*** markvoelker has joined #openstack-ansible | 00:01 | |
*** shashank_t_ has quit IRC | 00:01 | |
*** jwitk0 has quit IRC | 00:02 | |
*** deadnull_ has quit IRC | 00:03 | |
*** markvoelker has quit IRC | 00:05 | |
*** cathrichardson has quit IRC | 00:08 | |
*** cathrichardson has joined #openstack-ansible | 00:09 | |
*** thorst has quit IRC | 00:12 | |
*** schwicht has joined #openstack-ansible | 00:19 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_almanach master: Ensure the components are isolated from the system https://review.openstack.org/451124 | 00:22 |
---|---|---|
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_almanach master: Ensure the components are isolated from the system https://review.openstack.org/451124 | 00:25 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_glance master: Ensure the components are isolated from the system https://review.openstack.org/451126 | 00:30 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_trove master: Ensure the components are isolated from the system https://review.openstack.org/451127 | 00:42 |
*** sanfern has quit IRC | 00:48 | |
*** vnogin has quit IRC | 00:50 | |
*** dxiri has quit IRC | 00:55 | |
*** jamielennox is now known as jamielennox|away | 01:02 | |
*** Mahe has quit IRC | 01:04 | |
*** Mahe has joined #openstack-ansible | 01:04 | |
*** smatzek has joined #openstack-ansible | 01:04 | |
*** cpuga has joined #openstack-ansible | 01:06 | |
*** dxiri has joined #openstack-ansible | 01:07 | |
*** thorst has joined #openstack-ansible | 01:08 | |
*** cuongnv has joined #openstack-ansible | 01:09 | |
*** lkoranda has quit IRC | 01:11 | |
*** fyu has quit IRC | 01:11 | |
*** vnogin has joined #openstack-ansible | 01:12 | |
*** thorst has quit IRC | 01:12 | |
*** lkoranda has joined #openstack-ansible | 01:14 | |
*** jamielennox|away is now known as jamielennox | 01:16 | |
*** fyu has joined #openstack-ansible | 01:16 | |
*** adrian_otto has quit IRC | 01:18 | |
*** thorst has joined #openstack-ansible | 01:19 | |
*** david-lyle has joined #openstack-ansible | 01:24 | |
*** furlongm has quit IRC | 01:28 | |
*** thorst has quit IRC | 01:29 | |
*** SerenaFeng has joined #openstack-ansible | 01:32 | |
*** cathrichardson has quit IRC | 01:33 | |
*** cathrichardson has joined #openstack-ansible | 01:33 | |
*** vnogin has quit IRC | 01:42 | |
*** agrebennikov has quit IRC | 01:42 | |
*** dxiri has quit IRC | 01:44 | |
*** shashank_t_ has joined #openstack-ansible | 01:44 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_designate master: Ensure the components are isolated from the system https://review.openstack.org/451135 | 01:47 |
*** SerenaFeng has quit IRC | 01:50 | |
*** poopcat has quit IRC | 01:51 | |
*** acormier has joined #openstack-ansible | 01:52 | |
*** weezS has quit IRC | 01:55 | |
*** Oku_OS is now known as Oku_OS-away | 01:56 | |
*** weezS has joined #openstack-ansible | 01:56 | |
*** pramodrj07 has quit IRC | 01:58 | |
*** MasterOfBugs has quit IRC | 01:58 | |
*** dixiaoli has joined #openstack-ansible | 01:58 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_swift master: Ensure the components are isolated from the system https://review.openstack.org/451138 | 02:01 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_octavia master: Ensure the components are isolated from the system https://review.openstack.org/451139 | 02:05 |
*** rmelero_ has quit IRC | 02:14 | |
*** rmelero has joined #openstack-ansible | 02:14 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_ironic master: Ensure the components are isolated from the system https://review.openstack.org/451144 | 02:18 |
*** rmelero has quit IRC | 02:19 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_ironic master: Ensure the components are isolated from the system https://review.openstack.org/451144 | 02:19 |
*** adrian_otto has joined #openstack-ansible | 02:22 | |
openstackgerrit | Ravi Kumar Boyapati proposed openstack/openstack-ansible master: update package locations path in repo-build play https://review.openstack.org/450973 | 02:23 |
*** SerenaFeng has joined #openstack-ansible | 02:24 | |
*** adrian_otto has quit IRC | 02:27 | |
*** thorst has joined #openstack-ansible | 02:30 | |
*** poopcat has joined #openstack-ansible | 02:32 | |
*** shashank_t_ has quit IRC | 02:33 | |
*** david-lyle has quit IRC | 02:36 | |
*** gouthamr has quit IRC | 02:37 | |
*** poopcat has quit IRC | 02:40 | |
*** poopcat has joined #openstack-ansible | 02:40 | |
*** agrebennikov has joined #openstack-ansible | 02:42 | |
*** gouthamr has joined #openstack-ansible | 02:44 | |
*** sanfern has joined #openstack-ansible | 02:45 | |
*** smatzek has quit IRC | 02:49 | |
*** thorst has quit IRC | 02:49 | |
*** woodard_ has quit IRC | 02:51 | |
*** woodard has joined #openstack-ansible | 02:52 | |
*** woodard has quit IRC | 02:56 | |
*** acormier has quit IRC | 02:57 | |
*** deepak_jon has quit IRC | 03:03 | |
*** galstrom_zzz is now known as galstrom | 03:03 | |
*** deepak_jon has joined #openstack-ansible | 03:03 | |
openstackgerrit | zhongshengping proposed openstack/openstack-ansible-os_octavia master: Remove verbose option https://review.openstack.org/451153 | 03:03 |
*** deepak_jon has quit IRC | 03:09 | |
*** deepak_jon has joined #openstack-ansible | 03:10 | |
*** raginbajin has quit IRC | 03:14 | |
*** zerick has quit IRC | 03:15 | |
*** deepak_jon has quit IRC | 03:17 | |
*** zerick has joined #openstack-ansible | 03:17 | |
*** deepak_jon has joined #openstack-ansible | 03:18 | |
*** dixiaoli has quit IRC | 03:18 | |
*** gouthamr has quit IRC | 03:19 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron master: Ensure the components are isolated from the system https://review.openstack.org/451156 | 03:20 |
*** raginbajin has joined #openstack-ansible | 03:21 | |
*** agrebennikov has quit IRC | 03:23 | |
*** dixiaoli has joined #openstack-ansible | 03:26 | |
*** cmart has quit IRC | 03:28 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron master: Ensure the components are isolated from the system https://review.openstack.org/451156 | 03:29 |
openstackgerrit | zhongshengping proposed openstack/openstack-ansible-os_neutron master: Remove min_l3_agents_per_router option https://review.openstack.org/451163 | 03:36 |
*** david-lyle has joined #openstack-ansible | 03:37 | |
*** udesale has joined #openstack-ansible | 03:45 | |
*** thorst has joined #openstack-ansible | 03:46 | |
*** thorst has quit IRC | 03:51 | |
*** galstrom is now known as galstrom_zzz | 03:51 | |
*** SerenaFeng has quit IRC | 03:52 | |
*** jrobinson has quit IRC | 03:52 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_ceilometer master: Ensure the components are isolated from the system https://review.openstack.org/451165 | 03:55 |
*** jrobinson has joined #openstack-ansible | 03:56 | |
*** dxiri has joined #openstack-ansible | 03:56 | |
*** Dinesh_Bhor has joined #openstack-ansible | 04:00 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_gnocchi master: Ensure the components are isolated from the system https://review.openstack.org/451166 | 04:00 |
*** dxiri has quit IRC | 04:10 | |
*** dxiri has joined #openstack-ansible | 04:11 | |
*** dxiri_ has joined #openstack-ansible | 04:13 | |
*** dxiri_ has quit IRC | 04:13 | |
*** dxiri_ has joined #openstack-ansible | 04:14 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron master: Ensure the components are isolated from the system https://review.openstack.org/451156 | 04:16 |
*** dxiri has quit IRC | 04:16 | |
*** schwicht has quit IRC | 04:17 | |
*** dxiri_ has quit IRC | 04:17 | |
*** dxiri has joined #openstack-ansible | 04:17 | |
*** cjloader has joined #openstack-ansible | 04:18 | |
*** dxiri_ has joined #openstack-ansible | 04:19 | |
*** dxiri__ has joined #openstack-ansible | 04:20 | |
*** dxiri has quit IRC | 04:23 | |
*** dxiri_ has quit IRC | 04:24 | |
*** dxiri has joined #openstack-ansible | 04:24 | |
*** poopcat has quit IRC | 04:25 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_heat master: Ensure the components are isolated from the system https://review.openstack.org/451169 | 04:25 |
*** dxiri__ has quit IRC | 04:28 | |
*** hybridpollo has quit IRC | 04:29 | |
*** dixiaoli has quit IRC | 04:30 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_heat master: Ensure the components are isolated from the system https://review.openstack.org/451169 | 04:32 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_heat master: Ensure the components are isolated from the system https://review.openstack.org/451169 | 04:33 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_cloudkitty master: Ensure the components are isolated from the system https://review.openstack.org/451171 | 04:34 |
*** cjloader has quit IRC | 04:34 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_sahara master: Ensure the components are isolated from the system https://review.openstack.org/451172 | 04:37 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_aodh master: Ensure the components are isolated from the system https://review.openstack.org/451174 | 04:41 |
*** shashank_t_ has joined #openstack-ansible | 04:47 | |
*** thorst has joined #openstack-ansible | 04:47 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_keystone master: Ensure the components are isolated from the system https://review.openstack.org/451176 | 04:48 |
*** thorst has quit IRC | 04:52 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_barbican master: Ensure the components are isolated from the system https://review.openstack.org/451178 | 04:55 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-ops master: Ensure the components are isolated from the system https://review.openstack.org/451179 | 04:58 |
*** rmelero has joined #openstack-ansible | 04:59 | |
*** askb has quit IRC | 05:07 | |
*** askb has joined #openstack-ansible | 05:08 | |
*** d3n14l has joined #openstack-ansible | 05:15 | |
*** adrian_otto has joined #openstack-ansible | 05:26 | |
*** dixiaoli has joined #openstack-ansible | 05:31 | |
*** dixiaoli has quit IRC | 05:34 | |
*** jimbaker` has joined #openstack-ansible | 05:38 | |
*** jimbaker has quit IRC | 05:39 | |
*** SerenaFeng has joined #openstack-ansible | 05:42 | |
*** dxiri has quit IRC | 05:46 | |
*** thorst has joined #openstack-ansible | 05:48 | |
*** thorst has quit IRC | 05:52 | |
*** NikhilS has joined #openstack-ansible | 05:54 | |
*** shashank_t_ has quit IRC | 05:54 | |
*** shashank_t_ has joined #openstack-ansible | 05:55 | |
*** luzC has quit IRC | 05:55 | |
*** luzC has joined #openstack-ansible | 05:56 | |
*** dixiaoli has joined #openstack-ansible | 05:58 | |
*** shashank_t_ has quit IRC | 05:59 | |
*** jrobinson has quit IRC | 06:01 | |
*** rmelero has quit IRC | 06:01 | |
*** rmelero has joined #openstack-ansible | 06:02 | |
*** rmelero has quit IRC | 06:06 | |
*** jamielennox is now known as jamielennox|away | 06:10 | |
*** Oku_OS-away is now known as Oku_OS | 06:12 | |
*** weezS has quit IRC | 06:21 | |
*** pcaruana has joined #openstack-ansible | 06:24 | |
*** jamielennox|away is now known as jamielennox | 06:25 | |
*** d3n14l has quit IRC | 06:29 | |
*** pramod has joined #openstack-ansible | 06:31 | |
*** lihi has quit IRC | 06:46 | |
*** oanson has quit IRC | 06:48 | |
*** thorst has joined #openstack-ansible | 06:49 | |
*** jamielennox is now known as jamielennox|away | 06:50 | |
*** udesale__ has joined #openstack-ansible | 06:52 | |
*** thorst has quit IRC | 06:53 | |
*** udesale has quit IRC | 06:53 | |
*** McMurlock1 has joined #openstack-ansible | 06:54 | |
*** jamielennox|away is now known as jamielennox | 06:57 | |
*** muxdaemon has joined #openstack-ansible | 06:58 | |
*** d3n14l has joined #openstack-ansible | 07:03 | |
*** fxpester has joined #openstack-ansible | 07:09 | |
*** foutatoro has joined #openstack-ansible | 07:10 | |
*** fyu1 has joined #openstack-ansible | 07:11 | |
*** fyu has quit IRC | 07:12 | |
*** fyu1 is now known as fyu | 07:13 | |
mpranjic | mornin | 07:16 |
*** fabg has joined #openstack-ansible | 07:17 | |
*** Matias has quit IRC | 07:27 | |
*** Matias has joined #openstack-ansible | 07:39 | |
*** muxdaemon has quit IRC | 07:40 | |
*** d3n14l has quit IRC | 07:40 | |
*** thorst has joined #openstack-ansible | 07:49 | |
*** cpuga has quit IRC | 07:51 | |
*** d3n14l has joined #openstack-ansible | 07:52 | |
*** shardy has joined #openstack-ansible | 08:03 | |
*** NikhilS has quit IRC | 08:04 | |
hw_wutianwei | stevelle: hi, I want to know why set haproxy_state to disabled in line 81 in the file os-keystone-install.yml https://github.com/openstack/openstack-ansible/blob/master/playbooks/os-keystone-install.yml. | 08:07 |
*** NikhilS has joined #openstack-ansible | 08:07 | |
*** thorst has quit IRC | 08:08 | |
hw_wutianwei | stevelle: because of this, everytime I failed at the TASK [os_keystone : Ensure service tenant], see the log: http://paste.openstack.org/show/604410/ | 08:11 |
hw_wutianwei | stevelle: when I set haproxy_state to enabled in line 81in the file os-keystone-install.yml. that task is ok | 08:12 |
*** dixiaoli has quit IRC | 08:13 | |
*** jwitko has quit IRC | 08:14 | |
*** adrian_otto has quit IRC | 08:16 | |
*** jamielennox is now known as jamielennox|away | 08:17 | |
*** dixiaoli has joined #openstack-ansible | 08:18 | |
*** pbandark has joined #openstack-ansible | 08:20 | |
*** muxdaemon has joined #openstack-ansible | 08:30 | |
*** pramod has quit IRC | 08:33 | |
*** karimb has joined #openstack-ansible | 08:35 | |
*** karimb has quit IRC | 08:39 | |
*** Amit82 has joined #openstack-ansible | 08:41 | |
Amit82 | Hi All, I am installing Openstack Newton release using OSA 14.1.1 tag on Ubuntu 16.04 | 08:41 |
*** karimb has joined #openstack-ansible | 08:41 | |
Amit82 | While running "openstack-ansible setup-infrastructure.yml", I am facing this error: http://paste.openstack.org/show/604627/ | 08:42 |
Amit82 | Any idea that how to get away from this problem? | 08:42 |
*** muxdaemon has quit IRC | 08:45 | |
*** karimb has quit IRC | 08:46 | |
*** dixiaoli_ has joined #openstack-ansible | 08:46 | |
odyssey4me | Amit82 retry | 08:46 |
odyssey4me | if it persists, then check whether the cert is valid if you curl it | 08:47 |
odyssey4me | if you're going through a proxy, disable cert validation | 08:47 |
*** karimb has joined #openstack-ansible | 08:48 | |
*** dixiaoli has quit IRC | 08:48 | |
odyssey4me | the download happens from your deployment node | 08:48 |
*** esberglu has joined #openstack-ansible | 08:49 | |
jrosser__ | odyssey4me: where is the right place to properly make an aio build work behind a proxy? | 08:49 |
jrosser__ | becasue it rewrites /etc/environment and loses the config there | 08:49 |
odyssey4me | jrosser__ I've been meaning to update https://docs.openstack.org/project-deploy-guide/openstack-ansible/draft/app-limited-connectivity.html with content from https://blog.christophersmart.com/2016/08/09/setting-up-openstack-ansible-all-in-one-behind-a-proxy/ | 08:50 |
*** vnogin has joined #openstack-ansible | 08:50 | |
odyssey4me | if you feel up to doing that, I'd be glad to review it | 08:51 |
jrosser__ | it felt like the bootstrap-aio playbook should look for an existing proxy environment variable | 08:51 |
jrosser__ | then it could correctly rewrite /etc/environment and make the necessary entries in user_variables.yml | 08:52 |
odyssey4me | bootstrap-ansible does, and bootstrap-aio just uses ansible which relies on the env vars being exported ahead of time | 08:52 |
odyssey4me | yeah, I suppose some tasks could be added to do that | 08:52 |
odyssey4me | if we can make it easier to use, I'm all for it | 08:52 |
*** esberglu has quit IRC | 08:53 | |
Amit82 | odyssey4me: I will re-run the playbook | 08:54 |
jrosser__ | yes becasue as it stands you have to set your host up to use a proxy for bootstrap-ansible | 08:54 |
jrosser__ | then bootstrap-aio sort of breaks that a bit | 08:54 |
Amit82 | In my setup, Infra node is the deployment node | 08:54 |
evrardjp | jrosser__: that sounds like a bug then | 08:55 |
*** vnogin has quit IRC | 08:55 | |
odyssey4me | how does it get broken? that sounds odd | 08:56 |
jrosser__ | hmm this was late last night :) | 08:57 |
odyssey4me | evrardjp any thoughts on a better way to resolve this issue? https://review.openstack.org/450973 | 08:57 |
jrosser__ | basically i need to configure my /etc/environment myself to get boostrap-ansible to work through the proxy | 08:57 |
odyssey4me | jrosser__ I would expect that you typically have already done so if you're behind a proxy? | 08:58 |
jrosser__ | and then at some point, that file gains an "# Ansible managed" and the proxy lines are then miissing | 08:58 |
odyssey4me | ah, I don't think that's in bootstrap-aio - I think that's in openstack_hosts | 08:58 |
jrosser__ | quite likley, i'm just pulling on the string trying to find where on earth it happens! | 08:59 |
odyssey4me | in openstack_hosts we write proxy config into /etc/environment... and we probably shouldn't just overwrite the existing file | 08:59 |
odyssey4me | we should perhaps *add* to it, but not replace it | 08:59 |
evrardjp | odyssey4me: sure I'll have a look | 08:59 |
jrosser__ | it should also trigger the right things being put in user_variables.yml | 08:59 |
odyssey4me | jrosser__ https://github.com/openstack/openstack-ansible-openstack_hosts/blob/master/tasks/openstack_proxy_settings.yml | 09:00 |
jrosser__ | then you'd be good to just follow the instructions and have to do nothing special | 09:00 |
odyssey4me | yes, bootstrap-host could do that, but that won't help for a multi-node environment | 09:00 |
odyssey4me | my concern here is that we're simply overwriting a host's environment file, but a kick process may have added all sorts of things in there | 09:00 |
odyssey4me | I think instead we should replace that template task with a lineinfile task that does much the same thing | 09:01 |
odyssey4me | it'll retain the functionality without overwriting an existing environment file | 09:02 |
odyssey4me | that functionality was added back in kilo :) | 09:02 |
jrosser__ | ah global_environment_variables | 09:02 |
pjm6 | morning all | 09:02 |
jrosser__ | i raised another bug about that yesterday | 09:02 |
jrosser__ | this is related to proxies also https://bugs.launchpad.net/openstack-ansible/+bug/1677007 | 09:03 |
openstack | Launchpad bug 1677007 in openstack-ansible "Documentation bug - proxy config" [Undecided,New] | 09:03 |
odyssey4me | jrosser__ will you push up a patch to resolve this? | 09:03 |
jrosser__ | i wasnt sure what the right fix was | 09:04 |
*** thorst has joined #openstack-ansible | 09:05 | |
odyssey4me | hmm, for that bug I'm not sure I understand what you're saying there | 09:05 |
*** karimb has quit IRC | 09:05 | |
jrosser__ | as global_environment_variables and proxy_env_url kind of desrribe the same thing | 09:05 |
jrosser__ | well, for the purposes of proxies, anyway | 09:05 |
odyssey4me | well, global_environment_variables is more universal | 09:06 |
*** vnogin has joined #openstack-ansible | 09:06 | |
odyssey4me | you can put any arbitrary key/value pair in there | 09:06 |
*** manheim has joined #openstack-ansible | 09:06 | |
odyssey4me | it just hapens to be useful for proxy environment setting | 09:06 |
*** manheim has quit IRC | 09:07 | |
*** manheim has joined #openstack-ansible | 09:07 | |
odyssey4me | ok, let me put together a patch to address the environment file overwrite | 09:07 |
odyssey4me | with regards to the bug, proxy_env_url and no_proxy_env are not supposed to be used anywhere but in the lines below | 09:08 |
odyssey4me | they just provide a shortcut to re-use the same definition inside the global_environment_variables | 09:08 |
jrosser__ | i think they may pop up in the repo build | 09:09 |
odyssey4me | hmm, interesting - that should be unintentional | 09:09 |
*** thorst has quit IRC | 09:09 | |
odyssey4me | hah, you're right | 09:10 |
odyssey4me | there's a clash in that name with apt-cacher-ng | 09:10 |
jrosser__ | you much quicker than me at finding this stuff :) | 09:10 |
odyssey4me | http://codesearch.openstack.org/?q=proxy_env_url&i=nope&files=&repos= | 09:11 |
odyssey4me | codesearch is your friend | 09:11 |
*** electrofelix has joined #openstack-ansible | 09:11 | |
odyssey4me | that doesn't look like it should be a problem though | 09:11 |
odyssey4me | hmm, I wonder if the environment file is copied into the containers | 09:12 |
jrosser__ | this is why i was unsure what the correct fix for that bug was | 09:12 |
jrosser__ | and if it really involved fixing a role instead | 09:12 |
odyssey4me | hmmm, it is not | 09:12 |
evrardjp | odyssey4me: pkg_locations: "{{ playbook_dir }}/../" ? | 09:12 |
odyssey4me | so I wonder how we expect containers to be able to use a proxy | 09:13 |
odyssey4me | evrardjp ah, that sounds better :) | 09:13 |
odyssey4me | anything to avoid that horrible bash nonsense task | 09:13 |
jrosser__ | in my AIO the /etc/environment files are filled out to use a proxy | 09:13 |
evrardjp | it should be jinja parsed so it should be alright | 09:13 |
jrosser__ | as per global_environment_variables | 09:14 |
evrardjp | odyssey4me: well I guess the problem will be for wrappers like logan-'s or rpc's, but we override pkg_locations anyway | 09:15 |
odyssey4me | jrosser__ yeah, it looks like we do that here: https://github.com/openstack/openstack-ansible-lxc_container_create/blob/master/templates/environment.j2 | 09:15 |
evrardjp | so it should be fine | 09:15 |
odyssey4me | evrardjp yeah, the option is there to override | 09:16 |
odyssey4me | if you could suggest that as a replacement in review I'd appreciate it | 09:16 |
*** pmannidi has quit IRC | 09:16 | |
odyssey4me | jrosser__ ok, so my suggestion is twofold here | 09:16 |
odyssey4me | 1 - we don't overwrite the host environments file, we just add to it | 09:17 |
odyssey4me | this will ensure that if someone already has configured a proxy, they don't have to know about our variable to set those things | 09:17 |
odyssey4me | 2 - we do the same for containers | 09:18 |
odyssey4me | does that sound reasonable? | 09:18 |
Amit82 | odyssey4me: Faced the same error. So, how can I disable certificate validation as per the msg "You can use validate_certs=False" | 09:18 |
odyssey4me | oh interesting, we used to use lineinfile: https://github.com/openstack/openstack-ansible-lxc_container_create/commit/f2646d36d89548bd7ed4154aa0ef75a86d94b7b5 | 09:19 |
odyssey4me | Amit82 it appears that we don't have a var for that - if you could patch a var for that into the task I'd appreciate it | 09:20 |
jrosser__ | odyssey4me: yes that will certainly be good not to clobber existing /etc/environment | 09:20 |
jrosser__ | Amit82: do you mean more than pip_validate_certs: false | 09:21 |
jrosser__ | and galera_package_download_validate_certs: false | 09:21 |
jrosser__ | ? | 09:21 |
pjm6 | anyone here knows where's the location of inject password from horizon ? I have that option enabled in OSA but I can't find in the gui | 09:22 |
odyssey4me | pjm6 it probably is not available in the GUI | 09:22 |
odyssey4me | but I don't know for sure | 09:22 |
pjm6 | odyssey4me, i know that in other versions were (at least liberty or mitaka if not in mistake) in the ocata can't find it :/ | 09:23 |
Amit82 | odyssey4me: I am completely naive to the Ansible, just using it for deploying Openstack | 09:23 |
odyssey4me | Amit82 jrosser__ yeah, this task needs the ability to disable cert verification: https://github.com/openstack/openstack-ansible-haproxy_server/blob/master/tasks/haproxy_install_hatop.yml#L16 | 09:23 |
odyssey4me | ah ok, let me do a quick patch then | 09:23 |
jrosser__ | i have those two lines in my user_variables.yml and all this is OK behing a proxy | 09:23 |
pjm6 | odyssey4me, https://access.redhat.com/webassets/avalon/d/Red_Hat_OpenStack_Platform-8-Instances_and_Images_Guide-en-US/images/a28d3db71ad5ab400110bbc75ac3b604/dashboard.png | 09:25 |
odyssey4me | Amit82 as a workaround for now, set this in your useR_variables.yml file: haproxy_hatop_download_url: "http://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/hatop/hatop-0.7.7.tar.gz" | 09:26 |
odyssey4me | you'll notice that I removed the 's' from 'https' | 09:26 |
odyssey4me | it seems to work | 09:26 |
odyssey4me | jrosser__ it's likely that Amit82 has some sort of TLS proxying going on | 09:26 |
odyssey4me | pjm6 oh ok, perhaps it is supposed to be there then :) | 09:27 |
jrosser__ | ah right - ours is simpler than that and doesnt interfere with certs | 09:27 |
pjm6 | yeah odyssey4me, the problem is that i don't find that option in Ocata xD | 09:28 |
jrosser__ | i also note that the external connectivity test isn't proxy friendly either | 09:28 |
pjm6 | I asked in horizon channel to see if someone has tips | 09:28 |
Amit82 | odyssey4me: So you are suggesting to add "pip_validate_certs: false" and "galera_package_download_validate_certs: false" in user_variables.yml as a workaround? | 09:30 |
odyssey4me | Amit82 no, but that will help you later on | 09:31 |
Amit82 | or you are suggesting to add this complete line in user_variables.yml: "haproxy_hatop_download_url: "http://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/hatop/hatop-0.7.7.tar.gz"" | 09:31 |
odyssey4me | I'm suggesting that you add the above-mentioned key/value pair as a workaround | 09:32 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-haproxy_server master: Allow cert validation for hatop download to be disabled https://review.openstack.org/451287 | 09:32 |
Amit82 | odyssey4me, jrosser__: thanks, I will try with it | 09:33 |
odyssey4me | jrosser__ Amit82 ^ that patch provides the option to disable cert validation for the hatop download | 09:33 |
odyssey4me | once that merges I'll update the docs | 09:33 |
odyssey4me | jrosser__ ok, so to prevent the issue that we moved to using a template for the environment file... I think I may need to use something similar to what's been done in the security role for the SSHD config: https://github.com/openstack/openstack-ansible-security/blob/master/tasks/rhel7stig/sshd.yml#L43 | 09:36 |
odyssey4me | that gives the best of both worlds | 09:36 |
odyssey4me | the existing content will remain, and new content can be added to it, but if you remove content from global_environment_variables it will still be removed | 09:37 |
odyssey4me | I'm sure that evrardjp will school me on a more elegant alternative in review :p | 09:37 |
* odyssey4me goes to get more coffee | 09:37 | |
evrardjp | coffee is the trick! | 09:38 |
*** manheim has quit IRC | 09:41 | |
*** messy has quit IRC | 09:46 | |
*** muxdaemon has joined #openstack-ansible | 09:49 | |
*** d3n14l has quit IRC | 09:52 | |
*** McMurlock1 has quit IRC | 09:54 | |
*** SerenaFeng has quit IRC | 09:58 | |
*** karimb has joined #openstack-ansible | 09:59 | |
*** messy has joined #openstack-ansible | 09:59 | |
*** manheim has joined #openstack-ansible | 10:00 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-openstack_hosts master: Update instead of replacing the environment file https://review.openstack.org/451303 | 10:01 |
*** stuartgr has joined #openstack-ansible | 10:01 | |
odyssey4me | ^ jrosser__ if you could test that out I'd appreciate it | 10:02 |
jrosser__ | ok will take a look | 10:04 |
*** thorst has joined #openstack-ansible | 10:05 | |
*** karimb has quit IRC | 10:07 | |
*** foutatoro has quit IRC | 10:07 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Ensure the components are isolated from the system https://review.openstack.org/451179 | 10:08 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-lxc_container_create master: Update instead of replacing the environment file https://review.openstack.org/451309 | 10:10 |
*** thorst has quit IRC | 10:10 | |
odyssey4me | jrosser__ ^ and there's the partner for the containers | 10:10 |
odyssey4me | jrosser__ I find myself wondering though, does the lxc_hosts role execute the cache prep in a proxy environment without intervention? | 10:11 |
odyssey4me | I'd be curious to understand how, because it has no proxy config in it | 10:11 |
*** foutatoro has joined #openstack-ansible | 10:11 | |
odyssey4me | if it does, are you using local mirrors for everything that doesn't need proxy config? | 10:11 |
*** fabg has quit IRC | 10:12 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-lxc_hosts master: Copy host environment file into cache https://review.openstack.org/451314 | 10:15 |
odyssey4me | ^ jrosser__ that should take care of that situation | 10:15 |
jrosser__ | we don't have local mirrors | 10:15 |
*** karimb has joined #openstack-ansible | 10:16 | |
jrosser__ | it's a squid cache with giant ram very local to the deployment and behind that is another squid out to the internet | 10:16 |
*** udesale__ has quit IRC | 10:17 | |
odyssey4me | it's odd, then, how the apt install stuff in the cache chroot was able to work then | 10:17 |
odyssey4me | andymccr something I'm not sure you're aware of - in order to subscribe to the global requirements process, the repo name has to be in https://github.com/openstack/requirements/blob/master/projects.txt - so for any of our new repositories we should ensure that they're included, assuming that they want to subscribe to the process | 10:18 |
andymccr | odyssey4me: ahh - yeah good reminder. i'll do a quick check and see which ones are in and which aren't | 10:19 |
*** lostRhino has joined #openstack-ansible | 10:20 | |
*** lostRhino has quit IRC | 10:20 | |
*** cuongnv has quit IRC | 10:21 | |
openstackgerrit | Merged openstack/openstack-ansible-os_barbican master: Ensure the components are isolated from the system https://review.openstack.org/451178 | 10:22 |
Amit82 | odyssey4me, jrosser__: thanks, it worked. setup-infrastructure.yml is successful. | 10:23 |
openstackgerrit | Merged openstack/openstack-ansible-os_sahara master: Ensure the components are isolated from the system https://review.openstack.org/451172 | 10:23 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-lxc_container_create master: Update instead of replacing the environment file https://review.openstack.org/451309 | 10:25 |
openstackgerrit | Merged openstack/openstack-ansible-os_heat master: Ensure the components are isolated from the system https://review.openstack.org/451169 | 10:26 |
openstackgerrit | Merged openstack/openstack-ansible-os_glance master: Ensure the components are isolated from the system https://review.openstack.org/451126 | 10:28 |
*** d3n14l has joined #openstack-ansible | 10:29 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone master: Ensure the components are isolated from the system https://review.openstack.org/451176 | 10:29 |
*** McMurlock1 has joined #openstack-ansible | 10:30 | |
*** pester has joined #openstack-ansible | 10:31 | |
*** fxpester|2 has joined #openstack-ansible | 10:31 | |
*** pester has quit IRC | 10:35 | |
*** fxpester has quit IRC | 10:35 | |
*** deepak_jon has quit IRC | 10:45 | |
*** deepak_jon has joined #openstack-ansible | 10:46 | |
openstackgerrit | Merged openstack/openstack-ansible-os_aodh master: Ensure the components are isolated from the system https://review.openstack.org/451174 | 10:51 |
*** karimb has quit IRC | 10:52 | |
*** sanfern has quit IRC | 10:55 | |
openstackgerrit | Merged openstack/openstack-ansible-os_designate master: Ensure the components are isolated from the system https://review.openstack.org/451135 | 10:56 |
*** qiliang27 has quit IRC | 10:58 | |
*** qiliang27 has joined #openstack-ansible | 10:58 | |
Amit82 | While running setup-openstack.yml playbook, on console, I am observing these warnings: http://paste.openstack.org/show/604638/ | 11:01 |
Amit82 | Are these harmless? | 11:01 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder master: Ensure the components are isolated from the system https://review.openstack.org/451116 | 11:03 |
*** rgogunskiy has joined #openstack-ansible | 11:04 | |
*** thorst has joined #openstack-ansible | 11:06 | |
*** deepak_jon has quit IRC | 11:09 | |
*** deepak_jon has joined #openstack-ansible | 11:09 | |
odyssey4me | Amit82 yes | 11:09 |
*** thorst has quit IRC | 11:11 | |
andymccr | odyssey4me: cloudnull I added you both to a review for that machine readable sample conf patch: https://review.openstack.org/#/c/451081/ if you get a chance to take a look and provide feedback would be amaze (anybody else interested is welcome too of course!) | 11:14 |
*** muxdaemon has quit IRC | 11:20 | |
Amit82 | odyssey4me: ok, thanks | 11:20 |
*** karimb has joined #openstack-ansible | 11:25 | |
*** jamesdenton has joined #openstack-ansible | 11:27 | |
openstackgerrit | Merged openstack/openstack-ansible stable/ocata: Update role SHA's to get CentOS working https://review.openstack.org/450224 | 11:29 |
openstackgerrit | Merged openstack/openstack-ansible stable/ocata: deploy-guide: fix small rst format issues https://review.openstack.org/450898 | 11:29 |
*** smatzek has joined #openstack-ansible | 11:31 | |
*** jamesden_ has joined #openstack-ansible | 11:31 | |
*** jamesdenton has quit IRC | 11:31 | |
*** fabg has joined #openstack-ansible | 11:31 | |
*** karimb has quit IRC | 11:32 | |
*** muxdaemon has joined #openstack-ansible | 11:36 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install master: Resolve user_external_repo deprecation warnings https://review.openstack.org/451347 | 11:36 |
odyssey4me | evrardjp ^ will that do the right thing? | 11:36 |
evrardjp | Oh I thought I did it. | 11:37 |
evrardjp | yes that should do the trick | 11:37 |
*** karimb has joined #openstack-ansible | 11:37 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install master: Resolve user_external_repo deprecation warnings https://review.openstack.org/451347 | 11:37 |
evrardjp | well I didn't try, but I think it should | 11:37 |
odyssey4me | small edit to add the related bug | 11:38 |
evrardjp | I was planning to do it I guess, sorry. | 11:38 |
evrardjp | But "you stole my bug" | 11:38 |
odyssey4me | that's ok, I'm used to cleaning up your mess :p | 11:39 |
odyssey4me | I took your jerb | 11:39 |
*** spotz is now known as spotz_zzz | 11:40 | |
evrardjp | >< | 11:40 |
odyssey4me | interestingly, though, the role test doesn't show the deprecation warning | 11:41 |
odyssey4me | only the integrated build does | 11:41 |
evrardjp | maybe the var is defined in the the vars of the role | 11:41 |
evrardjp | I don't know | 11:41 |
evrardjp | worth investigating! | 11:42 |
odyssey4me | any thoughts on these patches? https://review.openstack.org/#/q/topic:be-kind-to-the-environment | 11:42 |
*** karimb has quit IRC | 11:43 | |
*** karimb has joined #openstack-ansible | 11:44 | |
mhayden | good morning | 11:45 |
andymccr | odyssey4me: my initial thought is that the branch name is +2 :P | 11:47 |
*** sanfern has joined #openstack-ansible | 11:47 | |
andymccr | im gonna get some lunch. i'll bbiab and will take a look | 11:48 |
odyssey4me | :) | 11:48 |
*** retreved has joined #openstack-ansible | 11:49 | |
*** dixiaoli_ has quit IRC | 11:49 | |
*** askb has quit IRC | 11:49 | |
*** dixiaoli has joined #openstack-ansible | 11:50 | |
odyssey4me | evrardjp lbragstad dolphm so, with regards to our discussion yesterday related to the policy file | 11:52 |
odyssey4me | what do you think is the best strategy for replacement | 11:52 |
*** pbandark is now known as pbandark`brb | 11:52 | |
odyssey4me | 1 - replace the policy file, then immediately restart the service | 11:52 |
odyssey4me | 2 - when the service restarts, move the new policy file into place afterwards | 11:53 |
odyssey4me | I think option 2 may just work better and should work considering that the policy file is continually read | 11:54 |
*** dixiaoli has quit IRC | 11:54 | |
*** thorst has joined #openstack-ansible | 11:54 | |
evrardjp | odyssey4me: notifying from the handler that restarts the service should do the trick for 2- | 11:57 |
odyssey4me | yep, that's what I'm prepping - ie option 2 | 11:57 |
evrardjp | "Reload policy file" | 11:57 |
*** spotz_zzz is now known as spotz | 11:58 | |
*** karimb has quit IRC | 11:59 | |
evrardjp | odyssey4me: we would have to think about it in details 'though | 12:05 |
evrardjp | see the impact of templating it afterwards | 12:05 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone master: Source template files from git or deploy host https://review.openstack.org/446235 | 12:05 |
odyssey4me | ^ so that's going to try it out | 12:06 |
evrardjp | mhayden: are you there? | 12:06 |
odyssey4me | I don't know what's going to happen for a new deployment with that enabled. We'll have to see. | 12:06 |
mhayden | si | 12:06 |
*** karimb has joined #openstack-ansible | 12:07 | |
*** mpranjic has quit IRC | 12:10 | |
dolphm | odyssey4me: ideally, you'd replace it while the service was down | 12:11 |
dolphm | odyssey4me: any other scenario will have race conditions | 12:11 |
dolphm | odyssey4me: but replacing it late would absolutely be the lesser of the two evil options :P | 12:12 |
odyssey4me | dolphm so instead of actioning a restart, we should ideally do shut down, move policy file into place, start | 12:14 |
dolphm | odyssey4me: i think that's the safest solution, yes. | 12:15 |
dolphm | odyssey4me: otherwise, your solution is better than the current behavior, for sure | 12:15 |
odyssey4me | we're orchestrating the restart across the nodes, we do it on the first and then the rest | 12:16 |
odyssey4me | what happens when the policy file is different between one node and the others? | 12:16 |
*** SerenaFeng has joined #openstack-ansible | 12:16 | |
dolphm | odyssey4me: nothing unexpected | 12:16 |
odyssey4me | ok, lemme revise to that course of action then | 12:17 |
dolphm | odyssey4me: the same request might get a 200 and then a 403 and then a 200? but i'd call that expected if you're rolling out such a policy change | 12:17 |
odyssey4me | if that's the best, then that's what we want | 12:17 |
dolphm | odyssey4me: in this case, our policy *should* not be changing. the old defaults in policy.json are just moved into code | 12:17 |
odyssey4me | yeah, I'm just thinking about a config change on the deployer's part | 12:18 |
*** SerenaFeng has quit IRC | 12:18 | |
dolphm | odyssey4me: i think swapping it while it's offline will prevent surprises in the future - i don't actually see anything wrong with swapping it "late" in this specific case | 12:18 |
*** udesale has joined #openstack-ansible | 12:25 | |
*** bauruine_ has quit IRC | 12:27 | |
openstackgerrit | Merged openstack/openstack-ansible-os_zaqar master: Deprecate auth_plugin option https://review.openstack.org/448373 | 12:28 |
*** schwicht has joined #openstack-ansible | 12:28 | |
*** acormier has joined #openstack-ansible | 12:30 | |
*** bauruine has joined #openstack-ansible | 12:32 | |
*** Andrew_jedi has joined #openstack-ansible | 12:35 | |
*** cathrichardson has quit IRC | 12:35 | |
*** schwicht has quit IRC | 12:35 | |
mgariepy | morning | 12:36 |
*** schwicht has joined #openstack-ansible | 12:38 | |
*** vnogin has quit IRC | 12:42 | |
*** vnogin has joined #openstack-ansible | 12:43 | |
*** acormier has quit IRC | 12:44 | |
openstackgerrit | Merged openstack/openstack-ansible-os_neutron master: Deprecate auth_plugin option https://review.openstack.org/448365 | 12:44 |
mhayden | evrardjp: just fixed osa-differ -> https://pypi.org/project/osa_differ/#files | 12:45 |
*** shashank_t_ has joined #openstack-ansible | 12:45 | |
*** gouthamr has joined #openstack-ansible | 12:47 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone master: Source template files from git or deploy host https://review.openstack.org/446235 | 12:47 |
odyssey4me | jmccrory dolphm lbragstad ^ I'd appreciate a good look through that. It changes the policy file when the service is down, still retains the co-ordinated restart but does it in what I think is a slightly more sensible way | 12:48 |
odyssey4me | evrardjp your thoughts would be most appreciated too | 12:48 |
*** Deys has joined #openstack-ansible | 12:48 | |
*** bauruine has quit IRC | 12:49 | |
odyssey4me | andymccr ^ when you have a gap to look too I'd appreciate it | 12:49 |
dolphm | odyssey4me: awesome | 12:49 |
*** shashank_t_ has quit IRC | 12:50 | |
*** agrebennikov has joined #openstack-ansible | 12:50 | |
*** Andrew_jedi has quit IRC | 12:50 | |
andymccr | odyssey4me: looking now | 12:51 |
*** bauruine has joined #openstack-ansible | 12:51 | |
odyssey4me | assuming that actually works, it's a model we can apply across other services | 12:52 |
odyssey4me | to be fair, that's two changes combined into one | 12:52 |
odyssey4me | I could perhaps do the handler changes in a separate patch first, then do the policy patch after | 12:52 |
openstackgerrit | Markus Zoeller (markus_z) proposed openstack/openstack-ansible master: deploy-guide + dev docs: fix info about branches/releases/tags https://review.openstack.org/451386 | 12:55 |
*** markus_z has joined #openstack-ansible | 12:55 | |
*** schwicht has quit IRC | 12:55 | |
*** SerenaFeng has joined #openstack-ansible | 12:56 | |
*** karimb_ has joined #openstack-ansible | 13:11 | |
*** karimb has quit IRC | 13:12 | |
*** cathrichardson has joined #openstack-ansible | 13:13 | |
*** Deys has quit IRC | 13:14 | |
*** klamath has joined #openstack-ansible | 13:14 | |
*** klamath has quit IRC | 13:14 | |
*** klamath has joined #openstack-ansible | 13:15 | |
*** schwicht has joined #openstack-ansible | 13:19 | |
*** lostRhino has joined #openstack-ansible | 13:22 | |
*** Matias has quit IRC | 13:25 | |
lostRhino | hello all - was wondering if I could get a little assistance on the following error : http://paste.openstack.org/show/604655/ | 13:27 |
lostRhino | Am I missing something on my buid or am I setting a variable incorrectly? | 13:28 |
*** Deys has joined #openstack-ansible | 13:28 | |
*** smatzek has quit IRC | 13:29 | |
andymccr | lostRhino: does this resove? --index-url=https://our-internal-devpi-server/ | 13:32 |
lostRhino | yes | 13:32 |
*** Matias has joined #openstack-ansible | 13:37 | |
*** Amit82 has quit IRC | 13:38 | |
*** dmsimard is now known as dmsimard|afk | 13:39 | |
lostRhino | I dont understand why the “Install pip packages” passes (or it appears to pass) but the fall back mode fails | 13:39 |
andymccr | lostRhino: it'll ignore failures so that there is a fallback its basically a "try this, if it doesnt work try this other thing" if you flat out fail it will stop there. | 13:40 |
lostRhino | did it get through the other 79 packages or is it possible it chose that one first?? | 13:41 |
odyssey4me | andymccr ok, based on your feedback I'll do a separate patch to change this pattern | 13:42 |
odyssey4me | not having separation of uWSGI and the web server definitely complicates this | 13:42 |
andymccr | the command seems to fail on the ndg-httpsclient version not being available - it looks like it tried to install requests and that package. | 13:42 |
odyssey4me | so I'll combine a switch to always use uWSGI with a change in the handlers | 13:42 |
andymccr | but given the paste its hardto see more :) | 13:42 |
andymccr | odyssey4me: awesome yeah - i think uWSGI + apache works with our current federation story right? | 13:43 |
andymccr | it feels way more complicated than it should be right now so yeah maybe we can just uncomplicated it first. happy to work with you on that since im doing thenova role right now | 13:43 |
odyssey4me | yep | 13:43 |
odyssey4me | FYI we would still have to swtop uWSGI, copy file, start uWSGI | 13:43 |
odyssey4me | the whole reason is that while keystone is running is constantly reads the file, so if it's already running it will pick up the new changes before you expect it to | 13:44 |
andymccr | odyssey4me: isnt the issue with that that hte newer policy may not work with the old keystone? | 13:44 |
andymccr | e.g. if i reload uwsgi first then its a newer keystone - drop file - it reads it in, and all is good? | 13:44 |
odyssey4me | andymccr well, yes - the new policy gets consumed by the old keystone | 13:45 |
lostRhino | andymccr: what other information can I provide to help out? | 13:45 |
andymccr | either way - just stopping uwsgi for keystone on one host is probably not so bad. | 13:45 |
odyssey4me | and really it's an issue of atomicity - the new policy (even for just a re-config) gets used by the service before you've actually actioned the restart (which is when you expect it to) | 13:45 |
andymccr | lostRhino: it looks like your index-url server doesnt have the package version required - although a good debug step is to try manually run the commands on the host (since all ansible does is ssh to hosts and run commands) | 13:45 |
odyssey4me | I'm guessing that this is an issue across all services | 13:45 |
andymccr | odyssey4me: is it an issue if you restart the service (e.g. new keystone runs with older policy file) and then drop policy file? i get the atomicity of it. | 13:46 |
*** esberglu has joined #openstack-ansible | 13:46 | |
odyssey4me | my previous patch set did that, and it was working | 13:47 |
odyssey4me | but in discussing that approach with dolphm he said that's ok, but not the best way | 13:47 |
odyssey4me | the best way is to switch them out when the service is down | 13:47 |
*** kstev has joined #openstack-ansible | 13:47 | |
odyssey4me | a 'lazy load' is a second best option | 13:47 |
odyssey4me | a bit of a band-aid really | 13:47 |
odyssey4me | another way to do this is that instead of copying the file, we could use a handler to template it | 13:48 |
odyssey4me | but that does make finding the task a little confusing | 13:48 |
andymccr | odyssey4me: ahh ok | 13:49 |
lostRhino | andymccr: I logged onto the server and checked to see if the package was installed/or not | 13:50 |
andymccr | well if the keystone devs recommend a restart i will not be arguing :D | 13:50 |
lostRhino | pip install ndg-httpsclient | 13:50 |
lostRhino | Requirement already satisfied: ndg-httpsclient in /usr/lib/python2.7/dist-packages | 13:50 |
andymccr | lostRhino: can you check the version? it should be 0.4.2 | 13:50 |
andymccr | lostRhino: as an aside he key thing is "No matching distribution found for ndg-httpsclient===0.4.2" - so check the repo server has that package version available | 13:51 |
andymccr | *the | 13:51 |
*** jamesden_ has quit IRC | 13:52 | |
lostRhino | interesting : http://paste.openstack.org/show/604660/ | 13:52 |
*** kstev has quit IRC | 13:52 | |
*** kstev has joined #openstack-ansible | 13:52 | |
andymccr | lostRhino: so that's the problem - your repo doesn't have the correct version of ndg-httpsclient so it's failing on that. | 13:54 |
*** smatzek has joined #openstack-ansible | 13:55 | |
agrebennikov | evrardjp odyssey4me mind taking a look at https://review.openstack.org/#/c/425997/32 please? | 13:56 |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Adds iptables rules to protect octavia server container https://review.openstack.org/447151 | 13:59 |
*** rmelero has joined #openstack-ansible | 14:04 | |
*** lucasxu has joined #openstack-ansible | 14:07 | |
*** marst has quit IRC | 14:09 | |
*** rboyapat has joined #openstack-ansible | 14:10 | |
*** udesale has quit IRC | 14:11 | |
lbragstad | odyssey4me looking, thanks | 14:11 |
*** cmart has joined #openstack-ansible | 14:13 | |
mgariepy | logan-, are you around? | 14:13 |
mgariepy | i have some question for the ceph role issue on Centos. | 14:14 |
mgariepy | hmm it's failing on ubuntu as well... didn't saw that.. | 14:16 |
*** weezS has joined #openstack-ansible | 14:16 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_nova master: [WIP] Move to use UWsgi + upstream NGinx for Nova https://review.openstack.org/451425 | 14:19 |
*** marst has joined #openstack-ansible | 14:19 | |
*** acormier has joined #openstack-ansible | 14:19 | |
*** foutatoro has quit IRC | 14:20 | |
*** Andrew_jedi has joined #openstack-ansible | 14:21 | |
*** rgogunskiy has quit IRC | 14:24 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron master: Ensure the components are isolated from the system https://review.openstack.org/451156 | 14:26 |
*** mpranjic has joined #openstack-ansible | 14:26 | |
*** shashank_t_ has joined #openstack-ansible | 14:28 | |
*** d3n14l has left #openstack-ansible | 14:29 | |
openstackgerrit | Ravi Kumar Boyapati proposed openstack/openstack-ansible master: update package locations path in repo-build play https://review.openstack.org/450973 | 14:30 |
*** adrian_otto has joined #openstack-ansible | 14:34 | |
*** NikhilS has quit IRC | 14:37 | |
*** galstrom_zzz is now known as galstrom | 14:41 | |
*** cmart has quit IRC | 14:41 | |
cloudnull | alextricity25: do you know what the state of the ceilo repo is? looks like the gate is totally busted https://review.openstack.org/#/c/451165/ | 14:43 |
*** manheim has quit IRC | 14:44 | |
*** fxpester|2 has quit IRC | 14:44 | |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_swift master: Fix "pretend_min_part_hours" for MR swift tests https://review.openstack.org/451444 | 14:45 |
*** manheim has joined #openstack-ansible | 14:45 | |
lostRhino | andymccr: changed the pip_install_options from —index-url=https://our-internal-devpi-server/ --trusted-host our-internal-devpi-server to just —upgrade and it seemed to have fixed my problem so far… just an FYI | 14:46 |
lostRhino | thanks for your help | 14:46 |
*** Andrew_jedi_ has joined #openstack-ansible | 14:47 | |
*** Andrew_jedi has quit IRC | 14:47 | |
*** Andrew_jedi_ is now known as Andrew_jedi | 14:47 | |
andymccr | lostRhino: no problem! | 14:48 |
*** SerenaFeng has quit IRC | 14:48 | |
*** lostRhino has left #openstack-ansible | 14:51 | |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Adds iptables rules to protect octavia server container https://review.openstack.org/447151 | 14:51 |
markus_z | I think I ran into https://bugs.launchpad.net/openstack-ansible/+bug/1672728 What's the typical debug information you need me to attach? | 14:55 |
openstack | Launchpad bug 1672728 in openstack-ansible "keystone fails to install, missing libgsasl-devel on CentOS 7" [Undecided,Incomplete] - Assigned to Andy McCrae (andrew-mccrae) | 14:55 |
*** Andrew_jedi has quit IRC | 14:56 | |
*** manheim has quit IRC | 14:56 | |
andymccr | markus_z: what version of OSA are you running? I think that one should be fixed | 14:57 |
markus_z | andymccr: I checked out "15.0.0" | 14:57 |
markus_z | I followed the aio quickstart guide. | 14:58 |
andymccr | markus_z: ahh that makes sense, that reminds me Ocata hasn't had a second release yet (that happens this week) - we'll need to update the quickstart guide to use 15.1.0 once that is released. | 14:58 |
andymccr | markus_z: we had some issues with our CentOS/RHEL repo setup bits. which should now be resolved, but the fixes are in 15.1.0 which is coming tomorrow (at least it should be!) | 14:59 |
andymccr | you could use the current head of stable/ocata instead of the 15.0.0 tag | 14:59 |
andymccr | if you do try that and could confirm if that has worked or not - that'd be great | 15:00 |
markus_z | andymccr: ahh, ok, yeah, I'll do that. | 15:00 |
markus_z | andymccr: FWIW, I pushed a change regarding the "last_tag" magic in the docs: https://review.openstack.org/#/c/451386/1 | 15:00 |
*** Deys has quit IRC | 15:00 | |
odyssey4me | andymccr the tag will auto-update with every new tag | 15:00 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder master: Do a whole word grep https://review.openstack.org/443142 | 15:00 |
markus_z | IIUC, the docs need no update after that | 15:00 |
odyssey4me | the docs automatically detect the last published tag and put them into the docs :) | 15:01 |
andymccr | odyssey4me: ahh sweet :D | 15:01 |
*** Andrew_jedi has joined #openstack-ansible | 15:01 | |
markus_z | odyssey4me: yes, right, but on master and not the latest stable | 15:01 |
andymccr | community! | 15:01 |
odyssey4me | markus_z it depends which docs you're looking at | 15:01 |
odyssey4me | the stable branch docs will show the latest tag for that branch | 15:01 |
odyssey4me | the draft/master docs will show the latest tag done on the master branch | 15:02 |
markus_z | odyssey4me: I'm looking at: https://docs.openstack.org/developer/openstack-ansible/developer-docs/quickstart-aio.html | 15:02 |
odyssey4me | markus_z see https://docs.openstack.org/developer/openstack-ansible/ocata/developer-docs/quickstart-aio.html :) | 15:02 |
markus_z | ahhh, I'm using the wrong URL, right? | 15:02 |
*** cpuga has joined #openstack-ansible | 15:02 | |
odyssey4me | or https://docs.openstack.org/developer/openstack-ansible/newton/developer-docs/quickstart-aio.html | 15:02 |
markus_z | dang it | 15:02 |
odyssey4me | yeah, unfortunately dev docs don't make it obvious | 15:02 |
markus_z | OK, that makes my patch obsolete I guess :) | 15:03 |
odyssey4me | ideally we should probably put something in the tag detection which changes the tag to master for the master branch or something | 15:03 |
odyssey4me | we do the funky business here: https://github.com/openstack/openstack-ansible/blob/master/doc/source/conf.py#L302 | 15:04 |
odyssey4me | then you'll see in https://raw.githubusercontent.com/openstack/openstack-ansible/master/doc/source/developer-docs/quickstart-aio.rst we only use '|latest_tag|' | 15:04 |
odyssey4me | this means that when we make a new branch, the docs auto-update | 15:04 |
*** Andrew_jedi has quit IRC | 15:05 | |
markus_z | I was confused, because the master docs say I should checkout "15.0.0.RC1" which was earlier than the ocata release :/ | 15:07 |
*** manheim has joined #openstack-ansible | 15:11 | |
*** dmsimard|afk is now known as dmsimard | 15:11 | |
dolphm | odyssey4me: another idea... what if the path to policy.json was release-specific? | 15:14 |
odyssey4me | yeah, that'll be like that until the first milestone of Pike, unless someone patches it up to do something else ;) | 15:14 |
odyssey4me | dolphm yeah, evrardjp suggested that perhaps we have an openstack_release folder/file name that's used | 15:14 |
dolphm | odyssey4me: config itself isn't reloaded, so you could have two policy files on disk at once, and whenever the service restarts with new code, it would pick up new config, and therefore be pointed to the correct policy file | 15:14 |
odyssey4me | but that doesn't give atomicity when doing a config change within the same release | 15:14 |
dolphm | odyssey4me: true | 15:15 |
* dolphm only has the major upgrades hat on | 15:15 | |
*** cpuga has quit IRC | 15:15 | |
odyssey4me | we could obviously use the release tag number for the '.new' file, and do the copy mechanism | 15:16 |
*** cpuga has joined #openstack-ansible | 15:16 | |
odyssey4me | we'd always leave an old policy file behind then when upgrading from one tag to the next | 15:16 |
odyssey4me | it seems a little pointless to do that though | 15:17 |
odyssey4me | we only really need a current and next version | 15:17 |
odyssey4me | keeping track of historical changes is a matter for your user config management, not for us to leave bits of things behind all the time | 15:17 |
*** jimbaker` is now known as jimbaker | 15:20 | |
*** jimbaker is now known as Guest47227 | 15:21 | |
*** Guest47227 has quit IRC | 15:21 | |
*** Guest47227 has joined #openstack-ansible | 15:21 | |
*** Guest47227 is now known as jimbaker | 15:21 | |
*** pbandark`brb has quit IRC | 15:24 | |
*** cathrichardson has quit IRC | 15:29 | |
*** adrian_otto has quit IRC | 15:30 | |
markus_z | andymccr: I used the latest stable/ocata (3dc580e Merge "deploy-guide: fix small rst format issues" into stable/ocata) but still encountered the issue with "lsyncd". | 15:31 |
*** fabg1 has joined #openstack-ansible | 15:34 | |
markus_z | What's the notion of the status "incomplete" in that bug https://bugs.launchpad.net/openstack-ansible/+bug/1672728 ? | 15:35 |
openstack | Launchpad bug 1672728 in openstack-ansible "keystone fails to install, missing libgsasl-devel on CentOS 7" [Undecided,Incomplete] - Assigned to Andy McCrae (andrew-mccrae) | 15:35 |
*** fabg2 has joined #openstack-ansible | 15:35 | |
markus_z | In Nova, we used it to say "the bug reporter needs to provide more information" but I'm not sure if it's the same case here. | 15:36 |
*** fabg has quit IRC | 15:38 | |
*** fabg1 has quit IRC | 15:38 | |
*** cathrichardson has joined #openstack-ansible | 15:41 | |
*** cmart has joined #openstack-ansible | 15:41 | |
andymccr | markus_z: yeah - thats here too. i must've misclicked that :) mybad | 15:41 |
andymccr | oh actually in that case it was a "try the update" and see if that works. btw markus_z did using head of stable/ocata work? | 15:42 |
andymccr | ahh you did | 15:42 |
markus_z | yeah, it stopped at the same place | 15:43 |
andymccr | mgariepy: mhayden: ^ thoughts? lysncd i think is in the epel repo | 15:43 |
mgariepy | latests fix not part of the 15.0.0 tag | 15:44 |
andymccr | mgariepy: this should be on stable/ocata head | 15:44 |
andymccr | i think there was a patch merged to do the fixes so it'll go into 15.1.0 so that should mean it's ready on stable/ocata head? | 15:44 |
markus_z | The package itself seems to be i EPEL: https://centos.pkgs.org/7/epel-x86_64/lsyncd-2.1.5-6.el7.x86_64.rpm.html | 15:44 |
openstackgerrit | Kyle L. Henderson proposed openstack/openstack-ansible-os_trove master: Add RPC encryption key support https://review.openstack.org/449810 | 15:45 |
mgariepy | I deployed yesterday with that patch : https://review.openstack.org/#/c/450224/ | 15:47 |
markus_z | ahhh, I checked out the code ~6h ago. I guess I missed that one. | 15:47 |
andymccr | ahh | 15:49 |
andymccr | makes sense then :D | 15:49 |
andymccr | thanks mgariepy! | 15:49 |
andymccr | but yeah as an FYI markus_z that'll go into 15.1.0 which i'll push a patch in for tomorrow | 15:49 |
mgariepy | I've seen issue with haproxy and ssl cert tho. not sure were it came from. | 15:49 |
markus_z | andymccr: Got it. Let me pull the latest code and run again. | 15:50 |
*** manheim has quit IRC | 15:57 | |
mgariepy | markus_z, let me know if you have some errors | 15:58 |
*** marst_ has joined #openstack-ansible | 16:01 | |
mgariepy | markus_z, form your bug report, we had some fighting with epel in the past few weeks ;) | 16:02 |
*** marst has quit IRC | 16:02 | |
markus_z | mgariepy: any survivors? | 16:02 |
*** adrian_otto has joined #openstack-ansible | 16:02 | |
markus_z | pow? | 16:02 |
mgariepy | haha we did .. i guess | 16:03 |
*** cmart has quit IRC | 16:03 | |
markus_z | ;) | 16:03 |
mgariepy | markus_z, are you using ceph ? | 16:04 |
markus_z | mgariepy: no (I guess). I didn't change any defaults. | 16:04 |
mgariepy | kk | 16:05 |
mgariepy | when updating openstack-ansible you will need to re-run bootstrap-ansible.sh | 16:05 |
markus_z | mgariepy: ohh, I didn't know that, the quickstart guide didn't mention it in the "rebuilding an aio" section. | 16:06 |
mgariepy | ha | 16:06 |
mgariepy | :D | 16:06 |
mgariepy | might explain your issue with epel :) | 16:07 |
*** cmart1 has joined #openstack-ansible | 16:09 | |
*** dmsimard is now known as dmsimard|afk | 16:13 | |
markus_z | A "rebuild-aio" playbook would be nice :) | 16:14 |
markus_z | mgariepy: Do I need to run "scripts/bootstrap-aio.sh" a second time too? | 16:15 |
mgariepy | not sure.. | 16:16 |
mgariepy | the best answer I can give you is : maybe | 16:16 |
mgariepy | someone else might know better | 16:16 |
odyssey4me | markus_z the rebuild will involve all the steps of the build | 16:18 |
*** craigs has joined #openstack-ansible | 16:20 | |
markus_z | odyssey4me: Ah, good to know, thanks | 16:20 |
*** cmart1 has quit IRC | 16:22 | |
*** fabg2 has quit IRC | 16:30 | |
*** vnogin has quit IRC | 16:32 | |
*** manheim has joined #openstack-ansible | 16:34 | |
*** shardy has quit IRC | 16:35 | |
odyssey4me | andymccr do we have a blueprint/bug for the switch to uwsgi by default? | 16:36 |
markus_z | mgariepy: sorry to say, but I still see the same issue with "lsyncd". | 16:36 |
markus_z | mgariepy: The odd thing is "yum list lsyncd" shows that it's available | 16:36 |
*** cmart has joined #openstack-ansible | 16:38 | |
*** manheim has quit IRC | 16:38 | |
*** weezS has quit IRC | 16:39 | |
*** shashank_t_ has quit IRC | 16:41 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone master: [WIP] Switch to using Nginx/uWSGI by default https://review.openstack.org/451480 | 16:45 |
odyssey4me | markus_z a bad cache perhaps? | 16:45 |
*** retreved has quit IRC | 16:45 | |
odyssey4me | maybe do something like: ansible all -m shell -a "yum clean all" | 16:45 |
odyssey4me | if you've destroyed the containers, then replace 'all' with 'hosts' | 16:46 |
*** shashank_t_ has joined #openstack-ansible | 16:47 | |
markus_z | odyssey4me: OK, the cleanup was without errors. What to do now? | 16:50 |
odyssey4me | markus_z was the failure in the repo-install playbook? | 16:50 |
odyssey4me | you can cd into /opt/openstack-ansible/playbooks | 16:50 |
odyssey4me | then execute: openstack-ansible repo-server.yml | 16:51 |
markus_z | odyssey4me: I think it's "/etc/ansible/roles/repo_server/tasks/repo_install.yml:16" | 16:51 |
odyssey4me | that'll do just the one playbook to see if you hit the same issue | 16:51 |
*** shardy has joined #openstack-ansible | 16:52 | |
markus_z | odyssey4me: :( nope, same issue http://paste.openstack.org/show/604706/ | 16:53 |
markus_z | well, I have to call it a day. I'll try a new clean setup tomorrow and will give feedback here. | 16:55 |
*** McMurlock1 has quit IRC | 16:55 | |
*** cmart has quit IRC | 16:56 | |
hachi | Hi, | 17:01 |
*** markus_z has quit IRC | 17:02 | |
hachi | I wanted to have another service be running alongside keystone within keystone container. So my /opt/openstack-ansible/playbooks/inventory/env.d/keystone.yml file looks loke this: | 17:02 |
hachi | http://paste.openstack.org/show/604709/ | 17:03 |
hachi | But when I run setup-host.yml the inventory manager throws this error message: | 17:03 |
hachi | http://paste.openstack.org/show/604710/ | 17:04 |
hachi | How I can define additional services inside a container ? | 17:05 |
openstackgerrit | Merged openstack/openstack-ansible-os_cinder master: Only install git when developer_mode is enabled https://review.openstack.org/450293 | 17:08 |
*** pbandark has joined #openstack-ansible | 17:08 | |
*** mrhillsman has quit IRC | 17:10 | |
*** cmart has joined #openstack-ansible | 17:10 | |
*** vnogin has joined #openstack-ansible | 17:17 | |
*** kstev has quit IRC | 17:19 | |
*** foutatoro has joined #openstack-ansible | 17:19 | |
*** codebauss has joined #openstack-ansible | 17:20 | |
*** codebauss is now known as mrhillsman | 17:20 | |
*** vnogin has quit IRC | 17:21 | |
*** mrhillsman has quit IRC | 17:21 | |
*** codebauss has joined #openstack-ansible | 17:23 | |
*** codebauss is now known as mrhillsman | 17:23 | |
mgariepy | odyssey4me, maybe the lxc template wasn't re-created ? | 17:24 |
odyssey4me | mgariepy hmm, yeah - as it was new it wouldn't have been | 17:25 |
mgariepy | and since we put epel in the template it might have caused issue. | 17:25 |
odyssey4me | you'd have to wipe /var/cache/lxc/download | 17:26 |
odyssey4me | maybe that should be in the rebuild steps | 17:26 |
mgariepy | yeah | 17:26 |
*** MasterOfBugs has joined #openstack-ansible | 17:29 | |
*** kstev has joined #openstack-ansible | 17:30 | |
rboyapat | odyssey4me: can you please look at this https://review.openstack.org/#/c/450973/ | 17:31 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone master: [WIP] Switch to using Nginx/uWSGI by default https://review.openstack.org/451480 | 17:32 |
sanfern | Hi all, while running repo-build.yml playbook is failing on script /opt/op-venv-script.sh - http://paste.openstack.org/show/5vfOXyNBciZTgoBR88JA/ | 17:32 |
odyssey4me | sanfern can you provide a paste of the log from /openstack/log/<repo container name>/repo/*venv*.log | 17:33 |
odyssey4me | the ansible output is impossible to read | 17:33 |
openstackgerrit | Marc Gariépy proposed openstack/openstack-ansible stable/ocata: updating ceph roles to 2.1.9 https://review.openstack.org/451494 | 17:34 |
*** electrofelix has quit IRC | 17:36 | |
*** cjloader has joined #openstack-ansible | 17:38 | |
*** cjloader has quit IRC | 17:41 | |
sanfern | odyssey4me, http://paste.openstack.org/show/Hog3hnbxCFVDDc3ibHHx/ there is a syntax error monasca code | 17:41 |
odyssey4me | sanfern and there you have it | 17:42 |
sanfern | odyssey4me, Thanks a lot | 17:42 |
*** cjloader has joined #openstack-ansible | 17:43 | |
odyssey4me | :) | 17:43 |
andymccr | odyssey4me: nope, not yet at least. i need to get my ass into gear on that side of things. | 17:43 |
odyssey4me | andymccr well, I made one up | 17:43 |
andymccr | haha nice | 17:43 |
andymccr | i was looking through projects that already support wsgi etc - that is gonna be the main hurdle atm :P | 17:43 |
odyssey4me | yeah, but we can do those that have it | 17:44 |
odyssey4me | we'll have to figure out what to do about the others on a case-by-case basis | 17:44 |
odyssey4me | ideally we want like functionality at least - a web server that can handle SSL with a service running behind it | 17:45 |
*** BjoernT has joined #openstack-ansible | 17:46 | |
agrebennikov | hey logan-, | 17:47 |
agrebennikov | I have a question regarding https://github.com/openstack/openstack-ansible-os_nova/commit/2c641baaffd6ec7f1a0222089252686f239bf150 | 17:47 |
agrebennikov | or odyssey4me actually, sorry for bugging you but it doesn't allow to deploy successfully | 17:48 |
*** retreved has joined #openstack-ansible | 17:48 | |
*** retreved_ has joined #openstack-ansible | 17:49 | |
*** retreved has quit IRC | 17:49 | |
odyssey4me | argh | 17:50 |
odyssey4me | that whole thing is a mess | 17:50 |
odyssey4me | I wish we could figure out a better way of achieving the goal | 17:50 |
*** cathrichardson has quit IRC | 17:50 | |
*** kstev has quit IRC | 17:50 | |
*** kstev has joined #openstack-ansible | 17:51 | |
*** cjloader has quit IRC | 17:52 | |
*** pcaruana has quit IRC | 17:52 | |
agrebennikov | the issue was that the service was started but there was no folder at all | 17:52 |
agrebennikov | and "service libvirtd status" showed it as running | 17:52 |
agrebennikov | and the processa was running | 17:52 |
*** stuartgr has left #openstack-ansible | 17:52 | |
*** vnogin has joined #openstack-ansible | 17:52 | |
agrebennikov | the folder though appeared right after I manually restarted it | 17:53 |
agrebennikov | odyssey4me, | 17:53 |
odyssey4me | yeah, that's come up before - but I thought that logan-'s patch fixed it | 17:54 |
*** tonytan4ever has joined #openstack-ansible | 17:56 | |
agrebennikov | logan's patch adds just waiting | 17:56 |
agrebennikov | hoping that the folder will magically show up | 17:56 |
*** vishwanathj has joined #openstack-ansible | 17:58 | |
*** weezS has joined #openstack-ansible | 18:01 | |
*** poopcat has joined #openstack-ansible | 18:03 | |
*** cathrichardson has joined #openstack-ansible | 18:04 | |
rboyapat | core members is there a way to run the gate tests again | 18:09 |
*** poopcat has quit IRC | 18:11 | |
rboyapat | some tests are failing, may be a glitch pulling packages form ubuntu repo , would like to run the gate tests again | 18:12 |
agrebennikov | rboyapat, just reply "recheck" | 18:12 |
rboyapat | agrebennikov: thanks | 18:13 |
*** acormier_ has joined #openstack-ansible | 18:14 | |
alextricity25 | cloudnull: I don't know to be honest. As of now I would say that ceilo in Pike is somewhat "under renovations" | 18:14 |
alextricity25 | the whole telemetry stack, for that matter. | 18:14 |
*** acormier has quit IRC | 18:16 | |
alextricity25 | cloudnull: I don't see any reason why the ceilometer role tests would fail | 18:17 |
*** galstrom is now known as galstrom_zzz | 18:20 | |
*** poopcat has joined #openstack-ansible | 18:24 | |
*** pbandark has quit IRC | 18:25 | |
openstackgerrit | Merged openstack/openstack-ansible-pip_install master: Resolve user_external_repo deprecation warnings https://review.openstack.org/451347 | 18:26 |
*** cjloader has joined #openstack-ansible | 18:28 | |
openstackgerrit | Merged openstack/openstack-ansible-os_almanach master: Ensure the components are isolated from the system https://review.openstack.org/451124 | 18:37 |
openstackgerrit | Merged openstack/openstack-ansible-os_cloudkitty master: Ensure the components are isolated from the system https://review.openstack.org/451171 | 18:39 |
openstackgerrit | Merged openstack/openstack-ansible-os_neutron master: Remove min_l3_agents_per_router option https://review.openstack.org/451163 | 18:43 |
*** openstackstatus has joined #openstack-ansible | 18:43 | |
*** ChanServ sets mode: +v openstackstatus | 18:43 | |
*** lucasxu has quit IRC | 18:45 | |
*** lucasxu has joined #openstack-ansible | 18:45 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install stable/ocata: Resolve user_external_repo deprecation warnings https://review.openstack.org/451513 | 18:49 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-pip_install stable/newton: Resolve user_external_repo deprecation warnings https://review.openstack.org/451514 | 18:49 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder stable/ocata: Do a whole word grep https://review.openstack.org/451515 | 18:50 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_cinder stable/newton: Do a whole word grep https://review.openstack.org/451516 | 18:50 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-haproxy_server master: Allow cert validation for hatop download to be disabled https://review.openstack.org/451287 | 18:54 |
odyssey4me | andymccr I thought that https://review.openstack.org/451444 wasn't needed with that other patch included which checks whether the rings need changing and it only happens if they do | 18:55 |
odyssey4me | ie https://review.openstack.org/447447 | 18:56 |
mhayden | andymccr: https://review.openstack.org/#/c/444325/ doh | 18:57 |
odyssey4me | mhayden you should reply with your ML request to work together, and the crickets in response | 18:58 |
mhayden | odyssey4me: ORLY | 18:58 |
mhayden | i also spoke to the famous mrhillsman about it | 18:58 |
odyssey4me | you could also add Melvin's support for the project | 18:59 |
mhayden | to be fair, mrhillsman had glowing praise for it... i think he said "it's the least worst idea proposed" | 18:59 |
andymccr | odyssey4me: it is for MR swift - in MR swift we attempt a rebalance with new devices within an hour (when we setup the new region) | 19:00 |
odyssey4me | andymccr ah, and that's a special case | 19:00 |
odyssey4me | okie dokey | 19:00 |
andymccr | yeah basically - unfortunatley it seems we still have a bug that sometimes occurs in our centos gates - and the cross policy write tests fail because the second policy tests our EC policies :( | 19:01 |
mrhillsman | someone mention me :) | 19:01 |
odyssey4me | mhayden with regard to monitorstack, you could also indicate that we've agreed to curate it until there is broader interest | 19:01 |
odyssey4me | that said, the questions are valid - will this reduce the chances that others will participate... | 19:02 |
andymccr | yeah thats worth noting | 19:02 |
andymccr | for me the issue is that participation has been low so far | 19:02 |
andymccr | i leave it in your capable hands mhayden :D | 19:02 |
odyssey4me | otherwise I guess you could just add a bunch of OSA people interested as cores and leave it at that | 19:03 |
mrhillsman | i did not see it on the mailing list originally unfortunately | 19:03 |
andymccr | yeah basically we could mirror the core list | 19:03 |
odyssey4me | it's possible to add a group to the list, so you could easily add the entire OSA core team | 19:03 |
odyssey4me | if you wanted | 19:03 |
mrhillsman | we have at least a couple folks on our team focused on ops tools | 19:03 |
odyssey4me | I'd suggest rather canvassing for a broader group though - try and get some people from across the deployment project teams. | 19:04 |
odyssey4me | And from the osops crew. | 19:04 |
*** brianw has quit IRC | 19:04 | |
mrhillsman | we started back having osops meetings | 19:04 |
mrhillsman | so ... what odyssey4me said :) | 19:04 |
mrhillsman | i think we just need a good explanation of the tool and where you would like to see it go mhayden | 19:06 |
mrhillsman | then we can bug the hell out of people to participate :) | 19:07 |
mrhillsman | would be good also i think if we can demo it, osic team tech talks could be a good place to start | 19:07 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron master: Ensure the components are isolated from the system https://review.openstack.org/451156 | 19:10 |
*** hybridpollo has joined #openstack-ansible | 19:15 | |
*** craigs has quit IRC | 19:15 | |
openstackgerrit | Merged openstack/openstack-ansible-os_gnocchi master: Do not try to create legacy resources https://review.openstack.org/450707 | 19:16 |
*** david-lyle has quit IRC | 19:19 | |
*** david-lyle has joined #openstack-ansible | 19:19 | |
*** hybridpollo has quit IRC | 19:21 | |
*** hybridpollo has joined #openstack-ansible | 19:21 | |
*** woodard has joined #openstack-ansible | 19:24 | |
EmilienM | odyssey4me: can you make sure we have some OSA folks in Boston about [deployment][forum] proposing a session about future of configuration management - ops + devs wanted! | 19:25 |
odyssey4me | EmilienM I expect that andymccr will be there at the very least. I don't know who else is definitely going. | 19:26 |
EmilienM | ok, please make sure someone from OSA goes and I'm happy | 19:26 |
odyssey4me | mgariepy it's nice to see the CentOS tests finally going green in most places again. :) | 19:27 |
*** david-lyle has quit IRC | 19:27 | |
odyssey4me | EmilienM yep, I expect that andymccr will haul whoever's there to the session - if I'm there, I'll definitely join | 19:27 |
EmilienM | odyssey4me: not you? | 19:28 |
EmilienM | odyssey4me: I hope you can join | 19:28 |
EmilienM | I mean | 19:28 |
EmilienM | I can't go to the Summit if you don't join | 19:28 |
*** shashank_t_ has quit IRC | 19:28 | |
odyssey4me | EmilienM I don't get automatic travel approval any more, now that I'm not PTL. :p | 19:28 |
odyssey4me | I will try to be there, but can't guarantee anything. | 19:29 |
EmilienM | I'll fly and pick you up in UK | 19:29 |
odyssey4me | hahaha | 19:29 |
odyssey4me | Bring your Jet, I'm totally up for it. | 19:29 |
vnogin | :) | 19:30 |
*** david-lyle has joined #openstack-ansible | 19:30 | |
EmilienM | well, I'm flying Cessna for now, but still 3 empty seats | 19:30 |
odyssey4me | sounds good to me | 19:30 |
EmilienM | I just need to refuel over atlantic :P | 19:31 |
odyssey4me | I'll bring the barf bags, and the whiskey. | 19:31 |
odyssey4me | Meh, we can use one of those flying refueling things. | 19:31 |
odyssey4me | Or I'll just strap on a harnass and refuel with jerry cans. | 19:31 |
mattt | EmilienM: did you see this? http://imgur.com/a/xOzzg | 19:31 |
EmilienM | wat | 19:32 |
EmilienM | I mean | 19:32 |
EmilienM | WHAT | 19:32 |
odyssey4me | hahaha | 19:32 |
*** openstackgerrit has quit IRC | 19:33 | |
*** jamielennox|away is now known as jamielennox | 19:33 | |
odyssey4me | oh dear, openstackgerrit has left | 19:33 |
odyssey4me | the world is about to end | 19:33 |
*** karimb_ has quit IRC | 19:34 | |
EmilienM | mattt: that's awesome | 19:34 |
EmilienM | mattt: do you know the TV show called "Ice pilots"? | 19:34 |
EmilienM | they did the same with fire fighting planes | 19:35 |
mgariepy | odyssey4me, what ? centos is greening up ? | 19:35 |
mattt | EmilienM: ha, never seen it | 19:36 |
odyssey4me | mgariepy in the last os_Swift patch it's all green | 19:36 |
mgariepy | cool | 19:37 |
mgariepy | nova and osa are the hardest | 19:37 |
mgariepy | haha | 19:37 |
EmilienM | mattt: on netflix | 19:37 |
*** karimb has joined #openstack-ansible | 19:39 | |
*** openstackgerrit has joined #openstack-ansible | 19:42 | |
openstackgerrit | Merged openstack/openstack-ansible master: Keystone: Source template files from git or deploy host https://review.openstack.org/450804 | 19:42 |
*** cpuga_ has joined #openstack-ansible | 19:46 | |
*** kstev has quit IRC | 19:46 | |
*** cpuga has quit IRC | 19:50 | |
*** woodard has quit IRC | 19:51 | |
*** galstrom_zzz is now known as galstrom | 19:53 | |
mhayden | mrhillsman: i do owe some docs there | 19:57 |
*** tonytan4ever has quit IRC | 19:57 | |
pjm6 | in OSA we don't have image-volume cache for cinder, right? | 19:58 |
*** galstrom is now known as galstrom_zzz | 20:00 | |
*** manheim has joined #openstack-ansible | 20:00 | |
*** BjoernT has quit IRC | 20:02 | |
*** galstrom_zzz is now known as galstrom | 20:02 | |
*** galstrom is now known as galstrom_zzz | 20:08 | |
mrda | Morning OSA | 20:11 |
spotz | hey mrda | 20:12 |
pjm6 | hey mrda, spotz | 20:13 |
mrda | o/ | 20:13 |
*** smatzek has quit IRC | 20:18 | |
*** pramodrj07 has joined #openstack-ansible | 20:31 | |
*** david-lyle has quit IRC | 20:33 | |
*** MasterOfBugs has quit IRC | 20:34 | |
*** david-lyle has joined #openstack-ansible | 20:35 | |
*** david-lyle has quit IRC | 20:40 | |
*** david-lyle has joined #openstack-ansible | 20:42 | |
*** cathrichardson has quit IRC | 20:46 | |
*** david-lyle has quit IRC | 20:46 | |
*** cathrichardson has joined #openstack-ansible | 20:46 | |
*** cathrichardson has quit IRC | 20:46 | |
*** cathrichardson has joined #openstack-ansible | 20:47 | |
foutatoro | hi all, did someone run "Failed to create certificates for Cluster" when creating magnum cluster in OSA ? | 20:47 |
*** weezS has quit IRC | 20:48 | |
*** weezS has joined #openstack-ansible | 20:49 | |
*** galstrom_zzz is now known as galstrom | 20:51 | |
*** david-lyle has joined #openstack-ansible | 20:52 | |
*** karimb has quit IRC | 20:52 | |
*** galstrom is now known as galstrom_zzz | 20:56 | |
*** acormier has joined #openstack-ansible | 20:57 | |
odyssey4me | foutatoro yeah, I think I saw a patch fly by to address that | 20:57 |
odyssey4me | https://review.openstack.org/#/q/If18a447a38f0b8ac9f1bf076d4124ccceb018627 | 20:57 |
*** rboyapat has quit IRC | 20:58 | |
odyssey4me | what tag or branch are you using? | 20:58 |
*** rboyapat has joined #openstack-ansible | 20:58 | |
openstackgerrit | Major Hayden proposed openstack/monitorstack master: [Docs] Initial docs for monitorstack https://review.openstack.org/451566 | 20:59 |
mhayden | cloudnull: ^^ | 20:59 |
foutatoro | odyssey4me: thanks. I'm using 14.1.1 | 21:00 |
pjm6 | mhayden, nice one :D | 21:01 |
*** acormier_ has quit IRC | 21:01 | |
odyssey4me | foutatoro ok, so that patch is in the next release of OSA Newton | 21:01 |
odyssey4me | so either you cherry pick it into your environment, or use the head of stable/newton instead | 21:02 |
*** rboyapat has quit IRC | 21:03 | |
pjm6 | it is possible to change the default avaiability zone name from an deployment that are in prod? | 21:03 |
foutatoro | odyssey4me: ok thanks | 21:06 |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_keystone master: [WIP] Switch to using Nginx/uWSGI by default https://review.openstack.org/451480 | 21:07 |
odyssey4me | pjm6 I'm not sure if AZ names can be changed via an API in OS | 21:08 |
*** galstrom_zzz is now known as galstrom | 21:09 | |
odyssey4me | it's plausible, but I haven't tried it | 21:09 |
*** jrobinson has joined #openstack-ansible | 21:09 | |
odyssey4me | pjm6 sorry - was stuck in the weeds there | 21:09 |
odyssey4me | re: image-volume cache for cinder... I have no idea what it is, or whether OSA would need to do anything to support it | 21:10 |
odyssey4me | does it need new services? how is it implemented? | 21:10 |
asettle | odyssey4me: yo udude why are you awake?! | 21:10 |
odyssey4me | if it's just config, then just use the config_override mechanism | 21:10 |
odyssey4me | asettle 'cos there is still whiskey to drink, naturally | 21:10 |
asettle | odyssey4me: drink and work, is my philosophy | 21:11 |
pjm6 | odyssey4me, i had take a look and don't see if I can change it via API, but I was looking in the nova role, and we can't change the default, right? We can only choose the default AZ but not the name | 21:11 |
odyssey4me | asettle actually because andymccr conned me into doing https://review.openstack.org/451480 | 21:11 |
* asettle sips whisky on at meeting | 21:11 | |
asettle | Ugh that guy | 21:11 |
asettle | He's such a wanker :P | 21:11 |
pjm6 | odyssey4me, it's only config related | 21:11 |
odyssey4me | pjm6 regardless of whether we have a var for it or not, if it's possible to change it in nova.conf, the config override can do it | 21:12 |
pjm6 | hey asettle :P | 21:12 |
asettle | pjm6: wasssup | 21:12 |
pjm6 | but the AZ are changed in the nova.config file? | 21:13 |
pjm6 | asettle, hows going? | 21:14 |
odyssey4me | pjm6 https://docs.openstack.org/project-deploy-guide/openstack-ansible/ocata/app-advanced-config-override.html#overriding-conf-files | 21:14 |
pjm6 | odyssey4me, forget, I missed the "if it's possible to change' | 21:14 |
odyssey4me | pjm6 with that, you can do ANYTHING! | 21:14 |
pjm6 | this applies to all services? | 21:15 |
odyssey4me | pjm6 yeah, so what I mean is that if there's a nova.conf entry for it, then you can use that mechanism to put it into your nova.conf | 21:15 |
odyssey4me | yep, it applies to all services | 21:15 |
odyssey4me | the var to use is different for each service though, but the same principle | 21:15 |
pjm6 | this helps a lot, and I think that solve the problem yes | 21:15 |
pjm6 | i used with keystone and nova | 21:15 |
odyssey4me | see '## Tunable overrides' here: https://docs.openstack.org/developer/openstack-ansible-os_cinder/ | 21:15 |
pjm6 | regarding to Image Caching, basically if I understood well it helps when we are fetching an image to a volume | 21:16 |
pjm6 | thanks, and i just need to put the extra configs there that will put in the correct section, right? | 21:17 |
foutatoro | odyssey4me: what's recommended to reinstall only magnum after modifying the os_magnum role ? | 21:18 |
*** woodard has joined #openstack-ansible | 21:21 | |
*** gouthamr has quit IRC | 21:21 | |
*** retreved_ has quit IRC | 21:25 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Added an ALL is_metal scenario https://review.openstack.org/449372 | 21:27 |
*** lucasxu has quit IRC | 21:34 | |
odyssey4me | foutatoro if no packages have changed, just re-execute the os-magnum-install.yml playbook | 21:35 |
odyssey4me | ie | 21:35 |
odyssey4me | cd /opt/openstack-ansible/playbooks | 21:35 |
odyssey4me | openstack-ansible os-magnum-install.yml | 21:35 |
*** cathrichardson has quit IRC | 21:37 | |
*** pramodrj07 has quit IRC | 21:41 | |
*** pramodrj07 has joined #openstack-ansible | 21:41 | |
*** schwicht has quit IRC | 21:43 | |
*** cpuga has joined #openstack-ansible | 21:44 | |
*** cpuga_ has quit IRC | 21:46 | |
spotz | asettle why are you awake?:) | 21:49 |
*** shardy has quit IRC | 21:50 | |
*** esberglu has quit IRC | 21:56 | |
*** esberglu has joined #openstack-ansible | 21:57 | |
*** esberglu has quit IRC | 22:02 | |
*** woodard has quit IRC | 22:04 | |
*** schwicht has joined #openstack-ansible | 22:09 | |
*** jamielennox is now known as jamielennox|away | 22:09 | |
*** adrian_otto has quit IRC | 22:09 | |
*** adrian_otto has joined #openstack-ansible | 22:10 | |
*** jamielennox|away is now known as jamielennox | 22:12 | |
*** acormier has quit IRC | 22:22 | |
*** marst_ has quit IRC | 22:27 | |
*** galstrom is now known as galstrom_zzz | 22:30 | |
*** manheim has quit IRC | 22:32 | |
*** shashank_t_ has joined #openstack-ansible | 22:33 | |
*** askb has joined #openstack-ansible | 22:33 | |
cmart | odyssey4me, have a moment? a couple weeks ago you suggested rootwrap as a solution to an issue I had encountered with libguestfs. i'm unsure if it's a workable solution, have another suggestion. want to see if you'd consider it good enough for OSA. | 22:33 |
odyssey4me | cmart sure, fire away | 22:34 |
* odyssey4me is waiting for another patch test to run | 22:34 | |
odyssey4me | I'm having a little fun trying to make an upgrade switch web server from Apache -> Nginx while not affecting upgrades | 22:35 |
cmart | ah that's gotta be a fun transplant | 22:35 |
cmart | so basically libguestfs doesn't work out of the box in Ubuntu because it needs to read the kernel, and Ubuntu has decided to make the kernel non-readable to non-root users by default.. we know this | 22:36 |
odyssey4me | the challenge is tto try and do the switch while not losing any transactions while it switches | 22:36 |
cmart | I was reading the rootwrap docs, apparently you run "nova.utils.execute(run_as_root=True)" inside Nova to request a command to be passed through rootwrap -- but the code running the root commands is actually a system-level Python package installed via APT (python-guestfs), that OSA links into the Nova virtualenv. | 22:37 |
cmart | Nova just does "import guestfs" and "guestfs.do_stuff()", and the guestfs package imports a C library and does things.. so Nova never has the opportunity (that I can see) to run anything using rootwrap. | 22:38 |
cmart | so if we go down this path, I think the guestfs code itself would need to be monkeyed with | 22:40 |
cmart | alternative solution: just make the kernel readable to the nova user | 22:40 |
cmart | it already readable is distros that *aren't* Ubuntu, and I believe it would solve this problem | 22:41 |
cmart | it's already readable in distros * | 22:41 |
odyssey4me | I guess if that was an opt-in setting, and the setting had a clear note and reference to the bug where this is discussed, then having a task which it activates that gives those right would work | 22:41 |
odyssey4me | is it a file system right issue, or an apparmor issue? | 22:44 |
cmart | I believe just a filesystem issue, though I'm not familiar with how we're using apparmor. | 22:44 |
cmart | (and everyone else's experience (Mirantis/Fuel, libguestfs dev team, etc) seems to indicate so) | 22:45 |
cmart | we could make the setting contingent upon "nova_libvirt_inject_key" being greater than -2, and one of either "nova_libvirt_inject_key" and "nova_libvirt_inject_password" being true. then it would just work if someone will need the feature | 22:46 |
odyssey4me | well, apparmor can block various actions to a path over and above the file system's rights | 22:46 |
odyssey4me | similar to selinux | 22:46 |
*** gouthamr has joined #openstack-ansible | 22:46 | |
odyssey4me | yep, I'm OK with that as long as we add some commented info where those are defined to warn of what happens if someone does it | 22:47 |
*** schwicht has quit IRC | 22:47 | |
cmart | ok. would the "default variables" section of the docs (or whatever generates it) be the right place for the warning information? | 22:47 |
cmart | I see a few warnings already in there, and that's hopefully where someone will be looking when they're configuring this stuff | 22:48 |
cmart | actually, I suspect it's not apparmor because when I relax the file permissions on the kernel, it works again | 22:48 |
*** marst has joined #openstack-ansible | 22:49 | |
odyssey4me | cmart yeah, the role defaults/main.yml file get exported verbatim into the role docs | 22:50 |
odyssey4me | so in this case, just add the comments to the os_nova role's defaults/main.yml file | 22:50 |
odyssey4me | it'll be an opt-in thing, so someone has to go and look for these settings to find them, and they would hopefully read the note | 22:51 |
odyssey4me | put the warning in the defaults where those vars are | 22:51 |
cmart | it sounds like AppArmor is used to "limit the actions that each LXC container may take on a system". for the issue we're talking about, all the action is happening on bare metal of Nova compute hosts. so I really doubt AppArmor is playing a role | 22:51 |
odyssey4me | but put the reference to the bug before the task to explain the purpose of the task | 22:51 |
odyssey4me | well, put a patch together, test it in your env | 22:52 |
cmart | ok. should I also file an OSA bug to capture this understanding? or just reference the existing bugs in Nova, Fuel, etc where this issue has been beaten to death? | 22:52 |
*** shashank_t_ has quit IRC | 22:54 | |
*** shashank_t_ has joined #openstack-ansible | 22:55 | |
cmart | I think I'll file it, would be a good place to summarize how we got here. | 22:55 |
*** thorst has quit IRC | 22:56 | |
*** shashank_t_ has quit IRC | 22:59 | |
*** vnogin has quit IRC | 23:05 | |
odyssey4me | if you feel that it needs summarizing, then go ahead | 23:09 |
odyssey4me | otherwise better to just reference the existing bugs | 23:09 |
*** acormier has joined #openstack-ansible | 23:12 | |
*** pmannidi has joined #openstack-ansible | 23:14 | |
*** acormier has quit IRC | 23:16 | |
*** pramodrj07 has quit IRC | 23:22 | |
*** cjloader_ has joined #openstack-ansible | 23:30 | |
*** klamath has quit IRC | 23:31 | |
*** cjloader has quit IRC | 23:33 | |
*** cjloader_ has quit IRC | 23:34 | |
*** foutatoro has quit IRC | 23:34 | |
*** schwicht has joined #openstack-ansible | 23:40 | |
*** adrian_otto has quit IRC | 23:51 | |
*** thorst has joined #openstack-ansible | 23:56 | |
*** cpuga has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!