prep as a drop-in replacement for the current default... but yeah, it might be that we can do without prepping a default cache altogether | 16:57 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable FIPS [+Docs] https://review.openstack.org/407218 | 16:57 |
cloudnull | indeed. | 16:58 |
cloudnull | it's good to have options :) | 16:58 |
cloudnull | also im just getting back into the swing of things | 16:58 |
cloudnull | so I may be lagging | 16:58 |
odyssey4me | so I guess we need to look into what it would take to rid ourselves of the default build to see if that's a viable option | 16:58 |
*** ChanServ changes topic to "Launchpad: https://launchpad.net/openstack-ansible || Weekly Meetings: https://wiki.openstack.org/wiki/Meetings/openstack-ansible || Review Dashboard: https://goo.gl/tTmdgs" | 16:58 | |
-openstackstatus- NOTICE: Canonical admins have resolved the issue with login.launchpad.net, so authentication should be restored now. | 16:58 | |
odyssey4me | we'd probably have to move the python package install somewhere | 16:59 |
odyssey4me | so yeah - I was thinking let's move the stuff out of lxc_hosts at least, then whittle it down | 16:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set user/group/modes on user init files [+Docs] https://review.openstack.org/408736 | 16:59 |
odyssey4me | if we ultimately retire the lxc_cache_build role then great | 16:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set user/group/modes on user init files [+Docs] https://review.openstack.org/408736 | 16:59 |
cloudnull | sgtm | 16:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set home dir mode/owner/group owner [+Docs] https://review.openstack.org/406329 | 16:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set cron.allow owner/group owner [+Docs] https://review.openstack.org/407178 | 16:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Find world-writable dirs with bad group owners https://review.openstack.org/407157 | 16:59 |
*** Jeffrey4l has quit IRC | 17:00 | |
*** sacharya_ has joined #openstack-ansible | 17:00 | |
*** Jeffrey4l has joined #openstack-ansible | 17:00 | |
odyssey4me | cloudnull I see in your utility playbook you took a similar approach to what I did here: https://review.openstack.org/396401 | 17:00 |
odyssey4me | in terms of whittling down the containers to one per service per lxc host I mean | 17:01 |
*** asettle__ is now known as asettle | 17:01 | |
cloudnull | yes. I was tyring to think about the world where distros and archetectures may be mixed and matched | 17:02 |
odyssey4me | I am thinking that perhaps that playbook is better suited to being in the ops repo for now though | 17:02 |
*** sacharya has quit IRC | 17:02 | |
cloudnull | in it's current state it | 17:02 |
cloudnull | it'd be serial | 17:02 |
odyssey4me | yeah, I see that - seeing as it all uses the same container for the builds | 17:03 |
cloudnull | but in a future state we should be able to build all images in parallel based on the number of nodes within the cluster. | 17:03 |
odyssey4me | well, the same container name | 17:03 |
odyssey4me | my approach was in parallel | 17:03 |
odyssey4me | using different names | 17:03 |
*** woodard has joined #openstack-ansible | 17:03 | |
cloudnull | yea. the LXC_NAME was used to ensure the container could be artifact'd | 17:03 |
cloudnull | lxc uses that special when you re-deploy a container. | 17:04 |
odyssey4me | so my thinking is kinda like this - a CI process to produce the container variants would be out of band to a deployment | 17:04 |
cloudnull | otherwise all containers would have the same host key and name | 17:04 |
odyssey4me | yeah, that name is important for LXC - not LXD | 17:04 |
cloudnull | yes. | 17:04 |
cloudnull | I didn't look into tackeling kxd | 17:04 |
cloudnull | **LXD | 17:04 |
odyssey4me | if we can work towards LXD in the next cycle then our world can be a lot simpler, perhaps | 17:04 |
odyssey4me | but for now our CI needs are focused on newton, so we need ot use LXC for now | 17:05 |
odyssey4me | so if the CI process to build the variants is out of band to a deployment, then speed is a non-issue | 17:06 |
*** aludwar has quit IRC | 17:06 | |
*** aludwar has joined #openstack-ansible | 17:07 | |
odyssey4me | also, the skipping of tags is a good approach, I think | 17:07 |
odyssey4me | at least for newton | 17:07 |
jrosser_ | lxd+zfs is potent, COW makes new containers instant | 17:09 |
*** sdake has quit IRC | 17:10 | |
*** asettle has quit IRC | 17:15 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Remove Ubuntu Trusty Support https://review.openstack.org/408549 | 17:17 |
odyssey4me | jrosser_ yep, any cow-backed containers actually work quite well - I did some tests with cow containers backed by LVM and they were also super fast | 17:18 |
jrosser_ | our stuff-you-need-before-osa is all built with lxd/zfs | 17:20 |
jrosser_ | pxe/dns etc | 17:20 |
jrosser_ | its working a treat | 17:20 |
*** markvoelker has quit IRC | 17:20 | |
jrosser_ | missing ability to configure network with cloud-init is only missing bit | 17:21 |
odyssey4me | agrebennikov_ sure, what's up? | 17:21 |
odyssey4me | jrosser_ sounds good - is this the stuff that's pending a review to the ops repo? | 17:22 |
*** markvoelker has joined #openstack-ansible | 17:22 | |
agrebennikov_ | odyssey4me, well, 3 things I wanted to bring to the table | 17:22 |
agrebennikov_ | but start from question | 17:22 |
agrebennikov_ | do you use ssl termination on the ext balancer at rackspace? | 17:22 |
odyssey4me | agrebennikov_ yes | 17:22 |
*** woodard has quit IRC | 17:22 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Don't delete container_cidr key when overriding https://review.openstack.org/410331 | 17:23 |
*** woodard has joined #openstack-ansible | 17:23 | |
palendae | alextricity25: ^ will make a newton backport, but that'll have to merge first | 17:23 |
jrosser_ | odyssey4me: theres no lxd in what we did to the multinode aio, but some of the roles are recycled from what went into our pxe/dhcp containers | 17:24 |
alextricity25 | thanks palendae!!! :) | 17:24 |
odyssey4me | palendae alextricity25 I'm not entirely sure why we're persisting that data at all considering that it's only needed for the process of generating an IP for the container. | 17:24 |
agrebennikov_ | odyssey4me, thanks :) because this is a host debates happening right now with the customer regarding this feature | 17:24 |
odyssey4me | it's also already persisted in openstack_user_config | 17:24 |
palendae | odyssey4me: It's used downstream in a load balancer script | 17:24 |
agrebennikov_ | all right, so 3 things | 17:25 |
alextricity25 | odyssey4me palendae: ^ right. sorry I wasn't very clear about that in the description. | 17:25 |
odyssey4me | palendae hmm, so the downstream script is loading the json file instead of reading the output from the dynamic inventory? | 17:25 |
palendae | I'm not sure the response to "This broke my downstream stuff" is "you don't need it." | 17:25 |
palendae | odyssey4me: Er...that json file *is* the output | 17:25 |
agrebennikov_ | 1. are we interested in ssl termination across all services? Do I have to create a BP for it with current services running in eventlet? | 17:25 |
odyssey4me | palendae sure, I'm not saying that's the attitude - I'm just trying to understand the situation and to figure out how we can prevent ourselved from getting stuck in a situation where we promise yet another interface to downstream consumers | 17:26 |
palendae | This existed up til Newton | 17:26 |
*** whiteveil has quit IRC | 17:26 | |
agrebennikov_ | 2. I have to implement CA option into keystone_authtoken section as "cafile" because requests uses its own CA bundle, as well as I have to extend openrc in the utility container with OS_CACERT | 17:26 |
odyssey4me | if there are options to be clear that this shouldn't be done, this is the alternative approach and that it'll work now but it's deprecated then we should do that | 17:26 |
odyssey4me | but yeah, the short term fix is obviously to make it work again | 17:27 |
palendae | It wasn't explicitly deprecated... | 17:27 |
palendae | https://review.openstack.org/#/c/325380/ didn't account for it | 17:27 |
odyssey4me | yep, understood | 17:27 |
palendae | As I mention in https://review.openstack.org/#/c/410331/ | 17:27 |
*** klamath has joined #openstack-ansible | 17:27 | |
*** klamath has quit IRC | 17:27 | |
palendae | IMO it's a bug, though granted I don't know why that was carried in the first place | 17:28 |
*** klamath has joined #openstack-ansible | 17:28 | |
agrebennikov_ | 3. I need to distribute the CA into all containers and add it to ca-cartificates bundle, and then use it as a hardcoded value for "cafile" for all services | 17:28 |
odyssey4me | agrebennikov_ well, eventlet has been pretty much removed upstream - so the approach should be to implement it with uwsgi and perhaps nginx | 17:28 |
agrebennikov_ | odyssey4me, seems that's it | 17:28 |
agrebennikov_ | odyssey4me, is it in OSA master already? | 17:29 |
agrebennikov_ | for all roles | 17:29 |
odyssey4me | we have discussed, but haven't yet had the resourcing to implement, moving all API services to being served via uwsgi and nginx based on the feedback from upstream developers that it is faster and scales better | 17:29 |
stevelle | agrebennikov_: can we slice things differently with 1) because not all OpenStack services have an eventlet model anymore | 17:29 |
stevelle | would termination in the WSGI container be OK? | 17:29 |
stevelle | (uwsgi for example) | 17:29 |
agrebennikov_ | stevelle, well, same as keystone is done today | 17:30 |
agrebennikov_ | it is pretty straightforward | 17:30 |
agrebennikov_ | except the concern that every api call with ssl takes 3 sec vs 0.1 sec without ssl | 17:30 |
agrebennikov_ | but this is apache | 17:30 |
agrebennikov_ | during the call apache thread takes 100% of cpu and spends 3 sec while rocessing ssl session | 17:31 |
stevelle | We added Nginx w/ uwsgi deploy option for keystone. We never finished the configuraitno of SSL termination at Nginx or uwsgi | 17:31 |
agrebennikov_ | *processing | 17:31 |
agrebennikov_ | is nginx from your perspective better than apache> | 17:31 |
agrebennikov_ | ? | 17:31 |
stevelle | the SSL termination work at the wsgi container for keystone would not require a blueprint for us | 17:31 |
agrebennikov_ | oh, keystone works already | 17:32 |
*** sdake has joined #openstack-ansible | 17:32 | |
agrebennikov_ | I'm talking about the rest of the services | 17:32 |
odyssey4me | agrebennikov_ to answer the question of whether there should be a bp/spec - you can opt to register a bp and then put together a patch against one service to establish a pattern which you will intend to replicate | 17:32 |
stevelle | I'm specifically bringing up SSL w/o using Apache | 17:32 |
odyssey4me | instead of debating the pattern in a spec, we'd do it in the initial review | 17:32 |
odyssey4me | once that review merges, you can go ahead with the rest of the patches | 17:33 |
odyssey4me | that said, the guidance really needs to come from andymccr - I'm just advising from prior art | 17:33 |
stevelle | also agrebennikov_ we suspect nginx w/ uwsgi would be marginally better than apache for a few reasons | 17:33 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible: Remove Ubuntu Trusty Support https://review.openstack.org/408549 | 17:35 |
*** thorst has quit IRC | 17:37 | |
*** thorst has joined #openstack-ansible | 17:37 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Fix Mitaka gate https://review.openstack.org/410265 | 17:41 |
*** thorst has quit IRC | 17:42 | |
*** jlockwood has joined #openstack-ansible | 17:46 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible-specs: Outline a pluggable inventory backend system https://review.openstack.org/410342 | 17:51 |
openstackgerrit | Merged openstack/openstack-ansible-repo_build: Make git clone process idempotent https://review.openstack.org/383709 | 17:56 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-repo_build: Make git clone process idempotent https://review.openstack.org/410346 | 17:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Fix Mitaka gate https://review.openstack.org/410265 | 17:59 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Fix Mitaka gate https://review.openstack.org/410265 | 18:01 |
*** cathrichardson has quit IRC | 18:02 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Enable FIPS [+Docs] https://review.openstack.org/407218 | 18:06 |
*** Jack_Iv_ has joined #openstack-ansible | 18:09 | |
*** cathrichardson has joined #openstack-ansible | 18:10 | |
*** vnogin has joined #openstack-ansible | 18:11 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Fix Mitaka gate https://review.openstack.org/410265 | 18:11 |
*** Jack_Iv_ has quit IRC | 18:13 | |
*** asettle has joined #openstack-ansible | 18:14 | |
*** pramodrj07 has joined #openstack-ansible | 18:15 | |
*** PramodJayathirth has joined #openstack-ansible | 18:15 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Handle SELinux properly when it is disabled https://review.openstack.org/410294 | 18:15 |
*** jmckind has quit IRC | 18:17 | |
*** pester has quit IRC | 18:20 | |
*** smatzek has joined #openstack-ansible | 18:22 | |
andymccr | i think as long as we're using mod_wsgi or uwsgi with apache or nginx we can easily (and uniformly) enable ssl - i dont think there is any point putting a lot of work into making SSL termination happen without those. | 18:26 |
andymccr | nice work on the repo stuff odyssey4me! hopefully that back port will go in and we can get that fixed up for release | 18:26 |
*** whiteveil has joined #openstack-ansible | 18:27 | |
*** vnogin has quit IRC | 18:28 | |
*** tnewhouse has joined #openstack-ansible | 18:28 | |
*** vnogin has joined #openstack-ansible | 18:29 | |
*** vnogin has quit IRC | 18:29 | |
*** vnogin has joined #openstack-ansible | 18:30 | |
stevelle | bumped that backport | 18:30 |
*** weezS has quit IRC | 18:30 | |
odyssey4me | thanks stevelle | 18:35 |
odyssey4me | andymccr yeah, it'll go into the next release which I think is fine considering that it's a bit of an edge case | 18:35 |
odyssey4me | it'll be good for it to get a little baking time anyway | 18:36 |
tnewhouse | Hi. Question regarding a 2-node test setup. Documentation indicates that block storage host is optional (http://docs.openstack.org/project-deploy-guide/openstack-ansible/newton/app-config-test.html). When I tried to create openstack_user_config.yml without storage_hosts, then I get a KeyError from the dynamic_inventory.py. Any tips? | 18:37 |
uthng | Anyone available for telling me why I got this error : Authorization failed. The request you have made requires authentication in the keystone log | 18:40 |
uthng | and 503 Service Unavailable | 18:41 |
uthng | The server is currently unavailable. Please try again at a later time for glance and cinder after the upgrade from Mitaka to Newton | 18:41 |
uthng | please ? | 18:41 |
uthng | Iam sur that a little stuff but I cannot find it out | 18:41 |
agrebennikov_ | you just let one keystone to run at a time, turn on debug logging on it and try once again. And look at the keystone log | 18:42 |
agrebennikov_ | it will tell you exactly what's going on | 18:42 |
uthng | How can I enable debug option on keystone ? | 18:43 |
uthng | I had to update password for cinder and glance yesterday in rabbitmq. I do not why rabbitmq lost them after the upgrade of the 2 components | 18:45 |
*** whiteveil has left #openstack-ansible | 18:46 | |
uthng | debug = True already on keystone.conf | 18:47 |
*** whiteveil has joined #openstack-ansible | 18:47 | |
openstackgerrit | Merged openstack/openstack-ansible-repo_build: Make git clone process idempotent https://review.openstack.org/410346 | 18:48 |
*** rmelero has joined #openstack-ansible | 18:53 | |
*** allanice001 has joined #openstack-ansible | 18:57 | |
*** allanice001 has quit IRC | 19:05 | |
*** thorst has joined #openstack-ansible | 19:06 | |
*** asettle has quit IRC | 19:08 | |
cloudnull | uthng: yes. debug=true | 19:11 |
cloudnull | you can distribute that change w/ ansible if you need | 19:11 |
cloudnull | openstack-ansible os-keystone-install.yml -e debug=true | 19:11 |
uthng | in this case, debug is already enabled | 19:11 |
*** allanice001 has joined #openstack-ansible | 19:12 | |
uthng | I got : CAST unique_id: 3d68f520edd444e8a5dd0ce9cbb09680 NOTIFY exchange 'keystone' topic 'notifications.info' and There is either no auth token in the request or the certificate issuer is not trusted. No auth context will be set. fill_context | 19:13 |
uthng | and Authorization failed | 19:13 |
uthng | the return of glance command : service unavailable | 19:14 |
uthng | is it normal this ? AMQPLAIN login refused: user 'cinder' - invalid credentials or AMQPLAIN login refused: user 'keystone' - invalid credentials ? | 19:15 |
cloudnull | uthng: is this a new osa deployment ? | 19:17 |
cloudnull | are the values populated in the user_secrets.yml file ? | 19:17 |
uthng | cloudnull: no, just a upgrade from mitaka to newton on aio | 19:17 |
*** allanice001 has quit IRC | 19:17 | |
uthng | yes, all values are in user_secrets | 19:18 |
uthng | they are the same in *.conf | 19:18 |
cloudnull | for "invalid credentials or AMQPLAIN login refused: user 'keystone' - invalid credentials" I'd imagine that the rabbitmq mesia db is busted. | 19:18 |
cloudnull | or that the keystone rabbitmq secrete is missing | 19:19 |
uthng | yester I have had to make a rabbitmqctl to set the password on user_secrets again | 19:19 |
cloudnull | if you rerrun the os-keystone-install role it should recreate the creds. | 19:19 |
cloudnull | start there to see if that corrects the amqp problems | 19:20 |
uthng | oki I will do this immediately | 19:20 |
cloudnull | if so, i'd suspect that the rabbitmq mnesia db is messed up and you'll likley need to rerun setup-openstack.yml | 19:21 |
*** h5t4 has joined #openstack-ansible | 19:22 | |
*** electrofelix has quit IRC | 19:22 | |
uthng | cloudnull: just rerun os-keystone-install, but it does not correct prob amqp cred | 19:23 |
*** jmckind has joined #openstack-ansible | 19:23 | |
uthng | Im continuing to get these errors on rabbit log | 19:23 |
*** allanice001 has joined #openstack-ansible | 19:23 | |
cloudnull | any cores around that might want to give this a shove https://review.openstack.org/#/q/owner:kevin%2540cloudnull.com+status:open+project:openstack/openstack-ansible-ops | 19:23 |
cloudnull | uthng: interesting. | 19:23 |
cloudnull | did you see any change when the rabbitmq user create tasks ran ? | 19:24 |
*** deadnull has quit IRC | 19:24 | |
cloudnull | mhayden: I've since revised this PR https://review.openstack.org/#/c/405061/ mind giving it another look ? | 19:24 |
uthng | cloudnull: i did not pay attention. But the rabbitmq user create in os-keystone-install ? | 19:27 |
cloudnull | yes | 19:27 |
uthng | are you sure that there is a task to create rabbitmq user in os_keystone ? I cannot find it out in the role | 19:28 |
cloudnull | it happens at the top of the play | 19:28 |
cloudnull | https://github.com/openstack/openstack-ansible/blob/master/playbooks/os-keystone-install.yml#L26-L48 | 19:28 |
*** jlockwood has quit IRC | 19:30 | |
uthng | ah it is in the playbook not in role. Wait a second, I try to get it | 19:30 |
*** cathrichardson has quit IRC | 19:31 | |
uthng | yes there is a change | 19:31 |
uthng | is it ? | 19:33 |
uthng | TASK [Ensure rabbitmq user] task path: /opt/openstack-ansible_Newton/playbooks/common-tasks/rabbitmq-vhost-user.yml:27 | 19:33 |
uthng | ok: [aio1_keystone_container-6045dc7e -> 172.29.237.19] => {"changed": false, "invocation": {"module_args": {"configure_priv": ".*", "force": false, "node": null, "password": "aa540d6f4ce8979930", "permissions": [{"configure_priv": ".*", "read_priv": ".*", "vhost": "/keystone", "write_priv": ".*"}], "read_priv": ".*", "state": "present", "tags": null, "user": "keystone", "vhost": "/keystone", "write_priv": ".*"}, | 19:36 |
uthng | "module_name": "rabbitmq_user"}, "state": "present", "user": "keystone"} | 19:36 |
*** poopcat has joined #openstack-ansible | 19:37 | |
mhayden | cloudnull: gandering | 19:37 |
mhayden | cloudnull: weird -- it didn't clear my -1 when you submitted your patch | 19:37 |
*** weezS has joined #openstack-ansible | 19:38 | |
*** jlockwood has joined #openstack-ansible | 19:42 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Fix Mitaka gate https://review.openstack.org/410265 | 19:43 |
*** poopcat has quit IRC | 19:44 | |
*** dxiri has joined #openstack-ansible | 19:44 | |
*** ianychoi has quit IRC | 19:45 | |
*** poopcat has joined #openstack-ansible | 19:45 | |
*** thorst has quit IRC | 19:46 | |
uthng | cloudnull: any idea ? Maybe the same kind of problem for other services against keystone ? | 19:46 |
openstackgerrit | Merged openstack/openstack-ansible-security: Enable FIPS [+Docs] https://review.openstack.org/407218 | 19:46 |
*** maeker has joined #openstack-ansible | 19:47 | |
*** maeker has quit IRC | 19:48 | |
*** PramodJayathirth has quit IRC | 19:48 | |
*** common has joined #openstack-ansible | 19:48 | |
*** maeker has joined #openstack-ansible | 19:48 | |
*** galstrom is now known as galstrom_zzz | 19:49 | |
*** pramodrj07 has quit IRC | 19:50 | |
*** cathrichardson has joined #openstack-ansible | 19:53 | |
*** jlockwood has quit IRC | 19:54 | |
*** Jack_Iv has quit IRC | 19:59 | |
*** Jack_Iv has joined #openstack-ansible | 20:00 | |
*** pwnall1337 is now known as zz_pwnall1337 | 20:03 | |
*** hybridpolio has joined #openstack-ansible | 20:04 | |
*** weezS_ has joined #openstack-ansible | 20:08 | |
*** weezS has quit IRC | 20:10 | |
*** weezS_ is now known as weezS | 20:10 | |
openstackgerrit | Merged openstack/openstack-ansible-os_ironic: Add ldlinux.c32 to the tftp directory https://review.openstack.org/404273 | 20:13 |
*** Jack_Iv_ has joined #openstack-ansible | 20:20 | |
*** PramodJayathirth has joined #openstack-ansible | 20:23 | |
*** pramodrj07 has joined #openstack-ansible | 20:23 | |
*** askb has joined #openstack-ansible | 20:24 | |
openstackgerrit | Merged openstack/openstack-ansible: Don't delete container_cidr key when overriding https://review.openstack.org/410331 | 20:30 |
openstackgerrit | Merged openstack/openstack-ansible: Update apt after proxy config is dropped https://review.openstack.org/410313 | 20:31 |
*** Jack_Iv_ has quit IRC | 20:31 | |
*** dfflanders has joined #openstack-ansible | 20:31 | |
*** Jack_Iv_ has joined #openstack-ansible | 20:31 | |
*** johnmilton has quit IRC | 20:33 | |
*** tnewhouse has quit IRC | 20:35 | |
*** Jack_Iv_ has quit IRC | 20:36 | |
*** dolphm has left #openstack-ansible | 20:37 | |
kylek3h | hughsaunders: Are you around? | 20:51 |
*** whiteveil has quit IRC | 20:53 | |
*** jmckind_ has joined #openstack-ansible | 20:56 | |
*** jmckind has quit IRC | 20:57 | |
*** PramodJ has joined #openstack-ansible | 21:01 | |
*** h5t4 has quit IRC | 21:02 | |
*** poopcat has quit IRC | 21:03 | |
*** smatzek has quit IRC | 21:03 | |
*** Jack_Iv_ has joined #openstack-ansible | 21:06 | |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible: Don't delete container_cidr key when overriding https://review.openstack.org/410397 | 21:08 |
palendae | alextricity25: ^ | 21:09 |
alextricity25 | thx | 21:09 |
*** tnewhouse has joined #openstack-ansible | 21:10 | |
*** vnogin has quit IRC | 21:11 | |
*** Jack_Iv_ has quit IRC | 21:13 | |
*** Jack_Iv_ has joined #openstack-ansible | 21:13 | |
*** dgonzalez has quit IRC | 21:14 | |
*** chris_hultin is now known as chris_hultin|AWA | 21:16 | |
*** vnogin has joined #openstack-ansible | 21:17 | |
*** Jack_Iv_ has quit IRC | 21:18 | |
mrda | thanks odyssey4me | 21:19 |
*** asettle has joined #openstack-ansible | 21:21 | |
alextricity25 | Do the repo server artifacts have a bind mount back to the host? | 21:22 |
*** vnogin has quit IRC | 21:27 | |
*** Jack_Iv has quit IRC | 21:31 | |
*** vnogin has joined #openstack-ansible | 21:31 | |
*** Jeffrey4l has quit IRC | 21:35 | |
*** poopcat has joined #openstack-ansible | 21:38 | |
*** asettle has quit IRC | 21:39 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set home dir mode/owner/group owner [+Docs] https://review.openstack.org/406329 | 21:41 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Find world-writable dirs with bad group owners https://review.openstack.org/407157 | 21:41 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set cron.allow owner/group owner [+Docs] https://review.openstack.org/407178 | 21:41 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Set user/group/modes on user init files [+Docs] https://review.openstack.org/408736 | 21:42 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Fix issues from new CentOS 7 release https://review.openstack.org/409913 | 21:44 |
dmsimard | How do we tell what was the particular configuration for, say, nova in a particular CI job ? | 21:44 |
dmsimard | It looks like you only store actual logs, not the configuration files | 21:44 |
*** vnogin has quit IRC | 21:45 | |
*** poopcat has quit IRC | 21:46 | |
*** poopcat has joined #openstack-ansible | 21:46 | |
*** retreved has quit IRC | 21:47 | |
*** Jeffrey4l has joined #openstack-ansible | 21:47 | |
*** johnmilton has joined #openstack-ansible | 21:47 | |
*** johnmilton has quit IRC | 21:48 | |
mhayden | dmsimard: what kind of configuration are you looking for? | 21:55 |
mhayden | could someone with zuul savvy look over my patch for project-config? https://review.openstack.org/#/c/410382/ | 21:55 |
dmsimard | whatever would be in nova.conf :) | 21:55 |
mhayden | dmsimard: hmm, you could add a 'cat /etc/nova/nova.conf' in your patch somewhere and view the CI results ;) | 21:55 |
palendae | dmsimard: ansible compute_hosts -m shell -a "cat /etc/nova/nova.conf" | 21:56 |
palendae | Oh, in gate jobs | 21:56 |
palendae | Might want to run your own AIO and look | 21:56 |
dmsimard | Bah, configurations are retrieved by other projects such as devstack, puppet and kolla and such. Why don't you retrieve them ? It's useful :( | 21:56 |
andymccr | i agree, it is useful - id like to change that up at some point, but at the moment it isnt there :( | 21:58 |
stevelle | partly because we already produce a very large volume of text artifacts and we were asked to trim that dmsimard | 21:58 |
stevelle | that derailed one effort to include them | 21:58 |
*** asettle has joined #openstack-ansible | 21:58 | |
*** vnogin has joined #openstack-ansible | 21:58 | |
dmsimard | stevelle: fair enough | 21:58 |
palendae | Certainly would be useful. I don't think infra's well equipped for running projects that build an entire stack | 22:00 |
*** woodard_ has joined #openstack-ansible | 22:00 | |
dmsimard | basically I was interested in seeing what hypervisor was used in the gate CI jobs | 22:00 |
dmsimard | i.e, libvirt_virt_type | 22:00 |
dmsimard | I would expect qemu -- and then the other config I was interested in was libvirt_cpu_mode | 22:00 |
dmsimard | i.e, host-model, host-passthrough and such. | 22:01 |
*** jamesdenton has quit IRC | 22:01 | |
dmsimard | https://github.com/openstack/openstack-ansible-os_nova/blob/master/defaults/main.yml#L257 tells me the default is host-model but that doesn't give me a whole lot of insight around what is actually tested/deployed | 22:01 |
*** maeker has quit IRC | 22:02 | |
*** woodard has quit IRC | 22:03 | |
stevelle | we run tempest.scenario.test_server_basic_ops.TestServerBasicOps.test_server_basic_ops if that helps | 22:04 |
*** woodard_ has quit IRC | 22:05 | |
stevelle | with the use of config overrides you should be able to do all the things to run whatever hypervisors you want, but we just rely on the nova gates for testing the feature grid | 22:06 |
stevelle | though that probably doesn't help much | 22:06 |
andymccr | dmsimard: it'll be qemu on gate jobs - it tries to calculate that if it isn't specified (so on gate jobs it'll be qemu). we don't change the cpu_mode so that'll be host-model (default for nova) | 22:07 |
palendae | Dunno if the os_nova role itself changed anything | 22:07 |
*** chris_hultin|AWA is now known as chris_hultin | 22:08 | |
*** asettle has quit IRC | 22:09 | |
dmsimard | andymccr: ty | 22:10 |
*** sacharya_ has quit IRC | 22:10 | |
*** sacharya has joined #openstack-ansible | 22:11 | |
*** fguillot has quit IRC | 22:11 | |
*** jmckind has joined #openstack-ansible | 22:13 | |
*** jmckind_ has quit IRC | 22:15 | |
andymccr | stevelle: i know you worked on ceilometer quite a bit before, wondering your thoughts on: https://bugs.launchpad.net/ceilometer/+bug/1643821 - i cant sha bump ceilometer unless i tell ceilometer installs to ignore the requirements (which i can do, but then consistency of ceilometer installs in a prod environment go out the window) | 22:18 |
openstack | Launchpad bug 1643821 in OpenStack Global Requirements "kafka-python version bump not compatible" [Undecided,New] | 22:18 |
*** TxGirlGeek has quit IRC | 22:18 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible: Update all SHAs for Ocata 2016-12-13 https://review.openstack.org/410433 | 22:19 |
*** aludwar has quit IRC | 22:19 | |
stevelle | andymccr: the telemetry folks were pinched by this in their gate too | 22:19 |
andymccr | so im thinking i just leave the ceilometer SHA at the version it was about a month ago (like in ^ PR) - but i guess i need to consider that it may not ever be within global reqs | 22:19 |
stevelle | not in touch with the current status atm but can look again | 22:19 |
andymccr | ahh did not know that | 22:19 |
andymccr | they seemed ok with it for the last few weeks since i reported the bug :P | 22:19 |
*** chris_hultin is now known as chris_hultin|AWA | 22:19 | |
stevelle | iirc it was an oslo.messaging problem | 22:20 |
andymccr | hmm | 22:20 |
*** aludwar has joined #openstack-ansible | 22:20 | |
stevelle | will try to look into it to be sure I'm current | 22:20 |
andymccr | that'd be great, i take it that means you think holding back the sha bump is the way forward (over deploying ceilometer ignoring reqs) | 22:21 |
stevelle | for now yes | 22:21 |
andymccr | would be great if ceilometer was part of reqs though | 22:21 |
andymccr | ok im out for tonight. thanks for the help! | 22:22 |
openstackgerrit | Nolan Brubaker proposed openstack/openstack-ansible-specs: Outline a pluggable inventory backend system https://review.openstack.org/410342 | 22:23 |
*** gouthamr has joined #openstack-ansible | 22:23 | |
*** gouthamr has quit IRC | 22:24 | |
*** gouthamr has joined #openstack-ansible | 22:24 | |
*** dgonzalez has joined #openstack-ansible | 22:27 | |
*** weezS has quit IRC | 22:30 | |
*** smatzek has joined #openstack-ansible | 22:31 | |
*** kstev has quit IRC | 22:32 | |
*** cathrichardson has quit IRC | 22:33 | |
*** maeker has joined #openstack-ansible | 22:36 | |
*** jheroux has quit IRC | 22:45 | |
stevelle | palendae: next update can you add that spec to a Pike section in the index plz? | 22:48 |
dmsimard | mgariepy: FYI there's issues with CentOS 7.3 (released yesterday) and qemu-kvm-ev 2.6.0 (released today) when using virt_type=qemu and cpu_mode=host-model. You need to use cpu_mode=none (like devstack does) or you'll run into something like this: | 22:48 |
dmsimard | http://logs.openstack.org/76/409476/4/check/gate-puppet-openstack-integration-4-scenario003-tempest-centos-7/8881991/logs/libvirt/qemu/instance-00000001.txt.gz | 22:48 |
dmsimard | Since this is provided by dependencies outside of OpenStack, you might run into this in any version >= Mitaka (not mentioning <= Liberty due to EOL) | 22:49 |
dmsimard | I'm trying to get a post to openstack-dev/openstack-operators out about it. | 22:50 |
*** allanice001 has quit IRC | 22:50 | |
*** adrian_otto has quit IRC | 22:50 | |
*** jlockwood has joined #openstack-ansible | 22:56 | |
*** vnogin has quit IRC | 23:02 | |
*** BjoernT has quit IRC | 23:02 | |
*** kjw3 has quit IRC | 23:06 | |
*** woodard has joined #openstack-ansible | 23:08 | |
*** gouthamr has quit IRC | 23:09 | |
*** retreved has joined #openstack-ansible | 23:09 | |
*** vnogin has joined #openstack-ansible | 23:09 | |
*** woodard has quit IRC | 23:11 | |
*** jmckind has quit IRC | 23:11 | |
*** woodard has joined #openstack-ansible | 23:12 | |
*** allanice001 has joined #openstack-ansible | 23:13 | |
*** retreved_ has joined #openstack-ansible | 23:13 | |
*** retreved has quit IRC | 23:14 | |
*** smatzek has quit IRC | 23:23 | |
*** klamath has quit IRC | 23:29 | |
*** vnogin has quit IRC | 23:29 | |
*** vnogin has joined #openstack-ansible | 23:31 | |
*** agrebennikov_ has quit IRC | 23:32 | |
*** retreved_ has quit IRC | 23:45 | |
*** zz_pwnall1337 is now known as pwnall1337 | 23:48 | |
*** chris_hultin|AWA is now known as chris_hultin | 23:52 | |
*** tnewhous_ has joined #openstack-ansible | 23:53 | |
*** tnewhous_ has quit IRC | 23:53 | |
*** tnewhouse has quit IRC | 23:55 | |
*** dxiri has quit IRC | 23:55 | |
*** tnewhouse has joined #openstack-ansible | 23:55 | |
*** dxiri has joined #openstack-ansible | 23:56 | |
*** dxiri_ has joined #openstack-ansible | 23:57 | |
*** sacharya has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!