openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 00:14 |
---|---|---|
snowman4839 | cloudnull: I mean should it fail out of the playbook if haproxy doesn't come up since other things like the pip install rely on the haproxy address to work correctly? | 00:18 |
snowman4839 | I've had two separate installs that failed to bring up haproxy correctly (one because of conflicting listening ports and one I don't remember why) and the subsequent playbooks failed because of it but kept on marching | 00:19 |
snowman4839 | Also just a note for others, my problems with the memcached slowing down everything on my test environment seems to have disappeared on my production install. Running the stock playbook works great on my 64GB/32 core nodes but my 16GB/8 core nodes had trouble with it | 00:23 |
snowman4839 | keystone is responding fine and memcached servers and databases are running great | 00:24 |
*** markvoelker_ has quit IRC | 00:38 | |
*** woodard_ has joined #openstack-ansible | 00:40 | |
*** woodard has quit IRC | 00:40 | |
*** thorst has joined #openstack-ansible | 00:49 | |
*** thorst has quit IRC | 00:51 | |
logan- | cloudnull snowman4839: i might not be a good example because i collapse everything into mgmt network so i don't have a storage bridge | 00:59 |
*** newmember has joined #openstack-ansible | 01:11 | |
*** markvoelker has joined #openstack-ansible | 01:23 | |
snowman4839 | logan-: Not trying to come off as rude, but isn't that a security risk? | 01:27 |
*** markvoelker has quit IRC | 01:27 | |
*** acormier has joined #openstack-ansible | 01:28 | |
*** markvoelker has joined #openstack-ansible | 01:32 | |
*** markvoelker has quit IRC | 01:36 | |
*** markvoelker has joined #openstack-ansible | 01:41 | |
*** acormier has quit IRC | 01:45 | |
*** acormier has joined #openstack-ansible | 01:45 | |
logan- | snowman4839: how so? | 01:49 |
*** acormier has quit IRC | 01:50 | |
logan- | snowman4839: same control plane hosts/communicating with each other either way, so i don't quite follow. but i do think you should apply firewall rules everywhere to prevent any unnecessary traffic between control plane hosts/containers | 01:55 |
*** acormier has joined #openstack-ansible | 01:56 | |
*** markvoelker has quit IRC | 02:14 | |
*** acormier has quit IRC | 02:15 | |
*** acormier has joined #openstack-ansible | 02:16 | |
SamYaple | snowman4839: anything on the mgmt network should be considered secure, because memcache itself has no security | 02:18 |
*** vnogin has joined #openstack-ansible | 02:18 | |
SamYaple | snowman4839: if you have clients talking to your ceph cluster outside of the openstack cluster, then you would want a seperate storage network. otherwise, no real added security sperating them | 02:19 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible-os_neutron stable/pike: Add support for Neutron FWaaS v2 https://review.openstack.org/509551 | 02:19 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 02:20 |
*** acormier has quit IRC | 02:20 | |
*** vnogin has quit IRC | 02:23 | |
logan- | yeah i think the big drivers for a separate storage network would be if you had an existing san that you were trying to integrate with cinder and you wanted to bridge into that storage network | 02:27 |
logan- | or if you had separate physical nics for storage in your openstack env (maybe higher speed than your mgmt network nics) and wanted to separate the traffic by bridging them separately | 02:27 |
cloudnull | ^ we do this frequently. 1gib mgmt, 10gib for storage, network, etc | 02:29 |
*** acormier has joined #openstack-ansible | 02:50 | |
SamYaple | yep thats my setup as well | 02:52 |
*** thorst has joined #openstack-ansible | 02:52 | |
*** dave-mccowan has quit IRC | 02:54 | |
*** thorst has quit IRC | 02:57 | |
snowman4839 | ah I guess that makes sense | 03:05 |
*** markvoelker has joined #openstack-ansible | 03:05 | |
snowman4839 | you don't know pain until you've gone through an entire install until you've gone through an entire install just to realize you swapped the external and internal lb vip :-( | 03:05 |
* snowman4839 facepalms | 03:06 | |
*** gkadam has joined #openstack-ansible | 03:10 | |
*** markvoelker has quit IRC | 03:10 | |
*** dxiri has joined #openstack-ansible | 03:11 | |
*** markvoelker has joined #openstack-ansible | 03:14 | |
*** snowman4839 has quit IRC | 03:14 | |
cloudnull | snowman4839 you should be able to just change it and rerun the plays | 03:17 |
cloudnull | no need to start from scratch | 03:17 |
cloudnull | if your playbooks ran through the openstack parts | 03:17 |
cloudnull | drop the keystone db and just rerun setup-everything.yml | 03:17 |
cloudnull | much faster than starting from 0 | 03:17 |
*** ianychoi_ has joined #openstack-ansible | 03:19 | |
*** ianychoi has quit IRC | 03:21 | |
*** xar- has quit IRC | 03:27 | |
*** snowman4839 has joined #openstack-ansible | 03:31 | |
*** xar- has joined #openstack-ansible | 03:32 | |
*** acormier has quit IRC | 03:45 | |
*** acormier has joined #openstack-ansible | 03:46 | |
*** markvoelker has quit IRC | 03:48 | |
*** acormier has quit IRC | 03:50 | |
*** xar- has quit IRC | 04:13 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 04:14 |
*** xar- has joined #openstack-ansible | 04:17 | |
*** germs has quit IRC | 04:17 | |
*** markvoelker has joined #openstack-ansible | 04:38 | |
*** markvoelker has quit IRC | 04:45 | |
*** markvoelker has joined #openstack-ansible | 04:50 | |
*** markvoelker has quit IRC | 04:51 | |
*** thorst has joined #openstack-ansible | 04:53 | |
*** thorst has quit IRC | 05:00 | |
*** gouthamr has joined #openstack-ansible | 05:22 | |
*** armaan has joined #openstack-ansible | 05:42 | |
*** gkadam has quit IRC | 05:49 | |
*** armaan has quit IRC | 05:49 | |
*** armaan has joined #openstack-ansible | 05:50 | |
*** armaan has quit IRC | 05:51 | |
*** gouthamr has quit IRC | 05:53 | |
*** armaan has joined #openstack-ansible | 06:55 | |
*** thorst has joined #openstack-ansible | 06:56 | |
*** thorst has quit IRC | 07:01 | |
*** armaan has quit IRC | 07:02 | |
*** snowman4839 has quit IRC | 07:23 | |
*** dxiri has quit IRC | 07:39 | |
*** mma has joined #openstack-ansible | 08:09 | |
*** armaan has joined #openstack-ansible | 08:13 | |
*** mma has quit IRC | 08:21 | |
*** mma has joined #openstack-ansible | 08:21 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible master: Initial integrated zuulv3 jobs https://review.openstack.org/513406 | 08:23 |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_glance stable/pike: Initial OSA zuul v3 role jobs https://review.openstack.org/513421 | 08:24 |
*** mma has quit IRC | 08:25 | |
*** mma has joined #openstack-ansible | 08:30 | |
*** mma has quit IRC | 08:32 | |
*** yolanda has quit IRC | 08:33 | |
*** snowman4839 has joined #openstack-ansible | 08:37 | |
*** dxiri has joined #openstack-ansible | 08:40 | |
*** dxiri has quit IRC | 08:44 | |
*** thorst has joined #openstack-ansible | 08:57 | |
*** dxiri has joined #openstack-ansible | 09:01 | |
*** thorst has quit IRC | 09:02 | |
*** taseer2 is now known as Taseer | 09:05 | |
*** armaan has quit IRC | 09:05 | |
*** dxiri has quit IRC | 09:06 | |
*** dxiri has joined #openstack-ansible | 09:18 | |
*** dxiri has quit IRC | 09:22 | |
*** dxiri has joined #openstack-ansible | 09:30 | |
*** Neptu has quit IRC | 09:34 | |
*** dxiri has quit IRC | 09:35 | |
*** gunix has joined #openstack-ansible | 09:36 | |
gunix | which bridge is for provider networks for the vms? | 09:37 |
*** pbandark has joined #openstack-ansible | 09:38 | |
*** dxiri has joined #openstack-ansible | 09:41 | |
*** dxiri has quit IRC | 09:45 | |
*** armaan has joined #openstack-ansible | 09:55 | |
*** dxiri has joined #openstack-ansible | 09:55 | |
*** pbandark has quit IRC | 09:55 | |
*** dxiri has quit IRC | 10:00 | |
*** Neptu has joined #openstack-ansible | 10:09 | |
*** dxiri has joined #openstack-ansible | 10:10 | |
*** dxiri has quit IRC | 10:14 | |
*** dxiri has joined #openstack-ansible | 10:24 | |
*** dxiri has quit IRC | 10:28 | |
*** armaan has quit IRC | 10:34 | |
*** dxiri has joined #openstack-ansible | 10:39 | |
*** dxiri has quit IRC | 10:43 | |
Tahvok | odyssey4me: hope you can find a minute to reply on this case: https://bugs.launchpad.net/openstack-ansible/+bug/1687594 | 10:44 |
openstack | Launchpad bug 1687594 in openstack-ansible "no configuration for osa neutron to configure external dns yet" [Wishlist,In progress] - Assigned to Albert Mikaelyan (tahvok) | 10:44 |
*** dxiri has joined #openstack-ansible | 10:57 | |
*** thorst has joined #openstack-ansible | 10:58 | |
*** dxiri has quit IRC | 11:02 | |
*** thorst has quit IRC | 11:02 | |
*** dxiri has joined #openstack-ansible | 11:12 | |
*** dxiri has quit IRC | 11:17 | |
*** thorst has joined #openstack-ansible | 11:21 | |
*** thorst has quit IRC | 11:21 | |
*** dxiri has joined #openstack-ansible | 11:26 | |
*** armaan has joined #openstack-ansible | 11:27 | |
*** dxiri has quit IRC | 11:31 | |
*** armaan has quit IRC | 11:31 | |
*** dave-mccowan has joined #openstack-ansible | 11:35 | |
*** dxiri has joined #openstack-ansible | 11:41 | |
*** dxiri has quit IRC | 11:45 | |
*** dxiri has joined #openstack-ansible | 11:55 | |
*** cshen has joined #openstack-ansible | 11:56 | |
*** dxiri has quit IRC | 12:00 | |
*** armaan has joined #openstack-ansible | 12:04 | |
*** dxiri has joined #openstack-ansible | 12:10 | |
*** dxiri has quit IRC | 12:14 | |
*** dxiri has joined #openstack-ansible | 12:43 | |
*** dxiri has quit IRC | 12:48 | |
*** dxiri has joined #openstack-ansible | 12:58 | |
*** dxiri has quit IRC | 13:02 | |
*** dxiri has joined #openstack-ansible | 13:12 | |
*** dxiri has quit IRC | 13:17 | |
*** thorst has joined #openstack-ansible | 13:22 | |
*** thorst has quit IRC | 13:27 | |
gunix | i am following this tutorial: https://docs.openstack.org/project-deploy-guide/openstack-ansible/newton/app-config-prod.html#production-environment-config | 13:28 |
gunix | my question is: what if i do not specify the rsyslog? | 13:29 |
gunix | what if i just don't want to deploy that server? | 13:29 |
gunix | can i just leave it out? | 13:29 |
gunix | or will something crash because the nodes expect an rsyslog? | 13:29 |
*** dxiri_ has joined #openstack-ansible | 13:30 | |
*** dxiri_ has quit IRC | 13:35 | |
*** dxiri has joined #openstack-ansible | 13:41 | |
*** dxiri has quit IRC | 13:45 | |
cloudnull | gunix: sorry if this is double posting, my connection dropped and IDK what got sent | 13:45 |
cloudnull | gunix: re- bridges for provider networks, that's totally up to you | 13:45 |
cloudnull | typically we use br-vlan | 13:45 |
cloudnull | re- rsyslog, you can leave it out. | 13:45 |
cloudnull | nothing will crash however no logging will be shipped to a central localtion | 13:45 |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 13:50 |
openstackgerrit | Merged openstack/openstack-ansible-os_glance stable/pike: Initial OSA zuul v3 role jobs https://review.openstack.org/513421 | 13:53 |
*** dxiri has joined #openstack-ansible | 13:55 | |
*** aaron has joined #openstack-ansible | 13:56 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 13:56 |
lagman | Hi, I made a localise mirror of pip modules, all the modules are there, but when i run the openstack-infrastructre playbook, I get this error on "pip_install : Install pip packages" No matching distribution found for pyasn1==modules | 13:56 |
*** aaron is now known as Guest31691 | 13:56 | |
lagman | can someone shed somelight on what I've done wrong? | 13:56 |
cloudnull | can you paste the error ? | 13:57 |
cloudnull | is this happening on all of your hosts? | 13:57 |
lagman | cloudnull https://pastebin.com/myYfBbha | 13:58 |
lagman | Im running the all-in-one for testing | 13:59 |
*** dxiri has quit IRC | 14:00 | |
cloudnull | can you hit | 14:01 |
cloudnull | http://172.29.236.100:8181/os-releases/15.1.10/ubuntu-16.04-x86_64/requirements_absolute_requirements.txt | 14:01 |
lagman | cloudnull yeah i can | 14:01 |
cloudnull | its odd that its trying to use "modules" as the version number. | 14:02 |
lagman | cloudnull also python==memcached | 14:02 |
cloudnull | try just rerunning repo-build.yml with the force rebuild flag: `openstack-ansible repo-build.yml -e repo_build_git_reclone=true -e repo_build_wheel_rebuild=true -e repo_build_venv_rebuild=true` | 14:04 |
cloudnull | then rerun the failing play | 14:04 |
*** Jeffrey4l has quit IRC | 14:05 | |
lagman | cloudnull the same error | 14:05 |
*** Jeffrey4l has joined #openstack-ansible | 14:06 | |
cloudnull | whats the task name where it fails? | 14:06 |
lagman | cloudnull TASK [pip_install : Install pip packages] | 14:07 |
*** Guest31691 has quit IRC | 14:11 | |
cloudnull | what checkout are you using ? | 14:13 |
cloudnull | it looks like its installing https://github.com/openstack/openstack-ansible-pip_install/blob/stable/ocata/vars/ubuntu-16.04.yml#L29-L33 | 14:14 |
cloudnull | using the following command: /usr/local/bin/pip2 install -U --constraint http://172.29.236.100:8181/os-releases/15.1.10/ubuntu-16.04-x86_64/requirements_absolute_requirements.txt --trusted-host --index-url=http://openstack.org/simple pyasn1 pyOpenSSL requests urllib3 | 14:15 |
cloudnull | which is pulling from pypi with that constraint file | 14:15 |
lagman | cloudnull stable/ocata | 14:15 |
cloudnull | are you seeing the busted versions in your constraint file too ? | 14:15 |
cloudnull | or is this potentially something coming from pypi ? | 14:16 |
lagman | let me check | 14:17 |
lagman | cloudnull no in my constraint file is pyasn1<=0.1.9 | 14:18 |
cloudnull | in that requirement file | 14:20 |
cloudnull | what does requirements_absolute_requirements.txt (line 147)) say ? | 14:21 |
cloudnull | is there a duplicate ? | 14:21 |
cloudnull | you could try destroying the repo containers, then rebuild them ? | 14:21 |
cloudnull | `openstack-ansible lxc-container-destory.yml --limit repo_all` | 14:21 |
lagman | i have i still get this erro | 14:22 |
cloudnull | `openstack-ansible lxc-container-create.yml --limit repo_all` | 14:22 |
cloudnull | then | 14:22 |
cloudnull | `openstack-ansible repo-install.yml` | 14:22 |
*** dxiri has joined #openstack-ansible | 14:28 | |
gunix | cloudnull: thank you for the help. i don't know who financed OSA, but it's incredible work | 14:29 |
gunix | if i managed to get this working, there might be another company on the openstack sponsor list | 14:29 |
*** dave-mccowan has quit IRC | 14:32 | |
*** dxiri has quit IRC | 14:33 | |
cloudnull | woot! | 14:37 |
cloudnull | it's been a community effort, so welcome to the community :) | 14:38 |
cloudnull | lagman: I'm trying to reproduce that error, and im at a loss. | 14:38 |
cloudnull | I think the best bet is to nuke and rebuild the repo infra | 14:39 |
*** dxiri has joined #openstack-ansible | 14:43 | |
*** cshen has quit IRC | 14:44 | |
*** dxiri has quit IRC | 14:45 | |
*** dxiri has joined #openstack-ansible | 14:45 | |
spotz | Woot! | 14:58 |
*** aaron has joined #openstack-ansible | 15:00 | |
*** aaron is now known as Guest46057 | 15:00 | |
*** Guest46057 has quit IRC | 15:02 | |
lagman | cloudnull i think its my fault for messing to much with the repos, I'm just gonna discard the changes to the pip | 15:05 |
*** thorst has joined #openstack-ansible | 15:23 | |
*** aaron__ has joined #openstack-ansible | 15:26 | |
*** thorst has quit IRC | 15:27 | |
*** aaron__ has quit IRC | 15:33 | |
*** aaron__ has joined #openstack-ansible | 15:41 | |
*** aaron__ has quit IRC | 15:44 | |
openstackgerrit | Merged openstack/openstack-ansible-os_nova master: Update upgrade role for Queens from P https://review.openstack.org/496679 | 15:58 |
evrardjp | wow. Nova merged. | 16:06 |
*** dave-mccowan has joined #openstack-ansible | 16:47 | |
*** newmember has quit IRC | 16:49 | |
*** Adri2000 has joined #openstack-ansible | 16:57 | |
*** Adri2000 has quit IRC | 16:57 | |
*** Adri2000 has joined #openstack-ansible | 16:57 | |
*** vnogin has joined #openstack-ansible | 16:58 | |
openstackgerrit | Merged openstack/openstack-ansible-os_keystone stable/pike: Initial OSA zuul v3 role jobs https://review.openstack.org/513623 | 17:14 |
*** vnogin has quit IRC | 17:25 | |
*** vnogin has joined #openstack-ansible | 17:33 | |
*** mma has joined #openstack-ansible | 17:39 | |
gunix | should i run osa with sudo or give my user rights to access the files or make a special user for osa? | 17:45 |
*** germs has joined #openstack-ansible | 17:47 | |
*** dave-mccowan has quit IRC | 17:50 | |
*** vnogin has quit IRC | 17:55 | |
gunix | nevermind that last question, that is irelevant | 18:03 |
gunix | here is a real question: i don't have an IP/subnet for haproxy_keepalived_external_vip_cidr and i am kind of confused to why this IP/range is different from the one on br-mgmt | 18:04 |
gunix | also i don't understand why VIP has a range and not just an IP | 18:04 |
gunix | if i am missing some basic knowledge about openstack, feel free to point me to an article without explaining much :D | 18:04 |
*** thorst has joined #openstack-ansible | 18:05 | |
*** thorst has quit IRC | 18:06 | |
*** rodolof has joined #openstack-ansible | 18:14 | |
*** mma has quit IRC | 18:46 | |
*** rodolof has quit IRC | 19:10 | |
*** cshen has joined #openstack-ansible | 19:22 | |
*** snowman4839 has quit IRC | 19:50 | |
*** snowman4839 has joined #openstack-ansible | 19:54 | |
*** thorst has joined #openstack-ansible | 20:07 | |
*** dxiri has quit IRC | 20:07 | |
*** dxiri has joined #openstack-ansible | 20:08 | |
*** thorst has quit IRC | 20:11 | |
*** snowman4839 has quit IRC | 21:14 | |
*** snowman4839 has joined #openstack-ansible | 21:15 | |
*** snowman48391 has joined #openstack-ansible | 21:17 | |
*** snowman4839 has quit IRC | 21:17 | |
openstackgerrit | Kevin Carter (cloudnull) proposed openstack/openstack-ansible master: Improve execution time by using dynamic groups https://review.openstack.org/513876 | 21:33 |
*** cshen has quit IRC | 21:39 | |
*** snowman48391 has quit IRC | 21:55 | |
*** snowman4839 has joined #openstack-ansible | 22:03 | |
*** markvoelker has joined #openstack-ansible | 22:04 | |
*** thorst has joined #openstack-ansible | 22:08 | |
*** thorst has quit IRC | 22:12 | |
*** jbadiapa has quit IRC | 22:15 | |
*** jbadiapa has joined #openstack-ansible | 22:31 | |
*** markvoelker has quit IRC | 22:48 | |
*** dxiri has quit IRC | 22:49 | |
*** markvoelker has joined #openstack-ansible | 22:53 | |
*** markvoelker has quit IRC | 23:06 | |
*** thorst has joined #openstack-ansible | 23:08 | |
*** thorst has quit IRC | 23:09 | |
*** armaan has quit IRC | 23:12 | |
openstackgerrit | Jean-Philippe Evrard proposed openstack/openstack-ansible-os_swift stable/pike: Initial OSA zuul v3 role jobs https://review.openstack.org/513813 | 23:37 |
*** mma has joined #openstack-ansible | 23:48 | |
*** mma has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!