*** adreznec has joined #openstack-ansible | 00:01 | |
*** gaudenz has joined #openstack-ansible | 00:07 | |
*** chas__ has quit IRC | 00:08 | |
*** chas has joined #openstack-ansible | 00:08 | |
*** gaudenz_ has quit IRC | 00:10 | |
*** chris_hultin|AWA is now known as chris_hultin | 00:10 | |
*** chas has quit IRC | 00:13 | |
*** May-meimei has quit IRC | 00:38 | |
*** chris_hultin is now known as chris_hultin|AWA | 00:39 | |
*** woodard has joined #openstack-ansible | 00:44 | |
*** david-lyle has joined #openstack-ansible | 00:51 | |
*** SerenaFeng has joined #openstack-ansible | 00:54 | |
*** david-lyle has quit IRC | 00:55 | |
*** markvoelker has joined #openstack-ansible | 01:05 | |
*** jamielennox is now known as jamielennox|away | 01:05 | |
*** markvoelker has quit IRC | 01:09 | |
*** May-meimei has joined #openstack-ansible | 01:58 | |
*** markvoelker has joined #openstack-ansible | 02:05 | |
*** Jack_Iv has joined #openstack-ansible | 02:08 | |
*** markvoelker has quit IRC | 02:10 | |
*** sdake has joined #openstack-ansible | 02:11 | |
*** Jack_Iv has quit IRC | 02:12 | |
*** sdake has quit IRC | 02:15 | |
*** sdake has joined #openstack-ansible | 02:16 | |
*** chris_hultin|AWA is now known as chris_hultin | 02:18 | |
*** jamielennox|away is now known as jamielennox | 02:19 | |
*** Jeffrey4l__ is now known as Jeffrey4l | 02:28 | |
*** chris_hultin is now known as chris_hultin|AWA | 02:29 | |
*** sdake has quit IRC | 02:31 | |
*** Mahe has quit IRC | 02:42 | |
*** Mahe has joined #openstack-ansible | 02:42 | |
*** david-lyle has joined #openstack-ansible | 02:52 | |
*** david-lyle has quit IRC | 02:57 | |
*** markvoelker has joined #openstack-ansible | 03:06 | |
*** marc_ab has joined #openstack-ansible | 03:07 | |
*** chas has joined #openstack-ansible | 03:10 | |
*** markvoelker has quit IRC | 03:10 | |
*** chas has quit IRC | 03:15 | |
*** marc_ab has quit IRC | 03:25 | |
*** hw_wutianwei has joined #openstack-ansible | 03:33 | |
*** pmannidi has quit IRC | 03:33 | |
*** adreznec has quit IRC | 03:34 | |
*** Mahe has quit IRC | 03:34 | |
*** May-meimei has quit IRC | 03:34 | |
*** gaudenz has quit IRC | 03:34 | |
*** woodard has quit IRC | 03:34 | |
*** Mahe has joined #openstack-ansible | 03:34 | |
*** May-meimei has joined #openstack-ansible | 03:34 | |
*** gaudenz has joined #openstack-ansible | 03:34 | |
*** woodard has joined #openstack-ansible | 03:35 | |
*** adreznec has joined #openstack-ansible | 03:35 | |
*** JRobinson has joined #openstack-ansible | 03:43 | |
*** woodard has quit IRC | 03:44 | |
*** JRobinson has quit IRC | 03:44 | |
*** jrobinson has joined #openstack-ansible | 03:44 | |
*** sdake has joined #openstack-ansible | 03:51 | |
*** Mudpuppy has joined #openstack-ansible | 03:52 | |
*** weezS has joined #openstack-ansible | 03:52 | |
*** sdake has quit IRC | 03:56 | |
*** pmannidi has joined #openstack-ansible | 03:57 | |
*** jrobinson has quit IRC | 03:58 | |
*** havenshi has joined #openstack-ansible | 04:01 | |
*** Jack_Iv has joined #openstack-ansible | 04:09 | |
*** Haven_ has joined #openstack-ansible | 04:09 | |
Haven_ | weezS | 04:10 |
---|---|---|
weezS | Haven_ | 04:10 |
*** Haven_ has left #openstack-ansible | 04:12 | |
*** winggundamth has quit IRC | 04:13 | |
*** Jack_Iv has quit IRC | 04:13 | |
*** sacharya has quit IRC | 04:15 | |
*** sacharya has joined #openstack-ansible | 04:16 | |
*** SerenaFeng has quit IRC | 04:17 | |
*** sacharya has quit IRC | 04:21 | |
*** omiday has joined #openstack-ansible | 04:22 | |
*** SerenaFeng has joined #openstack-ansible | 04:43 | |
*** gus has joined #openstack-ansible | 04:44 | |
*** pegmanm_ has joined #openstack-ansible | 04:48 | |
*** SerenaFeng has quit IRC | 04:49 | |
*** havenshi has quit IRC | 04:50 | |
*** sdake has joined #openstack-ansible | 04:56 | |
*** ivve has joined #openstack-ansible | 05:01 | |
*** shausy has joined #openstack-ansible | 05:10 | |
*** chas has joined #openstack-ansible | 05:11 | |
*** weezS has quit IRC | 05:14 | |
*** chas has quit IRC | 05:16 | |
*** sacharya has joined #openstack-ansible | 05:17 | |
*** sacharya has quit IRC | 05:22 | |
*** shausy has quit IRC | 05:27 | |
*** shausy has joined #openstack-ansible | 05:32 | |
*** shausy has quit IRC | 05:32 | |
*** weezS has joined #openstack-ansible | 05:33 | |
*** SerenaFeng has joined #openstack-ansible | 05:41 | |
*** sdake has quit IRC | 05:42 | |
*** jamielennox is now known as jamielennox|away | 05:52 | |
*** jamielennox|away is now known as jamielennox | 06:00 | |
*** Jack_Iv has joined #openstack-ansible | 06:00 | |
*** winggundamth has joined #openstack-ansible | 06:02 | |
*** Jack_Iv has quit IRC | 06:05 | |
*** SerenaFeng has quit IRC | 06:06 | |
*** SerenaFeng has joined #openstack-ansible | 06:09 | |
*** gaudenz_ has joined #openstack-ansible | 06:09 | |
*** gaudenz has quit IRC | 06:12 | |
*** woodard has joined #openstack-ansible | 06:17 | |
*** gaudenz has joined #openstack-ansible | 06:20 | |
*** woodard has quit IRC | 06:21 | |
*** gaudenz_ has quit IRC | 06:23 | |
*** hw_wutianwei1 has joined #openstack-ansible | 06:30 | |
*** hw_wutianwei has quit IRC | 06:31 | |
*** hw_wutianwei1 is now known as hw_wutianwei | 06:31 | |
*** caowei has joined #openstack-ansible | 06:43 | |
*** Mudpuppy has quit IRC | 06:52 | |
*** sdake has joined #openstack-ansible | 06:53 | |
*** Jack_Iv has joined #openstack-ansible | 06:59 | |
*** pegmanm_ has quit IRC | 07:04 | |
*** pegmanm_ has joined #openstack-ansible | 07:04 | |
*** sdake has quit IRC | 07:06 | |
*** winggundamth has quit IRC | 07:06 | |
*** Jack_Iv has quit IRC | 07:09 | |
*** chas has joined #openstack-ansible | 07:12 | |
*** chas has quit IRC | 07:17 | |
*** woodard has joined #openstack-ansible | 07:18 | |
*** sacharya has joined #openstack-ansible | 07:18 | |
*** winggundamth has joined #openstack-ansible | 07:19 | |
*** SerenaFeng has quit IRC | 07:21 | |
*** SerenaFeng has joined #openstack-ansible | 07:21 | |
*** woodard has quit IRC | 07:22 | |
*** sacharya has quit IRC | 07:22 | |
*** chas has joined #openstack-ansible | 07:25 | |
evrardjp | good morning everyone | 07:33 |
*** pmannidi has quit IRC | 07:37 | |
*** h5t4 has joined #openstack-ansible | 07:40 | |
*** pcaruana has joined #openstack-ansible | 07:41 | |
*** SerenaFeng has quit IRC | 07:52 | |
*** SerenaFeng has joined #openstack-ansible | 07:53 | |
*** Jack_Iv has joined #openstack-ansible | 08:07 | |
*** Jack_Iv has quit IRC | 08:12 | |
*** woodard has joined #openstack-ansible | 08:18 | |
*** Jack_Iv has joined #openstack-ansible | 08:19 | |
*** woodard has quit IRC | 08:23 | |
*** weezS has quit IRC | 08:25 | |
*** Andrew_jedi has joined #openstack-ansible | 08:30 | |
*** Jack_Iv has quit IRC | 08:31 | |
Andrew_jedi | Hello Folks, Anyone has any idea how to integrate ELK stack with OSA? | 08:31 |
*** Mudpuppy has joined #openstack-ansible | 08:53 | |
*** david-lyle has joined #openstack-ansible | 08:57 | |
*** Mudpuppy has quit IRC | 08:57 | |
*** david-lyle has quit IRC | 09:01 | |
andymccr | morning morning. | 09:06 |
andymccr | hey Andrew_jedi - on the ELK integration, RAX has some ELK integration that there was talk of moving to the osa ops repo. It's still an open repo atm though, so you could take a look and use it or just take a look at how theyve chosen to do it. | 09:07 |
evrardjp | good morning Andrew_jedi andymccr | 09:12 |
andymccr | hey evrardjp - good christmas/new years? | 09:13 |
evrardjp | yup, what about you? | 09:13 |
Andrew_jedi | andymccr: Thanks, let me look for it :) | 09:13 |
evrardjp | Andrew_jedi: do you have the links? | 09:13 |
Andrew_jedi | evrardjp: Good morning !! | 09:13 |
andymccr | Andrew_jedi: https://github.com/rcbops/rpc-openstack then in the rpcd directory you'll find playbooks/roles for elk and filebeat which i believe is a log shipper that replaced beaver. | 09:14 |
Andrew_jedi | evrardjp: this one ? https://github.com/rcbops/rpc-openstack/tree/master/maas/plugins | 09:14 |
evrardjp | I pinged you the link | 09:14 |
Andrew_jedi | andymccr: Ohhh, thanks for sharing !! | 09:14 |
andymccr | Andrew_jedi: maas is one of the "only useful for RAX" things unfortunately, since it plugs into the RAX specific MaaS - but the ELK/logging should all be applicable | 09:15 |
Andrew_jedi | evrardjp: thank you! | 09:15 |
evrardjp | Andrew_jedi: in any case, this should be an inspiration, and I think RAX is welcoming this to be a community thing | 09:18 |
evrardjp | so, "patches welcome" | 09:18 |
*** sacharya has joined #openstack-ansible | 09:19 | |
Andrew_jedi | evrardjp: rpc-openstack is using OSA, so if somebody wants ELK stack they can directly use rpc-openstack for ubuntu based environment? right ? | 09:20 |
evrardjp | Andrew_jedi: that's true, and on top of it, you can have rackspace support and managed services, but that's not a discussion for this chan IMO | 09:20 |
evrardjp | :p | 09:20 |
evrardjp | we stay vendor agnostic here :) | 09:21 |
Andrew_jedi | evrardjp: haha , yep :) | 09:21 |
*** sacharya has quit IRC | 09:23 | |
*** asettle has joined #openstack-ansible | 09:27 | |
*** gaudenz_ has joined #openstack-ansible | 09:31 | |
*** gaudenz has quit IRC | 09:35 | |
*** May-meimei has quit IRC | 09:38 | |
*** askb has quit IRC | 09:52 | |
*** Mudpuppy has joined #openstack-ansible | 09:53 | |
*** marc_ab has joined #openstack-ansible | 09:56 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-plugins: Cleanup temporary files after content argument usage https://review.openstack.org/413641 | 09:57 |
*** gaudenz has joined #openstack-ansible | 09:57 | |
*** david-lyle has joined #openstack-ansible | 09:58 | |
*** Mudpuppy has quit IRC | 09:58 | |
*** gaudenz_ has quit IRC | 10:00 | |
*** david-lyle has quit IRC | 10:02 | |
*** markvoelker has joined #openstack-ansible | 10:10 | |
*** Andrew_jedi has quit IRC | 10:11 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-plugins: Cleanup temporary files after content argument usage https://review.openstack.org/413641 | 10:12 |
*** SerenaFeng has quit IRC | 10:13 | |
*** marc_ab has quit IRC | 10:14 | |
*** markvoelker has quit IRC | 10:15 | |
*** SerenaFeng has joined #openstack-ansible | 10:17 | |
*** pegmanm_ has quit IRC | 10:20 | |
*** Jack_Iv has joined #openstack-ansible | 10:31 | |
*** Jack_Iv has quit IRC | 10:36 | |
*** spotz is now known as spotz_zzz | 10:39 | |
*** caowei has quit IRC | 10:41 | |
*** Andrew_jedi has joined #openstack-ansible | 10:45 | |
*** markvoelker has joined #openstack-ansible | 11:11 | |
*** markvoelker has quit IRC | 11:16 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_monasca: Fix the token cache_time https://review.openstack.org/416210 | 11:16 |
openstackgerrit | Merged openstack/openstack-ansible-galera_server: Use local facts for ansible_architecture https://review.openstack.org/413682 | 11:16 |
*** sacharya has joined #openstack-ansible | 11:20 | |
*** sacharya has quit IRC | 11:24 | |
openstackgerrit | Merged openstack/openstack-ansible-tests: Run cinder-setup against cinder_volume hosts https://review.openstack.org/413747 | 11:34 |
*** shausy has joined #openstack-ansible | 11:38 | |
*** smatzek has joined #openstack-ansible | 11:41 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-galera_client: Allow override of the repo filename https://review.openstack.org/416218 | 11:41 |
*** david-lyle has joined #openstack-ansible | 11:59 | |
*** Jack_Iv has joined #openstack-ansible | 12:00 | |
*** david-lyle has quit IRC | 12:04 | |
*** Jack_Iv has quit IRC | 12:04 | |
*** markvoelker has joined #openstack-ansible | 12:12 | |
*** markvoelker has quit IRC | 12:16 | |
*** NachoDuck has quit IRC | 12:19 | |
*** worstadmin has quit IRC | 12:19 | |
*** h1nch has quit IRC | 12:19 | |
*** errr has quit IRC | 12:19 | |
*** xar- has quit IRC | 12:19 | |
*** serverascode has quit IRC | 12:19 | |
*** kong_ has quit IRC | 12:19 | |
*** ArchiFleKs has quit IRC | 12:19 | |
*** xgerman has quit IRC | 12:19 | |
*** izaakk has quit IRC | 12:19 | |
*** h1nch has joined #openstack-ansible | 12:19 | |
*** ArchiFleKs has joined #openstack-ansible | 12:19 | |
*** errr has joined #openstack-ansible | 12:19 | |
*** xar- has joined #openstack-ansible | 12:20 | |
*** worstadmin has joined #openstack-ansible | 12:20 | |
*** kong_ has joined #openstack-ansible | 12:21 | |
*** izaakk has joined #openstack-ansible | 12:21 | |
*** NachoDuck has joined #openstack-ansible | 12:23 | |
*** xgerman has joined #openstack-ansible | 12:24 | |
*** serverascode has joined #openstack-ansible | 12:25 | |
*** SerenaFeng has quit IRC | 12:25 | |
ivve | hello, is this the proper channel to ask for configuration help/explanations? | 12:29 |
andymccr | ivve: for openstack-ansible? sure is! | 12:35 |
ivve | :) | 12:36 |
pjm6 | good morning guys :) | 12:37 |
*** pradiprwt has joined #openstack-ansible | 12:37 | |
ivve | so im trying to create a configuration here but having trouble understanding how to properly configure nova/glance/cinder with ceph, from what i can read from mitaka/newton documentation (wierdly enough they differ alot, not sure why) you can configure it completely with only openstack_user_config.yml? but its also possible with user_variables.yml.. | 12:39 |
*** marc_ab has joined #openstack-ansible | 12:39 | |
andymccr | ivve: we did a big restructure of the docs last cycle, so the newton docs are more up to date and should be easier to use! | 12:41 |
ivve | and of course i have a network question, is it possible to create an openstack installation with OSA with only 1 vlan but different machines? im guessing the net config will be wierd, its basically to test HA functionality | 12:41 |
ivve | i only have access to a /24 cidr with one vlan (doing it in vmware, ugh..) but this is what i have available | 12:42 |
openstackgerrit | Merged openstack/openstack-ansible-os_monasca: Fix the token cache_time https://review.openstack.org/416210 | 12:42 |
*** hw_wutianwei has quit IRC | 12:42 | |
andymccr | as a run down of the vars files, the openstack_user_config is generally where you would specify your physical hosts and settings for specific hosts, and the user_variables is more for generic overrides (e.g. you may override a specific var within nova for all nova hosts) | 12:42 |
andymccr | ivve: when you say you have only 1 vlan, for your physical hosts? | 12:43 |
ivve | yes, but im using virtual hosts | 12:43 |
ivve | as this is a poc sort of | 12:43 |
*** hwoarang_ is now known as hwoarang | 12:43 | |
ivve | basically learning OSA and trying out functionality at the same time | 12:44 |
andymccr | ivve: if you can create network interfaces that can connect to each other on both hosts it should be fine, you can use internal network ranges - the fact you have 1 vlan shouldn't matter since its a POC anyway. | 12:46 |
ivve | the confusing part is for example: some documentation tells me its possible to configure "container_vars:" in openstack_user_config.yml or in user_variables.yml | 12:48 |
ivve | plus when reading documentation some options are described but others are not, is there a full specification of all availble options? | 12:49 |
ivve | i would prefer to use a manual than waste someones time here :) | 12:49 |
ivve | yeah i got the thing with the vars vs user_config, and i can see what would be a best practice to understand configuration | 12:54 |
andymccr | ivve: definitely - so we don't specify all the vars you can override - the guide is meant as a "getting started here are some things you may need to know", although if you're finding things confusing and you'd like to file docs bugs that'd be great too! | 12:54 |
andymccr | the diff between container_Vars and puting a setting in user_variables is that container_vars would only apply to hosts/containers on the specified host, whereas user_variables would apply globally | 12:54 |
ivve | hmm alright is there a good example where you would put a specific variable on a host/container that exists on all? i mean as an example, "cinder_backends" would only apply to storage_hosts, no? | 12:58 |
ivve | ah okay, i get it now... forget this question | 12:59 |
andymccr | ivve: well its not so much that it only applies to storage_hosts, but its that a cinder_backend is specific to an individual host, so thats a great example of one that would go into the openstack_user_config.yml rather than user_variables. | 12:59 |
ivve | i see that it would be applicable in a very large environment where you have multiple storage_hosts serving different backend storages? | 13:00 |
andymccr | ivve: yeah i guess if you had one storage_host you could specify it in user_variables. but if you had more than one you wouldn't want to have the same applies to multiple storage hosts. | 13:00 |
andymccr | *applied | 13:00 |
ivve | there are configs like that in the examples so they confused me a bit | 13:02 |
ivve | i would tag it a rather "advanced" configuration :) | 13:02 |
ivve | but perhaps its more common than i would think :P | 13:02 |
*** sdake has joined #openstack-ansible | 13:03 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-galera_server: Allow override of the repo filename https://review.openstack.org/416234 | 13:08 |
evrardjp | andymccr: I saw your comment on the release note, I'll do it for all the commits on the same topic -- my prose isn't good so I delay as much as possible right now :p | 13:10 |
evrardjp | (this way you don't review the one just here ^ ) | 13:10 |
andymccr | evrardjp: thanks :D | 13:11 |
*** markvoelker has joined #openstack-ansible | 13:12 | |
*** alextricity25_ is now known as alextricity25 | 13:16 | |
*** markvoelker has quit IRC | 13:17 | |
*** Mudpuppy has joined #openstack-ansible | 13:18 | |
*** sacharya has joined #openstack-ansible | 13:20 | |
mhayden | buenos dias | 13:21 |
*** Mudpuppy has quit IRC | 13:23 | |
*** sacharya has quit IRC | 13:25 | |
evrardjp | bonjour mhayden | 13:29 |
*** thorst has joined #openstack-ansible | 13:30 | |
*** jheroux has joined #openstack-ansible | 13:34 | |
*** shausy has quit IRC | 13:36 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-galera_client: Allow override of the repo filename https://review.openstack.org/416218 | 13:38 |
*** klamath has joined #openstack-ansible | 13:39 | |
*** klamath has quit IRC | 13:39 | |
*** klamath has joined #openstack-ansible | 13:39 | |
*** shausy has joined #openstack-ansible | 13:40 | |
*** sdake has quit IRC | 13:41 | |
*** shausy has quit IRC | 13:43 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-galera_server: Allow override of the repo filename https://review.openstack.org/416234 | 13:44 |
*** mgariepy has quit IRC | 13:47 | |
*** mamitchl has quit IRC | 13:47 | |
*** toddnni has quit IRC | 13:47 | |
*** Jolrael has quit IRC | 13:47 | |
*** toddnni has joined #openstack-ansible | 13:47 | |
*** ivve has quit IRC | 13:48 | |
*** furlongm_ has quit IRC | 13:48 | |
*** furlongm has joined #openstack-ansible | 13:48 | |
*** ivve has joined #openstack-ansible | 13:49 | |
*** Jeffrey4l has quit IRC | 13:49 | |
*** mgariepy has joined #openstack-ansible | 13:50 | |
*** Jeffrey4l has joined #openstack-ansible | 13:59 | |
*** woodard has joined #openstack-ansible | 14:00 | |
*** david-lyle has joined #openstack-ansible | 14:01 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_neutron: Allow override of the repo filename https://review.openstack.org/416245 | 14:02 |
*** woodard has quit IRC | 14:02 | |
*** woodard has joined #openstack-ansible | 14:03 | |
*** ivve has quit IRC | 14:04 | |
*** david-lyle has quit IRC | 14:05 | |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: Update title for index file https://review.openstack.org/416247 | 14:09 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_neutron: Allow override of the repo filename https://review.openstack.org/416245 | 14:11 |
*** markvoelker has joined #openstack-ansible | 14:13 | |
*** Jack_Iv has joined #openstack-ansible | 14:16 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_nova: Allow override of the repo filename https://review.openstack.org/416251 | 14:16 |
*** fguillot has joined #openstack-ansible | 14:18 | |
openstackgerrit | Merged openstack/openstack-ansible: Update title for index file https://review.openstack.org/416247 | 14:18 |
*** markvoelker has quit IRC | 14:18 | |
*** kylek3h has joined #openstack-ansible | 14:18 | |
*** Jack_Iv has quit IRC | 14:20 | |
evrardjp | andymccr: bug triage today? | 14:30 |
evrardjp | and others :) | 14:31 |
evrardjp | We have 11 bugs, 5 are old | 14:31 |
andymccr | evrardjp: yeah think we should, i dont think there are too many - i had a look last week | 14:31 |
andymccr | easier if we keep on top of it imo | 14:31 |
evrardjp | ok | 14:31 |
evrardjp | let me ping everyone | 14:31 |
evrardjp | dear cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, | 14:32 |
evrardjp | spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, severion, bgmccollum, darrenc, JRobinson__, asettle, colinmcnamara, thorst, adreznec, eil397 : | 14:32 |
evrardjp | the osa bug triage will start in 1h30’. Please have a look at the bug list before starting: https://etherpad.openstack.org/p/osa-bugtriage | 14:32 |
evrardjp | qwang,nishpatwa_, cathrichardson, drifterza ^ | 14:32 |
*** smatzek has quit IRC | 14:34 | |
*** jperry has joined #openstack-ansible | 14:36 | |
*** markvoelker has joined #openstack-ansible | 14:38 | |
*** woodard has quit IRC | 14:39 | |
*** galstrom_zzz is now known as galstrom | 14:40 | |
*** julian1 has quit IRC | 14:44 | |
*** julian1 has joined #openstack-ansible | 14:45 | |
asettle | evrardjp: thanks man | 14:46 |
*** ivve has joined #openstack-ansible | 14:47 | |
*** chhavi has joined #openstack-ansible | 14:47 | |
*** shananigans has quit IRC | 14:48 | |
*** galstrom is now known as galstrom_zzz | 14:50 | |
*** jamesden_ has joined #openstack-ansible | 14:53 | |
*** shananigans has joined #openstack-ansible | 14:53 | |
*** v1k0d3n has joined #openstack-ansible | 14:59 | |
*** smatzek has joined #openstack-ansible | 15:01 | |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible: Add retries to apt update in cache proxy task https://review.openstack.org/416262 | 15:01 |
*** david-lyle has joined #openstack-ansible | 15:01 | |
*** david-lyle has quit IRC | 15:06 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:07 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-repo_build: Allow override of the repo filename https://review.openstack.org/416266 | 15:13 |
*** spotz_zzz is now known as spotz | 15:14 | |
*** sacharya has joined #openstack-ansible | 15:21 | |
*** sacharya has quit IRC | 15:26 | |
*** woodard has joined #openstack-ansible | 15:26 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 15:27 |
*** whiteveil has joined #openstack-ansible | 15:27 | |
spotz | Happy New Years all | 15:29 |
palendae | o/ | 15:30 |
*** Jolrael has joined #openstack-ansible | 15:30 | |
pjm6 | happy new year spotz :) | 15:34 |
*** woodard has quit IRC | 15:35 | |
*** sliver has quit IRC | 15:38 | |
openstackgerrit | Merged openstack/openstack-ansible-pip_install: Using sys.exit(main()) instead of main() https://review.openstack.org/415317 | 15:40 |
*** whiteveil has quit IRC | 15:41 | |
kysse | guys, I'm having weird problems with dnsmasq and newton. | 15:41 |
kysse | dnsmasq's logs says "dhcp not using configured address because it is leased to", and half of my instances don't get ip-addresses | 15:42 |
kysse | (not related to openstack-ansible project so this is not a bug report) | 15:42 |
kysse | I'm just interested if you guys have experienced anything like this. | 15:42 |
evrardjp | happy new year everyone | 15:43 |
evrardjp | kysse: you mean your instances have issues with your lxcbr0 ? | 15:44 |
mhayden | same to you, evrardjp | 15:44 |
evrardjp | kysse: what do you mean by don't get ip-addresses -- i.e. on which networks | 15:44 |
evrardjp | mhayden: while you're here, did you experience any issues with SSH when upgrading 14.04 to 16.04? | 15:45 |
mhayden | evrardjp: ssh was the least of my problems :/ | 15:45 |
*** sdake has joined #openstack-ansible | 15:45 | |
mhayden | still trying to figure out some of the blackscreening on boot that i had | 15:45 |
evrardjp | well with ansible it could be the worst if the init script is borked | 15:45 |
evrardjp | and you lose ssh everywhere | 15:45 |
evrardjp | oh well | 15:45 |
evrardjp | ok I see | 15:46 |
openstackgerrit | Merged openstack/openstack-ansible-os_aodh: Remove pki support https://review.openstack.org/415560 | 15:46 |
evrardjp | understood it was really the least of your problems! | 15:46 |
kysse | evrardjp: on any network. DNSMasq provides leases to ~50% of my instances. This problem is not ansible project related. | 15:46 |
openstackgerrit | Merged openstack/openstack-ansible-os_gnocchi: Remove pki support https://review.openstack.org/415583 | 15:47 |
mhayden | if you set up a periodic openstack ci job for a repo, what happens with the results? | 15:48 |
mhayden | in other words, if it fails, what happens? | 15:48 |
*** TxGirlGeek has joined #openstack-ansible | 15:49 | |
*** galstrom_zzz is now known as galstrom | 15:50 | |
*** adrian_otto has joined #openstack-ansible | 15:51 | |
*** shausy has joined #openstack-ansible | 15:51 | |
openstackgerrit | Merged openstack/openstack-ansible-os_watcher: Remove pki support https://review.openstack.org/415604 | 15:52 |
*** spotz_zzz has joined #openstack-ansible | 15:52 | |
mhayden | security role gate is broken again :| razzafrazza | 15:52 |
*** weezS has joined #openstack-ansible | 15:53 | |
openstackgerrit | Merged openstack/openstack-ansible-os_barbican: Remove pki support https://review.openstack.org/415571 | 15:54 |
openstackgerrit | Merged openstack/openstack-ansible-os_sahara: Remove pki support https://review.openstack.org/415603 | 15:54 |
kysse | it feels like dnsmasq is too slow | 15:55 |
kysse | and it seems so. bah. | 15:55 |
openstackgerrit | Merged openstack/openstack-ansible-os_designate: Remove pki support https://review.openstack.org/415580 | 15:55 |
*** whiteveil has joined #openstack-ansible | 15:57 | |
*** sliver has joined #openstack-ansible | 15:58 | |
andymccr | mhayden: that damn security role! | 15:58 |
mhayden | lawl | 15:58 |
*** shausy has quit IRC | 15:59 | |
openstackgerrit | Merged openstack/openstack-ansible-os_trove: Remove pki support https://review.openstack.org/415605 | 16:00 |
openstackgerrit | Merged openstack/openstack-ansible-os_ceilometer: Remove pki support https://review.openstack.org/415574 | 16:01 |
*** h5t4 has quit IRC | 16:01 | |
evrardjp | Bug triage cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, | 16:03 |
evrardjp | spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, severion, bgmccollum, darrenc, JRobinson__, asettle, colinmcnamara, thorst, adreznec, eil397, qwang, nishpatwa_, cathrichardson, drifterza | 16:03 |
evrardjp | Here is our bug list for today https://etherpad.openstack.org/p/osa-bugtriage | 16:03 |
asettle | Danke danke | 16:03 |
andymccr | lets do this | 16:04 |
alextricity25 | o/ | 16:04 |
d34dh0r53 | o/ | 16:04 |
prometheanfire | o/ | 16:04 |
evrardjp | first bug: https://bugs.launchpad.net/openstack-ansible/+bug/1653483 | 16:04 |
openstack | Launchpad bug 1653483 in openstack-ansible "/etc/keystone/ssl empty" [Undecided,New] | 16:04 |
evrardjp | I don't get this one, can keystone store things in ceph, like tokens? | 16:05 |
asettle | That doesn't seem like our problem? | 16:05 |
evrardjp | rados is cool but it's an unknown feature to me | 16:05 |
evrardjp | I'd be enclined to say invalid indeed, or ask for more questions -- not sure what's the problem here | 16:06 |
asettle | This honestly doesn't read as if it's an OPenStack-Ansible problem either. The reporter is simply trying to integrate a thing into OpenStack but is expecting a certificate in keystone. | 16:06 |
asettle | Which, we don't even have Ceph integrated properly either. | 16:06 |
asettle | I would comment on it, evrardjp with reasoning, and mark as invalid. | 16:06 |
asettle | We do not generate certificate | 16:06 |
asettle | certificates* | 16:06 |
alextricity25 | Keystone SSL is offloaded in the LB right? | 16:06 |
alextricity25 | If so, it makes sense that there are no certs in that container | 16:06 |
openstackgerrit | Merged openstack/openstack-ansible-os_ironic: Remove pki support https://review.openstack.org/415596 | 16:07 |
evrardjp | so there is no ceph object feature integrated with keystone | 16:07 |
alextricity25 | Where it would be a problem is if external_ssl is set to false, and it was still empty | 16:07 |
evrardjp | so then yes, it's invalid :p | 16:07 |
evrardjp | oh I understand what you mean -- but I'm sure we are using that folder in that case | 16:07 |
evrardjp | well it's worth clarifying in all cases, I'll ask the usual questions | 16:08 |
evrardjp | I'll handle this! | 16:08 |
evrardjp | next | 16:08 |
*** marst has joined #openstack-ansible | 16:08 | |
alextricity25 | Right - maybe we could mark this one as "needs more info". Still, it sounds like a configurations problem/lack of understanding. | 16:08 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1653228 | 16:08 |
openstack | Launchpad bug 1653228 in openstack-ansible "Install Guide not found (404)" [Undecided,New] | 16:08 |
asettle | Yeah I just read this one. | 16:08 |
logan- | that nss database is only used when keystone is using pki tokens. radosgw needs the keys to validate the keystone tokens it receives | 16:08 |
asettle | Honestly this shouldn't actually be a problem if someone was following hte right guide links | 16:08 |
evrardjp | alextricity25: yes indeed -- it will be marked as incomplete for now | 16:09 |
asettle | BUT this made me realise that people might be trying to access this link from google. | 16:09 |
alextricity25 | k | 16:09 |
asettle | And then it's returning a 404 | 16:09 |
*** chris_hultin is now known as chris_hultin|AWA | 16:09 | |
evrardjp | logan-: oh | 16:09 |
evrardjp | I forgot these different tokens | 16:09 |
evrardjp | pki and pki-z | 16:09 |
asettle | It might be worthwhile talking to infra evrardjp and andymccr to see if they could put a redirect on: http://docs.openstack.org/developer/openstack-ansible/install-guide/ | 16:10 |
evrardjp | or something like that | 16:10 |
asettle | Or maybe we could do it | 16:10 |
*** chris_hultin|AWA is now known as chris_hultin | 16:10 | |
evrardjp | if you don't mind guys it's worth getting back to previous bug: | 16:11 |
evrardjp | it means we have problem with deployers using PKI tokens | 16:11 |
*** winggundamth has quit IRC | 16:11 | |
evrardjp | I vote for still incomplete, but it's something we have to pay attention to | 16:11 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 16:11 |
evrardjp | ok now the docs one | 16:11 |
andymccr | evrardjp: i doubt theyre using pki - just default and wondering why its not there = but yeah more info is better | 16:12 |
evrardjp | redirect is not that easy IIRC - andymccr your opinion? Maybe just a page that says -- old content, see here instead ? | 16:13 |
openstackgerrit | Merged openstack/openstack-ansible-os_nova: Remove pki support https://review.openstack.org/415602 | 16:13 |
andymccr | the docs one would be good to get more info too - was the url typed in manually, or did the user get there some other way? if its manual im not too sure the best approach - we could maybe find out about a redirect like asettle suggested. | 16:13 |
asettle | Yeah I'm commenting on that now. I don't think we need a redirect. But I'm going to include a note. | 16:13 |
andymccr | i can look into that, but id like to get an idea of what actually happened vs what was expected before trying that | 16:13 |
asettle | I'll take this one and confirm it. | 16:13 |
andymccr | ok cool thanks asettle | 16:13 |
*** dxiri has joined #openstack-ansible | 16:13 | |
evrardjp | asettle: ok cool , thanks! | 16:14 |
evrardjp | next | 16:14 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1652501 | 16:14 |
openstack | Launchpad bug 1652501 in openstack-ansible "API: rados and rbd python libraries not found" [Undecided,New] | 16:14 |
dxiri | hey OSA, I am facing a problem during setup-hosts, any help? | 16:14 |
dxiri | HTTPConnectionPool(host='172.29.236.11', port=8181): Max retries exceeded with url: /os-releases/14.0.2/ (Caused by ResponseError('too many 503 error responses',))\n"} | 16:14 |
*** KLevenstein has joined #openstack-ansible | 16:15 | |
smatzek | evrardjp, on that Ceph bug. Ceph lets you setup its gateway servers to use Keystone for authentication. The Rados GW servers provide REST APIs for object access that have a high level of parity with Swift. The bug creator seems to be having problems because of a lack of SSL certs in the OSA deployed Keystone | 16:15 |
andymccr | dxiri: we're just doing bug triage, but we'll be done soon - and happy to help debug after that! | 16:15 |
dxiri | andymccr: awesome thanks :) sry to interrupt | 16:16 |
evrardjp | smatzek: ok so there was a feature with ceph and keystone, not just the way I thought! Cool to know | 16:16 |
evrardjp | I'll ask for more details and see if it wouldn't be a bug for ceph-ansible too | 16:16 |
evrardjp | well it seems it's a specific use case, but let's discuss that in the bug | 16:17 |
evrardjp | for the https://bugs.launchpad.net/openstack-ansible/+bug/1652501 -- incomplete -> ok for everyone? | 16:17 |
openstack | Launchpad bug 1652501 in openstack-ansible "API: rados and rbd python libraries not found" [Undecided,New] | 16:17 |
andymccr | evrardjp: seems fine to me | 16:17 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 16:17 |
evrardjp | next: https://bugs.launchpad.net/openstack-ansible/+bug/1651521 | 16:17 |
openstack | Launchpad bug 1651521 in openstack-ansible "OSA uses deprecated tenant_id for endpoints in catalog" [Undecided,New] | 16:17 |
openstackgerrit | Merged openstack/openstack-ansible-os_glance: Remove pki support https://review.openstack.org/415581 | 16:18 |
evrardjp | confirmed low? | 16:18 |
andymccr | yeah seems right to me | 16:18 |
evrardjp | except if alextricity25 thinks it higher prio? | 16:18 |
evrardjp | it doesn't seem blocking | 16:18 |
alextricity25 | evrardjp: That sounds good to me | 16:18 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [DOCS] Remove ops content from dev docs https://review.openstack.org/416286 | 16:18 |
evrardjp | ok | 16:19 |
evrardjp | next | 16:19 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1650647 | 16:19 |
openstack | Launchpad bug 1650647 in openstack-ansible "Newton: Git server not working " [Undecided,Invalid] | 16:19 |
evrardjp | good fixed! | 16:19 |
evrardjp | (or not) | 16:19 |
evrardjp | :p | 16:19 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1645728 | 16:19 |
openstack | Launchpad bug 1645728 in openstack-ansible "Liberty to Liberty Upgrade: MariaDB upgrade stuck on post dpkg configure task" [Undecided,New] | 16:19 |
evrardjp | sadly BjoernT isn't here | 16:19 |
andymccr | yeah that git one seems fixed | 16:20 |
*** ivve has quit IRC | 16:20 | |
andymccr | and that mariadb one is still pending more info. afaict its not really something we can fix, would be good to know it's being looked at upstream though | 16:20 |
evrardjp | next one on the list is also done | 16:20 |
evrardjp | andymccr: yes precisely | 16:20 |
evrardjp | that's why I don't close and I'm sad Bjoern isn't here to talk abou it | 16:21 |
evrardjp | but yes, we can't do much | 16:21 |
evrardjp | next next then | 16:21 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1646124 | 16:21 |
openstack | Launchpad bug 1646124 in openstack-ansible "Swift is generating audit.log errors on CentOS with selinux enabled" [Wishlist,New] | 16:21 |
evrardjp | mgariepy: are you there? | 16:21 |
evrardjp | probably still in the new year's holidays -- let's go to next one | 16:22 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1649381 | 16:22 |
openstack | Launchpad bug 1649381 in openstack-ansible "config_template does not support {% raw %}" [Low,New] - Assigned to Praveen N (praveenn) | 16:22 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder: Remove pki support https://review.openstack.org/415578 | 16:22 |
evrardjp | maybe worth discussing with praveen to see news, but I didn't see any commits -- logan- do you have news from this one? | 16:23 |
andymccr | yeah agreed | 16:23 |
andymccr | otherwise i think its fine where it is - at low, we can wait some for movement on that | 16:23 |
evrardjp | yes, it's not like if it was a performance issue that's unfixed... | 16:24 |
*** chhavi has quit IRC | 16:24 | |
evrardjp | #loveubuntuxenial | 16:24 |
*** KLevenstein has quit IRC | 16:24 | |
evrardjp | so last one for today | 16:24 |
evrardjp | https://bugs.launchpad.net/openstack-ansible/+bug/1650350 | 16:24 |
openstack | Launchpad bug 1650350 in openstack-ansible "Newton: Haproxy and repo roles SSL issues when internal=extenal VIP" [Medium,New] | 16:24 |
*** rromans has quit IRC | 16:24 | |
evrardjp | I still think we should explain to ppl not to do that | 16:25 |
*** cathrichardson has joined #openstack-ansible | 16:25 | |
evrardjp | we could still write a lot of jinja code to fix this, but I still think we shouldn't do it | 16:25 |
andymccr | hmm. | 16:26 |
andymccr | you mean set intenral and external to the same? | 16:26 |
evrardjp | we have public and internal endpoints -- why would you collocate all of them on the same IP port? It makes sense to me to at least separate them, even on the same network | 16:26 |
evrardjp | yes, we've done code to fix this already | 16:26 |
evrardjp | but we may need to add more | 16:26 |
evrardjp | and more | 16:26 |
andymccr | yeah true | 16:27 |
evrardjp | for something that shouldn't exist IMO | 16:27 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 16:27 |
evrardjp | it's not expensive to have ONE more ip | 16:27 |
evrardjp | even private | 16:27 |
andymccr | esp if youre using haproxy | 16:27 |
evrardjp | you can even assign 127.0.0.2 if you want | 16:27 |
evrardjp | :p | 16:27 |
evrardjp | well that doesn't make sense either | 16:27 |
evrardjp | but just as a point | 16:27 |
andymccr | haha yeah but at the same time, should you be able to do SSL internal? | 16:28 |
andymccr | i guess we dont support it so no? | 16:28 |
*** dmellado_ has joined #openstack-ansible | 16:28 | |
evrardjp | well internal SSL or internal no SSL is just detail -- not binding on the same IP and port is not a detail | 16:28 |
andymccr | true | 16:29 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [DOCS] Remove ops content from dev docs https://review.openstack.org/416286 | 16:29 |
evrardjp | and if we're lacking the flexibility of configuring haproxy differently (only one front for the backends), then we may need to find contributors willing to spend time to refactor this | 16:30 |
evrardjp | in the mean time I'd say low at best | 16:30 |
evrardjp | and confirmed | 16:30 |
evrardjp | because yes it sucks | 16:30 |
evrardjp | :p | 16:30 |
*** Andrew_jedi has quit IRC | 16:30 | |
andymccr | yeah | 16:30 |
andymccr | ok | 16:31 |
evrardjp | but we should really educate ppl to not do that | 16:31 |
andymccr | im sure when bjoernt is back we can get more discussion on that | 16:31 |
evrardjp | so the fix may only be a doc fix | 16:31 |
evrardjp | sure | 16:31 |
*** rromans has joined #openstack-ansible | 16:31 | |
asettle | evrardjp and andymccr - Bjoern actually should be back. He was only off until the 26th | 16:32 |
asettle | He probably just isn't online rn | 16:32 |
asettle | If it's not urgent, just email him and he'll get there | 16:32 |
evrardjp | that's so personal :) | 16:32 |
evrardjp | we can wait, it's now classified as a "low" bug :p | 16:32 |
evrardjp | anyway, thanks for your time everyone! | 16:33 |
evrardjp | and happy new year! | 16:33 |
evrardjp | wooot! | 16:33 |
asettle | \o/ yay | 16:33 |
asettle | Andy is watching PPAP | 16:33 |
asettle | *head desk* | 16:33 |
*** Andrew_jedi has joined #openstack-ansible | 16:34 | |
palendae | ? | 16:34 |
palendae | Pineapple pen? | 16:34 |
asettle | Pen pineapple apple pen | 16:34 |
palendae | Oh | 16:34 |
asettle | There's a orchestra version that Japan did for NY | 16:34 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 16:35 |
*** adrian_otto has quit IRC | 16:35 | |
andymccr | dxiri: sorry for the delay - the 503's on port 8181, that suggests the repo server is failing out - it would be go good to check the logs on the repo container(s). Otherwise confirm that haproxy is working properly for the repo server | 16:36 |
evrardjp | what is that? | 16:36 |
asettle | andymccr and evrardjp - in partial response to that install guide related bug, I've added this: https://review.openstack.org/#/c/416286/2/doc/source/developer-docs/index.rst | 16:36 |
*** adrian_otto has joined #openstack-ansible | 16:36 | |
asettle | It's just a little link within the dev docs | 16:36 |
asettle | But the rest of the bug is marked as incomplete and need context. | 16:36 |
evrardjp | oh man PPAP was definitely something lacking in my culture | 16:38 |
evrardjp | ok I think the context is the most important part here | 16:39 |
evrardjp | the bug was filed from main page so it's hard to know | 16:40 |
evrardjp | cloudnull: are you there? | 16:40 |
evrardjp | or still renovating? | 16:40 |
palendae | evrardjp: He's still out | 16:42 |
spotz | o/ late | 16:43 |
openstackgerrit | Alexandra Settle proposed openstack/openstack-ansible: [DOCS] Remove ops content from dev docs https://review.openstack.org/416286 | 16:44 |
*** adrian_otto has quit IRC | 16:45 | |
*** KLevenstein has joined #openstack-ansible | 16:47 | |
*** michaelgugino has joined #openstack-ansible | 16:50 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 16:50 |
dxiri | andymccr: even after destroying the containers and starting from scratch, I am seeing that same issue. | 16:52 |
andymccr | dxiri: 503 is service unavailable, so my guess is that the VIP is setup but it isn't pointing to the correct place | 16:54 |
dxiri | is it safe to remove /etc/haproxy/conf.d/ dir from the container host so the haproxy config gets recreated? | 16:54 |
andymccr | or the service inside the containers isn't running properly - so it can't be balanced to. | 16:54 |
andymccr | dxiri: it would be, but there shouldnt be any point since it should just write over it | 16:54 |
andymccr | brb! | 16:54 |
dxiri | k, so to give some context, I initially went trough all the playbooks and on the setup-openstack one I noticed I had an incorrect setting for the vxlan interface, so I fixed that, destroyed all containers and started over again | 16:56 |
dxiri | and now I am facing this 503 thing | 16:56 |
*** sdake has quit IRC | 16:57 | |
*** david-lyle has joined #openstack-ansible | 17:03 | |
kysse | https://www.softwareab.net/wordpress/openstack-debugging-neutron-dhcp/ how to fix this in newton other than restarting dhcp-agent? It seems to happen randomly. | 17:05 |
*** adrian_otto has joined #openstack-ansible | 17:06 | |
*** chris_hultin is now known as chris_hultin|AWA | 17:07 | |
*** cathrichardson has quit IRC | 17:07 | |
*** david-lyle has quit IRC | 17:08 | |
*** chas has quit IRC | 17:09 | |
*** chas has joined #openstack-ansible | 17:09 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: [WIP] Testing security role gate https://review.openstack.org/416269 | 17:09 |
*** chris_hultin|AWA is now known as chris_hultin | 17:11 | |
*** jgriffiths has joined #openstack-ansible | 17:12 | |
*** chas has quit IRC | 17:14 | |
dxiri | ok...the previous haproxy process was running, I moved /etc/haproxy to haproxy.backup and stopped haproxy, that seemed to have worked :) | 17:20 |
*** mudpuppy has joined #openstack-ansible | 17:23 | |
*** erikmwilson has quit IRC | 17:24 | |
*** erikmwilson has joined #openstack-ansible | 17:24 | |
*** joelgriffiths has joined #openstack-ansible | 17:26 | |
*** chris_hultin is now known as chris_hultin|AWA | 17:26 | |
*** cathrichardson has joined #openstack-ansible | 17:28 | |
*** jgriffiths has quit IRC | 17:29 | |
*** chris_hultin|AWA is now known as chris_hultin | 17:32 | |
*** adrian_otto has quit IRC | 17:33 | |
andymccr | dxiri: ahh nice, sorry i was away longer than expected - glad its working now though! | 17:34 |
*** thorst is now known as thorst_afk | 17:35 | |
dxiri | and of course there is a new problem now :) | 17:35 |
*** adrian_otto has joined #openstack-ansible | 17:35 | |
*** chris_hultin is now known as chris_hultin|AWA | 17:37 | |
*** dxiri has quit IRC | 17:37 | |
*** dxiri has joined #openstack-ansible | 17:37 | |
*** chris_hultin|AWA is now known as chris_hultin | 17:37 | |
*** cmart has joined #openstack-ansible | 17:37 | |
*** joelgriffiths has quit IRC | 17:38 | |
*** dxiri_ has joined #openstack-ansible | 17:38 | |
*** dxiri has quit IRC | 17:38 | |
cmart | is this the place to discuss the host security measures (specifically AIDE) that OSA implements? | 17:41 |
cmart | I'm curious why OSA configures AIDE to use so many checksums for each tracked file: "sha256+sha512+rmd160+haval+gost+crc32+tiger". Seems like super overkill and sha512 should suffice | 17:42 |
palendae | mhayden's probably the expert there | 17:43 |
cmart | It looks like that's the default for Ubuntu and OSA doesn't override it -- so maybe I should be bugging the AIDE developers or Ubuntu/Debian packagers instead :) | 17:46 |
*** whiteveil has quit IRC | 17:48 | |
stevelle | cmart: good call on the ubuntu default there | 17:49 |
*** thorst_afk is now known as thorst | 17:51 | |
openstackgerrit | Merged openstack/openstack-ansible: [DOCS] Remove ops content from dev docs https://review.openstack.org/416286 | 17:57 |
*** pcaruana has quit IRC | 17:58 | |
*** zz_pwnall1337 is now known as pwnall1337 | 17:58 | |
*** asettle has quit IRC | 18:02 | |
*** asettle has joined #openstack-ansible | 18:03 | |
*** david-lyle has joined #openstack-ansible | 18:03 | |
*** asettle has quit IRC | 18:07 | |
*** david-lyle has quit IRC | 18:08 | |
*** Jack_Iv has joined #openstack-ansible | 18:17 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Unblock security role gate https://review.openstack.org/416269 | 18:19 |
mhayden | cmart: i thought that was silly as well, but i found the requirement in the STIG for RHEL 7 | 18:20 |
mhayden | cmart: https://github.com/openstack/openstack-ansible-security/blob/master/files/aide_extra.conf | 18:21 |
*** Jack_Iv has quit IRC | 18:21 | |
mhayden | http://rhel7stig.readthedocs.io/en/latest/low.html#rhel-07-021600-the-file-integrity-tool-must-be-configured-to-verify-access-control-lists-acls | 18:21 |
*** cathrichardson has quit IRC | 18:23 | |
*** spotz_zzz is now known as spotz_ | 18:23 | |
*** KLevenstein has quit IRC | 18:25 | |
*** cathrichardson has joined #openstack-ansible | 18:25 | |
*** marc_ab has quit IRC | 18:28 | |
cmart | mhayden I'm not seeing where all of those other checksum algorithms are listed -- I see here http://rhel7stig.readthedocs.io/en/latest/medium.html?highlight=file%20integrity%20tool#rhel-07-021620-the-file-integrity-tool-must-use-fips-140-2-approved-cryptographic-hashes-for-validating-file-contents-and-directories basically says sha512 on its own is OK | 18:28 |
mhayden | hmm, i may need to go re-review that | 18:29 |
mhayden | ubuntu was weird because it's configured so much differently than centos | 18:29 |
mhayden | the config had a lot less in it | 18:29 |
*** marc_ab has joined #openstack-ansible | 18:32 | |
cmart | ya. not a big deal, but using seven different checksums for each file makes for looong reports from AIDE. | 18:33 |
*** whiteveil has joined #openstack-ansible | 18:35 | |
*** adrian_otto has quit IRC | 18:38 | |
*** adrian_otto has joined #openstack-ansible | 18:39 | |
*** sdake has joined #openstack-ansible | 18:41 | |
*** chyka has joined #openstack-ansible | 18:42 | |
*** david-lyle has joined #openstack-ansible | 18:42 | |
*** KLevenstein has joined #openstack-ansible | 18:50 | |
bgmccollum | mhayden: regarding black console, ive noticed this too. toggling between TTYs seems to force a redraw...work around while you dig for root cause... | 18:53 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Handle SELinux properly when it is disabled https://review.openstack.org/410294 | 19:02 |
mhayden | if someone has a few moments to help me unblock the security role gate, i'd be much obliged: https://review.openstack.org/#/c/416269/ | 19:03 |
*** sdake has quit IRC | 19:04 | |
*** chas has joined #openstack-ansible | 19:10 | |
*** h5t4 has joined #openstack-ansible | 19:13 | |
*** chas has quit IRC | 19:15 | |
*** MasterOfBugs has joined #openstack-ansible | 19:20 | |
*** pramodrj07 has joined #openstack-ansible | 19:20 | |
*** pramodrj07 has quit IRC | 19:23 | |
*** MasterOfBugs has quit IRC | 19:23 | |
*** MasterOfBugs has joined #openstack-ansible | 19:27 | |
*** cathrichardson has quit IRC | 19:27 | |
*** cmart has quit IRC | 19:30 | |
stevelle | would take me more than a moment to review it but I'll start | 19:33 |
*** cathrichardson has joined #openstack-ansible | 19:34 | |
*** joelgriffiths has joined #openstack-ansible | 19:34 | |
*** serverascode has quit IRC | 19:35 | |
*** NachoDuck has quit IRC | 19:35 | |
*** kong_ has quit IRC | 19:35 | |
*** ArchiFleKs has quit IRC | 19:35 | |
*** h1nch has quit IRC | 19:35 | |
*** gaudenz has quit IRC | 19:35 | |
*** gus has quit IRC | 19:35 | |
*** jamesdenton has quit IRC | 19:35 | |
*** mrhillsman has quit IRC | 19:35 | |
*** mathlin_ has quit IRC | 19:35 | |
*** gfa has quit IRC | 19:35 | |
*** irtermite has quit IRC | 19:35 | |
*** swente has quit IRC | 19:35 | |
*** gaudenz has joined #openstack-ansible | 19:35 | |
*** mathlin has joined #openstack-ansible | 19:36 | |
*** irtermite has joined #openstack-ansible | 19:36 | |
*** h1nch has joined #openstack-ansible | 19:36 | |
*** swente has joined #openstack-ansible | 19:36 | |
*** sdake has joined #openstack-ansible | 19:36 | |
*** gfa has joined #openstack-ansible | 19:36 | |
*** ArchiFleKs has joined #openstack-ansible | 19:36 | |
*** gus has joined #openstack-ansible | 19:36 | |
*** mrhillsman has joined #openstack-ansible | 19:36 | |
*** asettle has joined #openstack-ansible | 19:37 | |
alextricity25 | Does OSA have a mascot? | 19:39 |
alextricity25 | or logo? | 19:39 |
stevelle | in process | 19:39 |
alextricity25 | stevelle: Nice. What are our options? | 19:40 |
stevelle | we selected the cape buffalo | 19:40 |
stevelle | there was a 1st draft of the art but I don't have a convenient link | 19:40 |
alextricity25 | neat | 19:41 |
*** kong_ has joined #openstack-ansible | 19:41 | |
*** cmart has joined #openstack-ansible | 19:49 | |
*** poopcat has joined #openstack-ansible | 19:50 | |
*** serverascode has joined #openstack-ansible | 19:52 | |
*** NachoDuck has joined #openstack-ansible | 19:54 | |
*** sdake has quit IRC | 19:54 | |
*** jwitko has joined #openstack-ansible | 19:56 | |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder: Update paste, policy and rootwrap configurations 2016-12-30 https://review.openstack.org/415850 | 19:58 |
*** TxGirlGeek has quit IRC | 20:03 | |
*** openstackgerrit has quit IRC | 20:03 | |
*** openstackgerrit has joined #openstack-ansible | 20:07 | |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_neutron: First add for SR-IOV support in OpenStack-Ansible https://review.openstack.org/415903 | 20:07 |
*** hybridpollo has joined #openstack-ansible | 20:09 | |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_nova: Add pci_passthrough_whitelist config option for SR-IOV support in Nova https://review.openstack.org/415907 | 20:09 |
*** Andrew_jedi has quit IRC | 20:10 | |
*** hybridpolio has joined #openstack-ansible | 20:11 | |
openstackgerrit | James Denton proposed openstack/openstack-ansible: Make changes to inventory and user_variables for SR-IOV support https://review.openstack.org/415909 | 20:11 |
*** adrian_otto has quit IRC | 20:11 | |
*** hybridpollo has quit IRC | 20:14 | |
*** cathrichardson has quit IRC | 20:19 | |
*** askb has joined #openstack-ansible | 20:20 | |
*** cathrichardson has joined #openstack-ansible | 20:22 | |
openstackgerrit | Darren Chan proposed openstack/openstack-ansible: [docs] Add replace failed hardware section https://review.openstack.org/414392 | 20:32 |
*** Jack_Iv has joined #openstack-ansible | 20:32 | |
*** dxiri_ has quit IRC | 20:32 | |
*** cathrichardson has quit IRC | 20:33 | |
*** cathrichardson has joined #openstack-ansible | 20:36 | |
*** Jack_Iv has quit IRC | 20:37 | |
*** TxGirlGeek has joined #openstack-ansible | 20:37 | |
*** dxiri has joined #openstack-ansible | 20:39 | |
*** dfflanders has joined #openstack-ansible | 20:41 | |
openstackgerrit | Merged openstack/openstack-ansible: Add Apache 2.0 license to source file https://review.openstack.org/412665 | 20:41 |
openstackgerrit | Merged openstack/openstack-ansible: Update all SHAs for Ocata 2016-12-30 https://review.openstack.org/415854 | 20:41 |
*** asettle has quit IRC | 20:44 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible-security: Fix invalid user/group checks bug https://review.openstack.org/411395 | 20:50 |
openstackgerrit | James Denton proposed openstack/openstack-ansible-os_neutron: First add for SR-IOV support in OpenStack-Ansible https://review.openstack.org/415903 | 20:59 |
*** adrian_otto has joined #openstack-ansible | 21:02 | |
openstackgerrit | Merged openstack/openstack-ansible-security: Unblock security role gate https://review.openstack.org/416269 | 21:03 |
openstackgerrit | Merged openstack/openstack-ansible-security: Handle SELinux properly when it is disabled https://review.openstack.org/410294 | 21:03 |
*** whiteveil has quit IRC | 21:08 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] Test RHEL 7 STIG integration https://review.openstack.org/411406 | 21:10 |
*** chas has joined #openstack-ansible | 21:11 | |
*** jheroux has quit IRC | 21:14 | |
*** jheroux has joined #openstack-ansible | 21:15 | |
*** chas has quit IRC | 21:15 | |
mrda | Morning OSA | 21:17 |
openstackgerrit | Merged openstack/openstack-ansible-galera_client: Allow override of the repo filename https://review.openstack.org/416218 | 21:18 |
*** dxiri_ has joined #openstack-ansible | 21:20 | |
*** smatzek has quit IRC | 21:20 | |
*** Andrew_jedi has joined #openstack-ansible | 21:22 | |
spotz_ | hey mrda, happy new years | 21:22 |
*** dxiri has quit IRC | 21:23 | |
*** sdake has joined #openstack-ansible | 21:25 | |
mrda | HNYTY spotz_ | 21:26 |
*** KLevenstein has quit IRC | 21:29 | |
*** hybridpollo has joined #openstack-ansible | 21:32 | |
openstackgerrit | Merged openstack/openstack-ansible-security: Fix invalid user/group checks bug https://review.openstack.org/411395 | 21:34 |
mhayden | and there was much rejoicing | 21:35 |
*** Jeffrey4l has quit IRC | 21:35 | |
mhayden | the security role is feature complete! :) | 21:35 |
mhayden | now to find the bugs! | 21:35 |
*** Jeffrey4l has joined #openstack-ansible | 21:36 | |
spotz_ | mhayden: I'm pretty sure you said you were done before we all went off for holiday | 21:38 |
mhayden | well i was missing one thing | 21:38 |
mhayden | but now it's in | 21:38 |
palendae | until the stig is updated again | 21:38 |
mhayden | i already told the us govt to leave it alone | 21:38 |
palendae | I'm sure all the attck vectors have been found :) | 21:38 |
mhayden | :P | 21:38 |
stevelle | Some say it can do attack vector math in it's head. All we know is it's called the Stig. | 21:41 |
*** whiteveil has joined #openstack-ansible | 21:41 | |
palendae | Oof | 21:41 |
spotz_ | hehe | 21:42 |
palendae | Did the stig go over to the Grand Tour, too? | 21:42 |
stevelle | yeah, shoulda had another thing in the middle there for accuracy, but feeling lazy | 21:42 |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] Test RHEL 7 STIG integration https://review.openstack.org/411406 | 21:46 |
spotz_ | poor mhayden | 21:47 |
*** KLevenstein has joined #openstack-ansible | 21:47 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Add ANSIBLE_TEST_PLUGINS env variable https://review.openstack.org/416358 | 21:48 |
*** h5t4 has quit IRC | 21:48 | |
*** sdake has quit IRC | 21:51 | |
*** chas has joined #openstack-ansible | 21:51 | |
*** jrobinson has joined #openstack-ansible | 21:51 | |
bgmccollum | palendae no, they have some nascar guy...and he talks while driving, which is weird | 21:53 |
*** jrobinson has quit IRC | 21:53 | |
*** sdake has joined #openstack-ansible | 21:53 | |
*** jrobinson has joined #openstack-ansible | 21:54 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: Add ANSIBLE_TEST_PLUGINS env variable https://review.openstack.org/416358 | 21:56 |
*** chas has quit IRC | 21:56 | |
openstackgerrit | Major Hayden proposed openstack/openstack-ansible: [WIP] Test RHEL 7 STIG integration https://review.openstack.org/411406 | 21:57 |
*** michaelgugino has quit IRC | 21:57 | |
*** agrebennikov has joined #openstack-ansible | 21:58 | |
*** Andrew_jedi has quit IRC | 21:59 | |
*** smatzek has joined #openstack-ansible | 22:01 | |
*** thorst has quit IRC | 22:07 | |
*** thorst has joined #openstack-ansible | 22:08 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-plugins: Implementation Neutron SR-IOV https://review.openstack.org/416362 | 22:10 |
*** KLevenstein has quit IRC | 22:11 | |
*** chas has joined #openstack-ansible | 22:12 | |
*** thorst has quit IRC | 22:13 | |
*** chris_hultin is now known as chris_hultin|AWA | 22:15 | |
*** chas has quit IRC | 22:16 | |
*** whiteveil has quit IRC | 22:16 | |
*** cmart has quit IRC | 22:19 | |
*** fguillot has quit IRC | 22:22 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-plugins: Implementation Neutron SR-IOV https://review.openstack.org/416362 | 22:23 |
*** cathrichardson has quit IRC | 22:27 | |
*** cathrichardson has joined #openstack-ansible | 22:28 | |
*** sdake has quit IRC | 22:30 | |
*** pwnall1337 is now known as zz_pwnall1337 | 22:30 | |
*** cathrichardson has quit IRC | 22:32 | |
*** thorst has joined #openstack-ansible | 22:32 | |
*** cmart has joined #openstack-ansible | 22:35 | |
*** jlockwood has joined #openstack-ansible | 22:36 | |
*** thorst has quit IRC | 22:37 | |
*** galstrom is now known as galstrom_zzz | 22:41 | |
*** jheroux has quit IRC | 22:42 | |
*** smatzek has quit IRC | 22:44 | |
*** pmannidi has joined #openstack-ansible | 22:48 | |
*** adrian_otto has quit IRC | 22:52 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-plugins: Implementation Neutron SR-IOV https://review.openstack.org/416362 | 22:53 |
*** thorst has joined #openstack-ansible | 22:53 | |
*** zz_pwnall1337 is now known as pwnall1337 | 22:54 | |
*** jamesden_ has quit IRC | 22:57 | |
*** thorst has quit IRC | 22:57 | |
*** phalmos has joined #openstack-ansible | 22:58 | |
*** sdake has joined #openstack-ansible | 22:58 | |
*** jamesdenton has joined #openstack-ansible | 22:59 | |
*** chris_hultin|AWA is now known as chris_hultin | 22:59 | |
*** spotz_ is now known as spotz_zzz | 23:01 | |
*** jamesdenton has quit IRC | 23:01 | |
openstackgerrit | Bjoern Teipel proposed openstack/openstack-ansible-plugins: Implementation Neutron SR-IOV https://review.openstack.org/416362 | 23:06 |
*** jperry has quit IRC | 23:11 | |
*** openstack has joined #openstack-ansible | 23:16 | |
*** chris_hultin is now known as chris_hultin|AWA | 23:19 | |
*** marst has quit IRC | 23:21 | |
*** jlockwood has quit IRC | 23:27 | |
*** chris_hultin|AWA is now known as chris_hultin | 23:29 | |
*** chris_hultin is now known as chris_hultin|AWA | 23:30 | |
*** jlockwood has joined #openstack-ansible | 23:36 | |
*** rmelero has joined #openstack-ansible | 23:38 | |
*** winggundamth has joined #openstack-ansible | 23:47 | |
*** TxGirlGeek has quit IRC | 23:50 | |
*** klamath has quit IRC | 23:56 | |
*** woodard has joined #openstack-ansible | 23:56 | |
*** woodard has quit IRC | 23:56 | |
*** woodard has joined #openstack-ansible | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!