*** oanson has joined #openstack-ansible | 00:01 | |
*** cpuga has quit IRC | 00:08 | |
*** dxiri_ has joined #openstack-ansible | 00:09 | |
*** dxiri has quit IRC | 00:12 | |
*** acormier has quit IRC | 00:16 | |
*** schwicht has joined #openstack-ansible | 00:27 | |
*** nollide has joined #openstack-ansible | 00:30 | |
*** aslaen has quit IRC | 00:37 | |
*** thorst has quit IRC | 00:45 | |
*** acormier has joined #openstack-ansible | 00:49 | |
*** oanson has quit IRC | 00:54 | |
*** acormier has quit IRC | 00:55 | |
*** oanson has joined #openstack-ansible | 00:56 | |
*** acormier has joined #openstack-ansible | 00:56 | |
*** galstrom_zzz is now known as galstrom | 01:12 | |
*** dxiri_ has quit IRC | 01:18 | |
*** dxiri has joined #openstack-ansible | 01:18 | |
*** dxiri has quit IRC | 01:19 | |
*** dxiri has joined #openstack-ansible | 01:19 | |
*** dxiri has quit IRC | 01:19 | |
*** dxiri has joined #openstack-ansible | 01:19 | |
*** dxiri has quit IRC | 01:26 | |
*** dxiri has joined #openstack-ansible | 01:26 | |
*** thorst has joined #openstack-ansible | 01:28 | |
*** thorst has quit IRC | 01:28 | |
*** charcol has quit IRC | 01:38 | |
*** charcol has joined #openstack-ansible | 01:39 | |
*** smatzek has joined #openstack-ansible | 01:40 | |
*** smatzek has quit IRC | 01:41 | |
*** smatzek has joined #openstack-ansible | 01:41 | |
*** nollide has quit IRC | 01:42 | |
*** ricardoas has quit IRC | 01:42 | |
*** nollide has joined #openstack-ansible | 01:42 | |
*** cmart has joined #openstack-ansible | 01:43 | |
*** ricardoas has joined #openstack-ansible | 01:44 | |
*** dixiaoli has joined #openstack-ansible | 01:46 | |
*** klamath has quit IRC | 01:46 | |
*** klamath has joined #openstack-ansible | 01:47 | |
*** nollide has quit IRC | 01:49 | |
*** gkadam has joined #openstack-ansible | 01:49 | |
*** tonytan_brb has joined #openstack-ansible | 01:49 | |
*** acormier has quit IRC | 01:50 | |
*** smatzek has quit IRC | 01:50 | |
*** acormier has joined #openstack-ansible | 01:50 | |
*** schwicht has quit IRC | 01:51 | |
*** tonytan4ever has quit IRC | 01:52 | |
*** klamath has quit IRC | 01:52 | |
*** acormier_ has joined #openstack-ansible | 01:52 | |
*** klamath has joined #openstack-ansible | 01:53 | |
*** acormier has quit IRC | 01:55 | |
*** dixiaoli_ has joined #openstack-ansible | 02:04 | |
*** dixiaoli has quit IRC | 02:07 | |
*** galstrom is now known as galstrom_zzz | 02:11 | |
*** acormier_ has quit IRC | 02:12 | |
*** acormier has joined #openstack-ansible | 02:13 | |
*** hw_wutianwei has joined #openstack-ansible | 02:19 | |
*** phalmos_ has quit IRC | 02:23 | |
*** klamath has quit IRC | 02:28 | |
*** galstrom_zzz is now known as galstrom | 02:37 | |
*** ricardoas has quit IRC | 02:46 | |
*** acormier has quit IRC | 02:49 | |
*** acormier has joined #openstack-ansible | 02:50 | |
*** ricardoas has joined #openstack-ansible | 02:52 | |
*** acormier has quit IRC | 02:54 | |
*** tonytan_brb has quit IRC | 02:58 | |
*** schwicht has joined #openstack-ansible | 03:20 | |
*** LiterateHawk has quit IRC | 03:24 | |
*** schwicht has quit IRC | 03:27 | |
*** tonytan4ever has joined #openstack-ansible | 03:28 | |
*** thorst has joined #openstack-ansible | 03:29 | |
*** thorst has quit IRC | 03:34 | |
*** dixiaoli has joined #openstack-ansible | 03:38 | |
*** dixiaoli_ has quit IRC | 03:39 | |
*** dxiri has quit IRC | 03:41 | |
*** winggundamth has joined #openstack-ansible | 03:42 | |
*** udesale has joined #openstack-ansible | 03:46 | |
*** LiterateHawk has joined #openstack-ansible | 03:47 | |
*** dixiaoli has quit IRC | 03:49 | |
*** acormier has joined #openstack-ansible | 03:50 | |
*** schwicht has joined #openstack-ansible | 03:53 | |
*** cNilesh has joined #openstack-ansible | 03:54 | |
*** acormier has quit IRC | 03:54 | |
*** tonytan4ever has quit IRC | 03:57 | |
*** schwicht has quit IRC | 03:57 | |
*** cathrich_ has joined #openstack-ansible | 03:58 | |
*** cathrichardson has quit IRC | 03:58 | |
*** galstrom is now known as galstrom_zzz | 04:00 | |
*** poopcat has quit IRC | 04:03 | |
*** cNilesh is now known as cNilesh|bf | 04:05 | |
*** adreznec has quit IRC | 04:13 | |
*** adreznec has joined #openstack-ansible | 04:14 | |
*** dxiri has joined #openstack-ansible | 04:19 | |
*** dxiri has quit IRC | 04:19 | |
*** dxiri has joined #openstack-ansible | 04:19 | |
cloudnull | tots I am. | 04:21 |
---|---|---|
cloudnull | hows it ? | 04:21 |
*** dxiri has quit IRC | 04:26 | |
*** hybridpollo has quit IRC | 04:44 | |
*** cpuga has joined #openstack-ansible | 04:51 | |
*** acormier has joined #openstack-ansible | 04:52 | |
*** cpuga has quit IRC | 04:52 | |
*** cpuga has joined #openstack-ansible | 04:53 | |
*** acormier has quit IRC | 04:56 | |
*** cpuga has quit IRC | 04:58 | |
*** kristian__ has joined #openstack-ansible | 05:01 | |
*** kristian__ has quit IRC | 05:06 | |
*** pmannidi has quit IRC | 05:09 | |
*** pmannidi has joined #openstack-ansible | 05:13 | |
*** pmannidi has quit IRC | 05:13 | |
*** cathrich_ has quit IRC | 05:15 | |
*** dixiaoli has joined #openstack-ansible | 05:17 | |
*** cathrichardson has joined #openstack-ansible | 05:17 | |
*** woodard has quit IRC | 05:24 | |
*** thorst has joined #openstack-ansible | 05:30 | |
*** thorst has quit IRC | 05:34 | |
*** kristian__ has joined #openstack-ansible | 05:47 | |
*** gkadam has quit IRC | 05:56 | |
*** gkadam has joined #openstack-ansible | 05:58 | |
*** pcaruana has joined #openstack-ansible | 06:04 | |
odyssey4me | LiterateHawk and you completed the setup-hosts playbook without a hitch? | 06:12 |
odyssey4me | can you pastebin the contents of /etc/ansible/facts.d/openstack_ansible from that repo container? | 06:13 |
*** Oku_OS-away is now known as Oku_OS | 06:14 | |
*** gkadam has quit IRC | 06:17 | |
*** gkadam has joined #openstack-ansible | 06:17 | |
*** kristian__ has quit IRC | 06:18 | |
*** gkadam has quit IRC | 06:18 | |
*** kristian__ has joined #openstack-ansible | 06:18 | |
*** gkadam has joined #openstack-ansible | 06:19 | |
*** gkadam has quit IRC | 06:21 | |
*** cshen has joined #openstack-ansible | 06:23 | |
*** basilAB has quit IRC | 06:23 | |
*** vaishali has quit IRC | 06:24 | |
*** gtrxcb has joined #openstack-ansible | 06:25 | |
*** basilAB has joined #openstack-ansible | 06:28 | |
*** vaishali has joined #openstack-ansible | 06:29 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible master: [WIP] Just-in-time container creation https://review.openstack.org/471026 | 06:35 |
*** mbuil has joined #openstack-ansible | 06:43 | |
*** gkadam has joined #openstack-ansible | 06:44 | |
*** gkadam has quit IRC | 06:46 | |
*** aneos has joined #openstack-ansible | 06:49 | |
*** tobberydberg has joined #openstack-ansible | 06:53 | |
*** aneos has quit IRC | 06:54 | |
*** acormier has joined #openstack-ansible | 06:54 | |
*** tobberyd_ has joined #openstack-ansible | 06:55 | |
*** anetos has joined #openstack-ansible | 06:56 | |
*** tobberydberg has quit IRC | 06:58 | |
*** acormier has quit IRC | 06:59 | |
*** vishwana_ has joined #openstack-ansible | 07:06 | |
*** vishwanathj has quit IRC | 07:06 | |
anetos | hello , i have galera failures http://paste.openstack.org/show/614982/ . do i follow this to get it fixed ? https://docs.openstack.org/openstack-ansible/newton/newton/developer-docs/ops-galera-recovery.html | 07:08 |
*** shardy has joined #openstack-ansible | 07:11 | |
*** jvidal has joined #openstack-ansible | 07:17 | |
*** thorst has joined #openstack-ansible | 07:31 | |
*** anetos has quit IRC | 07:32 | |
*** openstackgerrit has quit IRC | 07:33 | |
*** thorst has quit IRC | 07:36 | |
*** anetos has joined #openstack-ansible | 07:37 | |
*** openstackgerrit has joined #openstack-ansible | 07:38 | |
openstackgerrit | Merged openstack/openstack-ansible stable/ocata: Tidy up keystone need_db_sync fact https://review.openstack.org/482232 | 07:38 |
*** toddnni has joined #openstack-ansible | 07:40 | |
*** toddnni has quit IRC | 07:40 | |
*** toddnni has joined #openstack-ansible | 07:45 | |
*** gtrxcb has quit IRC | 07:46 | |
*** markvoelker_ has quit IRC | 07:47 | |
*** pvradu has joined #openstack-ansible | 07:48 | |
*** pbandark has joined #openstack-ansible | 07:54 | |
*** openstackgerrit has quit IRC | 08:03 | |
*** openstackgerrit has joined #openstack-ansible | 08:04 | |
openstackgerrit | Adrien Cunin proposed openstack/openstack-ansible master: Vars passed to openstack-ansible take precedence https://review.openstack.org/482440 | 08:04 |
odyssey4me | anetos I would suggest you do your own research, but some stuff is documented here: https://docs.openstack.org/openstack-ansible/latest/admin/maintenance-tasks/galera.html | 08:09 |
*** vnogin has joined #openstack-ansible | 08:13 | |
anetos | odyssey4me: i have been reading that page | 08:15 |
kristian__ | Hey, does anyone know how do I deploy to a non / partition? because on ovh, you have / that has 30gb ish partition and /home that has 2tb | 08:16 |
odyssey4me | kristian__ sure, just prep your host before deployment accordingly | 08:16 |
kristian__ | on the same hdd. How can I deploy openstack-ansible on /home? | 08:17 |
anetos | as i understand it i should stop all 3 failed galera containers and rebuild them per the above instructions then run setup hosts and setup infra | 08:17 |
odyssey4me | ah no, the paths aren't quite that flexible | 08:17 |
odyssey4me | kristian__ it'll take a few patches to get it to the point that the paths are flexible, so if you're up to do it then we'd support the work | 08:17 |
kristian__ | odyssey4me: then what shall I do? I cannot find anything related in the docs. For now I need openstack running there and I cannot afford to reinstall the server because I have k8s running right now there and I plan on moving it to openstack. But is there a simple hack for that? | 08:19 |
kristian__ | odyssey4me: do you know how to do that? | 08:25 |
*** gkadam has joined #openstack-ansible | 08:25 | |
*** gkadam is now known as gkadam-afk | 08:26 | |
*** gkadam-afk has quit IRC | 08:26 | |
kristian__ | please could someone help me? It will be an AIO install | 08:35 |
andymccr | kristian__: if you have no access to how the file systems are mounted thats pretty hard. the majority of space is probably in /var/lib since that'd be where the containers live - but if you can't mount something there from the 2tb drive that could be difficult. maybe symlink to that location? (and remove the task that performs a disk space check) | 08:36 |
andymccr | more specifically /var/lib/lxc | 08:36 |
kristian__ | yeah, Thats what Im thinking about | 08:37 |
kristian__ | but I need all paths that I need to symlink | 08:37 |
kristian__ | andymccr: /var/lib/lxc is an executable. /var/lib/lxcfs is a dir | 08:38 |
andymccr | all of them - well, you would definitely want /var/lib/lxc then /openstack - those would be the main ones | 08:38 |
andymccr | kristian__: shouldn't be - /var/lib/lxc/container_name would be a directory for each container | 08:39 |
*** winggundamth has quit IRC | 08:39 | |
kristian__ | yeah but /var/lib/lxc is LXD cli client | 08:39 |
kristian__ | and /var/lib/lxcfs is a dir with cgroup and proc dirs in it | 08:40 |
andymccr | kristian__: that would be /usr/lib/lxc | 08:40 |
kristian__ | so I need to remove /var/lib/lxc executable and create a symlink /home/lxc -> /var/lib/lxc | 08:41 |
kristian__ | right? | 08:41 |
andymccr | the binary is /usr/lib/lxc (e.g. do a which lxc and it'll show you) it could be diff on your install i guess, but it would usually be /var/lib/lxc and when you have containers running there will be directories in /var/lib/lxc/mycontainer1 or w/e the name of the container is | 08:41 |
andymccr | if its actually an exectuable then you dont want to do that, but it should justbe a directory | 08:41 |
kristian__ | so remove the exec and symlink the dir from another partition, right? | 08:42 |
*** winggundamth has joined #openstack-ansible | 08:42 | |
andymccr | yeah - i mean i dont think anybody has tried this, its usually easier to have access to the hardware/partitioning ;) but if you need to get it done that way, that may be the only way. | 08:43 |
kristian__ | its ovh | 08:43 |
kristian__ | also I have a LOT of k8s pods running, but most of the system is free | 08:43 |
kristian__ | and it has a soft partitioning raid 0 on 2tb hdd | 08:43 |
odyssey4me | kristian__ this is something you should have planned better using a test environment, even if that was a test environment on your laptop/desktop using vagrant... trying to sort this out after the fact is going to be very, very messy | 08:44 |
odyssey4me | crossing partitions is going to involve quite a few issues with permissions | 08:44 |
odyssey4me | but yeah, it all depends on how you've deployed too | 08:45 |
kristian__ | this will be only deployed for 3-4 months, then I will move to a better solution with vrack on ovh | 08:45 |
odyssey4me | if you've used lvm for the containers, or you've used the file system backend | 08:45 |
kristian__ | also I like ovh, because they give you ips for free, all you need to pay is for the setup fee | 08:45 |
kristian__ | me only docker | 08:45 |
odyssey4me | there will be all sorts of things dotted all over the place, but most stuff is in /openstack and some in /var/lib/lxc as andymccr said | 08:45 |
odyssey4me | as the paths are not something you can edit, you'll likely have to figure out how to fudge it | 08:46 |
kristian__ | ok, if they will be the biggest dirs then I can live with it | 08:46 |
kristian__ | also I will move to rhel and maybe packstack in the future | 08:47 |
kristian__ | but for now, this should be goos | 08:47 |
kristian__ | *good | 08:47 |
kristian__ | gonna run the deployment, or should I rerun the bootstrap-aio script? | 08:49 |
kristian__ | just run-playbooks is enough I think | 08:49 |
odyssey4me | uh, you should not be using the AIO bootstrap at all | 08:52 |
odyssey4me | or run-playbooks | 08:52 |
odyssey4me | those are both for *development* environments | 08:52 |
odyssey4me | if you're wanting to do an AIO for production purposes, then you should craft your own configuration | 08:53 |
odyssey4me | the AIO has loads of security holes | 08:53 |
odyssey4me | the development AIO I mean | 08:53 |
kristian__ | its just for now, later I will deploy normal prod version. we are developing an app to run on and with openstack | 08:56 |
kristian__ | also got an error | 08:56 |
kristian__ | "/var/lib/lxc already exists as a link" | 08:57 |
kristian__ | odyssey4me: how can I fix it? | 08:59 |
odyssey4me | kristian__ you're on your own | 08:59 |
andymccr | kristian__: apparently you can set the lxc path in /etc/lxc/lxc.conf - check "man lxc.system.conf" that may be a better approach | 08:59 |
odyssey4me | I cannot afford the time to replicate your situation and help you solve it | 08:59 |
kristian__ | gonna check ir | 09:00 |
kristian__ | *it | 09:00 |
kristian__ | "/etc/lxc/" is empty | 09:02 |
kristian__ | gonna try it out again. did a mount --bind | 09:08 |
*** admin0 has joined #openstack-ansible | 09:12 | |
*** electrofelix has joined #openstack-ansible | 09:15 | |
*** winggundamth has quit IRC | 09:16 | |
admin0 | morning osa \o | 09:18 |
*** thorst has joined #openstack-ansible | 09:32 | |
*** thorst has quit IRC | 09:37 | |
*** markvoelker has joined #openstack-ansible | 09:48 | |
Martin___ | Hi all. I am deploying openstack on a cluster with heterogeneous architectures. The control node is x86, the compute nodes are supposed to be arm. When installing the nova services to the compute nodes, I get the following error: "HTTP Error 404: Not Found" for "http://172.29.236.1:8181/os-releases/14.2.6/ubuntu-16.04-armv7l/get-pip.py" | 09:52 |
Martin___ | When I take a look at the repo_container, there is no path for armv7, only for x86_64. There is a spec for multiple architectures: https://specs.openstack.org/openstack/openstack-ansible-specs/specs/newton/multi-arch-support.html | 09:52 |
Martin___ | Is that feature already available in Newton? Do I have to apply some variables somewhere to enable that feature? Or should I set up a second repo node for arm? | 09:52 |
*** acormier has joined #openstack-ansible | 09:56 | |
*** dixiaoli has quit IRC | 10:00 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_designate master: tests: Convert bind configuration file to template https://review.openstack.org/482490 | 10:01 |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_designate master: Add support for the openSUSE Leap distributions https://review.openstack.org/482491 | 10:01 |
*** acormier has quit IRC | 10:02 | |
*** kristia__ has joined #openstack-ansible | 10:05 | |
*** kristian__ has quit IRC | 10:09 | |
openstackgerrit | Merged openstack/openstack-ansible stable/ocata: Implement rolling upgrades for nova https://review.openstack.org/481924 | 10:10 |
openstackgerrit | Andy McCrae proposed openstack/openstack-ansible-os_nova master: [WIP] Move to use UWsgi for Nova https://review.openstack.org/451425 | 10:12 |
*** woodard has joined #openstack-ansible | 10:15 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_ceilometer master: Add support for the openSUSE Leap distributions https://review.openstack.org/482312 | 10:20 |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_ceilometer master: tests: Provide mongodb configuration template https://review.openstack.org/482311 | 10:20 |
*** woodard has quit IRC | 10:20 | |
*** markvoelker has quit IRC | 10:22 | |
evrardjp | sorry to push my agenda here, but can I get some votes on https://review.openstack.org/#/c/482208/ ? | 10:24 |
*** yolanda has quit IRC | 10:32 | |
*** gouthamr has quit IRC | 10:33 | |
*** yolanda has joined #openstack-ansible | 10:33 | |
*** yolanda_ has joined #openstack-ansible | 10:33 | |
*** yolanda_ has quit IRC | 10:33 | |
*** stuartgr has joined #openstack-ansible | 10:40 | |
*** gouthamr has joined #openstack-ansible | 10:40 | |
*** schwicht has joined #openstack-ansible | 10:41 | |
mbuil | guys, I think the tacker role is ready to be reviewed. As far as I see, I must create a new project in openstack called openstack-ansible-os_tacker, can anybody explained me what exactly I need to do to create a new project? | 10:45 |
evrardjp | mbuil: andymccr can work that out with you | 10:46 |
evrardjp | we'll ask infra to use your repo as basis for the project | 10:46 |
andymccr | mbuil: let me put the patch in now. gimme 2 secs - do you have a base repo you want to be imported? (that' be the repo that gets used as the tacker role to start with) | 10:47 |
evrardjp | if there is a base repo, we should probably review it too | 10:47 |
andymccr | we could create a blank one and review the initial pr | 10:47 |
*** schwicht has quit IRC | 10:48 | |
mbuil | andymccr: let's do it in a couple of hours because I am waiting for my pull request to be accepted. This is the repo: https://github.com/jrametta/openstack-ansible-os_tacker. I tried it using aio flavor and mini flavor and it works :) | 10:49 |
mbuil | you can start reviewing it (note that my pull request is pending) | 10:49 |
*** thorst has joined #openstack-ansible | 10:50 | |
andymccr | mbuil: ok sure - i'll prep that. we'll need jrametta to agree to that as well i think. | 10:50 |
mbuil | andymccr: ok. I contacted him a week ago and he was ok but maybe he should officially give the ok. How can we do that? | 10:51 |
andymccr | as long as hes aware and happy its all good :) | 10:51 |
andymccr | basically the process is: I'll create a PR to the governance and project-config repos, a repo then gets created as a clone of that repo and then it works like all the other osa repos. | 10:52 |
andymccr | it'll need some base tests which may fail at first and will probably have to be the first pr | 10:52 |
andymccr | (to fix hthe tests) | 10:52 |
mbuil | andymccr: This is literally what he said to me "If they are still relevant I would be happy to have them upstreamed so they can be worked on by more people." | 10:52 |
andymccr | nice! | 10:52 |
andymccr | i mean usually people are in favour, because nobody wants to maintain a role themselves :) | 10:53 |
mbuil | andymccr: ok. And in parallel I commit a patch to the OSA repo to add the tacker-installer,etc. right? | 10:54 |
andymccr | mbuil: so once the repo request merges and the repo is created as openstack/openstack-ansible-os_tacker you can put PRs in, but the first PR will probably need to be fixing the tests which may fail (linters/some form of func test etc - at first func test can just be a no-op) | 10:55 |
andymccr | oh you mean teh openstack-ansible repo | 10:55 |
andymccr | with an os-tacker-install.yml playbook? | 10:55 |
mbuil | andymccr: yes | 10:55 |
andymccr | ahh ok sorry i misunderstood! yeah we can get that added once the role is up and ready to go | 10:55 |
mbuil | andymccr: ok. Then I'll ping you when my PR is accepted | 10:56 |
andymccr | mbuil: excellent - thanks for working on that! | 10:56 |
mbuil | andymccr: you are welcome. Actually thanks for the help! This community is incredibly helpful :) | 10:57 |
*** gkadam has joined #openstack-ansible | 11:00 | |
*** kristian__ has joined #openstack-ansible | 11:11 | |
*** kristia__ has quit IRC | 11:15 | |
*** markvoelker has joined #openstack-ansible | 11:20 | |
*** smatzek has joined #openstack-ansible | 11:23 | |
*** smatzek has quit IRC | 11:24 | |
*** smatzek has joined #openstack-ansible | 11:24 | |
*** gkadam has quit IRC | 11:24 | |
*** admin0 has quit IRC | 11:32 | |
openstackgerrit | Merged openstack/openstack-ansible stable/newton: Implement rolling upgrades for nova https://review.openstack.org/481925 | 11:34 |
*** lkoranda has quit IRC | 11:34 | |
*** admin0 has joined #openstack-ansible | 11:36 | |
*** acormier has joined #openstack-ansible | 11:42 | |
*** acormier has quit IRC | 11:42 | |
*** acormier has joined #openstack-ansible | 11:43 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_designate master: tests: Convert bind configuration file to template https://review.openstack.org/482490 | 11:43 |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_designate master: Add support for the openSUSE Leap distributions https://review.openstack.org/482491 | 11:43 |
kristian__ | andymccr: how can I remove openstack-ansible without reinstalling the system? | 11:50 |
neith | kristian__: removing lxc container with the adhoc role is the max you can do | 11:51 |
kristian__ | what about networks? | 11:51 |
kristian__ | aio install on ubuntu 16.06 | 11:51 |
kristian__ | 16.04 | 11:51 |
neith | kristian__: Which net? | 11:51 |
kristian__ | br-mgmt, br-vxlan,... | 11:52 |
kristian__ | because I have k8s cluster running | 11:52 |
kristian__ | and I need it up along with openstack | 11:52 |
kristian__ | also I have multiple ext ips, so no problem | 11:53 |
*** markvoelker has quit IRC | 11:53 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_neutron master: Add support for the openSUSE Leap distributions https://review.openstack.org/482529 | 11:56 |
*** acormier has quit IRC | 11:59 | |
*** acormier has joined #openstack-ansible | 11:59 | |
*** acormier has quit IRC | 12:04 | |
*** gkadam has joined #openstack-ansible | 12:05 | |
*** schwicht has joined #openstack-ansible | 12:10 | |
mhayden | morning | 12:15 |
*** mbuil has quit IRC | 12:16 | |
*** markvoelker has joined #openstack-ansible | 12:19 | |
neith | kristian__: If you have a sensible deployment you should take care of it yourself | 12:28 |
anetos | AIO is not meant for such deployment kristian__ | 12:29 |
*** mbuil has joined #openstack-ansible | 12:32 | |
*** kylek3h has joined #openstack-ansible | 12:38 | |
*** woodard has joined #openstack-ansible | 12:44 | |
*** yifei has quit IRC | 12:46 | |
*** woodard has quit IRC | 12:46 | |
*** woodard has joined #openstack-ansible | 12:47 | |
*** openstackgerrit has quit IRC | 12:47 | |
*** gkadam_ has joined #openstack-ansible | 12:51 | |
*** gkadam has quit IRC | 12:54 | |
*** udesale has quit IRC | 12:58 | |
*** udesale__ has joined #openstack-ansible | 12:58 | |
*** galstrom_zzz is now known as galstrom | 12:59 | |
*** charcol has quit IRC | 12:59 | |
*** charcol has joined #openstack-ansible | 12:59 | |
*** esberglu has joined #openstack-ansible | 13:00 | |
*** openstackgerrit has joined #openstack-ansible | 13:01 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_heat master: Add support for the openSUSE Leap distributions https://review.openstack.org/482551 | 13:01 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-ops master: Do not delete containers named rpc.* https://review.openstack.org/482208 | 13:02 |
*** chhavi has joined #openstack-ansible | 13:03 | |
*** gkadam__ has joined #openstack-ansible | 13:04 | |
odyssey4me | os_neutron's calico job is now voting logan- andymccr https://review.openstack.org/#/c/481568/ :) | 13:04 |
odyssey4me | also, the ceph job on the integrated build is now voting too | 13:05 |
*** cNilesh has joined #openstack-ansible | 13:05 | |
*** gkadam_ has quit IRC | 13:06 | |
*** hmedhioub has quit IRC | 13:07 | |
*** cNilesh|bf has quit IRC | 13:07 | |
logan- | awesome | 13:08 |
hwoarang | hmm os_neutron centos7 gate job is failing http://logs.openstack.org/29/482529/1/check/gate-openstack-ansible-os_neutron-ansible-func-centos-7/42321e6/ anyone aware of it? :/ | 13:10 |
*** gkadam__ has quit IRC | 13:11 | |
*** cNilesh has quit IRC | 13:12 | |
*** cathrich_ has joined #openstack-ansible | 13:13 | |
logan- | interesting it looks like the neutron service setup task file never ran there | 13:13 |
*** nollide has joined #openstack-ansible | 13:15 | |
*** nollide has left #openstack-ansible | 13:16 | |
*** cathrichardson has quit IRC | 13:16 | |
logan- | hwoarang: http://logs.openstack.org/29/482529/1/check/gate-openstack-ansible-os_neutron-ansible-func-centos-7/42321e6/console.html#_2017-07-11_12_23_42_850157 | 13:17 |
logan- | that's why | 13:17 |
logan- | the server containers both failed out earlier in the play | 13:17 |
logan- | some dns issue there i guess | 13:17 |
hwoarang | logan-: ah right thanks. i didn't even try to debug it just wanted to check if it's known before i spend time on it! but it looks like it's a temporary issue | 13:18 |
hwoarang | i wonder why ansible didn't stop on that task that failed | 13:19 |
*** lostRhino has joined #openstack-ansible | 13:19 | |
hwoarang | hmm i guess it continued with the hosts that managed to install the packages ... | 13:19 |
logan- | because there were other hosts in the play that had not failed yet. it'll continue to work the playbook until max_fail_percentage (default 100%) is reached | 13:19 |
LiterateHawk | odyssey4me, I now see that setup-hosts is failing further up. It appears lxc-veth-wiring.sh is unhappy with OVS: "can't add 93d4ffa0_eth1 to bridge br-mgmt: Operation not supported" | 13:20 |
hwoarang | logan-: yeah makes sense | 13:21 |
LiterateHawk | Need to sort that one out | 13:21 |
*** DimGR has joined #openstack-ansible | 13:22 | |
Martin___ | Just for the record, in case someone else is having the same issue in the future: I created a repo container on one of the arm hosts. For container creation to work one needs to redefine "lxc_architecture_mapping:\n x86_64: amd64\n ppc64le: ppc64el\n armv7l: armhf" | 13:28 |
Martin___ | However, the new repo container does only contain another copy of the x86 repos and none for arm. If anyone has an idea how to overcome that hurdle and create the arm repos, they are very welcome ;) | 13:28 |
*** _nyloc_ is now known as nyloc | 13:28 | |
lostRhino | what is the best way for me to confirm the logs are making it to the logging server (I belive the openstack_user_config.yml file has the correct setting for log_host) thanks for any help | 13:29 |
odyssey4me | this is why I want to implement https://review.openstack.org/480956 | 13:29 |
nyloc | Hi, I know that this might not be 100% openstack-ansible related but I have a problem that instances inside a tennant can't resolve the hostnames of other instances in that tennant. | 13:29 |
*** jamesdenton has quit IRC | 13:29 | |
odyssey4me | Martin___ any chance you can share that modification via a bug or a patch? | 13:30 |
nyloc | I have made an example with two instances if I use "dig instance2 @192.168.1.100" from instance1. .100 is the dhcp server I get a ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 1638 | 13:30 |
nyloc | answer | 13:30 |
*** jamesdenton has joined #openstack-ansible | 13:31 | |
*** cpuga has joined #openstack-ansible | 13:31 | |
xgerman_ | hi, | 13:31 |
*** askb has quit IRC | 13:32 | |
xgerman_ | so andymccr suggested to make the aio files templates so we can have networks definitions in trove and octavia and… how would I do that? | 13:32 |
nyloc | I have set 8.8.8.8 as the DNS in the subnet where the two instances live in so dig google.de works as it uses 8.8.8.8 | 13:32 |
nyloc | But I would like to be able to resolve the hostnames too, not just internet dns queries. Any hints where to look for that? | 13:33 |
Martin___ | odyssey4me i can file a bug report, but that change would have to be applied to several of the default variables. I simply redefined that one in user_variables | 13:33 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-ops master: Do not delete containers named rpc.* https://review.openstack.org/482208 | 13:35 |
odyssey4me | Martin___ I'd like us to change it in all the places it needs to be done so that arm works out of the box :) | 13:36 |
odyssey4me | so if you can file a bug with all the changes you found necessary, we can work on that as a feature | 13:36 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-ops master: Do not delete containers named rpc.* https://review.openstack.org/482208 | 13:37 |
Martin___ | odyssey4me ok. I'm on it | 13:37 |
nyloc | I found in the docs something about adding dns to extension_drivers in the [ml2] section of the ml2 plugin config. Where would I set this via openstack ansible and is this the right place to look for enabling dns inside tennants? | 13:37 |
*** cpuga has quit IRC | 13:38 | |
*** cpuga has joined #openstack-ansible | 13:38 | |
*** klamath has joined #openstack-ansible | 13:40 | |
*** yifei has joined #openstack-ansible | 13:41 | |
*** dxiri has joined #openstack-ansible | 13:42 | |
*** weezS has joined #openstack-ansible | 13:42 | |
odyssey4me | nyloc anything you want to implement in any conf file can be done using conf overrides: https://docs.openstack.org/project-deploy-guide/openstack-ansible/ocata/app-advanced-config-override.html | 13:43 |
nyloc | odyssey4me: I found in the ansible role that if neutron_plugin_base contains dns this is added to extension_drivers, but I don't know in which file I should set this and if it is the right way to go | 13:45 |
*** dxiri has quit IRC | 13:46 | |
nyloc | odyssey4me: I would now add | 13:48 |
nyloc | neutron_plugin_base: | 13:48 |
nyloc | - dns | 13:48 |
nyloc | to /etc/openstack_deploy/user_variables.yml, but I am a bit afraid I will break something by doing so ;). | 13:48 |
LiterateHawk | Hi all - does br-mgmt have to be a regular linux bridge and not an OVS bridge? | 13:48 |
nyloc | odyssey4me: Would this overwrite the default router and metering values? Or would this extend the list? | 13:49 |
Tahvok | My galera installation fails | 13:51 |
Tahvok | ProtocolError('Connection aborted.', error(104, 'Connection reset by peer')) | 13:52 |
Tahvok | In Install pip packages step | 13:52 |
Tahvok | When I attached to the container, I could ping google just fine | 13:52 |
*** klamath has quit IRC | 13:52 | |
Tahvok | However, runnig pip install requests returns the same 104 error | 13:52 |
*** klamath has joined #openstack-ansible | 13:53 | |
*** anetos has quit IRC | 13:54 | |
*** ricardoas has quit IRC | 13:56 | |
*** vishwana_ has quit IRC | 13:56 | |
*** sachinvlk has quit IRC | 13:57 | |
*** vishwanathj has joined #openstack-ansible | 13:57 | |
*** klamath has quit IRC | 13:57 | |
*** klamath has joined #openstack-ansible | 13:58 | |
*** ricardoas has joined #openstack-ansible | 13:59 | |
asura | Hi, I'm about to run OSAD playbook for the first time. I have reviewed the documentation and I believe Appendix A (https://docs.openstack.org/project-deploy-guide/openstack-ansible/ocata/app-config-test.html) has some fields that are at least no longer in the environment layout sample file (/etc/openstack_deploy/openstack_user_config.yml). The following are the fields that I removed https://gist.github.com/michaelbarkdol | 14:01 |
odyssey4me | asura that link gives us a 404 | 14:03 |
Tahvok | odyssey4me: remove ) at end | 14:04 |
nyloc | odyssey4me: I reinstalled nova with the additional dns option and the created config looks good but local resolution still does not work. Do I have to restart the neutron service somehow or should the install script have done that? | 14:04 |
odyssey4me | Tahvok asura I meant the gist | 14:04 |
odyssey4me | nyloc I have no idea. | 14:05 |
nyloc | odyssey4me: Ok, I will try to figure out how to restart neutron ;) | 14:05 |
asura | The gist link works on my end, hmm. | 14:05 |
odyssey4me | asura so that gist may be a link to your profile, not a particular gist - can you give the link to the actual gist? | 14:06 |
asura | https://gist.github.com/37a32e361f513c3822724304acc9d0a8 Hope this one works | 14:07 |
odyssey4me | asura you removed those? why? | 14:09 |
odyssey4me | without those you have no glance, no nova, no heat, no horizon | 14:10 |
asura | We'll at one point the guide tells me to Copy the contents of the /opt/openstack-ansible/etc/openstack_deploy directory to the /etc/openstack_deploy directory. | 14:11 |
asura | Then Change to the /etc/openstack_deploy directory. Copy the openstack_user_config.yml.example file to /etc/openstack_deploy/openstack_user_config.yml. | 14:11 |
asura | The example doesn't have these fields | 14:11 |
asura | And Appendix A has some missing required fields | 14:11 |
odyssey4me | ah, so we need to update the .example file | 14:11 |
odyssey4me | can you register a bug for that please | 14:12 |
asura | So, I'll leave these fields in | 14:12 |
asura | Sure, how? :) | 14:12 |
*** nollide has joined #openstack-ansible | 14:12 | |
odyssey4me | https://launchpad.net/openstack-ansible | 14:12 |
asura | Thanks | 14:12 |
*** anetos has joined #openstack-ansible | 14:19 | |
*** acormier has joined #openstack-ansible | 14:20 | |
*** jwitko has joined #openstack-ansible | 14:26 | |
Tahvok | I found the reason for pip failing | 14:26 |
Tahvok | The repo for pip is not working.. | 14:27 |
Tahvok | Seems that the repo container has some problem... | 14:27 |
Tahvok | I'm checking it now, but would like to have some tips as well | 14:27 |
odyssey4me | that would usually be some sort of networking issue | 14:27 |
odyssey4me | alternatively, something wrong with the haproxy config | 14:27 |
odyssey4me | so check if the container can communicate with the world | 14:28 |
odyssey4me | if so, validate whether haproxy is running and listening on the right things | 14:28 |
*** schwicht has quit IRC | 14:28 | |
Tahvok | odyssey4me: I've configured vip instead of haproxy | 14:28 |
Tahvok | But that's some tip.. Gonna check if it's up | 14:29 |
*** marst has joined #openstack-ansible | 14:31 | |
*** dxiri has joined #openstack-ansible | 14:32 | |
openstackgerrit | Merged openstack/openstack-ansible-ops master: Do not delete containers named rpc.* https://review.openstack.org/482208 | 14:35 |
Tahvok | Nop, vip is up | 14:37 |
odyssey4me | Tahvok you only have a VIP? Then what is going to do the reverse proxy of the services to the containers? | 14:38 |
odyssey4me | if you don't want haproxy, you'll have to direct the traffic somehow | 14:38 |
Tahvok | virt on f5 | 14:39 |
odyssey4me | ah ok, that's fine - an external LB is good | 14:39 |
Tahvok | All traffic is going to from this vip to the controller | 14:39 |
Tahvok | What services should I check on the repo container? | 14:39 |
odyssey4me | do you have the correct IP's configured for external_lb_address and internal_lb_address? | 14:39 |
Tahvok | odyssey4me: yes | 14:39 |
Tahvok | Also, the pip repo received the correct ip | 14:40 |
odyssey4me | ok, so is the f5 seeing that the container is up? | 14:40 |
odyssey4me | can you curl the repo container address:port to validate that it's up? can you curl the vip address:port to validate that the lb is working? | 14:40 |
*** firebat has joined #openstack-ansible | 14:42 | |
firebat | Hey guys QQ. When running the os_ciner_install.yml part of setting up openstack I'm running into an issue. When the playbook attempts to ensure the cinder service exists in keystone it can't connect because it's using http instead of https. Is that setting retrieved from the openstack_deploy/user_variables.yml file? | 14:43 |
*** cuongnv has joined #openstack-ansible | 14:44 | |
Tahvok | odyssey4me: mgmt and lxc bridges work | 14:44 |
Tahvok | However vip doesn't | 14:44 |
Tahvok | But vip is forwarding fine to the controller. I checked with tcpdumpg | 14:44 |
*** cuongnv has left #openstack-ansible | 14:44 | |
odyssey4me | what do you mean by 'controller' ? the host or the repo container? | 14:45 |
Tahvok | odyssey4me: the host | 14:45 |
odyssey4me | heh, that's not going to work | 14:45 |
Tahvok | I tried the ip of the host, and got: Connection refused | 14:45 |
odyssey4me | the LB has to forward the right ports to the right containers | 14:46 |
Tahvok | odyssey4me: yes, that's what I thought, doesn't it what ansible is configuring? | 14:46 |
odyssey4me | can you rephrase the question? | 14:46 |
Tahvok | do I need to configure the lb myself to each container? | 14:46 |
odyssey4me | OSA does not have f5 configuration playbooks, so you have to configure the f5 yourself. | 14:46 |
odyssey4me | yep | 14:47 |
Tahvok | That's not written anywhere | 14:47 |
odyssey4me | how do you expect it to be fconfigured for you? | 14:47 |
Tahvok | I thought you need to forward lb to the host, and the host will transfer the appropriate ports by itself to the right containers | 14:47 |
odyssey4me | nope | 14:47 |
Tahvok | But I understand that's not the way? | 14:48 |
*** openstackgerrit has quit IRC | 14:48 | |
odyssey4me | you'd have to use haproxy as an intermediary if you'd like that to happen | 14:48 |
LiterateHawk | The LB forwards to haproxy who then sends it to the appropriate ports | 14:48 |
odyssey4me | you don't have to use haproxy, but you can | 14:48 |
odyssey4me | we (rackspace) have a script to compile the f5 config | 14:49 |
odyssey4me | https://github.com/rcbops/rpc-openstack/blob/master/scripts/f5-config.py | 14:49 |
jamesdenton | As it stands now, the F5 has to have an interface in the container network (L2 adjacency to the containers) | 14:49 |
Tahvok | odyssey4me: so I need to specifically configure each port to specific container? | 14:51 |
Tahvok | Is there a list of this ports (by container)? | 14:51 |
odyssey4me | Tahvok yep | 14:51 |
odyssey4me | not in documentation - but in your inventory | 14:51 |
admin0 | hi all .. can cluster-metrics be installed in another system that is not the deploy host itself .. if yes, what are the minmum files that needs to be copied over from deploy ? | 14:51 |
odyssey4me | that script I linked grabs it all from the inventory and prepares an f5 config | 14:51 |
admin0 | just the inventory ? | 14:52 |
Tahvok | odyssey4me: is there any arguments for running this script? | 14:52 |
Tahvok | admin0: the inventory has all the ips your containers will get | 14:52 |
Tahvok | So it should be enough | 14:53 |
odyssey4me | Tahvok I have no idea - never used it personally. jamesdenton may be able to help... otherwise try it with -h | 14:53 |
jamesdenton | There are some flags. Hang tight | 14:53 |
admin0 | it needs the deploy host ssh keys also right ? | 14:53 |
odyssey4me | Tahvok it would be rather nice to have some playbooks for f5 config, but that would take someone who wants that to develop and contribute them. :) | 14:53 |
odyssey4me | if I had one lying about I'd probably do it myself. :p | 14:54 |
jamesdenton | Tahvok - f5-config.py -f <inventory file> -s <snat address> --ssl-public-ip <external lb vip> --ssl-domain-name <external lb vip fqdn> --sec-host-network "<host_net:mask>" --sec-container-net "<container_net:mask>" --sec-public-vlan-name <external vlan name on F5> | 14:56 |
jamesdenton | Tahvok - You can also run the haproxy playbook and reverse engineer haproxy.cfg to build your own F5 config | 14:57 |
*** cathrich_ is now known as cathrichardson | 15:00 | |
Tahvok | Thanks a lot guys! Will look into it, and try running | 15:02 |
jamesdenton | sure thing | 15:02 |
*** phalmos has joined #openstack-ansible | 15:05 | |
*** jamesdenton has quit IRC | 15:05 | |
*** nollide has quit IRC | 15:08 | |
*** jamesdenton has joined #openstack-ansible | 15:08 | |
*** jamesdenton has quit IRC | 15:08 | |
*** anetos has quit IRC | 15:09 | |
*** jamesdenton has joined #openstack-ansible | 15:09 | |
*** nollide has joined #openstack-ansible | 15:11 | |
*** perniciouscaffei has joined #openstack-ansible | 15:11 | |
*** chyka has joined #openstack-ansible | 15:16 | |
*** chyka has quit IRC | 15:16 | |
*** chyka has joined #openstack-ansible | 15:17 | |
*** yifei has quit IRC | 15:18 | |
admin0 | when openstack-ansible-ops is done , at what port will I get the metrics ? | 15:19 |
admin0 | and if i am using haproxy and a DNS address, is that what it says when it talks about proxying ? | 15:20 |
*** anetos has joined #openstack-ansible | 15:21 | |
admin0 | ok .. that part is figured out | 15:22 |
*** nollide has left #openstack-ansible | 15:24 | |
admin0 | can someone help me in cluster-metrics error i am getting in the final playbook run.. https://pastebin.com/rbcramFD . openstack-ansible playbook-grafana.yml | 15:27 |
admin0 | finished OK .. the last one openstack-ansible playbook-kapacitor.yml fails on TASK [Execute tickscripts] | 15:27 |
admin0 | what is supposed to listen on 9032 ? | 15:28 |
*** Martin___ has quit IRC | 15:29 | |
asura | 9092* | 15:29 |
admin0 | yes :) | 15:30 |
admin0 | sorry | 15:30 |
*** Oku_OS is now known as Oku_OS-away | 15:30 | |
admin0 | whats supposed to be listening there | 15:30 |
admin0 | i only see grafana listeing on 8089 | 15:30 |
admin0 | and ssh | 15:30 |
admin0 | whats the admin login :) | 15:31 |
admin0 | there is no cluser or granana in user_secrets | 15:33 |
admin0 | grafana* | 15:33 |
firebat | Hey guys when cinder tries to ensure that it is registered under keystone it is using http instead of https... I can't seem to figure out what config that is | 15:34 |
admin0 | figured it out :) | 15:35 |
asura | how? | 15:35 |
*** tobberydberg has joined #openstack-ansible | 15:35 | |
admin0 | in the grafana config :) | 15:35 |
*** nollide has joined #openstack-ansible | 15:36 | |
odyssey4me | firebat that comes from your keystone service catalog | 15:36 |
*** anetos has quit IRC | 15:37 | |
admin0 | so next is to figure out influx stuff before the provided dashboards can be used | 15:38 |
*** tobberyd_ has quit IRC | 15:38 | |
*** anetos has joined #openstack-ansible | 15:39 | |
*** lostRhino has quit IRC | 15:39 | |
*** tobberydberg has quit IRC | 15:39 | |
*** lostRhino has joined #openstack-ansible | 15:40 | |
*** udesale__ has quit IRC | 15:40 | |
asura | Is /etc/openstack_deploy/openstack_user_config.yml defining 1000 vxlan's? https://pastebin.com/r63kWAJf Is this enough for production, e.g., can I increase the range? | 15:43 |
*** openstackgerrit has joined #openstack-ansible | 15:48 | |
openstackgerrit | Miguel Alex Cantu (alextricity25) proposed openstack/openstack-ansible-ops master: Improve openstack-release file discovery https://review.openstack.org/482608 | 15:48 |
*** lostRhino has left #openstack-ansible | 15:48 | |
*** mhayden has quit IRC | 15:48 | |
*** mhayden has joined #openstack-ansible | 15:48 | |
admin0 | i got the dashboard and the data source in grafana working .. but the metrics are none | 15:50 |
admin0 | figuring it out even more | 15:50 |
anetos | hello , when creating a gateway net i get this error Flat provider networks are disabled. , i had this error in the past but i cant remember how i had it solved. anyone care to help ? | 15:52 |
*** weezS has quit IRC | 15:52 | |
*** tobberydberg has joined #openstack-ansible | 15:56 | |
Tahvok | exit | 15:56 |
*** vnogin has quit IRC | 15:56 | |
*** admin0 has quit IRC | 15:56 | |
*** admin0 has joined #openstack-ansible | 15:56 | |
evrardjp | Tahvok: You're out of your shell now. | 15:59 |
*** tobberydberg has quit IRC | 16:00 | |
evrardjp | Bug triage cloudnull, mattt, andymccr, d34dh0r53, hughsaunders, b3rnard0, palendae, Sam-I-Am, odyssey4me, serverascode, rromans, erikmwilson, mancdaz, _shaps_, BjoernT, claco, echiu, dstanek, jwagner, ayoung, prometheanfire, evrardjp, arbrandes, mhayden, scarlisle, luckyinva, ntt, javeriak, automagically, | 16:00 |
evrardjp | spotz, vdo, jmccrory, alextricity25, jasondotstar, KLevenstein, admin0, michaelgugino, ametts, v1k0d3n, severion, bgmccollum, darrenc, JRobinson__, asettle, colinmcnamara, thorst, adreznec, eil397, qwang, nishpatwa_, cathrichardson, drifterza, sc68cal, rackertom | 16:00 |
evrardjp | Here is our bug list for today https://etherpad.openstack.org/p/osa-bugtriage | 16:00 |
evrardjp | #startmeeting openstack_ansible_meeting | 16:00 |
openstack | Meeting started Tue Jul 11 16:00:48 2017 UTC and is due to finish in 60 minutes. The chair is evrardjp. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
openstack | The meeting name has been set to 'openstack_ansible_meeting' | 16:00 |
andymccr | so pumped! lets do this thing. | 16:00 |
evrardjp | Yeah, it's not like our days are not full already, right? right? | 16:01 |
evrardjp | we have 42 bugs today. | 16:01 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1702962 Misconfigured health check for Barbican with haproxy | 16:01 |
openstack | Launchpad bug 1702962 in openstack-ansible "Misconfigured health check for Barbican with haproxy" [Undecided,New] | 16:01 |
spotz | I blame odyssey4me cause I haven't seen him yet today | 16:02 |
*** pvradu has quit IRC | 16:03 | |
andymccr | hmm | 16:03 |
andymccr | that should be easy enough to fix | 16:03 |
andymccr | id say its high if confirmed | 16:03 |
evrardjp | well that sounds bad | 16:04 |
evrardjp | jmccrory: did you deploy barbican at some point? Did you deploy it with haproxy? | 16:04 |
evrardjp | Or I remember wrong? | 16:04 |
andymccr | we should get a scenario with it in at some point - tbh i thought we had one already :) | 16:05 |
evrardjp | I don't see HEAD in the docs | 16:06 |
evrardjp | it looks probably valid | 16:06 |
evrardjp | confirmed high ? | 16:06 |
andymccr | yeah id say confirmed high | 16:06 |
evrardjp | or we wait for more confirmations? | 16:06 |
andymccr | we have had that with some other services recently, so i am guessing there is a change thats happened | 16:07 |
evrardjp | Yeah I remember seeing something on that topic | 16:07 |
evrardjp | ok let's move on | 16:08 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1702553 | 16:08 |
openstack | Launchpad bug 1702553 in openstack-ansible "ansible-hardening : V-38660 - The snmpd service must only use SNMPv3 or newer Bad Grep" [Undecided,New] | 16:08 |
andymccr | damnit mhayden | 16:09 |
andymccr | how could you | 16:09 |
mhayden | oopsies | 16:09 |
andymccr | :D | 16:09 |
mhayden | i grabbed that one | 16:09 |
evrardjp | low hanging fruit confirmed ? | 16:09 |
evrardjp | what does that mean, you already fixed it? | 16:09 |
mhayden | yeah | 16:09 |
evrardjp | Because you had other ^# issues | 16:09 |
evrardjp | ok | 16:10 |
mhayden | well, grep never seems easy, but you know what i mean | 16:10 |
mhayden | there are a shedload of bug fixes in ansible-hardening that need reviews | 16:10 |
* mhayden plugs | 16:10 | |
* mhayden waits for evrardjp to hit me with the bat | 16:10 | |
odyssey4me | mhayden you write such buggy software, sheesh | 16:10 |
mhayden | indeed | 16:10 |
evrardjp | no, I'm just letting a message for the bug reporter | 16:11 |
evrardjp | we are good to go I think. | 16:11 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1702526 | 16:11 |
openstack | Launchpad bug 1702526 in openstack-ansible "Setting security_pwquality_apply_rules: yes breaks passwd command" [Undecided,New] | 16:11 |
mhayden | https://review.openstack.org/#/q/project:openstack/ansible-hardening+status:open :) | 16:11 |
evrardjp | mhayden: ! | 16:11 |
andymccr | haha mhayden tbh its kinda nice the amount of bug reports you get - shows ppl are using it. | 16:11 |
mhayden | i missed this one | 16:11 |
evrardjp | andymccr: Who is using openstack-ansible anyway | 16:11 |
evrardjp | :p | 16:11 |
andymccr | how do we spin ansible-security-hardening into its own project so we can get rid of these bugs on our list? :P | 16:11 |
mhayden | evrardjp: confirmed, low, assign to me! :) | 16:11 |
evrardjp | I like how this goes mhayden | 16:12 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1702123 | 16:12 |
openstack | Launchpad bug 1702123 in openstack-ansible "SELinux error: keepalived reading haproxy pid file" [Undecided,New] - Assigned to Major Hayden (rackerhacker) | 16:12 |
evrardjp | darn. | 16:12 |
evrardjp | that's me | 16:12 |
evrardjp | good it merged. | 16:12 |
evrardjp | next | 16:12 |
evrardjp | oh wait | 16:13 |
evrardjp | It's not fixed for osa | 16:13 |
andymccr | huh? :P | 16:13 |
evrardjp | yes sorry | 16:13 |
mhayden | oh yeah, this was a PR in evrardjp's ansible-keepalived role | 16:13 |
evrardjp | the base code | 16:13 |
evrardjp | is merged in ansible-keepalived | 16:13 |
evrardjp | but there is something to do in OSA | 16:14 |
evrardjp | I assigned it to me | 16:14 |
evrardjp | let's go on | 16:14 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1701609 | 16:14 |
openstack | Launchpad bug 1701609 in openstack-ansible "DNS plugin is explicitly excluded from neutron config" [Undecided,New] | 16:14 |
evrardjp | It looks like this is done according to docs | 16:14 |
evrardjp | I remember this was at the source of an openstack ML thread | 16:14 |
evrardjp | anyone knows more about it? | 16:15 |
*** firebat has quit IRC | 16:16 | |
andymccr | mugsie: do you have a recommendation on that one? | 16:16 |
evrardjp | Adri2000: ArchiFleKs? | 16:16 |
mugsie | andymccr: oh, I found out what was up with that last night | 16:16 |
evrardjp | I remember that ArchiFleKs was on it | 16:16 |
andymccr | ahh sweet | 16:16 |
evrardjp | ok? | 16:16 |
mugsie | let me close it - someone did the right thing - DNS is a "special" ML2 integration | 16:16 |
evrardjp | Yeah I worked with ArchiFleKs on that | 16:17 |
andymccr | ahh ok cool. | 16:17 |
mugsie | there is a corresponding if "dns" in neutron_plugins | 16:17 |
andymccr | thanks for looking into it all the same | 16:17 |
evrardjp | so we're good? | 16:17 |
evrardjp | I will mark it as invalid then | 16:17 |
evrardjp | 3 | 16:17 |
evrardjp | 2 | 16:17 |
evrardjp | 1 | 16:17 |
evrardjp | next! | 16:17 |
andymccr | sweet :D | 16:18 |
andymccr | killing it | 16:18 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1700482 | 16:18 |
openstack | Launchpad bug 1700482 in openstack-ansible "haproxy-endpoint-manage.yml dose not exist in stable/ocata" [Undecided,New] | 16:18 |
evrardjp | this looks invalid to me | 16:18 |
evrardjp | Too bad we can't talk to the user, we could have helped him | 16:18 |
evrardjp | invalid, ok for everyone? | 16:18 |
odyssey4me | that's been fixed | 16:19 |
odyssey4me | it was valid | 16:19 |
evrardjp | oh ok | 16:19 |
evrardjp | my bad | 16:19 |
jmccrory | https://review.openstack.org/#/c/477470/ | 16:19 |
jmccrory | where odyssey4me fixed it | 16:19 |
andymccr | sweet | 16:19 |
andymccr | so its fixed pending sha bump? or the new sha is included | 16:20 |
andymccr | e.g. do we need a release asap? | 16:20 |
odyssey4me | it was never eeleased with the problem | 16:20 |
odyssey4me | this was someone chasing the head of the branch | 16:20 |
andymccr | ahh ok | 16:20 |
andymccr | thats even better then :D | 16:20 |
*** admin0 has quit IRC | 16:20 | |
evrardjp | in any case, I marked it as incomplete, waiting for user confirmation that it was solved, as I usually do. If no answer it will expire. | 16:21 |
andymccr | sounds good to me | 16:21 |
evrardjp | next! | 16:21 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1700061 | 16:21 |
openstack | Launchpad bug 1700061 in openstack-ansible "Telemetry doesn't work on deploying OpenStack using OSA Newton release" [Undecided,New] | 16:21 |
andymccr | telemetry | 16:21 |
evrardjp | so, it was working under Mitaka, but it's not working anymore | 16:22 |
evrardjp | but nobody put the time to make it work | 16:22 |
andymccr | yeah unfortunately, we havent had enough interested people maintaining those roles | 16:22 |
evrardjp | I'd say confirmed | 16:22 |
evrardjp | and we can go for low, because of the coverage of this | 16:22 |
andymccr | agered | 16:22 |
andymccr | agreed | 16:22 |
jmccrory | doesn't mention an error or what exactly isn't working | 16:22 |
andymccr | yeah that too | 16:23 |
andymccr | but im guessing its just not working in general since nobody has kept those maintained | 16:23 |
*** phalmos has quit IRC | 16:23 | |
evrardjp | let's first agree on the importance: low | 16:24 |
andymccr | yeah sure | 16:24 |
evrardjp | because of its scoping | 16:24 |
evrardjp | ok | 16:24 |
evrardjp | so | 16:24 |
evrardjp | next | 16:24 |
evrardjp | well | 16:24 |
evrardjp | I mean, do we confirm or not? | 16:25 |
andymccr | yeah | 16:25 |
andymccr | i mean i think its clear its not working | 16:25 |
andymccr | just that there doesnt seem to be much interest in fixing it up | 16:25 |
evrardjp | ok so confirmed low | 16:26 |
andymccr | gets my vote | 16:26 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1700051 | 16:27 |
openstack | Launchpad bug 1700051 in openstack-ansible "lsyncd don't work in centos7" [Undecided,New] | 16:27 |
evrardjp | that sounds bad | 16:27 |
evrardjp | mgariepy: mhayden? | 16:27 |
evrardjp | Did you see that? | 16:27 |
andymccr | that does sound bad | 16:27 |
andymccr | well | 16:29 |
evrardjp | confirmed high? | 16:29 |
andymccr | im spinning up a centos aio right now so maybe i can double check that | 16:29 |
andymccr | yeah | 16:30 |
andymccr | assign it to me i think | 16:30 |
evrardjp | don't forget the affinity :p | 16:30 |
evrardjp | even if not confirmed | 16:30 |
evrardjp | we can change the status | 16:30 |
andymccr | agreed | 16:30 |
andymccr | i'll probably just finish setting this up and add more hosts afterwards ;D | 16:31 |
evrardjp | haha true | 16:31 |
evrardjp | so | 16:31 |
evrardjp | next | 16:31 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1699875 | 16:31 |
openstack | Launchpad bug 1699875 in openstack-ansible "rsyslog client postrotate script contains invalid command" [Undecided,New] | 16:31 |
andymccr | hmm | 16:32 |
andymccr | ok we should fix that one | 16:33 |
evrardjp | I don't see what's rong | 16:33 |
evrardjp | oh ok | 16:33 |
evrardjp | yeah | 16:33 |
evrardjp | fair enough | 16:33 |
*** weezS has joined #openstack-ansible | 16:33 | |
*** kristia__ has joined #openstack-ansible | 16:34 | |
evrardjp | we should template that per sys_mgr or something like that | 16:34 |
evrardjp | I don't really remember | 16:34 |
*** kristia__ has quit IRC | 16:34 | |
andymccr | yeah | 16:34 |
evrardjp | sounds a large annoyance | 16:34 |
evrardjp | I'd like to put that into high and low hanging fruit. | 16:34 |
evrardjp | see if it helps resolving | 16:35 |
evrardjp | 3 | 16:35 |
evrardjp | 2 | 16:35 |
evrardjp | 1 | 16:35 |
evrardjp | next | 16:35 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1699539 | 16:36 |
openstack | Launchpad bug 1699539 in openstack-ansible "Ansible prior 2.2.3 is vulnerable with CVE-2017-7466, CVE-2017-7473, CVE-2017-7481" [Undecided,New] | 16:36 |
evrardjp | interesting one IMO | 16:36 |
*** kristian__ has quit IRC | 16:36 | |
andymccr | they surely would've backporte dthose to like 2.1 branch too | 16:37 |
odyssey4me | considering how long ago we went from 2.1 to 2.2, and all the pain it took, I just don't see how we can do that | 16:37 |
andymccr | if not we need those fixes backported if the 2.1 branch is vulnerable to those cve's | 16:37 |
andymccr | we can then bump to latest version of 2.1 | 16:37 |
evrardjp | isn't 2.1 receiving updates for this? | 16:37 |
evrardjp | sorry I didn't track it | 16:38 |
andymccr | not sure - we should look into that though | 16:38 |
andymccr | odyssey4me: is right though, moving 2.1 --> 2.2 is not really a viable plan for a stable branch | 16:38 |
evrardjp | Hi all, we are happy to announce that Ansible 2.3.1 and 2.1.6 final have been released. | 16:39 |
evrardjp | The 2.3.1 release fixes several bugs, and both releases include a fix for CVE-2017-7481 (SEVERITY: Moderate). | 16:39 |
evrardjp | Extract from ansible project group, from jimi-c | 16:39 |
evrardjp | I guess we can assume that if we bump 2.1.6 it's good enough for security. | 16:40 |
evrardjp | so what are we running? | 16:40 |
logan- | https://github.com/openstack/openstack-ansible/blob/stable/newton/scripts/bootstrap-ansible.sh#L25 | 16:40 |
logan- | 2.1.6.0 | 16:40 |
logan- | https://github.com/openstack/openstack-ansible/commit/8e0582b686b7aca97c6d34d512a3fcbeb1a63452 | 16:41 |
evrardjp | cool thanks logan- | 16:41 |
logan- | thanks odyssey4me :P | 16:41 |
andymccr | yeah was looking for that :P thanks | 16:42 |
evrardjp | so what's the triage? | 16:42 |
andymccr | well if we have resolved the cve's | 16:42 |
odyssey4me | haha :) | 16:42 |
evrardjp | thanks odyssey4me indeed | 16:42 |
andymccr | then its resolved already | 16:42 |
*** toddnni has quit IRC | 16:43 | |
evrardjp | let's continue | 16:44 |
evrardjp | sorry if I'm a little slow today :p | 16:44 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1699191 | 16:44 |
openstack | Launchpad bug 1699191 in openstack-ansible "Keystone role fails if backend admin or internal uri protocol differs from frontend" [Undecided,New] | 16:44 |
*** mbuil has quit IRC | 16:45 | |
odyssey4me | ah, good bug | 16:46 |
odyssey4me | we'll have to work around it | 16:46 |
evrardjp | I don't think bugs can be considered good, but I still agree with you odyssey4me :D | 16:47 |
*** cshen_ has joined #openstack-ansible | 16:47 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_gnocchi master: templates: gnocchi-httpd: Ensure proper user control in gnocchi root https://review.openstack.org/482632 | 16:48 |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-os_gnocchi master: Add support for the openSUSE Leap distributions https://review.openstack.org/482633 | 16:48 |
LiterateHawk | Hi all - does br-mgmt have to be a regular linuxbridge and not an OVS bridge? | 16:48 |
jamesdenton | LiterateHawk Yes, as far as i know | 16:48 |
*** shardy has quit IRC | 16:49 | |
evrardjp | ok let's mark it as confirmed and medium? | 16:49 |
evrardjp | let's finish this bug triage real quick | 16:49 |
LiterateHawk | jamesdenton Awesome. I got some strange errors trying to attach container veths to the bridge and figured | 16:49 |
evrardjp | could you discuss this guys at the end of the bug triage please? | 16:50 |
evrardjp | ok next | 16:50 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1698871 | 16:50 |
openstack | Launchpad bug 1698871 in openstack-ansible "[master] [os_gnocchi]Gnocchi role tests failing on installing pip packages" [Undecided,New] - Assigned to Miguel Alejandro Cantu (miguel-cantu) | 16:50 |
odyssey4me | internal SSL on the keystone container is not a tested code path - we should add a scenario to test it | 16:50 |
evrardjp | agreed odyssey4me | 16:51 |
evrardjp | next bug is targetting gnocchi, what should we do again? | 16:51 |
evrardjp | let's leave it as is? | 16:51 |
andymccr | yeah i thinkso | 16:51 |
evrardjp | ok | 16:52 |
evrardjp | let's move on | 16:52 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1698831 | 16:52 |
openstack | Launchpad bug 1698831 in openstack-ansible "os_cinder volume service fails with Volume group "cinder-volumes" not found" [Medium,New] - Assigned to Jesse Pretorius (jesse-pretorius) | 16:52 |
evrardjp | odyssey4me: what's the status of this? | 16:52 |
*** schwicht has joined #openstack-ansible | 16:52 | |
evrardjp | is it over with the related fixes? | 16:52 |
andymccr | i think thats fixed now - its an lxc issue that we couldnt get around afaik | 16:53 |
evrardjp | ok | 16:53 |
evrardjp | let's mark it as fixed then | 16:53 |
evrardjp | (waiting for odyssey4me's opinion, he is currently reading it) | 16:54 |
odyssey4me | it's only worked around for now | 16:54 |
odyssey4me | I still need to go back and implement a new test for it to ensure we increase coverage | 16:54 |
evrardjp | ok, good I'll leave it as in progress then | 16:55 |
odyssey4me | I'm marking as triaged | 16:55 |
*** weezS has quit IRC | 16:55 | |
evrardjp | ok that's good enough too. | 16:55 |
evrardjp | at the end of the meeting you can add a link to remember this :p | 16:55 |
evrardjp | next | 16:55 |
*** kristian__ has joined #openstack-ansible | 16:55 | |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1697981 | 16:55 |
openstack | Launchpad bug 1697981 in openstack-ansible "Override neutron_dnsmasq_neutron_conf_overrides is broken" [Undecided,New] | 16:55 |
evrardjp | looks a problem to me | 16:56 |
evrardjp | I'd personally mark it as confirmed and medium | 16:56 |
evrardjp | it's not high but it's very painful | 16:56 |
evrardjp | I'll take it, and I hope I will eventually have time to do it. | 16:58 |
*** cshen_ has quit IRC | 16:58 | |
evrardjp | next | 16:58 |
evrardjp | #link https://bugs.launchpad.net/openstack-ansible/+bug/1697782 | 16:58 |
openstack | Launchpad bug 1697782 in openstack-ansible "Mounting of ceph-backed cinder volumes is broken after Ocata upgrade" [Undecided,New] | 16:58 |
evrardjp | it's the last one for today, on the gong | 16:58 |
*** maybebuggy has joined #openstack-ansible | 16:59 | |
evrardjp | logan-: ? | 17:00 |
logan- | reading thru | 17:00 |
evrardjp | could you have a look at that? I think that might interest you | 17:00 |
logan- | yeah for sure. assign to me and ill try to confirm it. seems like it ought to be breaking our tempest runs in ceph builds if one of the tests tries to attach a volume to a nova instance | 17:01 |
logan- | ill make an aio and try to break it | 17:01 |
evrardjp | that's cool | 17:01 |
evrardjp | thanks logan-! | 17:01 |
evrardjp | we are done for today! | 17:02 |
evrardjp | thanks everyone, as usual. | 17:02 |
evrardjp | sorry for the time it took | 17:02 |
evrardjp | #endmeeting | 17:02 |
openstack | Meeting ended Tue Jul 11 17:02:33 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 17:02 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2017/openstack_ansible_meeting.2017-07-11-16.00.html | 17:02 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2017/openstack_ansible_meeting.2017-07-11-16.00.txt | 17:02 |
openstack | Log: http://eavesdrop.openstack.org/meetings/openstack_ansible_meeting/2017/openstack_ansible_meeting.2017-07-11-16.00.log.html | 17:02 |
evrardjp | LiterateHawk: jamesdenton you may continue :) sorry for the interruption! | 17:03 |
andymccr | mhayden: do you know how the centos7 caching bits work? | 17:03 |
andymccr | or mgariepy - i mean the apt-cacher-ng integration piece | 17:04 |
LiterateHawk | evrardjp No, I'm sorry for the interruption! | 17:04 |
openstackgerrit | Merged openstack/openstack-ansible master: Optimize the link address https://review.openstack.org/481570 | 17:04 |
jamesdenton | evrardjp :) | 17:05 |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-galera_server master: tasks: galera_install_zypper: Drop zypper workaround for Ansible < 2.2 https://review.openstack.org/482638 | 17:06 |
*** kristian__ has quit IRC | 17:06 | |
*** kristian__ has joined #openstack-ansible | 17:07 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-galera_client master: tasks: galera_client_install_zypper: Drop zypper workaround for Ansible < 2.2 https://review.openstack.org/482639 | 17:07 |
*** chyka has quit IRC | 17:10 | |
*** kristian__ has quit IRC | 17:11 | |
*** kristian__ has joined #openstack-ansible | 17:11 | |
*** schwicht has quit IRC | 17:13 | |
*** chyka has joined #openstack-ansible | 17:14 | |
*** schwicht has joined #openstack-ansible | 17:14 | |
*** dxiri has quit IRC | 17:14 | |
*** dxiri has joined #openstack-ansible | 17:15 | |
openstackgerrit | Miguel Alex Cantu (alextricity25) proposed openstack/openstack-ansible master: Remove telemetry roles from role requirements https://review.openstack.org/478573 | 17:18 |
*** kristian__ has quit IRC | 17:18 | |
*** esberglu has quit IRC | 17:19 | |
*** kristian__ has joined #openstack-ansible | 17:19 | |
*** cshen_ has joined #openstack-ansible | 17:22 | |
*** kristian__ has quit IRC | 17:24 | |
*** nollide has quit IRC | 17:25 | |
*** ricardoas1 has joined #openstack-ansible | 17:26 | |
*** ricardoas has quit IRC | 17:29 | |
openstackgerrit | Markos Chandras (hwoarang) proposed openstack/openstack-ansible-tests master: test-setup-swifthosts: Optimize xfsprogs installation https://review.openstack.org/482646 | 17:31 |
*** cpuga has quit IRC | 17:39 | |
*** cpuga has joined #openstack-ansible | 17:39 | |
*** nollide has joined #openstack-ansible | 17:40 | |
*** chhavi has quit IRC | 17:43 | |
*** toddnni has joined #openstack-ansible | 17:44 | |
*** jrniemijr has joined #openstack-ansible | 17:45 | |
*** cshen_ has quit IRC | 17:46 | |
*** cshen_ has joined #openstack-ansible | 17:47 | |
*** perniciouscaffei has quit IRC | 17:48 | |
*** weezS has joined #openstack-ansible | 17:55 | |
*** stuartgr has quit IRC | 17:56 | |
*** anetos has quit IRC | 18:02 | |
*** electrofelix has quit IRC | 18:02 | |
*** esberglu has joined #openstack-ansible | 18:02 | |
*** tobberydberg has joined #openstack-ansible | 18:04 | |
*** esberglu has quit IRC | 18:04 | |
*** esberglu has joined #openstack-ansible | 18:05 | |
*** poopcat has joined #openstack-ansible | 18:07 | |
*** perniciouscaffei has joined #openstack-ansible | 18:08 | |
*** albertcard1 has joined #openstack-ansible | 18:09 | |
*** poopcat has quit IRC | 18:12 | |
asura | Is /etc/openstack_deploy/openstack_user_config.yml defining 1000 vxlan's? https://pastebin.com/r63kWAJf Is this enough for production, e.g., can I increase the range? | 18:14 |
asura | I'm just not certain does this mean that range 1 - 1000 vxlans will be available? So this would mean essentially 1000 tenant networks? | 18:16 |
*** ggillies_ has quit IRC | 18:19 | |
*** ggillies has joined #openstack-ansible | 18:21 | |
openstackgerrit | Jesse Pretorius (odyssey4me) proposed openstack/openstack-ansible-os_glance master: Correct major upgrade detection logic https://review.openstack.org/482658 | 18:28 |
*** kristian__ has joined #openstack-ansible | 18:29 | |
*** kristian__ has quit IRC | 18:34 | |
*** yusef has joined #openstack-ansible | 18:35 | |
*** albertcard1 is now known as poopcat | 18:42 | |
*** esberglu_ has joined #openstack-ansible | 18:44 | |
*** cshen_ has quit IRC | 18:46 | |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Octavia will create the network upon request itself https://review.openstack.org/482664 | 18:47 |
*** esberglu has quit IRC | 18:47 | |
*** nollide has left #openstack-ansible | 18:53 | |
*** tobberydberg has quit IRC | 19:02 | |
*** tobberydberg has joined #openstack-ansible | 19:02 | |
jamesdenton | asura Yes, the default is VNI 1 thru 1000. You can increase that at any time, but would need to rerun the os-neutron-install.yml playbook with neutron-config tag (i think) to modify the configuration across hosts and restart neutron server service | 19:04 |
*** redondo-mk has joined #openstack-ansible | 19:05 | |
jamesdenton | The answer to 'is it enough' really varies between each cloud. It has been enough for us. You're likely to hit scaling limitations with stock neutron agents long before you hit the top of that range | 19:05 |
*** tobberydberg has quit IRC | 19:06 | |
*** tobberydberg has joined #openstack-ansible | 19:06 | |
*** tobberydberg has quit IRC | 19:10 | |
*** kristian__ has joined #openstack-ansible | 19:12 | |
*** tobberydberg has joined #openstack-ansible | 19:18 | |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Octavia will create the network upon request itself https://review.openstack.org/482664 | 19:18 |
*** kristian__ has quit IRC | 19:19 | |
skape | Hi all! I was following the faq http://www.openstackfaq.com/openstack-ansible-ceph/ but I have a question in my case the ceph cluster is already installed , which machines do I set as storage hosts? | 19:19 |
*** kristian__ has joined #openstack-ansible | 19:20 | |
skape | I want the compute nodes to access directly the OSDs | 19:20 |
asura | Wouldn't you have the ceph monitor node be the storage node? | 19:22 |
skape | in the faq the ceph monitors are on other ip addresses . | 19:24 |
*** hybridpollo has joined #openstack-ansible | 19:24 | |
*** kristian__ has quit IRC | 19:24 | |
asura | Idk, with cloudstack I configured it with the monitor node IP addresses, since I think they maintain the crush map, to the storage node OSDs. I'm planning to try that guide after testing a deployment today of OSAD. Perhaps someone else has more knowledge of the guide and Ceph to OSAD though.. | 19:27 |
*** kristian__ has joined #openstack-ansible | 19:28 | |
asura | I'm at the last step of the test deployment guide with OSAD and have an fail when running, openstack-ansible setup-openstack.yml; TASK [os_keystone : Wait for services to be up]; https://pastebin.com/RAaE5P7g | 19:33 |
asura | failed: [deploy_keystone_container-ad839eb8] (item={u'url': u'http://172.29.236.150:5000', u'validate_certs': True}) => {"attempts": 12, "content": "", "failed": true, "item": {"url": "http://172.29.236.150:5000", "validate_certs": true}, "msg": "Status code was not [300]: Request failed: <urlopen error [Errno 111] Connection refused>", "redirected": false, "status": -1, "url": "http://172.29.236.150:5000"} | 19:34 |
asura | I tried logging into the container and confirmed the port wasn't open. Restarted the container and the port is then open. Tried the playbook again, it fails port closes. | 19:35 |
asura | Is there any particular logs I can look at to understand the issue further? | 19:35 |
*** dxiri has quit IRC | 19:36 | |
jamesdenton | asura Which version are you working with? | 19:36 |
*** dxiri has joined #openstack-ansible | 19:37 | |
asura | git clone -b 15.1.6 https://git.openstack.org/openstack/openstack-ansible \ /opt/openstack-ansible | 19:37 |
jamesdenton | Is it an AIO? | 19:38 |
asura | I have three nodes | 19:38 |
asura | deploy, target, storage | 19:38 |
*** pbandark has quit IRC | 19:39 | |
asura | Using VyOS to network between them with virtualbox | 19:39 |
*** tobberydberg has quit IRC | 19:44 | |
*** tobberydberg has joined #openstack-ansible | 19:44 | |
jamesdenton | Do you have your openstack_user_config.yml handy? | 19:45 |
*** cathrichardson has quit IRC | 19:46 | |
*** tobberydberg has quit IRC | 19:46 | |
asura | Yes, https://pastebin.com/PLtCS9CA | 19:46 |
*** tobberydberg has joined #openstack-ansible | 19:46 | |
*** cathrichardson has joined #openstack-ansible | 19:47 | |
*** jamesden_ has joined #openstack-ansible | 19:48 | |
*** jamesdenton has quit IRC | 19:49 | |
*** jamesden_ has quit IRC | 19:49 | |
*** jamesdenton has joined #openstack-ansible | 19:51 | |
asura | Yes, I have /etc/openstack_deploy/openstack_user_config.yml available https://pastebin.com/PLtCS9CA | 19:52 |
*** esberglu_ is now known as esberglu | 19:53 | |
redondo-mk | Hi. I'm trying to deploy OpenStack AIO in Ubuntu 16.04, tag 16.0.0.0b2 for the sake of checking out Ocata but I have some issues... | 19:53 |
redondo-mk | https://www.irccloud.com/pastebin/ebYo1cCh/ | 19:54 |
*** cshen_ has joined #openstack-ansible | 19:55 | |
jmccrory | redondo-mk ocata is the 15 tag series, 16 is pike | 19:55 |
redondo-mk | jmccrory: Yes, you are right. What I meant is for the sake of checking out Octavia. I'm having some lack of sleep that are causing me naming issues :) | 19:57 |
redondo-mk | Octavia is not present in Ocata... | 19:58 |
jamesdenton | asura There may be some information in /var/log/keystone inside that keystone container that can help identify why the process is dying. | 20:02 |
*** schwicht has quit IRC | 20:04 | |
LiterateHawk | Hi all - I'm trudging through installing OSA and hit the following error. Destroying and recreating the container doesn't help. Is there perhaps a variable I should set? https://pastebin.com/jSa1ss9g | 20:05 |
openstackgerrit | German Eichberger proposed openstack/openstack-ansible-os_octavia master: Octavia will create the network upon request itself https://review.openstack.org/482664 | 20:05 |
LiterateHawk | Executing the command manually from within the container yields the same issue | 20:05 |
*** schwicht has joined #openstack-ansible | 20:07 | |
*** marst has quit IRC | 20:08 | |
LiterateHawk | It appears the -n "" is what causes the error, but I'm not sure of where it came from | 20:11 |
jmccrory | redondo-mk which version of the systemd package do you have installed? | 20:11 |
redondo-mk | jmccrory: I have systemd 219 | 20:14 |
redondo-mk | Should putting the latest one help? | 20:15 |
asura | jamesdenton does my /var/log/keystone/ssl_access.log mean that I'm getting error 300 due to SSL failing? https://pastebin.com/Sey63Bsv also keystone.log https://pastebin.com/UQVhq4Y9 keystone-apache-error.log https://pastebin.com/PBsHgupw | 20:15 |
jmccrory | yeah, try updating that, 219 is right at the cutoff where the loopback is created automatically. the role probably needs to be more specific in checking for the right version | 20:16 |
redondo-mk | My bad again...it's 229 and not 219...the latest version is 233...I'll try with that... | 20:17 |
LiterateHawk | Hm. Do these playbooks cache information outside of the containers? That might explain why deleting and recreating it doesn't fix the problem | 20:21 |
*** askb has joined #openstack-ansible | 20:26 | |
LiterateHawk | Actually, this bug looks like it's the same thing https://bugs.launchpad.net/openstack-ansible/+bug/1671795 | 20:26 |
openstack | Launchpad bug 1671795 in openstack-ansible "setting rabbitmq_policy failes during initial deployment" [Undecided,Expired] | 20:26 |
*** cpuga has quit IRC | 20:29 | |
*** cpuga_ has joined #openstack-ansible | 20:29 | |
*** jrniemijr has quit IRC | 20:31 | |
*** cpuga_ has quit IRC | 20:34 | |
*** thorst has quit IRC | 20:35 | |
jamesdenton | asura The 300 is the expected response from the service. The interval and IP indicates the healthcheck from haproxy. | 20:39 |
jamesdenton | In my AIO, it looks like apache is restarted every 24 hours. Guess there's a cron or something | 20:39 |
*** cshen_ has quit IRC | 20:42 | |
jamesdenton | It's possible the playbook is restarting the service and they next play is simply timing out waiting for it to come back. Not sure what the retry interval is. | 20:42 |
jamesdenton | 5 sec delay, 12 retries | 20:43 |
jamesdenton | you can try modifying /etc/ansible/roles/os_keystone/tasks/keystone_service_setup.yml and increasing the number of retries in that tasks - or let it fail again on the next run and pop into the container and see how long it takes for the service to come up, if ever | 20:44 |
*** yusef has quit IRC | 20:44 | |
asura | Is there a way to start haproxy manual inside the container? | 20:44 |
asura | or whatever service is running on 35357 | 20:45 |
asura | I increased the verbosity of the playbook https://pastebin.com/VLeu2v5i | 20:46 |
jamesdenton | well haproxy lives outside that container and appears to be working OK based on those logs. The deploy node is attempting to hit the individual service directly, and is timing out due to 'connection refused'. Apache is listening on 5000 and 35357 in the keystone container | 20:48 |
jamesdenton | And you were able to verify there was nothing listening on 5000|35357? Using netstat? | 20:48 |
asura | root@deploy-keystone-container-ad839eb8:~# netcat -z -v localhost 35357 netcat: connect to localhost port 35357 (tcp) failed: Connection refused; same for 5000 | 20:51 |
asura | output of ps -aux inside container and tailf of /var/log/syslog https://pastebin.com/NYz1nr5e | 20:51 |
asura | I don't see apache running and systemctl restart apache don't work | 20:52 |
LiterateHawk | Apache's not on | 20:52 |
LiterateHawk | journalctl -u apache will dump out log | 20:52 |
asura | says no entires | 20:52 |
asura | think i'll restart the container and see if apache starts | 20:53 |
asura | You know your desperate when you have to turn it off and back on again :) | 20:54 |
LiterateHawk | It's okay, I've been deleting and recreating this container, which I think is a more extreme version of the same thing | 20:54 |
asura | Yeah, now apache is running again... | 20:55 |
*** oneswig has joined #openstack-ansible | 20:56 | |
asura | Both ports 5000 and 35357 are working as well | 20:56 |
*** tobberydberg has quit IRC | 20:57 | |
*** tobberydberg has joined #openstack-ansible | 20:57 | |
*** tobberydberg has quit IRC | 21:01 | |
openstackgerrit | Merged openstack/openstack-ansible-tests master: test-setup-swifthosts: Optimize xfsprogs installation https://review.openstack.org/482646 | 21:03 |
*** kristian__ has quit IRC | 21:03 | |
*** jvidal has quit IRC | 21:05 | |
*** vnogin has joined #openstack-ansible | 21:16 | |
*** smatzek has quit IRC | 21:17 | |
*** kylek3h has quit IRC | 21:19 | |
*** admin0 has joined #openstack-ansible | 21:20 | |
*** pcaruana has quit IRC | 21:23 | |
jamesdenton | asura I was able to recreate your issue. Digging into it | 21:23 |
asura | really? | 21:23 |
jamesdenton | was the environment already deployed to some extent? | 21:24 |
asura | Well, I don't think so | 21:25 |
asura | I just followed the user guide | 21:25 |
asura | I ran it again only on this error | 21:25 |
jamesdenton | hmm ok | 21:25 |
LiterateHawk | Rabbitmq is getting confused because it's expecting a hostname with underscores, but "hostname" in the container returns hyphens | 21:26 |
LiterateHawk | Does that sound crazy? | 21:26 |
*** vnogin has quit IRC | 21:27 | |
LiterateHawk | I can take the command that fails in the playbook, swap out the hostname and it works | 21:28 |
jamesdenton | LiterateHawk Is this an upgrade? | 21:28 |
LiterateHawk | jamesdenton blank install | 21:29 |
asura | Well, I did a systemctl restart apache2.service right when the error occurs | 21:29 |
jamesdenton | That's been an issue before but i don't think i've seen it in a new install | 21:29 |
asura | and I think it is running past it | 21:29 |
jamesdenton | asura Yes that would do it. There's a restart task missing, i think | 21:29 |
*** vnogin has joined #openstack-ansible | 21:30 | |
LiterateHawk | jamesdenton, It's taken more than one failed run to get to here, so maybe there's some old state. I've deleted and recreated the containers, but that didn't tick it over | 21:30 |
asura | I have a new error in the glance container https://pastebin.com/L74RLKCr | 21:30 |
asura | That will have to wait til tomorrow | 21:31 |
jamesdenton | yeah i;'ve gotta bolt, to. I may open a bug for this keystone thing if i nail it down | 21:31 |
asura | Thanks for the help | 21:31 |
*** thorst has joined #openstack-ansible | 21:35 | |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible-rsyslog_server master: Consolidate package install tasks https://review.openstack.org/482715 | 21:41 |
*** thorst has quit IRC | 21:42 | |
openstackgerrit | weezer su proposed openstack/openstack-ansible-ops master: Do not exit if the REDEPLOY_EXTRA_SCRIPT is null or not set https://review.openstack.org/482716 | 21:45 |
*** dfflanders has joined #openstack-ansible | 21:48 | |
*** systems-sk has quit IRC | 21:55 | |
*** perniciouscaffei has quit IRC | 22:00 | |
LiterateHawk | Ah yeah, this appears to be the issue, /etc/rabbitmq/rabbitmq.config doesn't exist, which causes erlang to use the hostname and not the container name. It's strange though, the bits that set the config are after the parts that set the policy | 22:02 |
*** vnogin has quit IRC | 22:05 | |
*** oneswig has quit IRC | 22:07 | |
*** perniciouscaffei has joined #openstack-ansible | 22:09 | |
*** markvoelker has quit IRC | 22:16 | |
*** markvoelker has joined #openstack-ansible | 22:17 | |
*** kristian__ has joined #openstack-ansible | 22:20 | |
*** kristian__ has quit IRC | 22:25 | |
*** jbadiapa_ has joined #openstack-ansible | 22:29 | |
*** acormier has quit IRC | 22:29 | |
*** acormier has joined #openstack-ansible | 22:29 | |
*** jbadiapa has quit IRC | 22:31 | |
*** perniciouscaffei has quit IRC | 22:33 | |
*** acormier has quit IRC | 22:34 | |
*** galstrom is now known as galstrom_zzz | 22:38 | |
openstackgerrit | Jimmy McCrory proposed openstack/openstack-ansible master: Restart glance services only when necessary https://review.openstack.org/482727 | 22:40 |
*** brad[] has quit IRC | 22:46 | |
*** weezS has quit IRC | 22:47 | |
*** admin0 has quit IRC | 22:48 | |
*** brad[] has joined #openstack-ansible | 22:49 | |
*** ricardoas1 has quit IRC | 22:51 | |
*** ricardoas has joined #openstack-ansible | 22:53 | |
*** charcol has quit IRC | 22:58 | |
*** perniciouscaffei has joined #openstack-ansible | 23:02 | |
*** cpuga has joined #openstack-ansible | 23:02 | |
*** chyka has quit IRC | 23:07 | |
*** cpuga has quit IRC | 23:12 | |
LiterateHawk | I can't seem to figure out how rabbitmq is supposed to be configured to set nodename to the ansible version (with _) instead of the container's hostname (with -). I cant find anything in the role that actually sets is | 23:18 |
*** klamath has quit IRC | 23:25 | |
*** perniciouscaffei has quit IRC | 23:28 | |
*** weezS has joined #openstack-ansible | 23:31 | |
*** weezS has quit IRC | 23:40 | |
*** thorst has joined #openstack-ansible | 23:47 | |
*** dxiri has quit IRC | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!